Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

mediaplayer.exe,pop ups all over, and fix it ads. [Solved]


  • This topic is locked This topic is locked

#1
Huntersrain

Huntersrain

    Member

  • Member
  • PipPip
  • 24 posts
Not sure how I even picked it up, but now every time I need to open a tab or click to view something I get mediaplayer warnings, and various pop ups for fake sites asking me to download Java, Adobe, and other items, but it's also causing my laptop to overheat, and sometimes making it difficult to close anything down.
I have tried various programs (CCleaner, Spy Bot etc) to get rid of it and nothing seems to work.

OTL logfile created on: 3/11/2014 6:10:30 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.99 Gb Total Physical Memory | 1.27 Gb Available Physical Memory | 42.41% Memory free
6.20 Gb Paging File | 4.26 Gb Available in Paging File | 68.66% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 174.85 Gb Total Space | 87.50 Gb Free Space | 50.04% Space Free | Partition Type: NTFS
Drive D: | 11.46 Gb Total Space | 1.99 Gb Free Space | 17.33% Space Free | Partition Type: NTFS

Computer Name: MINWINPC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2014/03/11 18:10:23 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\User\Downloads\OTL.exe
PRC - [2014/03/10 19:32:17 | 002,539,544 | ---- | M] () -- C:\Program Files\AVG SafeGuard toolbar\vprot.exe
PRC - [2014/03/10 19:32:16 | 001,759,768 | ---- | M] (AVG Secure Search) -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\ToolbarUpdater.exe
PRC - [2014/03/10 19:32:16 | 000,159,768 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\loggingserver.exe
PRC - [2014/02/20 15:45:06 | 004,505,368 | ---- | M] (Piriform Ltd) -- C:\Program Files\CCleaner\CCleaner.exe
PRC - [2014/02/17 21:34:18 | 000,223,112 | ---- | M] (Google Inc.) -- C:\Users\User\AppData\Local\Google\Update\1.3.22.5\GoogleCrashHandler.exe
PRC - [2014/01/22 12:19:38 | 003,788,816 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgidsagent.exe
PRC - [2014/01/22 12:17:36 | 004,962,320 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgui.exe
PRC - [2013/12/18 13:42:32 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/11/25 22:03:56 | 000,591,888 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgcsrvx.exe
PRC - [2013/11/25 22:00:24 | 000,892,944 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgnsx.exe
PRC - [2013/11/13 22:03:10 | 000,729,616 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgrsx.exe
PRC - [2013/09/24 01:33:08 | 000,348,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgwdsvc.exe
PRC - [2013/08/20 23:53:02 | 000,335,408 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2014\avgcfgex.exe
PRC - [2013/06/05 01:01:52 | 004,489,472 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\User\AppData\Local\Akamai\netsession_win.exe
PRC - [2013/05/15 10:17:34 | 000,554,408 | ---- | M] (Lavasoft) -- C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
PRC - [2012/09/21 13:46:38 | 001,191,768 | ---- | M] (Lavasoft Limited) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2012/09/21 13:46:36 | 001,737,728 | ---- | M] (Lavasoft Limited ) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2010/05/17 14:24:16 | 000,308,592 | ---- | M] (Eastman Kodak Company) -- C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe
PRC - [2010/05/07 10:42:00 | 001,638,400 | ---- | M] (Eastman Kodak Company) -- C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
PRC - [2010/03/31 03:37:18 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009/04/11 01:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/01/26 16:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2007/10/03 17:45:02 | 000,358,936 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2007/10/03 17:44:58 | 000,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe


========== Modules (No Company Name) ==========

MOD - [2014/03/10 19:32:17 | 002,539,544 | ---- | M] () -- C:\Program Files\AVG SafeGuard toolbar\vprot.exe
MOD - [2014/03/10 19:32:17 | 000,519,704 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\log4cplusU.dll
MOD - [2014/03/01 21:35:25 | 000,394,568 | ---- | M] () -- C:\Users\User\AppData\Local\Google\Chrome\Application\33.0.1750.146\ppgooglenaclpluginchrome.dll
MOD - [2014/03/01 21:35:24 | 013,632,840 | ---- | M] () -- C:\Users\User\AppData\Local\Google\Chrome\Application\33.0.1750.146\PepperFlash\pepflashplayer.dll
MOD - [2014/03/01 21:35:23 | 004,061,000 | ---- | M] () -- C:\Users\User\AppData\Local\Google\Chrome\Application\33.0.1750.146\pdf.dll
MOD - [2014/03/01 21:35:17 | 001,647,432 | ---- | M] () -- C:\Users\User\AppData\Local\Google\Chrome\Application\33.0.1750.146\ffmpegsumo.dll
MOD - [2014/03/01 21:35:15 | 000,051,016 | ---- | M] () -- C:\Users\User\AppData\Local\Google\Chrome\Application\33.0.1750.146\chrome_elf.dll
MOD - [2014/01/25 01:30:43 | 004,591,616 | ---- | M] () -- C:\Users\User\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.5.0\libGLESv2.dll
MOD - [2014/01/25 01:30:43 | 000,112,128 | ---- | M] () -- C:\Users\User\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.5.0\libEGL.dll
MOD - [2013/12/19 11:36:50 | 000,039,192 | ---- | M] () -- C:\Program Files\CCleaner\branding.dll
MOD - [2013/01/28 14:08:56 | 000,087,952 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2013/01/28 14:08:28 | 001,242,512 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2012/06/14 04:00:46 | 001,801,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\18050fc0ebf2c4835d05ffd337aa1616\System.Deployment.ni.dll
MOD - [2012/06/14 03:57:55 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll
MOD - [2012/06/14 03:57:41 | 001,592,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll
MOD - [2012/05/25 04:25:00 | 000,921,600 | ---- | M] () -- C:\Program Files\Yahoo!\Messenger\yui.dll
MOD - [2012/05/10 15:18:34 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll
MOD - [2012/05/10 12:42:39 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012/05/10 12:38:34 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012/05/10 12:37:54 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2010/08/16 19:02:43 | 000,135,168 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Inkjet.Localization\5.3.4.0__5cc7ad8abd921325\Inkjet.Localization.dll
MOD - [2010/08/16 19:02:40 | 000,049,152 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Inkjet.Diagnostics\5.3.4.0__5cc7ad8abd921325\Inkjet.Diagnostics.dll
MOD - [2010/08/16 19:02:39 | 000,069,632 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Inkjet.Automation\5.3.4.0__5cc7ad8abd921325\Inkjet.Automation.dll
MOD - [2009/11/03 19:14:04 | 000,054,272 | ---- | M] () -- C:\Program Files\Notepad++\NppShell_01.dll
MOD - [2007/12/19 21:27:04 | 000,066,856 | ---- | M] () -- C:\Program Files\HP\QuickPlay\Kernel\common\MCEMediaStatus.dll
MOD - [2007/08/20 07:10:18 | 000,249,856 | ---- | M] () -- C:\Windows\System32\igfxTMM.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SBSDWSCService)
SRV - [2014/03/10 19:32:16 | 001,759,768 | ---- | M] (AVG Secure Search) [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\ToolbarUpdater.exe -- (vToolbarUpdater18.0.0)
SRV - [2014/02/20 16:57:28 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/01/22 12:19:38 | 003,788,816 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2014\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2013/12/18 13:42:32 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/09/24 01:33:08 | 000,348,008 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2014\avgwdsvc.exe -- (avgwd)
SRV - [2013/07/01 15:11:24 | 004,569,856 | ---- | M] () [Auto | Running] -- c:\program files\common files\akamai/netsession_win_8fa3539.dll -- (Akamai)
SRV - [2013/03/01 12:11:32 | 000,161,384 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/09/21 13:46:36 | 001,737,728 | ---- | M] (Lavasoft Limited ) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2010/05/17 14:24:16 | 000,308,592 | ---- | M] (Eastman Kodak Company) [Auto | Running] -- C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe -- (Kodak AiO Network Discovery Service)
SRV - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/01/20 21:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/10/03 17:45:02 | 000,358,936 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
SRV - [2007/03/05 11:30:06 | 000,110,592 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -- (Com4Qlb)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIMMP)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIM)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - [2014/03/10 19:32:17 | 000,042,784 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtpx86.sys -- (avgtp)
DRV - [2014/01/19 21:46:54 | 000,022,808 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgidsshimx.sys -- (AVGIDSShim)
DRV - [2013/11/25 21:56:22 | 000,210,712 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgidsdriverx.sys -- (AVGIDSDriver)
DRV - [2013/11/25 21:56:22 | 000,149,272 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avgidshx.sys -- (AVGIDSHX)
DRV - [2013/11/25 21:49:18 | 000,120,600 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgdiskx.sys -- (Avgdiskx)
DRV - [2013/10/31 23:00:28 | 000,176,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2013/10/31 22:30:08 | 000,222,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avglogx.sys -- (Avglogx)
DRV - [2013/10/01 00:49:38 | 000,102,712 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2013/09/10 00:43:20 | 000,027,448 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avgrkx86.sys -- (Avgrkx86)
DRV - [2013/08/01 16:08:52 | 000,193,848 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2013/07/05 18:13:06 | 000,013,560 | ---- | M] (GFI Software) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\gfibto.sys -- (gfibto)
DRV - [2012/07/31 05:42:48 | 000,181,344 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudmdm.sys -- (ssudmdm)
DRV - [2012/07/31 05:42:48 | 000,083,168 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus)
DRV - [2012/01/30 12:17:40 | 000,133,632 | ---- | M] (HTC Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\htcusbnet.sys -- (htcusbnet)
DRV - [2011/02/21 20:00:13 | 000,064,512 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\Windows\System32\drivers\Lbd.sys -- (Lbd)
DRV - [2011/02/21 20:00:12 | 000,015,232 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys -- (Lavasoft Kernexplorer)
DRV - [2009/05/03 22:32:16 | 000,049,904 | R--- | M] (Avanquest Software) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BVRPMPR5.SYS -- (BVRPMPR5)
DRV - [2008/02/27 06:26:04 | 000,201,728 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService)
DRV - [2007/10/11 06:17:56 | 000,176,640 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CHDART.sys -- (HdAudAddService)
DRV - [2007/07/10 09:27:56 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2007/06/25 06:53:10 | 000,155,136 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2007/06/18 18:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2007/05/30 17:40:42 | 000,735,232 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2007/04/23 16:51:08 | 000,050,176 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2006/11/02 02:30:56 | 000,429,056 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvm60x32.sys -- (NVENETFD)
DRV - [2006/06/28 11:54:00 | 000,009,472 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CPQBttn.sys -- (HBtnKey)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{668BC79E-B388-40B0-8A62-E8C0F200850A}: "URL" = http://search.yahoo....ing}&fr=hp-psdt
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\..\SearchScopes\{8B0A8A63-D27E-476E-BCF7-9614A7362469}: "URL" = http://www.ask.com/w...}&l=dis&o=uscqd

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
IE - HKCU\..\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}: "URL" = http://search.condui...rchTerms}&SSPV=
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://lavasoft.blek...q={searchTerms}
IE - HKCU\..\SearchScopes\{668BC79E-B388-40B0-8A62-E8C0F200850A}: "URL" = http://search.yahoo....ing}&fr=hp-psdt
IE - HKCU\..\SearchScopes\{68605E39-123D-4AB2-814E-1CA2E51130D6}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...1I7SUNA_enUS289
IE - HKCU\..\SearchScopes\{8B0A8A63-D27E-476E-BCF7-9614A7362469}: "URL" = http://www.ask.com/w...}&l=dis&o=uscqd
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local>;*.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo....ch?fr=ffsp1&p="
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.1.20091029021655
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:12.0.0.2222
FF - prefs.js..extensions.enabledItems: {F53C93F1-07D5-430c-86D4-C9531B27DFAF}:12.0.0.2189
FF - prefs.js..extensions.enabledItems: {5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}:1.26
FF - prefs.js..keyword.URL: "http://search.yahoo....ch?fr=ffds1&p="
FF - prefs.js..browser.search.selectedEngine: "SecureSearch"


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\18.0.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.732: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=1.0.0.0: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.732: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.1: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\User\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\User\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/01/28 20:07:16 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/01/28 20:07:16 | 000,000,000 | ---D | M]

[2009/03/20 01:44:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Extensions
[2014/02/28 17:18:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\extensions
[2010/07/30 23:48:49 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2013/03/13 19:45:09 | 000,000,000 | ---D | M] (Wajam) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\extensions\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}
[2010/03/19 04:28:16 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2013/05/22 17:08:16 | 000,000,000 | ---D | M] (Ad-Aware Security Add-on) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c}
[2014/02/28 17:18:38 | 000,000,000 | ---D | M] ("MediaPlayerEnhance") -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\extensions\[email protected]5ac7300ac.com
[2014/02/28 16:44:45 | 000,000,000 | ---D | M] ("Plus-HD-7.5") -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\extensions\[email protected]8abef45e2.com
[2013/01/28 21:20:23 | 000,000,000 | ---D | M] ("Shopping Sidekick Plugin") -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\extensions\[email protected]
[2013/05/22 16:21:53 | 000,000,000 | ---D | M] (Lavasoft Search Plugin) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\extensions\[email protected]
[2013/01/28 21:20:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\extensions\[email protected]\chrome
[2013/01/28 21:20:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\extensions\[email protected]\defaults
[2013/01/28 21:20:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\extensions\[email protected]\locale
[2013/01/28 21:20:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\extensions\[email protected]\skin
[2014/02/28 17:18:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\extensions\[email protected]5ac7300ac.com\extensionData
[2014/02/28 17:18:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\extensions\[email protected]5ac7300ac.com\extensionData\plugins
[2014/02/28 17:18:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\extensions\[email protected]5ac7300ac.com\extensionData\userCode
[2014/02/28 16:44:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\extensions\[email protected]8abef45e2.com\extensionData
[2014/02/28 16:44:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\extensions\[email protected]8abef45e2.com\extensionData\plugins
[2014/02/28 16:44:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\extensions\[email protected]8abef45e2.com\extensionData\userCode
[2013/01/28 21:20:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\extensions\[email protected]\chrome\content\extensionCode
[2013/01/28 21:18:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\kqf52soc.default\extensions
[2009/03/20 02:50:27 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\kqf52soc.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/10/13 12:27:00 | 000,037,914 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\kqf52soc.default\extensions\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi
[2014/02/16 19:40:23 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/05/23 21:10:10 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/11/04 18:59:13 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/02/15 13:45:45 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/07/04 10:49:32 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) -- C:\PROGRAM FILES\AVG\AVG2012\FIREFOX
File not found (No name found) -- C:\PROGRAM FILES\AVG\AVG2012\FIREFOX\DONOTTRACK
[2013/05/22 16:21:49 | 000,000,628 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\adawaretb.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\33.0.1750.146\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\33.0.1750.146\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\33.0.1750.146\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files\Garmin GPS Plugin\npGarmin.dll
CHR - plugin: Google Update (Enabled) = C:\Users\User\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: RealNetworks Rhapsody Player Engine (Enabled) = C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Swag Bucks = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apjkpjchfbckhjhokinlgdbmibpbbjak\10.26.9.505_0\
CHR - Extension: Swag Bucks = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apjkpjchfbckhjhokinlgdbmibpbbjak\10.26.9.505_0\nativeMessaging\nmHost
CHR - Extension: YouTube = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Shopping Sidekick Plugin = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\crossrider
CHR - Extension: Shopping Sidekick Plugin = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\
CHR - Extension: Plus-HD-7.5 = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbiodiodggnlakggeeckkjccjhhjndnb\12667.9222.4976_0\crossrider
CHR - Extension: Plus-HD-7.5 = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbiodiodggnlakggeeckkjccjhhjndnb\12667.9222.4976_0\
CHR - Extension: Love Smoke = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgibfhhccaknggplelmbaepoikkcnllb\1_0\
CHR - Extension: Speed Check = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\0.2_0\
CHR - Extension: Google Wallet = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Lavasoft NewTab = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\oejkcgajlodefenbbjdnaiahmbnnoole\0.9_0\
CHR - Extension: Gmail = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2006/09/18 16:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Ad-Aware Security Add-on) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files\adawaretb\adawareDx.dll ()
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Ad-Aware Security Add-on) - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files\adawaretb\adawareDx.dll ()
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Conime] C:\Windows\System32\conime.exe (Microsoft Corporation)
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe File not found
O4 - HKLM..\Run: [hpqSRMon] File not found
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [SearchProtection] C:\ProgramData\Search Protection\_run.bat ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [VMM Mode Selection] C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe ()
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG SafeGuard toolbar\vprot.exe ()
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\User\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKCU..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103470 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; InfoPath.2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; BO1IE8_v1;ENUS)" -"http://www.bastideto...jewellery.html" File not found
O4 - Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Verizon Wireless Software Utility Application for Android – Samsung.lnk = C:\Users\User\AppData\Roaming\Verizon\UA_ar\UA.exe (SAMSUNG Electornics Co., Ltd.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll ()
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: phoenix.edu ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: toolwire.com ([]* in Trusted sites)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{225C21AF-2FD1-4017-97F3-FFB266B81B98}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3CD21868-936F-405C-97DD-23C7597DF5F9}: DhcpNameServer = 198.224.148.135 198.224.149.135
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8DEF383B-2B60-4C98-A533-3021E62890F6}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner - No CLSID value found
O18 - Protocol\Handler\livecall - No CLSID value found
O18 - Protocol\Handler\msnim - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\18.0.0\ViProtocol.dll (AVG Secure Search)
O20 - AppInit_DLLs: (c:\progra~1\searchprotect\searchprotect\bin\spvc32loader.dll) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\User\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\User\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/22 11:35:03 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2005/09/11 10:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ]
O33 - MountPoints2\{3617a61e-f137-11de-865f-001eec744cb8}\Shell - "" = AutoRun
O33 - MountPoints2\{3617a61e-f137-11de-865f-001eec744cb8}\Shell\AutoRun\command - "" = G:\start.exe
O33 - MountPoints2\{3617a62f-f137-11de-865f-001eec744cb8}\Shell - "" = AutoRun
O33 - MountPoints2\{3617a62f-f137-11de-865f-001eec744cb8}\Shell\AutoRun\command - "" = I:\start.exe
O33 - MountPoints2\{6b704b5f-6d0a-11e3-b6a5-001eec744cb8}\Shell - "" = AutoRun
O33 - MountPoints2\{6b704b5f-6d0a-11e3-b6a5-001eec744cb8}\Shell\AutoRun\command - "" = F:\TLBootstrap_WPP.exe
O33 - MountPoints2\{7de53ad6-0ba7-11e3-8b85-001eec744cb8}\Shell - "" = AutoRun
O33 - MountPoints2\{7de53ad6-0ba7-11e3-8b85-001eec744cb8}\Shell\AutoRun\command - "" = F:\VZW_Software_upgrade_assistant_installer.exe
O33 - MountPoints2\{938ab858-646b-11e3-8b81-001eec744cb8}\Shell - "" = AutoRun
O33 - MountPoints2\{938ab858-646b-11e3-8b81-001eec744cb8}\Shell\AutoRun\command - "" = G:\TL-Bootstrap.exe
O33 - MountPoints2\{f1a0561d-c2fd-11e2-9fd4-001eec744cb8}\Shell - "" = AutoRun
O33 - MountPoints2\{f1a0561d-c2fd-11e2-9fd4-001eec744cb8}\Shell\AutoRun\command - "" = G:\TL-Bootstrap.exe
O33 - MountPoints2\{f1a060da-c2fd-11e2-9fd4-001eec744cb8}\Shell - "" = AutoRun
O33 - MountPoints2\{f1a060da-c2fd-11e2-9fd4-001eec744cb8}\Shell\AutoRun\command - "" = F:\TL-Bootstrap.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2014/03/10 21:11:05 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\AVG SafeGuard toolbar
[2014/03/10 19:33:50 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\AVG2014
[2014/03/10 19:33:44 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\TuneUp Software
[2014/03/10 19:33:01 | 000,042,784 | ---- | C] (AVG Technologies) -- C:\Windows\System32\drivers\avgtpx86.sys
[2014/03/10 19:32:21 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Secure Search
[2014/03/10 19:32:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AVG Secure Search
[2014/03/10 19:32:21 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG SafeGuard toolbar
[2014/03/10 19:32:20 | 000,000,000 | ---D | C] -- C:\Program Files\AVG SafeGuard toolbar
[2014/03/10 19:29:47 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2014
[2014/03/10 19:28:09 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\MFAData
[2014/03/10 19:28:09 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Avg2014
[2014/02/28 17:02:04 | 000,000,000 | ---D | C] -- C:\Program Files\Uninstaller
[2014/02/28 16:47:12 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Tuguu_SL
[2014/02/28 16:43:18 | 000,000,000 | ---D | C] -- C:\Program Files\MediaPlayerEnhance
[2014/02/28 16:42:47 | 000,000,000 | ---D | C] -- C:\Program Files\Plus-HD-7.5
[5 C:\Users\User\Desktop\*.tmp files -> C:\Users\User\Desktop\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2014/03/11 17:57:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/03/11 17:48:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA1cd3fa9daec4ce5.job
[2014/03/11 17:40:00 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2626124740-2734390021-4155123068-1001UA.job
[2014/03/11 17:35:55 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2014/03/11 17:35:55 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2014/03/11 15:46:00 | 000,001,580 | ---- | M] () -- C:\Windows\tasks\MediaPlayerEnhance-updater.job
[2014/03/11 15:46:00 | 000,001,494 | ---- | M] () -- C:\Windows\tasks\Plus-HD-7.5-updater.job
[2014/03/11 15:46:00 | 000,001,348 | ---- | M] () -- C:\Windows\tasks\Plus-HD-7.5-enabler.job
[2014/03/11 15:45:01 | 000,001,450 | ---- | M] () -- C:\Windows\tasks\Plus-HD-7.5-codedownloader.job
[2014/03/11 15:45:00 | 000,001,536 | ---- | M] () -- C:\Windows\tasks\MediaPlayerEnhance-codedownloader.job
[2014/03/11 15:44:59 | 000,001,434 | ---- | M] () -- C:\Windows\tasks\MediaPlayerEnhance-enabler.job
[2014/03/11 15:44:01 | 000,002,300 | ---- | M] () -- C:\Windows\tasks\Plus-HD-7.5-firefoxinstaller.job
[2014/03/11 15:44:00 | 000,003,106 | ---- | M] () -- C:\Windows\tasks\MediaPlayerEnhance-chromeinstaller.job
[2014/03/11 15:44:00 | 000,002,368 | ---- | M] () -- C:\Windows\tasks\MediaPlayerEnhance-firefoxinstaller.job
[2014/03/11 15:43:02 | 000,002,378 | ---- | M] () -- C:\Windows\tasks\Plus-HD-7.5-validator.job
[2014/03/11 13:43:20 | 000,604,502 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014/03/11 13:43:20 | 000,104,170 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014/03/11 13:38:10 | 000,000,279 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2014/03/11 13:36:06 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore1cd3fa9da20e695.job
[2014/03/11 13:35:54 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/03/11 13:35:51 | 3210,756,096 | -HS- | M] () -- C:\hiberfil.sys
[2014/03/11 13:19:04 | 000,012,594 | ---- | M] () -- C:\Users\User\Documents\cc_20140311_131854.reg
[2014/03/11 13:14:39 | 000,000,804 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014/03/11 12:14:07 | 000,000,064 | ---- | M] () -- C:\Windows\System32\rp_stats.dat
[2014/03/11 12:14:07 | 000,000,044 | ---- | M] () -- C:\Windows\System32\rp_rules.dat
[2014/03/10 19:33:44 | 000,000,842 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2014.lnk
[2014/03/10 19:32:17 | 000,042,784 | ---- | M] (AVG Technologies) -- C:\Windows\System32\drivers\avgtpx86.sys
[2014/03/09 20:40:02 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2626124740-2734390021-4155123068-1001Core.job
[2014/03/05 17:38:48 | 000,016,004 | ---- | M] () -- C:\Users\User\Documents\cc_20140305_163842.reg
[2014/03/05 16:57:16 | 000,039,448 | ---- | M] () -- C:\Users\User\Desktop\feb072014.pdf
[2014/03/05 16:56:56 | 000,039,459 | ---- | M] () -- C:\Users\User\Desktop\feb212014.pdf
[2014/02/28 23:47:55 | 000,151,569 | ---- | M] () -- C:\Users\User\Desktop\abef3481_8098703695_e96a1fe55d.jpeg
[2014/02/27 15:25:52 | 000,050,875 | ---- | M] () -- C:\Users\User\Desktop\mouse1.png
[2014/02/26 17:14:27 | 000,101,487 | ---- | M] () -- C:\Users\User\Desktop\il_570xN.559965597_le7f.jpg
[2014/02/26 00:44:19 | 000,035,003 | ---- | M] () -- C:\Users\User\Desktop\1624144_10152207086321907_484763309_n.jpg
[2014/02/26 00:44:07 | 000,032,966 | ---- | M] () -- C:\Users\User\Desktop\1608973_10152206384966907_1818589810_n.jpg
[2014/02/26 00:39:18 | 000,059,312 | ---- | M] () -- C:\Users\User\Desktop\il_570xN.549183430_jahv.jpg
[2014/02/17 11:48:23 | 000,382,351 | ---- | M] () -- C:\Users\User\Desktop\1926242_262927033870092_1701453597_o.jpg
[5 C:\Users\User\Desktop\*.tmp files -> C:\Users\User\Desktop\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2014/03/11 13:35:51 | 3210,756,096 | -HS- | C] () -- C:\hiberfil.sys
[2014/03/11 13:18:57 | 000,012,594 | ---- | C] () -- C:\Users\User\Documents\cc_20140311_131854.reg
[2014/03/10 19:33:44 | 000,000,842 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2014.lnk
[2014/03/05 17:38:44 | 000,016,004 | ---- | C] () -- C:\Users\User\Documents\cc_20140305_163842.reg
[2014/03/05 16:57:16 | 000,039,448 | ---- | C] () -- C:\Users\User\Desktop\feb072014.pdf
[2014/03/05 16:56:47 | 000,039,459 | ---- | C] () -- C:\Users\User\Desktop\feb212014.pdf
[2014/02/28 23:47:51 | 000,151,569 | ---- | C] () -- C:\Users\User\Desktop\abef3481_8098703695_e96a1fe55d.jpeg
[2014/02/28 16:46:07 | 000,001,494 | ---- | C] () -- C:\Windows\tasks\Plus-HD-7.5-updater.job
[2014/02/28 16:46:05 | 000,001,580 | ---- | C] () -- C:\Windows\tasks\MediaPlayerEnhance-updater.job
[2014/02/28 16:45:56 | 000,001,348 | ---- | C] () -- C:\Windows\tasks\Plus-HD-7.5-enabler.job
[2014/02/28 16:45:51 | 000,001,434 | ---- | C] () -- C:\Windows\tasks\MediaPlayerEnhance-enabler.job
[2014/02/28 16:45:27 | 000,001,450 | ---- | C] () -- C:\Windows\tasks\Plus-HD-7.5-codedownloader.job
[2014/02/28 16:45:24 | 000,001,536 | ---- | C] () -- C:\Windows\tasks\MediaPlayerEnhance-codedownloader.job
[2014/02/28 16:44:10 | 000,002,368 | ---- | C] () -- C:\Windows\tasks\MediaPlayerEnhance-firefoxinstaller.job
[2014/02/28 16:43:59 | 000,002,300 | ---- | C] () -- C:\Windows\tasks\Plus-HD-7.5-firefoxinstaller.job
[2014/02/28 16:43:32 | 000,003,106 | ---- | C] () -- C:\Windows\tasks\MediaPlayerEnhance-chromeinstaller.job
[2014/02/28 16:43:13 | 000,002,378 | ---- | C] () -- C:\Windows\tasks\Plus-HD-7.5-validator.job
[2014/02/27 15:25:51 | 000,050,875 | ---- | C] () -- C:\Users\User\Desktop\mouse1.png
[2014/02/26 17:14:27 | 000,101,487 | ---- | C] () -- C:\Users\User\Desktop\il_570xN.559965597_le7f.jpg
[2014/02/26 00:44:18 | 000,035,003 | ---- | C] () -- C:\Users\User\Desktop\1624144_10152207086321907_484763309_n.jpg
[2014/02/26 00:44:07 | 000,032,966 | ---- | C] () -- C:\Users\User\Desktop\1608973_10152206384966907_1818589810_n.jpg
[2014/02/26 00:39:15 | 000,059,312 | ---- | C] () -- C:\Users\User\Desktop\il_570xN.549183430_jahv.jpg
[2014/02/17 11:48:13 | 000,382,351 | ---- | C] () -- C:\Users\User\Desktop\1926242_262927033870092_1701453597_o.jpg
[2014/01/25 17:17:12 | 000,000,280 | ---- | C] () -- C:\Windows\wininit.ini
[2013/07/22 00:32:15 | 000,802,115 | ---- | C] () -- C:\Users\User\IMAG0143.jpg
[2009/03/20 02:53:32 | 000,000,081 | ---- | C] () -- C:\Users\User\CTX.DAT
[2009/02/16 01:16:27 | 000,004,096 | -H-- | C] () -- C:\Users\User\AppData\Local\keyfile3.drm
[2009/01/20 11:34:30 | 000,008,585 | ---- | C] () -- C:\Users\User\redheadscreenav.jpg
[2009/01/12 00:55:48 | 000,038,912 | ---- | C] () -- C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/09/07 19:37:20 | 000,000,000 | ---- | C] () -- C:\Users\User\AppData\Roaming\wklnhst.dat
[2008/08/22 08:32:50 | 000,006,324 | ---- | C] () -- C:\Users\User\AppData\Local\d3d9caps.dat
[2008/08/21 18:39:05 | 000,980,110 | ---- | C] () -- C:\ProgramData\LuUninstall.LiveUpdate

========== ZeroAccess Check ==========

[2006/11/02 07:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2011/01/21 11:35:22 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/11 01:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 01:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/11/06 21:15:37 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Ad-Aware Antivirus
[2011/04/20 01:49:02 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Avery
[2014/03/10 19:33:50 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\AVG2014
[2010/04/03 12:16:13 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\ChaosPro
[2010/04/03 12:24:04 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\ChaosPro 4.0
[2010/07/22 17:38:37 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/12/05 15:05:27 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\com.imeem.DesktopUploader.6C3F108F466C0F04F30B58747CAA4DF34281133B.1
[2014/02/16 19:36:59 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Garmin
[2008/10/18 23:02:40 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\GetRightToGo
[2011/02/08 12:56:45 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\ICAClient
[2010/04/05 13:56:25 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\iLike
[2009/12/21 02:57:05 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\IrfanView
[2010/12/04 23:20:51 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\JCreator
[2010/06/27 20:59:25 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Notepad++
[2010/10/24 11:44:03 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Registry Mechanic
[2010/08/21 15:37:21 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2010/08/16 18:57:01 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Temp
[2011/02/23 20:22:32 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Template
[2014/03/10 19:33:44 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TuneUp Software
[2008/08/20 11:00:33 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\WildTangent

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 176 bytes -> C:\ProgramData\TEMP:288A91F8
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:D1B5B4F1

< End of report >
  • 0

Advertisements


#2
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 10,962 posts
:welcome:
Posted Image Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

Download : ADWCleaner to your desktop.

NOTE: If using Internet Explorer and get an alert that stops the program downloading, click on the warning and allow the download to complete.

Close all programs and click on the AdwCleaner icon.

Posted Image

Click on Scan and follow the prompts. Let it run unhindered. When done, click on the Clean button, and follow the prompts. Allow the system to reboot. You will then be presented with the report. Copy & Paste this report on your next reply.

The report will be saved in the C:\AdwCleaner folder. as AdwCleaner[S0].txt

Posted Image Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Make sure that under Optional Scans, there is a checkmark on Addition.txt and Shortcut.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another two logs (Addition.txt and Shortcut.txt). Please attach these to your reply.

  • 0

#3
Huntersrain

Huntersrain

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.2 (02.20.2014:1)
OS: Windows Vista ™ Home Premium x86
Ran by User on Tue 03/11/2014 at 20:56:41.47
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\searchprotection
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\protector_dll.protectorbho
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\protector_dll.protectorbho.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\yt.ytnavassistplugin
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\yt.ytnavassistplugin.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\viprotocol.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\yahoopartnertoolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\adawarebp
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\axmetastream.metastreamctl
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\axmetastream.metastreamctl.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\axmetastream.metastreamctlsecondary
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\axmetastream.metastreamctlsecondary.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\protocols\handler\viprotocol
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\scripthelper.scripthelperapi
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\scripthelper.scripthelperapi.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\speedupmypc
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\viprotocol.viprotocolole
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\viprotocol.viprotocolole.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0021802.BHO
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0021802.BHO.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0021802.Sandbox
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0021802.Sandbox.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0044150.BHO
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0044150.BHO.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0044150.Sandbox
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0044150.Sandbox.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0050776.BHO
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0050776.BHO.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0050776.Sandbox
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0050776.Sandbox.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550255185502}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550455415550}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550555075576}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660266186602}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660466416650}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660566076676}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440244184402}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440444414450}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440544074476}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0021802.BHO
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0021802.BHO.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0021802.Sandbox
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0021802.Sandbox.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0044150.BHO
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0044150.BHO.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0044150.Sandbox
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0044150.Sandbox.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0050776.BHO
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0050776.BHO.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0050776.Sandbox
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0050776.Sandbox.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550255185502}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550455415550}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550555075576}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660266186602}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660466416650}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660566076676}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440244184402}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440444414450}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440544074476}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211181102}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110211181102}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{68605E39-123D-4AB2-814E-1CA2E51130D6}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}



~~~ Files

Successfully deleted: [File] C:\Windows\System32\Tasks\Plus-HD-7.5-codedownloader
Successfully deleted: [File] C:\Windows\System32\Tasks\Plus-HD-7.5-enabler
Successfully deleted: [File] C:\Windows\System32\Tasks\Plus-HD-7.5-firefoxinstaller
Successfully deleted: [File] C:\Windows\System32\Tasks\Plus-HD-7.5-updater
Successfully deleted: [File] C:\Windows\System32\Tasks\Plus-HD-7.5-validator
Successfully deleted: [File] C:\Windows\System32\Tasks\Updater21802.exe
Successfully deleted: [File] C:\Windows\Tasks\Plus-HD-7.5-codedownloader.job
Successfully deleted: [File] C:\Windows\Tasks\Plus-HD-7.5-enabler.job
Successfully deleted: [File] C:\Windows\Tasks\Plus-HD-7.5-firefoxinstaller.job
Successfully deleted: [File] C:\Windows\Tasks\Plus-HD-7.5-updater.job
Successfully deleted: [File] C:\Windows\Tasks\Plus-HD-7.5-validator.job
Successfully deleted: [File] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ebay.lnk"



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\blekko toolbars"
Successfully deleted: [Folder] "C:\ProgramData\search protection"
Successfully deleted: [Folder] "C:\ProgramData\trymedia"
Successfully deleted: [Folder] "C:\ProgramData\viewpoint"
Successfully deleted: [Folder] "C:\Users\User\AppData\Roaming\getrighttogo"
Successfully deleted: [Folder] "C:\Users\User\AppData\Roaming\registry mechanic"
Successfully deleted: [Folder] "C:\Users\User\appdata\local\adawarebp"
Successfully deleted: [Folder] "C:\Users\User\appdata\local\cre"
Successfully deleted: [Folder] "C:\Users\User\appdata\locallow\adawaretb"
Successfully deleted: [Folder] "C:\Program Files\adawaretb"
Successfully deleted: [Folder] "C:\Program Files\viewpoint"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 03/11/2014 at 21:02:55.54
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

# AdwCleaner v3.021 - Report created 11/03/2014 at 21:07:44
# Updated 10/03/2014 by Xplode
# Operating System : Windows Vista ™ Home Premium Service Pack 2 (32 bits)
# Username : User - MINWINPC
# Running from : C:\Users\User\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\AVG SafeGuard toolbar
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\Program Files\AVG SafeGuard toolbar
Folder Deleted : C:\Program Files\Toolbar Cleaner
Folder Deleted : C:\Program Files\MediaPlayerEnhance
Folder Deleted : C:\Program Files\Plus-HD-7.5
Folder Deleted : C:\Program Files\Common Files\AVG Secure Search
Folder Deleted : C:\Users\User\AppData\Local\AVG SafeGuard toolbar
Folder Deleted : C:\Users\User\AppData\LocalLow\AVG SafeGuard toolbar
Folder Deleted : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\adawaretb
Folder Deleted : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\Extensions\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}
Folder Deleted : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
Folder Deleted : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\kqf52soc.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
Folder Deleted : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\Extensions\[email protected]5ac7300ac.com
Folder Deleted : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\Extensions\[email protected]8abef45e2.com
Folder Deleted : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo
File Deleted : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\kqf52soc.default\Extensions\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\adawaretb.xml
File Deleted : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\user.js
File Deleted : C:\Windows\Tasks\MediaPlayerEnhance-chromeinstaller.job
File Deleted : C:\Windows\System32\Tasks\MediaPlayerEnhance-chromeinstaller
File Deleted : C:\Windows\Tasks\MediaPlayerEnhance-codedownloader.job
File Deleted : C:\Windows\System32\Tasks\MediaPlayerEnhance-codedownloader
File Deleted : C:\Windows\Tasks\MediaPlayerEnhance-enabler.job
File Deleted : C:\Windows\System32\Tasks\MediaPlayerEnhance-enabler
File Deleted : C:\Windows\Tasks\MediaPlayerEnhance-firefoxinstaller.job
File Deleted : C:\Windows\System32\Tasks\MediaPlayerEnhance-firefoxinstaller
File Deleted : C:\Windows\Tasks\MediaPlayerEnhance-updater.job
File Deleted : C:\Windows\System32\Tasks\MediaPlayerEnhance-updater

***** [ Shortcuts ] *****


***** [ Registry ] *****

[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{CFFEB787-EA86-4DCA-A39E-D101F48CFCA1}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CFFEB787-EA86-4DCA-A39E-D101F48CFCA1}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8B0B2970-76FB-467C-9BAF-141B32732C03}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8B0B2970-76FB-467C-9BAF-141B32732C03}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A060A337-4F67-40AD-80D5-C02521F023FF}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A060A337-4F67-40AD-80D5-C02521F023FF}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{CDA700EB-75A3-429D-9367-A9094ABB71BE}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CDA700EB-75A3-429D-9367-A9094ABB71BE}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0F3265D4-568C-448F-AD31-296C54D1B176}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0F3265D4-568C-448F-AD31-296C54D1B176}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{473CA52B-C4C1-4BC2-B85F-4A926139C191}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{473CA52B-C4C1-4BC2-B85F-4A926139C191}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{26145D9A-0982-4D11-BE81-8EFF04E36D41}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{26145D9A-0982-4D11-BE81-8EFF04E36D41}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{785F1573-03D3-4839-A703-781A6A860EB7}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{785F1573-03D3-4839-A703-781A6A860EB7}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9E2D46C3-DFFB-4642-8E8C-BC17E6FDF887}
[#] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9E2D46C3-DFFB-4642-8E8C-BC17E6FDF887}
Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{97D69524-BB57-4185-9C7F-5F05593B771A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{c95b251b-7567-4d60-abbc-8abfcade4bb0}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{daf7e0a7-c1ef-4f95-856f-ae568128a39f}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0b1e3db8-9521-444a-ad6a-033a43ab31ca}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{54765974-2282-4142-9303-bb7fc68715e7}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{6C97A91E-4524-4019-86AF-2AA2D567BF5C}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Key Deleted : HKCU\Software\AVG SafeGuard toolbar
Key Deleted : HKCU\Software\Headlight
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\Software\adawaretb
Key Deleted : HKCU\Software\AppDataLow\Software\Shopping Sidekick Plugin
Key Deleted : HKCU\Software\AppDataLow\Software\MediaPlayerEnhance
Key Deleted : HKCU\Software\AppDataLow\Software\Plus-HD-7.5
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\Software\adawaretb
Key Deleted : HKLM\Software\AVG SafeGuard toolbar
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\Software\MetaStream
Key Deleted : HKLM\Software\Toolbar Cleaner
Key Deleted : HKLM\Software\Trymedia Systems
Key Deleted : HKLM\Software\Viewpoint
Key Deleted : HKLM\Software\MediaPlayerEnhance
Key Deleted : HKLM\Software\Plus-HD-7.5
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG SafeGuard toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A957F04C-49F4-4375-8C8A-D04B769EFE47}_is1
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{E55B3271-7CA8-4D0C-AE06-69A24856E996}_is1
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\adawaretb
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG SafeGuard toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Optimizer Pro_is1
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Shopping Sidekick Plugin
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ViewpointMediaPlayer
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Wajam
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MediaPlayerEnhance
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Plus-HD-7.5
Data Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - 127.0.0.1:9421;<local>;*.local

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16446


-\\ Mozilla Firefox v

[ File : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\prefs.js ]

Line Deleted : user_pref("extensions.crossriderapp21802.adsOldValue", -1);

-\\ Google Chrome v

[ File : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [10950 octets] - [11/03/2014 21:05:25]
AdwCleaner[S0].txt - [10912 octets] - [11/03/2014 21:07:44]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [10973 octets] ##########


Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2014.03.12.01

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
User :: MINWINPC [administrator]

3/11/2014 9:38:27 PM
mbam-log-2014-03-11 (21-38-27).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 230669
Time elapsed: 14 minute(s), 23 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 1
HKLM\SOFTWARE\Google\Chrome\Extensions\apjkpjchfbckhjhokinlgdbmibpbbjak (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 13
C:\Users\User\AppData\Local\Updater21802 (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0 (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\plugins (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\userCode (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\icons (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\icons\actions (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\api (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib\popupResource (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.

Files Detected: 55
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\background.html (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\crossriderManifest.json (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\manifest.json (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\popup.html (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\manifest.xml (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\plugins.json (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\plugins\1000014_GPL Plugin (Loader).js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\plugins\1000015_GPL Background (BG).js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\plugins\13_CrossriderAppUtils.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\plugins\14_CrossriderUtils.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\plugins\17_jQuery.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\plugins\19_CHAppAPIWrapper.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\plugins\1_base.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\plugins\21_debug.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\plugins\22_resources.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\plugins\28_initializer.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\plugins\47_resources_background.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\plugins\4_jquery_1_7_1.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\plugins\64_appApiMessage.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\plugins\72_appApiValidation.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\plugins\78_CrossriderInfo.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\plugins\80_CHPopupAppAPI.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\plugins\97_resourceApiWrapper.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\userCode\background.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\extensionData\userCode\extension.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\icons\icon128.png (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\icons\icon16.png (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\icons\icon48.png (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\icons\actions\1.png (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\background.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\main.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\api\chrome.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\api\cookie.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\api\message.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\api\pageAction.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\api\pageActionBG.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib\app_api.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib\bg_app_api.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib\consts.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib\cookie_store.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib\crossriderAPI.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib\delegate.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib\events.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib\extensionDataStore.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib\installer.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib\logFile.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib\logging.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib\onBGDocumentLoad.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib\reports.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib\storageWrapper.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib\updateManager.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib\util.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib\xhr.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib\popupResource\newPopup.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlopielgodpjhkbapdlbbicpiefpaack\1.25.57_0\js\lib\popupResource\popup.js (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.

(end)

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2014
Ran by User (administrator) on MINWINPC on 11-03-2014 22:51:32
Running from C:\Users\User\Downloads
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingc...can-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingc...can-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Lavasoft Limited ) C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(CyberLink Corp.) C:\Program Files\HP\QuickPlay\QPService.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe
(Lavasoft Limited) C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
(RealNetworks, Inc.) C:\Program Files\Common Files\Real\Update_OB\realsched.exe
(Eastman Kodak Company) C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
() C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Akamai Technologies, Inc.) C:\Users\User\AppData\Local\Akamai\netsession_win.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Eastman Kodak Company) C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(Conexant Systems, Inc.) C:\Windows\system32\DRIVERS\xaudio.exe
(Yahoo! Inc.) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
(Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
(Microsoft Corporation) C:\Windows\system32\wbem\unsecapp.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apntex.exe
() C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
(Akamai Technologies, Inc.) C:\Users\User\AppData\Local\Akamai\netsession_win.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Update\1.3.22.5\GoogleCrashHandler.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Yahoo! Inc.) C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
(Hewlett-Packard) c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\system32\msiexec.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Apoint] - C:\Program Files\Apoint2K\Apoint.exe [159744 2007-06-30] (Alps Electric Co., Ltd.)
HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [178712 2007-10-03] (Intel Corporation)
HKLM\...\Run: [QPService] - C:\Program Files\HP\QuickPlay\QPService.exe [468264 2007-12-19] (CyberLink Corp.)
HKLM\...\Run: [QlbCtrl] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [202032 2007-12-06] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [UCam_Menu] - C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2007-09-13] (CyberLink Corp.)
HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-20] (Microsoft Corporation)
HKLM\...\Run: [hpqSRMon] - [X]
HKLM\...\Run: [HP Health Check Scheduler] - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
HKLM\...\Run: [hpWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [480560 2007-10-03] (Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [HP Software Update] - C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [AppleSyncNotifier] - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [47904 2010-10-08] (Apple Inc.)
HKLM\...\Run: [Ad-Watch] - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [1191768 2012-09-21] (Lavasoft Limited)
HKLM\...\Run: [Conime] - C:\Windows\system32\conime.exe [69120 2009-04-11] (Microsoft Corporation)
HKLM\...\Run: [TkBellExe] - C:\Program Files\Common Files\Real\Update_OB\realsched.exe [202256 2010-03-31] (RealNetworks, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-07-22] (Adobe Systems Incorporated)
HKLM\...\Run: [EKIJ5000StatusMonitor] - C:\Windows\system32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe [1638400 2010-05-07] (Eastman Kodak Company)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-02-20] (Apple Inc.)
HKLM\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [554408 2013-05-15] (Lavasoft)
HKLM\...\Run: [VMM Mode Selection] - C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe [43520 2011-02-14] ()
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2014\avgui.exe [4962320 2014-01-22] (AVG Technologies CZ, s.r.o.)
HKLM\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [1783136 2007-10-01] (Hewlett-Packard)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [455968 2007-08-23] (Hewlett-Packard Company)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\Run: [Messenger (Yahoo!)] - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [6595928 2012-05-25] (Yahoo! Inc.)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\Run: [Akamai NetSession Interface] - C:\Users\User\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\Run: [SpybotSD TeaTimer] - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\Run: [Google Update] - C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-05-20] (Google Inc.)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [18643560 2013-03-01] (Skype Technologies S.A.)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\Run: [CCleaner Monitoring] - C:\Program Files\CCleaner\CCleaner.exe [4505368 2014-02-20] (Piriform Ltd)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\RunOnce: [Shockwave Updater] - C:\Windows\System32\Adobe\Shockwave 11\SwHelper_1100470.exe [460216 2008-11-04] (Adobe Systems, Inc.)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\RunOnce: [Application Restart #6] - C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe [859464 2014-03-01] (Google Inc.)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\MountPoints2: {3617a61e-f137-11de-865f-001eec744cb8} - G:\start.exe
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\MountPoints2: {3617a62f-f137-11de-865f-001eec744cb8} - I:\start.exe
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\MountPoints2: {6b704b5f-6d0a-11e3-b6a5-001eec744cb8} - F:\TLBootstrap_WPP.exe
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\MountPoints2: {7de53ad6-0ba7-11e3-8b85-001eec744cb8} - F:\VZW_Software_upgrade_assistant_installer.exe
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\MountPoints2: {938ab858-646b-11e3-8b81-001eec744cb8} - G:\TL-Bootstrap.exe
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\MountPoints2: {f1a0561d-c2fd-11e2-9fd4-001eec744cb8} - G:\TL-Bootstrap.exe
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\MountPoints2: {f1a060da-c2fd-11e2-9fd4-001eec744cb8} - F:\TL-Bootstrap.exe
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\InprocServer32: [Default-pngfilt] <==== ATTENTION!

Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office Groove.lnk
ShortcutTarget: Microsoft Office Groove.lnk -> C:\Program Files\Microsoft Office\Office12\GROOVE.EXE (Microsoft Corporation)
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Verizon Wireless Software Utility Application for Android – Samsung.lnk
ShortcutTarget: Verizon Wireless Software Utility Application for Android – Samsung.lnk -> C:\Users\User\AppData\Roaming\Verizon\UA_ar\UA.exe (SAMSUNG Electornics Co., Ltd.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
URLSearchHook: HKCU - YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {668BC79E-B388-40B0-8A62-E8C0F200850A} URL = http://search.yahoo....ing}&fr=hp-psdt
SearchScopes: HKLM - {8B0A8A63-D27E-476E-BCF7-9614A7362469} URL = http://www.ask.com/w...}&l=dis&o=uscqd
SearchScopes: HKCU - {668BC79E-B388-40B0-8A62-E8C0F200850A} URL = http://search.yahoo....ing}&fr=hp-psdt
SearchScopes: HKCU - {8B0A8A63-D27E-476E-BCF7-9614A7362469} URL = http://www.ask.com/w...}&l=dis&o=uscqd
BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - No File
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default
FF DefaultSearchEngine: Yahoo
FF SelectedSearchEngine: Yahoo
FF Homepage: hxxp://www.yahoo.com
FF Keyword.URL: hxxp://search.yahoo.com/search?fr=ffds1&p=
FF SelectedSearchEngine: SecureSearch
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 - C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.12.732 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=1.0.3.732 - c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=1.0.0.0 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.732 - c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/RhapsodyPlayerEngine,version=1.1 - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\User\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\User\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Extension: Shopping Sidekick Plugin - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\Extensions\[email protected] [2013-01-28]
FF Extension: Lavasoft Search Plugin - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\Extensions\[email protected] [2013-05-22]
FF Extension: Microsoft .NET Framework Assistant - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-07-30]
FF Extension: Ad-Aware Security Add-on - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\Extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c} [2013-05-22]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} [2009-03-20]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} [2009-03-24]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} [2009-06-18]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [2009-09-03]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} [2009-09-17]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} [2009-11-23]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010-05-23]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2010-11-04]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [2011-02-15]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} [2011-07-04]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-01-28]
FF HKCU\...\Firefox\Extensions: [sma[email protected]] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-01-28]

Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\User\AppData\Local\Google\Chrome\Application\33.0.1750.146\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\User\AppData\Local\Google\Chrome\Application\33.0.1750.146\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\User\AppData\Local\Google\Chrome\Application\33.0.1750.146\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll No File
CHR Plugin: (AVG Internet Security) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\plugins/avgnpss.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll No File
CHR Plugin: (Java™ Platform SE 6 U31) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer™ HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
CHR Plugin: (Garmin Communicator Plug-In) - C:\Program Files\Garmin GPS Plugin\npGarmin.dll No File
CHR Plugin: (Google Update) - C:\Users\User\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (RealNetworks Rhapsody Player Engine) - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
CHR Plugin: (MetaStream 3 Plugin) - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll No File
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-05-20]
CHR Extension: (Google Search) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-05-20]
CHR Extension: (Plus-HD-7.5) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbiodiodggnlakggeeckkjccjhhjndnb [2014-03-04]
CHR Extension: (Love Smoke) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgibfhhccaknggplelmbaepoikkcnllb [2012-06-01]
CHR Extension: (Google Wallet) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-05]
CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-05-20]
CHR HKLM\...\Chrome\Extension: [oejkcgajlodefenbbjdnaiahmbnnoole] - C:\Program Files\adawaretb\chrome-newtab-search.crx [2012-05-20]
CHR HKCU\...\Chrome\Extension: [apjkpjchfbckhjhokinlgdbmibpbbjak] - C:\Users\User\AppData\Local\CRE\apjkpjchfbckhjhokinlgdbmibpbbjak.crx [2012-05-20]
CHR StartMenuInternet: Google Chrome - C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe

========================== Services (Whitelisted) =================

R2 Akamai; c:\program files\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-01] (Akamai Technologies, Inc.)
S2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3788816 2014-01-22] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.)
S3 Com4Qlb; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe [110592 2007-03-05] (Hewlett-Packard Development Company, L.P.)
R2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [65536 2007-09-19] (Hewlett-Packard)
R2 Kodak AiO Network Discovery Service; C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe [308592 2010-05-17] (Eastman Kodak Company)
R2 Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [1737728 2012-09-21] (Lavasoft Limited )
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024 2007-01-09] ()
R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
S2 vToolbarUpdater18.0.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\ToolbarUpdater.exe [X]

==================== Drivers (Whitelisted) ====================

R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [120600 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [210712 2013-11-25] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [149272 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22808 2014-01-19] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [176952 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [222520 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [102712 2013-10-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27448 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [193848 2013-08-01] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [42784 2014-03-10] (AVG Technologies)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [13560 2013-07-05] (GFI Software)
S3 HdAudAddService; C:\Windows\System32\drivers\CHDART.sys [176640 2007-10-11] (Conexant Systems Inc.)
S3 htcusbnet; C:\Windows\System32\DRIVERS\htcusbnet.sys [133632 2012-01-30] (HTC Corporation)
R3 Lavasoft Kernexplorer; C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys [15232 2011-02-21] ()
R0 Lbd; C:\Windows\System32\DRIVERS\Lbd.sys [64512 2011-02-21] (Lavasoft AB)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2014-03-11] (Malwarebytes Corporation)
U1 eabfiltr;
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 SymIM; system32\DRIVERS\SymIM.sys [X]
S3 SymIMMP; system32\DRIVERS\SymIM.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-11 22:51 - 2014-03-11 22:52 - 00031722 _____ () C:\Users\User\Downloads\FRST.txt
2014-03-11 22:51 - 2014-03-11 22:51 - 00000000 ____D () C:\FRST
2014-03-11 22:50 - 2014-03-11 22:50 - 01145856 _____ (Farbar) C:\Users\User\Downloads\FRST.exe
2014-03-11 21:37 - 2014-03-11 21:37 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2014-03-11 21:37 - 2014-03-11 21:37 - 00000906 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-11 21:35 - 2014-03-11 21:36 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-1.75.0.1300.exe
2014-03-11 21:24 - 2014-03-11 21:31 - 00000000 ____D () C:\Users\User\AppData\Local\adawarebp
2014-03-11 21:05 - 2014-03-11 21:12 - 00000000 ____D () C:\AdwCleaner
2014-03-11 21:04 - 2014-03-11 21:04 - 01949184 _____ () C:\Users\User\Downloads\AdwCleaner.exe
2014-03-11 21:02 - 2014-03-11 21:02 - 00012491 _____ () C:\Users\User\Desktop\JRT.txt
2014-03-11 20:57 - 2014-03-11 20:57 - 01037734 _____ (Thisisu) C:\Users\User\Downloads\JRT (1).exe
2014-03-11 20:56 - 2014-03-11 20:56 - 00000000 ____D () C:\Windows\ERUNT
2014-03-11 20:55 - 2014-03-11 20:56 - 01037734 _____ (Thisisu) C:\Users\User\Downloads\JRT.exe
2014-03-11 18:24 - 2014-03-11 18:24 - 00115046 _____ () C:\Users\User\Downloads\OTL.Txt
2014-03-11 18:10 - 2014-03-11 18:10 - 00602112 _____ (OldTimer Tools) C:\Users\User\Downloads\OTL.exe
2014-03-11 13:40 - 2014-03-11 21:35 - 00022782 _____ () C:\Windows\WindowsUpdate.log
2014-03-11 13:18 - 2014-03-11 13:19 - 00012594 _____ () C:\Users\User\Documents\cc_20140311_131854.reg
2014-03-11 13:13 - 2014-03-11 13:13 - 04763560 _____ (Piriform Ltd) C:\Users\User\Downloads\ccsetup411pro.exe
2014-03-10 19:33 - 2014-03-10 19:33 - 00000842 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-03-10 19:33 - 2014-03-10 19:33 - 00000000 ____D () C:\Users\User\AppData\Roaming\TuneUp Software
2014-03-10 19:33 - 2014-03-10 19:33 - 00000000 ____D () C:\Users\User\AppData\Roaming\AVG2014
2014-03-10 19:33 - 2014-03-10 19:32 - 00042784 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys
2014-03-10 19:29 - 2014-03-10 19:33 - 00000000 ____D () C:\ProgramData\AVG2014
2014-03-10 19:28 - 2014-03-10 19:35 - 00000000 ____D () C:\Users\User\AppData\Local\Avg2014
2014-03-10 19:28 - 2014-03-10 19:28 - 04462440 _____ (AVG Technologies) C:\Users\User\Downloads\avg_avct_stb_all_2014_4335_welcomecmp (1).exe
2014-03-10 19:28 - 2014-03-10 19:28 - 00000000 ____D () C:\Users\User\AppData\Local\MFAData
2014-03-10 19:27 - 2014-03-10 19:27 - 04462440 _____ (AVG Technologies) C:\Users\User\Downloads\avg_avct_stb_all_2014_4335_welcomecmp.exe
2014-03-10 19:10 - 2014-03-10 19:11 - 01727624 _____ () C:\Users\User\Downloads\Adaware_Installer (10).exe
2014-03-05 23:06 - 2013-12-18 22:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-03-05 23:06 - 2013-12-18 22:04 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-03-05 23:06 - 2013-12-18 22:03 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-03-05 23:05 - 2014-03-05 23:06 - 00005163 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log
2014-03-05 23:05 - 2013-12-18 22:04 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-03-05 17:38 - 2014-03-05 17:38 - 00016004 _____ () C:\Users\User\Documents\cc_20140305_163842.reg
2014-02-28 23:47 - 2014-02-28 23:47 - 00151569 _____ () C:\Users\User\Desktop\abef3481_8098703695_e96a1fe55d.jpeg
2014-02-28 17:00 - 2014-02-28 17:00 - 04765152 _____ (Piriform Ltd) C:\Users\User\Downloads\ccsetup411.exe
2014-02-28 16:47 - 2014-02-28 16:47 - 00000000 ____D () C:\Users\User\AppData\Local\Tuguu_SL

==================== One Month Modified Files and Folders =======

2014-03-11 22:52 - 2014-03-11 22:51 - 00031722 _____ () C:\Users\User\Downloads\FRST.txt
2014-03-11 22:51 - 2014-03-11 22:51 - 00000000 ____D () C:\FRST
2014-03-11 22:50 - 2014-03-11 22:50 - 01145856 _____ (Farbar) C:\Users\User\Downloads\FRST.exe
2014-03-11 22:48 - 2012-05-31 22:51 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cd3fa9daec4ce5.job
2014-03-11 22:48 - 2012-05-31 22:51 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cd3fa9da20e695.job
2014-03-11 22:40 - 2012-05-20 15:08 - 00000904 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2626124740-2734390021-4155123068-1001UA.job
2014-03-11 21:57 - 2012-04-04 09:08 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-11 21:37 - 2014-03-11 21:37 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2014-03-11 21:37 - 2014-03-11 21:37 - 00000906 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-11 21:37 - 2009-12-22 15:29 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-03-11 21:36 - 2014-03-11 21:35 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-1.75.0.1300.exe
2014-03-11 21:35 - 2014-03-11 13:40 - 00022782 _____ () C:\Windows\WindowsUpdate.log
2014-03-11 21:31 - 2014-03-11 21:24 - 00000000 ____D () C:\Users\User\AppData\Local\adawarebp
2014-03-11 21:31 - 2006-11-02 05:33 - 00703388 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-11 21:27 - 2013-01-28 21:44 - 00000000 ____D () C:\Users\User\AppData\Roaming\Skype
2014-03-11 21:26 - 2008-06-07 10:26 - 00000279 _____ () C:\Users\Public\Documents\hpqp.ini
2014-03-11 21:25 - 2010-07-22 16:47 - 00000000 ____D () C:\Program Files\Common Files\Akamai
2014-03-11 21:25 - 2009-03-04 02:03 - 00000000 ____D () C:\ProgramData\Kodak
2014-03-11 21:25 - 2006-11-02 07:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-11 21:25 - 2006-11-02 07:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-11 21:24 - 2009-02-05 02:06 - 00096667 _____ () C:\aaw7boot.log
2014-03-11 21:24 - 2006-11-02 08:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-11 21:23 - 2006-11-02 08:01 - 00032620 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-11 21:12 - 2014-03-11 21:05 - 00000000 ____D () C:\AdwCleaner
2014-03-11 21:04 - 2014-03-11 21:04 - 01949184 _____ () C:\Users\User\Downloads\AdwCleaner.exe
2014-03-11 21:02 - 2014-03-11 21:02 - 00012491 _____ () C:\Users\User\Desktop\JRT.txt
2014-03-11 20:57 - 2014-03-11 20:57 - 01037734 _____ (Thisisu) C:\Users\User\Downloads\JRT (1).exe
2014-03-11 20:57 - 2012-04-04 09:08 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-03-11 20:57 - 2011-05-17 08:39 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-03-11 20:56 - 2014-03-11 20:56 - 00000000 ____D () C:\Windows\ERUNT
2014-03-11 20:56 - 2014-03-11 20:55 - 01037734 _____ (Thisisu) C:\Users\User\Downloads\JRT.exe
2014-03-11 20:40 - 2012-05-20 15:08 - 00000852 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2626124740-2734390021-4155123068-1001Core.job
2014-03-11 19:12 - 2011-04-22 12:51 - 00000000 ____D () C:\ProgramData\MFAData
2014-03-11 18:24 - 2014-03-11 18:24 - 00115046 _____ () C:\Users\User\Downloads\OTL.Txt
2014-03-11 18:10 - 2014-03-11 18:10 - 00602112 _____ (OldTimer Tools) C:\Users\User\Downloads\OTL.exe
2014-03-11 13:19 - 2014-03-11 13:18 - 00012594 _____ () C:\Users\User\Documents\cc_20140311_131854.reg
2014-03-11 13:16 - 2012-02-26 03:39 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-03-11 13:14 - 2011-04-27 17:19 - 00000804 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-03-11 13:14 - 2011-04-27 17:19 - 00000000 ____D () C:\Program Files\CCleaner
2014-03-11 13:13 - 2014-03-11 13:13 - 04763560 _____ (Piriform Ltd) C:\Users\User\Downloads\ccsetup411pro.exe
2014-03-11 12:14 - 2011-04-26 12:11 - 00000064 _____ () C:\Windows\system32\rp_stats.dat
2014-03-11 12:14 - 2011-04-26 12:11 - 00000044 _____ () C:\Windows\system32\rp_rules.dat
2014-03-10 19:35 - 2014-03-10 19:28 - 00000000 ____D () C:\Users\User\AppData\Local\Avg2014
2014-03-10 19:33 - 2014-03-10 19:33 - 00000842 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-03-10 19:33 - 2014-03-10 19:33 - 00000000 ____D () C:\Users\User\AppData\Roaming\TuneUp Software
2014-03-10 19:33 - 2014-03-10 19:33 - 00000000 ____D () C:\Users\User\AppData\Roaming\AVG2014
2014-03-10 19:33 - 2014-03-10 19:29 - 00000000 ____D () C:\ProgramData\AVG2014
2014-03-10 19:32 - 2014-03-10 19:33 - 00042784 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys
2014-03-10 19:29 - 2008-09-01 14:09 - 00000000 ____D () C:\Program Files\AVG
2014-03-10 19:28 - 2014-03-10 19:28 - 04462440 _____ (AVG Technologies) C:\Users\User\Downloads\avg_avct_stb_all_2014_4335_welcomecmp (1).exe
2014-03-10 19:28 - 2014-03-10 19:28 - 00000000 ____D () C:\Users\User\AppData\Local\MFAData
2014-03-10 19:27 - 2014-03-10 19:27 - 04462440 _____ (AVG Technologies) C:\Users\User\Downloads\avg_avct_stb_all_2014_4335_welcomecmp.exe
2014-03-10 19:11 - 2014-03-10 19:10 - 01727624 _____ () C:\Users\User\Downloads\Adaware_Installer (10).exe
2014-03-05 23:07 - 2008-02-22 12:15 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-03-05 23:06 - 2014-03-05 23:05 - 00005163 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log
2014-03-05 23:06 - 2008-02-22 12:15 - 00000000 ____D () C:\Program Files\Java
2014-03-05 17:38 - 2014-03-05 17:38 - 00016004 _____ () C:\Users\User\Documents\cc_20140305_163842.reg
2014-02-28 23:47 - 2014-02-28 23:47 - 00151569 _____ () C:\Users\User\Desktop\abef3481_8098703695_e96a1fe55d.jpeg
2014-02-28 17:00 - 2014-02-28 17:00 - 04765152 _____ (Piriform Ltd) C:\Users\User\Downloads\ccsetup411.exe
2014-02-28 16:47 - 2014-02-28 16:47 - 00000000 ____D () C:\Users\User\AppData\Local\Tuguu_SL
2014-02-25 20:47 - 2008-10-06 03:40 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-02-16 19:41 - 2010-12-05 14:53 - 00000000 ____D () C:\ProgramData\Screentime
2014-02-16 19:40 - 2009-03-20 01:43 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-16 19:38 - 2009-11-02 16:09 - 00000000 ____D () C:\Program Files\iTunes
2014-02-16 19:36 - 2012-04-03 20:44 - 00000000 ____D () C:\ProgramData\Garmin
2014-02-16 19:36 - 2012-04-03 20:41 - 00000000 ____D () C:\Users\User\AppData\Roaming\Garmin

Files to move or delete:
====================
C:\Users\User\CTX.DAT


Some content of TEMP:
====================
C:\Users\User\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-11 21:32

==================== End Of Log ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-03-2014
Ran by User at 2014-03-11 22:52:23
Running from C:\Users\User\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Lavasoft Ad-Watch Live! Anti-Virus (Disabled - Up to date) {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
AV: AVG AntiVirus 2014 (Disabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus 2014 (Disabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}
AS: Lavasoft Ad-Watch Live! (Disabled - Up to date) {24938260-56EE-C1E5-047B-DC2BDD234BAB}

==================== Installed Programs ======================

Adobe Flash Player 12 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Akamai NetSession Interface (HKCU\...\Akamai) (Version: - Akamai Technologies, Inc)
Amazon Kindle (HKCU\...\Amazon Kindle) (Version: - Amazon)
AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4335 - AVG Technologies)
AVG 2014 (Version: 14.0.3722 - AVG Technologies) Hidden
AVG 2014 (Version: 14.0.4335 - AVG Technologies) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.11 - Piriform)
Google Chrome (HKCU\...\Google Chrome) (Version: 33.0.1750.146 - Google Inc.)
Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Malwarebytes Anti-Malware version 1.75.0.1300 (HKLM\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)

==================== Restore Points =========================

18-02-2014 22:53:06 Scheduled Checkpoint
19-02-2014 16:30:22 Scheduled Checkpoint
21-02-2014 03:13:44 Scheduled Checkpoint
23-02-2014 02:20:17 Scheduled Checkpoint
24-02-2014 06:44:08 Scheduled Checkpoint
05-03-2014 23:11:17 Scheduled Checkpoint
06-03-2014 04:04:27 Installed Java 7 Update 51
06-03-2014 22:55:38 Scheduled Checkpoint
07-03-2014 23:53:05 Scheduled Checkpoint
09-03-2014 01:25:16 Scheduled Checkpoint
09-03-2014 22:48:30 Scheduled Checkpoint
10-03-2014 22:10:05 Scheduled Checkpoint
11-03-2014 14:06:26 Scheduled Checkpoint

==================== Hosts content: ==========================

2006-11-02 05:23 - 2006-09-18 16:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {260D8683-D4D7-4F7F-B000-A52F2C95DC2A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2626124740-2734390021-4155123068-1001UA => C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-20] (Google Inc.)
Task: {2A2DF8A6-1D01-47BC-AFE6-AA414F99B7E5} - System32\Tasks\Microsoft\Windows\RestartManager\{9DA4B300-9B95-4205-9E19-15A6135F6B53} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation)
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {4456BCC1-2C0F-4530-A16F-818DA172C6C6} - System32\Tasks\GoogleUpdateTaskMachineUA1cd3fa9daec4ce5 => C:\Program Files\Google\Update\GoogleUpdate.exe [2009-11-30] (Google Inc.)
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-20] (Microsoft Corporation)
Task: {561CAA10-5CC3-41F8-8A2D-4E842B344516} - System32\Tasks\Registration => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-09-28] ()
Task: {63EDCC5A-641F-4A38-ABB5-5BE4FB4BA6BE} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-09-01] (Lavasoft Limited )
Task: {67D071EF-A2FA-4A57-BB6E-E783045C9D5C} - System32\Tasks\GoogleUpdateTaskMachineCore1cd3fa9da20e695 => C:\Program Files\Google\Update\GoogleUpdate.exe [2009-11-30] (Google Inc.)
Task: {6956B83F-1BD3-4E6F-BF26-14A1EB15F70B} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\netsh.exe [2006-11-02] (Microsoft Corporation)
Task: {81C5EB83-4D48-4D55-82E8-E8B06B806CCB} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2626124740-2734390021-4155123068-1001Core => C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-20] (Google Inc.)
Task: {82967D2E-A303-4806-8168-FF4E45B46F84} - System32\Tasks\IntenetServiceOffers => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-09-28] ()
Task: {83D18536-5D96-4A2D-ACD6-2C63CBDBFBE0} - \Updater21802.exe No Task File
Task: {9F721600-A441-4D56-B5B6-B03B59F0BE7F} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-2626124740-2734390021-4155123068-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2010-02-24] (RealNetworks, Inc.)
Task: {A22D6201-F33D-4430-9110-C02DCA5A273A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-11] (Adobe Systems Incorporated)
Task: {A3E315F2-DE4D-481D-BE81-E7F34573C9C6} - \Plus-HD-7.5-validator No Task File
Task: {A80A7C3F-30C0-4646-8F8B-F5FF1EBEF84E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-02-20] (Piriform Ltd)
Task: {DA364815-6325-479E-AA28-BC728E882426} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {DE0CE6DB-3180-451A-A417-93950A41CB0E} - System32\Tasks\ServicePlan => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-09-28] ()
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-20] ()
Task: {F0074043-46C5-46D7-BCE6-2C96EAA0494D} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-2626124740-2734390021-4155123068-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2010-02-24] (RealNetworks, Inc.)
Task: {F9DDF90F-31F7-45EC-8E34-1C347CBBB289} - System32\Tasks\AdobeAAMUpdater-1.0-GOMEZ-User => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-07-22] (Adobe Systems Incorporated)
Task: {FF69F5B3-5A24-4C47-BA50-7033D8F20454} - System32\Tasks\ExtendedServicePlan => C:\Program Files\Hewlett-Packard\SDP\RemEngine.exe [2007-09-28] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cd3fa9da20e695.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cd3fa9daec4ce5.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2626124740-2734390021-4155123068-1001Core.job => C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2626124740-2734390021-4155123068-1001UA.job => C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\User_Feed_Synchronization-{48099F80-F5FE-45BE-BB2B-59D8AEF45572}.job => C:\Windows\system32\msfeedssync.exe
Task: C:\Windows\Tasks\User_Feed_Synchronization-{8A910C33-6390-47F9-8F44-C19E50D72A95}.job => ?

==================== Loaded Modules (whitelisted) =============

2011-02-21 20:00 - 2011-06-28 06:19 - 00589184 _____ () C:\Program Files\Lavasoft\Ad-Aware\RPAPI.dll
2011-02-21 20:00 - 2011-06-28 06:19 - 00430568 _____ () C:\Program Files\Lavasoft\Ad-Aware\viprebridge.dll
2011-02-21 20:00 - 2011-06-16 10:32 - 00308560 _____ () C:\Program Files\Lavasoft\Ad-Aware\Vipre.dll
2012-07-13 13:45 - 2014-02-07 11:24 - 00190752 _____ () C:\ProgramData\Lavasoft\Ad-Aware\Defs\Extended\libBase64.dll
2012-07-13 13:45 - 2014-02-07 11:24 - 00178464 _____ () C:\ProgramData\Lavasoft\Ad-Aware\Defs\Extended\libMachoUniv.dll
2011-02-22 13:07 - 2011-06-07 04:44 - 00508776 _____ () C:\ProgramData\Lavasoft\Ad-Aware\Defs\thorax.aaw
2007-08-20 07:10 - 2007-08-20 07:10 - 00249856 _____ () C:\Windows\system32\igfxTMM.dll
2013-01-28 14:08 - 2013-01-28 14:08 - 00087952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2013-01-28 14:08 - 2013-01-28 14:08 - 01242512 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-12-22 12:22 - 2011-02-14 08:55 - 00043520 ____R () C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe
2008-06-07 10:24 - 2007-12-19 21:27 - 00066856 _____ () C:\Program Files\HP\QuickPlay\Kernel\Common\MCEMediaStatus.dll
2008-02-22 12:01 - 2007-01-09 04:25 - 00272024 _____ () C:\Program Files\CyberLink\Shared Files\RichVideo.exe
2007-05-16 13:43 - 2007-05-16 13:43 - 00677432 ____R () C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
2009-02-05 02:13 - 2012-05-25 04:25 - 00921600 _____ () C:\Program Files\Yahoo!\Messenger\yui.dll
2014-03-04 11:58 - 2014-03-01 21:35 - 00051016 _____ () C:\Users\User\AppData\Local\Google\Chrome\Application\33.0.1750.146\chrome_elf.dll
2014-03-04 11:58 - 2014-03-01 21:35 - 04061000 _____ () C:\Users\User\AppData\Local\Google\Chrome\Application\33.0.1750.146\pdf.dll
2014-03-04 11:58 - 2014-03-01 21:35 - 00394568 _____ () C:\Users\User\AppData\Local\Google\Chrome\Application\33.0.1750.146\ppGoogleNaClPluginChrome.dll
2014-03-04 11:58 - 2014-03-01 21:35 - 01647432 _____ () C:\Users\User\AppData\Local\Google\Chrome\Application\33.0.1750.146\ffmpegsumo.dll
2014-03-04 11:58 - 2014-03-01 21:35 - 13632840 _____ () C:\Users\User\AppData\Local\Google\Chrome\Application\33.0.1750.146\PepperFlash\pepflashplayer.dll
2014-01-25 01:30 - 2014-01-25 01:30 - 04591616 _____ () C:\Users\User\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.5.0\libglesv2.dll
2014-01-25 01:30 - 2014-01-25 01:30 - 00112128 _____ () C:\Users\User\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.5.0\libegl.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\TEMP:288A91F8
AlternateDataStreams: C:\ProgramData\TEMP:D1B5B4F1

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Lavasoft Ad-Aware Service => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

==================== Disabled items from MSCONFIG ==============


==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Tun Miniport Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunmp
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (03/11/2014 09:25:07 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (03/11/2014 09:47:13 PM) (Source: bowser) (User: )
Description: The master browser has received a server announcement from the computer ELECTRICA-HP
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{8DEF383B-2B60-4C98-A533-3021E.
The master browser is stopping or an election is being forced.

Error: (03/11/2014 09:25:58 PM) (Source: Dhcp) (User: )
Description: Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 001FE17246DD. The following error occurred:
%%121. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Error: (03/11/2014 09:25:08 PM) (Source: Service Control Manager) (User: )
Description: vToolbarUpdater18.0.0%%2

Error: (03/11/2014 09:24:45 PM) (Source: Dhcp) (User: )
Description: The IP address lease 192.168.1.100 for the Network Card with network address 001FE17246DD has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).

Error: (03/11/2014 09:08:15 PM) (Source: DCOM) (User: )
Description: {C2BFE331-6739-4270-86C9-493D9A04CD38}


Microsoft Office Sessions:
=========================
Error: (05/01/2013 11:36:13 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 12 seconds with 0 seconds of active time. This session ended with a crash.

Error: (05/01/2013 11:35:18 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 25 seconds with 0 seconds of active time. This session ended with a crash.

Error: (05/09/2011 01:29:57 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 192789 seconds with 6000 seconds of active time. This session ended with a crash.

Error: (02/06/2009 04:25:37 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6331.5000, Microsoft Office Version: 12.0.6215.1000. This session lasted 26622 seconds with 540 seconds of active time. This session ended with a crash.


CodeIntegrity Errors:
===================================
Date: 2014-03-11 22:51:56.736
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.

Date: 2014-03-11 22:51:56.020
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.

Date: 2014-03-11 22:51:55.410
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.

Date: 2014-03-11 22:51:54.758
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.

Date: 2014-03-11 22:51:54.202
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.

Date: 2014-03-11 22:51:53.626
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.

Date: 2014-03-11 22:51:53.130
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.

Date: 2014-03-11 22:51:52.603
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidsdriverx.sys because the set of per-page image hashes could not be found on the system.

Date: 2014-03-11 21:47:30.989
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.

Date: 2014-03-11 21:47:30.480
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\avgidshx.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Percentage of memory in use: 68%
Total physical RAM: 3061.27 MB
Available physical RAM: 975.76 MB
Total Pagefile: 6348.81 MB
Available Pagefile: 4117.84 MB
Total Virtual: 2047.88 MB
Available Virtual: 1887.09 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:174.85 GB) (Free:86.82 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (PRESARIO_RP) (Fixed) (Total:11.46 GB) (Free:1.99 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 186 GB) (Disk ID: FD02FD02)

Partition: GPT Partition Type.

==================== End Of Log ============================

Users shortcut scan result (x86) Version: 11-03-2014
Ran by User at 2014-03-11 22:54:31
Running from C:\Users\User\Downloads
Boot Mode: Normal
==================== Shortcuts =============================

Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat.com.lnk -> C:\Program Files\Adobe\Acrobat.com\Acrobat.com.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk -> C:\Program Files\Adobe\Adobe Help\Adobe Help.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk -> C:\Windows\Installer\{AC76BA86-7AD7-1033-7B44-AA1000000001}\SC_Reader.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk -> C:\Windows\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\AppleSoftwareUpdateIco.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Play.lnk -> C:\Program Files\HP\QuickPlay\QP.exe (CyberLink Corp.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Total Care Advisor.lnk -> C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe (Hewlett-Packard)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk -> C:\Windows\ehome\ehshell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2007.lnk -> C:\Windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works Task Launcher.lnk -> C:\Program Files\Microsoft Works\MSWorks.exe (Microsoft® Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Safari.lnk -> C:\Windows\Installer\{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}\SafariIco.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Calendar.lnk -> C:\Program Files\Windows Calendar\WinCal.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Collaboration.lnk -> C:\Program Files\Windows Collaboration\WinCollab.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Contacts.lnk -> C:\Program Files\Windows Mail\wab.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Defender.lnk -> C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk -> C:\Program Files\Movie Maker\DVDMaker.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk -> C:\Program Files\Windows Mail\WinMail.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Movie Maker.lnk -> C:\Program Files\Movie Maker\MOVIEMK.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Photo Gallery.lnk -> C:\Program Files\Windows Photo Gallery\WindowsPhotoGallery.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yahoo! Messenger\Yahoo! Messenger.lnk -> C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yahoo! Games\Text Twist 2\readme.lnk -> C:\Program Files\Yahoo! Games\Text Twist 2\readme.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yahoo! Games\Text Twist 2\Text Twist 2.lnk -> C:\Program Files\Yahoo! Games\Text Twist 2\TextTwist2.exe (GameHouse, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yahoo! Games\Text Twist 2\Uninstall Text Twist 2.lnk -> C:\Program Files\Yahoo! Games\Text Twist 2\Uninstall.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy\File Shredder.lnk -> C:\Program Files\Spybot - Search & Destroy\SDShred.exe (Safer Networking Limited)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy\Spybot - Search & Destroy.lnk -> C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe (Safer Networking Limited)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy\Tutorial.lnk -> C:\Program Files\Spybot - Search & Destroy\Help\English.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy\Uninstall Spybot-S&D.lnk -> C:\Program Files\Spybot - Search & Destroy\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy\Update Spybot-S&D.lnk -> C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe (Safer Networking Limited)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype\Skype.lnk -> C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery Manager\Recovery Disc Creation.lnk -> C:\Windows\SMINST\CD Creator.exe (SoftThinks)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery Manager\Recovery Manager.lnk -> C:\Windows\SMINST\Restore7.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek USB 2.0 Card Reader Software\Uninstall Realtek USB 2.0 Card Reader Software.lnk -> C:\Program Files\InstallShield Installation Information\{DC24971E-1946-445D-8A82-CE685433FA7D}\setup.exe (Macrovision Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real\RealPlayer Converter.lnk -> C:\Program Files\Real\RealPlayer\converter\RealConverter.exe (RealNetworks, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real\RealPlayer Trimmer.lnk -> C:\Program Files\Real\RealPlayer\converter\RealTrimmer.exe (RealNetworks, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime\About QuickTime.lnk -> C:\Windows\Installer\{57752979-A1C9-4C02-856B-FBB27AC4E02C}\RichText.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime\PictureViewer.lnk -> C:\Windows\Installer\{57752979-A1C9-4C02-856B-FBB27AC4E02C}\PictureViewer.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime\QuickTime Player.lnk -> C:\Windows\Installer\{57752979-A1C9-4C02-856B-FBB27AC4E02C}\QTPlayer.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PopCap Games\Bejeweled 2 Deluxe\Play Bejeweled 2 Deluxe.lnk -> C:\Program Files\PopCap Games\Bejeweled 2 Deluxe\Bejeweled2.exe (PopCap.com)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PopCap Games\Bejeweled 2 Deluxe\View Readme.lnk -> C:\Program Files\PopCap Games\Bejeweled 2 Deluxe\readme.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services\United States\EarthLink.lnk -> C:\Program Files\Online Services\EarthLink\InstallEarthLink.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services\United States\Juno Dial-up.lnk -> C:\Program Files\Online Services\JunoUS\JunoTurboSetup.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services\United States\MSN.lnk -> C:\Program Files\Online Services\MSN90\msnsusii.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services\United States\Netzero Dial-up.lnk -> C:\Program Files\Online Services\NetzeroUS_du\NetZeroHSSetup.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services\United States\Netzero High-speed.lnk -> C:\Program Files\Online Services\NetzeroUS_Acc\NetZeroHSSetup.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services\United States\Try AOL Today.lnk -> C:\Program Files\Online Services\Aolus\InstallAol.exe (Hewlett Packard)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services\Canada\Netzero Dial-up.lnk -> C:\Program Files\Online Services\Netzero_du_ca\NetZeroHSSetup.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services\Canada\Netzero High-speed.lnk -> C:\Program Files\Online Services\Netzero_Acc_ca\NetZeroHSSetup.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++\Notepad++.lnk -> C:\Program Files\Notepad++\notepad++.exe (Don HO [email protected])
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++\readme.lnk -> C:\Program Files\Notepad++\readme.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++\Uninstall.lnk -> C:\Program Files\Notepad++\uninstall.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\muvee\Home movies made easy!.lnk -> C:\Program Files\muvee Technologies\muvee autoProducer 6.1 - SE\muveeapp.exe (muvee Technologies Pte Ltd)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\muvee\muvee autoProducer 6.1\muvee autoProducer 6.1 - SE.lnk -> C:\Program Files\muvee Technologies\muvee autoProducer 6.1 - SE\muveeapp.exe (muvee Technologies Pte Ltd)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\muvee\muvee autoProducer 6.1\muvee autoProducer 6.1 Help.lnk -> C:\Program Files\muvee Technologies\muvee autoProducer 6.1 - SE\LaunchHelp.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works\Getting Started.lnk -> C:\Windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\gtngstrtd.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works\Microsoft Works Calendar.lnk -> C:\Windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\WksCal.exe (Microsoft® Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works\Microsoft Works Database.lnk -> C:\Windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\wksdb.exe (Microsoft® Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works\Microsoft Works Portfolio.lnk -> C:\Windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\WksSb.exe (Microsoft® Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works\Microsoft Works Spreadsheet.lnk -> C:\Windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\wksss.exe (Microsoft® Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works\Microsoft Works Task Launcher.lnk -> C:\Program Files\Microsoft Works\MSWorks.exe (Microsoft® Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works\Microsoft Works Word Processor.lnk -> C:\Windows\Installer\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}\WksWP.exe (Microsoft® Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight\Microsoft Silverlight.lnk -> C:\Program Files\Microsoft Silverlight\5.1.20913.0\Silverlight.Configuration.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Activation Assistant for Microsoft Office.lnk -> C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites\ota.hta ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Access 2007.lnk -> C:\Windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\accicons.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Excel 2007.lnk -> C:\Windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\xlicons.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Groove 2007.lnk -> C:\Windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\GrooveIcon.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office InfoPath 2007.lnk -> C:\Windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\inficon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office OneNote 2007.lnk -> C:\Windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\joticon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Outlook 2007.lnk -> C:\Windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\outicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office PowerPoint 2007.lnk -> C:\Windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\pptico.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Project 2007.lnk -> C:\Windows\Installer\{91120000-003B-0000-0000-0000000FF1CE}\pj11icon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Publisher 2007.lnk -> C:\Windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\pubs.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Visio 2007.lnk -> C:\Windows\Installer\{91120000-0051-0000-0000-0000000FF1CE}\visicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Word 2007.lnk -> C:\Windows\Installer\{91120000-002E-0000-0000-0000000FF1CE}\wordicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Digital Certificate for VBA Projects.lnk -> C:\Windows\Installer\{91120000-0051-0000-0000-0000000FF1CE}\misc.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Clip Organizer.lnk -> C:\Windows\Installer\{91120000-0051-0000-0000-0000000FF1CE}\cagicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2007 Language Settings.lnk -> C:\Windows\Installer\{91120000-0051-0000-0000-0000000FF1CE}\misc.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Diagnostics.lnk -> C:\Windows\Installer\{91120000-0051-0000-0000-0000000FF1CE}\misc.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Picture Manager.lnk -> C:\Windows\Installer\{91120000-0051-0000-0000-0000000FF1CE}\oisicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware\Malwarebytes Anti-Malware Help.lnk -> C:\Program Files\Malwarebytes' Anti-Malware\mbam.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware\Malwarebytes Anti-Malware.lnk -> C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware\Uninstall Malwarebytes Anti-Malware.lnk -> C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk -> C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\chameleon.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Problem Reports and Solutions.lnk -> C:\Windows\System32\wercon.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Remote Assistance.lnk -> C:\Windows\System32\msra.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling\LightScribe Control Panel.lnk -> C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Ad-Aware manual.lnk -> C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware_manual_EN.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Ad-Aware.lnk -> C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe (Lavasoft Limited)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Lavasoft Homepage.lnk -> C:\Program Files\Lavasoft\Ad-Aware\Lavasoft Homepage.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Uninstall Ad-Aware.lnk -> C:\ProgramData\{05D7E05D-9BCE-4F9F-8206-9129E8EAAF25}\Ad-Aware90Install.exe (Lavasoft )
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Toolbox\AutoStart Manager.lnk -> C:\Program Files\Lavasoft\Ad-Aware\ToolBox\AutoStart Manager\AutoStart Manager.exe (Lavasoft Limited )
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Toolbox\Hostfile Editor.lnk -> C:\Program Files\Lavasoft\Ad-Aware\ToolBox\LT\HostFileEditor.exe (Lavasoft Limited)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Toolbox\Process Watch.lnk -> C:\Program Files\Lavasoft\Ad-Aware\ToolBox\LT\ProcessWatch.exe (Lavasoft Limited)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Toolbox\ThreatWork.lnk -> C:\Program Files\Lavasoft\Ad-Aware\threatwork.exe (Lavasoft Limited)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodak\KODAK AiO Home Center.lnk -> C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe (Eastman Kodak Company)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodak\Kodak Printer Network Setup Utility.lnk -> C:\Program Files\Kodak\AiO\Center\NetworkPrinterDiscovery.exe (Eastman Kodak Company)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit\Java Mission Control.lnk -> C:\Program Files\Java\jdk1.6.0_22\bin\jmc.exe (No File)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk -> C:\Program Files\Java\jre7\bin\javacpl.exe (Oracle Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes\About iTunes.lnk -> C:\Program Files\iTunes\iTunes.Resources\en.lproj\About iTunes.rtf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes\iTunes.lnk -> C:\Program Files\iTunes\iTunes.exe (Apple Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel® Matrix Storage Manager\Help.lnk -> C:\Program Files\Intel\Intel Matrix Storage Manager\Shell_ENU.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel® Matrix Storage Manager\Intel Matrix Storage Console.lnk -> C:\Program Files\Intel\Intel Matrix Storage Manager\Shell.exe (Intel Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel® Matrix Storage Manager\Readme.lnk -> C:\Program Files\Intel\Intel Matrix Storage Manager\Readme.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel® Matrix Storage Manager\Uninstall.lnk -> C:\Windows\System32\Imsmudlg.exe (Intel® Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Update.lnk -> C:\Program Files\HP\HP Software Update\HPWUCli.exe (Hewlett-Packard)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\Wireless Home Network Setup.lnk -> C:\Program Files\HP\HPNetworkAssistant\HPNetworkAssistant.exe (Hewlett-Packard Co.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Smart Web Printing\HP Smart Web Printing Help.lnk -> C:\Program Files\HP\Digital Imaging\smart web printing\Help\hpsmartprint.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Photosmart Essential 2.5\HP Photosmart Essential 2.5.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe (Hewlett-Packard Development Co. L.P.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Chess.lnk -> C:\Program Files\Microsoft Games\Chess\Chess.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\FreeCell.lnk -> C:\Program Files\Microsoft Games\FreeCell\FreeCell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Hearts.lnk -> C:\Program Files\Microsoft Games\Hearts\Hearts.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\InkBall.lnk -> C:\Program Files\Microsoft Games\inkball\inkball.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Mahjong.lnk -> C:\Program Files\Microsoft Games\Mahjong\Mahjong.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Minesweeper.lnk -> C:\Program Files\Microsoft Games\Minesweeper\MineSweeper.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\PurblePlace.lnk -> C:\Program Files\Microsoft Games\Purble Place\PurblePlace.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Solitaire.lnk -> C:\Program Files\Microsoft Games\Solitaire\Solitaire.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Spider Solitaire.lnk -> C:\Program Files\Microsoft Games\SpiderSolitaire\SpiderSolitaire.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Extras and Upgrades\Windows Anytime Upgrade.lnk -> C:\Windows\System32\WindowsAnytimeUpgrade.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts\EA Link.lnk -> C:\Program Files\Electronic Arts\EA Link\Core.exe (Electronic Arts)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ChaosPro 4.0\ChaosPro Online Help.lnk -> C:\Program Files\ChaosPro 4.0\ChaosPro.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ChaosPro 4.0\ChaosPro.lnk -> C:\Program Files\ChaosPro 4.0\ChaosPro.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ChaosPro 4.0\Readme.lnk -> C:\Program Files\ChaosPro 4.0\ReadMe.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ChaosPro 4.0\Uninstall ChaosPro.lnk -> C:\Program Files\ChaosPro 4.0\uninstall.exe (Martin Pfingstl, http://www.chaospro.de)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner.lnk -> C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\Uninstall CCleaner.lnk -> C:\Program Files\CCleaner\uninst.exe (Piriform Ltd)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG\AVG 2014.lnk -> C:\Program Files\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe\Adobe Media Player.lnk -> C:\Program Files\Adobe Media Player\Adobe Media Player.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Data Sources (ODBC).lnk -> C:\Windows\System32\odbcad32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\Windows\System32\iscsicpl.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\Windows\System32\MdSched.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\Windows\System32\services.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\Windows\System32\msconfig.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk -> C:\Windows\System32\WF.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Calculator.lnk -> C:\Windows\System32\calc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\NetworkProjection.lnk -> C:\Windows\System32\NetProj.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\Windows\System32\mstsc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sidebar.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk -> C:\Windows\System32\SoundRecorder.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sync Center.lnk -> C:\Windows\System32\mobsync.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell_ise.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Sticky Notes.lnk -> C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\TabTip.lnk -> C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Windows Journal.lnk -> C:\Program Files\Windows Journal\Journal.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Backup.lnk -> C:\Windows\System32\sdclt.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\Windows\System32\charmap.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\dfrgui.lnk -> C:\Windows\System32\dfrgui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Disk Cleanup.lnk -> C:\Windows\System32\cleanmgr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\migwiz.lnk -> C:\Windows\System32\migwiz\migwiz.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Information.lnk -> C:\Windows\System32\msinfo32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Restore.lnk -> C:\Windows\System32\rstrui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\PlayTasks\0\Minesweeper.lnk -> C:\Program Files\Microsoft Games\Minesweeper\MineSweeper.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\PlayTasks\0\Hearts.lnk -> C:\Program Files\Microsoft Games\Hearts\Hearts.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\PlayTasks\0\Spider Solitaire.lnk -> C:\Program Files\Microsoft Games\SpiderSolitaire\SpiderSolitaire.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\PlayTasks\0\Mahjong.lnk -> C:\Program Files\Microsoft Games\Mahjong\Mahjong.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\PlayTasks\0\Purble Place.lnk -> C:\Program Files\Microsoft Games\Purble Place\PurblePlace.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\PlayTasks\0\FreeCell.lnk -> C:\Program Files\Microsoft Games\FreeCell\FreeCell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{509C009C-AF37-4B36-BCE4-47EBE166E32F}\PlayTasks\0\Play.lnk -> C:\Program Files\PopCap Games\Bejeweled 2 Deluxe\Bejeweled2.exe (PopCap.com)
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{48DE2B25-A3A2-4121-808D-5DD991D9FEBB}\PlayTasks\0\InkBall.lnk -> C:\Program Files\Microsoft Games\inkball\inkball.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{2EC2AD03-79F1-44BA-ABE2-BD8B9DB4E480}\PlayTasks\0\Play.lnk -> C:\Program Files\MSN Games\Scrabble Blast Deluxe\Launch.exe (Oberon Media Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\PlayTasks\0\Chess.lnk -> C:\Program Files\Microsoft Games\Chess\Chess.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\PlayTasks\0\Solitaire.lnk -> C:\Program Files\Microsoft Games\Solitaire\Solitaire.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Hewlett-Packard\Netzero\launchnz.lnk -> C:\Program Files\Online Services\NetzeroUS_Acc\NetZeroHSSetup.exe ()
Shortcut: C:\ProgramData\Hewlett-Packard\Juno\launchjuno.lnk -> C:\Program Files\Online Services\JunoUS\JunoTurboSetup.exe ()
Shortcut: C:\ProgramData\CyberLink\QuickPlay\Extension\Extension.1.0.lnk -> C:\Program Files\HP\QuickPlay\Kernel\Highlight\Extension.1.0\Extension.1.0.xml ()
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam\Cyberlink YouCam.lnk -> C:\Program Files\CyberLink\YouCam\YouCam.exe (CyberLink Corp.)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite\CyberLink DVD Suite.lnk -> C:\Program Files\CyberLink\DVD Suite\PowerStarter.exe (CyberLink)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite\Power2Go.lnk -> C:\Program Files\CyberLink\Power2Go\Power2Go.exe (CyberLink Corp.)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite\PowerDirector.lnk -> C:\Program Files\CyberLink\PowerDirector\PDR.exe (CyberLink Corp.)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\Public\Desktop\Ad-Aware.lnk -> C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe (Lavasoft Limited)
Shortcut: C:\Users\Public\Desktop\Adobe Help.lnk -> C:\Program Files\Adobe\Adobe Help\Adobe Help.exe ()
Shortcut: C:\Users\Public\Desktop\AVG 2014.lnk -> C:\Program Files\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.)
Shortcut: C:\Users\Public\Desktop\Bejeweled 2 Deluxe.lnk -> C:\Program Files\PopCap Games\Bejeweled 2 Deluxe\Bejeweled2.exe (PopCap.com)
Shortcut: C:\Users\Public\Desktop\CCleaner.lnk -> C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
Shortcut: C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk -> C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
Shortcut: C:\Users\Public\Desktop\Skype.lnk -> C:\Windows\Installer\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\SkypeIcon.exe ()
Shortcut: C:\Users\User\Videos\Sample Videos.lnk -> C:\Users\Public\Videos\Sample Videos ()
Shortcut: C:\Users\User\Pictures\Pictures.lnk -> C:\Users\User\Pictures ()
Shortcut: C:\Users\User\Pictures\Sample Pictures.lnk -> C:\Users\Public\Pictures\Sample Pictures ()
Shortcut: C:\Users\User\Music\Sample Music.lnk -> C:\Users\Public\Music\Sample Music ()
Shortcut: C:\Users\User\Links\Documents.lnk -> C:\Users\User\Documents ()
Shortcut: C:\Users\User\Links\Music.lnk -> C:\Users\User\Music ()
Shortcut: C:\Users\User\Links\Public.lnk -> C:\Users\Public ()
Shortcut: C:\Users\User\Links\Recently Changed.lnk -> C:\Users\User\Searches\Recently Changed.search-ms ()
Shortcut: C:\Users\User\Links\Searches.lnk -> C:\Users\User\Searches ()
Shortcut: C:\Users\User\Downloads\college notes and folders\pos420 - Shortcut.lnk -> C:\Users\User\Downloads\college notes and folders\NTC360\pos420 (No File)
Shortcut: C:\Users\User\Documents\Pictures - Shortcut.lnk -> C:\Users\User\Pictures ()
Shortcut: C:\Users\User\Documents\Youcam\YouCam(Webcam).lnk -> C:\Program Files\CyberLink\YouCam\YouCam.exe (CyberLink Corp.)
Shortcut: C:\Users\User\Desktop\Kindle.lnk -> C:\Users\User\AppData\Local\Amazon\Kindle\application\Kindle.exe (Amazon.com)
Shortcut: C:\Users\User\Desktop\Spybot - Search & Destroy.lnk -> C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe (Safer Networking Limited)
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk -> C:\Program Files\Windows Mail\WinMail.exe (Microsoft Corporation)
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Verizon\Verizon Wireless Software Utility Application for Android – Samsung.lnk -> C:\Users\User\AppData\Roaming\Verizon\UA_ar\UA.exe (SAMSUNG Electornics Co., Ltd.)
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Verizon Wireless Software Utility Application for Android – Samsung.lnk -> C:\Users\User\AppData\Roaming\Verizon\UA_ar\UA.exe (SAMSUNG Electornics Co., Ltd.)
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam\Cyberlink YouCam.lnk -> C:\Program Files\CyberLink\YouCam\YouCam.exe (CyberLink Corp.)
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite\CyberLink DVD Suite.lnk -> C:\Program Files\CyberLink\DVD Suite\PowerStarter.exe (CyberLink)
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite\Power2Go.lnk -> C:\Program Files\CyberLink\Power2Go\Power2Go.exe (CyberLink Corp.)
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink DVD Suite\PowerDirector.lnk -> C:\Program Files\CyberLink\PowerDirector\PDR.exe (CyberLink Corp.)
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amazon\Amazon Kindle\Kindle.lnk -> C:\Users\User\AppData\Local\Amazon\Kindle\application\Kindle.exe (Amazon.com)
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amazon\Amazon Kindle\Uninstall Kindle.lnk -> C:\Users\User\AppData\Local\Amazon\Kindle\application\uninstall.exe (Amazon.com)
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk -> C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe (Lavasoft Limited)
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk -> C:\Windows\Installer\{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}\SafariIco.exe ()
Shortcut: C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\User\AppData\Local\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\PlayTasks\0\Mahjong.lnk -> C:\Program Files\Microsoft Games\Mahjong\Mahjong.exe (Microsoft Corporation)
Shortcut: C:\Users\User\AppData\Local\Microsoft\Windows\GameExplorer\{48DE2B25-A3A2-4121-808D-5DD991D9FEBB}\PlayTasks\0\InkBall.lnk -> C:\Program Files\Microsoft Games\inkball\inkball.exe (Microsoft Corporation)
Shortcut: C:\Users\User\AppData\Local\Microsoft\Windows\GameExplorer\{2EC2AD03-79F1-44BA-ABE2-BD8B9DB4E480}\PlayTasks\0\Play.lnk -> C:\Program Files\MSN Games\Scrabble Blast Deluxe\Launch.exe (Oberon Media Inc.)


ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yahoo! Mail.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> C:\PROGRA~1\Yahoo!\Common\YMMAPI.dll,OpenURL hxxp://mail.yahoo.com/?.intl=us&.redir=ymmapi11
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TestGen\TestGen Plug-in\Test the plug-in in IE.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://support.pearsoncmg.com/testgen/tgPluginTest.htm


ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DefaultPrograms
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk -> C:\Windows\System32\wuapp.exe (Microsoft Corporation) -> startmenu
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TestGen\TestGen Plug-in\Remove TestGen Plug-in from IE.lnk -> C:\Windows\unvise32.exe (MindVision Software) -> C:\PROGRA~1\INTERN~1\Plugins\uninstal.log
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real\RealPlayer SP.lnk -> C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.) -> /launch:start_menu
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime\Uninstall QuickTime.lnk -> C:\Windows\System32\msiexec.exe (Microsoft Corporation) -> /i {57752979-A1C9-4C02-856B-FBB27AC4E02C} /qf
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PopCap Games\Bejeweled 2 Deluxe\Uninstall Bejeweled 2 Deluxe.lnk -> C:\Program Files\PopCap Games\Bejeweled 2 Deluxe\PopUninstall.exe () -> "C:\Program Files\PopCap Games\Bejeweled 2 Deluxe\Install.log"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services\Internet & Digital Services.lnk -> C:\Program Files\Hewlett-Packard\SDP\HPSdpApp.exe (Hewlett-Packard) -> /LaunchPage /eis
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\- My HP Game Console -.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\My HP Game Console\GameConsole-wt.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\3D Ultra Minigolf Adventures.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\3D Ultra Minigolf Adventures\MGA-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\7 Wonders of the Ancient World.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\7 Wonders of the Ancient World\Wonders-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Bejeweled 2 Deluxe.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Bejeweled 2 Deluxe\WinBej2-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Blasterball 2 Revolution.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Blasterball 2 Revolution\bb2-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Blasterball 3.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Blasterball 3\BlasterBall3-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Chuzzle Deluxe.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Chuzzle Deluxe\Chuzzle-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Crystal Maze.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Crystal Maze\Maze-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Diner Dash.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Diner Dash\Diner Dash-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\FATE.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\FATE\Fate-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Final Drive Nitro.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Final Drive Nitro\Racing-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Fish Tycoon.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Fish Tycoon\FishTycoon-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Insaniquarium Deluxe.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Insaniquarium Deluxe\InsaniquariumDeluxe-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Jewel Quest Solitaire.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Jewel Quest Solitaire\JQSolitaire-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Jewel Quest.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Jewel Quest\JewelQuest-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Magic Academy.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Magic Academy\academy-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Mah Jong Quest.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Mah Jong Quest\mahjong-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Otto's Magic Blocks.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Otto's Magic Blocks\otto-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Peggle.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Peggle\Peggle-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Penguins!.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Penguins!\penguins-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Polar Bowler.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Polar Bowler\Polar-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Polar Golfer Pineapple Cup.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Polar Golfer Pineapple Cup\golf-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Polar Golfer.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Polar Golfer\golf-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Ricochet Lost Worlds.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Ricochet Lost Worlds\Ricochet-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Shooting Stars Pool.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Shooting Stars Pool\ssp-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Slingo Deluxe.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Slingo Deluxe\Slingo-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Super Granny.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Super Granny\granny-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Tradewinds.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Tradewinds\tradewinds-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Virtual Villagers - A New Home.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Virtual Villagers - A New Home\VirtualVillagers-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Virtual Villagers - Chapter 2 - The Lost Children.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Virtual Villagers - Chapter 2 - The Lost Children\Virtual Villagers - The Lost Children-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My HP Games\Zuma Deluxe.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Zuma Deluxe\Zuma-WT.exe" /src startmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\muvee\muvee autoProducer 6.1\Quick Tour.lnk -> C:\Program Files\muvee Technologies\muvee autoProducer 6.1 - SE\LaunchFlash.exe () -> qt_menu.swf
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Project Server 2007 Accounts.lnk -> C:\Windows\Installer\{91120000-003B-0000-0000-0000000FF1CE}\pj11icon.exe () -> -ProjectProfiles
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Backup and Restore Center.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.BackupAndRestoreCenter
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling\Getting Started.lnk -> C:\Program Files\Common Files\LightScribe\LSLauncher.exe (Hewlett-Packard Company) -> 1
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\Ad-Aware\Ad-Aware Updates.lnk -> C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe (Lavasoft Limited ) -> update all
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodak\Uninstall KODAK AiO Home Center.lnk -> C:\ProgramData\Kodak\Installer\Setup.exe (Eastman Kodak Company) -> /Web /x {E0F274B7-592B-4669-8FB8-8D9825A09858} CompanyName="Eastman Kodak Company" /code 1033
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk -> C:\Program Files\Java\jre7\bin\javacpl.exe (Oracle Corporation) -> -tab about
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk -> C:\Program Files\Java\jre7\bin\javacpl.exe (Oracle Corporation) -> -tab update
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\- My HP Game Console -.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\My HP Game Console\GameConsole-wt.exe" /src gamesmenuoem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\Windows\System32\eventvwr.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Reliability and Performance Monitor.lnk -> C:\Windows\System32\perfmon.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell Modules.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) -> -NoExit -ImportSystemModules
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) -> /open
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.WelcomeCenter
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Speech Recognition.lnk -> C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{f97d86f8-4ea4-4231-b7a2-2eb33a03e176}\PlayTasks\0\Polar Golfer Pineapple Cup.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Polar Golfer Pineapple Cup\golf-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{f5719220-4b71-4b0a-8b34-489769cffad7}\PlayTasks\0\Mah Jong Quest.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Mah Jong Quest\mahjong-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{ec270eee-1658-418f-80d7-75f69a106a9f}\PlayTasks\0\Shooting Stars Pool.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Shooting Stars Pool\ssp-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{e9edf01b-8fd5-4bde-b184-cf41470765d9}\PlayTasks\0\Tradewinds.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Tradewinds\tradewinds-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{cfd9a075-4fcb-4fb1-a915-c55eb1fcf096}\PlayTasks\0\Jewel Quest Solitaire.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Jewel Quest Solitaire\JQSolitaire-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{ccce20a6-dd84-4066-9afb-c1b32960091a}\PlayTasks\0\Polar Bowler.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Polar Bowler\Polar-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{bc132a82-bec2-4315-ae6c-1ee984d12131}\PlayTasks\0\Virtual Villagers - A New Home.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Virtual Villagers - A New Home\VirtualVillagers-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{b9032f18-ca9e-4161-bc55-42d18a6a8b7f}\PlayTasks\0\Final Drive Nitro.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Final Drive Nitro\Racing-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{b788532d-7dca-4308-b6c8-018ec168f55e}\PlayTasks\0\Super Granny.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Super Granny\granny-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{9e923815-0b1a-4338-b101-f4b32ef15103}\PlayTasks\0\Polar Golfer.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Polar Golfer\golf-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{99a37123-5bd1-4f33-9f91-012f8638d573}\PlayTasks\0\Penguins!.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Penguins!\penguins-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{8d2a6d9a-8169-4247-879e-9aaea3c5ed06}\PlayTasks\0\3D Ultra Minigolf Adventures.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\3D Ultra Minigolf Adventures\MGA-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{81000ac9-0603-4ecd-b2d5-bde60218c6f7}\PlayTasks\0\Slingo Deluxe.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Slingo Deluxe\Slingo-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{7a0f03a9-6f95-420a-afb0-77c51076502e}\PlayTasks\0\Otto's Magic Blocks.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Otto's Magic Blocks\otto-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{6bc7c571-6e25-466d-872d-3dea46648f36}\PlayTasks\0\Insaniquarium Deluxe.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Insaniquarium Deluxe\InsaniquariumDeluxe-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{66d0623b-24d4-4c79-944a-b8a525b24a60}\PlayTasks\0\FATE.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\FATE\Fate-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{60b683b9-a33f-4d72-9752-3d3ddefece96}\PlayTasks\0\Crystal Maze.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Crystal Maze\Maze-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{54f5645f-e12a-482f-bc72-dbbe20e85f8c}\PlayTasks\0\Ricochet Lost Worlds.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Ricochet Lost Worlds\Ricochet-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{4408636f-4839-4857-aebc-eeeefc80562e}\PlayTasks\0\7 Wonders of the Ancient World.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\7 Wonders of the Ancient World\Wonders-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{2f61e3e5-6b0d-4ad6-a26c-4bfda653a70a}\PlayTasks\0\Diner Dash.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Diner Dash\Diner Dash-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{2a48c2c4-89a9-42ed-9319-5854fc201dad}\PlayTasks\0\Zuma Deluxe.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Zuma Deluxe\Zuma-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{1f9a4b82-672a-4547-bff6-db257123e77a}\PlayTasks\0\Chuzzle Deluxe.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Chuzzle Deluxe\Chuzzle-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{1ded66f9-9276-4fd2-9624-8cfa4fa67958}\PlayTasks\0\Blasterball 3.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Blasterball 3\BlasterBall3-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{1a1710aa-44bf-4a47-82e6-90ef1ea1123d}\PlayTasks\0\Bejeweled 2 Deluxe.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Bejeweled 2 Deluxe\WinBej2-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\GameExplorer\{194ff14d-f674-41b7-97e2-c060132fe1dd}\PlayTasks\0\Jewel Quest.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Jewel Quest\JewelQuest-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\ProgramData\Hewlett-Packard\wtwc\onplay.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\My HP Game Console\GameConsole.exe" /src welcomecenteroem
ShortcutWithArgument: C:\ProgramData\Hewlett-Packard\SDP\launchreg.lnk -> C:\Program Files\Hewlett-Packard\SDP\OOBEEzsetup.exe (Hewlett-Packard) -> /LaunchPage /reg
ShortcutWithArgument: C:\ProgramData\Hewlett-Packard\base\launch_base.lnk -> C:\Program Files\Hewlett-Packard\SDP\HPSdpApp.exe (Hewlett-Packard) -> /LaunchPage /eisbase,welcenter
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter
ShortcutWithArgument: C:\Users\User\AppData\Roaming\Real\RealPlayer\Favorites\Criminals For Gun Control (C.F.G.C.).lnk -> C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.) -> /startpos:00:00:00.0 file://C:/Users/User/AppData/Local/Temp/Criminals For Gun Control (C.F.G.C.).flv
ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office Groove.lnk -> C:\Program Files\Microsoft Office\Office12\GROOVE.EXE (Microsoft Corporation) -> -background
ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) -> /tsr
ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> -extoff
ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter
ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Windows\SendTo\Skype.lnk -> C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.) -> /sendto:
ShortcutWithArgument: C:\Users\User\AppData\Local\Microsoft\Windows\GameExplorer\{f5719220-4b71-4b0a-8b34-489769cffad7}\PlayTasks\0\Mah Jong Quest.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Mah Jong Quest\mahjong-WT.exe" /launchgc /src gameexploreroem
ShortcutWithArgument: C:\Users\User\AppData\Local\Microsoft\Windows\GameExplorer\{bc132a82-bec2-4315-ae6c-1ee984d12131}\PlayTasks\0\Virtual Villagers - A New Home.lnk -> C:\Program Files\HP Games\onplay\onplay.exe ( ) -> "C:\Program Files\HP Games\Virtual Villagers - A New Home\VirtualVillagers-WT.exe" /launchgc /src gameexploreroem


InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pandora Internet Radio.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=onlinesvs&s=pandora&pf=desktop&locale=en_us&bd=all&c=81
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PopCap Games\Bejeweled 2 Deluxe\Visit PopCap.com.url -> hxxp://www.popcap.com/?cid=retail_direct
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling\LightScribe Website.url -> hxxp://www.lightscribe.com/
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling\Quick Demo.url -> hxxp://www.lightscribe.com/go/videos/QuickDemo
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodak\KODAK Mobile Printing.url -> hxxp://www.kodak.com/go/mobileprinting
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodak\User Guides.url -> hxxp://www.kodak.com/go/manuals?pq-locale=en_US#aioprinters
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Yahoo! Backgammon.url -> hxxp://red.clientapps.yahoo.com/customize/startmenu/games/bg/msgr8/*hxxp://games.yahoo.com/bg
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Yahoo! Dominoes.url -> hxxp://red.clientapps.yahoo.com/customize/startmenu/games/do/msgr8/*hxxp://games.yahoo.com/do
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Yahoo! Euchre.url -> hxxp://red.clientapps.yahoo.com/customize/startmenu/games/eu/msgr8/*hxxp://games.yahoo.com/eu
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Yahoo! Poker.url -> hxxp://red.clientapps.yahoo.com/customize/startmenu/games/pk/msgr8/*hxxp://games.yahoo.com/po
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Yahoo! Pool.url -> hxxp://red.clientapps.yahoo.com/customize/startmenu/games/pl/msgr8/*hxxp://games.yahoo.com/pl
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Yahoo! Spades.url -> hxxp://red.clientapps.yahoo.com/customize/startmenu/games/sp/msgr8/*hxxp://games.yahoo.com/sp
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner Homepage.url -> hxxp://www.piriform.com/ccleaner
InternetURL: C:\Users\Default\Favorites\HP\Accessories.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=hpaccessories&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\Default\Favorites\HP\Activity Center.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=activitycenter&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\Default\Favorites\HP\Digital Entertainment.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=digitalentm&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\Default\Favorites\HP\eBay.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=ebay&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\Default\Favorites\HP\HP Club.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=hpclub&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\Default\Favorites\HP\HP Home.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=hphome&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\Default\Favorites\HP\HP Music.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=hpmusic&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\Default\Favorites\HP\HP Store.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=hpstore&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\Default\Favorites\HP\My HP Games.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=myhpgames&pf=laptop&locale=EN_US&bd=all&c=81
InternetURL: C:\Users\Default\Favorites\HP\Pandora Internet Radio.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=pandora&pf=desktop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\Default\Favorites\HP\PC Security.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=pcsecurity&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\Default\Favorites\HP\Photo Central.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=ephoto&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\Default\Favorites\HP\Printing.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=printing&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\Default\Favorites\HP\Software and Driver Downloads.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=downloads&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\User\Music\Internet Radio on Yahoo! Music.url -> hxxp://red.clientapps.yahoo.com/customize/mydocs/msgr8/*hxxp://music.yahoo.com/launchcast/
InternetURL: C:\Users\User\Music\Music Videos & More on Yahoo! Music.url -> hxxp://red.clientapps.yahoo.com/customize/mydocs/msgr8/*hxxp://music.yahoo.com/
InternetURL: C:\Users\User\Favorites\1CLUB.FM - Internet Radio - Community - Videos - Arcade Games - Altered State.url -> hxxp://1club.fm/dance-edm/altered-state.html
InternetURL: C:\Users\User\Favorites\2011 Louis Vuitton Monogram Artsy Bag Handbag MM GM for sale.url -> hxxp://www.ioffer.com/i/2011-louis-vuitton-monogram-artsy-bag-handbag-mm-gm-203911610
InternetURL: C:\Users\User\Favorites\30 Best Fast Recipes Ever Food & Wine.url -> hxxp://www.foodandwine.com/articles/30-best-fast-recipes-ever
InternetURL: C:\Users\User\Favorites\Addition Elle Plus Size Fashion Store.url -> hxxp://www.1-plus.com/addition-elle-AE-_stcVVcatId487088VVviewcat.htm
InternetURL: C:\Users\User\Favorites\Airliners.net Airplanes - Aviation - Aircraft- Aircraft Photos & News.url -> hxxp://www.airliners.net/
InternetURL: C:\Users\User\Favorites\allcopacetic - Photoblog.com.url -> hxxp://www.photoblog.com/allcopacetic
InternetURL: C:\Users\User\Favorites\Amateur tit[bleep]ing video.url -> hxxp://www.xhamster.com/movies/2641/amateur_tit[bleep]ing_video.html
InternetURL: C:\Users\User\Favorites\AmeroCurrency , SPP, NAU International Banking News, Stock Market Crash.url -> hxxp://www.amerocurrency.com/updates.html
InternetURL: C:\Users\User\Favorites\Anal Porn Videos New.url -> hxxp://www.xhamster.com/channels/new-anal-1.html
InternetURL: C:\Users\User\Favorites\Anderson Cooper 360 Blog Archive - Living on food stamps for a month « - Blogs from CNN.com.url -> hxxp://ac360.blogs.cnn.com/2009/02/03/living-on-food-stamps-for-a-month/#comment-554146
InternetURL: C:\Users\User\Favorites\aquascaping Aquarium meets terrarium in the Japanese-inspired design practice -- latimes.com.url -> hxxp://www.latimes.com/features/home/la-hm-aquascapes19-2009sep19,0,6049008.story
InternetURL: C:\Users\User\Favorites\Aquatic plants growing under water garden plants.url -> hxxp://www.gardening-supplies-online.com/oxygenators.htm
InternetURL: C:\Users\User\Favorites\Art of Dessert Celebrating with Champagne Truffles.url -> hxxp://artofdessert.blogspot.com/2008/12/celebrating-with-champagne-truffles.html
InternetURL: C:\Users\User\Favorites\Asian Titty Milk Fetish - Nice Boobs and Nips.url -> hxxp://www.spankwire.com/Asian-Titty-Milk-Fetish-Nice-Boobs-and-Nips/video135944/
InternetURL: C:\Users\User\Favorites\ATutorials Purchased - StudentOfFortune.com.url -> hxxp://studentoffortune.com/cgi/question_viewsolution?id=306628
InternetURL: C:\Users\User\Favorites\Authentic Louis Vuitton Damier Azur Canvas Galliera GM N55216 LV Bags For Sale Louis Vuitton Damier Azur Canvas.url -> hxxp://www.louisvuittonoutletmm.com/louis-vuitton-damier-azur-canvas-galliera-gm-n55216-lv-bags.html/index.php?route=product/search&category_id=7
InternetURL: C:\Users\User\Favorites\Axia to the University of Phoenix Student and Faculty Web.url -> https://ecampus.phoe...blic/login.aspx
InternetURL: C:\Users\User\Favorites\Bacardi Rum Cake Recipe Recipezaar.url -> hxxp://www.recipezaar.com/Bacardi-Rum-Cake-14499
InternetURL: C:\Users\User\Favorites\Bakerella.url -> hxxp://www.bakerella.blogspot.com/
InternetURL: C:\Users\User\Favorites\Banana Tres Leches Dessert Recipe from Betty Crocker.url -> hxxp://www.bettycrocker.com/recipes.aspx/banana-tres-leches-dessert?WT.dcsvid=Mzc3NTYwMzk3MgS2&WT.mc_id=Newsletter_BettyCrocker_07_13_2009&rvrin=E3EAE4DE-94C0-4491-8503-05C0EBFB7ADB
InternetURL: C:\Users\User\Favorites\BBPeopleMeet.com.url -> hxxp://www.bbpeoplemeet.com/community/search/?CFID=27819093&CFTOKEN=c539633c68c7f413-F76F1CCC-5056-9F31-DFB15D436EA62EF3
InternetURL: C:\Users\User\Favorites\Beaded Candle Rings ~ 7 Color Choices review at Kaboodle.url -> hxxp://www.kaboodle.com/reviews/beaded-candle-rings-~-7-color-choices-7
InternetURL: C:\Users\User\Favorites\beautiful agony - facettes de la petite mort view.url -> hxxp://beautifulagony.com/public/main.php
InternetURL: C:\Users\User\Favorites\Beijinhos de Coco (Coconut Kisses).url -> hxxp://www.maria-brazil.org/beijinhos_de_coco.htm
InternetURL: C:\Users\User\Favorites\Benefits of Telecommuting.url -> hxxp://www.gilgordon.com/telecommutesafe/telebenefits.html
InternetURL: C:\Users\User\Favorites\Better-Than-Almost-Anything Cake Recipe from Betty Crocker.url -> hxxp://www.bettycrocker.com/recipes.aspx/better-than-almost-anything-cake?WT.dcsvid=Mzc3NTYwMzk3MgS2&WT.mc_id=Newsletter_BettyCrocker_07_13_2009&rvrin=E3EAE4DE-94C0-4491-8503-05C0EBFB7ADB
InternetURL: C:\Users\User\Favorites\Bing.com.url -> hxxp://g.msn.com/1me10IE8ENUS01/401
InternetURL: C:\Users\User\Favorites\Blooming Teas A perfect Blooming Tea Gift.url -> hxxp://www.teavana.com/The-Teas/Blooming-Teas/
InternetURL: C:\Users\User\Favorites\Bob & Sheri . Homepage.url -> hxxp://www.bobandsheri.com/index.cfm
InternetURL: C:\Users\User\Favorites\Bodybuilding Cyclic Ketogenic Diet - Ketogenic Diet Plan, Menu, Food, Recipe and Newsletter.url -> hxxp://www.musclenet.com/getbulky/Info/WeightLoss/KetogenicDieting.htm
InternetURL: C:\Users\User\Favorites\Bracelet with Jablonex® Czech Fire-Polished Beads and Assorted Glass Beads - Fire Mountain Gems and Beads.url -> hxxp://www.firemountaingems.com/galleryofdesigns/jewelry_design_gallery.asp?docid=88TV&sact=search
InternetURL: C:\Users\User\Favorites\Bracelet with Swarovski® Crystal Hearts and Sterling Silver Charms - Fire Mountain Gems and Beads.url -> hxxp://www.firemountaingems.com/galleryofdesigns/jewelry_design_gallery.asp?docid=88TQ&sact=search
InternetURL: C:\Users\User\Favorites\Bracelet with White Lotus™ Cultured Freshwater Pearls and Silver-Plated Chain - Fire Mountain Gems and Beads.url -> hxxp://www.firemountaingems.com/galleryofdesigns/jewelry_design_gallery.asp?docid=88V3&sact=search
InternetURL: C:\Users\User\Favorites\Bureau of Indian Affairs.url -> hxxp://www.doi.gov/bia/
InternetURL: C:\Users\User\Favorites\Bushfires in Victoria, Australia - The Big Picture - Boston.com.url -> hxxp://www.boston.com/bigpicture/2009/02/bushfires_in_victoria_australi.html
InternetURL: C:\Users\User\Favorites\Business Continuity Management Software.url -> hxxp://www.availability.sungard.com/sungardsolutions/ITSolutions/software/Pages/software.aspx/MediaPR/BCPLibrary/BCPCaseStudies.asp
InternetURL: C:\Users\User\Favorites\Caramel Apple Cheesecake Recipe Paula Deen Food Network.url -> hxxp://www.foodnetwork.com/recipes/paula-deen/caramel-apple-cheesecake-recipe/index.html
InternetURL: C:\Users\User\Favorites\Careers And Colleges .com - Find Scholarships, College Grants, Colleges, and Loans.url -> hxxp://www.careersandcolleges.com/
InternetURL: C:\Users\User\Favorites\Category 7 cable - Wikipedia, the free encyclopedia.url -> hxxp://en.wikipedia.org/wiki/Category_7_cable
InternetURL: C:\Users\User\Favorites\CHAOS MANOR IN PERSPECTIVE.url -> hxxp://www.jerrypournelle.com/index.html
InternetURL: C:\Users\User\Favorites\Chapter 5 Topology.url -> hxxp://fcit.coedu.usf.edu/network/chap5/chap5.htm
InternetURL: C:\Users\User\Favorites\Chinese Symbols, Tattoo Symbol Guide.url -> hxxp://www.chinatownconnection.com/chinese-symbols.htm
InternetURL: C:\Users\User\Favorites\Chocolate Truffles Recipe Alton Brown Food Network.url -> hxxp://www.foodnetwork.com/recipes/alton-brown/chocolate-truffles-recipe/index.html
InternetURL: C:\Users\User\Favorites\Cisco Unified Wireless Network Overview  [Cisco 4400 Series Wireless LAN Controllers] - Cisco Systems.url -> hxxp://www.cisco.com/en/US/prod/collateral/wireless/ps5678/ps430/prod_brochure09186a0080184925_ps6366_Product_Solution_Overview.html
InternetURL: C:\Users\User\Favorites\CITY MUSEUM- Home.url -> hxxp://www.citymuseum.org/home.asp
InternetURL: C:\Users\User\Favorites\Clit Jewelry from Sexy Jewelry.url -> hxxp://www.sexejewelry.com/clitclips.asp
InternetURL: C:\Users\User\Favorites\College Admissions - College Search - Cappex - Scholarships.url -> hxxp://www.cappex.com/page/student/scholarships.jsp
InternetURL: C:\Users\User\Favorites\Comparison of WLAN, WPAN and WMAN Technologies NetworkDictionary.url -> hxxp://www.networkdictionary.com/Wireless/Comparison-of-WLAN.php
InternetURL: C:\Users\User\Favorites\Contact Us - MasterPieces Puzzle Company.url -> hxxp://www.masterpiecesinc.com/contactus.aspx
InternetURL: C:\Users\User\Favorites\Cooks Recipes Apple-Walnut Stuffing Recipe.url -> hxxp://www.cooksrecipes.com/sidedish/apple_walnut_stuffing_recipe.html
InternetURL: C:\Users\User\Favorites\Coupons, Coupon Codes & Promotion Codes - Free Stuff with a catch.url -> hxxp://www.dealtaker.com/Free-Stuff-with-a-catch-f37.html
InternetURL: C:\Users\User\Favorites\Crafta - Design Master Floral Sprays.url -> hxxp://www1.crafta.com/pag.php?_html=666C6F72616C2D737570706C792D666C6F72616C2D73707261792D636F6C6F72&layout=m&pageID=2
InternetURL: C:\Users\User\Favorites\Cranberry Bliss Bars Recipe Recipezaar.url -> hxxp://www.recipezaar.com/106405
InternetURL: C:\Users\User\Favorites\Cream Cheese Mints.url -> hxxp://www.wilton.com/recipe/Cream-Cheese-Mints
InternetURL: C:\Users\User\Favorites\Culinary Concoctions by Peabody –orange whoopie pies.url -> hxxp://www.culinaryconcoctionsbypeabody.com/2009/02/10/ordinary-people/
InternetURL: C:\Users\User\Favorites\Culinary in the Desert Chocolate Chip Cookie Truffles.url -> hxxp://desertculinary.blogspot.com/2005/05/chocolate-chip-cookie-truffles.html
InternetURL: C:\Users\User\Favorites\Cupid and His Soul Mate, Psyche - Wedlok.com.url -> hxxp://www.wedlok.com/lasvegaswedding/sacred_relationships/cupid_and_his_soul_mate_psyche-110431.html
InternetURL: C:\Users\User\Favorites\D-LINK SYSTEMS, INC WIRELESS ROUTER SETUP.url -> hxxp://192.168.0.1/wireless.htm
InternetURL: C:\Users\User\Favorites\Dad's Surprise - Incest-Taboo - Literotica.com.url -> hxxp://www.literotica.com/stories/showstory.php?id=304820
InternetURL: C:\Users\User\Favorites\Dad's Visit - Incest-Taboo - Literotica.com.url -> hxxp://www.literotica.com/stories/showstory.php?id=156434
InternetURL: C:\Users\User\Favorites\Daddy's Fetish - Incest-Taboo - Literotica.com.url -> hxxp://www.literotica.com/stories/showstory.php?id=135163
InternetURL: C:\Users\User\Favorites\Daddy's Fetish Ch. 02 - Incest-Taboo - Literotica.com.url -> hxxp://www.literotica.com/stories/showstory.php?id=135290
InternetURL: C:\Users\User\Favorites\Daddy's Fetish Ch. 03 - Incest-Taboo - Literotica.com.url -> hxxp://www.literotica.com/stories/showstory.php?id=136764
InternetURL: C:\Users\User\Favorites\daddydom What it means for his baby girl Social Perversion.url -> hxxp://www.socialperversion.com/2008/08/25/daddydom-what-it-means-for-his-baby-girl/
InternetURL: C:\Users\User\Favorites\Daryl's TCP-IP Primer.url -> hxxp://www.ipprimer.com/addressing.cfm
InternetURL: C:\Users\User\Favorites\Data transmission - Cabling.url -> hxxp://en.kioskea.net/contents/transmission/transcabl.php3
InternetURL: C:\Users\User\Favorites\Digital Domain - What Carriers Aren’t Eager to Tell You About Texting - NYTimes.com.url -> hxxp://www.nytimes.com/2008/12/28/business/28digi.htm?_r=1
InternetURL: C:\Users\User\Favorites\Dinner - Maximilien - French Romantic Restaurant - Pike Place Market, Downtown Seattle.url -> hxxp://www.maximilienrestaurant.com/dinner/index.html
InternetURL: C:\Users\User\Favorites\Direct Consolidation Loans - Welcome!!!.url -> hxxp://www.loanconsolidation.ed.gov/
InternetURL: C:\Users\User\Favorites\Discover Bing.url -> hxxp://g.msn.com/1me10IE8ENUS01/402
InternetURL: C:\Users\User\Favorites\Discussions - Sucks when Lit is down Google Groups.url -> hxxp://groups.google.com/group/sucks-when-lit-is-down/topics?hl=en&start=
InternetURL: C:\Users\User\Favorites\divorce Modifying Child Support FAQs - Lawyers.com.url -> hxxp://family-law.lawyers.com/child-support/Divorce-Modifying-Child-Support-FAQs.html
InternetURL: C:\Users\User\Favorites\Do's and Don'ts of Cable Routing (Part 2) Maximum PC.url -> hxxp://www.maximumpc.com/article/dos_and_donts_of_cable_routing_part_2
InternetURL: C:\Users\User\Favorites\Dorothy Lemay from small town girls.url -> hxxp://www.spankwire.com/Dorothy-Lemay-from-small-town-girls/video109848/
InternetURL: C:\Users\User\Favorites\Dr. Bronner's Magic Soaps Retail Store Peppermint Liquid Soap.url -> hxxp://www.drbronner.com/DBMS/PEP.htm
InternetURL: C:\Users\User\Favorites\Dr. Horrible.url -> hxxp://drhorrible.com/
InternetURL: C:\Users\User\Favorites\DryerLint-NewLeaf.com Forums - Powered by vBulletin.url -> hxxp://dryerlint-newleaf.com/forums/
InternetURL: C:\Users\User\Favorites\DryerLint.net Forums - View Profile JustSkye.url -> hxxp://dryerlint.net/newstart/member.php?u=172
InternetURL: C:\Users\User\Favorites\dud looks like a lady prt6...BMW.url -> hxxp://www.xhamster.com/movies/100723/dud_looks_like_a_lady_prt6_bmw.html
InternetURL: C:\Users\User\Favorites\E-sangha, Buddhist Forum and Buddhism Forum - Suggestion Box (moderated).url -> hxxp://www.lioncity.net/buddhism/index.php?act=announce&f=133&id=43
InternetURL: C:\Users\User\Favorites\Effexor - By Q.url -> hxxp://my.opera.com/Bilby/blog/2008/12/23/effexor?cid=6684029
InternetURL: C:\Users\User\Favorites\Enjoy an Underwater garden, Right in Your Own Livingroom!!.url -> hxxp://davesgarden.com/guides/articles/view/657/
InternetURL: C:\Users\User\Favorites\Ethernet Tutorial.url -> hxxp://www.lothlorien.net/collections/computer/ethernet.html
InternetURL: C:\Users\User\Favorites\eTwinning - Diferences Routers and switch.url -> hxxp://www.slideshare.net/ariedam/etwinning-diferences-routers-and-switch
InternetURL: C:\Users\User\Favorites\Exclusive Cherry Red Essential Baker's Set (2-pc.) by Le Creuset - Betty Crocker.url -> hxxp://www.bettycrockerstore.com/p-750913-0-750913_Le-Creuset-Exclusive-Essential-Bakers-Set-Cherry-Red-2-pc.aspx?Ntt=750913&Ntx=mode%20matchall&Nty=1&Ntk=All&CCAID=BCWBADLC
InternetURL: C:\Users\User\Favorites\Flapjacks - There is NO [bleep]ing Clique.url -> hxxp://thereisnoclique.com/snark/forumdisplay.php?f=2
InternetURL: C:\Users\User\Favorites\Flip My Text - Funny Text for Twitter Myspace Facebook YouTube & Blogs.url -> hxxp://flipmytext.com/
InternetURL: C:\Users\User\Favorites\Food Menu - Angel Food Ministries.url -> hxxp://www.angelfoodministries.com/menu_0909en.asp
InternetURL: C:\Users\User\Favorites\Foodgasms - Literotica Discussion Board.url -> hxxp://forum.literotica.com/showthread.php?t=467625&highlight=Foodgasms
InternetURL: C:\Users\User\Favorites\Four-in-One Fruit Chocolate Tin.url -> hxxp://www.harryanddavid.com/gifts/store/item__10051____13925?sliSearch=cherries
InternetURL: C:\Users\User\Favorites\Franks Tube - Free Porn Movies Daily From Frank.url -> hxxp://www.frankstube.com/
InternetURL: C:\Users\User\Favorites\Fregola Sarda [PSGR0357] Market Hall Foods, Rockridge Market Hall Online Store.url -> hxxp://www.markethallfoods.com/store/index.php?main_page=product_mh_info&products_id=273&gclid=CMjOiIiJ_poCFRJxxwodEljmeQ
InternetURL: C:\Users\User\Favorites\Garnate sucks Luke - SlutLoad.com.url -> hxxp://www.slutload.com/watch/ZnoVCEVqSjQ/Garnate-sucks-Luke.html
InternetURL: C:\Users\User\Favorites\General Board - Literotica Discussion Board.url -> hxxp://forum.literotica.com/forumdisplay.php?f=4
InternetURL: C:\Users\User\Favorites\Geologic Time Index Fossils.url -> hxxp://pubs.usgs.gov/gip/geotime/fossils.html
InternetURL: C:\Users\User\Favorites\Google Image Result for http--dryicons.com-files-graphics_previews-rose_red.jpg.url -> hxxp://images.google.com/imgres?imgurl=hxxp://dryicons.com/files/graphics_previews/rose_red.jpg&imgrefurl=hxxp://dryicons.com/free-graphics/preview/rose-red/&usg=__B2IWXJSKupe8gDXG8vmyy5qvFJ0=&h=513&w=420&sz=114&hl=en&start=29&um=1&tbnid=Q936UBvogDIjVM:&tbnh=131&tbnw=107&prev=/images%3Fq%3Dred%2Bswirl%2Bbackground%26start%3D21%26ndsp%3D21%26um%3D1%26hl%3Den%26rls%3Dcom.microsoft:*:IE-SearchBox%26rlz%3D1I7SUNA%26sa%3DN
InternetURL: C:\Users\User\Favorites\Google Image Result for http--www.idobelieve.co.uk-Resources-titaniasleeping.jpeg.url -> hxxp://images.google.com/imgres?imgurl=hxxp://www.idobelieve.co.uk/Resources/titaniasleeping.jpeg&imgrefurl=hxxp://www.idobelieve.co.uk/fairyshop.html&h=90&w=64&sz=9&hl=en&start=33&um=1&usg=__7a-Q_qn_vawepcZKJXLuiW-sMKg=&tbnid=UAG2We0IJoUs1M:&tbnh=78&tbnw=55&prev=/images%3Fq%3Dkinuko%2Bcraft%2Bpuzzles%26start%3D21%26ndsp%3D21%26um%3D1%26hl%3Den%26safe%3Doff%26rls%3Dcom.microsoft:*:IE-SearchBox%26rlz%3D1I7SUNA%26sa%3DN
InternetURL: C:\Users\User\Favorites\Google Image Result for http--www.latinmerchant.com-images-product-1Candy%20(47).jpg.url -> hxxp://images.google.com/imgres?imgurl=hxxp://www.latinmerchant.com/images/product/1Candy%2520(47).jpg&imgrefurl=hxxp://www.latinmerchant.com/productdetail.asp%3FProductID%3DSSD0029&usg=__lz5qSsZTA66Y1G78QUi_1p4N3KI=&h=216&w=288&sz=10&hl=en&start=30&um=1&tbnid=R5Y3u8FZC8G7tM:&tbnh=86&tbnw=115&prev=/images%3Fq%3Dlimon%2Bsalt%26ndsp%3D21%26hl%3Den%26safe%3Doff%26rls%3Dcom.microsoft:*:IE-SearchBox%26rlz%3D1I7SUNA%26sa%3DN%26start%3D21%26um%3D1
InternetURL: C:\Users\User\Favorites\Google Image Result for http--www.mbari.org-volcanism-images-Sheet-12_12_36_05-sm.jpg.url -> hxxp://images.google.com/imgres?imgurl=hxxp://www.mbari.org/volcanism/images/Sheet-12_12_36_05-sm.jpg&imgrefurl=hxxp://www.mbari.org/volcanism/Hawaii/HR-VolcProc.htm&usg=__6kogqmzkGEgAmBcfcLp9nnJYiuc=&h=149&w=220&sz=20&hl=en&start=91&um=1&tbnid=qOPbEhItCWFpvM:&tbnh=72&tbnw=107&prev=/images%3Fq%3DNiihau%2Bvolcanic%2Bpictures%26ndsp%3D21%26hl%3Den%26safe%3Doff%26rls%3Dcom.microsoft:*:IE-SearchBox%26rlz%3D1I7SUNA%26sa%3DN%26start%3D84%26um%3D1
InternetURL: C:\Users\User\Favorites\Google Image Result for http--www.ntsg.umt.edu-personnel-saxon-molly-molly_frozen_lake.jpg.url -> hxxp://images.google.com/imgres?imgurl=hxxp://www.ntsg.umt.edu/personnel/saxon/molly/molly_frozen_lake.jpg&imgrefurl=hxxp://www.ntsg.umt.edu/personnel/saxon/molly/&usg=__KUZ-GksjVMmteKkhUS4oD8Oy19c=&h=768&w=1024&sz=134&hl=en&start=37&um=1&tbnid=GbmJc2J_W1qo7M:&tbnh=113&tbnw=150&prev=/images%3Fq%3Dfrozen%2Blake%26start%3D21%26ndsp%3D21%26um%3D1%26hl%3Den%26rls%3Dcom.microsoft:*:IE-SearchBox%26rlz%3D1I7SUNA%26sa%3DN
InternetURL: C:\Users\User\Favorites\Google Image Result for http--www.vulkaner.no-v-vulkinfo-tomhaz-hawaii-is2.jpg.url -> hxxp://images.google.com/imgres?imgurl=hxxp://www.vulkaner.no/v/vulkinfo/tomhaz/hawaii-is2.jpg&imgrefurl=hxxp://www.vulkaner.no/v/vulkinfo/tomhaz/hawaii-is.html&usg=__VdVZNGuRlWJiCV8HGR00ui7JnnY=&h=259&w=401&sz=35&hl=en&start=69&um=1&tbnid=tKl0yC8aeBiWYM:&tbnh=80&tbnw=124&prev=/images%3Fq%3DNiihau%2Bvolcano%26ndsp%3D21%26hl%3Den%26safe%3Doff%26rls%3Dcom.microsoft:*:IE-SearchBox%26rlz%3D1I7SUNA%26sa%3DN%26start%3D63%26um%3D1
InternetURL: C:\Users\User\Favorites\Guidelines and Tools for Migrating to the Cisco Unified Wireless Network  [Cisco Unified Wireless Network] - Cisco Systems.url -> hxxp://www.cisco.com/en/US/prod/collateral/wireless/ps5679/ps5861/prod_white_paper0900aecd804f1a23_ns337_Networking_Solutions_White_Paper.html
InternetURL: C:\Users\User\Favorites\Guys with iPhones.url -> hxxp://guyswithiphones.com/
InternetURL: C:\Users\User\Favorites\Half.com.url -> hxxp://www.half.ebay.com/
InternetURL: C:\Users\User\Favorites\HELP SECTION  6DollarShirts.com.url -> hxxp://6dollarshirts.com/help.php?section=contactus&mode=update
InternetURL: C:\Users\User\Favorites\Hidden Emoticons - Yahoo! Messenger.url -> hxxp://messenger.yahoo.com/features/hiddenemoticons/
InternetURL: C:\Users\User\Favorites\Hindsight - Anal - Literotica.com.url -> hxxp://www.literotica.com/stories/showstory.php?id=98708
InternetURL: C:\Users\User\Favorites\Hot Asian Shemale.url -> hxxp://www.spankwire.com/Hot-Asian-Shemale/video153365/
InternetURL: C:\Users\User\Favorites\How to Grow Freshwater Aquarium Plants - wikiHow.url -> hxxp://www.wikihow.com/Grow-Freshwater-Aquarium-Plants
InternetURL: C:\Users\User\Favorites\How to Induce Lactation - the Well May Not Be Dry! - Associated Content.url -> hxxp://www.associatedcontent.com/article/157409/how_to_induce_lactation_the_well_may.html?cat=25
InternetURL: C:\Users\User\Favorites\http--csrc.nist.gov-publications-nistpubs-800-48-NIST_SP_800-48.pdf.url -> hxxp://csrc.nist.gov/publications/nistpubs/800-48/NIST_SP_800-48.pdf
InternetURL: C:\Users\User\Favorites\http--edge.networkworld.com-subnets-cisco-chapters-1587054620-graphics-01fig07.jpg.url -> hxxp://edge.networkworld.com/subnets/cisco/chapters/1587054620/graphics/01fig07.jpg
InternetURL: C:\Users\User\Favorites\http--gears.tucson.ars.ag.gov-beeclass-Pollination.pdf.url -> hxxp://gears.tucson.ars.ag.gov/beeclass/Pollination.pdf
InternetURL: C:\Users\User\Favorites\http--hawaiivacation.info-wp-content-uploads-2008-09-niihau-head.jpg.url -> hxxp://hawaiivacation.info/wp-content/uploads/2008/09/niihau-head.jpg
InternetURL: C:\Users\User\Favorites\http--hi.water.usgs.govNiihua.url -> hxxp://hi.water.usgs.gov/publications/pubs/fs/fs126-00.pdf
InternetURL: C:\Users\User\Favorites\http--pieinabottle.com-.url -> hxxp://pieinabottle.com/
InternetURL: C:\Users\User\Favorites\http--ultralit.com-.url -> hxxp://ultralit.com/
InternetURL: C:\Users\User\Favorites\http--www.airmagnet.com-assets-whitepaper-WP-802.11nPrimer.pdf.url -> hxxp://www.airmagnet.com/assets/whitepaper/WP-802.11nPrimer.pdf
InternetURL: C:\Users\User\Favorites\http--www.free-codecs.com-download-K_Lite_Codec_Pack.htm.url -> hxxp://www.free-codecs.com/download/K_Lite_Codec_Pack.htm
InternetURL: C:\Users\User\Favorites\http--www.levenger.com-blink=Y&cm_ven=Google&cm_ite=Levenger%20home%20page&engine=Adwords&keyword=Levenger+home+page.url -> hxxp://www.levenger.com/?blink=Y&cm_ven=Google&cm_ite=Levenger%20home%20page&engine=Adwords&keyword=Levenger+home+page
InternetURL: C:\Users\User\Favorites\http--www.soest.hawaii.edu-expeditions-Kauai-overview.htm.url -> hxxp://www.soest.hawaii.edu/expeditions/Kauai/overview.htm
InternetURL: C:\Users\User\Favorites\Hulu - Carrier All Hands - Watch the full episode now..url -> hxxp://www.hulu.com/watch/23364/carrier-all-hands
InternetURL: C:\Users\User\Favorites\Hulu - Dr. Horrible's Sing-Along Blog.url -> hxxp://www.hulu.com/watch/28343/dr-horribles-sing-along-blog
InternetURL: C:\Users\User\Favorites\Hyperbole and a Half How a Fish Almost Destroyed My Childhood - StumbleUpon.url -> hxxp://www.stumbleupon.com/su/2Ty8qL/hyperboleandahalf.blogspot.com/2010/03/how-fish-almost-destroyed-my-childhood.html
InternetURL: C:\Users\User\Favorites\I should be here more often - By Loquena.url -> hxxp://my.opera.com/Loquena/blog/2008/10/04/i-should-be-here-more-often?cid=6685748
InternetURL: C:\Users\User\Favorites\imeem Dashboard.url -> hxxp://www.imeem.com/home/
InternetURL: C:\Users\User\Favorites\Internetworking Technology Handbook - Open Systems Interconnection (OSI) Protocols  [Internetworking] - Cisco Systems.url -> hxxp://www.cisco.com/en/US/docs/internetworking/technology/handbook/OSI-Protocols.html
InternetURL: C:\Users\User\Favorites\Islamic Society Of Minot - Minot ND 58701-4011 CityWaboo.url -> hxxp://www.citywaboo.com/business/2111470/Islamic_Society_Of_Minot-in-Minot-ND_58701-4011.html
InternetURL: C:\Users\User\Favorites\IT Project Failures ZDNet.com.url -> hxxp://blogs.zdnet.com/projectfailures/
InternetURL: C:\Users\User\Favorites\IT Service Requests.url -> https://ecampus.phoe...iceRequests.htm
InternetURL: C:\Users\User\Favorites\James Joyce' dirty letters.url -> hxxp://johnhamilton.us/2/jamesjoyceletters.htm
InternetURL: C:\Users\User\Favorites\JES - Lyrics and Albums.url -> hxxp://www.plentonglyrics.com/artists/JES/517
InternetURL: C:\Users\User\Favorites\Joanne Chang's Sticky Buns Recipe Food Network.url -> hxxp://www.foodnetwork.com/recipes/throwdown-with-bobby-flay/joanne-changs-sticky-buns-recipe/index.html
InternetURL: C:\Users\User\Favorites\Kate's Gallery.url -> hxxp://soiroom.hyperchat.com/kate/gallery.htm
InternetURL: C:\Users\User\Favorites\Katie’s Cheesecake Delights from Betty Crocker.url -> hxxp://www.bettycrocker.com/recipes/recipe.aspx?recipeID=45639&WT.dcsvid=Mzc3NTYwMzk3MgS2&WT.mc_id=Newsletter_BettyCrocker_12_04_2008
InternetURL: C:\Users\User\Favorites\kellymom.com Fenugreek for Increasing Milk Supply.url -> hxxp://www.kellymom.com/herbal/milksupply/fenugreek.html
InternetURL: C:\Users\User\Favorites\kimber James ts.url -> hxxp://www.xhamster.com/movies/102468/kimber_james_ts.html
InternetURL: C:\Users\User\Favorites\Klehm's Song Sparrow Farm and Nursery--SUN.url -> hxxp://www.songsparrow.com/2010/plantlist.cfm?type=SUN,&subtype=all&startrow=76&pagetype=plantlist
InternetURL: C:\Users\User\Favorites\Klehm's Song Sparrow Farm and Nursery--TP.url -> hxxp://www.songsparrow.com/2010/plantlist.cfm?type=TP,&startrow=1&pageType=plantlist&subtype=all
InternetURL: C:\Users\User\Favorites\Lampwork Beads, Goody Beads, Beads, Awareness Beads, Bead Pens, Gemstones, Large Hole Beads.url -> hxxp://store.goodybeads.com/store/index.html
InternetURL: C:\Users\User\Favorites\Land of Milk and Honey.url -> hxxp://www.landmilkhoney.com/
InternetURL: C:\Users\User\Favorites\Learn To Subnet  A Free, Lecture-Based Presentation on IP Addressing and Subnetting.url -> hxxp://www.learntosubnet.com/
InternetURL: C:\Users\User\Favorites\Lela Star [bleep]ed Hard.url -> hxxp://www.spankwire.com/Lela-Star-[bleep]ed-Hard/video119039/
InternetURL: C:\Users\User\Favorites\Lemon Cheesecake Truffle Recipe - How to Make Cheesecake Truffles - Lemon Cheesecake - Truffle Recipes.url -> hxxp://candy.about.com/od/whitechocolatetruffles/r/lemonchscake.htm
InternetURL: C:\Users\User\Favorites\LiveLeak.com - Awesome footage from inside Blue Angels #7 over the US Naval Academy.url -> hxxp://www.liveleak.com/view?i=610_1244577346
InternetURL: C:\Users\User\Favorites\Low Brow Wannabe Elitists - Powered by vBulletin.url -> hxxp://thereisnoclique.com/snark/index.php
InternetURL: C:\Users\User\Favorites\LV Damier Azur Canvas Galliera GM N552165091 - Louis Vuitton Women Handbags.url -> hxxp://www.solebags.com/lv-damier-azur-canvas-galliera-gm-n55216-3059.html
InternetURL: C:\Users\User\Favorites\man [bleep]s real doll - HardSexTube.url -> hxxp://www.hardsextube.com/video/58221/man-[bleep]s-real-doll
InternetURL: C:\Users\User\Favorites\Map of registered offenders in your neighborhood.url -> hxxp://www12.familywatchdog.us/ShowMap.asp?frm=0
InternetURL: C:\Users\User\Favorites\Mariana Cordoba Shemale orgy.url -> hxxp://www.xhamster.com/movies/33805/mariana_cordoba_shemale_orgy.html
InternetURL: C:\Users\User\Favorites\Michael Thurmond's 6 Week Body Makeover Weight Loss Program.url -> hxxp://www.mybodymakeover.com/
InternetURL: C:\Users\User\Favorites\Microsoft Exchange Server - Wikipedia, the free encyclopedia.url -> hxxp://en.wikipedia.org/wiki/Microsoft_Exchange_Server
InternetURL: C:\Users\User\Favorites\Microsoft SQL Server - Wikipedia, the free encyclopedia.url -> hxxp://en.wikipedia.org/wiki/Microsoft_SQL_Server
InternetURL: C:\Users\User\Favorites\MIT Physics Faculty Walter H. G. Lewin.url -> hxxp://web.mit.edu/physics/facultyandstaff/faculty/walter_lewin.html
InternetURL: C:\Users\User\Favorites\MSN Autos.url -> hxxp://g.msn.com/1me10IE8ENUS01/405
InternetURL: C:\Users\User\Favorites\MSN Entertainment.url -> hxxp://g.msn.com/1me10IE8ENUS01/406
InternetURL: C:\Users\User\Favorites\MSN Lifestyle.url -> hxxp://g.msn.com/1me10IE8ENUS01/407
InternetURL: C:\Users\User\Favorites\MSN Money.url -> hxxp://g.msn.com/1me10IE8ENUS01/408
InternetURL: C:\Users\User\Favorites\MSN.url -> hxxp://g.msn.com/1me10IE8ENUS01/403
InternetURL: C:\Users\User\Favorites\MSNBC News.url -> hxxp://g.msn.com/1me10IE8ENUS01/404
InternetURL: C:\Users\User\Favorites\mW to dBm Calculator.url -> hxxp://www.aubraux.com/design/milli-watts-to-dbm-calculator.php
InternetURL: C:\Users\User\Favorites\National Congress of American Indians History.url -> hxxp://www.ncai.org/About.8.0.html
InternetURL: C:\Users\User\Favorites\network design - Google Image Search.url -> hxxp://images.google.com/images?q=network%20design&rls=com.microsoft:*:IE-SearchBox&oe=UTF-8&sourceid=ie7&rlz=1I7SUNA&um=1&ie=UTF-8&sa=N&hl=en&tab=wi
InternetURL: C:\Users\User\Favorites\Network Topologies STAR.url -> hxxp://hubpages.com/hub/Network-Topologies
InternetURL: C:\Users\User\Favorites\Network Topology Introduction.url -> hxxp://www.networktutorials.info/topology.html
InternetURL: C:\Users\User\Favorites\Networking Tutorials.url -> hxxp://www.brainbell.com/tutorials/Networking/
InternetURL: C:\Users\User\Favorites\New World Geek Surviving and thriving in the new world order Page 3.url -> hxxp://newworldgeek.com/?paged=3
InternetURL: C:\Users\User\Favorites\North Dakota Water Resources Research Institute - Home Page.url -> hxxp://www.ndsu.nodak.edu/ndsu/wrri/
InternetURL: C:\Users\User\Favorites\Over 80 flavors of candy oils!.url -> https://www.lorannoi...candy-oils.aspx
InternetURL: C:\Users\User\Favorites\palachinka Foodbuzz 24, 24, 24 Petits Fours Galore.url -> hxxp://palachinka.blogspot.com/2009/01/foodbuzz-24-24-24-petits-fours-galore.html
InternetURL: C:\Users\User\Favorites\Pecan Pie Recipe.url -> hxxp://www.myhomecooking.net/pecan-pie/pecan-pie-recipe.htm
InternetURL: C:\Users\User\Favorites\Plentyoffish.com Free Online Dating Service & Dating Site.url -> hxxp://www.plentyoffish.com/
InternetURL: C:\Users\User\Favorites\Posters & Prints.url -> hxxp://www.pennyarcademerch.com/posterprints.html
InternetURL: C:\Users\User\Favorites\Pregnant wife milk.url -> hxxp://www.xhamster.com/movies/12618/pregnant_wife_milk.html
InternetURL: C:\Users\User\Favorites\Project Free TV - Watch all your favorite tv shows and movies online free.url -> hxxp://www.free-tv-video-online.info/
InternetURL: C:\Users\User\Favorites\Public vs. private networks - Information Technology - Miller School of Medicine at the University of Miami.url -> hxxp://it.med.miami.edu/x198.xml
InternetURL: C:\Users\User\Favorites\rainbow necklace.url -> hxxp://www.firemountaingems.com/printdocs/printdocs.asp?docid=982Q
InternetURL: C:\Users\User\Favorites\Red Velvet Peppermint Cake Recipe - - MyRecipes.com.url -> hxxp://find.myrecipes.com/recipes/recipefinder.dyn?action=displayRecipe&recipe_id=520449
InternetURL: C:\Users\User\Favorites\Repeaters, Bridges, Routers.url -> hxxp://www.comptechdoc.org/independent/networking/cert/netdevices.html
InternetURL: C:\Users\User\Favorites\Resume Objective Examples – 15 Top Resume Objectives Examples.url -> hxxp://www.job-interview-site.com/resume-objective-examples-15-top-resume-objectives-examples.html
InternetURL: C:\Users\User\Favorites\Resume Templates Templates Based On Your Occupation - Pongo Resume.url -> hxxp://www.pongoresume.com/services/13/resume-templates.cfm
InternetURL: C:\Users\User\Favorites\RF Math Made Easy.url -> hxxp://www.wi-fiplanet.com/tutorials/article.php/3525531
InternetURL: C:\Users\User\Favorites\Rough it up with Tifanny Mynx - KeezMovies.com.url -> hxxp://www.keezmovies.com/422437
InternetURL: C:\Users\User\Favorites\Scholarship Spotlight A GPA Isn't Everything - FastWeb.url -> hxxp://www.fastweb.com/college-scholarships/articles/517-scholarship-spotlight-a-gpa-isnt-everything
InternetURL: C:\Users\User\Favorites\Seattle Hotels, Seattle Accommodations, Mayflower Park Hotel.url -> hxxp://www.mayflowerpark.com/
InternetURL: C:\Users\User\Favorites\Selection of Project Metrics.url -> hxxp://www.isixsigma.com/library/content/c011008a.asp
InternetURL: C:\Users\User\Favorites\Sex Toys – Adult Toys and Vibrators from Babeland - Babeland.url -> hxxp://www.babeland.com/?kbid=392
InternetURL: C:\Users\User\Favorites\Sexy Lingerie & Vibrating Panties by Booty Parlor.url -> hxxp://www.bootyparlor.com/sexy-lingerie.html
InternetURL: C:\Users\User\Favorites\Shemale Naomi Black Hammer [bleep]s a male virgin..., Free Porn Sex [bleep] at Tnaflix.url -> hxxp://www.tnaflix.com/view_video.php?viewkey=fd5ea97f96f1695286e9
InternetURL: C:\Users\User\Favorites\Shop for Sofas, Sectionals, Couches, and Loveseats.url -> hxxp://www.homereserve.com/shop.cfm
InternetURL: C:\Users\User\Favorites\Soil and Water Conservation BMPs for Groundwater Protection from Pesticides.url -> hxxp://www.ag.ndsu.edu/pubs/h2oqual/watgrnd/ae1115w.htm
InternetURL: C:\Users\User\Favorites\Sony Releases New Stupid Piece Of St That Doesn't Fking Work Video.url -> hxxp://www.break.com/tv-shows/onion-news-network/sony-releases-new-stupid-piece-of-st-that-doesnt-fking-work-666430.html
InternetURL: C:\Users\User\Favorites\Spiced Pumpkin Cupcakes from Betty Crocker.url -> hxxp://www.bettycrocker.com/recipes/recipe.aspx?recipeID=44651&WT.dcsvid=Mzc3NTYwMzk3MgS2&WT.mc_id=Newsletter_BettyCrocker_11_03_2008
InternetURL: C:\Users\User\Favorites\Staff Voicemail.url -> hxxp://mcms.maranacook.org/staffvoicemail
InternetURL: C:\Users\User\Favorites\Starbuck's Cranberry Bliss Bar Recipe.url -> hxxp://www.cookingcache.com/dessert/starbuckscranberryblissbar.shtml?rdid=rc1
InternetURL: C:\Users\User\Favorites\Strawberry Shortcake Truffles - How to Make Strawberry Shortcake Truffles - Strawberry Shortcake - Truffle Recipes.url -> hxxp://candy.about.com/od/whitechocolatetruffles/r/sberryshortcake.htm
InternetURL: C:\Users\User\Favorites\Tati's blog - Vox.url -> hxxp://tati.vox.com/
InternetURL: C:\Users\User\Favorites\tcp ip made easy USE THIS.url -> hxxp://www.tomax7.com/mcse/tcp_ip_made_easy.htm
InternetURL: C:\Users\User\Favorites\Technology Developments.url -> hxxp://water.nationalacademies.org/techdev.php
InternetURL: C:\Users\User\Favorites\spam MUSCLE Velocity Diet 3.0.url -> hxxp://www.t-nation.com/programs/vdiet30/vDietProgram000.jsp
InternetURL: C:\Users\User\Favorites\Tetris Friends Online Games - Acorn Drop.url -> hxxp://www.tetrisfriends.com/games/IceAge/game.php
InternetURL: C:\Users\User\Favorites\The Dildo Category at Vibrators.com.url -> hxxp://www.vibrators.com/dildosdongs.html
InternetURL: C:\Users\User\Favorites\THE FORBIDDEN ISLAND.url -> hxxp://www.niihau.us/island.htm
InternetURL: C:\Users\User\Favorites\The North American Tapestry of Time and Terrain.url -> hxxp://nationalatlas.gov/articles/geology/types/sedimentary.html
InternetURL: C:\Users\User\Favorites\The OSI Reference Model - A review - Unified Communications.url -> hxxp://www.realtime-unifiedcommunications.com/2006/04/the_osi_reference_model_a_revi.htm
InternetURL: C:\Users\User\Favorites\The Pioneer Woman - Ree Drummond.url -> hxxp://thepioneerwoman.com/
InternetURL: C:\Users\User\Favorites\The Snuggie Sutra.url -> hxxp://thesnuggiesutra.com/
InternetURL: C:\Users\User\Favorites\There is NO [bleep]ing Clique - Contacts & Friends.url -> hxxp://thereisnoclique.com/snark/profile.php?do=buddylist
InternetURL: C:\Users\User\Favorites\Thinkmap Visual Thesaurus - An online thesaurus and dictionary of over 145,000 words that you explore using an interactive map..url -> hxxp://www.visualthesaurus.com/landing/?word=spoil&ad=mwcom.dict.txt1
InternetURL: C:\Users\User\Favorites\Tied up.url -> hxxp://www.xhamster.com/movies/59967/tied_up.html
InternetURL: C:\Users\User\Favorites\Topologies - Network Topologies - Types of Topology Examples - Bus Ring Star.url -> hxxp://compnetworking.about.com/od/networkdesign/a/topologies.htm
InternetURL: C:\Users\User\Favorites\Twisted pair - Wikipedia, the free encyclopedia.url -> hxxp://en.wikipedia.org/wiki/Twisted_pair
InternetURL: C:\Users\User\Favorites\Underwater gardens Award winning planted aquariums - latimes.com.url -> hxxp://www.latimes.com/features/home/la-hm-aquascaping-pictures,0,6101092.photogallery
InternetURL: C:\Users\User\Favorites\US wants to paint the world white to save energy (AFP) Yahoo! Green.url -> hxxp://green.yahoo.com/news/afp/20090526/sc_afp/climatewarmingusbritainchu.html
InternetURL: C:\Users\User\Favorites\USGS North Dakota Water Science Center.url -> hxxp://nd.water.usgs.gov/
InternetURL: C:\Users\User\Favorites\Vac-u-Lock Dildos Ken's Twisted Mind.url -> hxxp://www.kenstwistedmind.com/[bleep]ing-Machines/VAC.html
InternetURL: C:\Users\User\Favorites\Vasqi on deviantART.url -> hxxp://vasqi.deviantart.com/
InternetURL: C:\Users\User\Favorites\Visit with Santa Claus at northpole.com.url -> hxxp://www.northpole.com/Kitchen/Cookbook/cat0001.html
InternetURL: C:\Users\User\Favorites\Web Naughty - Members Area.url -> hxxp://www.webnaughty.com/profile.php?show=albums&aid=251&mask=atahg&PHPSESSID=cf73aa039c9179251fed73a30e8356de
InternetURL: C:\Users\User\Favorites\Welcome to Scholarships.com, Free College Scholarship Search & Financial Aid Information.url -> hxxp://www.scholarships.com/
InternetURL: C:\Users\User\Favorites\Welcome to the University of Phoenix Student and Faculty Web.url -> https://ecampus.phoe...blic/login.aspx
InternetURL: C:\Users\User\Favorites\Well.... - by Loquena.url -> hxxp://my.opera.com/Loquena/blog/
InternetURL: C:\Users\User\Favorites\What are the Disadvantages of a VPN.url -> hxxp://www.wisegeek.com/what-are-the-disadvantages-of-a-vpn.htm
InternetURL: C:\Users\User\Favorites\What is Wireless Lan Favorite!.url -> hxxp://www.pulsewan.com/data101/wireless_lan_basics.htm
InternetURL: C:\Users\User\Favorites\Wireless Network Security - Cisco Systems.url -> hxxp://www.cisco.com/en/US/netsol/ns340/ns394/ns348/ns386/networking_solutions_package.html
InternetURL: C:\Users\User\Favorites\Woot One Day, One Deal (SM).url -> hxxp://www.woot.com/
InternetURL: C:\Users\User\Favorites\WWAN and WLAN Alphabet Soup or Wave of the Future - Intel® Software Network.url -> hxxp://software.intel.com/en-us/articles/wwan-and-wlan-alphabet-soup-or-wave-of-the-future/
InternetURL: C:\Users\User\Favorites\ RedTube - Great anal sex.url -> hxxp://www.redtube.com/336
InternetURL: C:\Users\User\Favorites\ RedTube - Hot babe gets it in her [bleep].url -> hxxp://www.redtube.com/21198
InternetURL: C:\Users\User\Favorites\ RedTube - Jodi Moore is too sexy for just one [bleep].url -> hxxp://www.redtube.com/19667
InternetURL: C:\Users\User\Favorites\ RedTube - Three hot boys having anal sex.url -> hxxp://www.redtube.com/1710
InternetURL: C:\Users\User\Favorites\Yahoo!\Finance.url -> hxxp://red.clientapps.yahoo.com/customize/yroot/msgr8/*hxxp://finance.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Games.url -> hxxp://red.clientapps.yahoo.com/customize/yroot/msgr8/*hxxp://games.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Groups.url -> hxxp://red.clientapps.yahoo.com/customize/yroot/msgr8/*hxxp://groups.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Hot Jobs.url -> hxxp://red.clientapps.yahoo.com/customize/yroot/msgr8/*hxxp://hotjobs.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Kids.url -> hxxp://red.clientapps.yahoo.com/customize/yroot/msgr8/*hxxp://kids.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Music.url -> hxxp://red.clientapps.yahoo.com/customize/yroot/msgr8/*hxxp://music.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\News.url -> hxxp://red.clientapps.yahoo.com/customize/yroot/msgr8/*hxxp://news.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Shopping.url -> hxxp://red.clientapps.yahoo.com/customize/yroot/msgr8/*hxxp://shopping.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Sports.url -> hxxp://red.clientapps.yahoo.com/customize/yroot/msgr8/*hxxp://sports.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Travel.url -> hxxp://red.clientapps.yahoo.com/customize/yroot/msgr8/*hxxp://travel.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Travel & Transportation\Maps & Driving Directions.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://maps.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Travel & Transportation\Travel.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://travel.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Tools for Business\Marketing Tools.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://smallbusiness.yahoo.com/bzinfo/prod/marketserv/
InternetURL: C:\Users\User\Favorites\Yahoo!\Tools for Business\Merchant Solutions.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://smallbusiness.yahoo.com/merchant
InternetURL: C:\Users\User\Favorites\Yahoo!\Tools for Business\Small Business.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://smallbusiness.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Tools for Business\Sponsor Listings.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://sponsoredsites.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Tools for Business\Web Hosting.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://smallbusiness.yahoo.com/webhosting
InternetURL: C:\Users\User\Favorites\Yahoo!\Sports & Outdoors\Fantasy Sports.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://fantasysports.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Sports & Outdoors\http--www.carebase.com-pdf-specifications-UPS-SG-UPS-Tower-Up-To-6kVA-120V-208V-230V-240V-True-On-Line-CB.pdf.url -> hxxp://www.carebase.com/pdf-specifications/UPS-SG-UPS-Tower-Up-To-6kVA-120V-208V-230V-240V-True-On-Line-CB.pdf
InternetURL: C:\Users\User\Favorites\Yahoo!\Sports & Outdoors\One island chain, several lines of volcanoes.url -> hxxp://hvo.wr.usgs.gov/volcanowatch/2001/01_11_01.html
InternetURL: C:\Users\User\Favorites\Yahoo!\Sports & Outdoors\Ski & Snow.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://snow.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Sports & Outdoors\Sports.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://sports.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Shopping\Autos.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://autos.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Shopping\Classifieds.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://classifieds.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Shopping\Coupons.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://coupons.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Shopping\Dept. 56 Christmas In The City, Lemax Village Collection.url -> hxxp://www.village-peddler.com/dept56christmasinthecity.html
InternetURL: C:\Users\User\Favorites\Yahoo!\Shopping\Real Estate.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://realestate.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Shopping\Shopping.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://shopping.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Shopping\Tech.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://tech.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Shopping\Tickets.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://tickets.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Shopping\Wallet.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://wallet.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Shopping\Yellow Pages.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://yp.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Personal Publishing\Domains.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://domains.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Personal Publishing\Flickr.url -> hxxp://www.flickr.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Personal Publishing\GeoCities.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://geocities.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Personal Publishing\Picture Gallery.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://gallery.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Personal Finance\Finance.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://finance.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Personal Finance\Personal Finance.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://finance.yahoo.com/personal-finance
InternetURL: C:\Users\User\Favorites\Yahoo!\News\Alerts.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://alerts.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\News\Buzz Index.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://buzz.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\News\Lottery Results.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://lottery.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\News\News Front Page.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://news.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\News\News Full Coverage.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://fullcoverage.yahoo.com/fc/
InternetURL: C:\Users\User\Favorites\Yahoo!\News\Weather.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://weather.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Information Management\360.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://360.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Information Management\Address Book.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://address.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Information Management\Answers.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://answers.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Information Management\Bookmarks.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://bookmarks.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Information Management\Briefcase.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://briefcase.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Information Management\Calendar.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://calendar.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Information Management\Directory.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://dir.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Information Management\Family Accounts.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://family.yahoo.com/family
InternetURL: C:\Users\User\Favorites\Yahoo!\Information Management\My Web.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://myweb.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Information Management\My Yahoo!.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://my.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Information Management\Notepad.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://notepad.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Information Management\Postal Center.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://postalcenter.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Information Management\Search.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://search.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Information Management\Toolbar.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://toolbar.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Information Management\Widgets.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://widgets.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Home & Living\Autos.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://autos.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Home & Living\Careers.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://careers.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Home & Living\Coupons.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://coupons.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Home & Living\Family Accounts.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://family.yahoo.com/family
InternetURL: C:\Users\User\Favorites\Yahoo!\Home & Living\Food.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://food.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Home & Living\Get Local.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://local.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Home & Living\Health.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://health.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Home & Living\hypothyroidism Nutritional, Lifestyle and Environmental Causes Your Doctor Might Miss.url -> hxxp://www.ei-resource.org/myblog/Hypothyroidism-Nutritional-Lifestyle-and-Environmental-Causes-Your-Doctor-Might-Miss.html
InternetURL: C:\Users\User\Favorites\Yahoo!\Home & Living\Kids.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://kids.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Home & Living\Personals.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://personals.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Home & Living\Pets.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://pets.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Home & Living\Real Estate.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://realestate.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Entertainment\Astrology.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://astrology.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Entertainment\Cool Photo Effects & Image Effects.url -> hxxp://www.coolphotofx.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Entertainment\Entertainment.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://entertainment.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Entertainment\Games.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://games.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Entertainment\Movies.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://movies.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Entertainment\Music.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://music.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Entertainment\TV Coverage.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://tv.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Entertainment\Video.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://video.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Community\360.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://360.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Community\Answers.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://answers.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Community\Chat.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://alerts.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Community\Education.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://education.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Community\Flickr.url -> hxxp://www.flickr.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Community\Groups.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://groups.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Community\Member Directory.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://members.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Community\Message Boards.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://messages.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Community\My Web.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://myweb.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Community\People Search.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://people.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Community\Personals.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://personals.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Communication\Alerts.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://alerts.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Communication\English to Cherokee Translation.url -> hxxp://home.earthlink.net/~deanna1jc/moondoves_spiral_maindictionary.htm
InternetURL: C:\Users\User\Favorites\Yahoo!\Communication\Greetings.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://greetings.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Communication\Mail.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://mail.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Communication\Messenger.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://messenger.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Communication\Mobile.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://mobile.yahoo.com/
InternetURL: C:\Users\User\Favorites\Yahoo!\Communication\Voice.url -> hxxp://red.clientapps.yahoo.com/customize/favorites/msgr8/*hxxp://voice.yahoo.com/
InternetURL: C:\Users\User\Favorites\Windows Live\Get Windows Live.url -> hxxp://go.microsoft.com/fwlink/?LinkId=69172
InternetURL: C:\Users\User\Favorites\Windows Live\Windows Live Gallery.url -> hxxp://go.microsoft.com/fwlink/?LinkId=70742
InternetURL: C:\Users\User\Favorites\Windows Live\Windows Live Mail.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68925
InternetURL: C:\Users\User\Favorites\Windows Live\Windows Live Spaces.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68927
InternetURL: C:\Users\User\Favorites\radio\play.it Radio Player.url -> hxxp://player.play.it/player/player.html?id=340&onestat=wxrk-hd2
InternetURL: C:\Users\User\Favorites\MSN Websites\Axia College Of UOP Student and Faculty Web - Home Page.url -> https://axiaecampus..../courseList.asp
InternetURL: C:\Users\User\Favorites\MSN Websites\MSN Autos.url -> hxxp://go.microsoft.com/fwlink/?LinkId=55143
InternetURL: C:\Users\User\Favorites\MSN Websites\MSN Entertainment.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68924
InternetURL: C:\Users\User\Favorites\MSN Websites\MSN Money.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68923
InternetURL: C:\Users\User\Favorites\MSN Websites\MSN Sports.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68921
InternetURL: C:\Users\User\Favorites\MSN Websites\MSN.url -> hxxp://go.microsoft.com/fwlink/?LinkId=54729
InternetURL: C:\Users\User\Favorites\MSN Websites\MSNBC News.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68922
InternetURL: C:\Users\User\Favorites\Microsoft Websites\IE Add-on site.url -> hxxp://go.microsoft.com/fwlink/?LinkId=50893
InternetURL: C:\Users\User\Favorites\Microsoft Websites\IE site on Microsoft.com.url -> hxxp://go.microsoft.com/fwlink/?linkid=44661
InternetURL: C:\Users\User\Favorites\Microsoft Websites\Marketplace.url -> hxxp://go.microsoft.com/fwlink/?linkid=69151
InternetURL: C:\Users\User\Favorites\Microsoft Websites\Microsoft At Home.url -> hxxp://go.microsoft.com/fwlink/?linkid=55424
InternetURL: C:\Users\User\Favorites\Microsoft Websites\Microsoft At Work.url -> hxxp://go.microsoft.com/fwlink/?linkid=68920
InternetURL: C:\Users\User\Favorites\Microsoft Websites\Microsoft Showcase.url -> hxxp://g.msn.com/1me10IE8ENUS01/413
InternetURL: C:\Users\User\Favorites\Microsoft Websites\Microsoft Store.url -> hxxp://go.microsoft.com/fwlink/?linkid=140813
InternetURL: C:\Users\User\Favorites\Microsoft Websites\Microsoft.com.url -> hxxp://g.msn.com/1me10IE8ENUS01/412
InternetURL: C:\Users\User\Favorites\Microsoft Websites\Welcome to IE7.url -> hxxp://go.microsoft.com/fwlink/?linkid=68919
InternetURL: C:\Users\User\Favorites\math\Free p-Value Calculator for the Student t-Test.url -> hxxp://danielsoper.com/statcalc/calc08.aspx
InternetURL: C:\Users\User\Favorites\math\GraphPad QuickCalcs t test calculator.url -> hxxp://www.graphpad.com/quickcalcs/ttest1.cfm
InternetURL: C:\Users\User\Favorites\math\http--www.sjsu.edu-faculty-gerstman-StatPrimer-t-table.pdf.url -> hxxp://www.sjsu.edu/faculty/gerstman/StatPrimer/t-table.pdf
InternetURL: C:\Users\User\Favorites\math\Interval Notation.url -> hxxp://id.mind.net/~zona/mmts/miscellaneousMath/intervalNotation/intervalNotation.html
InternetURL: C:\Users\User\Favorites\math\One-Way ANOVA.url -> hxxp://faculty.vassar.edu/lowry/anova1u.html
InternetURL: C:\Users\User\Favorites\math\Two-Way ANOVA.url -> hxxp://faculty.vassar.edu/lowry/anova2u.html
InternetURL: C:\Users\User\Favorites\math\Z Table.url -> hxxp://lilt.ilstu.edu/dasacke/eco148/ZTable.htm
InternetURL: C:\Users\User\Favorites\Links\(1) Rain Corr.url -> https://www.facebook...307&ref=tn_tnmn
InternetURL: C:\Users\User\Favorites\Links\2008 May « Parsley, Sage, Desserts and Line Drives.url -> hxxp://lisamichele.wordpress.com/2008/05/
InternetURL: C:\Users\User\Favorites\Links\7 signs your honey may cheat.url -> hxxp://yahoo.match.com/y/article.aspx?articleid=7764&TrackingID=526103&BannerID=740727
InternetURL: C:\Users\User\Favorites\Links\Account.url -> hxxp://www.facebook.com/editaccount.php?ref=mb&drop
InternetURL: C:\Users\User\Favorites\Links\Ana-White.com — Page 7.url -> hxxp://ana-white.com/page/7
InternetURL: C:\Users\User\Favorites\Links\Autumn Love Necklace.url -> hxxp://www.beadinspirations.com/index.php?main_page=index&cPath=231_168
InternetURL: C:\Users\User\Favorites\Links\Bacardi Rum Cake Recipe - Recipe for Bacardi Rum Cake - Cake Mix Recipe.url -> hxxp://baking.about.com/od/bundtcakes/r/bacardirum.htm
InternetURL: C:\Users\User\Favorites\Links\Bello Modo - Bello Modo.url -> hxxp://www.bellomodo.com/index.php
InternetURL: C:\Users\User\Favorites\Links\Bing™ Traffic.url -> hxxp://g.msn.com/1me10IE8ENUS01/602
InternetURL: C:\Users\User\Favorites\Links\Biscoff Cupcakes with Biscoff Buttercream Plain Chicken.url -> hxxp://www.plainchicken.com/2012/03/biscoff-cupcakes-with-biscoff.html
InternetURL: C:\Users\User\Favorites\Links\Bloom's Taxonomy.url -> hxxp://officeport.com/edu/blooms.htm
InternetURL: C:\Users\User\Favorites\Links\BLT Pasta Salad Recipe - Food.com - 229209.url -> hxxp://www.food.com/recipe/blt-pasta-salad-229209
InternetURL: C:\Users\User\Favorites\Links\Cafe World – Ingredients for Fry Hard 8, 9 and 10 » The Facegamer (2).url -> hxxp://www.thefacegamer.com/restaurant/cafe-world/cafe-world-ingredients-for-fry-hard-8-9-and-10/
InternetURL: C:\Users\User\Favorites\Links\Cafe World – Ingredients for Fry Hard 8, 9 and 10 » The Facegamer.url -> hxxp://www.thefacegamer.com/restaurant/cafe-world/cafe-world-ingredients-for-fry-hard-8-9-and-10/
InternetURL: C:\Users\User\Favorites\Links\Candy Store - Candy you ate as a kid®.url -> hxxp://www.oldtimecandy.com/candylist.htm
InternetURL: C:\Users\User\Favorites\Links\craigslist north dakota classifieds for jobs, apartments, personals, for sale, services, community, and events.url -> hxxp://nd.craigslist.org/
InternetURL: C:\Users\User\Favorites\Links\Creative Ways to Promote Your Etsy Shop - Discussions - Etsy Success - Etsy Teams.url -> hxxp://www.etsy.com/teams/5002/etsy-success/discuss/6766590/?utm_source=bronto&utm_medium=email&utm_term=in+this+thread...%C2%A0&utm_content=etsy_success_sm_020111&utm_campaign=etsy_success_sm_020111
InternetURL: C:\Users\User\Favorites\Links\Desserts.url -> hxxp://www.itsatrip.org/albuquerque/cuisine-dining/recipe/dessert/default.aspx
InternetURL: C:\Users\User\Favorites\Links\Devil Dogs The Pioneer Woman Cooks Ree Drummond.url -> hxxp://thepioneerwoman.com/cooking/2011/02/devil-dogs/
InternetURL: C:\Users\User\Favorites\Links\divorce Modifying Child Support FAQs - Lawyers.url -> hxxp://family-law.lawyers.com/child-support/Divorce-Modifying-Child-Support-FAQs.html
InternetURL: C:\Users\User\Favorites\Links\Doug Grosjean's Alaska Trip Report - Day 1.url -> hxxp://www.ibmwr.org/pastevnt/grosjeanalaska/day1.html
InternetURL: C:\Users\User\Favorites\Links\Etsy Newbies Get more exposure for your listings, and making more sales.url -> hxxp://www.etsy.com/forums_thread.php?thread_id=6586654&utm_source=bronto&utm_medium=email&utm_term=Newbies%3A+Get+More+Exposure&utm_content=etsy_success_121410&utm_campaign=etsy_success_121410
InternetURL: C:\Users\User\Favorites\Links\Fairview.url -> hxxp://www.range.fairview.org/
InternetURL: C:\Users\User\Favorites\Links\Florentiners à la Mama Gesine Bullock-Prado comes to visit King Arthur Flour – Baking Banter.url -> hxxp://www.kingarthurflour.com/blog/2011/03/25/florentiners-a-la-mama-gesine-bullock-prado-comes-to-visit/?go=RT110325D&utm_source=RT110325&utm_medium=email&utm_content=&spMailingID=3850742&spUserID=MTIyOTM0MTIwNjYS1&spJobID=227524141&spReportId=MjI3NTI0MTQxS0
InternetURL: C:\Users\User\Favorites\Links\Frustrated with buyers!!! - Discussions - etsian newbie - Etsy Teams.url -> hxxp://www.etsy.com/teams/6868/etsian-newbie/discuss/6788817/
InternetURL: C:\Users\User\Favorites\Links\Goals - Café World Wiki - Cookbook, Recipes, Gifts and more!.url -> hxxp://cafeworld.wikia.com/wiki/Category:Goals
InternetURL: C:\Users\User\Favorites\Links\How to Clean Eyebrow Wax Out of Carpet eHow.url -> hxxp://www.ehow.com/how_4885451_clean-eyebrow-wax-out-carpet.html
InternetURL: C:\Users\User\Favorites\Links\http--www.ronkleinphotos.com-lawrencezoom1111.url -> hxxp://www.ronkleinphotos.com/lawrencezoom1111.html
InternetURL: C:\Users\User\Favorites\Links\http--www.russellconsultinginc.com-docs-PDF-matrix.url -> hxxp://www.russellconsultinginc.com/docs/PDF/matrix.pdf
InternetURL: C:\Users\User\Favorites\Links\Ink Tools & Accessories Bead Inspirations!, Free shipping, no minimum order.url -> hxxp://www.beadinspirations.com/index.php?main_page=index&cPath=388_395
InternetURL: C:\Users\User\Favorites\Links\Kensho.url -> hxxp://the-wanderling.com/kensho.html
InternetURL: C:\Users\User\Favorites\Links\Linux vs Windows (a comparison).url -> hxxp://www.michaelhorowitz.com/Linux.vs.Windows.html
InternetURL: C:\Users\User\Favorites\Links\Managing your project's critical path - Project - Microsoft Office.url -> hxxp://office.microsoft.com/en-us/project-help/managing-your-project-s-critical-path-HA001021173.aspx
InternetURL: C:\Users\User\Favorites\Links\Masters Degree in Information Security - SANS Technology Institute.url -> hxxp://www.sans.edu/about
InternetURL: C:\Users\User\Favorites\Links\Microsoft Architecture Overview.url -> hxxp://msdn.microsoft.com/en-us/library/ms978007.aspx
InternetURL: C:\Users\User\Favorites\Links\My Yahoo!.url -> hxxp://red.clientapps.yahoo.com/customize/links/msgr8/*hxxp://my.yahoo.com/
InternetURL: C:\Users\User\Favorites\Links\NetBeans IDE 6.9 Java Quick Start Tutorial.url -> hxxp://netbeans.org/kb/docs/java/quickstart.html
InternetURL: C:\Users\User\Favorites\Links\North Dakota Womens' Way - Enrollment Locations.url -> hxxp://www.ndhealth.gov/womensway/?advancedmode=1&id=74&unit[]=First+District+Health+Unit&county_or_counties=&contact=&address=&phone=&fax=&ormode=1
InternetURL: C:\Users\User\Favorites\Links\Norwich State Hospital - Abandoned Photography at Opacity.url -> hxxp://www.opacity.us/site64_norwich_state_hospital.htm
InternetURL: C:\Users\User\Favorites\Links\Parenting Emotionally Intense Gifted Children.url -> hxxp://talentdevelop.com/articles/ParentingEIGC.html
InternetURL: C:\Users\User\Favorites\Links\Pig Cake The Pioneer Woman Cooks Ree Drummond.url -> hxxp://thepioneerwoman.com/cooking/2011/01/pig-cake/
InternetURL: C:\Users\User\Favorites\Links\Plate Tectonics.url -> hxxp://www.pacificislandtravel.com/nature_gallery/platetectonics.html
InternetURL: C:\Users\User\Favorites\Links\Project Assumptions.url -> hxxp://www.projectperfect.com.au/info_assumptions.php
InternetURL: C:\Users\User\Favorites\Links\Project Management Knowledge Schedule Milestone » Project Management Knowledge.url -> hxxp://project-management-knowledge.com/definitions/s/schedule-milestone/
InternetURL: C:\Users\User\Favorites\Links\qdb Latest 50 Quotes.url -> hxxp://www.bash.org/?latest
InternetURL: C:\Users\User\Favorites\Links\Quotes Facebook Banners.url -> hxxp://www.fbanners.com/tags/10/quotes.html
InternetURL: C:\Users\User\Favorites\Links\Red Velvet Sandwich Cookies The Family Kitchen.url -> hxxp://blogs.babble.com/family-kitchen/2010/11/08/red-velvet-sandwich-cookies/
InternetURL: C:\Users\User\Favorites\Links\Restaurant Style Salsa The Pioneer Woman Cooks Ree Drummond.url -> hxxp://thepioneerwoman.com/cooking/2010/01/restaurant-style-salsa/
InternetURL: C:\Users\User\Favorites\Links\resume-rules-fact-fiction Personal Finance News from Yahoo! Finance.url -> hxxp://finance.yahoo.com/career-work/article/111962/resume-rules-fact-fiction
InternetURL: C:\Users\User\Favorites\Links\Ritter Sport Chocolate.url -> hxxp://www.malincho.com/c-31-ritter-sport-chocolate.aspx
InternetURL: C:\Users\User\Favorites\Links\sans Computer Security Training, Network Security Research, InfoSec Resources.url -> hxxp://www.sans.org/
InternetURL: C:\Users\User\Favorites\Links\shakesville Today in Rape Culture.url -> hxxp://shakespearessister.blogspot.com/2011/02/today-in-rape-culture_24.html
InternetURL: C:\Users\User\Favorites\Links\Shaved Ice Beverage Sample Business Plan - Executive Summary — Bplans.url -> hxxp://www.bplans.com/shaved_ice_beverage_business_plan/executive_summary_fc.php
InternetURL: C:\Users\User\Favorites\Links\Sociobiological theories of rape - Wikipedia, the free encyclopedia.url -> hxxp://en.wikipedia.org/wiki/Sociobiological_theories_of_rape
InternetURL: C:\Users\User\Favorites\Links\Sock Dreams » Socks.url -> hxxp://www.sockdreams.com/products/socks/
InternetURL: C:\Users\User\Favorites\Links\software - photographer's exposure calculator robert klep.url -> hxxp://klep.name/programming/expocalc/
InternetURL: C:\Users\User\Favorites\Links\Speculoos Spread European Spread Alternative to Peanut Butter.url -> hxxp://www.biscoff.com/DirectionsWEB/webcart_category.php?catid=BSPREAD&pcatid=BISCOFF&sourcecode=GOOGLE4&gclid=CJ298-aDjqcCFcjsKgodei9XgA
InternetURL: C:\Users\User\Favorites\Links\Spicy Dr. Pepper Shredded Pork The Pioneer Woman Cooks Ree Drummond.url -> hxxp://thepioneerwoman.com/cooking/2011/03/spicy-dr-pepper-shredded-pork/
InternetURL: C:\Users\User\Favorites\Links\Starbucks has cakepops, whoopie pies and other sweet petites.url -> hxxp://networkedblogs.com/fiDM4
InternetURL: C:\Users\User\Favorites\Links\Suggested Sites.url -> https://ieonline.mic...ft.com/#ieslice
InternetURL: C:\Users\User\Favorites\Links\Support by Users for Users - Zynga Community Forums.url -> hxxp://forums.zynga.com/forumdisplay.php?f=162
InternetURL: C:\Users\User\Favorites\Links\Tea Treats from Harney & Sons.url -> hxxp://www.harney.com/Tea-Treats/departments/340/
InternetURL: C:\Users\User\Favorites\Links\The Art of Pricing Three Helpful Pricing Exercises Etsy Blog (2).url -> hxxp://www.etsy.com/storque/seller-handbook/the-art-of-pricing-three-helpful-pricing-exercises-3788/?utm_source=bronto&utm_medium=email&utm_term=Read+on...&utm_content=etsy_success_sm_012511&utm_campaign=etsy_success_sm_012511
InternetURL: C:\Users\User\Favorites\Links\The Art of Pricing Three Helpful Pricing Exercises Etsy Blog.url -> hxxp://www.etsy.com/storque/seller-handbook/the-art-of-pricing-three-helpful-pricing-exercises-3788/?utm_source=bronto&utm_medium=email&utm_term=Three+Pricing+Exercises&utm_content=etsy_success_sm_012511&utm_campaign=etsy_success_sm_012511
InternetURL: C:\Users\User\Favorites\Links\The Cooking Photographer Butterfinger Peanut Butter Chip Fudge Cookies.url -> hxxp://www.thecookingphotographer.com/2010/05/butterfinger-peanut-butter-chip-fudge.html
InternetURL: C:\Users\User\Favorites\Links\Ultimate Exposure Computer.url -> hxxp://www.fredparker.com/ultexp1.htm
InternetURL: C:\Users\User\Favorites\Links\Uploader - Uploader v6.url -> hxxp://www.aww-kittah-aww.com/up/index.php
InternetURL: C:\Users\User\Favorites\Links\W3Schools Online Web Tutorials.url -> hxxp://www.w3schools.com/
InternetURL: C:\Users\User\Favorites\Links\Web Slice Gallery.url -> hxxp://go.microsoft.com/fwlink/?LinkId=121315
InternetURL: C:\Users\User\Favorites\Links\Wonderfully Wordy.url -> hxxp://wonderfullywordy.blogspot.com/
InternetURL: C:\Users\User\Favorites\Links\Yahoo! Answers.url -> hxxp://red.clientapps.yahoo.com/customize/links/msgr8/*hxxp://answers.yahoo.com/
InternetURL: C:\Users\User\Favorites\Links\Yahoo! Downloads.url -> hxxp://red.clientapps.yahoo.com/customize/links/msgr8/*hxxp://downloads.yahoo.com/
InternetURL: C:\Users\User\Favorites\Links\Yahoo! Mail.url -> hxxp://red.clientapps.yahoo.com/customize/links/msgr8/*hxxp://mail.yahoo.com/
InternetURL: C:\Users\User\Favorites\Links\Yahoo!.url -> hxxp://red.clientapps.yahoo.com/customize/links/msgr8/*hxxp://www.yahoo.com/
InternetURL: C:\Users\User\Favorites\Links\“San Francisco in Ruins” by George Lawrence.url -> hxxp://earthquake.usgs.gov/regional/nca/1906/kap/lawrence.php
InternetURL: C:\Users\User\Favorites\Links\it stuff\Amazon.com Ivor Horton's Beginning Java 2, JDK 5 Edition (9780764568749) Ivor Horton Books.url -> hxxp://www.amazon.com/gp/product/0764568744/ref=oss_product
InternetURL: C:\Users\User\Favorites\Links\it stuff\Etsy Post Anything!!!.url -> hxxp://www.etsy.com/forums_thread.php?page=1&thread_id=6653516
InternetURL: C:\Users\User\Favorites\Links\it stuff\Facebook Messages.url -> hxxp://www.facebook.com/?sk=messages
InternetURL: C:\Users\User\Favorites\Links\it stuff\Generally Lubricious - DryerLint-NewLeaf.com Forums.url -> hxxp://dryerlint-newleaf.com/forums/forumdisplay.php?f=4
InternetURL: C:\Users\User\Favorites\Links\it stuff\http--sphotos.ak.fbcdn.net-hphotos-ak-snc3-hs458.snc3-26208_382029502383_606027383_3668691_2608882_n.jpg.url -> hxxp://sphotos.ak.fbcdn.net/hphotos-ak-snc3/hs458.snc3/26208_382029502383_606027383_3668691_2608882_n.jpg
InternetURL: C:\Users\User\Favorites\Links\it stuff\Inbox (103) - Yahoo! Mail.url -> hxxp://us.mc818.mail.yahoo.com/mc/welcome?.gx=1&.tm=1286979340&.rand=br0jkosegg5kr
InternetURL: C:\Users\User\Favorites\Links\it stuff\Mr.Bool - Place for software developers.url -> hxxp://www.mrbool.com/portal/
InternetURL: C:\Users\User\Favorites\Links\it stuff\SANS Computer Security Training, Network Security Research, InfoSec Resources.url -> hxxp://www.sans.org/
InternetURL: C:\Users\User\Favorites\IT Information for class\3.6 UNT INFORMATION RESOURCES SECURITY POLICY.url -> hxxp://www.unt.edu/policy/UNT_Policy/volume2/3_6.html
InternetURL: C:\Users\User\Favorites\IT Information for class\Acquisition Support Getting Started Areas of Work Put the SEI to Work for You.url -> hxxp://www.sei.cmu.edu/acquisition/start/work/index.cfm
InternetURL: C:\Users\User\Favorites\IT Information for class\Advantages and Disadvantages of Each Approach Erpstudies.com.url -> hxxp://erpstudies.com/sap/60-managing-business-with-sap-planningimplementation/229-advantages-and-disadvantages-of-each-approach.html
InternetURL: C:\Users\User\Favorites\IT Information for class\Advantages of dynamic routing.url -> hxxp://searchnetworking.techtarget.com/tip/0,289483,sid7_gci530176,00.html
InternetURL: C:\Users\User\Favorites\IT Information for class\Application Architecture & Process Design.url -> hxxp://web.simmons.edu/~benoit/LIS486/ApplicationArch.html
InternetURL: C:\Users\User\Favorites\IT Information for class\Basic Switch Setup.url -> hxxp://noc2.datacomm.unt.edu/Datacomm/SwitchSetup.htm
InternetURL: C:\Users\User\Favorites\IT Information for class\Benefits of VLANs - Bandipedia.url -> hxxp://www.bandwidth.com/wiki/article/Benefits_of_VLANs
InternetURL: C:\Users\User\Favorites\IT Information for class\Building a Cisco wireless LAN - Google Books.url -> hxxp://books.google.com/books?id=LN1xako6zIwC&pg=PA49&lpg=PA49&dq=Microwave+signals+and+WANS&source=bl&ots=xTtanhePVx&sig=6BkRhHHq2orJuDF5ifTjSmLCrd8&hl=en&ei=S2KbSrOBK6KNtgfHvMHJBA&sa=X&oi=book_result&ct=result&resnum=7
InternetURL: C:\Users\User\Favorites\IT Information for class\Business Continuity Management Software.url -> hxxp://www.availability.sungard.com/sungardsolutions/ITSolutions/software/Pages/software.aspx/MediaPR/BCPLibrary/BCPCaseStudies.asp
InternetURL: C:\Users\User\Favorites\IT Information for class\Circuit switching - Wikipedia, the free encyclopedia.url -> hxxp://en.wikipedia.org/wiki/Circuit_switching
InternetURL: C:\Users\User\Favorites\IT Information for class\Circuit Switching vs. Packet Switching.url -> hxxp://voip.about.com/od/voipbasics/a/switchingtypes.htm
InternetURL: C:\Users\User\Favorites\IT Information for class\Cisco - Routing Protocols.url -> hxxp://www.cisco.com/public/technotes/tech_protocol.shtml
InternetURL: C:\Users\User\Favorites\IT Information for class\Cisco SPA9000 Voice System  [Cisco Small Business Voice Systems (Linksys Business Series)] - Cisco Systems.url -> hxxp://www.cisco.com/en/US/prod/collateral/voicesw/ps6788/vcallcon/ps10030/ps10031/data_sheet_c78-504126.html
InternetURL: C:\Users\User\Favorites\IT Information for class\Computer viruses vs biological viruses.url -> hxxp://www.scienceinafrica.co.za/2002/october/viruses.htm
InternetURL: C:\Users\User\Favorites\IT Information for class\Configuring Ethernet VLAN Trunks  [Cisco Catalyst 6500 Series Switches] - Cisco Systems.url -> hxxp://www.cisco.com/en/US/docs/switches/lan/catalyst6500/catos/8.x/configuration/guide/e_trunk.html
InternetURL: C:\Users\User\Favorites\IT Information for class\configuring Switch Information.url -> hxxp://support.dell.com/support/edocs/network/pc6024/en/ug/html/configud.htm
InternetURL: C:\Users\User\Favorites\IT Information for class\Cyber Essays - Free Term Papers, Essays, and Reports!.url -> hxxp://www.cyberessays.com/
InternetURL: C:\Users\User\Favorites\IT Information for class\Document Type Definitions - DTD's - Cre8asite Forums.url -> hxxp://www.cre8asiteforums.com/forums/index.php?showtopic=395
InternetURL: C:\Users\User\Favorites\IT Information for class\Dynamic Routing Protocols Routing Protocol Basics.url -> hxxp://www.ciscopress.com/articles/article.asp?p=24090
InternetURL: C:\Users\User\Favorites\IT Information for class\Dynamic Routing Protocols Static or Dynamic Routing.url -> hxxp://www.ciscopress.com/articles/article.asp?p=24090&seqNum=6
InternetURL: C:\Users\User\Favorites\IT Information for class\Explain 7 layers of OSI model. Details..url -> hxxp://www.coders2020.com/explain-7-layers-of-osi-model-what-are-the-benifits-of-osi-model-does-every-networking-device-need-to-have-all-the-layers
InternetURL: C:\Users\User\Favorites\IT Information for class\Firewall - Wikipedia, the free encyclopedia.url -> hxxp://en.wikipedia.org/wiki/Firewall
InternetURL: C:\Users\User\Favorites\IT Information for class\Firewalls and Internet Security - The Internet Protocol Journal - Volume 2, No. 2 - Cisco Systems.url -> hxxp://www.cisco.com/web/about/ac123/ac147/ac174/ac200/about_cisco_ipj_archive_article09186a00800c85ae.html
InternetURL: C:\Users\User\Favorites\IT Information for class\Frequently Asked Questions about the GNU Licenses - GNU Project - Free Software Foundation (FSF).url -> hxxp://www.gnu.org/licenses/gpl-faq.html
InternetURL: C:\Users\User\Favorites\IT Information for class\Hey all...I need to know the basic of installing... - JustAnswer.url -> hxxp://www.justanswer.com/questions/1gsqy-hey-need-know-basic-installing
InternetURL: C:\Users\User\Favorites\IT Information for class\How Does a CPU Work eHow.com.url -> hxxp://www.ehow.com/how-does_4568642_a-cpu-work.html
InternetURL: C:\Users\User\Favorites\IT Information for class\How to Setup VLAN Trunking Protocol (VTP) on Cisco Switches.url -> hxxp://www.petri.co.il/csc_setup_a_vtp_on_cisco_switches.htm
InternetURL: C:\Users\User\Favorites\IT Information for class\http--www.cisco.com-en-US-docs-switches-lan-catalyst2960-software-release-12.2_25_see-command-reference-intro.html.url -> hxxp://www.cisco.com/en/US/docs/switches/lan/catalyst2960/software/release/12.2_25_see/command/reference/intro.html
InternetURL: C:\Users\User\Favorites\IT Information for class\http--www.cisco.com-en-US-docs-switches-metro-me2400-hardware-installation-guide-HGcliSET.html.url -> hxxp://www.cisco.com/en/US/docs/switches/metro/me2400/hardware/installation/guide/HGcliSET.html
InternetURL: C:\Users\User\Favorites\IT Information for class\http--www.cisco.com-en-US-prod-collateral-routers-ps5853-ps6184-product_data_sheet0900aecd8028a95f_ps5853_Products_Data_Sheet.html.url -> hxxp://www.cisco.com/en/US/prod/collateral/routers/ps5853/ps6184/product_data_sheet0900aecd8028a95f_ps5853_Products_Data_Sheet.html
InternetURL: C:\Users\User\Favorites\IT Information for class\http--www.dementia.org-~shadow-crypt-Cryptography_FAQ_(03_10_Basic_Cryptology).url -> hxxp://www.dementia.org/~shadow/crypt/Cryptography_FAQ_(03_10:_Basic_Cryptology)
InternetURL: C:\Users\User\Favorites\IT Information for class\http--www.wvdhhr.org-MIS-IT-512attA.pdf.url -> hxxp://www.wvdhhr.org/MIS/IT/512attA.pdf
InternetURL: C:\Users\User\Favorites\IT Information for class\https--www.cisco.com-web-about-ciscoitatwork-security-cisco_virtual_office_india_web.html.url -> https://www.cisco.co..._india_web.html
InternetURL: C:\Users\User\Favorites\IT Information for class\Is your company ready for a satellite-based WAN connection.url -> hxxp://articles.techrepublic.com.com/5100-10878_11-5142247.html
InternetURL: C:\Users\User\Favorites\IT Information for class\Key Measures of Success for System Implementation Project Management WebProNews.url -> hxxp://www.webpronews.com/expertarticles/2006/07/10/key-measures-of-success-for-system-implementation-project-management
InternetURL: C:\Users\User\Favorites\IT Information for class\Microwave - Wikipedia, the free encyclopedia.url -> hxxp://en.wikipedia.org/wiki/Microwave
InternetURL: C:\Users\User\Favorites\IT Information for class\Most Popular Programming Languages.url -> hxxp://www.devtopics.com/most-popular-programming-languages/
InternetURL: C:\Users\User\Favorites\IT Information for class\Network Security Firewalls (remember for report!).url -> hxxp://www.integritycomputing.com/security2.html
InternetURL: C:\Users\User\Favorites\IT Information for class\Phase 3 Implementation.url -> hxxp://msdn.microsoft.com/en-us/library/cc307416.aspx
InternetURL: C:\Users\User\Favorites\IT Information for class\Public-key encryption for dummies.url -> hxxp://www.networkworld.com/news/64452_05-17-1999.html
InternetURL: C:\Users\User\Favorites\IT Information for class\Software Acceptance and Installation.url -> hxxp://www.learn.geekinterview.com/it/sdlc/software-acceptance-and-installation.html
InternetURL: C:\Users\User\Favorites\IT Information for class\Software Development Life Cycle (SDLC), Process & Business Models.url -> hxxp://www.stylusinc.com/Common/Concerns/SoftwareDevtPhilosophy.php
InternetURL: C:\Users\User\Favorites\IT Information for class\Static Routing vs. Dynamic Routing.url -> hxxp://www.inetdaemon.com/tutorials/internet/ip/routing/dyamic_vs_static.shtml
InternetURL: C:\Users\User\Favorites\IT Information for class\System Development Life Cycle.url -> hxxp://www.startvbdotnet.com/sdlc/sdlc.aspx
InternetURL: C:\Users\User\Favorites\IT Information for class\Teach ICT What is Packet Switching.url -> hxxp://www.teach-ict.com/technology_explained/packet_switching/packet_switching.html
InternetURL: C:\Users\User\Favorites\IT Information for class\The TCP-IP Guide - Circuit Switching and Packet Switching Networks.url -> hxxp://www.tcpipguide.com/free/t_CircuitSwitchingandPacketSwitchingNetworks.htm
InternetURL: C:\Users\User\Favorites\IT Information for class\Types Of Firewalls.url -> hxxp://www.unifiedthreatmanagement.com/types-of-firewalls.htm
InternetURL: C:\Users\User\Favorites\IT Information for class\Understanding and Configuring Spanning Tree Protocol (STP) on Catalyst Switches - Cisco Systems.url -> hxxp://www.cisco.com/en/US/tech/tk389/tk621/technologies_configuration_example09186a008009467c.shtml
InternetURL: C:\Users\User\Favorites\IT Information for class\uninett WLAN - VPN portals.url -> hxxp://forskningsnett.uninett.no/wlan/vpn.html
InternetURL: C:\Users\User\Favorites\IT Information for class\Venture Into Linux A simple overview of Linux architecture.url -> hxxp://ventureintolinux.blogspot.com/2008/03/simple-overview-of-linux-architecture.html
InternetURL: C:\Users\User\Favorites\IT Information for class\VLAN Implementation Plan, Page 2 of 2 - Associated Content.url -> hxxp://www.associatedcontent.com/article/1000912/vlan_implementation_plan_pg2.html?cat=3
InternetURL: C:\Users\User\Favorites\IT Information for class\Wireless WAN Components - Wireless,Wlan,wifi,Configuration,and,Optimization Tips.url -> hxxp://www.wireless-center.net/WLANs-WPANs/2439.html
InternetURL: C:\Users\User\Favorites\IT Information for class\Wireless WAN, Radio Modem, Loop Bypass, Data Comm for Business, Inc..url -> hxxp://www.dcbnet.com/notes/9609wmux.html
InternetURL: C:\Users\User\Favorites\IT Information for class\z-OS basic skills information center.url -> hxxp://publib.boulder.ibm.com/infocenter/zos/basics/index.jsp?topic=/com.ibm.zos.znetwork/znetwork_107.htm
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\Adult - Free Streaming Porn - Popular Sites at OVGuide The Best Adult Movies, Porn, XXX, Erotic Video, Sex Films on the Web.url -> hxxp://qa.ovguide.com/adult.html
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\Free BDSM Tube Extreme BDSM Hardcore Bondage Videos.url -> hxxp://www.bdsmplaypen.com/
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\Free sex videos, Sex tube, Free porn movies - Tube8.com.url -> hxxp://www.tube8.com/
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\Gianna Michaels takes on Shane Diesel, Free Streaming Porn.url -> hxxp://www.empflix.com/view.php?id=45778
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\Juliana Grandi Two Cocks In The Booty - Anal sex video - Tube8.com.url -> hxxp://www.tube8.com/anal/juliana-grandi-two-cocks-in-the-booty/167371/
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\Lela Star [bleep]s big dick - Pornhub.com.url -> hxxp://www.pornhub.com/view_video.php?viewkey=995564901
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\Plus Size Clothing at Woman Within®.url -> hxxp://www.womanwithin.com/default.aspx
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\pornBB Index.url -> hxxp://www.pornbb.org/new-k-nk-c0m-videos-thread-updated-every-week-t980371.html?
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\Public-key encryption for dummies.url -> hxxp://www.networkworld.com/news/64452_05-17-1999.html
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\Skeezy - Full Free Gay Sex Tube Movies, All Gay Porn XXX Videos.url -> hxxp://www.skeezy.com/
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\SlutLoad.com - Free Porn Videos - Upload Porn For Free.url -> hxxp://www.slutload.com/
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\The World of Daddy Doms and their little girls.url -> hxxp://witchyhour.net/forum/index.php?board=5.0
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\xHamster's Free Porn Videos.url -> hxxp://xhamster.com/
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\recipes\Bacardi Rum Cake Recipe - Recipe for Bacardi Rum Cake - Cake Mix Recipe.url -> hxxp://baking.about.com/od/bundtcakes/r/bacardirum.htm
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\recipes\Barn Cake with Farm Animal Cupcakes Recipe from Betty Crocker.url -> hxxp://www.bettycrocker.com/recipes.aspx/barn-cake-with-farm-animal-cupcakes
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\recipes\Blues Hog Barbecue Company It Sticks To Your Meat!.url -> hxxp://www.blueshog.com/website/products.html
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\recipes\Bright Ideas Home Page.url -> hxxp://www.brightideas.com/Default.aspx
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\recipes\Carrot Cake-Oatmeal Cookies Recipe from Betty Crocker.url -> hxxp://www.bettycrocker.com/recipes.aspx/carrot-cake-oatmeal-cookies?WT.dcsvid=Mzc3NTYwMzk3MgS2&rvrin=E3EAE4DE-94C0-4491-8503-05C0EBFB7ADB&WT.mc_id=Newsletter_BettyCrocker_08_06_2009
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\recipes\Easy Ranger Cookies Recipe from Betty Crocker.url -> hxxp://www.bettycrocker.com/recipes.aspx/easy-ranger-cookies
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\recipes\Easy Salted Peanut Chews Recipe from Betty Crocker.url -> hxxp://www.bettycrocker.com/recipes.aspx/easy-salted-peanut-chews?WT.dcsvid=Mzc3NTYwMzk3MgS2&rvrin=E3EAE4DE-94C0-4491-8503-05C0EBFB7ADB&WT.mc_id=Newsletter_BettyCrocker_07_24_2009
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\recipes\Easy Scone Mix Recipe from Betty Crocker.url -> hxxp://www.bettycrocker.com/recipes.aspx/easy-scone-mix
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\recipes\Peach Crisp Recipe from Betty Crocker.url -> hxxp://www.bettycrocker.com/recipes.aspx/peach-crisp?WT.dcsvid=Mzc3NTYwMzk3MgS2&rvrin=E3EAE4DE-94C0-4491-8503-05C0EBFB7ADB&WT.mc_id=Newsletter_BettyCrocker_09_10_2009
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\recipes\Scone Recipes from BettyCrocker.com - Easy recipes & meal ideas.url -> hxxp://www.bettycrocker.com/recipelist.aspx/Scone
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\recipes\Sex in a Pan Food & Life.url -> hxxp://sweetnicks.com/weblog/2004/08/sex-in-a-pan-2/
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\recipes\Sinfully sweet apples.url -> hxxp://sinfullysweetgourmettreats.com/caramel-apples-goumet.html
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\recipes\Tasty Trail-Mix Treats Recipe from Betty Crocker.url -> hxxp://www.bettycrocker.com/recipes.aspx/tasty-trail-mix-treats?WT.dcsvid=Mzc3NTYwMzk3MgS2&rvrin=E3EAE4DE-94C0-4491-8503-05C0EBFB7ADB&WT.mc_id=Newsletter_BettyCrocker_08_06_2009
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\recipes\The Pioneer Woman Cooks - Ree Drummond.url -> hxxp://thepioneerwoman.com/cooking/2008/06/crash-hot-potatoes/
InternetURL: C:\Users\User\Favorites\IT Information for class\naughty\recipes\Tres Leches Cake Recipe.url -> hxxp://mexicanfood.about.com/od/sweetsanddesserts/r/treslechescake.htm
InternetURL: C:\Users\User\Favorites\HP\Accessories.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=hpaccessories&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\User\Favorites\HP\Activity Center.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=activitycenter&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\User\Favorites\HP\Digital Entertainment.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=digitalentm&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\User\Favorites\HP\eBay.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=ebay&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\User\Favorites\HP\HP Club.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=hpclub&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\User\Favorites\HP\HP Home.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=hphome&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\User\Favorites\HP\HP Music.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=hpmusic&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\User\Favorites\HP\HP Store.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=hpstore&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\User\Favorites\HP\My HP Games.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=myhpgames&pf=laptop&locale=EN_US&bd=all&c=81
InternetURL: C:\Users\User\Favorites\HP\Pandora Internet Radio.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=pandora&pf=desktop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\User\Favorites\HP\PC Security.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=pcsecurity&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\User\Favorites\HP\Photo Central.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=ephoto&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\User\Favorites\HP\Printing.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=printing&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\User\Favorites\HP\Software and Driver Downloads.url -> hxxp://redirect.hp.com/svs/rdr?TYPE=4&tp=iefavs&s=downloads&pf=laptop&locale=en_us&bd=all&c=81
InternetURL: C:\Users\User\Desktop\Router Login.url -> hxxp://www.routerlogin.com/
InternetURL: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yahoo!\Games\Backgammon.url -> hxxp://red.clientapps.yahoo.com/customize/startmenu/yg/bg/msgr8/*hxxp://games.yahoo.com/bf
InternetURL: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yahoo!\Games\Dominoes.url -> hxxp://red.clientapps.yahoo.com/customize/startmenu/yg/do/msgr8/*hxxp://games.yahoo.com/do
InternetURL: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yahoo!\Games\Euchre.url -> hxxp://red.clientapps.yahoo.com/customize/startmenu/yg/eu/msgr8/*hxxp://games.yahoo.com/eu
InternetURL: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yahoo!\Games\Poker.url -> hxxp://red.clientapps.yahoo.com/customize/startmenu/yg/pk/msgr8/*hxxp://games.yahoo.com/po
InternetURL: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yahoo!\Games\Pool.url -> hxxp://red.clientapps.yahoo.com/customize/startmenu/yg/pl/msgr8/*hxxp://games.yahoo.com/pl
InternetURL: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yahoo!\Games\Spades.url -> hxxp://red.clientapps.yahoo.com/customize/startmenu/yg/sp/msgr8/*hxxp://games.yahoo.com/sp
InternetURL: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yahoo!\Accessories\Address Book.url -> hxxp://red.clientapps.yahoo.com/customize/startmenu/ya/msgr8/*hxxp://address.yahoo.com
InternetURL: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yahoo!\Accessories\Calendar.url -> hxxp://red.clientapps.yahoo.com/customize/startmenu/ya/msgr8/*hxxp://calendar.yahoo.com
InternetURL: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yahoo!\Accessories\My Yahoo!.url -> hxxp://red.clientapps.yahoo.com/customize/startmenu/ya/msgr8/*hxxp://my.yahoo.com
InternetURL: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yahoo!\Accessories\Yahoo! Downloads.url -> hxxp://red.clientapps.yahoo.com/customize/startmenu/ya/msgr8/*hxxp://downloads.yahoo.com
InternetURL: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Yahoo! Address Book.url -> hxxp://red.clientapps.yahoo.com/customize/startmenu/acc/msgr8/*hxxp://address.yahoo.com
InternetURL: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Yahoo! Calendar.url -> hxxp://red.clientapps.yahoo.com/customize/startmenu/acc/msgr8/*hxxp://calendar.yahoo.com
InternetURL: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Yahoo! Downloads.url -> hxxp://red.clientapps.yahoo.com/customize/startmenu/acc/msgr8/*hxxp://downloads.yahoo.com
InternetURL: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Yahoo!.url -> hxxp://red.clientapps.yahoo.com/customize/startmenu/acc/msgr8/*hxxp://my.yahoo.com

==================== End of log =============================
  • 0

#4
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 10,962 posts
Download the enclosed file. Attached File  fixlist.txt   652bytes   53 downloads

Save it in the same location FRST is saved.

Run FRST and click on the Fix button.

The tool will make a log in the same location FRST is saved (Fixlog.txt); please post it to your reply.


How is the computer doing?
  • 0

#5
Huntersrain

Huntersrain

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01
Ran by User (administrator) on MINWINPC on 13-03-2014 18:58:45
Running from C:\Users\User\Downloads
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingc...can-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingc...can-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Lavasoft Limited ) C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
(Eastman Kodak Company) C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\Program Files\CyberLink\Shared Files\RichVideo.exe
(Conexant Systems, Inc.) C:\Windows\system32\DRIVERS\xaudio.exe
(Yahoo! Inc.) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
(Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
(Microsoft Corporation) C:\Windows\system32\wbem\unsecapp.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(CyberLink Corp.) C:\Program Files\HP\QuickPlay\QPService.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Lavasoft Limited) C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
(Eastman Kodak Company) C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
() C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Akamai Technologies, Inc.) C:\Users\User\AppData\Local\Akamai\netsession_win.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GROOVE.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(SAMSUNG Electornics Co., Ltd.) C:\Users\User\AppData\Roaming\Verizon\UA_ar\UA.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
(Akamai Technologies, Inc.) C:\Users\User\AppData\Local\Akamai\netsession_win.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Update\1.3.22.5\GoogleCrashHandler.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
() C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apntex.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Hewlett-Packard) c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\system32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
(Yahoo! Inc.) C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
(RealNetworks, Inc.) C:\Program Files\Common Files\Real\Update_OB\realsched.exe
(Microsoft Corporation) C:\Windows\system32\msiexec.exe
(Farbar) C:\Users\User\Downloads\FRST (1).exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Apoint] - C:\Program Files\Apoint2K\Apoint.exe [159744 2007-06-30] (Alps Electric Co., Ltd.)
HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [178712 2007-10-03] (Intel Corporation)
HKLM\...\Run: [QPService] - C:\Program Files\HP\QuickPlay\QPService.exe [468264 2007-12-19] (CyberLink Corp.)
HKLM\...\Run: [QlbCtrl] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [202032 2007-12-06] ( Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [UCam_Menu] - C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2007-09-13] (CyberLink Corp.)
HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-20] (Microsoft Corporation)
HKLM\...\Run: [hpqSRMon] - [X]
HKLM\...\Run: [HP Health Check Scheduler] - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
HKLM\...\Run: [hpWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [480560 2007-10-03] (Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [HP Software Update] - C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [AppleSyncNotifier] - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [47904 2010-10-08] (Apple Inc.)
HKLM\...\Run: [Ad-Watch] - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [1191768 2012-09-21] (Lavasoft Limited)
HKLM\...\Run: [Conime] - C:\Windows\system32\conime.exe [69120 2009-04-11] (Microsoft Corporation)
HKLM\...\Run: [TkBellExe] - C:\Program Files\Common Files\Real\Update_OB\realsched.exe [202256 2010-03-31] (RealNetworks, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-07-22] (Adobe Systems Incorporated)
HKLM\...\Run: [EKIJ5000StatusMonitor] - C:\Windows\system32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe [1638400 2010-05-07] (Eastman Kodak Company)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-01-28] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-02-20] (Apple Inc.)
HKLM\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [554408 2013-05-15] (Lavasoft)
HKLM\...\Run: [VMM Mode Selection] - C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe [43520 2011-02-14] ()
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2014\avgui.exe [4962320 2014-01-22] (AVG Technologies CZ, s.r.o.)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\Run: [HPADVISOR] - C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe [1783136 2007-10-01] (Hewlett-Packard)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [455968 2007-08-23] (Hewlett-Packard Company)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\Run: [Messenger (Yahoo!)] - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [6595928 2012-05-25] (Yahoo! Inc.)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\Run: [Akamai NetSession Interface] - C:\Users\User\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\Run: [SpybotSD TeaTimer] - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\Run: [Google Update] - C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-05-20] (Google Inc.)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [18643560 2013-03-01] (Skype Technologies S.A.)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\Run: [CCleaner Monitoring] - C:\Program Files\CCleaner\CCleaner.exe [4505368 2014-02-20] (Piriform Ltd)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\RunOnce: [Shockwave Updater] - C:\Windows\System32\Adobe\Shockwave 11\SwHelper_1100470.exe [460216 2008-11-04] (Adobe Systems, Inc.)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\RunOnce: [Application Restart #6] - C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe [859464 2014-03-01] (Google Inc.)
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\MountPoints2: {3617a61e-f137-11de-865f-001eec744cb8} - G:\start.exe
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\MountPoints2: {3617a62f-f137-11de-865f-001eec744cb8} - I:\start.exe
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\MountPoints2: {6b704b5f-6d0a-11e3-b6a5-001eec744cb8} - F:\TLBootstrap_WPP.exe
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\MountPoints2: {7de53ad6-0ba7-11e3-8b85-001eec744cb8} - F:\VZW_Software_upgrade_assistant_installer.exe
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\MountPoints2: {938ab858-646b-11e3-8b81-001eec744cb8} - G:\TL-Bootstrap.exe
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\MountPoints2: {f1a0561d-c2fd-11e2-9fd4-001eec744cb8} - G:\TL-Bootstrap.exe
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\MountPoints2: {f1a060da-c2fd-11e2-9fd4-001eec744cb8} - F:\TL-Bootstrap.exe
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\InprocServer32: [Default-pngfilt] <==== ATTENTION!

Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office Groove.lnk
ShortcutTarget: Microsoft Office Groove.lnk -> C:\Program Files\Microsoft Office\Office12\GROOVE.EXE (Microsoft Corporation)
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Verizon Wireless Software Utility Application for Android – Samsung.lnk
ShortcutTarget: Verizon Wireless Software Utility Application for Android – Samsung.lnk -> C:\Users\User\AppData\Roaming\Verizon\UA_ar\UA.exe (SAMSUNG Electornics Co., Ltd.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
URLSearchHook: HKCU - YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {668BC79E-B388-40B0-8A62-E8C0F200850A} URL = http://search.yahoo....ing}&fr=hp-psdt
SearchScopes: HKLM - {8B0A8A63-D27E-476E-BCF7-9614A7362469} URL = http://www.ask.com/w...}&l=dis&o=uscqd
SearchScopes: HKCU - {668BC79E-B388-40B0-8A62-E8C0F200850A} URL = http://search.yahoo....ing}&fr=hp-psdt
SearchScopes: HKCU - {8B0A8A63-D27E-476E-BCF7-9614A7362469} URL = http://www.ask.com/w...}&l=dis&o=uscqd
BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\Windows\system32\ieframe.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - No File
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default
FF DefaultSearchEngine: Yahoo
FF SelectedSearchEngine: Yahoo
FF Homepage: hxxp://www.yahoo.com
FF Keyword.URL: hxxp://search.yahoo.com/search?fr=ffds1&p=
FF SelectedSearchEngine: SecureSearch
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 - C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.12.732 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=1.0.3.732 - c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=1.0.0.0 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.732 - c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/RhapsodyPlayerEngine,version=1.1 - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\User\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\User\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Extension: Shopping Sidekick Plugin - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\Extensions\[email protected] [2013-01-28]
FF Extension: Lavasoft Search Plugin - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\Extensions\[email protected] [2013-05-22]
FF Extension: Microsoft .NET Framework Assistant - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010-07-30]
FF Extension: Ad-Aware Security Add-on - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\ifi5r5su.default\Extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c} [2013-05-22]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} [2009-03-20]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} [2009-03-24]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} [2009-06-18]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} [2009-09-03]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} [2009-09-17]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} [2009-11-23]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [2010-05-23]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2010-11-04]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [2011-02-15]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} [2011-07-04]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-01-28]
FF HKCU\...\Firefox\Extensions: [[email protected]] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-01-28]

Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\User\AppData\Local\Google\Chrome\Application\33.0.1750.146\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\User\AppData\Local\Google\Chrome\Application\33.0.1750.146\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\User\AppData\Local\Google\Chrome\Application\33.0.1750.146\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll No File
CHR Plugin: (AVG Internet Security) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\plugins/avgnpss.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll No File
CHR Plugin: (Java™ Platform SE 6 U31) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer™ HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.6.9) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
CHR Plugin: (Garmin Communicator Plug-In) - C:\Program Files\Garmin GPS Plugin\npGarmin.dll No File
CHR Plugin: (Google Update) - C:\Users\User\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (RealNetworks Rhapsody Player Engine) - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
CHR Plugin: (MetaStream 3 Plugin) - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll No File
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-05-20]
CHR Extension: (Google Search) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-05-20]
CHR Extension: (Plus-HD-7.5) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbiodiodggnlakggeeckkjccjhhjndnb [2014-03-04]
CHR Extension: (Love Smoke) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgibfhhccaknggplelmbaepoikkcnllb [2012-06-01]
CHR Extension: (Google Wallet) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-05]
CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-05-20]
CHR HKLM\...\Chrome\Extension: [oejkcgajlodefenbbjdnaiahmbnnoole] - C:\Program Files\adawaretb\chrome-newtab-search.crx [2012-05-20]
CHR HKCU\...\Chrome\Extension: [apjkpjchfbckhjhokinlgdbmibpbbjak] - C:\Users\User\AppData\Local\CRE\apjkpjchfbckhjhokinlgdbmibpbbjak.crx [2012-05-20]
CHR StartMenuInternet: Google Chrome - C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe

========================== Services (Whitelisted) =================

R2 Akamai; c:\program files\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-01] (Akamai Technologies, Inc.)
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3788816 2014-01-22] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.)
S3 Com4Qlb; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe [110592 2007-03-05] (Hewlett-Packard Development Company, L.P.)
R2 HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [65536 2007-09-19] (Hewlett-Packard)
R2 Kodak AiO Network Discovery Service; C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe [308592 2010-05-17] (Eastman Kodak Company)
R2 Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [1737728 2012-09-21] (Lavasoft Limited )
R2 RichVideo; C:\Program Files\CyberLink\Shared Files\RichVideo.exe [272024 2007-01-09] ()
R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
S2 vToolbarUpdater18.0.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\18.0.0\ToolbarUpdater.exe [X]

==================== Drivers (Whitelisted) ====================

R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [120600 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [210712 2013-11-25] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [149272 2013-11-25] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22808 2014-01-19] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [176952 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [222520 2013-10-31] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [102712 2013-10-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27448 2013-09-10] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [193848 2013-08-01] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [42784 2014-03-10] (AVG Technologies)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [13560 2013-07-05] (GFI Software)
S3 HdAudAddService; C:\Windows\System32\drivers\CHDART.sys [176640 2007-10-11] (Conexant Systems Inc.)
S3 htcusbnet; C:\Windows\System32\DRIVERS\htcusbnet.sys [133632 2012-01-30] (HTC Corporation)
R3 Lavasoft Kernexplorer; C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys [15232 2011-02-21] ()
R0 Lbd; C:\Windows\System32\DRIVERS\Lbd.sys [64512 2011-02-21] (Lavasoft AB)
U1 eabfiltr;
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 SymIM; system32\DRIVERS\SymIM.sys [X]
S3 SymIMMP; system32\DRIVERS\SymIM.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-03-13 18:57 - 2014-03-13 18:57 - 01145856 _____ (Farbar) C:\Users\User\Downloads\FRST (1).exe
2014-03-13 18:56 - 2014-03-13 18:56 - 00000652 _____ () C:\Users\User\Downloads\fixlist.txt
2014-03-13 18:56 - 2014-03-13 18:56 - 00000652 _____ () C:\Users\User\Downloads\fixlist (1).txt
2014-03-13 18:56 - 2014-03-13 18:56 - 00000652 _____ () C:\Users\User\Desktop\fixlist (1).txt
2014-03-11 23:11 - 2014-03-11 23:11 - 00011054 _____ () C:\Users\User\Desktop\AdwCleaner[S0].txt
2014-03-11 23:10 - 2014-03-11 23:10 - 00159549 _____ () C:\Users\User\Desktop\Shortcut.txt
2014-03-11 23:10 - 2014-03-11 23:10 - 00043016 _____ () C:\Users\User\Desktop\FRST.txt
2014-03-11 23:10 - 2014-03-11 23:10 - 00017916 _____ () C:\Users\User\Desktop\Addition.txt
2014-03-11 22:54 - 2014-03-11 22:54 - 00159549 _____ () C:\Users\User\Downloads\Shortcut.txt
2014-03-11 22:52 - 2014-03-11 22:54 - 00017916 _____ () C:\Users\User\Downloads\Addition.txt
2014-03-11 22:51 - 2014-03-13 18:58 - 00032144 _____ () C:\Users\User\Downloads\FRST.txt
2014-03-11 22:51 - 2014-03-13 18:58 - 00000000 ____D () C:\FRST
2014-03-11 22:50 - 2014-03-11 22:50 - 01145856 _____ (Farbar) C:\Users\User\Downloads\FRST.exe
2014-03-11 21:37 - 2014-03-11 21:37 - 00000906 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-11 21:35 - 2014-03-11 21:36 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-1.75.0.1300.exe
2014-03-11 21:24 - 2014-03-11 21:31 - 00000000 ____D () C:\Users\User\AppData\Local\adawarebp
2014-03-11 21:05 - 2014-03-11 21:12 - 00000000 ____D () C:\AdwCleaner
2014-03-11 21:04 - 2014-03-11 21:04 - 01949184 _____ () C:\Users\User\Downloads\AdwCleaner.exe
2014-03-11 21:02 - 2014-03-11 21:02 - 00012491 _____ () C:\Users\User\Desktop\JRT.txt
2014-03-11 20:57 - 2014-03-11 20:57 - 01037734 _____ (Thisisu) C:\Users\User\Downloads\JRT (1).exe
2014-03-11 20:56 - 2014-03-11 20:56 - 00000000 ____D () C:\Windows\ERUNT
2014-03-11 20:55 - 2014-03-11 20:56 - 01037734 _____ (Thisisu) C:\Users\User\Downloads\JRT.exe
2014-03-11 18:24 - 2014-03-11 18:24 - 00115046 _____ () C:\Users\User\Downloads\OTL.Txt
2014-03-11 18:10 - 2014-03-11 18:10 - 00602112 _____ (OldTimer Tools) C:\Users\User\Downloads\OTL.exe
2014-03-11 13:40 - 2014-03-13 18:53 - 00027422 _____ () C:\Windows\WindowsUpdate.log
2014-03-11 13:18 - 2014-03-11 13:19 - 00012594 _____ () C:\Users\User\Documents\cc_20140311_131854.reg
2014-03-11 13:13 - 2014-03-11 13:13 - 04763560 _____ (Piriform Ltd) C:\Users\User\Downloads\ccsetup411pro.exe
2014-03-10 19:33 - 2014-03-12 17:51 - 00000798 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-03-10 19:33 - 2014-03-10 19:33 - 00000000 ____D () C:\Users\User\AppData\Roaming\TuneUp Software
2014-03-10 19:33 - 2014-03-10 19:33 - 00000000 ____D () C:\Users\User\AppData\Roaming\AVG2014
2014-03-10 19:33 - 2014-03-10 19:32 - 00042784 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys
2014-03-10 19:29 - 2014-03-10 19:33 - 00000000 ____D () C:\ProgramData\AVG2014
2014-03-10 19:28 - 2014-03-10 19:35 - 00000000 ____D () C:\Users\User\AppData\Local\Avg2014
2014-03-10 19:28 - 2014-03-10 19:28 - 04462440 _____ (AVG Technologies) C:\Users\User\Downloads\avg_avct_stb_all_2014_4335_welcomecmp (1).exe
2014-03-10 19:28 - 2014-03-10 19:28 - 00000000 ____D () C:\Users\User\AppData\Local\MFAData
2014-03-10 19:27 - 2014-03-10 19:27 - 04462440 _____ (AVG Technologies) C:\Users\User\Downloads\avg_avct_stb_all_2014_4335_welcomecmp.exe
2014-03-10 19:10 - 2014-03-10 19:11 - 01727624 _____ () C:\Users\User\Downloads\Adaware_Installer (10).exe
2014-03-05 23:06 - 2013-12-18 22:10 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-03-05 23:06 - 2013-12-18 22:04 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-03-05 23:06 - 2013-12-18 22:03 - 00174504 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-03-05 23:05 - 2014-03-05 23:06 - 00005163 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log
2014-03-05 23:05 - 2013-12-18 22:04 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-03-05 17:38 - 2014-03-05 17:38 - 00016004 _____ () C:\Users\User\Documents\cc_20140305_163842.reg
2014-02-28 23:47 - 2014-02-28 23:47 - 00151569 _____ () C:\Users\User\Desktop\abef3481_8098703695_e96a1fe55d.jpeg
2014-02-28 17:00 - 2014-02-28 17:00 - 04765152 _____ (Piriform Ltd) C:\Users\User\Downloads\ccsetup411.exe
2014-02-28 16:47 - 2014-02-28 16:47 - 00000000 ____D () C:\Users\User\AppData\Local\Tuguu_SL

==================== One Month Modified Files and Folders =======

2014-03-13 18:59 - 2014-03-11 22:51 - 00032144 _____ () C:\Users\User\Downloads\FRST.txt
2014-03-13 18:58 - 2014-03-11 22:51 - 00000000 ____D () C:\FRST
2014-03-13 18:58 - 2011-04-22 12:51 - 00000000 ____D () C:\ProgramData\MFAData
2014-03-13 18:57 - 2014-03-13 18:57 - 01145856 _____ (Farbar) C:\Users\User\Downloads\FRST (1).exe
2014-03-13 18:57 - 2012-05-31 22:51 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cd3fa9da20e695.job
2014-03-13 18:57 - 2012-04-04 09:08 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-13 18:56 - 2014-03-13 18:56 - 00000652 _____ () C:\Users\User\Downloads\fixlist.txt
2014-03-13 18:56 - 2014-03-13 18:56 - 00000652 _____ () C:\Users\User\Downloads\fixlist (1).txt
2014-03-13 18:56 - 2014-03-13 18:56 - 00000652 _____ () C:\Users\User\Desktop\fixlist (1).txt
2014-03-13 18:54 - 2012-05-31 22:51 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cd3fa9daec4ce5.job
2014-03-13 18:54 - 2012-05-20 15:08 - 00000904 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2626124740-2734390021-4155123068-1001UA.job
2014-03-13 18:53 - 2014-03-11 13:40 - 00027422 _____ () C:\Windows\WindowsUpdate.log
2014-03-13 06:39 - 2006-11-02 07:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-13 06:39 - 2006-11-02 07:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-12 20:40 - 2012-05-20 15:08 - 00000852 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2626124740-2734390021-4155123068-1001Core.job
2014-03-12 17:51 - 2014-03-10 19:33 - 00000798 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-03-12 17:51 - 2011-04-05 09:15 - 00000000 __SHD () C:\Windows\system32\%APPDATA%
2014-03-12 17:50 - 2010-04-13 22:31 - 00000000 ___HD () C:\$AVG
2014-03-12 17:42 - 2006-11-02 05:33 - 00703388 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-11 23:26 - 2008-06-07 10:26 - 00000279 _____ () C:\Users\Public\Documents\hpqp.ini
2014-03-11 23:23 - 2010-07-22 16:47 - 00000000 ____D () C:\Program Files\Common Files\Akamai
2014-03-11 23:23 - 2009-03-04 02:03 - 00000000 ____D () C:\ProgramData\Kodak
2014-03-11 23:23 - 2009-02-05 02:06 - 00096891 _____ () C:\aaw7boot.log
2014-03-11 23:23 - 2006-11-02 08:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-11 23:22 - 2006-11-02 08:01 - 00032620 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-11 23:11 - 2014-03-11 23:11 - 00011054 _____ () C:\Users\User\Desktop\AdwCleaner[S0].txt
2014-03-11 23:10 - 2014-03-11 23:10 - 00159549 _____ () C:\Users\User\Desktop\Shortcut.txt
2014-03-11 23:10 - 2014-03-11 23:10 - 00043016 _____ () C:\Users\User\Desktop\FRST.txt
2014-03-11 23:10 - 2014-03-11 23:10 - 00017916 _____ () C:\Users\User\Desktop\Addition.txt
2014-03-11 22:54 - 2014-03-11 22:54 - 00159549 _____ () C:\Users\User\Downloads\Shortcut.txt
2014-03-11 22:54 - 2014-03-11 22:52 - 00017916 _____ () C:\Users\User\Downloads\Addition.txt
2014-03-11 22:50 - 2014-03-11 22:50 - 01145856 _____ (Farbar) C:\Users\User\Downloads\FRST.exe
2014-03-11 21:37 - 2014-03-11 21:37 - 00000906 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-11 21:37 - 2009-12-22 15:29 - 00000000 ____D () C:\Program Files\Malwarebytes' Anti-Malware
2014-03-11 21:36 - 2014-03-11 21:35 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-1.75.0.1300.exe
2014-03-11 21:31 - 2014-03-11 21:24 - 00000000 ____D () C:\Users\User\AppData\Local\adawarebp
2014-03-11 21:27 - 2013-01-28 21:44 - 00000000 ____D () C:\Users\User\AppData\Roaming\Skype
2014-03-11 21:12 - 2014-03-11 21:05 - 00000000 ____D () C:\AdwCleaner
2014-03-11 21:04 - 2014-03-11 21:04 - 01949184 _____ () C:\Users\User\Downloads\AdwCleaner.exe
2014-03-11 21:02 - 2014-03-11 21:02 - 00012491 _____ () C:\Users\User\Desktop\JRT.txt
2014-03-11 20:57 - 2014-03-11 20:57 - 01037734 _____ (Thisisu) C:\Users\User\Downloads\JRT (1).exe
2014-03-11 20:57 - 2012-04-04 09:08 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-03-11 20:57 - 2011-05-17 08:39 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-03-11 20:56 - 2014-03-11 20:56 - 00000000 ____D () C:\Windows\ERUNT
2014-03-11 20:56 - 2014-03-11 20:55 - 01037734 _____ (Thisisu) C:\Users\User\Downloads\JRT.exe
2014-03-11 18:24 - 2014-03-11 18:24 - 00115046 _____ () C:\Users\User\Downloads\OTL.Txt
2014-03-11 18:10 - 2014-03-11 18:10 - 00602112 _____ (OldTimer Tools) C:\Users\User\Downloads\OTL.exe
2014-03-11 13:19 - 2014-03-11 13:18 - 00012594 _____ () C:\Users\User\Documents\cc_20140311_131854.reg
2014-03-11 13:16 - 2012-02-26 03:39 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-03-11 13:14 - 2011-04-27 17:19 - 00000804 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-03-11 13:14 - 2011-04-27 17:19 - 00000000 ____D () C:\Program Files\CCleaner
2014-03-11 13:13 - 2014-03-11 13:13 - 04763560 _____ (Piriform Ltd) C:\Users\User\Downloads\ccsetup411pro.exe
2014-03-11 12:14 - 2011-04-26 12:11 - 00000064 _____ () C:\Windows\system32\rp_stats.dat
2014-03-11 12:14 - 2011-04-26 12:11 - 00000044 _____ () C:\Windows\system32\rp_rules.dat
2014-03-10 19:35 - 2014-03-10 19:28 - 00000000 ____D () C:\Users\User\AppData\Local\Avg2014
2014-03-10 19:33 - 2014-03-10 19:33 - 00000000 ____D () C:\Users\User\AppData\Roaming\TuneUp Software
2014-03-10 19:33 - 2014-03-10 19:33 - 00000000 ____D () C:\Users\User\AppData\Roaming\AVG2014
2014-03-10 19:33 - 2014-03-10 19:29 - 00000000 ____D () C:\ProgramData\AVG2014
2014-03-10 19:32 - 2014-03-10 19:33 - 00042784 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys
2014-03-10 19:29 - 2008-09-01 14:09 - 00000000 ____D () C:\Program Files\AVG
2014-03-10 19:28 - 2014-03-10 19:28 - 04462440 _____ (AVG Technologies) C:\Users\User\Downloads\avg_avct_stb_all_2014_4335_welcomecmp (1).exe
2014-03-10 19:28 - 2014-03-10 19:28 - 00000000 ____D () C:\Users\User\AppData\Local\MFAData
2014-03-10 19:27 - 2014-03-10 19:27 - 04462440 _____ (AVG Technologies) C:\Users\User\Downloads\avg_avct_stb_all_2014_4335_welcomecmp.exe
2014-03-10 19:11 - 2014-03-10 19:10 - 01727624 _____ () C:\Users\User\Downloads\Adaware_Installer (10).exe
2014-03-05 23:07 - 2008-02-22 12:15 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-03-05 23:06 - 2014-03-05 23:05 - 00005163 _____ () C:\Windows\system32\jupdate-1.7.0_51-b13.log
2014-03-05 23:06 - 2008-02-22 12:15 - 00000000 ____D () C:\Program Files\Java
2014-03-05 17:38 - 2014-03-05 17:38 - 00016004 _____ () C:\Users\User\Documents\cc_20140305_163842.reg
2014-02-28 23:47 - 2014-02-28 23:47 - 00151569 _____ () C:\Users\User\Desktop\abef3481_8098703695_e96a1fe55d.jpeg
2014-02-28 17:00 - 2014-02-28 17:00 - 04765152 _____ (Piriform Ltd) C:\Users\User\Downloads\ccsetup411.exe
2014-02-28 16:47 - 2014-02-28 16:47 - 00000000 ____D () C:\Users\User\AppData\Local\Tuguu_SL
2014-02-25 20:47 - 2008-10-06 03:40 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-02-16 19:41 - 2010-12-05 14:53 - 00000000 ____D () C:\ProgramData\Screentime
2014-02-16 19:40 - 2009-03-20 01:43 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-16 19:38 - 2009-11-02 16:09 - 00000000 ____D () C:\Program Files\iTunes
2014-02-16 19:36 - 2012-04-03 20:44 - 00000000 ____D () C:\ProgramData\Garmin
2014-02-16 19:36 - 2012-04-03 20:41 - 00000000 ____D () C:\Users\User\AppData\Roaming\Garmin

Files to move or delete:
====================
C:\Users\User\CTX.DAT


Some content of TEMP:
====================
C:\Users\User\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-11 23:30

==================== End Of Log ============================


After doing everything that you instructed me to do the other day, it's still there :(
Can we just kick it? :P
  • 0

#6
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 10,962 posts
The fixlist.txt file on Post #4 should be saved in the same location FRST is saved. Then rather than a scan, click on the Fix button. FRST will recognize the file and proceed with the fix. Post the Fixlog.txt that will be produced.

Then, try Combofix.

Please download ComboFix from Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Please, never rename Combofix unless instructed.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    -----------------------------------------------------------

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link or this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      -----------------------------------------------------------

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    -----------------------------------------------------------

  • Double click on combofix.exe & follow the prompts.
  • Install the Recovery Console if prompted.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" .
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.

Please do not install any new programs or update anything (always allow your antivirus/antispyware to update) unless told to do so while we are fixing your problem. If combofix alerts to a new version and offers to update, please let it. It is essential we always use the latest version.
  • 0

#7
Huntersrain

Huntersrain

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Ive tried saving FRST and the fixlist.txt in the same place twice, and it doesn't give me a file for FRST, just the app itself, in my download file. I have even moved both to my desktop, and it still says there is no fixlist.txt, but both are there.
  • 0

#8
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 10,962 posts
Right click on the Orb (Start button) and select Explore. Browse to the following location and click on FRST:

C:\Users\User\Downloads

Click on the Fix button. Post the contents of the Fixlog.txt that will be produced in that same location.
  • 0

#9
Huntersrain

Huntersrain

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Fixlog

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-03-2014 01
Ran by User at 2014-03-14 18:52:10 Run:2
Running from C:\Users\User\Downloads
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
HKLM\...\Run: [hpqSRMon] - [X]
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\...\InprocServer32: [Default-pngfilt] <==== ATTENTION!
SearchScopes: HKLM - {8B0A8A63-D27E-476E-BCF7-9614A7362469} URL = http://www.ask.com/w...}&l=dis&o=uscqd
SearchScopes: HKCU - {8B0A8A63-D27E-476E-BCF7-9614A7362469} URL = http://www.ask.com/w...}&l=dis&o=uscqd
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
Toolbar: HKLM - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKCU - No Name - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
C:\Users\User\AppData\Local\Temp\Quarantine.exe
C:\Users\User\CTX.DAT
End

*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\hpqSRMon => Value not found.
HKU\S-1-5-21-2626124740-2734390021-4155123068-1001\Software\Classes\CLSID\{A3CCEDF7-2DE2-11D0-86F4-00A0C913F750} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8B0A8A63-D27E-476E-BCF7-9614A7362469} => Key not found.
HKCR\Wow6432Node\CLSID\{8B0A8A63-D27E-476E-BCF7-9614A7362469} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8B0A8A63-D27E-476E-BCF7-9614A7362469} => Key not found.
HKCR\Wow6432Node\CLSID\{8B0A8A63-D27E-476E-BCF7-9614A7362469} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB} => Key not found.
HKCR\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB} => Key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Value not found.
HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} => Value not found.
HKCR\CLSID\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} => Key not found.
"C:\Users\User\AppData\Local\Temp\Quarantine.exe" => File/Directory not found.
"C:\Users\User\CTX.DAT" => File/Directory not found.

==== End of Fixlog ====
  • 0

#10
Huntersrain

Huntersrain

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
ComboFix 14-03-13.01 - User 03/14/2014 19:04:23.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3061.1474 [GMT -5:00]
Running from: c:\users\User\Downloads\ComboFix.exe
AV: AVG AntiVirus 2014 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
SP: AVG AntiVirus 2014 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\DFR1BA5.tmp
c:\users\User\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fbiodiodggnlakggeeckkjccjhhjndnb_0.localstorage-journal
c:\users\User\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fbiodiodggnlakggeeckkjccjhhjndnb_0.localstorage
c:\users\User\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\windows\system32\KBL.LOG
.
.
((((((((((((((((((((((((( Files Created from 2014-02-15 to 2014-03-15 )))))))))))))))))))))))))))))))
.
.
2014-03-15 00:20 . 2014-03-15 00:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-03-12 03:51 . 2014-03-14 23:52 -------- d-----w- C:\FRST
2014-03-12 02:24 . 2014-03-12 02:31 -------- d-----w- c:\users\User\AppData\Local\adawarebp
2014-03-12 02:05 . 2014-03-12 02:12 -------- d-----w- C:\AdwCleaner
2014-03-12 01:56 . 2014-03-12 01:56 -------- d-----w- c:\windows\ERUNT
2014-03-11 00:33 . 2014-03-11 00:33 -------- d-----w- c:\users\User\AppData\Roaming\AVG2014
2014-03-11 00:33 . 2014-03-11 00:33 -------- d-----w- c:\users\User\AppData\Roaming\TuneUp Software
2014-03-11 00:33 . 2014-03-11 00:32 42784 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2014-03-11 00:29 . 2014-03-11 00:33 -------- d-----w- c:\programdata\AVG2014
2014-03-11 00:29 . 2014-03-11 02:11 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\Avg2014
2014-03-11 00:28 . 2014-03-11 00:35 -------- d-----w- c:\users\User\AppData\Local\Avg2014
2014-03-11 00:28 . 2014-03-11 00:28 -------- d-----w- c:\users\User\AppData\Local\MFAData
2014-03-06 04:06 . 2013-12-19 03:10 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2014-02-28 22:02 . 2014-02-28 22:02 -------- d-----w- c:\program files\Uninstaller
2014-02-28 21:47 . 2014-02-28 21:47 -------- d-----w- c:\users\User\AppData\Local\Tuguu_SL
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-12 01:57 . 2012-04-04 14:08 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-03-12 01:57 . 2011-05-17 13:39 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-01-20 02:46 . 2014-01-20 02:46 22808 ----a-w- c:\windows\system32\drivers\avgidsshimx.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn1\yt.dll" [2012-01-12 1517368]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"HPADVISOR"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-10-02 1783136]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-24 455968]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe" [2012-05-25 6595928]
"Akamai NetSession Interface"="c:\users\User\AppData\Local\Akamai\netsession_win.exe" [2013-06-05 4489472]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-03-01 18643560]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner.exe" [2014-02-20 4505368]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-08-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-08-28 154136]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-08-28 137752]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-06-30 159744]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-12-20 468264]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-12-06 202032]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-09-13 222504]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-10-03 480560]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-27 30040]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-10-08 47904]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2012-09-21 1191768]
"Conime"="c:\windows\system32\conime.exe" [2009-04-11 69120]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-31 202256]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-07-22 500208]
"EKIJ5000StatusMonitor"="c:\windows\system32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2010-05-07 1638400]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-02-20 152392]
"Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2013-05-15 554408]
"VMM Mode Selection"="c:\program files\HTC\ModeSelection\VMMModeSelection.exe" [2011-02-14 43520]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"AVG_UI"="c:\program files\AVG\AVG2014\avgui.exe" [2014-01-22 4962320]
.
c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office Groove.lnk - c:\program files\Microsoft Office\Office12\GROOVE.EXE -background [2011-5-31 337264]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2009-2-26 97680]
Verizon Wireless Software Utility Application for Android – Samsung.lnk - c:\users\User\AppData\Roaming\Verizon\UA_ar\UA.exe [2013-8-8 877936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
Akamai REG_MULTI_SZ Akamai
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-24 00:34 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-03-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 01:57]
.
2014-03-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cd3fa9da20e695.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-01 03:18]
.
2014-03-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA1cd3fa9daec4ce5.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-01 03:18]
.
2014-03-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2626124740-2734390021-4155123068-1001Core.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-20 20:08]
.
2014-03-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2626124740-2734390021-4155123068-1001UA.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-20 20:08]
.
2010-12-15 c:\windows\Tasks\User_Feed_Synchronization-{48099F80-F5FE-45BE-BB2B-59D8AEF45572}.job
- c:\windows\system32\msfeedssync.exe [2012-03-07 07:10]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = <local>
Trusted Zone: phoenix.edu
Trusted Zone: toolwire.com
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2014-03-14 19:27
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_8fa3539.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\AVG\AVG2014\avgrsx.exe
c:\program files\AVG\AVG2014\avgcsrvx.exe
c:\program files\Lavasoft\Ad-Aware\AAWService.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\AVG\AVG2014\avgidsagent.exe
c:\program files\AVG\AVG2014\avgwdsvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Kodak\AiO\Center\ekdiscovery.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\AVG\AVG2014\avgnsx.exe
c:\program files\Spybot - Search & Destroy\SDWinSec.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\AVG\AVG2014\avgcsrvx.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2014-03-14 19:32:37 - machine was rebooted
ComboFix-quarantined-files.txt 2014-03-15 00:32
.
Pre-Run: 92,030,910,464 bytes free
Post-Run: 91,955,154,944 bytes free
.
- - End Of File - - F119A20A755BF11ADCC52604D4AADB5B
1A1A06F62E891045814007163C1C76C3
  • 0

Advertisements


#11
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 10,962 posts
How is the computer doing?
  • 0

#12
Huntersrain

Huntersrain

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
No more pop-ups! Thank you so much!
  • 0

#13
Huntersrain

Huntersrain

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
No more pop-ups! Thank you so much!
  • 0

#14
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 10,962 posts
We need to remove the tools we've used during cleaning your machine

  • Download Delfix from here
  • Ensure Remove disinfection tools is ticked
    Also tick:
    • Create registry backup
    • Purge system restore
    Posted Image
  • Click Run
The program will run for a few moments and then notepad will open with a log. Please paste the log in your next reply
  • 0

#15
Huntersrain

Huntersrain

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
# DelFix v10.6 - Logfile created 14/03/2014 at 20:51:02
# Updated 11/11/2013 by Xplode
# Username : User - MINWINPC
# Operating System : Windows Vista ™ Home Premium Service Pack 2 (32 bits)

~ Removing disinfection tools ...

Deleted : C:\Qoobox
Deleted : C:\Combofix
Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\ComboFix.txt
Deleted : C:\Users\User\Desktop\Addition.txt
Deleted : C:\Users\User\Desktop\AdwCleaner[S0].txt
Deleted : C:\Users\User\Desktop\FRST.exe
Deleted : C:\Users\User\Desktop\FRST.txt
Deleted : C:\Users\User\Desktop\JRT.txt
Deleted : C:\Users\User\Downloads\Addition.txt
Deleted : C:\Users\User\Downloads\AdwCleaner.exe
Deleted : C:\Users\User\Downloads\ComboFix.exe
Deleted : C:\Users\User\Downloads\Fixlog.txt
Deleted : C:\Users\User\Downloads\FRST (1).exe
Deleted : C:\Users\User\Downloads\FRST.txt
Deleted : C:\Users\User\Downloads\JRT (1).exe
Deleted : C:\Users\User\Downloads\JRT.exe
Deleted : C:\Users\User\Downloads\OTL.Txt
Deleted : C:\Users\User\Downloads\OTL.exe
Deleted : C:\Windows\grep.exe
Deleted : C:\Windows\PEV.exe
Deleted : C:\Windows\NIRCMD.exe
Deleted : C:\Windows\MBR.exe
Deleted : C:\Windows\SED.exe
Deleted : C:\Windows\SWREG.exe
Deleted : C:\Windows\SWSC.exe
Deleted : C:\Windows\SWXCACLS.exe
Deleted : C:\Windows\Zip.exe
Deleted : HKLM\SOFTWARE\OldTimer Tools
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\Swearware
Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #1206 [Scheduled Checkpoint | 02/18/2014 22:53:06]
Deleted : RP #1207 [Scheduled Checkpoint | 02/19/2014 16:30:22]
Deleted : RP #1208 [Scheduled Checkpoint | 02/21/2014 03:13:44]
Deleted : RP #1209 [Scheduled Checkpoint | 02/23/2014 02:20:17]
Deleted : RP #1210 [Scheduled Checkpoint | 02/24/2014 06:44:08]
Deleted : RP #1211 [Scheduled Checkpoint | 03/05/2014 23:11:17]
Deleted : RP #1212 [Installed Java 7 Update 51 | 03/06/2014 04:04:27]
Deleted : RP #1213 [Scheduled Checkpoint | 03/06/2014 22:55:38]
Deleted : RP #1214 [Scheduled Checkpoint | 03/07/2014 23:53:05]
Deleted : RP #1215 [Scheduled Checkpoint | 03/09/2014 01:25:16]
Deleted : RP #1216 [Scheduled Checkpoint | 03/09/2014 22:48:30]
Deleted : RP #1217 [Scheduled Checkpoint | 03/10/2014 22:10:05]
Deleted : RP #1218 [Scheduled Checkpoint | 03/11/2014 14:06:26]

New restore point created !

########## - EOF - ##########
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP