Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Help! Removed Virus and now System is a Mess - Windows 7 Home Prem


  • Please log in to reply

#1
infected99.9

infected99.9

    Member

  • Member
  • PipPip
  • 19 posts

I have gone through the steps advised and have run OTS - should I post the log here or upload???

 

I was running Macafee subscription however a 'ransom' virus (part of the Reveton family) infected my laptop at same time as a Windows Update downloaded just over a month ago.

 

I  removed the 'ransom' virus using Kaspersky Rescue Disc. Uninstalled Macafee, installed Norton 360, cleaned my machine, unistalled Norton and am now running Malwarebytes and Windows Defender.

 

Since removing the virus everything has been a nightmare.

 

I have a Sony Vaio VCPCCB2M0E running Windows 7 Home Premium 64 Bit.

 

The main issues are;

  • Cannot start Security Centre (Error 1075).
  • Services "Extended" view is blank/obscured by a light blue box.
  • My system cannot recognise or display my processor or RAM etc... in Windows Experience or anywhere.
  • I THINK my Windows Firewall is turned on however I never ever receive any pop up notifications and when I go to the log file I receive message that cannot be found as does not exist!
  • I have tried to run almost all Microsoft "Fix It" sections and each time I get an error message that it could not run.
  • My IRST (Intel Rapid Storage Technology) was not running and I have unistalled it in error and cannot re-install.
  • At least once a day my Graphics crash.
  • At least once every few days I get 'Blue Screen' and the computer recovers.
  • The entire system runs and sounds like it is straining at the seems... I cannot even watch a 2gb movie file without constant stopping, pixelation etc... and crashing.
  • I do not think that my USB 3 port is operating any different to any other USB port.

 

I have run;

  • Kaspersky Rescue Disc
  • Norton 360
  • Malwarebytes
  • TDSKiller
  • GMER
  • OTS

 

I have also used replaced the wscsvc reg entry.

 

My TDSSKiller Scan turned up SPTD.sys (locked) so I have just run gmer.exe and can send someone the log if they would have a look.

 

Any help would be greatly appreciated... I am thinking to do a repair install however I have no idea what this means or how to do it... I do not even have a Windows disc!


Edited by infected99.9, 27 April 2014 - 10:34 AM.

  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP
Going to give you a lot to do.  Best to post the logs as you get them.  Report any problems or error messages.
 
Download : ADWCleaner to your desktop.  Make sure you get the correct Download button.  Sometimes the ads on BleepingComputer will mimic the real Download button which should say: Download Now @BleepingComputer
 
NOTE: If using Internet Explorer and you get an alert that stops the program downloading, click on the warning and allow the download to complete.
 
Close  all programs, pause your anti-virus and run AdwCleaner (Vista or Win 7 => right click and Run As Administrator).
 
scan-results.jpg
 
Click on Scan  and follow the prompts. Let it run unhindered. When done, click on the Clean button, and follow the prompts. Allow the system to reboot. You will then be presented with the report. Copy & Paste this report on your next reply.
 
The report will be saved in the C:\AdwCleaner folder.
 
 
 
Junkware-Removal-Tool
 
Please download Junkware Removal Tool to your desktop.  Make sure you get the correct Download button.  Sometimes the ads on BleepingComputer will mimic the real Download button which should say: Download Now @Author's site
  • Pause your anti-virus.  Close all browsers.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
  •  
     
     
    Please download Farbar Recovery Scan Tool and save it to your Desktop. 
     
    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version. 
     
    •  
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer. 
  • Press Scan button. 
  • It will produce a log called FRST.txt in the same directory the tool is run from.  
  • Please copy and paste log back here. 
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply. 
  •  
     
     
    Download OTL from
    and Save it to your desktop.
     
    Copy the text in the code box:
     
    DRIVES
    nnetsvcs
    %SYSTEMDRIVE%\*.exe
    %systemroot%\assembly\GAC_32\*.ini
    %systemroot%\assembly\GAC_64\*.ini
    msconfig
    safebootminimal
    safebootnetwork
    activex
    drivers32
    %SYSTEMDRIVE%\*.exe
    %ALLUSERSPROFILE%\Application Data\*.exe
    %APPDATA%\*.
    /md5start
    rsvpsp.dll
    pnrpnsp.dll 
    nwprovau.dll
    nlaapi.dll
    napinsp.dll
    mswsock.dll
    winrnr.dll
    wshelper.dll
    services.exe
    atapi.sys
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    csrss.exe
    PrintIsolationHost.exe
    consrv.dll
    user32.dll
    /md5stop
    C:\Windows\assembly\tmp\U\*.* /s
    %systemroot%\*. /mp /s
    hklm\software\clients\startmenuinternet|command /rs
    hklm\software\clients\startmenuinternet|command /64 /rs
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %ProgramFiles%\WINDOWS NT\*.* /s
    %systemroot%\system32\drivers\*.sys /lockedfiles
    CREATERESTOREPOINT
    
     
    Run OTL (Vista or Win 7 => right click and Run As Administrator)
     
    Paste (Ctrl + v) the copied text in the box where it says Custom Scan/Fixes
     
    Select the All option in the Extra Registry group then Run Scan.
     
    You should get two logs.  Please copy and paste both of them.
     
     

     
    Right click on (My) Computer and select Manage (Continue) Then click on the arrow in front of Event Viewer. Next Click on the arrow in front of Windows Logs Right click on System and Clear Log, Clear. Repeat for Application.
     
     

    Download ESET's Service Repair http://kb.eset.com/l...vicesRepair.exe and Save it then right click on it and Run As Admin. 
     
    If it doesn't do it for you:
    Reboot.
     
     
    Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator.  Then type (with an Enter after each line).
    sfc  /scannow
     
    (This will check your critical system files. Does this finish without complaint?  IF it says it couldn't fix everything then:
     
    Copy the next two lines:
     
    findstr  /c:"[SR]"  \windows\logs\cbs\cbs.log  >  \windows\logs\cbs\junk.txt 
    notepad \windows\logs\cbs\junk.txt 
     
    Start, All Programs, Accessories, right click on Command Prompt and Run as Administrator, Continue.  Right click and Paste or Edit then Paste and the copied line should appear.
    Hit Enter. Copy and paste the text from notepad or if it is too big, just attach the file.)
     
     
    1. Please download the Event Viewer Tool by Vino Rosso
    and save it to your Desktop:
    2. Right-click VEW.exe and Run AS Administrator
    3. Under 'Select log to query', select:
     
    * System
    4. Under 'Select type to list', select:
    * Error
    * Warning
     
     
    Then use the 'Number of events' as follows:
     
     
    1. Click the radio button for 'Number of events'
    Type 20 in the 1 to 20 box
    Then click the Run button.
    Notepad will open with the output log.
     
     
    Please post the Output log in your next reply then repeat but select Application.
     
     

    Get Process Explorer
     
    Save it to your desktop then run it (Vista or Win7 - right click and Run As Administrator).  
     
    View, Select Column, check Verified Signer, OK
    Options, Verify Image Signatures
     
     
    Click twice on the CPU column header  to sort things by CPU usage with the big hitters at the top.  
     
    Wait a full minute then:
     
    File, Save As, Save.  Open the file Procexp.txt on your desktop and copy and paste the text to a reply.
     
     
     

    • 0

    #3
    infected99.9

    infected99.9

      Member

    • Topic Starter
    • Member
    • PipPip
    • 19 posts

    Ok, thank you. Will work through all if this and post logs in next reply


    • 0

    #4
    infected99.9

    infected99.9

      Member

    • Topic Starter
    • Member
    • PipPip
    • 19 posts
    After running AdwCleaner the machine was taking an age to shut down for the reboot. I then received a blue screen with the following at the top
     
    Driver_power_state_failure
     
    The machine then restarted in recovery and I started windows normally
     
    I will continue with the rest so please let me know ASAP if I should stop and re-run AdwCleaner.
     
    2 logs were generated, both posted below...
     
     
    Log 1: AdwCleaner[RO].txt
     
    # AdwCleaner v3.204 - Report created 27/04/2014 at 22:20:39
    # Updated 26/04/2014 by Xplode
    # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
    # Username : User - *****-VAIO
    # Running from : C:\Users\User\Desktop\AdwCleaner.exe
    # Option : Scan
     
    ***** [ Services ] *****
     
     
    ***** [ Files / Folders ] *****
     
    File Found : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\searchplugins\safesearch.xml
    Folder Found : C:\Program Files (x86)\DAEMON Tools Toolbar
    Folder Found : C:\Users\User\.android
     
    ***** [ Shortcuts ] *****
     
     
    ***** [ Registry ] *****
     
    Key Found : HKCU\Software\AppDataLow\Software\SmartBar
    Key Found : HKCU\Software\Conduit
    Key Found : HKCU\Software\dt soft\daemon tools toolbar
    Key Found : HKCU\Software\IGearSettings
    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17}
    Key Found : [x64] HKCU\Software\Conduit
    Key Found : [x64] HKCU\Software\dt soft\daemon tools toolbar
    Key Found : [x64] HKCU\Software\IGearSettings
    Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{1663C10B-0D55-438D-8496-19A3DBAEC0E4}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
    Key Found : HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj
    Key Found : HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj.1
    Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
    Key Found : HKLM\SOFTWARE\Classes\TypeLib\{3E288F79-03E4-4983-A48E-0D879B51FF19}
    Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
    Key Found : HKLM\Software\Conduit
    Key Found : HKLM\Software\DeviceVM
    Key Found : HKLM\Software\dt soft\daemon tools toolbar
    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
    Key Found : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\daemon tools toolbar
    Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
    Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
    Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
    Key Found : [x64] HKLM\SOFTWARE\DeviceVM
    Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
    Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
    Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]
    Value Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]
     
    ***** [ Browsers ] *****
     
    -\\ Internet Explorer v11.0.9600.17041
     
     
    -\\ Mozilla Firefox v28.0 (en-US)
     
    [ File : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\prefs.js ]
     
    Line Found : user_pref("CT3225826_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1396745730922,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
    Line Found : user_pref("plugin.state.npconduitfirefoxplugin", 2);
    Line Found : user_pref("smartbar.machineId", "9AJHJZVSIUMF+HEVTB1ZBE4VUCY2PGQGGQMU0L2CQS2RNXYWFAO735GJNIBQPVB12SQ8TCIG2ROGU+VHWWZIJG");
     
    -\\ Google Chrome v34.0.1847.131
     
    [ File : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\preferences ]
     
     
    *************************
     
    AdwCleaner[R0].txt - [4127 octets] - [27/04/2014 22:20:39]
     
    ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [4187 octets] ##########
     
     
     
     
    Log 2: AdwCleaner[S0].txt:
     
    # AdwCleaner v3.204 - Report created 27/04/2014 at 22:29:08
    # Updated 26/04/2014 by Xplode
    # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
    # Username : User - *****-VAIO
    # Running from : C:\Users\User\Desktop\AdwCleaner.exe
    # Option : Clean
     
    ***** [ Services ] *****
     
     
    ***** [ Files / Folders ] *****
     
    Folder Deleted : C:\Program Files (x86)\DAEMON Tools Toolbar
    Folder Deleted : C:\Users\User\.android
    File Deleted : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\searchplugins\safesearch.xml
     
    ***** [ Shortcuts ] *****
     
     
    ***** [ Registry ] *****
     
    Key Deleted : HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj
    Key Deleted : HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj.1
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1663C10B-0D55-438D-8496-19A3DBAEC0E4}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{3E288F79-03E4-4983-A48E-0D879B51FF19}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{32099AAC-C132-4136-9E9A-4E364A424E17}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{32099AAC-C132-4136-9E9A-4E364A424E17}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8}
    Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
    Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]
    Key Deleted : HKCU\Software\Conduit
    Key Deleted : HKCU\Software\dt soft\daemon tools toolbar
    Key Deleted : HKCU\Software\IGearSettings
    Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
    Key Deleted : HKLM\Software\Conduit
    Key Deleted : HKLM\Software\DeviceVM
    Key Deleted : HKLM\Software\dt soft\daemon tools toolbar
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\daemon tools toolbar
    Key Deleted : [x64] HKLM\SOFTWARE\DeviceVM
     
    ***** [ Browsers ] *****
     
    -\\ Internet Explorer v11.0.9600.17041
     
     
    -\\ Mozilla Firefox v28.0 (en-US)
     
    [ File : C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\prefs.js ]
     
    Line Deleted : user_pref("CT3225826_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1396745730922,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
    Line Deleted : user_pref("plugin.state.npconduitfirefoxplugin", 2);
    Line Deleted : user_pref("smartbar.machineId", "9AJHJZVSIUMF+HEVTB1ZBE4VUCY2PGQGGQMU0L2CQS2RNXYWFAO735GJNIBQPVB12SQ8TCIG2ROGU+VHWWZIJG");
     
    -\\ Google Chrome v34.0.1847.131
     
    [ File : C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\preferences ]
     
     
    *************************
     
    AdwCleaner[R0].txt - [4303 octets] - [27/04/2014 22:20:39]
    AdwCleaner[S0].txt - [4019 octets] - [27/04/2014 22:29:08]
     
    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4079 octets] ##########

    • 0

    #5
    RKinner

    RKinner

      Malware Expert

    • Expert
    • 24,624 posts
    • MVP

    Looks like AdwCleaner managed to get rid of the junk before the crash.  Just go on with the scans.


    • 0

    #6
    infected99.9

    infected99.9

      Member

    • Topic Starter
    • Member
    • PipPip
    • 19 posts
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Thisisu
    Version: 6.1.4 (04.06.2014:1)
    OS: Windows 7 Home Premium x64
    Ran by User on 27/04/2014 at 22:59:19.17
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     
    ~~~ Services
     
    ~~~ Registry Values
     
    ~~~ Registry Keys
     
    ~~~ Files
     
    Successfully deleted: [File] C:\Windows\syswow64\shoD846.tmp
     
     
    ~~~ Folders
     
    ~~~ FireFox
     
    Emptied folder: C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\p9m2w77c.default\minidumps [163 files]
     
     
    ~~~ Event Viewer Logs were cleared
     
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on 27/04/2014 at 23:04:22.44
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    • 0

    #7
    infected99.9

    infected99.9

      Member

    • Topic Starter
    • Member
    • PipPip
    • 19 posts
    Have ran FRST. In the additon log I have changed the path of a few 'scheduled items' to REMOVED\REMOVED\REMOVED\ as all point to the same folder however the path has personal details (family members name etc...). if required I will happily email the full log direct to you rather than post on here? I would not have thought there was any scheduled task waiting to take place for any file in the folder where the path points to, neither are there any visable (or hidden) .exe file(s) in the folder.
     
     
    FRST Log:
     
     
    Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 27-04-2014
    Ran by User (administrator) on *****-VAIO on 27-04-2014 23:08:23
    Running from C:\Users\User\Desktop
    Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
    Internet Explorer Version 11
    Boot Mode: Normal
     
    The only official download link for FRST:
    Download link from any site other than Bleeping Computer is unpermitted or outdated.
     
    ==================== Processes (Whitelisted) =================
     
    (Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
    (AMD) C:\Windows\system32\atiesrxx.exe
    (AMD) C:\Windows\system32\atieclxx.exe
    (Microsoft Corporation) C:\Windows\system32\WLANExt.exe
    (Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
    (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
    (SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
    (Nero AG) C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe
    (McAfee, Inc.) C:\Windows\system32\mfevtps.exe
    () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
    (Sony Corporation) c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
    (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
    (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
    (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
    (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
    (Akamai Technologies, Inc.) C:\Users\User\AppData\Local\Akamai\netsession_win.exe
    (Akamai Technologies, Inc.) C:\Users\User\AppData\Local\Akamai\netsession_win.exe
    (Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
    (Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
    (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESGfxMgr.exe
    (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
    (cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe
    (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
    (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe
    () C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
    (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
    (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    (Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe
    (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
    (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
    (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
    (Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe
    (Adobe Systems Incorporated) c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
    () C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
    (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
    (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
    (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
    (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
    (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe
    (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
    (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
    (Microsoft Corporation) C:\Windows\System32\vds.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
    (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
     
     
    ==================== Registry (Whitelisted) ==================
     
    HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277992 2011-11-15] (Realtek Semiconductor)
    HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [790688 2011-04-29] (Atheros Commnucations)
    HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [657568 2011-04-29] (Atheros Commnucations)
    HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2531624 2011-03-04] (Synaptics Incorporated)
    HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2277992 2011-11-15] (Realtek Semiconductor)
    HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472992 2013-03-21] (Adobe Systems Incorporated)
    HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
    HKLM-x32\...\Run: [StartCCC] => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-01-27] (Advanced Micro Devices, Inc.)
    HKLM-x32\...\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [2757312 2011-02-15] (Sony Corporation)
    HKLM-x32\...\Run: [PMBVolumeWatcher] => c:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation)
    HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
    HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [] => [X]
    HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840568 2013-12-18] (Adobe Systems Inc.)
    HKLM-x32\...\Run: [BDRegion] => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe [181208 2013-04-26] (cyberlink)
    HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
    HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
    HKLM-x32\...\Run: [WD Drive Unlocker] => C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe [1694072 2013-10-15] (Western Digital Technologies, Inc.)
    HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41336 2013-12-18] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
    HKLM-x32\...\Run: [HTC Sync Loader] => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [655360 2012-12-12] ()
    HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe [1523360 2011-01-12] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5545328 2014-02-28] (Western Digital Technologies, Inc.)
    HKU\S-1-5-21-3830866668-548323272-1850177600-1000\...\Run: [BitTorrent] => C:\Users\User\AppData\Roaming\BitTorrent\BitTorrent.exe [1236832 2014-04-26] (BitTorrent Inc.)
    HKU\S-1-5-21-3830866668-548323272-1850177600-1000\...\Run: [Google Update] => C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-11-15] (Google Inc.)
    HKU\S-1-5-21-3830866668-548323272-1850177600-1000\...\Run: [Akamai NetSession Interface] => C:\Users\User\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
    HKU\S-1-5-21-3830866668-548323272-1850177600-1000\...\MountPoints2: {9e4cc323-f20e-11e1-8496-ccaf78b751f4} - E:\LaunchU3.exe -a
    HKU\S-1-5-21-3830866668-548323272-1850177600-1000\...\MountPoints2: {c82aa577-3eb6-11e2-a71f-ccaf78b751f4} - E:\unlock.exe autoplay=true
    HKU\S-1-5-21-3830866668-548323272-1850177600-1000\...\MountPoints2: {c82aa587-3eb6-11e2-a71f-ccaf78b751f4} - E:\unlock.exe autoplay=true
     
    ==================== Internet (Whitelisted) ====================
     
    ProxyServer: cslibproxy:80
    HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.eu/vaioportal
    SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKCU - {08174720-A6AA-407F-A7CB-8CCCA7BDEDB2} URL = http://rover.ebay.co...e={searchTerms}
    SearchScopes: HKCU - {20555815-E80E-4BF7-99AB-CE6D9CC9022F} URL = https://www.google.c...q={searchTerms}
    BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
    BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20121218151054.dll No File
    BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
    BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    BHO-x32: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
    BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
    BHO-x32: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
    BHO-x32: No Name - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -  No File
    BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
    BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
    BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    BHO-x32: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    Toolbar: HKLM-x32 - Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
    Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll No File
    Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
     
    FireFox:
    ========
    FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default
    FF Homepage: about:home
    FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20(url.indexOf('turntable.fm')%20!%3D%20-1%20%26%26%20url.indexOf('static.turntable.fm')%20%3D%3D%20-1%20%26%26%20url.indexOf('s3.amazonaws.com')%20%3D%3D%20-1%20%26%26%20url.indexOf('ping.chartbeat.net')%20%3D%3D%20-1)%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1)%20%7B%20return%20'PROXY%20ab-us03.personalitycores.com%3A8000%3B%20PROXY%20ab-us09.personalitycores.com%3A8000%3B%20PROXY%20ab-us06.personalitycores.com%3A8000%3B%20PROXY%20ab-us10.personalitycores.com%3A8000%3B%20PROXY%20ab-us02.personalitycores.com%3A8000%3B%20PROXY%20ab-us11.personalitycores.com%3A8000%3B%20PROXY%20ab-us13.personalitycores.com%3A8000%3B%20PROXY%20ab-us08.personalitycores.com%3A8000%3B%20PROXY%20ab-us07.personalitycores.com%3A8000%3B%20PROXY%20ab-us01.personalitycores.com%3A8000%3B%20PROXY%20ab-us12.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
    FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
    FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
    FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF Plugin: @microsoft.com/GENUINE - disabled No File
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
    FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
    FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
    FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF Plugin-x32: @mcafee.com/MVT - C:\Program Files (x86)\McAfee\Supportability\MVT\npmvtplugin.dll (McAfee, Inc.)
    FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
    FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
    FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
    FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
    FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
    FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
    FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
    FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\User\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
    FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\User\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
    FF Extension: British English Dictionary - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\Extensions\[email protected] [2012-07-14]
    FF Extension: FT DeepDark - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\Extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66} [2014-03-19]
    FF Extension: Easy Google Translate - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\Extensions\[email protected] [2012-06-19]
    FF Extension: Video Downloader professional - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\Extensions\[email protected] [2013-04-09]
    FF Extension: Translate This! - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\Extensions\[email protected] [2012-08-15]
    FF Extension: ProxMate - Proxy on steroids! - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\Extensions\[email protected] [2013-04-09]
    FF Extension: S3.Google Translator - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\Extensions\[email protected] [2013-09-22]
    FF Extension: Screengrab  (fix version) - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\Extensions\{02450914-cdd9-410f-b1da-db004e18c671}.xpi [2013-04-09]
    FF Extension: eBay Sidebar for Firefox - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\Extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}.xpi [2013-10-21]
    FF Extension: Power Zoom - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\Extensions\{65030561-c150-4370-836c-7c9d04f7a1b4}.xpi [2013-04-09]
    FF HKLM-x32\...\Firefox\Extensions: [{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}] - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}
    FF Extension: Adobe Contribute Toolbar - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2012-06-02]
    FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
    FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012-06-02]
    FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore
    FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\IPSFF
    FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\McAfee\MSK
     
    Chrome: 
    =======
    CHR HomePage: 
    CHR DefaultSearchKeyword: google.co.uk
    CHR Extension: (Google Docs) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-25]
    CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-25]
    CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-25]
    CHR Extension: (Google Search) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-25]
    CHR Extension: (Google Wallet) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-25]
    CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-25]
     
    ==================== Services (Whitelisted) =================
     
    S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
    R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [146592 2011-04-29] (Atheros)
    S2 CLKMSVC10_9EC60124; C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe [247768 2013-04-26] (CyberLink)
    S3 DCDhcpService; C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe [104096 2011-07-19] (Atheros Communication Inc.)
    R2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2012-12-12] (Nero AG)
    R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
    R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
    R2 mfevtp; C:\Windows\system32\mfevtps.exe [184800 2013-12-05] (McAfee, Inc.)
    R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
    S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
    R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [80896 2011-03-31] ()
    R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation)
    R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.)
    S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [887000 2011-01-20] (Sony Corporation)
    R3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1369136 2013-09-25] (Sony Corporation)
    R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2014-02-28] (Western Digital Technologies, Inc.)
    R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [271728 2014-02-28] (Western Digital Technologies, Inc.)
     
    ==================== Drivers (Whitelisted) ====================
     
    R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
    R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-11-21] (Intel Corporation)
    R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
    R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-27] (Malwarebytes Corporation)
    R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
    S3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179792 2013-12-05] (McAfee, Inc.)
    R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [782616 2013-12-05] (McAfee, Inc.)
    R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
    S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
    S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] ()
    S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
    S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [74752 2011-07-25] (Research In Motion Limited)
    R3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44032 2011-07-20] (Research in Motion Ltd)
    R2 risdsnpe; C:\Windows\System32\DRIVERS\risdsnxc64.sys [98816 2011-03-07] (REDC)
    S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
    R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2012-06-02] ()
    U3 ay50xw50; C:\Windows\System32\Drivers\ay50xw50.sys [0 ] (Microsoft Corporation)
    R1 MpKslda15c24e; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9C739477-97F9-4B87-ADDF-ADF2FC3E107B}\MpKslda15c24e.sys [X]
     
    ==================== NetSvcs (Whitelisted) ===================
     
     
    ==================== One Month Created Files and Folders ========
     
    2014-04-27 23:08 - 2014-04-27 23:08 - 00026117 _____ () C:\Users\User\Desktop\FRST.txt
    2014-04-27 23:07 - 2014-04-27 23:08 - 00000000 ____D () C:\FRST
    2014-04-27 23:04 - 2014-04-27 23:04 - 00000820 _____ () C:\Users\User\Desktop\JRT.txt
    2014-04-27 22:59 - 2014-04-27 22:59 - 00000000 ____D () C:\Windows\ERUNT
    2014-04-27 22:41 - 2014-04-27 22:42 - 00581872 _____ () C:\Windows\Minidump\042714-31012-01.dmp
    2014-04-27 22:41 - 2014-04-27 22:41 - 998092758 _____ () C:\Windows\MEMORY.DMP
    2014-04-27 22:20 - 2014-04-27 22:29 - 00000000 ____D () C:\AdwCleaner
    2014-04-27 22:17 - 2014-04-27 22:17 - 00006033 _____ () C:\Users\User\Desktop\Instructions 27.04.2014.txt
    2014-04-27 22:14 - 2014-04-27 22:14 - 02925760 _____ (Sysinternals - www.sysinternals.com) C:\Users\User\Desktop\procexp.exe
    2014-04-27 22:14 - 2014-04-27 22:14 - 00061440 _____ ( ) C:\Users\User\Desktop\VEW.exe
    2014-04-27 22:13 - 2014-04-27 22:13 - 04009167 _____ () C:\Users\User\Desktop\ServicesRepair.exe
    2014-04-27 22:12 - 2014-04-27 22:12 - 02061824 _____ (Farbar) C:\Users\User\Desktop\FRST64.exe
    2014-04-27 22:11 - 2014-04-27 22:11 - 01016261 _____ (Thisisu) C:\Users\User\Desktop\JRT.exe
    2014-04-27 22:10 - 2014-04-27 22:10 - 01329501 _____ () C:\Users\User\Desktop\AdwCleaner.exe
    2014-04-27 17:09 - 2014-04-27 17:09 - 00141142 _____ () C:\Users\User\Downloads\Extras.Txt
    2014-04-27 17:07 - 2014-04-27 17:07 - 00114530 _____ () C:\Users\User\Downloads\OTL.Txt
    2014-04-27 16:28 - 2014-04-27 16:28 - 00602112 _____ (OldTimer Tools) C:\Users\User\Downloads\OTL.exe
    2014-04-27 16:16 - 2014-04-27 16:16 - 00646656 _____ (OldTimer Tools) C:\Users\User\Downloads\OTS.exe
    2014-04-27 16:01 - 2014-04-27 16:02 - 00347816 _____ (Microsoft Corporation) C:\Users\User\Downloads\MicrosoftFixit.wu.LB.38322040317233891.1.1.Run.exe
    2014-04-27 16:00 - 2014-04-27 16:00 - 00019052 _____ () C:\Users\User\Documents\GMER 27.04.2013.log
    2014-04-27 15:10 - 2014-04-27 15:10 - 00370943 _____ () C:\Users\User\Downloads\gmer.zip
    2014-04-27 14:06 - 2014-04-27 14:06 - 00003118 _____ () C:\Windows\System32\Tasks\{1A022E9E-2535-4D58-A4E0-9FE8E6D70CE1}
    2014-04-27 14:05 - 2014-04-27 14:05 - 00000000 ____D () C:\Users\User\AppData\Roaming\InstallShield
    2014-04-27 13:47 - 2014-04-27 13:47 - 00000000 ____D () C:\Users\User\AppData\Local\Akamai
    2014-04-27 13:46 - 2014-04-27 13:46 - 10552296 _____ (Akamai Technologies, Inc.) C:\Users\User\Downloads\Intel_Download_Manager_Installer.exe
    2014-04-27 00:39 - 2014-04-27 00:38 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
    2014-04-27 00:38 - 2014-04-27 00:38 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
    2014-04-27 00:38 - 2014-04-27 00:38 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
    2014-04-27 00:38 - 2014-04-27 00:38 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
    2014-04-27 00:08 - 2014-04-27 00:08 - 00921512 _____ (Oracle Corporation) C:\Users\User\Downloads\jxpiinstall(2).exe
    2014-04-26 23:57 - 2014-04-26 23:57 - 00000000 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
    2014-04-26 16:01 - 2014-04-26 16:01 - 00347816 _____ (Microsoft Corporation) C:\Users\User\Downloads\MicrosoftFixit.Performance.FISC.3832194991311108.3.2.Run.exe
    2014-04-26 15:57 - 2014-04-26 15:58 - 00347816 _____ (Microsoft Corporation) C:\Users\User\Downloads\MicrosoftFixit.malware.FISC.3832194991311108.3.1.Run.exe
    2014-04-26 14:36 - 2014-04-26 14:36 - 00001150 _____ () C:\Users\User\Downloads\w7-wscsvc.zip
    2014-04-26 14:08 - 2013-12-05 16:44 - 00184800 _____ (McAfee, Inc.) C:\Windows\system32\mfevtps.exe
    2014-04-26 13:24 - 2014-04-26 13:27 - 05142080 _____ (McAfee, Inc.) C:\Users\User\Downloads\McAfeeSetup-Serial.exe
    2014-04-25 01:02 - 2014-04-25 01:02 - 00002255 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
    2014-04-25 01:02 - 2014-04-25 01:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    2014-04-25 00:32 - 2014-04-25 00:32 - 00001945 _____ () C:\Windows\epplauncher.mif
    2014-04-25 00:31 - 2014-04-25 00:31 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
    2014-04-25 00:31 - 2014-04-25 00:31 - 00000000 ____D () C:\Program Files\Microsoft Security Client
    2014-04-25 00:31 - 2014-04-25 00:31 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
    2014-04-25 00:30 - 2014-04-25 00:30 - 13829304 _____ (Microsoft Corporation) C:\Users\User\Downloads\mseinstall.exe
    2014-04-22 22:51 - 2014-04-22 22:51 - 00000000 ____D () C:\Users\dub_cm_auto
    2014-04-19 12:34 - 2014-04-27 22:43 - 00008192 _____ () C:\Windows\SysWOW64\WDPABKP.dat
    2014-04-18 07:02 - 2014-04-18 07:02 - 00001141 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Update.lnk
    2014-04-13 15:28 - 2014-04-13 15:28 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieUserList
    2014-04-13 15:28 - 2014-04-13 15:28 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieSiteList
    2014-04-10 03:10 - 2014-03-06 09:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2014-04-10 03:10 - 2014-03-06 08:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2014-04-10 03:09 - 2014-03-06 11:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2014-04-10 03:09 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2014-04-10 03:09 - 2014-03-06 10:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2014-04-10 03:09 - 2014-03-06 10:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2014-04-10 03:09 - 2014-03-06 09:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2014-04-10 03:09 - 2014-03-06 09:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2014-04-10 03:09 - 2014-03-06 09:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2014-04-10 03:09 - 2014-03-06 09:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2014-04-10 03:09 - 2014-03-06 09:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2014-04-10 03:09 - 2014-03-06 09:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2014-04-10 03:09 - 2014-03-06 09:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2014-04-10 03:09 - 2014-03-06 09:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2014-04-10 03:09 - 2014-03-06 09:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2014-04-10 03:09 - 2014-03-06 09:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2014-04-10 03:09 - 2014-03-06 09:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2014-04-10 03:09 - 2014-03-06 09:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2014-04-10 03:09 - 2014-03-06 09:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2014-04-10 03:09 - 2014-03-06 09:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2014-04-10 03:09 - 2014-03-06 09:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2014-04-10 03:09 - 2014-03-06 09:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2014-04-10 03:09 - 2014-03-06 09:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2014-04-10 03:09 - 2014-03-06 08:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2014-04-10 03:09 - 2014-03-06 08:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2014-04-10 03:09 - 2014-03-06 08:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2014-04-10 03:09 - 2014-03-06 08:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2014-04-10 03:09 - 2014-03-06 08:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2014-04-10 03:09 - 2014-03-06 08:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2014-04-10 03:09 - 2014-03-06 08:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2014-04-10 03:09 - 2014-03-06 08:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2014-04-10 03:09 - 2014-03-06 08:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2014-04-10 03:09 - 2014-03-06 08:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2014-04-10 03:09 - 2014-03-06 08:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2014-04-10 03:09 - 2014-03-06 08:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2014-04-10 03:09 - 2014-03-06 08:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2014-04-10 03:09 - 2014-03-06 08:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2014-04-10 03:09 - 2014-03-06 08:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2014-04-10 03:09 - 2014-03-06 07:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2014-04-10 03:09 - 2014-03-06 07:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2014-04-10 03:09 - 2014-03-06 07:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2014-04-10 03:09 - 2014-03-06 07:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2014-04-10 03:09 - 2014-03-06 07:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2014-04-10 03:09 - 2014-03-06 06:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2014-04-10 03:09 - 2014-03-06 06:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2014-04-10 03:09 - 2014-03-06 06:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2014-04-10 03:09 - 2014-03-06 06:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2014-04-10 03:09 - 2014-03-06 06:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2014-04-10 00:59 - 2014-02-04 03:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
    2014-04-10 00:59 - 2014-02-04 03:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
    2014-04-10 00:59 - 2014-02-04 03:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
    2014-04-10 00:59 - 2014-02-04 03:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
    2014-04-10 00:59 - 2014-02-04 03:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
    2014-04-10 00:58 - 2014-03-04 10:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
    2014-04-10 00:58 - 2014-03-04 10:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
    2014-04-10 00:58 - 2014-03-04 10:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
    2014-04-10 00:58 - 2014-03-04 10:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
    2014-04-10 00:58 - 2014-03-04 10:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
    2014-04-10 00:58 - 2014-03-04 10:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
    2014-04-10 00:58 - 2014-03-04 10:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
    2014-04-10 00:58 - 2014-03-04 10:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
    2014-04-10 00:58 - 2014-03-04 10:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
    2014-04-10 00:58 - 2014-03-04 09:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
    2014-04-10 00:58 - 2014-03-04 09:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
    2014-04-10 00:58 - 2014-01-24 03:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
    2014-04-08 22:45 - 2014-04-27 22:41 - 02105552 _____ () C:\Windows\PFRO.log
    2014-04-06 21:11 - 2014-04-27 22:41 - 00003528 _____ () C:\Windows\setupact.log
    2014-04-06 21:11 - 2014-04-06 21:11 - 00000000 _____ () C:\Windows\setuperr.log
    2014-04-06 09:53 - 2014-04-27 23:05 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2014-04-06 09:53 - 2014-04-06 09:53 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2014-04-06 09:53 - 2014-04-06 09:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2014-04-06 09:53 - 2014-04-06 09:53 - 00000000 ____D () C:\ProgramData\Malwarebytes
    2014-04-06 09:53 - 2014-04-06 09:53 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
    2014-04-06 09:53 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
    2014-04-06 09:53 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2014-04-06 09:53 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
    2014-04-05 17:15 - 2014-04-05 17:16 - 04139872 _____ (Kaspersky Lab ZAO) C:\Users\User\Downloads\tdsskiller.exe
    2014-04-05 17:03 - 2014-04-05 17:04 - 12589848 _____ (Malwarebytes Corp.) C:\Users\User\Downloads\mbar-1.07.0.1009.exe
    2014-04-05 17:03 - 2014-04-05 17:03 - 01440846 _____ () C:\Users\User\Downloads\mbam-chameleon-1.62.1.1000.zip
    2014-04-05 17:03 - 2014-04-05 17:03 - 00065232 _____ (Malwarebytes) C:\Users\User\Downloads\regassassin-setup-1.03.exe
    2014-04-05 16:59 - 2014-04-05 17:01 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-2.0.1.1004.exe
    2014-04-05 16:45 - 2014-04-05 16:45 - 00000000 ____D () C:\Users\User\Documents\Symantec
    2014-04-05 15:26 - 2014-04-05 15:26 - 01059840 _____ () C:\Users\User\Downloads\MicrosoftFixit50981.msi
    2014-03-30 18:58 - 2014-03-30 18:58 - 01745736 _____ (Avanquest ) C:\Users\User\Downloads\SmartDriverUpdater(1).exe
    2014-03-30 18:46 - 2014-03-30 18:47 - 01745736 _____ (Avanquest ) C:\Users\User\Downloads\SmartDriverUpdater.exe
    2014-03-30 16:13 - 2014-03-30 16:15 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
    2014-03-30 15:02 - 2014-03-30 15:02 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
    2014-03-30 15:02 - 2014-03-30 15:02 - 00000000 ____D () C:\ProgramData\Intel
    2014-03-30 14:58 - 2014-03-30 14:58 - 00000000 ____D () C:\Users\User\Intel
    2014-03-30 13:27 - 2014-03-30 13:33 - 85312352 _____ () C:\Users\User\Downloads\INDVID-00247913-0042.zip
    2014-03-30 13:27 - 2014-03-30 13:31 - 50971445 _____ () C:\Users\User\Downloads\SOAVCA-00245717-0042.zip
    2014-03-30 13:27 - 2014-03-30 13:28 - 03570892 _____ () C:\Users\User\Downloads\INDCHI-00245644-0042.zip
    2014-03-30 13:22 - 2014-03-30 13:23 - 03875192 _____ (Sony Corporation) C:\Users\User\Downloads\EP0000251540.exe
    2014-03-30 13:18 - 2014-03-30 13:19 - 02600976 _____ (Sony Corporation) C:\Users\User\Downloads\EP0000250856.exe
    2014-03-30 13:11 - 2014-03-30 13:12 - 17535472 _____ (Intel Corporation) C:\Users\User\Downloads\SetupRST.exe
    2014-03-30 13:11 - 2014-03-30 13:11 - 00366486 _____ () C:\Users\User\Downloads\f6flpy-x64.zip
    2014-03-30 13:11 - 2014-03-30 13:11 - 00321746 _____ () C:\Users\User\Downloads\f6flpy-x86.zip
    2014-03-30 13:03 - 2014-03-30 13:03 - 01189560 _____ (AMD Inc.) C:\Users\User\Downloads\catalyst_mobility_64-bit_util.exe
    2014-03-30 12:40 - 2014-03-30 12:40 - 00921000 _____ (Oracle Corporation) C:\Users\User\Downloads\jxpiinstall(1).exe
     
    ==================== One Month Modified Files and Folders =======
     
    2014-04-27 23:08 - 2014-04-27 23:08 - 00026117 _____ () C:\Users\User\Desktop\FRST.txt
    2014-04-27 23:08 - 2014-04-27 23:07 - 00000000 ____D () C:\FRST
    2014-04-27 23:05 - 2014-04-06 09:53 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
    2014-04-27 23:05 - 2012-09-20 12:14 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2014-04-27 23:05 - 2012-05-30 08:04 - 01240239 _____ () C:\Windows\WindowsUpdate.log
    2014-04-27 23:04 - 2014-04-27 23:04 - 00000820 _____ () C:\Users\User\Desktop\JRT.txt
    2014-04-27 22:59 - 2014-04-27 22:59 - 00000000 ____D () C:\Windows\ERUNT
    2014-04-27 22:56 - 2012-06-01 15:50 - 00000000 ____D () C:\Users\User\AppData\Roaming\BitTorrent
    2014-04-27 22:51 - 2009-07-14 05:45 - 00021200 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2014-04-27 22:51 - 2009-07-14 05:45 - 00021200 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2014-04-27 22:48 - 2012-11-15 14:31 - 00000904 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3830866668-548323272-1850177600-1000UA.job
    2014-04-27 22:45 - 2013-01-14 17:28 - 00000000 ____D () C:\Users\User\AppData\Local\HTC MediaHub
    2014-04-27 22:43 - 2014-04-19 12:34 - 00008192 _____ () C:\Windows\SysWOW64\WDPABKP.dat
    2014-04-27 22:43 - 2013-01-14 17:30 - 00000000 ____D () C:\Users\User\AppData\Local\Htc
    2014-04-27 22:42 - 2014-04-27 22:41 - 00581872 _____ () C:\Windows\Minidump\042714-31012-01.dmp
    2014-04-27 22:42 - 2012-09-20 12:14 - 00000890 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2014-04-27 22:41 - 2014-04-27 22:41 - 998092758 _____ () C:\Windows\MEMORY.DMP
    2014-04-27 22:41 - 2014-04-08 22:45 - 02105552 _____ () C:\Windows\PFRO.log
    2014-04-27 22:41 - 2014-04-06 21:11 - 00003528 _____ () C:\Windows\setupact.log
    2014-04-27 22:41 - 2012-06-02 14:41 - 00000000 ____D () C:\Windows\Minidump
    2014-04-27 22:41 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
    2014-04-27 22:37 - 2012-06-04 18:18 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
    2014-04-27 22:29 - 2014-04-27 22:20 - 00000000 ____D () C:\AdwCleaner
    2014-04-27 22:17 - 2014-04-27 22:17 - 00006033 _____ () C:\Users\User\Desktop\Instructions 27.04.2014.txt
    2014-04-27 22:16 - 2012-06-09 17:01 - 00000000 ____D () C:\Users\User\AppData\Roaming\vlc
    2014-04-27 22:14 - 2014-04-27 22:14 - 02925760 _____ (Sysinternals - www.sysinternals.com) C:\Users\User\Desktop\procexp.exe
    2014-04-27 22:14 - 2014-04-27 22:14 - 00061440 _____ ( ) C:\Users\User\Desktop\VEW.exe
    2014-04-27 22:13 - 2014-04-27 22:13 - 04009167 _____ () C:\Users\User\Desktop\ServicesRepair.exe
    2014-04-27 22:12 - 2014-04-27 22:12 - 02061824 _____ (Farbar) C:\Users\User\Desktop\FRST64.exe
    2014-04-27 22:11 - 2014-04-27 22:11 - 01016261 _____ (Thisisu) C:\Users\User\Desktop\JRT.exe
    2014-04-27 22:10 - 2014-04-27 22:10 - 01329501 _____ () C:\Users\User\Desktop\AdwCleaner.exe
    2014-04-27 17:10 - 2012-06-02 11:59 - 00000000 ____D () C:\Users\User\Documents\D.C.W
    2014-04-27 17:09 - 2014-04-27 17:09 - 00141142 _____ () C:\Users\User\Downloads\Extras.Txt
    2014-04-27 17:07 - 2014-04-27 17:07 - 00114530 _____ () C:\Users\User\Downloads\OTL.Txt
    2014-04-27 16:28 - 2014-04-27 16:28 - 00602112 _____ (OldTimer Tools) C:\Users\User\Downloads\OTL.exe
    2014-04-27 16:16 - 2014-04-27 16:16 - 00646656 _____ (OldTimer Tools) C:\Users\User\Downloads\OTS.exe
    2014-04-27 16:02 - 2014-04-27 16:01 - 00347816 _____ (Microsoft Corporation) C:\Users\User\Downloads\MicrosoftFixit.wu.LB.38322040317233891.1.1.Run.exe
    2014-04-27 16:00 - 2014-04-27 16:00 - 00019052 _____ () C:\Users\User\Documents\GMER 27.04.2013.log
    2014-04-27 16:00 - 2012-08-13 21:54 - 00033415 _____ () C:\test.xml
    2014-04-27 15:10 - 2014-04-27 15:10 - 00370943 _____ () C:\Users\User\Downloads\gmer.zip
    2014-04-27 14:55 - 2012-05-30 08:59 - 00000000 ____D () C:\Users\User\AppData\Local\Adobe
    2014-04-27 14:46 - 2012-05-30 08:04 - 00000000 ____D () C:\Program Files (x86)\Intel
    2014-04-27 14:06 - 2014-04-27 14:06 - 00003118 _____ () C:\Windows\System32\Tasks\{1A022E9E-2535-4D58-A4E0-9FE8E6D70CE1}
    2014-04-27 14:05 - 2014-04-27 14:05 - 00000000 ____D () C:\Users\User\AppData\Roaming\InstallShield
    2014-04-27 13:47 - 2014-04-27 13:47 - 00000000 ____D () C:\Users\User\AppData\Local\Akamai
    2014-04-27 13:46 - 2014-04-27 13:46 - 10552296 _____ (Akamai Technologies, Inc.) C:\Users\User\Downloads\Intel_Download_Manager_Installer.exe
    2014-04-27 01:48 - 2012-11-15 14:31 - 00000852 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3830866668-548323272-1850177600-1000Core.job
    2014-04-27 00:41 - 2012-06-13 16:50 - 00000000 ____D () C:\Users\User\AppData\Local\CrashDumps
    2014-04-27 00:38 - 2014-04-27 00:39 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
    2014-04-27 00:38 - 2014-04-27 00:38 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
    2014-04-27 00:38 - 2014-04-27 00:38 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
    2014-04-27 00:38 - 2014-04-27 00:38 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
    2014-04-27 00:08 - 2014-04-27 00:08 - 00921512 _____ (Oracle Corporation) C:\Users\User\Downloads\jxpiinstall(2).exe
    2014-04-27 00:03 - 2014-03-25 22:53 - 00000000 ____D () C:\ProgramData\Oracle
    2014-04-26 23:57 - 2014-04-26 23:57 - 00000000 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log
    2014-04-26 23:57 - 2012-05-30 08:14 - 00000000 ____D () C:\Program Files (x86)\Java
    2014-04-26 16:43 - 2014-04-26 16:43 - 04954736 _____ (Microsoft Corporation) C:\Users\User\Downloads\WindowsUpgradeAssistant.exe
    2014-04-26 16:01 - 2014-04-26 16:01 - 00347816 _____ (Microsoft Corporation) C:\Users\User\Downloads\MicrosoftFixit.Performance.FISC.3832194991311108.3.2.Run.exe
    2014-04-26 15:58 - 2014-04-26 15:57 - 00347816 _____ (Microsoft Corporation) C:\Users\User\Downloads\MicrosoftFixit.malware.FISC.3832194991311108.3.1.Run.exe
    2014-04-26 14:36 - 2014-04-26 14:36 - 00001150 _____ () C:\Users\User\Downloads\w7-wscsvc.zip
    2014-04-26 14:28 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    2014-04-26 14:28 - 2009-07-14 05:54 - 00000749 ___RH () C:\Windows\WindowsShell.Manifest
    2014-04-26 14:28 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
    2014-04-26 14:28 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
    2014-04-26 14:08 - 2012-06-01 17:03 - 00000000 ____D () C:\Program Files\Common Files\McAfee
    2014-04-26 13:27 - 2014-04-26 13:24 - 05142080 _____ (McAfee, Inc.) C:\Users\User\Downloads\McAfeeSetup-Serial.exe
    2014-04-25 01:02 - 2014-04-25 01:02 - 00002255 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
    2014-04-25 01:02 - 2014-04-25 01:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    2014-04-25 01:02 - 2012-09-20 12:14 - 00000000 ____D () C:\Users\User\AppData\Local\Google
    2014-04-25 01:01 - 2012-09-20 12:14 - 00000000 ____D () C:\Program Files (x86)\Google
    2014-04-25 00:32 - 2014-04-25 00:32 - 00001945 _____ () C:\Windows\epplauncher.mif
    2014-04-25 00:31 - 2014-04-25 00:31 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
    2014-04-25 00:31 - 2014-04-25 00:31 - 00000000 ____D () C:\Program Files\Microsoft Security Client
    2014-04-25 00:31 - 2014-04-25 00:31 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
    2014-04-25 00:30 - 2014-04-25 00:30 - 13829304 _____ (Microsoft Corporation) C:\Users\User\Downloads\mseinstall.exe
    2014-04-25 00:14 - 2014-03-23 14:19 - 00000000 ____D () C:\ProgramData\Norton
    2014-04-24 23:52 - 2013-05-23 00:58 - 00000000 ____D () C:\Program Files (x86)\PokerStars
    2014-04-24 23:51 - 2013-05-23 00:58 - 00000000 ____D () C:\Users\User\AppData\Local\PokerStars
    2014-04-22 22:51 - 2014-04-22 22:51 - 00000000 ____D () C:\Users\dub_cm_auto
    2014-04-18 07:02 - 2014-04-18 07:02 - 00001141 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Update.lnk
    2014-04-18 07:02 - 2012-05-30 08:03 - 00000000 ____D () C:\ProgramData\Sony Corporation
    2014-04-18 06:59 - 2012-05-30 09:28 - 00000000 ____D () C:\Update
    2014-04-13 15:28 - 2014-04-13 15:28 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieUserList
    2014-04-13 15:28 - 2014-04-13 15:28 - 00000000 __SHD () C:\Users\User\AppData\Local\EmieSiteList
    2014-04-10 04:35 - 2014-02-16 10:04 - 00000000 ____D () C:\Windows\rescache
    2014-04-10 03:30 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
    2014-04-10 03:14 - 2012-06-16 22:43 - 00000000 ____D () C:\ProgramData\Microsoft Help
    2014-04-10 03:07 - 2013-07-13 14:42 - 00000000 ____D () C:\Windows\system32\MRT
    2014-04-10 03:03 - 2012-06-01 16:47 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
    2014-04-06 21:11 - 2014-04-06 21:11 - 00000000 _____ () C:\Windows\setuperr.log
    2014-04-06 10:10 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
    2014-04-06 09:53 - 2014-04-06 09:53 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2014-04-06 09:53 - 2014-04-06 09:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2014-04-06 09:53 - 2014-04-06 09:53 - 00000000 ____D () C:\ProgramData\Malwarebytes
    2014-04-06 09:53 - 2014-04-06 09:53 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
    2014-04-05 19:16 - 2013-05-15 23:03 - 00007597 _____ () C:\Users\User\AppData\Local\Resmon.ResmonCfg
    2014-04-05 17:16 - 2014-04-05 17:15 - 04139872 _____ (Kaspersky Lab ZAO) C:\Users\User\Downloads\tdsskiller.exe
    2014-04-05 17:04 - 2014-04-05 17:03 - 12589848 _____ (Malwarebytes Corp.) C:\Users\User\Downloads\mbar-1.07.0.1009.exe
    2014-04-05 17:03 - 2014-04-05 17:03 - 01440846 _____ () C:\Users\User\Downloads\mbam-chameleon-1.62.1.1000.zip
    2014-04-05 17:03 - 2014-04-05 17:03 - 00065232 _____ (Malwarebytes) C:\Users\User\Downloads\regassassin-setup-1.03.exe
    2014-04-05 17:01 - 2014-04-05 16:59 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-2.0.1.1004.exe
    2014-04-05 16:45 - 2014-04-05 16:45 - 00000000 ____D () C:\Users\User\Documents\Symantec
    2014-04-05 15:26 - 2014-04-05 15:26 - 01059840 _____ () C:\Users\User\Downloads\MicrosoftFixit50981.msi
    2014-04-03 16:00 - 2012-09-20 12:14 - 00003890 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
    2014-04-03 16:00 - 2012-09-20 12:14 - 00003638 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
    2014-04-03 09:51 - 2014-04-06 09:53 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
    2014-04-03 09:51 - 2014-04-06 09:53 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2014-04-03 09:50 - 2014-04-06 09:53 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
    2014-04-02 01:43 - 2012-11-15 14:31 - 00003872 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3830866668-548323272-1850177600-1000UA
    2014-04-02 01:43 - 2012-11-15 14:31 - 00003476 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3830866668-548323272-1850177600-1000Core
    2014-04-01 21:40 - 2012-06-01 15:47 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
    2014-03-30 21:56 - 2013-05-21 19:55 - 00000085 _____ () C:\Users\User\Desktop\New Text Document (4).txt
    2014-03-30 18:58 - 2014-03-30 18:58 - 01745736 _____ (Avanquest ) C:\Users\User\Downloads\SmartDriverUpdater(1).exe
    2014-03-30 18:47 - 2014-03-30 18:46 - 01745736 _____ (Avanquest ) C:\Users\User\Downloads\SmartDriverUpdater.exe
    2014-03-30 16:15 - 2014-03-30 16:13 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
    2014-03-30 15:50 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
    2014-03-30 15:02 - 2014-03-30 15:02 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
    2014-03-30 15:02 - 2014-03-30 15:02 - 00000000 ____D () C:\ProgramData\Intel
    2014-03-30 14:58 - 2014-03-30 14:58 - 00000000 ____D () C:\Users\User\Intel
    2014-03-30 13:33 - 2014-03-30 13:27 - 85312352 _____ () C:\Users\User\Downloads\INDVID-00247913-0042.zip
    2014-03-30 13:31 - 2014-03-30 13:27 - 50971445 _____ () C:\Users\User\Downloads\SOAVCA-00245717-0042.zip
    2014-03-30 13:28 - 2014-03-30 13:27 - 03570892 _____ () C:\Users\User\Downloads\INDCHI-00245644-0042.zip
    2014-03-30 13:23 - 2014-03-30 13:22 - 03875192 _____ (Sony Corporation) C:\Users\User\Downloads\EP0000251540.exe
    2014-03-30 13:19 - 2014-03-30 13:18 - 02600976 _____ (Sony Corporation) C:\Users\User\Downloads\EP0000250856.exe
    2014-03-30 13:12 - 2014-03-30 13:11 - 17535472 _____ (Intel Corporation) C:\Users\User\Downloads\SetupRST.exe
    2014-03-30 13:11 - 2014-03-30 13:11 - 00366486 _____ () C:\Users\User\Downloads\f6flpy-x64.zip
    2014-03-30 13:11 - 2014-03-30 13:11 - 00321746 _____ () C:\Users\User\Downloads\f6flpy-x86.zip
    2014-03-30 13:03 - 2014-03-30 13:03 - 01189560 _____ (AMD Inc.) C:\Users\User\Downloads\catalyst_mobility_64-bit_util.exe
    2014-03-30 12:40 - 2014-03-30 12:40 - 00921000 _____ (Oracle Corporation) C:\Users\User\Downloads\jxpiinstall(1).exe
     
    Some content of TEMP:
    ====================
    C:\Users\User\AppData\Local\Temp\Quarantine.exe
    C:\Users\User\AppData\Local\Temp\_unps.exe
     
     
    ==================== Bamital & volsnap Check =================
     
    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\rpcss.dll => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
     
     
    LastRegBack: 2014-04-20 00:19
     
    ==================== End Of Log ============================
     
     
     
     
    Addition Log:
     
    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-04-2014
    Ran by User at 2014-04-27 23:09:02
    Running from C:\Users\User\Desktop
    Boot Mode: Normal
    ==========================================================
     
     
    ==================== Security Center ========================
     
     
    ==================== Installed Programs ======================
     
     Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{90120000-0026-0000-0000-0000000FF1CE}_WebDesigner_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version:  - Microsoft)
     Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version:  - Microsoft)
     Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version:  - Microsoft)
     Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version:  - Microsoft)
    ActiveX контрола на Windows Live Mesh за отдалечени връзки (HKLM-x32\...\{B3BA4D1C-23EF-4859-9C11-1B2CCB7FADBB}) (Version: 15.4.5722.2 - Microsoft Corporation)
    ActiveX-kontroll för fjärranslutningar för Windows Live Mesh (HKLM-x32\...\{376D59B1-42D9-4FA2-B6CC-E346B6BE14F5}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.9 - Adobe Systems)
    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.5.0.880 - Adobe Systems Incorporated)
    Adobe AIR (x32 Version: 3.5.0.880 - Adobe Systems Incorporated) Hidden
    Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.4.980 - Adobe Systems Incorporated.)
    Adobe Community Help (x32 Version: 3.4.980 - Adobe Systems Incorporated.) Hidden
    Adobe Content Viewer (HKLM-x32\...\com.adobe.dmp.contentviewer) (Version: 1.4.0 - Adobe Systems Incorporated)
    Adobe Content Viewer (x32 Version: 1.4.0 - Adobe Systems Incorporated) Hidden
    Adobe Creative Suite 5.5 Master Collection (HKLM-x32\...\{D57FC112-312E-4D70-860F-2DB8FB6858F0}) (Version: 5.5 - Adobe Systems Incorporated)
    Adobe Flash Player 12 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated)
    Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated)
    Adobe Photoshop Elements 9 (HKLM-x32\...\Adobe Photoshop Elements 9) (Version: 9.0.3.0 - Adobe Systems Incorporated)
    Adobe Photoshop Elements 9 (x32 Version: 9.0.3.0 - Adobe Systems Incorporated) Hidden
    Adobe Premiere Elements 9 (HKLM-x32\...\PremElem90) (Version: 9.0 - Adobe Systems Incorporated)
    Adobe Premiere Elements 9 (x32 Version: 9.0.1 - Adobe Systems Incorporated) Hidden
    Adobe Reader X (10.1.9) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.9 - Adobe Systems Incorporated)
    Adobe Story (HKLM-x32\...\com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.0.571 - Adobe Systems Incorporated)
    Adobe Story (x32 Version: 1.0.571 - Adobe Systems Incorporated) Hidden
    Adobe Widget Browser (HKLM-x32\...\com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1) (Version: 2.0 Build 230 - Adobe Systems Incorporated.)
    Adobe Widget Browser (x32 Version: 2.0.230 - Adobe Systems Incorporated.) Hidden
    Aimersoft Video Converter Ultimate(Build 4.2.1.0) (HKLM-x32\...\Aimersoft Video Converter Ultimate_is1) (Version:  - Aimersoft Software)
    Akamai NetSession Interface (HKCU\...\Akamai) (Version:  - Akamai Technologies, Inc)
    AMD APP SDK Runtime (Version: 2.4.595.10 - Advanced Micro Devices Inc.) Hidden
    Apple Application Support (HKLM-x32\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    ArcSoft Magic-i Visual Effects 2 (HKLM-x32\...\{61438020-DDD4-42FA-99A2-50225441980A}) (Version: 2.0.1.142 - ArcSoft)
    ArcSoft WebCam Companion 4 (HKLM-x32\...\{C793AD32-2BB8-4CC4-ABD3-A1469C21593C}) (Version: 4.0.21.484 - ArcSoft)
    Atheros WiFi Driver Installation (HKLM-x32\...\{7D916FA5-DAE9-4A25-B089-655C70EAF607}) (Version: 3.0 - Atheros)
    ATI Catalyst Install Manager (HKLM\...\{BF3C5FE1-FD86-A14D-8EC2-6488D646515E}) (Version: 3.0.825.0 - ATI Technologies, Inc.)
    Basic PAYE Tools - Real Time Information (HKLM-x32\...\Basic PAYE Tools - Real Time Information) (Version: 13.1.13137.112 - HM Revenue & Customs)
    Basic PAYE Tools 2012 (HKLM-x32\...\Basic PAYE Tools 2012) (Version: 4.2.1.20469 - HM Revenue & Customs)
    BBC iPlayer Desktop (HKLM-x32\...\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1) (Version: 3.0.11 - British Broadcasting Corp.)
    BBC iPlayer Desktop (x32 Version: 3.0.11 - British Broadcasting Corp.) Hidden
    BBC iPlayer Downloads (HKLM-x32\...\{198DFB43-9C28-4204-93ED-1545E3E467B8}) (Version: 1.0.2 - BBC)
    BitTorrent (HKCU\...\BitTorrent) (Version: 7.9.1.30889 - BitTorrent Inc.)
    BlackBerry Desktop Software 7.1 (HKLM-x32\...\BlackBerry_Desktop) (Version: 7.1.0.32 - Research In Motion Ltd.)
    BlackBerry Desktop Software 7.1 (x32 Version: 7.1.0.32 - Research In Motion Ltd.) Hidden
    Bluetooth Win7 Suite (64) (HKLM\...\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.3.0.100 - Atheros Communications)
    Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
    Canon MP Navigator 3.1 (HKLM-x32\...\MP Navigator 3.1) (Version:  - )
    Canon MP140 series (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP140_series) (Version:  - )
    Catalyst Control Center Graphics Previews Common (x32 Version: 2011.0127.629.11510 - ATI) Hidden
    Catalyst Control Center Localization All (x32 Version: 2011.0127.629.11510 - ATI) Hidden
    CCC Help Chinese Standard (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    CCC Help Chinese Traditional (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    CCC Help Czech (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    CCC Help Danish (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    CCC Help Dutch (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    CCC Help English (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    CCC Help Finnish (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    CCC Help French (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    CCC Help German (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    CCC Help Greek (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    CCC Help Hungarian (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    CCC Help Italian (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    CCC Help Japanese (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    CCC Help Korean (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    CCC Help Norwegian (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    CCC Help Polish (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    CCC Help Portuguese (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    CCC Help Russian (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    CCC Help Spanish (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    CCC Help Swedish (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    CCC Help Thai (x32 Version: 2011.0127.0628.11510 - ATI) Hidden
    ccc-core-static (x32 Version: 2011.0127.629.11510 - ATI) Hidden
    ccc-utility64 (Version: 2011.0127.629.11510 - ATI) Hidden
    Control ActiveX Windows Live Mesh pentru conexiuni la distanță (HKLM-x32\...\{260E3D78-94E6-47EC-8E29-46301572BB1E}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation)
    CyberLink PowerDVD (HKLM-x32\...\InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}) (Version: 9.0.6426.52 - CyberLink Corp.)
    CyberLink PowerDVD (x32 Version: 9.0.6426.52 - CyberLink Corp.) Hidden
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    Dropbox (HKCU\...\Dropbox) (Version: 2.6.2 - Dropbox, Inc.)
    EaseUS Data Recovery Wizard 5.6.5 (HKLM-x32\...\EaseUS Data Recovery Wizard 5.6.5_is1) (Version: 5.6.5 - EaseUS)
    Elements 9 Organizer (x32 Version: 9.0 - Adobe Systems Incorporated) Hidden
    Elements STI Installer (x32 Version: 1.0 - Adobe Systems Incorporated) Hidden
    EPSON SX110 Series Printer Uninstall (HKLM\...\EPSON SX110 Series) (Version:  - SEIKO EPSON Corporation)
    FlacSquisher 1.0.13 (HKLM-x32\...\FlacSquisher) (Version: 1.0.13 - FlacSquisher)
    Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (HKLM-x32\...\{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    GenoPro 2.5.4.1 (HKLM-x32\...\GenoPro) (Version:  - GenoPro Inc.)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.131 - Google Inc.)
    Google Drive (HKLM-x32\...\{E87022D3-C8C9-4C76-8E27-BC7F18F9B8FB}) (Version: 1.14.6059.644 - Google, Inc.)
    Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden
    HTC BMP USB Driver (HKLM-x32\...\{31A559C1-9E4D-423B-9DD3-34A6C5398752}) (Version: 1.0.5375 - HTC)
    HTC Driver Installer (HKLM-x32\...\{6D6664A9-3342-4948-9B7E-034EFE366F0F}) (Version: 3.0.0.007 - HTC Corporation)
    HTC Sync (HKLM-x32\...\{B78CFC07-B623-4995-ADCC-B2B4D59D083A}) (Version: 3.3.21 - HTC Corporation)
    HTC Sync Manager (HKLM-x32\...\{5DC3BFF3-B84F-4CBE-B2BD-FB52B6C247CA}) (Version: 1.1.77.0 - HTC)
    Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
    Intel® Processor ID Utility (HKLM-x32\...\{A92A4DB0-CD37-42D1-BE1D-603D53C24328}) (Version: 4.80.0000 - Intel® Corporation)
    iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
    Java 7 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417051FF}) (Version: 7.0.510 - Oracle)
    Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217055FF}) (Version: 7.0.550 - Oracle)
    Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
    Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Malwarebytes Anti-Malware version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation)
    McAfee Virtual Technician (HKLM-x32\...\McAfee Virtual Technician) (Version: 6.5.0.2101 - McAfee, Inc.)
    Media Gallery (Version: 1.5.0.16020 - Your Company Name) Hidden
    Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
    Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
    Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
    Microsoft Expression Web (HKLM-x32\...\WebDesigner) (Version: 12.0.6215.1000 - Microsoft Corporation)
    Microsoft Expression Web (x32 Version: 12.0.6215.1000 - Microsoft Corporation) Hidden
    Microsoft Expression Web MUI (English) (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Expression Web Service Pack 1 (SP1) (HKLM-x32\...\{90120000-0026-0000-0000-0000000FF1CE}_WebDesigner_{9037FDA8-8383-4B6F-859D-D49C3C625225}) (Version:  - Microsoft)
    Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
    Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
    Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Office Access MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Access Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
    Microsoft Office Groove MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Groove Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office InfoPath MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office OneNote MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Outlook MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Project 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{8446EB22-A746-46DC-B1BD-E0DFA1F3CDDA}) (Version:  - Microsoft)
    Microsoft Office Project 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
    Microsoft Office Project MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Project Professional 2007 (HKLM-x32\...\PRJPRO) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Office Project Professional 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
    Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
    Microsoft Office Publisher MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office SharePoint Designer 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
    Microsoft Office Visio 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{CE144BF4-4950-4CDB-A5F7-CCE1888F49CB}) (Version:  - Microsoft)
    Microsoft Office Visio 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
    Microsoft Office Visio MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Visio Professional 2007 (HKLM-x32\...\VISPRO) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Office Visio Professional 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
    Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden
    Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
    Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
    Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
    Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
    Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
    Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
    Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
    Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
    Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053 - Adobe) Hidden
    Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
    Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
    Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
    Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
    Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
    Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
    Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
    Microsoft_VC90_MFCLOC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
    MiniTool Partition Wizard Home Edition 8.1.1 (HKLM-x32\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version:  - MiniTool Solution Ltd.)
    Monkey's Audio (HKLM-x32\...\Monkey's Audio_is1) (Version:  - )
    Mozilla Firefox 28.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 en-US)) (Version: 28.0 - Mozilla)
    Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla)
    MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
    MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
    MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
    MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
    MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
    MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
    Music Manager (HKCU\...\MusicManager) (Version:  - Google, Inc.)
    Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení (HKLM-x32\...\{B6190387-0036-4BEB-8D74-A0AFC5F14706}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia (HKLM-x32\...\{C2FD7DB5-FE30-49B6-8A2F-C5652E053C31}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Pam Call Recorder 4.8 (HKLM-x32\...\PamelaCR) (Version: 4.8 - Scendix Software-Vertriebsges. mbH)
    PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
    PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
    PMB (HKLM-x32\...\{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}) (Version: 5.5.02.12220 - Sony Corporation)
    PMB VAIO Edition Guide (x32 Version: 1.5.00.02250 - Sony Corporation) Hidden
    PMB VAIO Edition Plug-in (Version: 1.5.00.04010 - Sony Corporation) Hidden
    PMB VAIO Edition Plug-in (x32 Version: 1.5.00.02250 - Sony Corporation) Hidden
    PMB VAIO Edition Plug-in (x32 Version: 1.5.00.04060 - Sony Corporation) Hidden
    Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    PokerStars (HKLM-x32\...\PokerStars) (Version:  - PokerStars)
    PxMergeModule (x32 Version: 1.00.0000 - Your Company Name) Hidden
    Qualcomm Atheros Direct Connect (x32 Version: 3.0 - Qualcomm Atheros) Hidden
    QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
    Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Raptr (HKLM-x32\...\Raptr) (Version:  - )
    Realtek HDMI Audio Driver for ATI (HKLM-x32\...\{5449FB4F-1802-4D5B-A6D8-087DB1142147}) (Version: 6.0.1.6650 - Realtek Semiconductor Corp.)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6526 - Realtek Semiconductor Corp.)
    Remote Keyboard (x32 Version: 1.1.1.03020 - Sony Corporation) Hidden
    Remote Play with PlayStation 3 (x32 Version: 1.1.0.15070 - Sony Corporation) Hidden
    Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation)
    Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden
    Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
    Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
    SmartSound Quicktracks for Premiere Elements 9.0 (HKLM-x32\...\InstallShield_{6748E773-5DA0-4D19-8AA5-273B4133A09B}) (Version: 3.12.3090 - SmartSound Software Inc)
    SmartSound Quicktracks for Premiere Elements 9.0 (x32 Version: 3.12.3090 - SmartSound Software Inc) Hidden
    Sony Corporation (Version: 1.0.0 - Default Company Name) Hidden
    Spotify (HKCU\...\Spotify) (Version: 0.9.1.57.ge7405149 - Spotify AB)
    SSLx64 (Version: 1.0.0 - Sony Corporation ) Hidden
    SSLx86 (x32 Version: 1.0.0 - Sony Corporation ) Hidden
    Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
    Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.2.6.0 - Synaptics Incorporated)
    System Requirements Lab for Intel (HKLM-x32\...\{1EBDF6D2-CEA0-484C-A23E-2DDAD7FD0DD0}) (Version: 4.5.22.0 - Husdawg, LLC)
    TriDef 3D (Sony) 1.1.3 (HKLM-x32\...\experience-sony-bundle) (Version: 1.1.3 - Dynamic Digital Depth Australia Pty Ltd)
    Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0026-0000-0000-0000000FF1CE}_WebDesigner_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
    Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
    Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
    Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 Help for Common Features (KB963673) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{AB365889-0395-4FAD-B702-CA5985D53D42}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 Help for Common Features (KB963673) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_PRJPRO_{AB365889-0395-4FAD-B702-CA5985D53D42}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 Help for Common Features (KB963673) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_VISPRO_{AB365889-0395-4FAD-B702-CA5985D53D42}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 Help for Common Features (KB963673) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_WebDesigner_{AB365889-0395-4FAD-B702-CA5985D53D42}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (HKLM-x32\...\{90120000-0026-0000-0000-0000000FF1CE}_WebDesigner_{620E77C0-CDFE-4C14-AAEB-830ABB65864C}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (HKLM-x32\...\{90120000-0026-0000-0000-0000000FF1CE}_WebDesigner_{8153EC80-C988-4336-8DAF-6D99C0D26E0C}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6FAA03BD-2B51-4029-9AD9-64A3B8E3C84C}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (HKLM-x32\...\{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{6FAA03BD-2B51-4029-9AD9-64A3B8E3C84C}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (HKLM-x32\...\{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{6FAA03BD-2B51-4029-9AD9-64A3B8E3C84C}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_PRJPRO_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_VISPRO_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_WebDesigner_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0026-0000-0000-0000000FF1CE}_WebDesigner_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
    Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
    Update for Microsoft Office Access 2007 Help (KB963663) (HKLM-x32\...\{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{6B76A18A-AA1E-42AB-A7AD-6C84BBB43987}) (Version:  - Microsoft)
    Update for Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{199DF7B6-169C-448C-B511-1054101BE9C9}) (Version:  - Microsoft)
    Update for Microsoft Office Infopath 2007 Help (KB963662) (HKLM-x32\...\{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{716B81B8-B13C-41DF-8EAC-7A2F656CAB63}) (Version:  - Microsoft)
    Update for Microsoft Office OneNote 2007 Help (KB963670) (HKLM-x32\...\{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2744EF05-38E1-4D5D-B333-E021EDAEA245}) (Version:  - Microsoft)
    Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{ED38F8A3-4F61-494E-8BCA-E3AC7760C924}) (Version:  - Microsoft)
    Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version:  - Microsoft)
    Update for Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{0451F231-E3E3-4943-AB9F-58EB96171784}) (Version:  - Microsoft)
    Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2878297) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{9B1DEEA3-B4ED-49F0-9EF7-4A820EEEA7F1}) (Version:  - Microsoft)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{397B1D4F-ED7B-4ACA-A637-43B670843876}) (Version:  - Microsoft)
    Update for Microsoft Office Project 2007 Help (KB963668) (HKLM-x32\...\{90120000-00B4-0409-0000-0000000FF1CE}_PRJPRO_{1DF07773-4289-4998-BC2C-83539AD85C50}) (Version:  - Microsoft)
    Update for Microsoft Office Publisher 2007 Help (KB963667) (HKLM-x32\...\{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2E40DE55-B289-4C8B-8901-5D369B16814F}) (Version:  - Microsoft)
    Update for Microsoft Office Script Editor Help (KB963671) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{CD11C6A2-FFC6-4271-8EAB-79C3582F505C}) (Version:  - Microsoft)
    Update for Microsoft Office Script Editor Help (KB963671) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_PRJPRO_{CD11C6A2-FFC6-4271-8EAB-79C3582F505C}) (Version:  - Microsoft)
    Update for Microsoft Office Script Editor Help (KB963671) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_VISPRO_{CD11C6A2-FFC6-4271-8EAB-79C3582F505C}) (Version:  - Microsoft)
    Update for Microsoft Office Script Editor Help (KB963671) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_WebDesigner_{CD11C6A2-FFC6-4271-8EAB-79C3582F505C}) (Version:  - Microsoft)
    Update for Microsoft Office Visio 2007 Help (KB963666) (HKLM-x32\...\{90120000-0054-0409-0000-0000000FF1CE}_VISPRO_{D2C4ACC9-12F5-4E1C-81A8-5DC878AC6278}) (Version:  - Microsoft)
    Update for Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{80E762AA-C921-4839-9D7D-DB62A72C0726}) (Version:  - Microsoft)
    Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi (HKLM-x32\...\{241E7104-937A-4366-AD57-8FDDDB003939}) (Version: 15.4.5722.2 - Microsoft Corporation)
    V3DPX86 (x32 Version: 1.0.0 - Sony Corporation ) Hidden
    VAIO - Media Gallery (HKLM-x32\...\{FA870BF1-44A1-4B7D-93E1-C101369AF0C1}) (Version: 1.5.0.16020 - Sony Corporation)
    VAIO - PMB VAIO Edition Guide (HKLM-x32\...\InstallShield_{339F9B4D-00CB-4C1C-BED8-EC86A9AB602A}) (Version: 1.5.00.02250 - Sony Corporation)
    VAIO - PMB VAIO Edition Plug-in (HKLM-x32\...\InstallShield_{270380EB-8812-42E1-8289-53700DB840D2}) (Version: 1.5.00.04060 - Sony Corporation)
    VAIO - Remote Keyboard (HKLM-x32\...\{7396FB15-9AB4-4B78-BDD8-24A9C15D2C65}) (Version: 1.0.1.03020 - Sony Corporation)
    VAIO - Remote Play with PlayStation®3 (HKLM-x32\...\{07441A52-E208-478A-92B7-5C337CA8C131}) (Version: 1.1.0.15070 - Sony Corporation)
    VAIO 3D Portal (HKLM-x32\...\{C14EAE86-C526-4E00-B245-CFF86233C3D2}) (Version: 1.0.1.09270 - Sony Corporation)
    VAIO C Series - Summer 2011 Screensaver (HKLM-x32\...\VAIO C Series - Summer 2011 Screensaver) (Version:  - )
    VAIO Care (HKLM-x32\...\{36C5BBF0-E5BF-4DE1-B684-7E90B0C93FB5}) (Version: 6.4.0.15030 - Sony Corporation)
    VAIO Care (x32 Version: 6.4.0.15030 - Sony Corporation) Hidden
    VAIO Control Center (HKLM-x32\...\{72042FA6-5609-489F-A8EA-3C2DD650F667}) (Version: 4.5.0.03040 - Sony Corporation)
    VAIO Data Restore Tool (HKLM-x32\...\{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}) (Version: 1.6.0.13140 - Sony Corporation)
    VAIO Data Restore Tool (x32 Version: 1.6.0.13140 - Sony Corporation) Hidden
    VAIO Easy Connect (HKLM-x32\...\InstallShield_{7C80D30A-AC02-4E3F-B95D-29F0E4FF937B}) (Version: 1.1.2.01120 - Sony Corporation)
    VAIO Easy Connect (x32 Version: 1.1.2.01120 - Sony Corporation) Hidden
    VAIO Event Service (HKLM-x32\...\{73D8886A-D416-4687-B609-0D3836BA410C}) (Version: 5.5.0.03040 - Sony Corporation)
    VAIO Gate (HKLM-x32\...\{A7C30414-2382-4086-B0D6-01A88ABA21C3}) (Version: 2.4.2.02200 - Sony Corporation)
    VAIO Gate Default (HKLM-x32\...\{B7546697-2A80-4256-A24B-1C33163F535B}) (Version: 2.4.0.03240 - Sony Corporation)
    VAIO Hardware Diagnostics (x32 Version: 4.2.0.14280 - Sony Corporation) Hidden
    VAIO Improvement (HKLM-x32\...\{3A26D9BD-0F73-432D-B522-2BA18138F7EF}) (Version: 1.0.0.14150 - Sony Corporation)
    VAIO Improvement Validation (HKLM\...\{75C95C84-264F-4CC7-8A7E-346444E6C7C1}) (Version: 1.0.4.01190 - Sony Corporation)
    VAIO Manual (HKLM-x32\...\{C6E893E7-E5EA-4CD5-917C-5443E753FCBD}) (Version: 1.3.0.02180 - Sony Corporation)
    VAIO Quick Web Access (HKLM-x32\...\splashtop) (Version: 1.4.5.5 - Sony Corporation)
    VAIO Quick Web Access (x32 Version: 1.4.5.5 - Sony Corporation) Hidden
    VAIO Sample Contents (HKLM-x32\...\{547C9EB4-4CA6-402F-9D1B-8BD30DC71E44}) (Version: 1.4.2.09010 - Sony Corporation)
    VAIO Smart Network (HKLM-x32\...\{0899D75A-C2FC-42EA-A702-5B9A5F24EAD5}) (Version: 3.8.1.08270 - Sony Corporation)
    VAIO Transfer Support (HKLM-x32\...\{5DDAFB4B-C52E-468A-9E23-3B0CEEB671BF}) (Version: 1.4.0.14230 - Sony Corporation)
    VAIO Update (HKLM-x32\...\{9FF95DA2-7DA1-4228-93B7-DED7EC02B6B2}) (Version: 6.3.1.10120 - Sony Corporation)
    VCCx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
    VESx64 (Version: 1.0.0 - Sony Corporation) Hidden
    VESx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
    VGClientX64 (Version: 1.0.0 - Sony Corporation) Hidden
    VIx64 (Version: 1.0.0 - Sony Corporation) Hidden
    VIx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
    VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
    VPMx64 (Version: 1.0.0 - Sony Corporation ) Hidden
    VSNx64 (Version: 1.0.0 - Sony Corporation) Hidden
    VSNx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
    VU5x64 (Version: 1.1.0 - Sony Corporation ) Hidden
    VU5x86 (x32 Version: 1.0.0 - Sony Corporation ) Hidden
    VU5x86 (x32 Version: 1.1.0 - Sony Corporation ) Hidden
    VWSTx86 (x32 Version: 1.0.0 - Sony Corporation) Hidden
    WD Drive Utilities (HKLM-x32\...\{F9784E1D-4455-4BFF-A97A-1B1355A4FFDB}) (Version: 1.0.6.3 - Western Digital Technologies, Inc.)
    WD Quick View (HKLM-x32\...\{63911503-7EA4-4685-B2FD-D391EF622FB9}) (Version: 2.3.0.20 - Western Digital Technologies, Inc.)
    WD Security (HKLM-x32\...\{90C3D9C7-2F83-4399-8E28-A00228CFFDF8}) (Version: 1.0.7.3 - Western Digital Technologies, Inc.)
    WD SmartWare (HKLM\...\{34C6812E-E231-4B13-9DAC-21E06ECA864A}) (Version: 2.3.0.20 - Western Digital Technologies, Inc.)
    WD SmartWare Installer (HKLM-x32\...\{1ec9e03a-452b-48fb-8e1b-27ee0477985f}) (Version: 2.3.0.20 - Western Digital Technologies, Inc.)
    Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
    Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Fotogaléria (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Fotogalleri (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden
    Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
    Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Mail (x32 Version: 15.4.3502.0922 - Корпорація Майкрософт) Hidden
    Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger (HKLM-x32\...\{09B7C7EB-3140-4B5E-842F-9C79A7137139}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Windows Live Mesh ActiveX-objekt til fjernforbindelser (HKLM-x32\...\{57220148-3B2B-412A-A2E0-82B9DF423696}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz (HKLM-x32\...\{6E29C4F7-C2C2-4B18-A15C-E09B92065F15}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Windows Live Meshin etäyhteyksien ActiveX-komponentti (HKLM-x32\...\{4CF6F287-5121-483C-A5A2-07BDE19D8B4E}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Messenger (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
    Windows Live Messenger (x32 Version: 15.4.3502.0922 - Корпорація Майкрософт) Hidden
    Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
    Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
    Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Liven sähköposti (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    WinZip 16.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240D5}) (Version: 16.5.10096 - WinZip Computing, S.L. )
    Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (HKLM-x32\...\{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Елемент керування Windows Live Mesh ActiveX для віддалених підключень (HKLM-x32\...\{6756D5CA-3E31-4308-9BF0-79DFD1AF196E}) (Version: 15.4.5722.2 - Microsoft Corporation)
    Основи Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
    Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Фотоколекція Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Элемент управления Windows Live Mesh ActiveX для удаленных подключений (HKLM-x32\...\{BCB0D6F7-7EAB-4009-A6F2-8E0E7F317773}) (Version: 15.4.5722.2 - Microsoft Corporation)
     
    ==================== Restore Points  =========================
     
    Could not list Restore Points. Check "winmgmt" service or repair WMI.
     
     
    ==================== Hosts content: ==========================
     
    2009-07-14 03:34 - 2012-06-02 01:33 - 00001451 ____N C:\Windows\system32\Drivers\etc\hosts
    127.0.0.1 localhost
    127.0.0.1 3dns.adobe.com
    127.0.0.1 3dns-1.adobe.com
    127.0.0.1 3dns-2.adobe.com
    127.0.0.1 3dns-3.adobe.com
    127.0.0.1 3dns-4.adobe.com
    127.0.0.1 activate.adobe.com
    127.0.0.1 activate-sea.adobe.com
    127.0.0.1 activate-sjc0.adobe.com
    127.0.0.1 activate.wip.adobe.com
    127.0.0.1 activate.wip1.adobe.com
    127.0.0.1 activate.wip2.adobe.com
    127.0.0.1 activate.wip3.adobe.com
    127.0.0.1 activate.wip4.adobe.com
    127.0.0.1 adobe-dns.adobe.com
    127.0.0.1 adobe-dns-1.adobe.com
    127.0.0.1 adobe-dns-2.adobe.com
    127.0.0.1 adobe-dns-3.adobe.com
    127.0.0.1 adobe-dns-4.adobe.com
    127.0.0.1 adobeereg.com
    127.0.0.1 practivate.adobe
    127.0.0.1 practivate.adobe.com
    127.0.0.1 practivate.adobe.newoa
    127.0.0.1 practivate.adobe.ntp
    127.0.0.1 practivate.adobe.ipp
    127.0.0.1 ereg.adobe.com
    127.0.0.1 ereg.wip.adobe.com
    127.0.0.1 ereg.wip1.adobe.com
    127.0.0.1 ereg.wip2.adobe.com
     
    There are 18 more lines.
     
     
    ==================== Scheduled Tasks (whitelisted) =============
     
    Task: {0829C1FA-0F94-4938-AD60-1E3F87EB4FBF} - System32\Tasks\Sony Corporation\VAIO Gate\StartExecuteProxy => C:\Program Files\Sony\VAIO Gate\ExecutionProxy.exe [2012-02-20] (Sony Corporation)
    Task: {08F03222-47B8-4E58-866F-6EE669F2E872} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3830866668-548323272-1850177600-1000Core => C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-15] (Google Inc.)
    Task: {0FCCAC1B-5808-4996-AB4C-9BCAAD7F0F5B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-20] (Adobe Systems Incorporated)
    Task: {1EA3E74B-DEC1-4517-B165-7654CF8E5081} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair => C:\Program Files\Sony\VAIO Update\VUSR.exe [2013-09-19] (Sony Corporation)
    Task: {234EFE6F-3907-4FC5-86A6-647B95093913} - System32\Tasks\Sony Corporation\VAIO Improvement\VAIOImprovementUploader => C:\Program Files\Sony\VAIO Improvement\viuploader.exe [2011-02-15] (Sony Corporation)
    Task: {26749A01-7602-4E34-AB20-A912952EB974} - System32\Tasks\Sony Corporation\VAIO Improvement Validation\VAIO Improvement Validation => C:\Program Files\Sony\VAIO Improvement Validation\viv.exe [2011-01-20] (Sony Corporation)
    Task: {2D27A0B1-1D9A-4B99-BF04-A3071FB510F2} - System32\Tasks\Sony Corporation\VAIO Gate\VAIO Gate => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2012-02-20] (Sony Corporation)
    Task: {36B59390-EB11-475C-8233-22D013D252D4} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [2012-12-12] ()
    Task: {3CD4FCB6-22CC-484F-BA98-1AA4F8B0706A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-20] (Google Inc.)
    Task: {3FE32C02-769E-458E-B9A6-1539C51589FD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-09-20] (Google Inc.)
    Task: {485EC28C-07C9-4E56-AA2E-9A5DAABD8B78} - System32\Tasks\{EE8D0D98-8F1F-4DAD-9AF1-B5F271EBBA83} => C:\Users\User\Documents\REMOVED\REMOVED\REMOVED\SX110_TX110_TX111_TX117_119_W2K_661E_MP.exe
    Task: {4D64A5A6-13E9-4724-A156-AE2B3FE19B9F} - System32\Tasks\Sony Corporation\VAIO Power Management\VPM Unlock => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2011-02-14] (Sony Corporation)
    Task: {5C3AB5BC-85B8-4F62-AD1E-8779CFB91A33} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update => C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe [2013-09-27] (Sony Corporation)
    Task: {63956C6C-A750-4013-AA75-C80550464EB2} - System32\Tasks\{B599DD56-12D6-4C77-889F-0AF724FC0773} => C:\Users\User\Documents\REMOVED\REMOVED\REMOVED\SX110_TX110_TX111_TX117_119_W2K_661E_MP.exe
    Task: {6493A148-A82E-44CF-BC95-9F1A8C143CAA} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCsystray.exe [2011-02-16] (Sony Corporation)
    Task: {70602B6E-4B9D-4A66-A152-EB85D1CA2692} - System32\Tasks\{C8A50BEC-A400-4934-AA64-E5346A30E6E6} => C:\Users\User\Documents\REMOVED\REMOVED\REMOVED\SX110_TX110_TX111_TX117_119_W2K_661E_MP.exe
    Task: {73CBA920-EC35-401C-962C-4039D1306ABC} - System32\Tasks\Sony Corporation\VAIO Power Management\VPM Session Change => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2011-02-14] (Sony Corporation)
    Task: {74626C15-74A3-44F6-913D-3C6D1C1F1D6E} - System32\Tasks\Western Digital\SmartWare\dropbox_50fcc0b4_f9eb_4de9_ba48_2ef2f89dd12f_dropbox_____Volume_69ae76aa_6ef3_11e3_9d89_ccaf78b751f4__ => C:\Program Files (x86)\Western Digital\WD SmartWare\BackupTask.exe [2014-02-28] (Western Digital Technologies, Inc.)
    Task: {8435AD87-2884-47B8-ADF5-2E21BFC8EFD0} - System32\Tasks\{524A5C6B-C216-4F94-B9DC-F6FCDDECCDEF} => C:\Users\User\Documents\REMOVED\REMOVED\REMOVED\SX110_TX110_TX111_TX117_119_W2K_661E_MP.exe
    Task: {84C2C029-CC4E-4A9C-A6FF-0D52F239DC48} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
    Task: {8867B8D3-A1E1-4120-B66D-AA9FA8125842} - System32\Tasks\Sony Corporation\VAIO Smart Network\VSN Logon Start => C:\Program Files\Sony\VAIO Smart Network\VSNClient
    Task: {9B589D45-2EAF-43D2-9851-13A896F81FB2} - System32\Tasks\Sony Corporation\VAIO Event Service\Level4Daily => C:\Program Files (x86)\Sony\VAIO Event Service\WBCBatteryCare.exe [2011-03-05] (Sony Corporation)
    Task: {9D34FE21-5F6B-4BA8-81B6-478894A39E3A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3830866668-548323272-1850177600-1000UA => C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2012-11-15] (Google Inc.)
    Task: {B8282454-AA03-44E4-BE93-12DFA63DB9E8} - System32\Tasks\{59BAA88A-880A-4DD2-84AD-F9D85FB177FD} => C:\Users\User\AppData\Roaming\Dropbox\bin\Dropbox.exe [2014-01-03] (Dropbox, Inc.)
    Task: {C1DB51D8-554F-42AB-A0EE-294C73C77B9B} - System32\Tasks\Sony Corporation\VAIO Gate\VAIO Gate Restart => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2012-02-20] (Sony Corporation)
    Task: {C36AA95C-157E-4D98-BE52-F599B711413A} - System32\Tasks\Sony Corporation\VAIO Power Management\VPM Logon Start => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2011-02-14] (Sony Corporation)
    Task: {D31B4E14-E26D-4212-B989-AC1759AE5F3F} - System32\Tasks\Sony Corporation\VAIO Update\Launch Application => C:\Program Files\SONY\VAIO Update\ShellExeProxy.exe [2013-08-30] (Sony Corporation)
    Task: {EB36B887-F837-408F-B0EA-899F4642C613} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCOneClick.exe [2011-02-16] (Sony Corporation)
    Task: {ECA05373-2650-480C-B769-FE842D4B19A1} - System32\Tasks\Sony Corporation\VAIO Event Service\Level4Month => C:\Program Files (x86)\Sony\VAIO Event Service\WBCBatteryCare.exe [2011-03-05] (Sony Corporation)
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3830866668-548323272-1850177600-1000Core.job => C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3830866668-548323272-1850177600-1000UA.job => C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe
     
    ==================== Loaded Modules (whitelisted) =============
     
    2011-03-31 17:08 - 2011-03-31 17:08 - 00080896 _____ () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
    2012-12-12 15:56 - 2012-12-12 15:56 - 00655360 _____ () C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe
    2012-12-27 17:26 - 2012-12-27 17:26 - 00169464 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
    2012-05-30 08:47 - 2011-02-25 17:14 - 00297472 _____ () C:\Program Files\Sony\VAIO Care\CRM\ManagedVAIORecoveryMedia.dll
    2012-05-30 08:47 - 2011-02-25 17:14 - 00192000 _____ () C:\Program Files\Sony\VAIO Care\CRM\VAIORecovery.dll
    2012-05-30 08:47 - 2011-02-25 17:14 - 00070656 _____ () C:\Program Files\Sony\VAIO Care\CRM\Logging.dll
    2012-05-30 08:47 - 2011-02-25 17:14 - 00063488 _____ () C:\Program Files\Sony\VAIO Care\CRM\VAIOCommon.dll
    2012-05-30 08:47 - 2011-02-25 17:14 - 00215040 _____ () C:\Program Files\Sony\VAIO Care\CRM\OsServices.dll
    2012-05-30 08:47 - 2011-02-25 17:14 - 00043008 _____ () C:\Program Files\Sony\VAIO Care\CRM\PluginFactory.dll
    2012-05-30 08:47 - 2011-02-25 17:14 - 00260608 _____ () C:\Program Files\Sony\VAIO Care\CRM\RecoveryPartitionManager.dll
    2012-05-30 08:47 - 2011-02-25 17:14 - 00043520 _____ () C:\Program Files\Sony\VAIO Care\CRM\XMLTools.dll
    2012-05-30 08:47 - 2011-02-25 17:14 - 00059904 _____ () C:\Program Files\Sony\VAIO Care\CRM\VAIOInstallAppsDrivers.dll
    2012-05-30 08:47 - 2011-02-25 17:14 - 00157696 _____ () C:\Program Files\Sony\VAIO Care\CRM\InstallDB.dll
    2012-05-30 08:47 - 2011-02-25 17:14 - 00138752 _____ () C:\Program Files\Sony\VAIO Care\CRM\InstallationTools.dll
    2012-05-30 08:47 - 2011-02-25 17:14 - 00025600 _____ () C:\Program Files\Sony\VAIO Care\CRM\VAIOUtility.dll
    2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    2012-12-27 17:24 - 2012-12-27 17:24 - 00025088 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\DbAccess.dll
    2012-12-27 17:25 - 2012-12-27 17:25 - 00466856 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\sqlite3.dll
    2012-12-27 17:25 - 2012-12-27 17:25 - 00044544 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\NAdvLog.dll
    2012-12-27 17:25 - 2012-12-27 17:25 - 00036368 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\NFileCacheDBAccess.dll
    2012-12-27 17:25 - 2012-12-27 17:25 - 00080400 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\ninstallerhelper.dll
    2012-12-27 17:28 - 2012-12-27 17:28 - 00223744 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\DevConnMon.dll
    2012-05-30 08:16 - 2011-03-05 16:42 - 00013824 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESBasePS.dll
    2012-12-12 15:56 - 2012-12-12 15:56 - 00028672 _____ () C:\Program Files (x86)\HTC\HTC Sync 3.0\OutputLog.dll
    2012-12-12 15:56 - 2012-12-12 15:56 - 00516599 _____ () C:\Program Files (x86)\HTC\HTC Sync 3.0\sqlite3.dll
    2012-12-12 15:56 - 2012-12-12 15:56 - 00094208 _____ () C:\Program Files (x86)\HTC\HTC Sync 3.0\fdHttpd.dll
    2012-12-12 15:56 - 2012-12-12 15:56 - 00405504 _____ () C:\Program Files (x86)\HTC\HTC Sync 3.0\HtcDetect.dll
    2012-12-12 15:56 - 2012-12-12 15:56 - 00159744 _____ () C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDisk.dll
    2012-12-12 15:56 - 2012-12-12 15:56 - 00172032 _____ () C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDetectLegend.dll
    2012-12-12 15:56 - 2012-12-12 15:56 - 00559244 _____ () C:\Program Files (x86)\HTC\HTC Sync 3.0\sqlite3.7.dll
    2012-12-12 15:56 - 2012-12-12 15:56 - 01515520 _____ () C:\Program Files (x86)\HTC\HTC Sync 3.0\Maps\R66Api.dll
     
    ==================== Alternate Data Streams (whitelisted) =========
     
    AlternateDataStreams: C:\Users\User\Local Settings:x6laFWl6GxQDAG4LXA9jCa
    AlternateDataStreams: C:\Users\User\AppData\Local:x6laFWl6GxQDAG4LXA9jCa
    AlternateDataStreams: C:\Users\User\AppData\Local\Application Data:x6laFWl6GxQDAG4LXA9jCa
    AlternateDataStreams: C:\Users\User\AppData\Local\Temp:sPSLPOi4WsC0ctmUEBkwI
     
    ==================== Safe Mode (whitelisted) ===================
     
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\71720608.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\71720608.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"
     
    ==================== Disabled items from MSCONFIG ==============
     
    MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
    MSCONFIG\startupreg: RIMBBLaunchAgent.exe => C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
    MSCONFIG\startupreg: WD Quick View => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
     
    ==================== Faulty Device Manager Devices =============
     
    Could not list Devices. Check "winmgmt" service or repair WMI.
     
     
    ==================== Event log errors: =========================
     
    Application errors:
    ==================
     
    System errors:
    =============
     
    Microsoft Office Sessions:
    =========================
    Error: (09/02/2013 07:13:51 PM) (Source: Microsoft Office 12 Sessions)(User: )
    Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 18341 seconds with 8280 seconds of active time.  This session ended with a crash.
     
     
    CodeIntegrity Errors:
    ===================================
      Date: 2012-10-10 11:41:57.470
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
      Date: 2012-10-10 11:41:57.439
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
      Date: 2012-10-10 11:41:34.955
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
      Date: 2012-10-10 11:41:34.841
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
      Date: 2012-10-10 11:39:08.620
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
      Date: 2012-10-10 11:39:08.600
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
      Date: 2012-10-10 11:37:23.163
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
      Date: 2012-10-10 11:37:22.688
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
      Date: 2012-10-10 11:35:21.676
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
      Date: 2012-10-10 11:35:21.401
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
     
    ==================== Memory info =========================== 
     
    Percentage of memory in use: 30%
    Total physical RAM: 6125.21 MB
    Available physical RAM: 4264.99 MB
    Total Pagefile: 12248.61 MB
    Available Pagefile: 9539.36 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.81 MB
     
    ==================== Drives ================================
     
    Drive c: () (Fixed) (Total:580.58 GB) (Free:12.23 GB) NTFS
     
    ==================== MBR & Partition Table ==================
     
    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: D1FE922A)
    Partition 1: (Not Active) - (Size=15 GB) - (Type=27)
    Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=581 GB) - (Type=07 NTFS)
     
    ==================== End Of Log ============================

    • 0

    #8
    RKinner

    RKinner

      Malware Expert

    • Expert
    • 24,624 posts
    • MVP

    I see three Proxy entries.  One in IE (ProxyServer: cslibproxy:80)

     

    and two in Firefox:  

     

    FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20(url.indexOf('turntable.fm')%20!%3D%20-1%20%26%26%20url.indexOf('static.turntable.fm')%20%3D%3D%20-1%20%26%26%20url.indexOf('s3.amazonaws.com')%20%3D%3D%20-1%20%26%26%20url.indexOf('ping.chartbeat.net')%20%3D%3D%20-1)%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1)%20%7B%20return%20'PROXY%20ab-us03.personalitycores.com%3A8000%3B%20PROXY%20ab-us09.personalitycores.com%3A8000%3B%20PROXY%20ab-us06.personalitycores.com%3A8000%3B%20PROXY%20ab-us10.personalitycores.com%3A8000%3B%20PROXY%20ab-us02.personalitycores.com%3A8000%3B%20PROXY%20ab-us11.personalitycores.com%3A8000%3B%20PROXY%20ab-us13.personalitycores.com%3A8000%3B%20PROXY%20ab-us08.personalitycores.com%3A8000%3B%20PROXY%20ab-us07.personalitycores.com%3A8000%3B%20PROXY%20ab-us01.personalitycores.com%3A8000%3B%20PROXY%20ab-us12.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"

     

    and also:

    FF Extension: ProxMate - Proxy on steroids! - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\Extensions\[email protected] [2013-04-09]

     

     

    I'm not sure what these are for or if they are required by your location or have some purpose that you know about.  My instinct is to remove them but I don't want to break anything.  

     

    I would uninstall BitTorrent and also McAfee Virtual Technician.

     

    FRST says it thinks something is wrong with your WMI.  Let's run the diagnostic program and see what it says:

     

    Copy the next 2 lines:

     

    winmgmt /verifyrepository > \junk.txt

    notepad \junk.txt

     

    Start, All Programs, Accessories, right click on Command Prompt and Run as Administrator, Continue.  Right click and Paste or Edit then Paste and the copied line should appear.

    Hit Enter if notepad does not open.  Copy and paste the text from notepad into a reply.  Close notepad.  Close the Command Window.
     
    We can remove some deadwood with FRST but I want to wait until I hear about the proxy stuff - do you need to keep it?
     
     
     

    • 0

    #9
    infected99.9

    infected99.9

      Member

    • Topic Starter
    • Member
    • PipPip
    • 19 posts

    I have never used or tried to use a proxy therefore please guide me how to remove those.

     

    I will keep BitTorrent and have just removed McAfee Virtual Technician.

     

    Below is the text from the diagnostic, then in the next few replies I will post all the other logs in original order:

     

    WMI repository verification failed
    Error code: 0x80070424
    Facility: Win32
    Description: The specified service does not exist as an installed service.

    • 0

    #10
    infected99.9

    infected99.9

      Member

    • Topic Starter
    • Member
    • PipPip
    • 19 posts
    OTL Log and then Extras Log below...
     
     
     
    OTL Log:
     
     
    OTL logfile created on: 28/04/2014 00:13:03 - Run 2
    OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\User\Desktop
    64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.11.9600.17041)
    Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
     
    5.98 Gb Total Physical Memory | 4.26 Gb Available Physical Memory | 71.20% Memory free
    11.96 Gb Paging File | 9.41 Gb Available in Paging File | 78.65% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]
     
    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 580.58 Gb Total Space | 12.23 Gb Free Space | 2.11% Space Free | Partition Type: NTFS
     
    Computer Name: *****-VAIO | User Name: User | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days
     
    ========== Processes (SafeList) ==========
     
    PRC - C:\Users\User\Desktop\OTL (1).exe (OldTimer Tools)
    PRC - C:\Users\User\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
    PRC - C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe (Western Digital Technologies, Inc.)
    PRC - C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe (Western Digital Technologies, Inc.)
    PRC - C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe (Western Digital Technologies, Inc.)
    PRC - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
    PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
    PRC - C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe (Western Digital Technologies, Inc.)
    PRC - C:\Program Files (x86)\CyberLink\Shared files\brs.exe (cyberlink)
    PRC - C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe ()
    PRC - C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe (Nero AG)
    PRC - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
    PRC - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
    PRC - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe ()
    PRC - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation)
    PRC - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
    PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
    PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
    PRC - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (ArcSoft, Inc.)
    PRC - C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
    PRC - C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation)
    PRC - C:\Program Files\Sony\VAIO Care\listener.exe (Sony of America Corporation)
    PRC - C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
    PRC - c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
    PRC - c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
     
     
    ========== Modules (No Company Name) ==========
     
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\fe1942c05eda4f9744f80afb4ae76a2d\System.Data.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\217ece46920546d718414291d463bb1c\System.Xml.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\5b6ddf934128d538cd5cd77bf4209b93\System.Configuration.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\b3a78269847005365001c33870cd121f\System.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ede2c6c842840e009f01bcc74fa4c457\mscorlib.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\f6d7bb59f318c130d68816a89335d05e\System.Runtime.Serialization.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\bada32953bb6b16a53d653eae23d78dc\System.Xml.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\bbc48ec4245e502ae19b0601d3799c9e\System.Configuration.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ff26cc03e6d57d8abd13b990332e67c6\System.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\ce5f61c5754789df97be8dc991c47d07\mscorlib.ni.dll ()
    MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
    MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
    MOD - C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe ()
    MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\Maps\R66Api.dll ()
    MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
    MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\sqlite3.7.dll ()
    MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\sqlite3.dll ()
    MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDetect.dll ()
    MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDetectLegend.dll ()
    MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDisk.dll ()
    MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\fdHttpd.dll ()
    MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\OutputLog.dll ()
    MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
     
     
    ========== Services (SafeList) ==========
     
    SRV:64bit: - (NisSrv) -- c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
    SRV:64bit: - (MsMpSvc) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
    SRV:64bit: - (IEEtwCollectorService) -- C:\Windows\SysNative\IEEtwCollector.exe (Microsoft Corporation)
    SRV:64bit: - (mfevtp) -- C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.)
    SRV:64bit: - (VUAgent) -- C:\Program Files\Sony\VAIO Update\VUAgent.exe (Sony Corporation)
    SRV:64bit: - (VSNService) -- C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation)
    SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
    SRV:64bit: - (DCDhcpService) -- C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe (Atheros Communication Inc.)
    SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
    SRV:64bit: - (VcmXmlIfHelper) -- C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe (Sony Corporation)
    SRV:64bit: - (VcmIAlzMgr) -- C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe (Sony Corporation)
    SRV:64bit: - (VcmINSMgr) -- C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe (Sony Corporation)
    SRV:64bit: - (VAIO Power Management) -- C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Sony Corporation)
    SRV:64bit: - (VCService) -- C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation)
    SRV:64bit: - (SampleCollector) -- C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Sony Corporation)
    SRV:64bit: - (SpfService) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe (Sony Corporation)
    SRV:64bit: - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
    SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
    SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
    SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
    SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
    SRV - (WDBackup) -- C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe (Western Digital Technologies, Inc.)
    SRV - (WDDriveService) -- C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe (Western Digital Technologies, Inc.)
    SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
    SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
    SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
    SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
    SRV - (CLKMSVC10_9EC60124) -- C:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe (CyberLink)
    SRV - (HTCMonitorService) -- C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe (Nero AG)
    SRV - (Atheros Bt&Wlan Coex Agent) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
    SRV - (AtherosSvc) -- C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Atheros Commnucations)
    SRV - (PassThru Service) -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe ()
    SRV - (VAIO Event Service) -- C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
    SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
    SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
    SRV - (uCamMonitor) -- C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (ArcSoft, Inc.)
    SRV - (SOHCImp) -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe (Sony Corporation)
    SRV - (SOHDs) -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe (Sony Corporation)
    SRV - (VCFw) -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation)
    SRV - (PMBDeviceInfoProvider) -- c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
    SRV - (AdobeActiveFileMonitor9.0) -- c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
    SRV - (ACDaemon) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
    SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
    SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
    SRV - (EPSON_EB_RPCV4_01) -- C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE (SEIKO EPSON CORPORATION)
    SRV - (EPSON_PM_RPCV4_01) -- C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (SEIKO EPSON CORPORATION)
     
     
    ========== Driver Services (SafeList) ==========
     
    DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
    DRV:64bit: - (NisDrv) -- C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
    DRV:64bit: - (mfehidk) -- C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
    DRV:64bit: - (mfeapfk) -- C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
    DRV:64bit: - (iaStorA) -- C:\Windows\SysNative\drivers\iaStorA.sys (Intel Corporation)
    DRV:64bit: - (iaStorF) -- C:\Windows\SysNative\drivers\iaStorF.sys (Intel Corporation)
    DRV:64bit: - (pwdrvio) -- C:\Windows\SysNative\pwdrvio.sys ()
    DRV:64bit: - (pwdspio) -- C:\Windows\SysNative\pwdspio.sys ()
    DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
    DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
    DRV:64bit: - (RTHDMIAzAudService) -- C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
    DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys ()
    DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
    DRV:64bit: - (RimUsb) -- C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
    DRV:64bit: - (RimVSerPort) -- C:\Windows\SysNative\drivers\RimSerial_AMD64.sys (Research in Motion Ltd)
    DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
    DRV:64bit: - (BtFilter) -- C:\Windows\SysNative\drivers\btfilter.sys (Atheros)
    DRV:64bit: - (BTATH_RCP) -- C:\Windows\SysNative\drivers\btath_rcp.sys (Atheros)
    DRV:64bit: - (BTATH_HCRP) -- C:\Windows\SysNative\drivers\btath_hcrp.sys (Atheros)
    DRV:64bit: - (btath_avdt) -- C:\Windows\SysNative\drivers\btath_avdt.sys (Atheros)
    DRV:64bit: - (BTATH_LWFLT) -- C:\Windows\SysNative\drivers\btath_lwflt.sys (Atheros)
    DRV:64bit: - (AthBTPort) -- C:\Windows\SysNative\drivers\btath_flt.sys (Atheros)
    DRV:64bit: - (BTATH_BUS) -- C:\Windows\SysNative\drivers\btath_bus.sys (Atheros)
    DRV:64bit: - (BTATH_A2DP) -- C:\Windows\SysNative\drivers\btath_a2dp.sys (Atheros)
    DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
    DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
    DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
    DRV:64bit: - (rimspci) -- C:\Windows\SysNative\drivers\rimssne64.sys (REDC)
    DRV:64bit: - (risdsnpe) -- C:\Windows\SysNative\drivers\risdsnxc64.sys (REDC)
    DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
    DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
    DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
    DRV:64bit: - (L1C) -- C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
    DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
    DRV:64bit: - (nusb3xhc) -- C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
    DRV:64bit: - (nusb3hub) -- C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
    DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
    DRV:64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
    DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
    DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
    DRV:64bit: - (ivusb) -- C:\Windows\SysNative\drivers\ivusb.sys (Initio Corporation)
    DRV:64bit: - (htcnprot) -- C:\Windows\SysNative\drivers\htcnprot.sys (Windows ® Win 7 DDK provider)
    DRV:64bit: - (SFEP) -- C:\Windows\SysNative\drivers\SFEP.sys (Sony Corporation)
    DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
    DRV:64bit: - (HTCAND64) -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys (HTC, Corporation)
    DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
    DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
    DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
    DRV:64bit: - (ROOTMODEM) -- C:\Windows\SysNative\drivers\rootmdm.sys (Microsoft Corporation)
    DRV:64bit: - (e1yexpress) -- C:\Windows\SysNative\drivers\e1y60x64.sys (Intel Corporation)
    DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
    DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
    DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
    DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
    DRV:64bit: - (ArcSoftKsUFilter) -- C:\Windows\SysNative\drivers\ArcSoftKsUFilter.sys (ArcSoft, Inc.)
    DRV:64bit: - (NuidFltr) -- C:\Windows\SysNative\drivers\nuidfltr.sys (Microsoft Corporation)
    DRV:64bit: - (WDC_SAM) -- C:\Windows\SysNative\drivers\wdcsam64.sys (Western Digital Technologies)
    DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
     
     
    ========== Standard Registry (SafeList) ==========
     
     
    ========== Internet Explorer ==========
     
    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    IE - HKLM\..\SearchScopes,DefaultScope = 
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
     
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.eu/vaioportal
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    IE - HKCU\..\SearchScopes,DefaultScope = 
    IE - HKCU\..\SearchScopes\{08174720-A6AA-407F-A7CB-8CCCA7BDEDB2}: "URL" = http://rover.ebay.co...e={searchTerms}
    IE - HKCU\..\SearchScopes\{20555815-E80E-4BF7-99AB-CE6D9CC9022F}: "URL" = https://www.google.c...q={searchTerms}
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = cslibproxy:80
     
    ========== FireFox ==========
     
    FF - prefs.js..browser.search.useDBForOrder: true
    FF - prefs.js..browser.startup.homepage: "about:home"
    FF - prefs.js..extensions.enabledAddons: easygtranslate%40wrlf.com.br:4.8
    FF - prefs.js..extensions.enabledAddons: en-GB%40dictionaries.addons.mozilla.org:1.19.1
    FF - prefs.js..extensions.enabledAddons: %7B65030561-c150-4370-836c-7c9d04f7a1b4%7D:0.1
    FF - prefs.js..extensions.enabledAddons: %7B01A8CA0A-4C96-465b-A49B-65C46FAD54F9%7D:6.1
    FF - prefs.js..extensions.enabledAddons: web2pdfextension%40web2pdf.adobedotcom:1.2
    FF - prefs.js..extensions.enabledAddons: s3google%40translator:2.14
    FF - prefs.js..extensions.enabledAddons: %7B02450914-cdd9-410f-b1da-db004e18c671%7D:0.97.24c
    FF - prefs.js..extensions.enabledAddons: %7B62760FD6-B943-48C9-AB09-F99C6FE96088%7D:3.1.1
    FF - prefs.js..extensions.enabledAddons: %7B77d2ed30-4cd2-11e0-b8af-0800200c9a66%7D:9.5.4
    FF - prefs.js..network.proxy.autoconfig_url: "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20(url.indexOf('turntable.fm')%20!%3D%20-1%20%26%26%20url.indexOf('static.turntable.fm')%20%3D%3D%20-1%20%26%26%20url.indexOf('s3.amazonaws.com')%20%3D%3D%20-1%20%26%26%20url.indexOf('ping.chartbeat.net')%20%3D%3D%20-1)%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1)%20%7B%20return%20'PROXY%20ab-us03.personalitycores.com%3A8000%3B%20PROXY%20ab-us09.personalitycores.com%3A8000%3B%20PROXY%20ab-us06.personalitycores.com%3A8000%3B%20PROXY%20ab-us10.personalitycores.com%3A8000%3B%20PROXY%20ab-us02.personalitycores.com%3A8000%3B%20PROXY%20ab-us11.personalitycores.com%3A8000%3B%20PROXY%20ab-us13.personalitycores.com%3A8000%3B%20PROXY%20ab-us08.personalitycores.com%3A8000%3B%20PROXY%20ab-us07.personalitycores.com%3A8000%3B%20PROXY%20ab-us01.personalitycores.com%3A8000%3B%20PROXY%20ab-us12.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
    FF - user.js - File not found
     
    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
    FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.55.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.55.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files (x86)\McAfee\Supportability\MVT\npmvtplugin.dll (McAfee, Inc.)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.8: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
    FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
    FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.2: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
    FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.3: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
    FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\User\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\User\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
     
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2012/06/02 01:05:40 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2014/01/19 21:23:21 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\IPSFF
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 28.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014/03/30 16:14:12 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 28.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\McAfee\MSK
    FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 28.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014/03/30 16:14:12 | 000,000,000 | ---D | M]
    FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 28.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
     
    [2012/06/01 15:49:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Extensions
    [2014/04/26 12:47:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\extensions
    [2014/03/19 23:41:03 | 000,000,000 | ---D | M] (FT DeepDark) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66}
    [2012/07/14 20:03:23 | 000,000,000 | ---D | M] (British English Dictionary) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\extensions\[email protected]
    [2013/12/13 00:23:07 | 000,111,858 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\extensions\[email protected]
    [2013/12/23 13:34:48 | 000,395,578 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\extensions\[email protected]
    [2014/04/26 12:47:19 | 000,024,427 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\extensions\[email protected]
    [2013/09/18 22:17:30 | 000,377,153 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\extensions\[email protected]
    [2014/04/05 16:01:03 | 000,081,138 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\extensions\[email protected]
    [2014/04/09 01:14:59 | 000,103,260 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\extensions\{02450914-cdd9-410f-b1da-db004e18c671}.xpi
    [2014/04/20 13:56:47 | 000,946,888 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}.xpi
    [2013/04/09 19:27:12 | 000,037,883 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\p9m2w77c.default\extensions\{65030561-c150-4370-836c-7c9d04f7a1b4}.xpi
    [2014/03/30 16:14:03 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
    [2014/03/30 16:15:10 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    [2014/01/19 21:23:21 | 000,000,000 | ---D | M] (Adobe Acrobat - Create PDF) -- C:\PROGRAM FILES (X86)\ADOBE\ACROBAT 10.0\ACROBAT\BROWSER\WCFIREFOXEXTN
    [2012/06/02 01:05:40 | 000,000,000 | ---D | M] (Adobe Contribute Toolbar) -- C:\PROGRAM FILES (X86)\ADOBE\ADOBE CONTRIBUTE CS5.1\PLUGINS\FIREFOXPLUGIN\{01A8CA0A-4C96-465B-A49B-65C46FAD54F9}
     
    ========== Chrome  ==========
     
    CHR - default_search_provider: Google (Enabled)
    CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
    CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
    CHR - homepage: 
    CHR - plugin: Error reading preferences file
    CHR - Extension: Google Docs = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
    CHR - Extension: Google Drive = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
    CHR - Extension: YouTube = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
    CHR - Extension: Google Search = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
    CHR - Extension: Google Wallet = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
    CHR - Extension: Gmail = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
     
    O1 HOSTS File: ([2012/06/02 01:33:18 | 000,001,451 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O1 - Hosts: 127.0.0.1 3dns.adobe.com
    O1 - Hosts: 127.0.0.1 3dns-1.adobe.com
    O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
    O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
    O1 - Hosts: 127.0.0.1 3dns-4.adobe.com
    O1 - Hosts: 127.0.0.1 activate.adobe.com
    O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
    O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
    O1 - Hosts: 127.0.0.1 activate.wip.adobe.com
    O1 - Hosts: 127.0.0.1 activate.wip1.adobe.com
    O1 - Hosts: 127.0.0.1 activate.wip2.adobe.com
    O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
    O1 - Hosts: 127.0.0.1 activate.wip4.adobe.com
    O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
    O1 - Hosts: 127.0.0.1 adobe-dns-1.adobe.com
    O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
    O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
    O1 - Hosts: 127.0.0.1 adobe-dns-4.adobe.com
    O1 - Hosts: 127.0.0.1 adobeereg.com
    O1 - Hosts: 127.0.0.1 practivate.adobe
    O1 - Hosts: 127.0.0.1 practivate.adobe.com
    O1 - Hosts: 127.0.0.1 practivate.adobe.newoa
    O1 - Hosts: 127.0.0.1 practivate.adobe.ntp
    O1 - Hosts: 127.0.0.1 practivate.adobe.ipp
    O1 - Hosts: 23 more lines...
    O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
    O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20121218151054.dll File not found
    O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
    O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
    O2 - BHO: (no name) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - No CLSID value found.
    O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
    O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
    O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
    O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
    O4:64bit: - HKLM..\Run: [AthBtTray] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations)
    O4:64bit: - HKLM..\Run: [AtherosBtStack] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations)
    O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
    O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
    O4:64bit: - HKLM..\Run: [RtHDVBg_Dolby] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
    O4 - HKLM..\Run: []  File not found
    O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
    O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
    O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [BDRegion] C:\Program Files (x86)\CyberLink\Shared files\brs.exe (cyberlink)
    O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
    O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
    O4 - HKLM..\Run: [PMBVolumeWatcher] c:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
    O4 - HKLM..\Run: [StartCCC] c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
    O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
    O4 - HKLM..\Run: [WD Drive Unlocker] C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe (Western Digital Technologies, Inc.)
    O4 - HKLM..\Run: [WD Quick View] C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe (Western Digital Technologies, Inc.)
    O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\User\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
    O4 - HKCU..\Run: [BitTorrent] C:\Users\User\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc.)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O8:64bit: - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105 File not found
    O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105 File not found
    O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O1364bit: - gopher Prefix: missing
    O13 - gopher Prefix: missing
    O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.51.2)
    O16:64bit: - DPF: {CAFEEFAC-0017-0000-0004-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_04)
    O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.51.2)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{062C3A79-936A-436E-9C95-DF06BED53A50}: DhcpNameServer = 192.168.1.254
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FC29F66D-2EC7-4F5C-8CE2-111B3D11A3FE}: DhcpNameServer = 172.0.0.254
    O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
    O18:64bit: - Protocol\Handler\livecall - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll File not found
    O18:64bit: - Protocol\Handler\msnim - No CLSID value found
    O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
    O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
    O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O32 - HKLM CDRom: AutoRun - 1
    O33 - MountPoints2\{9e4cc323-f20e-11e1-8496-ccaf78b751f4}\Shell - "" = AutoRun
    O33 - MountPoints2\{9e4cc323-f20e-11e1-8496-ccaf78b751f4}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
    O33 - MountPoints2\{c82aa577-3eb6-11e2-a71f-ccaf78b751f4}\Shell - "" = AutoRun
    O33 - MountPoints2\{c82aa577-3eb6-11e2-a71f-ccaf78b751f4}\Shell\AutoRun\command - "" = E:\unlock.exe autoplay=true
    O33 - MountPoints2\{c82aa587-3eb6-11e2-a71f-ccaf78b751f4}\Shell - "" = AutoRun
    O33 - MountPoints2\{c82aa587-3eb6-11e2-a71f-ccaf78b751f4}\Shell\AutoRun\command - "" = E:\unlock.exe autoplay=true
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
    O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
     
     
    MsConfig:64bit - StartUpReg: Adobe ARM - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
    MsConfig:64bit - StartUpReg: Adobe Reader Speed Launcher - hkey= - key= - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
    MsConfig:64bit - StartUpReg: RIMBBLaunchAgent.exe - hkey= - key= - C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
    MsConfig:64bit - StartUpReg: WD Quick View - hkey= - key= - C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe (Western Digital Technologies, Inc.)
    MsConfig:64bit - State: "startup" - Reg Error: Key error.
     
    SafeBootMin:64bit: 71720608.sys - Driver
    SafeBootMin:64bit: AppMgmt - Service
    SafeBootMin:64bit: Base - Driver Group
    SafeBootMin:64bit: Boot Bus Extender - Driver Group
    SafeBootMin:64bit: Boot file system - Driver Group
    SafeBootMin:64bit: File system - Driver Group
    SafeBootMin:64bit: Filter - Driver Group
    SafeBootMin:64bit: HelpSvc - Service
    SafeBootMin:64bit: MCODS - Reg Error: Value error.
    SafeBootMin:64bit: MsMpSvc - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
    SafeBootMin:64bit: PCI Configuration - Driver Group
    SafeBootMin:64bit: PNP Filter - Driver Group
    SafeBootMin:64bit: Primary disk - Driver Group
    SafeBootMin:64bit: sacsvr - Service
    SafeBootMin:64bit: SCSI Class - Driver Group
    SafeBootMin:64bit: System Bus Extender - Driver Group
    SafeBootMin:64bit: vmms - Service
    SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
    SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
    SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
    SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
    SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
    SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
    SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
    SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
    SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
    SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
    SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
    SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
    SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
    SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
    SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
    SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
    SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
    SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
    SafeBootMin: 71720608.sys - Driver
    SafeBootMin: AppMgmt - Service
    SafeBootMin: Base - Driver Group
    SafeBootMin: Boot Bus Extender - Driver Group
    SafeBootMin: Boot file system - Driver Group
    SafeBootMin: File system - Driver Group
    SafeBootMin: Filter - Driver Group
    SafeBootMin: HelpSvc - Service
    SafeBootMin: MCODS - Reg Error: Value error.
    SafeBootMin: PCI Configuration - Driver Group
    SafeBootMin: PNP Filter - Driver Group
    SafeBootMin: Primary disk - Driver Group
    SafeBootMin: sacsvr - Service
    SafeBootMin: SCSI Class - Driver Group
    SafeBootMin: System Bus Extender - Driver Group
    SafeBootMin: vmms - Service
    SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
    SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
    SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
    SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
    SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
    SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
    SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
    SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
    SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
    SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
    SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
    SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
    SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
    SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
    SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
    SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
    SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
     
    SafeBootNet:64bit: 71720608.sys - Driver
    SafeBootNet:64bit: AppMgmt - Service
    SafeBootNet:64bit: Base - Driver Group
    SafeBootNet:64bit: Boot Bus Extender - Driver Group
    SafeBootNet:64bit: Boot file system - Driver Group
    SafeBootNet:64bit: File system - Driver Group
    SafeBootNet:64bit: Filter - Driver Group
    SafeBootNet:64bit: HelpSvc - Service
    SafeBootNet:64bit: MCODS - Reg Error: Value error.
    SafeBootNet:64bit: Messenger - Service
    SafeBootNet:64bit: mfehidk - C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
    SafeBootNet:64bit: mfehidk.sys - C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
    SafeBootNet:64bit: mfevtp - C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.)
    SafeBootNet:64bit: MsMpSvc - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
    SafeBootNet:64bit: NDIS Wrapper - Driver Group
    SafeBootNet:64bit: NetBIOSGroup - Driver Group
    SafeBootNet:64bit: NetDDEGroup - Driver Group
    SafeBootNet:64bit: Network - Driver Group
    SafeBootNet:64bit: NetworkProvider - Driver Group
    SafeBootNet:64bit: PCI Configuration - Driver Group
    SafeBootNet:64bit: PNP Filter - Driver Group
    SafeBootNet:64bit: PNP_TDI - Driver Group
    SafeBootNet:64bit: Primary disk - Driver Group
    SafeBootNet:64bit: rdsessmgr - Service
    SafeBootNet:64bit: sacsvr - Service
    SafeBootNet:64bit: SCSI Class - Driver Group
    SafeBootNet:64bit: Streams Drivers - Driver Group
    SafeBootNet:64bit: System Bus Extender - Driver Group
    SafeBootNet:64bit: TDI - Driver Group
    SafeBootNet:64bit: vmms - Service
    SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
    SafeBootNet:64bit: WudfUsbccidDriver - Driver
    SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
    SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
    SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
    SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
    SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
    SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
    SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
    SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
    SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
    SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
    SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
    SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
    SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
    SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
    SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
    SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
    SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
    SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
    SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
    SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
    SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
    SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
    SafeBootNet: 71720608.sys - Driver
    SafeBootNet: AppMgmt - Service
    SafeBootNet: Base - Driver Group
    SafeBootNet: Boot Bus Extender - Driver Group
    SafeBootNet: Boot file system - Driver Group
    SafeBootNet: File system - Driver Group
    SafeBootNet: Filter - Driver Group
    SafeBootNet: HelpSvc - Service
    SafeBootNet: MCODS - Reg Error: Value error.
    SafeBootNet: Messenger - Service
    SafeBootNet: NDIS Wrapper - Driver Group
    SafeBootNet: NetBIOSGroup - Driver Group
    SafeBootNet: NetDDEGroup - Driver Group
    SafeBootNet: Network - Driver Group
    SafeBootNet: NetworkProvider - Driver Group
    SafeBootNet: PCI Configuration - Driver Group
    SafeBootNet: PNP Filter - Driver Group
    SafeBootNet: PNP_TDI - Driver Group
    SafeBootNet: Primary disk - Driver Group
    SafeBootNet: rdsessmgr - Service
    SafeBootNet: sacsvr - Service
    SafeBootNet: SCSI Class - Driver Group
    SafeBootNet: Streams Drivers - Driver Group
    SafeBootNet: System Bus Extender - Driver Group
    SafeBootNet: TDI - Driver Group
    SafeBootNet: vmms - Service
    SafeBootNet: WudfUsbccidDriver - Driver
    SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
    SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
    SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
    SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
    SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
    SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
    SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
    SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
    SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
    SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
    SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
    SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
    SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
    SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
    SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
    SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
    SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
    SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
    SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
    SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
    SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
    SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
     
    ActiveX:64bit: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
    ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
    ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
    ActiveX:64bit: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
    ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
    ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
    ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
    ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
    ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
    ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
    ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
    ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
    ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
    ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
    ActiveX:64bit: {7DEBE4EB-6B40-3766-BB35-5CBBC385DA37} - .NET Framework
    ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
    ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig
    ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
    ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
    ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
    ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
    ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
    ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
    ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
    ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
    ActiveX:64bit: >{5916DEE9-1435-4865-86A1-F5019AF2749C} - RunDLL32 IEDKCS32.DLL,BrandIE4 CUSTOM
    ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
    ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
    ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
    ActiveX: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
    ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
    ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
    ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
    ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
    ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
    ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
    ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
    ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
    ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
    ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
    ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
    ActiveX: {7DEBE4EB-6B40-3766-BB35-5CBBC385DA37} - .NET Framework
    ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
    ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - 
    ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
    ActiveX: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
    ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
    ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
    ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
    ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
    ActiveX: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
    ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
     
    Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.l3codec - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
     
    CREATERESTOREPOINT
    System Restore Service not available.
     
    ========== Files/Folders - Created Within 60 Days ==========
     
    [2014/04/28 00:08:50 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\User\Desktop\OTL (1).exe
    [2014/04/27 23:07:53 | 000,000,000 | ---D | C] -- C:\FRST
    [2014/04/27 22:59:14 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
    [2014/04/27 22:20:19 | 000,000,000 | ---D | C] -- C:\AdwCleaner
    [2014/04/27 22:14:37 | 002,925,760 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Users\User\Desktop\procexp.exe
    [2014/04/27 22:12:20 | 002,061,824 | ---- | C] (Farbar) -- C:\Users\User\Desktop\FRST64.exe
    [2014/04/27 22:11:43 | 001,016,261 | ---- | C] (Thisisu) -- C:\Users\User\Desktop\JRT.exe
    [2014/04/27 14:05:03 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\InstallShield
    [2014/04/27 13:47:07 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Akamai
    [2014/04/27 00:39:10 | 000,264,616 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
    [2014/04/27 00:38:55 | 000,096,168 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
    [2014/04/27 00:38:54 | 000,175,528 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
    [2014/04/27 00:38:54 | 000,175,016 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
    [2014/04/26 14:08:14 | 000,184,800 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\mfevtps.exe
    [2014/04/25 01:02:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    [2014/04/25 00:31:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
    [2014/04/25 00:31:11 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
    [2014/04/13 15:28:29 | 000,000,000 | -HSD | C] -- C:\Users\User\AppData\Local\EmieUserList
    [2014/04/13 15:28:29 | 000,000,000 | -HSD | C] -- C:\Users\User\AppData\Local\EmieSiteList
    [2014/04/10 03:10:11 | 000,574,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
    [2014/04/10 03:10:11 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
    [2014/04/10 03:09:40 | 000,548,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
    [2014/04/10 03:09:17 | 000,586,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
    [2014/04/10 03:09:17 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
    [2014/04/10 03:09:17 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
    [2014/04/10 03:09:17 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
    [2014/04/10 03:09:14 | 000,752,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
    [2014/04/10 03:09:13 | 000,453,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
    [2014/04/10 03:09:13 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
    [2014/04/10 03:09:13 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
    [2014/04/10 03:09:12 | 000,628,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
    [2014/04/10 03:09:12 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
    [2014/04/10 03:09:11 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
    [2014/04/10 03:09:11 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
    [2014/04/10 03:09:11 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
    [2014/04/10 03:09:11 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
    [2014/04/10 03:09:11 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
    [2014/04/10 03:09:11 | 000,032,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
    [2014/04/10 03:09:08 | 000,940,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
    [2014/04/10 03:09:08 | 000,846,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
    [2014/04/10 03:09:08 | 000,704,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
    [2014/04/10 03:09:08 | 000,592,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
    [2014/04/10 03:09:08 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
    [2014/04/10 03:09:08 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
    [2014/04/10 03:09:08 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
    [2014/04/10 03:09:06 | 002,043,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
    [2014/04/10 03:09:06 | 001,967,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
    [2014/04/10 03:09:04 | 005,784,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
    [2014/04/10 00:59:01 | 000,190,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\storport.sys
    [2014/04/10 00:59:01 | 000,027,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Diskdump.sys
    [2014/04/10 00:59:01 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iologmsg.dll
    [2014/04/10 00:59:01 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iologmsg.dll
    [2014/04/10 00:58:58 | 001,163,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
    [2014/04/10 00:58:58 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
    [2014/04/10 00:58:58 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
    [2014/04/10 00:58:58 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
    [2014/04/10 00:58:58 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll
    [2014/04/10 00:58:58 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
    [2014/04/10 00:58:58 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
    [2014/04/10 00:58:58 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
    [2014/04/10 00:58:58 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
    [2014/04/10 00:58:58 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
    [2014/04/06 09:53:32 | 000,119,512 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
    [2014/04/06 09:53:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    [2014/04/06 09:53:10 | 000,088,280 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
    [2014/04/06 09:53:10 | 000,063,192 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
    [2014/04/06 09:53:10 | 000,025,816 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2014/04/06 09:53:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
    [2014/04/06 09:53:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
    [2014/04/05 16:45:01 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\Symantec
    [2014/03/30 16:13:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
    [2014/03/30 15:02:00 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
    [2014/03/30 15:02:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel
    [2014/03/30 14:58:15 | 000,000,000 | ---D | C] -- C:\Users\User\Intel
    [2014/03/25 22:58:36 | 000,312,744 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\javaws.exe
    [2014/03/25 22:58:08 | 000,189,352 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\javaw.exe
    [2014/03/25 22:58:08 | 000,189,352 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\java.exe
    [2014/03/25 22:58:08 | 000,108,968 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\WindowsAccessBridge-64.dll
    [2014/03/25 22:53:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
    [2014/03/25 22:53:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
    [2014/03/25 22:52:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
    [2014/03/25 09:57:22 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\NPE
    [2014/03/25 00:48:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel® Processor ID Utility
    [2014/03/25 00:48:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Intel Corporation
    [2014/03/25 00:39:02 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AMD Gaming Evolved
    [2014/03/25 00:38:21 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\library_dir
    [2014/03/25 00:37:56 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Raptr
    [2014/03/25 00:35:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Raptr
    [2014/03/25 00:25:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SystemRequirementsLab
    [2014/03/25 00:24:43 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\SystemRequirementsLab
    [2014/03/23 14:51:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Symantec Shared
    [2014/03/23 14:19:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
    [2014/03/23 14:19:28 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
    [2014/03/20 00:56:46 | 000,484,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wer.dll
    [2014/03/20 00:56:46 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wer.dll
    [2014/03/20 00:54:46 | 000,624,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qedit.dll
    [2014/03/20 00:54:46 | 000,509,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qedit.dll
    [2014/03/20 00:54:44 | 001,424,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecs.dll
    [2014/03/11 09:52:30 | 000,133,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\NisDrvWFP.sys
    [2014/03/03 23:26:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    [2014/03/03 23:24:48 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
    [2014/03/03 23:24:46 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
    [2014/03/03 23:24:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
    [2014/03/03 23:24:46 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
    [2014/03/03 23:14:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
    [2014/03/03 23:13:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
    [2014/02/28 11:35:29 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\FINAL Agreements
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
     
    ========== Files - Modified Within 60 Days ==========
     
    [2014/04/28 00:08:53 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\OTL (1).exe
    [2014/04/28 00:05:01 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2014/04/28 00:04:12 | 000,119,512 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
    [2014/04/27 23:48:12 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3830866668-548323272-1850177600-1000UA.job
    [2014/04/27 23:47:34 | 000,033,415 | ---- | M] () -- C:\test.xml
    [2014/04/27 23:37:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2014/04/27 22:51:04 | 000,021,200 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2014/04/27 22:51:04 | 000,021,200 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2014/04/27 22:43:09 | 000,008,192 | ---- | M] () -- C:\Windows\SysWow64\WDPABKP.dat
    [2014/04/27 22:42:13 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2014/04/27 22:41:50 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2014/04/27 22:41:40 | 998,092,758 | ---- | M] () -- C:\Windows\MEMORY.DMP
    [2014/04/27 22:41:40 | 522,096,639 | -HS- | M] () -- C:\hiberfil.sys
    [2014/04/27 22:14:47 | 002,925,760 | ---- | M] (Sysinternals - www.sysinternals.com) -- C:\Users\User\Desktop\procexp.exe
    [2014/04/27 22:14:09 | 000,061,440 | ---- | M] ( ) -- C:\Users\User\Desktop\VEW.exe
    [2014/04/27 22:13:46 | 004,009,167 | ---- | M] () -- C:\Users\User\Desktop\ServicesRepair.exe
    [2014/04/27 22:12:31 | 002,061,824 | ---- | M] (Farbar) -- C:\Users\User\Desktop\FRST64.exe
    [2014/04/27 22:11:52 | 001,016,261 | ---- | M] (Thisisu) -- C:\Users\User\Desktop\JRT.exe
    [2014/04/27 22:10:50 | 001,329,501 | ---- | M] () -- C:\Users\User\Desktop\AdwCleaner.exe
    [2014/04/27 14:53:44 | 000,002,279 | ---- | M] () -- C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
    [2014/04/27 01:48:01 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3830866668-548323272-1850177600-1000Core.job
    [2014/04/27 00:38:13 | 000,096,168 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
    [2014/04/27 00:38:09 | 000,264,616 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
    [2014/04/27 00:38:08 | 000,175,528 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
    [2014/04/27 00:38:07 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
    [2014/04/25 01:02:39 | 000,002,255 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
    [2014/04/25 00:32:07 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
    [2014/04/06 09:53:15 | 000,001,102 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2014/04/05 19:16:36 | 000,007,597 | ---- | M] () -- C:\Users\User\AppData\Local\Resmon.ResmonCfg
    [2014/04/03 09:51:16 | 000,063,192 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
    [2014/04/03 09:51:04 | 000,088,280 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
    [2014/04/03 09:50:58 | 000,025,816 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2014/03/25 22:57:40 | 000,312,744 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\javaws.exe
    [2014/03/25 22:57:40 | 000,189,352 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\javaw.exe
    [2014/03/25 22:57:40 | 000,189,352 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\java.exe
    [2014/03/25 22:57:40 | 000,108,968 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\WindowsAccessBridge-64.dll
    [2014/03/23 23:45:02 | 005,003,504 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
    [2014/03/20 00:37:30 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
    [2014/03/20 00:37:29 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    [2014/03/12 23:56:21 | 004,698,964 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2014/03/12 23:56:21 | 002,172,548 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2014/03/12 23:56:21 | 000,006,206 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2014/03/11 09:52:30 | 000,133,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\NisDrvWFP.sys
    [2014/03/06 10:31:33 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
    [2014/03/06 09:59:04 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
    [2014/03/06 09:57:34 | 000,548,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
    [2014/03/06 09:57:20 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
    [2014/03/06 09:39:09 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
    [2014/03/06 09:32:38 | 000,574,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
    [2014/03/06 09:29:40 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
    [2014/03/06 09:29:14 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
    [2014/03/06 09:28:15 | 000,752,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
    [2014/03/06 09:15:54 | 000,940,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
    [2014/03/06 09:11:41 | 005,784,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
    [2014/03/06 09:09:51 | 000,453,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
    [2014/03/06 09:03:58 | 000,586,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
    [2014/03/06 09:02:34 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
    [2014/03/06 09:01:01 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
    [2014/03/06 08:56:43 | 000,038,400 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
    [2014/03/06 08:48:35 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
    [2014/03/06 08:45:39 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
    [2014/03/06 08:42:24 | 000,296,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
    [2014/03/06 08:40:32 | 000,440,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
    [2014/03/06 08:38:13 | 000,112,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
    [2014/03/06 08:36:40 | 000,592,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
    [2014/03/06 08:21:40 | 000,628,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
    [2014/03/06 08:13:43 | 000,032,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
    [2014/03/06 08:11:15 | 002,043,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
    [2014/03/06 08:07:28 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
    [2014/03/06 07:40:39 | 001,967,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
    [2014/03/06 06:50:22 | 000,846,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
    [2014/03/06 06:43:59 | 000,704,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
    [2014/03/05 22:33:41 | 000,001,197 | ---- | M] () -- C:\Users\Public\Desktop\WD Security.lnk
    [2014/03/04 10:44:21 | 000,362,496 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
    [2014/03/04 10:44:21 | 000,243,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
    [2014/03/04 10:44:21 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
    [2014/03/04 10:44:03 | 000,016,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll
    [2014/03/04 10:44:00 | 001,163,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
    [2014/03/04 10:17:19 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
    [2014/03/04 10:16:54 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
    [2014/03/04 10:16:18 | 000,005,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
    [2014/03/04 09:09:30 | 000,007,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
    [2014/03/04 09:09:29 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
    [2014/03/03 23:26:12 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
     
    ========== Files Created - No Company Name ==========
     
    [2014/04/27 22:41:40 | 998,092,758 | ---- | C] () -- C:\Windows\MEMORY.DMP
    [2014/04/27 22:14:08 | 000,061,440 | ---- | C] ( ) -- C:\Users\User\Desktop\VEW.exe
    [2014/04/27 22:13:24 | 004,009,167 | ---- | C] () -- C:\Users\User\Desktop\ServicesRepair.exe
    [2014/04/27 22:10:38 | 001,329,501 | ---- | C] () -- C:\Users\User\Desktop\AdwCleaner.exe
    [2014/04/25 01:02:39 | 000,002,279 | ---- | C] () -- C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
    [2014/04/25 01:02:39 | 000,002,255 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
    [2014/04/25 00:32:07 | 000,001,945 | ---- | C] () -- C:\Windows\epplauncher.mif
    [2014/04/25 00:31:56 | 000,002,117 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
    [2014/04/19 12:34:47 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\WDPABKP.dat
    [2014/04/18 07:02:49 | 000,001,141 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Update.lnk
    [2014/04/06 09:53:14 | 000,001,102 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2014/03/05 22:33:41 | 000,001,197 | ---- | C] () -- C:\Users\Public\Desktop\WD Security.lnk
    [2014/03/03 23:26:12 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
    [2013/07/06 14:51:50 | 000,000,132 | ---- | C] () -- C:\Users\User\AppData\Roaming\Adobe BMP Format CS5 Prefs
    [2013/07/06 14:45:17 | 000,001,456 | ---- | C] () -- C:\Users\User\AppData\Local\Adobe Save for Web 12.0 Prefs
    [2013/05/31 15:00:37 | 000,000,132 | ---- | C] () -- C:\Users\User\AppData\Roaming\Adobe PNG Format CS5 Prefs
    [2013/05/15 23:03:13 | 000,007,597 | ---- | C] () -- C:\Users\User\AppData\Local\Resmon.ResmonCfg
    [2013/02/17 19:11:39 | 000,000,132 | ---- | C] () -- C:\Users\User\AppData\Roaming\Adobe GIF Format CS5 Prefs
    [2012/12/16 14:46:16 | 000,000,162 | ---- | C] () -- C:\Windows\ODBC.INI
    [2012/12/06 15:15:36 | 000,155,136 | ---- | C] () -- C:\Windows\SysWow64\AI_ContextMenu.dll
    [2012/11/21 20:33:42 | 000,321,288 | ---- | C] () -- C:\Program Files (x86)\Common Files\Sanpya.ttf
    [2012/11/13 17:04:16 | 000,164,352 | ---- | C] () -- C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2012/06/07 13:48:09 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
    [2012/05/30 08:13:01 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
     
    ========== ZeroAccess Check ==========
     
    [2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
     
    [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
     
    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
     
    [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
     
    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
     
    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
    "" = C:\Windows\SysNative\shell32.dll -- [2013/07/26 03:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment
     
    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
    "" = %SystemRoot%\system32\shell32.dll -- [2013/07/26 02:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment
     
    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012/08/21 14:11:31 | 000,857,088 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free
     
    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
    "" = %systemroot%\system32\wbem\fastprox.dll -- [2012/08/21 14:37:44 | 000,636,928 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free
     
    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012/08/21 14:08:38 | 000,453,120 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Both
     
    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
     
    ========== Custom Scans ==========
     
    ========== Drive Information ==========
     
    Physical Drives
    ---------------
     
    Error accessing drive info (0)
    Error accessing drive info (0)
     
    Partitions
    ---------------
     
    Error accessing partition info (0)
    Error accessing partition info (0)
     
    < %SYSTEMDRIVE%\*.exe >
    [2007/11/07 08:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
     
    < %systemroot%\assembly\GAC_32\*.ini >
     
    < %systemroot%\assembly\GAC_64\*.ini >
     
    < %SYSTEMDRIVE%\*.exe >
    [2007/11/07 08:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
     
    < %ALLUSERSPROFILE%\Application Data\*.exe >
     
    < %APPDATA%\*. >
    [2013/07/06 14:44:51 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Adobe
    [2013/01/06 04:52:51 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Adobe Mini Bridge CS5.1
    [2012/12/06 15:19:37 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Aimersoft Video Converter Ultimate
    [2013/01/14 17:29:13 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Apple Computer
    [2014/03/16 19:46:50 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\ArcSoft
    [2014/02/16 15:52:20 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Atheros
    [2012/05/30 08:59:58 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\ATI
    [2013/01/04 14:04:51 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\AusLogics
    [2013/10/12 01:36:30 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\BBCiPlayerDownloads
    [2014/04/27 22:56:42 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\BitTorrent
    [2013/04/24 16:35:22 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Canon
    [2012/05/30 09:11:29 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\CyberLink
    [2012/06/02 00:54:35 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DAEMON Tools Lite
    [2014/03/16 19:28:26 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Dropbox
    [2014/02/06 01:35:16 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DropboxMaster
    [2013/09/06 00:20:25 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\FlacSquisher
    [2013/04/23 16:50:05 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\HMRC
    [2013/01/14 17:35:56 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\HTC
    [2013/01/14 17:35:46 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\HTC Sync
    [2013/01/14 17:31:50 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
    [2012/05/30 08:59:32 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Identities
    [2014/04/27 14:05:03 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\InstallShield
    [2012/05/30 09:00:04 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Intel Corporation
    [2014/03/25 00:38:21 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\library_dir
    [2012/05/30 08:25:32 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Macromedia
    [2012/08/26 15:04:43 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\McAfee
    [2011/03/15 03:36:01 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Media Center Programs
    [2014/04/26 18:08:48 | 000,000,000 | --SD | M] -- C:\Users\User\AppData\Roaming\Microsoft
    [2012/06/01 15:49:12 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Mozilla
    [2013/12/19 11:03:45 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Outlook
    [2012/06/17 12:51:46 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\PACE Anti-Piracy
    [2012/08/20 16:45:14 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Pamela
    [2012/08/21 20:34:50 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Pamela Call Recorder
    [2014/03/25 00:39:09 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Raptr
    [2012/07/01 00:13:50 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Research In Motion
    [2014/01/31 23:53:12 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Skype
    [2012/06/17 23:14:23 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\skypePM
    [2012/06/16 22:31:26 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\SoftGrid Client
    [2014/03/16 19:46:51 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Sony Corporation
    [2014/03/16 19:46:51 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Spotify
    [2013/01/06 04:52:50 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
    [2013/12/27 15:12:42 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\SyncTunesDesktop
    [2014/03/25 00:24:43 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\SystemRequirementsLab
    [2012/06/02 11:56:37 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TP
    [2014/04/27 22:16:52 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\vlc
     
    < MD5 for: ATAPI.SYS  >
    [2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
    [2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_552ea5111ec825a6\atapi.sys
    [2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
    [2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
    [2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.18231_none_3b457059383c66e6\atapi.sys
    [2009/07/14 02:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.22414_none_3be7afc0514717fa\atapi.sys
     
    < MD5 for: CSRSS.EXE  >
    [2009/07/14 02:39:02 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=60C2862B4BF0FD9F582EF344C2B1EC72 -- C:\Windows\SysNative\csrss.exe
    [2009/07/14 02:39:02 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=60C2862B4BF0FD9F582EF344C2B1EC72 -- C:\Windows\winsxs\amd64_microsoft-windows-csrss_31bf3856ad364e35_6.1.7600.16385_none_b4d8d57efdc6b4f3\csrss.exe
     
    < MD5 for: EXPLORER.EXE  >
    [2011/02/26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
    [2011/02/25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
    [2011/02/25 07:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
    [2011/02/26 07:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
    [2010/11/21 04:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
    [2011/02/25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
    [2011/02/25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
    [2010/11/21 04:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
     
    < MD5 for: MSWSOCK.DLL  >
    [2010/11/21 04:24:00 | 000,326,144 | ---- | M] (Microsoft Corporation) MD5=1D5185A4C7E6695431AE4B55C3D7D333 -- C:\Windows\winsxs\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.17514_none_16795c7543eb48cf\mswsock.dll
    [2013/09/07 03:04:16 | 000,231,424 | ---- | M] (Microsoft Corporation) MD5=6547D445C4B69DC0083B619AC642DF04 -- C:\Windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.22444_none_bac3d364a4c3ea89\mswsock.dll
    [2010/11/21 04:24:09 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=8999B8631C7FD9F7F9EC3CAFD953BA24 -- C:\Windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.17514_none_ba5ac0f18b8dd799\mswsock.dll
    [2013/09/08 03:27:14 | 000,327,168 | ---- | M] (Microsoft Corporation) MD5=9A9F9F1A77D6A80EE28B57664F00013E -- C:\Windows\SysNative\mswsock.dll
    [2013/09/08 03:27:14 | 000,327,168 | ---- | M] (Microsoft Corporation) MD5=9A9F9F1A77D6A80EE28B57664F00013E -- C:\Windows\winsxs\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.18254_none_164e004b440bdabf\mswsock.dll
    [2013/09/07 03:24:39 | 000,327,168 | ---- | M] (Microsoft Corporation) MD5=BDDB1FD258B92DEE00F222D3304B5D9C -- C:\Windows\winsxs\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.22444_none_16e26ee85d215bbf\mswsock.dll
    [2013/09/08 03:03:58 | 000,231,424 | ---- | M] (Microsoft Corporation) MD5=E94C583CDE2348950155F2AF2876F34D -- C:\Windows\SysWOW64\mswsock.dll
    [2013/09/08 03:03:58 | 000,231,424 | ---- | M] (Microsoft Corporation) MD5=E94C583CDE2348950155F2AF2876F34D -- C:\Windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.18254_none_ba2f64c78bae6989\mswsock.dll
     
    < MD5 for: NAPINSP.DLL  >
    [2009/07/14 02:16:02 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=0B7E85364CB878E2AD531DB7B601A9E5 -- C:\Windows\SysWOW64\NapiNSP.dll
    [2009/07/14 02:16:02 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=0B7E85364CB878E2AD531DB7B601A9E5 -- C:\Windows\winsxs\x86_microsoft-windows-n..ider-infrastructure_31bf3856ad364e35_6.1.7600.16385_none_abf396ebf0847c31\NapiNSP.dll
    [2009/07/14 02:41:52 | 000,068,096 | ---- | M] (Microsoft Corporation) MD5=58A0CDABEA255616827B1C22C9994466 -- C:\Windows\SysNative\NapiNSP.dll
    [2009/07/14 02:41:52 | 000,068,096 | ---- | M] (Microsoft Corporation) MD5=58A0CDABEA255616827B1C22C9994466 -- C:\Windows\winsxs\amd64_microsoft-windows-n..ider-infrastructure_31bf3856ad364e35_6.1.7600.16385_none_0812326fa8e1ed67\NapiNSP.dll
     
    < MD5 for: NLAAPI.DLL  >
    [2012/01/13 08:12:03 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=0BA65122FFA7E37564EE86422DBF7AE8 -- C:\Windows\SysWOW64\nlaapi.dll
    [2012/01/13 08:12:03 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=0BA65122FFA7E37564EE86422DBF7AE8 -- C:\Windows\winsxs\wow64_microsoft-windows-nlasvc_31bf3856ad364e35_6.1.7601.17964_none_cfca9d84561311f2\nlaapi.dll
    [2010/11/21 04:24:01 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=104A1070E90F1C530328E69B49718841 -- C:\Windows\winsxs\wow64_microsoft-windows-nlasvc_31bf3856ad364e35_6.1.7601.17514_none_d000a58855ea91a1\nlaapi.dll
    [2012/10/03 17:29:27 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=11B8C7970C10650827D060AA81BEE63F -- C:\Windows\winsxs\wow64_microsoft-windows-nlasvc_31bf3856ad364e35_6.1.7601.22124_none_d07f52216f10753a\nlaapi.dll
    [2010/11/21 04:23:54 | 000,070,656 | ---- | M] (Microsoft Corporation) MD5=2DF36F15B2BC1571A6A542A3C2107920 -- C:\Windows\winsxs\amd64_microsoft-windows-nlasvc_31bf3856ad364e35_6.1.7601.17514_none_c5abfb362189cfa6\nlaapi.dll
    [2012/10/03 18:44:21 | 000,070,656 | ---- | M] (Microsoft Corporation) MD5=46BB91A169B9B31FF44EB04C48EC1D41 -- C:\Windows\SysNative\nlaapi.dll
    [2012/10/03 18:44:21 | 000,070,656 | ---- | M] (Microsoft Corporation) MD5=46BB91A169B9B31FF44EB04C48EC1D41 -- C:\Windows\winsxs\amd64_microsoft-windows-nlasvc_31bf3856ad364e35_6.1.7601.17964_none_c575f33221b24ff7\nlaapi.dll
    [2012/10/03 18:32:48 | 000,070,656 | ---- | M] (Microsoft Corporation) MD5=C98BCE54F31113D5E736C1097FD086DC -- C:\Windows\winsxs\amd64_microsoft-windows-nlasvc_31bf3856ad364e35_6.1.7601.22124_none_c62aa7cf3aafb33f\nlaapi.dll
     
    < MD5 for: PNRPNSP.DLL  >
    [2009/07/14 02:16:12 | 000,065,024 | ---- | M] (Microsoft Corporation) MD5=5CF640EDDB1E40A5AB1BB743BCDEC610 -- C:\Windows\SysWOW64\pnrpnsp.dll
    [2009/07/14 02:16:12 | 000,065,024 | ---- | M] (Microsoft Corporation) MD5=5CF640EDDB1E40A5AB1BB743BCDEC610 -- C:\Windows\winsxs\wow64_microsoft-windows-peertopeerpnrp_31bf3856ad364e35_6.1.7600.16385_none_d7c8b1ac70865dab\pnrpnsp.dll
    [2009/07/14 02:41:53 | 000,086,016 | ---- | M] (Microsoft Corporation) MD5=613C8CE10A5FDE582BA5FA64C4D56AAA -- C:\Windows\SysNative\pnrpnsp.dll
    [2009/07/14 02:41:53 | 000,086,016 | ---- | M] (Microsoft Corporation) MD5=613C8CE10A5FDE582BA5FA64C4D56AAA -- C:\Windows\winsxs\amd64_microsoft-windows-peertopeerpnrp_31bf3856ad364e35_6.1.7600.16385_none_cd74075a3c259bb0\pnrpnsp.dll
     
    < MD5 for: PRINTISOLATIONHOST.EXE  >
    [2009/07/14 02:39:27 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=22F020C76E339EB2B2187BA73A7E4173 -- C:\Windows\SysNative\PrintIsolationHost.exe
    [2009/07/14 02:39:27 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=22F020C76E339EB2B2187BA73A7E4173 -- C:\Windows\winsxs\amd64_microsoft-windows-p..ng-server-isolation_31bf3856ad364e35_6.1.7600.16385_none_f8a40495785334a9\PrintIsolationHost.exe
     
    < MD5 for: SERVICES.EXE  >
    [2009/07/14 02:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
    [2009/07/14 02:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
     
    < MD5 for: SVCHOST.EXE  >
    [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
    [2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
    [2014/04/03 09:49:02 | 000,742,200 | ---- | M] (MalwareBytes) MD5=96820649733BFB2B0499C371904B7B40 -- C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\svchost.exe
    [2009/07/14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
    [2009/07/14 02:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
     
    < MD5 for: USER32.DLL  >
    [2010/11/21 04:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\SysWOW64\user32.dll
    [2010/11/21 04:24:20 | 000,833,024 | ---- | M] (Microsoft Corporation) MD5=5E0DB2D8B2750543CD2EBB9EA8E6CDD3 -- C:\Windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
    [2010/11/21 04:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\SysNative\user32.dll
    [2010/11/21 04:24:09 | 001,008,128 | ---- | M] (Microsoft Corporation) MD5=FE70103391A64039A921DBFFF9C7AB1B -- C:\Windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_2b5e71b083fc0973\user32.dll
     
    < MD5 for: USERINIT.EXE  >
    [2010/11/21 04:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
    [2010/11/21 04:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
    [2010/11/21 04:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
    [2010/11/21 04:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe
     
    < MD5 for: WINLOGON.EXE  >
    [2010/11/21 04:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
    [2010/11/21 04:24:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
    [2014/04/03 09:49:02 | 000,742,200 | ---- | M] (MalwareBytes) MD5=96820649733BFB2B0499C371904B7B40 -- C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\winlogon.exe
     
    < MD5 for: WINRNR.DLL  >
    [2009/07/14 02:41:56 | 000,028,672 | ---- | M] (Microsoft Corporation) MD5=2E2072EB48238FCA8FBB7A9F5FABAC45 -- C:\Windows\SysNative\winrnr.dll
    [2009/07/14 02:41:56 | 000,028,672 | ---- | M] (Microsoft Corporation) MD5=2E2072EB48238FCA8FBB7A9F5FABAC45 -- C:\Windows\winsxs\amd64_microsoft-windows-dns-client-winrnr_31bf3856ad364e35_6.1.7600.16385_none_b543449669c73e11\winrnr.dll
    [2009/07/14 02:16:19 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=5DF5D8CFD9B9573FA3B2C89D9061A240 -- C:\Windows\SysWOW64\winrnr.dll
    [2009/07/14 02:16:19 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=5DF5D8CFD9B9573FA3B2C89D9061A240 -- C:\Windows\winsxs\x86_microsoft-windows-dns-client-winrnr_31bf3856ad364e35_6.1.7600.16385_none_5924a912b169ccdb\winrnr.dll
     
    < MD5 for: WSHELPER.DLL  >
    [2009/07/14 02:16:20 | 000,015,360 | ---- | M] (Microsoft Corporation) MD5=5B90BB3171504C9DAF3C5CB44B203CA7 -- C:\Windows\SysWOW64\wshelper.dll
    [2009/07/14 02:16:20 | 000,015,360 | ---- | M] (Microsoft Corporation) MD5=5B90BB3171504C9DAF3C5CB44B203CA7 -- C:\Windows\winsxs\wow64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6ace9e67456cc40b\wshelper.dll
    [2009/07/14 02:41:58 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=D314DA4B0B8DCD023D547FC568E34FB6 -- C:\Windows\SysNative\wshelper.dll
    [2009/07/14 02:41:58 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=D314DA4B0B8DCD023D547FC568E34FB6 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\wshelper.dll
     
    < C:\Windows\assembly\tmp\U\*.* /s >
     
    < %systemroot%\*. /mp /s >
     
    < hklm\software\clients\startmenuinternet|command /rs >
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2014/03/30 16:15:05 | 000,878,024 | ---- | M] (Mozilla Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2014/03/30 16:15:05 | 000,878,024 | ---- | M] (Mozilla Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2014/03/30 16:15:05 | 000,878,024 | ---- | M] (Mozilla Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" [2014/03/30 16:15:09 | 000,275,568 | ---- | M] (Mozilla Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -preferences [2014/03/30 16:15:09 | 000,275,568 | ---- | M] (Mozilla Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -safe-mode [2014/03/30 16:15:09 | 000,275,568 | ---- | M] (Mozilla Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [2014/04/24 01:33:15 | 000,841,032 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --hide-icons [2014/04/24 01:33:15 | 000,841,032 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --show-icons [2014/04/24 01:33:15 | 000,841,032 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [2014/04/24 01:33:15 | 000,841,032 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2014/03/08 03:34:14 | 000,809,680 | ---- | M] (Microsoft Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2014/03/08 03:34:14 | 000,809,680 | ---- | M] (Microsoft Corporation)
     
    < hklm\software\clients\startmenuinternet|command /64 /rs >
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /HIDESHORTCUTS [2014/03/30 16:15:05 | 000,878,024 | ---- | M] (Mozilla Corporation)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /SHOWSHORTCUTS [2014/03/30 16:15:05 | 000,878,024 | ---- | M] (Mozilla Corporation)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /SETASDEFAULTAPPGLOBAL [2014/03/30 16:15:05 | 000,878,024 | ---- | M] (Mozilla Corporation)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE" [2014/03/30 16:15:09 | 000,275,568 | ---- | M] (Mozilla Corporation)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE" -PREFERENCES [2014/03/30 16:15:09 | 000,275,568 | ---- | M] (Mozilla Corporation)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE" -SAFE-MODE [2014/03/30 16:15:09 | 000,275,568 | ---- | M] (Mozilla Corporation)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --MAKE-DEFAULT-BROWSER [2014/04/24 01:33:15 | 000,841,032 | ---- | M] (Google Inc.)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --HIDE-ICONS [2014/04/24 01:33:15 | 000,841,032 | ---- | M] (Google Inc.)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --SHOW-ICONS [2014/04/24 01:33:15 | 000,841,032 | ---- | M] (Google Inc.)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" [2014/04/24 01:33:15 | 000,841,032 | ---- | M] (Google Inc.)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -SHOW [2014/03/06 09:03:58 | 000,586,240 | ---- | M] (Microsoft Corporation)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -REINSTALL [2014/03/06 09:03:58 | 000,586,240 | ---- | M] (Microsoft Corporation)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -HIDE [2014/03/06 09:03:58 | 000,586,240 | ---- | M] (Microsoft Corporation)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE" -EXTOFF [2014/03/08 03:34:14 | 000,809,680 | ---- | M] (Microsoft Corporation)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE [2014/03/08 03:34:14 | 000,809,680 | ---- | M] (Microsoft Corporation)
     
    < %systemroot%\system32\*.dll /lockedfiles >
     
    < %systemroot%\Tasks\*.job /lockedfiles >
     
    < %ProgramFiles%\WINDOWS NT\*.* /s >
    [2010/11/21 04:24:51 | 004,247,040 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\WINDOWS NT\Accessories\wordpad.exe
    [2009/07/14 02:16:20 | 000,194,560 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\WINDOWS NT\Accessories\WordpadFilter.dll
    [2012/05/29 17:29:55 | 000,051,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\WINDOWS NT\Accessories\en-US\wordpad.exe.mui
    [2009/07/14 02:16:15 | 000,325,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\WINDOWS NT\TableTextService\TableTextService.dll
    [2009/06/10 22:43:18 | 000,016,212 | ---- | M] () -- C:\Program Files (x86)\WINDOWS NT\TableTextService\TableTextServiceAmharic.txt
    [2009/06/10 22:43:18 | 001,272,822 | ---- | M] () -- C:\Program Files (x86)\WINDOWS NT\TableTextService\TableTextServiceArray.txt
    [2009/06/10 22:43:18 | 000,980,102 | ---- | M] () -- C:\Program Files (x86)\WINDOWS NT\TableTextService\TableTextServiceDaYi.txt
    [2009/06/10 22:43:19 | 001,665,878 | ---- | M] () -- C:\Program Files (x86)\WINDOWS NT\TableTextService\TableTextServiceSimplifiedQuanPin.txt
    [2009/06/10 22:43:19 | 001,445,430 | ---- | M] () -- C:\Program Files (x86)\WINDOWS NT\TableTextService\TableTextServiceSimplifiedShuangPin.txt
    [2009/06/10 22:43:19 | 001,810,352 | ---- | M] () -- C:\Program Files (x86)\WINDOWS NT\TableTextService\TableTextServiceSimplifiedZhengMa.txt
    [2009/06/10 22:43:19 | 000,044,968 | ---- | M] () -- C:\Program Files (x86)\WINDOWS NT\TableTextService\TableTextServiceYi.txt
    [2012/05/29 17:29:48 | 000,008,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\WINDOWS NT\TableTextService\en-US\TableTextService.dll.mui
     
    < %systemroot%\system32\drivers\*.sys /lockedfiles >
     
    ========== Alternate Data Streams ==========
     
    @Alternate Data Stream - 1271 bytes -> C:\Users\User\AppData\Local\Temp:sPSLPOi4WsC0ctmUEBkwI
     
    < End of report >
     
     
     
    Extras Log:
     
    OTL Extras logfile created on: 28/04/2014 00:13:03 - Run 2
    OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\User\Desktop
    64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.11.9600.17041)
    Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
     
    5.98 Gb Total Physical Memory | 4.26 Gb Available Physical Memory | 71.20% Memory free
    11.96 Gb Paging File | 9.41 Gb Available in Paging File | 78.65% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]
     
    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 580.58 Gb Total Space | 12.23 Gb Free Space | 2.11% Space Free | Partition Type: NTFS
     
    Computer Name: *****-VAIO | User Name: User | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days
     
    ========== Extra Registry (All) ==========
     
     
    ========== File Associations ==========
     
    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
    .cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation)
    .hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
    .hta[@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
    .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
    .inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
    .ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
    .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
    .js[@ = jsfile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
    .jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
    .reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation)
    .txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
    .vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
    .vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
    .wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
    .wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
     
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .bat [@ = batfile] -- "%1" %*
    .chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
    .cmd [@ = cmdfile] -- "%1" %*
    .com [@ = comfile] -- "%1" %*
    .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
    .exe [@ = exefile] -- "%1" %*
    .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
    .hta [@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
    .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
    .inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
    .ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
    .url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation)
    .js [@ = jsfile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
    .jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
    .pif [@ = piffile] -- "%1" %*
    .reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)
    .scr [@ = scrfile] -- "%1" /S
    .txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
    .vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
    .vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
    .wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
    .wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
     
    [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
     
    ========== Shell Spawning ==========
     
    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
    batfile [open] -- "%1" %*
    batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
    chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
    cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
    cmdfile [open] -- "%1" %*
    cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
    htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
    htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
    htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
    http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
    inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
    inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
    inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
    InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
    jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
    jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
    jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
    jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
    jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
    jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
    regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
    regfile [merge] -- Reg Error: Key error.
    regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
    txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
    txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
    vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
    vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
    vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
    vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
    vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
    vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
    wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
    wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
    wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
    wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
    Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~4\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
    Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
     
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
    batfile [open] -- "%1" %*
    batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
    chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
    cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
    cmdfile [open] -- "%1" %*
    cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
    htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
    htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
    htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
    http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
    inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
    inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
    inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
    InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
    jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
    jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
    jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
    jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
    jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
    jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
    regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
    regfile [merge] -- Reg Error: Key error.
    regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
    txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
    txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
    vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
    vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
    vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
    vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
    vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
    vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
    wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
    wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
    wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
    wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
    Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~4\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
    Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
     
    ========== Security Center Settings ==========
     
    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
     
    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
     
    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0
     
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
     
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
     
    ========== Firewall Settings ==========
     
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0
     
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0
     
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "EnableFirewall" = 1
    "DisableNotifications" = 0
     
    ========== Authorized Applications List ==========
     
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Program Files (x86)\TriDef 3D\TriDef\TriDefMediaPlayer\TriDefMediaPlayer.exe" = C:\Program Files (x86)\TriDef 3D\TriDef\TriDefMediaPlayer\TriDefMediaPlayer.exe:*:Enabled:TriDef 3D Media Player -- (DDD Group Plc.)
    "C:\Program Files (x86)\TriDef 3D\TriDef\TriDefMediaPlayer\TriDefMediaPlayer.exe" = C:\Program Files (x86)\TriDef 3D\TriDef\TriDefMediaPlayer\TriDefMediaPlayer.exe:*:Enabled:TriDef 3D Media Player -- (DDD Group Plc.)
     
     
    ========== Vista Active Open Ports Exception List ==========
     
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{10049F75-1FB1-4667-A7EA-C339CB7D6955}" = lport=10243 | protocol=6 | dir=in | app=system | 
    "{1074BF6A-2A2A-48F5-94EF-18B024F11ABC}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
    "{12C871EF-DFBA-40EA-8BFD-6AF625FD2AB6}" = rport=445 | protocol=6 | dir=out | app=system | 
    "{19FC1346-9D35-4141-9E5B-6AA2B86F3DC1}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | 
    "{1F36B572-6F25-4A33-986D-544FF6C07A59}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
    "{1FBFA983-C6EF-4402-A923-DB265EF6FBAD}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | 
    "{20FA47BF-75E1-4D21-9370-C5F4EA6EACB5}" = lport=4482 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer | 
    "{29B2AD74-54E8-4FB2-91E6-5CCA25F23C27}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
    "{410F4735-ECAA-4FF7-9BAF-4A516CEC96C8}" = lport=445 | protocol=6 | dir=in | app=system | 
    "{444BC271-4E59-4494-8295-C6FD46F5729D}" = lport=2869 | protocol=6 | dir=in | app=system | 
    "{47175370-E1B6-41CE-9B80-C8B0E2FCFEAD}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
    "{4F71B09C-EAA0-4CB9-A4F7-DB6A2BDBF295}" = lport=137 | protocol=17 | dir=in | app=system | 
    "{51802FBF-FD46-4D7F-99EA-5ECAB6137E3E}" = rport=138 | protocol=17 | dir=out | app=system | 
    "{580AFCD3-5F88-40B4-8022-7E899926CB22}" = lport=4481 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer | 
    "{5F3CE311-16B6-4C05-8B9C-C5A7D74489FD}" = lport=80 | protocol=6 | dir=in | app=c:\program files\sony\vaio smart network\wfda\wifidirectapplication.exe | 
    "{5F63F210-2FDB-4B76-B26C-9812B04AA677}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
    "{63F1B5A6-C255-462A-86AF-E468D99F9F56}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
    "{684D05E3-E651-4C89-8A19-72B0DF4A9DE2}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
    "{73922989-570C-41A1-91EF-8046A85982A2}" = rport=10243 | protocol=6 | dir=out | app=system | 
    "{8313FD41-3B07-4B4F-BA72-E70E2520AF00}" = lport=139 | protocol=6 | dir=in | app=system | 
    "{911F8E0B-2F1B-4933-AC12-96EB443661C2}" = lport=4482 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery | 
    "{9A1A375A-5737-4E2B-BB08-40D57865D087}" = rport=137 | protocol=17 | dir=out | app=system | 
    "{A48E1D1E-B0C6-4D0F-8BE8-67D6C119EA3A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
    "{ABC718EB-F52B-403C-A022-6BE1F6BA3E79}" = lport=4481 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery | 
    "{B71CCC05-3B04-4D03-8084-67FE837CEFED}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
    "{C0812C1F-2CF4-486B-88F1-4CA231997F59}" = lport=138 | protocol=17 | dir=in | app=system | 
    "{C182BD05-E17F-4228-9F4D-77C4C8A60311}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 | 
    "{C8635932-3C35-4AE9-8145-CA61B8D8D373}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
    "{D1265D21-41CD-4B40-A841-07F286829C0B}" = lport=53 | protocol=17 | dir=in | app=c:\program files\sony\vaio smart network\wfda\dcdhcpservice.exe | 
    "{E9C62649-4A72-41F6-9505-8D4A55E83619}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
    "{EE505331-C93F-4A20-8765-3F95C9FD1A8B}" = lport=7935 | protocol=6 | dir=in | name=adobe flash builder 4.5 | 
    "{FC348606-1C70-4087-8F44-138E0D7A06E3}" = rport=139 | protocol=6 | dir=out | app=system | 
     
    ========== Vista Active Application Exception List ==========
     
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{005211B5-743A-4031-AE69-5C861B47BC16}" = protocol=17 | dir=in | app=c:\program files (x86)\research in motion\blackberry desktop\rim.desktop.exe | 
    "{0293F36F-0E66-435C-8DD7-44FD3DEE78C5}" = protocol=6 | dir=in | app=c:\users\user\appdata\roaming\bittorrent\bittorrent.exe | 
    "{05AFA060-2BDD-4337-936E-0B2CDA73C15C}" = protocol=17 | dir=in | app=c:\program files\sony\vaio smart network\wfda\wifidirectapplication.exe | 
    "{074188EE-4FA3-4016-8AE0-0BCC39FFADE3}" = protocol=6 | dir=in | app=c:\program files\sony\vaio care\vaiocaremain.exe | 
    "{07C59952-0DDD-40D7-95B8-F89AB6204DBF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
    "{098CA95E-8006-417E-BB41-78FE3ABA8E5E}" = protocol=1 | dir=in | [email protected],-28543 | 
    "{0A8B6D06-EF3E-4F99-8C2F-9EA5CFAE2635}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
    "{11EF2B87-49D8-4F70-BDCF-7AC8AC521F64}" = protocol=1 | dir=out | [email protected],-28544 | 
    "{120CAC1A-743C-4028-961F-DFDF77348E96}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
    "{120F8F38-60E9-4959-857D-6C999697D780}" = protocol=6 | dir=in | app=c:\program files (x86)\raptr\raptr_im.exe | 
    "{1A878681-DC33-4970-B359-F2A6624AC545}" = protocol=6 | dir=in | app=c:\program files\sony\vaio smart network\wfda\wifidirectapplication.exe | 
    "{1F21DC27-8A55-4DB4-9DFA-D66BC6360821}" = protocol=17 | dir=in | app=c:\users\user\appdata\roaming\dropbox\bin\dropbox.exe | 
    "{23B94829-7F4A-4866-BFC8-9F9E554EE7E2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
    "{243B06FA-4629-431C-97EC-FC1ADF98247D}" = protocol=17 | dir=in | app=c:\program files\sony\vaio care\vcagent.exe | 
    "{27528D1D-5069-41A0-BB1C-EBA828552B31}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
    "{28D78817-5976-4AE0-A1C2-A3A91E4801AE}" = protocol=17 | dir=in | app=c:\program files (x86)\adobe\adobe flash builder 4.5\flashbuilder.exe | 
    "{28DFA6B1-4D2F-4557-9660-99C99E6BD6E0}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | 
    "{304B06B7-1369-46DA-B468-5AC4AD308578}" = protocol=58 | dir=in | [email protected],-28545 | 
    "{34425323-6E1B-4278-A478-B3EC7A3B3C76}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
    "{35800C8E-9359-42C1-B991-735E69661895}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
    "{3DB8EB5F-453B-4915-8E4A-03EFA15AEC2F}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd9.exe | 
    "{4483410C-F4C4-41B5-89FF-E825F1F0EC90}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
    "{454A47DF-F2FF-406C-9785-D00AC813ADBD}" = protocol=17 | dir=in | app=c:\program files (x86)\raptr\raptr_im.exe | 
    "{456F5986-07D4-45C5-9021-4B50FBE7812F}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
    "{500760F6-94DE-4E49-889F-52CF5A95208B}" = protocol=58 | dir=out | [email protected],-28546 | 
    "{54B1BC0A-3E45-4BE2-B68C-75E778D99E49}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
    "{660F65D3-AB76-43D9-986E-A6FF02D30CE5}" = protocol=6 | dir=in | app=c:\program files\sony\vaio smart network\wfda\wifidirectapplication.exe | 
    "{6D24AA29-3B09-471B-ACCF-27F958187396}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
    "{77FAEC8B-DC03-46A3-8A51-E37BB5530703}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
    "{7A3B9205-D16A-405E-AA42-4E2B7403A74F}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
    "{8011BA1C-187B-43FB-A28E-A0E5054BE42A}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
    "{8109F27F-C6F3-401D-BB15-6DD643EE86C6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
    "{835742EF-50FC-4F49-9B6A-AF53BF5ECB3D}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
    "{8FBAFBEB-56D3-41D2-83DB-FC8D890268BF}" = protocol=17 | dir=in | app=c:\program files\sony\vaio care\selfhealupdate.exe | 
    "{92D49FF6-7968-4663-8D55-56092CBC85EC}" = protocol=6 | dir=in | app=c:\program files (x86)\raptr\raptr.exe | 
    "{9837BD3D-C58C-4BD8-9E2B-0B9F38A57176}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
    "{A499EA9A-2FB0-47B2-A771-7D2B3913B734}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
    "{A91CC8AE-526F-4F02-BF16-8BEF77411A83}" = protocol=6 | dir=in | app=c:\users\user\appdata\roaming\dropbox\bin\dropbox.exe | 
    "{A9628B82-535F-4230-8933-9EDAC2D22E52}" = protocol=17 | dir=in | app=c:\users\user\appdata\roaming\bittorrent\bittorrent.exe | 
    "{AC5BEA35-C61C-462B-B8E8-C36EFB9B7858}" = protocol=6 | dir=in | app=c:\program files (x86)\adobe\adobe flash builder 4.5\flashbuilder.exe | 
    "{B137F7E5-08D3-4190-92F7-AC6B303003E4}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | 
    "{B9D7436B-E8C5-40B8-957A-B9C24B9D60D5}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
    "{C426A08C-D280-485A-BE61-18B35C8F7D8C}" = protocol=17 | dir=in | app=c:\program files\sony\vaio care\vaiocaremain.exe | 
    "{CA592A07-ACDC-40B5-BC0A-36F66DCFF7B9}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | 
    "{CB787E23-D5D6-4657-B128-E6C78F56239C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
    "{CD22DEB0-EBF7-486D-A98E-A0060D2FF21C}" = dir=in | app=c:\program files (x86)\htc\htc sync manager\htcsyncmanager.exe | 
    "{D1658C5F-B0E7-4FB2-BC61-0A33B42E2FBE}" = protocol=17 | dir=in | app=c:\program files\sony\vaio smart network\wfda\wifidirectapplication.exe | 
    "{D63B188F-E527-49B0-98A5-D14AB91F94EE}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
    "{D763E87C-2C13-4D64-B8AA-0496BCC9E5AC}" = protocol=6 | dir=in | app=c:\program files (x86)\research in motion\blackberry desktop\rim.desktop.exe | 
    "{D9920AD7-BEE5-460D-957F-21AA18B72AB1}" = protocol=6 | dir=in | app=c:\program files\sony\vaio care\vcagent.exe | 
    "{E16DF0A0-375C-4CC5-9F03-90E720D061FF}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | 
    "{E74D58F5-0EB1-4FB5-97B9-941AF5639D29}" = protocol=17 | dir=in | app=c:\program files (x86)\raptr\raptr.exe | 
    "{F28614A6-3C71-49B2-B120-71F572774D72}" = protocol=6 | dir=in | app=c:\program files\sony\vaio care\selfhealupdate.exe | 
    "{FD90CF77-E7DC-47DF-B70B-4026C7B44FD4}" = protocol=6 | dir=out | app=system | 
    "TCP Query User{9601A321-2D80-43F5-A78D-343F9B0DFB78}C:\users\user\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\user\appdata\local\akamai\netsession_win.exe | 
    "TCP Query User{F168DC5A-0499-478E-9232-43DDC79A608A}C:\users\user\appdata\roaming\spotify\spotify.exe" = protocol=6 | dir=in | app=c:\users\user\appdata\roaming\spotify\spotify.exe | 
    "UDP Query User{9C8C0706-21C9-414C-805F-F96EF963F0A3}C:\users\user\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\user\appdata\local\akamai\netsession_win.exe | 
    "UDP Query User{B79285B9-B86C-41CE-97A5-047995BAD2A7}C:\users\user\appdata\roaming\spotify\spotify.exe" = protocol=17 | dir=in | app=c:\users\user\appdata\roaming\spotify\spotify.exe | 
     
    ========== HKEY_LOCAL_MACHINE Uninstall List ==========
     
    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{115B60D5-BBDB-490E-AF2E-064D37A3CE01}" = Media Gallery
    "{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP140_series" = Canon MP140 series
    "{133D3F07-D558-46CE-80E8-F4D75DBBAD63}" = PMB VAIO Edition Plug-in
    "{1685AE50-97ED-485B-80F6-145071EE14B0}" = Windows Live Remote Service Resources
    "{17A4FD95-A507-43F1-BC92-D8572AF8340A}" = Windows Live Remote Service Resources
    "{19F09425-3C20-4730-9E2A-FC2E17C9F362}" = Windows Live Remote Service Resources
    "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
    "{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
    "{1EB2CFC3-E1C5-4FC4-B1F8-549DD6242C67}" = Windows Live Remote Service Resources
    "{22AB5CFD-B3DB-414E-9F99-4D024CCF1DA6}" = Windows Live Remote Client Resources
    "{230D1595-57DA-4933-8C4E-375797EBB7E1}" = Bluetooth Win7 Suite (64)
    "{2426E29F-9E8C-4C0B-97FC-0DB690C1ED98}" = Windows Live Remote Client Resources
    "{26A24AE4-039D-4CA4-87B4-2F86417051FF}" = Java 7 Update 51 (64-bit)
    "{2C1A6191-9804-4FDC-AB01-6F9183C91A13}" = Windows Live Remote Client Resources
    "{2F304EF4-0C31-47F4-8557-0641AAE4197C}" = Windows Live Remote Client Resources
    "{312395BC-7CC2-434C-A660-30250276A926}" = SSLx64
    "{34384A2A-2CA2-4446-AB0E-1F360BA2AAC5}" = Windows Live Remote Service Resources
    "{34C6812E-E231-4B13-9DAC-21E06ECA864A}" = WD SmartWare
    "{3921492E-82D2-4180-8124-E347AD2F2DB4}" = Windows Live Remote Client Resources
    "{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
    "{480F28F0-8BCE-404A-A52E-0DBB7D1CE2EF}" = Windows Live Remote Service Resources
    "{4C2E49C0-9276-4324-841D-774CCCE5DB48}" = Windows Live Remote Client Resources
    "{4EFA8109-732B-4026-9F0C-B70ECF3F9293}" = Windows Live Remote Service Resources
    "{4F31AC31-0A28-4F5A-8416-513972DA1F79}" = Sony Corporation
    "{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
    "{5141AA6E-5FAC-4473-BFFB-BEE69DDC7F2B}" = Windows Live Remote Service Resources
    "{5151E2DB-0748-4FD1-86A2-72E2F94F8BE7}" = Windows Live Remote Service Resources
    "{57F2BD1C-14A3-4785-8E48-2075B96EB2DF}" = Windows Live Remote Service Resources
    "{5E2CD4FB-4538-4831-8176-05D653C3E6D4}" = Windows Live Remote Service Resources
    "{5F44A3A1-5D24-4708-8776-66B42B174C64}" = Windows Live Remote Client Resources
    "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
    "{5FEAD3E5-A158-4B66-B92B-0C959D7CF838}" = Windows Live Remote Service Resources
    "{61407251-7F7D-4303-810D-226A04D5CFF3}" = Windows Live Remote Service Resources
    "{63486834-B10B-4DD4-8216-C8D66A157D7E}_is1" = FMRTE 5.2.5
    "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
    "{692CCE55-9EAE-4F57-A834-092882E7FE0B}" = Windows Live Remote Client Resources
    "{6B7DE186-374B-4873-AEC1-7464DA337DD6}" = VU5x64
    "{6C9D3F1D-DBBE-46F9-96A0-726CC72935AF}" = Windows Live Remote Service Resources
    "{6CBFDC3C-CF21-4C02-A6DC-A5A2707FAF55}" = Windows Live Remote Service Resources
    "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
    "{75C95C84-264F-4CC7-8A7E-346444E6C7C1}" = VAIO Improvement Validation
    "{787136D2-F0F8-4625-AA3F-72D7795AC842}" = Apple Mobile Device Support
    "{7AEC844D-448A-455E-A34E-E1032196BBCD}" = Windows Live Remote Service Resources
    "{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1
    "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
    "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
    "{850B8072-2EA7-4EDC-B930-7FE569495E76}" = Windows Live Remote Client Resources
    "{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
    "{8970AE69-40BE-4058-9916-0ACB1B974A3D}" = Windows Live Remote Client Resources
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
    "{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
    "{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
    "{90BF0360-A1DB-4599-A643-95AB90A52C1E}" = Microsoft_VC90_MFCLOC_x86_x64
    "{918EC75F-50C3-52A9-FB2A-04A9BF1193FE}" = ccc-utility64
    "{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
    "{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
    "{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
    "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{99E6C2F3-59B2-4308-B1CD-4928B55B7E30}" = VGClientX64
    "{9E9C960F-7F47-46D5-A95D-950B354DE2B8}" = Windows Live Remote Service Resources
    "{9F672527-2BE4-47AB-B061-C057BDE30B30}" = Windows Live Remote Client Resources
    "{A060182D-CDBE-4AD6-B9B4-860B435D6CBD}" = Windows Live Remote Client Resources
    "{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
    "{B750FA38-7AB0-42CB-ACBB-E7DBE9FF603F}" = Windows Live Remote Client Resources
    "{B8BA155B-1E75-405F-9CB4-8A99615D09DC}" = iTunes
    "{BF3C5FE1-FD86-A14D-8EC2-6488D646515E}" = ATI Catalyst Install Manager
    "{BFAE8D5B-F918-486F-B74E-90762DF11C5C}" = Microsoft Security Client
    "{C504EC13-E122-4939-BD6E-EE5A3BAA5FEC}" = Windows Live Remote Client Resources
    "{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
    "{C9F05151-95A9-4B9B-B534-1760E2D014A5}" = Windows Live Remote Client Resources
    "{CD95F661-A5C4-44F5-A6AA-ECDD91C240D5}" = WinZip 16.5
    "{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
    "{D1C1556C-7FF3-48A3-A5D6-7126F0FAFB66}" = Windows Live Remote Client Resources
    "{D55EAC07-7207-44BD-B524-0F063F327743}" = VIx64
    "{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources
    "{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources
    "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
    "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319
    "{DBEAA361-F8A4-4298-B41C-9E9DCB9AAB84}" = VPMx64
    "{DBEDAF67-C5A3-4C91-951D-31F3FE63AF3F}" = Windows Live Remote Client Resources
    "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
    "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
    "{ED421F97-E1C3-4E78-9F54-A53888215D58}" = Windows Live Remote Client Resources
    "{EF79C448-6946-4D71-8134-03407888C054}" = Shared C Run-time for x64
    "{F1DC5C16-9B1F-467B-85E3-CB48C27AC50D}" = VESx64
    "{F2611404-06BF-4E67-A5B7-8DB2FFC1CBF6}" = VSNx64
    "{F6CB2C5F-B2C1-4DF1-BF44-39D0DC06FE6F}" = Windows Live Remote Service Resources
    "EPSON SX110 Series" = EPSON SX110 Series Printer Uninstall
    "Microsoft Security Client" = Microsoft Security Essentials
    "SynTPDeinstKey" = Synaptics Pointing Device Driver
     
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{007F778D-F15C-4EAB-AE92-071D21FAF632}" = Adobe Photoshop Elements 9
    "{00884F14-05BD-4D8E-90E5-1ABF78948CA4}" = Windows Live Mesh
    "{0125DB4D-98A0-4DBF-B68A-23BF08FFA6A3}" = Windows Live Messenger
    "{0145A2C2-D0D5-8D26-BD2C-C9F24DB57997}" = CCC Help Italian
    "{024521CF-C07E-4F8E-8481-0D75695E03AF}" = PxMergeModule
    "{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
    "{039480EE-6933-4845-88B8-77FD0C3D059D}" = Windows Live Mesh
    "{046885A1-B4AE-4459-A0D1-8C93706698D6}" = 
    "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
    "{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1" = MiniTool Partition Wizard Home Edition 8.1.1
    "{05E379CC-F626-4E7D-8354-463865B303BF}" = Windows Live UX Platform Language Pack
    "{0654EA5D-308A-4196-882B-5C09744A5D81}" = Windows Live Photo Common
    "{07441A52-E208-478A-92B7-5C337CA8C131}" = VAIO - Remote Play with PlayStation®3
    "{0899D75A-C2FC-42EA-A702-5B9A5F24EAD5}" = VAIO Smart Network
    "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
    "{08D7BC86-7358-464C-8AD0-0D84B5F0A0C9}" = Remote Keyboard
    "{09922FFE-D153-44AE-8B60-EA3CB8088F93}" = Windows Live UX Platform Language Pack
    "{09B7C7EB-3140-4B5E-842F-9C79A7137139}" = Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger
    "{0A9256E0-C924-46DE-921B-F6C4548A1C64}" = Windows Live Messenger
    "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
    "{0C1931EB-8339-4837-8BEC-75029BF42734}" = Windows Live UX Platform Language Pack
    "{0C975FCC-A06E-4CB6-8F54-A9B52CF37781}" = Windows Liven sähköposti
    "{0EC0B576-90F9-43C3-8FAD-A4902DF4B8F4}" = Galeria de Fotografias do Windows Live
    "{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
    "{10186F1A-6A14-43DF-A404-F0105D09BB07}" = Windows Live Mail
    "{10446D2D-F5D8-3155-0277-226C4FCF9B85}" = CCC Help Hungarian
    "{110668B7-54C6-47C9-BAC4-1CE77F156AF5}" = Windows Live Mesh
    "{111EE7DF-FC45-40C7-98A7-753AC46B12FB}" = QuickTime 7
    "{11417707-1F72-4279-95A3-01E0B898BBF5}" = Windows Live Mesh
    "{11778DA1-0495-4ED9-972F-F9E0B0367CD5}" = Windows Live Writer
    "{1203DC60-D9BD-44F9-B372-2B8F227E6094}" = Windows Live Temel Parçalar
    "{133D9D67-D475-4407-AC3C-D558087B2453}" = Windows Live Movie Maker
    "{14B441B7-774D-4170-98EA-A13667AE6218}" = Windows Live Writer Resources
    "{168E7302-890A-4138-9109-A225ACAF7AD1}" = Windows Live Photo Common
    "{17835B63-8308-427F-8CF5-D76E0D5FE457}" = Windows Live Essentials
    "{1798D459-6B8B-474B-868D-1229EADA3B95}" = Adobe AIR
    "{17F99FCE-8F03-4439-860A-25C5A5434E18}" = Windows Live Essentials
    "{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
    "{198DFB43-9C28-4204-93ED-1545E3E467B8}" = BBC iPlayer Downloads
    "{198EA334-8A3F-4CB2-9D61-6C10B8168A6F}" = Windows Live Writer
    "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
    "{1A72337E-D126-4BAF-AC89-E6122DB71866}" = Windows Liven valokuvavalikoima
    "{1B0545C4-620F-4661-A369-C4D113F24932}" = Windows Live Writer Resources
    "{1DA6D447-C54D-4833-84D4-3EA31CAECE9B}" = Windows Live UX Platform Language Pack
    "{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources
    "{1EBDF6D2-CEA0-484C-A23E-2DDAD7FD0DD0}" = System Requirements Lab for Intel
    "{1ec9e03a-452b-48fb-8e1b-27ee0477985f}" = WD SmartWare Installer
    "{1EDFEB81-EC04-3598-53F4-59AB2DD4D55D}" = CCC Help Russian
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{1F659865-1E3C-6E3B-4948-AE793AE74448}" = BBC iPlayer Desktop
    "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
    "{1FC83EAE-74C8-4C72-8400-2D8E40A017DE}" = Windows Live Writer
    "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
    "{21DD6041-7251-40FA-9D06-C5EB30268E0F}" = Qualcomm Atheros Direct Connect
    "{220C7F8C-929D-4F71-9DC7-F7A6823B38E4}" = Windows Live UX Platform Language Pack
    "{2303F9E7-6293-4A85-BC21-CA226FAD5CE4}" = Windows Live Mail
    "{241E7104-937A-4366-AD57-8FDDDB003939}" = Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi
    "{24DF33E0-F924-4D0D-9B96-11F28F0D602D}" = Windows Live UX Platform Language Pack
    "{24F62D16-78DC-29C2-7009-E373E44B4462}" = CCC Help Dutch
    "{25175695-4B20-4298-9F34-C2C57CD277B3}" = Elements STI Installer
    "{25A381E1-0AB9-4E7A-ACCE-BA49D519CF4E}" = Windows Live Mail
    "{25CD4B12-8CC5-433E-B723-C9CB41FA8C5A}" = Windows Live Writer
    "{260E3D78-94E6-47EC-8E29-46301572BB1E}" = Control ActiveX Windows Live Mesh pentru conexiuni la distanță
    "{26A24AE4-039D-4CA4-87B4-2F83217055FF}" = Java 7 Update 55
    "{26E3C07C-7FF7-4362-9E99-9E49E383CF16}" = Windows Live Writer Resources
    "{270380EB-8812-42E1-8289-53700DB840D2}" = PMB VAIO Edition Plug-in
    "{28B9D2D8-4304-483F-AD71-51890A063A74}" = Windows Live Photo Common
    "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
    "{2A07C35B-8384-4DA4-9A95-442B6C89A073}" = Windows Live Essentials
    "{2AD2DD70-27F7-4343-BB4E-DE50A32D854B}" = Windows Live Messenger
    "{2BA5FD10-653F-4CAF-9CCD-F685082A1DC1}" = Windows Live Writer
    "{2C7E8AA1-9C03-4606-BF34-5D99D07964DA}" = Windows Live Messenger
    "{2C8FBAB0-4564-47B8-AC4B-9C7401B94BF2}" = Основи Windows Live
    "{2D3E034E-F76B-410A-A169-55755D2637BB}" = Windows Live Mesh
    "{2E50E321-4747-4EB5-9ECB-BBC6C3AC0F31}" = Windows Live Writer Resources
    "{303143DD-1F6D-4BC5-9342-FFC2E19B2DBD}" = Windows Live Messenger
    "{3125D9DE-8D7A-4987-95F3-8A42389833D8}" = Windows Live Writer Resources
    "{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver
    "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
    "{339F9B4D-00CB-4C1C-BED8-EC86A9AB602A}" = PMB VAIO Edition Guide
    "{34319F1F-7CF2-4CC9-B357-1AE7D2FF3AC5}" = Windows Live
    "{34C4F5AF-D757-4E6A-ABCA-65AB5A50A1A8}" = Windows Live Messenger
    "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
    "{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
    "{36C5BBF0-E5BF-4DE1-B684-7E90B0C93FB5}" = VAIO Care
    "{370F888E-42A7-4911-9E34-7D74632E17EB}" = Windows Live Photo Common
    "{376D59B1-42D9-4FA2-B6CC-E346B6BE14F5}" = ActiveX-kontroll för fjärranslutningar för Windows Live Mesh
    "{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack
    "{39BDD209-5704-480C-9F4A-B69D0370DDBB}" = Windows Live Messenger
    "{39F95B0B-A0B7-4FA7-BB6C-197DA2546468}" = Windows Live Mesh
    "{3A26D9BD-0F73-432D-B522-2BA18138F7EF}" = VAIO Improvement
    "{3A94F54D-A8A4-4B82-B346-92B4D56A2708}" = VESx86
    "{3B9A92DA-6374-4872-B646-253F18624D5F}" = Windows Live Writer
    "{3C1F2A28-4F20-D366-4DB7-1A64BB1BD6FC}" = CCC Help Portuguese
    "{3D0C22FA-96D7-4789-BC5B-991A5A99BFFA}" = Windows Live Messenger
    "{3F4143A1-9C21-4011-8679-3BC1014C6886}" = Windows Live Mesh
    "{40BFD84C-64CD-42CC-9909-8734C50429C6}" = Windows Live UX Platform Language Pack
    "{4264C020-850B-4F08-ACBE-98205D9C336C}" = Windows Live Writer
    "{429DF1A0-3610-4E9E-8ACE-3C8AC1BA8FCA}" = Windows Live Photo Gallery
    "{433EACD8-4747-4A6A-826A-FFA9F39B0D40}" = Elements 9 Organizer
    "{4444F27C-B1A8-464E-9486-4C37BAB39A09}" = Фотогалерия на Windows Live
    "{458F399F-62AC-4747-99F5-499BBF073D29}" = Windows Live Writer Resources
    "{46872828-6453-4138-BE1C-CE35FBF67978}" = Windows Live Mesh
    "{488F0347-C4A7-4374-91A7-30818BEDA710}" = Galerie de photos Windows Live
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4A04DB63-8F81-4EF4-9D09-61A2057EF419}" = Windows Live Essentials
    "{4B28D47A-5FF0-45F8-8745-11DC2A1C9D0F}" = Windows Live Writer
    "{4C378B16-46B7-4DA1-A2CE-2EE676F74680}" = Windows Live UX Platform Language Pack
    "{4C49125B-7048-F17B-6EA0-6AF96B0F5B17}" = CCC Help Norwegian
    "{4CF6F287-5121-483C-A5A2-07BDE19D8B4E}" = Windows Live Meshin etäyhteyksien ActiveX-komponentti
    "{4E33D05D-76CF-5D3C-4D5D-7727530FA161}" = Adobe Content Viewer
    "{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.11
    "{4F8F4A0D-3913-3780-DEA3-7B7762B07A28}" = CCC Help Japanese
    "{50300123-F8FC-4B50-B449-E847D04F1BA2}" = Windows Live Messenger
    "{506FC723-8E6C-4417-9CFF-351F99130425}" = Windows Live UX Platform Language Pack
    "{523DF2BB-3A85-4047-9898-29DC8AEB7E69}" = Windows Live UX Platform Language Pack
    "{5275D81E-83AD-4DE4-BC2B-6E6BA3A33244}" = Windows Live Writer Resources
    "{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
    "{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI
    "{547C9EB4-4CA6-402F-9D1B-8BD30DC71E44}" = VAIO Sample Contents
    "{55D003F4-9599-44BF-BA9E-95D060730DD3}" = Contrôle ActiveX Windows Live Mesh pour connexions à distance
    "{57220148-3B2B-412A-A2E0-82B9DF423696}" = Windows Live Mesh ActiveX-objekt til fjernforbindelser
    "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
    "{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}" = VAIO Data Restore Tool
    "{5A92468F-3ED8-4F96-A9E1-4F176C80EC29}" = VAIO Quick Web Access
    "{5C2F5C1B-9732-4F81-8FBF-6711627DC508}" = Windows Live Fotogalleri
    "{5D2E7BD7-4B6F-4086-BA8A-E88484750624}" = Windows Live Writer Resources
    "{5DC3BFF3-B84F-4CBE-B2BD-FB52B6C247CA}" = HTC Sync Manager
    "{5DDAFB4B-C52E-468A-9E23-3B0CEEB671BF}" = VAIO Transfer Support
    "{5E627606-53B9-42D1-97E1-D03F6229E248}" = Windows Live UX Platform Language Pack
    "{5FA51AAF-23FE-42F4-A724-D79F85F41D4B}" = Remote Play with PlayStation 3
    "{6057E21C-ABE9-4059-AE3E-3BEB9925E660}" = Windows Live Messenger
    "{60C3C026-DB53-4DAB-8B97-7C1241F9A847}" = Windows Live Movie Maker
    "{611D7ADA-572B-5E9A-A0C6-5750444EF0BE}" = CCC Help Swedish
    "{61438020-DDD4-42FA-99A2-50225441980A}" = ArcSoft Magic-i Visual Effects 2
    "{62687B11-58B5-4A18-9BC3-9DF4CE03F194}" = Windows Live Writer Resources
    "{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
    "{63911503-7EA4-4685-B2FD-D391EF622FB9}" = WD Quick View
    "{63C43435-F428-42BA-8E7B-5848749D9262}" = SSLx86
    "{63CF7D0C-B6E7-4EE9-8253-816B613CC437}" = Windows Live Mail
    "{63F2FE22-8AB6-3AFE-70AA-72F54522F0B4}" = CCC Help Finnish
    "{640798A0-A4FB-4C52-AC72-755134767F1E}" = Windows Live Movie Maker
    "{64376910-1860-4CEF-8B34-AA5D205FC5F1}" = Poczta usługi Windows Live
    "{64614A1E-2FF0-5373-8649-C6DBF3781656}" = CCC Help Czech
    "{6491AB99-A11E-41FD-A5E7-32DE8A097B8E}" = Windows Live Essentials
    "{64B2D6B3-71AC-45A7-A6A1-2E07ABF58341}" = Windows Live Movie Maker
    "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
    "{66390CD0-C1E7-E454-2C4B-AC620D38BDFE}" = CCC Help Spanish
    "{6748E773-5DA0-4D19-8AA5-273B4133A09B}" = SmartSound Quicktracks for Premiere Elements 9.0
    "{6756D5CA-3E31-4308-9BF0-79DFD1AF196E}" = Елемент керування Windows Live Mesh ActiveX для віддалених підключень
    "{677AAD91-1790-4FC5-B285-0E6A9D65F7DC}" = Windows Live Mail
    "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
    "{6986737B-F286-40D1-87AF-938339DCF6AB}" = Windows Live Messenger
    "{69C5DC3C-1366-56E1-6B59-CFAECE4A264B}" = CCC Help Korean
    "{69CAC24D-B1DC-4B97-A1BE-FE21843108FE}" = Windows Live Writer Resources
    "{6A4ABCDC-0A49-4132-944E-01FBCCB3465C}" = Windows Live UX Platform Language Pack
    "{6A563426-3474-41C6-B847-42B39F1485B2}" = Windows Live Messenger
    "{6ABE832B-A5C7-44C1-B697-3E123B7B4D5B}" = Windows Live Mesh
    "{6AC57EEF-2733-4DE6-81BB-E78ACB964C22}" = Windows Live Photo Common
    "{6D30E864-46AE-435B-8230-8B5D42B4AE37}" = Windows Live Messenger
    "{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer
    "{6DEC8BD5-7574-47FA-B080-492BBBE2FEA3}" = Windows Live Movie Maker
    "{6E29C4F7-C2C2-4B18-A15C-E09B92065F15}" = Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz
    "{6EE9F44A-B8C7-4CDB-B2A9-441AF2AE315A}" = Windows Live Messenger
    "{6EF2BE2C-3121-48B7-B7A6-C56046B3A588}" = Windows Live Movie Maker
    "{6F37D92B-41AA-44B7-80D2-457ABDE11896}" = Windows Live Photo Common
    "{7068A606-15DC-370B-9825-4CA06865022F}" = CCC Help English
    "{70991E0A-1108-437E-BA7D-085702C670C0}" = 
    "{70EED410-697B-4193-A2CB-2F790F82B420}" = VAIO Data Restore Tool
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{71A81378-79D5-40CC-9BDC-380642D1A87F}" = Windows Live Writer
    "{71C95134-F6A9-45E7-B7B3-07CA6012BF2A}" = Windows Live Mesh
    "{71EFACDE-B62C-B680-314C-664A89EF452B}" = CCC Help French
    "{72042FA6-5609-489F-A8EA-3C2DD650F667}" = VAIO Control Center
    "{7272F232-A7E0-4B2B-A5D2-71B7C5E2379C}" = Windows Live Fotótár
    "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
    "{734104DE-C2BF-412F-BB97-FCCE1EC94229}" = Windows Live Writer Resources
    "{7373E17D-18E0-44A7-AC3A-6A3BFB85D3B3}" = Windows Live Movie Maker
    "{7396FB15-9AB4-4B78-BDD8-24A9C15D2C65}" = VAIO - Remote Keyboard
    "{73D8886A-D416-4687-B609-0D3836BA410C}" = VAIO Event Service
    "{73FC3510-6421-40F7-9503-EDAE4D0CF70D}" = Windows Live Photo Common
    "{7465A996-0FCA-4D2D-A52C-F833B0829B5B}" = Windows Live Movie Maker
    "{7496FD31-E5CB-4AE4-82D3-31099558BF6A}" = Windows Live Mesh
    "{74E8A7F6-575D-42C7-9178-E87D1B3BEFE8}" = Windows Live UX Platform Language Pack
    "{762700A1-9F6B-F606-D5BE-F4525B817516}" = ccc-core-static
    "{77F69CA1-E53D-4D77-8BA3-FA07606CC851}" = Фотоальбом Windows Live
    "{78906B56-0E81-42A7-AC25-F54C946E1538}" = Windows Live Photo Common
    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
    "{7A9D47BA-6D50-4087-866F-0800D8B89383}" = Podstawowe programy Windows Live
    "{7ADFA72D-2A9F-4DEC-80A5-2FAA27E23F0F}" = Windows Live Photo Common
    "{7AF8E500-B349-4A77-8265-9854E9A47925}" = Windows Live Movie Maker
    "{7C80D30A-AC02-4E3F-B95D-29F0E4FF937B}" = VAIO Easy Connect
    "{7CB529B2-6C74-4878-9C3F-C29C3C3BBDC6}" = Windows Live Writer Resources
    "{7D0DE76C-874E-4BDE-A204-F4240160693E}" = Windows Live Photo Common
    "{7D916FA5-DAE9-4A25-B089-655C70EAF607}" = Atheros WiFi Driver Installation
    "{7E017923-16F8-4E32-94EF-0A150BD196FE}" = Windows Live Writer
    "{7F6021AE-E688-4D03-843A-C2260482BA0D}" = Windows Live Messenger
    "{7FF11E53-C002-4F40-8D68-6BE751E5DD62}" = Windows Live Writer Resources
    "{803E4FA5-A940-4420-B89D-A8BC2E160247}" = 
    "{80651674-74AA-4155-AF2D-1339E628D187}" = Windows Live Movie Maker
    "{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
    "{80E8C65A-8F70-4585-88A2-ABC54BABD576}" = Windows Live Mesh
    "{825DCB59-48BE-EA62-95E2-BE9FE211CB17}" = CCC Help Danish
    "{827D3E4A-0186-48B7-9801-7D1E9DD40C07}" = Windows Live Essentials
    "{82803FF3-563F-414F-A403-8D4C167D4120}" = Windows Live Mail
    "{82F09B1C-F602-4552-9C40-5BD5F8EAF750}" = 
    "{8356CB97-A48F-44CB-837A-A12838DC4669}" = PMB VAIO Edition Plug-in
    "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
    "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
    "{841F1FB4-FDF8-461C-A496-3E1CFD84C0B5}" = Windows Live Mesh
    "{84267681-BF16-40B6-9564-27BC57D7D71C}" = Windows Live Photo Common
    "{85373DA7-834E-4850-8AF5-1D99F7526857}" = Windows Live Photo Common
    "{855DDD3C-131E-42A8-BCBD-F9581F80CACB}" = 
    "{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer
    "{873E4648-6F6E-47F6-A7B2-A6F8DFABDCE6}" = Windows Live Messenger
    "{885F1BCD-C344-4758-85BD-09640CF449A5}" = Windows Live Photo Gallery
    "{8909CFA8-97BF-4077-AC0F-6925243FFE08}" = Windows Liven asennustyökalu
    "{8BD3162F-AA3F-9FA7-46B2-C3665D701A42}" = Catalyst Control Center Graphics Previews Common
    "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
    "{8CF5D47D-27B7-49D6-A14F-10550B92749D}" = Windows Live UX Platform Language Pack
    "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
    "{8E87710C-C14C-51DC-148B-101789778891}" = CCC Help German
    "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
    "{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
    "{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
    "{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
    "{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
    "{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
    "{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-0409-0000-0000000FF1CE}_PRJPRO_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-0409-0000-0000000FF1CE}_VISPRO_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-0409-0000-0000000FF1CE}_WebDesigner_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-040C-0000-0000000FF1CE}_PRJPRO_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-040C-0000-0000000FF1CE}_VISPRO_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-040C-0000-0000000FF1CE}_WebDesigner_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
    "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-0C0A-0000-0000000FF1CE}_PRJPRO_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-0C0A-0000-0000000FF1CE}_VISPRO_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-0C0A-0000-0000000FF1CE}_WebDesigner_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-0026-0000-0000-0000000FF1CE}" = Microsoft Expression Web
    "{90120000-0026-0000-0000-0000000FF1CE}_WebDesigner_{9037FDA8-8383-4B6F-859D-D49C3C625225}" = Microsoft Expression Web Service Pack 1 (SP1)
    "{90120000-0026-0409-0000-0000000FF1CE}" = Microsoft Expression Web MUI (English)
    "{90120000-0026-0409-0000-0000000FF1CE}_WebDesigner_{C00A9857-850C-4C68-A583-2EF4F24706F5}" = Microsoft Office SharePoint Designer 2007 Service Pack 3 (SP3)
    "{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-002A-0000-1000-0000000FF1CE}_PRJPRO_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-002A-0000-1000-0000000FF1CE}_VISPRO_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-002A-0000-1000-0000000FF1CE}_WebDesigner_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-002A-0409-1000-0000000FF1CE}_PRJPRO_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-002A-0409-1000-0000000FF1CE}_VISPRO_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-002A-0409-1000-0000000FF1CE}_WebDesigner_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
    "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
    "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-003B-0000-0000-0000000FF1CE}" = Microsoft Office Project Professional 2007
    "{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{8446EB22-A746-46DC-B1BD-E0DFA1F3CDDA}" = Microsoft Office Project 2007 Service Pack 3 (SP3)
    "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
    "{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0051-0000-0000-0000000FF1CE}" = Microsoft Office Visio Professional 2007
    "{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{CE144BF4-4950-4CDB-A5F7-CCE1888F49CB}" = Microsoft Office Visio 2007 Service Pack 3 (SP3)
    "{90120000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2007
    "{90120000-0054-0409-0000-0000000FF1CE}_VISPRO_{7DA87C7E-E8A7-473E-ADFF-1B6BECCCADA7}" = Microsoft Office Visio 2007 Service Pack 3 (SP3)
    "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-006E-0409-0000-0000000FF1CE}_PRJPRO_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-006E-0409-0000-0000000FF1CE}_VISPRO_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-006E-0409-0000-0000000FF1CE}_WebDesigner_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
    "{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-00B4-0409-0000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2007
    "{90120000-00B4-0409-0000-0000000FF1CE}_PRJPRO_{F3CD3F3F-726C-4414-A1FE-5CD0968313EA}" = Microsoft Office Project 2007 Service Pack 3 (SP3)
    "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
    "{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
    "{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
    "{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0115-0409-0000-0000000FF1CE}_PRJPRO_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0115-0409-0000-0000000FF1CE}_VISPRO_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0115-0409-0000-0000000FF1CE}_WebDesigner_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0116-0409-1000-0000000FF1CE}_PRJPRO_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0116-0409-1000-0000000FF1CE}_VISPRO_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0116-0409-1000-0000000FF1CE}_WebDesigner_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
    "{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
    "{90C3D9C7-2F83-4399-8E28-A00228CFFDF8}" = WD Security
    "{91989CE7-EE83-4A53-8E06-D97887928119}" = VAIO Care
    "{91BD94FE-ADCA-49CC-BE96-97D4BBC36FAF}" = Windows Live Mesh
    "{92280FD3-A119-41E6-A740-A62DBA4DFB53}" = Windows Live UX Platform Language Pack
    "{924B4D82-1B97-48EB-8F1E-55C4353C22DB}" = Windows Live Mail
    "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
    "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
    "{93E464B3-D075-4989-87FD-A828B5C308B1}" = Windows Live Writer Resources
    "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
    "{97B70991-5002-4241-8B0C-D74B8ADEB2B5}" = BlackBerry Desktop Software 7.1
    "{97F77D62-5110-4FA3-A2D3-410B92D31199}" = Windows Live Fotogaléria
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9B088046-8A01-4355-99DD-8530C022F682}" = VCCx86
    "{9BD262D0-B788-4546-A0A5-F4F56EC3834B}" = Windows Live Photo Common
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{9D12A8B5-9D41-4465-BF11-70719EB0CD02}" = VU5x86
    "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
    "{9FAE6E8D-E686-49F5-A574-0A58DFD9580C}" = Windows Live Mail
    "{9FF95DA2-7DA1-4228-93B7-DED7EC02B6B2}" = VAIO Update
    "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
    "{A49A517F-5332-4665-922C-6D9AD31ADD4F}" = VSNx86
    "{A60B3BF0-954B-42AF-B8D8-2C1D34B613AA}" = Windows Live Photo Gallery
    "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
    "{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
    "{A7C30414-2382-4086-B0D6-01A88ABA21C3}" = VAIO Gate
    "{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD
    "{A92A4DB0-CD37-42D1-BE1D-603D53C24328}" = Intel® Processor ID Utility
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
    "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
    "{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}" = Apple Application Support
    "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
    "{AB78C965-5C67-409B-8433-D7B5BDB12073}" = Windows Live Writer Resources
    "{AC76BA86-1033-F400-7760-000000000005}" = Adobe Acrobat X Pro - English, Français, Deutsch
    "{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.9) MUI
    "{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh
    "{AD001A69-88CC-4766-B2DB-3C1DFAB9AC72}" = Windows Live Mesh
    "{ADE85655-8D1E-4E4B-BF88-5E312FB2C74F}" = Windows Live Mail
    "{ADFE4AED-7F8E-4658-8D6E-742B15B9F120}" = Windows Live Photo Common
    "{B04A0E2F-1E4C-4E61-B18E-3B2BD6779CA7}" = Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych
    "{B0AD205F-60D0-4084-AFB8-34D9A706D9A8}" = Windows Live Essentials
    "{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie
    "{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail
    "{B3BA4D1C-23EF-4859-9C11-1B2CCB7FADBB}" = ActiveX контрола на Windows Live Mesh за отдалечени връзки
    "{B618C3BF-5142-4630-81DD-F96864F97C7E}" = Windows Live Essentials
    "{B6190387-0036-4BEB-8D74-A0AFC5F14706}" = Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení
    "{B63F0CE3-CCD0-490A-9A9C-E1A3B3A17137}" = Почта Windows Live
    "{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}" = PMB
    "{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
    "{B7546697-2A80-4256-A24B-1C33163F535B}" = VAIO Gate Default
    "{B78CFC07-B623-4995-ADCC-B2B4D59D083A}" = HTC Sync
    "{B8991D99-88FD-41F2-8C32-DB70278D5C30}" = VWSTx86
    "{BCB0D6F7-7EAB-4009-A6F2-8E0E7F317773}" = Элемент управления Windows Live Mesh ActiveX для удаленных подключений
    "{BD4EBDB5-EB14-4120-BB04-BE0A26C7FB3E}" = Windows Live Photo Common
    "{BD695C2F-3EA0-4DA4-92D5-154072468721}" = Windows Live Fotoğraf Galerisi
    "{BDE646E8-86E0-50E1-37BC-0AEBB2185D76}" = Adobe Widget Browser
    "{BF022D76-9F72-4203-B8FA-6522DC66DFDA}" = Windows Live Movie Maker
    "{BF35168D-F6F9-4202-BA87-86B5E3C9BF7A}" = Windows Live Mesh
    "{BF6CD234-E079-E376-59B4-63B95FDF0BA4}" = CCC Help Chinese Standard
    "{C00C2A91-6CB3-483F-80B3-2958E29468F1}" = Συλλογή φωτογραφιών του Windows Live
    "{C08D5964-C42F-48EE-A893-2396F9562A7C}" = Windows Live Mesh
    "{C115A674-A398-49E5-9C6E-C0A541D3EA10}" = Фотоколекція Windows Live
    "{C14EAE86-C526-4E00-B245-CFF86233C3D2}" = VAIO 3D Portal
    "{C1C9D199-B4DD-4895-92DD-9A726A2FE341}" = Windows Live Writer
    "{C28DD992-5B7B-D195-6841-4EC57DF512BD}" = Adobe Story
    "{C29FC15D-E84B-4EEC-8505-4DED94414C59}" = Windows Live Writer Resources
    "{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common
    "{C2FD7DB5-FE30-49B6-8A2F-C5652E053C31}" = Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia
    "{C32CE55C-12BA-4951-8797-0967FDEF556F}" = Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen
    "{C454280F-3C3E-4929-B60E-9E6CED5717E7}" = Windows Live Mail
    "{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections
    "{C57AC303-8F13-ACD8-217A-88D4FB09AC25}" = CCC Help Thai
    "{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}" = Windows Live Mesh ActiveX Control for Remote Connections
    "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
    "{C6E893E7-E5EA-4CD5-917C-5443E753FCBD}" = VAIO Manual
    "{C72E35E5-C5C6-4328-AD9A-BBCCC816A2E6}" = VAIO Hardware Diagnostics
    "{C793AD32-2BB8-4CC4-ABD3-A1469C21593C}" = ArcSoft WebCam Companion 4
    "{C8421D85-CA0E-4E93-A9A9-B826C4FB88EA}" = Windows Live Mail
    "{C893D8C0-1BA0-4517-B11C-E89B65E72F70}" = Windows Live Photo Common
    "{CB3F59BB-7858-41A1-A7EA-4B8A6FC7D431}" = Galeria fotografii usługi Windows Live
    "{CB66242D-12B1-4494-82D2-6F53A7E024A3}" = Galerie foto Windows Live
    "{CB7224D9-6DCA-43F1-8F83-6B1E39A00F92}" = Windows Live Movie Maker
    "{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
    "{CD442136-9115-4236-9C14-278F6A9DCB3F}" = Windows Live Movie Maker
    "{CD7CB1E6-267A-408F-877D-B532AD2C882E}" = Windows Live Photo Common
    "{CDC39BF2-9697-4959-B893-A2EE05EF6ACB}" = Windows Live Writer
    "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
    "{CF671BFE-6BA3-44E7-98C1-500D9C51D947}" = Windows Live Photo Gallery
    "{D03CEAC4-267C-0924-AD38-B4298DBAC131}" = CCC Help Greek
    "{D07B1FDA-876B-4914-9E9A-309732B6D44F}" = Windows Live Mail
    "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
    "{D17C2A58-E0EA-4DD7-A2D6-C448FD25B6F6}" = VIx86
    "{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
    "{D2D23D08-D10E-43D6-883C-78E0B2AC9CC6}" = VU5x86
    "{D31169F2-CD71-4337-B783-3E53F29F4CAD}" = Windows Live Mail
    "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
    "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
    "{D4E7BB46-310E-4A21-B261-052A5997EA2F}" = V3DPX86
    "{D57A002F-2B34-4E7B-A58B-0A4FBDA2E93F}" = Windows Live Messenger
    "{D57FC112-312E-4D70-860F-2DB8FB6858F0}" = Adobe Creative Suite 5.5 Master Collection
    "{D588365A-AE39-4F27-BDAE-B4E72C8E900C}" = Windows Live Mail
    "{D6F25CF9-4E87-43EB-B324-C12BE9CDD668}" = Windows Live UX Platform Language Pack
    "{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
    "{DA29F644-2420-4448-8128-1331BE588999}" = Windows Live Writer
    "{DAEF48AD-89C8-4A93-B1DD-45B7E4FB6071}" = Windows Live Movie Maker
    "{DB1208F4-B2FE-44E9-BFE6-8824DBD7891B}" = Windows Live Movie Maker
    "{DCAB6BA7-6533-44BF-9235-E5BF33B7431C}" = Windows Live Writer
    "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
    "{DE7C13A6-E4EA-4296-B0D5-5D7E8AD69501}" = Windows Live Writer
    "{DE8F99FD-2FC7-4C98-AA67-2729FDE1F040}" = Windows Live Writer Resources
    "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
    "{DEF91E0F-D266-453D-B6F2-1BA002B40CB6}" = Windows Live Essentials
    "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
    "{E2AE009D-37E5-4724-A6B8-0ED6A6BA4F68}" = Elements STI Installer
    "{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker
    "{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}" = Controlo ActiveX do Windows Live Mesh para Ligações Remotas
    "{E55E0C35-AC3C-4683-BA2F-834348577B80}" = Windows Live Writer
    "{E5DD4723-FE0B-436E-A815-DC23CF902A0B}" = Windows Live UX Platform Language Pack
    "{E7688C7D-DE09-4D43-9785-534EDE9BC18E}" = Windows Live Messenger
    "{E8212C21-5DD3-B11B-952B-74B8EB33AE8E}" = CCC Help Chinese Traditional
    "{E83DC314-C926-4214-AD58-147691D6FE9F}" = Основные компоненты Windows Live
    "{E8524B28-3BBB-4763-AC83-0E83FE31C350}" = Windows Live Writer
    "{E87022D3-C8C9-4C76-8E27-BC7F18F9B8FB}" = Google Drive
    "{E9D98402-21AB-4E9F-BF6B-47AF36EF7E97}" = Windows Live Writer Resources
    "{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
    "{EB9955F8-467C-47FC-90F8-12CD5DF684C3}" = Adobe Premiere Elements 9
    "{ED16B700-D91F-44B0-867C-7EB5253CA38D}" = Raccolta foto di Windows Live
    "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
    "{F0F9505B-3ACF-4158-9311-D0285136AA00}" = Windows Live Essentials
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{F1907066-F579-9F30-5B78-1155024DE402}" = CCC Help Polish
    "{F28C98E9-BAC1-41FF-81F2-8885925CCB48}" = Windows Live Writer
    "{F4BEA6C1-AAC3-4810-AAEA-588E26E0F237}" = Windows Live UX Platform Language Pack
    "{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}" = Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις
    "{F694D1F7-1F12-4550-9B7A-C871273ABAD5}" = Windows Live Messenger
    "{F80E5450-3EF3-4270-B26C-6AC53BEC5E76}" = Windows Live Movie Maker
    "{F88A51E3-7D81-13DB-E6DC-67744B03F34B}" = Catalyst Control Center Localization All
    "{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials
    "{F9784E1D-4455-4BFF-A97A-1B1355A4FFDB}" = WD Drive Utilities
    "{FA6CF94F-DACF-4FE7-959D-55C421B91B17}" = Windows Live Mail
    "{FA870BF1-44A1-4B7D-93E1-C101369AF0C1}" = VAIO - Media Gallery
    "{FB3D07AE-73D0-47A9-AC12-6F50BF8B6202}" = Windows Live Movie Maker
    "{FB77DB0C-6951-47B6-9D80-A0FDBEE0334C}" = 
    "{FB79FDB7-4DE1-453D-99FE-9A880F57380E}" = Windows Live Fotogalerie
    "{FCDE76CB-989D-4E32-9739-6A272D2B0ED7}" = Windows Live Mesh
    "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
    "{FE62C88B-425B-4BDE-8B70-CD5AE3B83176}" = Windows Live Essentials
    "{FEEF7F78-5876-438B-B554-C4CC426A4302}" = Windows Live Essentials
    "{FF3DFA01-1E98-46B4-A065-DA8AD47C9598}" = Windows Live Movie Maker
    "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 12 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 12 Plugin
    "Adobe Photoshop Elements 9" = Adobe Photoshop Elements 9
    "Aimersoft Video Converter Ultimate_is1" = Aimersoft Video Converter Ultimate(Build 4.2.1.0)
    "Basic PAYE Tools - Real Time Information" = Basic PAYE Tools - Real Time Information
    "Basic PAYE Tools 2012" = Basic PAYE Tools 2012
    "BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1" = BBC iPlayer Desktop
    "BlackBerry_Desktop" = BlackBerry Desktop Software 7.1
    "chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
    "com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Story
    "com.adobe.dmp.contentviewer" = Adobe Content Viewer
    "com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Widget Browser
    "EaseUS Data Recovery Wizard 5.6.5_is1" = EaseUS Data Recovery Wizard 5.6.5
    "ENTERPRISE" = Microsoft Office Enterprise 2007
    "experience-sony-bundle" = TriDef 3D (Sony) 1.1.3
    "FlacSquisher" = FlacSquisher 1.0.13
    "GenoPro" = GenoPro 2.5.4.1
    "Google Chrome" = Google Chrome
    "InstallShield_{270380EB-8812-42E1-8289-53700DB840D2}" = VAIO - PMB VAIO Edition Plug-in
    "InstallShield_{339F9B4D-00CB-4C1C-BED8-EC86A9AB602A}" = VAIO - PMB VAIO Edition Guide
    "InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
    "InstallShield_{6748E773-5DA0-4D19-8AA5-273B4133A09B}" = SmartSound Quicktracks for Premiere Elements 9.0
    "InstallShield_{7C80D30A-AC02-4E3F-B95D-29F0E4FF937B}" = VAIO Easy Connect
    "InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD
    "Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.0.1.1004
    "McAfee Virtual Technician" = McAfee Virtual Technician
    "Monkey's Audio_is1" = Monkey's Audio
    "Mozilla Firefox 28.0 (x86 en-US)" = Mozilla Firefox 28.0 (x86 en-US)
    "MozillaMaintenanceService" = Mozilla Maintenance Service
    "MP Navigator 3.1" = Canon MP Navigator 3.1
    "PamelaCR" = Pam Call Recorder 4.8
    "PokerStars" = PokerStars
    "PremElem90" = Adobe Premiere Elements 9
    "PRJPRO" = Microsoft Office Project Professional 2007
    "Raptr" = Raptr
    "splashtop" = VAIO Quick Web Access
    "VAIO C Series - Summer 2011 Screensaver" = VAIO C Series - Summer 2011 Screensaver
    "VAIO Help and Support" = 
    "VISPRO" = Microsoft Office Visio Professional 2007
    "VLC media player" = VLC media player 2.1.3
    "WebDesigner" = Microsoft Expression Web
    "WinLiveSuite" = Windows Live Essentials
     
    ========== HKEY_CURRENT_USER Uninstall List ==========
     
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "Akamai" = Akamai NetSession Interface
    "BitTorrent" = BitTorrent
    "Dropbox" = Dropbox
    "MusicManager" = Music Manager
    "Spotify" = Spotify
     
    ========== Last 20 Event Log Errors ==========
     
    [ OSession Events ]
    Error - 02/09/2013 14:13:51 | Computer Name = *****-VAIO | Source = Microsoft Office 12 Sessions | ID = 7001
    Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
     12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 18341
     seconds with 8280 seconds of active time.  This session ended with a crash.
     
     
    < End of report >

    • 0

    Advertisements


    #11
    infected99.9

    infected99.9

      Member

    • Topic Starter
    • Member
    • PipPip
    • 19 posts

    ESET's ran.

     

    Then System File Checker found nothing to repair, log below:

     

    2014-04-28 01:35:28, Info                  CSI    00000009 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:35:28, Info                  CSI    0000000a [SR] Beginning Verify and Repair transaction
    2014-04-28 01:35:31, Info                  CSI    0000000c [SR] Verify complete
    2014-04-28 01:35:32, Info                  CSI    0000000d [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:35:32, Info                  CSI    0000000e [SR] Beginning Verify and Repair transaction
    2014-04-28 01:35:35, Info                  CSI    00000010 [SR] Verify complete
    2014-04-28 01:35:36, Info                  CSI    00000011 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:35:36, Info                  CSI    00000012 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:35:38, Info                  CSI    00000014 [SR] Verify complete
    2014-04-28 01:35:40, Info                  CSI    00000015 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:35:40, Info                  CSI    00000016 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:35:42, Info                  CSI    00000018 [SR] Verify complete
    2014-04-28 01:35:43, Info                  CSI    00000019 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:35:43, Info                  CSI    0000001a [SR] Beginning Verify and Repair transaction
    2014-04-28 01:35:47, Info                  CSI    0000001c [SR] Verify complete
    2014-04-28 01:35:48, Info                  CSI    0000001d [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:35:48, Info                  CSI    0000001e [SR] Beginning Verify and Repair transaction
    2014-04-28 01:35:54, Info                  CSI    00000020 [SR] Verify complete
    2014-04-28 01:35:55, Info                  CSI    00000021 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:35:55, Info                  CSI    00000022 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:35:59, Info                  CSI    00000024 [SR] Verify complete
    2014-04-28 01:36:00, Info                  CSI    00000025 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:36:00, Info                  CSI    00000026 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:36:04, Info                  CSI    00000028 [SR] Verify complete
    2014-04-28 01:36:04, Info                  CSI    00000029 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:36:04, Info                  CSI    0000002a [SR] Beginning Verify and Repair transaction
    2014-04-28 01:36:09, Info                  CSI    0000002c [SR] Verify complete
    2014-04-28 01:36:09, Info                  CSI    0000002d [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:36:09, Info                  CSI    0000002e [SR] Beginning Verify and Repair transaction
    2014-04-28 01:36:15, Info                  CSI    00000030 [SR] Verify complete
    2014-04-28 01:36:15, Info                  CSI    00000031 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:36:15, Info                  CSI    00000032 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:36:19, Info                  CSI    00000034 [SR] Verify complete
    2014-04-28 01:36:19, Info                  CSI    00000035 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:36:19, Info                  CSI    00000036 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:36:23, Info                  CSI    00000038 [SR] Verify complete
    2014-04-28 01:36:23, Info                  CSI    00000039 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:36:23, Info                  CSI    0000003a [SR] Beginning Verify and Repair transaction
    2014-04-28 01:36:33, Info                  CSI    0000003d [SR] Verify complete
    2014-04-28 01:36:33, Info                  CSI    0000003e [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:36:33, Info                  CSI    0000003f [SR] Beginning Verify and Repair transaction
    2014-04-28 01:36:43, Info                  CSI    00000044 [SR] Verify complete
    2014-04-28 01:36:44, Info                  CSI    00000045 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:36:44, Info                  CSI    00000046 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:36:52, Info                  CSI    0000004a [SR] Verify complete
    2014-04-28 01:36:53, Info                  CSI    0000004b [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:36:53, Info                  CSI    0000004c [SR] Beginning Verify and Repair transaction
    2014-04-28 01:37:00, Info                  CSI    0000004e [SR] Verify complete
    2014-04-28 01:37:01, Info                  CSI    0000004f [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:37:01, Info                  CSI    00000050 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:37:11, Info                  CSI    00000062 [SR] Verify complete
    2014-04-28 01:37:12, Info                  CSI    00000063 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:37:12, Info                  CSI    00000064 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:37:22, Info                  CSI    00000079 [SR] Verify complete
    2014-04-28 01:37:23, Info                  CSI    0000007a [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:37:23, Info                  CSI    0000007b [SR] Beginning Verify and Repair transaction
    2014-04-28 01:37:33, Info                  CSI    0000007d [SR] Verify complete
    2014-04-28 01:37:34, Info                  CSI    0000007e [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:37:34, Info                  CSI    0000007f [SR] Beginning Verify and Repair transaction
    2014-04-28 01:37:41, Info                  CSI    00000081 [SR] Verify complete
    2014-04-28 01:37:42, Info                  CSI    00000082 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:37:42, Info                  CSI    00000083 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:37:49, Info                  CSI    00000085 [SR] Verify complete
    2014-04-28 01:37:50, Info                  CSI    00000086 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:37:50, Info                  CSI    00000087 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:37:58, Info                  CSI    00000089 [SR] Verify complete
    2014-04-28 01:37:58, Info                  CSI    0000008a [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:37:58, Info                  CSI    0000008b [SR] Beginning Verify and Repair transaction
    2014-04-28 01:38:06, Info                  CSI    0000008d [SR] Verify complete
    2014-04-28 01:38:07, Info                  CSI    0000008e [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:38:07, Info                  CSI    0000008f [SR] Beginning Verify and Repair transaction
    2014-04-28 01:38:18, Info                  CSI    000000b2 [SR] Verify complete
    2014-04-28 01:38:19, Info                  CSI    000000b3 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:38:19, Info                  CSI    000000b4 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:38:32, Info                  CSI    000000b6 [SR] Verify complete
    2014-04-28 01:38:32, Info                  CSI    000000b7 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:38:32, Info                  CSI    000000b8 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:38:45, Info                  CSI    000000ba [SR] Verify complete
    2014-04-28 01:38:46, Info                  CSI    000000bb [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:38:46, Info                  CSI    000000bc [SR] Beginning Verify and Repair transaction
    2014-04-28 01:39:03, Info                  CSI    000000c0 [SR] Verify complete
    2014-04-28 01:39:03, Info                  CSI    000000c1 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:39:03, Info                  CSI    000000c2 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:39:08, Info                  CSI    000000c4 [SR] Verify complete
    2014-04-28 01:39:08, Info                  CSI    000000c5 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:39:08, Info                  CSI    000000c6 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:39:11, Info                  CSI    000000c8 [SR] Verify complete
    2014-04-28 01:39:12, Info                  CSI    000000c9 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:39:12, Info                  CSI    000000ca [SR] Beginning Verify and Repair transaction
    2014-04-28 01:39:17, Info                  CSI    000000cc [SR] Verify complete
    2014-04-28 01:39:17, Info                  CSI    000000cd [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:39:17, Info                  CSI    000000ce [SR] Beginning Verify and Repair transaction
    2014-04-28 01:39:27, Info                  CSI    000000e1 [SR] Verify complete
    2014-04-28 01:39:27, Info                  CSI    000000e2 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:39:27, Info                  CSI    000000e3 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:39:31, Info                  CSI    000000e5 [SR] Verify complete
    2014-04-28 01:39:31, Info                  CSI    000000e6 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:39:31, Info                  CSI    000000e7 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:39:37, Info                  CSI    000000e9 [SR] Verify complete
    2014-04-28 01:39:38, Info                  CSI    000000ea [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:39:38, Info                  CSI    000000eb [SR] Beginning Verify and Repair transaction
    2014-04-28 01:39:41, Info                  CSI    000000ed [SR] Verify complete
    2014-04-28 01:39:42, Info                  CSI    000000ee [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:39:42, Info                  CSI    000000ef [SR] Beginning Verify and Repair transaction
    2014-04-28 01:39:50, Info                  CSI    000000f2 [SR] Verify complete
    2014-04-28 01:39:50, Info                  CSI    000000f3 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:39:50, Info                  CSI    000000f4 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:40:01, Info                  CSI    000000f7 [SR] Verify complete
    2014-04-28 01:40:02, Info                  CSI    000000f8 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:40:02, Info                  CSI    000000f9 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:40:06, Info                  CSI    000000fb [SR] Verify complete
    2014-04-28 01:40:06, Info                  CSI    000000fc [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:40:06, Info                  CSI    000000fd [SR] Beginning Verify and Repair transaction
    2014-04-28 01:40:10, Info                  CSI    000000ff [SR] Verify complete
    2014-04-28 01:40:10, Info                  CSI    00000100 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:40:10, Info                  CSI    00000101 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:40:20, Info                  CSI    00000103 [SR] Verify complete
    2014-04-28 01:40:21, Info                  CSI    00000104 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:40:21, Info                  CSI    00000105 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:40:31, Info                  CSI    00000107 [SR] Verify complete
    2014-04-28 01:40:31, Info                  CSI    00000108 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:40:31, Info                  CSI    00000109 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:40:41, Info                  CSI    0000010b [SR] Verify complete
    2014-04-28 01:40:41, Info                  CSI    0000010c [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:40:41, Info                  CSI    0000010d [SR] Beginning Verify and Repair transaction
    2014-04-28 01:40:53, Info                  CSI    00000125 [SR] Verify complete
    2014-04-28 01:40:54, Info                  CSI    00000126 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:40:54, Info                  CSI    00000127 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:41:02, Info                  CSI    00000129 [SR] Verify complete
    2014-04-28 01:41:02, Info                  CSI    0000012a [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:41:02, Info                  CSI    0000012b [SR] Beginning Verify and Repair transaction
    2014-04-28 01:41:19, Info                  CSI    0000012d [SR] Verify complete
    2014-04-28 01:41:20, Info                  CSI    0000012e [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:41:20, Info                  CSI    0000012f [SR] Beginning Verify and Repair transaction
    2014-04-28 01:41:37, Info                  CSI    00000131 [SR] Verify complete
    2014-04-28 01:41:38, Info                  CSI    00000132 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:41:38, Info                  CSI    00000133 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:41:48, Info                  CSI    00000135 [SR] Verify complete
    2014-04-28 01:41:49, Info                  CSI    00000136 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:41:49, Info                  CSI    00000137 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:41:56, Info                  CSI    00000139 [SR] Verify complete
    2014-04-28 01:41:57, Info                  CSI    0000013a [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:41:57, Info                  CSI    0000013b [SR] Beginning Verify and Repair transaction
    2014-04-28 01:42:04, Info                  CSI    0000013d [SR] Verify complete
    2014-04-28 01:42:05, Info                  CSI    0000013e [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:42:05, Info                  CSI    0000013f [SR] Beginning Verify and Repair transaction
    2014-04-28 01:42:11, Info                  CSI    00000141 [SR] Verify complete
    2014-04-28 01:42:11, Info                  CSI    00000142 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:42:11, Info                  CSI    00000143 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:42:18, Info                  CSI    00000147 [SR] Verify complete
    2014-04-28 01:42:19, Info                  CSI    00000148 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:42:19, Info                  CSI    00000149 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:42:32, Info                  CSI    0000014b [SR] Verify complete
    2014-04-28 01:42:33, Info                  CSI    0000014c [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:42:33, Info                  CSI    0000014d [SR] Beginning Verify and Repair transaction
    2014-04-28 01:42:42, Info                  CSI    00000150 [SR] Verify complete
    2014-04-28 01:42:42, Info                  CSI    00000151 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:42:42, Info                  CSI    00000152 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:42:49, Info                  CSI    00000154 [SR] Verify complete
    2014-04-28 01:42:50, Info                  CSI    00000155 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:42:50, Info                  CSI    00000156 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:42:56, Info                  CSI    00000159 [SR] Verify complete
    2014-04-28 01:42:57, Info                  CSI    0000015a [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:42:57, Info                  CSI    0000015b [SR] Beginning Verify and Repair transaction
    2014-04-28 01:43:08, Info                  CSI    0000015e [SR] Verify complete
    2014-04-28 01:43:08, Info                  CSI    0000015f [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:43:08, Info                  CSI    00000160 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:43:16, Info                  CSI    00000162 [SR] Verify complete
    2014-04-28 01:43:16, Info                  CSI    00000163 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:43:16, Info                  CSI    00000164 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:43:23, Info                  CSI    00000166 [SR] Verify complete
    2014-04-28 01:43:24, Info                  CSI    00000167 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:43:24, Info                  CSI    00000168 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:43:31, Info                  CSI    0000016a [SR] Verify complete
    2014-04-28 01:43:31, Info                  CSI    0000016b [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:43:31, Info                  CSI    0000016c [SR] Beginning Verify and Repair transaction
    2014-04-28 01:43:42, Info                  CSI    0000016f [SR] Verify complete
    2014-04-28 01:43:42, Info                  CSI    00000170 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:43:42, Info                  CSI    00000171 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:43:49, Info                  CSI    00000173 [SR] Verify complete
    2014-04-28 01:43:49, Info                  CSI    00000174 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:43:49, Info                  CSI    00000175 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:43:54, Info                  CSI    00000177 [SR] Verify complete
    2014-04-28 01:43:54, Info                  CSI    00000178 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:43:54, Info                  CSI    00000179 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:44:02, Info                  CSI    0000017c [SR] Verify complete
    2014-04-28 01:44:03, Info                  CSI    0000017d [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:44:03, Info                  CSI    0000017e [SR] Beginning Verify and Repair transaction
    2014-04-28 01:44:11, Info                  CSI    00000182 [SR] Verify complete
    2014-04-28 01:44:12, Info                  CSI    00000183 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:44:12, Info                  CSI    00000184 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:44:19, Info                  CSI    00000187 [SR] Verify complete
    2014-04-28 01:44:19, Info                  CSI    00000188 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:44:19, Info                  CSI    00000189 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:44:30, Info                  CSI    0000018c [SR] Verify complete
    2014-04-28 01:44:30, Info                  CSI    0000018d [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:44:30, Info                  CSI    0000018e [SR] Beginning Verify and Repair transaction
    2014-04-28 01:44:39, Info                  CSI    00000190 [SR] Verify complete
    2014-04-28 01:44:40, Info                  CSI    00000191 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:44:40, Info                  CSI    00000192 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:44:46, Info                  CSI    00000194 [SR] Verify complete
    2014-04-28 01:44:46, Info                  CSI    00000195 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:44:46, Info                  CSI    00000196 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:44:51, Info                  CSI    00000198 [SR] Verify complete
    2014-04-28 01:44:51, Info                  CSI    00000199 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:44:51, Info                  CSI    0000019a [SR] Beginning Verify and Repair transaction
    2014-04-28 01:44:59, Info                  CSI    0000019c [SR] Verify complete
    2014-04-28 01:44:59, Info                  CSI    0000019d [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:44:59, Info                  CSI    0000019e [SR] Beginning Verify and Repair transaction
    2014-04-28 01:45:06, Info                  CSI    000001a0 [SR] Verify complete
    2014-04-28 01:45:07, Info                  CSI    000001a1 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:45:07, Info                  CSI    000001a2 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:45:15, Info                  CSI    000001a4 [SR] Verify complete
    2014-04-28 01:45:15, Info                  CSI    000001a5 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:45:15, Info                  CSI    000001a6 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:45:20, Info                  CSI    000001a8 [SR] Verify complete
    2014-04-28 01:45:20, Info                  CSI    000001a9 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:45:20, Info                  CSI    000001aa [SR] Beginning Verify and Repair transaction
    2014-04-28 01:45:28, Info                  CSI    000001ac [SR] Verify complete
    2014-04-28 01:45:28, Info                  CSI    000001ad [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:45:28, Info                  CSI    000001ae [SR] Beginning Verify and Repair transaction
    2014-04-28 01:45:56, Info                  CSI    000001b0 [SR] Verify complete
    2014-04-28 01:45:56, Info                  CSI    000001b1 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:45:56, Info                  CSI    000001b2 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:46:25, Info                  CSI    000001b4 [SR] Verify complete
    2014-04-28 01:46:25, Info                  CSI    000001b5 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:46:25, Info                  CSI    000001b6 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:46:36, Info                  CSI    000001b8 [SR] Verify complete
    2014-04-28 01:46:36, Info                  CSI    000001b9 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:46:36, Info                  CSI    000001ba [SR] Beginning Verify and Repair transaction
    2014-04-28 01:46:43, Info                  CSI    000001bc [SR] Verify complete
    2014-04-28 01:46:43, Info                  CSI    000001bd [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:46:43, Info                  CSI    000001be [SR] Beginning Verify and Repair transaction
    2014-04-28 01:46:48, Info                  CSI    000001c0 [SR] Verify complete
    2014-04-28 01:46:48, Info                  CSI    000001c1 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:46:48, Info                  CSI    000001c2 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:46:53, Info                  CSI    000001c4 [SR] Verify complete
    2014-04-28 01:46:53, Info                  CSI    000001c5 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:46:53, Info                  CSI    000001c6 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:47:02, Info                  CSI    000001c8 [SR] Verify complete
    2014-04-28 01:47:02, Info                  CSI    000001c9 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:47:02, Info                  CSI    000001ca [SR] Beginning Verify and Repair transaction
    2014-04-28 01:47:04, Info                  CSI    000001cc [SR] Verify complete
    2014-04-28 01:47:05, Info                  CSI    000001cd [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:47:05, Info                  CSI    000001ce [SR] Beginning Verify and Repair transaction
    2014-04-28 01:47:06, Info                  CSI    000001d0 [SR] Verify complete
    2014-04-28 01:47:07, Info                  CSI    000001d1 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:47:07, Info                  CSI    000001d2 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:47:13, Info                  CSI    000001da [SR] Verify complete
    2014-04-28 01:47:14, Info                  CSI    000001db [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:47:14, Info                  CSI    000001dc [SR] Beginning Verify and Repair transaction
    2014-04-28 01:47:19, Info                  CSI    000001de [SR] Verify complete
    2014-04-28 01:47:19, Info                  CSI    000001df [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:47:19, Info                  CSI    000001e0 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:47:24, Info                  CSI    000001e2 [SR] Verify complete
    2014-04-28 01:47:25, Info                  CSI    000001e3 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:47:25, Info                  CSI    000001e4 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:47:30, Info                  CSI    000001e6 [SR] Verify complete
    2014-04-28 01:47:31, Info                  CSI    000001e7 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:47:31, Info                  CSI    000001e8 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:47:37, Info                  CSI    000001ea [SR] Verify complete
    2014-04-28 01:47:37, Info                  CSI    000001eb [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:47:37, Info                  CSI    000001ec [SR] Beginning Verify and Repair transaction
    2014-04-28 01:47:46, Info                  CSI    000001ef [SR] Verify complete
    2014-04-28 01:47:46, Info                  CSI    000001f0 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:47:46, Info                  CSI    000001f1 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:47:52, Info                  CSI    000001f3 [SR] Verify complete
    2014-04-28 01:47:52, Info                  CSI    000001f4 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:47:52, Info                  CSI    000001f5 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:47:55, Info                  CSI    000001f7 [SR] Verify complete
    2014-04-28 01:47:56, Info                  CSI    000001f8 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:47:56, Info                  CSI    000001f9 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:48:05, Info                  CSI    000001fb [SR] Verify complete
    2014-04-28 01:48:06, Info                  CSI    000001fc [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:48:06, Info                  CSI    000001fd [SR] Beginning Verify and Repair transaction
    2014-04-28 01:48:19, Info                  CSI    00000202 [SR] Verify complete
    2014-04-28 01:48:19, Info                  CSI    00000203 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:48:19, Info                  CSI    00000204 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:48:27, Info                  CSI    00000209 [SR] Verify complete
    2014-04-28 01:48:28, Info                  CSI    0000020a [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:48:28, Info                  CSI    0000020b [SR] Beginning Verify and Repair transaction
    2014-04-28 01:48:35, Info                  CSI    00000211 [SR] Verify complete
    2014-04-28 01:48:36, Info                  CSI    00000212 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:48:36, Info                  CSI    00000213 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:48:45, Info                  CSI    0000021b [SR] Verify complete
    2014-04-28 01:48:45, Info                  CSI    0000021c [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:48:45, Info                  CSI    0000021d [SR] Beginning Verify and Repair transaction
    2014-04-28 01:48:55, Info                  CSI    00000223 [SR] Verify complete
    2014-04-28 01:48:56, Info                  CSI    00000224 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:48:56, Info                  CSI    00000225 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:49:02, Info                  CSI    00000227 [SR] Verify complete
    2014-04-28 01:49:02, Info                  CSI    00000228 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:49:02, Info                  CSI    00000229 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:49:08, Info                  CSI    0000022d [SR] Verify complete
    2014-04-28 01:49:08, Info                  CSI    0000022e [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:49:08, Info                  CSI    0000022f [SR] Beginning Verify and Repair transaction
    2014-04-28 01:49:14, Info                  CSI    00000231 [SR] Verify complete
    2014-04-28 01:49:14, Info                  CSI    00000232 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:49:14, Info                  CSI    00000233 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:49:21, Info                  CSI    00000258 [SR] Verify complete
    2014-04-28 01:49:22, Info                  CSI    00000259 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:49:22, Info                  CSI    0000025a [SR] Beginning Verify and Repair transaction
    2014-04-28 01:49:28, Info                  CSI    0000025c [SR] Verify complete
    2014-04-28 01:49:29, Info                  CSI    0000025d [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:49:29, Info                  CSI    0000025e [SR] Beginning Verify and Repair transaction
    2014-04-28 01:49:34, Info                  CSI    00000260 [SR] Verify complete
    2014-04-28 01:49:35, Info                  CSI    00000261 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:49:35, Info                  CSI    00000262 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:49:41, Info                  CSI    00000264 [SR] Verify complete
    2014-04-28 01:49:41, Info                  CSI    00000265 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:49:41, Info                  CSI    00000266 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:49:47, Info                  CSI    00000274 [SR] Verify complete
    2014-04-28 01:49:47, Info                  CSI    00000275 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:49:47, Info                  CSI    00000276 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:50:02, Info                  CSI    00000278 [SR] Verify complete
    2014-04-28 01:50:03, Info                  CSI    00000279 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:50:03, Info                  CSI    0000027a [SR] Beginning Verify and Repair transaction
    2014-04-28 01:50:09, Info                  CSI    00000288 [SR] Verify complete
    2014-04-28 01:50:09, Info                  CSI    00000289 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:50:09, Info                  CSI    0000028a [SR] Beginning Verify and Repair transaction
    2014-04-28 01:50:12, Info                  CSI    0000028c [SR] Verify complete
    2014-04-28 01:50:13, Info                  CSI    0000028d [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:50:13, Info                  CSI    0000028e [SR] Beginning Verify and Repair transaction
    2014-04-28 01:50:19, Info                  CSI    00000291 [SR] Verify complete
    2014-04-28 01:50:19, Info                  CSI    00000292 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:50:19, Info                  CSI    00000293 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:50:24, Info                  CSI    00000295 [SR] Verify complete
    2014-04-28 01:50:25, Info                  CSI    00000296 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:50:25, Info                  CSI    00000297 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:50:28, Info                  CSI    00000299 [SR] Verify complete
    2014-04-28 01:50:28, Info                  CSI    0000029a [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:50:28, Info                  CSI    0000029b [SR] Beginning Verify and Repair transaction
    2014-04-28 01:50:37, Info                  CSI    0000029d [SR] Verify complete
    2014-04-28 01:50:37, Info                  CSI    0000029e [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:50:37, Info                  CSI    0000029f [SR] Beginning Verify and Repair transaction
    2014-04-28 01:50:45, Info                  CSI    000002a1 [SR] Verify complete
    2014-04-28 01:50:46, Info                  CSI    000002a2 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:50:46, Info                  CSI    000002a3 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:50:54, Info                  CSI    000002b9 [SR] Verify complete
    2014-04-28 01:50:55, Info                  CSI    000002ba [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:50:55, Info                  CSI    000002bb [SR] Beginning Verify and Repair transaction
    2014-04-28 01:51:02, Info                  CSI    000002c1 [SR] Verify complete
    2014-04-28 01:51:02, Info                  CSI    000002c2 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:51:02, Info                  CSI    000002c3 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:51:18, Info                  CSI    000002c5 [SR] Verify complete
    2014-04-28 01:51:19, Info                  CSI    000002c6 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:51:19, Info                  CSI    000002c7 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:51:26, Info                  CSI    000002c9 [SR] Verify complete
    2014-04-28 01:51:26, Info                  CSI    000002ca [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:51:26, Info                  CSI    000002cb [SR] Beginning Verify and Repair transaction
    2014-04-28 01:51:32, Info                  CSI    000002ce [SR] Verify complete
    2014-04-28 01:51:32, Info                  CSI    000002cf [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:51:32, Info                  CSI    000002d0 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:51:37, Info                  CSI    000002d3 [SR] Verify complete
    2014-04-28 01:51:37, Info                  CSI    000002d4 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:51:37, Info                  CSI    000002d5 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:51:43, Info                  CSI    000002d7 [SR] Verify complete
    2014-04-28 01:51:44, Info                  CSI    000002d8 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:51:44, Info                  CSI    000002d9 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:51:51, Info                  CSI    000002db [SR] Verify complete
    2014-04-28 01:51:51, Info                  CSI    000002dc [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:51:51, Info                  CSI    000002dd [SR] Beginning Verify and Repair transaction
    2014-04-28 01:51:57, Info                  CSI    000002e0 [SR] Verify complete
    2014-04-28 01:51:57, Info                  CSI    000002e1 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:51:57, Info                  CSI    000002e2 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:52:03, Info                  CSI    000002e4 [SR] Verify complete
    2014-04-28 01:52:04, Info                  CSI    000002e5 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:52:04, Info                  CSI    000002e6 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:52:10, Info                  CSI    000002e9 [SR] Verify complete
    2014-04-28 01:52:10, Info                  CSI    000002ea [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:52:10, Info                  CSI    000002eb [SR] Beginning Verify and Repair transaction
    2014-04-28 01:52:17, Info                  CSI    000002ed [SR] Verify complete
    2014-04-28 01:52:17, Info                  CSI    000002ee [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:52:17, Info                  CSI    000002ef [SR] Beginning Verify and Repair transaction
    2014-04-28 01:52:25, Info                  CSI    000002f2 [SR] Verify complete
    2014-04-28 01:52:26, Info                  CSI    000002f3 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:52:26, Info                  CSI    000002f4 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:52:31, Info                  CSI    000002f6 [SR] Verify complete
    2014-04-28 01:52:32, Info                  CSI    000002f7 [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:52:32, Info                  CSI    000002f8 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:52:39, Info                  CSI    000002fa [SR] Verify complete
    2014-04-28 01:52:39, Info                  CSI    000002fb [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:52:39, Info                  CSI    000002fc [SR] Beginning Verify and Repair transaction
    2014-04-28 01:52:44, Info                  CSI    000002fe [SR] Verify complete
    2014-04-28 01:52:44, Info                  CSI    000002ff [SR] Verifying 100 (0x0000000000000064) components
    2014-04-28 01:52:44, Info                  CSI    00000300 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:52:50, Info                  CSI    00000302 [SR] Verify complete
    2014-04-28 01:52:51, Info                  CSI    00000303 [SR] Verifying 50 (0x0000000000000032) components
    2014-04-28 01:52:51, Info                  CSI    00000304 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:52:54, Info                  CSI    00000306 [SR] Verify complete
    2014-04-28 01:52:54, Info                  CSI    00000307 [SR] Repairing 0 components
    2014-04-28 01:52:54, Info                  CSI    00000308 [SR] Beginning Verify and Repair transaction
    2014-04-28 01:52:54, Info                  CSI    0000030a [SR] Repair complete

    • 0

    #12
    infected99.9

    infected99.9

      Member

    • Topic Starter
    • Member
    • PipPip
    • 19 posts

    Event Viewer did not work. When I run both sets on VEW I receive the following Run-ime error:

     
    2147023836 (80070424)
     
    Automation error
    The specified service does not exist as an installed service.

    • 0

    #13
    infected99.9

    infected99.9

      Member

    • Topic Starter
    • Member
    • PipPip
    • 19 posts

    Process Explorer Log:

     

    Process CPU Private Bytes Working Set PID Description Company Name Verified Signer
    System Idle Process 96.53 0 K 24 K 0
    procexp64.exe 1.89 29,408 K 48,840 K 4476 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Sysinternals
    netsession_win.exe 0.35 12,508 K 19,980 K 3804 Akamai NetSession Client Akamai Technologies, Inc. (Verified) Akamai Technologies
    svchost.exe 0.19 182,520 K 189,944 K 304 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    Interrupts 0.14 0 K 0 K n/a Hardware Interrupts and DPCs
    dwm.exe 0.13 33,168 K 32,204 K 2416 Desktop Window Manager Microsoft Corporation (Verified) Microsoft Windows
    System 0.13 112 K 304 K 4
    svchost.exe 0.11 4,160 K 7,892 K 768 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    mbam.exe 0.08 28,620 K 46,268 K 932 Malwarebytes Anti-Malware Malwarebytes Corporation (Verified) Malwarebytes Corporation
    csrss.exe 0.07 3,216 K 7,532 K 544 Client Server Runtime Process Microsoft Corporation (Verified) Microsoft Windows
    htcUPCTLoader.exe 0.07 239,212 K 41,744 K 732 HTC UPCT Loader (No signature was present in the subject)
    explorer.exe 0.06 48,212 K 78,320 K 2644 Windows Explorer Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
    WDDriveService.exe 0.04 9,268 K 13,664 K 2252 WD Drive Service Western Digital Technologies, Inc. (Verified) Western Digital Technologies
    LMS.exe 0.04 2,564 K 4,964 K 4844 Local Manageability Service Intel Corporation (Verified) Intel Corporation
    CCC.exe 0.03 104,208 K 21,184 K 4120 Catalyst Control Center: Host application ATI Technologies Inc. (No signature was present in the subject) ATI Technologies Inc.
    WDDMStatus.exe 0.02 12,756 K 19,384 K 3848 WD Quick View Western Digital Technologies, Inc. (Verified) Western Digital Technologies
    wmpnetwk.exe 0.02 394,392 K 10,716 K 5444 Windows Media Player Network Sharing Service Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
    iPodService.exe 0.02 2,708 K 6,944 K 4168 iPodService Module (64-bit) Apple Inc. (Verified) Apple Inc.
    WDDriveAutoUnlock.exe 0.02 2,460 K 7,764 K 3248 WD Drive Auto Unlock Western Digital Technologies, Inc. (Verified) Western Digital Technologies
    svchost.exe 0.01 5,088 K 9,976 K 2988 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    MOM.exe 0.01 44,116 K 11,544 K 3792 Catalyst Control Center: Monitoring program Advanced Micro Devices Inc. (No signature was present in the subject) Advanced Micro Devices Inc.
    lsm.exe 0.01 2,992 K 4,668 K 664 Local Session Manager Service Microsoft Corporation (Verified) Microsoft Windows
    adb.exe < 0.01 1,668 K 4,936 K 3016 (Verified) Nero AG
    AppleMobileDeviceService.exe < 0.01 3,316 K 9,688 K 1840 YSLoader.exe Apple Inc. (Verified) Apple Inc.
    VESMgrSub.exe < 0.01 6,232 K 13,472 K 2448 VAIO Event Service (Service Sub Module) Sony Corporation (Verified) Sony Corporation
    taskhost.exe < 0.01 12,644 K 12,592 K 2164 Host Process for Windows Tasks Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
    HSMServiceEntry.exe < 0.01 7,776 K 12,152 K 1104 NService Application Nero AG (Verified) Nero AG
    lsass.exe < 0.01 4,240 K 10,836 K 652 Local Security Authority Process Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
    SearchIndexer.exe < 0.01 45,000 K 29,184 K 1740 Microsoft Windows Search Indexer Microsoft Corporation (Verified) Microsoft Windows
    SynTPEnh.exe < 0.01 9,360 K 15,144 K 3192 Synaptics TouchPad Enhancements Synaptics Incorporated (Verified) Microsoft Windows Hardware Compatibility Publisher
    WDBackupEngine.exe < 0.01 37,724 K 39,208 K 2384 WD Backup Engine Western Digital Technologies, Inc. (Verified) Western Digital Technologies
    MsMpEng.exe < 0.01 209,176 K 33,116 K 916 Antimalware Service Executable Microsoft Corporation (Verified) Microsoft Corporation
    svchost.exe < 0.01 13,436 K 13,276 K 1164 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    iTunesHelper.exe < 0.01 3,768 K 11,508 K 3696 iTunesHelper Apple Inc. (Verified) Apple Inc.
    svchost.exe < 0.01 11,884 K 24,480 K 760 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    netsession_win.exe < 0.01 3,084 K 8,308 K 3088 Akamai NetSession Client Akamai Technologies, Inc. (Verified) Akamai Technologies
    csrss.exe < 0.01 2,684 K 5,660 K 452 Client Server Runtime Process Microsoft Corporation (Verified) Microsoft Windows
    PhotoshopElementsFileAgent.exe < 0.01 2,008 K 1,276 K 4656 Adobe Photoshop Elements 9.0 (component) Adobe Systems Incorporated (Verified) Adobe Systems Incorporated
    PMBVolumeWatcher.exe < 0.01 5,204 K 1,288 K 3468 Media Check Tool Sony Corporation (Verified) Sony Corporation
    WmiApSrv.exe 1,548 K 4,728 K 2344 WMI Performance Reverse Adapter Microsoft Corporation (Verified) Microsoft Windows
    WLIDSVCM.EXE 1,512 K 3,484 K 2400 Microsoft® Windows Live ID Service Monitor Microsoft Corp. (Verified) Microsoft Corporation
    WLIDSVC.EXE 5,336 K 11,516 K 2288 Microsoft® Windows Live ID Service Microsoft Corp. (Verified) Microsoft Corporation
    wlanext.exe 2,728 K 6,816 K 1312 Windows Wireless LAN 802.11 Extensibility Framework Microsoft Corporation (Verified) Microsoft Windows
    winlogon.exe 3,344 K 7,832 K 584 Windows Logon Application Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
    wininit.exe 1,676 K 4,672 K 516 Windows Start-Up Application Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
    VUAgent.exe 2,788 K 8,044 K 4100 VUAgent Sony Corporation (Verified) Sony Corporation
    VSNService.exe 2,988 K 8,460 K 4236 VAIO Smart Network Service Sony Corporation (Verified) Sony Corporation
    VSNClient.exe 4,528 K 13,392 K 4864 VAIO Smart Network Sony Corporation (Verified) Sony Corporation
    VESMgrSub.exe 4,080 K 8,592 K 2424 VAIO Event Service (Service Sub Module) Sony Corporation (Verified) Sony Corporation
    VESMgr.exe 2,340 K 6,464 K 2204 VAIO Event Service (Service Module) Sony Corporation (Verified) Sony Corporation
    VESGfxMgr.exe 2,152 K 6,020 K 1880 VAIO Event Service (VESVideo Module) Sony Corporation (Verified) Sony Corporation
    vds.exe 2,636 K 7,876 K 5752 Virtual Disk Service Microsoft Corporation (Verified) Microsoft Windows
    VCsystray.exe 56,208 K 900 K 1992 VAIO Care Sony Corporation (Verified) Sony Corporation
    VCService.exe 1,412 K 5,040 K 6124 VAIOCare Sony Corporation (Verified) Sony Corporation
    VCPerfService.exe 12,960 K 17,248 K 4316 VAIO Care Performance Service Sony Corporation (Verified) Sony Corporation of America
    VCAgent.exe 58,496 K 48,696 K 5268 VCAgent Sony Corporation (Verified) Sony Corporation
    VAIOUpdt.exe 3,904 K 3,160 K 5608 VAIOUpdt Sony Corporation (Verified) Sony Corporation
    VAIO Gate.exe 31,532 K 5,976 K 3800 VAIO Gate Sony Corporation (Verified) Sony Corporation
    UNS.exe 3,204 K 7,304 K 6108 User Notification Service Intel Corporation (Verified) Intel Corporation
    uCamMonitor.exe 1,796 K 4,872 K 1180 MgiSvr ArcSoft, Inc. (Verified) ArcSoft
    taskeng.exe 2,520 K 6,248 K 3372 Task Scheduler Engine Microsoft Corporation (Verified) Microsoft Windows
    taskeng.exe 2,404 K 6,100 K 3008 Task Scheduler Engine Microsoft Corporation (Verified) Microsoft Windows
    SynTPHelper.exe 1,560 K 3,608 K 3392 Synaptics Pointing Device Helper Synaptics Incorporated (Verified) Microsoft Windows Hardware Compatibility Publisher
    svchost.exe 5,232 K 9,376 K 852 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    svchost.exe 1,996 K 5,564 K 2176 Host Process for Windows Services Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
    svchost.exe 14,740 K 14,572 K 264 Host Process for Windows Services Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
    svchost.exe 11,236 K 14,116 K 1568 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
    svchost.exe 7,160 K 11,152 K 708 Host Process for Windows Services Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
    svchost.exe 2,184 K 5,388 K 1080 Host Process for Windows Services Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
    spoolsv.exe 7,288 K 13,600 K 1528 Spooler SubSystem App Microsoft Corporation (Verified) Microsoft Windows
    SPMService.exe 4,692 K 10,200 K 5132 SPM Module Sony Corporation (Verified) Sony Corporation
    SPMgr.exe 5,588 K 792 K 4896 SPM Module Sony Corporation (Verified) Sony Corporation
    smss.exe 544 K 1,200 K 284 Windows Session Manager Microsoft Corporation (Verified) Microsoft Windows
    services.exe 7,072 K 10,556 K 628 Services and Controller app Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
    RAVBg64.exe 15,216 K 11,212 K 4092 HD Audio Background Process Realtek Semiconductor (Verified) Microsoft Windows Hardware Compatibility Publisher
    procexp.exe 6,732 K 10,076 K 1452 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
    PresentationFontCache.exe 31,428 K 27,324 K 3092 PresentationFontCache.exe Microsoft Corporation (Verified) Microsoft Corporation
    PMBDeviceInfoProvider.exe 1,436 K 4,612 K 2132 Device Information Provider Sony Corporation (Verified) Sony Corporation
    PassThruSvr.exe 1,332 K 3,348 K 1924 PassThruSvr Application (No signature was present in the subject)
    notepad.exe 10,040 K 25,788 K 4068 Notepad Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
    notepad.exe 1,900 K 6,500 K 4620 Notepad Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
    msseces.exe 6,536 K 14,780 K 3632 Microsoft Security Client User Interface Microsoft Corporation (Verified) Microsoft Corporation
    mfevtps.exe 2,408 K 5,104 K 1764 McAfee Process Validation Service McAfee, Inc. (Verified) McAfee
    mDNSResponder.exe 2,396 K 5,864 K 1932 Bonjour Service Apple Inc. (Verified) Apple Inc.
    mbamservice.exe 143,636 K 6,700 K 1296 Malwarebytes Anti-Malware Malwarebytes Corporation (Verified) Malwarebytes Corporation
    mbamscheduler.exe 5,584 K 10,588 K 1224 Malwarebytes Anti-Malware Malwarebytes Corporation (Verified) Malwarebytes Corporation
    listener.exe 1,288 K 4,764 K 4900 VaioCare Window Listener Application Sony of America Corporation (Verified) Sony Corporation of America
    ISBMgr.exe 2,812 K 8,560 K 3212 Sony Corporation (Verified) Sony Corporation
    E_S40STB.EXE 1,592 K 3,928 K 2004 EPSON Status Monitor 3 SEIKO EPSON CORPORATION (Verified) SEIKO EPSON Corporation
    E_S40RPB.EXE 1,436 K 3,448 K 2036 EPSON Status Monitor 3 SEIKO EPSON CORPORATION (No signature was present in the subject) SEIKO EPSON CORPORATION
    dllhost.exe 3,460 K 7,008 K 2576 COM Surrogate Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
    dllhost.exe 3,596 K 7,576 K 3472 COM Surrogate Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
    dllhost.exe 2,920 K 6,396 K 2532 COM Surrogate Microsoft Corporation (Verified) Microsoft Windows
    conhost.exe 1,068 K 2,812 K 1320 Console Window Host Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
    BtvStack.exe 9,004 K 11,836 K 3140 Bluetooth Tray Atheros Commnucations (Certificate expired) Atheros Commnucations
    brs.exe 1,168 K 4,192 K 820 brs cyberlink (Verified) CyberLink Corp.
    atiesrxx.exe 1,728 K 4,516 K 1012 AMD External Events Service Module AMD (Verified) Microsoft Windows Hardware Compatibility Publisher
    atieclxx.exe 2,568 K 6,712 K 1200 AMD External Events Client Module AMD (Verified) Microsoft Windows Hardware Compatibility Publisher
    AthBtTray.exe 5,228 K 13,352 K 3204 Bluetooth Tray Atheros Commnucations (Certificate expired) Atheros Commnucations
    Ath_CoexAgent.exe 1,732 K 5,060 K 1860 Atheros Coex Service Application Atheros (Certificate expired) Atheros
    armsvc.exe 1,216 K 3,900 K 1812 Adobe Acrobat Update Service Adobe Systems Incorporated (Verified) Adobe Systems
    AdminService.exe 2,244 K 6,064 K 1892 AdminService Application Atheros Commnucations (Certificate expired) Atheros Commnucations
    acrotray.exe 1,352 K 4,708 K 3912 AcroTray Adobe Systems Inc. (Verified) Adobe Systems

    • 0

    #14
    RKinner

    RKinner

      Malware Expert

    • Expert
    • 24,624 posts
    • MVP

    This should clean up the proxies and also give us some of the same info that VEW would.

     

    Please download minitoolbox
     
     
    save it to your desktop and run it by right clicking and Run As Admin.
     
    Checkmark the following checkboxes:
    •  
    • Flush DNS
    • Report IE Proxy Settings
    • Reset IE Proxy Settings
    • Report FF Proxy Settings
    • Reset FF Proxy Settings
    • List content of Hosts
    • List IP configuration
    • List Winsock Entries
    • List last 10 Event Viewer Errors
    • List Installed Programs
    • List Devices
    • List Users, Partitions and Memory size.
    • List Minidump Files
     
    Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.
     
    Note: When using "Reset FF Proxy Settings" option Firefox should be closed.
     
    Run OTL Quickscan and post its log.  (You will only get one)

    • 0

    #15
    infected99.9

    infected99.9

      Member

    • Topic Starter
    • Member
    • PipPip
    • 19 posts
    MiniToolBox by Farbar  Version: 23-01-2014
    Ran by User (administrator) on 28-04-2014 at 09:12:06
    Running from "C:\Users\User\Desktop"
    Windows 7 Home Premium Service Pack 1 (X64)
    Boot Mode: Normal
    ***************************************************************************
     
    ========================= Flush DNS: ===================================
     
    Windows IP Configuration
     
    Successfully flushed the DNS Resolver Cache.
     
    ========================= IE Proxy Settings: ============================== 
     
    Proxy is not enabled.
    ProxyServer: cslibproxy:80
     
    "Reset IE Proxy Settings": IE Proxy Settings were reset.
     
    ========================= FF Proxy Settings: ============================== 
     
    "network.proxy.autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20(url.indexOf('turntable.fm')%20!%3D%20-1%20%26%26%20url.indexOf('static.turntable.fm')%20%3D%3D%20-1%20%26%26%20url.indexOf('s3.amazonaws.com')%20%3D%3D%20-1%20%26%26%20url.indexOf('ping.chartbeat.net')%20%3D%3D%20-1)%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1)%20%7B%20return%20'PROXY%20ab-us03.personalitycores.com%3A8000%3B%20PROXY%20ab-us09.personalitycores.com%3A8000%3B%20PROXY%20ab-us06.personalitycores.com%3A8000%3B%20PROXY%20ab-us10.personalitycores.com%3A8000%3B%20PROXY%20ab-us02.personalitycores.com%3A8000%3B%20PROXY%20ab-us11.personalitycores.com%3A8000%3B%20PROXY%20ab-us13.personalitycores.com%3A8000%3B%20PROXY%20ab-us08.personalitycores.com%3A8000%3B%20PROXY%20ab-us07.personalitycores.com%3A8000%3B%20PROXY%20ab-us01.personalitycores.com%3A8000%3B%20PROXY%20ab-us12.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
     
    "Reset FF Proxy Settings": Firefox Proxy settings were reset.
     
    ========================= Hosts content: =================================
    127.0.0.1 ood.opsource.net
    127.0.0.1 localhost
    127.0.0.1 3dns.adobe.com
    127.0.0.1 3dns-1.adobe.com
    127.0.0.1 3dns-2.adobe.com
    127.0.0.1 3dns-3.adobe.com
    127.0.0.1 3dns-4.adobe.com
    127.0.0.1 activate.adobe.com
    127.0.0.1 activate-sea.adobe.com
    127.0.0.1 activate-sjc0.adobe.com
    127.0.0.1 activate.wip.adobe.com
    127.0.0.1 activate.wip1.adobe.com
    127.0.0.1 activate.wip2.adobe.com
    127.0.0.1 activate.wip3.adobe.com
    127.0.0.1 activate.wip4.adobe.com
    127.0.0.1 adobe-dns.adobe.com
    127.0.0.1 adobe-dns-1.adobe.com
    127.0.0.1 adobe-dns-2.adobe.com
    127.0.0.1 adobe-dns-3.adobe.com
    127.0.0.1 adobe-dns-4.adobe.com
     
    There are 28 more lines starting with "127.0.0.1"
     
    ========================= IP Configuration: ================================
     
     
     
    # ----------------------------------
    # IPv4 Configuration
    # ----------------------------------
    pushd interface ipv4
     
    reset
    set global icmpredirects=enabled
     
     
    popd
    # End of IPv4 configuration
     
     
     
    Windows IP Configuration
     
       Host Name . . . . . . . . . . . . : *****-VAIO
       Primary Dns Suffix  . . . . . . . : 
       Node Type . . . . . . . . . . . . : Hybrid
       IP Routing Enabled. . . . . . . . : No
       WINS Proxy Enabled. . . . . . . . : No
       DNS Suffix Search List. . . . . . : home
     
    Wireless LAN adapter Wireless Network Connection 2:
     
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . : 
       Description . . . . . . . . . . . : Microsoft Virtual WiFi Miniport Adapter
       Physical Address. . . . . . . . . : EE-AF-78-B7-51-F3
       DHCP Enabled. . . . . . . . . . . : Yes
       Autoconfiguration Enabled . . . . : Yes
     
    Wireless LAN adapter Wireless Network Connection:
     
       Connection-specific DNS Suffix  . : home
       Description . . . . . . . . . . . : Atheros AR9285 Wireless Network Adapter
       Physical Address. . . . . . . . . : CC-AF-78-B7-51-F3
       DHCP Enabled. . . . . . . . . . . : Yes
       Autoconfiguration Enabled . . . . : Yes
       Link-local IPv6 Address . . . . . : fe80::1d3c:e042:faa5:b816%14(Preferred) 
       IPv4 Address. . . . . . . . . . . : 192.168.1.64(Preferred) 
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Lease Obtained. . . . . . . . . . : 28 April 2014 02:19:35
       Lease Expires . . . . . . . . . . : 29 April 2014 09:08:34
       Default Gateway . . . . . . . . . : 192.168.1.254
       DHCP Server . . . . . . . . . . . : 192.168.1.254
       DHCPv6 IAID . . . . . . . . . . . : 365735800
       DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-17-57-80-36-F0-BF-97-68-71-31
       DNS Servers . . . . . . . . . . . : 192.168.1.254
       NetBIOS over Tcpip. . . . . . . . : Enabled
     
    Ethernet adapter Local Area Connection:
     
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . : 
       Description . . . . . . . . . . . : Atheros AR8151 PCI-E Gigabit Ethernet Controller (NDIS 6.20)
       Physical Address. . . . . . . . . : F0-BF-97-68-71-31
       DHCP Enabled. . . . . . . . . . . : Yes
       Autoconfiguration Enabled . . . . : Yes
     
    Tunnel adapter isatap.{F9EBD23D-D69C-4E7C-8E1F-19A95B190E98}:
     
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . : 
       Description . . . . . . . . . . . : Microsoft ISATAP Adapter
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
     
    Tunnel adapter isatap.home:
     
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . : 
       Description . . . . . . . . . . . : Microsoft ISATAP Adapter #2
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
     
    Tunnel adapter isatap.{FC29F66D-2EC7-4F5C-8CE2-111B3D11A3FE}:
     
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . : 
       Description . . . . . . . . . . . : Microsoft ISATAP Adapter #3
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
     
    Tunnel adapter Teredo Tunneling Pseudo-Interface:
     
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . : 
       Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
       Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
       DHCP Enabled. . . . . . . . . . . : No
       Autoconfiguration Enabled . . . . : Yes
    Server:  BThomehub.home
    Address:  192.168.1.254
     
    Name:    google.com
    Addresses:  2a00:1450:4009:805::1004
     173.194.34.169
     173.194.34.160
     173.194.34.161
     173.194.34.168
     173.194.34.162
     173.194.34.167
     173.194.34.174
     173.194.34.164
     173.194.34.165
     173.194.34.166
     173.194.34.163
     
     
    Pinging google.com [173.194.34.168] with 32 bytes of data:
    Reply from 173.194.34.168: bytes=32 time=22ms TTL=52
    Reply from 173.194.34.168: bytes=32 time=21ms TTL=52
     
    Ping statistics for 173.194.34.168:
        Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 21ms, Maximum = 22ms, Average = 21ms
    Server:  BThomehub.home
    Address:  192.168.1.254
     
    Name:    yahoo.com
    Addresses:  98.138.253.109
     206.190.36.45
     98.139.183.24
     
     
    Pinging yahoo.com [206.190.36.45] with 32 bytes of data:
    Reply from 206.190.36.45: bytes=32 time=171ms TTL=42
    Reply from 206.190.36.45: bytes=32 time=168ms TTL=42
     
    Ping statistics for 206.190.36.45:
        Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 168ms, Maximum = 171ms, Average = 169ms
     
    Pinging 127.0.0.1 with 32 bytes of data:
    Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
    Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
     
    Ping statistics for 127.0.0.1:
        Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 0ms, Maximum = 0ms, Average = 0ms
    ===========================================================================
    Interface List
     16...ee af 78 b7 51 f3 ......Microsoft Virtual WiFi Miniport Adapter
     14...cc af 78 b7 51 f3 ......Atheros AR9285 Wireless Network Adapter
     13...f0 bf 97 68 71 31 ......Atheros AR8151 PCI-E Gigabit Ethernet Controller (NDIS 6.20)
      1...........................Software Loopback Interface 1
     19...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
     18...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
     20...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #3
     17...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
    ===========================================================================
     
    IPv4 Route Table
    ===========================================================================
    Active Routes:
    Network Destination        Netmask          Gateway       Interface  Metric
              0.0.0.0          0.0.0.0    192.168.1.254     192.168.1.64     25
            127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
            127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
      127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
          192.168.1.0    255.255.255.0         On-link      192.168.1.64    281
         192.168.1.64  255.255.255.255         On-link      192.168.1.64    281
        192.168.1.255  255.255.255.255         On-link      192.168.1.64    281
            224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
            224.0.0.0        240.0.0.0         On-link      192.168.1.64    281
      255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      255.255.255.255  255.255.255.255         On-link      192.168.1.64    281
    ===========================================================================
    Persistent Routes:
      None
     
    IPv6 Route Table
    ===========================================================================
    Active Routes:
     If Metric Network Destination      Gateway
      1    306 ::1/128                  On-link
     14    281 fe80::/64                On-link
     14    281 fe80::1d3c:e042:faa5:b816/128
                                        On-link
      1    306 ff00::/8                 On-link
     14    281 ff00::/8                 On-link
    ===========================================================================
    Persistent Routes:
      None
    ========================= Winsock entries =====================================
     
    Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
    Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
    Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
    Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
    Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
    Catalog5 07 C:\Windows\SysWOW64\wshbth.dll [36352] (Microsoft Corporation)
    Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
    Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
    Catalog5 10 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
    Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    Catalog9 11 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
    x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
    x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
    x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
    x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
    x64-Catalog5 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
    x64-Catalog5 07 C:\Windows\System32\wshbth.dll [47104] (Microsoft Corporation)
    x64-Catalog5 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)
    x64-Catalog5 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)
    x64-Catalog5 10 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.)
    x64-Catalog9 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog9 02 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog9 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog9 04 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog9 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog9 06 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog9 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog9 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog9 09 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog9 10 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
    x64-Catalog9 11 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
     
    ========================= Event log errors: ===============================
     
    Application errors:
    ==================
    Error: (04/28/2014 01:29:57 AM) (Source: Application Hang) (User: )
    Description: The program BitTorrent.exe version 7.9.1.30889 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
     
    Process ID: c4c
     
    Start Time: 01cf6278cb3011b6
     
    Termination Time: 0
     
    Application Path: C:\Users\User\AppData\Roaming\BitTorrent\BitTorrent.exe
     
    Report Id: 289a1d40-ce6c-11e3-ae14-f0bf97687131
     
     
    System errors:
    =============
    Error: (04/28/2014 01:33:50 AM) (Source: VDS Basic Provider) (User: )
    Description: Unexpected failure. Error code: 490@01010004
     
    Error: (04/28/2014 01:32:12 AM) (Source: Service Control Manager) (User: )
    Description: The Security Center service depends the following service: winmgmt. This service might not be installed.
     
    Error: (04/28/2014 01:30:57 AM) (Source: Service Control Manager) (User: )
    Description: The Security Center service depends the following service: winmgmt. This service might not be installed.
     
    Error: (04/28/2014 01:30:10 AM) (Source: Service Control Manager) (User: )
    Description: The Security Center service depends the following service: winmgmt. This service might not be installed.
     
    Error: (04/28/2014 01:26:54 AM) (Source: Service Control Manager) (User: )
    Description: The IP Helper service depends the following service: winmgmt. This service might not be installed.
     
     
    Microsoft Office Sessions:
    =========================
    Error: (09/02/2013 07:13:51 PM) (Source: Microsoft Office 12 Sessions)(User: )
    Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 18341 seconds with 8280 seconds of active time.  This session ended with a crash.
     
     
    CodeIntegrity Errors:
    ===================================
      Date: 2012-10-10 11:41:57.470
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
      Date: 2012-10-10 11:41:57.439
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
      Date: 2012-10-10 11:41:34.955
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
      Date: 2012-10-10 11:41:34.841
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
      Date: 2012-10-10 11:39:08.620
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
      Date: 2012-10-10 11:39:08.600
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
      Date: 2012-10-10 11:37:23.163
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
      Date: 2012-10-10 11:37:22.688
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
      Date: 2012-10-10 11:35:21.676
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
      Date: 2012-10-10 11:35:21.401
      Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
     
     
    =========================== Installed Programs ============================
     
     Update for Microsoft Office 2007 (KB2508958)
    ?????? Windows Live (Version: 15.4.3502.0922)
    ??????? ????????? Windows Live Mesh ActiveX ??? ?????????? ?????????? (Version: 15.4.5722.2)
    ??????? ?????????? Windows Live Mesh ActiveX ??? ????????? ??????????? (Version: 15.4.5722.2)
    ???????? ?????????? Windows Live (Version: 15.4.3502.0922)
    ?????????? Windows Live (Version: 15.4.3502.0922)
    ??????????? ?? Windows Live (Version: 15.4.3502.0922)
    ???????????? Windows Live (Version: 15.4.3502.0922)
    ActiveX ???????? ?? Windows Live Mesh ?? ?????????? ?????? (Version: 15.4.5722.2)
    ActiveX-kontroll för fjärranslutningar för Windows Live Mesh (Version: 15.4.5722.2)
    Adobe Acrobat X Pro - English, Français, Deutsch (Version: 10.1.9)
    Adobe AIR (Version: 3.5.0.880)
    Adobe Community Help (Version: 3.4.980)
    Adobe Content Viewer (Version: 1.4.0)
    Adobe Creative Suite 5.5 Master Collection (Version: 5.5)
    Adobe Flash Player 12 ActiveX (Version: 12.0.0.77)
    Adobe Flash Player 12 Plugin (Version: 12.0.0.77)
    Adobe Photoshop Elements 9 (Version: 9.0.3.0)
    Adobe Premiere Elements 9 (Version: 9.0)
    Adobe Premiere Elements 9 (Version: 9.0.1)
    Adobe Reader X (10.1.9) MUI (Version: 10.1.9)
    Adobe Story (Version: 1.0.571)
    Adobe Widget Browser (Version: 2.0 Build 230)
    Adobe Widget Browser (Version: 2.0.230)
    Aimersoft Video Converter Ultimate(Build 4.2.1.0)
    Akamai NetSession Interface
    AMD APP SDK Runtime (Version: 2.4.595.10)
    Apple Application Support (Version: 3.0.1)
    Apple Mobile Device Support (Version: 7.1.1.3)
    Apple Software Update (Version: 2.1.3.127)
    ArcSoft Magic-i Visual Effects 2 (Version: 2.0.1.142)
    ArcSoft WebCam Companion 4 (Version: 4.0.21.484)
    Atheros WiFi Driver Installation (Version: 3.0)
    ATI Catalyst Install Manager (Version: 3.0.825.0)
    Basic PAYE Tools - Real Time Information (Version: 13.1.13137.112)
    Basic PAYE Tools 2012 (Version: 4.2.1.20469)
    BBC iPlayer Desktop (Version: 3.0.11)
    BBC iPlayer Downloads (Version: 1.0.2)
    Bing Bar (Version: 7.0.850.0)
    BitTorrent (Version: 7.9.1.30889)
    BlackBerry Desktop Software 7.1 (Version: 7.1.0.32)
    Bluetooth Win7 Suite (64) (Version: 7.3.0.100)
    Bonjour (Version: 3.0.0.10)
    Canon MP Navigator 3.1
    Canon MP140 series
    Catalyst Control Center Graphics Previews Common (Version: 2011.0127.629.11510)
    Catalyst Control Center Localization All (Version: 2011.0127.629.11510)
    CCC Help Chinese Standard (Version: 2011.0127.0628.11510)
    CCC Help Chinese Traditional (Version: 2011.0127.0628.11510)
    CCC Help Czech (Version: 2011.0127.0628.11510)
    CCC Help Danish (Version: 2011.0127.0628.11510)
    CCC Help Dutch (Version: 2011.0127.0628.11510)
    CCC Help English (Version: 2011.0127.0628.11510)
    CCC Help Finnish (Version: 2011.0127.0628.11510)
    CCC Help French (Version: 2011.0127.0628.11510)
    CCC Help German (Version: 2011.0127.0628.11510)
    CCC Help Greek (Version: 2011.0127.0628.11510)
    CCC Help Hungarian (Version: 2011.0127.0628.11510)
    CCC Help Italian (Version: 2011.0127.0628.11510)
    CCC Help Japanese (Version: 2011.0127.0628.11510)
    CCC Help Korean (Version: 2011.0127.0628.11510)
    CCC Help Norwegian (Version: 2011.0127.0628.11510)
    CCC Help Polish (Version: 2011.0127.0628.11510)
    CCC Help Portuguese (Version: 2011.0127.0628.11510)
    CCC Help Russian (Version: 2011.0127.0628.11510)
    CCC Help Spanish (Version: 2011.0127.0628.11510)
    CCC Help Swedish (Version: 2011.0127.0628.11510)
    CCC Help Thai (Version: 2011.0127.0628.11510)
    ccc-core-static (Version: 2011.0127.629.11510)
    ccc-utility64 (Version: 2011.0127.629.11510)
    Control ActiveX Windows Live Mesh pentru conexiuni la distan?a (Version: 15.4.5722.2)
    Contrôle ActiveX Windows Live Mesh pour connexions à distance (Version: 15.4.5722.2)
    Controlo ActiveX do Windows Live Mesh para Ligações Remotas (Version: 15.4.5722.2)
    CyberLink PowerDVD (Version: 9.0.6426.52)
    D3DX10 (Version: 15.4.2368.0902)
    Dropbox (Version: 2.6.2)
    EaseUS Data Recovery Wizard 5.6.5 (Version: 5.6.5)
    Elements 9 Organizer (Version: 9.0)
    Elements STI Installer (Version: 1.0)
    EPSON SX110 Series Printer Uninstall
    FlacSquisher 1.0.13 (Version: 1.0.13)
    Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsluge polaczen zdalnych (Version: 15.4.5722.2)
    Galeria de Fotografias do Windows Live (Version: 15.4.3502.0922)
    Galeria fotografii uslugi Windows Live (Version: 15.4.3502.0922)
    Galerie de photos Windows Live (Version: 15.4.3502.0922)
    Galerie foto Windows Live (Version: 15.4.3502.0922)
    GenoPro 2.5.4.1
    Google Chrome (Version: 34.0.1847.131)
    Google Drive (Version: 1.14.6059.644)
    Google Update Helper (Version: 1.3.23.9)
    HTC BMP USB Driver (Version: 1.0.5375)
    HTC Driver Installer (Version: 3.0.0.007)
    HTC Sync (Version: 3.3.21)
    HTC Sync Manager (Version: 1.1.77.0)
    Intel® Management Engine Components (Version: 7.0.0.1144)
    Intel® Processor ID Utility (Version: 4.80.0000)
    iTunes (Version: 11.1.5.5)
    Java 7 Update 51 (64-bit) (Version: 7.0.510)
    Java 7 Update 55 (Version: 7.0.550)
    Java Auto Updater (Version: 2.1.9.8)
    Junk Mail filter update (Version: 15.4.3502.0922)
    Malwarebytes Anti-Malware version 2.0.1.1004 (Version: 2.0.1.1004)
    Media Gallery (Version: 1.5.0.16020)
    Mesh Runtime (Version: 15.4.5722.2)
    Microsoft .NET Framework 4.5.1 (Version: 4.5.50938)
    Microsoft Application Error Reporting (Version: 12.0.6015.5000)
    Microsoft Expression Web (Version: 12.0.6215.1000)
    Microsoft Expression Web MUI (English) (Version: 12.0.6612.1000)
    Microsoft Expression Web Service Pack 1 (SP1)
    Microsoft Office 2007 Service Pack 3 (SP3)
    Microsoft Office 2010 (Version: 14.0.4763.1000)
    Microsoft Office Access MUI (English) 2007 (Version: 12.0.6612.1000)
    Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
    Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000)
    Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000)
    Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
    Microsoft Office Groove MUI (English) 2007 (Version: 12.0.6612.1000)
    Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
    Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.6612.1000)
    Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000)
    Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000)
    Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000)
    Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000)
    Microsoft Office Project 2007 Service Pack 3 (SP3)
    Microsoft Office Project MUI (English) 2007 (Version: 12.0.6612.1000)
    Microsoft Office Project Professional 2007 (Version: 12.0.6612.1000)
    Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)
    Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)
    Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000)
    Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014)
    Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6612.1000)
    Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000)
    Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
    Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000)
    Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
    Microsoft Office SharePoint Designer 2007 Service Pack 3 (SP3)
    Microsoft Office Visio 2007 Service Pack 3 (SP3)
    Microsoft Office Visio MUI (English) 2007 (Version: 12.0.6612.1000)
    Microsoft Office Visio Professional 2007 (Version: 12.0.6612.1000)
    Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000)
    Microsoft Security Client (Version: 4.5.0216.0)
    Microsoft Security Essentials (Version: 4.5.216.0)
    Microsoft Silverlight (Version: 5.1.30214.0)
    Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
    Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
    Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
    Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
    Microsoft_VC80_ATL_x86 (Version: 8.0.50727.4053)
    Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053)
    Microsoft_VC80_CRT_x86 (Version: 8.0.50727.4053)
    Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053)
    Microsoft_VC80_MFC_x86 (Version: 8.0.50727.4053)
    Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053)
    Microsoft_VC80_MFCLOC_x86 (Version: 8.0.50727.4053)
    Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053)
    Microsoft_VC90_ATL_x86 (Version: 1.00.0000)
    Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000)
    Microsoft_VC90_CRT_x86 (Version: 1.00.0000)
    Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000)
    Microsoft_VC90_MFC_x86 (Version: 1.00.0000)
    Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000)
    Microsoft_VC90_MFCLOC_x86 (Version: 1.00.0000)
    Microsoft_VC90_MFCLOC_x86_x64 (Version: 1.00.0000)
    MiniTool Partition Wizard Home Edition 8.1.1
    Monkey's Audio
    Mozilla Firefox 28.0 (x86 en-US) (Version: 28.0)
    Mozilla Maintenance Service (Version: 28.0)
    MSVCRT (Version: 15.4.2862.0708)
    MSVCRT_amd64 (Version: 15.4.2862.0708)
    MSXML 4.0 SP3 Parser (KB2721691) (Version: 4.30.2114.0)
    MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0)
    MSXML 4.0 SP3 Parser (KB973685) (Version: 4.30.2107.0)
    MSXML 4.0 SP3 Parser (Version: 4.30.2100.0)
    Music Manager
    Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená pripojení (Version: 15.4.5722.2)
    Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia (Version: 15.4.5722.2)
    Pam Call Recorder 4.8 (Version: 4.8)
    PDF Settings CS5 (Version: 10.0)
    PlayReady PC Runtime x86 (Version: 1.3.0)
    PMB (Version: 5.5.02.12220)
    PMB VAIO Edition Plug-in (Version: 1.5.00.02250)
    PMB VAIO Edition Plug-in (Version: 1.5.00.04010)
    Poczta uslugi Windows Live (Version: 15.4.3502.0922)
    Podstawowe programy Windows Live (Version: 15.4.3502.0922)
    PokerStars
    PxMergeModule (Version: 1.00.0000)
    Qualcomm Atheros Direct Connect (Version: 3.0)
    QuickTime 7 (Version: 7.75.80.95)
    Raccolta foto di Windows Live (Version: 15.4.3502.0922)
    Raptr
    Realtek HDMI Audio Driver for ATI (Version: 6.0.1.6650)
    Realtek High Definition Audio Driver (Version: 6.0.1.6526)
    Remote Keyboard (Version: 1.1.1.03020)
    Remote Play with PlayStation 3 (Version: 1.1.0.15070)
    Renesas Electronics USB 3.0 Host Controller Driver (Version: 2.0.32.0)
    S?????? f?t???af??? t?? Windows Live (Version: 15.4.3502.0922)
    Shared C Run-time for x64 (Version: 10.0.0)
    Skype™ 6.11 (Version: 6.11.102)
    SmartSound Quicktracks for Premiere Elements 9.0 (Version: 3.12.3090)
    Sony Corporation (Version: 1.0.0)
    Spotify (Version: 0.9.1.57.ge7405149)
    SSLx64 (Version: 1.0.0)
    SSLx86 (Version: 1.0.0)
    St???e?? e?????? ActiveX t?? Windows Live Mesh ??a ap?µa???sµ??e? s??d?se?? (Version: 15.4.5722.2)
    Steam (Version: 1.0.0.0)
    Synaptics Pointing Device Driver (Version: 15.2.6.0)
    System Requirements Lab for Intel (Version: 4.5.22.0)
    TriDef 3D (Sony) 1.1.3 (Version: 1.1.3)
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition
    Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
    Update for Microsoft Office Access 2007 Help (KB963663)
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office Infopath 2007 Help (KB963662)
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
    Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition
    Update for Microsoft Office Outlook 2007 Help (KB963677)
    Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2878297) 32-Bit Edition
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Project 2007 Help (KB963668)
    Update for Microsoft Office Publisher 2007 Help (KB963667)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Visio 2007 Help (KB963666)
    Update for Microsoft Office Word 2007 Help (KB963665)
    Uzak Baglantilar Için Windows Live Mesh ActiveX Denetimi (Version: 15.4.5722.2)
    V3DPX86 (Version: 1.0.0)
    VAIO - Media Gallery (Version: 1.5.0.16020)
    VAIO - PMB VAIO Edition Guide (Version: 1.5.00.02250)
    VAIO - PMB VAIO Edition Plug-in (Version: 1.5.00.04060)
    VAIO - Remote Keyboard (Version: 1.0.1.03020)
    VAIO - Remote Play with PlayStation®3 (Version: 1.1.0.15070)
    VAIO 3D Portal (Version: 1.0.1.09270)
    VAIO C Series - Summer 2011 Screensaver
    VAIO Care (Version: 6.4.0.15030)
    VAIO Control Center (Version: 4.5.0.03040)
    VAIO Data Restore Tool (Version: 1.6.0.13140)
    VAIO Easy Connect (Version: 1.1.2.01120)
    VAIO Event Service (Version: 5.5.0.03040)
    VAIO Gate (Version: 2.4.2.02200)
    VAIO Gate Default (Version: 2.4.0.03240)
    VAIO Hardware Diagnostics (Version: 4.2.0.14280)
    VAIO Improvement (Version: 1.0.0.14150)
    VAIO Improvement Validation (Version: 1.0.4.01190)
    VAIO Manual (Version: 1.3.0.02180)
    VAIO Quick Web Access (Version: 1.4.5.5)
    VAIO Sample Contents (Version: 1.4.2.09010)
    VAIO Smart Network (Version: 3.8.1.08270)
    VAIO Transfer Support (Version: 1.4.0.14230)
    VAIO Update (Version: 6.3.1.10120)
    VCCx86 (Version: 1.0.0)
    VESx64 (Version: 1.0.0)
    VESx86 (Version: 1.0.0)
    VGClientX64 (Version: 1.0.0)
    VIx64 (Version: 1.0.0)
    VIx86 (Version: 1.0.0)
    VLC media player 2.1.3 (Version: 2.1.3)
    VPMx64 (Version: 1.0.0)
    VSNx64 (Version: 1.0.0)
    VSNx86 (Version: 1.0.0)
    VU5x64 (Version: 1.1.0)
    VU5x86 (Version: 1.0.0)
    VU5x86 (Version: 1.1.0)
    VWSTx86 (Version: 1.0.0)
    WD Drive Utilities (Version: 1.0.6.3)
    WD Quick View (Version: 2.3.0.20)
    WD Security (Version: 1.0.7.3)
    WD SmartWare (Version: 2.3.0.20)
    WD SmartWare Installer (Version: 2.3.0.20)
    Windows Live Communications Platform (Version: 15.4.3502.0922)
    Windows Live Essentials (Version: 15.4.3502.0922)
    Windows Live Essentials (Version: 15.4.3508.1109)
    Windows Live Fotogaléria (Version: 15.4.3502.0922)
    Windows Live Fotogalerie (Version: 15.4.3502.0922)
    Windows Live Fotogalleri (Version: 15.4.3502.0922)
    Windows Live Fotograf Galerisi (Version: 15.4.3502.0922)
    Windows Live Fotótár (Version: 15.4.3502.0922)
    Windows Live ID Sign-in Assistant (Version: 7.250.4225.0)
    Windows Live Installer (Version: 15.4.3502.0922)
    Windows Live Language Selector (Version: 15.4.3508.1109)
    Windows Live Mail (Version: 15.4.3502.0922)
    Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (Version: 15.4.5722.2)
    Windows Live Mesh (Version: 15.4.3502.0922)
    Windows Live Mesh ActiveX control for remote connections (Version: 15.4.5722.2)
    Windows Live Mesh ActiveX Control for Remote Connections (Version: 15.4.5722.2)
    Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger (Version: 15.4.5722.2)
    Windows Live Mesh ActiveX-objekt til fjernforbindelser (Version: 15.4.5722.2)
    Windows Live Mesh ActiveX-vezérlo távoli kapcsolatokhoz (Version: 15.4.5722.2)
    Windows Live Meshin etäyhteyksien ActiveX-komponentti (Version: 15.4.5722.2)
    Windows Live Messenger (Version: 15.4.3502.0922)
    Windows Live MIME IFilter (Version: 15.4.3502.0922)
    Windows Live Movie Maker (Version: 15.4.3502.0922)
    Windows Live Photo Common (Version: 15.4.3502.0922)
    Windows Live Photo Gallery (Version: 15.4.3502.0922)
    Windows Live PIMT Platform (Version: 15.4.3508.1109)
    Windows Live Remote Client (Version: 15.4.5722.2)
    Windows Live Remote Client Resources (Version: 15.4.5722.2)
    Windows Live Remote Service (Version: 15.4.5722.2)
    Windows Live Remote Service Resources (Version: 15.4.5722.2)
    Windows Live SOXE (Version: 15.4.3502.0922)
    Windows Live SOXE Definitions (Version: 15.4.3502.0922)
    Windows Live Temel Parçalar (Version: 15.4.3502.0922)
    Windows Live UX Platform (Version: 15.4.3502.0922)
    Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
    Windows Live Writer (Version: 15.4.3502.0922)
    Windows Live Writer Resources (Version: 15.4.3502.0922)
    Windows Liven asennustyökalu (Version: 15.4.3502.0922)
    Windows Liven sähköposti (Version: 15.4.3502.0922)
    Windows Liven valokuvavalikoima (Version: 15.4.3502.0922)
    WinZip 16.5 (Version: 16.5.10096)
     
    =========================
    Windows Management Instrumentation service is not running. Could not scan devices
    =========================
     
     
    ========================= Memory info: ===================================
     
    Percentage of memory in use: 38%
    Total physical RAM: 6125.21 MB
    Available physical RAM: 3789.23 MB
    Total Pagefile: 12248.61 MB
    Available Pagefile: 8853.7 MB
    Total Virtual: 4095.88 MB
    Available Virtual: 3970.95 MB
     
    ========================= Partitions: =====================================
     
    1 Drive c: () (Fixed) (Total:580.58 GB) (Free:12.73 GB) NTFS
     
    ========================= Users: ========================================
     
    User accounts for \\*****-VAIO
     
    Administrator            Guest                    User                     
     
    ========================= Minidump Files ==================================
     
    No minidump file found
     
     
    **** End of log ****

    • 0






    Similar Topics

    0 user(s) are reading this topic

    0 members, 0 guests, 0 anonymous users

    As Featured On:

    Microsoft Yahoo BBC MSN PC Magazine Washington Post HP