Hello
Looking for help removing those annoying ads running in background....Tried malwarebytes,hitman pro,mse,trend micro housecall.etc.
Any help would be appreciated. Here are my OTL logs from quick scan.
OTL logfile created on: 5/5/2014 07:53:47 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Admin\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.75 Gb Total Physical Memory | 1.33 Gb Available Physical Memory | 35.41% Memory free
7.71 Gb Paging File | 4.99 Gb Available in Paging File | 64.66% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 288.67 Gb Total Space | 212.76 Gb Free Space | 73.70% Space Free | Partition Type: NTFS
Computer Name: ADMIN-PC | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/05/05 19:50:08 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe
PRC - [2014/04/14 03:05:08 | 000,349,472 | ---- | M] (Glarysoft Ltd) -- C:\Program Files (x86)\Glary Utilities 4\SoftwareUpdate.exe
PRC - [2012/07/27 15:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/05/25 13:32:36 | 005,207,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SoftwareDistribution\Download\Install\vcredist_x64.exe
PRC - [2008/04/11 02:51:58 | 000,083,312 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files (x86)\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
PRC - [2007/10/23 18:27:16 | 000,066,928 | ---- | M] () -- c:\Toshiba\IVP\swupdate\swupdtmr.exe
PRC - [2007/02/12 18:43:44 | 000,065,536 | ---- | M] (O2Micro International) -- C:\Program Files (x86)\O2Micro Flash Memory Card Driver\o2flash.exe
PRC - [2007/01/25 20:47:50 | 000,136,816 | ---- | M] () -- C:\Toshiba\IVP\ISM\pinger.exe
PRC - [2006/08/23 18:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
========== Modules (No Company Name) ==========
MOD - [2013/09/05 01:14:10 | 004,300,456 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/20 15:45:26 | 008,801,120 | ---- | M] () -- C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
========== Services (SafeList) ==========
SRV:64bit: - [2014/03/11 12:34:10 | 000,347,872 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2014/03/11 12:34:10 | 000,023,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2012/07/04 02:36:06 | 000,361,984 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2012/07/04 01:20:54 | 000,238,080 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010/09/22 19:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2008/04/24 21:57:40 | 000,084,992 | ---- | M] (Toshiba) [On_Demand | Running] -- C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe -- (SmartFaceVWatchSrv)
SRV:64bit: - [2008/02/06 16:50:18 | 000,434,016 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV:64bit: - [2008/01/20 21:47:32 | 000,383,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2007/12/03 20:04:48 | 000,175,104 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe -- (TOSHIBA SMART Log Service)
SRV:64bit: - [2007/10/18 02:37:22 | 000,412,672 | ---- | M] (Conexant Systems, Inc.) [Auto | Running] -- C:\Windows\SysNative\DRIVERS\xaudio64.exe -- (XAudioService)
SRV - [2013/09/11 22:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2012/12/24 01:38:24 | 000,000,000 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\drivers\XAudio64.exe -- (XAudioService)
SRV - [2012/12/24 01:38:24 | 000,000,000 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysWOW64\TODDSrv.exe -- (TODDSrv)
SRV - [2012/12/24 01:38:24 | 000,000,000 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\spoolsv.exe -- (Spooler)
SRV - [2012/12/24 01:38:24 | 000,000,000 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\SLsvc.exe -- (slsvc)
SRV - [2012/12/24 01:38:24 | 000,000,000 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\lsass.exe -- (SamSs)
SRV - [2012/12/24 01:38:24 | 000,000,000 | ---- | M] () [On_Demand | Running] -- C:\Windows\SysWOW64\lsass.exe -- (ProtectedStorage)
SRV - [2012/12/24 01:38:24 | 000,000,000 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\lsass.exe -- (Netlogon)
SRV - [2012/12/24 01:38:24 | 000,000,000 | ---- | M] () [On_Demand | Running] -- C:\Windows\SysWOW64\lsass.exe -- (KeyIso)
SRV - [2012/07/27 15:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2009/03/29 23:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/04/16 18:53:00 | 000,954,368 | ---- | M] (Atheros Communications, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Jumpstart\jswpsapi.exe -- (jswpsapi)
SRV - [2008/04/11 13:58:10 | 000,158,568 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service)
SRV - [2008/04/11 02:51:58 | 000,083,312 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files (x86)\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe -- (TNaviSrv)
SRV - [2008/01/29 12:09:58 | 000,165,416 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2007/10/23 18:27:16 | 000,066,928 | ---- | M] () [Auto | Running] -- c:\Toshiba\IVP\swupdate\swupdtmr.exe -- (Swupdtmr)
SRV - [2007/02/12 18:43:44 | 000,065,536 | ---- | M] (O2Micro International) [Auto | Running] -- C:\Program Files (x86)\O2Micro Flash Memory Card Driver\o2flash.exe -- (o2flash)
SRV - [2007/01/25 20:47:50 | 000,136,816 | ---- | M] () [Auto | Running] -- C:\Toshiba\IVP\ISM\pinger.exe -- (pinger)
SRV - [2006/08/23 18:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2014/03/11 09:52:30 | 000,133,928 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012/12/13 13:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012/07/04 01:59:32 | 011,922,944 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2012/07/04 01:59:32 | 011,922,944 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012/07/04 00:10:56 | 000,359,936 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012/03/08 19:40:52 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2012/02/29 08:52:46 | 000,016,384 | ---- | M] (Microsoft Corporation) [Recognizer | System | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2010/02/18 10:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2009/10/27 02:29:46 | 000,173,456 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\PTUMWVsp.sys -- (PTUMWVsp)
DRV:64bit: - [2009/10/27 02:29:40 | 000,173,456 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\PTUMWNSP.sys -- (PTUMWNSP)
DRV:64bit: - [2009/10/27 02:29:34 | 000,144,912 | ---- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\PTUMWNET.sys -- (PTUMWNET)
DRV:64bit: - [2009/10/27 02:29:26 | 000,173,456 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\PTUMWMdm.sys -- (PTUMWMdm)
DRV:64bit: - [2009/10/27 02:29:20 | 000,012,688 | ---- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\PTUMWFLT.sys -- (PTUMWFLT)
DRV:64bit: - [2009/10/27 02:29:14 | 000,173,456 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\PTUMWCSP.sys -- (PTUMWCSP)
DRV:64bit: - [2009/10/27 02:29:00 | 000,071,056 | ---- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\PTUMWBus.sys -- (PTUMWBus)
DRV:64bit: - [2009/09/30 19:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)
DRV:64bit: - [2009/04/22 18:28:36 | 001,388,032 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\athrx.sys -- (athr)
DRV:64bit: - [2009/01/20 00:43:48 | 000,004,608 | ---- | M] (SupportSoft Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\ssrangdr.sys -- (ssrangdr)
DRV:64bit: - [2008/10/28 16:49:58 | 000,222,720 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
DRV:64bit: - [2008/04/28 19:59:26 | 000,026,624 | ---- | M] (Atheros Communications, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\DRIVERS\jswpslwfx.sys -- (JSWPSLWF)
DRV:64bit: - [2008/04/15 12:14:40 | 000,062,040 | ---- | M] (O2Micro ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\o2mdx64.sys -- (O2MDRDR)
DRV:64bit: - [2008/04/10 23:25:30 | 000,531,968 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\DRIVERS\tos_sps64.sys -- (tos_sps64)
DRV:64bit: - [2008/04/08 12:46:44 | 000,051,928 | ---- | M] (O2Micro ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\o2sdx64.sys -- (O2SDRDR)
DRV:64bit: - [2008/04/04 12:57:00 | 000,404,992 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\yk60x64.sys -- (yukonx64)
DRV:64bit: - [2008/03/25 19:51:16 | 001,487,872 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\CAX_DPV.sys -- (HSF_DPV)
DRV:64bit: - [2008/03/25 19:47:06 | 000,294,400 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\CAXHWAZL.sys -- (CAXHWAZL)
DRV:64bit: - [2008/03/25 19:45:44 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\CAX_CNXT.sys -- (winachsf)
DRV:64bit: - [2008/03/05 16:41:58 | 000,197,640 | ---- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\swmx00.sys -- (swmx00)
DRV:64bit: - [2008/03/05 16:41:58 | 000,195,584 | ---- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\SWNC5E00.sys -- (SWNC5E00)
DRV:64bit: - [2008/03/05 16:41:58 | 000,028,808 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\swmsflt.sys -- (swmsflt)
DRV:64bit: - [2008/01/20 21:46:55 | 000,111,104 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\DRIVERS\sdbus.sys -- (sdbus)
DRV:64bit: - [2008/01/20 21:46:52 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\Dot4Scan.sys -- (Dot4Scan)
DRV:64bit: - [2007/12/20 19:10:50 | 000,028,200 | ---- | M] (Chicony Electronics Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\UVCFTR_S.SYS -- (UVCFTR)
DRV:64bit: - [2007/12/11 16:03:36 | 000,027,272 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\tdcmdpst.sys -- (tdcmdpst)
DRV:64bit: - [2007/11/29 20:58:58 | 000,320,048 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\SynTP.sys -- (SynTP)
DRV:64bit: - [2007/11/09 17:00:30 | 000,026,968 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\DRIVERS\TVALZ_O.SYS -- (TVALZ)
DRV:64bit: - [2007/10/18 02:37:10 | 000,010,240 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\xaudio64.sys -- (XAudio)
DRV:64bit: - [2007/10/12 18:04:40 | 000,041,280 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\PCASp50a64.sys -- (PCASp50a64)
DRV:64bit: - [2007/04/09 18:15:44 | 000,009,728 | ---- | M] (TOSHIBA) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\QIOMem.sys -- (QIOMem)
DRV:64bit: - [2006/12/12 02:29:02 | 000,097,280 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\BrSerIf.sys -- (BrSerIf)
DRV:64bit: - [2006/11/09 16:34:00 | 000,237,568 | ---- | M] (TOSHIBA CORPORATION) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\kr10n64.sys -- (KR10N64)
DRV:64bit: - [2006/11/09 16:33:00 | 000,248,320 | ---- | M] (TOSHIBA CORPORATION) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\kr10i64.sys -- (KR10I64)
DRV:64bit: - [2006/11/07 14:30:56 | 000,016,656 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\DRIVERS\AtiPcie.sys -- (AtiPcie)
DRV:64bit: - [2006/06/19 01:27:24 | 000,017,024 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\mdmxsdk.sys -- (mdmxsdk)
DRV - [2013/04/24 01:52:06 | 000,016,640 | ---- | M] (<Glarysoft Ltd>) [Kernel | Boot | Stopped] -- C:\Windows\SysWOW64\drivers\BootDefragDriver.sys -- (BootDefragDriver)
DRV - [2008/03/05 16:41:58 | 000,028,808 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\swmsflt.sys -- (swmsflt)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{EAEE5007-FF2F-46F3-BD1F-148BFDAC541B}: "URL" = http://www.google.co...ng}&rlz=1I7TSHB
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsof...arch/search.asp
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://home.microsof...obby/search.asp
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.co...ng}&rlz=1I7TSHB
IE - HKLM\..\SearchScopes\{7CC94BCA-8E5E-4FAD-ACE5-798C208642BC}: "URL" = http://www.google.co...Page={startPage}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsof...arch/search.asp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://home.microsof...obby/search.asp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 68 C3 87 DF 31 60 CF 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.co...?q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@ConservativeTalkNow_4n.com/Plugin: File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
O1 HOSTS File: ([2014/04/29 20:25:57 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O4:64bit: - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - %SystemRoot%\System32\nwprovau.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{23CBCD86-916E-48AC-9920-5D3010D180A2}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3DA411C4-D7A7-4568-8004-7BB04A484C23}: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\gopher - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (BootDefrag.exe)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2014/05/05 19:50:08 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe
[2014/05/05 19:27:45 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2014/05/05 19:21:37 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\ElevatedDiagnostics
[2014/05/05 19:18:45 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft ATS
[2014/05/05 11:44:03 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{33D267A4-C44D-48DB-895D-62B457C96273}
[2014/05/04 23:42:45 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{FA441080-7521-49F9-9049-195CE559DF52}
[2014/05/03 00:08:27 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{C66CC789-D624-47DA-A7BF-A958B5834A3B}
[2014/05/02 23:12:17 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{0D392007-C0C0-4FAC-9596-5CE194BE0231}
[2014/05/02 11:11:34 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{01A509CF-47B9-4306-A212-9AA8159A86BF}
[2014/05/02 07:37:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 4
[2014/05/02 07:37:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Glary Utilities 4
[2014/05/01 22:46:27 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{AB52C7BB-9A02-41D8-8F09-88C70726F842}
[2014/05/01 12:43:43 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\CrashDumps
[2014/05/01 10:44:47 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{4EF0DC02-6131-4074-9501-4D8E7FB08DB2}
[2014/04/30 21:54:46 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{A53D3469-123A-4B77-9AF4-96A5D2B34092}
[2014/04/30 09:53:29 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{6F467159-964D-4523-B8CB-DE8CE2AF33D6}
[2014/04/29 20:34:16 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2014/04/29 20:34:15 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\temp
[2014/04/29 20:26:05 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2014/04/29 19:39:40 | 000,000,000 | ---D | C] -- C:\Users\Admin\Documents\RK_Quarantine
[2014/04/29 18:54:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
[2014/04/29 18:54:55 | 000,000,000 | ---D | C] -- C:\Program Files\HitmanPro
[2014/04/29 13:33:06 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{AB7C8C88-0B90-4DE8-B659-0636C53242E3}
[2014/04/29 08:01:03 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\SUPERAntiSpyware.com
[2014/04/29 08:00:24 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2014/04/29 01:31:51 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{E4631447-CB9D-4C74-B841-7643278AC083}
[2014/04/28 20:32:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2014/04/28 20:04:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Licenses
[2014/04/28 17:11:51 | 000,000,000 | ---D | C] -- C:\ProgramData\{52AC600B-5800-407E-99FF-83CD0669760B}
[2014/04/26 11:04:41 | 000,000,000 | ---D | C] -- C:\Users\Admin\Desktop\Test
[2014/04/25 12:23:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2014/04/25 12:23:38 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2014/04/25 11:04:52 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2014/04/25 07:38:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2014/04/25 03:30:35 | 000,000,000 | ---D | C] -- C:\Users\Admin\Documents\ProcAlyzer Dumps
[2014/04/25 03:21:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2014/04/25 03:21:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy 2
[2014/04/25 00:10:40 | 000,091,352 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2013/11/06 12:45:30 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Users\Admin\dxdllreg.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014/05/05 19:50:08 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe
[2014/05/05 19:37:29 | 000,000,078 | ---- | M] () -- C:\Windows\SysNative\edsthc.ylh
[2014/05/05 19:33:56 | 000,795,200 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/05/05 19:33:56 | 000,666,886 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/05/05 19:33:56 | 000,130,996 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/05/05 19:27:26 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\GlaryInitialize 4.job
[2014/05/05 19:27:21 | 000,037,888 | ---- | M] () -- C:\Windows\SysNative\ohayhgz.moe
[2014/05/05 19:27:21 | 000,000,107 | ---- | M] () -- C:\Windows\SysNative\mxglci.geh
[2014/05/05 19:27:14 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2014/05/05 19:27:14 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2014/05/05 19:26:55 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/05/05 19:06:49 | 000,408,608 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/05/02 07:37:45 | 000,000,954 | ---- | M] () -- C:\Users\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Glary Utilities 4.lnk
[2014/05/02 07:37:45 | 000,000,930 | ---- | M] () -- C:\Users\Public\Desktop\Glary Utilities 4.lnk
[2014/04/29 20:25:57 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2014/04/29 18:54:56 | 000,001,743 | ---- | M] () -- C:\Users\Public\Desktop\HitmanPro.lnk
[2014/04/29 18:04:47 | 000,091,352 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/04/29 08:16:06 | 000,017,475 | ---- | M] () -- C:\Users\Admin\Documents\SLC Sandestin condo rooming list.eml
[2014/04/28 20:33:24 | 000,001,933 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2014/04/25 12:23:40 | 000,000,781 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014/04/25 11:13:03 | 000,000,644 | ---- | M] () -- C:\Windows\SysNative\.crusader
[2014/04/25 07:26:12 | 000,000,085 | ---- | M] () -- C:\Windows\wininit.ini
[2014/04/25 06:50:13 | 000,000,010 | ---- | M] () -- C:\Users\Admin\AppData\Local\sponge.last.runtime.cache
[2014/04/24 21:28:08 | 000,001,460 | ---- | M] () -- C:\Users\Admin\AppData\Local\d3d9caps64.dat
[2014/04/24 21:26:19 | 000,001,356 | ---- | M] () -- C:\Users\Admin\AppData\Local\d3d9caps.dat
[2014/04/24 19:37:56 | 000,000,064 | ---- | M] () -- C:\Windows\SysNative\dyrr.max
[2014/04/24 19:21:42 | 000,301,959 | --S- | M] () -- C:\Windows\SysNative\moekui.skb
[2014/04/24 16:35:06 | 000,200,660 | -H-- | M] () -- C:\Windows\SysWow64\mlfcache.dat
[2014/04/22 23:45:11 | 000,043,008 | ---- | M] (Absolute Software Corp.) -- C:\Windows\SysWow64\agremove.exe
[2014/04/22 17:37:52 | 000,017,408 | ---- | M] () -- C:\Windows\SysWow64\rpcnetp.dll
[2014/04/22 17:37:29 | 000,017,408 | ---- | M] () -- C:\Windows\SysWow64\rpcnetp.exe
[2014/04/22 17:37:29 | 000,017,408 | ---- | M] () -- C:\Windows\SysNative\rpcnetp.exe
[2014/04/17 14:25:52 | 000,001,785 | ---- | M] () -- C:\Users\Public\Desktop\Defraggler.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014/05/05 19:06:19 | 000,408,608 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/05/02 07:37:45 | 000,000,954 | ---- | C] () -- C:\Users\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Glary Utilities 4.lnk
[2014/05/02 07:37:45 | 000,000,942 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 4.lnk
[2014/05/02 07:37:45 | 000,000,930 | ---- | C] () -- C:\Users\Public\Desktop\Glary Utilities 4.lnk
[2014/05/02 07:37:40 | 000,000,332 | ---- | C] () -- C:\Windows\tasks\GlaryInitialize 4.job
[2014/04/29 18:54:56 | 000,001,743 | ---- | C] () -- C:\Users\Public\Desktop\HitmanPro.lnk
[2014/04/28 22:33:57 | 000,017,475 | ---- | C] () -- C:\Users\Admin\Documents\SLC Sandestin condo rooming list.eml
[2014/04/28 20:33:24 | 000,001,933 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2014/04/28 20:33:24 | 000,001,804 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2014/04/25 18:36:17 | 000,002,265 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Migration Assistant.lnk
[2014/04/25 12:23:40 | 000,000,781 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2014/04/25 11:13:03 | 000,000,644 | ---- | C] () -- C:\Windows\SysNative\.crusader
[2014/04/25 07:26:05 | 000,000,085 | ---- | C] () -- C:\Windows\wininit.ini
[2014/04/25 06:50:13 | 000,000,010 | ---- | C] () -- C:\Users\Admin\AppData\Local\sponge.last.runtime.cache
[2014/04/24 20:04:47 | 000,000,078 | ---- | C] () -- C:\Windows\SysNative\edsthc.ylh
[2014/04/24 19:38:13 | 000,037,888 | ---- | C] () -- C:\Windows\SysNative\ohayhgz.moe
[2014/04/24 19:37:56 | 000,000,107 | ---- | C] () -- C:\Windows\SysNative\mxglci.geh
[2014/04/24 19:37:56 | 000,000,064 | ---- | C] () -- C:\Windows\SysNative\dyrr.max
[2014/04/24 19:21:42 | 000,301,959 | --S- | C] () -- C:\Windows\SysNative\moekui.skb
[2014/04/24 16:35:06 | 000,200,660 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2014/04/08 22:45:18 | 000,017,408 | ---- | C] () -- C:\Windows\SysWow64\rpcnetp.dll
[2014/04/08 22:44:50 | 000,017,408 | ---- | C] () -- C:\Windows\SysWow64\rpcnetp.exe
[2013/11/06 12:45:41 | 000,000,724 | ---- | C] () -- C:\Users\Admin\dxdllreg_x86.inf
[2012/12/24 01:38:24 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\XAudio64.exe
[2012/12/24 01:38:24 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\TODDSrv.exe
[2012/12/24 01:38:24 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\spoolsv.exe
[2012/12/24 01:38:24 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\SLsvc.exe
[2012/12/24 01:38:24 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\lsass.exe
[2012/12/24 01:38:24 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\dwm.exe
[2012/12/24 01:38:24 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\csrss.exe
[2012/12/24 01:38:24 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\Ati2evxx.exe
[2012/12/24 01:38:22 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\smss.exe
[2012/09/19 12:04:18 | 000,000,000 | ---- | C] () -- C:\Users\Admin\AppData\Local\¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿ
[2012/09/04 11:13:53 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/10/01 19:10:06 | 000,908,234 | ---- | C] () -- C:\Users\Admin\AppData\Local\census.cache
[2011/10/01 19:09:19 | 000,160,990 | ---- | C] () -- C:\Users\Admin\AppData\Local\ars.cache
[2011/10/01 18:56:39 | 000,000,036 | ---- | C] () -- C:\Users\Admin\AppData\Local\housecall.guid.cache
[2010/09/16 21:35:40 | 000,000,000 | ---- | C] () -- C:\Users\Admin\jagex__preferences3.dat
[2010/09/16 21:35:27 | 000,000,099 | ---- | C] () -- C:\Users\Admin\jagex_runescape_preferences2.dat
[2010/09/16 21:33:22 | 000,000,046 | ---- | C] () -- C:\Users\Admin\jagex_runescape_preferences.dat
[2009/05/30 12:02:59 | 000,006,144 | ---- | C] () -- C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/13 00:36:51 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009/03/12 11:41:24 | 000,001,356 | ---- | C] () -- C:\Users\Admin\AppData\Local\d3d9caps.dat
[2009/03/10 08:43:17 | 000,001,460 | ---- | C] () -- C:\Users\Admin\AppData\Local\d3d9caps64.dat
========== ZeroAccess Check ==========
[2006/11/02 10:30:40 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/08 12:59:03 | 012,899,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 12:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/04/11 02:11:14 | 000,891,392 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\SysWow64\wbem\fastprox.dll -- [2009/04/11 01:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2008/01/20 21:50:58 | 000,513,024 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2011/10/01 21:11:32 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\aK7fEL9gTqYwI
[2011/10/01 21:13:00 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\AqhYCwkUVlBx0c1
[2013/07/24 09:54:33 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Auslogics
[2011/10/01 21:10:41 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\axAuvS2ob3m5Q6W
[2011/10/01 21:06:43 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\bFF3pnn5aQ6dKfL
[2011/10/01 21:08:49 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\BobF3pmG5Q6W8
[2011/10/01 21:12:39 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\BuvS2ibF3n
[2011/10/01 21:08:22 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\c3onG4amHsJfLgZ
[2011/10/01 21:11:24 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\C4pmG5sQJdKfZhX
[2011/10/01 21:06:57 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\C6dEK8fRZhX
[2011/10/01 21:09:31 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\CG4amH6sW7E8TqY
[2011/10/01 21:11:47 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\CWJ7fEL8gZhCkVl
[2011/10/01 21:07:56 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\CZ9hTXwjUeIrPy
[2011/10/01 21:09:58 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\d2obF3pmGaJd
[2011/10/01 21:10:49 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\dF4pmH5sQ7E8R9Y
[2011/10/01 21:05:41 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\DfEL9gTZqYw
[2011/10/01 21:10:19 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\dH6sWJ7fE8TqYwU
[2014/05/05 18:51:25 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Disk Cleaner
[2014/05/01 10:35:15 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\DiskDefrag
[2011/10/01 21:05:27 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\e3onG4amHsJfLgZ
[2011/10/01 21:06:30 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\EaQH6sWK7E9Tq
[2011/10/01 21:09:04 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\eRZ99TTwjUClBzN
[2011/10/01 21:05:34 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\EsQJ6dEK8R9TwUe
[2011/10/01 21:06:37 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\F2oonF4pm5sQ7E8
[2010/02/25 14:53:31 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\FoxPlayerAIR.01F2E49DE175CC541F416F2DF78BDD5E63AD0096.1
[2011/10/01 21:08:02 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\FQH6dWK7fLgXjCk
[2011/10/01 21:10:11 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\FUVelIBtzNc1v2b
[2014/05/02 07:37:39 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\GlarySoft
[2011/10/01 21:05:21 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\GTXqjUCekB
[2011/10/01 21:12:46 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\h5sWJ7dEL
[2011/10/01 21:11:54 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\HXqjUCekIrO
[2011/10/01 21:09:44 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\irzONtxA0c2b3n4
[2011/10/01 21:13:06 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\itzPNycA1v2b4
[2011/10/01 21:06:01 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\j4aQH6sWKfLgZ
[2011/10/01 21:05:54 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\JNyxA1uvS
[2011/10/01 21:11:10 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\jRZ9hTXwjClBzNx
[2011/10/01 21:04:51 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\kwjUCelIBzNx1v2
[2011/10/01 21:07:43 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\KxP0ucS1iDoGaHs
[2011/10/01 21:06:50 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\LJ7fEL8gTqYwUrO
[2011/10/01 21:04:17 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\lK8fRZ9hT
[2011/10/01 21:05:48 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\lmH5sWJ7dLgZ
[2011/10/01 21:04:35 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\NwkUVelOBz0c1v2
[2011/10/01 21:11:40 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\O1uvS2obFpGaJdK
[2011/10/01 21:09:17 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\o8gRZ9hYXjVlBz
[2011/10/01 21:08:56 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\p0ucS2ibDpGaHsK
[2011/10/01 21:08:15 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\paQJ6dWK8R9TqUe
[2013/01/16 23:32:13 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\playitall(157)
[2011/10/01 21:12:31 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\PlOBtzP0yAiDoFp
[2011/10/01 21:11:03 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\pqhYCwkUVlBx0c1
[2011/10/01 21:06:08 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\rQJ6dEK8fZhXjCl
[2011/10/01 21:05:06 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\rXqjUCekIrOyAuS
[2011/10/01 21:09:38 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\SddEK8fRZ9TXjCl
[2011/10/01 21:08:35 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\sibF3pnG5Q6W7R
[2011/10/01 21:12:02 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\SmH6sWJ7fLgZhCk
[2011/10/01 21:08:29 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\sQJ7dEK8gZhXjV
[2012/10/30 19:23:06 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\SumatraPDF
[2009/03/09 15:38:58 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\SupportSoft
[2011/10/01 21:04:58 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\TBtxP0ycS
[2011/10/01 21:09:24 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\TeekkVVzONxA
[2014/03/12 08:42:56 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\TOSHIBA
[2011/10/01 21:12:23 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\uhTXqjUCe
[2010/05/08 12:24:55 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Ulead Systems
[2011/10/01 21:07:37 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\UNyxA0uvSiF
[2011/10/01 21:09:10 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\UqjYCwkIVlN
[2011/10/01 21:07:49 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\V5sQJ7dEKgZh
[2011/10/01 21:10:26 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\vK8fRZ9hTwUeI
[2011/10/01 21:13:20 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\VlOBtzP0y
[2011/10/01 21:07:30 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\VnF4pmH5sJdK
[2011/10/01 21:12:17 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\vRZqhYXwkVlBz0c
[2011/10/01 21:13:13 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\VS2ibD3pn
[2012/04/25 13:00:32 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\webex
[2011/10/01 21:10:33 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\wgTXqjYCeIrOtAu
[2011/10/01 21:11:17 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\wibD3onG4m
[2009/05/26 12:30:37 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\WinBatch
[2011/01/11 15:52:00 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Windows Live Writer
[2011/10/01 21:10:04 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\wIVrlONtx0
[2011/10/01 21:06:23 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\WjUVVllItzPyA1v
[2011/10/01 21:03:22 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\WnF4amH5sJdLgZh
[2011/10/01 21:07:10 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\wOBBtzP0yA
[2011/10/01 21:12:09 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\WTXqjUCekBzNx0v
[2011/10/01 21:13:34 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\WYCwkUVrlBx0c1v
[2011/10/01 21:08:42 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\X33onF4amHsW7E8
[2011/10/01 21:07:17 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\xL9hTXqjUeIrOyA
[2011/10/01 21:10:57 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\xxA0ucS2iDpGaHs
[2011/10/01 21:04:27 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\xXwjUCelIrPyAu2
[2011/10/01 21:04:43 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Yam6sWJ7fLgZhCk
[2011/10/01 21:07:24 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\yaQH6sWK7fL9TqY
[2011/10/01 21:12:53 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\yBrzONyxAuSiFp
[2011/10/01 21:07:04 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\yucS2ibD3n4Q6W7
[2011/10/01 21:08:08 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\zD3onF4am5W7E8R
[2011/10/01 21:09:51 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\ZellOBtz0ycA
[2011/10/01 21:05:14 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\ZK8gRZ9hYwUeItP
[2011/10/01 21:06:16 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\ZsWWJ7fELgTZhCk
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 841 bytes -> C:\Users\Admin\Documents\SLC Sandestin condo rooming list.eml:OECustomProperty
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:07F6D9E4
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:5C321E34
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >
OTL Extras logfile created on: 5/5/2014 07:53:47 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Admin\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.75 Gb Total Physical Memory | 1.33 Gb Available Physical Memory | 35.41% Memory free
7.71 Gb Paging File | 4.99 Gb Available in Paging File | 64.66% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 288.67 Gb Total Space | 212.76 Gb Free Space | 73.70% Space Free | Partition Type: NTFS
Computer Name: ADMIN-PC | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = 28 42 7F 04 1F E1 C9 01 [binary data]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-3402813050-4047483925-927164663-1000]
"EnableNotificationsRef" = 6
"EnableNotifications" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{2ACCABFA-EF7D-439C-92B9-69D49F8D7D8E}" = rport=138 | protocol=17 | dir=out | app=system |
"{2F207C39-9FB9-4C4F-897D-7FA2B25DCD33}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{41404D07-363F-46EE-9C82-7B82EE2F22B0}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |
"{4CBE5B32-79D0-4950-A083-D167FCFDE003}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6B276100-1643-436A-A4D7-A4A85185AE0B}" = rport=445 | protocol=6 | dir=out | app=system |
"{73472542-B843-4705-9A7A-A8B00061F6B6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7F8CA566-65EF-4BAE-A617-497D97B7A65A}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{80CD9F8E-CD35-49D7-A9AA-223CBFBD4455}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{8F125284-834E-4382-A2E1-7216E77BA6B5}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{905764E0-4313-4291-B9FD-277474942E77}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{999F163E-D78A-4905-B756-85044601406C}" = lport=138 | protocol=17 | dir=in | app=system |
"{ADF8450E-F37E-41A3-8F93-29733D7D3727}" = lport=445 | protocol=6 | dir=in | app=system |
"{B922937A-90B1-4EFD-87CD-B5255CF282CB}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{C38AD43F-F274-4160-A223-90945E096E07}" = rport=137 | protocol=17 | dir=out | app=system |
"{C62E848D-407E-4ECA-9DAF-46F36E1CC164}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CAB028B3-19AD-462C-B987-2EE2CBCB2267}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D2814BDE-A750-4CB3-A926-8E5E50C614FE}" = lport=139 | protocol=6 | dir=in | app=system |
"{F114CFB9-306E-472E-B553-805C1AF0654A}" = lport=137 | protocol=17 | dir=in | app=system |
"{F7A013AB-52AB-4358-87FC-AD60BC3D19CE}" = rport=139 | protocol=6 | dir=out | app=system |
"{F9959D03-4C73-4CA4-A038-D0A233D2720C}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02468A72-90D7-4DFE-9CD3-DAF846E99B5F}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{2DDC49C3-F88B-4CC6-9AF7-719C324CB215}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\apple\windows migration assistant\migrationassistant.exe |
"{4F7F4565-86E0-471E-83D8-A0D543DAFAEA}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{6BB2C06C-A218-4B57-BCF0-1B853C28C6C1}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{7E5BE654-2BC1-4957-AF5E-F9220B3F89AD}" = protocol=1 | dir=in | [email protected],-28543 |
"{7E7A6803-6151-4FEB-8058-361CDD0990FF}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\apple\windows migration assistant\migrationassistant.exe |
"{8B21D88A-0353-4977-8BCB-6A93100BDBC1}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{AD2CF5AE-F4BB-4664-BDA0-6F53C893F983}" = protocol=58 | dir=out | [email protected],-28546 |
"{CFFE9BD8-3D0C-4D62-B5D9-CA65F06BE9C8}" = protocol=58 | dir=in | [email protected],-28545 |
"{D6D0E379-A0DE-4A83-8906-93C079A9A779}" = protocol=1 | dir=out | [email protected],-28544 |
"TCP Query User{E1C1C99E-C42C-40CB-88A6-7DA6F1ABC4C7}C:\program files (x86)\common files\apple\windows migration assistant\migrationassistant.exe" = protocol=6 | dir=in | app=c:\program files (x86)\common files\apple\windows migration assistant\migrationassistant.exe |
"UDP Query User{ABDA979A-5A5A-4C1F-95F6-698E648D6615}C:\program files (x86)\common files\apple\windows migration assistant\migrationassistant.exe" = protocol=17 | dir=in | app=c:\program files (x86)\common files\apple\windows migration assistant\migrationassistant.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{02A5BD31-16AC-45DF-BE9F-A3167BC4AFB2}" = Windows Live Family Safety
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1C336D20-A089-4818-9C56-96AD81BF5A11}" = PANTECH USB Modem V2
"{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}" = Apple Mobile Device Support
"{387D9916-BD27-480f-8CF0-3228832BBAA2}" = HP Deskjet D4300 Printer Driver Software 10.0 Rel .3
"{4F2B8F3E-70FA-AA71-4526-3BFDEDE502EF}" = AMD Fuel
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5254156F-AA77-499A-B7C1-D5581D44E788}" = Marvell Miniport Driver
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{68CA3A47-3F7E-0E92-DC0D-5B0C02D9AFAD}" = ccc-utility64
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{914F7627-B645-9895-F723-BAEAAC865E75}" = AMD Catalyst Install Manager
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb" = Internet Explorer (Enable DEP)
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{AE64AAFB-8C9A-482A-B2A9-3A420A65D5D5}" = O2Micro Flash Memory Card Reader Driver (x64)
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Disc Creator
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BFAE8D5B-F918-486F-B74E-90762DF11C5C}" = Microsoft Security Client
"{c9920352-04e6-469d-bab8-e2b9c7c75415}.sdb" = Microsoft Automated Troubleshooting Services Shim
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DF0853CA-A1D0-4169-8472-F2822C8FA1EB}" = TOSHIBA Supervisor Password
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{E8B39B08-7FAB-48CC-89E9-37C5589E130C}" = TOSHIBA Hardware Setup
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F67FA545-D8E5-4209-86B1-AEE045D1003F}" = TOSHIBA Face Recognition
"CCleaner" = CCleaner
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_5051&SUBSYS_1179" = HDAUDIO Soft Data Fax Modem with SmartCP
"Defraggler" = Defraggler
"HitmanPro37" = HitmanPro 3.7
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"SynTPDeinstKey" = Synaptics Pointing Device Driver
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{02F5BEE7-0AB6-4E42-9BF8-2588AAECC7F2}" = EZ Fonts
"{03D45A4B-D7F5-C03E-1650-885756303D13}" = CCC Help Norwegian
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{07620C4F-0964-4086-A872-C9C12E418E52}" = DJ_SF_03_D4300_Software
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox
"{16E8BF9A-B419-4A44-A020-30F8CFB84B9D}" = Atheros Client Utility
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1A3A92EC-A218-4FEE-8A51-05BCD409A048}" = Windows Migration Assistant
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = CyberLink PowerCinema for TOSHIBA
"{284E9E9A-D8BE-3588-D0BA-E9BB61970A1D}" = CCC Help Hungarian
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{30E18A93-982E-AF1B-D646-E8C5DAECA390}" = CCC Help French
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Java 6 Update 6
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{4021F8B5-E8BB-D0F9-AF28-4970013FAE3D}" = AMD VISION Engine Control Center
"{425A2BC2-AA64-4107-9C29-484245BBEA05}" = TOSHIBA Software Upgrades
"{46F044A5-CE8B-4196-984E-5BD6525E361D}" = Apple Application Support
"{470D66DF-B597-124E-EDCE-8B966AA5F230}" = CCC Help Portuguese
"{483924A6-52C5-9169-0280-14272D5FBA70}" = CCC Help Chinese Standard
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{57AE1BE1-24E8-4169-D52C-ABE31BD91562}" = CCC Help Finnish
"{5B5745F7-23EF-9E5E-6689-512C9FA08222}" = CCC Help English
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{625031C9-E249-2A53-C282-C1E9872B211E}" = CCC Help Turkish
"{655E0B5A-7ADF-A052-587F-64F0E59B58E7}" = CCC Help Dutch
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{74437563-D720-0307-90FC-1C351B1041D7}" = Catalyst Control Center Localization All
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A4D10-821B-3FA5-52B0-F0FAEEDED9F4}" = CCC Help Czech
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7BA14A92-C229-5E00-3ADE-8D22F81B849E}" = CCC Help German
"{80A5B901-C7BD-D300-17BA-9E02F18EAB77}" = CCC Help Danish
"{82F505E6-5879-B30A-12B7-7795969D3BBB}" = CCC Help Polish
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{8476003F-6927-8393-C6F4-FAF47D61D00B}" = CCC Help Korean
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89A2D79E-B3AD-A83A-795F-5645EFF922D3}" = CCC Help Greek
"{89C0F58F-9E5B-2B45-D9DF-7988A54BECA8}" = CCC Help Italian
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport
"{8B0A7592-2AE0-48EA-A327-6EB7DAB25E4A}" = DJ_SF_03_D4300_Software_Min
"{8B91D776-792D-F02B-DE43-BF398549C729}" = CCC Help Spanish
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F272838-BDD6-B433-D650-25E231AEFA8A}" = Catalyst Control Center InstallProxy
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-007D-0409-0000-0000000FF1CE}" = Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit
"{95140000-0081-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{983BE967-28E9-5C78-8851-638DAC4AF66E}" = CCC Help Swedish
"{99A4344A-C723-4661-A507-D9D939480358}" = Cisco LEAP Module
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9BFD5911-93E3-42BB-BFCD-50E4BA5B8D67}" = Cisco EAP-FAST Module
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A707240D-18D3-07F4-AE2E-6AE76C220192}" = CCC Help Japanese
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}" = Windows 7 Upgrade Advisor
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B95AC87D-630B-603F-3F12-AA22B3BBA69C}" = CCC Help Chinese Traditional
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C53D16CC-E56F-47B8-906E-70AAF8EABB4F}" = Toshiba Registration
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{CD344FA5-6657-47CD-940F-8727EED35595}" = Cisco PEAP Module
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EB1C554C-5343-9A69-1B8C-666AF192CA19}" = CCC Help Russian
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{F32D24DD-D787-10F9-D21E-BC3FAB3064CB}" = Catalyst Control Center Graphics Previews Common
"{F8D90583-7BB5-75A9-B23F-A353AD4674BC}" = CCC Help Thai
"{FB356619-7ECE-42BC-A28A-541973E29F28}" = TOSHIBA PowerCinema Helper
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"ActiveTouchMeetingClient" = Cisco WebEx Meetings
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"CleanUp!" = CleanUp!
"DiskCleaner" = Disk Cleaner (remove only)
"Glary Utilities 4" = Glary Utilities 4.10
"InstallShield_{DF0853CA-A1D0-4169-8472-F2822C8FA1EB}" = TOSHIBA Supervisor Password
"InstallShield_{E8B39B08-7FAB-48CC-89E9-37C5589E130C}" = TOSHIBA Hardware Setup
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"WildTangent toshiba Master Uninstall" = TOSHIBA Games
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite" = Windows Live Essentials
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 5/5/2014 08:07:17 PM | Computer Name = Admin-PC | Source = EventSystem | ID = 4609
Description =
Error - 5/5/2014 08:07:34 PM | Computer Name = Admin-PC | Source = WinMgmt | ID = 10
Description =
Error - 5/5/2014 08:27:34 PM | Computer Name = Admin-PC | Source = WinMgmt | ID = 10
Description =
Error - 5/5/2014 08:51:43 PM | Computer Name = Admin-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =
Error - 5/5/2014 08:51:44 PM | Computer Name = Admin-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =
Error - 5/5/2014 08:53:19 PM | Computer Name = Admin-PC | Source = MsiInstaller | ID = 11935
Description =
[ System Events ]
Error - 5/5/2014 08:27:34 PM | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7026
Description =
Error - 5/5/2014 08:52:46 PM | Computer Name = Admin-PC | Source = Microsoft-Windows-Servicing | ID = 4385
Description =
Error - 5/5/2014 08:52:48 PM | Computer Name = Admin-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =
Error - 5/5/2014 08:52:48 PM | Computer Name = Admin-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =
Error - 5/5/2014 08:52:48 PM | Computer Name = Admin-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =
Error - 5/5/2014 08:52:53 PM | Computer Name = Admin-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =
Error - 5/5/2014 08:54:21 PM | Computer Name = Admin-PC | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.173.1283.0 Update Source: %%859 Update Stage:
%%854 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803
User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.10502.0
Error
code: 0x80240016 Error description: An unexpected problem occurred while checking
for updates. For information on installing or troubleshooting updates, see Help
and Support.
Error - 5/5/2014 08:54:21 PM | Computer Name = Admin-PC | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.173.1283.0 Update Source: %%859 Update Stage:
%%854 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803
User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.10502.0
Error
code: 0x80240016 Error description: An unexpected problem occurred while checking
for updates. For information on installing or troubleshooting updates, see Help
and Support.
Error - 5/5/2014 08:54:21 PM | Computer Name = Admin-PC | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.173.1283.0 Update Source: %%859 Update Stage:
%%853 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803
User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.10502.0
Error
code: 0x80240016 Error description: An unexpected problem occurred while checking
for updates. For information on installing or troubleshooting updates, see Help
and Support.
Error - 5/5/2014 08:56:14 PM | Computer Name = Admin-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =
< End of report >