Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Trojan Dropper from 'Ecard' [Closed]


  • This topic is locked This topic is locked

#1
Bismillah

Bismillah

    Member

  • Member
  • PipPipPip
  • 514 posts

Hi!

 

Unfortunately I've been the recipient of a new Trojan Dropper varient. My birthday is coming up and I received an 'Ecard' from a friends email address. As this all checked out and seemed legit, I opened the attatchment for it to then execute on my laptop. This started ringing alarm bells, So upon uploading the zipped ecard to virustotal it proves my suspicion that this indeed a Virus dropper, one which is not yet on Avasts database.

 

To further add to my suspicions I've had several emails from Microsoft telling me that my email account has been access by someone from Brazil, Spain and China! At least my email account has had an international outlook now.

 

 

The file on virustotal - https://www.virustot...sis/1399380855/

 

Tdsskiller - Clean

 

Mbam

 

Malwarebytes Anti-Malware 1.75.0.1300

www.malwarebytes.org
 
Database version: v2014.05.06.04
 
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16661
Dan :: BISMILLAH [administrator]
 
06/05/2014 13:52:37
mbam-log-2014-05-06 (13-52-37).txt
 
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 41923
Time elapsed: 11 minute(s), 40 second(s) [aborted]
 
Memory Processes Detected: 0
(No malicious items detected)
 
Memory Modules Detected: 0
(No malicious items detected)
 
Registry Keys Detected: 0
(No malicious items detected)
 
Registry Values Detected: 0
(No malicious items detected)
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 0
(No malicious items detected)
 
Files Detected: 
C:\Users\Dan\Downloads\downloadmanager_Setup (1).exe (PUP.Optional.Ibryte) -> No action taken.
C:\Users\Dan\Downloads\downloadmanager_Setup (2).exe (PUP.Optional.Ibryte) -> No action taken.
C:\Users\Dan\Downloads\downloadmanager_Setup (3).exe (PUP.Optional.Ibryte) -> No action taken.
C:\Users\Dan\Downloads\downloadmanager_Setup.exe (PUP.Optional.Ibryte) -> No action taken.
C:\Users\Dan\Downloads\Setup 2014 working 100%.exe (PUP.Optional.Smart) -> No action taken.
C:\Users\Dan\Downloads\SoftonicDownloader_for_directx.exe (PUP.Optional.Softonic.A) -> No action taken.
 
(end)
 
 
OTL Logs coming, gotta dash out! :(

  • 0

Advertisements


#2
Machiavelli

Machiavelli

    GeekU Moderator

  • GeekU Moderator
  • 3,698 posts
Hello and Welcome on board Bismillah :welcome:,

my Name is Machiavelli and I will assist you with your problem.
If you booted into safe mode on your computer then print my instructions!
I'm in the 'Malware Staff Team' and will provide you with advice:

To remove Malware on a computer can be very complicated. Malware (malicious software) is able to hide and so I may not be able to find it so easily. In order to remove Malware from you Computer, you need to follow my instructions carefully. Don't be worried if you don't know what to do. just ask me! Please stay in contact with me until the problem is fixed.

Below are a few tips:
  • Removing Malware is usually very difficult.
    We need to search and analyse a lot of files. As this is done in our free time, please be patient especially if I don't answer every day!
  • Please follow these instructions
    If you don't follow the instructions your computer may crash. If you fix your PC by yourself, this can be very risky!
  • Please stay in contact with me until your problem is resolved
    As Malware may not be totally removed in one session or in one day, please stay in contact with me until the problem is resolved.
  • Please don't run any other tools without consulting with me as this can complicate finding and removing all Malware
    Don't run any tools while I'm fixing your PC. That is counter productive and again, will only complicate finding and removing all Malware!
  • Read my post completely
    If you don't do so, you may make mistakes that could result in your System crashing by your own actions!
 

Hiya,
because you are a trainee it could be a good learning experience to analyze yourself the OTL Log and tell me what you see if you like. ;)

Please download OTL (by OldTimer) (if you haven't already) from the link below and save it to your Desktop.
 

Download Mirror #1

  • Please copy the text in the Quote box below, (Do Not copy the word Quote), and paste it in the customFix.png.pagespeed.ce.jU5V4w6MU1.pn box in OTL. To do that:
    • Highlight everything inside the quote box, (except the word Quote), right click the mouse and click Copy.

    netsvcs
    BASESERVICES
    %SYSTEMDRIVE%\*.exe
    /md5start
    services.*
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    qmgr.dll
    mpsvc.dll
    winsock.*
    rpcss.dll
    /md5stop
    dir "%systemdrive%\*" /S /A:L /C
    CREATERESTOREPOINT

  • Open otlicon.png on the desktop. To do that:
    • XP users: Double click on the OTL icon.
    • Vista / 7 Users: Right click on the icon and click Run as Administrator)
  • Make sure all other windows are closed.
    • You will see a console like the one below:

      OTL_Main_Tutorial.gif
      • Click the box beside Scan All Users at the top of the console
      • If you have a 64bit Windows, click the box beside Include 64bit Scans at the top of the console.
      • Make sure the Output box at the top is set to Standard Output.
      • Check the boxes beside LOP Check and Purity Check.
      • Make sure that Use Safe List is checked under Extra Registry.
      • Place the mouse pointer inside the customFix.png.pagespeed.ce.jU5V4w6MU1.pn box, right click and click Paste. This will put the above script inside OTL
      • Click the runscanbutton.png.pagespeed.ce.KPQ_c3iHh button. Do not change any settings unless otherwise told to do so.
      • Let the scan run uninterrupted.
      • When the scan completes, it will open OTL.Txt on the desktop.
      • Please copy the contents of these files and paste it into your reply. To do that:
        • On the OTL.txt file Menu Bar click Edit then click Select All. This will highlight the contents of the file. Then click Copy.
        • Right click inside the forum post window then click Paste. This will paste the contents of the OTL.txt file in the in the post window.
      • Please do the same for the Extras.txt

  • 0

#3
Bismillah

Bismillah

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 514 posts

Hi Machiavelli!

 

From the OTL log this is what catches my eye

 

O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. - Why is it locked?

[2014/04/20 22:31:56 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\ElevatedDiagnostics - This is a fraudulent Security program

 

Can't see anything else

 

 

OTL logfile created on: 06/05/2014 13:47:51 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Dan\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16521)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
 
5.89 Gb Total Physical Memory | 2.78 Gb Available Physical Memory | 47.17% Memory free
11.79 Gb Paging File | 7.98 Gb Available in Paging File | 67.71% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 578.98 Gb Total Space | 178.13 Gb Free Space | 30.77% Space Free | Partition Type: NTFS
 
Computer Name: BISMILLAH | User Name: Dan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/05/06 13:47:23 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Dan\Downloads\OTL (2).exe
PRC - [2014/04/24 01:33:15 | 000,841,032 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014/04/23 23:56:22 | 007,631,872 | ---- | M] (Google Inc.) -- C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\MusicManager.exe
PRC - [2014/04/23 23:01:04 | 000,572,096 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe
PRC - [2014/04/23 23:01:02 | 001,825,984 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Steam\Steam.exe
PRC - [2014/04/14 11:30:50 | 003,854,640 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2014/04/14 11:30:50 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014/04/11 19:45:50 | 001,764,992 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
PRC - [2014/04/11 19:45:42 | 001,390,720 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
PRC - [2014/04/04 18:59:49 | 000,257,224 | ---- | M] (Microsoft Corporation) -- C:\Users\Dan\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
PRC - [2014/03/19 00:09:43 | 001,287,168 | ---- | M] () -- C:\Program Files (x86)\Steam\vr\runtime\bin\vrserver.exe
PRC - [2014/02/22 19:44:06 | 000,107,832 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrB.exe
PRC - [2014/02/22 19:43:58 | 000,066,872 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2013/11/20 16:43:26 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
PRC - [2013/11/20 16:43:14 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
PRC - [2013/10/03 15:18:46 | 004,351,640 | ---- | M] (Insight Software Solutions, Inc.) -- C:\Program Files (x86)\ShortKeys 3\shortkey.exe
PRC - [2013/09/14 03:27:52 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe
PRC - [2013/06/26 19:21:50 | 000,207,528 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2013/06/26 19:21:46 | 000,523,944 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2013/06/10 10:59:46 | 005,399,888 | ---- | M] (ManyCam LLC) -- C:\Program Files (x86)\ManyCam\Bin\ManyCam.exe
PRC - [2013/05/10 00:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/02/19 00:28:08 | 014,800,896 | ---- | M] () -- C:\Program Files (x86)\FAHClient\FAHClient.exe
PRC - [2012/12/14 10:17:04 | 003,467,768 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
PRC - [2012/11/29 21:31:04 | 000,038,608 | ---- | M] () -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
PRC - [2012/08/28 12:00:32 | 001,327,104 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
PRC - [2012/08/28 11:55:16 | 000,393,216 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
PRC - [2012/04/03 13:33:00 | 000,940,168 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.EXE
PRC - [2012/04/03 13:27:16 | 001,087,608 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
PRC - [2012/04/03 13:26:14 | 001,273,448 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
PRC - [2012/03/28 13:49:11 | 000,140,456 | ---- | M] () -- C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
PRC - [2012/03/26 17:35:16 | 000,449,168 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
PRC - [2012/02/29 01:13:56 | 000,363,800 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2012/02/29 01:13:54 | 000,277,784 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2012/02/21 20:29:38 | 000,161,560 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
PRC - [2012/02/21 20:29:28 | 000,128,280 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
PRC - [2012/01/05 11:59:50 | 000,291,608 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
PRC - [2011/11/04 13:40:06 | 000,687,400 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2011/08/02 16:49:24 | 000,030,568 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe
PRC - [2011/08/02 16:47:26 | 000,145,256 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
PRC - [2009/05/05 16:06:06 | 000,222,496 | ---- | M] (Acresso Corporation) -- C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
PRC - [2007/11/07 00:20:15 | 000,377,303 | ---- | M] () -- C:\Users\Dan\Desktop\texter.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/05/06 13:38:45 | 000,086,016 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEMA34A.tmp
MOD - [2014/05/06 13:38:44 | 000,086,016 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEMA2BB.tmp
MOD - [2014/05/06 13:38:44 | 000,086,016 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM9FDC.tmp
MOD - [2014/05/06 13:38:44 | 000,086,016 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM9FBB.tmp
MOD - [2014/05/06 13:38:43 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM9CCA.tmp
MOD - [2014/05/06 13:38:43 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM9BCE.tmp
MOD - [2014/05/06 13:38:42 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM9A37.tmp
MOD - [2014/05/06 13:38:42 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM98BE.tmp
MOD - [2014/05/06 13:38:41 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM95B0.tmp
MOD - [2014/05/06 13:38:41 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM93FA.tmp
MOD - [2014/05/06 13:38:40 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM909E.tmp
MOD - [2014/05/06 13:38:39 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM8E5A.tmp
MOD - [2014/05/06 13:38:39 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM8C84.tmp
MOD - [2014/05/06 13:38:38 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM8B1C.tmp
MOD - [2014/05/06 13:38:38 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM8AAC.tmp
MOD - [2014/05/06 13:38:38 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM881B.tmp
MOD - [2014/05/06 13:38:37 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM86D2.tmp
MOD - [2014/05/06 13:38:37 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM85C6.tmp
MOD - [2014/05/06 13:38:37 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM8538.tmp
MOD - [2014/05/06 13:38:37 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM84B9.tmp
MOD - [2014/05/06 13:38:37 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM837F.tmp
MOD - [2014/05/06 13:38:35 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM7F2A.tmp
MOD - [2014/05/06 13:38:35 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM7C79.tmp
MOD - [2014/05/06 13:38:35 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM7BCC.tmp
MOD - [2014/05/06 13:38:34 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM790B.tmp
MOD - [2014/05/06 13:38:32 | 000,072,192 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM72F0.tmp
MOD - [2014/05/06 13:38:32 | 000,072,192 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM72AB.tmp
MOD - [2014/05/06 13:38:32 | 000,033,792 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\YTMP7MC8AA\TAA72DF.tmp
MOD - [2014/05/06 13:38:32 | 000,033,792 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\YTMP7MC8AA\TAA72CD.tmp
MOD - [2014/05/06 13:38:32 | 000,033,792 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\YTMP7MC8AA\TAA729B.tmp
MOD - [2014/05/06 13:38:32 | 000,033,792 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\YTMP7MC8AA\TAA7180.tmp
MOD - [2014/05/06 13:38:31 | 000,072,704 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6ECF.tmp
MOD - [2014/05/06 13:38:31 | 000,072,192 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6DD4.tmp
MOD - [2014/05/06 13:38:31 | 000,064,000 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6C29.tmp
MOD - [2014/05/06 13:38:31 | 000,057,344 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6D55.tmp
MOD - [2014/05/06 13:38:31 | 000,053,760 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6C4A.tmp
MOD - [2014/05/06 13:38:30 | 000,075,776 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6AED.tmp
MOD - [2014/05/06 13:38:30 | 000,075,776 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6A5E.tmp
MOD - [2014/05/06 13:38:30 | 000,075,776 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM68C5.tmp
MOD - [2014/05/06 13:38:30 | 000,056,320 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6A3D.tmp
MOD - [2014/05/06 13:38:30 | 000,053,760 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6B1D.tmp
MOD - [2014/05/06 13:38:29 | 000,075,776 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM673D.tmp
MOD - [2014/05/06 13:38:29 | 000,075,776 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM672B.tmp
MOD - [2014/05/06 13:38:29 | 000,075,776 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM66F8.tmp
MOD - [2014/05/06 13:38:29 | 000,075,776 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM66D7.tmp
MOD - [2014/05/06 13:38:29 | 000,075,776 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM66C5.tmp
MOD - [2014/05/06 13:38:29 | 000,068,608 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM66A4.tmp
MOD - [2014/05/06 13:38:29 | 000,056,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM670A.tmp
MOD - [2014/05/06 13:38:29 | 000,056,320 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6401.tmp
MOD - [2014/05/06 13:38:29 | 000,055,296 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6673.tmp
MOD - [2014/05/06 13:38:28 | 000,075,776 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM63D1.tmp
MOD - [2014/04/24 01:33:13 | 000,390,472 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\ppgooglenaclpluginchrome.dll
MOD - [2014/04/24 01:33:12 | 013,692,232 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\PepperFlash\pepflashplayer.dll
MOD - [2014/04/24 01:33:10 | 004,081,480 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\pdf.dll
MOD - [2014/04/24 01:33:05 | 000,674,632 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\libglesv2.dll
MOD - [2014/04/24 01:33:04 | 000,093,000 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\libegl.dll
MOD - [2014/04/24 01:33:03 | 001,647,432 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\ffmpegsumo.dll
MOD - [2014/04/24 01:33:01 | 000,065,352 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\chrome_elf.dll
MOD - [2014/04/23 23:40:00 | 000,253,440 | ---- | M] () -- C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\libid3tag.dll
MOD - [2014/04/23 23:39:38 | 000,231,936 | ---- | M] () -- C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\libmpgdec.dll
MOD - [2014/04/23 23:38:44 | 000,117,248 | ---- | M] () -- C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\libaacdec.dll
MOD - [2014/04/23 23:38:40 | 000,344,064 | ---- | M] () -- C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\libaudioenc.dll
MOD - [2014/04/23 23:01:04 | 001,092,288 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\chromehtml.dll
MOD - [2014/04/21 23:55:38 | 000,471,552 | ---- | M] () -- C:\Program Files (x86)\Steam\libavutil-53.dll
MOD - [2014/04/21 23:55:38 | 000,340,480 | ---- | M] () -- C:\Program Files (x86)\Steam\libavresample-1.dll
MOD - [2014/04/14 11:30:51 | 019,336,120 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014/03/31 23:09:18 | 000,754,688 | ---- | M] () -- C:\Program Files (x86)\Steam\SDL2.dll
MOD - [2014/03/19 00:09:43 | 001,287,168 | ---- | M] () -- C:\Program Files (x86)\Steam\vr\runtime\bin\vrserver.exe
MOD - [2014/03/19 00:09:43 | 000,315,392 | ---- | M] () -- C:\Program Files (x86)\Steam\vr\runtime\drivers\oculus\bin\driver_oculus.dll
MOD - [2014/03/03 20:15:40 | 020,626,624 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\libcef.dll
MOD - [2014/02/27 23:05:33 | 000,190,976 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\75b6a68103e1b76063d9f69b8275ae61\UIAutomationTypes.ni.dll
MOD - [2014/02/27 23:05:28 | 000,018,944 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\Presentatio49d6fefe#\47e7fc401facd4a5d3f2237f16948f36\PresentationFramework-SystemXml.ni.dll
MOD - [2014/02/27 01:27:27 | 018,813,440 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\a4b45c44490c75bc2fb22780e7ef087d\PresentationFramework.ni.dll
MOD - [2014/02/27 01:27:19 | 001,889,792 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\3fe705796c6a41d4889d9001d1c56af8\System.Xaml.ni.dll
MOD - [2014/02/27 01:27:17 | 012,894,208 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\f4f6ee0df2aa4189bf36e6335cb92761\System.Windows.Forms.ni.dll
MOD - [2014/02/27 01:27:17 | 000,802,816 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc9d#\966f64a25064fe74936295dc06ec586e\System.Runtime.Remoting.ni.dll
MOD - [2014/02/27 01:27:11 | 011,025,920 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\a74542efbeb46445949a39026c501132\PresentationCore.ni.dll
MOD - [2014/02/27 01:27:08 | 001,644,544 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\5cd2aee5e7c07227c694d89219688ab3\System.Drawing.ni.dll
MOD - [2014/02/27 01:27:04 | 006,990,336 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Core\dce99d8de14d8a015313db98c72552ee\System.Core.ni.dll
MOD - [2014/02/27 01:27:03 | 007,662,080 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml\bada32953bb6b16a53d653eae23d78dc\System.Xml.ni.dll
MOD - [2014/02/27 01:27:01 | 003,950,080 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\acf97bfe2a931d4a47253b26b7218991\WindowsBase.ni.dll
MOD - [2014/02/27 01:26:59 | 000,470,528 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\Presentatio1c9175f8#\75f8bc4cf08030c4a53b6d5e0ae20046\PresentationFramework.Aero.ni.dll
MOD - [2014/02/27 01:26:58 | 000,976,384 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\bbc48ec4245e502ae19b0601d3799c9e\System.Configuration.ni.dll
MOD - [2014/02/27 01:26:57 | 010,060,800 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System\ff26cc03e6d57d8abd13b990332e67c6\System.ni.dll
MOD - [2014/02/27 01:26:52 | 016,953,856 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\mscorlib\ce5f61c5754789df97be8dc991c47d07\mscorlib.ni.dll
MOD - [2014/02/12 21:58:32 | 000,073,544 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2014/02/12 21:58:10 | 001,044,808 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2013/12/10 22:06:52 | 000,026,624 | ---- | M] () -- C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\imageformats\qgif4.dll
MOD - [2013/12/10 22:06:42 | 010,683,392 | ---- | M] () -- C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\QtWebKit4.dll
MOD - [2013/12/10 22:06:40 | 001,681,408 | ---- | M] () -- C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\QtNetwork4.dll
MOD - [2013/12/10 22:06:38 | 007,741,952 | ---- | M] () -- C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\QtGui4.dll
MOD - [2013/12/10 22:06:36 | 002,248,192 | ---- | M] () -- C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\QtCore4.dll
MOD - [2013/09/14 01:51:02 | 000,087,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Internet Services\zlib1.dll
MOD - [2013/09/14 01:50:36 | 001,242,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Internet Services\libxml2.dll
MOD - [2013/06/15 00:49:12 | 001,100,800 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avcodec-53.dll
MOD - [2013/06/15 00:49:12 | 000,192,000 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avformat-53.dll
MOD - [2013/06/15 00:49:12 | 000,124,416 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avutil-51.dll
MOD - [2013/06/10 10:55:08 | 002,010,624 | ---- | M] () -- C:\Program Files (x86)\ManyCam\Bin\opencv_core220.dll
MOD - [2013/06/10 10:55:08 | 001,241,088 | ---- | M] () -- C:\Program Files (x86)\ManyCam\Bin\opencv_imgproc220.dll
MOD - [2013/06/10 10:55:08 | 000,775,680 | ---- | M] () -- C:\Program Files (x86)\ManyCam\Bin\opencv_highgui220.dll
MOD - [2013/06/10 10:55:08 | 000,241,152 | ---- | M] () -- C:\Program Files (x86)\ManyCam\Bin\opencv_objdetect220.dll
MOD - [2013/06/10 10:55:08 | 000,201,216 | ---- | M] () -- C:\Program Files (x86)\ManyCam\Bin\opencv_video220.dll
MOD - [2013/02/19 00:28:08 | 014,800,896 | ---- | M] () -- C:\Program Files (x86)\FAHClient\FAHClient.exe
MOD - [2009/12/07 12:09:18 | 000,055,296 | ---- | M] () -- C:\Program Files (x86)\ShortKeys 3\ssce32.dll
MOD - [2009/02/27 16:38:20 | 000,139,264 | R--- | M] () -- C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
MOD - [2007/11/07 00:20:15 | 000,377,303 | ---- | M] () -- C:\Users\Dan\Desktop\texter.exe
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2014/04/14 11:30:50 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2014/03/30 03:43:28 | 002,211,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe -- (ClickToRunSvc)
SRV:64bit: - [2014/03/01 05:33:34 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013/05/27 06:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2012/12/10 08:24:16 | 009,723,392 | ---- | M] () [Auto | Running] -- C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe -- (MySQL55)
SRV:64bit: - [2012/02/03 06:29:52 | 000,628,448 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel®
SRV:64bit: - [2011/12/16 07:16:48 | 000,583,088 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV:64bit: - [2011/12/14 23:11:38 | 000,833,976 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe -- (TPCHSrv)
SRV:64bit: - [2011/11/26 02:52:36 | 000,138,152 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe -- (TOSHIBA HDD SSD Alert Service)
SRV:64bit: - [2011/11/24 21:20:38 | 000,294,848 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\TECO\TecoService.exe -- (TOSHIBA eco Utility Service)
SRV:64bit: - [2010/10/20 22:41:00 | 000,138,656 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\SysNative\TODDSrv.exe -- (TODDSrv)
SRV:64bit: - [2010/09/10 01:26:34 | 000,162,824 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\GFNEXSrv.exe -- (GFNEXSrv)
SRV:64bit: - [2009/07/14 02:39:47 | 000,081,920 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\tlntsvr.exe -- (TlntSvr)
SRV - [2014/04/29 19:22:21 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/04/23 23:01:04 | 000,572,096 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2014/04/11 19:45:50 | 001,764,992 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
SRV - [2014/04/11 19:45:42 | 001,390,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
SRV - [2014/03/12 00:52:08 | 000,227,904 | ---- | M] (WildTangent) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe -- (GamesAppIntegrationService)
SRV - [2014/02/22 19:44:06 | 000,107,832 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrB.exe -- (PnkBstrB)
SRV - [2014/02/22 19:43:58 | 000,066,872 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2013/10/23 09:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/09/11 22:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/06/26 19:21:50 | 000,207,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2013/06/26 19:21:46 | 000,523,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2013/05/10 00:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/12/14 10:17:04 | 003,467,768 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)
SRV - [2012/11/29 21:31:04 | 000,038,608 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
SRV - [2012/05/10 16:20:46 | 000,276,248 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2012/03/28 13:49:11 | 000,140,456 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)
SRV - [2012/02/29 01:13:56 | 000,363,800 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2012/02/29 01:13:54 | 000,277,784 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2012/02/21 20:29:38 | 000,161,560 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe -- (jhi_service)
SRV - [2012/02/21 20:29:28 | 000,128,280 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe -- (Intel®
SRV - [2011/11/04 13:40:06 | 000,687,400 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2011/08/02 16:47:26 | 000,145,256 | ---- | M] (Nuance Communications, Inc.) [Auto | Running] -- C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe -- (PDFProFiltSrvPP)
SRV - [2011/07/12 01:16:06 | 000,057,216 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV - [2011/04/02 01:42:00 | 000,198,064 | ---- | M] (TOSHIBA CORPORATION) [On_Demand | Stopped] -- C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service)
SRV - [2011/02/10 08:25:36 | 000,112,080 | ---- | M] (Toshiba Europe GmbH) [Auto | Running] -- C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe -- (TemproMonitoringService)
SRV - [2010/10/12 18:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014/04/14 11:30:51 | 001,039,096 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2014/04/14 11:30:51 | 000,423,240 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2014/04/14 11:30:51 | 000,208,928 | ---- | M] () [Kernel | Boot | Running] -- C:\windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2014/04/14 11:30:51 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2014/04/14 11:30:51 | 000,084,816 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
DRV:64bit: - [2014/04/14 11:30:51 | 000,079,184 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2014/04/14 11:30:51 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2013/06/26 19:21:50 | 000,023,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2013/06/26 19:21:48 | 000,028,840 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2013/06/26 19:21:46 | 000,273,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2013/06/26 19:21:44 | 000,767,144 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2013/01/31 10:50:58 | 000,028,160 | ---- | M] (ManyCam LLC) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mcaudrv_x64.sys -- (mcaudrv_simple)
DRV:64bit: - [2013/01/29 19:15:04 | 000,050,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)
DRV:64bit: - [2012/12/13 13:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012/11/26 19:05:24 | 000,075,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d)
DRV:64bit: - [2012/10/11 04:08:10 | 000,044,928 | ---- | M] (ManyCam LLC) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mcvidrv_x64.sys -- (ManyCam)
DRV:64bit: - [2012/08/23 15:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/23 15:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2012/08/23 15:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012/08/21 14:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/07/17 19:12:08 | 000,062,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2012/05/10 16:11:04 | 014,759,136 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/01/30 22:14:00 | 000,304,696 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfbd.sys -- (tosrfbd)
DRV:64bit: - [2012/01/17 01:20:38 | 001,082,472 | ---- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtwlane.sys -- (RTL8192Ce)
DRV:64bit: - [2012/01/05 21:42:32 | 000,021,096 | ---- | M] (Realtek Microelectronics) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtkBtfilter.sys -- (RtkBtFilter)
DRV:64bit: - [2012/01/05 11:58:50 | 000,786,200 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc)
DRV:64bit: - [2012/01/05 11:58:50 | 000,355,096 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub)
DRV:64bit: - [2012/01/05 11:58:50 | 000,016,152 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs)
DRV:64bit: - [2011/12/19 20:15:10 | 000,411,920 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2011/12/17 01:24:00 | 000,079,040 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfusb.sys -- (Tosrfusb)
DRV:64bit: - [2011/12/06 12:23:08 | 000,331,264 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2011/12/01 10:42:44 | 000,072,240 | ---- | M] (Nero AG) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NBVol.sys -- (NBVol)
DRV:64bit: - [2011/12/01 10:42:44 | 000,015,920 | ---- | M] (Nero AG) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NBVolUp.sys -- (NBVolUp)
DRV:64bit: - [2011/11/30 03:40:32 | 000,568,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011/08/24 05:57:24 | 000,565,352 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/08/17 22:27:06 | 000,251,496 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/02/08 19:07:00 | 000,038,096 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\PGEffect.sys -- (PGEffect)
DRV:64bit: - [2010/11/21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 14:34:04 | 000,360,832 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcvmm.sys -- (vpcvmm)
DRV:64bit: - [2010/11/20 14:34:04 | 000,194,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpchbus.sys -- (vpcbus)
DRV:64bit: - [2010/11/20 12:35:34 | 000,095,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpcusb.sys -- (vpcusb)
DRV:64bit: - [2010/11/20 12:35:22 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcnfltr.sys -- (vpcnfltr)
DRV:64bit: - [2010/08/30 18:48:00 | 000,094,528 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Tosrfhid.sys -- (Tosrfhid)
DRV:64bit: - [2010/06/19 00:45:00 | 000,018,872 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tosrfec.sys -- (tosrfec)
DRV:64bit: - [2009/07/31 04:22:04 | 000,027,784 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV:64bit: - [2009/07/15 00:31:18 | 000,026,840 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TVALZ_O.SYS -- (TVALZ)
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/14 01:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009/06/24 23:36:48 | 000,482,384 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tos_sps64.sys -- (tos_sps64)
DRV:64bit: - [2009/06/20 03:15:22 | 000,014,472 | ---- | M] (TOSHIBA Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TVALZFL.sys -- (TVALZFL)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2007/05/14 17:06:18 | 000,027,520 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimUsb_AMD64.sys -- (RimUsb)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {1AEAB112-D45F-4C13-BAD6-EE71ED7B8B64}
IE:64bit: - HKLM\..\SearchScopes\{1AEAB112-D45F-4C13-BAD6-EE71ED7B8B64}: "URL" = http://www.google.co...g}&rlz=1I7TEUA;
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = 
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{1AEAB112-D45F-4C13-BAD6-EE71ED7B8B64}: "URL" = http://www.google.co...g}&rlz=1I7TEUA;
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
IE - HKCU\..\SearchScopes,DefaultScope = {1AEAB112-D45F-4C13-BAD6-EE71ED7B8B64}
IE - HKCU\..\SearchScopes\{1AEAB112-D45F-4C13-BAD6-EE71ED7B8B64}: "URL" = http://www.google.co...UA_enGB516GB517
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\system32\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.55.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.55.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll File not found
FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@nsroblox.roblox.com/launcher: C:\Users\Dan\AppData\Local\Roblox\Versions\version-38d9c3e04e394773\\NPRobloxProxy.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Dan\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Dan\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Dan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/01/12 01:27:42 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/01/12 01:27:42 | 000,000,000 | ---D | M]
 
[2013/05/10 23:30:16 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Extensions
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U30 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Nero Kwik Media Helper (Enabled) = C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Intel® Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll
CHR - plugin: Intel® Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll
CHR - plugin: Windows Live™ Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll
CHR - Extension: WOT = C:\Users\Dan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\2.5.14_0\
CHR - Extension: Adblock Plus = C:\Users\Dan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.7.4_0\
CHR - Extension: avast! Online Security = C:\Users\Dan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2018.95_0\
CHR - Extension: RealDownloader = C:\Users\Dan\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0\
CHR - Extension: Skype Click to Call = C:\Users\Dan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\7.2.15747.10003_0\
CHR - Extension: Google Wallet = C:\Users\Dan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
 
O1 HOSTS File: ([2014/04/14 11:20:27 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O2:64bit: - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\x64\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Viewer Plus\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Logitech Download Assistant] C:\windows\SysNative\LogiLDA.dll (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SRS Premium Sound HD] C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe (SRS Labs, Inc.)
O4:64bit: - HKLM..\Run: [TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Toshiba Registration] C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe (Toshiba Europe GmbH)
O4:64bit: - HKLM..\Run: [Toshiba TEMPRO] C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CanonQuickMenu] C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [IJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (CANON INC.)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKCU..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKCU..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - HKCU..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O4 - HKCU..\Run: [ManyCam] C:\Program Files (x86)\ManyCam\Bin\ManyCam.exe (ManyCam LLC)
O4 - HKCU..\Run: [MusicManager] C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\MusicManager.exe (Google Inc.)
O4 - HKCU..\Run: [SkyDrive] C:\Users\Dan\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (TOSHIBA)
O4 - Startup: C:\Users\Dan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\[email protected] = C:\Program Files (x86)\FAHClient\HideConsole.exe ()
O4 - Startup: C:\Users\Dan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Texter.lnk = C:\Users\Dan\Desktop\texter.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Open with PDF Viewer Plus - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O8:64bit: - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Open with PDF Viewer Plus - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O9:64bit: - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.55.2)
O16 - DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.55.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.168.4.100 194.168.8.100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9002BD8E-F33D-49AA-8006-E4BF84F58C8B}: DhcpNameServer = 194.168.4.100 194.168.8.100
O18:64bit: - Protocol\Handler\osf - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O18 - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/04/20 22:31:56 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\ElevatedDiagnostics
[2014/04/18 23:28:01 | 000,000,000 | ---D | C] -- C:\Users\Dan\Documents\Horizon Game
[2014/04/18 20:32:21 | 000,000,000 | ---D | C] -- C:\Users\Dan\Documents\TJR
[2014/04/14 11:42:11 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Roaming\AVAST Software
[2014/04/14 11:30:57 | 000,084,816 | ---- | C] (AVAST Software) -- C:\windows\SysNative\drivers\aswStm.sys
[2014/04/14 11:30:51 | 000,043,152 | ---- | C] (AVAST Software) -- C:\windows\avastSS.scr
[2014/04/14 11:23:33 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2014/04/13 16:13:47 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Roaming\SpaceEngineers
[2014/04/07 22:25:23 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Roaming\Nero
[2 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[12 C:\windows\SysWow64\*.tmp files -> C:\windows\SysWow64\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2014/05/06 13:49:34 | 000,000,434 | ---- | M] () -- C:\Users\Dan\Desktop\texter.ini
[2014/05/06 13:47:01 | 000,024,608 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/05/06 13:47:01 | 000,024,608 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/05/06 13:42:24 | 002,735,678 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2014/05/06 13:42:24 | 000,671,118 | ---- | M] () -- C:\windows\SysNative\perfh01D.dat
[2014/05/06 13:42:24 | 000,669,734 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2014/05/06 13:42:24 | 000,501,912 | ---- | M] () -- C:\windows\SysNative\perfh014.dat
[2014/05/06 13:42:24 | 000,488,900 | ---- | M] () -- C:\windows\SysNative\perfh00B.dat
[2014/05/06 13:42:24 | 000,148,440 | ---- | M] () -- C:\windows\SysNative\perfc01D.dat
[2014/05/06 13:42:24 | 000,128,110 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2014/05/06 13:42:24 | 000,107,486 | ---- | M] () -- C:\windows\SysNative\perfc00B.dat
[2014/05/06 13:42:24 | 000,101,370 | ---- | M] () -- C:\windows\SysNative\perfc014.dat
[2014/05/06 13:35:50 | 000,000,828 | ---- | M] () -- C:\windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
[2014/05/06 13:35:49 | 000,000,908 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/05/06 13:35:03 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2014/05/06 13:35:01 | 451,776,511 | -HS- | M] () -- C:\hiberfil.sys
[2014/05/06 00:22:10 | 000,000,830 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2014/05/06 00:11:29 | 000,000,912 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/05/06 00:00:45 | 000,000,900 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-269794971-2251558941-1448437433-1000UA.job
[2014/05/05 17:47:17 | 000,001,319 | ---- | M] () -- C:\Users\Dan\Desktop\ROBLOX Player.lnk
[2014/05/05 17:47:17 | 000,001,138 | ---- | M] () -- C:\Users\Dan\Desktop\ROBLOX Studio 2013.lnk
[2014/05/05 16:00:02 | 000,000,848 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-269794971-2251558941-1448437433-1000Core.job
[2014/04/28 22:40:56 | 000,441,712 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2014/04/19 23:46:23 | 004,070,573 | ---- | M] () -- C:\Users\Dan\Documents\09 Ghost.mp3
[2014/04/19 23:37:08 | 000,369,837 | ---- | M] () -- C:\Users\Dan\Documents\IMG_20140411_031534.jpg
[2014/04/14 11:31:20 | 000,001,977 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2014/04/14 11:30:51 | 001,039,096 | ---- | M] (AVAST Software) -- C:\windows\SysNative\drivers\aswSnx.sys
[2014/04/14 11:30:51 | 000,423,240 | ---- | M] (AVAST Software) -- C:\windows\SysNative\drivers\aswSP.sys
[2014/04/14 11:30:51 | 000,334,648 | ---- | M] (AVAST Software) -- C:\windows\SysNative\aswBoot.exe
[2014/04/14 11:30:51 | 000,208,928 | ---- | M] () -- C:\windows\SysNative\drivers\aswVmm.sys
[2014/04/14 11:30:51 | 000,093,568 | ---- | M] (AVAST Software) -- C:\windows\SysNative\drivers\aswRdr2.sys
[2014/04/14 11:30:51 | 000,084,816 | ---- | M] (AVAST Software) -- C:\windows\SysNative\drivers\aswStm.sys
[2014/04/14 11:30:51 | 000,079,184 | ---- | M] (AVAST Software) -- C:\windows\SysNative\drivers\aswMonFlt.sys
[2014/04/14 11:30:51 | 000,065,776 | ---- | M] () -- C:\windows\SysNative\drivers\aswRvrt.sys
[2014/04/14 11:30:51 | 000,043,152 | ---- | M] (AVAST Software) -- C:\windows\avastSS.scr
[2014/04/14 11:27:25 | 000,000,000 | ---- | M] () -- C:\windows\SysWow64\config.nt
[2014/04/14 11:20:27 | 000,000,027 | ---- | M] () -- C:\windows\SysNative\drivers\etc\hosts
[2014/04/14 11:04:23 | 005,194,807 | R--- | M] (Swearware) -- C:\Users\Dan\Desktop\ComboFixed.exe
[2014/04/10 16:44:44 | 000,001,009 | ---- | M] () -- C:\Users\Public\Desktop\Blueline.lnk
[2014/04/07 22:26:21 | 349,413,276 | ---- | M] () -- C:\Users\Dan\Documents\Image.nrg
[2 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[12 C:\windows\SysWow64\*.tmp files -> C:\windows\SysWow64\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2014/05/05 23:31:48 | 001,287,168 | ---- | C] () -- C:\Users\Dan\Desktop\vrserver.exe
[2014/04/19 23:45:11 | 004,070,573 | ---- | C] () -- C:\Users\Dan\Documents\09 Ghost.mp3
[2014/04/19 23:36:51 | 000,369,837 | ---- | C] () -- C:\Users\Dan\Documents\IMG_20140411_031534.jpg
[2014/04/10 16:44:44 | 000,001,009 | ---- | C] () -- C:\Users\Public\Desktop\Blueline.lnk
[2014/04/07 22:26:20 | 349,413,276 | ---- | C] () -- C:\Users\Dan\Documents\Image.nrg
[2014/02/22 19:44:00 | 000,107,832 | ---- | C] () -- C:\windows\SysWow64\PnkBstrB.exe
[2014/02/22 19:43:58 | 002,337,865 | ---- | C] () -- C:\windows\SysWow64\pbsvc.exe
[2014/02/22 19:43:58 | 000,066,872 | ---- | C] () -- C:\windows\SysWow64\PnkBstrA.exe
[2014/01/03 01:03:29 | 000,000,023 | ---- | C] () -- C:\Users\Dan\jagexappletviewer.preferences
[2013/09/19 15:10:21 | 000,196,128 | -H-- | C] () -- C:\windows\SysWow64\mlfcache.dat
[2013/09/10 17:52:13 | 000,000,600 | ---- | C] () -- C:\Users\Dan\AppData\Local\PUTTY.RND
[2013/08/11 00:56:15 | 171,059,279 | ---- | C] () -- C:\Users\Dan\AppData\Roaming\.technic.rar
[2013/05/03 16:18:01 | 000,007,602 | ---- | C] () -- C:\Users\Dan\AppData\Local\Resmon.ResmonCfg
[2013/04/02 20:05:30 | 000,013,055 | ---- | C] () -- C:\windows\BRRBCOM.INI
[2013/04/02 20:03:22 | 000,045,056 | ---- | C] () -- C:\windows\SysWow64\BRTCPCON.DLL
[2013/04/02 20:03:21 | 000,000,114 | ---- | C] () -- C:\windows\SysWow64\BRLMW03A.INI
[2013/01/19 23:35:05 | 000,703,007 | ---- | C] () -- C:\Users\Dan\AppData\Roaming\technic-launcher.jar.bak
[2013/01/05 22:09:33 | 002,673,230 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/05/31 08:38:27 | 000,128,312 | ---- | C] () -- C:\windows\SysWow64\GFNEX.dll
[2012/05/31 08:35:05 | 000,028,528 | ---- | C] () -- C:\windows\rlt8723a_chip_bt40_fw_asic_rom_patch.dll
[2012/05/31 08:32:19 | 000,451,072 | ---- | C] () -- C:\windows\SysWow64\ISSRemoveSP.exe
[2012/05/10 16:14:32 | 000,755,572 | ---- | C] () -- C:\windows\SysWow64\igkrng700.bin
[2012/05/10 16:14:32 | 000,559,972 | ---- | C] () -- C:\windows\SysWow64\igfcg700m.bin
[2012/05/10 16:07:18 | 000,058,880 | ---- | C] () -- C:\windows\SysWow64\igdde32.dll
[2012/05/10 15:25:28 | 013,026,304 | ---- | C] () -- C:\windows\SysWow64\ig7icd32.dll
 
========== ZeroAccess Check ==========
 
[2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/07/26 03:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/26 02:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2014/01/19 21:19:36 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\.minecraft
[2013/09/16 13:55:01 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\.mono
[2013/04/02 22:01:17 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\.technic
[2013/03/23 00:29:19 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\.techniclauncher
[2013/12/20 22:16:46 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\11bitstudios
[2013/08/08 22:57:05 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\3909
[2013/04/24 19:08:34 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\3909 LLC
[2013/12/20 00:53:33 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\8BitMMO
[2014/04/14 11:42:11 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\AVAST Software
[2013/01/12 03:32:23 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2013/05/23 22:51:22 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\BitTorrent
[2013/09/17 21:23:49 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Canon
[2013/06/23 20:34:17 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\com.shirogames.evoland
[2013/04/02 20:12:38 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\ControlCenter4
[2013/04/21 14:25:32 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\CorsixTH
[2013/07/31 18:17:56 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Faerie Solitaire
[2014/05/06 13:37:14 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\FAHClient
[2013/03/23 00:28:54 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\logs
[2013/06/16 23:42:59 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\ManyCam
[2013/01/02 19:58:18 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\MotioninJoy
[2013/01/04 00:17:03 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\MySQL
[2013/01/25 00:35:12 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\NetBeans
[2013/01/08 01:27:10 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Notepad++
[2013/04/02 19:56:55 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Nuance
[2013/03/10 11:56:22 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Origin
[2013/10/12 17:42:13 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\PC Remote
[2013/02/03 19:38:01 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\PDF Writer
[2014/02/23 01:53:08 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\PrimoPDF
[2013/09/04 12:16:07 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\SoftGrid Client
[2014/04/20 14:55:06 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\SpaceEngineers
[2013/04/05 19:26:58 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Spore
[2013/01/04 02:03:08 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\TeamViewer
[2013/03/13 20:43:23 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\The Creative Assembly
[2013/06/20 14:36:47 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Toshiba
[2013/01/16 23:17:42 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\TOSHIBA Online Product Information
[2013/01/05 22:10:37 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\TP
[2012/12/28 00:04:12 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Tropico 3
[2013/11/16 01:21:07 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Unity
[2014/03/20 23:00:02 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\WildTangent
[2012/12/27 15:55:07 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\WinBatch
 
========== Purity Check ==========
 
 
 
< End of report >

OTL logfile created on: 06/05/2014 13:47:51 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Dan\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16521)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
 
5.89 Gb Total Physical Memory | 2.78 Gb Available Physical Memory | 47.17% Memory free
11.79 Gb Paging File | 7.98 Gb Available in Paging File | 67.71% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 578.98 Gb Total Space | 178.13 Gb Free Space | 30.77% Space Free | Partition Type: NTFS
 
Computer Name: BISMILLAH | User Name: Dan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/05/06 13:47:23 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Dan\Downloads\OTL (2).exe
PRC - [2014/04/24 01:33:15 | 000,841,032 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014/04/23 23:56:22 | 007,631,872 | ---- | M] (Google Inc.) -- C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\MusicManager.exe
PRC - [2014/04/23 23:01:04 | 000,572,096 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe
PRC - [2014/04/23 23:01:02 | 001,825,984 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Steam\Steam.exe
PRC - [2014/04/14 11:30:50 | 003,854,640 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2014/04/14 11:30:50 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2014/04/11 19:45:50 | 001,764,992 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
PRC - [2014/04/11 19:45:42 | 001,390,720 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
PRC - [2014/04/04 18:59:49 | 000,257,224 | ---- | M] (Microsoft Corporation) -- C:\Users\Dan\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
PRC - [2014/03/19 00:09:43 | 001,287,168 | ---- | M] () -- C:\Program Files (x86)\Steam\vr\runtime\bin\vrserver.exe
PRC - [2014/02/22 19:44:06 | 000,107,832 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrB.exe
PRC - [2014/02/22 19:43:58 | 000,066,872 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2013/11/20 16:43:26 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
PRC - [2013/11/20 16:43:14 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
PRC - [2013/10/03 15:18:46 | 004,351,640 | ---- | M] (Insight Software Solutions, Inc.) -- C:\Program Files (x86)\ShortKeys 3\shortkey.exe
PRC - [2013/09/14 03:27:52 | 000,059,720 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe
PRC - [2013/06/26 19:21:50 | 000,207,528 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2013/06/26 19:21:46 | 000,523,944 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2013/06/10 10:59:46 | 005,399,888 | ---- | M] (ManyCam LLC) -- C:\Program Files (x86)\ManyCam\Bin\ManyCam.exe
PRC - [2013/05/10 00:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/02/19 00:28:08 | 014,800,896 | ---- | M] () -- C:\Program Files (x86)\FAHClient\FAHClient.exe
PRC - [2012/12/14 10:17:04 | 003,467,768 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
PRC - [2012/11/29 21:31:04 | 000,038,608 | ---- | M] () -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
PRC - [2012/08/28 12:00:32 | 001,327,104 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
PRC - [2012/08/28 11:55:16 | 000,393,216 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
PRC - [2012/04/03 13:33:00 | 000,940,168 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.EXE
PRC - [2012/04/03 13:27:16 | 001,087,608 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
PRC - [2012/04/03 13:26:14 | 001,273,448 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
PRC - [2012/03/28 13:49:11 | 000,140,456 | ---- | M] () -- C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
PRC - [2012/03/26 17:35:16 | 000,449,168 | ---- | M] (CANON INC.) -- C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
PRC - [2012/02/29 01:13:56 | 000,363,800 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2012/02/29 01:13:54 | 000,277,784 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2012/02/21 20:29:38 | 000,161,560 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
PRC - [2012/02/21 20:29:28 | 000,128,280 | ---- | M] () -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
PRC - [2012/01/05 11:59:50 | 000,291,608 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
PRC - [2011/11/04 13:40:06 | 000,687,400 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2011/08/02 16:49:24 | 000,030,568 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe
PRC - [2011/08/02 16:47:26 | 000,145,256 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
PRC - [2009/05/05 16:06:06 | 000,222,496 | ---- | M] (Acresso Corporation) -- C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
PRC - [2007/11/07 00:20:15 | 000,377,303 | ---- | M] () -- C:\Users\Dan\Desktop\texter.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/05/06 13:38:45 | 000,086,016 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEMA34A.tmp
MOD - [2014/05/06 13:38:44 | 000,086,016 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEMA2BB.tmp
MOD - [2014/05/06 13:38:44 | 000,086,016 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM9FDC.tmp
MOD - [2014/05/06 13:38:44 | 000,086,016 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM9FBB.tmp
MOD - [2014/05/06 13:38:43 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM9CCA.tmp
MOD - [2014/05/06 13:38:43 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM9BCE.tmp
MOD - [2014/05/06 13:38:42 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM9A37.tmp
MOD - [2014/05/06 13:38:42 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM98BE.tmp
MOD - [2014/05/06 13:38:41 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM95B0.tmp
MOD - [2014/05/06 13:38:41 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM93FA.tmp
MOD - [2014/05/06 13:38:40 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM909E.tmp
MOD - [2014/05/06 13:38:39 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM8E5A.tmp
MOD - [2014/05/06 13:38:39 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM8C84.tmp
MOD - [2014/05/06 13:38:38 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM8B1C.tmp
MOD - [2014/05/06 13:38:38 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM8AAC.tmp
MOD - [2014/05/06 13:38:38 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM881B.tmp
MOD - [2014/05/06 13:38:37 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM86D2.tmp
MOD - [2014/05/06 13:38:37 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM85C6.tmp
MOD - [2014/05/06 13:38:37 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM8538.tmp
MOD - [2014/05/06 13:38:37 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM84B9.tmp
MOD - [2014/05/06 13:38:37 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM837F.tmp
MOD - [2014/05/06 13:38:35 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM7F2A.tmp
MOD - [2014/05/06 13:38:35 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM7C79.tmp
MOD - [2014/05/06 13:38:35 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM7BCC.tmp
MOD - [2014/05/06 13:38:34 | 000,120,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM790B.tmp
MOD - [2014/05/06 13:38:32 | 000,072,192 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM72F0.tmp
MOD - [2014/05/06 13:38:32 | 000,072,192 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM72AB.tmp
MOD - [2014/05/06 13:38:32 | 000,033,792 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\YTMP7MC8AA\TAA72DF.tmp
MOD - [2014/05/06 13:38:32 | 000,033,792 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\YTMP7MC8AA\TAA72CD.tmp
MOD - [2014/05/06 13:38:32 | 000,033,792 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\YTMP7MC8AA\TAA729B.tmp
MOD - [2014/05/06 13:38:32 | 000,033,792 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\YTMP7MC8AA\TAA7180.tmp
MOD - [2014/05/06 13:38:31 | 000,072,704 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6ECF.tmp
MOD - [2014/05/06 13:38:31 | 000,072,192 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6DD4.tmp
MOD - [2014/05/06 13:38:31 | 000,064,000 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6C29.tmp
MOD - [2014/05/06 13:38:31 | 000,057,344 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6D55.tmp
MOD - [2014/05/06 13:38:31 | 000,053,760 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6C4A.tmp
MOD - [2014/05/06 13:38:30 | 000,075,776 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6AED.tmp
MOD - [2014/05/06 13:38:30 | 000,075,776 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6A5E.tmp
MOD - [2014/05/06 13:38:30 | 000,075,776 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM68C5.tmp
MOD - [2014/05/06 13:38:30 | 000,056,320 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6A3D.tmp
MOD - [2014/05/06 13:38:30 | 000,053,760 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6B1D.tmp
MOD - [2014/05/06 13:38:29 | 000,075,776 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM673D.tmp
MOD - [2014/05/06 13:38:29 | 000,075,776 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM672B.tmp
MOD - [2014/05/06 13:38:29 | 000,075,776 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM66F8.tmp
MOD - [2014/05/06 13:38:29 | 000,075,776 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM66D7.tmp
MOD - [2014/05/06 13:38:29 | 000,075,776 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM66C5.tmp
MOD - [2014/05/06 13:38:29 | 000,068,608 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM66A4.tmp
MOD - [2014/05/06 13:38:29 | 000,056,832 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM670A.tmp
MOD - [2014/05/06 13:38:29 | 000,056,320 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6401.tmp
MOD - [2014/05/06 13:38:29 | 000,055,296 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM6673.tmp
MOD - [2014/05/06 13:38:28 | 000,075,776 | ---- | M] () -- C:\Users\Dan\AppData\Local\Temp\XTMP1MC3VE\DEM63D1.tmp
MOD - [2014/04/24 01:33:13 | 000,390,472 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\ppgooglenaclpluginchrome.dll
MOD - [2014/04/24 01:33:12 | 013,692,232 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\PepperFlash\pepflashplayer.dll
MOD - [2014/04/24 01:33:10 | 004,081,480 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\pdf.dll
MOD - [2014/04/24 01:33:05 | 000,674,632 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\libglesv2.dll
MOD - [2014/04/24 01:33:04 | 000,093,000 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\libegl.dll
MOD - [2014/04/24 01:33:03 | 001,647,432 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\ffmpegsumo.dll
MOD - [2014/04/24 01:33:01 | 000,065,352 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\chrome_elf.dll
MOD - [2014/04/23 23:40:00 | 000,253,440 | ---- | M] () -- C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\libid3tag.dll
MOD - [2014/04/23 23:39:38 | 000,231,936 | ---- | M] () -- C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\libmpgdec.dll
MOD - [2014/04/23 23:38:44 | 000,117,248 | ---- | M] () -- C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\libaacdec.dll
MOD - [2014/04/23 23:38:40 | 000,344,064 | ---- | M] () -- C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\libaudioenc.dll
MOD - [2014/04/23 23:01:04 | 001,092,288 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\chromehtml.dll
MOD - [2014/04/21 23:55:38 | 000,471,552 | ---- | M] () -- C:\Program Files (x86)\Steam\libavutil-53.dll
MOD - [2014/04/21 23:55:38 | 000,340,480 | ---- | M] () -- C:\Program Files (x86)\Steam\libavresample-1.dll
MOD - [2014/04/14 11:30:51 | 019,336,120 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2014/03/31 23:09:18 | 000,754,688 | ---- | M] () -- C:\Program Files (x86)\Steam\SDL2.dll
MOD - [2014/03/19 00:09:43 | 001,287,168 | ---- | M] () -- C:\Program Files (x86)\Steam\vr\runtime\bin\vrserver.exe
MOD - [2014/03/19 00:09:43 | 000,315,392 | ---- | M] () -- C:\Program Files (x86)\Steam\vr\runtime\drivers\oculus\bin\driver_oculus.dll
MOD - [2014/03/03 20:15:40 | 020,626,624 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\libcef.dll
MOD - [2014/02/27 23:05:33 | 000,190,976 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\75b6a68103e1b76063d9f69b8275ae61\UIAutomationTypes.ni.dll
MOD - [2014/02/27 23:05:28 | 000,018,944 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\Presentatio49d6fefe#\47e7fc401facd4a5d3f2237f16948f36\PresentationFramework-SystemXml.ni.dll
MOD - [2014/02/27 01:27:27 | 018,813,440 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\a4b45c44490c75bc2fb22780e7ef087d\PresentationFramework.ni.dll
MOD - [2014/02/27 01:27:19 | 001,889,792 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\3fe705796c6a41d4889d9001d1c56af8\System.Xaml.ni.dll
MOD - [2014/02/27 01:27:17 | 012,894,208 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\f4f6ee0df2aa4189bf36e6335cb92761\System.Windows.Forms.ni.dll
MOD - [2014/02/27 01:27:17 | 000,802,816 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc9d#\966f64a25064fe74936295dc06ec586e\System.Runtime.Remoting.ni.dll
MOD - [2014/02/27 01:27:11 | 011,025,920 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\a74542efbeb46445949a39026c501132\PresentationCore.ni.dll
MOD - [2014/02/27 01:27:08 | 001,644,544 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\5cd2aee5e7c07227c694d89219688ab3\System.Drawing.ni.dll
MOD - [2014/02/27 01:27:04 | 006,990,336 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Core\dce99d8de14d8a015313db98c72552ee\System.Core.ni.dll
MOD - [2014/02/27 01:27:03 | 007,662,080 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml\bada32953bb6b16a53d653eae23d78dc\System.Xml.ni.dll
MOD - [2014/02/27 01:27:01 | 003,950,080 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\acf97bfe2a931d4a47253b26b7218991\WindowsBase.ni.dll
MOD - [2014/02/27 01:26:59 | 000,470,528 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\Presentatio1c9175f8#\75f8bc4cf08030c4a53b6d5e0ae20046\PresentationFramework.Aero.ni.dll
MOD - [2014/02/27 01:26:58 | 000,976,384 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\bbc48ec4245e502ae19b0601d3799c9e\System.Configuration.ni.dll
MOD - [2014/02/27 01:26:57 | 010,060,800 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System\ff26cc03e6d57d8abd13b990332e67c6\System.ni.dll
MOD - [2014/02/27 01:26:52 | 016,953,856 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\mscorlib\ce5f61c5754789df97be8dc991c47d07\mscorlib.ni.dll
MOD - [2014/02/12 21:58:32 | 000,073,544 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2014/02/12 21:58:10 | 001,044,808 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2013/12/10 22:06:52 | 000,026,624 | ---- | M] () -- C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\imageformats\qgif4.dll
MOD - [2013/12/10 22:06:42 | 010,683,392 | ---- | M] () -- C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\QtWebKit4.dll
MOD - [2013/12/10 22:06:40 | 001,681,408 | ---- | M] () -- C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\QtNetwork4.dll
MOD - [2013/12/10 22:06:38 | 007,741,952 | ---- | M] () -- C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\QtGui4.dll
MOD - [2013/12/10 22:06:36 | 002,248,192 | ---- | M] () -- C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\QtCore4.dll
MOD - [2013/09/14 01:51:02 | 000,087,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Internet Services\zlib1.dll
MOD - [2013/09/14 01:50:36 | 001,242,952 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Internet Services\libxml2.dll
MOD - [2013/06/15 00:49:12 | 001,100,800 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avcodec-53.dll
MOD - [2013/06/15 00:49:12 | 000,192,000 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avformat-53.dll
MOD - [2013/06/15 00:49:12 | 000,124,416 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avutil-51.dll
MOD - [2013/06/10 10:55:08 | 002,010,624 | ---- | M] () -- C:\Program Files (x86)\ManyCam\Bin\opencv_core220.dll
MOD - [2013/06/10 10:55:08 | 001,241,088 | ---- | M] () -- C:\Program Files (x86)\ManyCam\Bin\opencv_imgproc220.dll
MOD - [2013/06/10 10:55:08 | 000,775,680 | ---- | M] () -- C:\Program Files (x86)\ManyCam\Bin\opencv_highgui220.dll
MOD - [2013/06/10 10:55:08 | 000,241,152 | ---- | M] () -- C:\Program Files (x86)\ManyCam\Bin\opencv_objdetect220.dll
MOD - [2013/06/10 10:55:08 | 000,201,216 | ---- | M] () -- C:\Program Files (x86)\ManyCam\Bin\opencv_video220.dll
MOD - [2013/02/19 00:28:08 | 014,800,896 | ---- | M] () -- C:\Program Files (x86)\FAHClient\FAHClient.exe
MOD - [2009/12/07 12:09:18 | 000,055,296 | ---- | M] () -- C:\Program Files (x86)\ShortKeys 3\ssce32.dll
MOD - [2009/02/27 16:38:20 | 000,139,264 | R--- | M] () -- C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
MOD - [2007/11/07 00:20:15 | 000,377,303 | ---- | M] () -- C:\Users\Dan\Desktop\texter.exe
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2014/04/14 11:30:50 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2014/03/30 03:43:28 | 002,211,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe -- (ClickToRunSvc)
SRV:64bit: - [2014/03/01 05:33:34 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013/05/27 06:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2012/12/10 08:24:16 | 009,723,392 | ---- | M] () [Auto | Running] -- C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe -- (MySQL55)
SRV:64bit: - [2012/02/03 06:29:52 | 000,628,448 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel®
SRV:64bit: - [2011/12/16 07:16:48 | 000,583,088 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV:64bit: - [2011/12/14 23:11:38 | 000,833,976 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe -- (TPCHSrv)
SRV:64bit: - [2011/11/26 02:52:36 | 000,138,152 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe -- (TOSHIBA HDD SSD Alert Service)
SRV:64bit: - [2011/11/24 21:20:38 | 000,294,848 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\TECO\TecoService.exe -- (TOSHIBA eco Utility Service)
SRV:64bit: - [2010/10/20 22:41:00 | 000,138,656 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\SysNative\TODDSrv.exe -- (TODDSrv)
SRV:64bit: - [2010/09/10 01:26:34 | 000,162,824 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\GFNEXSrv.exe -- (GFNEXSrv)
SRV:64bit: - [2009/07/14 02:39:47 | 000,081,920 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\tlntsvr.exe -- (TlntSvr)
SRV - [2014/04/29 19:22:21 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/04/23 23:01:04 | 000,572,096 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2014/04/11 19:45:50 | 001,764,992 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
SRV - [2014/04/11 19:45:42 | 001,390,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
SRV - [2014/03/12 00:52:08 | 000,227,904 | ---- | M] (WildTangent) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe -- (GamesAppIntegrationService)
SRV - [2014/02/22 19:44:06 | 000,107,832 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrB.exe -- (PnkBstrB)
SRV - [2014/02/22 19:43:58 | 000,066,872 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2013/10/23 09:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/09/11 22:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/06/26 19:21:50 | 000,207,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2013/06/26 19:21:46 | 000,523,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2013/05/10 00:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/12/14 10:17:04 | 003,467,768 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe -- (TeamViewer8)
SRV - [2012/11/29 21:31:04 | 000,038,608 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
SRV - [2012/05/10 16:20:46 | 000,276,248 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2012/03/28 13:49:11 | 000,140,456 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)
SRV - [2012/02/29 01:13:56 | 000,363,800 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2012/02/29 01:13:54 | 000,277,784 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2012/02/21 20:29:38 | 000,161,560 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe -- (jhi_service)
SRV - [2012/02/21 20:29:28 | 000,128,280 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe -- (Intel®
SRV - [2011/11/04 13:40:06 | 000,687,400 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2011/08/02 16:47:26 | 000,145,256 | ---- | M] (Nuance Communications, Inc.) [Auto | Running] -- C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe -- (PDFProFiltSrvPP)
SRV - [2011/07/12 01:16:06 | 000,057,216 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV - [2011/04/02 01:42:00 | 000,198,064 | ---- | M] (TOSHIBA CORPORATION) [On_Demand | Stopped] -- C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe -- (TOSHIBA Bluetooth Service)
SRV - [2011/02/10 08:25:36 | 000,112,080 | ---- | M] (Toshiba Europe GmbH) [Auto | Running] -- C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe -- (TemproMonitoringService)
SRV - [2010/10/12 18:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2014/04/14 11:30:51 | 001,039,096 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2014/04/14 11:30:51 | 000,423,240 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2014/04/14 11:30:51 | 000,208,928 | ---- | M] () [Kernel | Boot | Running] -- C:\windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2014/04/14 11:30:51 | 000,093,568 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2014/04/14 11:30:51 | 000,084,816 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
DRV:64bit: - [2014/04/14 11:30:51 | 000,079,184 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2014/04/14 11:30:51 | 000,065,776 | ---- | M] () [Kernel | Boot | Running] -- C:\windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2013/06/26 19:21:50 | 000,023,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2013/06/26 19:21:48 | 000,028,840 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2013/06/26 19:21:46 | 000,273,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2013/06/26 19:21:44 | 000,767,144 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2013/01/31 10:50:58 | 000,028,160 | ---- | M] (ManyCam LLC) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mcaudrv_x64.sys -- (mcaudrv_simple)
DRV:64bit: - [2013/01/29 19:15:04 | 000,050,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)
DRV:64bit: - [2012/12/13 13:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012/11/26 19:05:24 | 000,075,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d)
DRV:64bit: - [2012/10/11 04:08:10 | 000,044,928 | ---- | M] (ManyCam LLC) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mcvidrv_x64.sys -- (ManyCam)
DRV:64bit: - [2012/08/23 15:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/23 15:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2012/08/23 15:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012/08/21 14:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/07/17 19:12:08 | 000,062,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2012/05/10 16:11:04 | 014,759,136 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/01/30 22:14:00 | 000,304,696 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfbd.sys -- (tosrfbd)
DRV:64bit: - [2012/01/17 01:20:38 | 001,082,472 | ---- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtwlane.sys -- (RTL8192Ce)
DRV:64bit: - [2012/01/05 21:42:32 | 000,021,096 | ---- | M] (Realtek Microelectronics) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtkBtfilter.sys -- (RtkBtFilter)
DRV:64bit: - [2012/01/05 11:58:50 | 000,786,200 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc)
DRV:64bit: - [2012/01/05 11:58:50 | 000,355,096 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub)
DRV:64bit: - [2012/01/05 11:58:50 | 000,016,152 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs)
DRV:64bit: - [2011/12/19 20:15:10 | 000,411,920 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2011/12/17 01:24:00 | 000,079,040 | ---- | M] (TOSHIBA CORPORATION) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tosrfusb.sys -- (Tosrfusb)
DRV:64bit: - [2011/12/06 12:23:08 | 000,331,264 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2011/12/01 10:42:44 | 000,072,240 | ---- | M] (Nero AG) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NBVol.sys -- (NBVol)
DRV:64bit: - [2011/12/01 10:42:44 | 000,015,920 | ---- | M] (Nero AG) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NBVolUp.sys -- (NBVolUp)
DRV:64bit: - [2011/11/30 03:40:32 | 000,568,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011/08/24 05:57:24 | 000,565,352 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/08/17 22:27:06 | 000,251,496 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/02/08 19:07:00 | 000,038,096 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\PGEffect.sys -- (PGEffect)
DRV:64bit: - [2010/11/21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 14:34:04 | 000,360,832 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcvmm.sys -- (vpcvmm)
DRV:64bit: - [2010/11/20 14:34:04 | 000,194,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpchbus.sys -- (vpcbus)
DRV:64bit: - [2010/11/20 12:35:34 | 000,095,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpcusb.sys -- (vpcusb)
DRV:64bit: - [2010/11/20 12:35:22 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcnfltr.sys -- (vpcnfltr)
DRV:64bit: - [2010/08/30 18:48:00 | 000,094,528 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Tosrfhid.sys -- (Tosrfhid)
DRV:64bit: - [2010/06/19 00:45:00 | 000,018,872 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tosrfec.sys -- (tosrfec)
DRV:64bit: - [2009/07/31 04:22:04 | 000,027,784 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV:64bit: - [2009/07/15 00:31:18 | 000,026,840 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TVALZ_O.SYS -- (TVALZ)
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/14 01:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009/06/24 23:36:48 | 000,482,384 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tos_sps64.sys -- (tos_sps64)
DRV:64bit: - [2009/06/20 03:15:22 | 000,014,472 | ---- | M] (TOSHIBA Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TVALZFL.sys -- (TVALZFL)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2007/05/14 17:06:18 | 000,027,520 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimUsb_AMD64.sys -- (RimUsb)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {1AEAB112-D45F-4C13-BAD6-EE71ED7B8B64}
IE:64bit: - HKLM\..\SearchScopes\{1AEAB112-D45F-4C13-BAD6-EE71ED7B8B64}: "URL" = http://www.google.co...g}&rlz=1I7TEUA;
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = 
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{1AEAB112-D45F-4C13-BAD6-EE71ED7B8B64}: "URL" = http://www.google.co...g}&rlz=1I7TEUA;
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
IE - HKCU\..\SearchScopes,DefaultScope = {1AEAB112-D45F-4C13-BAD6-EE71ED7B8B64}
IE - HKCU\..\SearchScopes\{1AEAB112-D45F-4C13-BAD6-EE71ED7B8B64}: "URL" = http://www.google.co...UA_enGB516GB517
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\system32\Adobe\Director\np32dsw_1210150.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.55.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.55.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll File not found
FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@nsroblox.roblox.com/launcher: C:\Users\Dan\AppData\Local\Roblox\Versions\version-38d9c3e04e394773\\NPRobloxProxy.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Dan\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Dan\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Dan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/01/12 01:27:42 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/01/12 01:27:42 | 000,000,000 | ---D | M]
 
[2013/05/10 23:30:16 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Dan\AppData\Roaming\Mozilla\Extensions
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U30 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Nero Kwik Media Helper (Enabled) = C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Intel® Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll
CHR - plugin: Intel® Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll
CHR - plugin: Windows Live™ Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll
CHR - Extension: WOT = C:\Users\Dan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\2.5.14_0\
CHR - Extension: Adblock Plus = C:\Users\Dan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.7.4_0\
CHR - Extension: avast! Online Security = C:\Users\Dan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2018.95_0\
CHR - Extension: RealDownloader = C:\Users\Dan\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0\
CHR - Extension: Skype Click to Call = C:\Users\Dan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\7.2.15747.10003_0\
CHR - Extension: Google Wallet = C:\Users\Dan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
 
O1 HOSTS File: ([2014/04/14 11:20:27 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O2:64bit: - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O2:64bit: - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
O2:64bit: - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
O2:64bit: - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\x64\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Viewer Plus\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\office15\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Logitech Download Assistant] C:\windows\SysNative\LogiLDA.dll (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SRS Premium Sound HD] C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe (SRS Labs, Inc.)
O4:64bit: - HKLM..\Run: [TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Toshiba Registration] C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe (Toshiba Europe GmbH)
O4:64bit: - HKLM..\Run: [Toshiba TEMPRO] C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CanonQuickMenu] C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [IJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (CANON INC.)
O4 - HKLM..\Run: [IndexSearch] C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKCU..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKCU..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O4 - HKCU..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
O4 - HKCU..\Run: [ManyCam] C:\Program Files (x86)\ManyCam\Bin\ManyCam.exe (ManyCam LLC)
O4 - HKCU..\Run: [MusicManager] C:\Users\Dan\AppData\Local\Programs\Google\MusicManager\MusicManager.exe (Google Inc.)
O4 - HKCU..\Run: [SkyDrive] C:\Users\Dan\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (TOSHIBA)
O4 - Startup: C:\Users\Dan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\[email protected] = C:\Program Files (x86)\FAHClient\HideConsole.exe ()
O4 - Startup: C:\Users\Dan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Texter.lnk = C:\Users\Dan\Desktop\texter.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Open with PDF Viewer Plus - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O8:64bit: - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Open with PDF Viewer Plus - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIE.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
O9:64bit: - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesX64\Microsoft Office\Office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\office15\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.55.2)
O16 - DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.55.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 194.168.4.100 194.168.8.100
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9002BD8E-F33D-49AA-8006-E4BF84F58C8B}: DhcpNameServer = 194.168.4.100 194.168.8.100
O18:64bit: - Protocol\Handler\osf - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\SkypeIEPlugin.dll (Microsoft Corporation)
O18 - Protocol\Handler\osf {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\office15\MSOSB.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/04/20 22:31:56 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\ElevatedDiagnostics
[2014/04/18 23:28:01 | 000,000,000 | ---D | C] -- C:\Users\Dan\Documents\Horizon Game
[2014/04/18 20:32:21 | 000,000,000 | ---D | C] -- C:\Users\Dan\Documents\TJR
[2014/04/14 11:42:11 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Roaming\AVAST Software
[2014/04/14 11:30:57 | 000,084,816 | ---- | C] (AVAST Software) -- C:\windows\SysNative\drivers\aswStm.sys
[2014/04/14 11:30:51 | 000,043,152 | ---- | C] (AVAST Software) -- C:\windows\avastSS.scr
[2014/04/14 11:23:33 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2014/04/13 16:13:47 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Roaming\SpaceEngineers
[2014/04/07 22:25:23 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Roaming\Nero
[2 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[12 C:\windows\SysWow64\*.tmp files -> C:\windows\SysWow64\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2014/05/06 13:49:34 | 000,000,434 | ---- | M] () -- C:\Users\Dan\Desktop\texter.ini
[2014/05/06 13:47:01 | 000,024,608 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/05/06 13:47:01 | 000,024,608 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/05/06 13:42:24 | 002,735,678 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2014/05/06 13:42:24 | 000,671,118 | ---- | M] () -- C:\windows\SysNative\perfh01D.dat
[2014/05/06 13:42:24 | 000,669,734 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2014/05/06 13:42:24 | 000,501,912 | ---- | M] () -- C:\windows\SysNative\perfh014.dat
[2014/05/06 13:42:24 | 000,488,900 | ---- | M] () -- C:\windows\SysNative\perfh00B.dat
[2014/05/06 13:42:24 | 000,148,440 | ---- | M] () -- C:\windows\SysNative\perfc01D.dat
[2014/05/06 13:42:24 | 000,128,110 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2014/05/06 13:42:24 | 000,107,486 | ---- | M] () -- C:\windows\SysNative\perfc00B.dat
[2014/05/06 13:42:24 | 000,101,370 | ---- | M] () -- C:\windows\SysNative\perfc014.dat
[2014/05/06 13:35:50 | 000,000,828 | ---- | M] () -- C:\windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
[2014/05/06 13:35:49 | 000,000,908 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/05/06 13:35:03 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2014/05/06 13:35:01 | 451,776,511 | -HS- | M] () -- C:\hiberfil.sys
[2014/05/06 00:22:10 | 000,000,830 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2014/05/06 00:11:29 | 000,000,912 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/05/06 00:00:45 | 000,000,900 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-269794971-2251558941-1448437433-1000UA.job
[2014/05/05 17:47:17 | 000,001,319 | ---- | M] () -- C:\Users\Dan\Desktop\ROBLOX Player.lnk
[2014/05/05 17:47:17 | 000,001,138 | ---- | M] () -- C:\Users\Dan\Desktop\ROBLOX Studio 2013.lnk
[2014/05/05 16:00:02 | 000,000,848 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-269794971-2251558941-1448437433-1000Core.job
[2014/04/28 22:40:56 | 000,441,712 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2014/04/19 23:46:23 | 004,070,573 | ---- | M] () -- C:\Users\Dan\Documents\09 Ghost.mp3
[2014/04/19 23:37:08 | 000,369,837 | ---- | M] () -- C:\Users\Dan\Documents\IMG_20140411_031534.jpg
[2014/04/14 11:31:20 | 000,001,977 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2014/04/14 11:30:51 | 001,039,096 | ---- | M] (AVAST Software) -- C:\windows\SysNative\drivers\aswSnx.sys
[2014/04/14 11:30:51 | 000,423,240 | ---- | M] (AVAST Software) -- C:\windows\SysNative\drivers\aswSP.sys
[2014/04/14 11:30:51 | 000,334,648 | ---- | M] (AVAST Software) -- C:\windows\SysNative\aswBoot.exe
[2014/04/14 11:30:51 | 000,208,928 | ---- | M] () -- C:\windows\SysNative\drivers\aswVmm.sys
[2014/04/14 11:30:51 | 000,093,568 | ---- | M] (AVAST Software) -- C:\windows\SysNative\drivers\aswRdr2.sys
[2014/04/14 11:30:51 | 000,084,816 | ---- | M] (AVAST Software) -- C:\windows\SysNative\drivers\aswStm.sys
[2014/04/14 11:30:51 | 000,079,184 | ---- | M] (AVAST Software) -- C:\windows\SysNative\drivers\aswMonFlt.sys
[2014/04/14 11:30:51 | 000,065,776 | ---- | M] () -- C:\windows\SysNative\drivers\aswRvrt.sys
[2014/04/14 11:30:51 | 000,043,152 | ---- | M] (AVAST Software) -- C:\windows\avastSS.scr
[2014/04/14 11:27:25 | 000,000,000 | ---- | M] () -- C:\windows\SysWow64\config.nt
[2014/04/14 11:20:27 | 000,000,027 | ---- | M] () -- C:\windows\SysNative\drivers\etc\hosts
[2014/04/14 11:04:23 | 005,194,807 | R--- | M] (Swearware) -- C:\Users\Dan\Desktop\ComboFixed.exe
[2014/04/10 16:44:44 | 000,001,009 | ---- | M] () -- C:\Users\Public\Desktop\Blueline.lnk
[2014/04/07 22:26:21 | 349,413,276 | ---- | M] () -- C:\Users\Dan\Documents\Image.nrg
[2 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[12 C:\windows\SysWow64\*.tmp files -> C:\windows\SysWow64\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2014/05/05 23:31:48 | 001,287,168 | ---- | C] () -- C:\Users\Dan\Desktop\vrserver.exe
[2014/04/19 23:45:11 | 004,070,573 | ---- | C] () -- C:\Users\Dan\Documents\09 Ghost.mp3
[2014/04/19 23:36:51 | 000,369,837 | ---- | C] () -- C:\Users\Dan\Documents\IMG_20140411_031534.jpg
[2014/04/10 16:44:44 | 000,001,009 | ---- | C] () -- C:\Users\Public\Desktop\Blueline.lnk
[2014/04/07 22:26:20 | 349,413,276 | ---- | C] () -- C:\Users\Dan\Documents\Image.nrg
[2014/02/22 19:44:00 | 000,107,832 | ---- | C] () -- C:\windows\SysWow64\PnkBstrB.exe
[2014/02/22 19:43:58 | 002,337,865 | ---- | C] () -- C:\windows\SysWow64\pbsvc.exe
[2014/02/22 19:43:58 | 000,066,872 | ---- | C] () -- C:\windows\SysWow64\PnkBstrA.exe
[2014/01/03 01:03:29 | 000,000,023 | ---- | C] () -- C:\Users\Dan\jagexappletviewer.preferences
[2013/09/19 15:10:21 | 000,196,128 | -H-- | C] () -- C:\windows\SysWow64\mlfcache.dat
[2013/09/10 17:52:13 | 000,000,600 | ---- | C] () -- C:\Users\Dan\AppData\Local\PUTTY.RND
[2013/08/11 00:56:15 | 171,059,279 | ---- | C] () -- C:\Users\Dan\AppData\Roaming\.technic.rar
[2013/05/03 16:18:01 | 000,007,602 | ---- | C] () -- C:\Users\Dan\AppData\Local\Resmon.ResmonCfg
[2013/04/02 20:05:30 | 000,013,055 | ---- | C] () -- C:\windows\BRRBCOM.INI
[2013/04/02 20:03:22 | 000,045,056 | ---- | C] () -- C:\windows\SysWow64\BRTCPCON.DLL
[2013/04/02 20:03:21 | 000,000,114 | ---- | C] () -- C:\windows\SysWow64\BRLMW03A.INI
[2013/01/19 23:35:05 | 000,703,007 | ---- | C] () -- C:\Users\Dan\AppData\Roaming\technic-launcher.jar.bak
[2013/01/05 22:09:33 | 002,673,230 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/05/31 08:38:27 | 000,128,312 | ---- | C] () -- C:\windows\SysWow64\GFNEX.dll
[2012/05/31 08:35:05 | 000,028,528 | ---- | C] () -- C:\windows\rlt8723a_chip_bt40_fw_asic_rom_patch.dll
[2012/05/31 08:32:19 | 000,451,072 | ---- | C] () -- C:\windows\SysWow64\ISSRemoveSP.exe
[2012/05/10 16:14:32 | 000,755,572 | ---- | C] () -- C:\windows\SysWow64\igkrng700.bin
[2012/05/10 16:14:32 | 000,559,972 | ---- | C] () -- C:\windows\SysWow64\igfcg700m.bin
[2012/05/10 16:07:18 | 000,058,880 | ---- | C] () -- C:\windows\SysWow64\igdde32.dll
[2012/05/10 15:25:28 | 013,026,304 | ---- | C] () -- C:\windows\SysWow64\ig7icd32.dll
 
========== ZeroAccess Check ==========
 
[2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/07/26 03:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/26 02:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2014/01/19 21:19:36 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\.minecraft
[2013/09/16 13:55:01 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\.mono
[2013/04/02 22:01:17 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\.technic
[2013/03/23 00:29:19 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\.techniclauncher
[2013/12/20 22:16:46 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\11bitstudios
[2013/08/08 22:57:05 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\3909
[2013/04/24 19:08:34 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\3909 LLC
[2013/12/20 00:53:33 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\8BitMMO
[2014/04/14 11:42:11 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\AVAST Software
[2013/01/12 03:32:23 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2013/05/23 22:51:22 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\BitTorrent
[2013/09/17 21:23:49 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Canon
[2013/06/23 20:34:17 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\com.shirogames.evoland
[2013/04/02 20:12:38 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\ControlCenter4
[2013/04/21 14:25:32 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\CorsixTH
[2013/07/31 18:17:56 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Faerie Solitaire
[2014/05/06 13:37:14 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\FAHClient
[2013/03/23 00:28:54 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\logs
[2013/06/16 23:42:59 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\ManyCam
[2013/01/02 19:58:18 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\MotioninJoy
[2013/01/04 00:17:03 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\MySQL
[2013/01/25 00:35:12 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\NetBeans
[2013/01/08 01:27:10 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Notepad++
[2013/04/02 19:56:55 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Nuance
[2013/03/10 11:56:22 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Origin
[2013/10/12 17:42:13 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\PC Remote
[2013/02/03 19:38:01 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\PDF Writer
[2014/02/23 01:53:08 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\PrimoPDF
[2013/09/04 12:16:07 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\SoftGrid Client
[2014/04/20 14:55:06 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\SpaceEngineers
[2013/04/05 19:26:58 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Spore
[2013/01/04 02:03:08 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\TeamViewer
[2013/03/13 20:43:23 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\The Creative Assembly
[2013/06/20 14:36:47 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Toshiba
[2013/01/16 23:17:42 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\TOSHIBA Online Product Information
[2013/01/05 22:10:37 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\TP
[2012/12/28 00:04:12 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Tropico 3
[2013/11/16 01:21:07 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\Unity
[2014/03/20 23:00:02 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\WildTangent
[2012/12/27 15:55:07 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\WinBatch
 
========== Purity Check ==========
 
 
 
< End of report >

OTL Extras logfile created on: 06/05/2014 13:47:51 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Dan\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16521)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
 
5.89 Gb Total Physical Memory | 2.78 Gb Available Physical Memory | 47.17% Memory free
11.79 Gb Paging File | 7.98 Gb Available in Paging File | 67.71% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 578.98 Gb Total Space | 178.13 Gb Free Space | 30.77% Space Free | Partition Type: NTFS
 
Computer Name: BISMILLAH | User Name: Dan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
========== Firewall Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{70B82F0C-2337-4E90-B5B1-DF0F5F9285FF}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office 15\root\office15\outlook.exe | 
"{7B483EC8-13A5-4AF5-886C-A38766793949}" = lport=54925 | protocol=17 | dir=in | name=brothernetwork scanner | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{003C13D0-9853-44F0-8363-9FE1F19CA773}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\bioware\star wars - the old republic\launcher.exe | 
"{02150094-964B-42FE-90F0-D3492AFD7895}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rainbow six vegas 2\binaries\r6vegas2_game.exe | 
"{027EC5FB-0BAB-4DA1-901C-2CE00BAB962E}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{02A12B29-2228-4D9B-AF44-D1D87E1547CF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\grand theft auto iv\gtaiv\launchgtaiv.exe | 
"{02CB47D6-92DC-4EED-B628-B8FD2A1F0EFD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spiral knights\java_vm\bin\javaw.exe | 
"{038022D4-A078-49ED-93B8-78F2371FFB30}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | 
"{07D3F9B3-9DDC-48DE-AAA3-C8FCEA03491F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\stronghold crusader extreme\stronghold crusader.exe | 
"{082224E6-9DD8-4E55-B590-88E82E1AFB14}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe | 
"{099D6954-EC1D-4AAB-9F17-155AC85375BB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star wars empire at war\runme.exe | 
"{09A7392C-0A44-4E56-9711-A68AC81A6623}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\plagueinc\plagueincevolved.exe | 
"{0AA57D9F-9FC5-4339-B6AD-D02A885052BE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{0C4C936C-D547-4F53-8C0E-E9EAE9C608C5}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\dead space 3\deadspace3.exe | 
"{0D80AFD8-D439-4BD3-84F9-F84301040C80}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{0DE4D4DF-1836-4B1F-B2E5-C6FF443EDC97}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | 
"{0DE7A797-FDC5-4865-8883-E873F6400C11}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spiral knights\java_vm\bin\javaw.exe | 
"{0E6187E6-B6F0-45D7-A0A0-1DBEC86D7CCC}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\dead space 3\deadspace3.exe | 
"{13084134-5622-4F3F-9F0A-2CEA04099E10}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | 
"{1352BC57-F10E-4465-B08B-4EA7B8D2A6C4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{13AB39C2-FFDD-4709-A941-B6AC7E560EE9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization iii complete\conquests\civ3conquests.exe | 
"{17DCA85A-3806-4453-A739-AC0C2FBE9696}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\horizon\launcher.exe | 
"{18A78732-94F4-4410-BF82-8A1D8790195D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\faerie solitaire\faeriesolitaire.exe | 
"{1A2F51D2-B6CA-407C-8823-494AFA052ED6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1A6D9DAA-FB80-49F7-9433-2AEF58F6BFF4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{1B028ABB-CD73-4000-B824-1B09D82E5BD0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\orcs must die 2\build\release\orcsmustdie2.exe | 
"{1B16EFDB-5C94-4C3B-8C88-2DE5178B5C00}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe | 
"{1C39453A-A7CE-4124-90F5-20C56D76A9A6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\game dev tycoon\gamedevtycoon.exe | 
"{1C888DE1-1FFB-45BA-8112-BB33BB7ACE5B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\smashmuck champions\smashmuck.exe | 
"{1D8797FA-4E26-44F4-90BC-2E7942E4B352}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{1D8AC000-070D-41C1-B49C-21EEDB3645A4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\8bitmmo\jre\bin\javaw.exe | 
"{1D90B82E-1C6C-47B3-A816-6F348ACC62A8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\smashmuck champions\smashmuck.exe | 
"{1EF5756E-A6BF-4933-B7A9-BBAD81A7D905}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe | 
"{1F4B1852-1263-4C16-B530-D7FEF2EBE146}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\stronghold crusader extreme\stronghold crusader.exe | 
"{1F57A300-5F06-42CB-AD02-A34C7E750A7A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\superpower 2\extras\gleditor.exe | 
"{1FD6D426-2631-4B5C-9F34-124C4D3112AC}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | 
"{216D2040-B66D-44CF-8DD3-C8F7664FE471}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\age3.exe | 
"{226421A9-6373-429C-B14E-DD0ABD47E8A2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hospital tycoon\hospitaltycoon.exe | 
"{22E230AD-827A-4DE6-B632-32B97D382024}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{2592F32E-D135-48B6-9622-22BD3E208A31}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{267BA0BC-2BA4-45BE-B4BA-E9BF0EF10224}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the stanley parable\stanley.exe | 
"{274B13BE-DC52-40B5-A9E1-98AF477EF9F9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the ship single player\ship.exe | 
"{27AFF721-FF1B-4578-AEFB-83E3A20793F8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the stanley parable\stanley.exe | 
"{29EB6B79-808A-452B-89E7-5F52C55EB487}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\antichamber\binaries\win32\udk.exe | 
"{2A3F0A1B-046D-4A87-89DE-A39410AFD426}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\railworks\railworks.exe | 
"{2C70F3E9-12D3-4C20-A449-09FE4C268823}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe | 
"{2D88F765-F9C9-4485-AD6F-F04A4ACC6899}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row iv\saintsrowiv.exe | 
"{303706AE-AB1D-4892-BFDC-DFEC4BBA17C3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{3087E3D1-9A7C-45CB-85EE-69A5FC1760A6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\kerbal space program\ksp.exe | 
"{329DF6E3-E31B-4F41-AC9D-C64C6711CA5A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{32B1F888-F286-42FD-931E-E2CC1FC5BEC9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\octodad dadliest catch\octodaddadliestcatch.exe | 
"{341A93A4-4993-4FB0-AB80-A81F7624ACF4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's railroads\railroads.exe | 
"{34AEFF56-6CEE-4E15-BC98-ABACDC634C75}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star wars empire at war\runme2.exe | 
"{34C9190E-48E3-41B4-A509-4458F2067CE4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\goatsimulator\binaries\win32\goatgame-win32-shipping.exe | 
"{35868725-518F-45D2-BDAA-C8B357AE2E49}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\nortan360\garrysmod\hl2.exe | 
"{3658ED39-0ACA-4676-B988-250C36F8334F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2\hl2.exe | 
"{36FD42F9-4302-4031-A749-121B983BB765}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the ship dedicated server\srcds.exe | 
"{3788296C-9965-42E7-AEEF-6301219FF66F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{379D48A5-ED36-4924-A356-5E4D32B22869}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe | 
"{37BC0FD0-7934-4BBC-B4D9-1A7E0BB12BF9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{37CFF307-859D-42EC-8EAC-4CD05745AED5}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe | 
"{37F9C9D9-92B0-45FE-A023-35C347F9261C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{3870B74B-940B-4CB6-9E24-A254FA3D30E6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spiral knights\java_vm\bin\javaw.exe | 
"{38CC279E-64D6-4733-BA24-6529C309B288}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\bioware\star wars - the old republic\swtor\retailclient\swtor.exe | 
"{3B627297-41DD-4F1E-838B-ECCBB7D9482A}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
"{3B768E13-1528-43FB-B147-AD52CBF7CE98}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{3BA16C7B-4F40-4CDE-978B-AA7623E98A2A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dream\_rift\binaries\win32\dreamrift.exe | 
"{3E1BD9C5-FE4F-4648-89D3-7211EC8A16AA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\superpower 2\joshua.exe | 
"{414F78B6-6363-4E66-9980-552A57489E58}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spore\runme.exe | 
"{4166E2CE-55D2-4773-A49B-5142CADF3657}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spaceengineers\bin64\spaceengineers.exe | 
"{424929CF-AE1B-4606-AFAE-55E888EF308E}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\bioware\star wars - the old republic\launcher.exe | 
"{43FD6A45-6D9F-426F-8D6B-C3A1EB60365D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{464CE354-6680-4429-975C-C24B0AB167F6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
"{47D09D92-A309-4081-80FD-5D32998570C2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hospital tycoon\hospitaltycoon.exe | 
"{47E14B42-662E-4A7A-AEBA-29B5F1A9234D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe | 
"{4856D487-B89D-47F3-A40E-7D592D5E3476}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe | 
"{49169C95-461C-4B9F-BCEF-528D32D49E87}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\stronghold 2\stronghold2.exe | 
"{49717CA5-BFD3-4A6C-AD5E-5A816158C0B0}" = dir=in | app=c:\users\dan\appdata\local\microsoft\skydrive\skydrive.exe | 
"{49873D41-4AC5-462F-B7FF-3B28D1335D53}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\smashmuck champions\smashmuck.exe | 
"{4D74DEEA-1288-404A-9650-91A30F97E1C9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\nortan360\garrysmod\hl2.exe | 
"{4D815678-22ED-4B23-8599-F2C6D9E753EB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{4DBEEA5E-2D99-47B9-86B3-0A2FD59CD25E}" = protocol=6 | dir=in | app=c:\program files (x86)\gamespy arcade\aphex.exe | 
"{4E85349E-5B32-4D0F-9CAE-D420FE3E9679}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
"{4E863CAA-83A1-4219-9EC3-0466CDAA6FDE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{4F80C6E4-0413-4D94-BBC2-C7E09F9B5898}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\age of empires iii\age3.exe | 
"{5118F99D-B36C-43E9-A774-8601456F48BE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\anomaly 2\anomaly 2.exe | 
"{5192EC8E-5F4F-450B-97EA-C6C16854AEB4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\octodad dadliest catch\octodaddadliestcatch.exe | 
"{51DC6055-E2B5-442A-823F-10FA96F865C0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ftl faster than light\ftlgame.exe | 
"{56BA84DE-A7B6-441F-BFB9-38EC818E9A64}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{59F0CA19-EAFC-4567-BC4B-1A30480B87E4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\empire total war\empire.exe | 
"{5A30F4C2-3C62-4D84-BA51-87BBA36C9266}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe | 
"{5AB0D0F7-E869-4609-91E1-0A3C7106BD7E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{5AFA56CE-EAF9-4360-90F8-727CBF8126D7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\stronghold\stronghold.exe | 
"{5B1C4ED6-ACE3-48DC-A95A-337DEF835DDE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\swkotor\swkotor.exe | 
"{5B329A41-7C61-414C-9CFF-D95111FF280C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\8bitmmo\jre\bin\javaw.exe | 
"{5D56CEBD-F8A5-46B7-B3FD-B8F873362A46}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spiral knights\java_vm\bin\javaw.exe | 
"{5D63EC3F-78EF-4A95-8618-062AE13CA08B}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\bioware\star wars - the old republic\swtor\retailclient\swtor.exe | 
"{5E67E6C8-7CC6-4003-811B-E914AE8CF0E3}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
"{5EA6170A-E729-4FD6-B991-EC8C8076EA7E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\nortan360\garrysmod\hl2.exe | 
"{61A5339A-06A9-477E-9F1F-74C974F6AB0E}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\bioware\star wars - the old republic\launcher.exe | 
"{61ECC5C6-42ED-4240-89EC-EAE9D640D29B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\surgeon simulator 2013\ss2013.exe | 
"{6481915B-224E-4BBA-8F9D-ED32E444C026}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{64A581F3-A0A2-4BCA-AB24-663B6E13FC85}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\stronghold3\bin\win32_release\stronghold3.exe | 
"{64F1C856-C2B1-4570-8965-74CA5449A732}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prison architect\prison architect.exe | 
"{656A4A2C-83A9-4CE8-A5CB-275254B47A2B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star wars empire at war\runme.exe | 
"{657CFC45-A1F2-4841-8739-6F964C75F3B2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\frozen synapse\frozensynapse.exe | 
"{65B11C76-FDDF-4904-8F0C-ADBC30FDA8A1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\oblivion\oblivionlauncher.exe | 
"{673EC85D-1BD0-485A-BAB5-D5659EEA747B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the ship\ship.exe | 
"{68512355-E8B3-4BF2-A5B7-9D4120C2B2CF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\stronghold3\bin\win32_release\stronghold3.exe | 
"{69FB75D5-767B-4B75-90FD-60A94EDC38DE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row iv inauguration station\saintsrowiv_inaugurationstation.exe | 
"{6CFF80B5-1A00-43C6-B1FE-15199F28A2E3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\game dev tycoon\gamedevtycoon.exe | 
"{6DCED73D-0F0D-459F-AE2D-D11E7A8DD240}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2\hl2.exe | 
"{6E49410F-78EB-4E12-B626-E756EDE231A9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{72F6052B-8161-42BA-AC35-A7ECD85EE7F7}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | 
"{737A0FEE-C124-472C-A429-ECBD74651CF8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\planetary annihilation\pa.exe | 
"{74232BEE-6D2C-43B7-933C-8D4350D27279}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{74B85CE9-46C9-4F46-B6B9-18CCE6421A0E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\8bitmmo\jre\bin\javaw.exe | 
"{74DD9F4A-3A68-4EFB-BB98-82E9432C8AFB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{75A51793-688F-4945-A1F6-7F0F304B0C5A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\monaco\monaco.exe | 
"{761088B5-1EF9-4BB2-90FD-A20F5C7776C3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\towns\towns.exe | 
"{78B3241D-09A0-4AEE-BD66-9E4C85D43D09}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\superpower 2\video_config.exe | 
"{794EEC65-4B60-4E64-A1B5-EA364E15F8F2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\8bitmmo\jre\bin\javaw.exe | 
"{7BCFE827-F7EF-4434-8221-752FFF17EBA9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{7D0FC7BD-E1D8-4E62-972D-41F530ABD9A2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\8bitmmo\jre\bin\javaw.exe | 
"{7D846355-7A0F-40EE-A549-FDED95BE1637}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe | 
"{7E6279AB-E35F-4A9A-A597-14A521433F49}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{7E85F5CC-95C8-45F1-A849-9365D8BCCF67}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\interplanetary\interplanetary.exe | 
"{7F0A0DD8-E9BB-4742-9EC6-CCB686C0A330}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\smashmuck champions\smashmuck.exe | 
"{7FE5582B-2F94-47F9-AB8B-DC7F0BA54C96}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v\launcher.exe | 
"{80C7CDB2-16F5-420E-8D21-1A39EEE1C3B5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rainbow six vegas 2\binaries\r6vegas2_game.exe | 
"{80CA33D7-34E2-4046-827A-3E997FA28F9D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\8bitmmo\jre\bin\javaw.exe | 
"{82A793F8-E5FC-4974-A4B8-FDF13033978E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\game dev tycoon\gamedevtycoon.exe | 
"{82CC8B47-41A7-49CA-A5EF-40BCD60EB5D4}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe | 
"{82D0195D-4628-40EF-BD4F-B87A7D56093D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{839832A8-9CB5-4C80-865E-91C8896CBF4A}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\simcity\simcity\simcity.exe | 
"{858866BE-AE6B-4955-9173-51569A865DE7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\stronghold crusader extreme\stronghold_crusader_extreme.exe | 
"{86394DF0-9CDA-42F3-B987-8E79918AFB79}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{87842B8B-C35A-47EE-B37F-C49A85C14DAF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\anomaly 2\anomaly 2.exe | 
"{887C4374-C77B-4BFE-8C96-C6945FB36071}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe | 
"{8A7AC87F-97EB-43D0-AEC3-A71D83ED1B5F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spore\support\ea help\electronic_arts_technical_support.htm | 
"{8E752F74-F332-4AFE-869C-187FE43E246A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v\launcher.exe | 
"{8E957C36-4D37-45B5-9581-28C9079CC0F6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{8F2BD73C-4028-4B1E-9DBC-5DB0F8D3C8AC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\goatsimulator\binaries\win32\goatgame-win32-shipping.exe | 
"{8FFBCC60-9A55-4A4B-AD55-F18168B89076}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\age of empires online\aoeonline.exe | 
"{92441759-3451-4BDF-B572-BAB9A685896B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\towns\towns.exe | 
"{92B22E32-5F77-4E43-B610-1151456B78D6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{940180B4-2D22-45E4-9EA6-0E0410F77B63}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{95DEE150-A722-40BD-99A2-B63E022E461A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{96FE9EB5-D917-47BA-A7F3-985A3E6776B2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\superpower 2\video_config.exe | 
"{9759182E-9B00-4663-B3BA-6FAF6A5F42F9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\kerbal space program\ksp.exe | 
"{988673CA-268A-4613-A699-50EC5A9259DB}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\simcity\simcity\simcity.exe | 
"{98868516-953C-4903-94CB-6652FFA3343C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prison architect\prison architect.exe | 
"{989DE62B-607A-440C-839D-825B54730E92}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{9A12E871-4C20-4C04-93A6-5B0C245036B4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\surgeon simulator 2013\ss2013.exe | 
"{9B3799E7-7610-465D-A92D-217CE50D7911}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\faerie solitaire\faeriesolitaire.exe | 
"{9B888CB8-0B4C-4DFD-8504-07F89FF45833}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\orcs must die 2\build\release\orcsmustdie2.exe | 
"{9D9789F1-A30F-4873-8750-471F8E3B364A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spore\runme.exe | 
"{9ECB6030-4E67-4A9B-B7D0-E62590C3827B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\game dev tycoon\gamedevtycoon.exe | 
"{9EEA6BD6-BBFC-4AD7-A674-B17B8939CE81}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\horizon\launcher.exe | 
"{9F0B5F3A-42E6-4558-AD78-9EA774B8C316}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spore\support\ea help\electronic_arts_technical_support.htm | 
"{9F37EA0E-0065-4EF5-977C-FE325639DE05}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\bioware\star wars - the old republic\launcher.exe | 
"{9F687404-A104-4A08-915A-FA5004D36383}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\planetary annihilation\pa.exe | 
"{A3458FEA-0279-4FFF-B0F1-19BB28BD04E5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\superpower 2\extras\gleditor.exe | 
"{A3DFDAE5-2162-473C-8BFE-237BF86A2228}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2\hl2.exe | 
"{A41AE3E3-89F0-4220-9484-6AE7EE0368D0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's railroads\railroads.exe | 
"{A80CA8AB-E366-4A9A-9937-6BF8B88475F1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2\hl2.exe | 
"{A9088FAC-B1A4-4A0B-8A9D-7221995A1544}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prison architect\prison architect.exe | 
"{ABF769BE-B2B3-466F-B5CE-6A8811B3DBCE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\age of empires online\aoeonline.exe | 
"{AC2F61EC-46E2-468D-9AD8-3219F03A5ACE}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\bioware\star wars - the old republic\swtor\retailclient\swtor.exe | 
"{AC3D37A9-3BCE-4125-9D9F-E7A1E618C682}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\interplanetary\interplanetary.exe | 
"{AD995323-C2F0-4C31-90A6-28B9F2908A83}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe | 
"{AFEFFC41-37D3-4F96-9419-2E37E6E8F4A6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spiral knights\java_vm\bin\javaw.exe | 
"{B12EAC39-2203-4417-B0FF-38A40884AD29}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\monaco\monaco.exe | 
"{B22EBAC0-9657-4853-AA15-5395CC06FCDD}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | 
"{B28505A7-F55A-4564-8F05-06B90AD0CB7A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\superpower 2\joshua.exe | 
"{B54C3887-B60B-4EF8-86DE-35A3C87F5F5C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dream\binaries\win32\dream.exe | 
"{B5E475DF-C2B3-4C8E-BD66-C1F150A6F4F3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\stronghold legends\strongholdlegends.exe | 
"{B638C61A-5732-4C58-B730-5DDCFA6132C4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\prison architect\prison architect.exe | 
"{B693F4AF-B41D-42B2-A7F4-6746F526092E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\antichamber\binaries\win32\udk.exe | 
"{B6C9958C-4094-4848-AAB4-8C72679C02C2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{B777B1BF-5628-4A2E-8F8E-45AA212CA332}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ftl faster than light\ftlgame.exe | 
"{B8E8C830-A484-4E3F-9BAC-215837E107FF}" = protocol=17 | dir=in | app=c:\program files (x86)\gamespy arcade\aphex.exe | 
"{BE2D0283-B086-46FD-BD43-FC54AFC95633}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe | 
"{BFD4576D-E32D-414D-B1A8-A97C38A0EFF0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the ship dedicated server\srcds.exe | 
"{C0C02B9B-C160-461D-9148-938B3C5C1998}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\8bitmmo\jre\bin\javaw.exe | 
"{C22B7F9A-9DE5-4411-B687-331DC44ACF4C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\grand theft auto iv\gtaiv\launchgtaiv.exe | 
"{C32F3545-1EE1-4DC3-AA1C-567DE6FCB717}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{C52BACFF-F94C-4729-9F5D-8EB38B435C62}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2\hl2.exe | 
"{C61A6654-B926-4C6C-8967-7E6950CA376B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the ship\ship.exe | 
"{C705031F-774A-40E0-98F9-406DB959E16D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\frozen synapse\frozensynapse.exe | 
"{C8217F4D-C5A9-41C6-9FCF-BC5133EAF0A2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2\hl2.exe | 
"{C960899F-983D-4B1D-AB03-A894091A2BF1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{CB32E9E5-FF9F-4A28-B33B-43A2CD154526}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | 
"{CDBDB1ED-ABAB-4054-9049-DF4B5F366363}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spiral knights\java_vm\bin\javaw.exe | 
"{CE9CA799-02CC-4E40-B861-DA70BD06FA91}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\papersplease\papersplease.exe | 
"{D09095E7-6C2B-41D5-9C4A-D453B36A7294}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dream\binaries\win32\dream.exe | 
"{D11F55E2-77FF-4476-BF37-17D137D03AAC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row iv inauguration station\saintsrowiv_inaugurationstation.exe | 
"{D37A1B21-368E-4BED-B11E-3AE81B8E035D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\empire total war\empire.exe | 
"{D4BBBD04-D0CD-466F-A9EA-D1189A2564DC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2\hl2.exe | 
"{D61D37F0-CFD0-4772-B3D2-CFDE5D77B588}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\swkotor\swkotor.exe | 
"{D92A4133-F6A5-4ADF-A969-F83DB1F6094F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spaceengineers\bin64\spaceengineers.exe | 
"{D97D9DC3-2FBC-43B3-9A52-ECED64C0529B}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | 
"{DA2D532D-DBA9-448F-90E2-53A26B8382E0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 test\dota.exe | 
"{DA6FF357-CE06-49E0-9E4C-9B01C5D2007B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\plagueinc\plagueincevolved.exe | 
"{DAD135AC-1947-4B6C-ADE0-FEF28B9DCBD3}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | 
"{DB8F516A-6C5C-449A-83DD-B6F10250664D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\stronghold 2\stronghold2.exe | 
"{DDAA60D7-6D46-4903-99E4-AACDB0201FCE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\8bitmmo\jre\bin\javaw.exe | 
"{DE44B49C-3A11-4043-8E3F-EA61859A4773}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{DEA76B44-63A1-4190-9224-B7B1445CD8EE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{DED1C9B2-E7BE-44D6-BDED-533C6EFDB58A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\oblivion\oblivionlauncher.exe | 
"{E0BA74CB-057C-49C6-95C4-11364184038A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spiral knights\java_vm\bin\javaw.exe | 
"{E17029D2-86DE-4A02-B058-9F41A2B20176}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\nortan360\garrysmod\hl2.exe | 
"{E3FC0236-334E-4D80-A7C9-48CE07AE484A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dream\_rift\binaries\win32\dreamrift.exe | 
"{E448FF81-B06C-4A1D-8D16-3DF6CCE71FF6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\railworks\railworks.exe | 
"{E5F748B7-CFD6-463B-81CE-823A44C9F67C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\skyrim\skyrimlauncher.exe | 
"{E6EBC1DB-D5EC-4B38-B2DC-19A3C591AED0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\saints row iv\saintsrowiv.exe | 
"{E807C978-09E3-4F2D-A768-96FECF5A8A2F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\papersplease\papersplease.exe | 
"{EC43E6A0-75D4-42A6-BDB4-57B24E0A9380}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\stronghold legends\strongholdlegends.exe | 
"{ECFD6AAE-CBE4-491B-8135-DBEA182F8B06}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | 
"{EE1D269F-4DF5-4869-9CE2-99FA4A104646}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spiral knights\java_vm\bin\javaw.exe | 
"{EE632184-59AB-4358-9588-6030B1F8E5D2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization iii complete\conquests\civ3conquests.exe | 
"{EE9CF3D9-FDA2-46F3-A1EE-A9ACE1FA79FB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2\hl2.exe | 
"{EF129953-A23C-489A-BF37-F3BF1C46B3AC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star wars empire at war\runme2.exe | 
"{F22B80CF-8005-4E89-932E-969BB1E85011}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | 
"{F3CE1815-8A19-4B9E-B74C-BB0A94A592D1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star wars battlefront ii\gamedata\battlefrontii.exe | 
"{F5CEBCE1-406D-4C54-8401-9C030F4A5B8F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the ship single player\ship.exe | 
"{FAE404D0-AABC-4509-991E-331A3EB873C3}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\bioware\star wars - the old republic\swtor\retailclient\swtor.exe | 
"{FBEFEB6D-6F72-445C-A2C9-84705644CFA3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star wars battlefront ii\gamedata\battlefrontii.exe | 
"{FBF1F396-31EE-47D5-8BD4-A98CBD975AE3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{FCBF059E-4FBD-48FA-AB9A-876F526B5549}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\stronghold crusader extreme\stronghold_crusader_extreme.exe | 
"{FF837AA2-7008-4AF5-B919-3072AEC376E0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{FFADE687-68FA-4063-9A24-A3ADE5EC5605}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\stronghold\stronghold.exe | 
"TCP Query User{0054A27F-EF1F-4B04-82EE-1E0CACB204D3}C:\users\dan\appdata\local\microsoft\age of empires online\spartan.exe" = protocol=6 | dir=in | app=c:\users\dan\appdata\local\microsoft\age of empires online\spartan.exe | 
"TCP Query User{19BD221E-B153-4C84-A292-BEF828B0ABAD}C:\program files (x86)\steam\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe | 
"TCP Query User{3F6C64C9-02F5-4EC6-AA62-ECC501B3FCE1}C:\program files (x86)\steam\steamapps\nortan360\the ship\ship.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\nortan360\the ship\ship.exe | 
"TCP Query User{42A8C505-EE84-415A-A397-89C4B0888F51}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | 
"TCP Query User{45836664-9D4A-462E-B13C-EF4BA5A25B86}C:\program files (x86)\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files (x86)\real\realplayer\realplay.exe | 
"TCP Query User{4F82835C-EF24-4BD5-8CF0-8F510891B6AD}C:\program files (x86)\fahclient\fahclient.exe" = protocol=6 | dir=in | app=c:\program files (x86)\fahclient\fahclient.exe | 
"TCP Query User{57DD6413-C887-4EB2-8A40-49B72C2803E8}C:\program files (x86)\steam\steamapps\common\orcs must die 2\build\game\orcsmustdie2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\orcs must die 2\build\game\orcsmustdie2.exe | 
"TCP Query User{665876B9-F394-4319-8B78-6328274A0BDA}C:\program files (x86)\java\jdk1.7.0_11\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jdk1.7.0_11\bin\java.exe | 
"TCP Query User{692E9126-3454-4366-BA95-4CE4366AA407}C:\program files (x86)\steam\steamapps\nortan360\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\nortan360\team fortress 2\hl2.exe | 
"TCP Query User{701504EB-9116-4358-A380-4466C9D07788}C:\program files (x86)\steam\steamapps\common\star wars empire at war\corruption\swfoc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star wars empire at war\corruption\swfoc.exe | 
"TCP Query User{7AF1EB18-A7F9-4AAA-B34A-5143C189ED11}C:\program files (x86)\pc remote\pc remote\pcremote.exe" = protocol=6 | dir=in | app=c:\program files (x86)\pc remote\pc remote\pcremote.exe | 
"TCP Query User{806F0857-02A1-480C-9203-A43B5ACFA08F}C:\program files (x86)\java\jre7\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe | 
"TCP Query User{C38746D9-42F7-45FF-B1D7-520D3C1DE99C}C:\program files (x86)\steam\steamapps\common\signs of life\signs of life.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\signs of life\signs of life.exe | 
"TCP Query User{D321B914-740D-4371-B63D-C50EFFCE3F40}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe | 
"TCP Query User{DCFA989C-51B5-4446-8F46-818909225276}C:\program files (x86)\fahclient\fahclient.exe" = protocol=6 | dir=in | app=c:\program files (x86)\fahclient\fahclient.exe | 
"TCP Query User{E7A21096-C1FB-4D47-A151-C55DB4D9779F}C:\program files (x86)\steam\steamapps\common\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2\hl2.exe | 
"TCP Query User{F4178C20-5784-4683-B420-0D5D0B170B39}C:\hlserver\orangebox\srcds.exe" = protocol=6 | dir=in | app=c:\hlserver\orangebox\srcds.exe | 
"TCP Query User{FD57065A-3CAB-4ECC-8D64-7913F971C003}C:\program files (x86)\steam\steamapps\common\age of empires online\spartan.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\age of empires online\spartan.exe | 
"TCP Query User{FE5CE6AD-E3B5-4BD9-921A-614BCD063422}C:\program files (x86)\steam\steam.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
"UDP Query User{049CC518-40BB-462C-A648-4E6CED74BD5C}C:\program files (x86)\fahclient\fahclient.exe" = protocol=17 | dir=in | app=c:\program files (x86)\fahclient\fahclient.exe | 
"UDP Query User{08C6E122-57DE-4EFA-A0A0-10EEB51CE3BB}C:\program files (x86)\steam\steamapps\common\signs of life\signs of life.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\signs of life\signs of life.exe | 
"UDP Query User{17ACB785-D6B2-4EBE-9688-AA1639D94A26}C:\users\dan\appdata\local\microsoft\age of empires online\spartan.exe" = protocol=17 | dir=in | app=c:\users\dan\appdata\local\microsoft\age of empires online\spartan.exe | 
"UDP Query User{27728A69-8884-41DD-812E-E31901FDC3F3}C:\program files (x86)\steam\steamapps\nortan360\the ship\ship.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\nortan360\the ship\ship.exe | 
"UDP Query User{31EF1E9E-F473-4ABB-9B25-20B8A38A89ED}C:\program files (x86)\steam\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe | 
"UDP Query User{33228A5E-1811-4C24-B5DA-E50AD197D389}C:\program files (x86)\steam\steam.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
"UDP Query User{425E47BB-51D4-4B94-A7CD-1A7B893B35EA}C:\program files (x86)\fahclient\fahclient.exe" = protocol=17 | dir=in | app=c:\program files (x86)\fahclient\fahclient.exe | 
"UDP Query User{777B30FE-06EF-4298-8523-A82FF9404355}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | 
"UDP Query User{7F121C1B-3C05-450F-96B6-F88DAE92EE70}C:\program files (x86)\java\jdk1.7.0_11\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jdk1.7.0_11\bin\java.exe | 
"UDP Query User{88F85F5B-DC71-4201-BCF5-198C50EA5BC4}C:\hlserver\orangebox\srcds.exe" = protocol=17 | dir=in | app=c:\hlserver\orangebox\srcds.exe | 
"UDP Query User{99AD3048-52B2-42AC-8EA1-4409DBC5A17D}C:\program files (x86)\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files (x86)\real\realplayer\realplay.exe | 
"UDP Query User{A204804A-A812-4679-AECA-5BE063F5AE35}C:\program files (x86)\pc remote\pc remote\pcremote.exe" = protocol=17 | dir=in | app=c:\program files (x86)\pc remote\pc remote\pcremote.exe | 
"UDP Query User{AA5A1D5D-759B-4507-9ECD-C386C21200B0}C:\program files (x86)\steam\steamapps\common\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2\hl2.exe | 
"UDP Query User{AB5746EC-1584-4F80-B7BD-338677FE2440}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe | 
"UDP Query User{C2976B4C-CDAD-4E4E-9119-ABAAE585F473}C:\program files (x86)\java\jre7\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\java.exe | 
"UDP Query User{C4EF5BA7-E1AA-4FD5-9366-E5061DB3D73E}C:\program files (x86)\steam\steamapps\nortan360\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\nortan360\team fortress 2\hl2.exe | 
"UDP Query User{F3210D63-21DB-4358-A0B1-7D6DAA43FAC2}C:\program files (x86)\steam\steamapps\common\age of empires online\spartan.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\age of empires online\spartan.exe | 
"UDP Query User{F4BA330C-1BDF-4F25-8A03-BECB5305B418}C:\program files (x86)\steam\steamapps\common\orcs must die 2\build\game\orcsmustdie2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\orcs must die 2\build\game\orcsmustdie2.exe | 
"UDP Query User{FB7131DF-EFD2-4B0E-9747-0F8655FD3B41}C:\program files (x86)\steam\steamapps\common\star wars empire at war\corruption\swfoc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star wars empire at war\corruption\swfoc.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{09536BA1-E498-4CC3-B834-D884A67D7E34}" = Intel® Trusted Connect Service Client
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5400_series" = Canon MG5400 series MP Drivers
"{1374CC63-B520-4f3f-98E8-E9020BF01CFF}" = Windows XP Mode
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{24F93B56-61F5-415F-85B9-AA444DA34AFC}" = Microsoft Mouse and Keyboard Center
"{2C486987-D447-4E36-8D61-86E48E24199C}" = TOSHIBA eco Utility
"{2EDC2FA3-1F34-34E5-9085-588C9EFD1CC6}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610
"{3007FF9F-5B2C-41FF-8BFC-08BF25DB2681}" = Premium Sound HD
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6150345A-1382-4713-B38B-482388DC7E7B}" = MySQL Server 5.5
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}" = PaperPort Image Printer 64-bit
"{764384C5-BCA9-307C-9AAC-FD443662686A}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610
"{787136D2-F0F8-4625-AA3F-72D7795AC842}" = Apple Mobile Device Support
"{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1
"{81E20D41-C277-4526-934D-F2380AF91B78}" = iCloud
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{90150000-008F-0000-1000-0000000FF1CE}" = Office 15 Click-to-Run Licensing Component
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}" = TOSHIBA PC Health Monitor
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B8BA155B-1E75-405F-9CB4-8A99615D09DC}" = iTunes
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{D600D357-5CB9-4DE9-8FD4-14E208BD1970}" = Nero Backup Drivers
"Bullzip PDF Printer_is1" = Bullzip PDF Printer 9.3.0.1516
"EA90D42054890B3938D0BEF1E8A316D20C6D6003" = Windows Driver Package - Realtek Semiconductor Corp. RtkBtFilter Bluetooth  (12/02/2011 2.3.8.1)
"Microsoft Mouse and Keyboard Center" = Microsoft Mouse and Keyboard Center
"O365HomePremRetail - en-us" = Microsoft Office 365 - en-us
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"UDK-08caf252-36af-4c61-8543-dfbe6f351002" = My Game Long Name
"UDK-3531519b-ca54-4c4e-8864-5ac89628ba53" = My Game Long Name
"WinRAR archiver" = WinRAR 4.20 (64-bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01E9B2FF-DAF4-4529-9CC9-2101625517C7}" = nero.prerequisites.msi
"{034DCAF9-96E7-4936-9A07-712F80B5181E}" = Nero RescueAgent 11
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}" = Scansoft PDF Professional
"{07035AB3-5C70-3315-35A9-CFFECA140880}" = BBC iPlayer Desktop
"{09B7C7EB-3140-4B5E-842F-9C79A7137139}" = Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger
"{119826A8-4EF6-4BE5-A88B-D2D81FA7CEE2}" = TOSHIBA Supervisor Password
"{11D3EF85-63E1-4AE4-A7C1-9241BDB16B51}" = Nero ControlCenter 11
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{216DF734-6004-42C7-AFC9-A81DFD344BA8}" = Nero BurnRights 11
"{2290A680-4083-410A-ADCC-7092C67FC052}" = TOSHIBA Online Product Information
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{236FF571-7197-40E9-921D-D5FDC752C697}" = MySQL Installer
"{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel® USB 3.0 eXtensible Host Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F83216039FF}" = Java™ 6 Update 39
"{26A24AE4-039D-4CA4-87B4-2F83217009F0}" = Java 7 Update 9
"{26A24AE4-039D-4CA4-87B4-2F83217045FF}" = Java 7 Update 55
"{28656860-4728-433C-8AD4-D1A930437BC8}" = Nuance PDF Viewer Plus
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{2FD5D2C5-A7A1-4065-89BA-90542BF7CCD3}" = TOSHIBA Hardware Setup
"{32A3A4F4-B792-11D6-A78A-00B0D0170100}" = Java SE Development Kit 7 Update 10
"{32A3A4F4-B792-11D6-A78A-00B0D0170110}" = Java SE Development Kit 7 Update 11
"{376D59B1-42D9-4FA2-B6CC-E346B6BE14F5}" = ActiveX-kontroll för fjärranslutningar för Windows Live Mesh
"{3B11D799-48E0-48ED-BFD7-EA655676D8BB}" = Star Wars: The Old Republic
"{3D6AD258-61EA-35F5-812C-B7A02152996E}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX
"{461F6F0D-7173-4902-9604-AB1A29108AF2}" = TOSHIBA Places Icon Utility
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4CF6F287-5121-483C-A5A2-07BDE19D8B4E}" = Windows Live Meshin etäyhteyksien ActiveX-komponentti
"{4D2122D0-66F7-4A53-96FC-079C900B1CAF}" = Nero BurnRights 11 Help (CHM)
"{4D530FA3-9B89-4186-98B7-F51000008100}" = Age of Empires Online
"{57220148-3B2B-412A-A2E0-82B9DF423696}" = Windows Live Mesh ActiveX-objekt til fjernforbindelser
"{5A212B2D-140D-46F4-B625-2D1CA5A00594}" = Nero 11 Kwik Themes Basic
"{5AF4B3C4-C393-48D7-AC7E-8E7615579548}" = Adobe AIR
"{5CDB70CD-C4F4-4A2F-A676-36F4C8FAE377}" = PC Remote
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{65A5E87D-7A3F-4819-807D-B86990D5F369}" = inSSIDer
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{6AB2427E-A18F-4809-9A12-29F5EBABBB3A}" = Nero BackItUp 11 Help (CHM)
"{6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94}" = TOSHIBA Resolution+ Plug-in for Windows Media Player
"{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}" = TOSHIBA Web Camera Application
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-toshiba" = WildTangent Games App (Toshiba Games)
"{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TOSHIBA Recovery Media Creator Reminder
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.14
"{8220FCF2-A57F-4236-BFCC-C6C2268E851E}" = RtkClassFilter
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{88B5FBDC-967D-4B1F-B291-39284AE12201}" = Nuance PaperPort 12
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{90150000-008C-0000-0000-0000000FF1CE}" = Office 15 Click-to-Run Extensibility Component
"{90150000-008C-0409-0000-0000000FF1CE}" = Office 15 Click-to-Run Localization Component
"{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}" = Toshiba Manuals
"{9193490D-5229-4FC4-9BB9-A6D63C09574A}" = High-Definition Video Playback
"{95140000-00AF-0409-0000-0000000FF1CE}" = Microsoft PowerPoint Viewer
"{95716cce-fc71-413f-8ad5-56c2892d4b3a}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D3D8C60-A55F-4fed-B2B9-173001290E16}" = Realtek WLAN Driver
"{a1909659-0a08-4554-8af1-2175904903a1}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610
"{A6C48A9F-694A-4234-B3AA-62590B668927}" = Intel® Manageability Engine Firmware Recovery Agent
"{A7E19604-93AF-4611-8C9F-CE509C2B286F}_is1" = Free YouTube Downloader 3.5.134
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}" = Apple Application Support
"{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime
"{AB2BBC64-8AC8-4E66-BBF3-E22D5EACEECA}" = Nero BackItUp 11
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station
"{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.8) MUI
"{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}" = RealDownloader
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Media Creator
"{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime
"{B9B1BA7F-7E07-49DD-A713-5B397A5BB66B}" = Nero Kwik Media Help (CHM)
"{BB285C9F-C821-4770-8970-56C4AB52C87E}" = Skype Click to Call
"{BE814218-3919-4EA3-868A-2F60BC135CB4}" = Nero Kwik Media
"{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}" = Nero Core Components 11
"{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}" = TOSHIBA Assist
"{C7A4F26F-F9B0-41B2-8659-99181108CDE3}" = TOSHIBA Media Controller
"{CCE210DF-7EEF-4A76-A63C-3EB091FDB992}" = welcome
"{D01CE99A-8802-483C-A79F-298B691EB432}" = Nero RescueAgent 11 Help (CHM)
"{D2CBEFA4-F2D3-4E97-A171-8BFD6A31A5EC}" = Nero Express 11 Help (CHM)
"{D4329609-4102-4F8C-B83F-7FE024EEA314}" = Dead Space™ 3
"{D4D66270-9147-4BDF-9946-FCA2B303AA8F}" = Nero ControlCenter 11 Help (CHM)
"{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}" = Microsoft XNA Framework Redistributable 4.0 Refresh
"{DD98C438-D769-4677-AA87-3481FA32D20C}" = Brother MFL-Pro Suite DCP-J4110DW
"{E10AAE4A-98B8-420A-BD93-E0520C23D624}" = Nero Express 11
"{E7D4E834-93EB-351F-B8FB-82CDAE623003}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610
"{F082CB11-4794-4259-99A1-D91BA762AD15}" = TOSHIBA TEMPRO
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F26FDF57-483E-42C8-A9C9-EEE1EDB256E0}" = TOSHIBA Media Controller Plug-in
"{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}" = SimCity™
"{F8635CF8-B797-4EFD-80BC-DE2D26C65D4F}" = Nero 11 Essentials
"{FAE99C85-0732-4C58-9C6B-10B5B12FA2E9}" = RuneScape Launcher 1.2.3
"{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel® OpenCL CPU Runtime
"{FF0815E9-0ECC-48B5-AF2C-47F3601CEC2E}" = MySQL Workbench 5.2 CE
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 13 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 13 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 12.0
"avast" = avast! Free Antivirus
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"Batch Picture Resizer_is1" = Batch Picture Resizer 5.1
"BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1" = BBC iPlayer Desktop
"Blueline_is1" = Blueline 1.1.1
"Canon MG5400 series On-screen Manual" = Canon MG5400 series On-screen Manual
"Canon MG5400 series User Registration" = Canon MG5400 series User Registration
"Canon My Image Garden" = Canon My Image Garden
"Canon My Image Garden Design Files" = Canon My Image Garden Design Files
"Canon_IJ_Network_Scanner_Selector_EX" = Canon IJ Network Scanner Selector EX
"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool
"Canon_IJ_Scan_Utility" = Canon IJ Scan Utility
"CANONIJPLM100" = Canon Inkjet Printer/Scanner/Fax Extended Survey Program
"CanonMyPrinter" = Canon My Printer
"CanonQuickMenu" = Canon Quick Menu
"Cheat Engine 6.2_is1" = Cheat Engine 6.2
"Cheat Engine 6.3_is1" = Cheat Engine 6.3
"CorsixTH" = CorsixTH 0.30
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"ESET Online Scanner" = ESET Online Scanner v3
"FAHClient" = FAHClient
"GameSpy Arcade" = GameSpy Arcade
"GFWL_{4D530FA3-9B89-4186-98B7-F51000008100}" = Age of Empires Online
"Google Chrome" = Google Chrome
"Half-Life Dedicated Server Update Tool" = Half-Life Dedicated Server Update Tool
"HijackThis" = HijackThis 2.0.2
"InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"InstallShield_{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}" = TOSHIBA Web Camera Application
"InstallShield_{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III
"InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TOSHIBA Recovery Media Creator Reminder
"InstallShield_{8220FCF2-A57F-4236-BFCC-C6C2268E851E}" = RtkClassFilter
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"ManyCam" = ManyCam 3.1.57
"nbi-glassfish-mod-3.0.1.22.0" = GlassFish Server Open Source Edition 3.0.1
"nbi-nb-base-6.9.1.0.0" = NetBeans IDE 6.9.1
"nbi-nb-base-7.2.1.0.201210100934" = NetBeans IDE 7.2.1
"Notepad++" = Notepad++
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"OpenAL" = OpenAL
"Origin" = Origin
"pcsx2-r4600" = PCSX2 - Playstation 2 Emulator
"Pocket Tanks_is1" = Pocket Tanks v1.6
"PrimoPDF" = PrimoPDF -- brought to you by Nitro PDF Software
"PunkBusterSvc" = PunkBuster Services
"RealPlayer 16.0" = RealPlayer
"ShortKeys 3" = ShortKeys 3
"ShortKeys Lite" = ShortKeys Lite
"Steam App 10500" = Empire: Total War
"Steam App 105430" = Age of Empires Online
"Steam App 113020" = Monaco
"Steam App 11590" = Hospital Tycoon
"Steam App 12210" = Grand Theft Auto IV
"Steam App 15120" = Tom Clancy's Rainbow Six: Vegas 2
"Steam App 17390" = Spore
"Steam App 201790" = Orcs Must Die! 2
"Steam App 205790" = Dota 2 Test
"Steam App 206420" = Saints Row IV
"Steam App 212680" = FTL: Faster Than Light
"Steam App 213231" = Borderlands 2: Premiere Club
"Steam App 218330" = Smashmuck Champions
"Steam App 219890" = Antichamber
"Steam App 220200" = Kerbal Space Program
"Steam App 221020" = Towns
"Steam App 221910" = The Stanley Parable
"Steam App 22330" = The Elder Scrolls IV: Oblivion 
"Steam App 224480" = Octodad: Dadliest Catch
"Steam App 229580" = Dream
"Steam App 233250" = Planetary Annihilation
"Steam App 233450" = Prison Architect
"Steam App 233470" = Evoland
"Steam App 233720" = Surgeon Simulator 2013
"Steam App 236130" = Horizon
"Steam App 236730" = Anomaly 2
"Steam App 239030" = Papers, Please
"Steam App 239820" = Game Dev Tycoon
"Steam App 2400" = The Ship
"Steam App 24010" = Train Simulator 2013
"Steam App 2403" = The Ship Dedicated Server
"Steam App 2420" = The Ship Single Player
"Steam App 242590" = Saints Row IV Inauguration Station
"Steam App 2430" = The Ship Tutorial
"Steam App 244850" = Space Engineers
"Steam App 246620" = Plague Inc: Evolved
"Steam App 250420" = 8BitMMO
"Steam App 263200" = Signs of Life
"Steam App 265930" = Goat Simulator
"Steam App 278910" = Interplanetary
"Steam App 282400" = SuperPower 2 Steam Edition
"Steam App 32370" = Star Wars: Knights of the Old Republic
"Steam App 32470" = Star Wars: Empire at War Gold
"Steam App 38600" = Faerie Solitaire
"Steam App 3910" = Sid Meier's Civilization III: Complete
"Steam App 4000" = Garry's Mod
"Steam App 40950" = Stronghold
"Steam App 40960" = Stronghold 2
"Steam App 40970" = Stronghold Crusader + Extreme
"Steam App 40980" = Stronghold Legends
"Steam App 440" = Team Fortress 2
"Steam App 47400" = Stronghold 3
"Steam App 49520" = Borderlands 2
"Steam App 570" = Dota 2
"Steam App 6060" = Star Wars - Battlefront II
"Steam App 72850" = The Elder Scrolls V: Skyrim
"Steam App 7600" = Sid Meier's Railroads!
"Steam App 8930" = Sid Meier's Civilization V
"Steam App 98200" = Frozen Synapse
"Steam App 99900" = Spiral Knights
"TeamViewer 8" = TeamViewer 8
"Theme Park World" = Theme Park World
"Tropico3" = Tropico 3: Absolute Power
"VTFEdit_is1" = VTFEdit 1.2.5
"WildTangent toshiba Master Uninstall" = WildTangent Games
"World of Warcraft" = World of Warcraft
"WTA-0f92a45a-0d72-4bdb-b56d-80fa63955900" = Plants vs. Zombies - Game of the Year
"WTA-13108051-f90b-4f62-baf0-0bdac8785511" = Polar Bowler
"WTA-42e5c9cc-9d31-460b-ba04-79cf9be5be59" = Mystery P.I. - The London Caper
"WTA-44d2d6ab-8ae0-48c0-b4b6-6632bba19e0b" = Virtual Villagers 4 - The Tree of Life
"WTA-5929a798-9dc7-47ab-b719-0453bf4c0154" = Agatha Christie - Death on the Nile
"WTA-6858590f-3950-47fb-b5de-7553842dc548" = Aloha TriPeaks
"WTA-8c3100a8-799b-4622-8026-c9a0b85f0847" = Jewel Quest Solitaire 2
"WTA-99bd473c-04ba-4f79-a917-eadd9eb35cd7" = Cake Mania
"WTA-9a0522b5-1bcb-41ba-858b-74cf4991120a" = Bejeweled 3
"WTA-e3fd4493-83c6-448f-a175-9cce817318d5" = Chuzzle Deluxe
"WTA-e74822f9-c9e1-4dac-955a-5b6d34e5c470" = Insaniquarium Deluxe
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{2922D6F1-2865-4EFA-97A9-94EEAB3AFA14}" = ROBLOX Studio 2013 for Dan
"{373B1718-8CC5-4567-8EE2-9033AD08A680}" = ROBLOX Player for Dan
"MusicManager" = Music Manager
"OneDriveSetup.exe" = Microsoft OneDrive
"UnityWebPlayer" = Unity Web Player
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 05/05/2014 19:12:23 | Computer Name = Bismillah | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 17
 
Error - 05/05/2014 19:12:23 | Computer Name = Bismillah | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 18
 
Error - 05/05/2014 19:12:23 | Computer Name = Bismillah | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 19
 
Error - 05/05/2014 19:12:23 | Computer Name = Bismillah | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 20
 
Error - 05/05/2014 19:12:23 | Computer Name = Bismillah | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 21
 
Error - 05/05/2014 19:12:23 | Computer Name = Bismillah | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 22
 
Error - 05/05/2014 19:12:23 | Computer Name = Bismillah | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 23
 
Error - 05/05/2014 19:12:23 | Computer Name = Bismillah | Source = Bonjour Service | ID = 100
Description = ERROR: handle_resolve_request bad interfaceIndex 24
 
Error - 06/05/2014 06:28:45 | Computer Name = Bismillah | Source = WinMgmt | ID = 10
Description = 
 
Error - 06/05/2014 08:35:28 | Computer Name = Bismillah | Source = WinMgmt | ID = 10
Description = 
 
[ System Events ]
Error - 03/05/2014 13:35:48 | Computer Name = Bismillah | Source = Service Control Manager | ID = 7022
Description = The Windows Update service hung on starting.
 
Error - 03/05/2014 19:36:06 | Computer Name = Bismillah | Source = DCOM | ID = 10010
Description = 
 
Error - 03/05/2014 19:36:36 | Computer Name = Bismillah | Source = DCOM | ID = 10010
Description = 
 
Error - 04/05/2014 13:48:18 | Computer Name = Bismillah | Source = DCOM | ID = 10010
Description = 
 
Error - 04/05/2014 13:50:50 | Computer Name = Bismillah | Source = Service Control Manager | ID = 7022
Description = The Windows Update service hung on starting.
 
Error - 05/05/2014 09:42:18 | Computer Name = Bismillah | Source = EventLog | ID = 6008
Description = The previous system shutdown at 01:20:21 on ?05/?05/?2014 was unexpected.
 
Error - 05/05/2014 09:47:04 | Computer Name = Bismillah | Source = DCOM | ID = 10010
Description = 
 
Error - 06/05/2014 06:28:05 | Computer Name = Bismillah | Source = EventLog | ID = 6008
Description = The previous system shutdown at 00:34:13 on ?06/?05/?2014 was unexpected.
 
Error - 06/05/2014 06:32:10 | Computer Name = Bismillah | Source = DCOM | ID = 10010
Description = 
 
Error - 06/05/2014 08:41:53 | Computer Name = Bismillah | Source = Service Control Manager | ID = 7022
Description = The Windows Update service hung on starting.
 
 
< End of report >
 

  • 0

#4
Machiavelli

Machiavelli

    GeekU Moderator

  • GeekU Moderator
  • 3,698 posts
Hey,

O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. - Why is it locked?

Very good question. I'm myself not 100% sure being honest :/

O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
I think Locked may be the name of the toolbar - it points to no CLSID so there is a "No CLSID value found"

I made a RegExport of that key on my computer:
 
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}"="avast! Online Security"
"Locked"=""
The OTL Results:
 
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (avast! Online Security) - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Programme\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
OK, look back to my first Registry Export, do you know how OTL knows which file points to that CLSID? Hint: There is another registry key where OTL looks at.

Don't worry, if you don't know, you will learn this in Upperclass. But maybe you know it.

You can do a RegExport and show me what the content of that key is. Then we have clarification. Do this before the OTL Fix because we will delete that entry with OTL since it is an orphaned entry and may be created by Malware.
 

[2014/04/20 22:31:56 | 000,000,000 | ---D | C] -- C:\Users\Dan\AppData\Local\ElevatedDiagnostics - This is a fraudulent Security program

Nope, please research again and tell me what it is. :) A simple Google search helped me.

 
 

[2013/08/08 22:57:05 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\3909
[2013/04/24 19:08:34 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\3909 LLC

Do you know these folder? My research points me to this here.

Please move the OTL.exe to your Desktop. Your OTL Logs look pretty good to me.
  • Run OTL (If you have Windows Vista / Windows 7 / Windows 8 please do a Right click on the OTL icon and select Run as Administrator).
  • Copy (Ctrl+C) and Paste (Ctrl+V) all of the following text into the Custom Scans/Fixes box:


    :Commands
    [CREATERESTOREPOINT]
    
    :OTL
    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll File not found
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O13 - gopher Prefix: missing
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    
    :Commands
    [EMPTYTEMP]
    
  • Click the Run Fix button.
  • After your computer has rebooted, run OTL and click Quick Scan.
  • Copy and paste the contents of the log that it produces into your next post.

  • 0

#5
Bismillah

Bismillah

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 514 posts

It's strange because the file associated with the Ecard definitely executed, as there was no sign of it on my desktop and the suspicious activity relating to my email account.

 

[2013/08/08 22:57:05 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\3909
[2013/04/24 19:08:34 | 000,000,000 | ---D | M] -- C:\Users\Dan\AppData\Roaming\3909 LLC

 

3909 is the company which produces the game Papers Please which I have :)

 

In regards for the Registry Entries I'm unsure on the answer :( - I'm not sure how to do a RegExport, do you mean using Regedit to find the key then export it?

 

 

In regards for ElevatedDiagnostics from more googling I think It's related to SFC - This is what made me think it was malware - http://www.systemloo...wjrvfx_dll.html

 

 

I noticed you included the two WebCheck items in the OTL fix, they did catch my notice however from looking at the CLSID on SystemLookup they seemed clean - http://www.systemloo...bcheck_dll.html


Edited by Bismillah, 07 May 2014 - 06:49 AM.

  • 0

#6
Machiavelli

Machiavelli

    GeekU Moderator

  • GeekU Moderator
  • 3,698 posts
Hey,
 

In regards for the Registry Entries I'm unsure on the answer :( - I'm not sure how to do a RegExport, do you mean using Regedit to find the key then export it?

Correct. ;)
 

In regards for ElevatedDiagnostics from more googling I think It's related to SFC

Nearly, it is related to Windows Troubleshooter. More see here.
 

I noticed you included the two WebCheck items in the OTL fix, they did catch my notice however from looking at the CLSID on SystemLookup they seemed clean

Correct. I don't like to tell that much about it because you will learn this in your PL actually. Look at your PL entry #10. Your instructor will tell you what this is.

Please procceed with the Registry Export and OTL Fix. Well done ;)
  • 0

#7
Machiavelli

Machiavelli

    GeekU Moderator

  • GeekU Moderator
  • 3,698 posts
Are you still with me?
  • 0

#8
Machiavelli

Machiavelli

    GeekU Moderator

  • GeekU Moderator
  • 3,698 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP