Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

cvtres.exe wont go away [Closed]


  • This topic is locked This topic is locked

#1
Coldsteel123

Coldsteel123

    New Member

  • Member
  • Pip
  • 1 posts

cvtres.exe is using up almost all of my cpu and i dont know how to get rid of it.  when i end the process from task manager it just starts right back up again a few seconds later.  i will be shutting down my computer while im at work to see if that does anything.

 

heres the OTL log file:

 

OTL logfile created on: 9/23/2014 3:40:50 PM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Troy\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17280)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
16.00 Gb Total Physical Memory | 9.32 Gb Available Physical Memory | 58.24% Memory free
31.99 Gb Paging File | 24.93 Gb Available in Paging File | 77.94% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 149.04 Gb Total Space | 15.22 Gb Free Space | 10.21% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 135.23 Gb Free Space | 14.52% Space Free | Partition Type: NTFS
Drive F: | 100.00 Mb Total Space | 63.62 Mb Free Space | 63.62% Space Free | Partition Type: NTFS
Drive G: | 465.66 Gb Total Space | 77.97 Gb Free Space | 16.74% Space Free | Partition Type: NTFS
 
Computer Name: TROY-PC | User Name: Troy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2014/09/23 15:36:48 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Troy\Downloads\OTL.exe
PRC - [2014/09/22 15:27:49 | 003,600,216 | ---- | M] (Electronic Arts) -- E:\Origin\Origin.exe
PRC - [2014/09/18 16:33:40 | 001,416,016 | ---- | M] (BitTorrent Inc.) -- C:\Users\Troy\AppData\Roaming\uTorrent\uTorrent.exe
PRC - [2014/09/18 16:09:11 | 010,523,184 | ---- | M] (Blizzard Entertainment) -- C:\ProgramData\Battle.net\Agent\Agent.3372\Agent.exe
PRC - [2014/09/12 15:31:42 | 009,948,720 | ---- | M] (Blizzard Entertainment) -- G:\Battle.net\Battle.net.5011\Battle.net.exe
PRC - [2014/09/03 23:01:19 | 000,852,808 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014/08/28 07:48:04 | 001,521,344 | ---- | M] (Valve Corporation) -- E:\Steam\bin\steamwebhelper.exe
PRC - [2014/08/28 07:48:02 | 000,833,728 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe
PRC - [2014/08/28 07:48:00 | 001,939,136 | ---- | M] (Valve Corporation) -- E:\Steam\Steam.exe
PRC - [2014/06/29 19:22:44 | 001,551,872 | -HS- | M] ( ) -- C:\Users\Troy\AppData\Roaming\Microsoft\Wcenter71.exe
PRC - [2014/04/17 21:07:28 | 004,672,920 | ---- | M] (Akamai Technologies, Inc.) -- C:\Users\Troy\AppData\Local\Akamai\netsession_win.exe
PRC - [2014/04/04 21:49:24 | 012,174,384 | ---- | M] (ZeniMax Online Studios) -- G:\Elder Scrolls Online\Launcher\Bethesda.net_Launcher.exe
PRC - [2014/03/20 18:49:17 | 000,032,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2014/09/22 15:27:43 | 000,962,560 | ---- | M] () -- E:\Origin\platforms\qwindows.dll
MOD - [2014/09/22 15:27:42 | 000,302,592 | ---- | M] () -- E:\Origin\imageformats\qtiff.dll
MOD - [2014/09/22 15:27:42 | 000,261,632 | ---- | M] () -- E:\Origin\imageformats\qmng.dll
MOD - [2014/09/22 15:27:42 | 000,217,088 | ---- | M] () -- E:\Origin\imageformats\qjpeg.dll
MOD - [2014/09/22 15:27:42 | 000,025,088 | ---- | M] () -- E:\Origin\imageformats\qico.dll
MOD - [2014/09/22 15:27:42 | 000,024,064 | ---- | M] () -- E:\Origin\imageformats\qgif.dll
MOD - [2014/09/22 15:27:42 | 000,019,968 | ---- | M] () -- E:\Origin\imageformats\qtga.dll
MOD - [2014/09/22 15:27:42 | 000,018,944 | ---- | M] () -- E:\Origin\imageformats\qwbmp.dll
MOD - [2014/09/12 15:31:41 | 026,065,408 | ---- | M] () -- G:\Battle.net\Battle.net.5011\libcef.dll
MOD - [2014/09/12 15:31:41 | 000,739,840 | ---- | M] () -- G:\Battle.net\Battle.net.5011\libGLESv2.dll
MOD - [2014/09/12 15:31:41 | 000,130,048 | ---- | M] () -- G:\Battle.net\Battle.net.5011\libEGL.dll
MOD - [2014/09/11 19:47:22 | 001,669,632 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\d941c7e0001a4d98e39785da42b57341\Microsoft.VisualBasic.ni.dll
MOD - [2014/09/11 19:06:47 | 001,051,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\ef19f3d0c255664d453183a254330b56\System.Management.ni.dll
MOD - [2014/09/11 16:35:45 | 011,922,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\349461c3a273efc2b4bd643c2645bd70\System.Web.ni.dll
MOD - [2014/09/11 16:35:34 | 000,774,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\2508b25b4d961a45659a8a8f128818a1\System.Runtime.Remoting.ni.dll
MOD - [2014/09/11 16:34:26 | 012,435,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\3f2952ec748f60fbb5deacfc4db0a2a3\System.Windows.Forms.ni.dll
MOD - [2014/09/11 16:34:18 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\8b7f86e5a6f0aa23f4b25dfeeaa6b318\System.Drawing.ni.dll
MOD - [2014/09/11 16:33:54 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\95854f4f1f37b8eab1b1e3d7103b48ef\System.ni.dll
MOD - [2014/09/11 16:33:33 | 011,497,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll
MOD - [2014/09/03 23:01:18 | 000,331,592 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\ppgooglenaclpluginchrome.dll
MOD - [2014/09/03 23:01:17 | 014,891,848 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\PepperFlash\pepflashplayer.dll
MOD - [2014/09/03 23:01:16 | 008,577,864 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\pdf.dll
MOD - [2014/09/03 23:01:12 | 001,098,056 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\libglesv2.dll
MOD - [2014/09/03 23:01:10 | 000,174,408 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\libegl.dll
MOD - [2014/09/03 23:01:09 | 001,660,232 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\ffmpegsumo.dll
MOD - [2014/08/28 07:48:14 | 002,224,320 | ---- | M] () -- E:\Steam\video.dll
MOD - [2014/08/28 07:48:02 | 000,678,080 | ---- | M] () -- E:\Steam\bin\chromehtml.dll
MOD - [2014/08/21 14:15:22 | 001,171,456 | ---- | M] () -- E:\Steam\libavcodec-56.dll
MOD - [2014/08/21 14:15:22 | 000,485,888 | ---- | M] () -- E:\Steam\libswscale-3.dll
MOD - [2014/08/21 14:15:22 | 000,442,368 | ---- | M] () -- E:\Steam\libavutil-54.dll
MOD - [2014/08/21 14:15:22 | 000,403,968 | ---- | M] () -- E:\Steam\libavformat-56.dll
MOD - [2014/08/21 14:15:22 | 000,332,800 | ---- | M] () -- E:\Steam\libavresample-2.dll
MOD - [2014/08/20 18:38:18 | 034,589,376 | ---- | M] () -- E:\Steam\bin\libcef.dll
MOD - [2014/08/20 18:38:18 | 000,837,824 | ---- | M] () -- E:\Steam\bin\ffmpegsumo.dll
MOD - [2014/08/20 18:38:12 | 000,774,656 | ---- | M] () -- E:\Steam\SDL2.dll
MOD - [2014/04/04 21:49:08 | 022,908,928 | ---- | M] () -- G:\Elder Scrolls Online\Launcher\libcef.dll
MOD - [2014/04/04 21:49:06 | 000,027,168 | ---- | M] () -- G:\Elder Scrolls Online\Launcher\MinSpecDetectionInterop.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2014/08/18 18:03:37 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013/10/08 10:34:38 | 000,344,064 | ---- | M] (Advanced Micro Devices, Inc.) [Disabled | Stopped] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2013/10/08 08:52:58 | 000,239,616 | ---- | M] (AMD) [Disabled | Stopped] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2013/05/27 01:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2014/09/22 15:32:50 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/08/28 07:48:02 | 000,833,728 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2014/03/20 18:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2013/12/21 02:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/10/23 08:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/09/11 22:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/08/14 16:19:24 | 000,039,056 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
SRV - [2012/10/24 04:16:51 | 004,702,568 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GameMon.des -- (npggsvc)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2013/10/08 09:58:42 | 012,534,784 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2013/10/08 08:27:46 | 000,619,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2013/07/05 04:40:38 | 000,096,256 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2013/04/30 12:55:32 | 000,052,640 | ---- | M] (Saitek) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SaiBus.sys -- (SaiNtBus)
DRV:64bit: - [2013/04/30 12:55:32 | 000,025,120 | ---- | M] (Saitek) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SaiMini.sys -- (SaiMini)
DRV:64bit: - [2012/12/21 13:53:58 | 000,017,480 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\epmntdrv.sys -- (epmntdrv)
DRV:64bit: - [2012/12/21 13:53:58 | 000,009,800 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\EuGdiDrv.sys -- (EuGdiDrv)
DRV:64bit: - [2012/11/20 14:55:42 | 000,057,512 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Stopped] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.2)
DRV:64bit: - [2012/11/20 14:55:42 | 000,057,512 | ---- | M] (Advanced Micro Devices) [Kernel | Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys -- (AODDriver4.01)
DRV:64bit: - [2012/09/20 15:23:56 | 000,180,544 | ---- | M] (Saitek) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SaiK1713.sys -- (SaiK1713)
DRV:64bit: - [2012/09/20 15:23:56 | 000,047,168 | ---- | M] (Saitek) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SaiU1713.sys -- (SaiU1713)
DRV:64bit: - [2012/08/21 14:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/07/09 14:42:54 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/12/12 17:42:00 | 001,256,192 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmwlhigh664.sys -- (BCMH43XX)
DRV:64bit: - [2011/12/02 06:38:08 | 000,239,208 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtHDMIVX.sys -- (RTHDMIAzAudService)
DRV:64bit: - [2011/09/29 05:30:34 | 000,646,248 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/07/22 10:33:48 | 000,025,056 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SCMNdisP.sys -- (SCMNdisP)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/07/18 17:14:40 | 000,944,672 | R--- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtl8192ce.sys -- (RTL8192Ce)
DRV:64bit: - [2010/02/18 10:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2010/02/03 11:21:56 | 000,047,632 | ---- | M] (CACE Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\npf.sys -- (NPF)
DRV:64bit: - [2009/08/13 22:10:18 | 000,073,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/03/18 17:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV:64bit: - [2008/05/06 17:06:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
DRV:64bit: - [2007/07/23 08:57:04 | 000,052,992 | ---- | M] (Ideazon Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Alpham164.sys -- (Alpham1)
DRV:64bit: - [2007/03/20 10:51:04 | 000,021,760 | ---- | M] (Ideazon Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Alpham264.sys -- (Alpham2)
DRV - [2012/12/21 13:54:00 | 000,014,920 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\epmntdrv.sys -- (epmntdrv)
DRV - [2012/12/21 13:53:58 | 000,009,160 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\EuGdiDrv.sys -- (EuGdiDrv)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://searchy.easyl...961&lg=EN&cc=US
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{01bd49d7-c76b-4310-8beb-14d7e5f322c6}: "URL" = http://searchy.easyl...961&lg=EN&cc=US
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://searchy.easyl...961&lg=EN&cc=US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 2C 21 58 F3 34 F3 CC 01  [binary data]
IE - HKCU\..\URLSearchHook: {e9df9360-97f8-4690-afe6-996c80790da4} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{01bd49d7-c76b-4310-8beb-14d7e5f322c6}: "URL" = http://searchy.easyl...961&lg=EN&cc=US
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE11SR
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...1I7MXGB_enUS524
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={04B71B33-84CD-4038-9362-95BD817BC391}&mid=754f1d66a43d47d093592e35af22c6b3-5b2683fdb58f912efe88910d4149366e57906e59&lang=en&ds=st011&pr=sa&d=2012-03-19 20:53:39&v=10.0.0.7&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>
 
 
========== FireFox ==========
 
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.3.0: C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/npbattlelog,version=2.3.2: C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.67.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@nexon.com/NxGame: C:\ProgramData\Nexon\NGM\npnxgame.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.3.51: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.3: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.3.51: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Troy\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\thehappycloud.com/HappyCloudPlugin: C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll (The Happy Cloud)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/12/18 13:17:11 | 000,000,000 | ---D | M]
 
[2012/03/19 20:58:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Troy\AppData\Roaming\Mozilla\Firefox\extensions
[2012/03/19 20:58:30 | 000,000,000 | ---D | M] (uTorrentControl Community Toolbar) -- C:\Users\Troy\AppData\Roaming\Mozilla\Firefox\extensions\{e9df9360-97f8-4690-afe6-996c80790da4}
 
========== Chrome  ==========
 
CHR - default_search_provider:  (Enabled)
CHR - default_search_provider: search_url = 
CHR - default_search_provider: suggest_url = 
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.120\pdf.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll
CHR - plugin: ESN Sonar API (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Troy\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - default_search_provider: AA605002DB731275D4648F68122C0451D619AD4BAEDF02BD067A945B2E127B18 (Enabled)
CHR - default_search_provider: search_url = E602C0536F88EE9138D056C1A495F6008ABA1E2C9C17A72677F6339D6E7202E7
CHR - default_search_provider: suggest_url = 
CHR - homepage: 6A47ECE66EDEED629E6B6674E5DBE15E8CE4504A9A2F6BFDCB844A53A36647FA
CHR - Extension: No name found = C:\Users\Troy\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\
CHR - Extension: No name found = C:\Users\Troy\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.8.5_0\
CHR - Extension: No name found = C:\Users\Troy\AppData\Local\Google\Chrome\User Data\Default\Extensions\danjmbbdjabpapehlajpomcignjnoidp\1.0_0\
CHR - Extension: No name found = C:\Users\Troy\AppData\Local\Google\Chrome\User Data\Default\Extensions\flcpelgcagfhfoegekianiofphddckof\2.0.4_0\
CHR - Extension: No name found = C:\Users\Troy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcbommkclmclpchllfjekcdonpmejbdp\2014.9.11_0\
CHR - Extension: No name found = C:\Users\Troy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
 
O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll File not found
O2 - BHO: (I Want This) - {11111111-1111-1111-1111-110011221158} - C:\Program Files (x86)\I Want This\I Want This.dll File not found
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (DoWnnloaad keEper) - {32EF0D3E-FD53-6F02-15A3-E61E3AA5ACEE} - C:\ProgramData\DoWnnloaad keEper\Ry53zijG.dll ()
O2 - BHO: (Downuload kkeeper) - {33545706-0684-0897-1231-24BD49D753DF} - C:\ProgramData\Downuload kkeeper\owaXLX.dll ()
O2 - BHO: (Download keeapeer) - {59647F3C-B8D5-AD57-F3C1-59A1A0F805BF} - C:\ProgramData\Download keeapeer\VP6N.dll ()
O2 - BHO: (Funmoods Helper Object) - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - C:\PROGRA~2\Funmoods\1.5.23.22\bh\escort.dll File not found
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (DownlaOAd kueeper) - {957FC261-9E36-6D20-DDDF-4F1A8C1F4CFC} - C:\ProgramData\DownlaOAd kueeper\KgSyJpCh_.dll ()
O2 - BHO: (DOwnlOaD. keePeR) - {9AA85E4F-36D7-BE7B-DF13-8DDD3B2DFCC5} - C:\ProgramData\DOwnlOaD. keePeR\b.dll ()
O2 - BHO: (DDownloiaeD kkeepeuR) - {B60F7B7E-329A-1CD0-D2CB-9DD1EF3568DC} - C:\ProgramData\DDownloiaeD kkeepeuR\XzdOw.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Download keeoppero) - {FC8A4317-B5A0-DC5B-57FB-CCDD7EFD4828} - C:\ProgramData\Download keeoppero\mB.dll ()
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (Funmoods Toolbar) - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - C:\PROGRA~2\Funmoods\1.5.23.22\escorTlbr.dll File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E9DF9360-97F8-4690-AFE6-996C80790DA4} - No CLSID value found.
O4:64bit: - HKLM..\Run: [ProfilerU] C:\Program Files\SmartTechnology\Software\ProfilerU.exe (Saitek)
O4:64bit: - HKLM..\Run: [SaiMfd] C:\Program Files\SmartTechnology\Software\SaiMfd.exe (Saitek)
O4 - HKLM..\Run: [Aeria Ignite] "C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe" silent File not found
O4 - HKLM..\Run: [NCUpdateHelper] C:\Program Files (x86)\NCWest\NCLauncher\NCUpdateHelper.exe (NCSOFT Corporation)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Troy\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKCU..\Run: [Battle.net] "G:\Battle.net\Battle.net Launcher.exe" --autostarted File not found
O4 - HKCU..\Run: [C:\ProgramData\lsassm.exe] lsassm.exe File not found
O4 - HKCU..\Run: [C:\ProgramData\lsassp.exe] lsassp.exe File not found
O4 - HKCU..\Run: [EADM] E:\Origin\Origin.exe (Electronic Arts)
O4 - HKCU..\Run: [lsassc.exe] C:\ProgramData\lsassc.exe ( )
O4 - HKCU..\Run: [Steam] E:\Steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [uTorrent] C:\Users\Troy\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
O4 - HKCU..\Run: [Wcenter] C:\Users\Troy\AppData\Roaming\Microsoft\Wcenter71.exe ( )
O4 - Startup: C:\Users\Troy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
O4 - Startup: C:\Users\Troy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\lsassc.exe ( )
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: aeriagames.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: aeriagames.com ([]https in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2294E6FA-705B-4706-87A5-4DC0FB87ADDF}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3AE1A14E-9EDC-4535-A705-FDBCB8099E6E}: DhcpNameServer = 38.118.52.2 4.2.2.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{54EC90D9-AE7F-49CE-8852-E11AD7FE7097}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7FEA65FF-081D-4C4E-9123-2280A697FB6C}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/02/08 14:06:48 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{2667691b-8e23-11e1-ae38-93940702a145}\Shell - "" = AutoRun
O33 - MountPoints2\{2667691b-8e23-11e1-ae38-93940702a145}\Shell\AutoRun\command - "" = H:\Setup.exe
O33 - MountPoints2\{696621a1-6289-11e1-9deb-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{696621a1-6289-11e1-9deb-806e6f6e6963}\Shell\AutoRun\command - "" = D:\SETUP.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/09/14 03:01:26 | 000,000,000 | ---D | C] -- C:\Users\Troy\AppData\Local\Surazal
[2014/09/14 02:36:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BOSS
[2014/09/14 02:36:24 | 000,000,000 | ---D | C] -- C:\BOSS
[6 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2014/09/23 15:18:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/09/23 14:49:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/09/23 05:18:00 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/09/22 15:34:17 | 000,025,200 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/09/22 15:34:17 | 000,025,200 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/09/22 15:25:19 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/09/22 15:25:14 | 4292,882,430 | -HS- | M] () -- C:\hiberfil.sys
[2014/09/18 14:37:03 | 000,124,339 | ---- | M] () -- C:\Users\Troy\Desktop\SKSE_1_07_01 Scripts.rar
[2014/09/16 23:51:37 | 000,000,973 | ---- | M] () -- C:\Users\Troy\Desktop\Skyrim (SKSE).lnk
[2014/09/16 10:48:58 | 001,518,686 | ---- | M] () -- C:\Users\Troy\Desktop\Update.esm
[2014/09/14 02:58:30 | 000,003,047 | ---- | M] () -- C:\Users\Troy\Desktop\BOSS Userlist Manager.lnk
[2014/09/14 02:41:02 | 000,000,890 | ---- | M] () -- C:\Users\Public\Desktop\Nexus Mod Manager.lnk
[2014/09/11 03:03:54 | 000,788,992 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2014/09/11 03:03:54 | 000,671,748 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/09/11 03:03:54 | 000,126,770 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/09/11 03:03:46 | 000,788,992 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/08/28 04:11:13 | 000,269,832 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[6 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2014/09/19 16:00:36 | 001,518,686 | ---- | C] () -- C:\Users\Troy\Desktop\Update.esm
[2014/09/18 14:37:08 | 000,124,339 | ---- | C] () -- C:\Users\Troy\Desktop\SKSE_1_07_01 Scripts.rar
[2014/09/15 23:51:27 | 000,000,973 | ---- | C] () -- C:\Users\Troy\Desktop\Skyrim (SKSE).lnk
[2014/09/14 02:58:30 | 000,003,047 | ---- | C] () -- C:\Users\Troy\Desktop\BOSS Userlist Manager.lnk
[2014/07/09 15:14:56 | 000,000,092 | ---- | C] () -- C:\Users\Troy\AppData\Local\fusioncache.dat
[2014/06/29 19:22:24 | 001,551,872 | ---- | C] ( ) -- C:\ProgramData\lsassm.exe
[2014/06/29 14:04:09 | 000,124,416 | ---- | C] ( ) -- C:\ProgramData\lsassp.exe
[2014/06/29 14:03:44 | 000,459,776 | ---- | C] ( ) -- C:\ProgramData\lsassc.exe
[2014/02/20 18:14:02 | 000,179,377 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2013/10/08 10:45:08 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2013/10/08 09:39:08 | 000,995,342 | ---- | C] () -- C:\Windows\SysWow64\amdocl_as32.exe
[2013/10/08 09:39:08 | 000,798,734 | ---- | C] () -- C:\Windows\SysWow64\amdocl_ld32.exe
[2013/09/30 17:43:36 | 000,053,299 | ---- | C] () -- C:\Windows\SysWow64\pthreadVC.dll
[2013/06/25 21:42:02 | 000,000,040 | ---- | C] () -- C:\ProgramData\ra3.ini
[2013/03/19 20:18:59 | 002,468,520 | ---- | C] () -- C:\Windows\SysWow64\BootMan.exe
[2013/03/19 20:18:59 | 000,087,112 | ---- | C] () -- C:\Windows\SysWow64\setupempdrv03.exe
[2013/03/19 20:18:59 | 000,019,840 | ---- | C] () -- C:\Windows\SysWow64\EuEpmGdi.dll
[2013/03/19 20:18:59 | 000,014,920 | ---- | C] () -- C:\Windows\SysWow64\epmntdrv.sys
[2013/03/19 20:18:59 | 000,009,160 | ---- | C] () -- C:\Windows\SysWow64\EuGdiDrv.sys
[2012/12/24 17:31:43 | 000,681,478 | ---- | C] () -- C:\Windows\SysWow64\msvcrtnew.dll
[2012/12/24 17:31:43 | 000,000,236 | ---- | C] () -- C:\Program Files (x86)\Common Files\dx.reg
[2012/12/24 17:31:42 | 000,874,502 | ---- | C] () -- C:\Windows\SysWow64\kernel32new.dll
[2012/12/24 17:31:42 | 000,716,153 | ---- | C] () -- C:\Windows\SysWow64\unins000.exe
[2012/12/24 17:31:42 | 000,004,806 | ---- | C] () -- C:\Windows\SysWow64\unins000.dat
[2012/08/09 14:56:36 | 000,033,958 | ---- | C] () -- C:\ProgramData\uninstaller.exe
[2012/08/09 14:55:30 | 000,031,465 | ---- | C] () -- C:\Users\Troy\AppData\Local\funmoods.crx
[2012/08/07 14:49:20 | 004,608,000 | ---- | C] () -- C:\ProgramData\ReadOnlyInstaller.msi
 
========== ZeroAccess Check ==========
 
[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/06/24 22:05:42 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/06/24 21:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 21:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 08:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 21:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2014/09/23 02:10:29 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\Awesomium
[2013/03/21 15:19:59 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\Babylon
[2013/10/25 19:35:20 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\Battle.net
[2014/05/06 19:46:13 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\Command and Conquer 3 Kanes Wrath
[2014/05/06 13:16:00 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\Command and Conquer 3 Tiberium Wars
[2014/05/06 22:11:36 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\Command and Conquer 4
[2013/04/07 10:14:36 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\Curse Advertising
[2012/04/28 12:57:47 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\DAEMON Tools Pro
[2012/04/09 21:29:11 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\IObit
[2012/03/05 21:21:12 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\LolClient
[2012/06/04 15:45:47 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\LolClient2
[2014/05/09 17:51:42 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\NCSOFT
[2014/06/14 19:52:34 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\Oracle
[2013/08/22 20:28:15 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\Origin
[2014/01/22 17:40:38 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\PunkBuster
[2013/06/25 21:42:08 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\Red Alert 3
[2013/06/26 21:48:31 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\Red Alert 3 Uprising
[2014/06/25 10:09:03 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\RenPy
[2014/04/30 22:28:14 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\RIFT
[2013/06/19 20:39:34 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\Stardock
[2014/07/02 15:13:29 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\Touchstone
[2013/11/08 19:47:33 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\TS3Client
[2014/07/02 14:22:20 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\Turok
[2013/12/06 16:31:05 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\Ubisoft
[2014/09/23 16:04:13 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\uTorrent
[2012/09/01 05:31:18 | 000,000,000 | ---D | M] -- C:\Users\Troy\AppData\Roaming\WeatherBug
 
========== Purity Check ==========
 
 
 
< End of report >
 
and the 'extras' file:
 

OTL Extras logfile created on: 9/23/2014 3:40:50 PM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Troy\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17280)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
16.00 Gb Total Physical Memory | 9.32 Gb Available Physical Memory | 58.24% Memory free
31.99 Gb Paging File | 24.93 Gb Available in Paging File | 77.94% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 149.04 Gb Total Space | 15.22 Gb Free Space | 10.21% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 135.23 Gb Free Space | 14.52% Space Free | Partition Type: NTFS
Drive F: | 100.00 Mb Total Space | 63.62 Mb Free Space | 63.62% Space Free | Partition Type: NTFS
Drive G: | 465.66 Gb Total Space | 77.97 Gb Free Space | 16.74% Space Free | Partition Type: NTFS
 
Computer Name: TROY-PC | User Name: Troy | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
.ini [@ = inifile] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{29C19F3C-0BC3-4774-BE5F-4E9790D49163}" = lport=138 | protocol=17 | dir=in | app=system | 
"{29F9B232-BAAF-44BE-A49C-3F11C9D1C163}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | 
"{2B3A200D-FE22-44CB-B9D4-B63631DE9C65}" = rport=139 | protocol=6 | dir=out | app=system | 
"{2BECC05E-53CB-4823-BDAA-F1D7E3C5DFED}" = rport=137 | protocol=17 | dir=out | app=system | 
"{2F404D33-E382-4F00-8C84-6BD86040993C}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{47F83E5C-3B91-4020-9E3E-FEE0342F1645}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{4AD99942-1AD6-40CA-A937-ED2660800131}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 | 
"{50AC67A3-6C99-447C-ABA2-D5350C64612C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{6366B6E5-2A13-4070-9441-47F33953D3B1}" = lport=137 | protocol=17 | dir=in | app=system | 
"{643DF887-1CB3-4657-A86C-C0B7193BF75B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{660E1D0D-EE04-49E8-BD39-B8D922776CA2}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{6D4BF1DE-3003-4F6A-83A9-219655CA45CE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{6D714B54-0A8D-4F38-A617-52CA667B9383}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{843C8D95-0017-4A62-884C-7F59CDC17659}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{889FF6EE-9EE0-4162-AEF7-7544156CBA7B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{963D202D-DA77-47A9-883D-2A38593C42C2}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{A894DA00-5DED-4F6D-B23F-8E6C7884EBF6}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{AB727241-B7C1-47D1-8199-825F17A9F397}" = lport=445 | protocol=6 | dir=in | app=system | 
"{B7B21B7B-E08A-4F94-A916-A4FDCB14017C}" = rport=138 | protocol=17 | dir=out | app=system | 
"{DAD6EF9A-E0B9-46E3-8B40-E868329DED1F}" = lport=139 | protocol=6 | dir=in | app=system | 
"{E356FBE7-9699-44A2-8477-02849A9E447D}" = rport=445 | protocol=6 | dir=out | app=system | 
"{FA1CB5DF-E2BF-4E68-A980-8BC7ABD6E56F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00443198-4C00-4BCA-9553-88F635B440CF}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe | 
"{01B6152B-C708-4EA3-8D57-B55295717D27}" = dir=in | app=e:\battlefield 3\command and conquer 3 tw and kw\command conquer 3 tiberium wars\retailexe\1.9\cnc3game.dat | 
"{02FDA1EE-404B-4FA2-8706-D2AEFB449CE8}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{0367B02A-E699-4F77-9D86-25D0B850F7C4}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe | 
"{036F14E1-5C13-4BED-B82E-4F2278AFDA34}" = protocol=58 | dir=out | [email protected],-503 | 
"{041B00C8-193C-4C4F-A8B8-DEB297C04E3F}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\path of exile\pathofexilesteam.exe | 
"{04A75BEF-A46C-44CD-826B-8CA2EFD9C91E}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3332\agent.exe | 
"{067A0301-72D1-465E-AAFC-205A052AA3D4}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\skyrim\skyrimlauncher.exe | 
"{06C8CEF7-E150-4B74-903B-A9B5129E8666}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{07C78D8B-10B8-4D3E-967F-D62DF9B2CC69}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2293\agent.exe | 
"{07D39C6E-C667-4E8D-A022-5FE1158C174D}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\path of exile\pathofexilesteam.exe | 
"{08E0F32F-2E93-4280-87A4-50D2B580C72F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe | 
"{090D9324-C5BE-4042-B870-7919C854F084}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2680\agent.exe | 
"{0C3C9CD8-73F1-4D93-B21B-7E9E281A699E}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{0C3DEAB9-54F2-4233-8FC1-10E4A0423FE8}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2787\agent.exe | 
"{0CB53E7C-15C1-4EFD-A48A-5D1AF1619D95}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2380\agent.exe | 
"{0CE1B3F7-8748-483C-AA4F-2209384CA3A1}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe | 
"{0DEB51C8-2E07-4B49-B957-85B73D73E8DC}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{0E5BF48D-8A46-49F4-B4E9-24F9781E0453}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{0EBBE88A-8766-4268-879B-0F595EBB34B4}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe | 
"{0F7DAA79-2FCE-4862-A758-0B1E0F25EDD9}" = protocol=6 | dir=in | app=c:\world of warcraft\launcher.patch.exe | 
"{100B819A-FB6A-498B-A07B-6D8238BCF305}" = protocol=6 | dir=in | app=c:\world of warcraft\launcher.patch.exe | 
"{135DBDC9-A3B6-4E27-AAB3-BE737107E597}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\the witcher enhanced edition\system\witcher.exe | 
"{143EB88F-CBB0-415F-B303-7BCD3B000B92}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3147\agent.exe | 
"{14861E7A-E6D6-4A82-B248-D931030B267B}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{14B3A417-84DA-4B89-A67F-C93E732AF057}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{15FED112-C233-4808-84E6-FDBFF0F12EC4}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2391\agent.exe | 
"{1626F3EF-A6DA-49CC-AFE3-84835CD22E97}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | 
"{16CE22D3-33A2-4D99-84F8-8DE5765F1CD3}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{16F6D68E-B5E5-4743-9B45-59B03AA8642A}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | 
"{17737C2A-6A1D-42D5-96DE-E0BB1B9A9325}" = protocol=6 | dir=in | app=e:\battlefield 3\cnc and the covert operations\cnc95launcher.exe | 
"{179F5FAB-6E6D-418D-88A8-5985AFFB4453}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
"{17BD9FE1-7082-4436-BFEC-D5646D3D7E68}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3334\agent.exe | 
"{183B37CB-DEE7-4F9E-86EB-C51723BFC512}" = protocol=6 | dir=in | app=e:\battlefield 3\mass effect 3\binaries\win32\masseffect3.exe | 
"{1A46F21A-DAD3-434F-B7D7-38630FE5E071}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3235\agent.exe | 
"{1B0E4E42-4C8B-48BC-B21E-21EE1D872AC1}" = protocol=17 | dir=in | app=e:\starcraft ii\starcraft ii public test.exe | 
"{1D207BD9-E7C3-4066-9E40-E960F5E76649}" = protocol=17 | dir=in | app=e:\battlefield 3\command conquer 4 tiberian twilight\cnc4.exe | 
"{1EA16162-2DDB-4EC1-AB3B-14E834177CF3}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{1F27C702-B66C-4406-AE31-79E15EBE5222}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | 
"{1F785B19-F03E-4F25-9B08-937662DFB2BF}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1225\agent.exe | 
"{1FD3E778-2039-47BE-9680-B551A6428A42}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\blades of time\bladesoftime.exe | 
"{1FEAA9F1-B56F-403E-918F-B9B9A9812096}" = protocol=6 | dir=in | app=e:\battlefield 3\battlefield 3\bf3.exe | 
"{216299D7-551D-412C-9CE8-814349448EB8}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | 
"{21FCD895-E268-403A-BADC-F73DC530FA65}" = protocol=17 | dir=in | app=e:\battlefield 3\renegade\renegadelauncher.exe | 
"{222B6A4C-7ADE-402C-B7CB-B6FE54C4DD77}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\the witcher enhanced edition\system\witcher.exe | 
"{223236DF-D220-473B-8397-0B2067FFF2A7}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2391\agent.exe | 
"{228B81AC-284F-4E9A-B422-9AA883B0C272}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe | 
"{236042F5-D1C8-48E3-9F32-A6D828102126}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{24AEB028-9496-47DD-BEAE-C5E2A9683D5A}" = protocol=6 | dir=in | app=c:\program files (x86)\ati technologies\ati.ace\core-static\ccc.exe | 
"{27A860AD-EEF4-4BCC-8D84-E494DDC1D6A8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\darksiders\darksiderspc.exe | 
"{27D52588-EB27-42D0-8E56-89CB6BAE4547}" = protocol=6 | dir=in | app=g:\squareenix\final fantasy xiv - a realm reborn\game\ffxiv.exe | 
"{2970DCCA-E034-4245-BCE2-90423A5DB77A}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe | 
"{2A357277-3BF7-4B6C-9416-E7F0224416FF}" = protocol=17 | dir=in | app=c:\users\troy\appdata\roaming\utorrent\utorrent.exe | 
"{2B6E6145-670D-4832-AE1A-9AB6E76F4991}" = protocol=17 | dir=in | app=c:\program files (x86)\ati technologies\ati.ace\core-static\ccc.exe | 
"{2C9544C5-44B9-4E74-952B-E6743A4D06B7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{2DC8C8A4-11CB-4DBA-8158-F823D27F0EF3}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\path of exile\pathofexilesteam.exe | 
"{3085400B-9475-4C1F-9CED-925B6BD408AB}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{3087CF5E-F6FD-432D-9188-A26B630AB453}" = protocol=58 | dir=out | [email protected],-28546 | 
"{3292ED2C-8F5F-4AFF-9DF9-3FE963AA8A00}" = protocol=17 | dir=in | app=e:\hearthstone\hearthstone.exe | 
"{3305CA23-4064-4284-B319-70AAA9D2C150}" = protocol=17 | dir=in | app=g:\squareenix\final fantasy xiv - a realm reborn\boot\ffxivboot.exe | 
"{33D1C924-58D9-44FF-A924-BA1B76A710D3}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\path of exile\pathofexilesteam.exe | 
"{36096870-9B1F-4E11-A9CD-1C63BA05F267}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2000\agent.exe | 
"{36ACE4DB-7DD1-46CC-9B77-5E70E5C9EFED}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3334\agent.exe | 
"{36C56FCA-CB44-4362-9CCC-03F3A417AEF4}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2816\agent.exe | 
"{38856EE1-30F2-4659-8F13-BED92E0FEC41}" = protocol=6 | dir=in | app=e:\steam\bin\steamwebhelper.exe | 
"{38AA1D08-7CEE-422B-82B3-C72B5D5C56D7}" = protocol=6 | dir=in | app=e:\battlefield 3\battlefield 4\bf4_x86.exe | 
"{39830251-0DE3-484A-AAA1-1DA4F9C4C2C2}" = protocol=6 | dir=in | app=e:\starcraft ii\starcraft ii public test.exe | 
"{3A74FC38-A632-4446-96AD-4240BAC49CB2}" = protocol=6 | dir=in | app=e:\battlefield 3\renegade\renegadelauncher.exe | 
"{3B5B1594-D277-4B51-AEEB-2CF5DE576015}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | 
"{3BB436A1-B23C-45F8-8764-FD8951D4FA92}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1225\agent.exe | 
"{3C4A9190-2F50-4D1F-AE55-53B25011297A}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\killingfloor\system\killingfloor.exe | 
"{3CBCF5B0-4032-4DF7-A360-3841FDEF3F27}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\path of exile\pathofexilesteam.exe | 
"{3DAF1F70-AAC7-4676-A18B-99F5E4A67E29}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2638\agent.exe | 
"{3EB5591B-E4E4-4E15-9223-7779CE4ABE9C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{3ED0A4CD-9FBE-4A11-BDFD-41A862768BF5}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3147\agent.exe | 
"{3F47BF20-2EFD-415E-9F56-BC662532A85C}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\the witcher 2\launcher.exe | 
"{3F79C9BB-FC47-4F94-AB97-A6CBD7477CFA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
"{41933D99-542D-475F-832A-C3F553AB4560}" = protocol=17 | dir=in | app=e:\battlefield 3\command and conquer red alert\ra95launcher.exe | 
"{41C377B6-9509-46C2-BF7F-806D14EFE6BB}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\elven legacy\elvenlegacy.exe | 
"{41F0EFDC-488E-4B86-94CD-CD2A4061BFED}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2787\agent.exe | 
"{429497ED-636E-4ED7-A829-C12B3411083D}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe | 
"{43BD0379-942A-423B-8523-13B09D3D17D5}" = protocol=17 | dir=in | app=g:\squareenix\final fantasy xiv - a realm reborn\boot\ffxivlauncher.exe | 
"{44324AAE-7AB0-45C8-A7D8-5EECB74D9A74}" = protocol=6 | dir=in | app=c:\users\troy\appdata\local\teamspeak 3 client\ts3client_win64.exe | 
"{44AF0782-E467-412C-AEB4-C6931DDA9F4F}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2328\agent.exe | 
"{468B87D2-2388-44B1-B2CD-3B7F6C8746B2}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2426\agent.exe | 
"{47D64354-B030-4FC8-B051-E6F377316D19}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\darksiders 2\darksiders2.exe | 
"{489D8692-5B45-4EC8-B51D-8C6F944F23E8}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\path of exile\pathofexilesteam.exe | 
"{49DC0D4F-93DE-4156-B7D9-B22F28B4C199}" = protocol=6 | dir=in | app=e:\battlefield 3\plants vs. zombies\plantsvszombies.exe | 
"{4A198B63-3187-4CD8-B2FC-0678D4DFFA68}" = protocol=17 | dir=in | app=e:\battlefield 3\command and conquer 3 tw and kw\cnc3launcher.exe | 
"{4B127964-0571-4229-9CC6-B2858CABC243}" = protocol=17 | dir=in | app=e:\battlefield 3\mass effect 3\binaries\win32\masseffect3.exe | 
"{4B34A09C-F5B5-46F1-B0B1-11C2D9F2DF31}" = protocol=17 | dir=in | app=e:\battlefield 3\battlefield 4\bf4_x86.exe | 
"{4B6ED625-73CA-485A-AD7E-C62DAAAC335F}" = protocol=6 | dir=in | app=e:\happycloud\cache\tera\client\binaries\tera.exe | 
"{4C11A516-C43F-43AE-9A76-A1DCA7B81A3F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\darksiders\darksiderspc.exe | 
"{4CBC8D5B-9139-4B3A-AEF5-67D1AD6F8861}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\sanctum2\binaries\win32\sanctumgame-win32-shipping.exe | 
"{4CCB5F3B-8B5C-4EC9-B76D-AE1209B0E0E0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{4D95BC45-5EB8-485C-88F1-0B6ACAED7BC3}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | 
"{4F42A243-398B-4408-9477-DEDF6330EBB4}" = protocol=17 | dir=in | app=e:\happycloud\cache\tera\tera-launcher.exe | 
"{506DB592-6B40-4163-BBFD-556BA5FD170A}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe | 
"{519B6891-05F4-4A5C-A57A-7C16BF9FBD42}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3322\agent.exe | 
"{51A241B4-6127-4C7E-A363-680F1E346557}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe | 
"{51EB6B9C-DEF4-4903-8F88-90DB24E4609A}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{52D6AF5E-5F4A-454C-9579-5ADC7C8744DE}" = protocol=17 | dir=in | app=e:\battlefield 3\command and conquer red alert ii\ra2launcher.exe | 
"{5329EBCE-372D-49AE-9E64-B622302AA2CB}" = protocol=6 | dir=in | app=e:\battlefield 3\command and conquer red alert\ra95launcher.exe | 
"{53348CA2-526A-4350-8B2B-F9978406286A}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{536A9F29-9F07-4922-9D39-CCC46C09D3F1}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3372\agent.exe | 
"{53B85664-6902-4BF8-A15E-5155A5B1A135}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{5403601A-5A7A-466C-8CF9-6B7EE7DA021F}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{571BE840-FF05-4FCA-B14D-2846C288530B}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2514\agent.exe | 
"{582403E0-EBCC-454A-9F9F-2BD9E449B982}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2293\agent.exe | 
"{5859D96E-A75D-484C-A6D3-D0199B6ED6F9}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\borderlands\binaries\borderlands.exe | 
"{58982F0A-7401-45A0-A6F0-03E566139FE1}" = protocol=6 | dir=in | app=e:\battlefield 3\dead space 2\deadspace2.exe | 
"{590CA532-4819-43B2-95DF-948BB0B01010}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{5C4988D4-208A-47F0-A632-1A3B4A19A0E3}" = protocol=6 | dir=in | app=g:\squareenix\final fantasy xiv - a realm reborn\boot\ffxivlauncher.exe | 
"{5C5CB42D-946C-4BB6-9FB3-0A2C60174F86}" = protocol=6 | dir=in | app=e:\battlefield 3\command and conquer the ultimate collection additional content\launcher.exe | 
"{5CF642A3-33C6-47FC-B945-645DE39A08CB}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe | 
"{5F61606E-87C6-46EB-A35C-433ABE188E8E}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.913\agent.exe | 
"{6028726E-3211-4B7F-940C-F1E965E45F83}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\elven legacy\siege.exe | 
"{60FCA1D5-B976-4C87-8DE0-D5F2ACBA72FB}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1199\agent.exe | 
"{618D58DE-DF9D-4F3A-9992-683042A7421A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{622F7970-955A-4661-86C8-6A346F253207}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{62EB3BD8-2AD6-466E-834F-073B5F4C183A}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2717\agent.exe | 
"{6362CF78-A465-4A54-9FD5-F4F129DA7E01}" = protocol=6 | dir=in | app=e:\battlefield 3\dead space\dead space.exe | 
"{642EE97C-4543-48B9-A2DF-DD8DC7D44923}" = protocol=1 | dir=in | [email protected],-28543 | 
"{64630561-8F5E-49F9-A485-EDA12A70F489}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2417\agent.exe | 
"{666BD240-A277-4B2C-96B9-EE11D1319DE1}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | 
"{6683139C-9E2B-468D-AEAB-25165067F02C}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\the witcher 2\launcher.exe | 
"{66BE96B4-F9C4-441F-B662-79AB640E6369}" = protocol=17 | dir=in | app=e:\watch_dogs\bin\watch_dogs.exe | 
"{6739A6BB-F46C-4749-8ECF-676C3E4E0128}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3346\agent.exe | 
"{67413B32-04E9-4824-940D-4620F9924E4E}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2880\agent.exe | 
"{68A0E149-4560-44FB-ADE7-CE87F1B2FA07}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1225\agent.exe | 
"{68BCD1F7-D286-4C47-AAC3-A3959604D007}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3235\agent.exe | 
"{6902B80A-BE18-4DC2-A04E-E14D2A6AF85D}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\crysis 2 game of the year\bin32\crysis2launcher.exe | 
"{69468DA2-5A39-4EA4-8581-8A60880137A3}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{6977AB47-4306-423F-B757-BCEDED887D1A}" = protocol=17 | dir=in | app=e:\happycloud\cache\tera\client\tl.exe | 
"{6A090DE7-49B1-4178-8597-37985D6AC0E3}" = protocol=58 | dir=in | app=system | 
"{6DBC8257-DFA0-4046-8DDC-E432C599B31F}" = protocol=6 | dir=in | app=e:\battlefield 3\command and conquer generals zero hour\generals.exe | 
"{6EDD6646-411B-47E6-B556-593D81E20ACD}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\path of exile\pathofexilesteam.exe | 
"{718A39A5-B365-41D3-A9E7-0054D8851E5C}" = protocol=6 | dir=in | app=c:\users\troy\appdata\roaming\utorrent\utorrent.exe | 
"{72047C2A-C55D-4F50-8A62-57F51E281731}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2380\agent.exe | 
"{737E7F58-80E4-4B76-A533-854B0355673B}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\path of exile\pathofexilesteam.exe | 
"{759458E6-91D3-453A-B855-459D5D90FEE9}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\the witcher enhanced edition\system\djinni!.exe | 
"{76AD742F-4FBB-4D3B-AF24-6CBB9A02EA18}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe | 
"{76FFD9EA-F631-47E1-BB5D-50A759B5BBC9}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe | 
"{773F5F6C-98F4-47F4-8CDF-7458579AB592}" = protocol=6 | dir=in | app=e:\battlefield 3\command and conquer red alert ii\ra2launcher.exe | 
"{77A1E316-3006-4082-9C43-C3B723BCDE20}" = protocol=17 | dir=in | app=e:\battlefield 3\command and conquer tiberian sun\tslauncher.exe | 
"{79C4DD45-DDD5-4227-B98D-FC84E4B79E57}" = protocol=17 | dir=in | app=e:\battlefield 3\battlefield 4\bf4.exe | 
"{7B64B74F-4354-42B2-A985-0F83344D7208}" = protocol=6 | dir=in | app=e:\watch_dogs\bin\watch_dogs.exe | 
"{7C21D8AF-449B-4170-9078-3E9C86F8EFC2}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\dawn of war 2\dow2.exe | 
"{7E2E9448-895F-4B7D-80F1-C7B801744F69}" = protocol=6 | dir=in | app=c:\users\troy\appdata\roaming\utorrent\utorrent.exe | 
"{7E5F2530-AF0B-4466-B05B-5BF1737CA0A2}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{7EA4A231-3BC3-40F5-B94B-921BC16E076D}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\the witcher enhanced edition\system\djinni!.exe | 
"{7F03409D-1200-4613-ABEA-74C85E56F1CA}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{7F2D720C-B89B-4437-9399-7055A5F4FFD1}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\path of exile\pathofexilesteam.exe | 
"{7FA3EB72-DFD7-4403-89F5-CE7E37EE2629}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe | 
"{7FC87D44-11ED-4725-B059-336CBF41954B}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3023\agent.exe | 
"{80765847-5B65-4920-A544-756558A41069}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\borderlands\binaries\borderlands.exe | 
"{80BDE9C5-C4B2-4ED7-B9A7-BF8732A9A132}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | 
"{8150AD35-BDA3-4B8D-9FC4-BD0A265DFA7B}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\dark souls prepare to die edition\data\darksouls.exe | 
"{81619E42-FEE3-4DCB-95AA-DE7303129E78}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\dawn of war 2\dow2.exe | 
"{82B8C555-CC21-402F-9713-64D91D91EF76}" = protocol=17 | dir=in | app=c:\world of warcraft\launcher.patch.exe | 
"{8329C0E4-B4D5-406B-B9A6-C42966AF64E3}" = protocol=6 | dir=in | app=e:\battlefield 3\dead space 3\deadspace3.exe | 
"{83437FD8-BB63-41E4-9025-8FD3E5DEE4C9}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{83AB98A7-7579-4A9A-9537-DB3A11B41E64}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2717\agent.exe | 
"{8480B720-C981-495F-BE85-973AD4ADA204}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\path of exile\pathofexilesteam.exe | 
"{85A57E3A-ECDD-428F-8C29-0A404BFC009D}" = protocol=17 | dir=in | app=c:\users\troy\appdata\roaming\utorrent\utorrent.exe | 
"{86ECF272-3E19-42D1-8002-A762F4453BB1}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\elven legacy\magic.exe | 
"{878BB909-974E-451D-A1D3-15A749775265}" = protocol=17 | dir=in | app=e:\battlefield 3\mass effect\binaries\masseffect.exe | 
"{87A7D416-A8F3-4F74-A318-E2CB3C35EF69}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\elven legacy\ranger.exe | 
"{882829C1-8782-4E2B-91BB-0331230DEA46}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3323\agent.exe | 
"{88861821-5525-45AF-8B02-24F9B15D2A81}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{896B41F0-E11F-4D70-8C2E-334AD1D29274}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{8B000C9C-DE99-4144-9C12-65142866EB73}" = protocol=17 | dir=in | app=g:\vindictus\en-us\nmservice.exe | 
"{8B2ED7C7-4010-4204-A116-181B693C19CB}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | 
"{8BEC632B-599D-4F7B-B00A-4E0A9B1D3E3F}" = protocol=17 | dir=in | app=e:\assassin's creed iv black flag\ac4bfsp.exe | 
"{8CFDBD81-F465-4453-BBCD-7A8D3E8EEEB1}" = protocol=17 | dir=in | app=e:\battlefield 3\dead space\dead space.exe | 
"{8D2C133E-51ED-4263-9897-63F368ED1BE4}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{8DC4DB0D-DF73-40F8-AB4B-BA0119E00970}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2359\agent.exe | 
"{8DD5C409-4D54-4481-A647-9FAE1F0EA56F}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe | 
"{8E9796BC-31E5-4D2E-86AD-BE524AA59F87}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2417\agent.exe | 
"{8F391F0E-2045-47D3-8E80-0619CC71B02D}" = protocol=6 | dir=in | app=e:\happycloud\cache\tera\client\tl.exe | 
"{92BF634E-9420-4903-B044-C44AABC97091}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{9348AFDF-4D26-4105-A204-89859E2E7E15}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\darksiders\darksiderspc.exe | 
"{94268D85-AAC1-4BDF-B32A-83FE968BB466}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{942CA96E-0A4E-437D-9FD2-D236A532E666}" = protocol=17 | dir=in | app=e:\battlefield 3\command and conquer red alert 3\ra3launcher.exe | 
"{962FAA22-3CA7-4630-9C01-7CFF1E419317}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe | 
"{97169A9E-0F5F-4CF6-9C1C-26DC3D2F49D2}" = protocol=6 | dir=in | app=e:\battlefield 3\command and conquer tiberian sun\tslauncher.exe | 
"{98625483-A8E4-4FEF-921F-A36DECD79405}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.913\agent.exe | 
"{9A58FF03-2526-41DA-9235-F599E6C4602B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\darksiders\darksiderspc.exe | 
"{9AA2623E-9869-4706-A10B-3D5C14078893}" = protocol=17 | dir=in | app=e:\steam\bin\steamwebhelper.exe | 
"{9BBF5C6A-3EC0-46CA-8436-93BB5E6840AB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{9CCCBF98-A2C9-4F7A-85AB-B5AC1C442720}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe | 
"{9DD1A284-A1DB-4320-BB59-199484A92B10}" = protocol=6 | dir=in | app=e:\battlefield 3\command and conquer 3 tw and kw\cnc3launcher.exe | 
"{9DDB9EA6-E49E-4966-8393-4C71E6AABE84}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe | 
"{9E4AB3D3-683B-4BC7-99A4-EA8F92A8AE74}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2426\agent.exe | 
"{9E6940EC-6F4B-4D97-AA4D-5FC1A212A20F}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\dawn of war ii - retribution\dow2.exe | 
"{9F0DE8C4-89B3-49AC-BD19-AF488849B38F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2737\agent.exe | 
"{A26B12A5-80D6-4DED-9033-1A9548CD0089}" = protocol=6 | dir=in | app=g:\squareenix\final fantasy xiv - a realm reborn\boot\ffxivboot.exe | 
"{A28A90A9-22FF-4EA5-8483-E218039D4E2E}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\skyrim\creationkit.exe | 
"{A66F95FE-15EA-4199-9181-250E4945083C}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3322\agent.exe | 
"{A9558F2D-31EE-4664-BC2E-1647CD4A43FE}" = protocol=17 | dir=in | app=e:\battlefield 3\cnc and the covert operations\cnc95launcher.exe | 
"{A9B5EF5B-E50C-4B2A-9AB4-0C08FF326A2C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\darksiders 2\darksiders2.exe | 
"{A9F37CAF-E6AB-4C77-88A6-64E2BA62836A}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe | 
"{A9F76EC2-AB46-434D-A2EC-616F614E8724}" = protocol=17 | dir=in | app=e:\battlefield 3\command and conquer the ultimate collection additional content\launcher.exe | 
"{AB0B62EA-BC6F-4DC2-81E6-7A666F74FEDE}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\left 4 dead 2\left4dead2.exe | 
"{AB2E3F5D-4752-4026-B8DF-9B24E129E336}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe | 
"{AB6C7FA5-BFEF-4B19-8EED-2636D94291D4}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\path of exile\pathofexilesteam.exe | 
"{AD48B6EA-64B0-4054-913C-2A5366B78B6B}" = protocol=17 | dir=in | app=c:\users\troy\appdata\local\teamspeak 3 client\ts3client_win64.exe | 
"{AD4C8CE9-2B5E-447E-B447-A2503FAB44E7}" = protocol=6 | dir=in | app=e:\battlefield 3\titanfall\titanfall.exe | 
"{AEFD200F-1A8D-46A9-9A8E-15AAF170CCB1}" = protocol=17 | dir=in | app=g:\battle.net\battle.net.exe | 
"{B10224A0-5DDF-408A-A828-28B0087DAEB5}" = protocol=17 | dir=in | app=e:\assassin's creed iv black flag\ac4bfmp.exe | 
"{B19F6900-421A-4D24-A5E9-A9FEA9F812E0}" = protocol=17 | dir=in | app=e:\battlefield 3\command and conquer generals zero hour\generals.exe | 
"{B27ACFB8-6A56-4A6B-9DD1-10C570D94DF6}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\path of exile\pathofexilesteam.exe | 
"{B30AE595-B739-4FB4-A461-435244827CD0}" = protocol=6 | dir=in | app=e:\diablo\diablo iii\diablo iii.exe | 
"{B4AFC123-1296-4192-86BC-BC66572BF8DF}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3346\agent.exe | 
"{B562BFF1-7803-4A25-848F-AC848ACAA4BD}" = protocol=6 | dir=in | app=g:\battle.net\battle.net.exe | 
"{B776ED17-B9C3-4649-8D92-32434BE3702E}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | 
"{B7C3A021-5C4C-4EB7-9B13-B2D91F3367FA}" = protocol=58 | dir=in | [email protected],-28545 | 
"{B7D7E6A3-E56E-49FF-A2E4-D0368CD22010}" = protocol=6 | dir=in | app=e:\happycloud\cache\tera\tera-launcher.exe | 
"{B83578C2-26D3-4DAA-B1B7-2A5C0B870C47}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{B85352AF-9323-48CC-84B6-1773F348EB86}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe | 
"{B89CC0C4-6146-400E-9731-2C44A8775ACD}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\elven legacy\mapeditor.exe | 
"{B9FB20F7-A094-4E6F-BA53-EE0893DD2E76}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{BA20B790-3CB8-4CC4-B408-C58D546A6EE4}" = protocol=17 | dir=in | app=g:\squareenix\final fantasy xiv - a realm reborn\game\ffxiv.exe | 
"{BACE2DB0-45C4-42CC-9D85-34332659357F}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{BB87A87B-B530-4F4B-8D37-5BC166DA3230}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2514\agent.exe | 
"{BBD690A6-609B-4DCA-AB2A-0388E3828658}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe | 
"{BE61FA0B-3E5E-44D0-ABB8-A7DF7B2999FB}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2689\agent.exe | 
"{BF1A9D03-B95B-459C-BF6D-0C0C9166380D}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1225\agent.exe | 
"{C0226873-7500-4440-8EBF-9FEDA0063F9B}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | 
"{C0A009F4-28C9-4A2F-BAB6-0A58C0E30690}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\skyrim\skyrimlauncher.exe | 
"{C320639C-C7DA-47F8-9F39-3770CC595D92}" = protocol=6 | dir=in | app=e:\assassin's creed iv black flag\ac4bfsp.exe | 
"{C36E8327-9083-4683-B1D1-ADED43536049}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | 
"{C36EAE69-AC91-466C-AE30-EE6220A1ABF0}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\sanctum2\binaries\win32\sanctumgame-win32-shipping.exe | 
"{C39A2B53-48D8-40B9-B3E6-471AB874E9F1}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3332\agent.exe | 
"{C4661CC0-D506-4F7B-BB45-7D99E25C9E9E}" = protocol=6 | dir=in | app=e:\battlefield 3\command conquer 4 tiberian twilight\cnc4.exe | 
"{C4963496-B4DF-47DC-BBE9-87AFE200A526}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | 
"{C5D9DC14-6F16-47FF-B3D8-0A7ECD5ECD5D}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2816\agent.exe | 
"{C65364A0-7696-41B0-A3C2-3B99D9AA9B5D}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{C67C67F0-A897-4400-AE52-FF87AC41229C}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\left 4 dead 2\left4dead2.exe | 
"{C67E229A-8D35-46D6-927B-10DBC1522AB0}" = protocol=6 | dir=in | app=e:\hearthstone\hearthstone.exe | 
"{C93A6636-BD22-4D7C-A8A6-EC4203B52623}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe | 
"{CBBD593B-E8DE-44EB-A857-EF3F85F643A5}" = protocol=17 | dir=in | app=e:\battlefield 3\titanfall\titanfall.exe | 
"{CCEF7913-64B5-4A32-A220-BF6467CED273}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{CD372C40-4F22-4C4E-B5F9-14206562AE2D}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\skyrim\creationkit.exe | 
"{CEBF1515-5B83-4E71-810F-DD719B5045C3}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{CF9C7DA5-E2B4-4C4B-8B46-1452E58E9014}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2880\agent.exe | 
"{D067B7B6-7283-4AA1-9DC9-54DA7BBE3138}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\elven legacy\siege.exe | 
"{D0DE5CE0-1FC8-4487-8E07-FBC64D2B523A}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{D17133B5-46C6-4800-BE1F-192E25901523}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\elven legacy\mapeditor.exe | 
"{D1E0E9D3-D498-4C49-9448-CB6E855C064E}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2737\agent.exe | 
"{D2BF19BE-922C-47BE-8154-B8B87022662B}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{D3BC0587-E10B-4373-834A-CECC963346C7}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2000\agent.exe | 
"{D46193A6-C0D1-43B8-A1E4-CE4DBDB0DD5C}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2006\agent.exe | 
"{D58BC992-DB0D-44CA-8DB7-8FDAA59ADCAB}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{D5D7E746-1DD9-4EE8-994A-F854CA74B449}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
"{D61BF78D-5513-4C74-9509-C79BA6D3068A}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\crysis 2 game of the year\bin32\crysis2launcher.exe | 
"{D632E06A-AED3-466B-AB11-04D44E358E67}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2787\agent.exe | 
"{D6CACCF9-8BA0-4BDC-AA34-77CCF9513A54}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2328\agent.exe | 
"{D74C91CC-0020-4FBF-89ED-C1D49CC109E0}" = protocol=17 | dir=in | app=e:\battlefield 3\battlefield 3\bf3.exe | 
"{D7D77341-9782-4971-AED2-8CC30ED6823F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2680\agent.exe | 
"{D83218AC-5091-452E-B7E2-89E12DC75BF9}" = protocol=6 | dir=in | app=e:\battlefield 3\battlefield 4\bf4.exe | 
"{D862DF4E-E5F9-4540-BD7D-B4992A6E4889}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
"{D929CFBA-CABC-425E-9901-CCD8C962BDF2}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2638\agent.exe | 
"{DA7406E9-5584-4A02-87AA-9719955BC822}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\killingfloor\system\killingfloor.exe | 
"{DB1AD580-59C6-4721-90B9-EDAFF36A4E53}" = protocol=6 | dir=in | app=g:\vindictus\en-us\nmservice.exe | 
"{DB7A10AC-125D-4E5B-89EE-A0C6E347B7A0}" = protocol=6 | dir=in | app=e:\assassin's creed iv black flag\ac4bfmp.exe | 
"{DBB94E05-EF6B-48E9-93A8-C58A80B45CB5}" = protocol=17 | dir=in | app=e:\battlefield 3\dead space 2\deadspace2.exe | 
"{DBDA1D59-D883-4E79-BF92-D9A31AD4A582}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{DC63BF99-4893-478D-9937-46AB7C745A3E}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3323\agent.exe | 
"{DD1A5B85-427E-43A9-9B96-447D71976BBA}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe | 
"{DE3DBA1E-F6D1-432D-B73C-E18F53943EA9}" = protocol=17 | dir=in | app=e:\diablo\diablo iii\diablo iii.exe | 
"{DFA21110-E702-47DA-BD41-5623613A793A}" = protocol=6 | dir=out | app=system | 
"{E015C16F-36A2-4B26-AF75-F99752206AC5}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2787\agent.exe | 
"{E10F09E1-337A-4381-8005-A0D477710CF3}" = protocol=17 | dir=in | app=c:\world of warcraft\launcher.patch.exe | 
"{E85CF716-BCD4-4824-A055-C51A5BEA7BC1}" = protocol=1 | dir=out | [email protected],-28544 | 
"{E90C3F46-58F2-4F33-B270-0517D13D455C}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{EA3FBD6B-274D-4472-93AA-9329C3FF5E4B}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\dawn of war ii - retribution\dow2.exe | 
"{EB10C8C1-4D07-42B7-991F-31EC7657906D}" = protocol=6 | dir=in | app=e:\battlefield 3\command and conquer red alert 3\ra3launcher.exe | 
"{ECA4A9D6-8417-46B5-BC3F-AB4D44237396}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2689\agent.exe | 
"{ECB39620-DC05-4321-B0C9-794ABEDD0BBF}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\assassin's creed revelations\acrmp.exe | 
"{EDBEC5DD-0789-4768-B8C1-D5E3DA28B6A8}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\elven legacy\elvenlegacy.exe | 
"{EE2B69F5-371D-4263-9D9C-8EAE00312072}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\elven legacy\magic.exe | 
"{EF184422-A187-4824-90DC-F5B74B276B0A}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\dota 2 beta\dota.exe | 
"{F1DD4056-9248-4F89-8CA3-39B4EFA6AE57}" = protocol=6 | dir=in | app=e:\battlefield 3\mass effect 2\binaries\masseffect2.exe | 
"{F2BABA05-1B0D-4A3F-8FCD-B534B97E77AE}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2006\agent.exe | 
"{F4A5D691-E8F8-4D61-8955-ED7143B613D4}" = protocol=17 | dir=in | app=e:\battlefield 3\mass effect 2\binaries\masseffect2.exe | 
"{F570E174-3FDE-4226-B5BD-3BBE127814CF}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\blades of time\bladesoftime.exe | 
"{F598FAD1-47FD-44B6-96C1-C32A8B45AD3F}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\elven legacy\ranger.exe | 
"{F63ADF69-2B78-4EC2-B391-F6E46CD13A0A}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3023\agent.exe | 
"{F7D38D58-A3F8-4822-B65D-B39DF00A0D37}" = protocol=17 | dir=in | app=e:\happycloud\cache\tera\client\binaries\tera.exe | 
"{F815BFC0-0B53-426E-9E3B-F4A60A09217E}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\dark souls prepare to die edition\data\darksouls.exe | 
"{F89804CF-C647-4193-BF8E-525172EBF4B4}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1199\agent.exe | 
"{FB35B013-A7A4-4B93-9A3E-F648A13B8973}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3372\agent.exe | 
"{FBD4E05B-6A37-46E1-985C-238B4BF6E887}" = protocol=17 | dir=in | app=e:\battlefield 3\dead space 3\deadspace3.exe | 
"{FD7EE97D-CF7B-4B4D-BED0-3C1D21E270ED}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe | 
"{FE2A8F60-4DCB-46EA-B1F4-D82FF6E032A5}" = protocol=17 | dir=in | app=e:\battlefield 3\plants vs. zombies\plantsvszombies.exe | 
"{FFAF2ED3-6CD4-4241-801B-1A07DC224A2D}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2359\agent.exe | 
"{FFDAE7BE-3F09-4914-BD27-B15F0F8C7A29}" = protocol=6 | dir=in | app=e:\battlefield 3\mass effect\binaries\masseffect.exe | 
"TCP Query User{004A15B0-9C69-4823-BFC5-D8D79C03631F}E:\kingdoms of amalur reckoning\reckoning.exe" = protocol=6 | dir=in | app=e:\kingdoms of amalur reckoning\reckoning.exe | 
"TCP Query User{05E2FE5D-DBF4-47C9-BBDB-B67014571B67}D:\setup.exe" = protocol=6 | dir=in | app=d:\setup.exe | 
"TCP Query User{06164E29-6AB8-4230-9572-59A2C619F1CC}G:\whorecraft\episode 1\binaries\win32\udk.exe" = protocol=6 | dir=in | app=g:\whorecraft\episode 1\binaries\win32\udk.exe | 
"TCP Query User{06C81586-387A-4727-B8EF-B2388E26820E}E:\warcraft iii better\war3.exe" = protocol=6 | dir=in | app=e:\warcraft iii better\war3.exe | 
"TCP Query User{10782E07-70A5-4A88-BE54-63FEDCD5A4AB}G:\world of warcraft\launcher.patch.exe" = protocol=6 | dir=in | app=g:\world of warcraft\launcher.patch.exe | 
"TCP Query User{14192580-5331-41CC-BE85-04BB77432C68}E:\wow\temp\wow-4.2.1.2756-enus-tools-downloader.exe" = protocol=6 | dir=in | app=e:\wow\temp\wow-4.2.1.2756-enus-tools-downloader.exe | 
"TCP Query User{16247446-733C-4F1C-98C5-2C43682E2FA4}C:\program files (x86)\ncwest\nclauncher\ncupdatehelper.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ncwest\nclauncher\ncupdatehelper.exe | 
"TCP Query User{1A436DA8-FC94-4512-A232-44C77E3DF8B4}C:\users\troy\downloads\diablo-iii-8370-enus-installer-downloader (1).exe" = protocol=6 | dir=in | app=c:\users\troy\downloads\diablo-iii-8370-enus-installer-downloader (1).exe | 
"TCP Query User{1F6C2381-4C02-47F6-A79A-FE11FBE415C2}E:\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe" = protocol=6 | dir=in | app=e:\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe | 
"TCP Query User{22F45D47-FA23-4373-8388-E754C644F935}E:\starcraft ii\versions\base22612\sc2.exe" = protocol=6 | dir=in | app=e:\starcraft ii\versions\base22612\sc2.exe | 
"TCP Query User{2C055180-9398-4962-ABE4-A4844E3420D6}C:\programdata\battle.net\agent\agent.3182\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3182\agent.exe | 
"TCP Query User{2D8ABCC9-9F83-4A8E-ABC4-76689E58847C}E:\starcraft ii\versions\base26490\sc2.exe" = protocol=6 | dir=in | app=e:\starcraft ii\versions\base26490\sc2.exe | 
"TCP Query User{32039103-5556-4A3A-BCDE-2E94E3CE76AB}C:\programdata\battle.net\agent\agent.beta.2581\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2581\agent.exe | 
"TCP Query User{353FE64C-712D-4D19-87D5-9D4EA771F95A}E:\starcraft ii\versions\base23260\sc2.exe" = protocol=6 | dir=in | app=e:\starcraft ii\versions\base23260\sc2.exe | 
"TCP Query User{54EDF420-53CF-42E2-92C7-B739D73D41D3}G:\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe" = protocol=6 | dir=in | app=g:\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe | 
"TCP Query User{551E3680-EE70-45CA-8B4E-5B7D90D19B97}E:\wow\launcher.patch.exe" = protocol=6 | dir=in | app=e:\wow\launcher.patch.exe | 
"TCP Query User{55D985A6-BE87-4AC9-B649-1AA85FF9A8AD}E:\starcraft ii\versions\base22612\sc2.exe" = protocol=6 | dir=in | app=e:\starcraft ii\versions\base22612\sc2.exe | 
"TCP Query User{57FC984C-B58D-4E14-B487-06452EB8BFC9}E:\wow\temp\wow-4.2.1.2727-enus-tools-downloader.exe" = protocol=6 | dir=in | app=e:\wow\temp\wow-4.2.1.2727-enus-tools-downloader.exe | 
"TCP Query User{582744BC-3538-47A8-B271-F76D7E9641EC}E:\starcraft ii\versions\base24944\sc2.exe" = protocol=6 | dir=in | app=e:\starcraft ii\versions\base24944\sc2.exe | 
"TCP Query User{66E72231-4713-432A-B482-964931ED398F}E:\wow\launcher.exe" = protocol=6 | dir=in | app=e:\wow\launcher.exe | 
"TCP Query User{6D5935F3-9A24-4FB7-8B46-67464ACD806A}C:\programdata\battle.net\agent\agent.868\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.868\agent.exe | 
"TCP Query User{6DAC5149-528B-42B6-9DC0-C6F3008F59FB}E:\starcraft ii\versions\base28667\sc2.exe" = protocol=6 | dir=in | app=e:\starcraft ii\versions\base28667\sc2.exe | 
"TCP Query User{71B1DA14-BA09-40DE-B77E-881D3E77EFDC}C:\users\troy\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\troy\appdata\local\akamai\netsession_win.exe | 
"TCP Query User{722E1644-5658-46D8-9F7F-D258E61F06EC}E:\starcraft ii\versions\base21029\sc2.exe" = protocol=6 | dir=in | app=e:\starcraft ii\versions\base21029\sc2.exe | 
"TCP Query User{82FA8B50-7EE2-4CFB-8633-DDC3DEBD433A}C:\programdata\battle.net\agent\agent.3109\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3109\agent.exe | 
"TCP Query User{86C87AC2-352F-4881-A9EC-96BAD60C1FBE}E:\wowpron2\binaries\win32\udk.exe" = protocol=6 | dir=in | app=e:\wowpron2\binaries\win32\udk.exe | 
"TCP Query User{8925E21D-9664-4BEF-93D9-9586DBC32AEB}C:\program files (x86)\whorecraft\binaries\win32\udk.exe" = protocol=6 | dir=in | app=c:\program files (x86)\whorecraft\binaries\win32\udk.exe | 
"TCP Query User{8A556F1D-0BF1-4401-9470-813551CDEC2E}E:\wow\backgrounddownloader.exe" = protocol=6 | dir=in | app=e:\wow\backgrounddownloader.exe | 
"TCP Query User{8C203C9E-01A2-4EC0-B545-E7150F314F13}C:\programdata\battle.net\agent\agent.749\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.749\agent.exe | 
"TCP Query User{91D8C455-6768-4F32-B206-460F2B4EB3AB}C:\users\troy\downloads\diablo-iii-8370-enus-installer-downloader.exe" = protocol=6 | dir=in | app=c:\users\troy\downloads\diablo-iii-8370-enus-installer-downloader.exe | 
"TCP Query User{9472AA57-0616-4088-A46D-3EBB9CC9F63A}C:\programdata\battle.net\agent\agent.3182\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3182\agent.exe | 
"TCP Query User{969AFC79-48C8-44C6-BB2F-4275E5A18C73}E:\steam\steam.exe" = protocol=6 | dir=in | app=e:\steam\steam.exe | 
"TCP Query User{9F642129-B5DA-402E-BDCE-48B38D3EED60}E:\wow\temp\wow-4.3-5.0.15890-enus-downloader.exe" = protocol=6 | dir=in | app=e:\wow\temp\wow-4.3-5.0.15890-enus-downloader.exe | 
"TCP Query User{A45F674D-7120-4D0B-9548-1531F43B0711}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe | 
"TCP Query User{A6F349FD-6B47-483E-817B-9F40B29ED138}C:\programdata\battle.net\agent\agent.beta.2753\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2753\agent.exe | 
"TCP Query User{A7708A85-DF2E-435F-8123-51B6AEC0D2A1}G:\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe" = protocol=6 | dir=in | app=g:\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe | 
"TCP Query User{B7AE3EF1-ECB1-4EF4-BEEF-23BA4F0D937C}C:\programdata\battle.net\agent\agent.3286\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3286\agent.exe | 
"TCP Query User{B9C4F714-A0E2-4027-AC2D-E5EC0D5D170B}C:\program files (x86)\ncwest\nclauncher\ncupdatehelper.exe" = protocol=6 | dir=in | app=c:\program files (x86)\ncwest\nclauncher\ncupdatehelper.exe | 
"TCP Query User{BB46E47E-555C-4B22-B01D-4F5FF9A2BA8D}E:\battlefield 3\command conquer 4 tiberian twilight\data\cnc4.game" = protocol=6 | dir=in | app=e:\battlefield 3\command conquer 4 tiberian twilight\data\cnc4.game | 
"TCP Query User{BBD333A8-FA0F-4DA6-AD2B-970D912F1524}E:\launcher.patch.exe" = protocol=6 | dir=in | app=e:\launcher.patch.exe | 
"TCP Query User{BC32E561-DC7A-4CC5-AEDB-47B8EE666A87}E:\wow\wow-4.2.1.2736-enus-tools-downloader.exe" = protocol=6 | dir=in | app=e:\wow\wow-4.2.1.2736-enus-tools-downloader.exe | 
"TCP Query User{C2A18ED7-1183-4FDE-9FFC-C30789A6BCDF}C:\programdata\battle.net\agent\agent.1040\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe | 
"TCP Query User{C2AD5DD4-A77E-4251-ACB5-F91A47B69B1F}G:\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=g:\world of warcraft\launcher.exe | 
"TCP Query User{C3995420-22ED-4EC0-A704-D2DD4793447C}E:\starcraft ii\starcraft ii.exe" = protocol=6 | dir=in | app=e:\starcraft ii\starcraft ii.exe | 
"TCP Query User{C482B456-EA36-4895-A854-C225A20E034C}E:\wow\wow-4.2.1.2730-enus-tools-downloader.exe" = protocol=6 | dir=in | app=e:\wow\wow-4.2.1.2730-enus-tools-downloader.exe | 
"TCP Query User{C6184832-BD39-4549-87EF-E652EB04F0C4}E:\wowpron2\binaries\win64\udk.exe" = protocol=6 | dir=in | app=e:\wowpron2\binaries\win64\udk.exe | 
"TCP Query User{D1BAAA8D-EBAB-4324-AA42-61C4A785EA9B}C:\udk\aodp\binaries\win32\udk.exe" = protocol=6 | dir=in | app=c:\udk\aodp\binaries\win32\udk.exe | 
"TCP Query User{D395F702-FD21-447C-A857-B003C8E8FD1B}C:\programdata\battle.net\agent\agent.998\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe | 
"TCP Query User{D74A143A-10B8-44F7-ABDE-4A7EAB55C470}E:\steam\steamapps\common\borderlands\binaries\borderlands.exe" = protocol=6 | dir=in | app=e:\steam\steamapps\common\borderlands\binaries\borderlands.exe | 
"TCP Query User{D7B0D987-DAA7-4967-AC85-53873DA1A4A1}E:\warcraft iii\war3.exe" = protocol=6 | dir=in | app=e:\warcraft iii\war3.exe | 
"TCP Query User{D9608EFA-1CA4-41B6-88F4-D92B0E6D1314}E:\turok\binaries\turokgame.exe" = protocol=6 | dir=in | app=e:\turok\binaries\turokgame.exe | 
"TCP Query User{E330C2D2-AF81-4687-B9A0-9EA9D4C1E6AD}E:\wow\temp\wow-4.2.1.2706-enus-tools-downloader.exe" = protocol=6 | dir=in | app=e:\wow\temp\wow-4.2.1.2706-enus-tools-downloader.exe | 
"TCP Query User{E3F5D391-0F1B-4AC3-96A5-0AFB46C2A93D}G:\python\pythonw.exe" = protocol=6 | dir=in | app=g:\python\pythonw.exe | 
"TCP Query User{E6394603-70E5-47F2-82B0-587E416D7FE3}C:\programdata\battle.net\agent\agent.976\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe | 
"TCP Query User{EB0EFF17-998D-4FA4-9F83-FF97813F26B5}C:\program files (x86)\timegate studios\section 8\binaries\s8game-f.exe" = protocol=6 | dir=in | app=c:\program files (x86)\timegate studios\section 8\binaries\s8game-f.exe | 
"TCP Query User{EED93863-594B-44E2-846E-066E4A688FB4}E:\farcry 3\farcry 3\bin\farcry3.exe" = protocol=6 | dir=in | app=e:\farcry 3\farcry 3\bin\farcry3.exe | 
"TCP Query User{F1130E9E-4391-4B5F-9FA3-DB4B8072F496}E:\starcraft ii\support\blizzarddownloader.exe" = protocol=6 | dir=in | app=e:\starcraft ii\support\blizzarddownloader.exe | 
"TCP Query User{F587750B-B99D-4CAA-B79E-3F94EEF5DD3A}C:\users\troy\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\troy\appdata\local\akamai\netsession_win.exe | 
"TCP Query User{F9ED0110-FFC4-406B-A457-E190B0D1CADB}C:\program files (x86)\whorecraft\binaries\win64\udk.exe" = protocol=6 | dir=in | app=c:\program files (x86)\whorecraft\binaries\win64\udk.exe | 
"UDP Query User{01C142D9-DBAB-422D-94D7-368797777E09}C:\programdata\battle.net\agent\agent.868\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.868\agent.exe | 
"UDP Query User{02874EB4-6791-4B6B-8911-6B791EBE935E}E:\wow\backgrounddownloader.exe" = protocol=17 | dir=in | app=e:\wow\backgrounddownloader.exe | 
"UDP Query User{066B280D-14AA-4B38-9260-5011454A62EA}E:\starcraft ii\versions\base22612\sc2.exe" = protocol=17 | dir=in | app=e:\starcraft ii\versions\base22612\sc2.exe | 
"UDP Query User{0B43FCB5-FE23-431B-A085-727A86C0A440}C:\users\troy\downloads\diablo-iii-8370-enus-installer-downloader (1).exe" = protocol=17 | dir=in | app=c:\users\troy\downloads\diablo-iii-8370-enus-installer-downloader (1).exe | 
"UDP Query User{0D42E1B0-1A18-4C6C-B8FB-E08EC56F8043}E:\launcher.patch.exe" = protocol=17 | dir=in | app=e:\launcher.patch.exe | 
"UDP Query User{0DE5F6C4-8C37-439C-B3FC-6F48F675EA63}C:\udk\aodp\binaries\win32\udk.exe" = protocol=17 | dir=in | app=c:\udk\aodp\binaries\win32\udk.exe | 
"UDP Query User{119E5D75-7E65-4F8B-B644-811B87534C79}E:\starcraft ii\support\blizzarddownloader.exe" = protocol=17 | dir=in | app=e:\starcraft ii\support\blizzarddownloader.exe | 
"UDP Query User{20C26AD3-8673-44C4-AD3A-BDF64183597B}E:\wow\wow-4.2.1.2736-enus-tools-downloader.exe" = protocol=17 | dir=in | app=e:\wow\wow-4.2.1.2736-enus-tools-downloader.exe | 
"UDP Query User{23B9C6C0-257B-436D-A3BF-01D0130DCDD9}G:\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=g:\world of warcraft\launcher.exe | 
"UDP Query User{26E4E582-3D91-4E9A-B88E-7DB5884F3250}E:\turok\binaries\turokgame.exe" = protocol=17 | dir=in | app=e:\turok\binaries\turokgame.exe | 
"UDP Query User{28238A33-B806-441A-95C4-89D439D37183}C:\programdata\battle.net\agent\agent.749\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.749\agent.exe | 
"UDP Query User{2B8D37FF-F713-4D4A-B0DF-70951E87E070}E:\starcraft ii\versions\base22612\sc2.exe" = protocol=17 | dir=in | app=e:\starcraft ii\versions\base22612\sc2.exe | 
"UDP Query User{2F6CF42F-541C-473A-A0BC-C8B2BEF8AE8F}C:\programdata\battle.net\agent\agent.3109\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3109\agent.exe | 
"UDP Query User{349D115B-2EC0-4026-83BE-F0D8F577BF02}E:\starcraft ii\starcraft ii.exe" = protocol=17 | dir=in | app=e:\starcraft ii\starcraft ii.exe | 
"UDP Query User{388C48DC-78AC-470A-9737-7191EC93E94A}E:\wowpron2\binaries\win32\udk.exe" = protocol=17 | dir=in | app=e:\wowpron2\binaries\win32\udk.exe | 
"UDP Query User{46E31826-B1AC-402F-94B6-7612C09CB7F5}E:\wow\temp\wow-4.2.1.2756-enus-tools-downloader.exe" = protocol=17 | dir=in | app=e:\wow\temp\wow-4.2.1.2756-enus-tools-downloader.exe | 
"UDP Query User{4BBEFEF5-69E6-437E-B25E-F30AC874EFF1}E:\battlefield 3\command conquer 4 tiberian twilight\data\cnc4.game" = protocol=17 | dir=in | app=e:\battlefield 3\command conquer 4 tiberian twilight\data\cnc4.game | 
"UDP Query User{52295529-5ECF-452B-A0A1-9E4C167434CD}C:\programdata\battle.net\agent\agent.1040\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe | 
"UDP Query User{5281B709-1A9B-42C7-9185-EC3C1FC61D77}G:\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe" = protocol=17 | dir=in | app=g:\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe | 
"UDP Query User{56690321-AF86-4F95-969B-5FA0F97346EC}E:\farcry 3\farcry 3\bin\farcry3.exe" = protocol=17 | dir=in | app=e:\farcry 3\farcry 3\bin\farcry3.exe | 
"UDP Query User{5D9E1458-FEAB-4B18-8EAD-FD314E003A24}C:\users\troy\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\troy\appdata\local\akamai\netsession_win.exe | 
"UDP Query User{6B0F8920-DEE4-4F57-9481-070F1D3FAD88}E:\warcraft iii better\war3.exe" = protocol=17 | dir=in | app=e:\warcraft iii better\war3.exe | 
"UDP Query User{6D335EC9-AF94-41F1-ADD5-8EB24E37CDD9}E:\starcraft ii\versions\base21029\sc2.exe" = protocol=17 | dir=in | app=e:\starcraft ii\versions\base21029\sc2.exe | 
"UDP Query User{71DD1C5A-438F-467C-A565-91DBB7D9B5AF}C:\programdata\battle.net\agent\agent.998\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe | 
"UDP Query User{7378851E-D257-4D75-804F-8ADA7DC0E0F3}E:\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe" = protocol=17 | dir=in | app=e:\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe | 
"UDP Query User{73FB9F14-D98F-4F01-A150-667DD8064F53}G:\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe" = protocol=17 | dir=in | app=g:\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe | 
"UDP Query User{791EF013-2F5F-475B-B877-A96D206879BD}E:\wow\wow-4.2.1.2730-enus-tools-downloader.exe" = protocol=17 | dir=in | app=e:\wow\wow-4.2.1.2730-enus-tools-downloader.exe | 
"UDP Query User{7A134DB3-F7AA-4433-9870-D8CDBEF63930}E:\starcraft ii\versions\base24944\sc2.exe" = protocol=17 | dir=in | app=e:\starcraft ii\versions\base24944\sc2.exe | 
"UDP Query User{8703DB38-ADB3-4AA1-82B4-2AC93681AF11}C:\programdata\battle.net\agent\agent.beta.2581\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2581\agent.exe | 
"UDP Query User{87070B96-5916-466E-B166-B4F95E8C7B4D}C:\users\troy\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\troy\appdata\local\akamai\netsession_win.exe | 
"UDP Query User{8773B953-1564-4E1A-BE34-D9CE705879E0}E:\kingdoms of amalur reckoning\reckoning.exe" = protocol=17 | dir=in | app=e:\kingdoms of amalur reckoning\reckoning.exe | 
"UDP Query User{8D4F7A1B-D026-4BBC-B661-C39B4359446A}C:\program files (x86)\ncwest\nclauncher\ncupdatehelper.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ncwest\nclauncher\ncupdatehelper.exe | 
"UDP Query User{9899FEBC-2AC7-4A32-B5D2-01F67827F782}C:\programdata\battle.net\agent\agent.3182\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3182\agent.exe | 
"UDP Query User{9AF95823-2DA7-4E92-80DD-9A327859C192}E:\wow\launcher.exe" = protocol=17 | dir=in | app=e:\wow\launcher.exe | 
"UDP Query User{A58078CD-C12E-4C52-8298-6DC5925D78D4}C:\programdata\battle.net\agent\agent.976\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe | 
"UDP Query User{A7343A59-8142-495E-B0EB-6C2184FD2446}C:\users\troy\downloads\diablo-iii-8370-enus-installer-downloader.exe" = protocol=17 | dir=in | app=c:\users\troy\downloads\diablo-iii-8370-enus-installer-downloader.exe | 
"UDP Query User{AE892E83-61F9-4272-8010-7E70159C5D7C}E:\warcraft iii\war3.exe" = protocol=17 | dir=in | app=e:\warcraft iii\war3.exe | 
"UDP Query User{AFB29472-D96A-4BFF-B004-5375E70B1A99}E:\wow\temp\wow-4.3-5.0.15890-enus-downloader.exe" = protocol=17 | dir=in | app=e:\wow\temp\wow-4.3-5.0.15890-enus-downloader.exe | 
"UDP Query User{BE6ECCA9-CC17-436F-8C31-C72F7D9CA5A4}C:\programdata\battle.net\agent\agent.3182\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3182\agent.exe | 
"UDP Query User{BFE37DB9-C226-41D5-88BD-F42FDF864962}E:\steam\steam.exe" = protocol=17 | dir=in | app=e:\steam\steam.exe | 
"UDP Query User{C6C8D05C-B228-44CE-8EEC-CBC31EA466E4}C:\program files (x86)\whorecraft\binaries\win32\udk.exe" = protocol=17 | dir=in | app=c:\program files (x86)\whorecraft\binaries\win32\udk.exe | 
"UDP Query User{C8454D07-2912-4579-8669-089CBDFDE672}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe | 
"UDP Query User{C9216A6C-EECD-41E8-A2EC-2487B4509BE1}E:\starcraft ii\versions\base23260\sc2.exe" = protocol=17 | dir=in | app=e:\starcraft ii\versions\base23260\sc2.exe | 
"UDP Query User{CCCAD072-EF1C-4BF4-8135-E0FA9BD53AC4}D:\setup.exe" = protocol=17 | dir=in | app=d:\setup.exe | 
"UDP Query User{D4620D49-744F-4A73-A0BF-5DDBE699B38C}E:\starcraft ii\versions\base26490\sc2.exe" = protocol=17 | dir=in | app=e:\starcraft ii\versions\base26490\sc2.exe | 
"UDP Query User{D4B4B412-5B53-4AAD-9F74-14EDEC865C39}C:\program files (x86)\ncwest\nclauncher\ncupdatehelper.exe" = protocol=17 | dir=in | app=c:\program files (x86)\ncwest\nclauncher\ncupdatehelper.exe | 
"UDP Query User{D67F16B8-371D-43C8-B310-5A6DF2D7B06A}C:\program files (x86)\timegate studios\section 8\binaries\s8game-f.exe" = protocol=17 | dir=in | app=c:\program files (x86)\timegate studios\section 8\binaries\s8game-f.exe | 
"UDP Query User{DA9F9C54-4478-4071-AF27-0D3B22B67561}E:\wowpron2\binaries\win64\udk.exe" = protocol=17 | dir=in | app=e:\wowpron2\binaries\win64\udk.exe | 
"UDP Query User{DABFC6B9-6934-462D-BBBF-BC0C55404DD8}C:\program files (x86)\whorecraft\binaries\win64\udk.exe" = protocol=17 | dir=in | app=c:\program files (x86)\whorecraft\binaries\win64\udk.exe | 
"UDP Query User{DE10BCB9-1D46-4919-8D25-9DC312D976FC}E:\wow\temp\wow-4.2.1.2727-enus-tools-downloader.exe" = protocol=17 | dir=in | app=e:\wow\temp\wow-4.2.1.2727-enus-tools-downloader.exe | 
"UDP Query User{DEC94892-90E4-4647-9C58-5E34A2F9C226}C:\programdata\battle.net\agent\agent.3286\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3286\agent.exe | 
"UDP Query User{E77ACF56-83C5-4B28-9EFC-F8BFFFB5441A}E:\starcraft ii\versions\base28667\sc2.exe" = protocol=17 | dir=in | app=e:\starcraft ii\versions\base28667\sc2.exe | 
"UDP Query User{E985B2E5-B726-4049-91E3-586272552817}C:\programdata\battle.net\agent\agent.beta.2753\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2753\agent.exe | 
"UDP Query User{EAB808C0-BD9F-4786-97A7-924D6D1F45B4}G:\python\pythonw.exe" = protocol=17 | dir=in | app=g:\python\pythonw.exe | 
"UDP Query User{EC15E3FD-A993-475E-A844-0E19C473478E}G:\world of warcraft\launcher.patch.exe" = protocol=17 | dir=in | app=g:\world of warcraft\launcher.patch.exe | 
"UDP Query User{F4EE4E14-413A-4D16-A11A-3ABEAAC7CE8E}E:\wow\launcher.patch.exe" = protocol=17 | dir=in | app=e:\wow\launcher.patch.exe | 
"UDP Query User{F6C6AAFF-DB18-428A-9D8A-3F611388BD81}E:\wow\temp\wow-4.2.1.2706-enus-tools-downloader.exe" = protocol=17 | dir=in | app=e:\wow\temp\wow-4.2.1.2706-enus-tools-downloader.exe | 
"UDP Query User{F9FC5B62-B726-4B99-8799-09A54DA2685C}G:\whorecraft\episode 1\binaries\win32\udk.exe" = protocol=17 | dir=in | app=g:\whorecraft\episode 1\binaries\win32\udk.exe | 
"UDP Query User{FBCBD14B-F5D6-4641-B077-9C8D23FF09BD}E:\steam\steamapps\common\borderlands\binaries\borderlands.exe" = protocol=17 | dir=in | app=e:\steam\steamapps\common\borderlands\binaries\borderlands.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1493B2AE-0261-47D2-B1AA-F4DAD0F6C48B}" = iTunes
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{2EDC2FA3-1F34-34E5-9085-588C9EFD1CC6}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5AE0838D-19B1-5D12-5FE8-E6503B2C8716}" = AMD Catalyst Install Manager
"{5F92DAD2-FD95-DD12-50DF-A6F66C7E67C8}" = AMD Drag and Drop Transcoding
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}" = Apple Mobile Device Support
"{764384C5-BCA9-307C-9AAC-FD443662686A}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610
"{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8AB933A1-603C-5B22-3D56-19593698C41A}" = AMD Fuel
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727
"{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{ADCB5F9E-EF88-6D61-EE2F-99F51DF1B6EF}" = AMD Media Foundation Decoders
"{BD90BC1C-115D-47E1-B85C-07AE182C3AB8}" = Smart Technology Programming Software 7.0.27.13
"{E57289A3-B314-F00A-F0D0-7CB63E588CFF}" = AMD Accelerated Video Transcoding
"{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64
"{FEB22B7A-7B05-4A49-3BA3-D24815D37FAE}" = ccc-utility64
"6af12c54-643b-4752-87d0-8335503010de_is1" = Nexus Mod Manager
"UDK-6904d497-eef5-4f94-aa03-a3c9ea9626c2" = Unreal Development Kit: 2012-10
"UDK-71191b4f-8262-4d56-82ce-077cb3e48b86" = Unreal Development Kit: 2012-10
"UDK-adec2510-b606-4e1b-900e-d237506515c2" = Unreal Development Kit: 2012-10
"UDK-caf9fb72-9252-40db-aac3-13b6d104d293" = Unreal Development Kit: 2012-10
"WinRAR archiver" = WinRAR 4.20 (64-bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{050E298D-C9B8-4582-A332-26201268A297}" = Command & Conquer™ and The Covert Operations™
"{15134cb0-b767-4960-a911-f2d16ae54797}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727
"{170236F2-1F88-A116-DA64-3FEED17B9387}" = CCC Help Italian
"{1A882F29-BC18-4AC2-A71E-0FC30FA32568}" = Command & Conquer™ The Ultimate Collection Additional Content
"{2178EDD8-A3A6-50E3-407B-6629EA8E6ECE}" = AMD Catalyst Control Center
"{22154f09-719a-4619-bb71-5b3356999fbf}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727
"{25456D58-2414-4CC4-AA1B-CF3A2BE00A79}" = Command & Conquer™ Red Alert, Counterstrike and The Aftermath
"{26A24AE4-039D-4CA4-87B4-2F03217060FF}" = Java 7 Update 60
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2B41E132-07DF-4925-A3D3-F2D1765CCDFE}" = FINAL FANTASY XIV - A Realm Reborn
"{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727
"{32957F2B-A371-151F-9DA1-7BCA54BA2C71}" = CCC Help Danish
"{347EE0C3-0690-48F6-A231-53853C2A80D6}" = Titanfall™
"{35A2FE53-CC80-4D17-941F-3A7C82824FC7}" = Command & Conquer™ 3 Tiberium Wars and Kane's Wrath
"{398004A7-6198-B8AB-443A-D250FFA57446}" = CCC Help Greek
"{3A29665B-2304-A9F7-601D-86340BD29D57}" = CCC Help Korean
"{3C315BF7-4B64-4024-8102-174A197437FA}" = Command & Conquer™ Red Alert™ 3 and Uprising
"{3D6AD258-61EA-35F5-812C-B7A02152996E}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.60610
"{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}" = Microsoft Games for Windows - LIVE Redistributable
"{4310E447-8AF3-020C-06D0-CB317D1BC92B}" = CCC Help Spanish
"{44A570EE-FD93-4086-8997-2C38DFDE0019}" = Mass Effect™
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4DF0CAAC-F479-1673-EE92-03FFB9A05C1A}" = CCC Help English
"{517FAF1E-3045-49DE-8079-107C2851389E}" = Command & Conquer™ Tiberian Sun™ and Firestorm™
"{534A31BD-20F4-46b0-85CE-09778379663C}" = Mass Effect™ 3
"{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI
"{5BA9357B-E876-4FB2-8F1B-C7E63AC90E6F}" = Skyrim NPC Editor
"{5E6536C2-E79A-49CF-83EA-817AD81F9FC8}" = Plants vs. Zombies™
"{609F6FD5-4B22-4D7A-AD30-8C9DD480D5BE}" = Command & Conquer™: Generals and Zero Hour
"{6151cf20-0bd8-4023-a4a0-6a86dcfe58e5}" = Python 2.6.6
"{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support
"{6670AE0A-83FD-C514-C4EC-51618BEDCF04}" = Catalyst Control Center InstallProxy
"{6DD76706-759A-1D77-9D1B-39FFFEC203BE}" = CCC Help Hungarian
"{6DF3C5B5-AEA5-198E-289C-CAADC4A17C04}" = CCC Help Dutch
"{6F9B3984-08EB-19EE-5E93-E79FD0854596}" = CCC Help Czech
"{6F9D5A0B-202C-4161-BC7F-0664EA39E7E7}" = NVIDIA PhysX (Legacy)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.14
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7CAE6A67-AF7B-4A6A-8705-8AFACA45BB60}" = WestwoodChat
"{82DA3D5E-0041-D8F7-6ACD-53A06C863FD4}" = CCC Help Swedish
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{88B2ABCF-9C00-47C1-8FC4-369B98845DD7}" = Catalyst Control Center - Branding
"{8E63AD00-6BEB-9E98-739E-C8EE42CF0419}" = CCC Help Norwegian
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{95716cce-fc71-413f-8ad5-56c2892d4b3a}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
"{9584BE1B-2FBE-4F45-13EA-6567F3E2D9A2}" = CCC Help Chinese Traditional
"{9789E33B-317A-44B2-AF9A-FF8708AD93E0}" = Dead Space™
"{97B5E8B9-D5E6-49C4-8CDA-7E096BE2601A}" = Command & Conquer™ Renegade
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{993609E5-B0A7-0270-BA78-385016D5A4FA}" = CCC Help Chinese Standard
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C50B767-48BA-A567-0CFE-31620AE8FC97}" = CCC Help German
"{9D3D8C60-A55F-4123-B2B9-173F09590E16}" = ENCORE Wireless LAN Driver - PCIE Adapter
"{9E94C6F8-2B4E-D900-E73C-E7BCC7653188}" = CCC Help Japanese
"{a1909659-0a08-4554-8af1-2175904903a1}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime
"{ABADE36E-EC37-413B-8179-B432AD3FACE7}" = Battlefield 4™
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.06)
"{B810D852-DFD6-FC3-89A5-CC4D47756DAF}_is1" = FarCry 3 version 5.1
"{B9291CA2-6FA5-44EA-8EE0-923EB32ADAAB}" = Aion
"{B93EEE50-9C8F-45DF-95E4-3D85A6E242F3}" = DarksidersInstaller
"{BA4C8F9F-D81B-4AFE-AE5A-3837830F5B89}" = Command & Conquer™ 4 Tiberian Twilight
"{BBCD6D56-8A26-4DDE-9482-DBC9C7B7341D}" = WestwoodOnline
"{BEFD4139-C684-DBF8-33F2-7963161E2F10}" = CCC Help Russian
"{C2425F91-1F7B-4037-9A05-9F290184798D}" = NETGEAR WNA3100 wireless USB 2.0 adapter
"{C549C2A2-574F-4ABC-933C-BD11D027C16A}" = Dead Space™ 2
"{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}" = RealDownloader
"{CFBC3C9F-C781-4A0A-4AC9-BEBDE9850C16}" = CCC Help Turkish
"{D17BE572-CBFB-2AA4-759B-E21F04093001}" = CCC Help Thai
"{D3C44AE6-7A77-6CB3-0708-C970C53E8136}" = Catalyst Control Center Localization All
"{D4329609-4102-4F8C-B83F-7FE024EEA314}" = Dead Space™ 3
"{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}" = Microsoft XNA Framework Redistributable 4.0 Refresh
"{E19B628D-A9BC-4519-B1D4-4C8C09074F7F}" = Mass Effect™ 2
"{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}" = Far Cry 3
"{E7D4E834-93EB-351F-B8FB-82CDAE623003}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.60610
"{E7D59759-9859-4D74-888A-5CC3D888FB6C}" = Section 8
"{E9E87CFE-894C-8FFB-31C2-61C6B640F2B2}" = CCC Help Finnish
"{E9F63F5F-00EF-516C-C7F6-ABD3DC174B5E}" = CCC Help Polish
"{EA2DB6E0-72C5-4ef9-A3A0-E6705F4A6A9E}" = Nexon Game Manager
"{EA3960CB-883C-5B18-FA85-7C36C320E4BC}" = Catalyst Control Center Graphics Previews Common
"{EA450D5D-95EA-4FD0-B8B0-6D8E68FBE2C7}" = GameStop App
"{ED62231A-B71D-C39A-7CE0-B2C8388A67C2}" = CCC Help French
"{F0AB569C-99EF-4F4D-992D-2206E354C903}" = BOSS Userlist Manager
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F5275D1C-D133-486D-8F07-D6C571F0A8EC}" = Command & Conquer™ Red Alert 2 and Yuri’s Revenge
"{FBC9A8BD-C74D-86B3-7818-D584C9174F48}" = CCC Help Portuguese
"{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727
"{FE2D627E-D7E0-46EA-93A6-8583420285FA}" = Aeria Ignite
"Adobe Flash Player ActiveX" = Adobe Flash Player 15 ActiveX
"Aeria Ignite" = Aeria Ignite
"Aeria Ignite 1.13.3296" = Aeria Ignite
"Assassin's Creed® Revelations - Mediterranean Pack" = Assassin's Creed® Revelations - Mediterranean Pack
"Battle.net" = Battle.net
"Battlefield 4™" = Battlefield 4™
"Battlelog Web Plugins" = Battlelog Web Plugins
"Blender" = Blender (remove only)
"BlenderNIFScripts" = Blender NIF Scripts (remove only)
"BOSS" = BOSS
"Command & Conquer™ The Ultimate Collection" = Command & Conquer™ The Ultimate Collection
"Diablo III" = Diablo III
"DirectX10 for Windows XP - Win2000, 2003,..._is1" = DirectX10 RC2 Pre Fix 3
"EaseUS Partition Master Home Edition_is1" = EaseUS Partition Master 9.2.1 Home Edition
"Final Fantasy XIV: A Realm Reborn Collector's Ed." = Final Fantasy XIV: A Realm Reborn Collector's Ed.
"Final Fantasy XIV: A Realm Reborn Pre-Order Bonus" = Final Fantasy XIV: A Realm Reborn Pre-Order Bonus
"GameStop App" = GameStop App
"Glyph" = Glyph
"Google Chrome" = Google Chrome
"Hearthstone" = Hearthstone
"InstallShield_{E7D59759-9859-4D74-888A-5CC3D888FB6C}" = Section 8
"Kingdoms of Amalur Reckoning_is1" = Kingdoms of Amalur Reckoning
"Mass Effect Trilogy" = Mass Effect Trilogy
"NCLauncher_NCWest" = NCSOFT Game Launcher
"Origin" = Origin
"PyFFI" = PyFFI 2.1.11
"PyFFI-py2.6" = Python 2.6 PyFFI-2.1.11
"RealPlayer 16.0" = RealPlayer
"ScarletBlade" = ScarletBlade
"StarCraft II" = StarCraft II
"Steam App 1250" = Killing Floor
"Steam App 15620" = Warhammer® 40,000™: Dawn of War® II
"Steam App 202480" = Creation Kit
"Steam App 20570" = Warhammer® 40,000™: Dawn of War® II - Chaos Rising™
"Steam App 208670" = Blades of Time
"Steam App 20900" = The Witcher: Enhanced Edition
"Steam App 20920" = The Witcher 2: Assassins of Kings Enhanced Edition
"Steam App 210770" = Sanctum 2
"Steam App 238960" = Path of Exile
"Steam App 25850" = Elven Legacy
"Steam App 35420" = Killing Floor Mod: Defence Alliance 2
"Steam App 42930" = Elven Legacy: Magic
"Steam App 42940" = Elven Legacy: Siege
"Steam App 42950" = Elven Legacy: Ranger
"Steam App 50620" = Darksiders
"Steam App 50650" = Darksiders II
"Steam App 550" = Left 4 Dead 2
"Steam App 56400" = Warhammer® 40,000™: Dawn of War® II – Retribution™
"Steam App 570" = Dota 2
"Steam App 72850" = The Elder Scrolls V: Skyrim
"Steam App 8980" = Borderlands
"The Elder Scrolls Online Beta_is1" = The Elder Scrolls Online Beta
"Titanfall" = Titanfall
"Turok_R.G. Mechanics_is1" = Turok
"Uplay" = Uplay
"Uplay Install 273" = Assassin's Creed IV Black Flag
"Uplay Install 274" = WATCH_DOGS
"Vindictus" = Vindictus
"VLC media player" = VLC media player 2.0.0
"WhoreCraft1.6.1r" = WhoreCraft
"World of Warcraft" = World of Warcraft
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"101a9f93b8f0bb6f" = Curse Client
"Akamai" = Akamai NetSession Interface
"HappyCloud" = Happy Cloud Client
"RIFT" = RIFT
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"UnityWebPlayer" = Unity Web Player
"uTorrent" = µTorrent
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 9/17/2014 3:39:23 PM | Computer Name = Troy-PC | Source = Application Hang | ID = 1002
Description = The program TESV.exe version 1.9.32.0 stopped interacting with Windows
 and was closed. To see if more information about the problem is available, check
 the problem history in the Action Center control panel.    Process ID: 14bc    Start Time:
 01cfd2ae761807d3    Termination Time: 405    Application Path: E:\Steam\SteamApps\common\Skyrim\TESV.exe
 
Report
 Id:   
 
Error - 9/17/2014 3:57:28 PM | Computer Name = Troy-PC | Source = Application Hang | ID = 1002
Description = The program TESV.exe version 1.9.32.0 stopped interacting with Windows
 and was closed. To see if more information about the problem is available, check
 the problem history in the Action Center control panel.    Process ID: 51e8    Start Time:
 01cfd2b0e58aaa49    Termination Time: 431    Application Path: E:\Steam\SteamApps\common\Skyrim\TESV.exe
 
Report
 Id:   
 
Error - 9/19/2014 4:42:40 AM | Computer Name = Troy-PC | Source = Desktop Window Manager | ID = 9020
Description = The Desktop Window Manager has encountered a fatal error (0x8898009b)
 
Error - 9/19/2014 4:42:57 AM | Computer Name = Troy-PC | Source = Desktop Window Manager | ID = 9020
Description = The Desktop Window Manager has encountered a fatal error (0x8898009b)
 
Error - 9/21/2014 11:41:49 PM | Computer Name = Troy-PC | Source = Application Hang | ID = 1002
Description = The program IEXPLORE.EXE version 11.0.9600.17280 stopped interacting
 with Windows and was closed. To see if more information about the problem is available,
 check the problem history in the Action Center control panel.    Process ID: efa4    Start
 Time: 01cfd616e5dd22a2    Termination Time: 37    Application Path: C:\Program Files (x86)\Internet
 Explorer\IEXPLORE.EXE    Report Id:   
 
Error - 9/21/2014 11:49:04 PM | Computer Name = Troy-PC | Source = Application Error | ID = 1000
Description = Faulting application name: IEXPLORE.EXE, version: 11.0.9600.17280,
 time stamp: 0x53f262ac  Faulting module name: KERNELBASE.dll, version: 6.1.7601.18409,
 time stamp: 0x53159a86  Exception code: 0xe06d7363  Fault offset: 0x0000c42d  Faulting
 process id: 0xfa30  Faulting application start time: 0x01cfd617244738d7  Faulting application
 path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE  Faulting module path:
 C:\Windows\syswow64\KERNELBASE.dll  Report Id: 65303f6c-420b-11e4-ae93-1c6f65f95c3c
 
Error - 9/22/2014 3:30:04 PM | Computer Name = Troy-PC | Source = Application Error | ID = 1000
Description = Faulting application name: NCUpdateHelper.exe, version: 0.0.0.1, time
 stamp: 0x525b6657  Faulting module name: NCUpdateHelper.exe, version: 0.0.0.1, time
 stamp: 0x525b6657  Exception code: 0xc000000d  Fault offset: 0x0001d162  Faulting process
 id: 0x9d8  Faulting application start time: 0x01cfd69b459b5df1  Faulting application
 path: C:\Program Files (x86)\NCWest\NCLauncher\NCUpdateHelper.exe  Faulting module
 path: C:\Program Files (x86)\NCWest\NCLauncher\NCUpdateHelper.exe  Report Id: da05137f-428e-11e4-a5f3-1c6f65f95c3c
 
Error - 9/22/2014 5:53:59 PM | Computer Name = Troy-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe".
Dependent
 Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" 
could not be found.  Please use sxstrace.exe for detailed diagnosis.
 
Error - 9/22/2014 11:48:51 PM | Computer Name = Troy-PC | Source = .NET Runtime | ID = 1026
Description = 
 
Error - 9/22/2014 11:48:52 PM | Computer Name = Troy-PC | Source = Application Error | ID = 1000
Description = Faulting application name: NexusClient.exe, version: 0.52.1.0, time
 stamp: 0x53fcb368  Faulting module name: KERNELBASE.dll, version: 6.1.7601.18409,
 time stamp: 0x5315a05a  Exception code: 0xe0434352  Fault offset: 0x000000000000940d
Faulting
 process id: 0x2198  Faulting application start time: 0x01cfd6c72113eb01  Faulting application
 path: C:\Program Files\Nexus Mod Manager\NexusClient.exe  Faulting module path: C:\Windows\system32\KERNELBASE.dll
Report
 Id: 888f4dc7-42d4-11e4-a5f3-1c6f65f95c3c
 
Error - 9/23/2014 9:55:11 AM | Computer Name = Troy-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe".
Dependent
 Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" 
could not be found.  Please use sxstrace.exe for detailed diagnosis.
 
[ System Events ]
Error - 9/22/2014 7:00:26 PM | Computer Name = Troy-PC | Source = bowser | ID = 8003
Description = 
 
Error - 9/22/2014 7:02:11 PM | Computer Name = Troy-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.
 
Error - 9/22/2014 7:03:25 PM | Computer Name = Troy-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.
 
Error - 9/22/2014 8:37:52 PM | Computer Name = Troy-PC | Source = bowser | ID = 8003
Description = 
 
Error - 9/23/2014 9:58:18 AM | Computer Name = Troy-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.
 
Error - 9/23/2014 10:02:51 AM | Computer Name = Troy-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.
 
Error - 9/23/2014 10:39:07 AM | Computer Name = Troy-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.
 
Error - 9/23/2014 10:41:26 AM | Computer Name = Troy-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.
 
Error - 9/23/2014 11:17:20 AM | Computer Name = Troy-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.
 
Error - 9/23/2014 11:19:39 AM | Computer Name = Troy-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\DR0, has a bad block.
 
 
< End of report >
 

 


  • 0

Advertisements


#2
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts

Minion%20Welcome.jpg


My name's Naathim and I'm a GeekU Minion! Now that we are mates and will be working together to clean your machine out of any junkware, feel free to call me Naat :)

Before we start please note the following:

icon_arrow.gif Analysis and research take some time, also sometimes real life gets in the way, please be patient.
icon_arrow.gif Limit your internet access to posting here, some infections just wait to steal typed-in passwords.
icon_arrow.gif Don't run any scripts or tools on your own, unsupervised usage may cause more harm than good.
icon_arrow.gif Paste the logs in your posts, attachments make my work harder and more complicated.
icon_arrow.gif Stay with me to the end, the absence of symtoms doesn't mean that your machine is fully operational.
icon_arrow.gif Note that we may live in totally different time zones, what may cause some delays between answers.

icon_idea.gif I can't foresee everything, so if anything unexpected happens, please stop and inform me!
icon_idea.gif There are no silly questions. Never be afraid to ask if in doubt!

Let's start and enjoy the fight! :)

We've got a better scanner for the 64-bit systems, so please go ahead and provide me its logfiles.


FRST.gif Scan with Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool x64 and save it to your Desktop.

  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    > Windows 8 users will be prompted about Windows SmartScreen protection - click More information and Run.
  • When the tool opens click Yes to disclaimer.
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please include their content in your next reply.


  • 0

#3
Biscuithd

Biscuithd

    Trusted Helper

  • Malware Removal
  • 2,573 posts

Hello coldsteel123,

 

I am stepping in for Naathim. I will assess your logs when you have a chance to post them :)

 

Biscuithd


  • 0

#4
Biscuithd

Biscuithd

    Trusted Helper

  • Malware Removal
  • 2,573 posts

I have not heard from you. Do you still need help?


  • 0

#5
Biscuithd

Biscuithd

    Trusted Helper

  • Malware Removal
  • 2,573 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP