Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Suspicious *.so files reappear on every reboot [Closed]


  • This topic is locked This topic is locked

#1
wemogil

wemogil

    Member

  • Member
  • PipPip
  • 25 posts

Hello,

 

I recently had a pretty serious explosion of malware and thought I had everything cleaned up using malwarebytes,hitmanpro,TDSkiller,Adwcleaner,Roguekiller and Emsisoft Anti-Malware.  Nonetheless...

 

...on reboot, HitmanPro keeps finding the same suspicious files popping up; if I remove them, I lose by main Windows desktop toolbar and have to reboot, bringing the files back.  I am listing the suspicious files below and posting my OTL file after them.  Thanks to anyone who can help!

 

 

C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so

C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so

 C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so

C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\single_byte.so

 C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so

C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\utf_16_32.so

C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16le.so

C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so

C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so

 C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so

 C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19\win32\api.so

 

OTL logfile created on: 3/7/2015 9:30:27 AM - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Wayne\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17633)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
5.99 Gb Total Physical Memory | 2.81 Gb Available Physical Memory | 46.93% Memory free
11.98 Gb Paging File | 8.12 Gb Available in Paging File | 67.75% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 83.11 Gb Free Space | 8.92% Space Free | Partition Type: NTFS
 
Computer Name: WAYNE-PC | User Name: Wayne | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2015/03/07 09:26:39 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Wayne\Downloads\OTL.exe
PRC - [2015/03/07 07:45:18 | 000,070,239 | ---- | M] (http://www.ruby-lang.org/) -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\bin\rubyw.exe
PRC - [2015/03/07 07:42:49 | 000,070,239 | ---- | M] (http://www.ruby-lang.org/) -- C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\bin\rubyw.exe
PRC - [2015/03/05 20:51:51 | 000,376,944 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2015/02/05 06:32:13 | 001,880,752 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
PRC - [2014/12/19 08:48:18 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014/12/16 12:15:26 | 003,247,120 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
PRC - [2014/12/16 12:13:58 | 001,417,160 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgfws.exe
PRC - [2014/12/16 12:11:20 | 005,188,112 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgui.exe
PRC - [2014/12/16 12:09:34 | 000,289,328 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
PRC - [2014/11/21 06:12:56 | 000,969,016 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
PRC - [2014/11/21 06:12:54 | 001,871,160 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
PRC - [2014/11/21 06:12:46 | 007,229,752 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
PRC - [2014/08/19 10:34:19 | 000,070,760 | ---- | M] (AOL Inc.) -- C:\Program Files (x86)\AOL Desktop 9.7a\waol.exe
PRC - [2014/08/19 10:34:18 | 000,045,160 | ---- | M] (AOL Inc.) -- C:\Program Files (x86)\AOL Desktop 9.7a\shellmon.exe
PRC - [2014/07/28 14:07:26 | 000,184,320 | ---- | M] () -- C:\Program Files\pia_manager\pia_tray\pia_tray.exe
PRC - [2014/07/28 14:07:25 | 008,817,890 | ---- | M] () -- C:\Program Files\pia_manager\pia_manager.exe
PRC - [2014/07/25 06:02:45 | 002,403,104 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
PRC - [2014/07/25 06:02:40 | 001,720,608 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
PRC - [2014/07/02 09:44:41 | 000,411,936 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2014/07/02 00:10:36 | 002,442,856 | ---- | M] (AOL Inc.) -- C:\Program Files (x86)\AOL Desktop 9.7a\aolbrowser.exe
PRC - [2014/02/06 14:09:56 | 000,046,184 | R--- | M] (AOL Inc.) -- C:\Program Files (x86)\Common Files\aol\acs\AOLacsd.exe
PRC - [2014/02/06 14:08:39 | 000,039,016 | ---- | M] (AOL Inc.) -- C:\Program Files (x86)\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe
PRC - [2013/11/27 09:12:02 | 007,393,280 | ---- | M] (LeapFrog Enterprises, Inc.) -- C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe
PRC - [2013/06/21 17:34:06 | 000,610,152 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
PRC - [2012/01/18 05:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
PRC - [2010/05/11 15:43:48 | 006,061,400 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe
PRC - [2010/03/19 20:53:26 | 000,026,624 | ---- | M] () -- C:\Python26\python.exe
PRC - [2010/03/07 23:27:49 | 000,041,800 | ---- | M] (AOL Inc.) -- C:\Program Files (x86)\Common Files\aol\1267029088\ee\aolsoftware.exe
PRC - [2010/01/27 15:14:10 | 000,286,720 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
PRC - [2008/05/02 15:59:14 | 000,077,824 | ---- | M] () -- C:\Program Files\pyTivo\pyTivoService.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2015/03/07 07:48:54 | 000,026,624 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19\win32\api.so
MOD - [2015/03/07 07:46:46 | 000,016,384 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so
MOD - [2015/03/07 07:46:43 | 000,087,552 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so
MOD - [2015/03/07 07:46:38 | 000,126,976 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so
MOD - [2015/03/07 07:46:27 | 000,036,352 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\generator.so
MOD - [2015/03/07 07:46:27 | 000,023,552 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\parser.so
MOD - [2015/03/07 07:46:24 | 000,008,704 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32le.so
MOD - [2015/03/07 07:46:22 | 000,008,704 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32be.so
MOD - [2015/03/07 07:46:17 | 000,008,704 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16be.so
MOD - [2015/03/07 07:46:09 | 000,009,216 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so
MOD - [2015/03/07 07:46:03 | 000,275,968 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\openssl.so
MOD - [2015/03/07 07:46:03 | 000,015,360 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\digest.so
MOD - [2015/03/07 07:46:03 | 000,008,192 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\fcntl.so
MOD - [2015/03/07 07:46:01 | 000,026,624 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\stringio.so
MOD - [2015/03/07 07:46:00 | 000,069,120 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\zlib.so
MOD - [2015/03/07 07:45:50 | 000,118,784 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\socket.so
MOD - [2015/03/07 07:45:50 | 000,095,744 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\single_byte.so
MOD - [2015/03/07 07:45:50 | 000,094,208 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\site_ruby\1.9.1\rgloader\rgloader193.mswin.so
MOD - [2015/03/07 07:45:50 | 000,013,312 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\utf_16_32.so
MOD - [2015/03/07 07:45:50 | 000,008,704 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16le.so
MOD - [2015/03/07 07:45:34 | 000,014,848 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so
MOD - [2015/03/07 07:45:33 | 000,012,800 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so
MOD - [2015/03/07 07:45:33 | 000,009,728 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so
MOD - [2015/03/07 07:45:25 | 000,127,316 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\bin\libffi-6.dll
MOD - [2015/03/07 07:45:21 | 000,083,968 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\bin\zlib1.dll
MOD - [2015/03/07 07:45:13 | 000,094,208 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr49BC.tmp\src\rgloader\rgloader193.mswin.so
MOD - [2015/03/07 07:44:50 | 000,026,624 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19\win32\api.so
MOD - [2015/03/07 07:43:29 | 000,016,384 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so
MOD - [2015/03/07 07:43:28 | 000,126,976 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so
MOD - [2015/03/07 07:43:28 | 000,087,552 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so
MOD - [2015/03/07 07:43:21 | 000,009,216 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so
MOD - [2015/03/07 07:43:07 | 000,095,744 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\single_byte.so
MOD - [2015/03/07 07:43:07 | 000,094,208 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\site_ruby\1.9.1\rgloader\rgloader193.mswin.so
MOD - [2015/03/07 07:43:07 | 000,013,312 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\utf_16_32.so
MOD - [2015/03/07 07:43:07 | 000,008,704 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16le.so
MOD - [2015/03/07 07:43:02 | 000,014,848 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so
MOD - [2015/03/07 07:43:02 | 000,012,800 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so
MOD - [2015/03/07 07:43:02 | 000,009,728 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so
MOD - [2015/03/07 07:42:57 | 000,127,316 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\bin\libffi-6.dll
MOD - [2015/03/07 07:42:47 | 000,094,208 | ---- | M] () -- C:\Users\Wayne\AppData\Local\Temp\ocr1EDD.tmp\src\rgloader\rgloader193.mswin.so
MOD - [2015/02/05 06:32:12 | 016,852,144 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll
MOD - [2014/10/21 12:57:18 | 000,018,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio49d6fefe#\38d6578b4fe29bede85ffff08e3697b6\PresentationFramework-SystemXml.ni.dll
MOD - [2014/10/21 12:57:18 | 000,014,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio4b37ff64#\9370714a38ae2805434296b26a9f5b14\PresentationFramework-SystemXmlLinq.ni.dll
MOD - [2014/10/21 12:56:24 | 000,399,872 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\7ab3e68c2e523f60bfc4f222cbd1c1d0\System.Xml.Linq.ni.dll
MOD - [2014/10/21 12:48:42 | 018,813,440 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\3646375313dd2b8e3afecbf945960336\PresentationFramework.ni.dll
MOD - [2014/10/21 12:48:31 | 011,025,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\006d28e7c86f3e70db90ce06ea2f33fb\PresentationCore.ni.dll
MOD - [2014/10/21 12:48:29 | 012,894,208 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\db563d596d76daed04e9b5d25b2f4cb9\System.Windows.Forms.ni.dll
MOD - [2014/10/21 12:48:25 | 001,889,792 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\8b133e0d94535a7534719f70873ca7fe\System.Xaml.ni.dll
MOD - [2014/10/21 12:48:24 | 007,668,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\7147fa233a070283dba824da40089bf1\System.Xml.ni.dll
MOD - [2014/10/21 12:48:24 | 006,990,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\691c1ad89d16f49d80e84fa06a79089a\System.Core.ni.dll
MOD - [2014/10/21 12:48:23 | 003,950,080 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\94bbd298ec8575f3c6151a59538a109c\WindowsBase.ni.dll
MOD - [2014/10/21 12:48:22 | 002,822,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\f9f13cd8fe1cefaad78579a7c3a41464\System.Runtime.Serialization.ni.dll
MOD - [2014/10/21 12:48:21 | 001,644,544 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\b4c08872c259018b17b2801da33ac80f\System.Drawing.ni.dll
MOD - [2014/10/21 12:48:21 | 000,470,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio1c9175f8#\7971f3a1c08c4043cf981f457855b4d4\PresentationFramework.Aero.ni.dll
MOD - [2014/10/21 12:48:20 | 000,976,384 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\0648dbecb7e3fb9523565107e04a5caf\System.Configuration.ni.dll
MOD - [2014/10/21 12:48:20 | 000,794,112 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\35d3a1b878542de59cb4fc0593992404\System.ServiceModel.Internals.ni.dll
MOD - [2014/10/21 12:48:20 | 000,122,880 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\046058f81b039ab6fd839e03e67595f8\SMDiagnostics.ni.dll
MOD - [2014/10/21 12:48:19 | 001,180,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\c90a4b709b46b64c89fce02585d55370\System.Management.ni.dll
MOD - [2014/10/21 12:48:18 | 010,100,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\17a393b77ae757f0768501fb95ff5af6\System.ni.dll
MOD - [2014/08/19 10:34:19 | 000,048,640 | ---- | M] () -- C:\Program Files (x86)\AOL Desktop 9.7a\zlib.dll
MOD - [2014/08/19 10:34:11 | 021,151,232 | ---- | M] () -- C:\Program Files (x86)\AOL Desktop 9.7a\libcef.dll
MOD - [2014/08/19 10:34:11 | 000,648,704 | ---- | M] () -- C:\Program Files (x86)\AOL Desktop 9.7a\libGLESv2.dll
MOD - [2014/08/19 10:34:11 | 000,122,880 | ---- | M] () -- C:\Program Files (x86)\AOL Desktop 9.7a\libEGL.dll
MOD - [2014/08/19 10:34:09 | 000,094,208 | ---- | M] () -- C:\Program Files (x86)\AOL Desktop 9.7a\components\Tier2Svc.dll
MOD - [2014/08/19 10:34:09 | 000,060,928 | ---- | M] () -- C:\Program Files (x86)\AOL Desktop 9.7a\components\DataSvcs.dll
MOD - [2014/07/28 14:07:28 | 000,059,904 | ---- | M] () -- C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\zlib1.dll
MOD - [2014/07/28 14:07:26 | 001,234,944 | ---- | M] () -- C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\libxml2.dll
MOD - [2014/07/28 14:07:26 | 001,198,592 | ---- | M] () -- C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoFoundation.dll
MOD - [2014/07/28 14:07:26 | 000,815,104 | ---- | M] () -- C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\khost.dll
MOD - [2014/07/28 14:07:26 | 000,745,472 | ---- | M] () -- C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\CFLite.dll
MOD - [2014/07/28 14:07:26 | 000,642,048 | ---- | M] () -- C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoNet.dll
MOD - [2014/07/28 14:07:26 | 000,511,488 | ---- | M] () -- C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoXML.dll
MOD - [2014/07/28 14:07:26 | 000,344,064 | ---- | M] () -- C:\Program Files\pia_manager\pia_tray\modules\tiui\1.2.0.RC6d\tiuimodule.dll
MOD - [2014/07/28 14:07:26 | 000,290,816 | ---- | M] () -- C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoUtil.dll
MOD - [2014/07/28 14:07:26 | 000,184,320 | ---- | M] () -- C:\Program Files\pia_manager\pia_tray\pia_tray.exe
MOD - [2014/07/28 14:07:25 | 008,817,890 | ---- | M] () -- C:\Program Files\pia_manager\pia_manager.exe
MOD - [2014/07/28 14:07:25 | 000,368,640 | ---- | M] () -- C:\Program Files\pia_manager\pia_tray\modules\tinetwork\1.2.0.RC6d\tinetworkmodule.dll
MOD - [2014/07/28 14:07:25 | 000,217,088 | ---- | M] () -- C:\Program Files\pia_manager\pia_tray\modules\tiprocess\1.2.0.RC6d\tiprocessmodule.dll
MOD - [2014/07/28 14:07:25 | 000,200,704 | ---- | M] () -- C:\Program Files\pia_manager\pia_tray\modules\tiapp\1.2.0.RC6d\tiappmodule.dll
MOD - [2014/07/28 14:07:25 | 000,180,224 | ---- | M] () -- C:\Program Files\pia_manager\pia_tray\modules\tifilesystem\1.2.0.RC6d\tifilesystemmodule.dll
MOD - [2014/02/27 03:07:21 | 000,190,976 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\75b6a68103e1b76063d9f69b8275ae61\UIAutomationTypes.ni.dll
MOD - [2014/02/27 03:04:30 | 016,953,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\ce5f61c5754789df97be8dc991c47d07\mscorlib.ni.dll
MOD - [2012/01/17 22:43:56 | 000,183,320 | ---- | M] () -- C:\Program Files (x86)\Common Files\logishrd\SharedBin\LvApi11.dll
MOD - [2009/07/16 14:36:20 | 000,138,000 | ---- | M] () -- C:\Program Files (x86)\Logitech\Logitech Vid\plugins\imageformats\qjpeg4.dll
MOD - [2009/07/16 14:36:16 | 000,035,088 | ---- | M] () -- C:\Program Files (x86)\Logitech\Logitech Vid\plugins\imageformats\qico4.dll
MOD - [2009/07/16 14:36:16 | 000,028,944 | ---- | M] () -- C:\Program Files (x86)\Logitech\Logitech Vid\plugins\imageformats\qgif4.dll
MOD - [2009/07/16 14:35:30 | 000,027,408 | ---- | M] () -- C:\Program Files (x86)\Logitech\Logitech Vid\SDL.dll
MOD - [2009/07/16 14:35:20 | 000,363,792 | ---- | M] () -- C:\Program Files (x86)\Logitech\Logitech Vid\qtxml4.dll
MOD - [2009/07/16 14:35:08 | 011,311,888 | ---- | M] () -- C:\Program Files (x86)\Logitech\Logitech Vid\QtWebKit4.dll
MOD - [2009/07/16 14:34:56 | 000,199,952 | ---- | M] () -- C:\Program Files (x86)\Logitech\Logitech Vid\qtsql4.dll
MOD - [2009/07/16 14:34:46 | 000,475,408 | ---- | M] () -- C:\Program Files (x86)\Logitech\Logitech Vid\QtOpenGL4.dll
MOD - [2009/07/16 14:34:34 | 000,968,976 | ---- | M] () -- C:\Program Files (x86)\Logitech\Logitech Vid\QtNetwork4.dll
MOD - [2009/07/16 14:34:22 | 007,704,336 | ---- | M] () -- C:\Program Files (x86)\Logitech\Logitech Vid\QtGui4.dll
MOD - [2009/07/16 14:34:22 | 002,140,944 | ---- | M] () -- C:\Program Files (x86)\Logitech\Logitech Vid\QtCore4.dll
MOD - [2009/07/16 14:34:12 | 000,291,600 | ---- | M] () -- C:\Program Files (x86)\Logitech\Logitech Vid\phonon4.dll
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - [2015/03/01 07:32:37 | 000,127,752 | ---- | M] (SurfRight B.V.) [Auto | Running] -- C:\Program Files\HitmanPro\hmpsched.exe -- (HitmanProScheduler)
SRV:64bit: - [2015/01/11 18:34:30 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2014/07/25 06:02:38 | 018,956,064 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe -- (NvStreamSvc)
SRV:64bit: - [2013/05/26 21:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2008/05/02 15:59:14 | 000,077,824 | ---- | M] () [Auto | Running] -- C:\Program Files\pyTivo\pyTivoService.exe -- (pyTivo)
SRV - [2015/03/05 20:51:51 | 000,148,080 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2015/02/05 06:32:13 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/12/19 08:48:18 | 000,081,088 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014/12/16 12:15:26 | 003,247,120 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe -- (AVGIDSAgent)
SRV - [2014/12/16 12:13:58 | 001,417,160 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2014\avgfws.exe -- (avgfws)
SRV - [2014/12/16 12:09:34 | 000,289,328 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe -- (avgwd)
SRV - [2014/11/21 06:12:56 | 000,969,016 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2014/11/21 06:12:54 | 001,871,160 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2014/07/25 06:02:40 | 001,720,608 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService)
SRV - [2014/07/02 09:44:41 | 000,411,936 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2014/03/20 14:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2014/02/06 14:09:56 | 000,046,184 | R--- | M] (AOL Inc.) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\aol\acs\AOLacsd.exe -- (AOL ACS)
SRV - [2013/11/27 09:12:02 | 007,393,280 | ---- | M] (LeapFrog Enterprises, Inc.) [Auto | Running] -- C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe -- (LeapFrog Connect Device Service)
SRV - [2013/10/23 11:53:56 | 000,018,360 | ---- | M] (Overwolf Ltd) [Disabled | Stopped] -- C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe -- (OverwolfUpdaterService)
SRV - [2013/09/11 21:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/07/11 22:34:05 | 000,032,984 | ---- | M] (Razer) [Auto | Running] -- C:\Program Files (x86)\Razer\Core\64bit\RzOvlMon.exe -- (RzOvlMon)
SRV - [2012/04/22 16:50:44 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2012/01/18 05:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2011/07/15 00:03:00 | 000,021,488 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe -- (BOT4Service)
SRV - [2011/07/13 06:41:52 | 000,340,976 | ---- | M] (Rovi Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxWatch13.exe -- (RoxWatch12)
SRV - [2011/07/13 06:41:30 | 001,095,664 | ---- | M] (Rovi Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxMediaDB13.exe -- (RoxMediaDB13)
SRV - [2011/06/22 10:18:40 | 001,191,656 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2011/02/09 16:36:58 | 000,457,200 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe -- (9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269)
SRV - [2010/05/17 16:10:06 | 001,104,656 | ---- | M] (TiVo Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\TiVo\Desktop\TiVoBeacon.exe -- (TivoBeacon2)
SRV - [2010/03/18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2010/02/25 21:24:59 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/01/27 15:14:10 | 000,286,720 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)
SRV - [2007/05/31 16:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 16:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - [2015/03/07 07:44:37 | 000,129,752 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys -- (MBAMSwissArmy)
DRV:64bit: - [2015/03/07 07:42:18 | 000,043,664 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hitmanpro37.sys -- (hitmanpro37)
DRV:64bit: - [2015/03/01 08:01:34 | 000,035,064 | ---- | M] () [Kernel | On_Demand | Unknown] -- C:\Windows\SysNative\drivers\TrueSight.sys -- (TrueSight)
DRV:64bit: - [2015/02/02 19:23:22 | 000,069,320 | ---- | M] (Mozy, Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mozy.sys -- (mozyFilter)
DRV:64bit: - [2014/12/27 10:54:37 | 000,052,000 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:64bit: - [2014/11/21 06:14:22 | 000,063,704 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mwac.sys -- (MBAMWebAccessControl)
DRV:64bit: - [2014/11/21 06:14:08 | 000,025,816 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2014/10/29 21:03:36 | 000,123,672 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (Avgmfx64)
DRV:64bit: - [2014/10/24 10:20:06 | 000,237,848 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (Avgldx64)
DRV:64bit: - [2014/10/20 15:15:50 | 000,269,080 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (Avgtdia)
DRV:64bit: - [2014/07/28 14:07:31 | 000,031,232 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901)
DRV:64bit: - [2014/07/25 06:02:38 | 000,020,256 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys -- (NvStreamKms)
DRV:64bit: - [2014/07/21 20:03:12 | 000,244,504 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgidsdrivera.sys -- (AVGIDSDriver)
DRV:64bit: - [2014/06/30 11:43:02 | 000,152,344 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgdiska.sys -- (Avgdiska)
DRV:64bit: - [2014/06/17 15:07:12 | 000,328,984 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgloga.sys -- (Avgloga)
DRV:64bit: - [2014/06/17 15:06:24 | 000,190,744 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgidsha.sys -- (AVGIDSHA)
DRV:64bit: - [2014/06/17 15:06:06 | 000,031,512 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (Avgrkx64)
DRV:64bit: - [2014/03/31 08:42:44 | 000,040,392 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvvad64v.sys -- (nvvad_WaveExtensible)
DRV:64bit: - [2013/09/26 09:44:54 | 000,057,144 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgfwd6a.sys -- (Avgfwfd)
DRV:64bit: - [2013/07/11 19:51:23 | 000,128,856 | ---- | M] (Razer USA Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RzDxgk.sys -- (RzDxgk)
DRV:64bit: - [2013/07/11 19:51:23 | 000,074,456 | ---- | M] (Razer USA Ltd) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\RzFilter.sys -- (RzFilter)
DRV:64bit: - [2013/07/09 22:29:34 | 000,039,096 | ---- | M] (Razer Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rzendpt.sys -- (rzendpt)
DRV:64bit: - [2013/07/09 22:29:34 | 000,034,488 | ---- | M] (Razer Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rzmpos.sys -- (rzmpos)
DRV:64bit: - [2013/07/09 22:29:32 | 000,137,400 | ---- | M] (Razer Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rzudd.sys -- (rzudd)
DRV:64bit: - [2013/03/18 15:51:08 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/07/24 12:11:54 | 000,041,704 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\hssdrv6.sys -- (HssDRV6)
DRV:64bit: - [2012/07/24 12:11:52 | 000,038,632 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\taphss.sys -- (taphss)
DRV:64bit: - [2012/02/29 22:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/01/18 05:44:36 | 004,865,568 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64)
DRV:64bit: - [2012/01/18 05:44:28 | 000,351,136 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64)
DRV:64bit: - [2011/10/04 11:44:07 | 000,971,360 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\timntr.sys -- (timounter)
DRV:64bit: - [2011/10/04 11:42:46 | 000,210,016 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vididr.sys -- (vididr)
DRV:64bit: - [2011/10/04 11:42:39 | 000,141,920 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vsflt53.sys -- (vidsflt53)
DRV:64bit: - [2011/10/04 11:42:30 | 000,275,552 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snapman.sys -- (snapman)
DRV:64bit: - [2011/06/10 05:34:52 | 000,539,240 | ---- | M] (Realtek                                            ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/05/24 02:00:00 | 000,055,952 | ---- | M] (Rovi Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2011/03/10 22:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/10 22:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/02/09 00:00:00 | 000,027,632 | ---- | M] (Sonic Solutions) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SaibVdAd64.sys -- (SaibVdAd64)
DRV:64bit: - [2011/02/09 00:00:00 | 000,027,120 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\Sahdad64.sys -- (Sahdad64)
DRV:64bit: - [2011/02/09 00:00:00 | 000,019,952 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\Saibad64.sys -- (Saibad64)
DRV:64bit: - [2010/12/20 21:55:02 | 000,172,104 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sscdmdm.sys -- (sscdmdm)
DRV:64bit: - [2010/12/20 21:55:02 | 000,136,264 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sscdbus.sys -- (sscdbus)
DRV:64bit: - [2010/12/20 21:55:02 | 000,019,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV:64bit: - [2010/11/20 05:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 03:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/07/20 02:38:24 | 000,159,208 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdm.sys -- (ssadmdm)
DRV:64bit: - [2010/07/20 02:38:24 | 000,125,416 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadbus.sys -- (ssadbus)
DRV:64bit: - [2010/07/20 02:38:24 | 000,036,328 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadadb.sys -- (androidusb)
DRV:64bit: - [2010/07/20 02:38:24 | 000,016,872 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdfl.sys -- (ssadmdfl)
DRV:64bit: - [2010/05/23 18:47:08 | 000,164,848 | ---- | M] (Sonic Solutions) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\syscowad64v.sys -- (SysCow)
DRV:64bit: - [2010/05/07 17:43:30 | 000,030,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2Mon)
DRV:64bit: - [2010/05/07 17:43:30 | 000,030,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2M64)
DRV:64bit: - [2009/11/08 19:28:08 | 000,091,568 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\scdemu.sys -- (SCDEmu)
DRV:64bit: - [2009/07/13 17:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 17:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 17:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 16:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009/07/13 16:10:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rootmdm.sys -- (ROOTMODEM)
DRV:64bit: - [2009/06/17 08:54:30 | 000,057,872 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2009/06/17 08:54:22 | 000,055,312 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2009/06/17 08:53:34 | 000,030,736 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV:64bit: - [2009/06/10 12:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 12:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 12:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 12:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2007/03/07 12:13:20 | 000,017,920 | ---- | M] (June Fabrics Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\pnetmdm64.sys -- (pnetmdm)
DRV:64bit: - [2006/11/29 14:24:49 | 000,024,064 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wanatw64.sys -- (wanatw)
DRV - [2015/03/01 00:13:46 | 000,057,024 | ---- | M] (Emsisoft GmbH) [File_System | On_Demand | Stopped] -- C:\EEK\bin\cleanhlp64.sys -- (cleanhlp)
DRV - [2015/03/01 00:13:46 | 000,026,176 | ---- | M] (Emsisoft GmbH) [File_System | System | Running] -- C:\EEK\bin\a2ddax64.sys -- (A2DDA)
DRV - [2009/07/13 17:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = BC 09 E8 94 99 03 CE 01  [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6B72EDE3-E0C3-42CC-A78E-734BAB16CB2A}: "URL" = http://search.yahoo....p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
========== FireFox ==========
 
FF - prefs.js..browser.startup.homepage: "about:home"about:home
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.2
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.716
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20091209.4
FF - prefs.js..keyword.URL: ""
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..keyword.URL: "http://search.yahoo....type=994519&p="
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=994519"
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\@virtools.com/3DviaPlayer: C:\Program Files (x86)\Virtools\3D Life Player\npvirtools.dll (Dassault Systèmes)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@citrixonline.com/appdetectorplugin: C:\Users\Wayne\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Wayne\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013/07/07 16:16:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 36.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2015/03/05 20:51:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 36.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2015/03/05 20:51:48 | 000,000,000 | ---D | M]
 
[2010/02/23 18:26:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wayne\AppData\Roaming\Mozilla\Extensions
[2015/03/01 02:06:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\1s3p04df.default-1372534857879\extensions
[2013/10/29 12:08:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\b6kgyt2u.default\extensions
[2010/02/23 19:50:02 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\b6kgyt2u.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/23 19:50:02 | 000,000,000 | ---D | M] (CacheViewer) -- C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\b6kgyt2u.default\extensions\{71328583-3CA7-4809-B4BA-570A85818FBB}
[2010/02/23 19:50:02 | 000,000,000 | ---D | M] (Work Offline) -- C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\b6kgyt2u.default\extensions\{761a54f1-8ccf-4112-9e48-dbf72adf6244}
[2010/02/23 19:50:02 | 000,000,000 | ---D | M] (BugMeNot) -- C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\b6kgyt2u.default\extensions\{987311C6-B504-4aa2-90BF-60CC49808D42}
[2010/02/23 19:50:02 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\b6kgyt2u.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/02/23 19:50:02 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\b6kgyt2u.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/02/23 19:50:03 | 000,000,000 | ---D | M] (CustomizeGoogle) -- C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\b6kgyt2u.default\extensions\{fce36c1e-58d8-498a-b2a5-66ad1cedebbb}
[2010/02/23 19:50:02 | 000,000,000 | ---D | M] (refspoof) -- C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\b6kgyt2u.default\extensions\[email protected]
[2010/02/23 19:50:02 | 000,000,000 | ---D | M] ("VideoDownloader") -- C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\b6kgyt2u.default\extensions\[email protected]
[2015/03/02 09:19:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\nhh3koui.default-1394378070080\extensions
[2015/03/01 02:06:41 | 000,007,807 | ---- | M] () (No name found) -- C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\1s3p04df.default-1372534857879\extensions\[email protected]
[2015/03/02 09:19:27 | 000,985,112 | ---- | M] () (No name found) -- C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\nhh3koui.default-1394378070080\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2015/03/05 20:51:48 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2015/03/05 20:51:48 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2015/03/05 20:51:47 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2015/03/05 20:51:52 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
File not found (No name found) -- C:\PROGRAM FILES (X86)\AVG\AVG9\FIREFOX
 
========== Chrome  ==========
 
CHR - default_search_provider:  (Enabled)
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.76\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.76\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.76\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Browser\nppdf32.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Wayne\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll
CHR - plugin: Java Deployment Toolkit 7.0.70.11 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Windows Activation Technologies (Enabled) = C:\Windows\system32\Wat\npWatWeb.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: No name found = C:\Users\Wayne\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn\4.1.0.404_0\
CHR - Extension: No name found = C:\Users\Wayne\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg\0.3.0.2_0\
CHR - Extension: No name found = C:\Users\Wayne\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.0.0_0\
CHR - Extension: No name found = C:\Users\Wayne\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.126_0\
 
O1 HOSTS File: ([2015/03/01 08:10:25 | 000,000,000 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll File not found
O4:64bit: - HKLM..\Run: [Logitech Download Assistant] C:\Windows\SysNative\LogiLDA.dll (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [NvBackend] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [ShadowPlay] C:\Windows\SysNative\nvspcap64.dll (NVIDIA Corporation)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CPMonitor] C:\Program Files (x86)\Roxio 2012\5.0\CPMonitor.exe ()
O4 - HKLM..\Run: [EMET Notifier] C:\Program Files (x86)\EMET\EMET_notifier.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HostManager] C:\Program Files (x86)\Common Files\aol\1267029088\ee\aolsoftware.exe (AOL Inc.)
O4 - HKLM..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\isuspm.exe (Flexera Software, Inc.)
O4 - HKLM..\Run: [Razer Synapse] C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc.)
O4 - HKCU..\Run: [AOL Fast Start] C:\Program Files (x86)\AOL Desktop 9.7a\AOL.EXE (AOL Inc.)
O4 - HKCU..\Run: [Logitech Vid] C:\Program Files (x86)\Logitech\Logitech Vid\vid.exe (Logitech Inc.)
O4 - HKCU..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWow64\N1Service.dll (Nite Media, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWow64\N1Service.dll (Nite Media, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWow64\N1Service.dll (Nite Media, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWow64\N1Service.dll (Nite Media, LLC)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\SysWow64\N1Service.dll (Nite Media, LLC)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range -  5)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.222.18.222 209.222.18.218
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0E74BCD5-1CB4-4C48-BDE3-D272D10CBE2C}: DhcpNameServer = 209.222.18.222 209.222.18.218
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4F9C464A-587C-4F7D-9A72-12BAFA6931C5}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\linkscanner - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\linkscanner - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (bootdelete)
O34 - HKLM BootExecute: (bootdelete)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
========== Files/Folders - Created Within 30 Days ==========
 
[2015/03/06 00:09:25 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MozyHome
[2015/03/06 00:09:18 | 000,069,320 | ---- | C] (Mozy, Inc.) -- C:\Windows\SysNative\drivers\mozy.sys
[2015/03/06 00:09:17 | 000,000,000 | ---D | C] -- C:\Program Files\MozyHome
[2015/03/05 23:58:23 | 000,000,000 | ---D | C] -- C:\Users\Wayne\AppData\Local\mozysync
[2015/03/05 23:58:19 | 000,000,000 | ---D | C] -- C:\Program Files\Mozy Sync
[2015/03/05 23:58:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozy
[2015/03/05 20:51:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2015/03/03 19:16:43 | 000,000,000 | ---D | C] -- C:\Users\Wayne\AppData\Local\Mozy Restore Manager
[2015/03/03 19:16:39 | 000,000,000 | ---D | C] -- C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozy
[2015/03/03 19:16:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozy
[2015/03/02 09:37:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Viewpoint
[2015/03/02 09:37:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Viewpoint
[2015/03/01 08:12:53 | 000,000,000 | ---D | C] -- C:\EEK
[2015/03/01 08:08:07 | 000,000,000 | ---D | C] -- C:\Users\Wayne\AppData\Local\CrashDumps
[2015/03/01 08:01:33 | 000,000,000 | ---D | C] -- C:\ProgramData\RogueKiller
[2015/03/01 07:49:13 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2015/03/01 07:32:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
[2015/03/01 07:32:37 | 000,000,000 | ---D | C] -- C:\Program Files\HitmanPro
[2015/03/01 07:31:52 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2015/03/01 02:56:22 | 000,129,752 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2015/03/01 02:56:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
[2015/03/01 02:56:04 | 000,093,400 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2015/03/01 02:56:04 | 000,063,704 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2015/03/01 02:56:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2015/03/01 02:16:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Opera
[2015/03/01 02:15:30 | 000,324,760 | ---- | C] (Nite Media, LLC) -- C:\Windows\SysWow64\N1Service.dll
[2015/03/01 02:15:29 | 000,000,000 | ---D | C] -- C:\Windows\NMsvc
[2015/03/01 02:15:29 | 000,000,000 | ---D | C] -- C:\Windows\msservice
[2015/03/01 02:11:43 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\ShopperPro
[2015/03/01 02:09:22 | 000,000,000 | ---D | C] -- C:\ProgramData\SearchModulePlus
[2015/02/26 03:00:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft ASP.NET
[2015/02/24 02:26:43 | 000,000,000 | ---D | C] -- C:\Users\Wayne\Desktop\Scan0008
[2015/02/07 16:57:44 | 000,000,000 | ---D | C] -- C:\Users\Wayne\AppData\Local\ElevatedDiagnostics
[2015/02/07 16:38:58 | 000,000,000 | -HSD | C] -- C:\Users\Wayne\AppData\Local\EmieBrowserModeList
[2015/02/07 16:29:50 | 000,000,000 | ---D | C] -- C:\Users\Wayne\AppData\Local\Skype
[2015/02/07 16:29:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[5 C:\Users\Wayne\Desktop\*.tmp files -> C:\Users\Wayne\Desktop\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2015/03/07 09:32:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015/03/07 09:15:30 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2015/03/07 07:53:17 | 000,022,784 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2015/03/07 07:53:17 | 000,022,784 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2015/03/07 07:44:37 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2015/03/07 07:42:47 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2015/03/07 07:42:18 | 000,043,664 | ---- | M] () -- C:\Windows\SysNative\drivers\hitmanpro37.sys
[2015/03/07 07:42:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015/03/07 07:42:09 | 529,932,287 | -HS- | M] () -- C:\hiberfil.sys
[2015/03/07 07:42:02 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\drivers\lvuvc.hs
[2015/03/07 07:31:04 | 000,008,578 | ---- | M] () -- C:\Windows\SysNative\.crusader
[2015/03/06 00:09:25 | 000,000,913 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MozyHome Status.lnk
[2015/03/05 23:31:14 | 000,002,044 | ---- | M] () -- C:\Users\Wayne\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2015/03/05 11:29:04 | 000,377,921 | ---- | M] () -- C:\Users\Wayne\Desktop\cattoilet.jpg
[2015/03/01 08:12:59 | 000,000,743 | ---- | M] () -- C:\Users\Wayne\Desktop\Start Emsisoft Emergency Kit.lnk
[2015/03/01 08:10:25 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2015/03/01 08:01:34 | 000,035,064 | ---- | M] () -- C:\Windows\SysNative\drivers\TrueSight.sys
[2015/03/01 07:32:37 | 000,001,893 | ---- | M] () -- C:\Users\Public\Desktop\HitmanPro.lnk
[2015/03/01 02:56:06 | 000,001,102 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2015/03/01 02:30:47 | 000,002,279 | ---- | M] () -- C:\Users\Wayne\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2015/03/01 02:30:47 | 000,001,437 | ---- | M] () -- C:\Users\Wayne\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2015/03/01 02:15:45 | 000,002,384 | ---- | M] () -- C:\Windows\SysNative\N1ServiceOff.ini
[2015/03/01 02:03:38 | 000,001,075 | ---- | M] () -- C:\Users\Wayne\Desktop\Continue installation .lnk
[2015/02/26 19:40:11 | 000,519,847 | ---- | M] () -- C:\Users\Wayne\Desktop\jackieworkproblems.jpg
[2015/02/24 19:54:56 | 000,202,484 | -H-- | M] () -- C:\Users\Wayne\Desktop\PP11Thumbs.ptn
[2015/02/24 19:54:56 | 000,001,696 | -H-- | M] () -- C:\Users\Wayne\Desktop\maxdesk.ini2
[2015/02/24 19:54:56 | 000,000,088 | -H-- | M] () -- C:\Users\Wayne\Desktop\PP11Thumbs.ptn2
[2015/02/24 19:54:47 | 001,446,353 | ---- | M] () -- C:\Users\Wayne\Desktop\royaagreement (3).jpg
[2015/02/24 19:54:46 | 002,517,744 | ---- | M] () -- C:\Users\Wayne\Desktop\royaagreement (2).jpg
[2015/02/24 19:54:46 | 001,602,077 | ---- | M] () -- C:\Users\Wayne\Desktop\royaagreement.jpg
[2015/02/24 19:45:33 | 000,531,303 | ---- | M] () -- C:\Users\Wayne\Desktop\EngagementAgreement.pdf
[2015/02/24 02:26:43 | 001,473,391 | ---- | M] () -- C:\Users\Wayne\Desktop\Scan0008.zip
[2015/02/24 02:25:23 | 000,461,091 | ---- | M] () -- C:\Users\Wayne\Desktop\Scan0001.jpg
[2015/02/22 17:47:55 | 000,024,904 | ---- | M] () -- C:\Users\Wayne\Desktop\Capture1.jpg
[2015/02/22 17:46:42 | 000,279,484 | ---- | M] () -- C:\Users\Wayne\Desktop\Capture.JPG
[2015/02/14 18:17:15 | 000,000,700 | ---- | M] () -- C:\Windows\tasks\Open Chrome.job
[2015/02/14 11:31:16 | 000,095,567 | ---- | M] () -- C:\Users\Wayne\Desktop\gameloftMLPreceipt.JPG
[2015/02/11 03:44:01 | 000,470,416 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2015/02/10 15:45:34 | 001,947,928 | ---- | M] () -- C:\Users\Wayne\Desktop\Label-325841048.pdf
[2015/02/08 17:40:38 | 001,202,693 | ---- | M] () -- C:\Users\Wayne\Desktop\IMAG0023.jpg
[5 C:\Users\Wayne\Desktop\*.tmp files -> C:\Users\Wayne\Desktop\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2015/03/07 07:42:18 | 000,043,664 | ---- | C] () -- C:\Windows\SysNative\drivers\hitmanpro37.sys
[2015/03/06 00:09:25 | 000,000,913 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MozyHome Status.lnk
[2015/03/05 11:28:29 | 000,377,921 | ---- | C] () -- C:\Users\Wayne\Desktop\cattoilet.jpg
[2015/03/01 08:12:59 | 000,000,743 | ---- | C] () -- C:\Users\Wayne\Desktop\Start Emsisoft Emergency Kit.lnk
[2015/03/01 08:01:34 | 000,035,064 | ---- | C] () -- C:\Windows\SysNative\drivers\TrueSight.sys
[2015/03/01 07:40:51 | 000,008,578 | ---- | C] () -- C:\Windows\SysNative\.crusader
[2015/03/01 07:32:37 | 000,001,893 | ---- | C] () -- C:\Users\Public\Desktop\HitmanPro.lnk
[2015/03/01 02:56:06 | 000,001,102 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2015/03/01 02:15:45 | 000,002,384 | ---- | C] () -- C:\Windows\SysNative\N1ServiceOff.ini
[2015/03/01 02:03:38 | 000,001,075 | ---- | C] () -- C:\Users\Wayne\Desktop\Continue installation .lnk
[2015/02/26 19:38:53 | 000,519,847 | ---- | C] () -- C:\Users\Wayne\Desktop\jackieworkproblems.jpg
[2015/02/24 19:54:46 | 002,517,744 | ---- | C] () -- C:\Users\Wayne\Desktop\royaagreement (2).jpg
[2015/02/24 19:54:46 | 001,446,353 | ---- | C] () -- C:\Users\Wayne\Desktop\royaagreement (3).jpg
[2015/02/24 19:54:45 | 001,602,077 | ---- | C] () -- C:\Users\Wayne\Desktop\royaagreement.jpg
[2015/02/24 19:45:29 | 000,531,303 | ---- | C] () -- C:\Users\Wayne\Desktop\EngagementAgreement.pdf
[2015/02/24 02:26:31 | 001,473,391 | ---- | C] () -- C:\Users\Wayne\Desktop\Scan0008.zip
[2015/02/24 02:25:01 | 000,461,091 | ---- | C] () -- C:\Users\Wayne\Desktop\Scan0001.jpg
[2015/02/22 17:47:55 | 000,024,904 | ---- | C] () -- C:\Users\Wayne\Desktop\Capture1.jpg
[2015/02/22 17:46:39 | 000,279,484 | ---- | C] () -- C:\Users\Wayne\Desktop\Capture.JPG
[2015/02/14 15:21:06 | 000,000,700 | ---- | C] () -- C:\Windows\tasks\Open Chrome.job
[2015/02/14 11:31:15 | 000,095,567 | ---- | C] () -- C:\Users\Wayne\Desktop\gameloftMLPreceipt.JPG
[2015/02/10 13:47:53 | 001,947,928 | ---- | C] () -- C:\Users\Wayne\Desktop\Label-325841048.pdf
[2015/02/08 17:40:28 | 001,202,693 | ---- | C] () -- C:\Users\Wayne\Desktop\IMAG0023.jpg
[2015/01/19 06:24:28 | 000,000,095 | ---- | C] () -- C:\Windows\NMI.ini
[2014/07/25 21:02:40 | 000,000,495 | ---- | C] () -- C:\Users\Wayne\request.xml
[2014/07/25 21:02:40 | 000,000,491 | ---- | C] () -- C:\Users\Wayne\response.xml
[2014/07/02 07:43:54 | 000,006,336 | ---- | C] () -- C:\Users\Wayne\AppData\Local\rx_audio.Cache
[2013/07/10 11:17:21 | 000,000,000 | ---- | C] () -- C:\Users\Wayne\AppData\Local\rx_image32.Cache
[2013/01/21 15:58:48 | 000,005,120 | ---- | C] () -- C:\Users\Wayne\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/12/26 14:43:50 | 000,046,117 | ---- | C] () -- C:\Users\Wayne\AppData\Local\jjnbtrhk
[2012/12/26 14:36:41 | 000,000,000 | ---- | C] () -- C:\Users\Wayne\AppData\Roaming\SharedSettings.ccs
[2012/12/26 14:30:25 | 000,006,524 | ---- | C] () -- C:\Users\Wayne\AppData\Local\1786b1d9-8e44-4993-b87c-f8b0702c8038.crx
[2012/05/03 14:54:38 | 000,000,218 | ---- | C] () -- C:\Users\Wayne\AppData\Local\recently-used.xbel
[2012/03/12 19:38:49 | 000,007,597 | ---- | C] () -- C:\Users\Wayne\AppData\Local\Resmon.ResmonCfg
[2010/08/09 17:33:29 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/06/07 05:46:46 | 000,000,760 | ---- | C] () -- C:\Users\Wayne\AppData\Roaming\setup_ldm.iss
[2010/02/23 19:26:00 | 000,000,026 | -H-- | C] () -- C:\ProgramData\.811261211181235583101118113995
 
========== ZeroAccess Check ==========
 
[2009/07/13 20:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/06/24 18:05:42 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/06/24 17:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 17:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 04:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 17:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2010/09/20 22:23:18 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\.minecraft
[2011/10/04 11:37:35 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\22950016-A91E-4F84-B449-6D543E65BBF4
[2010/10/17 06:53:34 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\Acronis
[2013/02/19 13:40:16 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\Amazon
[2015/02/14 15:28:48 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\AVG
[2013/11/03 13:07:54 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\AVG2014
[2015/03/07 07:39:49 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\Azureus
[2013/08/03 09:38:33 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\com.torparse.TorparseApplication
[2012/12/26 14:17:25 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\Essiu
[2010/02/23 19:26:28 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\Final Draft
[2010/11/28 09:27:07 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\IMCapture for Skype
[2010/08/08 11:58:24 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\Leadertech
[2012/01/07 13:33:03 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\LolClient
[2012/12/26 14:14:45 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\Miun
[2012/08/23 06:47:06 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\mkvtoolnix
[2014/07/02 07:23:37 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\Mp3 Audio Editor
[2014/10/31 09:31:58 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\Mumble
[2012/05/03 13:00:29 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\Participatory Culture Foundation
[2011/10/04 11:51:13 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\QuickScan
[2010/03/06 12:53:34 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\ScanSoft
[2010/12/26 07:17:55 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\Smith Micro
[2011/01/07 10:15:49 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\SystemRequirementsLab
[2014/07/28 14:10:16 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\Titanium
[2014/01/20 10:40:18 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\TS3Client
[2012/12/26 21:49:12 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\TuneUp Software
[2010/05/06 19:19:55 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\Unity
[2010/07/06 19:19:30 | 000,000,000 | ---D | M] -- C:\Users\Wayne\AppData\Roaming\Yamb
 
========== Purity Check ==========
 
 
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 181 bytes -> C:\ProgramData\Temp:0B4227B4

< End of report >
 

 


  • 0

Advertisements


#2
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts

:welcome:
 
Please download Farbar Recovery Scan Tool and save it to your desktop.
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  •  
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Make sure that under Optional Scans, there is a checkmark on Addition.txt and Shortcut.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The tool will also produce another two logs (Addition.txt and Shortcut.txt). Please attach these to your reply.

  • 0

#3
wemogil

wemogil

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

Thanks for the reply.  Here are the contents of the txt files:

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-03-2015 03
Ran by Wayne (administrator) on WAYNE-PC on 08-03-2015 14:55:22
Running from C:\Users\Wayne\Downloads
Loaded Profiles: Wayne (Available profiles: Wayne)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgfws.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(LeapFrog Enterprises, Inc.) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(SurfRight B.V.) C:\Program Files\HitmanPro\HitmanPro.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
() C:\Program Files\pyTivo\pyTivoService.exe
(Razer) C:\Program Files (x86)\Razer\Core\64bit\RzOvlMon.exe
() C:\Python26\python.exe
() C:\Program Files\pia_manager\pia_manager.exe
(http://www.ruby-lang.org/) C:\Users\Wayne\AppData\Local\Temp\ocr1F3B.tmp\bin\rubyw.exe
() C:\Program Files\pia_manager\pia_manager.exe
(http://www.ruby-lang.org/) C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\bin\rubyw.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
() C:\Program Files\pia_manager\pia_tray\pia_tray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\Logitech Vid\Vid.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(AOL Inc.) C:\Program Files (x86)\AOL Desktop 9.7a\waol.exe
(Microsoft Corporation) C:\Program Files (x86)\EMET\EMET_notifier.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(AOL Inc.) C:\Program Files (x86)\Common Files\aol\1267029088\ee\aolsoftware.exe
(Microsoft Corporation) C:\Windows\System32\WerFault.exe
(AOL Inc.) C:\Program Files (x86)\Common Files\aol\acs\AOLacsd.exe
(AOL Inc.) C:\Program Files (x86)\AOL Desktop 9.7a\shellmon.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(AOL Inc.) C:\Program Files (x86)\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe
(Mozilla Foundation) C:\Program Files (x86)\Mozilla Firefox\crashreporter.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
() C:\Program Files (x86)\Mozy\Mozy Restore Manager\MozyRestoreManager.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe
() C:\Program Files\pia_manager\openvpn.exe
(AOL Inc.) C:\Program Files (x86)\AOL Desktop 9.7a\aolbrowser.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat.exe
(Macrovision Europe Ltd.) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
(Farbar) C:\Users\Wayne\Downloads\FRST64(1).exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [BrMfcWnd] => C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe [1159168 2009-05-26] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [EMET Notifier] => C:\Program Files (x86)\EMET\EMET_notifier.exe [152152 2012-05-09] (Microsoft Corporation)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5188112 2014-12-16] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [324976 2010-05-21] (Flexera Software, Inc.)
HKLM-x32\...\Run: [CPMonitor] => C:\Program Files (x86)\Roxio 2012\5.0\CPMonitor.exe [84464 2011-07-08] ()
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [610152 2013-06-21] (Razer Inc.)
HKLM-x32\...\Run: [HostManager] => C:\Program Files (x86)\Common Files\AOL\1267029088\ee\AOLSoftware.exe [41800 2010-03-08] (AOL Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-04-23] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKU\S-1-5-21-2408619476-591646424-3276866331-1001\...\Run: [Logitech Vid] => C:\Program Files (x86)\Logitech\Logitech Vid\vid.exe [6061400 2010-05-11] (Logitech Inc.)
HKU\S-1-5-21-2408619476-591646424-3276866331-1001\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-13] (Microsoft Corporation)
HKU\S-1-5-21-2408619476-591646424-3276866331-1001\...\Run: [AOL Fast Start] => C:\Program Files (x86)\AOL Desktop 9.7a\AOL.EXE [72296 2014-08-19] (AOL Inc.)
ShellIconOverlayIdentifiers: [ mozysyncNotUploaded] -> {34DF8AC2-A6BB-4855-B45A-CC1B4D9183E3} => C:\Program Files\Mozy Sync\mozysyncshell.dll (Mozy, Inc.)
ShellIconOverlayIdentifiers: [ mozysyncPendingChanges] -> {6673BC77-4A7B-4299-A130-14312E6B203A} => C:\Program Files\Mozy Sync\mozysyncshell.dll (Mozy, Inc.)
ShellIconOverlayIdentifiers: [ mozysyncUpToDate] -> {04547006-32F5-4635-844B-B8D7FCE47692} => C:\Program Files\Mozy Sync\mozysyncshell.dll (Mozy, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} =>  No File
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} =>  No File
ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} =>  No File
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} =>  No File
BootExecute: autocheck autochk * bootdeletebootdelete

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2408619476-591646424-3276866331-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft...d=ie&ar=msnhome
HKU\S-1-5-21-2408619476-591646424-3276866331-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
HKU\S-1-5-21-2408619476-591646424-3276866331-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2408619476-591646424-3276866331-1001 -> {6B72EDE3-E0C3-42CC-A78E-734BAB16CB2A} URL = http://search.yahoo....p={searchTerms}
BHO-x32: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll [2011-05-23] (DivX, LLC)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-10-10] (Skype Technologies S.A.)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll No File
Toolbar: HKU\S-1-5-21-2408619476-591646424-3276866331-1001 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
Toolbar: HKU\S-1-5-21-2408619476-591646424-3276866331-1001 -> No Name - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} -  No File
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -  No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-10-10] (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Winsock: Catalog9 01 C:\Windows\SysWOW64\N1Service.dll [324760] (Nite Media, LLC)
Winsock: Catalog9 02 C:\Windows\SysWOW64\N1Service.dll [324760] (Nite Media, LLC)
Winsock: Catalog9 03 C:\Windows\SysWOW64\N1Service.dll [324760] (Nite Media, LLC)
Winsock: Catalog9 04 C:\Windows\SysWOW64\N1Service.dll [324760] (Nite Media, LLC)
Winsock: Catalog9 15 C:\Windows\SysWOW64\N1Service.dll [324760] (Nite Media, LLC)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\nhh3koui.default-1394378070080
FF NewTab:
FF DefaultSearchEngine: Google
FF DefaultSearchEngine.US: Google
FF SelectedSearchEngine:
FF Homepage: hxxp://www.google.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-05] ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll [2011-06-20] (DivX, LLC.)
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2010-02-26] (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-05] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-21] ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll [2011-05-25] (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2011-06-20] (DivX, LLC.)
FF Plugin-x32: @java.com/DTPlugin,version=10.7.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2012-09-22] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll [2010-02-26] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-07-02] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-07-02] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2012-01-07] (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-03] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin-x32: @viewpoint.com/VMP -> C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll [2004-02-20] ()
FF Plugin-x32: @virtools.com/3DviaPlayer -> C:\Program Files (x86)\Virtools\3D Life Player\npvirtools.dll [2012-04-05] (Dassault Systèmes)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-02] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2408619476-591646424-3276866331-1001: @citrixonline.com/appdetectorplugin -> C:\Users\Wayne\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2014-01-03] (Citrix Online)
FF Plugin HKU\S-1-5-21-2408619476-591646424-3276866331-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Wayne\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2009-11-30] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-2408619476-591646424-3276866331-1001: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll [2013-01-23] (Amazon.com, Inc.)
FF Plugin HKU\S-1-5-21-2408619476-591646424-3276866331-1001: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2012-01-07] (Pando Networks)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2014-12-02] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-05-27] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-05-27] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-05-27] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-05-27] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-05-27] (Apple Inc.)
FF Extension: Adblock Plus - C:\Users\Wayne\AppData\Roaming\Mozilla\Firefox\Profiles\nhh3koui.default-1394378070080\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-03-02]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2015-03-05]
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 &lt;video&gt; - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013-07-07]

Chrome:
=======
CHR StartupUrls: Default -> "hxxp://search.yahoo.com?type=994519&fr=spigot-yhp-ch", "hxxp://www.google.com"
CHR DefaultSearchKeyword: Default -> default-search.net
CHR DefaultSearchURL: Default -> http://www.default-s...p={searchTerms}
CHR DefaultSuggestURL: Default ->
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.76\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.76\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.76\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.2) - C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll No File
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Unity Player) - C:\Users\Wayne\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.70.11) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Windows Activation Technologies) - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Profile: C:\Users\Wayne\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (AVG Secure Search) - C:\Users\Wayne\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn [2015-03-03]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Wayne\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-04]
CHR Extension: (Google Wallet) - C:\Users\Wayne\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-27]
CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\Wayne\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2014-05-27]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-05-23]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S4 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269; C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe [457200 2011-02-09] ()
S4 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 avgfws; C:\Program Files (x86)\AVG\AVG2014\avgfws.exe [1417160 2014-12-16] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3247120 2014-12-16] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-12-16] (AVG Technologies CZ, s.r.o.)
S4 BOT4Service; C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe [21488 2011-07-15] ()
S4 BOTService; C:\Program Files (x86)\Roxio\BackOnTrack\Instant Restore\BOTService.exe [211440 2011-07-14] (Rovi Corporation)
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2012-04-22] (Creative Labs) [File not signed]
R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-01-27] (Creative Technology Ltd) [File not signed]
R3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2010-02-25] (Macrovision Europe Ltd.) [File not signed]
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [127752 2015-03-01] (SurfRight B.V.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 LeapFrog Connect Device Service; C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe [7393280 2013-11-27] (LeapFrog Enterprises, Inc.) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation)
S4 OverwolfUpdaterService; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [18360 2013-10-23] (Overwolf Ltd)
R2 pyTivo; C:\Program Files\pyTivo\pyTivoService.exe [77824 2008-05-02] () [File not signed]
S4 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [247152 2009-04-17] ()
S4 RoxMediaDB13; C:\Program Files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxMediaDB13.exe [1095664 2011-07-13] (Rovi Corporation)
S4 RoxWatch12; C:\Program Files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxWatch13.exe [340976 2011-07-13] (Rovi Corporation)
R2 RzOvlMon; C:\Program Files (x86)\Razer\Core\64bit\rzovlmon.exe [32984 2013-07-11] (Razer)
S4 TivoBeacon2; C:\Program Files (x86)\TiVo\Desktop\TiVoBeacon.exe [1104656 2010-05-17] (TiVo Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
S3 getPlusHelper; C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 A2DDA; C:\EEK\bin\a2ddax64.sys [26176 2015-03-01] (Emsisoft GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-06-30] (AVG Technologies CZ, s.r.o.)
R1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6a.sys [57144 2013-09-26] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [244504 2014-07-21] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [237848 2014-10-24] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-10-29] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [269080 2014-10-20] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [52000 2014-12-27] (AVG Technologies)
S3 cleanhlp; C:\EEK\bin\cleanhlp64.sys [57024 2015-03-01] (Emsisoft GmbH)
R3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [43664 2015-03-07] ()
R1 HssDRV6; C:\Windows\System32\DRIVERS\hssdrv6.sys [41704 2012-07-24] (AnchorFree Inc.)
S3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30304 2010-05-07] ()
S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30304 2010-05-07] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-03-08] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
R3 RzDxgk; C:\Windows\system32\drivers\RzDxgk.sys [128856 2013-07-11] (Razer USA Ltd)
R3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [39096 2013-07-09] (Razer Inc)
R0 RzFilter; C:\Windows\System32\drivers\RzFilter.sys [74456 2013-07-11] (Razer USA Ltd)
R3 rzmpos; C:\Windows\System32\DRIVERS\rzmpos.sys [34488 2013-07-09] (Razer Inc)
R0 SysCow; C:\Windows\System32\drivers\syscowad64v.sys [164848 2010-05-23] (Sonic Solutions)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2015-03-01] ()
R0 vidsflt53; C:\Windows\System32\DRIVERS\vsflt53.sys [141920 2011-10-04] (Acronis)
U4 bdselfpr; No ImagePath
R4 mozyFilter; system32\DRIVERS\mozy.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-08 14:55 - 2015-03-08 14:55 - 00029440 _____ () C:\Users\Wayne\Downloads\FRST.txt
2015-03-08 14:54 - 2015-03-08 14:54 - 02095104 _____ (Farbar) C:\Users\Wayne\Downloads\FRST64(1).exe
2015-03-07 11:09 - 2015-03-07 11:09 - 00022320 _____ () C:\Users\Wayne\Desktop\HitmanPro_20150307_1009.log
2015-03-07 10:59 - 2015-03-08 14:55 - 00000000 ____D () C:\FRST
2015-03-07 10:42 - 2015-03-07 10:42 - 00124418 _____ () C:\Users\Wayne\Downloads\Extras.Txt
2015-03-07 10:41 - 2015-03-07 10:41 - 00156254 _____ () C:\Users\Wayne\Downloads\OTL.Txt
2015-03-07 10:26 - 2015-03-07 10:26 - 00602112 _____ (OldTimer Tools) C:\Users\Wayne\Downloads\OTL.exe
2015-03-07 10:21 - 2015-03-07 10:21 - 02094592 _____ (Farbar) C:\Users\Wayne\Downloads\FRST64.exe
2015-03-07 08:42 - 2015-03-07 12:27 - 00043664 _____ () C:\Windows\system32\Drivers\hitmanpro37.sys
2015-03-06 01:09 - 2015-03-07 18:04 - 00000000 ____D () C:\Program Files\MozyHome
2015-03-06 00:58 - 2015-03-06 00:58 - 13326752 _____ (Mozy, Inc.) C:\Users\Wayne\Downloads\mozysetup.exe
2015-03-06 00:58 - 2015-03-06 00:58 - 00000000 ____D () C:\Users\Wayne\AppData\Local\mozysync
2015-03-06 00:58 - 2015-03-06 00:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozy
2015-03-06 00:58 - 2015-03-06 00:58 - 00000000 ____D () C:\Program Files\Mozy Sync
2015-03-06 00:56 - 2015-03-06 00:57 - 09188320 _____ () C:\Users\Wayne\Downloads\mozy-sync.exe
2015-03-05 21:51 - 2015-03-05 21:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-03-03 20:16 - 2015-03-07 17:47 - 00000000 ____D () C:\Users\Wayne\AppData\Local\Mozy Restore Manager
2015-03-03 20:16 - 2015-03-03 20:16 - 00000000 ____D () C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozy
2015-03-03 20:16 - 2015-03-03 20:16 - 00000000 ____D () C:\Program Files (x86)\Mozy
2015-03-03 12:51 - 2015-01-08 20:14 - 00950272 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll
2015-03-03 12:51 - 2015-01-08 20:14 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll
2015-03-03 12:51 - 2015-01-08 20:14 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll
2015-03-03 12:51 - 2015-01-08 19:48 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdi.dll
2015-03-02 10:37 - 2015-03-02 10:37 - 00000000 ____D () C:\ProgramData\Viewpoint
2015-03-02 10:37 - 2015-03-02 10:37 - 00000000 ____D () C:\Program Files (x86)\Viewpoint
2015-03-01 11:06 - 2015-03-01 11:06 - 00024338 _____ () C:\Users\Wayne\Downloads\ViewpointKiller.zip
2015-03-01 10:57 - 2015-03-01 10:57 - 00232200 _____ () C:\Users\Wayne\Downloads\ViewpointKiller-26899324.exe
2015-03-01 09:12 - 2015-03-01 09:13 - 00000000 ____D () C:\EEK
2015-03-01 09:12 - 2015-03-01 09:12 - 00000743 _____ () C:\Users\Wayne\Desktop\Start Emsisoft Emergency Kit.lnk
2015-03-01 09:11 - 2015-03-01 09:12 - 163924848 _____ () C:\Users\Wayne\Downloads\EmsisoftEmergencyKit.exe
2015-03-01 09:08 - 2015-03-07 16:24 - 00000000 ____D () C:\Users\Wayne\AppData\Local\CrashDumps
2015-03-01 09:01 - 2015-03-01 09:01 - 15536728 _____ () C:\Users\Wayne\Downloads\RogueKiller.exe
2015-03-01 09:01 - 2015-03-01 09:01 - 00035064 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2015-03-01 09:01 - 2015-03-01 09:01 - 00000000 ____D () C:\ProgramData\RogueKiller
2015-03-01 08:49 - 2015-03-01 08:55 - 00000000 ____D () C:\AdwCleaner
2015-03-01 08:48 - 2015-03-01 08:48 - 02126848 _____ () C:\Users\Wayne\Downloads\adwcleaner_4.111.exe
2015-03-01 08:40 - 2015-03-07 08:31 - 00008578 _____ () C:\Windows\system32\.crusader
2015-03-01 08:32 - 2015-03-01 08:32 - 00001893 _____ () C:\Users\Public\Desktop\HitmanPro.lnk
2015-03-01 08:32 - 2015-03-01 08:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2015-03-01 08:32 - 2015-03-01 08:32 - 00000000 ____D () C:\Program Files\HitmanPro
2015-03-01 08:31 - 2015-03-01 08:41 - 00000000 ____D () C:\ProgramData\HitmanPro
2015-03-01 08:30 - 2015-03-01 08:31 - 10995632 _____ (SurfRight B.V.) C:\Users\Wayne\Downloads\HitmanPro_x64.exe
2015-03-01 03:56 - 2015-03-08 14:32 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-03-01 03:56 - 2015-03-01 03:56 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-03-01 03:56 - 2015-03-01 03:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-03-01 03:56 - 2015-03-01 03:56 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-03-01 03:56 - 2014-11-21 07:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-03-01 03:56 - 2014-11-21 07:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-03-01 03:54 - 2015-03-01 03:54 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Wayne\Downloads\mbam-setup-2.0.4.1028.exe
2015-03-01 03:44 - 2015-03-01 03:46 - 00003036 _____ () C:\Users\Wayne\Desktop\Rkill.txt
2015-03-01 03:43 - 2015-03-01 03:43 - 01943800 _____ (Bleeping Computer, LLC) C:\Users\Wayne\Downloads\iExplore.exe
2015-03-01 03:41 - 2015-03-01 03:41 - 04197016 _____ (Kaspersky Lab ZAO) C:\Users\Wayne\Downloads\tdsskiller(1).exe
2015-03-01 03:16 - 2015-03-01 03:29 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-03-01 03:16 - 2015-03-01 03:16 - 00003820 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1425205012
2015-03-01 03:15 - 2015-03-01 03:30 - 00000000 ____D () C:\Windows\NMsvc
2015-03-01 03:15 - 2015-03-01 03:15 - 00003558 _____ () C:\Windows\System32\Tasks\BLZYASW
2015-03-01 03:15 - 2015-03-01 03:15 - 00002384 _____ () C:\Windows\system32\N1ServiceOff.ini
2015-03-01 03:15 - 2015-03-01 03:15 - 00000000 ____D () C:\Windows\msservice
2015-03-01 03:15 - 2015-01-19 07:24 - 00324760 _____ (Nite Media, LLC) C:\Windows\SysWOW64\N1Service.dll
2015-03-01 03:11 - 2015-03-01 03:11 - 00000000 ____D () C:\Users\Public\Documents\ShopperPro
2015-03-01 03:09 - 2015-03-01 03:09 - 00000000 ____D () C:\ProgramData\SearchModulePlus
2015-03-01 03:03 - 2015-03-01 03:03 - 00001075 _____ () C:\Users\Wayne\Desktop\Continue installation .lnk
2015-03-01 02:55 - 2015-03-01 02:55 - 00149504 _____ () C:\Users\Wayne\Downloads\Google Books Downloader Lite.exe
2015-03-01 02:55 - 2015-03-01 02:55 - 00149504 _____ () C:\Users\Wayne\Downloads\Google Books Downloader Lite(1).exe
2015-02-26 04:00 - 2015-02-26 04:00 - 00000000 ____D () C:\Program Files (x86)\Microsoft ASP.NET
2015-02-25 04:00 - 2015-01-08 16:44 - 00419936 _____ () C:\Windows\SysWOW64\locale.nls
2015-02-25 04:00 - 2015-01-08 16:43 - 00419936 _____ () C:\Windows\system32\locale.nls
2015-02-24 03:26 - 2015-02-24 03:26 - 01473391 _____ () C:\Users\Wayne\Desktop\Scan0008.zip
2015-02-24 03:26 - 2015-02-24 03:26 - 00000000 ____D () C:\Users\Wayne\Desktop\Scan0008
2015-02-14 19:18 - 2015-02-14 19:18 - 00000988 _____ () C:\Users\Wayne\.pia_manager_crash.log
2015-02-14 16:21 - 2015-02-14 19:17 - 00000700 _____ () C:\Windows\Tasks\Open Chrome.job
2015-02-14 16:21 - 2015-02-14 16:21 - 00003018 _____ () C:\Windows\System32\Tasks\Open Chrome
2015-02-14 16:19 - 2015-02-14 16:19 - 00001862 _____ () C:\Users\Wayne\Uninstall-VzInHomeAgentlog.log
2015-02-11 09:27 - 2015-01-22 21:42 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-02-11 09:27 - 2015-01-22 21:41 - 06041600 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-02-11 09:27 - 2015-01-22 20:43 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-02-11 09:27 - 2015-01-22 20:17 - 04300800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-02-10 14:08 - 2015-02-03 20:16 - 00894976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-02-10 14:08 - 2015-02-03 20:16 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-02-10 14:08 - 2015-02-03 20:16 - 00609280 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-02-10 14:08 - 2015-02-03 20:16 - 00414720 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-02-10 14:08 - 2015-02-03 20:16 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-02-10 14:08 - 2015-02-03 20:16 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-02-10 14:08 - 2015-02-03 20:13 - 01098752 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-02-10 14:08 - 2015-01-27 16:36 - 01239720 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2015-02-10 14:08 - 2015-01-09 23:48 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-02-10 14:08 - 2015-01-09 23:48 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-02-10 14:08 - 2015-01-09 23:48 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-02-10 14:08 - 2015-01-09 23:48 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-02-10 14:08 - 2015-01-09 23:48 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-02-10 14:08 - 2015-01-09 23:48 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-02-10 14:08 - 2015-01-09 23:48 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-02-10 14:08 - 2015-01-09 23:27 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-02-10 14:08 - 2015-01-09 23:27 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-02-10 14:08 - 2015-01-09 23:27 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-02-10 14:08 - 2015-01-09 23:27 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-02-10 14:08 - 2015-01-09 23:27 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-02-10 14:08 - 2015-01-09 23:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-02-10 14:08 - 2015-01-09 23:27 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-02-10 14:07 - 2015-01-15 01:14 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-02-10 14:07 - 2015-01-15 01:14 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-02-10 14:07 - 2015-01-15 01:09 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-02-10 14:07 - 2015-01-15 01:09 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-02-10 14:07 - 2015-01-15 01:09 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-02-10 14:07 - 2015-01-15 01:09 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-02-10 14:07 - 2015-01-15 01:09 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-02-10 14:07 - 2015-01-15 01:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-02-10 14:07 - 2015-01-15 01:06 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-02-10 14:07 - 2015-01-15 01:06 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-02-10 14:07 - 2015-01-15 01:04 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-02-10 14:07 - 2015-01-15 00:42 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-02-10 14:07 - 2015-01-15 00:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-02-10 14:07 - 2015-01-15 00:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-02-10 14:07 - 2015-01-15 00:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-02-10 14:07 - 2015-01-15 00:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-02-10 14:07 - 2015-01-15 00:37 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-02-10 14:07 - 2015-01-14 21:22 - 00458824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-02-10 14:07 - 2015-01-13 22:47 - 00389808 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-02-10 14:07 - 2015-01-13 22:09 - 00342712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-02-10 14:07 - 2015-01-12 20:10 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-02-10 14:07 - 2015-01-12 19:49 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-02-10 14:07 - 2015-01-11 20:09 - 25056256 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-02-10 14:07 - 2015-01-11 20:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-02-10 14:07 - 2015-01-11 20:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-02-10 14:07 - 2015-01-11 19:49 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-02-10 14:07 - 2015-01-11 19:48 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-02-10 14:07 - 2015-01-11 19:48 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-02-10 14:07 - 2015-01-11 19:48 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-02-10 14:07 - 2015-01-11 19:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-02-10 14:07 - 2015-01-11 19:40 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-02-10 14:07 - 2015-01-11 19:39 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-02-10 14:07 - 2015-01-11 19:36 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-02-10 14:07 - 2015-01-11 19:34 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-02-10 14:07 - 2015-01-11 19:34 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-02-10 14:07 - 2015-01-11 19:25 - 19740160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-02-10 14:07 - 2015-01-11 19:25 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-02-10 14:07 - 2015-01-11 19:21 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-02-10 14:07 - 2015-01-11 19:21 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-02-10 14:07 - 2015-01-11 19:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-02-10 14:07 - 2015-01-11 19:08 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-02-10 14:07 - 2015-01-11 19:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-02-10 14:07 - 2015-01-11 19:07 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-02-10 14:07 - 2015-01-11 19:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-02-10 14:07 - 2015-01-11 19:07 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-02-10 14:07 - 2015-01-11 19:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-02-10 14:07 - 2015-01-11 19:04 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-02-10 14:07 - 2015-01-11 19:02 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-02-10 14:07 - 2015-01-11 19:00 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-02-10 14:07 - 2015-01-11 18:59 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-02-10 14:07 - 2015-01-11 18:57 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-02-10 14:07 - 2015-01-11 18:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-02-10 14:07 - 2015-01-11 18:48 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-02-10 14:07 - 2015-01-11 18:48 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-02-10 14:07 - 2015-01-11 18:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-02-10 14:07 - 2015-01-11 18:46 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-02-10 14:07 - 2015-01-11 18:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-02-10 14:07 - 2015-01-11 18:43 - 14401024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-02-10 14:07 - 2015-01-11 18:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-02-10 14:07 - 2015-01-11 18:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-02-10 14:07 - 2015-01-11 18:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-02-10 14:07 - 2015-01-11 18:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-02-10 14:07 - 2015-01-11 18:27 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-02-10 14:07 - 2015-01-11 18:23 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-02-10 14:07 - 2015-01-11 18:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-02-10 14:07 - 2015-01-11 18:22 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-02-10 14:07 - 2015-01-11 18:14 - 12829184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-02-10 14:07 - 2015-01-11 18:14 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-02-10 14:07 - 2015-01-11 18:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-02-10 14:07 - 2015-01-11 18:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-02-10 14:07 - 2015-01-11 17:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-02-10 14:07 - 2015-01-11 17:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-02-10 14:07 - 2014-12-11 22:31 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-02-10 14:07 - 2014-12-11 22:07 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2015-02-10 14:07 - 2014-07-06 19:07 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-02-10 14:07 - 2014-07-06 19:06 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-02-10 14:07 - 2014-07-06 18:40 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2015-02-10 14:07 - 2014-07-06 18:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2015-02-10 14:06 - 2015-01-13 23:09 - 05554112 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-02-10 14:06 - 2015-01-13 23:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-02-10 14:06 - 2015-01-13 23:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-02-10 14:06 - 2015-01-13 23:04 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-02-10 14:06 - 2015-01-13 22:44 - 03972544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-02-10 14:06 - 2015-01-13 22:44 - 03917760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-02-10 14:06 - 2015-01-13 22:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-02-10 14:06 - 2014-12-07 20:09 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-02-10 14:06 - 2014-12-07 19:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
2015-02-10 14:06 - 2014-11-25 20:53 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2015-02-10 14:06 - 2014-11-25 20:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2015-02-10 14:06 - 2014-10-03 19:10 - 03722752 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-02-10 14:06 - 2014-10-03 18:42 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-02-10 14:06 - 2014-10-03 18:42 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2015-02-10 14:05 - 2015-01-08 19:03 - 03201536 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-02-07 17:38 - 2015-02-07 17:38 - 00000000 __SHD () C:\Users\Wayne\AppData\Local\EmieBrowserModeList
2015-02-07 17:29 - 2015-02-07 17:29 - 00000000 ____D () C:\Users\Wayne\AppData\Local\Skype

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-03-08 14:50 - 2011-10-04 00:00 - 00000000 ____D () C:\ProgramData\MFAData
2015-03-08 14:38 - 2010-02-23 19:23 - 01644120 _____ () C:\Windows\WindowsUpdate.log
2015-03-08 14:32 - 2012-03-29 20:20 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-03-08 14:15 - 2011-07-12 10:52 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-08 14:15 - 2011-07-12 10:52 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-08 12:45 - 2014-12-24 17:41 - 00000000 ____D () C:\Users\Wayne\Desktop\dadtrust
2015-03-07 12:48 - 2011-07-12 10:30 - 00000000 ____D () C:\Users\Wayne\Desktop\blackstork
2015-03-07 12:33 - 2009-07-13 21:45 - 00022784 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-07 12:33 - 2009-07-13 21:45 - 00022784 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-07 12:25 - 2014-01-21 20:25 - 00027646 _____ () C:\Windows\setupact.log
2015-03-07 12:25 - 2010-02-23 19:44 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-03-07 12:25 - 2009-07-13 22:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-07 12:24 - 2010-08-08 12:54 - 00000000 _____ () C:\Windows\system32\Drivers\lvuvc.hs
2015-03-07 12:00 - 2010-02-23 20:35 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-03-07 11:59 - 2009-07-13 19:34 - 00000583 _____ () C:\Windows\win.ini
2015-03-07 08:42 - 2012-05-07 16:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-07 08:39 - 2010-06-22 21:46 - 00000000 ____D () C:\ProgramData\Temp
2015-03-07 08:39 - 2010-02-23 19:58 - 00000000 ____D () C:\Users\Wayne\AppData\Roaming\Azureus
2015-03-05 07:44 - 2009-07-13 22:08 - 00032582 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-03-04 04:17 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\tracing
2015-03-04 01:56 - 2010-02-27 09:54 - 00000000 ____D () C:\Users\Wayne\AppData\Roaming\vlc
2015-03-02 09:20 - 2014-02-13 04:48 - 00329228 _____ () C:\Windows\PFRO.log
2015-03-01 11:06 - 2010-02-23 19:23 - 00000000 ____D () C:\Users\Wayne\AppData\Local\VirtualStore
2015-03-01 08:09 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\Help
2015-03-01 03:56 - 2012-12-29 15:36 - 00000000 ____D () C:\Users\Wayne\AppData\Roaming\Malwarebytes
2015-03-01 03:56 - 2012-12-29 15:36 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-03-01 03:37 - 2009-07-13 20:20 - 00000000 ____D () C:\Program Files\Common Files\System
2015-03-01 03:30 - 2011-10-11 03:03 - 00001413 _____ () C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-03-01 03:30 - 2011-10-03 23:59 - 00001159 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-03-01 03:30 - 2009-07-13 20:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2015-03-01 03:30 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2015-03-01 03:05 - 2013-11-03 13:55 - 00000000 ____D () C:\ProgramData\AVG2014
2015-02-25 11:22 - 2014-03-21 19:48 - 00000000 ____D () C:\Users\Wayne\AppData\Local\NVIDIA Corporation
2015-02-24 20:54 - 2015-01-19 20:51 - 00202484 ____H () C:\Users\Wayne\Desktop\PP11Thumbs.ptn
2015-02-24 20:54 - 2015-01-19 20:51 - 00001696 ____H () C:\Users\Wayne\Desktop\maxdesk.ini2
2015-02-24 20:54 - 2015-01-19 20:51 - 00000088 ____H () C:\Users\Wayne\Desktop\PP11Thumbs.ptn2
2015-02-14 19:18 - 2010-02-23 19:23 - 00000000 ____D () C:\Users\Wayne
2015-02-14 16:28 - 2013-01-01 00:58 - 00000000 ____D () C:\Users\Wayne\AppData\Roaming\AVG
2015-02-14 16:19 - 2014-07-25 22:02 - 00000000 ____D () C:\Program Files (x86)\Verizon
2015-02-14 16:19 - 2010-08-09 18:32 - 00000000 ____D () C:\ProgramData\Skype
2015-02-14 16:18 - 2010-08-09 18:32 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-02-14 16:17 - 2014-01-03 15:57 - 00000000 ____D () C:\Users\Wayne\AppData\Local\Citrix
2015-02-12 11:46 - 2010-08-09 18:32 - 00000000 ____D () C:\Users\Wayne\AppData\Roaming\Skype
2015-02-12 04:55 - 2009-07-13 20:20 - 00000000 ____D () C:\Windows\rescache
2015-02-11 04:44 - 2009-07-13 21:45 - 00470416 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-11 04:39 - 2014-12-28 04:24 - 00000000 ____D () C:\Windows\system32\appraiser
2015-02-11 04:39 - 2014-05-06 03:01 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-02-11 04:15 - 2013-08-24 21:11 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-11 04:05 - 2010-02-26 08:49 - 116773704 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

==================== Files in the root of some directories =======

2010-06-07 06:46 - 2010-06-07 06:46 - 0000760 _____ () C:\Users\Wayne\AppData\Roaming\setup_ldm.iss
2012-12-26 15:36 - 2012-12-26 15:36 - 0000000 _____ () C:\Users\Wayne\AppData\Roaming\SharedSettings.ccs
2012-12-26 15:30 - 2012-12-31 13:32 - 0006524 _____ () C:\Users\Wayne\AppData\Local\1786b1d9-8e44-4993-b87c-f8b0702c8038.crx
2013-01-21 16:58 - 2013-01-21 16:59 - 0005120 _____ () C:\Users\Wayne\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-12-26 15:43 - 2012-12-26 15:43 - 0046117 _____ () C:\Users\Wayne\AppData\Local\jjnbtrhk
2012-05-03 15:54 - 2012-05-03 15:54 - 0000218 _____ () C:\Users\Wayne\AppData\Local\recently-used.xbel
2012-03-12 20:38 - 2012-03-12 20:38 - 0007597 _____ () C:\Users\Wayne\AppData\Local\Resmon.ResmonCfg
2014-07-02 08:43 - 2014-07-02 08:44 - 0006336 _____ () C:\Users\Wayne\AppData\Local\rx_audio.Cache
2013-07-10 12:17 - 2013-07-10 12:17 - 0000000 _____ () C:\Users\Wayne\AppData\Local\rx_image32.Cache
2010-02-23 20:26 - 2010-02-23 20:26 - 0000026 ____H () C:\ProgramData\.811261211181235583101118113995
2010-08-09 18:33 - 2011-10-12 12:00 - 0000056 ____H () C:\ProgramData\ezsidmv.dat

Some content of TEMP:
====================
C:\Users\Wayne\AppData\Local\Temp\Delta.exe
C:\Users\Wayne\AppData\Local\Temp\dllnt_dump.dll
C:\Users\Wayne\AppData\Local\Temp\i4jdel0.exe
C:\Users\Wayne\AppData\Local\Temp\Opera_NI_stable.exe
C:\Users\Wayne\AppData\Local\Temp\Quarantine.exe
C:\Users\Wayne\AppData\Local\Temp\SpOrder.dll
C:\Users\Wayne\AppData\Local\Temp\sqlite3.dll
C:\Users\Wayne\AppData\Local\Temp\tu17p84.exe
C:\Users\Wayne\AppData\Local\Temp\WSSetup.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-03-05 01:42

==================== End Of Log ============================

 

 

Users shortcut scan result (x64) Version: 08-03-2015 03
Ran by Wayne at 2015-03-08 14:57:38
Running from C:\Users\Wayne\Downloads
Boot Mode: Normal
==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)



Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\AOL Desktop 9.7.lnk -> C:\Program Files (x86)\AOL Desktop 9.7a\aol.exe (AOL Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk -> C:\Program Files\WinZip\WINZIP64.EXE (WinZip Computing, S.L.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Distiller 9.lnk -> C:\Windows\Installer\{AC76BA86-1033-F400-7761-000000000004}\_SC_Distiller.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat_com.lnk -> C:\Program Files (x86)\Adobe\Acrobat_com\Acrobat_com.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe 3D Reviewer.lnk -> C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\plug_ins3d\prc\A3DReviewer.exe (Adobe Systems Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat 9 Pro Extended.lnk -> C:\Windows\Installer\{AC76BA86-1033-F400-7761-000000000004}\_SC_Acrobat_3D.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle Designer ES 8.2.lnk -> C:\Program Files (x86)\Adobe\Acrobat 9.0\Designer 8.2\FormDesigner.exe (Adobe Systems Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk -> C:\Windows\Installer\{AC76BA86-7AD7-1033-7B44-AB0000000001}\SC_Reader.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk -> C:\Windows\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\AppleSoftwareUpdateIco.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Final Draft 8.lnk -> C:\Program Files (x86)\Final Draft 8\Final Draft.exe (Final Draft Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk -> C:\Windows\ehome\ehshell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TORParse.lnk -> C:\Program Files (x86)\TORParse\TORParse.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vuze.lnk -> C:\Program Files (x86)\Vuze\Azureus.exe (Azureus Software, Inc)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk -> C:\Windows\System32\WindowsAnytimeUpgradeUI.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk -> C:\Program Files\DVD Maker\DVDMaker.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk -> C:\Windows\System32\xpsrchvw.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip\WinZip 16.0.lnk -> C:\Program Files\WinZip\WINZIP64.EXE (WinZip Computing, S.L.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Console RAR manual.lnk -> C:\Program Files\WinRAR\Rar.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR help.lnk -> C:\Program Files\WinRAR\WinRAR.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VisiPics\Uninstall VisiPics.lnk -> C:\Program Files (x86)\VisiPics\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VisiPics\VisiPics-Help.lnk -> C:\Program Files (x86)\VisiPics\VisiPics-Help.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VisiPics\VisiPics.lnk -> C:\Program Files (x86)\VisiPics\VisiPics.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Documentation.lnk -> C:\Program Files (x86)\VideoLAN\VLC\Documentation.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Release Notes.lnk -> C:\Program Files (x86)\VideoLAN\VLC\NEWS.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VideoLAN Website.lnk -> C:\Program Files (x86)\VideoLAN\VLC\VideoLAN Website.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player.lnk -> C:\Program Files (x86)\VideoLAN\VLC\vlc.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Verizon\Verizon Update Center\Inbox.lnk -> C:\Program Files (x86)\Verizon\IHA_MessageCenter\Bin\DisplayAgent.exe (No File)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Verizon\Verizon Update Center\Preferences.lnk -> C:\Program Files (x86)\Verizon\IHA_MessageCenter\Bin\MC_Client_Preferences.exe (No File)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ultra MKV Converter\Help.lnk -> C:\Program Files (x86)\Ultra MKV Converter\Help.CHM ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ultra MKV Converter\Readme.lnk -> C:\Program Files (x86)\Ultra MKV Converter\Readme.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ultra MKV Converter\Ultra MKV Converter Homepage.lnk -> C:\Program Files (x86)\Ultra MKV Converter\Ultra MKV Converter.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ultra MKV Converter\Ultra MKV Converter.lnk -> C:\Program Files (x86)\Ultra MKV Converter\Ultra MKV Converter.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ultra MKV Converter\Uninstall Ultra MKV Converter.lnk -> C:\Program Files (x86)\Ultra MKV Converter\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ultra MKV Converter\What's New.lnk -> C:\Program Files (x86)\Ultra MKV Converter\New.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TiVo Desktop\LogFinder.lnk -> C:\Program Files (x86)\TiVo\Desktop\LogFinder.exe (TiVo Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TiVo Desktop\Read Me.lnk -> C:\Program Files (x86)\TiVo\Desktop\ReadMe.rtf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TiVo Desktop\TiVo Desktop Troubleshooting.lnk -> C:\Program Files (x86)\TiVo\Desktop\TiVoDiag.exe (TiVo Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TiVo Desktop\TiVo Desktop.lnk -> C:\Program Files (x86)\TiVo\Desktop\TiVoDesktop.exe (TiVo Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TiVo Desktop\TiVo Server Properties.lnk -> C:\Program Files (x86)\TiVo\Desktop\TiVoServer.exe (TiVo Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client\TeamSpeak 3 Client.lnk -> C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win32.exe (TeamSpeak Systems GmbH)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client\Uninstall.lnk -> C:\Program Files (x86)\TeamSpeak 3 Client\Uninstall.exe (TeamSpeak Systems GmbH)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ScanSoft PaperPort 11\PageViewer.lnk -> C:\Program Files (x86)\ScanSoft\PaperPort\pppagevw.exe (Nuance Communications, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ScanSoft PaperPort 11\PaperPort.lnk -> C:\Program Files (x86)\ScanSoft\PaperPort\PaprPort.exe (Nuance Communications, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Kies mini\Samsung Kies mini.lnk -> C:\Program Files (x86)\Samsung\KiesMini\AMiniVersionCheck.exe (Mobileleader)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio 2012\Roxio Creator 2012 Pro.lnk -> C:\Program Files (x86)\Roxio 2012\Roxio Central\RoxioCentralFx.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio 2012\Applications\3D Photo Creator.lnk -> C:\Program Files (x86)\Roxio 2012\3DPhotoCreator\3DPhotoCreator.exe (Rovi Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio 2012\Applications\CinePlayer.lnk -> C:\Program Files (x86)\Roxio 2012\5.0\CinePlayer.exe (Sonic Solutions)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio 2012\Applications\Creator Classic.lnk -> C:\Program Files (x86)\Roxio 2012\Creator Classic\Creator13.exe (Rovi Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio 2012\Applications\Label Creator.lnk -> C:\Program Files (x86)\Common Files\Roxio Shared\13.0\Label Creator\RxLabelCreator13.exe (Rovi Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio 2012\Applications\Music Disc Creator.lnk -> C:\Program Files (x86)\Roxio 2012\AudioCore\MusicDiscCreator13.exe (Rovi Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio 2012\Applications\MyDVD.lnk -> C:\Program Files (x86)\Roxio 2012\VideoUI\MyDVD13.exe (Rovi Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio 2012\Applications\PhotoSuite.lnk -> C:\Program Files (x86)\Roxio 2012\PhotoSuite\PhotoSuite13.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio 2012\Applications\Sound Editor.lnk -> C:\Program Files (x86)\Roxio 2012\AudioCore\SoundEdit13.exe (Rovi Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio 2012\Applications\Video Copy & Convert.lnk -> C:\Program Files (x86)\Roxio 2012\Video Convert\VideoConvert13.exe (Rovi Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio 2012\Applications\VideoWave.lnk -> C:\Program Files (x86)\Roxio 2012\VideoUI\VideoWave13.exe (Rovi Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio\Roxio Burn Options.lnk -> C:\Program Files (x86)\Roxio 2012\Roxio Burn\Roxio Burn.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio\Roxio BackOnTrack\BackOnTrack.lnk -> C:\Program Files (x86)\Roxio\BackOnTrack\App\BackOnTrack.exe (Rovi Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime\About QuickTime.lnk -> C:\Windows\Installer\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}\RichText.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime\QuickTime Player.lnk -> C:\Windows\Installer\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}\QTPlayer.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pyTivo\Configuration.lnk -> C:\Program Files (x86)\pyTivo\config.url (No File)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pyTivo\Configure - Admin Web.lnk -> C:\Program Files\pyTivo\config.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pyTivo\Configure - pyTivo.conf.lnk -> C:\Users\Public\Documents\pyTivo\pyTivo.conf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pyTivo\pyTivo Data Folder.lnk -> C:\Users\Public\Documents\pyTivo ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pyTivo\ReadMe.lnk -> C:\Program Files\pyTivo\readme.rtf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pyTivo\Uninstall.lnk -> C:\Program Files\pyTivo\uninst.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pyTivo\Ver - wgw-2008.10.15-RC1.lnk -> C:\Program Files (x86)\pyTivo\version.url (No File)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pyTivo\Version - wmcbrine-2009.03.19-RC1.lnk -> C:\Program Files\pyTivo\version.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pyTivo\Web Forum.lnk -> C:\Program Files\pyTivo\forum.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pyTivo\Website.lnk -> C:\Program Files\pyTivo\pyTivo.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pyTivo\X-Advanced - Recompile Python files.lnk -> C:\Program Files\pyTivo\regenpyc.cmd ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.6\Python (command line).lnk -> C:\Windows\Installer\{4723F199-FA64-4233-8E6E-9FCCC95A18EE}\python_icon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.6\Python Manuals.lnk -> C:\Python26\Doc\python265.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO\PowerISO Help.lnk -> C:\Program Files (x86)\PowerISO\PowerISO.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO\PowerISO Virtual Drive Manager.lnk -> C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO\PowerISO.lnk -> C:\Program Files (x86)\PowerISO\PowerISO.exe (PowerISO Computing, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO\Uninstall PowerISO.lnk -> C:\Program Files (x86)\PowerISO\uninstall.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PdaNet for Android\PdaNet Desktop.lnk -> C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PdaNet for Android\Uninstall PdaNet.lnk -> C:\Program Files (x86)\PdaNet for Android\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\GeForce Experience.lnk -> C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\GFExperience.exe (NVIDIA)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\3D Vision Photo Viewer.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstview.exe (NVIDIA Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mumble\Mumble.lnk -> C:\Program Files (x86)\Mumble\mumble.exe (Thorvald Natvig)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mumble\Qt License.lnk -> C:\Program Files (x86)\Mumble\qt.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mumble\Speex License.lnk -> C:\Program Files (x86)\Mumble\speex.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozy\Mozy Sync.lnk -> C:\Windows\Installer\{95DB05B2-371B-3957-A65A-7CD9433701AD}\icon.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\mkvmerge GUI.lnk -> C:\Program Files (x86)\MKVToolNix\mmg.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Uninstall.lnk -> C:\Program Files (x86)\MKVToolNix\uninst.exe (Moritz Bunkus)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Website.lnk -> C:\Program Files (x86)\MKVToolNix\MKVToolNix.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Other documentation\ChangeLog - What is new.lnk -> C:\Program Files (x86)\MKVToolNix\doc\ChangeLog.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Other documentation\README.lnk -> C:\Program Files (x86)\MKVToolNix\doc\README.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Other documentation\The GNU GPL.lnk -> C:\Program Files (x86)\MKVToolNix\doc\COPYING.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\mkvmerge GUI guide\mkvmerge GUI guide.lnk -> C:\Program Files (x86)\MKVToolNix\doc\guide\en\mkvmerge-gui.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\mkvmerge GUI guide\Chinese Simplified\mkvmerge GUI guide.lnk -> C:\Program Files (x86)\MKVToolNix\doc\guide\zh_CN\mkvmerge-gui.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Command line reference\mkvextract CLI reference.lnk -> C:\Program Files (x86)\MKVToolNix\doc\en\mkvextract.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Command line reference\mkvinfo CLI reference.lnk -> C:\Program Files (x86)\MKVToolNix\doc\en\mkvinfo.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Command line reference\mkvmerge CLI reference.lnk -> C:\Program Files (x86)\MKVToolNix\doc\en\mkvmerge.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Command line reference\mkvpropedit CLI reference.lnk -> C:\Program Files (x86)\MKVToolNix\doc\en\mkvpropedit.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Command line reference\Ukrainian\mkvextract CLI reference.lnk -> C:\Program Files (x86)\MKVToolNix\doc\uk\mkvextract.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Command line reference\Ukrainian\mkvinfo CLI reference.lnk -> C:\Program Files (x86)\MKVToolNix\doc\uk\mkvinfo.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Command line reference\Ukrainian\mkvmerge CLI reference.lnk -> C:\Program Files (x86)\MKVToolNix\doc\uk\mkvmerge.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Command line reference\Ukrainian\mkvpropedit CLI reference.lnk -> C:\Program Files (x86)\MKVToolNix\doc\uk\mkvpropedit.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Command line reference\Japanese\mkvextract CLI reference.lnk -> C:\Program Files (x86)\MKVToolNix\doc\ja\mkvextract.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Command line reference\Japanese\mkvinfo CLI reference.lnk -> C:\Program Files (x86)\MKVToolNix\doc\ja\mkvinfo.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Command line reference\Japanese\mkvmerge CLI reference.lnk -> C:\Program Files (x86)\MKVToolNix\doc\ja\mkvmerge.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Command line reference\Japanese\mkvpropedit CLI reference.lnk -> C:\Program Files (x86)\MKVToolNix\doc\ja\mkvpropedit.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Command line reference\Dutch\mkvextract CLI reference.lnk -> C:\Program Files (x86)\MKVToolNix\doc\nl\mkvextract.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Command line reference\Dutch\mkvinfo CLI reference.lnk -> C:\Program Files (x86)\MKVToolNix\doc\nl\mkvinfo.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Command line reference\Dutch\mkvmerge CLI reference.lnk -> C:\Program Files (x86)\MKVToolNix\doc\nl\mkvmerge.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Command line reference\Dutch\mkvpropedit CLI reference.lnk -> C:\Program Files (x86)\MKVToolNix\doc\nl\mkvpropedit.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Command line reference\Chinese Simplified\mkvextract CLI reference.lnk -> C:\Program Files (x86)\MKVToolNix\doc\zh_CN\mkvextract.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Command line reference\Chinese Simplified\mkvinfo CLI reference.lnk -> C:\Program Files (x86)\MKVToolNix\doc\zh_CN\mkvinfo.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Command line reference\Chinese Simplified\mkvmerge CLI reference.lnk -> C:\Program Files (x86)\MKVToolNix\doc\zh_CN\mkvmerge.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\Documentation\Command line reference\Chinese Simplified\mkvpropedit CLI reference.lnk -> C:\Program Files (x86)\MKVToolNix\doc\zh_CN\mkvpropedit.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Miro\Miro.lnk -> C:\Program Files (x86)\Participatory Culture Foundation\Miro\Miro.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Miro\Uninstall Miro.lnk -> C:\Program Files (x86)\Participatory Culture Foundation\Miro\uninstall.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight\Microsoft Silverlight.lnk -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\Silverlight.Configuration.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Access 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Excel 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Groove 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\GrooveIcon.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office InfoPath 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office OneNote 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Outlook 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office PowerPoint 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Publisher 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Word 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Digital Certificate for VBA Projects.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Clip Organizer.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2007 Language Settings.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Diagnostics.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Picture Manager.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Manga Studio EX 4.0\Manga Studio EX 4.0.lnk -> C:\Program Files (x86)\Smith Micro\MangaStudio EX 4E\Tool\MS_EX.exe (CELSYS,Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Manga Studio EX 4.0\Uninstall Materials.lnk -> C:\Program Files (x86)\Smith Micro\MangaStudio EX 4E\Tool\MaterialUninstaller.exe (CELSYS,Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk -> C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Uninstall Malwarebytes Anti-Malware.lnk -> C:\Program Files (x86)\Malwarebytes Anti-Malware\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk -> C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Create Recovery Disc.lnk -> C:\Windows\System32\recdisc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Remote Assistance.lnk -> C:\Windows\System32\msra.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech\Logitech Webcam Software.lnk -> C:\Program Files (x86)\Common Files\logishrd\LWSPlugins\LWS\Applets\HelpMain\launchershortcut.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech\Logitech Vid\Logitech Vid.lnk -> C:\Windows\Installer\{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}\VidIcon.BA73B1B0_EF22_43B4_9B31_1EC3736CBBD6.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LeapFrog Connect\LeapFrog Connect.lnk -> C:\Program Files (x86)\LeapFrog\LeapFrog Connect\LeapFrogConnect.exe (LeapFrog Enterprises, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LeapFrog Connect\Uninstall LeapFrog Connect.lnk -> C:\Program Files (x86)\LeapFrog\LeapFrog Connect\uninst.exe (LeapFrog Enterprises, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes\About iTunes.lnk -> C:\Program Files (x86)\iTunes\iTunes.Resources\en.lproj\About iTunes.rtf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes\iTunes.lnk -> C:\Program Files (x86)\iTunes\iTunes.exe (Apple Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IMCapture\Home page.lnk -> C:\Program Files (x86)\IMCapture\Skype\HomePage.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IMCapture\IMCapture Converter.lnk -> C:\Program Files (x86)\IMCapture\Skype\Converter.exe (GeoVid)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IMCapture\IMCapture for Skype.lnk -> C:\Program Files (x86)\IMCapture\Skype\IMCaptureForSkype.exe (GeoVid)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro\HitmanPro.lnk -> C:\Program Files\HitmanPro\HitmanPro.exe (SurfRight B.V.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Enhanced Mitigation Experience Toolkit\EMET 3.0.lnk -> C:\Windows\Installer\{DE7A5DDF-47B3-42FF-A082-E158DEA37392}\_4D69E3CD100D782CD01439.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Enhanced Mitigation Experience Toolkit\EMET Users Guide.lnk -> C:\Windows\Installer\{DE7A5DDF-47B3-42FF-A082-E158DEA37392}\_9A017C9EDA4365E39E44AF.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA\BioWare\Star Wars - The Old Republic\Star Wars - The Old Republic.lnk -> C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe (BioWare)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA\BioWare\Star Wars - The Old Republic\SWTOR Customer Support.lnk -> C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\SWTOR Customer Support.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA\BioWare\Star Wars - The Old Republic\Uninstall Star Wars - The Old Republic.lnk -> C:\Program Files (x86)\Common Files\BioWare\Uninstall Star Wars - The Old Republic.exe (BioWare, LucasArts)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA\BioWare\Star Wars - The Old Republic\View License.lnk -> C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\EUALAs\EUALA_en.rtf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA\BioWare\Star Wars - The Old Republic\View Readme.lnk -> C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\readmes\readme_en.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 8 Qt\DVDFab 8 Profile Editor.lnk -> C:\Program Files (x86)\DVDFab 8 Qt\ProfileEditor.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 8 Qt\DVDFab 8 Qt.lnk -> C:\Program Files (x86)\DVDFab 8 Qt\DVDFab.exe (Fengtao Software Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 8 Qt\DVDFab History.lnk -> C:\Program Files (x86)\DVDFab 8 Qt\Changes.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 8 Qt\DVDFab Online.lnk -> C:\Program Files (x86)\DVDFab 8 Qt\DVDFab.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 8 Qt\Uninstall DVDFab 8 Qt.lnk -> C:\Program Files (x86)\DVDFab 8 Qt\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus\DivX Plus Converter.lnk -> C:\Program Files (x86)\DivX\DivX Plus Converter\DivXConverterLauncher.exe (DivX, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus\DivX Plus Player.lnk -> C:\Program Files (x86)\DivX\DivX Plus Player\DivX Plus Player.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative\Creative Audio Control Panel.lnk -> C:\Program Files (x86)\Creative\AudioCS\CTAudCS.exe (Creative Technology Ltd)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDisplay\CDisplay.lnk -> C:\Program Files (x86)\CDisplay\CDisplay.exe (David Ayton)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner.lnk -> C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\Uninstall CCleaner.lnk -> C:\Program Files\CCleaner\uninst.exe (Piriform Ltd)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-8870DW LAN\Read Me.lnk -> C:\Program Files (x86)\Brother\Brmfl05c\RM09aUsa.rtf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-8870DW LAN\Scanner Settings\Read Me.lnk -> C:\Program Files (x86)\Brother\Brmfl05c\ScanRead.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-8870DW LAN\Scanner Settings\Scanner Utility.lnk -> C:\Program Files (x86)\Brother\Brmfl05c\BrScUtil.exe (Brother Industries Ltd.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-8870DW LAN\PC-FAX Sending\How to use PC-FAX Sending.lnk -> C:\Program Files (x86)\Brother\Brmfl05c\howtousebrotherpc.htm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-8870DW LAN\PC-FAX Receiving\How to use PC-FAX Receiving.lnk -> C:\Program Files (x86)\Brother\Brmfl05c\howtousepcfaxrx.htm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU\Activation.lnk -> C:\Program Files (x86)\AVS4YOU\Registration.exe (Online Media Technologies Ltd.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU\AVS Update Manager.lnk -> C:\Program Files (x86)\AVS4YOU\AVSUpdateManager\AVSUpdateManager.exe (Online Media Technologies LTD.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU\AVS4YOU Software Navigator.lnk -> C:\Program Files (x86)\AVS4YOU\AVSSoftwareNavigator\AVS4YOUSoftwareNavigator.exe (Online Media Technologies Ltd.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU\Help.lnk -> C:\Program Files (x86)\AVS4YOU\AVS4YOUHelp.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU\License Agreement.lnk -> C:\Program Files (x86)\AVS4YOU\License Agreement.rtf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU\Repair.lnk -> C:\Program Files (x86)\Common Files\AVSMedia\ActiveX\Repairing.exe (Online Media Technologies Ltd.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVS4YOU\Video\AVS Video Converter 6.lnk -> C:\Program Files (x86)\AVS4YOU\AVSVideoConverter6\AVSVideoConverter.exe (Online Media Technologies Ltd.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\AVG PC Tuneup on the Web.lnk -> C:\Program Files (x86)\AVG\AVG PC Tuneup\boostspeed.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\AVG PC Tuneup.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\BoostSpeed.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\AVG Rescue Center.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\RescueCenter.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Uninstall AVG PC Tuneup.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Utilities\AVG Disk Cleaner.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\DiskCleaner.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Utilities\AVG Disk Defrag.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\DiskDefrag.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Utilities\AVG Disk Doctor.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\DiskDoctor.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Utilities\AVG Disk Explorer.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\DiskExplorer.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Utilities\AVG Disk Wiper.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\DiskWiper.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Utilities\AVG Duplicate File Finder.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\DuplicateFileFinder.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Utilities\AVG File Recovery.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\FileRecovery.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Utilities\AVG File Shredder.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\FileShredder.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Utilities\AVG Internet Optimizer.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\InternetOptimizer.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Utilities\AVG Registry Cleaner.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\RegCleaner.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Utilities\AVG Registry Defrag.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\RegistryDefrag.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Utilities\AVG Rescue Center.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\RescueCenter.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Utilities\AVG Service Manager.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\ServiceManager.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Utilities\AVG Startup Manager.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\StartupManager.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Utilities\AVG System Information.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\SystemInformation.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Utilities\AVG Task Manager.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\TaskManager.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Utilities\AVG Track Eraser.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\TrackEraser.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Utilities\AVG Tweak Manager.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\TweakManager.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Utilities\AVG Uninstall Manager.lnk -> C:\Program Files (x86)\AVG\AVG PC TuneUp\ProgramManager.exe (AVG)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG\AVG 2014.lnk -> C:\Program Files (x86)\AVG\AVG2014\avgui.exe (AVG Technologies CZ, s.r.o.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft MediaImpression for Kodak\MediaImpression.lnk -> C:\Program Files (x86)\Kodak\MediaImpression\MediaImpression.exe (ArcSoft, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Applian Technologies\Uninstall Replay media Catcher 4.lnk -> C:\Windows\Installer\{F0DC0069-4D38-4BF4-B706-AB781D73267D}\_4C4E1A6DFEACB39CDFCF64.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOL\AOL Desktop 9.7.lnk -> C:\Program Files (x86)\AOL Desktop 9.7a\aol.exe (AOL Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOL\AOL System Information.lnk -> C:\Program Files (x86)\Common Files\aol\System Information\sinf.exe (AOL Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOL\Check for Updates.lnk -> C:\Program Files (x86)\Common Files\aol\1267029088\ee\SUUILauncher.exe (AOL Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOL\Uninstall.lnk -> C:\Program Files (x86)\Common Files\aol\uninstaller.exe (AOL Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amazon\Amazon MP3 Downloader\Amazon MP3 Downloader.lnk -> C:\Program Files (x86)\Amazon\MP3 Downloader\AmazonMP3Downloader.exe (Amazon.com)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amazon\Amazon MP3 Downloader\Uninstall Amazon MP3 Downloader.lnk -> C:\Program Files (x86)\Amazon\MP3 Downloader\Uninstall.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\Windows\System32\comexp.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Data Sources (ODBC).lnk -> C:\Windows\System32\odbcad32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\Windows\System32\iscsicpl.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\Windows\System32\MdSched.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\Windows\System32\services.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\Windows\System32\msconfig.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk -> C:\Windows\System32\WF.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis\Acronis True Image\Acronis True Image WD Edition.lnk -> C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageLauncher.exe (Acronis)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis\Acronis True Image\Bootable Media Builder.lnk -> C:\Program Files (x86)\Common Files\Acronis\MediaBuilderHome\MediaBuilder.exe (Acronis)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Calculator.lnk -> C:\Windows\System32\calc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\displayswitch.lnk -> C:\Windows\System32\displayswitch.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\Windows\System32\mstsc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk -> C:\Windows\System32\SoundRecorder.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk -> C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sync Center.lnk -> C:\Windows\System32\mobsync.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\Windowspowershell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\ShapeCollector.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\TabTip.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Windows Journal.lnk -> C:\Program Files\Windows Journal\Journal.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\Windows\System32\charmap.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\dfrgui.lnk -> C:\Windows\System32\dfrgui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Disk Cleanup.lnk -> C:\Windows\System32\cleanmgr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Information.lnk -> C:\Windows\System32\msinfo32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Restore.lnk -> C:\Windows\System32\rstrui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer Reports.lnk -> C:\Windows\System32\migwiz\PostMig.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer.lnk -> C:\Windows\System32\migwiz\migwiz.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4Videosoft\4Videosoft MKV Video Converter\4Videosoft MKV Video Converter On the Web.lnk -> C:\Program Files (x86)\4Videosoft Studio\4Videosoft MKV Video Converter\sys\soft\4Videosoft MKV Video Converter\On the Web.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4Videosoft\4Videosoft MKV Video Converter\4Videosoft MKV Video Converter User Help.lnk -> C:\Program Files (x86)\4Videosoft Studio\4Videosoft MKV Video Converter\sys\soft\4Videosoft MKV Video Converter\help.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4Videosoft\4Videosoft MKV Video Converter\4Videosoft MKV Video Converter.lnk -> C:\Program Files (x86)\4Videosoft Studio\4Videosoft MKV Video Converter\4Videosoft MKV Video Converter.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4Videosoft\4Videosoft MKV Video Converter\Uninstall.lnk -> C:\Program Files (x86)\4Videosoft Studio\4Videosoft MKV Video Converter\unins000.exe ()
Shortcut: C:\Users\Default\Desktop\CyberLink PowerDirector.lnk -> C:\Program Files (x86)\CyberLink\PowerDirector\PDR8.exe (CyberLink Corp.)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDirector\CyberLink PowerDirector Online Help.lnk -> C:\Program Files (x86)\CyberLink\PowerDirector\Language\Enu\PowerDirector.chm ()
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDirector\CyberLink PowerDirector.lnk -> C:\Program Files (x86)\CyberLink\PowerDirector\PDR8.exe (CyberLink Corp.)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDirector\Readme.lnk -> C:\Program Files (x86)\CyberLink\PowerDirector\Language\Enu\Readme.htm ()
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDirector\User's Guide.lnk -> C:\Program Files (x86)\CyberLink\PowerDirector\Language\Enu\PowerDirector_UG.pdf ()
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\Public\Desktop\HitmanPro.lnk -> C:\Program Files\HitmanPro\HitmanPro.exe (SurfRight B.V.)
Shortcut: C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk -> C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes Corporation)
Shortcut: C:\Users\Wayne\Links\Desktop.lnk -> C:\Users\Wayne\Desktop ()
Shortcut: C:\Users\Wayne\Links\Downloads.lnk -> C:\Users\Wayne\Downloads ()
Shortcut: C:\Users\Wayne\Links\Magic Briefcase.lnk -> C:\Users\Wayne\Documents\Magic Briefcase (No File)
Shortcut: C:\Users\Wayne\Links\Pictures.lnk -> C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Libraries\Pictures.library-ms ()
Shortcut: C:\Users\Wayne\Desktop\Continue installation .lnk -> C:\Users\Wayne\AppData\Local\Temp\Gbooks__1598_il262508.exe (No File)
Shortcut: C:\Users\Wayne\Desktop\Start Emsisoft Emergency Kit.lnk -> C:\EEK\bin\a2emergencykit.exe (Emsisoft GmbH)
Shortcut: C:\Users\Wayne\Desktop\goodcoverage\AOL Desktop 9.7.lnk -> C:\Program Files (x86)\AOL Desktop 9.7a\aol.exe (AOL Inc.)
Shortcut: C:\Users\Wayne\Desktop\Desktop\DivX Movies.lnk -> C:\Users\Wayne\Videos\DivX Movies ()
Shortcut: C:\Users\Wayne\Desktop\dadtrust\dadsstuff\mydocuments\ENTERPRISE-TAXI LETTER.lnk -> C:\Users\Wayne\Desktop\OpenOffice.org 3.1 (en-US) Installation Files\February 10.doc (No File)
Shortcut: C:\Users\Wayne\Desktop\dadtrust\dadsstuff\daddesktop\Public Music.lnk -> C:\Users\Public\Music ()
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yamb 2.1.0.0 beta 2\Uninstall.lnk -> C:\Users\Wayne\AppData\Roaming\Yamb\Uninstall.exe (http://yamb.unite-video.com)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ventrilo\Ventrilo.lnk -> C:\Program Files\Ventrilo\Ventrilo.exe (Flagship Industries, Inc.)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller\Revo Uninstaller.lnk -> C:\Program Files (x86)\VS Revo Group\Revo Uninstaller\Revouninstaller.exe (VS Revo Group)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller\Uninstall.lnk -> C:\Program Files (x86)\VS Revo Group\Revo Uninstaller\uninst.exe (VS Revo Group Ltd.)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller\Website.lnk -> C:\Program Files (x86)\VS Revo Group\Revo Uninstaller\Revo Uninstaller.url ()
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Private Internet Access\Private Internet Access.lnk -> C:\Program Files\pia_manager\pia_manager.exe ()
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf\Overwolf.lnk -> C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe ()
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf\Uninstall Overwolf.lnk -> C:\Program Files (x86)\Overwolf\OWUninstaller.exe (Overwolf Ltd)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mozy\Mozy Restore Manager.lnk -> C:\Users\Wayne\AppData\Roaming\Microsoft\Installer\{ACBF3584-2D91-4EB1-9EFF-8DCECB2A7A84}\icon.ico ()
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amazon\Amazon Kindle For PC\Kindle For PC.lnk -> C:\Users\Wayne\AppData\Local\Amazon\Kindle For PC\application\KindleForPC.exe (Amazon.com)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Amazon\Amazon Kindle For PC\Uninstall Kindle For PC.lnk -> C:\Users\Wayne\AppData\Local\Amazon\Kindle For PC\application\uninstall.exe (Amazon.com)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\SendTo\AVS Mobile Uploader.lnk -> C:\Program Files (x86)\Common Files\AVSMedia\MobileUploader\AVSMobileUploader.exe (Online Media Technologies Ltd.)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\SendTo\AVS Video Burner.lnk -> C:\Program Files (x86)\Common Files\AVSMedia\BurnerService\AVSVideoBurner.exe (Online Media Technologies Ltd.)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\AOL Desktop 9.7.lnk -> C:\Program Files (x86)\AOL Desktop 9.7a\aol.exe (AOL Inc.)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Samsung Kies mini.lnk -> C:\Program Files (x86)\Samsung\KiesMini\AMiniVersionCheck.exe (Mobileleader)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Vuze.lnk -> C:\Program Files (x86)\Vuze\Azureus.exe (Azureus Software, Inc)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Office Word 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe ()
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Sticky Notes.lnk -> C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Vuze.lnk -> C:\Program Files (x86)\Vuze\Azureus.exe (Azureus Software, Inc)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Task Manager.lnk -> C:\Windows\System32\taskmgr.exe (Microsoft Corporation)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\DVDFab 8 Profile Editor.lnk -> C:\Program Files (x86)\DVDFab 8 Qt\ProfileEditor.exe ()
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Microsoft Office Excel 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe ()
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Microsoft Office Word 2007.lnk -> C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe ()
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Star Wars - The Old Republic.lnk -> C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe (BioWare)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Vuze.lnk -> C:\Program Files (x86)\Vuze\Azureus.exe (Azureus Software, Inc)
Shortcut: C:\Users\Wayne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation)
Shortcut: C:\Users\Wayne\AppData\Local\TiVo Desktop\Photos\My Pictures.lnk -> C:\Users\Wayne\Pictures ()
Shortcut: C:\Users\Wayne\AppData\Local\TiVo Desktop\Music\My Music.lnk -> C:\Users\Wayne\Music ()




ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DefaultPrograms
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk -> C:\Windows\System32\wuapp.exe (Microsoft Corporation) -> startmenu
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) -> /showgadgets
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Mobile Device Center.lnk -> C:\Windows\Installer\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}\wmdc.exe (Microsoft Corporation) -> /show
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Reset VLC media player preferences and cache files.lnk -> C:\Program Files (x86)\VideoLAN\VLC\vlc.exe () -> --reset-config --reset-plugins-cache vlc://quit
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player skinned.lnk -> C:\Program Files (x86)\VideoLAN\VLC\vlc.exe () -> -Iskins
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ScanSoft PaperPort 11\Scanner Setup Wizard.lnk -> C:\Program Files (x86)\ScanSoft\PaperPort\ScannerWizard.exe (Nuance Communications, Inc.) -> /A [PaperPort 11.1] /L [eng]
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Kies mini\Uninstall Samsung Kies mini.lnk -> C:\Program Files (x86)\InstallShield Installation Information\{EE43894E-FDCF-4A8C-BCD6-3AAA9A48B486}\setup.exe (Samsung Electronics Co., Ltd.                                ) -> -L1033 /removeonly
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio 2012\Applications\Triple Scoop Music.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> C:\Users\Wayne\Documents\My Music\Triple Scoop Music\
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio 2012\Applications\3D Samples\3D Photo Samples.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> C:\Users\Wayne\Pictures\Roxio 3D Samples\
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio 2012\Applications\3D Samples\3D Video Samples.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> C:\Users\Wayne\Documents\My Videos\Roxio 3D Samples\
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roxio\Roxio Burn.lnk -> C:\Program Files (x86)\Roxio 2012\Roxio Burn\Roxio Burn.exe () -> /STARTMENU
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer\Razer Synapse 2.0\Razer Synapse 2.0.lnk -> C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc.) -> -launch
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime\Uninstall QuickTime.lnk -> C:\Windows\SysWOW64\msiexec.exe (Microsoft Corporation) -> /i {111EE7DF-FC45-40C7-98A7-753AC46B12FB} /qf
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pyTivo\pyTivo - Start on Console.lnk -> C:\Program Files\pyTivo\pyTivo.cmd () -> Console
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pyTivo\pyTivo - Start Service.lnk -> C:\Program Files\pyTivo\pyTivo.cmd () -> Start
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pyTivo\pyTivo - Stop Service.lnk -> C:\Program Files\pyTivo\pyTivo.cmd () -> Stop
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.6\IDLE (Python GUI).lnk -> C:\Windows\Installer\{4723F199-FA64-4233-8E6E-9FCCC95A18EE}\python_icon.exe () -> "C:\Python26\Lib\idlelib\idle.pyw"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.6\Module Docs.lnk -> C:\Windows\Installer\{4723F199-FA64-4233-8E6E-9FCCC95A18EE}\python_icon.exe () -> "C:\Python26\Tools\scripts\pydocgui.pyw"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.6\Uninstall Python.lnk -> C:\Windows\SysWOW64\msiexec.exe (Microsoft Corporation) -> /x{4723f199-fa64-4233-8e6e-9fccc95a18ee}
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\3D Vision preview pack 1.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe (NVIDIA Corporation) -> /show
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\Disable 3D Vision.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe (NVIDIA Corporation) -> /disable
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\Enable 3D Vision.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe (NVIDIA Corporation) -> /enable
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKVToolNix\mkvinfo GUI.lnk -> C:\Program Files (x86)\MKVToolNix\mkvinfo.exe () -> -g
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Backup and Restore Center.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.BackupAndRestore
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro\Remove HitmanPro 3.7.lnk -> C:\Program Files\HitmanPro\HitmanPro.exe (SurfRight B.V.) -> /uninstall
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus\Check for Updates.lnk -> C:\Program Files (x86)\DivX\DivX Control Panel\DivXControlPanelLauncher.exe (DivX, Inc.) -> /start=update
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus\Codec Settings.lnk -> C:\Program Files (x86)\DivX\DivX Control Panel\DivXControlPanelLauncher.exe (DivX, Inc.) -> /start=decoder
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus\Register.lnk -> C:\Program Files (x86)\DivX\DivX Control Panel\DivXControlPanelLauncher.exe (DivX, Inc.) -> /start=registration
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-8870DW LAN\ControlCenter3.lnk -> C:\Program Files (x86)\Brother\ControlCenter3\BrCtrCen.exe (Brother Industries, Ltd.) -> /Model=MFC-8870DW LAN
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-8870DW LAN\Installation Diagnostics.lnk -> C:\Program Files (x86)\Brother\Brmfl05c\Brinstck.exe (Brother Industries, Ltd.) -> MFC-8870DW LAN
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-8870DW LAN\On-Line Registration.lnk -> C:\Program Files (x86)\Brother\Brmfl05c\Brolink\Brolink0.exe (Brother Industories, Ltd.) -> OLR_URL /mMFC-8870DW
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-8870DW LAN\Remote Setup.lnk -> C:\Program Files (x86)\Brother\Brmfl05c\brmfrmss.exe (Brother Industries Ltd.) -> NET "MFC-8870DW LAN"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-8870DW LAN\Status Monitor.lnk -> C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.) -> Brother MFC-8870DW USB Printer on BRW_C963B0 /SHOW
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-8870DW LAN\UnInstall.lnk -> C:\Program Files (x86)\InstallShield Installation Information\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}\setup.exe (Macrovision Corporation) -> -runfromtemp -l0x0009 UNINSTALL Reg=ALFB,Brother MFC-8870DW,LAN
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-8870DW LAN\PC-FAX Sending\PC-FAX Address Book.lnk -> C:\Program Files (x86)\Brother\Brmfl05c\AddrBook.exe (Brother Industries, Ltd.) -> PCFAX TOP
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-8870DW LAN\PC-FAX Sending\PC-FAX Setup.lnk -> C:\Program Files (x86)\Brother\Brmfl05c\PCfxSet.exe (Brother Industries, Ltd.) -> PCFAX
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-8870DW LAN\PC-FAX Receiving\Receive.lnk -> C:\Program Files (x86)\Brother\Brmfl05c\FAXRX.exe (Brother Industries Ltd.) -> -Net "MFC-8870DW LAN"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup\Utilities\AVG Console Defragmentation.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) -> /K "C:\Program Files (x86)\AVG\AVG PC Tuneup\cdefrag.exe"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOL\AOL Desktop Mail.lnk -> C:\Program Files (x86)\AOL Desktop 9.7a\aol.exe (AOL Inc.) -> /SMailbox
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOL\AOL Favorites.lnk -> C:\Program Files (x86)\AOL Desktop 9.7a\aol.exe (AOL Inc.) -> /SFavorites
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOL\AOL MyBenefits.lnk -> C:\Program Files (x86)\AOL Desktop 9.7a\aol.exe (AOL Inc.) -> /SMyBenefits
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOL\AOL Search.lnk -> C:\Program Files (x86)\AOL Desktop 9.7a\aol.exe (AOL Inc.) -> /SAOLSearch
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\Windows\System32\eventvwr.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\Windows\System32\perfmon.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell Modules.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) -> -NoExit -ImportSystemModules
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) -> /open
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Resource Monitor.lnk -> C:\Windows\System32\perfmon.exe (Microsoft Corporation) -> /res
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Speech Recognition.lnk -> C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDirector\Online Registration.lnk -> C:\Program Files (x86)\CyberLink\PowerDirector\OLRSubmission\OLRSubmission.exe () -> /LANG:ENU
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\Wayne\Desktop\Desktop\Windows Mobile Device Center.lnk -> C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation) -> /show
ShortcutWithArgument: C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller\Run Hunter Mode.lnk -> C:\Program Files (x86)\VS Revo Group\Revo Uninstaller\Revouninstaller.exe (VS Revo Group) -> -hunter
ShortcutWithArgument: C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Private Internet Access\Reinstall TAP Driver.lnk -> C:\Program Files\pia_manager\pia_manager.exe () -> --reinstall-tap
ShortcutWithArgument: C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo


InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner Homepage.url -> hxxp://www.piriform.com/ccleaner
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother\MFC-8870DW LAN\On-line help and FAQ's.url -> hxxp://solutions.brother.com/cgi-bin/solutions.cgi?MDL=mfc113&LNG=en&SRC=FAQ
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AC3Filter\AC3Filter home.url -> hxxp://ac3filter.net
InternetURL: C:\Users\Wayne\Favorites\    scriptapalooza screenwriting competition    .URL -> hxxp://www.scriptapalooza.com/index2.html
InternetURL: C:\Users\Wayne\Favorites\A Bright Shining Lie (1998) (TV).URL -> hxxp://www.imdb.com/title/tt0126220/
InternetURL: C:\Users\Wayne\Favorites\A TV sound regulator to maintain comfortable sound for your home.URL -> hxxp://www.tvsoundregulator.com/?gclid=CIXd4-uYqJsCFQtN5QodPTrhhw
InternetURL: C:\Users\Wayne\Favorites\a885ea039f0bc66d.jpg (JPEG Image, 990x363 pixels).URL -> hxxp://www.pitcell.com/images/usertickets/a885ea039f0bc66d.jpg
InternetURL: C:\Users\Wayne\Favorites\ADOBE ACROBAT 9.2.0 PRO EXTENDED EDITION + 9.3.1 UPDATE (download torrent) - TPB.URL -> hxxp://thepiratebay.org/torrent/5130222/ADOBE_ACROBAT_9.2.0_PRO_EXTENDED_EDITION___9.3.1_UPDATE
InternetURL: C:\Users\Wayne\Favorites\Amazon.com  Used and New  AMT - Star Wars Millennium Falcon.URL -> hxxp://www.amazon.com/gp/offer-listing/B0008109RU/ref=dp_olp_new?ie=UTF8&condition=new
InternetURL: C:\Users\Wayne\Favorites\AnandTech -- Hot Deals.URL -> hxxp://forums.anandtech.com/categories.aspx?catid=40&entercat=y
InternetURL: C:\Users\Wayne\Favorites\Angel Baby (1995).URL -> hxxp://www.imdb.com/title/tt0112362/
InternetURL: C:\Users\Wayne\Favorites\Angie & Wayne's Wedding Website on WeddingChannel.com - Home.URL -> hxxp://www.weddingchannel.com/wedding_websites/PersonalWebsite.action?view=home&occ=566948700
InternetURL: C:\Users\Wayne\Favorites\Canyoneering in the San Gabriels - Christopher E. Brennen.URL -> hxxp://www.dankat.com/advents/content.htm
InternetURL: C:\Users\Wayne\Favorites\Casewraps.com - Custom Wraps for the World - Pc, Consoles, Mp3 - Keyboards & more - Just ask (From Firefox).URL -> hxxp://www.casewraps.com/
InternetURL: C:\Users\Wayne\Favorites\Casewraps.com - Custom Wraps for the World - Pc, Consoles, Mp3 - Keyboards & more - Just ask.URL -> hxxp://casewraps.com/
InternetURL: C:\Users\Wayne\Favorites\Collectors Gallery  Star Wars Millenium Falcon cut away ERTL AMT model kit sealed.URL -> hxxp://74.125.155.132/search?q=cache:DS6i7scghCYJ:www.collectorsgalleryonline.com/Merchant2/merchant.mv%3FScreen%3DPROD%26Store_Code%3DCG%26Product_Code%3DFALCONCUTAWAYMODEL%26Category_Code%3DSWM+millenium+falcon+amt&cd=12&hl=en&ct=clnk&gl=us
InternetURL: C:\Users\Wayne\Favorites\Core unlocking MSI 785GM-E51 & Phenom II X2 555 - MSI-Microstar - Motherboards-Memory.URL -> hxxp://www.tomshardware.com/forum/273493-30-core-unlocking-785gm-phenom
InternetURL: C:\Users\Wayne\Favorites\craigslist  los angeles classifieds for jobs, apartments, personals, for sale, services, community, and events.URL -> hxxp://losangeles.craigslist.org/
InternetURL: C:\Users\Wayne\Favorites\Custom Decals  Shops online that let you .URL -> hxxp://www.tomshardware.com/forum/257619-28-custom-decals-shops-online
InternetURL: C:\Users\Wayne\Favorites\Custom Decals.URL -> hxxp://casebadger.com/customwraps.html
InternetURL: C:\Users\Wayne\Favorites\Dark Horizons   Movie Trailers, TV Guide, Movie Reviews, Celebrity Interviews, Entertainment News.URL -> hxxp://www.darkhorizons.com/
InternetURL: C:\Users\Wayne\Favorites\de2511i.pdf (application pdf Object).URL -> hxxp://www.edd.ca.gov/pdf_pub_ctr/de2511i.pdf
InternetURL: C:\Users\Wayne\Favorites\Deadline Hollywood Daily.URL -> hxxp://www.deadlinehollywooddaily.com/
InternetURL: C:\Users\Wayne\Favorites\Defamer, the L.A. Gossip Rag.URL -> hxxp://www.defamer.com/
InternetURL: C:\Users\Wayne\Favorites\disk clone software free download - Free Software Download from AtoZ.URL -> hxxp://www.downloadatoz.com/toplight/disk%20clone%20software.html
InternetURL: C:\Users\Wayne\Favorites\Dolby - Dolby Home Theater Speaker Guide - Speaker Placement and Setup Guide for Home Theater Surround Sound.URL -> hxxp://www.dolby.com/consumer/setup/speaker-setup-guide/index.html
InternetURL: C:\Users\Wayne\Favorites\Done Deal Pro - The Business and Craft of Screenwriting.URL -> hxxp://www.donedealpro.com/default.aspx
InternetURL: C:\Users\Wayne\Favorites\DVD Pricesearch.URL -> hxxp://www.dvdpricesearch.com/
InternetURL: C:\Users\Wayne\Favorites\Dynamic Disk Converter v1.0 Shareware Download - Dynamic Disk Converter is a powerful dynamic disk management software.URL -> hxxp://www.filebuzz.com/fileinfo/57720/Dynamic_Disk_Converter.html
InternetURL: C:\Users\Wayne\Favorites\Eugenic Archives  Pedigree exhibit   Family stock of G. Washington,  3rd International Eugenics Conference.URL -> hxxp://www.eugenicsarchive.org/html/eugenics/static/images/1062.html
InternetURL: C:\Users\Wayne\Favorites\eugenic report card.URL -> hxxp://www.uvm.edu/~lkaelber/eugenics/TX/TX1.jpg
InternetURL: C:\Users\Wayne\Favorites\Eugenics1930ssterilization.URL -> hxxp://docs.google.com/viewer?a=v&q=cache:WESTXjqa-Q8J:www.elliotinstitute.org/images/EugenicsInTransition.pdf+%22eugenics+society%22+sterilization+%2214+million%22&hl=en&gl=us&pid=bl&srcid=ADGEESjuc335804gqqvQgghkYJKt9scjDN7gmNbZZuSOGdi8Yc2Etz8I90wx5oUL5ya5BlfBzzbAVyJ8v9zKwqe4vjtcrEq2ekkLFSYtd8-mY4w31-cWs4c_V1oEAvb_B8-0As1MUFnw&sig=AHIEtbTq_9dKTQuf5cHpNw05DGeJmIiGog
InternetURL: C:\Users\Wayne\Favorites\Everglide Special Ops Case Wrap.URL -> hxxp://www.technoyard.com/hardware/miscellaneous/everglide-case-wrap/page_1.html
InternetURL: C:\Users\Wayne\Favorites\EVGA X58 Overclocking Guide.URL -> hxxp://www.evga.com/forums/tm.asp?m=642527
InternetURL: C:\Users\Wayne\Favorites\Farmer & Chase (1997).URL -> hxxp://www.imdb.com/title/tt0113031/
InternetURL: C:\Users\Wayne\Favorites\FiringSquad  Home of the Hardcore Gamer - Games, Hardware, Reviews and News.URL -> hxxp://www.firingsquad.com/
InternetURL: C:\Users\Wayne\Favorites\Game Rankings - Video Game Reviews, Release Dates, Cheat Codes.URL -> hxxp://www.gamerankings.com/
InternetURL: C:\Users\Wayne\Favorites\GameSpot Video Games PC PlayStation 2 GameCube PSP DS GBA PS2 PS3 Xbox 360 PlayStation 3.URL -> hxxp://www.gamespot.com/
InternetURL: C:\Users\Wayne\Favorites\glenn alan.URL -> hxxp://74.125.155.132/search?q=cache:-wfbpUfKyPgJ:www.thatsentertainmentproductions.com/crew.htm+%22glenn+alan%22+writer+-cheney+-cannon+-smith+-herdling+-akers&cd=1&hl=en&ct=clnk&gl=us
InternetURL: C:\Users\Wayne\Favorites\Go Blackwater Rafting in Waitomo's Underground River.URL -> hxxp://goaustralia.about.com/b/2008/01/08/waitomo-blackwater-rafting.htm
InternetURL: C:\Users\Wayne\Favorites\Google Image Result for http   medinfo.ufl.edu other histmed stoyan images 56.jpg.URL -> hxxp://images.google.com/imgres?imgurl=hxxp://medinfo.ufl.edu/other/histmed/stoyan/images/56.jpg&imgrefurl=hxxp://medinfo.ufl.edu/other/histmed/stoyan/slide56.html&usg=__wHqdyOPNcO21dBTQArb9U-V7mtI=&h=476&w=352&sz=32&hl=en&start=5&um=1&tbnid=olxbOotb75ucpM:&tbnh=129&tbnw=95&prev=/images%3Fq%3D%2522fitter%2Bfamily%2522%2Bcontest%26hl%3Den%26um%3D1
InternetURL: C:\Users\Wayne\Favorites\Google Image Result for http   www.fireplacedesigninfo.com images modern-fireplace.jpg.URL -> hxxp://images.google.com/imgres?imgurl=hxxp://www.fireplacedesigninfo.com/images/modern-fireplace.jpg&imgrefurl=hxxp://www.fireplacedesigninfo.com/fireplace-pictures.html&usg=__m3gSY0LSvj0xwo0I6fICTAtwO54=&h=300&w=400&sz=68&hl=en&start=39&um=1&itbs=1&tbnid=tPuJGATyVMxs3M:&tbnh=93&tbnw=124&prev=/images%3Fq%3Dfireplace%2Bmodern%26start%3D36%26um%3D1%26hl%3Den%26safe%3Doff%26sa%3DN%26ndsp%3D18%26tbs%3Disch:1
InternetURL: C:\Users\Wayne\Favorites\Google Image Result for http   www.platonicfireplaces.co.uk images platonic_collection_fireplaces 9 9_default.jpg.URL -> hxxp://images.google.com/imgres?imgurl=hxxp://www.platonicfireplaces.co.uk/images/platonic_collection_fireplaces/9/9_default.jpg&imgrefurl=hxxp://www.stylehive.com/tag/minimalist_hole_in_the_wall_fireplaces&usg=__9W7WxHajIjA3C0cgFJ14WXnomYk=&h=453&w=524&sz=153&hl=en&start=44&um=1&itbs=1&tbnid=P__JWHRLqsMpLM:&tbnh=114&tbnw=132&prev=/images%3Fq%3Dfireplace%2Bmodern%26start%3D36%26um%3D1%26hl%3Den%26safe%3Doff%26sa%3DN%26ndsp%3D18%26tbs%3Disch:1
InternetURL: C:\Users\Wayne\Favorites\Google Image Result for http   www.stone-essentials.co.uk Images stone_fireplace_1.jpg.URL -> hxxp://images.google.com/imgres?imgurl=hxxp://www.stone-essentials.co.uk/Images/stone_fireplace_1.jpg&imgrefurl=hxxp://www.stone-essentials.co.uk/Html/Fireplaces_3.html&usg=__C7PoU2W8aPuLj8a7UiCe55UmQfo=&h=500&w=500&sz=25&hl=en&start=31&um=1&itbs=1&tbnid=aPXSBJfyqPuE-M:&tbnh=130&tbnw=130&prev=/images%3Fq%3Dfireplace%2Bmodern%26start%3D18%26um%3D1%26hl%3Den%26safe%3Doff%26sa%3DN%26ndsp%3D18%26tbs%3Disch:1
InternetURL: C:\Users\Wayne\Favorites\HDMI over one CAT5 Cable.URL -> hxxp://www.hdtvsupply.com/hdmi-to-single-cat5.html
InternetURL: C:\Users\Wayne\Favorites\HDMI OVER SINGLE CAT5E 6 EXTENDER BALUN SET from Milestek - Electronic Components for Home Automation, Security Surveillance, Fiber Optics, Voice and Data, Networking, Custom Cables 1553, CAT 5e and More.URL -> hxxp://www.milestek.com/shop/product.asp?id=90%2012016
InternetURL: C:\Users\Wayne\Favorites\hole2.jpg (JPEG Image, 659x360 pixels).URL -> hxxp://www.burningdesires.co.uk/images/home/hole2.jpg
InternetURL: C:\Users\Wayne\Favorites\Home Page.URL -> hxxp://www.nextgentactics.com/Games.aspx?Area=1&GName=God%20of%20War%20III
InternetURL: C:\Users\Wayne\Favorites\How To  Install Windows 7 on an XP or Vista Machine.URL -> hxxp://www.tomshardware.com/forum/248-63-install-windows-vista-machine
InternetURL: C:\Users\Wayne\Favorites\How to Unlock Your iPhone and Use The $5.99 T-Zones Plan.URL -> hxxp://uneasysilence.com/archive/2007/09/12232/
InternetURL: C:\Users\Wayne\Favorites\http   www.ikonique.com 2008_1122 .URL -> hxxp://www.ikonique.com/2008_1122/
InternetURL: C:\Users\Wayne\Favorites\In-wall, In-ceiling, and On-wall Speaker Placement.URL -> hxxp://www.crutchfield.com/S-JdNloCgUSc9/learn/learningcenter/home/mr/inwall_placement.html
InternetURL: C:\Users\Wayne\Favorites\io9. Strung out on science fiction.URL -> hxxp://io9.com/
InternetURL: C:\Users\Wayne\Favorites\Jeff's Heron photos.URL -> hxxp://www.ikonique.com/2008_1122/
InternetURL: C:\Users\Wayne\Favorites\Jo and Sarb's Year Off.URL -> hxxp://209.85.173.104/search?q=cache:Q9dSt_rr_eAJ:joandsarb.blogspot.com/+%22glow+worms%22+griffith+park&hl=en&ct=clnk&cd=7&gl=us
InternetURL: C:\Users\Wayne\Favorites\Love Is the Drug (2006).URL -> hxxp://www.imdb.com/title/tt0266732/
InternetURL: C:\Users\Wayne\Favorites\Modern Contemporary Interior Design with Mediterranean Style in Seattle’s Queen Anne - Interior Design - Modern Design, Dining Room, Home Design.URL -> hxxp://www.outinhome.com/2009/10/modern-contemporary-interior-design-with-mediterranean-style-in-seattle%e2%80%99s-queen-anne/
InternetURL: C:\Users\Wayne\Favorites\Monster-Hardware.URL -> hxxp://209.85.173.132/search?q=cache:6hPo--2mCqEJ:www.monster-hardware.com/modules.php%3Fname%3DReviews%26rop%3Dshowcontent%26id%3D87+custom+pc+case+wraps&hl=en&ct=clnk&cd=9&gl=us
InternetURL: C:\Users\Wayne\Favorites\MSNBC - MSNBC.com.URL -> hxxp://www.msnbc.msn.com/
InternetURL: C:\Users\Wayne\Favorites\Off the Black (2006).URL -> hxxp://www.imdb.com/title/tt0479965/
InternetURL: C:\Users\Wayne\Favorites\Ozone-T.URL -> hxxp://www.ozone-torrents.org/browse.php
InternetURL: C:\Users\Wayne\Favorites\PC Case Wrap Lifeforce - Paddys Trash and Treasure Professional Web and Graphic Designers.URL -> hxxp://www.paddystrashandtreasure.com/product_info.php?products_id=228&osCsid=93f5d2fcac3370875fec7a9bdc44fe08
InternetURL: C:\Users\Wayne\Favorites\PriceGrabber.com - Comparison Shopping Beyond Compare.URL -> hxxp://www.pricegrabber.com/
InternetURL: C:\Users\Wayne\Favorites\Print Boarding Passes and Security Documents - Southwest Airlines.URL -> hxxp://www.southwest.com/flight/viewCheckinDocument.html?companyName=&cid=&memberName=&disc=0%3A3%3A1257721176.488000%3A24693%40449411E1B03695815B622AA0FB57756004E5CE8C&ss=0&dest=
InternetURL: C:\Users\Wayne\Favorites\Puerto-Princesa Subterranean River National Park - World Heritage Site - Pictures, info and travel reports.URL -> hxxp://www.worldheritagesite.org/sites/puertoprincesa.html
InternetURL: C:\Users\Wayne\Favorites\Returns Label   Old Navy.URL -> https://secure-oldna...eturns_label.do
InternetURL: C:\Users\Wayne\Favorites\reuters.URL -> hxxp://www.reuters.com/
InternetURL: C:\Users\Wayne\Favorites\ROTTEN TOMATOES  Movies and Games, Reviews and Previews.URL -> hxxp://www.rottentomatoes.com/
InternetURL: C:\Users\Wayne\Favorites\San Gabriel Chapter (Southern California) - Canyon Forums Gallery.URL -> hxxp://www.canyoneering.net/forums/forumdisplay.php?f=29
InternetURL: C:\Users\Wayne\Favorites\Script P.I.M.P. (Pipeline Into Motion Pictures).URL -> hxxp://www.scriptpimp.com/two/index.cfm?do=competition&CFID=62488403&CFTOKEN=46826655
InternetURL: C:\Users\Wayne\Favorites\Sony DA5300ES progamming issues - TiVo Community.URL -> hxxp://www.tivocommunity.com/tivo-vb/showthread.php?t=381219&highlight=da5300es
InternetURL: C:\Users\Wayne\Favorites\Sony_STRDA5300_manual.pdf (application pdf Object).URL -> hxxp://www.superfi.co.uk/extras/Sony/Sony_STRDA5300_manual.pdf
InternetURL: C:\Users\Wayne\Favorites\Spellbound New Zealand   Waitomo Glowworm Caves & Glowworm Tours, Waitomo, New Zealand.URL -> hxxp://www.glowworm.co.nz/
InternetURL: C:\Users\Wayne\Favorites\Spring Break for the Whoooole Family - washingtonpost.com.URL -> hxxp://www.washingtonpost.com/wp-dyn/content/article/2008/03/07/AR2008030701349.html?hpid=artslot
InternetURL: C:\Users\Wayne\Favorites\Star Wars Cut-Away Millenium Falcon AMT Ertl (MISB)1996 - eBay (item 330260803789 end time Oct-04-09 00 23 19 PDT).URL -> hxxp://cgi.ebay.com/Star-Wars-Cut-Away-Millenium-Falcon-AMT%2fErtl-(MISB)1996_W0QQitemZ330260803789QQcmdZViewItem
InternetURL: C:\Users\Wayne\Favorites\Star Wars Millenium Falcon ERTL AMT Model Kit BNIB New - eBay (item 230371470735 end time Sep-25-09 12 29 25 PDT).URL -> hxxp://cgi.ebay.com/Star-Wars-Millenium-Falcon-ERTL-AMT-Model-Kit-BNIB-New_W0QQitemZ230371470735QQcmdZViewItemQQptZUK_ToysGames_ModelKits_ModelKits_JN?hash=item35a335ad8f&_trksid=p3286.c0.m14
InternetURL: C:\Users\Wayne\Favorites\STAR WARS MILLENIUM FALCON MODEL KIT on eBay (end time 30-Sep-09 18 36 21 BST).URL -> hxxp://cgi.ebay.co.uk/STAR-WARS-MILLENIUM-FALCON-MODEL-KIT_W0QQitemZ180409989792QQcmdZViewItemQQptZUK_Construction_Toys_Kits?hash=item2a0145faa0&_trksid=p3286.c0.m14
InternetURL: C:\Users\Wayne\Favorites\Star Wars Millenium Falcon Model Lighting Kit - Lighting Kits - Miniature machine tools and unique hobby items.URL -> hxxp://www.vcshobbies.com/merchant.ihtml?pid=1275&step=4
InternetURL: C:\Users\Wayne\Favorites\Starship Modeler - ERTL Millenium Falcon.URL -> hxxp://www.starshipmodeler.com/starwars/jm_mf.htm
InternetURL: C:\Users\Wayne\Favorites\Starship Modeler - Star Wars' Millenium Falcon.URL -> hxxp://74.125.155.132/search?q=cache:Yte6x3kwosUJ:www.starshipmodeler.com/starwars/rm_falcon.htm+millenium+falcon+amt&cd=3&hl=en&ct=clnk&gl=us
InternetURL: C:\Users\Wayne\Favorites\StoryLink  Contests.URL -> hxxp://www.storylink.com/contests
InternetURL: C:\Users\Wayne\Favorites\StoryLink  FREE SCREENPLAY CONTEST - 2009 2010.URL -> hxxp://www.storylink.com/contest/freescreenplaycontest
InternetURL: C:\Users\Wayne\Favorites\Stream of Consciousness (The Outer Limits) - Wikipedia, the free encyclopedia.URL -> hxxp://en.wikipedia.org/wiki/Stream_of_Consciousness_(The_Outer_Limits)
InternetURL: C:\Users\Wayne\Favorites\T-mobile G1 internet with 9.99 Tzones hack, 5.99 no more  ( « HydTech.URL -> hxxp://hydtech.wordpress.com/2009/02/10/t-mobile-g1-internet-with-999-tzones-hack-599-no-more/
InternetURL: C:\Users\Wayne\Favorites\Techbargains - discount computer sale buy cheap digital camera review cheap laptop techbargain tech bargain - Techbargains.com.URL -> hxxp://www.techbargains.com/
InternetURL: C:\Users\Wayne\Favorites\Television Without Pity.URL -> hxxp://www.televisionwithoutpity.com/
InternetURL: C:\Users\Wayne\Favorites\The Adventures of Sebastian Cole (1998).URL -> hxxp://www.imdb.com/title/tt0168449/combined
InternetURL: C:\Users\Wayne\Favorites\The Cleanest Fireplace Around by Spark Fires.URL -> hxxp://www.furniturestoreblog.com/2007/12/21/the_cleanest_fireplace_around_by_sprark_fires.html
InternetURL: C:\Users\Wayne\Favorites\The Crime & Detective Pulps.URL -> hxxp://www.thrillingdetective.com/trivia/pulps.html
InternetURL: C:\Users\Wayne\Favorites\The Huffington Post.URL -> hxxp://www.huffingtonpost.com/
InternetURL: C:\Users\Wayne\Favorites\The Internet Movie Database (IMDb).URL -> hxxp://www.imdb.com/
InternetURL: C:\Users\Wayne\Favorites\The New York Times - Breaking News, World News & Multimedia.URL -> hxxp://www.nytimes.com/
InternetURL: C:\Users\Wayne\Favorites\The Pirate Bay.URL -> hxxp://thepiratebay.org/
InternetURL: C:\Users\Wayne\Favorites\Tom's Hardware.URL -> hxxp://www.tomshardware.com/
InternetURL: C:\Users\Wayne\Favorites\Traces of Red (1992) - Plot summary.URL -> hxxp://www.imdb.com/title/tt0105631/plotsummary
InternetURL: C:\Users\Wayne\Favorites\Tzones hack on 3.0 - Hackint0sh.URL -> hxxp://www.hackint0sh.org/f201/76391.htm
InternetURL: C:\Users\Wayne\Favorites\very+expensive+fireplaces.jpg (JPEG Image, 390x363 pixels).URL -> hxxp://1.bp.blogspot.com/_1wHfU1IM-UE/STV_BYbMS4I/AAAAAAAABFo/LafetS6qJR4/s400/very+expensive+fireplaces.jpg
InternetURL: C:\Users\Wayne\Favorites\Video  Installing In-wall and In-ceiling Speakers — The Basics.URL -> hxxp://www.crutchfield.com/Learn/learningcenter/home/inwall_video.html
InternetURL: C:\Users\Wayne\Favorites\View Forum - ARG  Flynn Lives.URL -> hxxp://forums.unfiction.com/forums/index.php?f=260
InternetURL: C:\Users\Wayne\Favorites\Vinyl Decals, Banners, Full Color Signs, Vehicle Stickers.URL -> hxxp://www.graphxonline.com/products.php
InternetURL: C:\Users\Wayne\Favorites\washingtonpost.com - nation, world, technology and Washington area news and headlines.URL -> hxxp://www.washingtonpost.com/
InternetURL: C:\Users\Wayne\Favorites\WHEDONesque   Joss Whedon weblog.URL -> hxxp://whedonesque.com/
InternetURL: C:\Users\Wayne\Favorites\Wikipedia.URL -> hxxp://www.wikipedia.org/
InternetURL: C:\Users\Wayne\Favorites\YouTube - Case Mod  Computer Modding with Vinyl Film.URL -> hxxp://www.youtube.com/watch?v=7aUnaVO8iLs
InternetURL: C:\Users\Wayne\Favorites\YouTube - Fox News Blames Democrats for Foley Coverup to Save Seat.URL -> hxxp://www.youtube.com/watch?v=KchQ55q62N0
InternetURL: C:\Users\Wayne\Favorites\YouTube - Hamster Dance Star Wars.URL -> hxxp://www.youtube.com/watch?v=A7JhLr5jlh8&NR=1
InternetURL: C:\Users\Wayne\Favorites\YouTube - Rednex - Cotton Eye Joe.URL -> hxxp://www.youtube.com/watch?v=ddgyg_5FF_0
InternetURL: C:\Users\Wayne\Favorites\★iPhone Hacks & Mods★  How to get $5.99 T-Zones on iPhone 3G (grandfathered plan).URL -> hxxp://www.iphonehacksnmods.com/2009/06/how-to-get-599-t-zones-on-iphone-3g.html
InternetURL: C:\Users\Wayne\Favorites\훘sorted Bookmarks\Ghostbusters  The Video Game Video Game, Exclusive Opening Cinematic HD   Game Trailers & Videos   GameTrailers.com.URL -> hxxp://www.gametrailers.com/player/48373.html
InternetURL: C:\Users\Wayne\Favorites\훘sorted Bookmarks\HSI Field Technician Ping Tool.URL -> hxxp://ping.verizon.net/micro/ping/HSIPingTestPage.aspx?ResultStatus=completed&testID=688137746&displayView=FULLVIEW
InternetURL: C:\Users\Wayne\Favorites\훘sorted Bookmarks\Images.URL -> hxxp://www.amblerexpressions.com/Ambler_Expressions/Images.html#9
InternetURL: C:\Users\Wayne\Favorites\훘sorted Bookmarks\PdaNet -- USB Tether Bluetooth DUN for Android.URL -> hxxp://www.junefabrics.com/android/index.php
InternetURL: C:\Users\Wayne\Favorites\Windows Live\Get Windows Live.url -> hxxp://go.microsoft.com/fwlink/?LinkId=69172
InternetURL: C:\Users\Wayne\Favorites\Windows Live\Windows Live Gallery.url -> hxxp://go.microsoft.com/fwlink/?LinkId=70742
InternetURL: C:\Users\Wayne\Favorites\Windows Live\Windows Live Mail.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68925
InternetURL: C:\Users\Wayne\Favorites\Windows Live\Windows Live Spaces.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68927
InternetURL: C:\Users\Wayne\Favorites\torrentsites\dcp    isoHunt - IRC and Bit Torrent search engine.URL -> hxxp://isohunt.com/torrents.php?ihq=dcp&ext=&op=and&ihs1=2&iho1=d&iht=-1&ihp=4
InternetURL: C:\Users\Wayne\Favorites\torrentsites\Devon - Gallery from Monster Dick Series.URL -> hxxp://gals.monsterdickseries.com/part/02-100/devonm.html
InternetURL: C:\Users\Wayne\Favorites\torrentsites\EZTV - TV torrents online.URL -> hxxp://www.eztvefnet.org/index.php
InternetURL: C:\Users\Wayne\Favorites\torrentsites\mininova   the ultimate bittorrent source!.URL -> hxxp://www.mininova.org/
InternetURL: C:\Users\Wayne\Favorites\torrentsites\Movie Shark - 500+ free porn steele movie galleries per day, 500+ categories and a searchable database.URL -> hxxp://72.14.203.104/search?q=cache:weCc_bzRYPYJ:www.movieshark.com/steele.html+%22lexington+steele%22+mpg&hl=en&gl=us&ct=clnk&cd=3
InternetURL: C:\Users\Wayne\Favorites\torrentsites\SceneTorrents    Login.URL -> hxxp://www.scenetorrents.org/login.php?returnto=%2F
InternetURL: C:\Users\Wayne\Favorites\torrentsites\SuperTorrents.URL -> hxxp://www.supertorrents.org/
InternetURL: C:\Users\Wayne\Favorites\torrentsites\The Pirate Bay - The worlds largest BitTorrent tracker (From Firefox).URL -> hxxp://thepiratebay.org/details.php?id=3450922
InternetURL: C:\Users\Wayne\Favorites\torrentsites\The Pirate Bay - The worlds largest BitTorrent tracker.URL -> hxxp://thepiratebay.org/
InternetURL: C:\Users\Wayne\Favorites\torrentsites\TvTorrents.COM -.URL -> hxxp://www.tvtorrents.com/
InternetURL: C:\Users\Wayne\Favorites\torrents\Soulbitz.URL -> hxxp://soulbitz.com/
InternetURL: C:\Users\Wayne\Favorites\torrents\Torrent list - Demonoid.URL -> hxxp://www.demonoid.com/files/
InternetURL: C:\Users\Wayne\Favorites\torrents\TorrentLeech.org.URL -> hxxp://www.torrentleech.org/browse.php
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\Acrylic Products on ThomasNet.com in Southern California.URL -> hxxp://72.14.207.104/search?q=cache:kQzHC04PWI0J:www.thomasnet.com/southern-california/acrylic-products-295402-1.html+%22acrylic+sheet%22+%22california%22&hl=en&gl=us&ct=clnk&cd=11
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\AntennaWeb.URL -> hxxp://antennaweb.org/aw/Address.aspx
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\Bello PVS-4218HG Black - Bello PVS-4218HG.URL -> hxxp://www.audio-video-furniture.com/Bello-PVS-4218HG-Black.htm
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\Bush Furniture Plasma TV Stands & HD TV Stand.URL -> hxxp://www.ifurn.com/Plasma%20_%20HD%20TV%20Stands.html
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\Bush Furniture VS44850-03 Midnight Mist Collection - Bush VS44850.URL -> hxxp://www.audio-video-furniture.com/Bush-Furniture-VS44850-03-Midnight-Mist-Collection.htm
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\Cal Plastics and Metals.URL -> hxxp://www.calplasticsandmetals.com/acrylic.htm
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\Calsak Plastics - Plastic Materials, ABS Plastic, Plexiglass (Plexiglas), Acrylic Plastic, PVC.URL -> hxxp://www.calsakplastics.com/display_category_products.php?CategoryID=639
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\Computing.Net - Windows Firewall Settings Dont Open.URL -> hxxp://66.102.7.104/search?q=cache:qdHr_m-jqdYJ:www.computing.net/windowsxp/wwwboard/forum/149891.html+%22due+to+an+unidentified+problem,+windows+can+not+display+windows+firewall%22&hl=en&gl=us&ct=clnk&cd=2
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\Cordless Keyboard and Mouse Optical Suite.URL -> hxxp://64.233.167.104/search?q=cache:Xd8dB79JXZgJ:www.ergonomicresource.com/corkey.html+cordless+keyboard+range&hl=en&gl=us&ct=clnk&cd=31
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\eBay  BellO PVS-4260 Plasma TV and Audio Video System Stand (item 4459841265 end time May-08-06 18 56 29 PDT).URL -> hxxp://cgi.ebay.com/BellO-PVS-4260-Plasma-TV-and-Audio-Video-System-Stand_W0QQitemZ4459841265QQcategoryZ20488QQrdZ1QQcmdZViewItem
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\eBay  OMNIMOUNT STELLAR G3FP UNIVERSAL FLAT PANEL TV STAND (item 9724780813 end time May-12-06 18 31 09 PDT).URL -> hxxp://cgi.ebay.com/OMNIMOUNT-STELLAR-G3FP-UNIVERSAL-FLAT-PANEL-TV-STAND_W0QQitemZ9724780813QQcategoryZ84078QQssPageNameZWDVWQQrdZ1QQcmdZViewItem
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\eBay  Plasma TV stand w 2 AV shelves for 42 - 50  TVs - NEW (item 4460984752 end time May-13-06 08 27 13 PDT).URL -> hxxp://cgi.ebay.com/Plasma-TV-stand-w-2-AV-shelves-for-42-50-TVs-NEW_W0QQitemZ4460984752QQcategoryZ20488QQrdZ1QQcmdZViewItem
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\eBay – TV Stands, Accessories Cables and Televisions items on eBay.com.URL -> hxxp://listings.ebay.com/_W0QQsocmdZListingItemList?sofocus=bs&sbrftog=1&from=R2&socmd=ListingItemList&fcl=3&catref=C3&satitle=&sacat=84078%26catref%3DC6&bs=Search&fsop=2%26fsoo%3D2&coaction=compare&copagenum=1&coentrypage=search&fgtp=&sargn=-1%26saslc%3D2&sadis=200&fpos=90048&ftrt=1&ftrv=1&saprclo=&saprchi=
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\eStreetPlastics - plexiglass sheet supplier.URL -> hxxp://www.estreetplastics.com/category_s/55.htm
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\Flat Panel Furniture - Bello.URL -> hxxp://www.bello.com/index.php?partition=categories&categ_id=39
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\Init TV Stand.URL -> hxxp://losangeles.craigslist.org/ele/159739111.html
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\Oodle University of California, Los Angeles - Classifieds for jobs, cars, apartments, and more.URL -> hxxp://ucla.oodle.com/
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\PennySaverUSA Classifieds Online  Local ads in California - TV VCR STAND DINING TABLE.URL -> hxxp://www.pennysaverusa.com/info/showinfo.aspx?id=i06042221011137383
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\Plasma Centers and Stands.URL -> hxxp://www.racksandstands.com/Black-l70-c59-A590~1010.html
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\Plasma Stand Users - AVS Forum.URL -> hxxp://72.14.207.104/search?q=cache:yhi7ccHHYLoJ:www.avsforum.com/avs-vb/showthread.php%3Ft%3D420633+%22los+angeles%22+plasma+stands&hl=en&gl=us&ct=clnk&cd=12
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\Plasma TV.URL -> hxxp://losangeles.craigslist.org/ele/160832310.html
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\Solter Plastics [ colored plastics ].URL -> hxxp://www.solterplastics.com/plastics/colored/
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\Sonus Homepage.URL -> hxxp://www.sonus-systems.co.uk/av.html
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\The Facts and Fiction of 1080p - Xbox.URL -> hxxp://editorials.teamxbox.com/xbox/1544/The-Facts-and-Fiction-of-1080p/p3/
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\TV Stands, Plasma TV Stands, TV Carts, Plasma Television Stands, Wood Plasma TV Stands.URL -> hxxp://www.autumngalleryforthehome.com/4297.html
InternetURL: C:\Users\Wayne\Favorites\plasmatvstuff\Welcome to Professional Plastics.URL -> hxxp://www.professionalplastics.com/cgi-bin/main/co_disp/displ/prrfnbr/85259/sesent/00/ACRYLIC-SHEETS-EXTRUDED-Plexiglass
InternetURL: C:\Users\Wayne\Favorites\overclocking\$89 Pentium Dual Core that Runs at 3.2 GHz   Tom's Hardware.URL -> hxxp://www.tomshardware.com/2007/09/12/pentium_dual_core/index.html
InternetURL: C:\Users\Wayne\Favorites\overclocking\Core 2 motherboard overclocking roundup - Feature - CPUs, motherboards, overclocking and cooling - www.atomicmpc.com.au.URL -> hxxp://www.atomicmpc.com.au/article.asp?CIID=74255
InternetURL: C:\Users\Wayne\Favorites\overclocking\How To OverClock.URL -> hxxp://www.basichardware.com/how_to_overclock.html
InternetURL: C:\Users\Wayne\Favorites\overclocking\How-to overclock - Geeks to Go!.URL -> hxxp://www.geekstogo.com/forum/How-to-overclock-t11177.html
InternetURL: C:\Users\Wayne\Favorites\overclocking\HOWTO  Overclock C2Q (Quads) and C2D (Duals) - A Guide v1.2.URL -> hxxp://www.tomshardware.com/forum/240001-29-howto-overclock-quads-duals-guide
InternetURL: C:\Users\Wayne\Favorites\overclocking\Overclocking  Dual- vs. Quad-Core CPUs   Tom's Hardware.URL -> hxxp://www.tomshardware.com/2007/11/08/dual_vs_quad/
InternetURL: C:\Users\Wayne\Favorites\overclocking\[H] Enthusiast - EVGA e-GeForce 8800 GTS 320 MB Superclocked.URL -> hxxp://enthusiast.hardocp.com/article.html?art=MTI5MywxMSwsaGVudGh1c2lhc3Q=
InternetURL: C:\Users\Wayne\Favorites\MSN Websites\MSN Autos.url -> hxxp://go.microsoft.com/fwlink/?LinkId=55143
InternetURL: C:\Users\Wayne\Favorites\MSN Websites\MSN Entertainment.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68924
InternetURL: C:\Users\Wayne\Favorites\MSN Websites\MSN Money.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68923
InternetURL: C:\Users\Wayne\Favorites\MSN Websites\MSN Sports.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68921
InternetURL: C:\Users\Wayne\Favorites\MSN Websites\MSN.url -> hxxp://go.microsoft.com/fwlink/?LinkId=54729
InternetURL: C:\Users\Wayne\Favorites\MSN Websites\MSNBC News.url -> hxxp://go.microsoft.com/fwlink/?LinkId=68922
InternetURL: C:\Users\Wayne\Favorites\Microsoft Websites\IE Add-on site.url -> hxxp://go.microsoft.com/fwlink/?LinkId=50893
InternetURL: C:\Users\Wayne\Favorites\Microsoft Websites\IE site on Microsoft.com.url -> hxxp://go.microsoft.com/fwlink/?linkid=44661
InternetURL: C:\Users\Wayne\Favorites\Microsoft Websites\Microsoft At Home.url -> hxxp://go.microsoft.com/fwlink/?linkid=55424
InternetURL: C:\Users\Wayne\Favorites\Microsoft Websites\Microsoft At Work.url -> hxxp://go.microsoft.com/fwlink/?linkid=68920
InternetURL: C:\Users\Wayne\Favorites\Microsoft Websites\Microsoft Store.url -> hxxp://go.microsoft.com/fwlink/?linkid=140813
InternetURL: C:\Users\Wayne\Favorites\Links for United States\GobiernoUSA.gov.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129792
InternetURL: C:\Users\Wayne\Favorites\Links for United States\USA.gov.url -> hxxp://go.microsoft.com/fwlink/?LinkId=129791
InternetURL: C:\Users\Wayne\Favorites\Links\Flynn Lives.URL -> hxxp://www.flynnlives.com/default.aspx
InternetURL: C:\Users\Wayne\Favorites\Links\FW.URL -> hxxp://www.fatwallet.com/forums/hot-deals/
InternetURL: C:\Users\Wayne\Favorites\Links\Huffpo.URL -> hxxp://www.huffingtonpost.com/
InternetURL: C:\Users\Wayne\Favorites\Links\imdb.URL -> hxxp://www.imdb.com/
InternetURL: C:\Users\Wayne\Favorites\Links\Mr. M.URL -> hxxp://mhanson.com/blog
InternetURL: C:\Users\Wayne\Favorites\Links\MSNBC .URL -> hxxp://www.msnbc.msn.com/
InternetURL: C:\Users\Wayne\Favorites\Links\Pbay.URL -> hxxp://thepiratebay.org/top/201
InternetURL: C:\Users\Wayne\Favorites\Links\SlickDeals.URL -> hxxp://slickdeals.net/forums/forumdisplay.php?f=9
InternetURL: C:\Users\Wayne\Favorites\Links\Suggested Sites.url -> 0
InternetURL: C:\Users\Wayne\Favorites\Housing\2007 and 2008 South Bay Sold Homes and Real Estate Prices.URL -> hxxp://www.keithkylehomes.com/Recent_South_Bay_Home_Sales.htm
InternetURL: C:\Users\Wayne\Favorites\Housing\Blake and Diana Homes   high-torque real estate sales and marketing.URL -> hxxp://www.blakeanddiana.com/
InternetURL: C:\Users\Wayne\Favorites\Housing\Bubble Markets Inventory Tracking.URL -> hxxp://bubbletracking.blogspot.com/
InternetURL: C:\Users\Wayne\Favorites\Housing\Countrywide Foreclosures (REO) Blog - Housing Bubble.URL -> hxxp://countrywide-foreclosures.blogspot.com/
InternetURL: C:\Users\Wayne\Favorites\Housing\Curbed LA   The Los Angeles Neighborhoods and Real Estate Blog.URL -> hxxp://la.curbed.com/
InternetURL: C:\Users\Wayne\Favorites\Housing\Dr. Housing Bubble Blog.URL -> hxxp://www.doctorhousingbubble.com/
InternetURL: C:\Users\Wayne\Favorites\Housing\HousingTracker.net  Median Home Asking Price & Inventory Data for Los Angeles, California.URL -> hxxp://www.housingtracker.net/askingprices/California/LosAngeles-LongBeach-SantaAna/LosAngeles-LongBeach-Glendale
InternetURL: C:\Users\Wayne\Favorites\Housing\L.A. Land  Los Angeles Times.URL -> hxxp://latimesblogs.latimes.com/laland/
InternetURL: C:\Users\Wayne\Favorites\Housing\LA Life - Find Your Place in Los Angeles.URL -> hxxp://www.lalife.com/
InternetURL: C:\Users\Wayne\Favorites\Housing\Los Angeles South Bay Beach Cities Housing Bubble.URL -> hxxp://sbbeachbubble.blogspot.com/
InternetURL: C:\Users\Wayne\Favorites\Housing\Manhattan Beach Confidential.URL -> hxxp://www.mbconfidential.com/
InternetURL: C:\Users\Wayne\Favorites\Housing\Manhattan Beach Real Estate-Redondo Beach Townhomes.URL -> hxxp://beachcityrealestateinfo.blogspot.com/
InternetURL: C:\Users\Wayne\Favorites\Housing\Santa Monica Distress Monitor.URL -> hxxp://smdistress.blogspot.com/
InternetURL: C:\Users\Wayne\Favorites\Housing\Southern California Real Estate Bubble Crash Blog.URL -> hxxp://www.socalbubble.com/
InternetURL: C:\Users\Wayne\Favorites\Housing\Westside Bubble.URL -> hxxp://www.westside-bubble.blogspot.com/
InternetURL: C:\Users\Wayne\Favorites\Housing\WestsideREmeltdown.URL -> hxxp://westsideremeltdown.blogspot.com/
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\A look back at the history of the American Eugenics movement will help us learn from flaws of naïve genetic judgment so that we ma.URL -> hxxp://209.85.173.132/search?q=cache:tFora6nNj5oJ:www.accd.edu/sac/honors/main/papers02/Judge.htm+%22freak+shows%22+eugenics&hl=en&ct=clnk&cd=10&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\About The PureLife Alternative Wellness Center.URL -> hxxp://www.purelifealternative.com/AboutUs.html
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Amazon Online Reader   Davenport's Dream  21st Century Reflections on Heredity and Eugenics.URL -> hxxp://www.amazon.com/gp/reader/0879697563/ref=sib_dp_pop_ff?ie=UTF8&p=S002#reader-link
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Amazon.com  The deeps of deliverance (The Library of Netherlandic literature, v. 5)  Books  Frederik van Eeden.URL -> hxxp://www.amazon.com/gp/product/0805734198/sr=8-4/qid=1154857358/ref=sr_1_4/104-5017756-3732735?ie=UTF8
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\America 1930-1939  Medicine and Health History  Ovevriew   American Decades.URL -> hxxp://72.14.253.104/search?q=cache:qcxXVx2U_lUJ:www.bookrags.com/history/america-1930s-medicine-and-health/+1930s+medicine&hl=en&ct=clnk&cd=1&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\American Eugenics Society Records , American Philosophical Society.URL -> hxxp://www.amphilsoc.org/library/mole/a/aes.htm#boxfolder2
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Black Mask Magazine - An American Classic.URL -> hxxp://209.85.173.132/search?q=cache:foHXhkx_BV8J:www.blackmaskmagazine.com/bm_08.html+%22weird+tales%22+%22black+book+detective%22&cd=20&hl=en&ct=clnk&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Blue Coats-Black Skin  The Black Experience in the New York City Police Department Since 1891 (An Exposition-University Book)  James I. Alexander  Books.URL -> hxxp://www.amazon.com/Blue-Coats-Black-Skin-Experience-Exposition-University/dp/0682490318/ref=sr_1_3?ie=UTF8&s=books&qid=1237207298&sr=1-3
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Boldtype   June 2005 - Issue Twenty.URL -> hxxp://72.14.203.104/search?q=cache:VCBRu9mlhtIJ:boldtype.com/issues/june2005/index.html+police+%22homicide+detectives%22+biography&hl=en&gl=us&ct=clnk&cd=6
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\CELEBRITY ARCHIVE - High Profile Autopsies.URL -> hxxp://72.14.253.104/search?q=cache:W7ijD0Nb1O8J:www.celebritycollectables.com/cgi-bin/ezshopper/loadpage.cgi%3Fuser_id%3D%26file%3Dautopsy.htm+phenobarbital+autopsy&hl=en&gl=us&ct=clnk&cd=6
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\croton_water_works.pdf (application pdf Object).URL -> hxxp://www.stadtentwicklung.berlin.de/denkmal/berliner_denkmaltage/vortraege2004/croton_water_works.pdf
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\description of reservoir oceanus.URL -> hxxp://209.85.173.132/search?q=cache:iuzu97wCKqYJ:infomotions.com/etexts/gutenberg/dirs/1/7/3/7/17374/17374.htm+oceanus+reservoir+manhattan&hl=en&ct=clnk&cd=6&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Divas - The Site   Society Divas   Brenda Frazier.URL -> hxxp://72.14.253.104/search?q=cache:HU00ali9JaQJ:www.divasthesite.com/Society_Divas/brenda_frazier_a.htm+%22brenda+frazier%22&hl=en&gl=us&ct=clnk&cd=1
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\EHE Book Reviews.URL -> hxxp://www.ehe.org/display/ehe-bookreviews.cfm?formtype=d1&revid=450
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Frederik van Eeden.URL -> hxxp://66.102.7.104/search?q=cache:xK27jjD1ZnwJ:www.lucidity.com/vanEeden.html+%22van+eeden%22+lucid&hl=en&gl=us&ct=clnk&cd=1
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Full text of  Catalogue of the Illustrations of the Water-supply of the City of New York ... .URL -> hxxp://209.85.173.132/search?q=cache:be888d330RoJ:www.archive.org/stream/catalogueillust00wegmgoog/catalogueillust00wegmgoog_djvu.txt+central+park+gatehouse+%22new+york+city%22+steam&cd=1&hl=en&ct=clnk&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Heart of Hinduism  Maya  Illusion.URL -> hxxp://72.14.203.104/search?q=cache:ZBrnlLWiihwJ:hinduism.iskcon.com/concepts/105.htm+hinduism+illusion&hl=en&gl=us&ct=clnk&cd=4
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Image Archive on the American Eugenics Movement.URL -> hxxp://www.dnalc.org/ddnalc/websites/eugenics.html
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\ISAR - Barry Mehler,  Eliminating the Inferior  American and [bleep] Sterilization.URL -> hxxp://66.102.7.104/search?q=cache:uJbRGHl5gQcJ:www.ferris.edu/isar/archives/mehler/eliminating.htm+%22irving+fisher%22+eugenics&hl=en&gl=us&ct=clnk&cd=10
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Lisa's Nostalgia Cafe--The 30's  The Great Depression.URL -> hxxp://72.14.253.104/search?q=cache:WYxJ7u0TxQMJ:www.angelfire.com/retro/lisawebworld/depression.html+%22red+cross%22+depression+%22soup+kitchen%22&hl=en&gl=us&ct=clnk&cd=4
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Murder or Suicide  How You (and Your Detective) Can Tell the Difference.URL -> hxxp://72.14.253.104/search?q=cache:zpMBoD7Gav0J:www.writing-world.com/mystery/suicide.shtml+%22look+like+an+accident%22+murder&hl=en&ct=clnk&cd=1
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Myth, Mind and the Screen ... - Google Book Search.URL -> hxxp://books.google.com/books?id=shsB2nwVPnoC&pg=PA115&lpg=PA115&dq=%22talk+to+her+shadow%22&source=web&ots=bjPAZwxxNJ&sig=65xnxwRbGXrC2Yc36cPprAhtKv4#PPA216,M1
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\New York Underground  Main Menu @ nationalgeographic.com.URL -> hxxp://www.nationalgeographic.com/nyunderground/docs/nymain.html
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\NYC - Central Park  South Gate House on Flickr - Photo Sharing!.URL -> hxxp://www.flickr.com/photos/wallyg/247004963/
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\P. Scott Cummins = The Urbane R  Weekly's Rick Anderson  Scandal Nothing New for Alonzo Plough.URL -> hxxp://72.14.207.104/search?q=cache:bB95rururscJ:www.pscottcummins.com/blog/2005/04/weeklys-rick-anderson-scandal-nothing.html+%22medical+examiner%22+misplaced&hl=en&gl=us&ct=clnk&cd=5&client=firefox-a
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\PAW May 11, 2005  Features.URL -> hxxp://www.princeton.edu/~paw/archive_new/PAW04-05/14-0511/features1.html
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Police Psychology.URL -> hxxp://72.14.203.104/search?q=cache:WG72A7Rg6RsJ:faculty.ncwc.edu/toconnor/psy/psylect03.htm+%22police+psychologist%22&hl=en&gl=us&ct=clnk&cd=1
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Principles of Genetics.URL -> hxxp://personal.uncc.edu/jmarks/eugenics/Sinnott.html
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\PubMed Central, Figure  BMJ. 1999 August 14; 319(7207)  435–438.URL -> hxxp://www.pubmedcentral.nih.gov/articlerender.fcgi?artid=1127045&rendertype=figure&id=FN0x97803d0.0x99a4778
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\pulptitles.URL -> hxxp://209.85.173.132/search?q=cache:CoZWiT9VUe8J:onlinebooks.library.upenn.edu/cce/firstperiod.html+%22strange+detective%22+%22public+domain%22&cd=14&hl=en&ct=clnk&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\pump room 2.URL -> hxxp://209.85.173.132/search?q=cache:VMQt4xemytYJ:www.cooperator.com/articles/1364/1/Bringing-Water-to-the-Masses/Page1.html+%22central+park%22+reservoir+%22pump+room%22&hl=en&ct=clnk&cd=1&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\pump room.URL -> hxxp://209.85.173.132/search?q=cache:QuQF9AVA_E0J:newyork.construction.com/projects/05_BestOf/columbusCircle.asp+%22pump+room%22+%22central+park%22&hl=en&ct=clnk&cd=14&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Ridgewood Reservoir - Wikipedia, the free encyclopedia.URL -> hxxp://209.85.173.132/search?q=cache:DvadF9Yvr9cJ:en.wikipedia.org/wiki/Ridgewood_Reservoir+%22pumping+station%22+reservoir+croton&hl=en&ct=clnk&cd=1&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Secret US Human Biological Experimentation.URL -> hxxp://72.14.253.104/search?q=cache:mVjG498h-UYJ:www.apfn.org/apfn/experiment.htm+experiments+illegal+human&hl=en&gl=us&ct=clnk&cd=1
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Some Approaches to Appreciating the Import of Eugenics for American Public Life in the 1920s.URL -> hxxp://72.14.253.104/search?q=cache:5oD5gLpmK68J:www.assumption.edu/ahc/1920s/Eugenics/default.html+eugenics+%22state+fair%22&hl=en&ct=clnk&cd=3&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Streetscapes  The Croton Gatehouse; Worthy Interests Clash on 113th St. - The New York Times.URL -> hxxp://query.nytimes.com/gst/fullpage.html?res=9C0CE5D81138F936A15752C1A966958260
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Taphophilia (dot) Com - Corpse vanishes from county morgue.URL -> hxxp://72.14.207.104/search?q=cache:icAB7CwYpMAJ:www.taphophilia.com/modules.php%3Fname%3DNews%26file%3Dprint%26sid%3D1979+%22missing+body%22+morgue&hl=en&gl=us&ct=clnk&cd=3&client=firefox-a
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Tate Collection   Portrait Study  Five Figures by Thomas Hennell.URL -> hxxp://www.tate.org.uk/servlet/ViewWork?cgroupid=999999961&workid=5960&searchid=8498&tabview=image
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\The Bugs Bunny Road Runner song.URL -> hxxp://looney.goldenagecartoons.com/tv/bbrr/
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\The Individuation Process.URL -> hxxp://www.soul-guidance.com/houseofthesun/individuationprocess.htm
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\The Leuchter Report -- Use of HCN and Zyklon B as a Fumigant.URL -> hxxp://72.14.253.104/search?q=cache:0MgVvUt0oC4J:www.ihr.org/books/leuchter/fumigant.html+%22sulfuric+acid%22+zyklon&hl=en&ct=clnk&cd=1&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\The Pharmaceutical Industry History.URL -> hxxp://www.bioanalytical.com/info/calendar/99/index.htm
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\The Yellow Wallpaper - Wikipedia, the free encyclopedia.URL -> hxxp://en.wikipedia.org/wiki/The_Yellow_Wallpaper
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Untitled.URL -> hxxp://209.85.173.132/search?q=cache:MWnJl6lIdMIJ:www.mcgill.ca/files/tcpsych/Report4.pdf+%22inside+his+head%22+%22let+it+out%22+schizophrenia&hl=en&ct=clnk&cd=6&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Vermont Eugenics  A Documentaty History.URL -> hxxp://www.uvm.edu/~eugenics/vtsurvey.html
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\VERYIMPORTANTARTICLE.URL -> hxxp://www.eugenicsarchive.org/html/eugenics/index2.html?tag=627
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Zyklon B Poison Gas - Degesch REPLICA.URL -> hxxp://72.14.253.104/search?q=cache:rs5Ew1ajokcJ:www.usmbooks.com/zyklon_b.html+%22zyklon+b%22+label&hl=en&ct=clnk&cd=6&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Zyklon B, Auschwitz, and Bruno Tesch (From Firefox).URL -> hxxp://www.ihr.org/jhr/v04/v04p261_Lindsey.html#note11
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Zyklon B, Auschwitz, and Bruno Tesch.URL -> hxxp://72.14.253.104/search?q=cache:wNu2Od_ZD_QJ:www.ihr.org/jhr/v04/v04p261_Lindsey.html+zyklon+vaporize&hl=en&ct=clnk&cd=3&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\A SHORT HISTORY OF US GOVERNMENT RESPECT FOR HUMAN LIFE.URL -> hxxp://72.14.203.104/search?q=cache:bNcstnphf6YJ:www.whatreallyhappened.com/biowar.html+elgin+mental+radium&hl=en&gl=us&ct=clnk&cd=15
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\Amazon.com  Body Snatching  The Robbing of Graves for the Education of Physicians in Early Nineteenth Century America  Books  Suzanne M. Shultz.URL -> hxxp://www.amazon.com/gp/product/0786422327/qid=1152430859/sr=2-1/ref=pd_bbs_b_2_1/103-7711040-4508668?s=books&v=glance&n=283155
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\Amazon.com  Gracefully Insane  The Rise and Fall of America's Premier Mental Hospital  Books  Alex Beam.URL -> hxxp://72.14.203.104/search?q=cache:v17Zx5Yb0ucJ:www.amazon.com/exec/obidos/tg/detail/-/1891620754%3Fv%3Dglance+lobotomy+hydrotherapy+insulin&hl=en&gl=us&ct=clnk&cd=14
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\Amazon.com  Out of It  Books  Anonymous.URL -> hxxp://www.amazon.com/gp/product/B0009V6DOC/ref=ed_oe_d/103-7711040-4508668?%5Fencoding=UTF8&v=glance&n=551440
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\Background Regarding Gifts to Emergency Physicians from the Biomedical Industry.URL -> hxxp://72.14.203.104/search?q=cache:gRUBJjXt5JsJ:www.acep.org/webportal/PracticeResources/issues/medleg/ethics/giftsfrombiomed.htm+%22biomedical+corporations%22&hl=en&gl=us&ct=clnk&cd=12
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\Bristol-Myers Squibb - About Us - Our Company - Our History.URL -> hxxp://www.bms.com/aboutbms/content/data/ourhis.html
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\Early Years - Our History.URL -> hxxp://www.jnj.com/our_company/history/history_section_1.htm
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\EH.Net Encyclopedia  Health Insurance in the United States.URL -> hxxp://eh.net/encyclopedia/article/thomasson.insurance.health.us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\History of Merck.URL -> hxxp://www.msd.com.hk/about_us/e_history_of_merck.html
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\History.URL -> hxxp://www.abbott.com/global/url/content/en_US/10.30:30/general_content/General_Content_00069.htm
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\Hoffmann-La Roche - Wikipedia, the free encyclopedia.URL -> hxxp://en.wikipedia.org/wiki/Hoffmann-La_Roche
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\How Drug Company Money Has Corrupted Psychiatry.URL -> hxxp://66.102.7.104/search?q=cache:oWWar67hdh8J:www.ritalindeath.com/Corruption.htm+%22drug+companies%22+corruption&hl=en&gl=us&ct=clnk&cd=3
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\Idaho Observer  The American Red Double-Cross.URL -> hxxp://66.102.7.104/search?q=cache:j1It7tTlCMAJ:proliberty.com/observer/20011020.htm+rockefeller+%22American+Medical+Association%22&hl=en&gl=us&ct=clnk&cd=2
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\Mad in America  Bad Science and Bad Medicine TERRY MESSMAN   Street Spirit (San Francisco) Jun03.URL -> hxxp://72.14.203.104/search?q=cache:aX_EOufC8MYJ:www.mindfully.org/Health/2003/Mad-In-AmericaJun03.htm+%22rockefeller+institute+for+medical+research%22+walter+freeman&hl=en&gl=us&ct=clnk&cd=10
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\Miller Guide to Flexner Papers.URL -> hxxp://72.14.203.104/search?q=cache:gDr1SCnj4v0J:www.amphilsoc.org/library/guides/flexner/flextext.htm+rockefeller+%22American+Medical+Association%22&hl=en&gl=us&ct=clnk&cd=22
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\Mrs. Brown's Sad Story  A History of the Food, Drug and Cosmetic Act.URL -> hxxp://72.14.203.104/search?q=cache:duEqmlUwoiIJ:www.ahsc.arizona.edu/uac/notes/classes/Alternmethod/Fdapap03.htm+%22elixir+of+sulfanilamide%22&hl=en&gl=us&ct=clnk&cd=7
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\OCRegister.com.URL -> hxxp://www.ocregister.com/features/body/day3_human.shtml
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\Overview of Mental Health in New York and the Nation.URL -> hxxp://72.14.203.104/search?q=cache:j6CCAg-Kw38J:www.archives.nysed.gov/a/researchroom/rr_health_mh_timeline.shtml+%22department+of+mental+hygiene%22+%22new+york%22&hl=en&gl=us&ct=clnk&cd=5
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\Pfizer   Exploring Our History   1900 - 1950.URL -> hxxp://www.pfizer.com/pfizer/history/1900_1950.jsp
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\Probe V7N3  Mind Control Part I  Canadian and U.S. Survivors Seek Justice.URL -> hxxp://72.14.203.104/search?q=cache:H5PtSqRY3XoJ:myweb.cableone.net/mtilton/tyner.htm+%22pharmaceutical+companies%22+%22department+of+mental+hygiene%22&hl=en&gl=us&ct=clnk&cd=26
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\Psychiatric Times.URL -> hxxp://64.233.187.104/search?q=cache:OglFxoov0SsJ:www.psychiatrictimes.com/p020928.html+autism+%22catatonic+schizophrenia%22&hl=en&gl=us&ct=clnk&cd=10
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\Research Papers - New York  The Biotechnology State.URL -> hxxp://72.14.203.104/search?q=cache:vueHESeAPGsJ:www.nystar.state.ny.us/pa/papers01.htm+%22pharmaceutical+companies%22+%22new+york%22+history&hl=en&gl=us&ct=clnk&cd=8
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\Sandoz - Wikipedia, the free encyclopedia.URL -> hxxp://en.wikipedia.org/wiki/Sandoz_Laboratories
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\The American Medical Association - A Sordid History. In 1998 there were 70,000 hospital visit deaths vs 40,000 auto accidents deaths.URL -> hxxp://66.102.7.104/search?q=cache:BtD6YyejYPAJ:www.healthe-livingnews.com/articles/american_medical_association_sorbid_history.html+rockefeller+%22American+Medical+Association%22&hl=en&gl=us&ct=clnk&cd=4
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\The Door in the Wall.URL -> hxxp://72.14.203.104/search?q=cache:SFUKlKzlPeEJ:www.psychedelic-library.org/stevens1.htm+%22the+witnesses%22+hennell&hl=en&gl=us&ct=clnk&cd=13
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\The New York Psychoanalytic Society & Institute.URL -> hxxp://www.psychoanalysis.org/about-history.html
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\The Pharmaceutical Century - 1920 to 1930.URL -> hxxp://pubs.acs.org/journals/pharmcent/Ch2.html
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\The Seattle Times  Nation & World  Illegal profits drive trade in body parts.URL -> hxxp://72.14.203.104/search?q=cache:h5-AnDLQKmYJ:seattletimes.nwsource.com/html/nationworld/2001874083_parts08.html+%22willed+body+programs%22+pharmaceutical&hl=en&gl=us&ct=clnk&cd=10
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\schizophrenia\TIME Magazine Archive Article -- Madmen's Manager -- Dec. 16, 1935.URL -> hxxp://time-proxy.yaga.com/time/archive/preview/0,10987,755461,00.html
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\A Strategic Plan for Documenting Mental Health in New York State - Executive Summary.URL -> hxxp://72.14.203.104/search?q=cache:wYe55o4sMPgJ:www.archives.nysed.gov/a/researchroom/rr_health_mh_recguide.shtml+%22rockefeller+institute+for+medical+research%22+%22mental+health%22&hl=en&gl=us&ct=clnk&cd=12
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\All In The Mind - 30 December 2006 - Epilepsy  taming seizures and dispelling myths.URL -> hxxp://72.14.253.104/search?q=cache:p1-DjXBJduoJ:www.abc.net.au/rn/allinthemind/stories/2006/1807543.htm+epilepsy+aura&hl=en&gl=us&ct=clnk&cd=85
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\Brief History of the Lobotomy.URL -> hxxp://66.102.7.104/search?q=cache:XwCRd4t_KVsJ:www.u.arizona.edu/~rmertens/Psych381/lobotomy/lobotomy.htm+lobotomy+effects&hl=en&gl=us&ct=clnk&cd=1
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\Drug Treatment in Modern Psychiatry .URL -> hxxp://72.14.203.104/search?q=cache:3iIFAL5e2sgJ:www.critpsynet.freeuk.com/Moncrieff.htm+hydrotherapy+schizophrenia&hl=en&gl=us&ct=clnk&cd=15
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\Epilepsy.URL -> hxxp://72.14.253.104/search?q=cache:hi0hWeb9_qQJ:www.epilepsy.dk/Handbook/Mental-complications-uk.asp+%22temporal+lobe+epilepsy%22+schizophrenia&hl=en&ct=clnk&cd=4&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\Health Matters  Schizophrenia.URL -> hxxp://video.google.com/videoplay?docid=8625196662971824778
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\Health Matters  The Genetics of Schizophrenia and other Human Disorders.URL -> hxxp://video.google.com/videoplay?docid=-6192744428741398976&pl=true
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\Hypnagogic Hallucinations.URL -> hxxp://66.102.7.104/search?q=cache:OtVUmlVmQdAJ:www.expage.com/page/hypna+hypnagogic+hallucinations&hl=en&gl=us&ct=clnk&cd=1
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\Living With Epilepsy - Adult Issues   my.epilepsy.com.URL -> hxxp://my.epilepsy.com/?q=forum/117&from=25
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\Lucid Dream Camp Diary.URL -> hxxp://www.lucidity.com/NL7.34.LDcampDiary.html
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\Lucid Dreaming Frequently Asked Questions Answered by The Lucidity Institute.URL -> hxxp://www.lucidity.com/LucidDreamingFAQ2.html#LD
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\neurotheology article.URL -> hxxp://72.14.253.104/search?q=cache:mSTfz-oCOq8J:www.cognitiveliberty.org/neuro/neuronewswk.htm+epilepsy+mystic&hl=en&gl=us&ct=clnk&cd=2
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\NLP, Hypnosis, Hypnotherapy, Counselling in Chichester, West Sussex, UK.URL -> hxxp://66.102.7.104/search?q=cache:6X_44pIUhyAJ:www.23nlpeople.com/schizophrenia_catatonic.html+%22catatonic+schizophrenia%22&hl=en&gl=us&ct=clnk&cd=3
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\P&S Med Rev Vol. 8, No.URL -> hxxp://72.14.253.104/search?q=cache:jTJYzVVFucoJ:www.cumc.columbia.edu/news/review/pdf/f19_Rutherford.pdf+epilepsy+aura+possession&hl=en&gl=us&ct=clnk&cd=5
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\Police PTSD.URL -> hxxp://www.geocities.com/stressline_com/ptsd-family.html
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\Police Stress - line.URL -> hxxp://members.tripod.com/CranberryBogShrink/index.html
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\Police Stress, Marriage and Divorce.URL -> hxxp://72.14.203.104/search?q=cache:Sml9A8hDI5gJ:divorcesupport.about.com/cs/avoidingdivorce/a/policestress.htm+police+stress+marriage&hl=en&gl=us&ct=clnk&cd=1
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\Post Traumatic Stress Disorder.URL -> hxxp://66.102.7.104/search?q=cache:ATMeVqh2Mh0J:www.halexandria.org/dward082.htm+%22post+traumatic+stress%22+dreaming&hl=en&gl=us&ct=clnk&cd=11
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\Sudden Emergence of Visual Creativity in Patients With Frontotemporal Dementia.URL -> hxxp://72.14.253.104/search?q=cache:eNcmcbRgmLYJ:www.neuropsychiatryreviews.com/jun03/jun03_frontotemporal.html+%22temporal+lobe%22+imagination&hl=en&gl=us&ct=clnk&cd=8
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\Temporal Lobe Epilepsy, 1948-1986  A ... - Google Book Search.URL -> hxxp://books.google.com/books?id=hLOOuPAjreYC&pg=PA40&lpg=PA40&dq=%22temporal+lobe+epilepsy%22+murder&source=web&ots=WJH6MZkbNt&sig=N9SLHBsVjpmOe5VAoT-oti3PQ2A#PPA35,M1
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\The Third Eye and the Pineal Gland.URL -> hxxp://72.14.253.104/search?q=cache:6_oRFlvRN20J:www.strayreality.com/Lanis_Strayreality/thirdtyepinealgland.htm+%22pineal+gland%22&hl=en&ct=clnk&cd=5&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\van Eeden.URL -> hxxp://66.102.7.104/search?q=cache:dUVwbvoz6fsJ:members.shaw.ca/jgfriesen/Notes/VanEeden.html+%22frederik+van+eeden%22&hl=en&gl=us&ct=clnk&cd=2
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Neuroscience & Psychology\Wired 7.11  This Is Your Brain on God.URL -> hxxp://www.wired.com/wired/archive/7.11/persinger.html?pg=1&topic=&topic_set=
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Mental Hospitals\A Day in a Mental Hospital, a Dream of Life Outside - New York Times.URL -> hxxp://query.nytimes.com/gst/fullpage.html?sec=health&res=940DEED91330F934A35752C1A96E948260
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Mental Hospitals\Danvers State Hospital History - Abandoned Photography   opacity.us.URL -> hxxp://64.233.167.104/search?q=cache:n3xmbcKUvEkJ:www.opacity.us/site22_danvers_state_hospital.htm+%22danvers+state%22&hl=en&gl=us&ct=clnk&cd=3
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Mental Hospitals\Danvers State Insane Asylum.URL -> hxxp://www.danversstateinsaneasylum.com/home.html
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Mental Hospitals\Escape From the Cuckoo's Nest - Human Rights Magazine Fall 1996.URL -> hxxp://72.14.203.104/search?q=cache:Bkba2cop2IEJ:www.abanet.org/irr/hr/fall96/escape.html+%22new+york+state+mental+institutions%22&hl=en&gl=us&ct=clnk&cd=5
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Mental Hospitals\Haunted Salem - The lore, and lure, of Danvers State Hospital.URL -> hxxp://64.233.167.104/search?q=cache:56f-hCFQxYIJ:www.hauntedsalem.com/news/oct03-dh-danversstate.html+%22danvers+state%22&hl=en&gl=us&ct=clnk&cd=6
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Mental Hospitals\Henry Cotton (doctor) - Wikipedia, the free encyclopedia.URL -> hxxp://en.wikipedia.org/wiki/Henry_Cotton_(doctor)
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Mental Hospitals\Historic Asylums of America.URL -> hxxp://www.rootsweb.com/~asylums/index.html#mn
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Mental Hospitals\Human medical experimentation in the United States  The shocking true history of modern medicine and psychiatry (1833-1965).URL -> hxxp://72.14.203.104/search?q=cache:1YQ_L5J-oAYJ:www.newstarget.com/019189.html+%22human+guinea+pigs%22+pharmaceutical&hl=en&gl=us&ct=clnk&cd=59
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Mental Hospitals\Locations - Abandoned Photography and Urban Exploration   opacity.us.URL -> hxxp://www.opacity.us/locations/#site22
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Mental Hospitals\New York Mental Health Documentation Project.URL -> hxxp://66.102.7.104/search?q=cache:AScmI9NWlCQJ:www.archives.nysed.gov/a/researchroom/rr_health_mh_hist.shtml+%22new+york+state+mental+hygiene+law%22&hl=en&gl=us&ct=clnk&cd=1
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Mental Hospitals\opacity.us - Abandoned Photography and Urban Exploration.URL -> hxxp://www.opacity.us/
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Mental Hospitals\totse.com   Private Psychiatric Hospitals (the U.S. Health car.URL -> hxxp://72.14.203.104/search?q=cache:ISeakyHQLIUJ:www.totse.com/en/bad_ideas/scams_and_rip_offs/privpsyc.html+%22national+medical+enterprises%22&hl=en&gl=us&ct=clnk&cd=26
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Mental Hospitals\Welcome to Cambridge Mental Hospital.URL -> hxxp://72.14.253.104/search?q=cache:814nm7Jtaa0J:www.cambridgementalhospital.com/history.html+%22mental+hospital%22+epilepsy&hl=en&gl=us&ct=clnk&cd=13
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\490205.pdf (application pdf Object).URL -> hxxp://www.aps-pub.com/proceedings/1492/490205.pdf
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\American Eugenics Society Records , American Philosophical Society.URL -> hxxp://72.14.253.104/search?q=cache:81oFlXC3K3sJ:www.amphilsoc.org/library/mole/a/aes.htm+eugenics+%22state+fair%22&hl=en&ct=clnk&cd=19&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\American Eugenics Society Scrapbook.URL -> hxxp://www.amphilsoc.org/library/exhibits/treasures/aes.htm
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\BETTER MAP OF EUGENICS LEGISLATION.URL -> hxxp://people.clarkson.edu/~sheilafw/classes/hp201/grayscience/images/States%20with%20eugenics%20laws.jpg
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\David Morgan, Yale Study  U.S. Eugenics Paralleled [bleep] Germany.URL -> hxxp://www.hartford-hwp.com/archives/45/302.html
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\Dysgenics - Wikipedia, the free encyclopedia.URL -> hxxp://72.14.253.104/search?q=cache:I8zMuXzFToMJ:en.wikipedia.org/wiki/Dysgenic+dysgenic&hl=en&ct=clnk&cd=1&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\Eugenic Archives  American Eugenics Society, invitation to  Conference on the Relation of Eugenics and the Church,  including Albert Wiggam, New York.URL -> hxxp://72.14.253.104/search?q=cache:oZpDf1xRTAoJ:www.eugenicsarchive.org/html/eugenics/static/images/1686.html+%22eugenics+society%22+%22card%22&hl=en&ct=clnk&cd=1&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\Eugenic Archives  Eugenics Record Office, about 1925.URL -> hxxp://www.eugenicsarchive.org/html/eugenics/static/images/1651.html
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\Eugenic Archives  Stewart House, an existing Victorian structure that housed the Eugenics Record Office (ERO) 1910-1913 while new building was constructed next door.URL -> hxxp://www.eugenicsarchive.org/html/eugenics/static/images/1650.html
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\Eugenical News - Google Book Search.URL -> hxxp://books.google.com/books?hl=en&id=9yQLAAAAYAAJ&dq=eugenics+society+%22eugenics+record+office%22&printsec=frontcover&source=web&ots=uBIfTbKeTo&sig=tun6gdFbJkuh-RESpAdYWa1WMMg&sa=X&oi=book_result&resnum=1&ct=result#PPA4,M1
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\Eugenics  individual report .URL -> hxxp://eugenicsarchive.bii.a-star.edu.sg/html/eugenics/view_image.html?1691
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\Eugenics  Three Generations, No Imbeciles  Virginia, Eugenics & Buck v. Bell.URL -> hxxp://www.hsl.virginia.edu/historical/eugenics/index.cfm
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\Eugenics and Sterilization in California, 1909-1945.URL -> hxxp://66.102.7.104/search?q=cache:l6e1hby5i_QJ:www.gottshall.com/thesis/article.htm+sterilization+eugenics&hl=en&gl=us&ct=clnk&cd=3
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\Eugenics Archive  American Eugenics Society, program for  Round Table Conferences and Annual Meeting,  New York, 1936.URL -> hxxp://72.14.253.104/search?q=cache:ic4vuv2DQUIJ:www.eugenicsarchive.org/eugenics/image_header.pl%3Fid%3D1684%26detailed%3D0+%22eugenics+society%22+%22card%22&hl=en&ct=clnk&cd=2&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\eugenics handbook.URL -> hxxp://www.eugenicsarchive.org/eugenics/view_image.pl?id=1702
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\Eugenics Record Office Records , American Philosophical Society.URL -> hxxp://www.amphilsoc.org/library/mole/e/ero.htm#series1
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\Eugenics Watch.URL -> hxxp://www.eugenics-watch.com/
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\eugenics-01.jpg (JPEG Image, 139x211 pixels).URL -> hxxp://www.stanford.edu/~wine/202/eugenics-01.jpg
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\EugenicsArchive.URL -> hxxp://72.14.253.104/search?q=cache:T0bttfq6NBUJ:www.eugenicsarchive.org/html/eugenics/static/themes/8.html+%22fitter+family%22+fair&hl=en&ct=clnk&cd=1&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\Evangelical Engagements With Eugenics, 1900-1940 - Ethics & Medicine.URL -> hxxp://72.14.203.104/search?q=cache:CKwMJufXC9YJ:www.ethicsandmedicine.com/18/2/18-2-durst.htm+kellogg+eugenics&hl=en&gl=us&ct=clnk&cd=14
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\Fitter Family Introduction.URL -> hxxp://www1.umn.edu/scitech/assign/fitter/fitterintro.htm
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\fitter family report card.URL -> hxxp://eugenicsarchive.bii.a-star.edu.sg/eugenics/view_image.pl?id=168
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\Francis Galton and the Eugenics Society.URL -> hxxp://www.eugenics-watch.com/roots/chap02.html
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\Funding the Eugenics Movement.URL -> hxxp://72.14.203.104/search?q=cache:nrLbeLO41qAJ:www.eugenics-watch.com/roots/chap12.html+kellogg+eugenics&hl=en&gl=us&ct=clnk&cd=8
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\Irving Fisher  Origins of Modern Central Bank Policy - Economic Insights, vol. 10, no. 1 - Dallas Fed.URL -> hxxp://66.102.7.104/search?q=cache:KxvPnqN0GxsJ:www.dallasfed.org/research/ei/ei0501.pdf+%22irving+fisher%22+%22my+father%22&hl=en&gl=us&ct=clnk&cd=4
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\Irving Fisher - Wikipedia, the free encyclopedia.URL -> hxxp://en.wikipedia.org/wiki/Irving_Fisher
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\Julian Huxley - Wikipedia, the free encyclopedia.URL -> hxxp://en.wikipedia.org/wiki/Julian_Huxley
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\MAP OF EUGENIC LEGISLATION.URL -> hxxp://www.eugenicsarchive.org/html/eugenics/essay_8_fs.html
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\Origins of Eugenics.URL -> hxxp://www.hsl.virginia.edu/historical/eugenics/2-origins.cfm
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\PopularEugenics.pdf (application pdf Object).URL -> hxxp://www.yale.edu/agrarianstudies/papers/PopularEugenics.pdf
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\The eugenics movement.URL -> hxxp://72.14.253.104/search?q=cache:-6J62YpHClgJ:www.uncc.edu/jmarks/eugenics/eugenics.html+eugenics+breeding&hl=en&ct=clnk&cd=1&gl=us
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\War Against The Weak  Eugenics And America's ... - Google Book Search.URL -> hxxp://books.google.com/books?id=qYHscsPFF-wC&pg=PA97&lpg=PA97&dq=%22eugenic+evaluation%22&source=web&ots=aazNhzEnU3&sig=eIFdgkoh2CqdUyE--_bsYpbkOTo#PPA186,M1
InternetURL: C:\Users\Wayne\Favorites\Eugenics Research\Eugenics\What is Eugenics   Eugenics Project  A Documentary History, UVM.URL -> hxxp://64.233.167.104/search?q=cache:Ta9qle8sOh0J:www.uvm.edu/~eugenics/officef.html+sterilization+eugenics+%22new+york%22&hl=en&ct=clnk&cd=2&gl=us
InternetURL: C:\Users\Wayne\Favorites\computertech\3DGPU.com » GeForce 6800 Tweak Guide.URL -> hxxp://72.14.203.104/search?q=cache:zORZ3_oG0owJ:3dgpu.com/archives/2004/08/09/geforce-6800-tweak-guide/+%22detect+optimal+frequencies%22&hl=en&gl=us&ct=clnk&cd=12&client=firefox-a
InternetURL: C:\Users\Wayne\Favorites\computertech\AMD Processor Support Forum -  Guide to Overclocking Your NVIDIA GPU.URL -> hxxp://72.14.207.104/search?q=cache:zDOgLGWk2e4J:forums.amd.com/index.php%3Fshowtopic%3D12551%26view%3Dgetlastpost+%22detect+optimal+settings%22+nvidia&hl=en&gl=us&ct=clnk&cd=9&client=firefox-a
InternetURL: C:\Users\Wayne\Favorites\computertech\AnandTech - 7900GT  Unlocking the Beast Within.URL -> hxxp://forums.anandtech.com/messageview.aspx?catid=31&threadid=1833642&frmKeyword=&STARTPAGE=12&FTVAR_FORUMVIEWTMP=Linear
InternetURL: C:\Users\Wayne\Favorites\computertech\Arctic Cooling NV Silencer 5 AVC-NV5R3 (Rev. 3) nVidia GeForce 6800 7800 GT Ultra AGP PCI-X High Performance VGA Cooler    VGA & Chipset Coolers    Cooling Devices    CensusPC.URL -> hxxp://www.censuspc.com/product.php?productid=2879
InternetURL: C:\Users\Wayne\Favorites\computertech\Audigy SE working Multichannel in Vista! - Windows Vista - Creative Labs.URL -> hxxp://forums.creative.com/creativelabs/board/message?board.id=Vista&message.id=589
InternetURL: C:\Users\Wayne\Favorites\computertech\ChiefValue.com - Digital Camera, Computer parts, PDA, Notebook, GPS, MP3, Player and Printers.URL -> hxxp://www.chiefvalue.com/product/productdetails.aspx?linkid=111&item=35-126-051
InternetURL: C:\Users\Wayne\Favorites\computertech\Creative Crap - Audio - PC Hardware.URL -> hxxp://64.233.167.104/search?q=cache:PxCxi_MZjtEJ:forums.whirlpool.net.au/forum-replies-archive.cfm/803160.html+auzentech+omega+%22pass+through%22&hl=en&ct=clnk&cd=1&gl=us
InternetURL: C:\Users\Wayne\Favorites\computertech\EVGA   Community.URL -> hxxp://www.evga.com/community/messageboard/topic.asp?TOPIC_ID=10946&SearchTerms=silencer
InternetURL: C:\Users\Wayne\Favorites\computertech\EVGA   Message Boards (From Firefox).URL -> hxxp://www.evga.com/community/messageboard/topic.asp?TOPIC_ID=14021
InternetURL: C:\Users\Wayne\Favorites\computertech\EVGA   Message Boards.URL -> hxxp://www.evga.com/community/messageboard/topic.asp?TOPIC_ID=13979
InternetURL: C:\Users\Wayne\Favorites\computertech\EVGA   Products.URL -> hxxp://www.evga.com/products/prodlist.asp?family=GeForce+7+Series+Family
InternetURL: C:\Users\Wayne\Favorites\computertech\EXTREME Overclocking Forums - Tweaking PC Hardware To The Max.URL -> hxxp://forums.extremeoverclocking.com/
InternetURL: C:\Users\Wayne\Favorites\computertech\Guide to Air Cooling v0.1 (inside - maybe no 56k) - Overclock.net - Overclocking.net.URL -> hxxp://www.overclock.net/other-cooling-discussions/63277-guide-air-cooling-v0-1-inside.html
InternetURL: C:\Users\Wayne\Favorites\computertech\How to enable Creative Software in Vista with SBLive 5.1 Digital - Windows Vista - Creative Labs.URL -> hxxp://forums.creative.com/creativelabs/board/message?board.id=Vista&message.id=7648
InternetURL: C:\Users\Wayne\Favorites\computertech\How to get 7.1 audio EAX fully functional on Vistax64 and Audigy 2 - Windows Vista - Creative Labs.URL -> hxxp://forums.creative.com/creativelabs/board/message?board.id=Vista&message.id=427
InternetURL: C:\Users\Wayne\Favorites\computertech\IGN  Half-Life 2 Optimization Guide.URL -> hxxp://gear.ign.com/articles/554/554744p2.html
InternetURL: C:\Users\Wayne\Favorites\computertech\Lenin's Overclocking thread...look here to be overclocked! - Hardware Discussions - FiringSquad Forums (From Firefox).URL -> hxxp://forums.firingsquad.com/firingsquad/board/message?board.id=hardware&message.id=49587&view=by_date_ascending&page=35
InternetURL: C:\Users\Wayne\Favorites\computertech\Lenin's Overclocking thread...look here to be overclocked! - Hardware Discussions - FiringSquad Forums.URL -> hxxp://forums.firingsquad.com/firingsquad/board/message?board.id=hardware&thread.id=49587&view=by_date_ascending&page=38
InternetURL: C:\Users\Wayne\Favorites\computertech\mvktech.net.URL -> hxxp://www.mvktech.net/
InternetURL: C:\Users\Wayne\Favorites\computertech\Noob switching to HD. Wants good DVR and good PQ... help. - AVS Forum.URL -> hxxp://www.avsforum.com/avs-vb/showthread.php?t=666179
InternetURL: C:\Users\Wayne\Favorites\computertech\NVIDIA Forums   Need A Good Respected Driver Cleaner.URL -> hxxp://72.14.203.104/search?q=cache:ZmVwJy6AkjkJ:forums.nvidia.com/lofiversion/index.php%3Ft5793.html+%22driver+cleaner%22&hl=en&gl=us&ct=clnk&cd=18&client=firefox-a
InternetURL: C:\Users\Wayne\Favorites\computertech\Re  Lenin's Overclocking thread...look here to be overclocked! - Hardware Discussions - FiringSquad Forums.URL -> hxxp://forums.firingsquad.com/firingsquad/board/message?board.id=hardware&message.id=61806
InternetURL: C:\Users\Wayne\Favorites\computertech\techPowerUp!    Guide to Video BIOS flashing.URL -> hxxp://www.techpowerup.com/articles//overclocking/vidcard/34/10
InternetURL: C:\Users\Wayne\Favorites\computertech\The Heatsink Guide - All about PC cooling.URL -> hxxp://www.heatsink-guide.com/content.php?content=case.shtml
InternetURL: C:\Users\Wayne\Favorites\computertech\Vista, AC3, S PDIF - gnegg (From Firefox).URL -> hxxp://64.233.167.104/search?q=cache:34MiNxrK8JAJ:www.gnegg.ch/archives/344-Vista,-AC3,-SPDIF.html+spdif+vista&hl=en&ct=clnk&cd=6&gl=us
InternetURL: C:\Users\Wayne\Favorites\computertech\Vista, AC3, S PDIF - gnegg.URL -> hxxp://64.233.167.104/search?q=cache:34MiNxrK8JAJ:www.gnegg.ch/archives/344-Vista,-AC3,-SPDIF.html+vista+spdif&hl=en&ct=clnk&cd=5&gl=us
InternetURL: C:\Users\Wayne\Favorites\computertech\VR-Zone   Technology Beats - 7900GT  Unlocking the Beast Within.URL -> hxxp://www.vr-zone.com/?i=3437&s=3
InternetURL: C:\Users\Wayne\Favorites\computertech\Ziff Davis Web Buyer's Guide  GeForce 7900 Drives Down the Cost of Speed.URL -> hxxp://72.14.203.104/search?q=cache:rQO3IRf54oQJ:www.webbuyersguide.com/sub/infrastructure/reviews/3429-wbginfrastructure_reviews.html+overclock+memory+7900&hl=en&gl=us&ct=clnk&cd=17&client=firefox-a
InternetURL: C:\Users\Wayne\Desktop\unsortedolddesktop8-3-11\APPLY.URL -> hxxp://jobview.monster.com/Apply/Apply.aspx?JobID=99011265
InternetURL: C:\Users\Wayne\Desktop\Desktop\YouTube - Case Mod Computer Modding with Vinyl Film.url -> hxxp://www.youtube.com/watch?v=7aUnaVO8iLs

==================== End of log =============================
 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-03-2015 03
Ran by Wayne at 2015-03-08 14:56:15
Running from C:\Users\Wayne\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: AVG Internet Security 2014 (Enabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Internet Security 2014 (Enabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}
FW: AVG Internet Security 2014 (Enabled) {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

3DVIA player 5.0.0.20 (HKLM-x32\...\{B01DD1A4-F4E1-4CE7-AB6E-3168C5BD5D30}) (Version: 5.0.20 - 3DVIA)
4Videosoft MKV Video Converter (HKLM-x32\...\4Videosoft MKV Video Converter_is1) (Version:  - )
Acrobat.com (HKLM-x32\...\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 2.0.0.0 - Adobe Systems Incorporated)
Acrobat.com (x32 Version: 2.0.0 - Adobe Systems Incorporated) Hidden
Acronis True Image WD Edition (HKLM-x32\...\{9B683A28-2172-4CF1-B85D-41375E80652A}) (Version: 13.0.14157 - Acronis)
Adobe Acrobat 9 Pro Extended - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7761-000000000004}{AC76BA86-1033-F400-7761-000000000004}) (Version: 9.5.5 - Adobe Systems)
Adobe Acrobat 9 Pro Extended 64-bit Add-On (HKLM\...\{AC76BA86-1033-0000-0064-0003D0000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
Adobe Acrobat 9.5.5 - CPSID_83708 (HKLM-x32\...\{AC76BA86-1033-F400-7761-000000000004}_955) (Version:  - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 13.0.0.83 - Adobe Systems Incorporated)
Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Amazon Kindle For PC v1.1 (HKU\S-1-5-21-2408619476-591646424-3276866331-1001\...\Amazon Kindle For PC) (Version:  - Amazon)
Amazon MP3 Downloader 1.0.17 (HKLM-x32\...\Amazon MP3 Downloader) (Version: 1.0.17 - Amazon Services LLC)
AOL Toolbar (HKLM-x32\...\AOL Toolbar) (Version:  - AOL Inc.)
AOL Uninstaller (Choose which Products to Remove) (HKLM-x32\...\AOL Uninstaller) (Version:  - AOL Inc.)
Apple Application Support (HKLM-x32\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AVG 2014 (HKLM\...\AVG) (Version: 2014.0.4800 - AVG Technologies)
AVG 2014 (Version: 14.0.4257 - AVG Technologies) Hidden
AVG 2014 (Version: 14.0.4800 - AVG Technologies) Hidden
AVG PC Tuneup (HKLM-x32\...\{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1) (Version: 10.0.0.27 - AVG)
AVG Web TuneUp (HKLM-x32\...\AVG Web TuneUp) (Version: 4.0.5.7 - AVG Technologies)
AVS Update Manager 1.0 (HKLM-x32\...\AVS Update Manager_is1) (Version:  - Online Media Technologies Ltd.)
AVS Video Converter 6 (HKLM-x32\...\AVS4YOU Video Converter 6_is1) (Version:  - Online Media Technologies Ltd.)
AVS4YOU Software Navigator 1.3 (HKLM-x32\...\AVS4YOU Software Navigator_is1) (Version:  - Online Media Technologies Ltd.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Brother MFL-Pro Suite MFC-8870DW (HKLM-x32\...\{9211CCBB-BEFE-4A0C-9199-D7A535DBFE5F}) (Version: 1.0.0.0 - Brother Industries, Ltd.)
CameraHelperMsi (x32 Version: 13.31.1038.0 - Logitech) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 3.27 - Piriform)
CDisplay 1.8 (HKLM-x32\...\CDisplay_is1) (Version:  - dvd8n)
Citrix Online Launcher (HKLM-x32\...\{AC7E7905-8C59-4806-A96D-30936A2B1FC5}) (Version: 1.0.168 - Citrix)
Creative Audio Control Panel (HKLM-x32\...\AudioCS) (Version: 3.00 - Creative Technology Limited)
CyberLink PowerDirector (HKLM-x32\...\InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}) (Version: 8.0.1930 - CyberLink Corp.)
DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden
DivX Setup (HKLM-x32\...\DivX Setup.divx.com) (Version: 2.5.0.15 - DivX, LLC)
DVDFab 8.2.0.7 (25/08/2012) Qt (HKLM-x32\...\DVDFab 8 Qt_is1) (Version:  - Fengtao Software Inc.)
EMET (HKLM-x32\...\{DE7A5DDF-47B3-42FF-A082-E158DEA37392}) (Version: 3.0.0 - Microsoft)
erLT (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Face Filter (x32 Version: 1.0.007 - Roxio) Hidden
Final Draft (HKLM-x32\...\{7C3C895B-AE02-4F30-8A6A-051D37A38DD0}) (Version: 8.0.3.120 - Final Draft, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 41.0.2272.76 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.9.238 - SurfRight B.V.)
Host OpenAL (HKLM-x32\...\Host OpenAL) (Version: 2.02 - Creative Technology Limited)
IMCapture for Skype (HKLM-x32\...\IMCapture for Skype_is1) (Version:  - IMCapture)
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
iTunes (HKLM\...\{1CF5754A-545B-4360-BFDE-2847BC728DFC}) (Version: 11.2.0.115 - Apple Inc.)
Kies mini (HKLM-x32\...\InstallShield_{EE43894E-FDCF-4A8C-BCD6-3AAA9A48B486}) (Version: 1.00.0000 - Samsung Electronics Co., Ltd.)
Kies mini (x32 Version: 1.00.0000 - Samsung Electronics Co., Ltd.) Hidden
LeapFrog Connect (HKLM-x32\...\UPCShell) (Version: 5.2.4.18506 - LeapFrog)
LeapFrog Connect (x32 Version: 5.2.4.18506 - LeapFrog) Hidden
LeapFrog LeapPad Explorer Plugin (x32 Version: 5.2.1.18456 - LeapFrog) Hidden
Logitech Vid (HKLM-x32\...\{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}) (Version: 1.70.1044 - Logitech Inc.)
Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.0 - Logitech Inc.)
Logitech Webcam Software Driver Package (HKLM\...\lvdrivers_12.10) (Version: 12.10.1110 - Logitech Inc.)
LWS VideoEffects (Version: 13.30.1379.0 - Logitech) Hidden
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Manga Studio EX 4.0 (HKLM-x32\...\Manga Studio EX 4.0) (Version:  - )
MediaImpression (HKLM-x32\...\{CA72A82C-7DBC-4814-8CCB-E5BFAC59FAEF}) (Version:  - )
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Miro (HKLM-x32\...\Miro) (Version: 5.0 - Participatory Culture Foundation)
MKVToolNix 5.7.0 (HKLM-x32\...\MKVToolNix) (Version: 5.7.0 - Moritz Bunkus)
Mozilla Firefox 36.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 36.0.1 (x86 en-US)) (Version: 36.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
Mozy Restore Manager (HKLM-x32\...\{ACBF3584-2D91-4EB1-9EFF-8DCECB2A7A84}) (Version: 2.2.1.564 - Mozy, Inc)
Mozy Sync (HKLM\...\{95DB05B2-371B-3957-A65A-7CD9433701AD}) (Version: 1.3.1.4068 - Mozy, Inc.)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Mumble 1.2.4 (HKLM-x32\...\{E0955568-4353-4C85-8988-285A8C0F5E87}) (Version: 1.2.4 - Thorvald Natvig)
NVIDIA 3D Vision Controller Driver 340.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 340.50 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 340.52 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.1.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.1 - NVIDIA Corporation)
NVIDIA Graphics Driver 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
Overwolf (HKLM-x32\...\{5D30F159-FFB9-458F-8A03-1747DDE499D8}) (Version: 0.45.266 - Overwolf)
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.1 - Pando Networks Inc.)
Parsec (HKU\S-1-5-21-2408619476-591646424-3276866331-1001\...\a53dc3b81e52c50e) (Version: 1.0.0.50 - Parsec)
PdaNet for Android 2.41 (HKLM-x32\...\PdaNet_is1) (Version:  - June Fabrics Technology Inc)
PowerISO (HKLM-x32\...\PowerISO) (Version: 4.6 - PowerISO Computing, Inc.)
Private Internet Access Support Files (HKLM-x32\...\{7D72DAFF-DCB2-437B-BC22-4B2ABF21462B}) (Version: 1.0.0.0 - Private Internet Access)
PVSonyDll (Version: 1.00.0001 - NVIDIA Corporation) Hidden
Python 2.6.5 (HKLM-x32\...\{4723f199-fa64-4233-8e6e-9fccc95a18ee}) (Version: 2.6.5150 - Python Software Foundation)
pyTivo wmcbrine-2009.03.19-RC1 (HKLM\...\pyTivo) (Version: wmcbrine-2009.03.19-RC1 - pyTivo)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Razer Core (HKLM-x32\...\Razer Core) (Version: 1.0.1.17 - Razer Inc)
Razer Synapse 2.0 (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.11.3 - Razer Inc.)
RBVirtualFolder64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6602 - Realtek Semiconductor Corp.)
Replay Media Catcher 4 (HKLM\...\{F0DC0069-4D38-4BF4-B706-AB781D73267D}) (Version: 4.0.10 - Applian Technologies)
Revo Uninstaller 1.94 (HKLM-x32\...\Revo Uninstaller) (Version: 1.94 - VS Revo Group)
Roxio Creator 2012 Pro (HKLM-x32\...\{AAB42DD0-9551-4E30-A3E4-F87D4A4E1C52}) (Version: 13.5 - Roxio)
Roxio System Rollback (Version: 3.9.0 - Roxio) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.3.1800.0 - SAMSUNG Electronics Co., Ltd.)
ScanSoft PaperPort 11 (HKLM-x32\...\{B6C89654-A6A2-477C-873B-724EC1C56407}) (Version: 11.1.0000 - Nuance Communications, Inc.)
SHIELD Streaming (Version: 3.1.100 - NVIDIA Corporation) Hidden
Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 5.6.8442 - Skype Technologies S.A.)
SmartSound Common Data (HKLM-x32\...\InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.)
SmartSound Common Data (x32 Version: 1.1.0 - SmartSound Software Inc.) Hidden
SmartSound Quicktracks 5 (HKLM-x32\...\InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.7 - SmartSound Software Inc.)
SmartSound Quicktracks 5 (x32 Version: 5.1.7 - SmartSound Software Inc.) Hidden
SmartSound Quicktracks Plugin (HKLM-x32\...\InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}) (Version: 3.0.3.0 - SmartSound Software Inc)
SmartSound Quicktracks Plugin (x32 Version: 3.0.3.0 - SmartSound Software Inc) Hidden
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
System Requirements Lab (HKLM-x32\...\SystemRequirementsLab) (Version:  - )
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.13 - TeamSpeak Systems GmbH)
TiVo Desktop 2.8.1 (HKLM-x32\...\{4E839090-3B68-436A-B3CF-A2A08C38DD26}) (Version: 2.8.393.288 - TiVo Inc.)
TORParse (HKLM-x32\...\com.torparse.TorparseApplication) (Version: 1.0.2 - UNKNOWN)
TORParse (x32 Version: 1.0.2 - UNKNOWN) Hidden
Ultra MKV Converter 3.2.0610 (HKLM-x32\...\Ultra MKV Converter_is1) (Version:  - Aone Software)
Uninstall AOL Emergency Connect Utility 1.0 (HKLM-x32\...\AOL Emergency Connect Utility 1.0) (Version:  - )
Unity Web Player (HKU\S-1-5-21-2408619476-591646424-3276866331-1001\...\UnityWebPlayer) (Version: 2.6.1f3_31223 - Unity Technologies ApS)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Use the entry named LeapFrog Connect to uninstall (LeapFrog LeapPad Explorer Plugin) (HKLM-x32\...\LeapPadExplorerPlugin) (Version:  - LeapFrog)
VC80CRTRedist - 8.0.50727.4053 (x32 Version: 1.1.0 - DivX, Inc) Hidden
VD64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden
Ventrilo Client for Windows x64 (HKLM\...\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}) (Version: 3.0.8.0 - Flagship Industries, Inc.)
Viewpoint Media Player (HKLM-x32\...\ViewpointMediaPlayer) (Version:  - )
VisiPics V1.31 (HKLM-x32\...\VisiPics_is1) (Version:  - Ozone)
Visual C++ 8.0 Runtime Setup Package (x64) (HKLM-x32\...\{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}) (Version: 9.0.0.623 - AVG Technologies CZ, s.r.o.)
Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Vuze (HKLM-x32\...\8461-7759-5462-8226) (Version: 5.5.0.0 - Azureus Software, Inc.)
Vuze Remote Toolbar v8.1 (HKLM-x32\...\{E88D354D-7344-4049-A0B7-29E6D418E9D0}) (Version: 8.1 - Spigot, Inc.) <==== ATTENTION
Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net  (09/10/2009 02.03.05.012) (HKLM\...\8F14F2ECEDE68D26EA515B48DC25B39103C4FE8D) (Version: 09/10/2009 02.03.05.012 - Leapfrog)
Windows Mobile Device Center (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation)
WinRAR archiver (HKLM\...\WinRAR archiver) (Version:  - )
WinRAR archiver (HKLM-x32\...\WinRAR archiver) (Version:  - )
WinZip 16.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240C9}) (Version: 16.0.9686 - WinZip Computing, S.L. )

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

04-03-2015 04:00:13 Windows Update
04-03-2015 09:58:16 Checkpoint by HitmanPro
05-03-2015 07:39:27 Checkpoint by HitmanPro
06-03-2015 00:57:22 Installed Mozy Sync
06-03-2015 01:08:54 Installed MozyHome
07-03-2015 08:28:26 Checkpoint by HitmanPro
07-03-2015 18:03:33 Removed MozyHome

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 19:34 - 2015-03-01 09:10 - 00000000 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0C54A3E5-7105-4349-A885-B2446E0B1D2E} - \SPBIW_UpdateTask_Time_343138333235343032342d3437415a556c2a3223346c41 No Task File <==== ATTENTION
Task: {10A0186E-4802-48F6-96CA-F67D53262620} - System32\Tasks\AVG_SYS_TASK_1214avi_DELETE => C:\ProgramData\Avg_Update_1214avi\AVG-Secure-Search-Update_1214avi.exe
Task: {15053C8F-24D7-4BA8-8948-7C57768647B7} - \ShopperProJSUpd No Task File <==== ATTENTION
Task: {190E84CA-281A-46EA-9BC7-4DC9C14AB88D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {256641E3-9A21-4454-B48A-6F44D83F8024} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-01-23] (Piriform Ltd)
Task: {2A3242DF-C703-4A59-8661-E5AA741842A1} - \YTDownloaderUpd No Task File <==== ATTENTION
Task: {313E6FE1-5519-47D0-BD34-8C1701013727} - System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update2 <==== ATTENTION
Task: {387C53C6-8722-4A26-A528-58D404359450} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {3BCAB783-4E9A-4649-8891-50C4E6D22CEC} - \ShopperPro No Task File <==== ATTENTION
Task: {403B006B-1DFA-470D-BCEB-D897D814189B} - System32\Tasks\AVG_SYS_TASK_1214avi => C:\ProgramData\Avg_Update_1214avi\AVG-Secure-Search-Update_1214avi.exe
Task: {58FC3B0A-D828-4CFF-B57C-4DCF2B3F4BA3} - \SPDriver No Task File <==== ATTENTION
Task: {632936F3-34D9-4C5B-89FA-A6EE510BD7A3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.)
Task: {6AF3EBAE-2915-44A9-B1ED-627398322A5A} - System32\Tasks\Open Chrome => Chrome.exe --new-window toolbar.avg.com/ch-uninstall?cid={56EE5C2C-0036-4337-8E70-12AB9817E829}&amp;mid=1d277b5a8918b666f3adf72b1305cbf7-9a17500a96d428a5cdb8b2643968b9a928fc107f&amp;lang=en&amp;ds=AVG&amp;coid=avgtbavg&amp;cmpid=1214avi&amp;pr=fr&amp;d=&amp;v=4.0.5.7&amp;pid=wtu&amp;sg=
Task: {6CA98119-A827-4A6C-9669-3C1813665B01} - \YTDownloader No Task File <==== ATTENTION
Task: {7E0B2791-5AA6-4ABD-80DA-00C352223FB5} - System32\Tasks\BLZYASW => C:\ProgramData\3e2a3a4b2e7d4a2ca793dd4127047b9e\3e2a3a4b2e7d4a2ca793dd4127047b9e.exe
Task: {81095262-EBA7-4757-8356-17C43277649F} - \SMupdate1 No Task File <==== ATTENTION
Task: {9E3461E7-EE85-4727-A53E-C23D8BDEB188} - System32\Tasks\Opera scheduled Autoupdate 1425205012 => C:\Program Files (x86)\Opera\launcher.exe
Task: {A0DCA15B-29DB-4B31-8BD1-49F15EEA7BAC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-05] (Adobe Systems Incorporated)
Task: {A3ED3FD5-8F5C-49F4-8F81-373DCDB5041D} - System32\Tasks\{2E617A3B-FF70-4BAB-A824-23CC84D183AA} => Firefox.exe http://ui.skype.com/...all?page=tsMain
Task: {B11342FB-FBE9-4FC9-8BC1-9460749B4432} - System32\Tasks\{B70A269E-3D27-4C7C-9B98-F35535750DFC} => pcalua.exe -a C:\Users\Wayne\Desktop\pyTivo-wgw-2008.10.15-RC1.exe -d C:\Users\Wayne\Desktop
Task: {B1246E0B-C6E1-4CB8-926F-8445985D6457} - \SMW_UpdateTask_Time_343138333235343032342d3437415a556c2a3223346c41 No Task File <==== ATTENTION
Task: {B3D7FC40-6C48-4B7A-BF94-90993A4C0508} - System32\Tasks\Adobe online update program => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {C08C4ABB-9AA8-4016-ABFA-FD5BBB47671B} - System32\Tasks\Divx online update program => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2011-03-21] ()
Task: {C416A8EB-83A5-45CE-B2A2-F84D58149C4E} - System32\Tasks\Private Internet Access Startup => C:\Program Files\pia_manager\pia_manager.exe [2014-07-28] ()
Task: {D2905D43-B785-4242-9310-90E1C7E67184} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
Task: {D61D10BE-8BA5-4237-8283-37E95617F1A8} - System32\Tasks\{4C3CC11A-DC8F-452E-A6A7-F73882881CC1} => pcalua.exe -a "C:\Users\Wayne\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3NID1Y7M\QuickTimeInstaller[1].exe" -d C:\Users\Wayne\Desktop
Task: {DAC533FC-6E30-4C7C-9F6E-EB04C6406A63} - System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update3 <==== ATTENTION
Task: {E73CF447-0166-449E-A31E-7920B343E654} - \SMWPUpd No Task File <==== ATTENTION
Task: {F1CE9FE0-5310-4646-9B83-B693948C68CA} - System32\Tasks\{BC313DBD-6870-40E1-8117-6488E439AB70} => C:\Program Files (x86)\Skype\Phone\Skype.exe
Task: {FC7B1AC8-2875-420B-B316-8C611E86650D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-21] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Open Chrome.job => c:\program files (x86)\Google\Chrome\Application\chrome.exeí--new-window toolbar.avg.com/

==================== Loaded Modules (whitelisted) ==============

2012-11-18 04:06 - 2014-07-02 11:55 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2010-02-23 20:20 - 2009-12-12 16:12 - 00166400 _____ () C:\Program Files\WinRAR\rarext.dll
2008-05-02 16:59 - 2008-05-02 16:59 - 00077824 _____ () C:\Program Files\pyTivo\pyTivoService.exe
2010-03-19 21:53 - 2010-03-19 21:53 - 00026624 _____ () C:\Python26\python.exe
2014-07-28 15:07 - 2014-07-28 15:07 - 08817890 _____ () C:\Program Files\pia_manager\pia_manager.exe
2010-03-06 13:39 - 2005-04-22 14:36 - 00143360 ____N () C:\Windows\system32\BrSNMP64.dll
2014-07-28 15:07 - 2014-07-28 15:07 - 00184320 _____ () C:\Program Files\pia_manager\pia_tray\pia_tray.exe
2014-10-23 22:01 - 2014-10-23 22:01 - 04567552 _____ () C:\Program Files (x86)\Mozy\Mozy Restore Manager\MozyRestoreManager.exe
2014-07-28 15:07 - 2014-07-28 15:07 - 00690176 _____ () C:\Program Files\pia_manager\openvpn.exe
2014-07-28 15:07 - 2014-07-28 15:07 - 00190317 _____ () C:\Program Files\pia_manager\liblzo2-2.dll
2014-07-28 15:07 - 2014-07-28 15:07 - 00108441 _____ () C:\Program Files\pia_manager\libpkcs11-helper-1.dll
2014-04-23 16:05 - 2014-04-23 16:05 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-04-23 16:04 - 2014-04-23 16:04 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2010-03-19 21:53 - 2010-03-19 21:53 - 00040448 _____ () C:\Python26\DLLs\_socket.pyd
2010-03-19 21:54 - 2010-03-19 21:54 - 00665600 _____ () C:\Python26\DLLs\_ssl.pyd
2010-03-19 21:53 - 2010-03-19 21:53 - 00011776 _____ () C:\Python26\DLLs\select.pyd
2010-03-19 21:56 - 2010-03-19 21:56 - 00286208 _____ () C:\Python26\DLLs\_hashlib.pyd
2015-03-07 12:25 - 2015-03-07 12:25 - 00012800 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1F3B.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00009728 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1F3B.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00014848 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1F3B.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00094208 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1F3B.tmp\src\rgloader\rgloader193.mswin.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00009216 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1F3B.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00094208 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1F3B.tmp\lib\ruby\site_ruby\1.9.1\rgloader\rgloader193.mswin.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00126976 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1F3B.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00087552 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1F3B.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00016384 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1F3B.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00127316 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1F3B.tmp\bin\libffi-6.dll
2015-03-07 12:25 - 2015-03-07 12:25 - 00008704 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1F3B.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16le.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00013312 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1F3B.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\utf_16_32.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00095744 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1F3B.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\single_byte.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00026624 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1F3B.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19\win32\api.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00012800 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00009728 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00014848 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00094208 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\src\rgloader\rgloader193.mswin.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00094208 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\site_ruby\1.9.1\rgloader\rgloader193.mswin.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00118784 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\socket.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00069120 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\zlib.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00083968 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\bin\zlib1.dll
2015-03-07 12:25 - 2015-03-07 12:25 - 00026624 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\stringio.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00275968 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\openssl.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00015360 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\digest.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00008192 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\fcntl.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00009216 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00023552 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\parser.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00008704 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16be.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00008704 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16le.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00008704 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32be.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00008704 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32le.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00036352 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\generator.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00126976 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00087552 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00016384 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00127316 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\bin\libffi-6.dll
2015-03-07 12:25 - 2015-03-07 12:25 - 00013312 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\utf_16_32.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00095744 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\single_byte.so
2015-03-07 12:25 - 2015-03-07 12:25 - 00026624 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr3FB3.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19\win32\api.so
2014-07-28 15:07 - 2014-07-28 15:07 - 00815104 _____ () C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\khost.dll
2014-07-28 15:07 - 2014-07-28 15:07 - 01198592 _____ () C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoFoundation.dll
2014-07-28 15:07 - 2014-07-28 15:07 - 00745472 _____ () C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\CFLite.dll
2014-07-28 15:07 - 2014-07-28 15:07 - 00059904 _____ () C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\zlib1.dll
2014-07-28 15:07 - 2014-07-28 15:07 - 01234944 _____ () C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\libxml2.dll
2014-07-28 15:07 - 2014-07-28 15:07 - 00200704 _____ () C:\Program Files\pia_manager\pia_tray\modules\tiapp\1.2.0.RC6d\tiappmodule.dll
2014-07-28 15:07 - 2014-07-28 15:07 - 00290816 _____ () C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoUtil.dll
2014-07-28 15:07 - 2014-07-28 15:07 - 00511488 _____ () C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoXML.dll
2014-07-28 15:07 - 2014-07-28 15:07 - 00180224 _____ () C:\Program Files\pia_manager\pia_tray\modules\tifilesystem\1.2.0.RC6d\tifilesystemmodule.dll
2014-07-28 15:07 - 2014-07-28 15:07 - 00344064 _____ () C:\Program Files\pia_manager\pia_tray\modules\tiui\1.2.0.RC6d\tiuimodule.dll
2014-07-28 15:07 - 2014-07-28 15:07 - 00368640 _____ () C:\Program Files\pia_manager\pia_tray\modules\tinetwork\1.2.0.RC6d\tinetworkmodule.dll
2014-07-28 15:07 - 2014-07-28 15:07 - 00642048 _____ () C:\Program Files\pia_manager\pia_tray\runtime\1.2.0.RC6d\PocoNet.dll
2014-07-28 15:07 - 2014-07-28 15:07 - 00217088 _____ () C:\Program Files\pia_manager\pia_tray\modules\tiprocess\1.2.0.RC6d\tiprocessmodule.dll
2009-07-16 15:34 - 2009-07-16 15:34 - 02140944 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtCore4.dll
2009-07-16 15:34 - 2009-07-16 15:34 - 07704336 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtGui4.dll
2009-07-16 15:34 - 2009-07-16 15:34 - 00968976 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtNetwork4.dll
2009-07-16 15:34 - 2009-07-16 15:34 - 00475408 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtOpenGL4.dll
2009-07-16 15:35 - 2009-07-16 15:35 - 00363792 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtXml4.dll
2009-07-16 15:34 - 2009-07-16 15:34 - 00199952 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtSql4.dll
2009-07-16 15:35 - 2009-07-16 15:35 - 00027408 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\SDL.dll
2009-07-16 15:35 - 2009-07-16 15:35 - 11311888 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\QtWebKit4.dll
2009-07-16 15:34 - 2009-07-16 15:34 - 00291600 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\phonon4.dll
2009-07-16 15:36 - 2009-07-16 15:36 - 00028944 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\plugins\imageformats\qgif4.dll
2009-07-16 15:36 - 2009-07-16 15:36 - 00035088 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\plugins\imageformats\qico4.dll
2009-07-16 15:36 - 2009-07-16 15:36 - 00138000 _____ () C:\Program Files (x86)\Logitech\Logitech Vid\plugins\imageformats\qjpeg4.dll
2012-01-17 23:43 - 2012-01-17 23:43 - 00183320 _____ () C:\Program Files (x86)\Common Files\logishrd\SharedBin\LVAPI11.dll
2014-08-19 11:34 - 2014-08-19 11:34 - 00048640 _____ () C:\Program Files (x86)\AOL Desktop 9.7a\zlib.dll
2014-08-19 11:34 - 2014-08-19 11:34 - 21151232 _____ () C:\Program Files (x86)\AOL Desktop 9.7a\libcef.dll
2014-08-19 11:34 - 2014-08-19 11:34 - 00648704 _____ () C:\Program Files (x86)\AOL Desktop 9.7a\libglesv2.dll
2014-08-19 11:34 - 2014-08-19 11:34 - 00122880 _____ () C:\Program Files (x86)\AOL Desktop 9.7a\libegl.dll
2014-08-19 11:34 - 2014-08-19 11:34 - 00094208 _____ () C:\Program Files (x86)\AOL Desktop 9.7a\Components\Tier2Svc.dll
2014-08-19 11:34 - 2014-08-19 11:34 - 00060928 _____ () C:\Program Files (x86)\AOL Desktop 9.7a\Components\DataSvcs.dll
2010-02-24 09:32 - 2009-10-28 11:38 - 00118784 _____ () c:\program files (x86)\common files\aol\1267029088\ee\services\proxyprovider\ver1_0_0_1\proxyprovider.dll
2013-07-10 18:07 - 2013-07-10 18:07 - 00756888 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL
2009-06-24 13:12 - 2009-06-24 13:12 - 00059904 _____ () C:\Program Files (x86)\Mozy\Mozy Restore Manager\zlib1.dll
2015-02-05 07:32 - 2015-02-05 07:32 - 16852144 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll
2007-11-16 16:02 - 2007-11-16 16:02 - 00401408 ____R () C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\cryptocme2.dll
2007-11-16 16:02 - 2007-11-16 16:02 - 00479232 ____R () C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\ccme_base.dll
2013-12-21 11:20 - 2009-01-18 16:50 - 00417792 _____ () C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\AdobeXMP.dll
2013-12-21 11:20 - 2009-02-27 13:52 - 00258048 _____ () C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\sqlite.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:0B4227B4
AlternateDataStreams: C:\Users\Wayne\Downloads\My Little Pony-Friendship is Magic-Extended Theme Song.MP3:Roxio EMC Stream

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\95716721.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\95716721.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\N1Service => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2408619476-591646424-3276866331-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 209.222.18.222 - 209.222.18.218

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: ACDaemon => 2
MSCONFIG\Services: AcrSch2Svc => 2
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: Apple Mobile Device => 2
MSCONFIG\Services: Application Updater => 2
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: OverwolfUpdaterService => 3
MSCONFIG\Services: RichVideo => 2
MSCONFIG\Services: RoxMediaDB13 => 3
MSCONFIG\Services: RoxWatch12 => 2
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\Services: vToolbarUpdater17.0.12 => 2
MSCONFIG\startupreg: Acronis Scheduler2 Service => "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe"
MSCONFIG\startupreg: AOL Fast Start => "C:\Program Files (x86)\AOL 9.5\AOL.EXE" -b
MSCONFIG\startupreg: ArcSoft Connection Service => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
MSCONFIG\startupreg: Desktop Disc Tool => "C:\Program Files (x86)\Roxio 2012\Roxio Burn\RoxioBurnLauncher.exe"                                                                                                                                                                                                     
MSCONFIG\startupreg: DivXUpdate => "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: HostManager => C:\Program Files (x86)\Common Files\AOL\1267029088\ee\AOLSoftware.exe
MSCONFIG\startupreg: IndexSearch => "C:\Program Files (x86)\ScanSoft\PaperPort\IndexSearch.exe"
MSCONFIG\startupreg: Itibiti.exe => C:\Program Files (x86)\Itibiti Soft Phone\Itibiti.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: PaperPort PTD => "C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe"
MSCONFIG\startupreg: PWRISOVM.EXE => C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RoxWatchTray => "C:\Program Files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxWatchTray13.exe"
MSCONFIG\startupreg: SAOB Monitor => C:\Program Files (x86)\Acronis\OnlineBackupStandalone\TrueImageMonitor.exe
MSCONFIG\startupreg: SearchSettings => "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe"
MSCONFIG\startupreg: SSBkgdUpdate => "C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
MSCONFIG\startupreg: TivoNotify => C:\Program Files (x86)\TiVo\Desktop\TiVoNotify.exe /service /registry /auto:TivoNotify
MSCONFIG\startupreg: TivoServer => C:\Program Files (x86)\TiVo\Desktop\TiVoServer.exe /service /registry
MSCONFIG\startupreg: TivoTransfer => C:\Program Files (x86)\TiVo\Desktop\TiVoTransfer.exe
MSCONFIG\startupreg: TranscodingService => C:\Program Files (x86)\TiVo\Desktop\Plus\\TranscodingService.exe
MSCONFIG\startupreg: TrueImageMonitor.exe => "C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe"
MSCONFIG\startupreg: UpdatePDRShortCut => "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\8.0"
MSCONFIG\startupreg: vProt => "C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"

==================== Accounts: =============================

Administrator (S-1-5-21-2408619476-591646424-3276866331-500 - Administrator - Disabled)
Guest (S-1-5-21-2408619476-591646424-3276866331-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2408619476-591646424-3276866331-1002 - Limited - Enabled)
Wayne (S-1-5-21-2408619476-591646424-3276866331-1001 - Administrator - Enabled) => C:\Users\Wayne

==================== Faulty Device Manager Devices =============

Name: Standard PS/2 Keyboard
Description: Standard PS/2 Keyboard
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard keyboards)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: WAN Miniport (ATW) #2
Description: WAN Miniport (ATW)
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: America Online, Inc.
Service: wanatw
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (03/08/2015 01:37:29 AM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (03/07/2015 04:23:56 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 36.0.1.5542, time stamp: 0x54f851c0
Faulting module name: mozalloc.dll, version: 36.0.1.5542, time stamp: 0x54f8437e
Exception code: 0x80000003
Fault offset: 0x00001e02
Faulting process id: 0xba4
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3

Error: (03/07/2015 03:52:59 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 36.0.1.5542, time stamp: 0x54f851c0
Faulting module name: mozalloc.dll, version: 36.0.1.5542, time stamp: 0x54f8437e
Exception code: 0x80000003
Fault offset: 0x00001e02
Faulting process id: 0x1338
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3

Error: (03/07/2015 03:38:23 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (03/07/2015 03:38:22 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (03/07/2015 03:38:22 PM) (Source: SideBySide) (EventID: 80) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (03/07/2015 00:25:19 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcNvVAD initialization failed [6]

Error: (03/07/2015 00:25:19 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]

Error: (03/07/2015 00:25:19 PM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcNvVAD endpoint registration failed [0]

Error: (03/07/2015 00:21:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: WINWORD.EXE, version: 12.0.6715.5000, time stamp: 0x54b6a9ab
Faulting module name: wwlib.dll, version: 12.0.6715.5000, time stamp: 0x54b6aa79
Exception code: 0xc0000005
Fault offset: 0x00ea1e3f
Faulting process id: 0x2140
Faulting application start time: 0xWINWORD.EXE0
Faulting application path: WINWORD.EXE1
Faulting module path: WINWORD.EXE2
Report Id: WINWORD.EXE3


System errors:
=============
Error: (03/07/2015 08:19:45 PM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer ANGIE-PC
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{4F9C464A-587C-4F7D-9A72-12BAFA6931C5}.
The master browser is stopping or an election is being forced.

Error: (03/07/2015 00:24:27 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 35) (User: NT AUTHORITY)
Description: Performance power management features on processor 1 in group 0 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.

Error: (03/07/2015 00:24:27 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 35) (User: NT AUTHORITY)
Description: Performance power management features on processor 3 in group 0 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.

Error: (03/07/2015 00:24:27 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 35) (User: NT AUTHORITY)
Description: Performance power management features on processor 5 in group 0 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.

Error: (03/07/2015 00:24:27 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 35) (User: NT AUTHORITY)
Description: Performance power management features on processor 7 in group 0 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.

Error: (03/07/2015 00:24:27 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 35) (User: NT AUTHORITY)
Description: Performance power management features on processor 2 in group 0 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.

Error: (03/07/2015 00:24:27 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 35) (User: NT AUTHORITY)
Description: Performance power management features on processor 4 in group 0 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.

Error: (03/07/2015 00:24:27 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 35) (User: NT AUTHORITY)
Description: Performance power management features on processor 6 in group 0 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.

Error: (03/07/2015 00:24:27 PM) (Source: Microsoft-Windows-Kernel-Processor-Power) (EventID: 35) (User: NT AUTHORITY)
Description: Performance power management features on processor 0 in group 0 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.

Error: (03/07/2015 00:22:11 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}


Microsoft Office Sessions:
=========================
Error: (03/07/2015 00:21:42 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6715.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 30 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (03/07/2015 00:21:03 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6715.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 93 seconds with 60 seconds of active time.  This session ended with a crash.

Error: (03/07/2015 00:19:10 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6715.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1405 seconds with 1260 seconds of active time.  This session ended with a crash.

Error: (03/07/2015 11:54:33 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6715.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 543 seconds with 540 seconds of active time.  This session ended with a crash.

Error: (03/07/2015 11:45:15 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6715.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 1027 seconds with 180 seconds of active time.  This session ended with a crash.

Error: (03/07/2015 11:27:42 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6715.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 289 seconds with 240 seconds of active time.  This session ended with a crash.

Error: (01/01/2015 06:45:53 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6713.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 29 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (01/01/2015 06:44:53 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6713.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 548 seconds with 540 seconds of active time.  This session ended with a crash.

Error: (01/01/2015 06:35:35 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6713.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 47 seconds with 0 seconds of active time.  This session ended with a crash.

Error: (01/01/2015 06:34:37 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6713.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 428 seconds with 420 seconds of active time.  This session ended with a crash.


CodeIntegrity Errors:
===================================
  Date: 2013-02-03 07:39:31.185
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-02-03 07:39:31.105
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2011-10-16 17:26:51.111
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2012\Active Virus Control\Avc3_00081_007\avcuf64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2011-10-16 13:15:07.526
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2012\Active Virus Control\Avc3_00081_007\avcuf64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2011-10-16 10:08:17.206
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2012\Active Virus Control\Avc3_00081_007\avcuf64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2011-10-16 09:43:31.526
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2012\Active Virus Control\Avc3_00081_007\avcuf64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2011-10-14 16:19:40.836
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2012\Active Virus Control\Avc3_00081_007\avcuf64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2011-10-14 15:44:15.748
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2012\Active Virus Control\Avc3_00081_007\avcuf64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2011-10-14 15:38:07.302
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2012\Active Virus Control\Avc3_00081_007\avcuf64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2011-10-13 13:40:23.408
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Bitdefender\Bitdefender 2012\Active Virus Control\Avc3_00080_006\avcuf64.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: Intel® Core™ i7 CPU 920 @ 2.67GHz
Percentage of memory in use: 71%
Total physical RAM: 6135.18 MB
Available physical RAM: 1758.15 MB
Total Pagefile: 12268.55 MB
Available Pagefile: 6594.45 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.41 GB) (Free:83.39 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 137A7799)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)

==================== End Of Log ============================


  • 0

#4
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Those files seems to belong to Ruby, a Programming Language
.
Please download this attached [attachment=75905:fixlist.txt] and save it in the same directory as FRST.
  • Start FRST with Administrator privileges.
  • Press the Fix button.
  • When finished, a log file (Fixlog.txt) pops up and is saved to the same location the tool was run from.
Please copy and paste its contents in your next reply.

Restart the computer. Let me know how is it doing.
  • 0

#5
wemogil

wemogil

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

Hitman found the *.so files again,unfortunately.  Also--and it looks like this has happened repeatedly--Malwarebytes detected and blocked an outbound package a couple of minutes after booting up and before Hitman reported the *.so files turning up again.  The outbound data looks related--

 

Detection, 3/8/2015 7:52:43 PM, SYSTEM, WAYNE-PC, Protection, Malicious Website Protection, IP, 93.115.83.244, 49354, Outbound, C:\Users\Wayne\AppData\Local\Temp\ocrEE48.tmp\bin\rubyw.exe,
Detection, 3/8/2015 7:52:43 PM, SYSTEM, WAYNE-PC, Protection, Malicious Website Protection, IP, 93.115.83.244, 49354, Outbound, C:\Users\Wayne\AppData\Local\Temp\ocrEE48.tmp\bin\rubyw.exe,
 

Thanks again, here is the fixlog:

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-03-2015 03
Ran by Wayne at 2015-03-08 19:43:42 Run:1
Running from C:\Users\Wayne\Downloads
Loaded Profiles: Wayne (Available profiles: Wayne)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
CloseProcesses:
ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} =>  No File
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} =>  No File
ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} =>  No File
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} =>  No File
BootExecute: autocheck autochk * bootdeletebootdelete
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2408619476-591646424-3276866331-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Toolbar: HKLM-x32 - AOL Toolbar - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll No File
Toolbar: HKU\S-1-5-21-2408619476-591646424-3276866331-1001 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
Toolbar: HKU\S-1-5-21-2408619476-591646424-3276866331-1001 -> No Name - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} -  No File
U4 bdselfpr; No ImagePath
C:\Users\Wayne\AppData\Local\Temp\Delta.exe
C:\Users\Wayne\AppData\Local\Temp\dllnt_dump.dll
C:\Users\Wayne\AppData\Local\Temp\i4jdel0.exe
C:\Users\Wayne\AppData\Local\Temp\Opera_NI_stable.exe
C:\Users\Wayne\AppData\Local\Temp\Quarantine.exe
C:\Users\Wayne\AppData\Local\Temp\SpOrder.dll
C:\Users\Wayne\AppData\Local\Temp\sqlite3.dll
C:\Users\Wayne\AppData\Local\Temp\tu17p84.exe
C:\Users\Wayne\AppData\Local\Temp\WSSetup.exe
Task: {0C54A3E5-7105-4349-A885-B2446E0B1D2E} - \SPBIW_UpdateTask_Time_343138333235343032342d3437415a556c2a3223346c41 No Task File <==== ATTENTION
Task: {2A3242DF-C703-4A59-8661-E5AA741842A1} - \YTDownloaderUpd No Task File <==== ATTENTION
Task: {3BCAB783-4E9A-4649-8891-50C4E6D22CEC} - \ShopperPro No Task File <==== ATTENTION
Task: {58FC3B0A-D828-4CFF-B57C-4DCF2B3F4BA3} - \SPDriver No Task File <==== ATTENTION
Task: {6CA98119-A827-4A6C-9669-3C1813665B01} - \YTDownloader No Task File <==== ATTENTION
Task: {81095262-EBA7-4757-8356-17C43277649F} - \SMupdate1 No Task File <==== ATTENTION
Task: {B1246E0B-C6E1-4CB8-926F-8445985D6457} - \SMW_UpdateTask_Time_343138333235343032342d3437415a556c2a3223346c41 No Task File <==== ATTENTION
Task: {DAC533FC-6E30-4C7C-9F6E-EB04C6406A63} - System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update3
Task: {E73CF447-0166-449E-A31E-7920B343E654} - \SMWPUpd No Task File <==== ATTENTION
Task: {DAC533FC-6E30-4C7C-9F6E-EB04C6406A63} - System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update3 <==== ATTENTION
C:\Users\Wayne\AppData\Local\Temp
EmptyTemp:
DeleteQuarantine:
End
*****************

Processes closed successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncBackedUp" => Key deleted successfully.
HKCR\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncPending" => Key deleted successfully.
HKCR\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncRoot" => Key deleted successfully.
HKCR\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351} => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\SugarSyncShared" => Key deleted successfully.
HKCR\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51} => Key not found.
HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKU\S-1-5-21-2408619476-591646424-3276866331-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => Value was restored successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{ba00b7b1-0351-477a-b948-23e3ee5a73d4} => value deleted successfully.
"HKCR\Wow6432Node\CLSID\{ba00b7b1-0351-477a-b948-23e3ee5a73d4}" => Key deleted successfully.
HKU\S-1-5-21-2408619476-591646424-3276866331-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => value deleted successfully.
HKCR\CLSID\{47833539-D0C5-4125-9FA8-0819E2EAAC93} => Key not found.
HKU\S-1-5-21-2408619476-591646424-3276866331-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BA00B7B1-0351-477A-B948-23E3EE5A73D4} => value deleted successfully.
HKCR\CLSID\{BA00B7B1-0351-477A-B948-23E3EE5A73D4} => Key not found.
bdselfpr => Service deleted successfully.
C:\Users\Wayne\AppData\Local\Temp\Delta.exe => Moved successfully.
C:\Users\Wayne\AppData\Local\Temp\dllnt_dump.dll => Moved successfully.
C:\Users\Wayne\AppData\Local\Temp\i4jdel0.exe => Moved successfully.
C:\Users\Wayne\AppData\Local\Temp\Opera_NI_stable.exe => Moved successfully.
C:\Users\Wayne\AppData\Local\Temp\Quarantine.exe => Moved successfully.
C:\Users\Wayne\AppData\Local\Temp\SpOrder.dll => Moved successfully.
C:\Users\Wayne\AppData\Local\Temp\sqlite3.dll => Moved successfully.
C:\Users\Wayne\AppData\Local\Temp\tu17p84.exe => Moved successfully.
C:\Users\Wayne\AppData\Local\Temp\WSSetup.exe => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0C54A3E5-7105-4349-A885-B2446E0B1D2E}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0C54A3E5-7105-4349-A885-B2446E0B1D2E}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPBIW_UpdateTask_Time_343138333235343032342d3437415a556c2a3223346c41" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2A3242DF-C703-4A59-8661-E5AA741842A1}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A3242DF-C703-4A59-8661-E5AA741842A1}" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YTDownloaderUpd => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3BCAB783-4E9A-4649-8891-50C4E6D22CEC}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3BCAB783-4E9A-4649-8891-50C4E6D22CEC}" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ShopperPro => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{58FC3B0A-D828-4CFF-B57C-4DCF2B3F4BA3}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{58FC3B0A-D828-4CFF-B57C-4DCF2B3F4BA3}" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPDriver => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6CA98119-A827-4A6C-9669-3C1813665B01}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6CA98119-A827-4A6C-9669-3C1813665B01}" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YTDownloader => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{81095262-EBA7-4757-8356-17C43277649F}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{81095262-EBA7-4757-8356-17C43277649F}" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SMupdate1 => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B1246E0B-C6E1-4CB8-926F-8445985D6457}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B1246E0B-C6E1-4CB8-926F-8445985D6457}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SMW_UpdateTask_Time_343138333235343032342d3437415a556c2a3223346c41" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DAC533FC-6E30-4C7C-9F6E-EB04C6406A63}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DAC533FC-6E30-4C7C-9F6E-EB04C6406A63}" => Key deleted successfully.
C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Multimedia\SMupdate3" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E73CF447-0166-449E-A31E-7920B343E654}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E73CF447-0166-449E-A31E-7920B343E654}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SMWPUpd" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DAC533FC-6E30-4C7C-9F6E-EB04C6406A63} => Key not found.
C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Multimedia\SMupdate3 => Key not found.

"C:\Users\Wayne\AppData\Local\Temp" directory move:

Could not move "C:\Users\Wayne\AppData\Local\Temp" directory. => Scheduled to move on reboot.

"C:\FRST\Quarantine" => Removed successfully.

=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-03-08 19:50:19)<=

"C:\Users\Wayne\AppData\Local\Temp" => Directory could not move.


  • 0

#6
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts

Lets try that again:

 

Please download this attached [attachment=75911:fixlist.txt] and save it in the same directory as FRST.

  • Start FRST with Administrator privileges.
  • Press the Fix button.
  • When finished, a log file (Fixlog.txt) pops up and is saved to the same location the tool was run from.

Please copy and paste its contents in your next reply.

Restart the computer. Let me know how is it doing.


  • 0

#7
wemogil

wemogil

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

Hi, unfortunately I'm still having the issue.  I can see the files in question listed against a black screen just before the Windows Welcome screen.  If I go to the containing temp folder and try to delete the files in question, I'm told I can't because it is open in another program.  What exactly is this thing?

 

Here is the fixlog text:

 

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-03-2015 01
Ran by Wayne at 2015-03-10 09:33:40 Run:2
Running from C:\Users\Wayne\Downloads\FRST-OlderVersion
Loaded Profiles: Wayne (Available profiles: Wayne)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
BootExecute: autocheck autochk * bootdeletebootdelete
CMD: DEL /Q /F /S C:\*.so
EmptyTemp:
DeleteQuarantine:
Folder: C:\Users\Wayne\AppData\Local\Temp
End
*****************

HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => Value was restored successfully.

=========  DEL /Q /F /S C:\*.so =========

Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\date_core.so
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\digest.so
C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so
Access is denied.
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\fcntl.so
C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so
Access is denied.
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\openssl.so
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\psych.so
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\socket.so
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\stringio.so
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\strscan.so
C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so
Access is denied.
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\zlib.so
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\dl\callback.so
C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so
Access is denied.
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16be.so
C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16le.so
Access is denied.
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32be.so
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32le.so
C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\single_byte.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\utf_16_32.so
Access is denied.
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\generator.so
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\parser.so
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby18\win32\api.so
C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19\win32\api.so
Access is denied.
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby2_32\win32\api.so
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby2_64\win32\api.so
C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rgloader\rgloader193.mswin.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\src\rgloader\rgloader193.mswin.so
Access is denied.
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\date_core.so
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\digest.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\fcntl.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\openssl.so
Access is denied.
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\psych.so
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\socket.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\stringio.so
Access is denied.
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\strscan.so
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\zlib.so
Access is denied.
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\dl\callback.so
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16be.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16le.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32be.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32le.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\single_byte.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\utf_16_32.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\generator.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\parser.so
Access is denied.
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby18\win32\api.so
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19\win32\api.so
Access is denied.
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby2_32\win32\api.so
Deleted file - C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby2_64\win32\api.so
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rgloader\rgloader193.mswin.so
Access is denied.
C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\src\rgloader\rgloader193.mswin.so
Access is denied.

========= End of CMD: =========

"C:\FRST\Quarantine" => Removed successfully.

========================= Folder: C:\Users\Wayne\AppData\Local\Temp ========================

2015-03-09 12:26 - 2015-03-09 12:26 - 0000512 ____T () C:\Users\Wayne\AppData\Local\Temp\~DF0A2D964D35C1F722.TMP
2015-03-10 08:04 - 2015-03-10 08:05 - 11665408 _____ () C:\Users\Wayne\AppData\Local\Temp\~DF2BB58DD37972F156.TMP
2015-03-09 13:13 - 2015-03-09 13:13 - 0000512 ____T () C:\Users\Wayne\AppData\Local\Temp\~DF3DE98097A35B4DCB.TMP
2015-03-08 19:51 - 2015-03-08 19:52 - 11665408 _____ () C:\Users\Wayne\AppData\Local\Temp\~DFBDCE8434949AFAD1.TMP
2015-03-08 22:09 - 2015-03-08 22:09 - 0000512 ____T () C:\Users\Wayne\AppData\Local\Temp\~DFFAF1704B03791B6E.TMP
2015-03-09 10:38 - 2015-03-09 10:38 - 24379392 _____ () C:\Users\Wayne\AppData\Local\Temp\~PIB55E.tmp
2015-03-09 10:38 - 2015-03-09 10:38 - 0655360 _____ () C:\Users\Wayne\AppData\Local\Temp\~PIB59D.tmp
2015-03-09 13:10 - 2015-03-09 13:10 - 24379392 _____ () C:\Users\Wayne\AppData\Local\Temp\~PIE67E.tmp
2015-03-09 13:10 - 2015-03-09 13:10 - 0655360 _____ () C:\Users\Wayne\AppData\Local\Temp\~PIE67F.tmp
2015-03-09 13:10 - 2015-03-09 13:10 - 46465024 _____ () C:\Users\Wayne\AppData\Local\Temp\~PIE73D.tmp
2015-03-08 22:08 - 2015-03-08 22:08 - 0000134 _____ () C:\Users\Wayne\AppData\Local\Temp\8395625.od
2015-03-08 22:08 - 2015-03-08 22:08 - 0000668 _____ () C:\Users\Wayne\AppData\Local\Temp\A3DOfc_203a219f-b95b-4d3c-9c0f-6284db968dfb.u3d
2015-03-08 20:00 - 2015-03-10 08:14 - 0019273 _____ () C:\Users\Wayne\AppData\Local\Temp\AdobeARM.log
2015-03-09 10:41 - 2015-03-09 10:41 - 0001538 _____ () C:\Users\Wayne\AppData\Local\Temp\alm.log
2015-03-09 10:41 - 2015-03-09 10:41 - 0002901 _____ () C:\Users\Wayne\AppData\Local\Temp\amt.log
2015-03-08 19:50 - 2015-03-08 19:50 - 0000061 _____ () C:\Users\Wayne\AppData\Local\Temp\CMLS--2015-03-08--19-50-53.log
2015-03-10 08:04 - 2015-03-10 08:04 - 0000061 _____ () C:\Users\Wayne\AppData\Local\Temp\CMLS--2015-03-10--08-04-42.log
2015-03-08 22:08 - 2015-03-08 22:08 - 0000000 _____ () C:\Users\Wayne\AppData\Local\Temp\CVR1B59.tmp.cvr
2015-03-08 19:51 - 2015-03-08 19:51 - 0000000 _____ () C:\Users\Wayne\AppData\Local\Temp\e4jBA1E.tmp
2015-03-08 19:58 - 2015-03-08 19:58 - 0000512 ___HT () C:\Users\Wayne\AppData\Local\Temp\etilqs_2MugYJCkoal4nwd
2015-03-09 10:55 - 2015-03-09 10:55 - 0000512 ___HT () C:\Users\Wayne\AppData\Local\Temp\etilqs_C7Zzexesg7Uc6f4
2015-03-09 10:55 - 2015-03-09 10:55 - 0032768 ___HT () C:\Users\Wayne\AppData\Local\Temp\etilqs_fNsfE70tKR3qS0z
2015-03-10 09:33 - 2015-03-10 09:33 - 0032768 ___HT () C:\Users\Wayne\AppData\Local\Temp\etilqs_qjpPsEESKGfghmB
2015-03-08 19:58 - 2015-03-08 19:58 - 0032768 ___HT () C:\Users\Wayne\AppData\Local\Temp\etilqs_tCEWfBhDfde3s0i
2015-03-10 09:33 - 2015-03-10 09:33 - 0000512 ___HT () C:\Users\Wayne\AppData\Local\Temp\etilqs_XTUQ48UOKSyc890
2015-03-10 09:29 - 2015-03-10 09:29 - 0000166 _____ () C:\Users\Wayne\AppData\Local\Temp\fixlist.txt
2015-03-08 19:50 - 2015-03-08 19:50 - 0000000 _____ () C:\Users\Wayne\AppData\Local\Temp\FXSAPIDebugLogFile.txt
2015-03-08 19:57 - 2015-03-08 19:57 - 0028099 _____ () C:\Users\Wayne\AppData\Local\Temp\i4jdel0.exe
2015-03-09 10:41 - 2015-03-09 10:41 - 0000633 _____ () C:\Users\Wayne\AppData\Local\Temp\swtag.log
2015-03-08 19:57 - 2015-03-08 19:57 - 0176410 _____ () C:\Users\Wayne\AppData\Local\Temp\The.Walking.Dead.S05E13.720p.HDTV.x264-KILLERS.torrent
2015-03-09 10:46 - 2015-03-09 10:48 - 0007109 _____ () C:\Users\Wayne\AppData\Local\Temp\TWAIN.LOG
2015-03-09 10:46 - 2015-03-09 10:46 - 0000002 _____ () C:\Users\Wayne\AppData\Local\Temp\Twain001.Mtx
2015-03-09 10:46 - 2015-03-09 10:46 - 0000156 _____ () C:\Users\Wayne\AppData\Local\Temp\Twunk001.MTX
2015-03-09 10:46 - 2015-03-09 10:46 - 0000000 _____ () C:\Users\Wayne\AppData\Local\Temp\Twunk002.MTX
2015-03-08 20:01 - 1969-12-31 17:00 - 0006100 _____ () C:\Users\Wayne\AppData\Local\Temp\yvtbzrj.ABI
2015-03-09 11:18 - 2015-03-09 11:18 - 0000000 _____ () C:\Users\Wayne\AppData\Local\Temp\ZNP6BE6.tmp
2015-03-09 10:46 - 2015-03-09 11:18 - 8447380 _____ () C:\Users\Wayne\AppData\Local\Temp\ZNP8A22.tmp
2015-03-08 20:14 - 2015-03-10 09:35 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\acro_rd_dir
2015-03-08 19:51 - 2015-03-08 19:51 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\e4jBA1E.tmp_dir1425869466
2015-03-08 19:51 - 2015-03-08 19:51 - 0029894 _____ () C:\Users\Wayne\AppData\Local\Temp\e4jBA1E.tmp_dir1425869466\exe4jlib.jar
2015-03-08 19:51 - 2015-03-08 19:51 - 0028099 _____ () C:\Users\Wayne\AppData\Local\Temp\e4jBA1E.tmp_dir1425869466\i4jdel.exe
2015-03-08 19:51 - 2015-03-08 19:57 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\hsperfdata_Wayne
2015-03-08 19:51 - 2015-03-08 19:51 - 0065536 _____ () C:\Users\Wayne\AppData\Local\Temp\hsperfdata_Wayne\5164
2015-03-09 07:02 - 2015-03-10 06:25 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\mozilla-temp-files
2015-03-10 06:25 - 2015-03-10 06:25 - 0131072 _____ () C:\Users\Wayne\AppData\Local\Temp\mozilla-temp-files\mozilla-temp-6227
2014-05-26 21:31 - 2014-05-26 21:31 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\NVIDIA Corporation
2014-05-26 21:31 - 2015-03-10 09:33 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\NVIDIA Corporation\NV_Cache
2015-03-08 19:55 - 2015-03-08 19:55 - 0016384 _____ () C:\Users\Wayne\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\30e343e5b0f707dd240618f10b741aa_fce8394c8fd8a80f_15f74c7777689be5_0_0.bin
2015-03-08 19:55 - 2015-03-08 19:55 - 0004096 _____ () C:\Users\Wayne\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\30e343e5b0f707dd240618f10b741aa_fce8394c8fd8a80f_15f74c7777689be5_0_0.toc
2015-03-08 19:58 - 2015-03-08 19:58 - 1048576 _____ () C:\Users\Wayne\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\30e343e5b0f707dd240618f10b741aa_fce8394c8fd8a80f_15f74c7777689be5_0_1.bin
2015-03-08 19:55 - 2015-03-08 19:55 - 0016384 _____ () C:\Users\Wayne\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\30e343e5b0f707dd240618f10b741aa_fce8394c8fd8a80f_15f74c7777689be5_1_0.bin
2015-03-08 19:55 - 2015-03-08 19:55 - 0004096 _____ () C:\Users\Wayne\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\30e343e5b0f707dd240618f10b741aa_fce8394c8fd8a80f_15f74c7777689be5_1_0.toc
2014-07-30 00:04 - 2015-03-10 09:33 - 0016384 _____ () C:\Users\Wayne\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\63547c51a55c7182c5c77fb521826c6c_fce8394c8fd8a80f_6229ccd76215aea1_0_0.bin
2014-07-30 00:04 - 2015-03-10 09:33 - 0004096 _____ () C:\Users\Wayne\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\63547c51a55c7182c5c77fb521826c6c_fce8394c8fd8a80f_6229ccd76215aea1_0_0.toc
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\bin
2015-03-10 08:02 - 2015-03-10 08:02 - 1486336 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\bin\LIBEAY32.dll
2015-03-10 08:02 - 2015-03-10 08:02 - 0127316 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\bin\libffi-6.dll
2015-03-10 08:02 - 2015-03-10 08:02 - 0358439 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\bin\libyaml-0-2.dll
2015-03-10 08:02 - 2015-03-10 08:02 - 2141184 _____ (http://www.ruby-lang.org/) C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\bin\msvcrt-ruby191.dll
2015-03-10 08:02 - 2015-03-10 08:02 - 0070239 _____ (http://www.ruby-lang.org/) C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\bin\rubyw.exe
2015-03-10 08:02 - 2015-03-10 08:02 - 0000831 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\bin\rubyw.exe.manifest
2015-03-10 08:02 - 2015-03-10 08:02 - 0340992 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\bin\SSLEAY32.dll
2015-03-10 08:02 - 2015-03-10 08:02 - 0083968 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\bin\zlib1.dll
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1
2015-03-10 08:02 - 2015-03-10 08:02 - 0002694 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\base64.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0018431 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\benchmark.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0009519 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\cgi.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000946 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\date.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0002298 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\digest.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000176 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\dl.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000928 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\fiddle.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0046411 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\fileutils.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0007823 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\forwardable.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0009041 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\gserver.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0001779 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\json.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000547 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\openssl.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0013630 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\pp.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0009859 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\prettyprint.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0010055 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0023616 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\socket.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0006454 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\thread.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0003335 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\timeout.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0006958 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\tsort.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0003144 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\uri.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000975 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\Win32API.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000403 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\win32ole.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0002641 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\yaml.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\cgi
2015-03-10 08:02 - 2015-03-10 08:02 - 0005198 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\cgi\cookie.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0027558 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\cgi\core.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0034415 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\cgi\html.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0006387 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\cgi\util.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\date
2015-03-10 08:02 - 2015-03-10 08:02 - 0000051 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\date\format.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\fiddle
2015-03-10 08:02 - 2015-03-10 08:02 - 0001211 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\fiddle\closure.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000093 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\fiddle\function.rb
2015-03-10 08:02 - 2015-03-10 09:35 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32
2015-03-10 08:02 - 2015-03-10 08:02 - 0087552 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so
2015-03-10 08:02 - 2015-03-10 08:02 - 0009216 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so
2015-03-10 08:02 - 2015-03-10 08:02 - 0016384 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so
2015-03-10 08:02 - 2015-03-10 08:02 - 0009219 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\rbconfig.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0126976 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so
2015-03-10 08:02 - 2015-03-10 09:35 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\dl
2015-03-10 08:02 - 2015-03-10 09:35 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\enc
2015-03-10 08:02 - 2015-03-10 08:02 - 0012800 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so
2015-03-10 08:02 - 2015-03-10 08:02 - 0009728 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so
2015-03-10 08:02 - 2015-03-10 08:02 - 0008704 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16le.so
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans
2015-03-10 08:02 - 2015-03-10 08:02 - 0095744 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\single_byte.so
2015-03-10 08:02 - 2015-03-10 08:02 - 0014848 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so
2015-03-10 08:02 - 2015-03-10 08:02 - 0013312 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\utf_16_32.so
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\json
2015-03-10 08:02 - 2015-03-10 09:35 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\json
2015-03-10 08:02 - 2015-03-10 08:02 - 0014759 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\json\common.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000391 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\json\ext.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000271 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\json\version.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\net
2015-03-10 08:02 - 2015-03-10 08:02 - 0085674 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\net\http.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000496 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\net\https.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0008026 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\net\protocol.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\openssl
2015-03-10 08:02 - 2015-03-10 08:02 - 0000579 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\openssl\bn.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0009410 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\openssl\buffering.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0001623 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\openssl\cipher.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0007417 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\openssl\config.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0001717 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\openssl\digest.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0004773 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\openssl\ssl-internal.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0004557 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\openssl\x509-internal.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych
2015-03-10 08:02 - 2015-03-10 08:02 - 0002068 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\coder.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000876 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\core_ext.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0002460 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\deprecated.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0006827 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\handler.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0002381 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\nodes.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000045 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\omap.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0001681 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\parser.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0003369 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\scalar_scanner.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000044 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\set.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000851 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\stream.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000483 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\streaming.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000525 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\syntax_error.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0002104 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\tree_builder.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000206 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\visitors.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\handlers
2015-03-10 08:02 - 2015-03-10 08:02 - 0000488 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\handlers\document_stream.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\json
2015-03-10 08:02 - 2015-03-10 08:02 - 0000458 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\json\ruby_events.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000332 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\json\stream.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000327 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\json\tree_builder.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000749 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\json\yaml_events.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\nodes
2015-03-10 08:02 - 2015-03-10 08:02 - 0000464 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\nodes\alias.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0001795 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\nodes\document.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0001516 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\nodes\mapping.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0001200 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\nodes\node.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0001607 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\nodes\scalar.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0002018 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\nodes\sequence.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000965 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\nodes\stream.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\visitors
2015-03-10 08:02 - 2015-03-10 08:02 - 0000596 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\visitors\depth_first.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0001452 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\visitors\emitter.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000436 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\visitors\json_tree.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0009202 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\visitors\to_ruby.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000329 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\visitors\visitor.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0013072 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\psych\visitors\yaml_tree.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\uri
2015-03-10 08:02 - 2015-03-10 08:02 - 0029543 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\uri\common.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0006950 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\uri\ftp.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0036413 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\uri\generic.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0002821 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\uri\http.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000581 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\uri\https.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0005874 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\uri\ldap.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000470 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\uri\ldaps.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0007217 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\1.9.1\uri\mailto.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32
2015-03-10 08:02 - 2015-03-10 08:02 - 0001032 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\win32-api.gemspec
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32
2015-03-10 08:02 - 2015-03-10 08:02 - 0000416 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\api.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby18
2015-03-10 08:02 - 2015-03-10 09:35 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby18\win32
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19\win32
2015-03-10 08:02 - 2015-03-10 08:02 - 0026624 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19\win32\api.so
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby2_32
2015-03-10 08:02 - 2015-03-10 09:35 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby2_32\win32
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby2_64
2015-03-10 08:02 - 2015-03-10 09:35 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby2_64\win32
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-process-0.6.5
2015-03-10 08:02 - 2015-03-10 08:02 - 0001135 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-process-0.6.5\win32-process.gemspec
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-process-0.6.5\lib
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-process-0.6.5\lib\win32
2015-03-10 08:02 - 2015-03-10 08:02 - 0034897 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\win32-process-0.6.5\lib\win32\process.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-api-0.4.2
2015-03-10 08:02 - 2015-03-10 08:02 - 0001082 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-api-0.4.2\windows-api.gemspec
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-api-0.4.2\lib
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-api-0.4.2\lib\windows
2015-03-10 08:02 - 2015-03-10 08:02 - 0016319 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-api-0.4.2\lib\windows\api.rb
2015-03-10 08:02 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2
2015-03-10 08:03 - 2015-03-10 08:03 - 0001179 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\windows-pr.gemspec
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows
2015-03-10 08:02 - 2015-03-10 08:02 - 0004612 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\console.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0017222 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\error.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000665 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\handle.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0001317 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\library.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0006904 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\process.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0023045 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\security.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0004133 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\synchronize.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0002196 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\thread.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0001144 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\tool_helper.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0005033 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\unicode.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0003225 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\window.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\msvcrt
2015-03-10 08:02 - 2015-03-10 08:02 - 0005274 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\msvcrt\string.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\specifications
2015-03-10 08:02 - 2015-03-10 08:02 - 0001528 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\specifications\ocra-1.3.1.gemspec
2015-03-10 08:02 - 2015-03-10 08:02 - 0001468 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\specifications\win32-api-1.5.0-universal-mingw32.gemspec
2015-03-10 08:02 - 2015-03-10 08:02 - 0001708 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\specifications\win32-process-0.6.5.gemspec
2015-03-10 08:02 - 2015-03-10 08:02 - 0001572 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\specifications\windows-api-0.4.2.gemspec
2015-03-10 08:02 - 2015-03-10 08:02 - 0001645 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\gems\1.9.1\specifications\windows-pr-1.2.2.gemspec
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1
2015-03-10 08:02 - 2015-03-10 08:02 - 0006913 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\debug_log_mailer.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0057689 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\openvpn_manager.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0010337 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\pia_common.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0023297 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\pia_manager.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0003853 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\pia_win32.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0010561 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\region_manager.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0034951 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0001421 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\win32_dialog.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rgloader
2015-03-10 08:02 - 2015-03-10 08:02 - 0000436 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rgloader\loader.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0094208 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rgloader\rgloader193.mswin.so
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems
2015-03-10 08:02 - 2015-03-10 08:02 - 0002268 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\builder.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0009920 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\config_file.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0001871 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\custom_require.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0002716 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\defaults.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0006589 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\dependency.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0005719 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\dependency_list.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0001851 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\deprecate.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000793 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\errors.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0002393 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\exceptions.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0004682 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\gem_path_searcher.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0002204 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\package.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0001538 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\path_support.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0005684 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\platform.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000249 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\psych_additions.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000687 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\psych_tree.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0014114 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\remote_fetcher.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0005108 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\requirement.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0011269 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\source_index.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0007345 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\spec_fetcher.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0055992 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\specification.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0002067 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\syck_hack.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0001255 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\text.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0011494 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\user_interaction.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0010427 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\version.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\defaults
2015-03-10 08:02 - 2015-03-10 08:02 - 0000680 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\defaults\operating_system.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\package
2015-03-10 08:02 - 2015-03-10 08:02 - 0000403 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\package\f_sync_dir.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0006382 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\package\tar_header.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0007130 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\package\tar_input.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0003930 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\package\tar_output.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0002048 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\package\tar_reader.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0004487 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\package\tar_writer.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\package\tar_reader
2015-03-10 08:02 - 2015-03-10 08:02 - 0002226 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\lib\ruby\site_ruby\1.9.1\rubygems\package\tar_reader\entry.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\src
2015-03-10 08:02 - 2015-03-10 08:02 - 0004161 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\src\pia_manager.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\src\rgloader
2015-03-10 08:02 - 2015-03-10 08:02 - 0000436 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\src\rgloader\loader.rb
2015-03-10 08:02 - 2015-03-10 08:02 - 0094208 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr1076.tmp\src\rgloader\rgloader193.mswin.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\bin
2015-03-10 08:03 - 2015-03-10 08:03 - 1486336 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\bin\LIBEAY32.dll
2015-03-10 08:03 - 2015-03-10 08:03 - 0127316 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\bin\libffi-6.dll
2015-03-10 08:03 - 2015-03-10 08:03 - 0358439 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\bin\libyaml-0-2.dll
2015-03-10 08:03 - 2015-03-10 08:03 - 2141184 _____ (http://www.ruby-lang.org/) C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\bin\msvcrt-ruby191.dll
2015-03-10 08:03 - 2015-03-10 08:03 - 0070239 _____ (http://www.ruby-lang.org/) C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\bin\rubyw.exe
2015-03-10 08:03 - 2015-03-10 08:03 - 0000831 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\bin\rubyw.exe.manifest
2015-03-10 08:03 - 2015-03-10 08:03 - 0340992 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\bin\SSLEAY32.dll
2015-03-10 08:03 - 2015-03-10 08:03 - 0083968 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\bin\zlib1.dll
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby
2015-03-10 08:03 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1
2015-03-10 08:03 - 2015-03-10 08:03 - 0002694 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\base64.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0018431 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\benchmark.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0009519 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\cgi.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000946 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\date.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0002298 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\digest.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000176 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\dl.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000928 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\fiddle.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0046411 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\fileutils.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0007823 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\forwardable.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0009041 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\gserver.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0001779 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\json.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000547 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\openssl.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0013630 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\pp.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0009859 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\prettyprint.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0010055 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0023616 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\socket.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0006454 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\thread.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0003335 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\timeout.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0006958 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\tsort.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0003144 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\uri.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000975 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\Win32API.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000403 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\win32ole.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0002641 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\yaml.rb
2015-03-10 08:03 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\cgi
2015-03-10 08:03 - 2015-03-10 08:03 - 0005198 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\cgi\cookie.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0027558 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\cgi\core.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0034415 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\cgi\html.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0006387 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\cgi\util.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\date
2015-03-10 08:04 - 2015-03-10 08:04 - 0000051 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\date\format.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\fiddle
2015-03-10 08:03 - 2015-03-10 08:03 - 0001211 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\fiddle\closure.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000093 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\fiddle\function.rb
2015-03-10 08:03 - 2015-03-10 09:35 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32
2015-03-10 08:03 - 2015-03-10 08:03 - 0015360 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\digest.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0087552 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\dl.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0009216 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\etc.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0008192 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\fcntl.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0016384 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\fiddle.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0275968 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\openssl.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0009219 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\rbconfig.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0118784 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\socket.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0026624 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\stringio.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0126976 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\win32ole.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0069120 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\zlib.so
2015-03-10 08:04 - 2015-03-10 09:35 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\dl
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\enc
2015-03-10 08:03 - 2015-03-10 08:03 - 0012800 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\enc\encdb.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0009728 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\enc\iso_8859_1.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0008704 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16be.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0008704 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_16le.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0008704 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32be.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0008704 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\enc\utf_32le.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans
2015-03-10 08:03 - 2015-03-10 08:03 - 0095744 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\single_byte.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0014848 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\transdb.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0013312 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\enc\trans\utf_16_32.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\json
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext
2015-03-10 08:03 - 2015-03-10 08:03 - 0036352 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\generator.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0023552 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\i386-mingw32\json\ext\parser.so
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\json
2015-03-10 08:03 - 2015-03-10 08:03 - 0014759 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\json\common.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000391 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\json\ext.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000271 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\json\version.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\net
2015-03-10 08:03 - 2015-03-10 08:03 - 0085674 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\net\http.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000496 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\net\https.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0008026 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\net\protocol.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\openssl
2015-03-10 08:03 - 2015-03-10 08:03 - 0000579 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\openssl\bn.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0009410 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\openssl\buffering.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0001623 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\openssl\cipher.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0007417 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\openssl\config.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0001717 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\openssl\digest.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0004773 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\openssl\ssl-internal.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0004557 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\openssl\x509-internal.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych
2015-03-10 08:04 - 2015-03-10 08:04 - 0002068 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\coder.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000876 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\core_ext.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0002460 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\deprecated.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0006827 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\handler.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0002381 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\nodes.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000045 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\omap.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0001681 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\parser.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0003369 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\scalar_scanner.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000044 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\set.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000851 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\stream.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000483 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\streaming.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000525 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\syntax_error.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0002104 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\tree_builder.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000206 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\visitors.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\handlers
2015-03-10 08:04 - 2015-03-10 08:04 - 0000488 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\handlers\document_stream.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\json
2015-03-10 08:04 - 2015-03-10 08:04 - 0000458 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\json\ruby_events.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000332 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\json\stream.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000327 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\json\tree_builder.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000749 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\json\yaml_events.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\nodes
2015-03-10 08:04 - 2015-03-10 08:04 - 0000464 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\nodes\alias.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0001795 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\nodes\document.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0001516 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\nodes\mapping.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0001200 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\nodes\node.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0001607 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\nodes\scalar.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0002018 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\nodes\sequence.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000965 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\nodes\stream.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\visitors
2015-03-10 08:04 - 2015-03-10 08:04 - 0000596 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\visitors\depth_first.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0001452 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\visitors\emitter.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000436 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\visitors\json_tree.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0009202 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\visitors\to_ruby.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000329 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\visitors\visitor.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0013072 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\psych\visitors\yaml_tree.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\uri
2015-03-10 08:03 - 2015-03-10 08:03 - 0029543 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\uri\common.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0006950 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\uri\ftp.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0036413 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\uri\generic.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0002821 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\uri\http.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000581 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\uri\https.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0005874 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\uri\ldap.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000470 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\uri\ldaps.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0007217 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\1.9.1\uri\mailto.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1
2015-03-10 08:03 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems
2015-03-10 08:03 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32
2015-03-10 08:04 - 2015-03-10 08:04 - 0001032 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\win32-api.gemspec
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib
2015-03-10 08:03 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32
2015-03-10 08:03 - 2015-03-10 08:04 - 0000416 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\api.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby18
2015-03-10 08:04 - 2015-03-10 09:35 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby18\win32
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19\win32
2015-03-10 08:03 - 2015-03-10 08:04 - 0026624 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby19\win32\api.so
2015-03-10 08:04 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby2_32
2015-03-10 08:04 - 2015-03-10 09:35 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby2_32\win32
2015-03-10 08:04 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby2_64
2015-03-10 08:04 - 2015-03-10 09:35 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-api-1.5.0-universal-mingw32\lib\win32\ruby2_64\win32
2015-03-10 08:04 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-process-0.6.5
2015-03-10 08:04 - 2015-03-10 08:04 - 0001135 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-process-0.6.5\win32-process.gemspec
2015-03-10 08:04 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-process-0.6.5\lib
2015-03-10 08:04 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-process-0.6.5\lib\win32
2015-03-10 08:04 - 2015-03-10 08:04 - 0034897 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\win32-process-0.6.5\lib\win32\process.rb
2015-03-10 08:03 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-api-0.4.2
2015-03-10 08:04 - 2015-03-10 08:04 - 0001082 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-api-0.4.2\windows-api.gemspec
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-api-0.4.2\lib
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-api-0.4.2\lib\windows
2015-03-10 08:03 - 2015-03-10 08:04 - 0016319 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-api-0.4.2\lib\windows\api.rb
2015-03-10 08:03 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2
2015-03-10 08:04 - 2015-03-10 08:04 - 0001179 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\windows-pr.gemspec
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib
2015-03-10 08:03 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows
2015-03-10 08:03 - 2015-03-10 08:04 - 0004612 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\console.rb
2015-03-10 08:03 - 2015-03-10 08:04 - 0017222 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\error.rb
2015-03-10 08:03 - 2015-03-10 08:04 - 0000665 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\handle.rb
2015-03-10 08:03 - 2015-03-10 08:04 - 0001317 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\library.rb
2015-03-10 08:03 - 2015-03-10 08:04 - 0006904 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\process.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0023045 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\security.rb
2015-03-10 08:03 - 2015-03-10 08:04 - 0004133 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\synchronize.rb
2015-03-10 08:03 - 2015-03-10 08:04 - 0002196 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\thread.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0001144 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\tool_helper.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0005033 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\unicode.rb
2015-03-10 08:03 - 2015-03-10 08:04 - 0003225 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\window.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\msvcrt
2015-03-10 08:03 - 2015-03-10 08:04 - 0005274 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\gems\windows-pr-1.2.2\lib\windows\msvcrt\string.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\specifications
2015-03-10 08:03 - 2015-03-10 08:03 - 0001528 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\specifications\ocra-1.3.1.gemspec
2015-03-10 08:03 - 2015-03-10 08:03 - 0001468 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\specifications\win32-api-1.5.0-universal-mingw32.gemspec
2015-03-10 08:03 - 2015-03-10 08:03 - 0001708 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\specifications\win32-process-0.6.5.gemspec
2015-03-10 08:03 - 2015-03-10 08:03 - 0001572 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\specifications\windows-api-0.4.2.gemspec
2015-03-10 08:03 - 2015-03-10 08:03 - 0001645 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\gems\1.9.1\specifications\windows-pr-1.2.2.gemspec
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby
2015-03-10 08:03 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1
2015-03-10 08:03 - 2015-03-10 08:03 - 0006913 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\debug_log_mailer.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0057689 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\openvpn_manager.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0010337 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\pia_common.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0023297 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\pia_manager.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0003853 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\pia_win32.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0010561 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\region_manager.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0034951 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0001421 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\win32_dialog.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rgloader
2015-03-10 08:03 - 2015-03-10 08:03 - 0000436 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rgloader\loader.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0094208 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rgloader\rgloader193.mswin.so
2015-03-10 08:03 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems
2015-03-10 08:04 - 2015-03-10 08:04 - 0002268 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\builder.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0009920 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\config_file.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0001871 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\custom_require.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0002716 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\defaults.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0006589 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\dependency.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0005719 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\dependency_list.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0001851 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\deprecate.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000793 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\errors.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0002393 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\exceptions.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0004682 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\gem_path_searcher.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0002204 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\package.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0001538 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\path_support.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0005684 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\platform.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000249 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\psych_additions.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000687 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\psych_tree.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0014114 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\remote_fetcher.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0005108 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\requirement.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0011269 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\source_index.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0007345 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\spec_fetcher.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0055992 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\specification.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0002067 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\syck_hack.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0001255 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\text.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0011494 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\user_interaction.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0010427 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\version.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\defaults
2015-03-10 08:03 - 2015-03-10 08:03 - 0000680 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\defaults\operating_system.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\package
2015-03-10 08:04 - 2015-03-10 08:04 - 0000403 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\package\f_sync_dir.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0006382 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\package\tar_header.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0007130 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\package\tar_input.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0003930 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\package\tar_output.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0002048 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\package\tar_reader.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0004487 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\package\tar_writer.rb
2015-03-10 08:04 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\package\tar_reader
2015-03-10 08:04 - 2015-03-10 08:04 - 0002226 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\lib\ruby\site_ruby\1.9.1\rubygems\package\tar_reader\entry.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\src
2015-03-10 08:03 - 2015-03-10 08:03 - 0004161 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\src\pia_manager.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\src\rgloader
2015-03-10 08:03 - 2015-03-10 08:03 - 0000436 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\src\rgloader\loader.rb
2015-03-10 08:03 - 2015-03-10 08:03 - 0094208 _____ () C:\Users\Wayne\AppData\Local\Temp\ocr80B4.tmp\src\rgloader\rgloader193.mswin.so
2015-03-08 20:14 - 2015-03-10 06:41 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\plugtmp
2015-03-10 09:35 - 2015-03-10 09:36 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\plugtmp-1
2015-03-09 10:48 - 2015-03-09 10:48 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ScanSoft
2015-03-09 10:48 - 2015-03-09 10:48 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ScanSoft\OmniPageCSDK15.0
2015-03-09 10:48 - 2015-03-09 10:48 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\ScanSoft\OmniPageCSDK15.0\010112
2015-03-08 19:50 - 2015-03-08 19:50 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir3184_22413
2015-03-08 19:50 - 2015-03-08 19:50 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir3184_22416
2015-03-08 19:50 - 2015-03-08 19:50 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir3184_22419
2015-03-08 20:01 - 2015-03-08 20:01 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir3184_24506
2015-03-10 08:04 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir5648_22352
2015-03-10 08:04 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir5648_22358
2015-03-10 08:04 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir5648_22361
2015-03-10 09:34 - 2015-03-10 09:34 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir5648_7198
2015-03-10 09:34 - 2015-03-10 09:34 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir7676_26676
2015-03-10 09:34 - 2015-03-10 09:34 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir7676_27832
2015-03-10 09:34 - 2015-03-10 09:34 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir7676_7175
2015-03-10 09:34 - 2015-03-10 09:34 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir7676_7178
2015-03-09 09:23 - 2015-03-09 09:23 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_10327
2015-03-09 17:09 - 2015-03-09 17:09 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_10830
2015-03-08 20:01 - 2015-03-08 20:01 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_12351
2015-03-09 17:09 - 2015-03-09 17:09 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_13352
2015-03-09 12:10 - 2015-03-09 12:10 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_17759
2015-03-09 09:23 - 2015-03-09 09:23 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_17900
2015-03-09 07:01 - 2015-03-09 07:01 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_22721
2015-03-09 07:01 - 2015-03-09 07:01 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_22725
2015-03-08 20:01 - 2015-03-08 20:01 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_24503
2015-03-08 20:01 - 2015-03-08 20:01 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_24506
2015-03-09 11:11 - 2015-03-09 11:11 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_25616
2015-03-09 11:05 - 2015-03-09 11:05 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_271
2015-03-09 13:03 - 2015-03-09 13:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_28208
2015-03-09 16:04 - 2015-03-09 16:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_30843
2015-03-09 11:05 - 2015-03-09 11:05 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_4971
2015-03-09 11:05 - 2015-03-09 11:05 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_5075
2015-03-09 13:03 - 2015-03-09 13:03 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_5419
2015-03-10 06:38 - 2015-03-10 06:38 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_5439
2015-03-10 06:38 - 2015-03-10 06:38 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_5442
2015-03-09 11:10 - 2015-03-09 11:10 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_6065
2015-03-09 11:11 - 2015-03-09 11:11 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_6133
2015-03-09 11:11 - 2015-03-09 11:11 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_6146
2015-03-09 11:23 - 2015-03-09 11:23 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_8589
2015-03-08 20:01 - 2015-03-08 20:01 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\scoped_dir8036_9523
2015-03-08 20:14 - 2015-03-08 20:14 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\tmp000069ce
2015-03-08 20:14 - 2015-03-08 20:14 - 0000000 _____ () C:\Users\Wayne\AppData\Local\Temp\tmp000069ce\tmp00000000
2015-03-08 20:15 - 2015-03-08 20:15 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\tmp00006a74
2015-03-08 20:15 - 2015-03-08 20:15 - 0000000 _____ () C:\Users\Wayne\AppData\Local\Temp\tmp00006a74\tmp00000000
2015-03-08 20:15 - 2015-03-08 20:15 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\tmp00006aa8
2015-03-08 20:15 - 2015-03-08 20:15 - 0000000 _____ () C:\Users\Wayne\AppData\Local\Temp\tmp00006aa8\tmp00000000
2015-03-08 20:15 - 2015-03-08 20:15 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\tmp00006ac3
2015-03-08 20:15 - 2015-03-08 20:15 - 0000000 _____ () C:\Users\Wayne\AppData\Local\Temp\tmp00006ac3\tmp00000000
2015-03-08 20:15 - 2015-03-08 20:15 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\tmp00006ad9
2015-03-08 20:15 - 2015-03-08 20:15 - 0000000 _____ () C:\Users\Wayne\AppData\Local\Temp\tmp00006ad9\tmp00000000
2015-03-08 20:16 - 2015-03-08 20:20 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\tmp00006af0
2015-03-08 20:16 - 2015-03-08 20:16 - 0000000 _____ () C:\Users\Wayne\AppData\Local\Temp\tmp00006af0\tmp00000000
2015-03-08 20:20 - 2015-03-08 20:20 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\tmp00006e24
2015-03-08 20:20 - 2015-03-08 20:20 - 0000000 _____ () C:\Users\Wayne\AppData\Local\Temp\tmp00006e24\tmp00000000
2015-03-08 22:08 - 2015-03-08 22:08 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\VBE
2015-03-10 08:04 - 2015-03-10 08:04 - 0000000 ____D () C:\Users\Wayne\AppData\Local\Temp\WPDNSE

====== End of Folder: ======

EmptyTemp: => Removed 2.5 GB temporary data.


The system needed a reboot.

==== End of Fixlog 09:38:12 ====


  • 0

#8
wemogil

wemogil

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

I think this might be ok--I found this while researching a solution:

 

https://www.privatei...ks-like-malware

 

I do have PIA running on my machine and the application is starting at logon, is this what I'm seeing?


  • 0

#9
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts

It is worth the try.

 

There are PIA and Ruby files interacting in the temp folder.

 

What would you like to do?

 

You can remove PIA and cleanup the Temp folder. Then reinstall.

 

You let me know.


  • 0

#10
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0

#11
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0

#12
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0

#13
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP