Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Desktop Internet Shortcuts Stopped Working


  • Please log in to reply

#31
Jackpine

Jackpine

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 347 posts

Here are the VEW System and Application logs:

 

Vino's Event Viewer v01c run on Windows XP in English
Report run at 28/01/2017 3:58:06 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 28/01/2017 3:46:15 PM
Type: error Category: 0
Event: 4311 Source: NetBT
Initialization failed because the driver device could not be created.

Log: 'System' Date/Time: 28/01/2017 3:44:46 PM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Log: 'System' Date/Time: 28/01/2017 3:44:21 PM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Log: 'System' Date/Time: 28/01/2017 3:44:19 PM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}

Log: 'System' Date/Time: 28/01/2017 3:44:02 PM
Type: error Category: 0
Event: 7026 Source: Service Control Manager
The following boot-start or system-start driver(s) failed to load:  AFD AsIO ElbyCDIO Fips HWiNFO32 intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip WS2IFSL

Log: 'System' Date/Time: 28/01/2017 3:44:02 PM
Type: error Category: 0
Event: 7001 Source: Service Control Manager
The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error:  A device attached to the system is not functioning.  

Log: 'System' Date/Time: 28/01/2017 3:44:02 PM
Type: error Category: 0
Event: 7001 Source: Service Control Manager
The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error:  A device attached to the system is not functioning.  

Log: 'System' Date/Time: 28/01/2017 3:44:02 PM
Type: error Category: 0
Event: 7001 Source: Service Control Manager
The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error:  A device attached to the system is not functioning.  

Log: 'System' Date/Time: 28/01/2017 3:44:02 PM
Type: error Category: 0
Event: 7001 Source: Service Control Manager
The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error:  A device attached to the system is not functioning.  

Log: 'System' Date/Time: 28/01/2017 3:40:11 PM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Log: 'System' Date/Time: 28/01/2017 3:38:59 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Tweaking Run As System 0011 service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.  

Log: 'System' Date/Time: 28/01/2017 3:38:59 PM
Type: error Category: 0
Event: 7009 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for the Tweaking Run As System 0011 service to connect.

Log: 'System' Date/Time: 28/01/2017 3:38:29 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Tweaking Run As System 0010 service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.  

Log: 'System' Date/Time: 28/01/2017 3:38:29 PM
Type: error Category: 0
Event: 7009 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for the Tweaking Run As System 0010 service to connect.

Log: 'System' Date/Time: 28/01/2017 3:38:24 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Tweaking Run As System 0009 service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.  

Log: 'System' Date/Time: 28/01/2017 3:38:24 PM
Type: error Category: 0
Event: 7009 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for the Tweaking Run As System 0009 service to connect.

Log: 'System' Date/Time: 28/01/2017 3:38:18 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Tweaking Run As System 0008 service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.  

Log: 'System' Date/Time: 28/01/2017 3:38:18 PM
Type: error Category: 0
Event: 7009 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for the Tweaking Run As System 0008 service to connect.

Log: 'System' Date/Time: 28/01/2017 3:38:13 PM
Type: error Category: 0
Event: 7000 Source: Service Control Manager
The Tweaking Run As System 0007 service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.  

Log: 'System' Date/Time: 28/01/2017 3:38:13 PM
Type: error Category: 0
Event: 7009 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for the Tweaking Run As System 0007 service to connect.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 27/01/2017 11:42:28 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 27/01/2017 7:28:50 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 27/01/2017 6:43:21 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 27/01/2017 6:26:27 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 27/01/2017 4:45:14 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 27/01/2017 3:33:14 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 27/01/2017 2:21:14 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 27/01/2017 12:33:29 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 26/01/2017 9:42:14 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 26/01/2017 6:58:47 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 26/01/2017 5:28:47 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 26/01/2017 4:54:03 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 26/01/2017 3:34:26 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 26/01/2017 12:59:33 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 26/01/2017 11:29:27 AM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 26/01/2017 11:06:02 AM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 26/01/2017 10:49:06 AM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 26/01/2017 10:18:14 AM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 26/01/2017 9:59:15 AM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 26/01/2017 9:23:02 AM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Vino's Event Viewer v01c run on Windows XP in English
Report run at 28/01/2017 4:01:02 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 28/01/2017 3:33:06 PM
Type: error Category: 0
Event: 4 Source: WinMgmt
Failed to load MOF Z:\FA6FF83199FDB974327DBE\I386\LICWMI.MOF while recovering repository file.

Log: 'Application' Date/Time: 28/01/2017 3:33:06 PM
Type: error Category: 0
Event: 4 Source: WinMgmt
Failed to load MOF C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\CLR.MOF while recovering repository file.

Log: 'Application' Date/Time: 28/01/2017 3:33:06 PM
Type: error Category: 0
Event: 4 Source: WinMgmt
Failed to load MOF C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\ASPNET.MOF while recovering repository file.

Log: 'Application' Date/Time: 28/01/2017 3:33:05 PM
Type: error Category: 0
Event: 4 Source: WinMgmt
Failed to load MOF C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\MOF\SERVICEMODEL.MOF while recovering repository file.

Log: 'Application' Date/Time: 28/01/2017 3:33:04 PM
Type: error Category: 0
Event: 4 Source: WinMgmt
Failed to load MOF C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\ASPNET.MOF while recovering repository file.

Log: 'Application' Date/Time: 28/01/2017 3:33:04 PM
Type: error Category: 0
Event: 4 Source: WinMgmt
Failed to load MOF C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V2.0.50727\CLR.MOF while recovering repository file.

Log: 'Application' Date/Time: 28/01/2017 3:33:04 PM
Type: error Category: 0
Event: 4 Source: WinMgmt
Failed to load MOF C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.0\WINDOWS COMMUNICATION FOUNDATION\SERVICEMODEL.MOF while recovering repository file.

Log: 'Application' Date/Time: 28/01/2017 3:33:03 PM
Type: error Category: 0
Event: 4 Source: WinMgmt
Failed to load MOF C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V2.0.50727\ASPNET.MOF while recovering repository file.

Log: 'Application' Date/Time: 28/01/2017 3:32:08 PM
Type: error Category: 0
Event: 4101 Source: VSS
Volume Shadow Copy Service error: Cannot obtain the collection 'Applications' from the COM+ catalog [0x8007043c].

Log: 'Application' Date/Time: 28/01/2017 3:29:19 PM
Type: error Category: 0
Event: 8193 Source: VSS
Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80040206.

Log: 'Application' Date/Time: 28/01/2017 3:29:19 PM
Type: error Category: 50
Event: 4609 Source: EventSystem
The COM+ Event System detected a bad return code during its internal processing.  HRESULT was 8007043C from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.  Please contact Microsoft Product Support Services to report this error.

Log: 'Application' Date/Time: 28/01/2017 3:29:00 PM
Type: error Category: 0
Event: 4101 Source: VSS
Volume Shadow Copy Service error: Cannot obtain the collection 'Applications' from the COM+ catalog [0x8007043c].

Log: 'Application' Date/Time: 28/01/2017 3:25:55 PM
Type: error Category: 0
Event: 8193 Source: VSS
Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80040206.

Log: 'Application' Date/Time: 28/01/2017 3:25:55 PM
Type: error Category: 50
Event: 4609 Source: EventSystem
The COM+ Event System detected a bad return code during its internal processing.  HRESULT was 8007043C from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.  Please contact Microsoft Product Support Services to report this error.

Log: 'Application' Date/Time: 28/01/2017 2:23:02 PM
Type: error Category: 0
Event: 2002 Source: PerfNet
Unable to open the Redirector service. Redirector performance data will not be returned. Error code returned is in data DWORD 0.

Log: 'Application' Date/Time: 28/01/2017 2:23:02 PM
Type: error Category: 0
Event: 2004 Source: PerfNet
Unable to open the Server service. Server performance data will not be returned. Error code returned is in data DWORD 0.

Log: 'Application' Date/Time: 28/01/2017 2:18:06 PM
Type: error Category: 0
Event: 4 Source: WinMgmt
Failed to load MOF Z:\FA6FF83199FDB974327DBE\I386\LICWMI.MOF while recovering repository file.

Log: 'Application' Date/Time: 28/01/2017 2:18:06 PM
Type: error Category: 0
Event: 4 Source: WinMgmt
Failed to load MOF C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\CLR.MOF while recovering repository file.

Log: 'Application' Date/Time: 28/01/2017 2:18:06 PM
Type: error Category: 0
Event: 4 Source: WinMgmt
Failed to load MOF C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\ASPNET.MOF while recovering repository file.

Log: 'Application' Date/Time: 28/01/2017 2:18:05 PM
Type: error Category: 0
Event: 4 Source: WinMgmt
Failed to load MOF C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V4.0.30319\MOF\SERVICEMODEL.MOF while recovering repository file.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 28/01/2017 3:38:09 PM
Type: warning Category: 0
Event: 47 Source: WinMgmt
WMI ADAP was unable to retrieve data from the PerfLib subkey: SYSTEM\CurrentControlSet\Services\RSSearch\Performance\Library, error code: 0x80041009

Log: 'Application' Date/Time: 28/01/2017 3:38:09 PM
Type: warning Category: 0
Event: 47 Source: WinMgmt
WMI ADAP was unable to retrieve data from the PerfLib subkey: SYSTEM\CurrentControlSet\Services\RSIndex\Performance\Library, error code: 0x80041009

Log: 'Application' Date/Time: 28/01/2017 3:38:09 PM
Type: warning Category: 0
Event: 47 Source: WinMgmt
WMI ADAP was unable to retrieve data from the PerfLib subkey: SYSTEM\CurrentControlSet\Services\RSGTHRSVC\Performance\Library, error code: 0x80041009

Log: 'Application' Date/Time: 28/01/2017 3:38:08 PM
Type: warning Category: 0
Event: 47 Source: WinMgmt
WMI ADAP was unable to retrieve data from the PerfLib subkey: SYSTEM\CurrentControlSet\Services\RSGatherer\Performance\Library, error code: 0x80041009

Log: 'Application' Date/Time: 28/01/2017 3:34:22 PM
Type: warning Category: 0
Event: 5603 Source: WinMgmt
A provider, OffProv10, has been registered in the WMI namespace, Root\MSAPPS10, but did not specify the HostingModel property.  This provider will be run using the LocalSystem account.  This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.  Ensure that provider has been reviewed for security behavior and update the HostingModel property of the provider registration to an account with the least privileges possible for the required functionality.

Log: 'Application' Date/Time: 28/01/2017 3:34:22 PM
Type: warning Category: 0
Event: 5603 Source: WinMgmt
A provider, OffProv10, has been registered in the WMI namespace, Root\MSAPPS10, but did not specify the HostingModel property.  This provider will be run using the LocalSystem account.  This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.  Ensure that provider has been reviewed for security behavior and update the HostingModel property of the provider registration to an account with the least privileges possible for the required functionality.

Log: 'Application' Date/Time: 28/01/2017 3:34:14 PM
Type: warning Category: 0
Event: 63 Source: WinMgmt
A provider, HiPerfCooker_v1, has been registered in the WMI namespace, Root\WMI, to use the LocalSystem account.  This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

Log: 'Application' Date/Time: 28/01/2017 3:34:14 PM
Type: warning Category: 0
Event: 63 Source: WinMgmt
A provider, HiPerfCooker_v1, has been registered in the WMI namespace, Root\WMI, to use the LocalSystem account.  This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

Log: 'Application' Date/Time: 28/01/2017 3:34:01 PM
Type: warning Category: 0
Event: 63 Source: WinMgmt
A provider, WinRMProv, has been registered in the WMI namespace, root, to use the LocalSystem account.  This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

Log: 'Application' Date/Time: 28/01/2017 3:33:57 PM
Type: warning Category: 0
Event: 63 Source: WinMgmt
A provider, HiPerfCooker_v1, has been registered in the WMI namespace, Root\WMI, to use the LocalSystem account.  This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

Log: 'Application' Date/Time: 28/01/2017 3:33:57 PM
Type: warning Category: 0
Event: 63 Source: WinMgmt
A provider, HiPerfCooker_v1, has been registered in the WMI namespace, Root\WMI, to use the LocalSystem account.  This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

Log: 'Application' Date/Time: 28/01/2017 3:33:37 PM
Type: warning Category: 0
Event: 63 Source: WinMgmt
A provider, OffProv12, has been registered in the WMI namespace, Root\MSAPPS12, to use the LocalSystem account.  This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

Log: 'Application' Date/Time: 28/01/2017 3:33:37 PM
Type: warning Category: 0
Event: 63 Source: WinMgmt
A provider, OffProv12, has been registered in the WMI namespace, Root\MSAPPS12, to use the LocalSystem account.  This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

Log: 'Application' Date/Time: 28/01/2017 3:33:31 PM
Type: warning Category: 0
Event: 63 Source: WinMgmt
A provider, HiPerfCooker_v1, has been registered in the WMI namespace, Root\WMI, to use the LocalSystem account.  This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

Log: 'Application' Date/Time: 28/01/2017 2:23:10 PM
Type: warning Category: 0
Event: 47 Source: WinMgmt
WMI ADAP was unable to retrieve data from the PerfLib subkey: SYSTEM\CurrentControlSet\Services\RSSearch\Performance\Library, error code: 0x80041009

Log: 'Application' Date/Time: 28/01/2017 2:23:10 PM
Type: warning Category: 0
Event: 47 Source: WinMgmt
WMI ADAP was unable to retrieve data from the PerfLib subkey: SYSTEM\CurrentControlSet\Services\RSIndex\Performance\Library, error code: 0x80041009

Log: 'Application' Date/Time: 28/01/2017 2:23:10 PM
Type: warning Category: 0
Event: 47 Source: WinMgmt
WMI ADAP was unable to retrieve data from the PerfLib subkey: SYSTEM\CurrentControlSet\Services\RSGTHRSVC\Performance\Library, error code: 0x80041009

Log: 'Application' Date/Time: 28/01/2017 2:23:10 PM
Type: warning Category: 0
Event: 47 Source: WinMgmt
WMI ADAP was unable to retrieve data from the PerfLib subkey: SYSTEM\CurrentControlSet\Services\RSGatherer\Performance\Library, error code: 0x80041009

Log: 'Application' Date/Time: 28/01/2017 2:19:12 PM
Type: warning Category: 0
Event: 5603 Source: WinMgmt
A provider, OffProv10, has been registered in the WMI namespace, Root\MSAPPS10, but did not specify the HostingModel property.  This provider will be run using the LocalSystem account.  This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.  Ensure that provider has been reviewed for security behavior and update the HostingModel property of the provider registration to an account with the least privileges possible for the required functionality.

Log: 'Application' Date/Time: 28/01/2017 2:19:12 PM
Type: warning Category: 0
Event: 5603 Source: WinMgmt
A provider, OffProv10, has been registered in the WMI namespace, Root\MSAPPS10, but did not specify the HostingModel property.  This provider will be run using the LocalSystem account.  This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.  Ensure that provider has been reviewed for security behavior and update the HostingModel property of the provider registration to an account with the least privileges possible for the required functionality.

 


  • 0

Advertisements


#32
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

 

 

Not sure which disk this is so run the diskcheck on each hard drive you have then clear the events and reboot and run vew again.

 

1. Double-click My Computer, and then right-click the hard disk that you want to check. C:
2. Click Properties, and then click Tools.
3. Under Error-checking, click Check Now. A dialog box that shows the Check disk options is displayed,
4. Check both boxes and then click Start.
You will receive the following message:
The disk check could not be performed because the disk check utility needs exclusive access to some Windows files on the disk. These files can be accessed by restarting Windows. Do you want to schedule the disk check to occur the next time you restart the computer?
Click Yes to schedule the disk check, 
 
Reboot.  Repeat for any other drives you have tho you shouldn't have to reboot for them.
 
Clear the events:
Start, Run, eventvwr.msc, OK to bring up the Event Viewer.  Right click on System and Clear All Events, No (we don't want to save the old log), OK. Repeat for Application. 
 
Reboot and run VEW again:
2. Double-click VEW.exe
3. Under 'Select log to query', select:
 
* System
4. Under 'Select type to list', select:
* Error
* Warning
 
 
Then use the 'Number of events' as follows:
 
 
1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.
 
 
Please post the Output log in your next reply then repeat but select Application. (Each time you run VEW it overwrites the log so copy the first one to a Reply or rename it before running it a second time.)
 

  • 0

#33
Jackpine

Jackpine

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 347 posts

When I first ran VEW I forgot to first clear the events.  I now did that an ran VEW again.  The logs are at the end of this post.

 

(By the way, when I click on Start, there are about 5 icons that appear in a column.  One of them is Internet Explorer.  When I click on it the Google page shows up and on top of that is a window saying Welcome to Internet Explorer 8.  It gives me the option to install/setup IE8 (I think), i.e, Next, or Ask Me Later.  I click on Ask Me Later and then the Google page remains.  When I go the Favourites, I recognize many of the folders and individual favourites, but a bunch that I used to see before my desktop shortcuts stopped working are not there.  Anyway, the favourites work, but slower than usual.  I wonder if something basic in terms of my default browser and search engine are messed up?)

 

Vino's Event Viewer v01c run on Windows XP in English
Report run at 29/01/2017 8:59:48 AM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 29/01/2017 8:59:12 AM
Type: error Category: 0
Event: 7011 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for a transaction response from the MBAMService service.

Log: 'System' Date/Time: 29/01/2017 8:58:33 AM
Type: error Category: 0
Event: 4311 Source: NetBT
Initialization failed because the driver device could not be created.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

Vino's Event Viewer v01c run on Windows XP in English
Report run at 29/01/2017 9:01:02 AM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

NOTE:  I will be away from my computer from Monday, Jan 30, returning Wed Feb 1.

 

Hi RKinner, I'm back home now.  Hope we can continue with fixing this! :)


Edited by Jackpine, 01 February 2017 - 02:05 PM.

  • 0

#34
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP

OK.  I don't get a notification if you just edit a post.  Best to just do a reply.

 

Let's  disable NetBIOS over TCP/IP support

From the Network and Dial-up Connections icon in Control Panel , select Local Area Connection and right-click Properties .
On the General tab, click Internet Protocol (TCP/IP) in the list of components, and click the Properties button.
Click the Advanced button.
Click the WINS tab. Click Disable NetBIOS over TCP/IP .
 
It's an obsolete protocol and it is causing an error.
 
I would also uninstall Malware Bytes as it also causing an error.
 
Reboot when done.
 
Then since it's been a while, let's run VEW again just like before.
 
I'm surprised that IE8 has never been setup.  I would go ahead and set it up and see if it works OK.

  • 0

#35
Jackpine

Jackpine

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 347 posts
  1. I uninstalled Malewarebytes.
  2. I clicked Disable NetBIOS over TCP/IP.
  3. I rebooted, but for some reason, it wouldn't reboot.  I didnt' hear the start beep, so I turned off the power, then turned it on and it rebooted.
  4. I ran VEW.  Logs posted below.
  5. I am running Check disk on my boot disk and two data disks (one internal and one external.)  I will let you know how those turn out when complete.
  6. Tried the web shortcuts, but they still don't work.
  7. After checkdisk is complete and I hear back from you, I will either set up IE8 or follow other instructions.

Vino's Event Viewer v01c run on Windows XP in English
Report run at 02/02/2017 4:10:12 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

Vino's Event Viewer v01c run on Windows XP in English
Report run at 02/02/2017 4:11:03 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 02/02/2017 4:08:22 PM
Type: error Category: 0
Event: 4311 Source: NetBT
Initialization failed because the driver device could not be created.

Log: 'System' Date/Time: 02/02/2017 4:06:13 PM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Log: 'System' Date/Time: 02/02/2017 4:02:01 PM
Type: error Category: 0
Event: 7011 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for a transaction response from the MBAMService service.

Log: 'System' Date/Time: 02/02/2017 4:01:31 PM
Type: error Category: 0
Event: 4311 Source: NetBT
Initialization failed because the driver device could not be created.

Log: 'System' Date/Time: 02/02/2017 3:51:24 PM
Type: error Category: 0
Event: 7011 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for a transaction response from the MBAMService service.

Log: 'System' Date/Time: 02/02/2017 3:50:50 PM
Type: error Category: 0
Event: 4311 Source: NetBT
Initialization failed because the driver device could not be created.

Log: 'System' Date/Time: 02/02/2017 3:50:44 PM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1058" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Log: 'System' Date/Time: 29/01/2017 7:37:14 PM
Type: error Category: 0
Event: 7011 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for a transaction response from the MBAMService service.

Log: 'System' Date/Time: 29/01/2017 7:36:27 PM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1058" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Log: 'System' Date/Time: 29/01/2017 7:36:23 PM
Type: error Category: 0
Event: 4311 Source: NetBT
Initialization failed because the driver device could not be created.

Log: 'System' Date/Time: 29/01/2017 7:18:45 PM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1058" attempting to start the service gupdate with arguments "/comsvc" in order to run the server: {4EB61BAC-A3B6-4760-9581-655041EF4D69}

Log: 'System' Date/Time: 29/01/2017 2:18:25 PM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1058" attempting to start the service gupdate with arguments "/comsvc" in order to run the server: {4EB61BAC-A3B6-4760-9581-655041EF4D69}

Log: 'System' Date/Time: 29/01/2017 9:18:17 AM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1058" attempting to start the service gupdate with arguments "/comsvc" in order to run the server: {4EB61BAC-A3B6-4760-9581-655041EF4D69}

Log: 'System' Date/Time: 29/01/2017 8:59:12 AM
Type: error Category: 0
Event: 7011 Source: Service Control Manager
Timeout (30000 milliseconds) waiting for a transaction response from the MBAMService service.

Log: 'System' Date/Time: 29/01/2017 8:58:33 AM
Type: error Category: 0
Event: 4311 Source: NetBT
Initialization failed because the driver device could not be created.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 29/01/2017 3:17:17 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 29/01/2017 1:38:16 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 29/01/2017 12:22:04 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 29/01/2017 11:07:22 AM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 29/01/2017 10:11:10 AM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

 


  • 0

#36
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP

go ahead and set up IE.  

 

Then try windows repair all in one:

 

Windows Repair all in one
 
 
Download it and save it then run it.
 
You can skip to step 4 or 5 where it gives you the same picture as in the above link.
 
Make sure all of these are checked before hitting Start:
 
Reset Registry Permissions
Reset File Permissions
Register System Files
Repair WMI
Repair Windows Firewall
Repair Internet Explorer
Repair MDAC & MS Jet
Repair Hosts File
Remove Policies Set By Infections
Repair Icons
 
Remove Temp Files
Repair Proxy Settings
Unhide Non System Files
Repair Windows Updates
Repair CD/DVD Missing/Not Working
 
Reboot when done and run VEW again as before.

  • 0

#37
Jackpine

Jackpine

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 347 posts

I set up IE7.  It works, but my shortcuts still don't work.  I used to drive repair tool on my boot drive and two data drives.  I didn't get any messages that anything was wrong.

 

I ran the Windows repair tool.  Rebooted.  Ran VEW.  Logs are below. 

 

(Something worth considering is that I have a complete image of my C:\ drive from about a year ago, created using Macrium Reflect.  I created the image after GtoG removed malware from the machine.)

 

Vino's Event Viewer v01c run on Windows XP in English
Report run at 02/02/2017 10:43:14 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

Vino's Event Viewer v01c run on Windows XP in English
Report run at 02/02/2017 10:43:51 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 02/02/2017 10:18:41 PM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1058" attempting to start the service gupdate with arguments "/comsvc" in order to run the server: {4EB61BAC-A3B6-4760-9581-655041EF4D69}

Log: 'System' Date/Time: 02/02/2017 9:55:50 PM
Type: error Category: 0
Event: 4311 Source: NetBT
Initialization failed because the driver device could not be created.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 02/02/2017 10:43:13 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

Log: 'System' Date/Time: 02/02/2017 10:23:01 PM
Type: warning Category: 0
Event: 51 Source: Disk
An error was detected on device \Device\Harddisk2\D during a paging operation.

 


  • 0

#38
Jackpine

Jackpine

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 347 posts

Correction: in my previous post I said I set up IE7.  It was actually IE8.


  • 0

#39
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP

Did you let IE8 become the default browser?  If not do so for now.

 

Does IE work OK?

 

Did that change any of your shortcuts?

 

 

For the NetBT error:

 

Click Start, click Control Panel, double-click Device Manager, expand Network Adapters, right-click the adapter you want to initialize, click Disable, and then click Yes.
Right-click the adapter that you just disabled, and then click Enable.  Do this for each device under network adapters.
 
Let's run FRST:
 

  •  
  • Get FRST from http://www.bleepingc...very-scan-tool/You need to download the appropriate tool for your PC.  If you don't know if you have a 32 or 64 bit system get them both.  Only one will work and that's the right one.
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer. 
  • Check the Addition.txt box
  • Press Scan button. 
  • It will produce a log called FRST.txt in the same directory the tool is run from.  
  • Please copy and paste log back here. 
  • It will generate another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply. 
  •  
    I'll have to have this moved to the malware forum since I'm not supposed to use FRST in this forum.  So don't be surprised if the forum moves.
     

    • 0

    #40
    Jackpine

    Jackpine

      Member

    • Topic Starter
    • Member
    • PipPipPip
    • 347 posts

    Just so I do this correctly, what are the steps in Windows XP to ensure that IE8 becomes the default browser?


    • 0

    Advertisements


    #41
    Jackpine

    Jackpine

      Member

    • Topic Starter
    • Member
    • PipPipPip
    • 347 posts

    I managed to make IE8 my default browser.  Shortcuts now work, but all my login information for certain forums needed to be re-entered. (no big deal). 

     

    However, I believe that many of my favourites are now gone since I no longer seem them listed. Also, I used to have AdBlock installed.  That's gone too. The FRST logs are below.

     

    Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-01-2017
    Ran by Robert (administrator) on FIRSTBUILD (03-02-2017 13:00:04)
    Running from C:\Documents and Settings\Robert\Desktop
    Loaded Profiles: Robert (Available Profiles: Robert & UpdatusUser & Administrator & Guest)
    Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) Language: English (United States)
    Internet Explorer Version 8 (Default browser: IE)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe

    ==================== Registry (Whitelisted) ====================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
    HKLM\...\Policies\Explorer: [NoCDBurning] 0
    HKU\S-1-5-21-299502267-789336058-725345543-1004\...\Policies\Explorer: [NoBandCustomize] 0
    HKU\S-1-5-21-299502267-789336058-725345543-1004\...\Policies\Explorer: [NoMovingBands] 0
    HKU\S-1-5-21-299502267-789336058-725345543-1004\...\Policies\Explorer: [NoCloseDragDropBands] 0
    HKU\S-1-5-21-299502267-789336058-725345543-1004\...\Policies\Explorer: [NoSetTaskbar] 0
    HKU\S-1-5-21-299502267-789336058-725345543-1004\...\Policies\Explorer: [NoToolbarsOnTaskbar] 0
    HKU\S-1-5-18\...\RunOnce: [tscuninstall] => C:\WINDOWS\system32\tscupgrd.exe [44544 2004-08-04] (Microsoft Corporation)
    ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\WINDOWS\system32\AcSignIcon.dll [2008-02-09] (Autodesk, Inc.)
    BootExecute: PDBoot.exeautocheck autochk *

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc.)
    Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
    Tcpip\..\Interfaces\{83ABCB39-813D-4C57-89F5-141B6B76F736}: [DhcpNameServer] 192.168.2.1

    Internet Explorer:
    ==================
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\S-1-5-21-299502267-789336058-725345543-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-09-12] (Adobe Systems Incorporated)
    BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-09-12] (Adobe Systems Incorporated)
    Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-09-12] (Adobe Systems Incorporated)
    Toolbar: HKU\.DEFAULT -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-09-12] (Adobe Systems Incorporated)
    Toolbar: HKU\S-1-5-21-299502267-789336058-725345543-1004 -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-09-12] (Adobe Systems Incorporated)
    DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
    DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
    DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} hxxp://support.asus.com/common/asusTek_sys_ctrl.cab
    DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
    DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Twisted%20Lands%20-%20Shadow%20Town/Images/stg_drm.ocx
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab
    DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
    DPF: {588031A3-94BF-4CDD-86D0-939F6F93910F} hxxps://fixit.support.microsoft.com/ActiveX/FixItClient.CAB
    DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1292380760937
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1420669599859
    DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
    DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab
    DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
    DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
    DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
    DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Twisted%20Lands%20-%20Shadow%20Town/Images/armhelper.ocx
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} hxxp://eserv.sympatico.ca/netassistant/controls/BellCanadaPortalAX.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} hxxp://driveragent.com/files/driveragent.cab
    DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} hxxps://secure.logmein.com//activex/ractrl.cab?lmi=1007

    FireFox:
    ========
    FF ProfilePath: C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\tonk28m2.default [2017-01-29]
    FF DefaultSearchEngine.US: C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\tonk28m2.default -> Google
    FF Extension: (Advertising Cookie Opt-out) - C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\tonk28m2.default\Extensions\[email protected] [2015-08-16] [not signed]
    FF Extension: (Adblock Plus) - C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\tonk28m2.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-24]
    FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    FF Extension: (Microsoft .NET Framework Assistant) - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-06-25] [not signed]
    FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
    FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2015-03-16] [not signed]
    FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-12] ()
    FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
    FF Plugin: @nosltd.com/getPlus+®,version=1.6.2.91 -> C:\Program Files\NOS\bin\np_gp.dll [2010-09-01] (NOS Microsystems Ltd.)
    FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
    FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
    FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2014-09-12] (Adobe Systems Inc.)
    FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-04-28] (Adobe Systems)
    FF Plugin ProgramFiles/Appdata: C:\Documents and Settings\Robert\Application Data\mozilla\plugins\npPxPlay.dll [2009-04-23] ( )

    Chrome:
    =======
    CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
    CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2014-09-12]

    ==================== Services (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S4 AcrSch2Svc; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [618944 2009-01-21] (Acronis)
    S4 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2008-12-23] (Macrovision Europe Ltd.) [File not signed]
    S4 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
    S4 PDAgent; C:\Program Files\Raxco\PerfectDisk\PDAgent.exe [2234160 2014-11-12] (Raxco Software, Inc.)
    S4 PDEngine; C:\Program Files\Common Files\Raxco\Shared\PDEngine.exe [2247472 2014-11-12] (Raxco Software, Inc.)
    S4 ProtexisLicensing; C:\WINDOWS\system32\PSIService.exe [174656 2006-11-02] () [File not signed]
    S4 ReflectService.exe; C:\Program Files\Macrium\Reflect\ReflectService.exe [2613200 2015-10-12] (Paramount Software UK Ltd)
    S4 ScsiAccess; C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe [181312 2009-04-23] () [File not signed]
    S4 SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [79360 2008-07-10] (SolidWorks) [File not signed]
    S4 Update service; C:\Program Files\Popcorn Time\Updater.exe [339968 2016-08-26] (Popcorn Time) [File not signed]
    S4 WMPNetworkSvc; C:\Program Files\Windows Media Player\WMPNetwk.exe [913408 2006-10-18] (Microsoft Corporation) [File not signed]
    S4 Roxio UPnP Renderer 9; "C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe" [X]
    S4 RoxLiveShare9; "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe" [X]

    ===================== Drivers (Whitelisted) ======================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
    S3 AnyDVD; C:\WINDOWS\System32\Drivers\AnyDVD.sys [139216 2016-07-11] (RedFox)
    R1 AsIO; C:\WINDOWS\System32\drivers\AsIO.sys [4962 2004-10-14] () [File not signed]
    R2 cvintdrv; C:\WINDOWS\system32\Drivers\cvintdrv.sys [4096 2006-07-27] () [File not signed]
    R2 DefragFS; C:\WINDOWS\system32\Drivers\DefragFS.sys [104088 2012-09-11] (Raxco Software, Inc.)
    R1 ElbyCDIO; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [30616 2014-12-20] (Elaborate Bytes AG)
    R2 Hardlock; C:\WINDOWS\system32\drivers\hardlock.sys [670208 2004-11-05] (Aladdin Knowledge Systems Ltd.)
    R1 HWiNFO32; C:\WINDOWS\system32\drivers\HWiNFO32.SYS [23840 2015-02-12] (REALiX™)
    R0 iteatapi; C:\WINDOWS\System32\DRIVERS\iteatapi.sys [28672 2008-03-01] (ITE Tech. Inc.)
    S3 KLIF; C:\WINDOWS\system32\drivers\klif.sys [700616 2014-11-18] (Kaspersky Lab ZAO)
    R3 klim5; C:\WINDOWS\System32\DRIVERS\klim5.sys [36448 2013-04-19] (Kaspersky Lab ZAO)
    S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
    S3 moufiltr; C:\WINDOWS\System32\DRIVERS\moufiltr.sys [62592 2007-01-14] (Chic Tech.) [File not signed]
    R3 MTsensor; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [5810 2004-08-12] ()
    S3 pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [47360 2010-08-22] (VSO Software) [File not signed]
    R2 PDFSFilter; C:\WINDOWS\System32\DRIVERS\PDFsFilter.sys [69016 2012-08-23] (Raxco Software, Inc.)
    R0 pssnap; C:\WINDOWS\System32\DRIVERS\pssnap.sys [16016 2015-10-12] (Windows ® Win 7 DDK provider)
    R0 PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [36624 2006-11-02] (Sonic Solutions) [File not signed]
    R0 SI3132; C:\WINDOWS\System32\DRIVERS\SI3132.sys [80424 2007-10-03] (Silicon Image, Inc)
    R0 SiFilter; C:\WINDOWS\System32\DRIVERS\SiWinAcc.sys [19240 2007-10-03] (Silicon Image, Inc)
    R0 SiRemFil; C:\WINDOWS\System32\DRIVERS\SiRemFil.sys [15400 2007-10-03] (Silicon Image, Inc)
    R0 snapman380; C:\WINDOWS\System32\DRIVERS\snman380.sys [134272 2009-10-24] (Acronis)
    S3 SONYPVU1; C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS [7552 2001-08-17] (Sony Corporation)
    R0 tdrpman174; C:\WINDOWS\System32\DRIVERS\tdrpm174.sys [971552 2009-10-24] (Acronis)
    R2 tifsfilter; C:\WINDOWS\System32\DRIVERS\tifsfilt.sys [44704 2009-10-24] (Acronis)
    S3 TVICHW32; C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS [23600 2008-05-10] (EnTech Taiwan) [File not signed]
    R3 yukonwxp; C:\WINDOWS\System32\DRIVERS\yk51x86.sys [298752 2015-02-12] ()
    S3 EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys [X]
    S3 FLASHSYS; no ImagePath
    S3 GMSIPCI; no ImagePath
    S4 IntelIde; no ImagePath
    S3 MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [X]
    S3 NTACCESS; no ImagePath
    U2 RemoteRegistry; no ImagePath
    U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
    U5 Tcpip6; C:\Windows\System32\Drivers\Tcpip6.sys [226880 2010-02-11] (Microsoft Corporation)
    U3 TlntSvr; no ImagePath
    U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [4096 2010-03-08] () [File not signed]

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2017-02-03 13:00 - 2017-02-03 13:00 - 00014896 _____ C:\Documents and Settings\Robert\Desktop\FRST.txt
    2017-02-03 12:59 - 2017-02-03 13:00 - 00000000 ____D C:\FRST
    2017-02-03 12:59 - 2017-02-03 12:00 - 01762816 _____ (Farbar) C:\Documents and Settings\Robert\Desktop\FRST.exe
    2017-02-03 12:58 - 2017-02-03 12:58 - 00000242 _____ C:\Documents and Settings\Robert\Desktop\BitHQ  Browse Torrents.url
    2017-02-02 22:44 - 2017-02-02 22:44 - 00001149 _____ C:\Documents and Settings\Robert\Desktop\VEW System.txt
    2017-02-02 22:43 - 2017-02-02 22:43 - 00000359 _____ C:\Documents and Settings\Robert\Desktop\VEW Application.txt
    2017-01-29 21:41 - 2017-01-29 21:41 - 00010451 _____ C:\Documents and Settings\Robert\Desktop\MTB.txt
    2017-01-28 15:55 - 2017-02-02 22:43 - 00001149 _____ C:\VEW.txt
    2017-01-28 15:55 - 2017-01-28 15:48 - 00061440 _____ ( ) C:\Documents and Settings\Robert\Desktop\VEW.exe
    2017-01-28 14:17 - 2017-02-02 21:26 - 00000000 _____ C:\av.mof
    2017-01-28 13:13 - 2017-01-28 13:13 - 00000000 ____D C:\RegBackup
    2017-01-27 11:03 - 2017-02-03 10:06 - 00000550 _____ C:\WINDOWS\Tasks\Tweaking.com - Windows Repair Tray Icon.job
    2017-01-27 11:03 - 2017-01-27 11:03 - 00001822 _____ C:\Documents and Settings\Robert\Desktop\Tweaking.com - Windows Repair.lnk
    2017-01-27 11:03 - 2017-01-27 11:03 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Tweaking.com
    2017-01-27 11:02 - 2017-01-27 11:03 - 00183308 _____ C:\WINDOWS\Tweaking.com - Windows Repair Setup Log.txt
    2017-01-27 11:02 - 2017-01-27 10:56 - 32836248 _____ (Tweaking.com) C:\Documents and Settings\Robert\Desktop\tweaking.com_windows_repair_aio_setup.exe
    2017-01-26 17:07 - 2017-01-26 17:07 - 00001280 _____ C:\NetworkSettings.txt
    2017-01-26 11:46 - 2017-01-26 11:46 - 00090112 _____ C:\WINDOWS\Minidump\Mini012617-01.dmp
    2017-01-25 18:34 - 2017-01-25 18:35 - 00000345 _____ C:\WINDOWS\OEWABLog.txt
    2017-01-25 16:18 - 2017-01-25 16:13 - 00892416 _____ (Farbar) C:\Documents and Settings\Robert\Desktop\MiniToolBox.exe
    2017-01-25 08:37 - 2017-01-25 08:37 - 00000000 ____D C:\Program Files\Mozilla Firefox
    2017-01-25 08:35 - 2017-01-25 08:35 - 00000000 ____D C:\WINDOWS\Haunted Hotel 6- Ancient Bane Collector's Edition
    2017-01-25 08:25 - 2017-01-25 08:25 - 00321639 _____ C:\Documents and Settings\Robert\My Documents\8EA3F33C--EBEC--2CD6--DC9750D7--B7B643769989.osiris
    2017-01-25 08:25 - 2017-01-25 08:25 - 00142521 _____ C:\Documents and Settings\Robert\My Documents\8EA3F33C--EBEC--2CD6--34079205--A9D3226CA15A.osiris
    2017-01-25 08:25 - 2017-01-25 08:25 - 00113479 _____ C:\Documents and Settings\Robert\Desktop\8EA3F33C--EBEC--2CD6--89660407--3DB49742E42A.osiris
    2017-01-25 08:25 - 2017-01-25 08:25 - 00080104 _____ C:\Documents and Settings\Robert\My Documents\8EA3F33C--EBEC--2CD6--72DE5ACF--D5FE6330098D.osiris
    2017-01-25 08:25 - 2017-01-25 08:25 - 00065898 _____ C:\Documents and Settings\Robert\My Documents\8EA3F33C--EBEC--2CD6--5948EF8C--90EC739DAA88.osiris
    2017-01-25 08:25 - 2017-01-25 08:25 - 00057588 _____ C:\Documents and Settings\Robert\My Documents\8EA3F33C--EBEC--2CD6--55562075--5FF2AF875EFA.osiris
    2017-01-25 08:25 - 2017-01-25 08:25 - 00029789 _____ C:\Documents and Settings\Robert\8EA3F33C--EBEC--2CD6--735A51BC--B0238B6FFC5E.osiris
    2017-01-25 08:25 - 2017-01-25 08:25 - 00018244 _____ C:\Documents and Settings\Robert\8EA3F33C--EBEC--2CD6--4DFA7389--E57C34FEE239.osiris
    2017-01-25 08:25 - 2017-01-25 08:25 - 00009166 _____ C:\OSIRIS-843c.htm
    2017-01-25 08:25 - 2017-01-25 08:25 - 00009166 _____ C:\Documents and Settings\Robert\OSIRIS-4c6a.htm
    2017-01-25 08:25 - 2017-01-25 08:25 - 00009166 _____ C:\Documents and Settings\Robert\My Documents\OSIRIS-ca08.htm
    2017-01-25 08:25 - 2017-01-25 08:25 - 00003152 _____ C:\Documents and Settings\Robert\8EA3F33C--EBEC--2CD6--16066830--3A133EDDB3BC.osiris
    2017-01-25 08:25 - 2017-01-25 08:25 - 00000836 _____ C:\8EA3F33C--EBEC--2CD6--7ED232F7--81EE105CDA45.osiris
    2017-01-20 22:43 - 2017-01-22 16:26 - 00000000 ____D C:\Program Files\Games
    2017-01-19 14:14 - 2017-01-19 14:14 - 00000093 _____ C:\Documents and Settings\Robert\Desktop\Volunteer Invictus Games 2017.URL
    2017-01-15 21:08 - 2017-01-15 21:08 - 05090071 _____ C:\Documents and Settings\Robert\Desktop\Samsung-Galaxy-S5-Neo-Manual.pdf
    2017-01-15 21:05 - 2017-01-15 21:06 - 05154782 _____ C:\Documents and Settings\Robert\My Documents\Samsung-Galaxy-S5-Neo-Manual.pdf
    2017-01-05 21:13 - 2017-01-05 21:14 - 01472740 _____ C:\WINDOWS\Haunted Hotel 6- Ancient Bane Collector's Edition Uninstall Log.txt
    2017-01-05 20:54 - 2017-01-05 21:09 - 03157144 _____ C:\WINDOWS\Haunted Hotel 6- Ancient Bane Collector's Edition Setup Log.txt

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2017-02-03 13:00 - 2015-12-13 21:42 - 00000000 ____D C:\Documents and Settings\Robert\Local Settings\temp
    2017-02-03 12:58 - 2016-06-01 18:09 - 00000120 _____ C:\Documents and Settings\Robert\Desktop\BitHQ.URL
    2017-02-03 12:51 - 2016-07-23 21:38 - 00000122 _____ C:\Documents and Settings\Robert\Desktop\The Horror Charnel Home.URL
    2017-02-03 12:18 - 2010-03-11 22:40 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
    2017-02-03 10:20 - 2010-10-30 13:18 - 00002521 _____ C:\Documents and Settings\Robert\Desktop\Outlook 2007.lnk
    2017-02-03 10:07 - 2010-10-30 13:30 - 00002515 _____ C:\Documents and Settings\Robert\Desktop\Word 2007.lnk
    2017-02-03 10:06 - 2014-03-12 22:32 - 00000224 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
    2017-02-03 10:06 - 2010-03-11 22:40 - 00000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
    2017-02-03 10:06 - 2006-06-03 17:31 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2017-02-03 10:06 - 2004-08-04 07:00 - 00012054 _____ C:\WINDOWS\system32\wpa.dbl
    2017-02-02 22:46 - 2006-06-03 17:32 - 00000278 ___SH C:\Documents and Settings\Robert\ntuser.ini
    2017-02-02 22:46 - 2006-06-03 17:31 - 00032632 _____ C:\WINDOWS\SchedLgU.Txt
    2017-02-02 21:54 - 2006-06-03 12:49 - 00724282 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2017-02-02 21:51 - 2006-06-03 12:47 - 00000281 ___SH C:\boot.ini
    2017-02-02 21:51 - 2004-08-04 07:00 - 00000855 _____ C:\WINDOWS\win.ini
    2017-02-02 21:51 - 2004-08-04 07:00 - 00000227 _____ C:\WINDOWS\system.ini
    2017-02-02 21:50 - 2006-06-03 12:48 - 01708392 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2017-02-02 21:31 - 2006-06-03 17:07 - 00023392 _____ C:\WINDOWS\system32\nscompat.tlb
    2017-02-02 21:31 - 2006-06-03 17:07 - 00016832 _____ C:\WINDOWS\system32\amcompat.tlb
    2017-02-02 19:42 - 2006-06-03 23:10 - 00133064 _____ C:\Documents and Settings\Robert\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2017-01-29 19:34 - 2008-08-16 08:32 - 00000000 ____D C:\Documents and Settings\Robert\Application Data\uTorrent
    2017-01-29 09:31 - 2008-04-21 19:21 - 00002329 _____ C:\Documents and Settings\Robert\Start Menu\Programs\Windows Install Clean Up.lnk
    2017-01-28 15:38 - 2004-08-04 07:00 - 00000855 _____ C:\WINDOWS\system32\Drivers\etc\hosts_bak_470
    2017-01-28 14:23 - 2004-08-04 07:00 - 00000855 _____ C:\WINDOWS\system32\Drivers\etc\hosts_bak_974
    2017-01-28 14:16 - 2006-06-03 17:09 - 00000000 __SHD C:\Documents and Settings\NetworkService
    2017-01-27 18:49 - 2014-05-06 19:07 - 00000000 ____D C:\Documents and Settings\Robert\My Documents\Reflect
    2017-01-27 18:49 - 2006-06-03 12:41 - 00000000 ____D C:\WINDOWS\repair
    2017-01-27 17:02 - 2006-06-03 17:05 - 00000000 ____D C:\WINDOWS\Registration
    2017-01-27 16:56 - 2015-12-14 16:51 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\TEMP
    2017-01-27 09:22 - 2006-06-03 12:48 - 00000000 ____D C:\Documents and Settings
    2017-01-26 11:46 - 2006-12-11 18:21 - 00000000 ____D C:\WINDOWS\Minidump
    2017-01-26 08:08 - 2006-06-03 12:41 - 00000000 ____D C:\WINDOWS\inf
    2017-01-25 08:39 - 2015-01-16 17:03 - 00000000 ____D C:\Documents and Settings\UpdatusUser
    2017-01-25 08:39 - 2011-03-31 17:57 - 00000000 ____D C:\Documents and Settings\Administrator
    2017-01-25 08:39 - 2006-09-03 14:13 - 00000000 ____D C:\Documents and Settings\Guest
    2017-01-25 08:39 - 2006-06-03 17:32 - 00000000 ____D C:\Documents and Settings\Robert
    2017-01-25 08:39 - 2006-06-03 17:31 - 00000000 __SHD C:\Documents and Settings\LocalService
    2017-01-25 08:37 - 2016-02-16 21:08 - 00000000 ____D C:\Program Files\Macrium
    2017-01-25 08:37 - 2013-03-20 17:20 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
    2017-01-25 08:36 - 2006-06-03 17:05 - 00000000 ____D C:\WINDOWS\system32\Macromed
    2017-01-25 08:25 - 2015-03-17 19:19 - 00000000 ___RD C:\Documents and Settings\Robert\My Documents\Dropbox
    2017-01-25 08:25 - 2008-05-15 22:53 - 00000000 ____D C:\watcom-1.3
    2017-01-25 08:25 - 2007-07-23 17:05 - 00000000 ____D C:\Documents and Settings\Robert\Collectorz Print lists
    2017-01-25 08:25 - 2007-02-16 20:05 - 00000000 ____D C:\Documents and Settings\Robert\My Documents\Movie Collector
    2017-01-25 08:25 - 2006-06-03 17:32 - 00000000 ___RD C:\Documents and Settings\Robert\My Documents
    2017-01-24 20:48 - 2006-06-03 17:32 - 00000000 ___RD C:\Documents and Settings\Robert\My Documents\My Pictures
    2017-01-24 12:15 - 2006-06-03 12:41 - 00000000 RSHDC C:\WINDOWS\system32\dllcache
    2017-01-22 21:13 - 2014-04-17 20:09 - 00000000 ____D C:\Documents and Settings\Robert\Application Data\Elephant Games
    2017-01-21 19:59 - 2016-03-28 11:48 - 00000284 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
    2017-01-12 16:25 - 2012-08-13 15:23 - 00802904 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
    2017-01-12 16:25 - 2012-08-13 15:23 - 00144472 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
    2017-01-12 16:25 - 2006-06-10 07:50 - 00000000 ____D C:\Documents and Settings\Robert\Local Settings\Application Data\Adobe
    2017-01-11 19:24 - 2016-02-24 17:45 - 00000926 _____ C:\Documents and Settings\All Users\Desktop\Movie Collector.lnk

    ==================== Files in the root of some directories =======

    2016-06-22 18:40 - 2016-06-22 18:40 - 0003072 _____ () C:\Documents and Settings\Robert\Application Data\.spark_db
    2014-04-02 21:28 - 2014-04-02 21:30 - 0009333 _____ () C:\Documents and Settings\Robert\Application Data\Comma Separated Values (Windows).EML
    2007-03-23 16:38 - 2007-07-21 12:39 - 0087608 _____ () C:\Documents and Settings\Robert\Application Data\ezpinst.exe
    2008-08-30 11:14 - 2010-01-03 19:51 - 0000108 _____ () C:\Documents and Settings\Robert\Application Data\netstat.bat
    2007-03-23 16:38 - 2011-04-10 14:47 - 0007887 _____ () C:\Documents and Settings\Robert\Application Data\pcouffin.cat
    2007-03-23 16:38 - 2011-04-10 14:47 - 0001144 _____ () C:\Documents and Settings\Robert\Application Data\pcouffin.inf
    2007-03-23 16:38 - 2011-04-10 14:48 - 0000033 _____ () C:\Documents and Settings\Robert\Application Data\pcouffin.log
    2007-03-23 16:38 - 2011-04-10 14:47 - 0047360 _____ (VSO Software) C:\Documents and Settings\Robert\Application Data\pcouffin.sys
    2008-07-05 10:41 - 2008-07-05 10:41 - 0002494 _____ () C:\Documents and Settings\Robert\Application Data\sldIMLog_20080-40000-1100_00002.txt
    2010-10-24 16:36 - 2010-10-24 16:36 - 0000036 _____ () C:\Documents and Settings\Robert\Local Settings\Application Data\housecall.guid.cache
    2009-09-24 17:41 - 2009-09-24 17:41 - 5257216 _____ () C:\Documents and Settings\Robert\Local Settings\Application Data\mfm2_database.dat
    2007-08-25 13:19 - 2007-08-25 13:19 - 0002108 _____ () C:\Documents and Settings\Robert\Local Settings\Application Data\rx_audio.Cache
    2007-01-25 22:46 - 2007-12-03 19:42 - 1462572 _____ () C:\Documents and Settings\Robert\Local Settings\Application Data\rx_image.Cache
    2007-11-25 22:46 - 2016-10-31 17:27 - 0000123 ___SH () C:\Documents and Settings\All Users\Application Data\.zreglib
    2013-09-14 19:49 - 2013-09-14 19:49 - 0000057 _____ () C:\Documents and Settings\All Users\Application Data\Ament.ini
    2008-03-02 15:30 - 2008-08-29 17:51 - 0110892 _____ () C:\Documents and Settings\All Users\Application Data\Svclog.log

    Files to move or delete:
    ====================
    C:\Documents and Settings\Robert\mylist.dat


    ==================== Bamital & volsnap ======================

    (There is no automatic fix for files that do not pass verification.)

    C:\WINDOWS\explorer.exe => File is digitally signed
    C:\WINDOWS\system32\winlogon.exe => File is digitally signed
    C:\WINDOWS\system32\svchost.exe => File is digitally signed
    C:\WINDOWS\system32\services.exe => File is digitally signed
    C:\WINDOWS\system32\User32.dll => File is digitally signed
    C:\WINDOWS\system32\userinit.exe => File is digitally signed
    C:\WINDOWS\system32\rpcss.dll => File is digitally signed
    C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
    C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

    ==================== End of FRST.txt ============================

     

     

    Additional scan result of Farbar Recovery Scan Tool (x86) Version: 29-01-2017
    Ran by Robert (03-02-2017 13:01:15)
    Running from C:\Documents and Settings\Robert\Desktop
    Microsoft Windows XP Home Edition Service Pack 3 (X86) (2015-01-06 17:20:53)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-299502267-789336058-725345543-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator
    ASPNET (S-1-5-21-299502267-789336058-725345543-1013 - Limited - Enabled)
    Guest (S-1-5-21-299502267-789336058-725345543-501 - Limited - Disabled) => %SystemDrive%\Documents and Settings\Guest
    HelpAssistant (S-1-5-21-299502267-789336058-725345543-1000 - Limited - Disabled)
    Robert (S-1-5-21-299502267-789336058-725345543-1004 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Robert
    SUPPORT_388945a0 (S-1-5-21-299502267-789336058-725345543-1002 - Limited - Disabled)
    UpdatusUser (S-1-5-21-299502267-789336058-725345543-1014 - Limited - Enabled) => %SystemDrive%\Documents and Settings\UpdatusUser

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)


    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    µTorrent (HKLM\...\uTorrent) (Version: 2.0.3 - )
    Acronis True Image Home (HKLM\...\{37C8899D-FD70-481F-94AA-1F1B08765E22}) (Version: 12.0.9709 - Acronis)
    Adobe Acrobat XI Pro (HKLM\...\{AC76BA86-1033-FFFF-7760-000000000006}) (Version: 11.0.09 - Adobe Systems)
    Adobe Color Common Settings (HKLM\...\Adobe_6c8e2cb4fd241c55406016127a6ab2e) (Version: 1.0.1 - Adobe Systems Incorporated)
    Adobe Download Manager (HKLM\...\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}) (Version: 1.6.2.91 - NOS Microsystems Ltd.)
    Adobe ExtendScript Toolkit 2 (HKLM\...\Adobe_3e054d2218e7aa282c2369d939e58ff) (Version: 2.0.2 - Adobe Systems Incorporated)
    Adobe Flash Player 21 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 21.0.0.197 - Adobe Systems Incorporated)
    Adobe Flash Player 24 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated)
    Adobe Photoshop CS3 (HKLM\...\Adobe_719d6f144d0c086a0dfa7ff76bb9ac1) (Version: 10.0 - Adobe Systems Incorporated)
    Amnesia - The Dark Descent  (HKLM\...\{54B7A3C7-0940-4C16-A509-FC3C3758D22A}_is1) (Version: 1.0.0 - Frictional Games)
    AnyDVD (HKLM\...\AnyDVD) (Version: 8.0.5.0 - RedFox)
    Apple Application Support (HKLM\...\{EE6097DD-05F4-4178-9719-D3170BF098E8}) (Version: 1.4.1 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{308B6AEA-DE50-4666-996D-0FA461719D6B}) (Version: 3.3.0.69 - Apple Inc.)
    Apple Software Update (HKLM\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
    AVIcodec (remove only) (HKLM\...\AVIcodec) (Version:  - )
    Beyond Compare Version 2.4.3 (HKLM\...\BC2_is1) (Version:  - Scooter Software)
    Canon MG5700 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5700_series) (Version: 1.00 - Canon Inc.)
    CCleaner (HKLM\...\CCleaner) (Version: 5.14 - Piriform)
    CloneDVD2 (HKLM\...\CloneDVD2) (Version:  - Elaborate Bytes)
    Collectorz.com Movie Collector (HKLM\...\Collectorz.com Movie Collector) (Version:  - )
    Compatibility Pack for the 2007 Office system (HKLM\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
    CoreFLAC Audio Decoder+Source Filter (remove only) (HKLM\...\CoreFLAC Audio Decoder+Source Filter) (Version:  - )
    Corel Painter X (Version: 10.1 - Corel Corporation) Hidden
    COSMOSMotion 2008 SP0 (HKLM\...\{8876F541-F374-4375-BF2A-8FD9FA8141C4}) (Version: 16.00.9035 - SolidWorks Corporation)
    COSMOSWorks 2008 SP03 (HKLM\...\{0C631AC5-3AA0-418F-B132-29F8432F1C19}) (Version: 16.30.41 - SolidWorks Corporation)
    Data Lifeguard Diagnostic for Windows 1.24 (HKLM\...\{519C4DB6-B53B-4F5C-8297-89B2BE949FA5}_is1) (Version:  - Western Digital Corporation)
    Dolphin Futures XPS Viewer version 1.1.0 (HKLM\...\{75480068-162F-4D6B-B38E-76606A4E5320}_is1) (Version: 1.1.0 - Dolphin Futures Limited)
    DVD Decrypter (Remove Only) (HKLM\...\DVD Decrypter) (Version:  - )
    DVD Rebuilder (HKLM\...\{584A1ECC-00AB-4FCC-B6AE-172741F32ABC}_is1) (Version: PRO v1.09 - jdobbs softworks and rockas association)
    DVD Shrink 3.2 (HKLM\...\DVD Shrink_is1) (Version:  - DVD Shrink)
    DVDFab 8.1.7.8 (17/04/2012) Qt (HKLM\...\DVDFab 8 Qt_is1) (Version:  - Fengtao Software Inc.)
    DVDFab 9.2.0.2 (10/06/2015) (HKLM\...\DVDFab 9_is1) (Version:  - Fengtao Software Inc.)
    DVDInfoPro (HKLM\...\{32611C62-474D-47B1-B347-06453D430A28}) (Version: 4.36.0000 - Nic Wilson)
    DWGeditor (HKLM\...\{C8DE0FC9-5BD0-4D26-B5AD-D38146F2083C}) (Version: 16.00.9034 - SolidWorks)
    Easy CD-DA Extractor 2011 (HKLM\...\Easy CD-DA Extractor 2011) (Version: 2011 - Poikosoft)
    eDrawings 2008 (HKLM\...\{40345A8F-3B72-44DE-814F-72E8A52B1161}) (Version: 8.0.708 - SolidWorks)
    ERUNT 1.1j (HKLM\...\ERUNT_is1) (Version:  - Lars Hederer)
    Exact Audio Copy 0.99pb5 (HKLM\...\Exact Audio Copy) (Version: 0.99pb5 - Andre Wiethoff)
    GoldWave v5.13 (HKLM\...\GoldWave v5.13) (Version:  - )
    Google Update Helper (Version: 1.3.32.7 - Google Inc.) Hidden
    HPDiagnosticAlert (Version: 1.00.0001 - Microsoft) Hidden
    ImageConverter Plus 7.1 (HKLM\...\ImageConverter Plus_is1) (Version:  - fCoder, Ltd.)
    ImgBurn (HKLM\...\ImgBurn) (Version: 2.5.6.0 - LIGHTNING UK!)
    Intel Processor Diagnostic Tool (HKLM\...\{C53C4130-CC50-40F3-9457-A7D4A2B980BC}) (Version: 2.11.0.0 - Intel Corporation)
    IsoBuster 3.6 (HKLM\...\IsoBuster_is1) (Version: 3.6 - Smart Projects)
    K-Lite Mega Codec Pack 10.9.5 (HKLM\...\KLiteCodecPack_is1) (Version: 10.9.5 - )
    Kyodai Mahjongg 2006 v1.42 (HKLM\...\Kyodai Mahjongg 2006_is1) (Version:  - Rene-Gilles Deberdt)
    Macrium Reflect Home Edition (HKLM\...\MacriumReflect) (Version: 6.1 - Paramount Software (UK) Ltd.)
    Macrium Reflect Home Edition (Version: 6.1.1000 - Paramount Software (UK) Ltd.) Hidden
    Maple 12 (HKLM\...\Maple 12) (Version: 12.0.0.0 - Maplesoft)
    Marvell Miniport Driver (HKLM\...\{C950420B-4182-49EA-850A-A6A2ABF06C6B}) (Version: 8.20.10.3 - Marvell)
    MathType 5 (HKLM\...\DSMT5) (Version: 5.2 - Design Science, Inc.)
    Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
    Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version:  - )
    Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version:  - )
    Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version:  - )
    Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
    Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
    Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
    Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
    Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
    Microsoft Math (HKLM\...\{07043840-959A-4B0D-8825-2C533F0DDB19}) (Version: 2007 - Microsoft Corporation)
    Microsoft Office 2003 Web Components (HKLM\...\{90120000-00A4-0409-0000-0000000FF1CE}) (Version: 12.0.6213.1000 - Microsoft Corporation)
    Microsoft Office 2007 Primary Interop Assemblies (HKLM\...\{50120000-1105-0000-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation)
    Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
    Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
    Microsoft Office Project 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{8446EB22-A746-46DC-B1BD-E0DFA1F3CDDA}) (Version:  - Microsoft)
    Microsoft Office Project Professional 2007 (HKLM\...\PRJPRO) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Office Visio 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{CE144BF4-4950-4CDB-A5F7-CCE1888F49CB}) (Version:  - Microsoft)
    Microsoft Office Visio Professional 2007 (HKLM\...\VISPRO) (Version: 12.0.6612.1000 - Microsoft Corporation)
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual Studio 2005 Tools for Office Runtime (HKLM\...\Microsoft Visual Studio 2005 Tools for Office Runtime) (Version:  - Microsoft Corporation)
    Movie Collector (HKLM\...\{8EC6EBB4-D899-4C6B-BA17-C21B78988F23}_is1) (Version:  - Collectorz.com)
    Mozilla Firefox 50.1.0 (x86 en-US) (HKLM\...\Mozilla Firefox 50.1.0 (x86 en-US)) (Version: 50.1.0 - Mozilla)
    Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 50.1.0.6186 - Mozilla)
    MSConfig CleanUp 1.2 (HKLM\...\MSConfig CleanUp_is1) (Version:  - Virtuoza)
    MSXML 4.0 SP2 (KB925672) (HKLM\...\{A9CF9052-F4A0-475D-A00F-A8388C62DD63}) (Version: 4.20.9839.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB927978) (HKLM\...\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
    MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
    MSXML 4.0 SP2 and SOAP Toolkit 3.0 (Version: 1.0.0.0 - Webroot Software, Inc.) Hidden
    MSXML 4.0 SP2 Parser and SDK (HKLM\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
    MSXML 6 Service Pack 2 (KB973686) (HKLM\...\{56EA8BC0-3751-4B93-BC9D-6651CC36E5AA}) (Version: 6.20.2003.0 - Microsoft Corporation)
    Nero 7 Ultra Edition (HKLM\...\{43FFE159-3199-4188-A1CD-629166AD1033}) (Version: 7.02.6445 - Nero AG)
    NOD32 v3.0.642 FiX1.2 by TemDono (31 days remaining forever up  (HKLM\...\Eset NOD32 v3.0.642 FiX1.2 by TemDono_is1) (Version:  - )
    NOD32 v3.x FiX 1.1 by TemDono (Free Updates - Expire in 2050) (HKLM\...\NOD32 v3.x FiX 1.1 by TemDono_is1) (Version:  - )
    NVIDIA Graphics Driver 307.83 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 307.83 - NVIDIA Corporation)
    NVIDIA nView 136.53 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView) (Version: 136.53 - NVIDIA Corporation)
    NVIDIA Update 1.10.8 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation)
    OJ4620FWUpdateAlert (Version: 1.00.0000 - HP) Hidden
    OriginPro 7.5 (HKLM\...\{ECE12161-B445-48FA-9056-FD54D8A72459}) (Version:  - )
    PC Probe II (HKLM\...\{F7338FA3-DAB5-49B2-900D-0AFB5760C166}) (Version: 1.00.43 - )
    PDF Settings (Version: 1.0 - Adobe Systems Incorporated) Hidden
    PerfectDisk Professional Business (HKLM\...\{682B22AB-EAAA-4B1C-83AF-B26E7D4ED01E}) (Version: 13.0.842 - Raxco Software Inc.)
    PFConfig 1.0.296 (HKLM\...\PFConfig) (Version: 1.0.296 - Portforward.com)
    PFPortChecker 1.0.39 (HKLM\...\PFPortChecker) (Version: 1.0.39 - Portforward.com)
    Photodex Presenter (HKLM\...\Photodex Presenter) (Version:  - )
    Picture Package Music Transfer (HKLM\...\{CE2121C6-C94D-4A73-8EA4-6943F33EE335}) (Version: 1.0.02.02130 - Sony Corporation)
    Portforward Static IP Address 1.0.47 (HKLM\...\Portforward Static IP Address) (Version: 1.0.47 - Portforward.com)
    ProShow Producer (HKLM\...\ProShow Producer) (Version:  - )
    Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 5.10.0.7111 - Realtek Semiconductor Corp.)
    River Past Audio Converter Pro (HKLM\...\Audio Converter Pro) (Version: 7.7.1 - River Past)
    SigmaPlot 10.0 (HKLM\...\{43224D30-5941-47A4-9AD7-9250EE794396}) (Version: 10.0.0 - Systat Software, Inc.)
    SolidWorks 2008 SP03 (HKLM\...\{266EB766-9ABB-40D0-AB9F-41EE46D23876}) (Version: 16.1.0303 - SolidWorks)
    SolidWorks Explorer 2008 sp0 (HKLM\...\{A8567E18-9E80-4EA3-A5C1-A6186C86F2CC}) (Version: 16.00.9034 - SolidWorks Corporation)
    Spy Sweeper Updater 2.0.0 Alpha 4000 (HKLM\...\Spy Sweeper Updater 2.0.0 Alpha 4000) (Version: 2.0.0 Alpha 4000 - BigScott27)
    Sudoku Works (HKLM\...\{5B10C186-C6CF-45D8-9E2D-4F18247A5C63}) (Version: 1.0 - Oak Systems)
    System Requirements Lab (HKLM\...\SystemRequirementsLab) (Version:  - )
    Tetris (HKLM\...\{95E0E6DC-C308-4C96-BEDB-68C75A32FAF8}_is1) (Version: 1.35 - Crystal Office Systems)
    Tweaking.com - Windows Repair (HKLM\...\Tweaking.com - Windows Repair) (Version: 3.9.24 - Tweaking.com)
    Unlocker 1.8.9 (HKLM\...\Unlocker) (Version: 1.8.9 - Cedrick Collomb)
    Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
    Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-003B-0000-0000-0000000FF1CE}_PRJPRO_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
    Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
    VBA (2627.01) (Version: 6.03.00.9402 - Microsoft Corporation) Hidden
    VC 9.0 Runtime (Version: 1.0.0 - Check Point Software Technologies Ltd) Hidden
    VC80CRTRedist - 8.0.50727.762 (Version: 1.0.0 - DivX, Inc) Hidden
    VCRedistSetup (Version: 1.0.0 - Nero AG) Hidden
    Visual C++ 2008 x86 Runtime - v9.0.30729.01 (HKLM\...\{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01) (Version: 9.0.30729.01 - Microsoft Corporation)
    WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
    Window Washer (HKLM\...\Window Washer) (Version:  - )
    Windows Defender (HKLM\...\{A06275F4-324B-4E85-95E6-87B2CD729401}) (Version: 1.1.1593.0 - Microsoft Corporation)
    Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\WGA) (Version: 1.7.0069.2 - Microsoft Corporation)
    Windows Installer Clean Up (HKLM\...\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}) (Version: 3.00.00.0000 - Microsoft Corporation)
    Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation)
    Windows Management Framework Core (HKLM\...\KB968930) (Version:  - Microsoft Corporation)
    Windows Media Format Runtime (HKLM\...\Windows Media Format Runtime) (Version:  - )
    Windows Media Player 11 (HKLM\...\Windows Media Player) (Version:  - )
    Windows PowerShell™ 1.0 (HKLM\...\PowerShell) (Version: 1 - Microsoft Corporation)
    Windows XP Service Pack 3 (HKLM\...\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
    WinRAR archiver (HKLM\...\WinRAR archiver) (Version:  - )
    XML Paper Specification Shared Components Pack 1.0 (Version:  - Microsoft Corporation) Hidden
    Your Uninstaller! 2010 (HKLM\...\YU2010_is1) (Version: 7.0 - URSoft, Inc.)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-299502267-789336058-725345543-1004_Classes\CLSID\{0000002F-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-299502267-789336058-725345543-1004_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-299502267-789336058-725345543-1004_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-299502267-789336058-725345543-1004_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-299502267-789336058-725345543-1004_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-299502267-789336058-725345543-1004_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-299502267-789336058-725345543-1004_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-299502267-789336058-725345543-1004_Classes\CLSID\{0002E005-0000-0000-C000-000000000046}\InprocServer32 -> C:\WINDOWS\system32\OLE32.DLL (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-299502267-789336058-725345543-1004_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Documents and Settings\Robert\Application Data\Dropbox\bin\Dropbox.exe /autoplay => No File
    CustomCLSID: HKU\S-1-5-21-299502267-789336058-725345543-1004_Classes\CLSID\{026371C0-1B7C-11CF-9D53-00AA003C9CB6}\InprocServer32 -> C:\WINDOWS\System32\ComCt232.ocx (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-299502267-789336058-725345543-1004_Classes\CLSID\{0BE35203-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-299502267-789336058-725345543-1004_Classes\CLSID\{0BE35204-8F91-11CE-9DE3-00AA004BB851}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-299502267-789336058-725345543-1004_Classes\CLSID\{1E216240-1B7D-11CF-9D53-00AA003C9CB6}\InprocServer32 -> C:\WINDOWS\System32\ComCt232.ocx (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-299502267-789336058-725345543-1004_Classes\CLSID\{46763EE0-CAB2-11CE-8C20-00AA0051E5D4}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-299502267-789336058-725345543-1004_Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32 -> C:\WINDOWS\system32\oleaut32.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-299502267-789336058-725345543-1004_Classes\CLSID\{D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731}\InprocServer32 -> C:\WINDOWS\System32\msvbvm60.dll (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-299502267-789336058-725345543-1004_Classes\CLSID\{E69341A3-E6D2-4175-B60C-C9D3D6FA40F6}\localserver32 -> C:\Documents and Settings\Robert\Application Data\Dropbox\bin\Dropbox.exe /wiacallback => No File

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\WINDOWS\Tasks\AppleSoftwareUpdate.job => C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe
    Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe
    Task: C:\WINDOWS\Tasks\Tweaking.com - Windows Repair Tray Icon.job => C:\Program Files\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe C:\Program Files\Tweaking.com\Windows Repair (All in One) Tweaking.com - Windows Repair )Created By Tweaking.com

    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)

    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\AVIcodec\Website.lnk -> hxxp://avicodec.duby.inf

    ==================== Loaded Modules (Whitelisted) ==============

    2010-03-08 21:55 - 2010-03-08 21:55 - 00010752 _____ () C:\Program Files\Unlocker\UnlockerCOM.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)

    AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:1CE11B51 [173]
    AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:28BEC2EC [115]
    AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:5D351BC6 [94]

    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppXSvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ClipSvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TweakingRemoveSafeBoot => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WSService => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppXSvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BITS => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ClipSvc => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\msiserver => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SamSs => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv2 => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srvnet => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TweakingRemoveSafeBoot => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vss => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WSService => ""="Service"

    ==================== Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)

    HKU\S-1-5-21-299502267-789336058-725345543-1004\Software\Classes\exefile: "%1" %* <===== ATTENTION
    HKU\S-1-5-21-299502267-789336058-725345543-1004\Software\Classes\scrfile: "%1" /S <===== ATTENTION
    HKU\S-1-5-21-299502267-789336058-725345543-1004\Software\Classes\.cmd: cmdfile =>  <===== ATTENTION
    HKU\S-1-5-21-299502267-789336058-725345543-1004\Software\Classes\.reg: regfile =>  <===== ATTENTION

    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)

    IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
    IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
    IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
    IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
    IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
    IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
    IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
    IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
    IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
    IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
    IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
    IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
    IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
    IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
    IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
    IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
    IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
    IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
    IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
    IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com

    There are 7832 more sites.

    IE restricted site: HKU\S-1-5-19\...\007guard.com -> install.007guard.com
    IE restricted site: HKU\S-1-5-19\...\008i.com -> 008i.com
    IE restricted site: HKU\S-1-5-19\...\008k.com -> www.008k.com
    IE restricted site: HKU\S-1-5-19\...\00hq.com -> www.00hq.com
    IE restricted site: HKU\S-1-5-19\...\010402.com -> 010402.com
    IE restricted site: HKU\S-1-5-19\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
    IE restricted site: HKU\S-1-5-19\...\1-domains-registrations.com -> www.1-domains-registrations.com
    IE restricted site: HKU\S-1-5-19\...\1-extreme.biz -> www.1-extreme.biz
    IE restricted site: HKU\S-1-5-19\...\1001-search.info -> www.1001-search.info
    IE restricted site: HKU\S-1-5-19\...\100888290cs.com -> mir.100888290cs.com
    IE restricted site: HKU\S-1-5-19\...\100sexlinks.com -> www.100sexlinks.com
    IE restricted site: HKU\S-1-5-19\...\10sek.com -> www.10sek.com
    IE restricted site: HKU\S-1-5-19\...\123topsearch.com -> www.123topsearch.com
    IE restricted site: HKU\S-1-5-19\...\132.com -> www.132.com
    IE restricted site: HKU\S-1-5-19\...\136136.net -> down.136136.net
    IE restricted site: HKU\S-1-5-19\...\139mm.com -> www.139mm.com
    IE restricted site: HKU\S-1-5-19\...\163.com -> www.163.com
    IE restricted site: HKU\S-1-5-19\...\163ns.com -> ert0003.e76.163ns.com
    IE restricted site: HKU\S-1-5-19\...\17-plus.com -> 17-plus.com
    IE restricted site: HKU\S-1-5-19\...\171203.com -> 171203.com

    There are 4190 more sites.

    IE restricted site: HKU\S-1-5-20\...\007guard.com -> install.007guard.com
    IE restricted site: HKU\S-1-5-20\...\008i.com -> 008i.com
    IE restricted site: HKU\S-1-5-20\...\008k.com -> www.008k.com
    IE restricted site: HKU\S-1-5-20\...\00hq.com -> www.00hq.com
    IE restricted site: HKU\S-1-5-20\...\010402.com -> 010402.com
    IE restricted site: HKU\S-1-5-20\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
    IE restricted site: HKU\S-1-5-20\...\1-domains-registrations.com -> www.1-domains-registrations.com
    IE restricted site: HKU\S-1-5-20\...\1-extreme.biz -> www.1-extreme.biz
    IE restricted site: HKU\S-1-5-20\...\1001-search.info -> www.1001-search.info
    IE restricted site: HKU\S-1-5-20\...\100888290cs.com -> mir.100888290cs.com
    IE restricted site: HKU\S-1-5-20\...\100sexlinks.com -> www.100sexlinks.com
    IE restricted site: HKU\S-1-5-20\...\10sek.com -> www.10sek.com
    IE restricted site: HKU\S-1-5-20\...\123topsearch.com -> www.123topsearch.com
    IE restricted site: HKU\S-1-5-20\...\132.com -> www.132.com
    IE restricted site: HKU\S-1-5-20\...\136136.net -> down.136136.net
    IE restricted site: HKU\S-1-5-20\...\139mm.com -> www.139mm.com
    IE restricted site: HKU\S-1-5-20\...\163.com -> www.163.com
    IE restricted site: HKU\S-1-5-20\...\163ns.com -> ert0003.e76.163ns.com
    IE restricted site: HKU\S-1-5-20\...\17-plus.com -> 17-plus.com
    IE restricted site: HKU\S-1-5-20\...\171203.com -> 171203.com

    There are 4190 more sites.

    IE restricted site: HKU\S-1-5-21-299502267-789336058-725345543-1004\...\007guard.com -> install.007guard.com
    IE restricted site: HKU\S-1-5-21-299502267-789336058-725345543-1004\...\008i.com -> 008i.com
    IE restricted site: HKU\S-1-5-21-299502267-789336058-725345543-1004\...\008k.com -> www.008k.com
    IE restricted site: HKU\S-1-5-21-299502267-789336058-725345543-1004\...\00hq.com -> www.00hq.com
    IE restricted site: HKU\S-1-5-21-299502267-789336058-725345543-1004\...\010402.com -> 010402.com
    IE restricted site: HKU\S-1-5-21-299502267-789336058-725345543-1004\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
    IE restricted site: HKU\S-1-5-21-299502267-789336058-725345543-1004\...\0scan.com -> www.0scan.com
    IE restricted site: HKU\S-1-5-21-299502267-789336058-725345543-1004\...\1-2005-search.com -> www.1-2005-search.com
    IE restricted site: HKU\S-1-5-21-299502267-789336058-725345543-1004\...\1-domains-registrations.com -> www.1-domains-registrations.com
    IE restricted site: HKU\S-1-5-21-299502267-789336058-725345543-1004\...\1000gratisproben.com -> www.1000gratisproben.com
    IE restricted site: HKU\S-1-5-21-299502267-789336058-725345543-1004\...\1001namen.com -> www.1001namen.com
    IE restricted site: HKU\S-1-5-21-299502267-789336058-725345543-1004\...\100888290cs.com -> mir.100888290cs.com
    IE restricted site: HKU\S-1-5-21-299502267-789336058-725345543-1004\...\100sexlinks.com -> www.100sexlinks.com
    IE restricted site: HKU\S-1-5-21-299502267-789336058-725345543-1004\...\10sek.com -> www.10sek.com
    IE restricted site: HKU\S-1-5-21-299502267-789336058-725345543-1004\...\12-26.net -> user1.12-26.net
    IE restricted site: HKU\S-1-5-21-299502267-789336058-725345543-1004\...\12-27.net -> user1.12-27.net
    IE restricted site: HKU\S-1-5-21-299502267-789336058-725345543-1004\...\123fporn.info -> www.123fporn.info
    IE restricted site: HKU\S-1-5-21-299502267-789336058-725345543-1004\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
    IE restricted site: HKU\S-1-5-21-299502267-789336058-725345543-1004\...\123moviedownload.com -> www.123moviedownload.com
    IE restricted site: HKU\S-1-5-21-299502267-789336058-725345543-1004\...\123simsen.com -> www.123simsen.com

    There are 7794 more sites.


    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2004-08-04 07:00 - 2017-02-02 21:32 - 00000855 ____A C:\WINDOWS\system32\Drivers\etc\hosts

    127.0.0.1       localhost

    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-299502267-789336058-725345543-1004\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\Robert\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
    DNS Servers: 192.168.2.1
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    MSCONFIG\startupreg: Acrobat Assistant 8.0 => "C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe"
    MSCONFIG\startupreg: Adobe ARM => "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    MSCONFIG\startupreg: ctfmon.exe => C:\WINDOWS\system32\ctfmon.exe
    MSCONFIG\startupreg: KernelFaultCheck => %systemroot%\system32\dumprep 0 -k
    MSCONFIG\startupreg: NvCplDaemon => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    MSCONFIG\startupreg: NvMediaCenter => RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
    MSCONFIG\startupreg: nwiz => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe /installquiet
    MSCONFIG\startupreg: RTHDCPL => RTHDCPL.EXE
    MSCONFIG\startupreg: SkyTel => SkyTel.EXE

    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    StandardProfile\AuthorizedApplications: [C:\Program Files\uTorrent\uTorrent.exe] => Enabled:µTorrent
    StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Robert\Local Settings\Temp\7zSC2.tmp\SymNRT.exe] => Enabled:Norton Removal Tool
    StandardProfile\AuthorizedApplications: [C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe] => Enabled:Daemonu.exe
    StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Robert\Local Settings\Temp\7zS2FC2\HPDiagnosticCoreUI.exe] => Enabled:HPSAPS
    StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Robert\Local Settings\Temp\7zS333D\HPDiagnosticCoreUI.exe] => Enabled:HPSAPS
    StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Robert\Local Settings\Temp\7zS352D\HPDiagnosticCoreUI.exe] => Enabled:HPSAPS
    StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Robert\Local Settings\Temp\7zS0DA0\HPDiagnosticCoreUI.exe] => Enabled:HPSAPS
    StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Robert\Local Settings\Temp\7zS71B5\HPDiagnosticCoreUI.exe] => Enabled:HPSAPS
    StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Robert\Local Settings\Temp\7zS5311\HPDiagnosticCoreUI.exe] => Enabled:HPSAPS
    StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Robert\Local Settings\Temp\7zS1A7F\HPDiagnosticCoreUI.exe] => Enabled:HPSAPS
    StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Robert\Local Settings\Temp\7zS7A19\HPDiagnosticCoreUI.exe] => Enabled:HPSAPS
    StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Robert\Local Settings\Temp\7zS7A61\HPDiagnosticCoreUI.exe] => Enabled:HPSAPS
    StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Robert\Local Settings\Temp\7zS7CF2\HPDiagnosticCoreUI.exe] => Enabled:HPSAPS
    StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Robert\Local Settings\Temp\7zS1717\HPDiagnosticCoreUI.exe] => Enabled:HPSAPS
    StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Robert\Local Settings\Temp\7zS18B2\HPDiagnosticCoreUI.exe] => Enabled:HPSAPS
    StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Robert\Local Settings\Temp\7zS47BD\HPDiagnosticCoreUI.exe] => Enabled:HPSAPS
    StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Robert\Local Settings\Temp\7zS4802\HPDiagnosticCoreUI.exe] => Enabled:HPSAPS
    StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Robert\Local Settings\temp\7zS6464\HPDiagnosticCoreUI.exe] => Enabled:HPSAPS
    StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Robert\Local Settings\temp\7zS67D6\HPDiagnosticCoreUI.exe] => Enabled:HPSAPS
    StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Robert\Local Settings\temp\7zS05C3\HPDiagnosticCoreUI.exe] => Enabled:HPSAPS
    StandardProfile\AuthorizedApplications: [C:\Documents and Settings\Robert\Local Settings\temp\7zS2B9F\HPDiagnosticCoreUI.exe] => Enabled:HPSAPS
    StandardProfile\AuthorizedApplications: [C:\Program Files\Bonjour\mDNSResponder.exe] => Enabled:Bonjour Service
    StandardProfile\AuthorizedApplications: [C:\Program Files\Popcorn Time\Updater.exe] => Enabled:Updater.exe
    StandardProfile\AuthorizedApplications: [C:\Program Files\Mozilla Firefox\firefox.exe] => Enabled:Firefox (C:\Program Files\Mozilla Firefox)
    StandardProfile\GloballyOpenPorts: [139:TCP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22004
    StandardProfile\GloballyOpenPorts: [445:TCP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22005
    StandardProfile\GloballyOpenPorts: [137:UDP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22001
    StandardProfile\GloballyOpenPorts: [138:UDP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22002
    StandardProfile\GloballyOpenPorts: [1900:UDP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22007
    StandardProfile\GloballyOpenPorts: [2869:TCP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22008
    StandardProfile\GloballyOpenPorts: [5985:TCP] => Disabled:Windows Remote Management
    StandardProfile\GloballyOpenPorts: [80:TCP] => Disabled:Windows Remote Management - Compatibility Mode (HTTP-In)

    ==================== Restore Points =========================

    06-11-2016 10:09:31 System Checkpoint
    07-11-2016 17:00:04 System Checkpoint
    08-11-2016 17:11:04 System Checkpoint
    09-11-2016 18:27:40 System Checkpoint
    11-11-2016 19:19:11 System Checkpoint
    15-11-2016 18:12:30 System Checkpoint
    16-11-2016 22:39:02 System Checkpoint
    17-11-2016 22:50:53 System Checkpoint
    19-11-2016 14:30:54 System Checkpoint
    21-11-2016 17:38:55 System Checkpoint
    23-11-2016 06:54:07 System Checkpoint
    24-11-2016 18:22:14 System Checkpoint
    26-11-2016 12:47:38 System Checkpoint
    27-11-2016 18:00:26 System Checkpoint
    28-11-2016 19:45:11 System Checkpoint
    29-11-2016 20:23:28 System Checkpoint
    03-01-2017 19:21:53 System Checkpoint
    05-01-2017 17:40:20 System Checkpoint
    09-01-2017 22:20:43 System Checkpoint
    11-01-2017 07:03:30 System Checkpoint
    12-01-2017 17:42:30 System Checkpoint
    13-01-2017 21:52:20 System Checkpoint
    15-01-2017 02:34:27 System Checkpoint
    16-01-2017 18:28:24 System Checkpoint
    18-01-2017 11:27:13 System Checkpoint
    20-01-2017 08:52:17 System Checkpoint
    21-01-2017 10:22:58 System Checkpoint
    22-01-2017 13:52:55 System Checkpoint
    24-01-2017 08:40:57 Removed ESET NOD32 Antivirus
    24-01-2017 08:41:45 Installed ESET NOD32 Antivirus
    24-01-2017 12:10:33 Restore Operation
    24-01-2017 12:16:50 Restore Operation
    24-01-2017 12:24:44 Before uninstalling ESET NOD32 Antivirus
    24-01-2017 13:51:14 Restore Operation
    24-01-2017 15:01:29 Restore Operation
    24-01-2017 17:02:08 Restore Operation
    24-01-2017 17:41:46 Before uninstalling ESET NOD32 Antivirus
    24-01-2017 17:43:06 Removed ESET NOD32 Antivirus
    25-01-2017 08:27:37 Restore Operation
    26-01-2017 08:10:07 Removed ESET NOD32 Antivirus
    26-01-2017 08:13:31 Before uninstalling ESET NOD32 Antivirus
    26-01-2017 08:13:49 Removed ESET NOD32 Antivirus
    27-01-2017 11:48:09 System Checkpoint
    28-01-2017 16:18:30 System Checkpoint
    02-02-2017 20:05:47 System Checkpoint

    ==================== Faulty Device Manager Devices =============

    Name: Beep
    Description: Beep
    Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
    Manufacturer:
    Service: Beep
    Problem: : This device is disabled. (Code 22)
    Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


    ==================== Event log errors: =========================

    Application errors:
    ==================

    System errors:
    =============
    Error: (02/03/2017 10:18:02 AM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
    Description: DCOM got error "%%1058 = The service cannot be started, either because it is disabled or because it has no enabled devices associated with it." attempting to start the service gupdate with arguments "/comsvc"
    in order to run the server:
    {4EB61BAC-A3B6-4760-9581-655041EF4D69}

    Error: (02/03/2017 10:16:46 AM) (Source: DCOM) (EventID: 10005) (User: FIRSTBUILD)
    Description: DCOM got error "%%1058 = The service cannot be started, either because it is disabled or because it has no enabled devices associated with it." attempting to start the service wuauserv with arguments ""
    in order to run the server:
    {E60687F7-01A1-40AA-86AC-DB1CBF673334}

    Error: (02/03/2017 10:06:20 AM) (Source: 0) (EventID: 4311) (User: )
    Description: Event-ID 4311

    Error: (02/02/2017 10:18:41 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
    Description: DCOM got error "%%1058 = The service cannot be started, either because it is disabled or because it has no enabled devices associated with it." attempting to start the service gupdate with arguments "/comsvc"
    in order to run the server:
    {4EB61BAC-A3B6-4760-9581-655041EF4D69}

    Error: (02/02/2017 09:55:50 PM) (Source: 0) (EventID: 4311) (User: )
    Description: Event-ID 4311


    ==================== Memory info ===========================

    Processor:  Intel® Pentium® 4 CPU 3.40GHz
    Percentage of memory in use: 15%
    Total physical RAM: 3071.04 MB
    Available physical RAM: 2597.49 MB
    Total Virtual: 4959.18 MB
    Available Virtual: 4753.12 MB

    ==================== Drives ================================

    Drive c: (Boot Drive) (Fixed) (Total:298.09 GB) (Free:196.29 GB) NTFS ==>[drive with boot components (Windows XP)]
    Drive f: (Expansion Drive) (Fixed) (Total:465.76 GB) (Free:45.35 GB) NTFS
    Drive z: (Data Drive) (Fixed) (Total:465.76 GB) (Free:302.19 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows XP) (Size: 298.1 GB) (Disk ID: 7975DF18)
    Partition 1: (Active) - (Size=298.1 GB) - (Type=07 NTFS)

    ========================================================
    Disk: 1 (MBR Code: Windows XP) (Size: 465.8 GB) (Disk ID: F0128678)
    Partition 1: (Not Active) - (Size=465.8 GB) - (Type=07 NTFS)

    ========================================================
    Disk: 2 (Size: 465.8 GB) (Disk ID: 0143820D)
    Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)

    ==================== End of Addition.txt ============================


    • 0

    #42
    RKinner

    RKinner

      Malware Expert

    • Expert
    • 20,031 posts
    • MVP

    IE does not work the same way that Firefox does so you need to install a program to block ads.  Go to

     

    adblockplus.org with IE and Download and install the program.

     

    Run FRST again.  Make sure everything is checked under Whitelist  

    Uncheck addition.txt,

    check Shortcut.txt

     

    Hit SCAN.  I think you will get a separate shortcut.txt file which is what I want to see.  Haven't run it in a while so it may just be tacked on to the end of FRST.txt


    • 0

    #43
    Jackpine

    Jackpine

      Member

    • Topic Starter
    • Member
    • PipPipPip
    • 347 posts

    FRST scan logs:

     

    Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-01-2017
    Ran by Robert (administrator) on FIRSTBUILD (03-02-2017 15:31:04)
    Running from C:\Documents and Settings\Robert\Desktop
    Loaded Profiles: Robert (Available Profiles: Robert & UpdatusUser & Administrator & Guest)
    Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) Language: English (United States)
    Internet Explorer Version 8 (Default browser: IE)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
    (BitTorrent, Inc.) C:\Program Files\uTorrent\uTorrent.exe

    ==================== Registry (Whitelisted) ====================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
    HKLM\...\Policies\Explorer: [NoCDBurning] 0
    HKU\S-1-5-21-299502267-789336058-725345543-1004\...\Policies\Explorer: [NoBandCustomize] 0
    HKU\S-1-5-21-299502267-789336058-725345543-1004\...\Policies\Explorer: [NoMovingBands] 0
    HKU\S-1-5-21-299502267-789336058-725345543-1004\...\Policies\Explorer: [NoCloseDragDropBands] 0
    HKU\S-1-5-21-299502267-789336058-725345543-1004\...\Policies\Explorer: [NoSetTaskbar] 0
    HKU\S-1-5-21-299502267-789336058-725345543-1004\...\Policies\Explorer: [NoToolbarsOnTaskbar] 0
    HKU\S-1-5-18\...\RunOnce: [tscuninstall] => C:\WINDOWS\system32\tscupgrd.exe [44544 2004-08-04] (Microsoft Corporation)
    ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\WINDOWS\system32\AcSignIcon.dll [2008-02-09] (Autodesk, Inc.)
    BootExecute: PDBoot.exeautocheck autochk *

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc.)
    Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
    Tcpip\..\Interfaces\{83ABCB39-813D-4C57-89F5-141B6B76F736}: [DhcpNameServer] 192.168.2.1

    Internet Explorer:
    ==================
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\S-1-5-21-299502267-789336058-725345543-1004\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-09-12] (Adobe Systems Incorporated)
    BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-09-12] (Adobe Systems Incorporated)
    Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-09-12] (Adobe Systems Incorporated)
    Toolbar: HKU\.DEFAULT -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-09-12] (Adobe Systems Incorporated)
    Toolbar: HKU\S-1-5-21-299502267-789336058-725345543-1004 -> Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2014-09-12] (Adobe Systems Incorporated)
    DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
    DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} hxxp://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab
    DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} hxxp://support.asus.com/common/asusTek_sys_ctrl.cab
    DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
    DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Twisted%20Lands%20-%20Shadow%20Town/Images/stg_drm.ocx
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab
    DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
    DPF: {588031A3-94BF-4CDD-86D0-939F6F93910F} hxxps://fixit.support.microsoft.com/ActiveX/FixItClient.CAB
    DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1292380760937
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1420669599859
    DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
    DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab
    DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
    DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
    DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
    DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Twisted%20Lands%20-%20Shadow%20Town/Images/armhelper.ocx
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} hxxp://eserv.sympatico.ca/netassistant/controls/BellCanadaPortalAX.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} hxxp://driveragent.com/files/driveragent.cab
    DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} hxxps://secure.logmein.com//activex/ractrl.cab?lmi=1007

    FireFox:
    ========
    FF ProfilePath: C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\tonk28m2.default [2017-01-29]
    FF DefaultSearchEngine.US: C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\tonk28m2.default -> Google
    FF Extension: (Advertising Cookie Opt-out) - C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\tonk28m2.default\Extensions\[email protected] [2015-08-16] [not signed]
    FF Extension: (Adblock Plus) - C:\Documents and Settings\Robert\Application Data\Mozilla\Firefox\Profiles\tonk28m2.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-24]
    FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    FF Extension: (Microsoft .NET Framework Assistant) - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-06-25] [not signed]
    FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
    FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2015-03-16] [not signed]
    FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-12] ()
    FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
    FF Plugin: @nosltd.com/getPlus+®,version=1.6.2.91 -> C:\Program Files\NOS\bin\np_gp.dll [2010-09-01] (NOS Microsystems Ltd.)
    FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
    FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
    FF Plugin: Adobe Acrobat -> C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2014-09-12] (Adobe Systems Inc.)
    FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2014-04-28] (Adobe Systems)
    FF Plugin ProgramFiles/Appdata: C:\Documents and Settings\Robert\Application Data\mozilla\plugins\npPxPlay.dll [2009-04-23] ( )

    Chrome:
    =======
    CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - hxxps://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
    CHR HKLM\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2014-09-12]

    ==================== Services (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S4 AcrSch2Svc; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [618944 2009-01-21] (Acronis)
    S4 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2008-12-23] (Macrovision Europe Ltd.) [File not signed]
    S4 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
    S4 PDAgent; C:\Program Files\Raxco\PerfectDisk\PDAgent.exe [2234160 2014-11-12] (Raxco Software, Inc.)
    S4 PDEngine; C:\Program Files\Common Files\Raxco\Shared\PDEngine.exe [2247472 2014-11-12] (Raxco Software, Inc.)
    S4 ProtexisLicensing; C:\WINDOWS\system32\PSIService.exe [174656 2006-11-02] () [File not signed]
    S4 ReflectService.exe; C:\Program Files\Macrium\Reflect\ReflectService.exe [2613200 2015-10-12] (Paramount Software UK Ltd)
    S4 ScsiAccess; C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe [181312 2009-04-23] () [File not signed]
    S4 SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [79360 2008-07-10] (SolidWorks) [File not signed]
    S4 Update service; C:\Program Files\Popcorn Time\Updater.exe [339968 2016-08-26] (Popcorn Time) [File not signed]
    S4 WMPNetworkSvc; C:\Program Files\Windows Media Player\WMPNetwk.exe [913408 2006-10-18] (Microsoft Corporation) [File not signed]
    S4 Roxio UPnP Renderer 9; "C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe" [X]
    S4 RoxLiveShare9; "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe" [X]

    ===================== Drivers (Whitelisted) ======================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
    S3 AnyDVD; C:\WINDOWS\System32\Drivers\AnyDVD.sys [139216 2016-07-11] (RedFox)
    R1 AsIO; C:\WINDOWS\System32\drivers\AsIO.sys [4962 2004-10-14] () [File not signed]
    R2 cvintdrv; C:\WINDOWS\system32\Drivers\cvintdrv.sys [4096 2006-07-27] () [File not signed]
    R2 DefragFS; C:\WINDOWS\system32\Drivers\DefragFS.sys [104088 2012-09-11] (Raxco Software, Inc.)
    R1 ElbyCDIO; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [30616 2014-12-20] (Elaborate Bytes AG)
    R2 Hardlock; C:\WINDOWS\system32\drivers\hardlock.sys [670208 2004-11-05] (Aladdin Knowledge Systems Ltd.)
    R1 HWiNFO32; C:\WINDOWS\system32\drivers\HWiNFO32.SYS [23840 2015-02-12] (REALiX™)
    R0 iteatapi; C:\WINDOWS\System32\DRIVERS\iteatapi.sys [28672 2008-03-01] (ITE Tech. Inc.)
    S3 KLIF; C:\WINDOWS\system32\drivers\klif.sys [700616 2014-11-18] (Kaspersky Lab ZAO)
    R3 klim5; C:\WINDOWS\System32\DRIVERS\klim5.sys [36448 2013-04-19] (Kaspersky Lab ZAO)
    S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
    S3 moufiltr; C:\WINDOWS\System32\DRIVERS\moufiltr.sys [62592 2007-01-14] (Chic Tech.) [File not signed]
    R3 MTsensor; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [5810 2004-08-12] ()
    S3 pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [47360 2010-08-22] (VSO Software) [File not signed]
    R2 PDFSFilter; C:\WINDOWS\System32\DRIVERS\PDFsFilter.sys [69016 2012-08-23] (Raxco Software, Inc.)
    R0 pssnap; C:\WINDOWS\System32\DRIVERS\pssnap.sys [16016 2015-10-12] (Windows ® Win 7 DDK provider)
    R0 PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [36624 2006-11-02] (Sonic Solutions) [File not signed]
    R0 SI3132; C:\WINDOWS\System32\DRIVERS\SI3132.sys [80424 2007-10-03] (Silicon Image, Inc)
    R0 SiFilter; C:\WINDOWS\System32\DRIVERS\SiWinAcc.sys [19240 2007-10-03] (Silicon Image, Inc)
    R0 SiRemFil; C:\WINDOWS\System32\DRIVERS\SiRemFil.sys [15400 2007-10-03] (Silicon Image, Inc)
    R0 snapman380; C:\WINDOWS\System32\DRIVERS\snman380.sys [134272 2009-10-24] (Acronis)
    S3 SONYPVU1; C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS [7552 2001-08-17] (Sony Corporation)
    R0 tdrpman174; C:\WINDOWS\System32\DRIVERS\tdrpm174.sys [971552 2009-10-24] (Acronis)
    R2 tifsfilter; C:\WINDOWS\System32\DRIVERS\tifsfilt.sys [44704 2009-10-24] (Acronis)
    S3 TVICHW32; C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS [23600 2008-05-10] (EnTech Taiwan) [File not signed]
    R3 yukonwxp; C:\WINDOWS\System32\DRIVERS\yk51x86.sys [298752 2015-02-12] ()
    S3 EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys [X]
    S3 FLASHSYS; no ImagePath
    S3 GMSIPCI; no ImagePath
    S4 IntelIde; no ImagePath
    S3 MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [X]
    S3 NTACCESS; no ImagePath
    U2 RemoteRegistry; no ImagePath
    U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
    U5 Tcpip6; C:\Windows\System32\Drivers\Tcpip6.sys [226880 2010-02-11] (Microsoft Corporation)
    U3 TlntSvr; no ImagePath
    U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [4096 2010-03-08] () [File not signed]

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2017-02-03 15:31 - 2017-02-03 15:31 - 00014955 _____ C:\Documents and Settings\Robert\Desktop\FRST.txt
    2017-02-03 12:59 - 2017-02-03 15:31 - 00000000 ____D C:\FRST
    2017-02-03 12:59 - 2017-02-03 12:00 - 01762816 _____ (Farbar) C:\Documents and Settings\Robert\Desktop\FRST.exe
    2017-02-03 12:58 - 2017-02-03 12:58 - 00000242 _____ C:\Documents and Settings\Robert\Desktop\BitHQ  Browse Torrents.url
    2017-01-29 21:41 - 2017-01-29 21:41 - 00010451 _____ C:\Documents and Settings\Robert\Desktop\MTB.txt
    2017-01-28 15:55 - 2017-02-02 22:43 - 00001149 _____ C:\VEW.txt
    2017-01-28 15:55 - 2017-01-28 15:48 - 00061440 _____ ( ) C:\Documents and Settings\Robert\Desktop\VEW.exe
    2017-01-28 14:17 - 2017-02-02 21:26 - 00000000 _____ C:\av.mof
    2017-01-28 13:13 - 2017-01-28 13:13 - 00000000 ____D C:\RegBackup
    2017-01-27 11:03 - 2017-02-03 10:06 - 00000550 _____ C:\WINDOWS\Tasks\Tweaking.com - Windows Repair Tray Icon.job
    2017-01-27 11:03 - 2017-01-27 11:03 - 00001822 _____ C:\Documents and Settings\Robert\Desktop\Tweaking.com - Windows Repair.lnk
    2017-01-27 11:03 - 2017-01-27 11:03 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Tweaking.com
    2017-01-27 11:02 - 2017-01-27 11:03 - 00183308 _____ C:\WINDOWS\Tweaking.com - Windows Repair Setup Log.txt
    2017-01-27 11:02 - 2017-01-27 10:56 - 32836248 _____ (Tweaking.com) C:\Documents and Settings\Robert\Desktop\tweaking.com_windows_repair_aio_setup.exe
    2017-01-26 17:07 - 2017-01-26 17:07 - 00001280 _____ C:\NetworkSettings.txt
    2017-01-26 11:46 - 2017-01-26 11:46 - 00090112 _____ C:\WINDOWS\Minidump\Mini012617-01.dmp
    2017-01-25 18:34 - 2017-01-25 18:35 - 00000345 _____ C:\WINDOWS\OEWABLog.txt
    2017-01-25 16:18 - 2017-01-25 16:13 - 00892416 _____ (Farbar) C:\Documents and Settings\Robert\Desktop\MiniToolBox.exe
    2017-01-25 08:37 - 2017-01-25 08:37 - 00000000 ____D C:\Program Files\Mozilla Firefox
    2017-01-25 08:35 - 2017-01-25 08:35 - 00000000 ____D C:\WINDOWS\Haunted Hotel 6- Ancient Bane Collector's Edition
    2017-01-25 08:25 - 2017-01-25 08:25 - 00321639 _____ C:\Documents and Settings\Robert\My Documents\8EA3F33C--EBEC--2CD6--DC9750D7--B7B643769989.osiris
    2017-01-25 08:25 - 2017-01-25 08:25 - 00142521 _____ C:\Documents and Settings\Robert\My Documents\8EA3F33C--EBEC--2CD6--34079205--A9D3226CA15A.osiris
    2017-01-25 08:25 - 2017-01-25 08:25 - 00113479 _____ C:\Documents and Settings\Robert\Desktop\8EA3F33C--EBEC--2CD6--89660407--3DB49742E42A.osiris
    2017-01-25 08:25 - 2017-01-25 08:25 - 00080104 _____ C:\Documents and Settings\Robert\My Documents\8EA3F33C--EBEC--2CD6--72DE5ACF--D5FE6330098D.osiris
    2017-01-25 08:25 - 2017-01-25 08:25 - 00065898 _____ C:\Documents and Settings\Robert\My Documents\8EA3F33C--EBEC--2CD6--5948EF8C--90EC739DAA88.osiris
    2017-01-25 08:25 - 2017-01-25 08:25 - 00057588 _____ C:\Documents and Settings\Robert\My Documents\8EA3F33C--EBEC--2CD6--55562075--5FF2AF875EFA.osiris
    2017-01-25 08:25 - 2017-01-25 08:25 - 00029789 _____ C:\Documents and Settings\Robert\8EA3F33C--EBEC--2CD6--735A51BC--B0238B6FFC5E.osiris
    2017-01-25 08:25 - 2017-01-25 08:25 - 00018244 _____ C:\Documents and Settings\Robert\8EA3F33C--EBEC--2CD6--4DFA7389--E57C34FEE239.osiris
    2017-01-25 08:25 - 2017-01-25 08:25 - 00009166 _____ C:\OSIRIS-843c.htm
    2017-01-25 08:25 - 2017-01-25 08:25 - 00009166 _____ C:\Documents and Settings\Robert\OSIRIS-4c6a.htm
    2017-01-25 08:25 - 2017-01-25 08:25 - 00009166 _____ C:\Documents and Settings\Robert\My Documents\OSIRIS-ca08.htm
    2017-01-25 08:25 - 2017-01-25 08:25 - 00003152 _____ C:\Documents and Settings\Robert\8EA3F33C--EBEC--2CD6--16066830--3A133EDDB3BC.osiris
    2017-01-25 08:25 - 2017-01-25 08:25 - 00000836 _____ C:\8EA3F33C--EBEC--2CD6--7ED232F7--81EE105CDA45.osiris
    2017-01-20 22:43 - 2017-01-22 16:26 - 00000000 ____D C:\Program Files\Games
    2017-01-19 14:14 - 2017-01-19 14:14 - 00000093 _____ C:\Documents and Settings\Robert\Desktop\Volunteer Invictus Games 2017.URL
    2017-01-15 21:08 - 2017-01-15 21:08 - 05090071 _____ C:\Documents and Settings\Robert\Desktop\Samsung-Galaxy-S5-Neo-Manual.pdf
    2017-01-15 21:05 - 2017-01-15 21:06 - 05154782 _____ C:\Documents and Settings\Robert\My Documents\Samsung-Galaxy-S5-Neo-Manual.pdf
    2017-01-05 21:13 - 2017-01-05 21:14 - 01472740 _____ C:\WINDOWS\Haunted Hotel 6- Ancient Bane Collector's Edition Uninstall Log.txt
    2017-01-05 20:54 - 2017-01-05 21:09 - 03157144 _____ C:\WINDOWS\Haunted Hotel 6- Ancient Bane Collector's Edition Setup Log.txt

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2017-02-03 15:31 - 2015-12-13 21:42 - 00000000 ____D C:\Documents and Settings\Robert\Local Settings\temp
    2017-02-03 15:31 - 2008-08-16 08:32 - 00000000 ____D C:\Documents and Settings\Robert\Application Data\uTorrent
    2017-02-03 15:18 - 2010-03-11 22:40 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
    2017-02-03 12:58 - 2016-06-01 18:09 - 00000120 _____ C:\Documents and Settings\Robert\Desktop\BitHQ.URL
    2017-02-03 12:51 - 2016-07-23 21:38 - 00000122 _____ C:\Documents and Settings\Robert\Desktop\The Horror Charnel Home.URL
    2017-02-03 10:20 - 2010-10-30 13:18 - 00002521 _____ C:\Documents and Settings\Robert\Desktop\Outlook 2007.lnk
    2017-02-03 10:07 - 2010-10-30 13:30 - 00002515 _____ C:\Documents and Settings\Robert\Desktop\Word 2007.lnk
    2017-02-03 10:06 - 2014-03-12 22:32 - 00000224 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
    2017-02-03 10:06 - 2010-03-11 22:40 - 00000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
    2017-02-03 10:06 - 2006-06-03 17:31 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2017-02-03 10:06 - 2004-08-04 07:00 - 00012054 _____ C:\WINDOWS\system32\wpa.dbl
    2017-02-02 22:46 - 2006-06-03 17:32 - 00000278 ___SH C:\Documents and Settings\Robert\ntuser.ini
    2017-02-02 22:46 - 2006-06-03 17:31 - 00032632 _____ C:\WINDOWS\SchedLgU.Txt
    2017-02-02 21:54 - 2006-06-03 12:49 - 00724282 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2017-02-02 21:51 - 2006-06-03 12:47 - 00000281 ___SH C:\boot.ini
    2017-02-02 21:51 - 2004-08-04 07:00 - 00000855 _____ C:\WINDOWS\win.ini
    2017-02-02 21:51 - 2004-08-04 07:00 - 00000227 _____ C:\WINDOWS\system.ini
    2017-02-02 21:50 - 2006-06-03 12:48 - 01708392 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2017-02-02 21:31 - 2006-06-03 17:07 - 00023392 _____ C:\WINDOWS\system32\nscompat.tlb
    2017-02-02 21:31 - 2006-06-03 17:07 - 00016832 _____ C:\WINDOWS\system32\amcompat.tlb
    2017-02-02 19:42 - 2006-06-03 23:10 - 00133064 _____ C:\Documents and Settings\Robert\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2017-01-29 09:31 - 2008-04-21 19:21 - 00002329 _____ C:\Documents and Settings\Robert\Start Menu\Programs\Windows Install Clean Up.lnk
    2017-01-28 15:38 - 2004-08-04 07:00 - 00000855 _____ C:\WINDOWS\system32\Drivers\etc\hosts_bak_470
    2017-01-28 14:23 - 2004-08-04 07:00 - 00000855 _____ C:\WINDOWS\system32\Drivers\etc\hosts_bak_974
    2017-01-28 14:16 - 2006-06-03 17:09 - 00000000 __SHD C:\Documents and Settings\NetworkService
    2017-01-27 18:49 - 2014-05-06 19:07 - 00000000 ____D C:\Documents and Settings\Robert\My Documents\Reflect
    2017-01-27 18:49 - 2006-06-03 12:41 - 00000000 ____D C:\WINDOWS\repair
    2017-01-27 17:02 - 2006-06-03 17:05 - 00000000 ____D C:\WINDOWS\Registration
    2017-01-27 16:56 - 2015-12-14 16:51 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\TEMP
    2017-01-27 09:22 - 2006-06-03 12:48 - 00000000 ____D C:\Documents and Settings
    2017-01-26 11:46 - 2006-12-11 18:21 - 00000000 ____D C:\WINDOWS\Minidump
    2017-01-26 08:08 - 2006-06-03 12:41 - 00000000 ____D C:\WINDOWS\inf
    2017-01-25 08:39 - 2015-01-16 17:03 - 00000000 ____D C:\Documents and Settings\UpdatusUser
    2017-01-25 08:39 - 2011-03-31 17:57 - 00000000 ____D C:\Documents and Settings\Administrator
    2017-01-25 08:39 - 2006-09-03 14:13 - 00000000 ____D C:\Documents and Settings\Guest
    2017-01-25 08:39 - 2006-06-03 17:32 - 00000000 ____D C:\Documents and Settings\Robert
    2017-01-25 08:39 - 2006-06-03 17:31 - 00000000 __SHD C:\Documents and Settings\LocalService
    2017-01-25 08:37 - 2016-02-16 21:08 - 00000000 ____D C:\Program Files\Macrium
    2017-01-25 08:37 - 2013-03-20 17:20 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
    2017-01-25 08:36 - 2006-06-03 17:05 - 00000000 ____D C:\WINDOWS\system32\Macromed
    2017-01-25 08:25 - 2015-03-17 19:19 - 00000000 ___RD C:\Documents and Settings\Robert\My Documents\Dropbox
    2017-01-25 08:25 - 2008-05-15 22:53 - 00000000 ____D C:\watcom-1.3
    2017-01-25 08:25 - 2007-07-23 17:05 - 00000000 ____D C:\Documents and Settings\Robert\Collectorz Print lists
    2017-01-25 08:25 - 2007-02-16 20:05 - 00000000 ____D C:\Documents and Settings\Robert\My Documents\Movie Collector
    2017-01-25 08:25 - 2006-06-03 17:32 - 00000000 ___RD C:\Documents and Settings\Robert\My Documents
    2017-01-24 20:48 - 2006-06-03 17:32 - 00000000 ___RD C:\Documents and Settings\Robert\My Documents\My Pictures
    2017-01-24 12:15 - 2006-06-03 12:41 - 00000000 RSHDC C:\WINDOWS\system32\dllcache
    2017-01-22 21:13 - 2014-04-17 20:09 - 00000000 ____D C:\Documents and Settings\Robert\Application Data\Elephant Games
    2017-01-21 19:59 - 2016-03-28 11:48 - 00000284 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
    2017-01-12 16:25 - 2012-08-13 15:23 - 00802904 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
    2017-01-12 16:25 - 2012-08-13 15:23 - 00144472 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
    2017-01-12 16:25 - 2006-06-10 07:50 - 00000000 ____D C:\Documents and Settings\Robert\Local Settings\Application Data\Adobe
    2017-01-11 19:24 - 2016-02-24 17:45 - 00000926 _____ C:\Documents and Settings\All Users\Desktop\Movie Collector.lnk

    ==================== Files in the root of some directories =======

    2016-06-22 18:40 - 2016-06-22 18:40 - 0003072 _____ () C:\Documents and Settings\Robert\Application Data\.spark_db
    2014-04-02 21:28 - 2014-04-02 21:30 - 0009333 _____ () C:\Documents and Settings\Robert\Application Data\Comma Separated Values (Windows).EML
    2007-03-23 16:38 - 2007-07-21 12:39 - 0087608 _____ () C:\Documents and Settings\Robert\Application Data\ezpinst.exe
    2008-08-30 11:14 - 2010-01-03 19:51 - 0000108 _____ () C:\Documents and Settings\Robert\Application Data\netstat.bat
    2007-03-23 16:38 - 2011-04-10 14:47 - 0007887 _____ () C:\Documents and Settings\Robert\Application Data\pcouffin.cat
    2007-03-23 16:38 - 2011-04-10 14:47 - 0001144 _____ () C:\Documents and Settings\Robert\Application Data\pcouffin.inf
    2007-03-23 16:38 - 2011-04-10 14:48 - 0000033 _____ () C:\Documents and Settings\Robert\Application Data\pcouffin.log
    2007-03-23 16:38 - 2011-04-10 14:47 - 0047360 _____ (VSO Software) C:\Documents and Settings\Robert\Application Data\pcouffin.sys
    2008-07-05 10:41 - 2008-07-05 10:41 - 0002494 _____ () C:\Documents and Settings\Robert\Application Data\sldIMLog_20080-40000-1100_00002.txt
    2010-10-24 16:36 - 2010-10-24 16:36 - 0000036 _____ () C:\Documents and Settings\Robert\Local Settings\Application Data\housecall.guid.cache
    2009-09-24 17:41 - 2009-09-24 17:41 - 5257216 _____ () C:\Documents and Settings\Robert\Local Settings\Application Data\mfm2_database.dat
    2007-08-25 13:19 - 2007-08-25 13:19 - 0002108 _____ () C:\Documents and Settings\Robert\Local Settings\Application Data\rx_audio.Cache
    2007-01-25 22:46 - 2007-12-03 19:42 - 1462572 _____ () C:\Documents and Settings\Robert\Local Settings\Application Data\rx_image.Cache
    2007-11-25 22:46 - 2016-10-31 17:27 - 0000123 ___SH () C:\Documents and Settings\All Users\Application Data\.zreglib
    2013-09-14 19:49 - 2013-09-14 19:49 - 0000057 _____ () C:\Documents and Settings\All Users\Application Data\Ament.ini
    2008-03-02 15:30 - 2008-08-29 17:51 - 0110892 _____ () C:\Documents and Settings\All Users\Application Data\Svclog.log

    Files to move or delete:
    ====================
    C:\Documents and Settings\Robert\mylist.dat


    ==================== Bamital & volsnap ======================

    (There is no automatic fix for files that do not pass verification.)

    C:\WINDOWS\explorer.exe => File is digitally signed
    C:\WINDOWS\system32\winlogon.exe => File is digitally signed
    C:\WINDOWS\system32\svchost.exe => File is digitally signed
    C:\WINDOWS\system32\services.exe => File is digitally signed
    C:\WINDOWS\system32\User32.dll => File is digitally signed
    C:\WINDOWS\system32\userinit.exe => File is digitally signed
    C:\WINDOWS\system32\rpcss.dll => File is digitally signed
    C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
    C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

    ==================== End of FRST.txt ============================

     

     

    Users shortcut scan result (x86) Version: 29-01-2017
    Ran by Robert (03-02-2017 15:32:24)
    Running from C:\Documents and Settings\Robert\Desktop
    Boot Mode: Normal

    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)



    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\AVIcodec\Website.lnk -> hxxp://avicodec.duby.inf


    Shortcut: C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Notepad.lnk -> C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Program Compatibility Wizard.lnk -> C:\WINDOWS\system32\compatui.dll ()
    Shortcut: C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Synchronize.lnk -> C:\WINDOWS\system32\mobsync.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Tour Windows XP.lnk -> C:\WINDOWS\system32\tourstart.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk -> C:\WINDOWS\system32\magnify.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\WINDOWS\system32\narrator.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\system32\osk.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk -> C:\WINDOWS\system32\moricons.dll (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk -> C:\WINDOWS\system32\wupdmgr.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\µTorrent.lnk -> C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Acrobat Distiller XI.lnk -> C:\Program Files\Adobe\Acrobat 11.0\Acrobat\acrodist.exe (Adobe Systems Incorporated.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Acrobat XI Pro.lnk -> C:\WINDOWS\Installer\{AC76BA86-1033-FFFF-7760-000000000006}\_SC_Acrobat.ico ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Bridge CS3.lnk -> C:\Program Files\Adobe\Adobe Bridge CS3\Bridge.exe (Adobe Systems, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Device Central CS3.lnk -> C:\Program Files\Adobe\Adobe Device Central CS3\DeviceCentral.exe (Adobe Systems)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Adobe ExtendScript Toolkit 2.lnk -> C:\Program Files\Adobe\Adobe Utilities\ExtendScript Toolkit 2\ExtendScript Toolkit 2.exe (Adobe Systems, Incorporated)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Adobe FormsCentral.lnk -> C:\Program Files\Adobe\Acrobat 11.0\FormsCentral\FormsCentralForAcrobat.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Photoshop CS3.lnk -> C:\Program Files\Adobe\Adobe Photoshop CS3\Photoshop.exe (Adobe Systems, Incorporated)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk -> C:\WINDOWS\Installer\{56EC47AA-5813-4FF6-8E75-544026FBEA83}\AppleSoftwareUpdateIco.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\PerfectDisk.lnk -> C:\Program Files\Raxco\PerfectDisk\PerfectDisk.exe (Raxco Software, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Tetris.lnk -> C:\Program Files\Tetris\tetris.exe (Crystal Office Systems)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Windows Defender.lnk -> C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk -> C:\Program Files\Movie Maker\moviemk.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Your Uninstaller 2010\Help document.lnk -> C:\Program Files\Your Uninstaller 2010\uninstaller.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Your Uninstaller 2010\Uninstall.lnk -> C:\Program Files\Your Uninstaller 2010\unins000.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Your Uninstaller 2010\Your Uninstaller!.lnk -> C:\Program Files\Your Uninstaller 2010\urmain.exe (URSoft,Inc)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\WinRAR\Console RAR manual.lnk -> C:\Program Files\WinRAR\Rar.txt ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\WinRAR\WinRAR help.lnk -> C:\Program Files\WinRAR\WinRAR.hlp ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Western Digital Corporation\Data Lifeguard Diagnostic for Windows\Data Lifeguard Diagnostic for Windows.lnk -> C:\Program Files\Western Digital Corporation\Data Lifeguard Diagnostic for Windows\WinDlg.exe (Western Digital)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Western Digital Corporation\Data Lifeguard Diagnostic for Windows\Help Documentation.lnk -> C:\Program Files\Western Digital Corporation\Data Lifeguard Diagnostic for Windows\help.htm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Western Digital Corporation\Data Lifeguard Diagnostic for Windows\Uninstall Data Lifeguard Diagnostic for Windows.lnk -> C:\Program Files\Western Digital Corporation\Data Lifeguard Diagnostic for Windows\unins000.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Tweaking.com\Windows Repair (All in One)\Open Windows Repair (WR) Tray Icon.lnk -> C:\Program Files\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe (Tweaking.com)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Tweaking.com\Windows Repair (All in One)\Tweaking.com - Registry Backup.lnk -> C:\Program Files\Tweaking.com\Windows Repair (All in One)\files\registry_backup_tool\TweakingRegistryBackup.exe (Tweaking.com)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Tweaking.com\Windows Repair (All in One)\Tweaking.com - Windows Repair.lnk -> C:\Program Files\Tweaking.com\Windows Repair (All in One)\Repair_Windows.exe (Tweaking.com)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\SolidWorks 2008\DWGeditor.lnk -> C:\WINDOWS\Installer\{C8DE0FC9-5BD0-4D26-B5AD-D38146F2083C}\DWGEditor_D0220928AF1811D3AEA400C04F79FCDD.exe (Macrovision Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\SolidWorks 2008\eDrawings 2008.lnk -> C:\Program Files\Common Files\eDrawings2008\EModelViewer.exe (Solidworks)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\SolidWorks 2008\PDMWorks Workgroup VaultAdmin.lnk -> C:\WINDOWS\Installer\{A8567E18-9E80-4EA3-A5C1-A6186C86F2CC}\NewShortcut2.exe (Macrovision Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\SolidWorks 2008\SolidWorks Explorer 2008.lnk -> C:\WINDOWS\Installer\{A8567E18-9E80-4EA3-A5C1-A6186C86F2CC}\NewShortcut1.exe (Macrovision Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\SolidWorks 2008\SolidWorks 2008 SP3.0\SolidWorks 2008 SP3.0.lnk -> C:\WINDOWS\Installer\{266EB766-9ABB-40D0-AB9F-41EE46D23876}\i386_SldWorks.exe (Macrovision Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\SolidWorks 2008\SolidWorks 2008 SP3.0\SolidWorks Tools\Conversion Wizard.lnk -> C:\WINDOWS\Installer\{266EB766-9ABB-40D0-AB9F-41EE46D23876}\SldConverter.exe (Macrovision Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\SolidWorks 2008\SolidWorks 2008 SP3.0\SolidWorks Tools\Copy Settings Wizard.lnk -> C:\WINDOWS\Installer\{266EB766-9ABB-40D0-AB9F-41EE46D23876}\CopyOptWiz.exe (Macrovision Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\SolidWorks 2008\SolidWorks 2008 SP3.0\SolidWorks Tools\SolidNetWork License Administrator.lnk -> C:\WINDOWS\Installer\{266EB766-9ABB-40D0-AB9F-41EE46D23876}\swlmwizard.exe (Macrovision Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\SolidWorks 2008\SolidWorks 2008 SP3.0\SolidWorks Tools\SolidWorks Rx.lnk -> C:\WINDOWS\Installer\{266EB766-9ABB-40D0-AB9F-41EE46D23876}\i386_SldRx.exe (Macrovision Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\SolidWorks 2008\SolidWorks 2008 SP3.0\SolidWorks Tools\SolidWorks Task Scheduler.lnk -> C:\WINDOWS\Installer\{266EB766-9ABB-40D0-AB9F-41EE46D23876}\swScheduler.exe (Macrovision Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\SolidWorks 2008\COSMOS Tools\Material Browser.lnk -> C:\Program Files\SolidWorks\COSMOS\Utilities\Material.exe (SRAC)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\SigmaPlot\SigmaPlot 10.0.lnk -> C:\Program Files\SigmaPlot\SPW10\Spw.exe (Systat Software, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\River Past\Audio Converter Pro\Audio Converter Pro.lnk -> C:\Program Files\River Past\Audio Converter Pro\AudioConverterPro.exe (River Past Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\River Past\Audio Converter Pro\Uninstall Audio Converter Pro.lnk -> C:\WINDOWS\Audio Converter Pro Uninstaller.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\RedFox\AnyDVD\AnyDVD Help.lnk -> C:\Program Files\RedFox\HelpLauncher.exe (Elaborate Bytes AG)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\RedFox\AnyDVD\AnyDVD History.lnk -> C:\Program Files\RedFox\manual\changes.txt ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\RedFox\AnyDVD\AnyDVD.lnk -> C:\Program Files\RedFox\AnyDVD.exe (RedFox)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\RedFox\AnyDVD\Register AnyDVD.lnk -> C:\Program Files\RedFox\RegAnyDVD.exe (RedFox)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\RedFox\AnyDVD\Uninstall.lnk -> C:\Program Files\RedFox\AnyDVD-uninst.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\ProShow Producer\Help with ProShow Producer.lnk -> C:\Program Files\Photodex\ProShowProducer\proshow.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\ProShow Producer\Ordering ProShow Producer.lnk -> C:\Program Files\Photodex\ProShowProducer\order.html ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\ProShow Producer\ProShow Producer.lnk -> C:\Program Files\Photodex\ProShowProducer\proshow.exe (Photodex)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\ProShow Producer\Uninstall ProShow Producer.lnk -> C:\Program Files\Photodex\ProShowProducer\uninst.exe ( )
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Manuals\Nero BackItUp [English Help].lnk -> C:\Program Files\Nero\Nero 7\Nero BackItUp\NeroBackItUp_eng.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Manuals\Nero BurnRights [English Help].lnk -> C:\Program Files\Nero\Nero 7\Nero Toolkit\NeroBurnRights_eng.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Manuals\Nero CD-DVD Speed [English Help].lnk -> C:\Program Files\Nero\Nero 7\Nero Toolkit\CDSpeed_eng.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Manuals\Nero CoverDesigner [English Help].lnk -> C:\Program Files\Nero\Nero 7\Nero CoverDesigner\NeroCoverDesigner_eng.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Manuals\Nero Express [English Help].lnk -> C:\Program Files\Nero\Nero 7\Core\NeroExpress_eng.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Manuals\Nero Home [English Help].lnk -> C:\Program Files\Nero\Nero 7\Nero Home\NeroHome_Eng.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Manuals\Nero MediaHome [English Help].lnk -> C:\Program Files\Nero\Nero 7\Nero MediaHome\NeroMediaHome_Eng.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Manuals\Nero PhotoSnap [English Help].lnk -> C:\Program Files\Nero\Nero 7\Nero PhotoSnap\NeroPhotoSnap_Eng.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Manuals\Nero Recode [English Help].lnk -> C:\Program Files\Nero\Nero 7\Nero Recode\NeroRecode_eng.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Manuals\Nero ShowTime [English Help].lnk -> C:\Program Files\Nero\Nero 7\Nero ShowTime\NeroShowTime_eng.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Manuals\Nero StartSmart [English Help].lnk -> C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart_eng.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Manuals\Nero Vision [English Help].lnk -> C:\Program Files\Nero\Nero 7\Nero Vision\NeroVisionExpress_ENG.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Manuals\Nero WaveEditor [English Help].lnk -> C:\Program Files\Nero\Nero 7\Nero WaveEditor\NeroWaveEditor_eng.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\MSConfig CleanUp\InControl Startup Manager.lnk -> C:\Program Files\MSConfig CleanUp\InControl.url ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\MSConfig CleanUp\MSConfig Cleanup on the Web.lnk -> C:\Program Files\MSConfig CleanUp\MSConfigCleanUp.url ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\MSConfig CleanUp\MSConfig Cleanup.lnk -> C:\Program Files\MSConfig CleanUp\MSConfigCleanUp.exe (Virtuoza)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\MSConfig CleanUp\Uninstall MSConfig CleanUp.lnk -> C:\Program Files\MSConfig CleanUp\UninsHs.exe (Han-soft)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Student\Microsoft Math.lnk -> C:\WINDOWS\Installer\{07043840-959A-4B0D-8825-2C533F0DDB19}\CALCICO6B.EXE (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Access 2007.lnk -> C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Excel 2007.lnk -> C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office InfoPath 2007.lnk -> C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Outlook 2007.lnk -> C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office PowerPoint 2007.lnk -> C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Project 2007.lnk -> C:\WINDOWS\Installer\{90120000-003B-0000-0000-0000000FF1CE}\pj11icon.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Publisher 2007.lnk -> C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Visio 2007.lnk -> C:\WINDOWS\Installer\{90120000-0051-0000-0000-0000000FF1CE}\visicon.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Word 2007.lnk -> C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Digital Certificate for VBA Projects.lnk -> C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Clip Organizer.lnk -> C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office 2007 Language Settings.lnk -> C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Diagnostics.lnk -> C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Picture Manager.lnk -> C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\MathType 5\MathType Help.lnk -> C:\Program Files\MathType\MT5enu.hlp ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\MathType 5\MathType User Manual.lnk -> C:\Program Files\MathType\MathType User Manual.pdf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\MathType 5\MathType.lnk -> C:\Program Files\MathType\MathType.exe (Design Science, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Maple 12\Classic Worksheet Maple 12.lnk -> C:\Program Files\Maple 12\bin.win\cwmaple.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Maple 12\Maple 12.lnk -> C:\Program Files\Maple 12\bin.win\maplew.exe (Maplesoft)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Maple 12\Maple Calculator.lnk -> C:\Program Files\Maple 12\bin.win\calculator.exe (Maplesoft)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Maple 12\Maple Reader 12.lnk -> C:\Program Files\Maple 12\reader\reader.exe (Maplesoft)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Maple 12\Readme.lnk -> C:\Program Files\Maple 12\readme.txt ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Maple 12\Tools\Activate Maple 12.lnk -> C:\Program Files\Maple 12\bin.win\activation.exe (Maplesoft)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Maple 12\Tools\Mint.lnk -> C:\Program Files\Maple 12\bin.win\wmint.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Maple 12\Tools\Uninstall Maple 12.lnk -> C:\Program Files\Maple 12\Uninstall_Maple 12\Uninstall Maple 12.exe (Macrovision)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Maple 12\Tools\Worksheet File Association Selector.lnk -> C:\Program Files\Maple 12\bin.win\ToggleAssociation.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Macrium\Reflect\Reflect.lnk -> C:\Program Files\Macrium\Reflect\Reflect.exe (Paramount Software UK Ltd)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Kyodai Mahjongg 2006\Get legacy 2D version.lnk -> C:\Program Files\Kyodai Mahjongg 2006\3.url ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Kyodai Mahjongg 2006\Kyodai Mahjongg 2006.lnk -> C:\Program Files\Kyodai Mahjongg 2006\kmj.exe (Rene-Gilles Deberdt)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Kyodai Mahjongg 2006\Kyodai Mahjongg on the Web.lnk -> C:\Program Files\Kyodai Mahjongg 2006\1.url ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Kyodai Mahjongg 2006\Purchase KMJ now.lnk -> C:\Program Files\Kyodai Mahjongg 2006\2.url ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Kyodai Mahjongg 2006\Uninstall Kyodai Mahjongg.lnk -> C:\Program Files\Kyodai Mahjongg 2006\unins000.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Kyodai Mahjongg 2006\English Help\Game Rules.lnk -> C:\Program Files\Kyodai Mahjongg 2006\Help\rules.rtf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Kyodai Mahjongg 2006\English Help\Help.lnk -> C:\Program Files\Kyodai Mahjongg 2006\Help\kyodai.rtf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Kyodai Mahjongg 2006\English Help\Miscellaneous.lnk -> C:\Program Files\Kyodai Mahjongg 2006\Help\misc.rtf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Kyodai Mahjongg 2006\English Help\Troubleshooting.lnk -> C:\Program Files\Kyodai Mahjongg 2006\Help\trouble.rtf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Kyodai Mahjongg 2006\English Help\What's New.lnk -> C:\Program Files\Kyodai Mahjongg 2006\Help\whatsnew.rtf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Kyodai Mahjongg 2006\English Help\What's Old.lnk -> C:\Program Files\Kyodai Mahjongg 2006\Help\whatsold.rtf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Codec Tweak Tool.lnk -> C:\Program Files\K-Lite Codec Pack\Tools\CodecTweakTool.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Media Player Classic.lnk -> C:\Program Files\K-Lite Codec Pack\MPC-HC\mpc-hc.exe (MPC-HC Team)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Uninstall\Uninstall K-Lite Codec Pack.lnk -> C:\Program Files\K-Lite Codec Pack\unins000.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Tools\GraphStudioNext.lnk -> C:\Program Files\K-Lite Codec Pack\Tools\GraphStudioNext.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Tools\Haali Muxer.lnk -> C:\Program Files\K-Lite Codec Pack\Filters\Haali\gdsmux.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Tools\MediaInfo.lnk -> C:\Program Files\K-Lite Codec Pack\Tools\mediainfo.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Tools\Win7DSFilterTweaker.lnk -> C:\Program Files\K-Lite Codec Pack\Tools\CodecTweakTool.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Help\Frequently Asked Questions.lnk -> C:\Program Files\K-Lite Codec Pack\Info\faq.htm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\IsoBuster\Help.lnk -> C:\Program Files\Iso Buster 3.5.5\IsoBuster\Help\IsoBuster.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\IsoBuster\IsoBuster Online.lnk -> C:\Program Files\Iso Buster 3.5.5\IsoBuster\Online\IsoBuster Online.html ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\IsoBuster\IsoBuster.lnk -> C:\Program Files\Iso Buster 3.5.5\IsoBuster\IsoBuster.exe (Smart Projects)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\IsoBuster\Order Now.lnk -> C:\Program Files\Iso Buster 3.5.5\IsoBuster\Online\Order Now.html ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\IsoBuster\Uninstall IsoBuster.lnk -> C:\Program Files\Iso Buster 3.5.5\IsoBuster\Uninst\unins000.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Intel Corporation\Intel Processor Diagnostic Tool\Intel Processor Diagnostic Tool.lnk -> C:\Program Files\Intel Corporation\Intel Processor Diagnostic Tool\Win-IPDT.exe (Intel Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\ImgBurn\ImgBurn Read Me.lnk -> C:\Program Files\ImgBurn\ReadMe.txt ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\ImgBurn\ImgBurn.lnk -> C:\Program Files\ImgBurn\ImgBurn.exe (LIGHTNING UK!)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\ImgBurn\Uninstall.lnk -> C:\Program Files\ImgBurn\uninstall.exe (LIGHTNING UK!)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\ImageConverter Plus\ImageConverter Plus on the Web.lnk -> C:\Program Files\ImageConverter Plus\ImageConverter Plus on the Web.htm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\ImageConverter Plus\Uninstall ImageConverter Plus.lnk -> C:\Program Files\ImageConverter Plus\unins000.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Freecell.lnk -> C:\WINDOWS\system32\freecell.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Hearts.lnk -> C:\WINDOWS\system32\mshearts.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Internet Backgammon.lnk -> C:\Program Files\MSN Gaming Zone\Windows\bckgzm.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Internet Checkers.lnk -> C:\Program Files\MSN Gaming Zone\Windows\chkrzm.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Internet Hearts.lnk -> C:\Program Files\MSN Gaming Zone\Windows\hrtzzm.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Internet Reversi.lnk -> C:\Program Files\MSN Gaming Zone\Windows\Rvsezm.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Internet Spades.lnk -> C:\Program Files\MSN Gaming Zone\Windows\shvlzm.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Minesweeper.lnk -> C:\WINDOWS\system32\winmine.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Pinball.lnk -> C:\Program Files\Windows NT\Pinball\pinball.exe (Cinematronics)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Solitaire.lnk -> C:\WINDOWS\system32\sol.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Games\Spider Solitaire.lnk -> C:\WINDOWS\system32\spider.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT\Documentation.lnk -> C:\Program Files\ERUNT\README.TXT ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT\ERUNT Homepage.lnk -> C:\Program Files\ERUNT\ERUNT.URL ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT\ERUNT.lnk -> C:\Program Files\ERUNT\ERUNT.EXE ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT\NTREGOPT.lnk -> C:\Program Files\ERUNT\NTREGOPT.EXE ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT\Uninstall ERUNT.lnk -> C:\Program Files\ERUNT\unins000.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Elaborate Bytes\CloneDVD2\CloneDVD2 Help.lnk -> C:\Program Files\Elaborate Bytes\CloneDVD2\HelpLauncher.exe (Elaborate Bytes AG)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Elaborate Bytes\CloneDVD2\CloneDVD2 Revision History.lnk -> C:\Program Files\Elaborate Bytes\CloneDVD2\manual\clonedvd_changes.txt ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Elaborate Bytes\CloneDVD2\CloneDVD2.lnk -> C:\Program Files\Elaborate Bytes\CloneDVD2\CloneDVD2.exe (Elaborate Bytes AG)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Elaborate Bytes\CloneDVD2\Register CloneDVD2.lnk -> C:\Program Files\Elaborate Bytes\CloneDVD2\RegCloneDVD.exe (Elaborate Bytes AG)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Elaborate Bytes\CloneDVD2\Uninstall.lnk -> C:\Program Files\Elaborate Bytes\CloneDVD2\CloneDVD2-uninst.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Easy CD-DA Extractor 2011\Easy CD-DA Extractor.lnk -> C:\Program Files\Easy CD-DA Extractor 2011\ezcddax.exe (Poikosoft)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\DvdInfo\DvdInfo.lnk -> C:\Program Files\DVDInfoPro\DvdInfo.exe (Nic Wilson)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\DVDFab 9\DVDFab 9.lnk -> C:\Program Files\DVDFab 9\DVDFab.exe (FengTao Software Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\DVDFab 9\DVDFab History.lnk -> C:\Program Files\DVDFab 9\Changes.txt ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\DVDFab 9\Uninstall DVDFab 9.lnk -> C:\Program Files\DVDFab 9\unins000.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\DVDFab 8 Qt\DVDFab 8 Profile Editor.lnk -> C:\Program Files\DVDFab 8 Qt\ProfileEditor.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\DVDFab 8 Qt\DVDFab 8 Qt.lnk -> C:\Program Files\DVDFab 8 Qt\DVDFab.exe (Fengtao Software Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\DVDFab 8 Qt\DVDFab History.lnk -> C:\Program Files\DVDFab 8 Qt\Changes.txt ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\DVDFab 8 Qt\DVDFab Online.lnk -> C:\Program Files\DVDFab 8 Qt\DVDFab.url ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\DVDFab 8 Qt\Uninstall DVDFab 8 Qt.lnk -> C:\Program Files\DVDFab 8 Qt\unins000.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\DVD Shrink\DVD Shrink 3.2.lnk -> C:\Program Files\DVD Shrink\DVD Shrink 3.2.exe (DVD Shrink)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\DVD Shrink\Uninstall DVD Shrink.lnk -> C:\Program Files\DVD Shrink\unins000.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\DVD Rebuilder PRO\DVD Rebuilder on the Web.lnk -> C:\Program Files\DVD-RB PRO\Rebuilder.url ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\DVD Rebuilder PRO\DVD Rebuilder.lnk -> C:\Program Files\DVD-RB PRO\Rebuilder.exe (jdobbs softworks)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\DVD Rebuilder PRO\Help.lnk -> C:\Program Files\DVD-RB PRO\Help\DVD-RBHELP.CHM ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\DVD Rebuilder PRO\Uninstall  DVD Rebuilder.lnk -> C:\Program Files\DVD-RB PRO\unins000.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\DVD Rebuilder PRO\Extras (Addons)\CCE & ProCoder - Configuration.lnk -> C:\Program Files\DVD-RB PRO\Config\Encoders.exe (Copyright © 2005 jdobbs softworks in association with Rockas)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Dolphin Futures\XPS Viewer.lnk -> C:\Program Files\Dolphin Futures\XPSViewer\XPSViewer.exe (Dolphin Futures Limited)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Corel Painter X\Corel Painter X User Guide.lnk -> C:\Program Files\Corel\Corel Painter X\Help\PX_UserGuide.pdf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Corel Painter X\Corel Painter X.lnk -> C:\WINDOWS\Installer\{05D60953-9012-44DF-A1A6-9DD97AD6580A}\NewShortcut2.exe_A0383B7D81A249D3BE06C0FD9EFB9DFC_1.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Collectorz.com\Movie Collector\Movie Collector.lnk -> C:\Program Files\Collectorz.com\Movie Collector\MovieCollector.exe (Collectorz.com)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Collectorz.com\Movie Collector\Uninstall Movie Collector.lnk -> C:\Program Files\Collectorz.com\Movie Collector\unins000.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Collectorz.com\Movie Collector\What's New.lnk -> C:\Program Files\Collectorz.com\Movie Collector\Docs\WhatsNew.txt (No File)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner\CCleaner.lnk -> C:\Program Files\CCleaner\ccleaner.exe (Piriform Ltd)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Beyond Compare 2\Beyond Compare 2 Help.lnk -> C:\Program Files\Beyond Compare 2\BC2.chm ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Beyond Compare 2\Beyond Compare 2.lnk -> C:\Program Files\Beyond Compare 2\BC2.exe (Scooter Software)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Beyond Compare 2\Uninstall Beyond Compare 2.lnk -> C:\Program Files\Beyond Compare 2\unins000.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\ASUS\PC Probe II\PC Probe II v1.00.43.lnk -> C:\Program Files\ASUS\PC Probe II\Probe2.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\ASUS\PC Probe II\UnInstall PC Probe II .lnk -> C:\Program Files\InstallShield Installation Information\{F7338FA3-DAB5-49B2-900D-0AFB5760C166}\Setup.exe (InstallShield Software Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Amnesia - The Dark Descent\Amnesia.lnk -> C:\Program Files\Amnesia - The Dark Descent\redist\Launcher.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Amnesia - The Dark Descent\Frictional Games Support.lnk -> C:\Program Files\Amnesia - The Dark Descent\Frictional Games Support.url ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Amnesia - The Dark Descent\Frictional Games.lnk -> C:\Program Files\Amnesia - The Dark Descent\Frictional Games.url ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Amnesia - The Dark Descent\Manual.lnk -> C:\Program Files\Amnesia - The Dark Descent\install_files\eng\Manual.pdf ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Amnesia - The Dark Descent\Uninstall Amnesia.lnk -> C:\Program Files\Amnesia - The Dark Descent\unins000.exe ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\WINDOWS\system32\Com\comexp.msc ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Data Sources (ODBC).lnk -> C:\WINDOWS\system32\odbcad32.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Microsoft .NET Framework 1.1 Configuration.lnk -> C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\mscorcfg.msc ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Microsoft .NET Framework 1.1 Wizards.lnk -> C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe ( )
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Acronis\Acronis True Image Home\Acronis True Image Home.lnk -> C:\Program Files\Acronis\TrueImageHome\TrueImage.exe (Acronis)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Acronis\Acronis True Image Home\Bootable Rescue Media Builder.lnk -> C:\Program Files\Common Files\Acronis\MediaBuilderHome\MediaBuilder.exe (Acronis)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Calculator.lnk -> C:\WINDOWS\system32\calc.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Paint.lnk -> C:\WINDOWS\system32\mspaint.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\WINDOWS\system32\mstsc.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\WordPad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\WINDOWS\system32\windowspowershell\v1.0\powershell_ise.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk -> C:\WINDOWS\system32\windowspowershell\v1.0\powershell.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\WINDOWS\system32\charmap.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\Disk Cleanup.lnk -> C:\WINDOWS\system32\cleanmgr.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\Disk Defragmenter.lnk -> C:\WINDOWS\system32\dfrg.msc ()
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\Files and Settings Transfer Wizard.lnk -> C:\WINDOWS\system32\usmt\migwiz.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\System Information.lnk -> C:\Program Files\Common Files\Microsoft Shared\MSInfo\msinfo32.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\System Restore.lnk -> C:\WINDOWS\system32\Restore\rstrui.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Sound Recorder.lnk -> C:\WINDOWS\system32\sndrec32.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Entertainment\Volume Control.lnk -> C:\WINDOWS\system32\sndvol32.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Communications\HyperTerminal.lnk -> C:\Program Files\Windows NT\hypertrm.exe (Hilgraeve, Inc.)
    Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Accessibility\Accessibility Wizard.lnk -> C:\WINDOWS\system32\accwiz.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\All Users\Desktop\AnyDVD.lnk -> C:\Program Files\RedFox\AnyDVD.exe (RedFox)
    Shortcut: C:\Documents and Settings\All Users\Desktop\Media Player Classic.lnk -> C:\Program Files\K-Lite Codec Pack\MPC-HC\mpc-hc.exe (MPC-HC Team)
    Shortcut: C:\Documents and Settings\All Users\Desktop\Movie Collector.lnk -> C:\Program Files\Collectorz.com\Movie Collector\MovieCollector.exe (Collectorz.com)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Notepad.lnk -> C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Program Compatibility Wizard.lnk -> C:\WINDOWS\system32\compatui.dll ()
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Synchronize.lnk -> C:\WINDOWS\system32\mobsync.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Tour Windows XP.lnk -> C:\WINDOWS\system32\tourstart.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk -> C:\WINDOWS\system32\magnify.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\WINDOWS\system32\narrator.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\system32\osk.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Guest\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Guest\Start Menu\Programs\Accessories\Address Book.lnk -> C:\Program Files\Outlook Express\wab.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Guest\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Guest\Start Menu\Programs\Accessories\Notepad.lnk -> C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Guest\Start Menu\Programs\Accessories\Program Compatibility Wizard.lnk -> C:\WINDOWS\system32\compatui.dll ()
    Shortcut: C:\Documents and Settings\Guest\Start Menu\Programs\Accessories\Synchronize.lnk -> C:\WINDOWS\system32\mobsync.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Guest\Start Menu\Programs\Accessories\Tour Windows XP.lnk -> C:\WINDOWS\system32\tourstart.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Guest\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Guest\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk -> C:\WINDOWS\system32\magnify.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Guest\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\WINDOWS\system32\narrator.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Guest\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\system32\osk.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Guest\My Documents\My Pictures\Sample Pictures.lnk -> C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures ()
    Shortcut: C:\Documents and Settings\Guest\My Documents\My Music\Sample Music.lnk -> C:\Documents and Settings\All Users\Documents\My Music\Sample Music ()
    Shortcut: C:\Documents and Settings\Guest\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\LocalService\Start Menu\Programs\Accessories\Synchronize.lnk -> C:\WINDOWS\system32\mobsync.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\NetworkService\Start Menu\Programs\Accessories\Synchronize.lnk -> C:\WINDOWS\system32\mobsync.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Windows Install Clean Up.lnk -> C:\Documents and Settings\Robert\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\WinRAR\Console RAR manual.lnk -> C:\Program Files\WinRAR\Rar.txt ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\WinRAR\WinRAR help.lnk -> C:\Program Files\WinRAR\WinRAR.hlp ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.exe ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Webroot\Window Washer\Uninstall Window Washer.lnk -> C:\WINDOWS\Unwash6.exe (Webroot Software, Inc.)
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Webroot\Window Washer\Window Washer Help.lnk -> C:\Program Files\Webroot\Washer\Documents\Washer6.chm ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Unlocker\README.lnk -> C:\Program Files\Unlocker\README.TXT ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Unlocker\Start Unlocker Assistant.lnk -> C:\Program Files\Unlocker\UnlockerAssistant.exe ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Unlocker\Start Unlocker.lnk -> C:\Program Files\Unlocker\Unlocker.exe ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Unlocker\Uninstall.lnk -> C:\Program Files\Unlocker\uninst.exe ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Unlocker\Website.lnk -> C:\Program Files\Unlocker\Unlocker.url ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Portforward.com\Portforward Setup Static IP Address\Portforward Setup Static IP Address.lnk -> C:\Program Files\PFStaticIP\PFStaticIP.exe (Portforward.com)
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Portforward.com\Portforward Setup Static IP Address\Uninstall.lnk -> C:\Program Files\PFStaticIP\uninst.exe ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Portforward.com\PFPortChecker\PFPortChecker.lnk -> C:\Program Files\PFPortChecker\PFPortChecker.exe (portforward.com)
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Portforward.com\PFPortChecker\Uninstall.lnk -> C:\Program Files\PFPortChecker\uninst.exe ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Portforward.com\PFConfig\PFConfig.lnk -> C:\Program Files\PFConfig\PFConfigLauncher.exe (PFConfigLauncher is part of PFConfig. Please allow access through your firewall to properly configure your router.)
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Portforward.com\PFConfig\Uninstall.lnk -> C:\Program Files\PFConfig\uninst.exe ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\OriginLab\OriginPro 7.5\OriginPro 7.5 Add or Remove Files.lnk -> C:\Program Files\InstallShield Installation Information\{ECE12161-B445-48FA-9056-FD54D8A72459}\Setup.exe (InstallShield Software Corporation)
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\OriginLab\OriginPro 7.5\OriginPro 7.5.lnk -> C:\Program Files\OriginLab\OriginPro75\origin75.exe (OriginLab Corporation)
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Oak Systems\Sudoku Works\Sudoku Works Help.lnk -> C:\Program Files\Oak Systems\Sudoku Works\sudoku.chm ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Oak Systems\Sudoku Works\Sudoku Works.lnk -> C:\Program Files\Oak Systems\Sudoku Works\SudokuWorks.exe (Oak Systems  www.oak-systems.co.uk)
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Exact Audio Copy\Exact Audio Copy.lnk -> C:\Program Files\Exact Audio Copy\EAC.exe ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Exact Audio Copy\FAQ.lnk -> C:\Program Files\Exact Audio Copy\Documentation\FAQ.txt ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Exact Audio Copy\Legal.lnk -> C:\Program Files\Exact Audio Copy\Legal.rtf ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Exact Audio Copy\News.lnk -> C:\Program Files\Exact Audio Copy\News.rtf ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Exact Audio Copy\Uninstall.lnk -> C:\Program Files\Exact Audio Copy\uninst.exe ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\DVD Decrypter\DVD Decrypter Read Me.lnk -> C:\Program Files\DVD Decrypter\ReadMe.txt ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\DVD Decrypter\DVD Decrypter.lnk -> C:\Program Files\DVD Decrypter\DVDDecrypter.exe (LIGHTNING UK!)
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\DVD Decrypter\Uninstall.lnk -> C:\Program Files\DVD Decrypter\uninstall.exe ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\CCleaner\CCleaner.lnk -> C:\Program Files\CCleaner\ccleaner.exe (Piriform Ltd)
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\AviSynth 2.5\Plugin Directory.lnk -> C:\Program Files\AviSynth 2.5\plugins ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\AVIcodec\AVIcodec.lnk -> C:\Program Files\AVIcodec\AVIcodec.exe (P. Duby Productions)
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\AVIcodec\Uninstall.lnk -> C:\Program Files\AVIcodec\uninst.exe ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Accessories\Address Book.lnk -> C:\Program Files\Outlook Express\wab.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Accessories\Notepad.lnk -> C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Accessories\Program Compatibility Wizard.lnk -> C:\WINDOWS\system32\compatui.dll ()
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Accessories\Synchronize.lnk -> C:\WINDOWS\system32\mobsync.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Accessories\Tour Windows XP.lnk -> C:\WINDOWS\system32\tourstart.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk -> C:\WINDOWS\system32\magnify.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\WINDOWS\system32\narrator.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Robert\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\system32\osk.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Robert\SendTo\Dropbox.lnk -> C:\Documents and Settings\Robert\My Documents\Dropbox ()
    Shortcut: C:\Documents and Settings\Robert\SendTo\IsoBuster.lnk -> C:\Program Files\Iso Buster 3.5.5\IsoBuster\IsoBuster.exe (Smart Projects)
    Shortcut: C:\Documents and Settings\Robert\My Documents\Spider Solitaire.lnk -> C:\WINDOWS\system32\spider.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\Robert\My Documents\My Pictures\Sample Pictures.lnk -> C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures ()
    Shortcut: C:\Documents and Settings\Robert\My Documents\My Music\Sample Music.lnk -> C:\Documents and Settings\All Users\Documents\My Music\Sample Music ()
    Shortcut: C:\Documents and Settings\Robert\Local Settings\Application Data\Collectorz.com\Movie Collector\MCE\Movie Collector MCE.lnk -> C:\WINDOWS\ehome\ehshell.exe (No File)
    Shortcut: C:\Documents and Settings\Robert\Desktop\Algonquin Map.lnk -> C:\Documents and Settings\Robert\My Documents\alg22a.pdf ()
    Shortcut: C:\Documents and Settings\Robert\Desktop\Amnesia.lnk -> C:\Program Files\Amnesia - The Dark Descent\redist\Launcher.exe ()
    Shortcut: C:\Documents and Settings\Robert\Desktop\Excel 2007.lnk -> C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe ()
    Shortcut: C:\Documents and Settings\Robert\Desktop\Outlook 2007.lnk -> C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe ()
    Shortcut: C:\Documents and Settings\Robert\Desktop\Tweaking.com - Windows Repair.lnk -> C:\Program Files\Tweaking.com\Windows Repair (All in One)\Repair_Windows.exe (Tweaking.com)
    Shortcut: C:\Documents and Settings\Robert\Desktop\uTorrent.lnk -> C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
    Shortcut: C:\Documents and Settings\Robert\Desktop\Word 2007.lnk -> C:\WINDOWS\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe ()
    Shortcut: C:\Documents and Settings\Robert\Application Data\Microsoft\Internet Explorer\Quick Launch\IsoBuster.lnk -> C:\Program Files\Iso Buster 3.5.5\IsoBuster\IsoBuster.exe (Smart Projects)
    Shortcut: C:\Documents and Settings\Robert\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
    Shortcut: C:\Documents and Settings\Robert\Application Data\Microsoft\Internet Explorer\Quick Launch\MSConfigCleanUp.lnk -> C:\Program Files\MSConfig CleanUp\MSConfigCleanUp.exe (Virtuoza)
    Shortcut: C:\Documents and Settings\Robert\Application Data\Microsoft\Internet Explorer\Quick Launch\SolidWorks 2008 SP3.0.lnk -> C:\WINDOWS\Installer\{266EB766-9ABB-40D0-AB9F-41EE46D23876}\i386_SldWorks.exe (Macrovision Corporation)
    Shortcut: C:\Documents and Settings\Robert\Application Data\Microsoft\Internet Explorer\Quick Launch\SolidWorks Explorer.lnk -> C:\WINDOWS\Installer\{A8567E18-9E80-4EA3-A5C1-A6186C86F2CC}\NewShortcut1.exe (Macrovision Corporation)
    Shortcut: C:\Documents and Settings\Robert\Application Data\Microsoft\Internet Explorer\Quick Launch\XPS Viewer.lnk -> C:\Program Files\Dolphin Futures\XPSViewer\XPSViewer.exe (Dolphin Futures Limited)
    Shortcut: C:\Documents and Settings\Robert\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk -> C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
    Shortcut: C:\Documents and Settings\Robert\Application Data\Adobe\Workflow\working.lnk -> C:\Documents and Settings\Robert\My Documents\Version Cue ()
    Shortcut: C:\Documents and Settings\Robert\Application Data\Adobe\Workflow\workinghidden.lnk -> C:\Documents and Settings\Robert\My Documents\Version Cue\myprojectshidden ()
    Shortcut: C:\Documents and Settings\UpdatusUser\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\UpdatusUser\Start Menu\Programs\Accessories\Notepad.lnk -> C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\UpdatusUser\Start Menu\Programs\Accessories\Program Compatibility Wizard.lnk -> C:\WINDOWS\system32\compatui.dll ()
    Shortcut: C:\Documents and Settings\UpdatusUser\Start Menu\Programs\Accessories\Synchronize.lnk -> C:\WINDOWS\system32\mobsync.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\UpdatusUser\Start Menu\Programs\Accessories\Tour Windows XP.lnk -> C:\WINDOWS\system32\tourstart.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\UpdatusUser\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\UpdatusUser\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk -> C:\WINDOWS\system32\magnify.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\UpdatusUser\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\WINDOWS\system32\narrator.exe (Microsoft Corporation)
    Shortcut: C:\Documents and Settings\UpdatusUser\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\WINDOWS\system32\osk.exe (Microsoft Corporation)




    ShortcutWithArgument: C:\Documents and Settings\Administrator\Start Menu\Programs\Remote Assistance.lnk -> C:\WINDOWS\system32\rcimlby.exe (Microsoft Corporation) -> -LaunchRA
    ShortcutWithArgument: C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk -> C:\WINDOWS\system32\utilman.exe (Microsoft Corporation) -> /start
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Microsoft Update.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> C:\WINDOWS\system32\muweb.dll,LaunchMUSite
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk -> C:\WINDOWS\system32\control.exe (Microsoft Corporation) -> appwiz.cpl,,3
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Your Uninstaller 2010\Your Uninstaller! - Hunter Mode.lnk -> C:\Program Files\Your Uninstaller 2010\urmain.exe (URSoft,Inc) -> -hunter
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Tweaking.com\Windows Repair (All in One)\Uninstall Tweaking.com - Windows Repair.lnk -> C:\Program Files\Tweaking.com\Windows Repair (All in One)\uninstall.exe (Indigo Rose Corporation) -> "/U:C:\Program Files\Tweaking.com\Windows Repair (All in One)\Uninstall\uninstall.xml"
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\SolidWorks Installation Manager\Check For Updates.lnk -> C:\Program Files\Common Files\SolidWorks Installation Manager\Scheduler\sldIMScheduler.exe (Dassault Systemes) -> /check 0
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\SolidWorks 2008\COSMOSMotion 2008.lnk -> C:\Program Files\SolidWorks\SLDWORKS.exe (Dassault Systemes) -> /m "C:\Program Files\SolidWorks\COSMOS\Motion For SolidWorks\load_cosmos.swb"
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\SolidWorks 2008\COSMOSWorks 2008.lnk -> C:\Program Files\SolidWorks\SLDWORKS.exe (Dassault Systemes) -> /m "C:\Program Files\SolidWorks\COSMOS\load_cosmos.swb"
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\RedFox\AnyDVD\AnyDVD Image Ripper.lnk -> C:\Program Files\RedFox\AnyDVD.exe (RedFox) -> -iso
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\RedFox\AnyDVD\AnyDVD Ripper.lnk -> C:\Program Files\RedFox\AnyDVD.exe (RedFox) -> -r
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\RedFox\AnyDVD\AnyDVD System Information.lnk -> C:\Program Files\RedFox\AnyDVD.exe (RedFox) -> -syslog
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Nero Home.lnk -> C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Nero ProductSetup.lnk -> C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe (Nero AG) -> -ScParameter=8  MODE="update"
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Nero StartSmart.lnk -> C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Tools\Nero BurnRights.lnk -> C:\Program Files\Nero\Nero 7\Nero Toolkit\NeroBurnRights.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Tools\Nero CD-DVD Speed.lnk -> C:\Program Files\Nero\Nero 7\Nero Toolkit\CDSpeed.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Tools\Nero DriveSpeed.lnk -> C:\Program Files\Nero\Nero 7\Nero Toolkit\DriveSpeed.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Tools\Nero ImageDrive.lnk -> C:\Program Files\Nero\Nero 7\Nero ImageDrive\ImageDrive.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Tools\Nero InfoTool.lnk -> C:\Program Files\Nero\Nero 7\Nero Toolkit\InfoTool.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Tools\Nero Scout.lnk -> C:\Program Files\Common Files\Ahead\Lib\NeroScoutOptions.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Share\Nero MediaHome.lnk -> C:\Program Files\Nero\Nero 7\Nero MediaHome\NeroMediaHome.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Play\Nero ShowTime.lnk -> C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Photo and Video\Nero PhotoSnap Viewer.lnk -> C:\Program Files\Nero\Nero 7\Nero PhotoSnap\PhotoSnapViewer.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Photo and Video\Nero PhotoSnap.lnk -> C:\Program Files\Nero\Nero 7\Nero PhotoSnap\PhotoSnap.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Photo and Video\Nero Recode.lnk -> C:\Program Files\Nero\Nero 7\Nero Recode\Recode.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Photo and Video\Nero Vision.lnk -> C:\Program Files\Nero\Nero 7\Nero Vision\NeroVision.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Labels\Nero CoverDesigner.lnk -> C:\Program Files\Nero\Nero 7\Nero CoverDesigner\CoverDes.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Data\Nero BackItUp.lnk -> C:\Program Files\Nero\Nero 7\Nero BackItUp\BackItUp.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Data\Nero Burning ROM.lnk -> C:\Program Files\Nero\Nero 7\Core\nero.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Data\Nero Express.lnk -> C:\Program Files\Nero\Nero 7\Core\nero.exe (Nero AG) -> -ScParameter=8  /w
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Audio\Nero Burning ROM.lnk -> C:\Program Files\Nero\Nero 7\Core\nero.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Audio\Nero Express.lnk -> C:\Program Files\Nero\Nero 7\Core\nero.exe (Nero AG) -> -ScParameter=8  /w
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Nero 7 Ultra Edition\Audio\Nero WaveEditor.lnk -> C:\Program Files\Nero\Nero 7\Nero WaveEditor\waveedit.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office\Microsoft Office Tools\Microsoft Office Project Server 2007 Accounts.lnk -> C:\WINDOWS\Installer\{90120000-003B-0000-0000-0000000FF1CE}\pj11icon.exe () -> -ProjectProfiles
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\MathType 5\Equation Conversion Manager.lnk -> C:\Program Files\MathType\Setup.exe (Design Science, Inc.) -> -OLEMGR
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\MathType 5\MathType Read Me.lnk -> C:\WINDOWS\system32\winhlp32.exe (Microsoft Corporation) -> -n 1002 C:\Program Files\MathType\MT5ENU.HLP
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\MathType 5\MathType Server.lnk -> C:\Program Files\MathType\MathType.exe (Design Science, Inc.) -> -server
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\MathType 5\Remove MathType.lnk -> C:\Program Files\MathType\Setup.exe (Design Science, Inc.) -> -R
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Maple 12\Command-line Maple 12.lnk -> C:\Program Files\Maple 12\bin.win\cmaple.exe () -> -I  "C:\Program Files\Maple 12\lib\include"
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Maple 12\Shared Server Maple 12.lnk -> C:\Program Files\Maple 12\bin.win\maplew.exe (Maplesoft) -> -km s
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Learning Essentials\Learning Essentials for Students.lnk -> C:\Program Files\Learning Essentials\1.0\UserCenter.exe (Microsoft Corporation) -> /mode student
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Kyodai Mahjongg 2006\Reset to Default Options.lnk -> C:\Program Files\Kyodai Mahjongg 2006\kmj.exe (Rene-Gilles Deberdt) -> /reset
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Configuration\DirectVobSub.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files\K-Lite Codec Pack\Filters\vsfilter.dll",DirectVobSub
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Configuration\ffdshow audio decoder.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files\K-Lite Codec Pack\Filters\ffdshow\ffdshow.ax",configureAudio
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Configuration\ffdshow VFW interface.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> "C:\WINDOWS\system32\ff_vfw.dll",configureVFW
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Configuration\ffdshow video decoder.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files\K-Lite Codec Pack\Filters\ffdshow\ffdshow.ax",configure
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Audio.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files\K-Lite Codec Pack\Filters\LAV\lavaudio.ax",OpenConfiguration
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Splitter.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files\K-Lite Codec Pack\Filters\LAV\lavsplitter.ax",OpenConfiguration
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Video.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> "C:\Program Files\K-Lite Codec Pack\Filters\LAV\lavvideo.ax",OpenConfiguration
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Configuration\madVR.lnk -> C:\Program Files\K-Lite Codec Pack\Filters\madVR\madHcCtrl.exe (madshi.net) -> editLocalSettingsDontWait
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Configuration\Reset to recommended settings.lnk -> C:\Program Files\K-Lite Codec Pack\Tools\CodecTweakTool.exe () -> /resetsettings
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Configuration\x264 VFW (x86).lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> "C:\WINDOWS\system32\x264vfw.dll",Configure
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack\Configuration\Xvid VFW.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> "C:\WINDOWS\system32\xvidvfw.dll",Configure
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Intel Corporation\Intel Processor Diagnostic Tool\Uninstall Intel Processor Diagnostic Tool.lnk -> C:\WINDOWS\system32\msiexec.exe (Microsoft Corporation) -> /x {C53C4130-CC50-40F3-9457-A7D4A2B980BC}
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\ImageConverter Plus\ImageConverter Plus.lnk -> C:\Program Files\ImageConverter Plus\icp.exe (fCoder Group, Inc.) -> -show
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Easy CD-DA Extractor 2011\Programs\Audio CD Ripper.lnk -> C:\Program Files\Easy CD-DA Extractor 2011\ezcddax.exe (Poikosoft) -> -R
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Easy CD-DA Extractor 2011\Programs\Audio Converter.lnk -> C:\Program Files\Easy CD-DA Extractor 2011\ezcddax.exe (Poikosoft) -> -C
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Easy CD-DA Extractor 2011\Programs\CD-DVD Creator.lnk -> C:\Program Files\Easy CD-DA Extractor 2011\ezcddax.exe (Poikosoft) -> -B
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Easy CD-DA Extractor 2011\Programs\Metadata Editor.lnk -> C:\Program Files\Easy CD-DA Extractor 2011\ezcddax.exe (Poikosoft) -> -E
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Corel Painter X\Register.lnk -> C:\WINDOWS\Installer\{05D60953-9012-44DF-A1A6-9DD97AD6580A}\RegisterShortcut_A0383B7D81A249D3BE06C0FD9EFB9DFC_1.exe () -> DTAName=corelpainter.dta languagecode=EN
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\WINDOWS\system32\compmgmt.msc () -> /s
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\WINDOWS\system32\eventvwr.msc () -> /s
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Performance.lnk -> C:\WINDOWS\system32\perfmon.msc () -> /s
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk -> C:\WINDOWS\system32\services.msc () -> /s
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Scanner and Camera Wizard.lnk -> C:\WINDOWS\system32\wiaacmgr.exe (Microsoft Corporation) -> -SelectDevice
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\Scheduled Tasks.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> ::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{21EC2020-3AEA-1069-A2DD-08002B30309D}\::{D6277990-4C6A-11CF-8D87-00AA0060F5BF}
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Communications\Network Connections.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> ::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{21EC2020-3AEA-1069-A2DD-08002B30309D}\::{7007acc7-3202-11d1-aad2-00805fc1270e}
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Communications\Network Setup Wizard.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> hnetwiz.dll,HomeNetWizardRunDll
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Communications\New Connection Wizard.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> netshell.dll,StartNCW
    ShortcutWithArgument: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Communications\Wireless Network Setup Wizard.lnk -> C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation) -> shell32.dll,Control_RunDLL NetSetup.cpl,@0,WNSW
    ShortcutWithArgument: C:\Documents and Settings\Default User\Start Menu\Programs\Remote Assistance.lnk -> C:\WINDOWS\system32\rcimlby.exe (Microsoft Corporation) -> -LaunchRA
    ShortcutWithArgument: C:\Documents and Settings\Default User\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
    ShortcutWithArgument: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
    ShortcutWithArgument: C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk -> C:\WINDOWS\system32\utilman.exe (Microsoft Corporation) -> /start
    ShortcutWithArgument: C:\Documents and Settings\Guest\Start Menu\Programs\Remote Assistance.lnk -> C:\WINDOWS\system32\rcimlby.exe (Microsoft Corporation) -> -LaunchRA
    ShortcutWithArgument: C:\Documents and Settings\Guest\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
    ShortcutWithArgument: C:\Documents and Settings\Guest\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
    ShortcutWithArgument: C:\Documents and Settings\Guest\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk -> C:\WINDOWS\system32\utilman.exe (Microsoft Corporation) -> /start
    ShortcutWithArgument: C:\Documents and Settings\LocalService\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
    ShortcutWithArgument: C:\Documents and Settings\LocalService\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
    ShortcutWithArgument: C:\Documents and Settings\Robert\Start Menu\Programs\Remote Assistance.lnk -> C:\WINDOWS\system32\rcimlby.exe (Microsoft Corporation) -> -LaunchRA
    ShortcutWithArgument: C:\Documents and Settings\Robert\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
    ShortcutWithArgument: C:\Documents and Settings\Robert\Start Menu\Programs\Webroot\Window Washer\Window Washer.lnk -> C:\Program Files\Webroot\Washer\wwDisp.exe (Webroot Software, Inc.) -> /shortcut
    ShortcutWithArgument: C:\Documents and Settings\Robert\Start Menu\Programs\OriginLab\OriginPro 7.5\OriginPro 7.5 PFM.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> C:\Program Files\OriginLab\OriginPro75\PFM
    ShortcutWithArgument: C:\Documents and Settings\Robert\Start Menu\Programs\OriginLab\OriginPro 7.5\OriginPro 7.5 Sample Projects and Data.lnk -> C:\WINDOWS\explorer.exe (Microsoft Corporation) -> C:\Program Files\OriginLab\OriginPro75\Samples
    ShortcutWithArgument: C:\Documents and Settings\Robert\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) ->  -extoff
    ShortcutWithArgument: C:\Documents and Settings\Robert\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
    ShortcutWithArgument: C:\Documents and Settings\Robert\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk -> C:\WINDOWS\system32\utilman.exe (Microsoft Corporation) -> /start
    ShortcutWithArgument: C:\Documents and Settings\Robert\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk -> C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE (Microsoft Corporation) ->  /recycle
    ShortcutWithArgument: C:\Documents and Settings\Robert\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero Home.lnk -> C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\Robert\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart.lnk -> C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe (Nero AG) -> -ScParameter=8  
    ShortcutWithArgument: C:\Documents and Settings\Robert\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
    ShortcutWithArgument: C:\Documents and Settings\UpdatusUser\Start Menu\Programs\Remote Assistance.lnk -> C:\WINDOWS\system32\rcimlby.exe (Microsoft Corporation) -> -LaunchRA
    ShortcutWithArgument: C:\Documents and Settings\UpdatusUser\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
    ShortcutWithArgument: C:\Documents and Settings\UpdatusUser\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk -> C:\Program Files\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
    ShortcutWithArgument: C:\Documents and Settings\UpdatusUser\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk -> C:\WINDOWS\system32\utilman.exe (Microsoft Corporation) -> /start


    InternetURL: C:\Documents and Settings\All Users\Start Menu\Programs\Your Uninstaller 2010\Visit our site.url -> URL: hxxp://www.ursoftware.com/?ref=setup
    InternetURL: C:\Documents and Settings\All Users\Start Menu\Programs\DVDFab 9\DVDFab Online.url -> URL: hxxp://www.dvdfab.cn/
    InternetURL: C:\Documents and Settings\All Users\Start Menu\Programs\Collectorz.com\Movie Collector\Movie Collector Website.url -> URL: hxxp://www.collectorz.com/movie/
    InternetURL: C:\Documents and Settings\All Users\Start Menu\Programs\Collectorz.com\Movie Collector\Website.url -> URL: hxxp://www.collectorz.com/movie/
    InternetURL: C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner\CCleaner Homepage.url -> URL: hxxp://www.piriform.com/ccleaner
    InternetURL: C:\Documents and Settings\All Users\Start Menu\Programs\Acronis\Acronis True Image Home\Acronis Web Site.url -> URL: hxxp://www.acronis.eu
    InternetURL: C:\Documents and Settings\Guest\Favorites\Links\Windows Marketplace.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=30857&clcid=0x409
    InternetURL: C:\Documents and Settings\Robert\Start Menu\Programs\CCleaner\CCleaner Homepage.url -> URL: hxxp://www.ccleaner.com/
    InternetURL: C:\Documents and Settings\Robert\Start Menu\Programs\AviSynth 2.5\AviSynth Online.url -> URL: hxxp://www.avisynth.org
    InternetURL: C:\Documents and Settings\Robert\Start Menu\Programs\AviSynth 2.5\Download Plugins.url -> URL: hxxp://www.avisynth.org/warpenterprises/
    InternetURL: C:\Documents and Settings\Robert\Favorites\.The FAN 590 .url -> BASEURL: hxxp://www.fan590.com/ URL: hxxp://www.fan590.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\2013 Calendar.url -> BASEURL: hxxp://www.printfree.com/Calendar_files/Yearly/2013printable.htm URL: hxxp://www.printfree.com/Calendar_files/Yearly/2013printable.htm
    InternetURL: C:\Documents and Settings\Robert\Favorites\2013 Ride for Cancer - Beatrice site.url -> BASEURL: hxxp://www.conquercancer.ca/site/TR/Events/Toronto2013?px=2868938&pg=personal&fr_id=1431 URL: hxxp://www.conquercancer.ca/site/TR/Events/Toronto2013?px=2868938&pg=personal&fr_id=1431
    InternetURL: C:\Documents and Settings\Robert\Favorites\2014 Calendar.url -> BASEURL: hxxp://www.printfree.com/Calendar_files/Yearly/2014printable.htm URL: hxxp://www.printfree.com/Calendar_files/Yearly/2014printable.htm
    InternetURL: C:\Documents and Settings\Robert\Favorites\Autoplay - Windows XP Home and Professional.url -> BASEURL: hxxp://www.bleepingcomputer.com/forums/t/482222/autoplay/ URL: hxxp://www.bleepingcomputer.com/forums/t/482222/autoplay/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Canadian Red Cross - Etobicoke Branch - Meals on Wheels - centralhealthline.ca.url -> BASEURL: hxxp://www.centralhealthline.ca/displayservice.aspx?id=142430 URL: hxxp://www.centralhealthline.ca/displayservice.aspx?id=142430
    InternetURL: C:\Documents and Settings\Robert\Favorites\Daily currency converter - Bank of Canada.url -> BASEURL: hxxp://www.bankofcanada.ca/rates/exchange/daily-converter/ URL: hxxp://www.bankofcanada.ca/rates/exchange/daily-converter/
    InternetURL: C:\Documents and Settings\Robert\Favorites\EasyWeb.url -> BASEURL: hxxps://easywebcpo.td.com/waw/idp/login.htm?execution=e1s1 URL: hxxps://easywebcpo.td.com/waw/idp/login.htm?execution=e1s1
    InternetURL: C:\Documents and Settings\Robert\Favorites\Google Search.url -> URL: hxxp://easy-google-search.blogspot.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Honda Accord Forum - Honda Accord Enthusiast Forums - Powered by vBulletin.url -> BASEURL: hxxp://www.hondaaccordforum.com/forum/ URL: hxxp://www.hondaaccordforum.com/forum/
    InternetURL: C:\Documents and Settings\Robert\Favorites\How NOT to install Puppy Linux (to hard disk).url -> BASEURL: hxxp://puppylinux.org/main/How%20NOT%20to%20install%20Puppy.htm URL: hxxp://puppylinux.org/main/How%20NOT%20to%20install%20Puppy.htm
    InternetURL: C:\Documents and Settings\Robert\Favorites\How to slipstream an XP disc with SP3 and all other updates  Expert Reviews.url -> BASEURL: hxxp://www.expertreviews.co.uk/software/1306762/how-to-slipstream-an-xp-disc-with-sp3-and-all-other-updates URL: http%3A%2F%2Fwww.expertreviews.co.uk%2Fsoftware%2F1306762%2Fhow-to-slipstream-an-xp-disc-with-sp3-and-all-other-updates&dt=1396389804765&bpp=1&shv=r20140327&cbv=r20140311&saldr=sa&correlator=1396389804781&frm=20&ga_vid=1271475424.1396389588&ga_sid=1396389588&ga_hid=329731509&ga_fc=1&u_tz=-240&u_his=4&u_java=1&u_h=768&u_w=1024&u_ah=734&u_aw=1024&u_cd=32&u_nplug=0&u_nmime=0&dff=arial&dfs=12&adx=488&ady=2032&biw=995&bih=584&eid=317150304&oid=3&ref=http%3A%2F%2Fwww.expertreviews.co.uk%2Fsoftware%2F1304965%2Fwhen-windows-xp-support-ends-this-is-how-you-secure-your-pc-and-save-all-updates&rx=0&eae=4&docm=8&vis=0&fu=0&ifi=1&dtd=47
    InternetURL: C:\Documents and Settings\Robert\Favorites\Puppy Linux Discussion Forum  View topic - How do you insert a DVD film disc and it plays automatically.url -> BASEURL: hxxp://murga-linux.com/puppy/viewtopic.php?t=60032&sid=5120318fd984748a7cad099734478fbc URL: hxxp://murga-linux.com/puppy/viewtopic.php?t=60032&sid=5120318fd984748a7cad099734478fbc
    InternetURL: C:\Documents and Settings\Robert\Favorites\Shop Swiss  Contact Us.url -> BASEURL: hxxp://www.shopswiss.com/Default.aspx?tabid=226 URL: hxxp://www.shopswiss.com/Default.aspx?tabid=226
    InternetURL: C:\Documents and Settings\Robert\Favorites\Snorg Tees - New Funny T-Shirts Every Week (Vintage T-Shirt, Cool Graphic Tee Shirts).url -> BASEURL: hxxp://www.snorgtees.com/?utm_source=UD&utm_medium=Banner&utm_content=160by600_glassfull_4&utm_campaign=UD&sn_prod=technically-the-glass-is-always-full URL: hxxp://www.snorgtees.com/?utm_source=UD&utm_medium=Banner&utm_content=160by600_glassfull_4&utm_campaign=UD&sn_prod=technically-the-glass-is-always-full
    InternetURL: C:\Documents and Settings\Robert\Favorites\TSN.url -> BASEURL: hxxp://www.tsn.ca/ URL: hxxp://www.tsn.ca/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Volunteer Form  Act  Ontario Nature.url -> BASEURL: hxxp://www.ontarionature.org/act/volunteer_form.php URL: hxxp://www.ontarionature.org/act/volunteer_form.php
    InternetURL: C:\Documents and Settings\Robert\Favorites\Welcome to Calendaria.url -> BASEURL: hxxp://www.calendaria.ch/ URL: hxxp://www.calendaria.ch/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Torrent Sites\- SUMOTorrent.com.url -> BASEURL: hxxp://www.sumotorrent.com/infos.php?page=policy URL: hxxp://www.sumotorrent.com/infos.php?page=policy
    InternetURL: C:\Documents and Settings\Robert\Favorites\Torrent Sites\BitTorrentMonster.url -> BASEURL: hxxp://www.btmon.com/browse/ URL: hxxp://www.btmon.com/browse/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Torrent Sites\CD Freaks.com .url -> BASEURL: hxxp://www.cdfreaks.com/ URL: hxxp://www.cdfreaks.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Torrent Sites\Demonoid.me.url -> BASEURL: hxxp://www.demonoid.me/ URL: http%3A%2F%2Fwww.demonoid.me%2F
    InternetURL: C:\Documents and Settings\Robert\Favorites\Torrent Sites\introductions Rules, FAQ and Registration Form.url -> BASEURL: hxxp://www.torrent-invites.com/starting-member-lounge/45689-introductions-rules-faq-registration-form.html URL: hxxp://www.torrent-invites.com/starting-member-lounge/45689-introductions-rules-faq-registration-form.html
    InternetURL: C:\Documents and Settings\Robert\Favorites\Torrent Sites\isoHunt.url -> BASEURL: hxxp://isohunt.com/ URL: hxxp://isohunt.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Torrent Sites\KickassTorrents.url -> BASEURL: hxxp://kat.ph/ URL: hxxp://kat.ph/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Torrent Sites\Meganova Torrents .url -> BASEURL: hxxp://www.meganova.org/ URL: hxxp://www.meganova.org/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Torrent Sites\The Pirate Bay - The galaxy's most resilient bittorrent site.url -> BASEURL: hxxp://thepiratebay.se/browse URL: hxxp://thepiratebay.se/browse
    InternetURL: C:\Documents and Settings\Robert\Favorites\Torrent Sites\The Pirate Bay.url -> BASEURL: hxxp://thepiratebay.org/ URL: hxxp://thepiratebay.org/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Torrent Sites\Torrent Portal.url -> BASEURL: hxxp://www.torrentportal.com/ URL: hxxp://www.torrentportal.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Torrent Sites\TorrentReactor.Net.url -> BASEURL: hxxp://www.torrentreactor.net/ URL: hxxp://www.torrentreactor.net/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Stereo\Dual Garage 'A Records Phonograph Cartridges.url -> BASEURL: hxxp://www.garage-a-records.com/index.php URL: hxxp://www.garage-a-records.com/index.php
    InternetURL: C:\Documents and Settings\Robert\Favorites\Stereo\Dual-Reference Website.url -> BASEURL: hxxp://www.dual-reference.com/ URL: hxxp://www.dual-reference.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Stereo\FixMyDual.com - .url -> BASEURL: hxxp://www.fixmydual.com/ URL: hxxp://www.fixmydual.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Stereo\http--www.canadianastatic.com-.url -> BASEURL: hxxp://www.canadianastatic.com/ URL: hxxp://www.canadianastatic.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Stereo\National Sound - 644 Queen Street West, Toronto.url -> BASEURL: hxxp://www.nationalsound.ca/products.html URL: hxxp://www.nationalsound.ca/products.html
    InternetURL: C:\Documents and Settings\Robert\Favorites\Stereo\Needle Doctor.url -> BASEURL: hxxp://www.needledoctor.com/ URL: hxxp://www.needledoctor.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Stereo\ROTEL RA612 812 REPAIR Manual.url -> BASEURL: hxxp://www.tradebit.com/filedetail.php/2084877-Documents-eBooks URL: hxxp://www.tradebit.com/filedetail.php/2084877-Documents-eBooks
    InternetURL: C:\Documents and Settings\Robert\Favorites\Stereo\Turntable Forum • Stylus Overhang.url -> BASEURL: hxxp://www.vinylengine.com/turntable_forum/viewtopic.php?f=19&t=50091 URL: http%3A%2F%2Fwww.vinylengine.com%2Fturntable_forum%2Fviewtopic.php%3Ff%3D19%26t%3D50091&dt=1347923883328&bpp=15&shv=r20120905&jsv=r20110914&correlator=1347923883500&frm=20&adk=1993389537&ga_vid=955713732.1347923884&ga_sid=1347923884&ga_hid=1996302959&ga_fc=1&u_tz=-240&u_his=3&u_java=1&u_h=768&u_w=1024&u_ah=734&u_aw=1024&u_cd=32&u_nplug=0&u_nmime=0&dff=verdana&dfs=11&adx=133&ady=376&biw=995&bih=584&oid=3&ref=http%3A%2F%2Fwww.google.ca%2Furl%3Fsa%3Dt%26rct%3Dj%26q%3Ddual%2520601%2520turntable%2520alignment%2520gauge%26source%3Dweb%26cd%3D2%26sqi%3D2%26ved%3D0CCUQFjAB%26url%3Dhttp%253A%252F%252Fwww.vinylengine.com%252Fturntable_forum%252Fviewtopic.php%253Ff%253D19%2526t%253D50091%26ei%3Dfa9XUN39C-u40QHrhIGoAg%26usg%3DAFQjCNFmsbEaybGSw6PK_fdM_nsC9beANA&docm=8&fu=0&ifi=1&dtd=297&xpc=bKE49b5RQA&p=http%3A//www.vinylengine.com
    InternetURL: C:\Documents and Settings\Robert\Favorites\Stereo\Vinyl Engine  The Home of the Turntable.url -> BASEURL: hxxp://www.vinylengine.com/ URL: hxxp://www.vinylengine.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\PFConfig\bell Changing firewall settings (advanced users).url -> BASEURL: hxxps://internet.bell.ca/index.cfm?method=content.view&category_id=675&content_id=12851 URL: hxxps://internet.bell.ca/index.cfm?method=content.view&category_id=675&content_id=12851
    InternetURL: C:\Documents and Settings\Robert\Favorites\PFConfig\bell Efficient Networks SpeedStream 4200 modem.url -> BASEURL: hxxp://internet.bell.ca/index.cfm?method=content.view&category_id=621&content_id=5384 URL: hxxp://internet.bell.ca/index.cfm?method=content.view&category_id=621&content_id=5384
    InternetURL: C:\Documents and Settings\Robert\Favorites\PFConfig\Bridge Mode Router Connection Guide - SpeedStream 4200.url -> BASEURL: hxxp://speedstream4200.com/bridge-mode/connecting-router/ URL: hxxp://speedstream4200.com/bridge-mode/connecting-router/
    InternetURL: C:\Documents and Settings\Robert\Favorites\PFConfig\How to change Bell’s modem SpeedStream 4200 into Bridge mode  Rabih Dagher's Techlog.url -> BASEURL: hxxp://www.rabihdagher.com/techlog/2010/06/how-to-change-bells-modem-speedstream-4200-into-bridge-mode/ URL: hxxp://www.rabihdagher.com/techlog/2010/06/how-to-change-bells-modem-speedstream-4200-into-bridge-mode/
    InternetURL: C:\Documents and Settings\Robert\Favorites\PFConfig\PFConfig Support System - PortForward.com.url -> BASEURL: hxxps://secure.portforward.com/websupport/messagesystem.cgi URL: hxxps://secure.portforward.com/websupport/messagesystem.cgi
    InternetURL: C:\Documents and Settings\Robert\Favorites\PFConfig\Siemens Speedstream 4200 tech support.url -> BASEURL: hxxp://bc.whirlpool.net.au/bc/hardware/?action=h_view&model_id=278 URL: hxxp://bc.whirlpool.net.au/bc/hardware/?action=h_view&model_id=278
    InternetURL: C:\Documents and Settings\Robert\Favorites\PFConfig\SpeedStream 4200 to Bridge Mode - DSL Hardware.url -> BASEURL: hxxp://forums.whirlpool.net.au/archive/926694 URL: hxxp://forums.whirlpool.net.au/archive/926694
    InternetURL: C:\Documents and Settings\Robert\Favorites\PFConfig\The Port Forwarding Progression - PortForward.com.url -> BASEURL: hxxp://portforward.com/help/pfprogression.htm URL: hxxp://portforward.com/help/pfprogression.htm
    InternetURL: C:\Documents and Settings\Robert\Favorites\Miscellaneous\3M™ Headlight Lens Restoration System - YouTube.url -> BASEURL: hxxp://www.youtube.com/watch?v=_t1RBw0IGXA URL: hxxp://www.youtube.com/watch?v=_t1RBw0IGXA
    InternetURL: C:\Documents and Settings\Robert\Favorites\Miscellaneous\Air Canada - Flight Status Information  Departures and Arrivals.url -> BASEURL: hxxp://www.aircanada.com/en/travelinfo/traveller/flightstatus/index.html URL: hxxp://www.aircanada.com/en/travelinfo/traveller/flightstatus/index.html#299
    InternetURL: C:\Documents and Settings\Robert\Favorites\Miscellaneous\allmusic.url -> BASEURL: hxxp://www.allmusic.com/ URL: hxxp://www.allmusic.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Miscellaneous\Classics Illustrated Comic Book Website.url -> BASEURL: hxxp://www.classicscentral.com/classics.html URL: hxxp://www.classicscentral.com/classics.html
    InternetURL: C:\Documents and Settings\Robert\Favorites\Miscellaneous\Currency Converter .url -> BASEURL: hxxp://finance.yahoo.com/currency URL: hxxp://finance.yahoo.com/currency
    InternetURL: C:\Documents and Settings\Robert\Favorites\Miscellaneous\Designstudios GmbH - Home.url -> BASEURL: hxxp://www.designstudios.ch/ URL: hxxp://www.designstudios.ch/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Miscellaneous\Free People Search  WhitePages.url -> BASEURL: hxxp://www.whitepages.com/person URL: hxxp://www.whitepages.com/person
    InternetURL: C:\Documents and Settings\Robert\Favorites\Miscellaneous\Great-West Life GroupNet for Plan Members.url -> BASEURL: hxxps://groupnet.greatwestlife.com/public/signin/login.public?e=&username=unauthenticated&dl=/secureGnPM/gn/portal URL: hxxps://groupnet.greatwestlife.com/public/signin/login.public?e=&username=unauthenticated&dl=/secureGnPM/gn/portal
    InternetURL: C:\Documents and Settings\Robert\Favorites\Miscellaneous\Greater Toronto Airports Authority - Home.url -> BASEURL: hxxp://www.gtaa.com/en/home/ URL: hxxp://www.gtaa.com/en/home/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Miscellaneous\http--www.handa-accessories.com-accord-acc4drrack.pdf.url -> URL: hxxp://www.handa-accessories.com/accord/acc4drrack.pdf
    InternetURL: C:\Documents and Settings\Robert\Favorites\Miscellaneous\Kingsman Fireplaces.url -> BASEURL: hxxp://www.kingsmanind.com/fireplaceinserts URL: hxxp://www.kingsmanind.com/fireplaceinserts
    InternetURL: C:\Documents and Settings\Robert\Favorites\Miscellaneous\Love & Marriage Is Your Spouse Your Best Friend by Krystal Kuehn Be Happy 4 Life.url -> BASEURL: hxxp://searchwarp.com/swa319154.htm URL: http%3A%2F%2FSearchWarp.com%2Fswa319154.htm&via=SWarpArticles
    InternetURL: C:\Documents and Settings\Robert\Favorites\Miscellaneous\MPS The Ride to Conquer Cancer.url -> BASEURL: hxxp://www.conquercancer.ca/site/TR/Events/Toronto2012?team_id=49121&pg=team&fr_id=1401 URL: hxxp://www.conquercancer.ca/site/TR/Events/Toronto2012?team_id=49121&pg=team&fr_id=1401
    InternetURL: C:\Documents and Settings\Robert\Favorites\Miscellaneous\NLD Electric - Most reliable electrical contractors in Toronto.url -> BASEURL: hxxp://electricalcontractorstoronto.ca/ URL: hxxp://electricalcontractorstoronto.ca/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Miscellaneous\Service Canada Account.url -> BASEURL: hxxp://www.servicecanada.gc.ca/en/online/mysca.shtml URL: hxxp://www.servicecanada.gc.ca/en/online/mysca.shtml
    InternetURL: C:\Documents and Settings\Robert\Favorites\Miscellaneous\The Official WhitePage.url -> BASEURL: hxxp://www.whitepages.com/ URL: hxxp://www.whitepages.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Miscellaneous\Wine Country Cooking School.url -> BASEURL: hxxp://www.winecountrycooking.com/class_calendar/events.aspx?year=l URL: hxxp://www.winecountrycooking.com/class_calendar/events.aspx?year=l
    InternetURL: C:\Documents and Settings\Robert\Favorites\Miscellaneous\µTorrent - The Lightweight and Efficient BitTorrent Client.url -> BASEURL: hxxp://www.utorrent.com/ URL: hxxp://www.utorrent.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Microsoft Websites\IE Add-on site.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=50893
    InternetURL: C:\Documents and Settings\Robert\Favorites\Microsoft Websites\IE site on Microsoft.com.url -> URL: hxxp://go.microsoft.com/fwlink/?linkid=44661
    InternetURL: C:\Documents and Settings\Robert\Favorites\Microsoft Websites\Marketplace.url -> URL: hxxp://go.microsoft.com/fwlink/?linkid=69151
    InternetURL: C:\Documents and Settings\Robert\Favorites\Microsoft Websites\Microsoft At Home.url -> URL: hxxp://go.microsoft.com/fwlink/?linkid=55424
    InternetURL: C:\Documents and Settings\Robert\Favorites\Microsoft Websites\Microsoft At Work.url -> URL: hxxp://go.microsoft.com/fwlink/?linkid=68920
    InternetURL: C:\Documents and Settings\Robert\Favorites\Microsoft Websites\Microsoft Store.url -> URL: hxxp://go.microsoft.com/fwlink/?linkid=140813
    InternetURL: C:\Documents and Settings\Robert\Favorites\Microsoft Websites\Welcome to IE7.url -> URL: hxxp://go.microsoft.com/fwlink/?linkid=68919
    InternetURL: C:\Documents and Settings\Robert\Favorites\Maps\Free Algonquin Park Map - Download.url -> BASEURL: hxxp://homepage.mac.com/canoecamping/map/download.html URL: hxxp://homepage.mac.com/canoecamping/map/download.html
    InternetURL: C:\Documents and Settings\Robert\Favorites\Maps\Index of -pub-canmatrix.url -> BASEURL: hxxp://ftp2.cits.rncan.gc.ca/pub/canmatrix/ URL: hxxp://ftp2.cits.rncan.gc.ca/pub/canmatrix/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Maps\Lake Superior Canoe Routes.url -> BASEURL: hxxp://www.lakesuperiorpark.ca/index.php?option=com_content&view=category&layout=blog&id=16&Itemid=142 URL: hxxp://www.lakesuperiorpark.ca/index.php?option=com_content&view=category&layout=blog&id=16&Itemid=142
    InternetURL: C:\Documents and Settings\Robert\Favorites\Maps\mapquest Maps.url -> BASEURL: hxxp://www.mapquest.ca/maps/main.adp URL: hxxp://www.mapquest.ca/maps/main.adp
    InternetURL: C:\Documents and Settings\Robert\Favorites\Maps\Massasauga Provincial Park - Google Maps.url -> BASEURL: hxxp://maps.google.com/maps/ms?ie=UTF8&hl=en&msa=0&msid=111722455438984723797.0004848d28a848ba557a2&ll=45.269933,-80.033684&spn=0.051103,0.072012&t=h&z=14 URL: hxxp://maps.google.com/maps/ms?ie=UTF8&hl=en&msa=0&msid=111722455438984723797.0004848d28a848ba557a2&ll=45.269933,-80.033684&spn=0.051103,0.072012&t=h&z=14
    InternetURL: C:\Documents and Settings\Robert\Favorites\Maps\Road Map of Ontario.url -> BASEURL: hxxp://www.mto.gov.on.ca/english/traveller/map/ URL: hxxp://www.mto.gov.on.ca/english/traveller/map/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Maps\Topo Maps.url -> BASEURL: hxxp://ftp2.cits.rncan.gc.ca/pub/canmatrix/ URL: hxxp://ftp2.cits.rncan.gc.ca/pub/canmatrix/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Maps\Topographic Map Search.url -> BASEURL: hxxp://maps.nrcan.gc.ca/topo_metadata/index_e.php URL: hxxp://maps.nrcan.gc.ca/topo_metadata/index_e.php
    InternetURL: C:\Documents and Settings\Robert\Favorites\Maps\Topographic Maps Index.url -> BASEURL: hxxp://www.mapconnection.com/ontariotopoindex.html URL: hxxp://www.mapconnection.com/ontariotopoindex.html
    InternetURL: C:\Documents and Settings\Robert\Favorites\Maps\Topos Index of -pub-canmatrix.url -> BASEURL: hxxp://ftp2.cits.rncan.gc.ca/pub/canmatrix/ URL: hxxp://ftp2.cits.rncan.gc.ca/pub/canmatrix/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Links\Suggested Sites.url -> URL: hxxps://ieonline.microsoft.com/#ieslice
    InternetURL: C:\Documents and Settings\Robert\Favorites\Links\Web Slice Gallery.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=121315
    InternetURL: C:\Documents and Settings\Robert\Favorites\Internet Purchasing\Aeroplan.url -> BASEURL: hxxp://www.aeroplan.com/landing/process.do?lang=E URL: hxxp://www.aeroplan.com/landing/process.do?lang=E
    InternetURL: C:\Documents and Settings\Robert\Favorites\Internet Purchasing\amazon.ca Bob.url -> BASEURL: hxxp://www.amazon.ca/gp/yourstore/home/ref=topnav_ys_ URL: hxxp://www.amazon.ca/gp/yourstore/home/ref=topnav_ys_
    InternetURL: C:\Documents and Settings\Robert\Favorites\Internet Purchasing\coleman peak 1  eBay.url -> BASEURL: hxxp://www.ebay.ca/sch/i.html?_from=R40&_trksid=p5039.m570.l1313&_nkw=coleman+peak+1&_sacat=See-All-Categories URL: hxxp://www.ebay.ca/sch/i.html?_from=R40&_trksid=p5039.m570.l1313&_nkw=coleman+peak+1&_sacat=See-All-Categories
    InternetURL: C:\Documents and Settings\Robert\Favorites\Internet Purchasing\eBay.ca.url -> BASEURL: hxxps://signin.ebay.ca/ws/eBayISAPI.dll?SignIn&UsingSSL=1&pUserId=&co_partnerId=2&siteid=2&ru=http%3A%2F%2Fmy.ebay.ca%2Fws%2FeBayISAPI.dll%3FMyEbayBeta%26TrackingItemId%3D180162789017%26guest%3D1%26CurrentPage%3DMyeBayBidding%26ssPageName%3DVIFS%253ABID%26guest%3D1&pageType=3984 URL: hxxps://signin.ebay.ca/ws/eBayISAPI.dll?SignIn&UsingSSL=1&pUserId=&co_partnerId=2&siteid=2&ru=http%3A%2F%2Fmy.ebay.ca%2Fws%2FeBayISAPI.dll%3FMyEbayBeta%26TrackingItemId%3D180162789017%26guest%3D1%26CurrentPage%3DMyeBayBidding%26ssPageName%3DVIFS%253ABID%26guest%3D1&pageType=3984
    InternetURL: C:\Documents and Settings\Robert\Favorites\Internet Purchasing\Kijiji Toronto (GTA).url -> BASEURL: hxxp://toronto.kijiji.ca/ URL: hxxp://toronto.kijiji.ca/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Internet Purchasing\My eBay Summary.url -> BASEURL: hxxp://my.ebay.ca/ws/eBayISAPI.dll?MyEbayForGuests&ssPageName=STRK:ME:GBRE URL: hxxp://my.ebay.ca/ws/eBayISAPI.dll?MyEbayForGuests&ssPageName=STRK:ME:GBRE
    InternetURL: C:\Documents and Settings\Robert\Favorites\Internet Purchasing\PayPal.url -> BASEURL: hxxp://www.paypal.ca/ca/cgi-bin/webscr?cmd=_home URL: hxxp://www.paypal.ca/ca/cgi-bin/webscr?cmd=_home
    InternetURL: C:\Documents and Settings\Robert\Favorites\Internet Purchasing\Shoppers easypix Online.url -> BASEURL: hxxp://www.easypix.ca/home.aspx URL: hxxp://www.easypix.ca/home.aspx
    InternetURL: C:\Documents and Settings\Robert\Favorites\Internet Purchasing\Timex Watchband.url -> BASEURL: hxxp://www.jewelryservice.com/SearchResults.asp?Cat=163&Redirected=Y&gclid=CMiuwYm45JUCFQMQswodiwXLeQ URL: hxxp://www.jewelryservice.com/SearchResults.asp?Cat=163&Redirected=Y&gclid=CMiuwYm45JUCFQMQswodiwXLeQ
    InternetURL: C:\Documents and Settings\Robert\Favorites\HDTV\Ask Audyssey.url -> BASEURL: hxxp://ask.audyssey.com/home URL: hxxp://ask.audyssey.com/home
    InternetURL: C:\Documents and Settings\Robert\Favorites\HDTV\Infinite Cables (Audio,Video, VGA-DVI-HDMI).url -> BASEURL: hxxp://www.infinitecables.com/ URL: hxxp://www.infinitecables.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\HDTV\Technology FAQ  Audyssey.url -> BASEURL: hxxp://www.audyssey.com/audio-technology/faq URL: hxxp://www.audyssey.com/audio-technology/faq
    InternetURL: C:\Documents and Settings\Robert\Favorites\Gressaero\France vader.url -> BASEURL: hxxp://www.tournereau.com/modelisme/nVader_US/Accueil/Home.html URL: hxxp://www.tournereau.com/modelisme/nVader_US/Accueil/Home.html
    InternetURL: C:\Documents and Settings\Robert\Favorites\Gressaero\gressaero.url -> BASEURL: hxxp://www.gressaero.com/ URL: hxxp://www.gressaero.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Gressaero\nVader 600 build - Page 76 - RC Groups.url -> BASEURL: hxxp://www.rcgroups.com/forums/showthread.php?t=1278074&page=76 URL: http%3A%2F%2Fwww.rcgroups.com%2Fforums%2Fshowthread.php%3Ft%3D1278074%26page%3D76&dt=1353720235139&bpp=1&shv=r20121107&jsv=r20110914&correlator=1353720235170&frm=20&adk=733103198&ga_vid=2009852792.1347504157&ga_sid=1353720221&ga_hid=1987308489&ga_fc=1&u_tz=-300&u_his=7&u_java=1&u_h=768&u_w=1024&u_ah=734&u_aw=1024&u_cd=32&u_nplug=0&u_nmime=0&dff=arial&dfs=15&adx=-2&ady=-2&biw=995&bih=567&oid=3&ref=http%3A%2F%2Fwww.rcgroups.com%2Fforums%2Fshowthread.php%3Ft%3D1278074%26page%3D75&docm=8&fu=0&ifi=1&dtd=78&xpc=DT4HcSt970&p=http%3A//www.rcgroups.com
    InternetURL: C:\Documents and Settings\Robert\Favorites\Film Resources\Bay Street Video .url -> BASEURL: hxxp://www.baystreetvideo.com/ URL: hxxp://www.baystreetvideo.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Film Resources\BBAlert.url -> BASEURL: hxxp://www.bigboobsalert.com/ URL: hxxp://www.bigboobsalert.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Film Resources\big blog.url -> BASEURL: hxxp://mybigtitsbabes.com/ URL: hxxp://mybigtitsbabes.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Film Resources\BitHQ  Search results for warner archive collection.url -> BASEURL: hxxp://www.bithq.org/browse.php?search=warner archive collection&cat=0&incldead=1 URL: hxxp://www.bithq.org/browse.php?search=warner archive collection&cat=0&incldead=1
    InternetURL: C:\Documents and Settings\Robert\Favorites\Film Resources\Classic Film Guide.url -> BASEURL: hxxp://www.classicfilmguide.com/index.php?s=home URL: hxxp://www.classicfilmguide.com/index.php?s=home
    InternetURL: C:\Documents and Settings\Robert\Favorites\Film Resources\Collectorz.com Forum • Index page.url -> BASEURL: hxxp://www.collectorz.com/phpbb2/index.php URL: hxxp://www.collectorz.com/phpbb2/index.php
    InternetURL: C:\Documents and Settings\Robert\Favorites\Film Resources\Collectorz.url -> BASEURL: hxxp://www.collectorz.com/ URL: hxxp://www.collectorz.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Film Resources\Hammer filmography - Wikipedia, the free encyclopedia.url -> BASEURL: hxxp://en.wikipedia.org/wiki/List_of_Hammer_films URL: hxxp://en.wikipedia.org/wiki/List_of_Hammer_films
    InternetURL: C:\Documents and Settings\Robert\Favorites\Film Resources\ImageShack® - Hosting.url -> BASEURL: hxxp://imageshack.us/ URL: hxxp://imageshack.us/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Film Resources\Legends.url -> BASEURL: hxxp://www.busty-legends.com/ URL: hxxp://www.busty-legends.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\DVD Info\DVDs Release Dates.url -> BASEURL: hxxp://www.dvdsreleasedates.com/ URL: http%3A%2F%2Fwww.dvdsreleasedates.com&dt=1362440899203&bpp=15&shv=r20130227&cbv=r20130206&prev_slotnames=8096732949&correlator=1362440899031&frm=20&adk=3571990567&ga_vid=1329606568.1362440899&ga_sid=1362440899&ga_hid=522662103&ga_fc=0&u_tz=-300&u_his=3&u_java=1&u_h=768&u_w=1024&u_ah=734&u_aw=1024&u_cd=32&u_nplug=0&u_nmime=0&dff=arial&dfs=11&adx=679&ady=645&biw=995&bih=584&oid=3&ref=http%3A%2F%2Fwww.dvdsreleasedates.com%2Fmovies%2F5276%2FThe-Hobbit-An-Unexpected-Journey-2012.html&loc=http%3A%2F%2Fwww.dvdsreleasedates.com%2F&docm=8&fu=0&ifi=2&dtd=172&xpc=LxCjvJW8dx&p=http%3A//www.dvdsreleasedates.com
    InternetURL: C:\Documents and Settings\Robert\Favorites\DVD Info\Movie Info - CD Universe.url -> BASEURL: hxxp://www.cduniverse.com/default.asp?style=movie URL: hxxp://www.cduniverse.com/default.asp?style=movie
    InternetURL: C:\Documents and Settings\Robert\Favorites\DVD Info\Movie Posters - DVD Empire.url -> BASEURL: hxxp://www.dvdempire.com/index.asp?tab_id=1 URL: hxxp://www.dvdempire.com/index.asp?tab_id=1
    InternetURL: C:\Documents and Settings\Robert\Favorites\DVD Info\Movie Posters Amazon.com .url -> BASEURL: hxxp://www.amazon.com/dvds-used-hd-action-comedy-oscar/b/ref=sa_menu_mov1?ie=UTF8&node=130&pf_rd_p=328655101&pf_rd_s=left-nav-1&pf_rd_t=101&pf_rd_i=507846&pf_rd_m=ATVPDKIKX0DER&pf_rd_r=19K4FTHFH39VPDW3VVJB URL: hxxp://www.amazon.com/dvds-used-hd-action-comedy-oscar/b/ref=sa_menu_mov1?ie=UTF8&node=130&pf_rd_p=328655101&pf_rd_s=left-nav-1&pf_rd_t=101&pf_rd_i=507846&pf_rd_m=ATVPDKIKX0DER&pf_rd_r=19K4FTHFH39VPDW3VVJB
    InternetURL: C:\Documents and Settings\Robert\Favorites\DVD Info\Rare and Classic Movies on DVD.url -> BASEURL: hxxp://movieola.ecrater.com/c/135015327/rare-and-classic-movies-on-dvd URL: hxxp://movieola.ecrater.com/c/135015327/rare-and-classic-movies-on-dvd
    InternetURL: C:\Documents and Settings\Robert\Favorites\DVD Info\The Criterion Collection.url -> BASEURL: hxxp://www.criterion.com/ URL: hxxp://www.criterion.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\DVD Info\The Movie Database.url -> BASEURL: hxxp://www.themoviedb.org/movie/124530-the-big-deadly-game URL: hxxp://www.themoviedb.org/movie/124530-the-big-deadly-game
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\5 Best Free Trojan Remover  webworldtoday.url -> BASEURL: hxxp://www.webworldtoday.org/en/2012/02/5-best-free-trojan-remover/ URL: hxxp://www.webworldtoday.org/en/2012/02/5-best-free-trojan-remover/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\Acronis Backup Series.url -> BASEURL: hxxp://ask-leo.com/how_to_backup.html URL: hxxp://ask-leo.com/how_to_backup.html
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\Add Custom Options to the Windows AutoPlay Dialog.url -> BASEURL: hxxp://lifehacker.com/371677/add-custom-options-to-the-windows-autoplay-dialog URL: hxxp://lifehacker.com/371677/add-custom-options-to-the-windows-autoplay-dialog
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\bell Sympatico mail server settings.url -> BASEURL: hxxp://service.sympatico.ca/index.cfm?method=content.view&content_id=1067 URL: hxxp://service.sympatico.ca/index.cfm?method=content.view&content_id=1067
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\Best AntiVirus Software Review 2013  Compare Antivirus Software  Best Virus Protection - TopTenREVIEWS.url -> BASEURL: hxxp://anti-virus-software-review.toptenreviews.com/ URL: hxxp://anti-virus-software-review.toptenreviews.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\Binary-Decimal-Hexadecimal Converter.url -> BASEURL: hxxp://www.mathsisfun.com/binary-decimal-hexadecimal-converter.html URL: http%3A%2F%2Fwww.mathsisfun.com%2Fbinary-decimal-hexadecimal-converter.html&dt=1395180724765&bpp=94&shv=r20140313&cbv=r20140311&saldr=sa&correlator=1395180725656&frm=20&ga_vid=745345251.1395180726&ga_sid=1395180726&ga_hid=949544115&ga_fc=0&u_tz=-240&u_his=0&u_java=1&u_h=768&u_w=1024&u_ah=734&u_aw=1024&u_cd=32&u_nplug=0&u_nmime=0&dff=verdana&dfs=15&adx=263&ady=163&biw=995&bih=584&eid=317150303&oid=3&rx=0&eae=4&docm=8&vis=0&fu=0&ifi=1&pfi=0&dtd=922
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\Bit Calculator - Convert between bits-bytes-kilobits-kilobytes-megabits-megabytes-gigabits-gigabytes..url -> BASEURL: hxxp://www.matisse.net/bitcalc/?input_amount=100&input_units=megabits&notation=legacy URL: hxxp://www.matisse.net/bitcalc/?input_amount=100&input_units=megabits&notation=legacy
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\Computer memory upgrades for ASUS P5LD2 Deluxe Motherboard from Crucial.com.url -> BASEURL: hxxp://www.crucial.com/upgrade/ASUS-memory/ASUS+Motherboards/P5LD2+Deluxe-upgrades.html URL: hxxp://www.crucial.com/upgrade/ASUS-memory/ASUS+Motherboards/P5LD2+Deluxe-upgrades.html
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\Default Programs Editor, Example Usage Setting Media Player Classic to Autoplay DVDs « Factor Mystic.url -> BASEURL: hxxp://factormystic.net/blog/default-programs-editor-example-usage-setting-media-player-classic-to-autoplay-dvds URL: hxxp://factormystic.net/blog/default-programs-editor-example-usage-setting-media-player-classic-to-autoplay-dvds
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\HijackThis log Analysis.url -> BASEURL: hxxp://www.wedoc.com/wedoc_frame.html?hxxp://hijackthis.de/index.php?langselect=english URL: hxxp://www.wedoc.com/wedoc_frame.html?hxxp://hijackthis.de/index.php?langselect=english
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\How to Install Puppy Linux onto a USB Flash Drive Without a CD by Britec - YouTube.url -> BASEURL: hxxp://www.youtube.com/watch?v=Iqj6JJjC1yw URL: hxxp://www.youtube.com/watch?v=Iqj6JJjC1yw
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\HP Pavilion 15.6&quot; Laptop featuring Intel Core i3-370M Processor (G6-1C75CA) - Pewter  15&quot; Laptops - Best Buy Canada.url -> BASEURL: hxxp://www.bestbuy.ca/en-CA/product/hewlett-packard-hp-pavilion-15-6-laptop-featuring-intel-core-i3-370m-processor-g6-1c75ca-pewter-g6-1c75ca/10185515.aspx?path=579142b87b7d2b75e5e6f14475e48d70en02 URL: &lang=en
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\HP vs17e 17 inch LCD Monitor  HP® Support.url -> BASEURL: hxxp://h10025.www1.hp.com/ewfrf/wc/product?product=1822299&lc=en&cc=us&dlc=en&lang=en&tmp_track_link=ot_we/prodlink/en_us/1822299/loc:0&cc=us URL: hxxp://h10025.www1.hp.com/ewfrf/wc/product?product=1822299&lc=en&cc=us&dlc=en&lang=en&tmp_track_link=ot_we/prodlink/en_us/1822299/loc:0&cc=us
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\http--h18000.www1.hp.com-products-quickspecs-10016_div-10016_div.html.url -> BASEURL: hxxp://h18000.www1.hp.com/products/quickspecs/10016_div/10016_div.html URL: hxxp://h18000.www1.hp.com/products/quickspecs/10016_div/10016_div.html
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\http--www.uniden.com-content-ebiz-uniden-resources-ownersmanuals-EXAI7248om.pdf.url -> URL: hxxp://www.uniden.com/content/ebiz/uniden/resources/ownersmanuals/EXAI7248om.pdf
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\Internet explorer window opens too small (not full screen) in - Microsoft Answers.url -> BASEURL: hxxp://answers.microsoft.com/en-us/windows/forum/windows_vista-windows_programs/internet-explorer-window-opens-too-small-not-full/de7b9293-4e00-4476-871e-26bf4affc19b URL: hxxp://answers.microsoft.com/en-us/windows/forum/windows_vista-windows_programs/internet-explorer-window-opens-too-small-not-full/de7b9293-4e00-4476-871e-26bf4affc19b
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\Macrium Reflect Series - YouTube.url -> BASEURL: hxxp://www.youtube.com/playlist?list=PL5264A3830C39025C URL: hxxp://www.youtube.com/playlist?list=PL5264A3830C39025C
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\Old Version of uTorrent Download - OldApps.com.url -> BASEURL: hxxp://www.oldapps.com/utorrent.php URL: http%3A%2F%2Fwww.oldapps.com%2Futorrent.php&dt=1353724328170&bpp=16&shv=r20121107&jsv=r20110914&correlator=1353724328499&frm=20&adk=2917952807&ga_vid=1193081240.1353724328&ga_sid=1353724328&ga_hid=1291586264&ga_fc=1&u_tz=-300&u_his=0&u_java=1&u_h=768&u_w=1024&u_ah=734&u_aw=1024&u_cd=32&u_nplug=0&u_nmime=0&dff=verdana&dfs=12&adx=26&ady=1295&biw=995&bih=584&oid=3&docm=8&fu=0&ifi=1&dtd=563&xpc=DTcxKnBSy2&p=http%3A//www.oldapps.com
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\Outlook Tips.url -> BASEURL: hxxp://www.outlook-tips.net/howto/missinghol.htm URL: hxxp://www.outlook-tips.net/howto/missinghol.htm
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\Port Forwarding Utorrent on the Dlink DIR-655 - PortForward.com.url -> BASEURL: hxxp://portforward.com/english/routers/port_forwarding/Dlink/DIR-655/Utorrent.htm URL: hxxp://portforward.com/english/routers/port_forwarding/Dlink/DIR-655/Utorrent.htm
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\Port Forwarding Utorrent on the Siemens 4200 - PortForward.com.url -> BASEURL: hxxp://portforward.com/english/routers/port_forwarding/Siemens/4200/Utorrent.htm URL: hxxp://portforward.com/english/routers/port_forwarding/Siemens/4200/Utorrent.htm
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\PortForward.com - Free Software to Setup a Static IP Address.url -> BASEURL: hxxp://portforward.com/help/setup_static_ip_address.htm URL: hxxp://portforward.com/help/setup_static_ip_address.htm
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\Screen Shot, and how do I make one - Ask Leo!.url -> BASEURL: hxxp://ask-leo.com/whats_a_screen_shot_and_how_do_i_make_one.html URL: hxxp://ask-leo.com/whats_a_screen_shot_and_how_do_i_make_one.html
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\Slash Dot Dash » Blog Archive » Kill the annoying Windows Beep (internal speaker).url -> BASEURL: hxxp://www.slashdotdash.net/2006/08/17/kill-the-annoying-windows-beep-internal-speaker/ URL: hxxp://www.slashdotdash.net/2006/08/17/kill-the-annoying-windows-beep-internal-speaker/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\TECHNO BABBLE - Customize the right click context menus.url -> BASEURL: hxxp://www2.technobabble.com.au/article182.html URL: hxxp://www2.technobabble.com.au/article182.html
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\The Windows XP Start Menu and Taskbar.url -> BASEURL: hxxp://www.theeldergeek.com/start_menu.htm URL: http%3A%2F%2Fwww.theeldergeek.com%2Fstart_menu.htm&region=_google_cpa_region_&ea=off&ref=http%3A%2F%2Fwww.google.ca%2Fsearch%3Fhl%3Den%26q%3Dhow%2Bto%2Badd%2Bitems%2Bto%2Bstart%2Bmenu%26btnG%3DGoogle%2BSearch%26meta%3D&frm=0&cc=1933&ga_vid=360677031.1224113320&ga_sid=1224113320&ga_hid=763011879&flash=9.0.124.0&u_h=768&u_w=1024&u_ah=738&u_aw=1024&u_cd=32&u_tz=-240&u_his=4&u_java=true
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\Turn Off the Annoying Windows XP System Beeps  the How-To Geek.url -> BASEURL: hxxp://www.howtogeek.com/howto/windows/turn-off-the-annoying-windows-xp-system-beeps/ URL: hxxp://www.howtogeek.com/howto/windows/turn-off-the-annoying-windows-xp-system-beeps/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\UNLOCKER 1.8.7 BY CEDRICK 'NITCH' COLLOMB.url -> BASEURL: hxxp://ccollomb.free.fr/unlocker/ URL: hxxp://ccollomb.free.fr/unlocker/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\Website down or just me.url -> BASEURL: hxxp://www.websitedown.info/ URL: hxxp://www.websitedown.info/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Technical Resources\Windows - Troubleshooting Using Safe Mode and Device Manager.url -> BASEURL: hxxp://kb.wisc.edu/helpdesk/page.php?id=502 URL: hxxp://kb.wisc.edu/helpdesk/page.php?id=502
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Stores\Best Buy Canada.url -> BASEURL: hxxp://www.bestbuy.ca/home.asp?newlang=EN&logon=&langid=EN URL: hxxp://www.bestbuy.ca/home.asp?newlang=EN&logon=&langid=EN
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Stores\canadacomputers.url -> BASEURL: hxxp://www.canadacomputers.com/ URL: hxxp://www.canadacomputers.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Stores\Filtech Computer .url -> BASEURL: hxxp://www.filtechcomputer.com/ URL: hxxp://www.filtechcomputer.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Stores\Future Shop.url -> BASEURL: hxxp://www.futureshop.ca/home.asp?newlang=EN&logon=&langid=EN URL: hxxp://www.futureshop.ca/home.asp?newlang=EN&logon=&langid=EN
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Stores\TigerDirect.ca.url -> BASEURL: hxxp://www.tigerdirect.ca/indexca.asp?AffiliateID=E5JUo8r42BE-uBFXQA1zwwWC0M8Vykl.YQ URL: hxxp://www.tigerdirect.ca/indexca.asp?AffiliateID=E5JUo8r42BE-uBFXQA1zwwWC0M8Vykl.YQ
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Forums\AfterDawn.com.url -> BASEURL: hxxp://www.afterdawn.com/ URL: hxxp://www.afterdawn.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Forums\ASUSTeK Computer Inc.-Forum-.url -> BASEURL: hxxp://vip.asus.com/forum/default.aspx?SLanguage=en-us URL: hxxp://vip.asus.com/forum/default.aspx?SLanguage=en-us
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Forums\BleedinEdge - A Community of Hardcore Computing.url -> BASEURL: hxxp://www.bleedinedge.com/cms/ URL: hxxp://www.bleedinedge.com/cms/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Forums\BleepingComputer.com .url -> BASEURL: hxxp://www.bleepingcomputer.com/forums/ URL: hxxp://www.bleepingcomputer.com/forums/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Forums\CollectorToolz.co.uk - Home Page.url -> BASEURL: hxxp://www.collectortoolz.co.uk/ URL: hxxp://www.collectortoolz.co.uk/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Forums\Geeks to Go Forums.url -> BASEURL: hxxp://www.geekstogo.com/forum/forum/37-virus-spyware-malware-removal/ URL: hxxp://www.geekstogo.com/forum/forum/37-virus-spyware-malware-removal/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Forums\Hardware,Geeks to Go Forums.url -> BASEURL: hxxp://www.geekstogo.com/forum/forum/9-hardware-components-and-peripherals/ URL: hxxp://www.geekstogo.com/forum/forum/9-hardware-components-and-peripherals/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Forums\HowToFixComputers.com.url -> BASEURL: hxxp://www.howtofixcomputers.com/ URL: hxxp://www.howtofixcomputers.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Forums\Puppy Linux Discussion Forum.url -> BASEURL: hxxp://208.109.22.214/puppy/index.php?sid=15952e69f38b3e944228ff448a794df1 URL: hxxp://208.109.22.214/puppy/index.php?sid=15952e69f38b3e944228ff448a794df1
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Forums\Tech Support Forum.url -> BASEURL: hxxp://www.techsupportforum.com/ URL: hxxp://www.techsupportforum.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Forums\Welcome to Outlook Daily Tips.url -> BASEURL: hxxp://www.outlook-tips.net/index.html URL: hxxp://www.outlook-tips.net/index.html
    InternetURL: C:\Documents and Settings\Robert\Favorites\Computer Forums\wise Geek.url -> BASEURL: hxxp://www.wisegeek.com/what-is-a-rootkit.htm URL: hxxp://www.wisegeek.com/what-is-a-rootkit.htm
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Stores\Classic Camp Stoves.url -> BASEURL: hxxp://www.spiritburner.com/fusion/index.php? URL: hxxp://www.spiritburner.com/fusion/index.php?
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Stores\Coleman - Part List For 400-499 1 Burner Gas Stove.url -> BASEURL: hxxp://www.colemantrailers.com/Parts/240/coleman-fuel/400-499/1-burner-gas-stove URL: hxxp://www.colemantrailers.com/Parts/240/coleman-fuel/400-499/1-burner-gas-stove
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Stores\Coleman - Repair & Replacement Parts.url -> BASEURL: hxxp://www.coleman.com/parts?product_id=400-499 URL: hxxp://www.coleman.com/parts?product_id=400-499
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Stores\Coleman Canada.url -> BASEURL: hxxp://www.colemancanada.ca/Default.en.aspx URL: hxxp://www.colemancanada.ca/Default.en.aspx
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Stores\Coleman Peak 1 Stove, Backpacking Stoves  Campmor.url -> BASEURL: hxxp://www.campmor.com/coleman-fuel-old-style-generator-peak-1-stoves.shtml?source=GAN&cm_mmc=GAN-_-TheFind%2C%20Inc.-_-Primary-_- URL: hxxp://www.campmor.com/coleman-fuel-old-style-generator-peak-1-stoves.shtml?source=GAN&cm_mmc=GAN-_-TheFind%2C%20Inc.-_-Primary-_-
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Stores\Maintaining a Coleman 400 stove - ADVrider.url -> BASEURL: hxxp://www.advrider.com/forums/showthread.php?t=392613 URL: hxxp://www.advrider.com/forums/showthread.php?t=392613
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Stores\MEC.url -> BASEURL: hxxp://www.mec.ca/Main/home.jsp;jsessionid=T4HnKdxdX51JvT2vwtV7LCTYlQ9J31vCPdGGhm3B1mBMwkm69dNv!-477005822?bmLocale=en&bmUID=1251848669534 URL: hxxp://www.mec.ca/Main/home.jsp;jsessionid=T4HnKdxdX51JvT2vwtV7LCTYlQ9J31vCPdGGhm3B1mBMwkm69dNv!-477005822?bmLocale=en&bmUID=1251848669534
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Stores\OldColemanParts.com.url -> BASEURL: hxxp://www.oldcolemanparts.com/home.php URL: hxxp://www.oldcolemanparts.com/home.php
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Stores\Ole Time Woodsman Insect, Mosquito and Black Fly Repellent.url -> BASEURL: hxxp://www.oletimewoodsman.com/ URL: hxxp://www.oletimewoodsman.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Stores\Open Country Campware® - Buy Online!.url -> BASEURL: hxxp://www.opencountrycampware.com/category_bf57b176bf55/subcategory_187c1463a809/product_bb9acc73d716/session_c25414589fbb/ URL: hxxp://www.opencountrycampware.com/category_bf57b176bf55/subcategory_187c1463a809/product_bb9acc73d716/session_c25414589fbb/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Stores\Quest Outfitters - Outdoor Fabrics.url -> BASEURL: hxxp://www.questoutfitters.com/ URL: hxxp://www.questoutfitters.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Stores\Reuseit.com.url -> BASEURL: hxxp://www.reuseit.com/ URL: hxxp://www.reuseit.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Stores\SAIL.url -> BASEURL: hxxp://www.sail.ca/en/home/ URL: hxxp://www.sail.ca/en/home/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Stores\Warehouse Outlet - ServiceTek Coleman.url -> BASEURL: hxxp://www.warehouseoutlet.ca/ URL: hxxp://www.warehouseoutlet.ca/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Forums\Algonquin Adventures Message Board.url -> BASEURL: hxxp://www.network54.com/Forum/352882/ URL: hxxp://www.network54.com/Forum/352882/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Forums\Algonquin Adventures.url -> BASEURL: hxxp://www.algonquinadventures.com/ URL: hxxp://www.algonquinadventures.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Forums\APRUA - Algonquin Park Recreational Users Association.url -> BASEURL: hxxp://www.outdooradventurecanada.com/aprua/ URL: hxxp://www.outdooradventurecanada.com/aprua/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Forums\Canadian Canoe Routes .url -> BASEURL: hxxp://www.myccr.com/ URL: hxxp://www.myccr.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Forums\Fan 590.url -> BASEURL: hxxp://www.sportsnet.ca/590/ URL: hxxp://www.sportsnet.ca/590/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Forums\SoloTripping.com.url -> BASEURL: hxxp://www.solotripping.com/ URL: hxxp://www.solotripping.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Forums\Temagami - Ottertooth.com.url -> BASEURL: hxxp://www.ottertooth.com/temagami.htm URL: hxxp://www.ottertooth.com/temagami.htm
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Forums\The Friends of Algonquin Park.url -> BASEURL: hxxp://www.algonquinpark.on.ca/ URL: hxxp://www.algonquinpark.on.ca/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping Forums\TheBackpacker.com.url -> BASEURL: hxxp://www.thebackpacker.com/trailtalk/ URL: hxxp://www.thebackpacker.com/trailtalk/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping\Algonquin Park - General Info.url -> BASEURL: hxxp://www.algonquinpark.on.ca/geninfo/contact.html URL: hxxp://www.algonquinpark.on.ca/geninfo/contact.html
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping\Campsite Pictures - Pictures of Campsites in Ontario Parks.url -> BASEURL: hxxp://www.campsitepictures.com/index.html URL: hxxp://www.campsitepictures.com/index.html
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping\Cliff Jacobson - Outdoor Writer & Consultant.url -> BASEURL: hxxp://www.cliff-jacobson.com/ URL: hxxp://www.cliff-jacobson.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping\eBird  Your destination for birding on the Web.url -> BASEURL: hxxp://ebird.ca/sightings.jsp?country=CA&back=7&prov=ON URL: hxxp://ebird.ca/sightings.jsp?country=CA&back=7&prov=ON
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping\Ontario Parks Reservation System.url -> BASEURL: hxxps://reservations.ontarioparks.com/Home.aspx URL: hxxps://reservations.ontarioparks.com/Home.aspx
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping\The Massasauga Provincial Park- campsites..url -> BASEURL: hxxp://www.angelfire.com/blues2/bcaron/campsite.html URL: hxxp://www.angelfire.com/blues2/bcaron/campsite.html
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping\The Weather Network.url -> BASEURL: hxxp://www.theweathernetwork.com/ URL: hxxp://www.theweathernetwork.com/
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping\Trails Ontario, Canada  Snowshoe Back Country.url -> BASEURL: hxxp://www.ontariotrails.on.ca/trail-activities/snowshoeing-backcountry/?CFID=6477343&CFTOKEN=21375725&jsessionid=f0302b2d479af14245d43580472bb2254259 URL: hxxp://www.ontariotrails.on.ca/trail-activities/snowshoeing-backcountry/?CFID=6477343&CFTOKEN=21375725&jsessionid=f0302b2d479af14245d43580472bb2254259
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping\Weather - Environment Canada.url -> BASEURL: hxxp://www.weatheroffice.gc.ca/canada_e.html URL: hxxp://www.weatheroffice.gc.ca/canada_e.html
    InternetURL: C:\Documents and Settings\Robert\Favorites\Camping\Welcome to Ontario Parks.url -> BASEURL: hxxp://www.ontarioparks.com/english/index.html URL: hxxp://www.ontarioparks.com/english/index.html
    InternetURL: C:\Documents and Settings\Robert\Desktop\BitHQ  Browse Torrents.url -> BASEURL: hxxp://www.bithq.org/browse.php?cat=49 URL: hxxp://www.bithq.org/browse.php?cat=49
    InternetURL: C:\Documents and Settings\Robert\Desktop\BitHQ.URL -> URL: hxxp://www.bithq.org/browse.php?cat=49
    InternetURL: C:\Documents and Settings\Robert\Desktop\Cinematik.URL -> URL: hxxp://cinematik.net/browse.php
    InternetURL: C:\Documents and Settings\Robert\Desktop\Classix-Unlimited.co.uk Home.URL -> URL: hxxp://classix-unlimited.co.uk/index.php
    InternetURL: C:\Documents and Settings\Robert\Desktop\Facebook.URL -> URL: hxxps://www.facebook.com/
    InternetURL: C:\Documents and Settings\Robert\Desktop\Google.url -> BASEURL: hxxp://www.google.ca/ URL: hxxp://www.google.ca/
    InternetURL: C:\Documents and Settings\Robert\Desktop\IMDb.url -> BASEURL: hxxp://www.imdb.com/ URL: hxxp://www.imdb.com/
    InternetURL: C:\Documents and Settings\Robert\Desktop\Official Algonquin Park Canoe Routes Map.URL -> URL: hxxp://algonquinpark.on.ca/virtual/canoe_routes_map/index.php
    InternetURL: C:\Documents and Settings\Robert\Desktop\The Horror Charnel Home.URL -> URL: hxxps://horrorcharnel.org/index.php
    InternetURL: C:\Documents and Settings\Robert\Desktop\TSN.URL -> URL: hxxp://www.tsn.ca/
    InternetURL: C:\Documents and Settings\Robert\Desktop\Volunteer Invictus Games 2017.URL -> URL: hxxps://apps.invictusgames2017.com/Portal/index.cfm/volunteer/login
    InternetURL: C:\Documents and Settings\Robert\Desktop\Demonoid.URL -> URL: hxxp://www.dnoid.me/?rl=147752666257a4d9d1d9e86663603d1ddfff19ea60

    ==================== End of Shortcut.txt =============================
     


    • 0

    #44
    RKinner

    RKinner

      Malware Expert

    • Expert
    • 20,031 posts
    • MVP

    Nothing wrong with your shortcuts.  I'm thinking that Firefox is just messed up and won't run.  I would uninstall it then download a new copy and install the new copy.

     

    Note that Firefox is going to stop working with newer version of Firefox in the near future.

     

    http://www.ghacks.ne...ws-xp-or-vista/

     

    You may want to download Opera and start using it as it is one of the few browsers that is still being updated that will work with XP.

     

    http://www.opera.com/

     

    While IE 8 will continue to work it is not getting security updates so sort of dangerous to use.


    • 0

    #45
    Jackpine

    Jackpine

      Member

    • Topic Starter
    • Member
    • PipPipPip
    • 347 posts

    I tried to uninstall Firefox in Add/Remove, but when I clicked on it, literally nothing happened.  The list of programs in Add/Remove remained on the screen, with Firefox showing on the list of programs.

     

    I also tried to do a system restore to before all this trouble began.  It took about half an hour and when it was over, a window announced that my computer had been successfully restored.  But when my desktop reappeared, it was not the same desktop from a couple of weeks ago (when I did not have VEW and Minitoolbox on my desktop.)  The web shortcuts still didn't work.

     

    I'm afraid that there is something seriously wrong and that maybe all services that should be running are stopped?  I don't know.  Just pulling at straws.


    • 0






    Similar Topics

    0 user(s) are reading this topic

    0 members, 0 guests, 0 anonymous users

    As Featured On:

    Microsoft Yahoo BBC MSN PC Magazine Washington Post HP