
OTL logfile created on: 8/7/2012 6:55:48 PM - Run 1
OTL by OldTimer - Version 3.2.56.0 Folder = C:\Users\Rhomel\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.89 Gb Total Physical Memory | 1.75 Gb Available Physical Memory | 45.10% Memory free
7.78 Gb Paging File | 5.23 Gb Available in Paging File | 67.26% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 405.67 Gb Total Space | 352.78 Gb Free Space | 86.96% Space Free | Partition Type: NTFS
Drive D: | 292.87 Gb Total Space | 240.01 Gb Free Space | 81.95% Space Free | Partition Type: NTFS
Computer Name: RHOMEL-PC | User Name: Rhomel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Rhomel\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
PRC - C:\Program Files (x86)\Connectify\Connectifyd.exe (Connectify)
PRC - C:\Program Files (x86)\Connectify\ConnectifyService.exe ()
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Windows\AsScrPro.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.)
PRC - C:\Windows\SysWOW64\NLSSRV32.EXE (Nalpeiron Ltd.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe (ASUS)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe (ASUS)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS)
PRC - C:\Windows\SysWOW64\ACEngSvr.exe (ASUSTeK)
PRC - C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe (Autodesk, Inc.)
PRC - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe ()
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
PRC - C:\Program Files (x86)\USB Disk Security\USBGuard.exe (AbeGunnerZ Lab)
PRC - C:\Program Files (x86)\netcut\services\aips.exe (Arcai.com)
PRC - C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (Tonec Inc.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (ASUS)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Users\Rhomel\AppData\Local\Google\Chrome\Application\21.0.1180.60\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\Rhomel\AppData\Local\Google\Chrome\Application\21.0.1180.60\PepperFlash\pepflashplayer.dll ()
MOD - C:\Users\Rhomel\AppData\Local\Google\Chrome\Application\21.0.1180.60\pdf.dll ()
MOD - C:\Users\Rhomel\AppData\Local\Google\Chrome\Application\21.0.1180.60\libglesv2.dll ()
MOD - C:\Users\Rhomel\AppData\Local\Google\Chrome\Application\21.0.1180.60\libegl.dll ()
MOD - C:\Users\Rhomel\AppData\Local\Google\Chrome\Application\21.0.1180.60\avutil-51.dll ()
MOD - C:\Users\Rhomel\AppData\Local\Google\Chrome\Application\21.0.1180.60\avformat-54.dll ()
MOD - C:\Users\Rhomel\AppData\Local\Google\Chrome\Application\21.0.1180.60\avcodec-54.dll ()
MOD - C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (avast! Antivirus) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (FLEXnet Licensing Service 64) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Flexera Software, Inc.)
SRV:64bit: - (NitroDriverReadSpool2) -- C:\Program Files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe (Nitro PDF Software)
SRV:64bit: - (UxTuneUp) -- C:\Windows\SysNative\uxtuneup.dll (TuneUp Software)
SRV:64bit: - (Intel® -- C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel® Corporation)
SRV:64bit: - (AFBAgent) -- C:\Windows\SysNative\FBAgent.exe (ASUSTeK Computer Inc.)
SRV:64bit: - (gogoc) -- C:\Program Files\gogo6\gogoCLIENT\gogoc.exe (gogo6, Inc.)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (Connectify) -- C:\Program Files (x86)\Connectify\ConnectifyService.exe ()
SRV - (Skype C2C Service) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (nlsX86cc) -- C:\Windows\SysWOW64\NLSSRV32.EXE (Nalpeiron Ltd.)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (TuneUp.UtilitiesSvc) -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (TuneUp Software)
SRV - (UxTuneUp) -- C:\Windows\SysWOW64\uxtuneup.dll (TuneUp Software)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (ASUS InstantOn) -- C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe (ASUS)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (cphs) -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (Autodesk Content Service) -- C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe (Autodesk, Inc.)
SRV - (ZAtheros Bt&Wlan Coex Agent) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
SRV - (AtherosSvc) -- C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Atheros Commnucations)
SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (jhi_service) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
SRV - (Intel® -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe ()
SRV - (ASLDRService) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS)
SRV - (ATKGFNEXSrv) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
SRV - (AIPS) -- C:\Program Files (x86)\netcut\services\aips.exe (Arcai.com)
SRV - (rpcapd) -- C:\Program Files (x86)\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (NILM License Manager) -- C:\Program Files (x86)\National Instruments\Shared\License Manager\Bin\lmgrd.exe (Macrovision Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NIDomainService) -- C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe (National Instruments Corporation)
SRV - (lkTimeSync) -- C:\Windows\SysWOW64\lktsrv.exe (National Instruments Corporation)
SRV - (lkClassAds) -- C:\Windows\SysWOW64\lkads.exe (National Instruments Corporation)
SRV - (niSvcLoc) -- C:\Windows\SysWOW64\nisvcloc.exe (National Instruments Corporation)
SRV - (LkCitadelServer) -- C:\Windows\SysWOW64\lkcitdl.exe (National Instruments, Inc.)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV:64bit: - (IDMWFP) -- C:\Windows\SysNative\drivers\idmwfp.sys (Tonec Inc.)
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (aswSnx) -- C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) -- C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) -- C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswTdi) -- C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswRdr) -- C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) -- C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (cnnctfy2) -- C:\Windows\SysNative\drivers\cnnctfy2.sys (Connectify)
DRV:64bit: - (pwdrvio) -- C:\Windows\SysNative\pwdrvio.sys ()
DRV:64bit: - (pwdspio) -- C:\Windows\SysNative\pwdspio.sys ()
DRV:64bit: - (VBoxNetAdp) -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys (Oracle Corporation)
DRV:64bit: - (ssudserd) -- C:\Windows\SysNative\drivers\ssudserd.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (ssudmdm) -- C:\Windows\SysNative\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (dg_ssudbus) -- C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (AiCharger) -- C:\Windows\SysNative\drivers\AiCharger.sys (ASUSTek Computer Inc.)
DRV:64bit: - (nvpciflt) -- C:\Windows\SysNative\drivers\nvpciflt.sys (NVIDIA Corporation)
DRV:64bit: - (cpuz135) -- C:\Windows\SysNative\drivers\cpuz135_x64.sys (CPUID)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (ETD) -- C:\Windows\SysNative\drivers\ETD.sys (ELAN Microelectronics Corp.)
DRV:64bit: - (iusb3xhc) -- C:\Windows\SysNative\drivers\iusb3xhc.sys (Intel Corporation)
DRV:64bit: - (iusb3hub) -- C:\Windows\SysNative\drivers\iusb3hub.sys (Intel Corporation)
DRV:64bit: - (iusb3hcs) -- C:\Windows\SysNative\drivers\iusb3hcs.sys (Intel Corporation)
DRV:64bit: - (RSBASTOR) -- C:\Windows\SysNative\drivers\RtsBaStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (BtFilter) -- C:\Windows\SysNative\drivers\btfilter.sys (Atheros)
DRV:64bit: - (BTATH_RCP) -- C:\Windows\SysNative\drivers\btath_rcp.sys (Atheros)
DRV:64bit: - (BTATH_LWFLT) -- C:\Windows\SysNative\drivers\btath_lwflt.sys (Atheros)
DRV:64bit: - (BTATH_HCRP) -- C:\Windows\SysNative\drivers\btath_hcrp.sys (Atheros)
DRV:64bit: - (AthBTPort) -- C:\Windows\SysNative\drivers\btath_flt.sys (Atheros)
DRV:64bit: - (BTATH_BUS) -- C:\Windows\SysNative\drivers\btath_bus.sys (Atheros)
DRV:64bit: - (btath_avdt) -- C:\Windows\SysNative\drivers\btath_avdt.sys (Atheros)
DRV:64bit: - (BTATH_A2DP) -- C:\Windows\SysNative\drivers\btath_a2dp.sys (Atheros)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (AsusVBus) -- C:\Windows\SysNative\drivers\AsusVBus.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (sscdmdm) -- C:\Windows\SysNative\drivers\sscdmdm.sys (MCCI Corporation)
DRV:64bit: - (sscdbus) -- C:\Windows\SysNative\drivers\sscdbus.sys (MCCI Corporation)
DRV:64bit: - (sscdmdfl) -- C:\Windows\SysNative\drivers\sscdmdfl.sys (MCCI Corporation)
DRV:64bit: - (ssadmdm) -- C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation)
DRV:64bit: - (ssadbus) -- C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
DRV:64bit: - (ssadserd) -- C:\Windows\SysNative\drivers\ssadserd.sys (MCCI Corporation)
DRV:64bit: - (androidusb) -- C:\Windows\SysNative\drivers\ssadadb.sys (Google Inc)
DRV:64bit: - (ssadmdfl) -- C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation)
DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (AsusVTouch) -- C:\Windows\SysNative\drivers\AsusVTouch.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (NPF) -- C:\Windows\SysNative\drivers\npf.sys (CACE Technologies, Inc.)
DRV:64bit: - (gogoTunnelDevice) -- C:\Windows\SysNative\drivers\gogotun.sys (gogo6 Inc.)
DRV:64bit: - (kbfiltr) -- C:\Windows\SysNative\drivers\kbfiltr.sys ( )
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (mcdbus) -- C:\Windows\SysNative\drivers\mcdbus.sys (MagicISO, Inc.)
DRV:64bit: - (WimFltr) -- C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (TuneUpUtilitiesDrv) -- C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys (TuneUp Software)
DRV - (ATKWMIACPIIO) -- C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys (ASUS)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (ASMMAP64) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys (ASUS)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?ilc=8
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=8
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://isearch.avg.c...sa&d=2012-07-07 20:58:41&v=11.1.0.12&sap=hp
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.c...sa&d=2012-07-07 20:58:41&v=11.1.0.12&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo....erms}&fr=mkg028
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo....h?fr=mkg030&p="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..keyword.URL: "http://search.yahoo....h?fr=mkg030&p="
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_268.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.52: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/Lync,version=15.0: C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nitropdf.com/NitroPDF: C:\Program Files (x86)\Nitro PDF\Professional 7\npnitromozilla.dll ( )
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Rhomel\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Rhomel\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Rhomel\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/07/08 18:27:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/07/19 17:24:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/07/18 20:41:35 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Users\Rhomel\AppData\Roaming\IDM\idmmzcc5 [2012/08/07 10:35:40 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[email protected]: C:\Users\Rhomel\AppData\Roaming\IDM\idmmzcc5 [2012/08/07 10:35:40 | 000,000,000 | ---D | M]
[2012/06/28 12:56:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rhomel\AppData\Roaming\Mozilla\Extensions
[2012/07/01 23:38:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Rhomel\AppData\Roaming\Mozilla\Firefox\Profiles\a1fd0z6f.default\extensions
[2012/07/17 16:37:10 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/07/17 16:37:10 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/07/08 18:27:23 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2012/08/07 10:35:40 | 000,000,000 | ---D | M] (IDM CC) -- C:\USERS\RHOMEL\APPDATA\ROAMING\IDM\IDMMZCC5
[2012/07/19 17:24:53 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2008/12/10 14:49:34 | 000,023,040 | ---- | M] (National Instruments) -- C:\Program Files (x86)\mozilla firefox\plugins\nplv86win32.dll
[2010/05/25 12:43:16 | 000,025,088 | ---- | M] (National Instruments) -- C:\Program Files (x86)\mozilla firefox\plugins\nplv90win32.dll
[2012/06/23 18:20:16 | 000,033,992 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll
[2012/07/07 20:58:34 | 000,003,750 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/07/19 17:24:51 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/07/19 17:24:51 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms},
CHR - homepage:
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Rhomel\AppData\Local\Google\Chrome\Application\21.0.1180.60\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Rhomel\AppData\Local\Google\Chrome\Application\21.0.1180.60\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Rhomel\AppData\Local\Google\Chrome\Application\21.0.1180.60\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Rhomel\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - Extension: YouTube = C:\Users\Rhomel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Rhomel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Premium Cookie Injector (Multi-Server) = C:\Users\Rhomel\AppData\Local\Google\Chrome\User Data\Default\Extensions\hglhnookgghcefjamdoakhhfamnhodpd\1.4_0\
CHR - Extension: avast! WebRep = C:\Users\Rhomel\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1456_0\
CHR - Extension: Skype Click to Call = C:\Users\Rhomel\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.1.0.10441_0\
CHR - Extension: FastestChrome - Browse Faster = C:\Users\Rhomel\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmffncokckfccddfenhkhnllmlobdahm\6.5.0_0\
CHR - Extension: Gmail = C:\Users\Rhomel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/07/21 22:29:03 | 000,000,865 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 updates.connectify.me
O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKLM..\Run: [USB Security] C:\Program Files (x86)\USB Disk Security\USBGuard.exe (AbeGunnerZ Lab)
O4 - HKCU..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O8:64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8:64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 121.1.3.82 121.1.3.20 121.1.3.250
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{212C1621-DD63-4548-A3DB-6CCE1E4C8CE5}: NameServer = 192.168.31.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F5612C4-53DA-48D5-8000-D4F4661D4DC4}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E156B9CC-8764-4C61-80EF-0B9709EFD6CE}: DhcpNameServer = 121.1.3.82 121.1.3.20 121.1.3.250
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F721C091-B959-4759-AB9C-32F30D02584B}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (C:\Windows\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{5bbff264-c150-11e1-8d7d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{5bbff264-c150-11e1-8d7d-806e6f6e6963}\Shell\AutoRun\command - "" = E:\InstAll.exe
O33 - MountPoints2\{81dd5171-c6ca-11e1-8e2c-94dbc9ab461d}\Shell - "" = AutoRun
O33 - MountPoints2\{81dd5171-c6ca-11e1-8e2c-94dbc9ab461d}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{bdd3b8a3-db5d-11e1-a988-94dbc9ab461d}\Shell - "" = AutoRun
O33 - MountPoints2\{bdd3b8a3-db5d-11e1-a988-94dbc9ab461d}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{c977f6b5-c2ef-11e1-b6d0-94dbc9ab461d}\Shell - "" = AutoRun
O33 - MountPoints2\{c977f6b5-c2ef-11e1-b6d0-94dbc9ab461d}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{c977f6d9-c2ef-11e1-b6d0-94dbc9ab461d}\Shell - "" = AutoRun
O33 - MountPoints2\{c977f6d9-c2ef-11e1-b6d0-94dbc9ab461d}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{dd93d89f-d5bb-11e1-becd-94dbc9ab461d}\Shell - "" = AutoRun
O33 - MountPoints2\{dd93d89f-d5bb-11e1-becd-94dbc9ab461d}\Shell\AutoRun\command - "" = G:\Autorun.exe
O33 - MountPoints2\{ea93573f-d66f-11e1-9422-94dbc9ab461d}\Shell - "" = AutoRun
O33 - MountPoints2\{ea93573f-d66f-11e1-9422-94dbc9ab461d}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/08/07 18:53:29 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Rhomel\Desktop\OTL.exe
[2012/08/07 11:52:53 | 000,000,000 | -H-D | C] -- C:\ProgramData\CanonIJSIP
[2012/08/07 10:35:35 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\IDM
[2012/08/06 16:07:09 | 000,000,000 | R--D | C] -- C:\Users\Rhomel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
[2012/08/04 20:58:04 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
[2012/08/03 02:30:28 | 000,158,944 | ---- | C] (Tonec Inc.) -- C:\Windows\SysNative\drivers\idmwfp.sys
[2012/08/02 07:26:12 | 000,000,000 | R--D | C] -- C:\Users\Rhomel\Documents\Notes
[2012/07/31 16:46:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap
[2012/07/31 16:46:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinPcap
[2012/07/31 16:46:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\arcai.com
[2012/07/31 16:46:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\netcut
[2012/07/31 06:51:03 | 000,035,680 | ---- | C] (TuneUp Software) -- C:\Windows\SysNative\uxtuneup.dll
[2012/07/31 06:51:03 | 000,029,024 | ---- | C] (TuneUp Software) -- C:\Windows\SysWow64\uxtuneup.dll
[2012/07/30 22:56:30 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Local\HonLauncher
[2012/07/30 20:55:30 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Local\Chromium
[2012/07/30 20:55:07 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\Documents\Heroes of Newerth (Garena)
[2012/07/30 20:45:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GarenaHoN
[2012/07/30 19:01:07 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Local\Garena
[2012/07/29 20:50:44 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2012/07/29 18:39:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\gogo6
[2012/07/29 18:39:10 | 000,000,000 | ---D | C] -- C:\Program Files\gogo6
[2012/07/29 15:26:10 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\com.prezi.PreziDesktop
[2012/07/27 00:50:18 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Canopy
[2012/07/27 00:50:10 | 000,000,000 | ---D | C] -- C:\Canopy
[2012/07/27 00:50:02 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Zero G Registry
[2012/07/27 00:49:53 | 000,000,000 | -H-D | C] -- C:\Users\Rhomel\InstallAnywhere
[2012/07/25 19:16:43 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++
[2012/07/25 19:16:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
[2012/07/25 08:55:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sun Broadband Wireless
[2012/07/24 16:23:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Disktrix
[2012/07/24 16:23:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Disktrix
[2012/07/24 11:42:19 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\SupportAppCB
[2012/07/23 23:12:40 | 000,000,000 | ---D | C] -- C:\Temp
[2012/07/23 23:06:08 | 000,203,320 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\Windows\SysNative\drivers\ssudserd.sys
[2012/07/23 23:06:08 | 000,203,320 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\Windows\SysNative\drivers\ssudmdm.sys
[2012/07/23 23:06:08 | 000,099,384 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\Windows\SysNative\drivers\ssudbus.sys
[2012/07/23 22:51:12 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012/07/23 22:49:08 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Local\Samsung
[2012/07/23 22:48:58 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\Samsung
[2012/07/23 22:48:55 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\Documents\samsung
[2012/07/23 22:47:29 | 000,013,800 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadwhnt.sys
[2012/07/23 22:47:29 | 000,013,800 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadwh.sys
[2012/07/23 22:47:28 | 000,177,640 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadmdm.sys
[2012/07/23 22:47:28 | 000,157,672 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadbus.sys
[2012/07/23 22:47:28 | 000,146,920 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadserd.sys
[2012/07/23 22:47:28 | 000,016,872 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadmdfl.sys
[2012/07/23 22:47:28 | 000,013,288 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadcmnt.sys
[2012/07/23 22:47:28 | 000,013,288 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadcm.sys
[2012/07/23 22:46:52 | 000,172,104 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\sscdmdm.sys
[2012/07/23 22:46:52 | 000,136,264 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\sscdbus.sys
[2012/07/23 22:46:52 | 000,019,016 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\sscdmdfl.sys
[2012/07/23 22:46:52 | 000,015,944 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\sscdwhnt.sys
[2012/07/23 22:46:52 | 000,015,944 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\sscdwh.sys
[2012/07/23 22:46:52 | 000,015,432 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\sscdcmnt.sys
[2012/07/23 22:46:52 | 000,015,432 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\sscdcm.sys
[2012/07/23 22:45:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
[2012/07/23 22:45:42 | 004,659,712 | ---- | C] (Dmitry Streblechenko) -- C:\Windows\SysWow64\Redemption.dll
[2012/07/23 22:45:28 | 000,821,824 | ---- | C] (Devguru Co., Ltd.) -- C:\Windows\SysWow64\dgderapi.dll
[2012/07/23 22:45:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MarkAny
[2012/07/23 22:44:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Samsung
[2012/07/23 22:44:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Samsung
[2012/07/23 22:43:13 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Local\Downloaded Installations
[2012/07/22 00:30:35 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2012/07/22 00:27:09 | 000,000,000 | ---D | C] -- C:\ProgramData\YTD Video Downloader
[2012/07/22 00:27:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader
[2012/07/22 00:27:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\GreenTree Applications
[2012/07/21 23:32:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\UX Pack
[2012/07/21 23:32:22 | 000,000,000 | ---D | C] -- C:\UXFiles
[2012/07/21 22:30:05 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Local\SkinSoft
[2012/07/21 01:02:03 | 000,000,000 | ---D | C] -- C:\Windows\AutoKMS
[2012/07/20 18:57:53 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\Unified Remote
[2012/07/20 18:57:37 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unified Remote
[2012/07/20 18:57:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Unified Remote
[2012/07/20 18:39:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother
[2012/07/20 18:38:42 | 000,176,128 | ---- | C] (Brother Industries, Ltd.) -- C:\Windows\SysWow64\BroSNMP.dll
[2012/07/20 18:38:42 | 000,073,728 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\SysWow64\BrDctF2.dll
[2012/07/20 18:38:42 | 000,005,120 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\SysWow64\BrDctF2L.dll
[2012/07/20 18:38:42 | 000,003,072 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\SysWow64\BrDctF2S.dll
[2012/07/20 18:38:39 | 001,560,576 | ---- | C] (Brother Industries, Ltd.) -- C:\Windows\SysNative\BrWia09b.dll
[2012/07/20 18:38:30 | 000,167,936 | ---- | C] (brother) -- C:\Windows\SysWow64\NSSearch.dll
[2012/07/19 23:52:34 | 000,034,656 | ---- | C] (TuneUp Software) -- C:\Windows\SysNative\TURegOpt.exe
[2012/07/19 23:52:34 | 000,025,952 | ---- | C] (TuneUp Software) -- C:\Windows\SysNative\authuitu.dll
[2012/07/19 23:52:34 | 000,021,344 | ---- | C] (TuneUp Software) -- C:\Windows\SysWow64\authuitu.dll
[2012/07/19 23:52:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2012
[2012/07/19 23:52:11 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\TuneUp Software
[2012/07/19 23:51:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TuneUp Utilities 2012
[2012/07/19 23:51:23 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software
[2012/07/19 23:51:19 | 000,000,000 | -HSD | C] -- C:\ProgramData\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2012/07/19 17:08:15 | 010,235,904 | ---- | C] (AutoDWG) -- C:\Windows\SysWow64\PDF2DWG.dll
[2012/07/19 17:08:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoDWG
[2012/07/19 17:08:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AutoDWG
[2012/07/19 00:03:58 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Shared Memory
[2012/07/18 22:52:32 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Local\[email protected]
[2012/07/18 20:45:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
[2012/07/18 20:43:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server
[2012/07/18 20:43:24 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2012/07/18 20:41:06 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server
[2012/07/18 00:09:36 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012/07/18 00:09:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe Download Assistant
[2012/07/18 00:09:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
[2012/07/17 22:24:56 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\NV
[2012/07/17 22:24:56 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\NV
[2012/07/17 21:59:14 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2012/07/17 21:57:57 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2012/07/17 21:57:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
[2012/07/17 19:11:31 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Local\Temp
[2012/07/17 19:11:28 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/07/17 17:51:02 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\ParetoLogic
[2012/07/17 17:51:02 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\DriverCure
[2012/07/17 17:50:56 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ParetoLogic
[2012/07/17 17:50:51 | 000,000,000 | ---D | C] -- C:\ProgramData\ParetoLogic
[2012/07/17 17:50:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ParetoLogic
[2012/07/17 17:50:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ParetoLogic
[2012/07/17 17:20:24 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\Malwarebytes
[2012/07/17 17:20:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/07/17 17:20:19 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/07/17 17:20:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/07/17 17:20:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/07/17 16:35:15 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\Skype
[2012/07/17 16:35:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/07/17 16:35:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2012/07/17 16:35:04 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2012/07/17 16:35:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2012/07/15 16:57:01 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\DriverGenius
[2012/07/15 12:43:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Skin Pack
[2012/07/15 12:42:58 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\MetroClock
[2012/07/15 12:13:31 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Local\Diagnostics
[2012/07/15 12:05:34 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Local\Labcenter Electronics
[2012/07/15 12:05:34 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Downloaded Data Sheets
[2012/07/15 05:35:44 | 001,048,576 | ---- | C] (Blue Sky Software Corporation.) -- C:\Windows\SysWow64\ROBOEX32.DLL
[2012/07/15 05:35:44 | 000,054,784 | ---- | C] (Blue Sky Software Corporation.) -- C:\Windows\SysWow64\INETWH32.DLL
[2012/07/15 05:35:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Labcenter Electronics
[2012/07/15 03:04:45 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\PTC
[2012/07/15 03:04:42 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Local\Mathsoft
[2012/07/15 03:03:05 | 000,000,000 | ---D | C] -- C:\ProgramData\PTC
[2012/07/15 03:02:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PTC
[2012/07/15 03:00:22 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\Mathsoft
[2012/07/15 02:57:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mathcad
[2012/07/15 02:53:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSXML 4.0
[2012/07/15 02:53:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2012/07/15 00:51:45 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/07/15 00:51:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/07/15 00:51:39 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2012/07/15 00:49:15 | 000,000,000 | -H-D | C] -- C:\ProgramData\CanonBJ
[2012/07/15 00:49:09 | 000,000,000 | -H-D | C] -- C:\Windows\SysNative\CanonIJ Uninstaller Information
[2012/07/15 00:49:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon iP2700 series
[2012/07/15 00:48:47 | 000,000,000 | -H-D | C] -- C:\Program Files\CanonBJ
[2012/07/15 00:41:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DipTrace
[2012/07/15 00:41:22 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\Documents\DipTrace
[2012/07/15 00:40:24 | 000,000,000 | ---D | C] -- C:\ProgramData\DipTrace
[2012/07/15 00:40:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DipTrace
[2012/07/14 22:51:29 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Local\ShamurShamur
[2012/07/13 16:31:54 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Local\CrashDumps
[2012/07/12 23:13:00 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\Notepad++
[2012/07/12 23:13:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Notepad++
[2012/07/12 15:40:33 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool
[2012/07/11 23:52:11 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\AppData\Roaming\GarenaPlus
[2012/07/11 23:51:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Garena Plus
[2012/07/11 23:51:49 | 000,000,000 | ---D | C] -- C:\ProgramData\GarenaMessenger
[2012/07/11 20:53:46 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\.VirtualBox
[2012/07/11 20:53:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
[2012/07/11 20:53:05 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE
[2012/07/11 20:52:56 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle
[2012/07/11 10:07:10 | 000,000,000 | ---D | C] -- C:\Users\Rhomel\Documents\OneNote Notebooks
[2012/07/09 21:38:32 | 000,000,000 | R--D | C] -- C:\Users\Rhomel\AppData\Roaming\Brother
[2012/07/08 23:01:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Brother
[2012/07/08 23:00:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Brother
========== Files - Modified Within 30 Days ==========
[2012/08/07 18:53:29 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Rhomel\Desktop\OTL.exe
[2012/08/07 18:51:10 | 000,257,431 | ---- | M] () -- C:\Users\Rhomel\Desktop\Untitled.jpg
[2012/08/07 17:18:40 | 000,000,496 | ---- | M] () -- C:\Windows\tasks\ParetoLogic Update Version3 Startup Task.job
[2012/08/07 17:18:40 | 000,000,444 | ---- | M] () -- C:\Windows\tasks\ParetoLogic Update Version3.job
[2012/08/07 10:43:36 | 000,014,416 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/07 10:43:36 | 000,014,416 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/07 10:35:52 | 000,000,380 | ---- | M] () -- C:\Users\Rhomel\AppData\Roaming\sp_data.sys
[2012/08/07 10:35:28 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/08/07 10:35:18 | 3131,490,304 | -HS- | M] () -- C:\hiberfil.sys
[2012/08/07 02:34:00 | 000,000,030 | ---- | M] () -- C:\0.bak
[2012/08/06 22:30:17 | 000,000,521 | ---- | M] () -- C:\0
[2012/08/06 11:26:28 | 000,778,834 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/08/06 11:26:28 | 000,660,318 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/08/06 11:26:28 | 000,121,214 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/08/04 20:58:04 | 000,000,219 | ---- | M] () -- C:\Users\Rhomel\Desktop\Dota 2.url
[2012/08/04 13:17:55 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/08/01 17:23:14 | 000,158,944 | ---- | M] (Tonec Inc.) -- C:\Windows\SysNative\drivers\idmwfp.sys
[2012/08/01 05:27:07 | 000,002,162 | ---- | M] () -- C:\Windows\SysNative\ServiceFilter.ini
[2012/08/01 05:25:53 | 000,002,388 | ---- | M] () -- C:\Windows\SysNative\AutoRunFilter.ini
[2012/07/31 17:15:00 | 000,000,822 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/07/31 16:46:30 | 000,704,512 | ---- | M] () -- C:\Windows\is-RODFQ.exe
[2012/07/31 16:46:30 | 000,010,498 | ---- | M] () -- C:\Windows\is-RODFQ.msg
[2012/07/31 16:46:30 | 000,001,003 | ---- | M] () -- C:\Users\Rhomel\Application Data\Microsoft\Internet Explorer\Quick Launch\Arcai.com's NetCut.lnk
[2012/07/31 16:46:30 | 000,000,213 | ---- | M] () -- C:\Windows\is-RODFQ.lst
[2012/07/30 20:52:24 | 000,001,973 | ---- | M] () -- C:\Users\Public\Desktop\Heroes of Newerth.lnk
[2012/07/28 06:27:50 | 000,028,786 | ---- | M] () -- C:\Users\Rhomel\Documents\Drawing1_recover000.dwg
[2012/07/28 06:15:53 | 000,819,727 | ---- | M] () -- C:\Users\Rhomel\Documents\Drawing1_recover.dwg
[2012/07/27 23:26:06 | 000,000,202 | -H-- | M] () -- C:\Users\Rhomel\Documents\Drawing1.dwl2
[2012/07/27 23:26:06 | 000,000,052 | -H-- | M] () -- C:\Users\Rhomel\Documents\Drawing1.dwl
[2012/07/27 00:50:18 | 000,001,659 | ---- | M] () -- C:\Users\Rhomel\Desktop\Network Updater.lnk
[2012/07/27 00:31:05 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2012/07/23 23:11:50 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ssadadb_01005.Wdf
[2012/07/23 22:57:03 | 000,773,050 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/07/23 22:48:45 | 000,001,953 | ---- | M] () -- C:\Users\Public\Desktop\Samsung Kies.lnk
[2012/07/23 22:45:47 | 000,001,977 | ---- | M] () -- C:\Users\Rhomel\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2012/07/22 01:32:54 | 000,000,180 | ---- | M] () -- C:\Windows\dotahotkeys.ini
[2012/07/21 23:32:45 | 006,912,054 | ---- | M] () -- C:\Windows\clwcp.bmp
[2012/07/21 22:29:03 | 000,000,865 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/07/21 22:14:22 | 000,000,375 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.ics
[2012/07/20 18:39:31 | 000,000,050 | ---- | M] () -- C:\Windows\SysNative\bridf08b.dat
[2012/07/20 18:39:28 | 000,000,419 | ---- | M] () -- C:\Windows\BRWMARK.INI
[2012/07/20 18:39:28 | 000,000,027 | ---- | M] () -- C:\Windows\BRPP2KA.INI
[2012/07/19 23:52:19 | 000,002,209 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp 1-Click Maintenance.lnk
[2012/07/19 23:52:19 | 000,002,183 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp Utilities 2012.lnk
[2012/07/18 22:36:50 | 000,002,681 | ---- | M] () -- C:\Users\Rhomel\Desktop\AutoCAD 2013 - English.lnk
[2012/07/18 21:10:45 | 000,002,937 | ---- | M] () -- C:\Users\Rhomel\Desktop\PowerPoint 2013.lnk
[2012/07/18 21:10:41 | 000,003,021 | ---- | M] () -- C:\Users\Rhomel\Desktop\Word 2013.lnk
[2012/07/17 20:52:39 | 000,000,412 | ---- | M] () -- C:\Windows\tasks\RegCure Pro.job
[2012/07/17 19:29:52 | 000,000,105 | ---- | M] () -- C:\Windows\SysNative\FastBoot.ini
[2012/07/17 19:27:05 | 000,002,408 | ---- | M] () -- C:\Users\Public\Desktop\AutoCAD Architecture 2013 - English (US Imperial).lnk
[2012/07/17 19:27:05 | 000,002,404 | ---- | M] () -- C:\Users\Public\Desktop\AutoCAD Architecture 2013 - English (US Metric).lnk
[2012/07/17 19:27:05 | 000,002,398 | ---- | M] () -- C:\Users\Public\Desktop\AutoCAD Architecture 2013 - English (Global).lnk
[2012/07/17 17:50:56 | 000,001,182 | ---- | M] () -- C:\Users\Rhomel\Desktop\RegCure Pro.lnk
[2012/07/16 00:51:09 | 000,034,308 | ---- | M] () -- C:\Windows\SysWow64\BASSMOD.dll
[2012/07/15 02:59:10 | 000,002,050 | ---- | M] () -- C:\Users\Rhomel\Application Data\Microsoft\Internet Explorer\Quick Launch\Mathcad 15.lnk
[2012/07/15 02:59:10 | 000,002,026 | ---- | M] () -- C:\Users\Public\Desktop\Mathcad 15.lnk
[2012/07/13 12:32:33 | 000,045,663 | ---- | M] () -- C:\Users\Rhomel\Documents\lancet window.dwg
[2012/07/12 00:17:45 | 000,045,270 | ---- | M] () -- C:\Users\Rhomel\AppData\Roaming\room_v3.dat
[2012/07/11 20:51:16 | 000,001,908 | ---- | M] () -- C:\Windows\diagwrn.xml
[2012/07/11 20:51:16 | 000,001,908 | ---- | M] () -- C:\Windows\diagerr.xml
========== Files Created - No Company Name ==========
[2012/08/07 17:18:40 | 000,000,496 | ---- | C] () -- C:\Windows\tasks\ParetoLogic Update Version3 Startup Task.job
[2012/08/07 12:13:59 | 000,257,431 | ---- | C] () -- C:\Users\Rhomel\Desktop\Untitled.jpg
[2012/08/07 02:34:00 | 000,000,030 | ---- | C] () -- C:\0.bak
[2012/08/04 20:58:04 | 000,000,219 | ---- | C] () -- C:\Users\Rhomel\Desktop\Dota 2.url
[2012/07/31 16:46:30 | 000,704,512 | ---- | C] () -- C:\Windows\is-RODFQ.exe
[2012/07/31 16:46:30 | 000,010,498 | ---- | C] () -- C:\Windows\is-RODFQ.msg
[2012/07/31 16:46:30 | 000,001,003 | ---- | C] () -- C:\Users\Rhomel\Application Data\Microsoft\Internet Explorer\Quick Launch\Arcai.com's NetCut.lnk
[2012/07/31 16:46:30 | 000,000,213 | ---- | C] () -- C:\Windows\is-RODFQ.lst
[2012/07/31 16:46:29 | 000,389,120 | ---- | C] () -- C:\Windows\SysWow64\actskn43.ocx
[2012/07/30 20:52:24 | 000,001,973 | ---- | C] () -- C:\Users\Public\Desktop\Heroes of Newerth.lnk
[2012/07/28 06:27:50 | 000,028,786 | ---- | C] () -- C:\Users\Rhomel\Documents\Drawing1_recover000.dwg
[2012/07/28 06:15:53 | 000,819,727 | ---- | C] () -- C:\Users\Rhomel\Documents\Drawing1_recover.dwg
[2012/07/27 23:26:06 | 000,000,202 | -H-- | C] () -- C:\Users\Rhomel\Documents\Drawing1.dwl2
[2012/07/27 23:26:06 | 000,000,052 | -H-- | C] () -- C:\Users\Rhomel\Documents\Drawing1.dwl
[2012/07/27 00:50:18 | 000,001,659 | ---- | C] () -- C:\Users\Rhomel\Desktop\Network Updater.lnk
[2012/07/23 23:11:50 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ssadadb_01005.Wdf
[2012/07/23 22:48:45 | 000,001,953 | ---- | C] () -- C:\Users\Public\Desktop\Samsung Kies.lnk
[2012/07/23 22:45:47 | 000,001,977 | ---- | C] () -- C:\Users\Rhomel\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2012/07/22 01:32:54 | 000,000,180 | ---- | C] () -- C:\Windows\dotahotkeys.ini
[2012/07/21 23:32:45 | 006,912,054 | ---- | C] () -- C:\Windows\clwcp.bmp
[2012/07/21 23:32:26 | 000,517,120 | ---- | C] () -- C:\Windows\SysWow64\CLWCP.exe
[2012/07/21 23:32:25 | 000,925,184 | ---- | C] () -- C:\Windows\expstart.exe
[2012/07/19 23:52:19 | 000,002,209 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp 1-Click Maintenance.lnk
[2012/07/19 23:52:19 | 000,002,195 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2012.lnk
[2012/07/19 23:52:19 | 000,002,183 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp Utilities 2012.lnk
[2012/07/19 17:08:14 | 000,925,696 | ---- | C] () -- C:\Windows\SysWow64\AxEImage.dll
[2012/07/19 17:08:14 | 000,663,552 | ---- | C] () -- C:\Windows\SysWow64\FreeImage.dll
[2012/07/18 22:36:50 | 000,002,681 | ---- | C] () -- C:\Users\Rhomel\Desktop\AutoCAD 2013 - English.lnk
[2012/07/18 21:10:45 | 000,002,937 | ---- | C] () -- C:\Users\Rhomel\Desktop\PowerPoint 2013.lnk
[2012/07/18 21:10:41 | 000,003,021 | ---- | C] () -- C:\Users\Rhomel\Desktop\Word 2013.lnk
[2012/07/18 00:09:34 | 000,001,043 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Download Assistant.lnk
[2012/07/17 21:58:51 | 002,587,633 | ---- | C] () -- C:\Windows\SysNative\nvcoproc.bin
[2012/07/17 21:57:00 | 000,012,780 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb
[2012/07/17 21:45:13 | 000,000,380 | ---- | C] () -- C:\Users\Rhomel\AppData\Roaming\sp_data.sys
[2012/07/17 19:27:05 | 000,002,408 | ---- | C] () -- C:\Users\Public\Desktop\AutoCAD Architecture 2013 - English (US Imperial).lnk
[2012/07/17 19:27:05 | 000,002,404 | ---- | C] () -- C:\Users\Public\Desktop\AutoCAD Architecture 2013 - English (US Metric).lnk
[2012/07/17 19:27:05 | 000,002,398 | ---- | C] () -- C:\Users\Public\Desktop\AutoCAD Architecture 2013 - English (Global).lnk
[2012/07/17 17:50:56 | 000,001,182 | ---- | C] () -- C:\Users\Rhomel\Desktop\RegCure Pro.lnk
[2012/07/17 17:50:56 | 000,000,444 | ---- | C] () -- C:\Windows\tasks\ParetoLogic Update Version3.job
[2012/07/17 17:50:53 | 000,000,412 | ---- | C] () -- C:\Windows\tasks\RegCure Pro.job
[2012/07/16 00:48:04 | 000,034,308 | ---- | C] () -- C:\Windows\SysWow64\BASSMOD.dll
[2012/07/15 02:59:10 | 000,002,050 | ---- | C] () -- C:\Users\Rhomel\Application Data\Microsoft\Internet Explorer\Quick Launch\Mathcad 15.lnk
[2012/07/15 02:59:10 | 000,002,026 | ---- | C] () -- C:\Users\Public\Desktop\Mathcad 15.lnk
[2012/07/13 11:55:24 | 000,045,663 | ---- | C] () -- C:\Users\Rhomel\Documents\lancet window.dwg
[2012/07/12 00:17:45 | 000,045,270 | ---- | C] () -- C:\Users\Rhomel\AppData\Roaming\room_v3.dat
[2012/07/11 20:50:12 | 000,001,908 | ---- | C] () -- C:\Windows\diagwrn.xml
[2012/07/11 20:50:12 | 000,001,908 | ---- | C] () -- C:\Windows\diagerr.xml
[2012/07/08 23:03:10 | 000,000,419 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2012/07/08 23:03:10 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2012/07/08 23:02:13 | 000,000,050 | ---- | C] () -- C:\Windows\SysNative\bridf08b.dat
[2012/06/28 13:24:48 | 000,773,050 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/06/28 11:50:39 | 013,020,160 | ---- | C] () -- C:\Windows\SysWow64\ig7icd32.dll
[2012/06/28 11:50:39 | 000,735,796 | ---- | C] () -- C:\Windows\SysWow64\igkrng700.bin
[2012/06/28 11:50:39 | 000,561,508 | ---- | C] () -- C:\Windows\SysWow64\igfcg700m.bin
[2012/06/28 11:50:39 | 000,058,880 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2011/12/23 20:58:28 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2011/12/23 20:58:24 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2011/12/23 20:58:24 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2011/12/23 20:58:24 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2011/12/23 20:58:24 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2011/12/08 16:14:58 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll
========== LOP Check ==========
[2012/06/30 00:21:09 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\(F8-D0-BD-3B-A0-6D)
[2012/07/07 08:18:37 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\Autodesk
[2012/07/18 00:09:36 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012/07/29 15:26:10 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\com.prezi.PreziDesktop
[2012/07/15 04:28:54 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\DAEMON Tools Pro
[2012/08/07 17:21:59 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\DMCache
[2012/07/04 22:16:48 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\Downloaded Installations
[2012/07/17 17:51:02 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\DriverCure
[2012/08/03 23:28:44 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\GarenaPlus
[2012/08/07 18:49:19 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\IDM
[2012/07/08 17:01:05 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\ImgBurn
[2012/07/15 03:00:22 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\Mathsoft
[2012/07/06 15:21:15 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\National Instruments
[2012/08/02 04:02:47 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\Nitro PDF
[2012/08/02 23:56:15 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\Notepad++
[2012/07/17 17:51:02 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\ParetoLogic
[2012/07/15 03:04:45 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\PTC
[2012/07/23 22:48:58 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\Samsung
[2012/08/07 02:34:08 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\TeraCopy
[2012/07/31 06:49:45 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\TuneUp Software
[2012/07/20 18:57:56 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\Unified Remote
[2012/08/07 18:49:19 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\uTorrent
[2012/07/04 22:23:54 | 000,000,000 | ---D | M] -- C:\Users\Rhomel\AppData\Roaming\Zbshareware Lab
[2012/07/05 13:02:47 | 000,000,910 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-269433224-411305373-2250994567-1000Core.job
[2012/07/05 13:02:47 | 000,000,932 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-269433224-411305373-2250994567-1000UA.job
[2012/06/29 03:54:32 | 000,000,828 | ---- | M] () -- C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
[2012/06/29 03:54:32 | 000,000,830 | ---- | M] () -- C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
[2012/08/07 17:18:40 | 000,000,496 | ---- | M] () -- C:\Windows\Tasks\ParetoLogic Update Version3 Startup Task.job
[2012/08/07 17:18:40 | 000,000,444 | ---- | M] () -- C:\Windows\Tasks\ParetoLogic Update Version3.job
[2012/07/17 20:52:39 | 000,000,412 | ---- | M] () -- C:\Windows\Tasks\RegCure Pro.job
[2012/07/20 19:23:46 | 000,032,598 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:A1EDB939
< End of report >
OTL Extras logfile created on: 8/7/2012 6:55:48 PM - Run 1
OTL by OldTimer - Version 3.2.56.0 Folder = C:\Users\Rhomel\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.89 Gb Total Physical Memory | 1.75 Gb Available Physical Memory | 45.10% Memory free
7.78 Gb Paging File | 5.23 Gb Available in Paging File | 67.26% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 405.67 Gb Total Space | 352.78 Gb Free Space | 86.96% Space Free | Partition Type: NTFS
Drive D: | 292.87 Gb Total Space | 240.01 Gb Free Space | 81.95% Space Free | Partition Type: NTFS
Computer Name: RHOMEL-PC | User Name: Rhomel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{078BD67F-4FF3-4A76-8D17-79CF786C5764}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{0AA87542-211A-410D-A699-B5E5A6BC8197}" = lport=6113 | protocol=17 | dir=in | name=ghb1 |
"{19202CD2-C614-488D-9F74-D4B8BD239546}" = rport=1900 | protocol=17 | dir=out | app=c:\windows\system32\svchost.exe |
"{1A11A615-089E-4792-B9A6-A95FA8FE8630}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |
"{2BCD9AAF-D8AB-4F82-B935-2EA80BD0C51E}" = lport=1317 | protocol=17 | dir=in | app=c:\program files (x86)\connectify\connectifynetservices.exe |
"{35D8E5F6-6A7C-48AB-9AE7-E7891B413812}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{3AC3C4EB-DC59-4015-852A-53FB64F4CB67}" = lport=2987 | protocol=6 | dir=in | app=c:\program files (x86)\connectify\connectify.exe |
"{3B6E311C-F4C3-4D5F-BDF7-F90544A994AF}" = lport=1303 | protocol=17 | dir=in | app=c:\program files (x86)\connectify\connectifynetservices.exe |
"{3FA30321-E634-4A89-9984-B84845353DD3}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{45E1E37B-1791-49A1-98E2-8C5478070063}" = rport=445 | protocol=6 | dir=out | app=system |
"{47F360ED-A630-4DE4-B7CF-E2C8BB38F6CD}" = rport=2869 | protocol=6 | dir=out | app=system |
"{4A128486-AA5D-461F-ADA9-49BCB5337AC1}" = lport=445 | protocol=6 | dir=in | app=system |
"{52769687-9866-4B48-9D81-52A00BB678DF}" = lport=1900 | protocol=17 | dir=in | app=c:\windows\system32\svchost.exe |
"{55115BE9-9E68-4E46-9B38-92BE8186F584}" = lport=50248 | protocol=6 | dir=in | name=autodesk content service |
"{629015DF-E03C-4AA8-AC76-6678240EAB4B}" = lport=7000 | protocol=6 | dir=in | name=windows easy transfer tcp port |
"{770FA037-E428-4578-90D4-BEE4930ABEA8}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{81F91416-9048-47EB-BCDB-105388F0514F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8CB0004B-F88D-4BAA-AC7F-4271DF2BB4FD}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9063B563-2978-407C-B251-30E35EE21905}" = lport=139 | protocol=6 | dir=in | app=system |
"{91E82E47-E5CA-4BFA-9303-24DC1C94EF2B}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{968EDC61-9851-405E-8BBD-1F0D8EB98C7E}" = lport=68 | protocol=17 | dir=in | app=c:\program files (x86)\connectify\connectifynetservices.exe |
"{9754E279-A4DE-46C8-81CF-4CAA009EECE0}" = rport=138 | protocol=17 | dir=out | app=system |
"{97A7218E-F163-463F-9FE0-77D4CE7FF59B}" = lport=6114 | protocol=17 | dir=in | name=ghb3 |
"{9F42501E-B182-4243-AB58-18B4A5407F87}" = lport=7000 | protocol=17 | dir=in | name=windows easy transfer udp port |
"{A1CAC11D-94EA-47EB-8926-87D738622E1C}" = lport=138 | protocol=17 | dir=in | app=system |
"{ADD2338B-A595-4A1E-91B8-9464B98AB890}" = lport=67 | protocol=17 | dir=in | app=c:\program files (x86)\connectify\connectifynetservices.exe |
"{B3097DD3-0344-48AC-A676-11D6DF18205D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B8CC7E80-D729-44E0-9A7F-40337B438AEA}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{C088C246-AFE4-4C30-AC22-29C711643FC3}" = lport=547 | protocol=17 | dir=in | app=c:\windows\system32\svchost.exe |
"{C27E4107-35C9-4AD0-A872-D7C26004CF6C}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D11A2926-987A-430E-ABB8-BF6525147FC2}" = lport=6113 | protocol=6 | dir=in | name=ghb |
"{D205065C-B7A2-4A3D-A07F-F0282A85CBF8}" = lport=53 | protocol=17 | dir=in | app=c:\program files (x86)\connectify\connectifynetservices.exe |
"{D317EECB-57EA-4D4D-AD89-3CFA3F954D6D}" = lport=137 | protocol=17 | dir=in | app=system |
"{D39BAB8C-0538-4563-A675-C1E382B6F216}" = lport=2869 | protocol=6 | dir=in | app=system |
"{D862DDF2-8ECC-4A40-9E32-862FDBD9EB6C}" = rport=137 | protocol=17 | dir=out | app=system |
"{D87D5A4E-4820-4D12-B0AB-B992F259F7AF}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office15\outlook.exe |
"{E80E75AC-652B-4052-803E-292F370F7D3C}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F47D35C7-8664-4D07-ABBC-E77C6CED7B69}" = rport=139 | protocol=6 | dir=out | app=system |
"{FE5C8413-0730-4D94-9B69-6E6213F3E8D8}" = lport=6114 | protocol=6 | dir=in | name=ghb2 |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0846CDCF-E958-441A-BAD3-04054E8DE265}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{121DB783-E878-421C-B25F-5FEB0E5313AA}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe |
"{1D18A91B-EA28-41E8-BD1C-64316650A143}" = protocol=17 | dir=in | app=c:\windows\system32\migwiz\migwiz.exe |
"{2A50DE3B-870F-44CC-9552-0A2B43D29014}" = protocol=17 | dir=in | app=c:\program files (x86)\e-games\pointblank\pointblank.exe |
"{37CCF330-DC2D-4960-BD01-9BE6512444F8}" = protocol=6 | dir=in | app=c:\windows\syswow64\muzapp.exe |
"{3A8AF538-7018-4785-8EC0-DD0AB1FE50EE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{3E3C5DDB-0ED4-4DD9-9CA8-DC547B35C6B9}" = protocol=6 | dir=in | app=c:\program files (x86)\e-games\pointblank\pointblank.exe |
"{40BB38C5-25FA-43D1-8E5C-28F9B0ECDB08}" = protocol=58 | dir=out | [email protected],-28546 |
"{4CEB621F-967E-41B7-80CC-5AF39E305C11}" = dir=in | app=c:\users\rhomel\appdata\local\facebook\video\skype\facebookvideocalling.exe |
"{4DDA1C13-2EBD-4738-8355-0431DE32C230}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{51378B2F-BFFA-4DCC-9F36-D3940F6B6557}" = protocol=58 | dir=in | [email protected],-28545 |
"{61586DA7-928F-41BF-B6C5-13BF9D222A25}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{67641EE6-9A46-4691-AB31-486EE63BF614}" = protocol=17 | dir=in | app=c:\windows\syswow64\muzapp.exe |
"{6BE37784-8048-4337-91BD-17089FE112EA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{6E651D5C-3FE2-4A11-BC57-2A35508492AD}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{77992350-2D2F-4BF9-8854-1302DDA5CEC7}" = protocol=6 | dir=out | app=c:\windows\system32\svchost.exe |
"{86CB3B82-1AF5-447A-832E-D80DCF7D777C}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{8D9959AD-64E8-4945-B621-2C44838F7652}" = protocol=6 | dir=in | app=c:\windows\system32\migwiz\migwiz.exe |
"{955A419A-67F7-4948-88CB-1AAE7E5CC407}" = dir=out | app=c:\windows\system32\svchost.exe |
"{A5ADE09D-4E89-49E3-84D8-1DAD4CADD294}" = protocol=1 | dir=out | [email protected],-28544 |
"{A729FAF7-BF8F-4474-9B49-CC8DCA1CED99}" = protocol=58 | dir=in | name=internet connection sharing (router solicitation-in) |
"{AA8889E7-C637-4893-AF47-161F64EF500C}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{AD552CEF-E11D-457B-BD1A-5AFBD84F8092}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{B311D782-0B5F-4491-99EC-1FC73CE0E86C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C139F47E-E8B3-4CB2-992E-7ADD2C6D0379}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\lync.exe |
"{CD554351-A40F-4638-8BC0-3ACE160818E5}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{D5F3E323-93FD-4062-9D9E-AF8599FC1DA4}" = protocol=1 | dir=in | [email protected],-28543 |
"{DCAEA52D-881A-4EF3-AAF6-9172AC0399CB}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe |
"{F3982D68-406E-4F30-B82E-25FBEBC394E8}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\lync.exe |
"{FCE37E20-25B8-4C97-81B4-589AA18AC1AA}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"TCP Query User{03002BC3-098A-4686-8D81-1AECFA02C735}C:\program files (x86)\internet download manager\idman.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet download manager\idman.exe |
"TCP Query User{0B7B9039-9102-4C9F-AE6F-DE208F1ED813}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe" = protocol=6 | dir=in | app=c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe |
"TCP Query User{1727948E-A7A9-43C6-9AD4-9AC0610A9A72}C:\users\rhomel\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\rhomel\appdata\local\akamai\netsession_win.exe |
"TCP Query User{1FE9CDA2-2F34-433C-B260-F1DCBEFA0BE8}C:\program files (x86)\garena plus\garenamessenger.exe" = protocol=6 | dir=in | app=c:\program files (x86)\garena plus\garenamessenger.exe |
"TCP Query User{27763F30-A688-42F1-9091-481BE1BAE6AA}D:\games\warcraft iii\war3.exe" = protocol=6 | dir=in | app=d:\games\warcraft iii\war3.exe |
"TCP Query User{289E698E-75DC-4EFD-976F-BCC379292796}D:\downloads\honinstaller.exe" = protocol=6 | dir=in | app=d:\downloads\honinstaller.exe |
"TCP Query User{36FB6C07-9270-4229-84F2-4F912FD905EA}D:\games\sierra\half-life\hl.exe" = protocol=6 | dir=in | app=d:\games\sierra\half-life\hl.exe |
"TCP Query User{4463FF61-6D4C-45F6-8F82-07EB1E47F07C}D:\games\garena hostbot v6.0\ghost.exe" = protocol=6 | dir=in | app=d:\games\garena hostbot v6.0\ghost.exe |
"TCP Query User{50E24B0A-FC59-480C-AB20-0C3E61D2C1EE}C:\program files (x86)\unified remote\remoteserver.exe" = protocol=6 | dir=in | app=c:\program files (x86)\unified remote\remoteserver.exe |
"TCP Query User{8B925F44-0A4B-424B-9CC9-85AEE5956241}C:\program files (x86)\unified remote\remoteserver.exe" = protocol=6 | dir=in | app=c:\program files (x86)\unified remote\remoteserver.exe |
"TCP Query User{B115A69E-AD62-48A1-9448-B0695069D993}C:\program files (x86)\garena plus\room\garena_room.exe" = protocol=6 | dir=in | app=c:\program files (x86)\garena plus\room\garena_room.exe |
"TCP Query User{C99EFDBF-2306-42CB-89A7-C1F5EEF40212}C:\program files (x86)\connectify\connectify.exe" = protocol=6 | dir=in | app=c:\program files (x86)\connectify\connectify.exe |
"TCP Query User{D00501D7-1B98-4DDB-BDF9-A98806A8CEC0}C:\program files (x86)\garena\garena.exe" = protocol=6 | dir=in | app=c:\program files (x86)\garena\garena.exe |
"TCP Query User{D752334D-7966-4930-8656-057E6CFB4E75}D:\games\garena hostbot v6.0\garenahostbot.exe" = protocol=6 | dir=in | app=d:\games\garena hostbot v6.0\garenahostbot.exe |
"TCP Query User{EC523943-6B68-43E6-8F23-F324EC478BAF}C:\canopy\networkupdater\_jvm\bin\java.exe" = protocol=6 | dir=in | app=c:\canopy\networkupdater\_jvm\bin\java.exe |
"UDP Query User{0989A800-5982-4BD5-B4B4-D9CAE782033C}C:\program files (x86)\connectify\connectify.exe" = protocol=17 | dir=in | app=c:\program files (x86)\connectify\connectify.exe |
"UDP Query User{24C9344A-767B-4871-8CB7-1D87699DAA9F}C:\program files (x86)\unified remote\remoteserver.exe" = protocol=17 | dir=in | app=c:\program files (x86)\unified remote\remoteserver.exe |
"UDP Query User{2577D56C-673D-41E8-BD5B-E1A1E284F528}D:\downloads\honinstaller.exe" = protocol=17 | dir=in | app=d:\downloads\honinstaller.exe |
"UDP Query User{3C45FB7D-F7CB-44D4-90BC-735680422AA0}D:\games\garena hostbot v6.0\ghost.exe" = protocol=17 | dir=in | app=d:\games\garena hostbot v6.0\ghost.exe |
"UDP Query User{3C4C8F06-0543-4D1C-A73A-3A17EAF9F13A}D:\games\sierra\half-life\hl.exe" = protocol=17 | dir=in | app=d:\games\sierra\half-life\hl.exe |
"UDP Query User{5A3A001D-AC48-43C8-8646-CD8A8FA968AD}D:\games\warcraft iii\war3.exe" = protocol=17 | dir=in | app=d:\games\warcraft iii\war3.exe |
"UDP Query User{5FAD4778-1BD4-4070-9378-AD7ABD23A2A0}C:\program files (x86)\garena plus\room\garena_room.exe" = protocol=17 | dir=in | app=c:\program files (x86)\garena plus\room\garena_room.exe |
"UDP Query User{974E4692-320A-4B7C-A5DA-7B88BDF2215C}C:\users\rhomel\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\rhomel\appdata\local\akamai\netsession_win.exe |
"UDP Query User{B9C7E03C-F261-4903-9B2A-261492D845CA}C:\canopy\networkupdater\_jvm\bin\java.exe" = protocol=17 | dir=in | app=c:\canopy\networkupdater\_jvm\bin\java.exe |
"UDP Query User{BA4CEAB3-4024-489E-8670-34C10AE6B564}D:\games\garena hostbot v6.0\garenahostbot.exe" = protocol=17 | dir=in | app=d:\games\garena hostbot v6.0\garenahostbot.exe |
"UDP Query User{CF5B9006-783E-44AC-B7DC-4B508AA19CEB}C:\program files (x86)\garena plus\garenamessenger.exe" = protocol=17 | dir=in | app=c:\program files (x86)\garena plus\garenamessenger.exe |
"UDP Query User{DACB1E2A-EABB-4026-B9FF-0885D35FCE52}C:\program files (x86)\garena\garena.exe" = protocol=17 | dir=in | app=c:\program files (x86)\garena\garena.exe |
"UDP Query User{E4B020F7-B50F-4CB4-9140-23450E936F81}C:\program files (x86)\unified remote\remoteserver.exe" = protocol=17 | dir=in | app=c:\program files (x86)\unified remote\remoteserver.exe |
"UDP Query User{F34162C3-1E76-4911-A77F-5BA344FD8E38}C:\program files (x86)\internet download manager\idman.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet download manager\idman.exe |
"UDP Query User{F3ED6DED-7A3F-4177-8035-2984B799C33C}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe" = protocol=17 | dir=in | app=c:\windows\microsoft.net\framework\v2.0.50727\vbc.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2700_series" = Canon iP2700 series Printer Driver
"{13F4A7F3-EABC-4261-AF6B-1317777F0755}" = Fast Boot
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{1FC54CF7-6940-4456-BE5B-88CF8FF71A7E}" = Nitro Pro 7
"{20150000-0011-0000-1000-0000000FF1CE}" = Microsoft Professional Plus 2013
"{20150000-0015-0409-1000-0000000FF1CE}" = Microsoft Access MUI (English) 2013
"{20150000-0016-0409-1000-0000000FF1CE}" = Microsoft Excel MUI (English) 2013
"{20150000-0018-0409-1000-0000000FF1CE}" = Microsoft PowerPoint MUI (English) 2013
"{20150000-0019-0409-1000-0000000FF1CE}" = Microsoft Publisher MUI (English) 2013
"{20150000-001A-0409-1000-0000000FF1CE}" = Microsoft Outlook MUI (English) 2013
"{20150000-001B-0409-1000-0000000FF1CE}" = Microsoft Word MUI (English) 2013
"{20150000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 Preview - English
"{20150000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 Preview - French
"{20150000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 Preview - Spanish
"{20150000-002C-0409-1000-0000000FF1CE}" = Microsoft Proofing (English) 2013
"{20150000-0044-0409-1000-0000000FF1CE}" = Microsoft InfoPath MUI (English) 2013
"{20150000-0051-0000-1000-0000000FF1CE}" = Microsoft Visio Professional 2013
"{20150000-0054-0409-1000-0000000FF1CE}" = Microsoft Visio MUI (English) 2013
"{20150000-006E-0409-1000-0000000FF1CE}" = Microsoft Shared MUI (English) 2013
"{20150000-0090-0409-1000-0000000FF1CE}" = Microsoft DCF MUI (English) 2013
"{20150000-00A1-0409-1000-0000000FF1CE}" = Microsoft OneNote MUI (English) 2013
"{20150000-00BA-0409-1000-0000000FF1CE}" = Microsoft Groove MUI (English) 2013
"{20150000-00C1-0000-1000-0000000FF1CE}" = Microsoft Office 32-bit Components 2013
"{20150000-00C1-0409-1000-0000000FF1CE}" = Microsoft Shared 32-bit MUI (English) 2013
"{20150000-00E1-0409-1000-0000000FF1CE}" = Microsoft OSM MUI (English) 2013
"{20150000-00E2-0409-1000-0000000FF1CE}" = Microsoft OSM UX MUI (English) 2013
"{20150000-0115-0409-1000-0000000FF1CE}" = Microsoft Shared Setup Metadata MUI (English) 2013
"{20150000-0117-0409-1000-0000000FF1CE}" = Microsoft Access Setup Metadata MUI (English) 2013
"{20150000-012B-0409-1000-0000000FF1CE}" = Microsoft Lync MUI (English) 2013
"{21903252-3854-48D6-8F0C-F648CFA818C9}" = NI Help Assistant (64bit)
"{230D1595-57DA-4933-8C4E-375797EBB7E1}" = Atheros Bluetooth Suite (64)
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{3DD68F17-2C5D-49AC-9280-13C90FE19B71}" = NI Logos64 5.1.3
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4EBBC187-6988-4B10-A846-E1DBD2AD2B8D}" = NI Math Kernel Libraries (64-bit)
"{4EE61784-10C6-4B7C-A0B2-5BED17B05741}" = Oracle VM VirtualBox 4.1.18
"{5783F2D7-B001-0000-0102-0060B0CE6BBA}" = AutoCAD 2013 - English
"{5783F2D7-B001-0409-1102-0060B0CE6BBA}" = AutoCAD 2013 Language Pack - English
"{5783F2D7-B001-0409-2102-0060B0CE6BBA}" = AutoCAD 2013 - English
"{5783F2D7-B004-0000-0102-0060B0CE6BBA}" = AutoCAD Architecture 2013 - English
"{5783F2D7-B004-0409-1102-0060B0CE6BBA}" = AutoCAD Architecture 2013 Language Pack - English
"{5783F2D7-B004-0409-2102-0060B0CE6BBA}" = AutoCAD Architecture 2013 - English
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6199B534-A1B6-46ED-873B-97B0ECF8F81E}" = Intel® Trusted Connect Service Client
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{82C1E6E4-6718-4EFD-9DCC-E276D690EF46}" = Autodesk Inventor Fusion plug-in for AutoCAD 2013
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-0044-0409-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0054-0409-1000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2010
"{90140000-0054-0409-1000-0000000FF1CE}_Office14.VISIO_{7DC2B20B-31B9-4C7C-B8DC-8492A9A3095E}" = Microsoft Office 2010 Language Pack Service Pack 1 (SP1)
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-1000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{945CF655-4A32-4667-B085-70A9D53C5A86}" = NI VC2008MSMs x64
"{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}" = ASUS Power4Gear Hybrid
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B092C4EE-F80B-48DD-B57D-C42B66543BE0}" = NI VC2005MSMs x64
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 296.67
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 296.67
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.7.13
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.7.13
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{C342A5D7-9D75-4D37-879A-BAA68D168670}" = NI Logos64 XT Support
"{CA7DAF6F-D5F4-46FD-A824-7E0B472C3211}" = NI USI 1.7.0 64-Bit
"{CCC79B52-19CF-4A50-BE60-AEE3DE96B3EA}" = NI Web Pipeline 2.0.1 64-bit support
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D8C0E5E1-3B66-465D-8F9B-F591F5CDA726}" = NI Trace Engine (64-bit)
"{E63A64BC-6458-432B-A5FA-A61BFD34EA6E}" = NI TDMS (64-bit)
"{EE5F74BC-5CD5-4EF2-86BA-81E6CF46A18F}" = Autodesk Sync
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FE2F4875-095C-427C-9A97-4F8DE05ACF22}" = Autodesk Inventor Fusion plug-in language pack for AutoCAD 2013
"{FFF5619F-2013-0064-A85E-9994F70A9E5D}" = Autodesk Inventor Fusion 2013
"AutoCAD 2013 - English" = AutoCAD 2013 - English
"AutoCAD Architecture 2013 - English" = AutoCAD Architecture 2013 - English
"Autodesk Inventor Fusion 2013" = Autodesk Inventor Fusion 2013
"Autodesk Inventor Fusion plug-in for AutoCAD 2013" = Autodesk Inventor Fusion plug-in for AutoCAD 2013
"CCleaner" = CCleaner
"Connectify" = Connectify
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.60.1
"Elantech" = ETDWare PS/2-X64 10.5.9.0
"gogoc" = gogo6 gogoCLIENT
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"Office15.PROPLUS" = Microsoft Office Professional Plus 2013 Preview
"Office15.VISPRO" = Microsoft Visio Professional 2013 Preview
"TeraCopy_is1" = TeraCopy 2.27
"WinRAR archiver" = WinRAR 4.20 (64-bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02B6E651-686D-4BCD-8A93-C07B01761745}" = NI Logos 5.1.3
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04B34E21-5BEE-3D2B-8D3D-E3E80D253F64}" = Microsoft Visual C++ 2008 x86 ATL Runtime 9.0.30729
"{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1" = MiniTool Partition Wizard Home Edition 7.5
"{0969AF05-4FF6-4C00-9406-43599238DE0D}" = ASUS Splendid Video Enhancement Technology
"{0AAB121C-8EA7-49F5-B37C-DF117FB46771}" = NI LabVIEW Run-Time Engine 2009 SP1
"{0FCE0BA9-8AD4-4622-9ADF-EFF0355EEAE7}" = NI LabVIEW Run-Time Engine Interop 2009
"{0FD812C9-3BBE-4CC5-A43C-B7304E3EC581}" = NI Web Pipeline 2.0.1
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{117EBEEB-5DB0-43C8-9FD6-DD583DB152DD}" = Autodesk Material Library 2013
"{129024FF-A6C9-4696-91BC-570C6C05193A}" = Windchill ProductPoint Client Manager
"{14866AAD-1F23-39AC-A62B-7091ED1ADE64}" = Microsoft Visual C++ 2008 x86 CRT Runtime 9.0.30729
"{19EA33FB-B34E-40EA-8B8A-61743AEB795A}" = Wireless Console 3
"{1A014690-36EF-45FC-B97F-F8081E9706B4}" = Pointblank
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YTD Video Downloader 3.9
"{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200927E3-5E45-493A-9343-508613BC59CE}" = NI LabVIEW Web Services Runtime
"{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel® USB 3.0 eXtensible Host Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F83217005FF}" = Java 7 Update 5
"{27C6C0A2-2EC9-4FEA-BE2B-659EAAC2C68C}" = Autodesk Material Library Low Resolution Image Library 2013
"{32364CEA-7855-4A3C-B674-53D8E9B97936}" = TuneUp Utilities 2012
"{41A0986C-CED7-4C93-AFF2-DC8566253B7B}" = NI MetaSuite Installer
"{48D082B9-18F6-4426-AFAC-8B6A3E7021B1}" = Brother MFL-Pro Suite DCP-385C
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B90093A-5D9C-3956-8ABB-95848BE6EFAD}" = Microsoft Visual C++ 2008 x86 OpenMP Runtime 9.0.30729
"{4FFBBF14-D82E-483D-8C1D-FCECAABD399E}" = NI LabWindows/CVI 9.0.1 Run-Time Engine
"{5172E572-C175-4F80-A6D5-5CB45826AD61}" = SceneSwitch
"{547C9628-C490-48AB-94F4-7F2495562930}" = PDF to DWG Converter
"{57B77060-04B4-468E-89A9-F68EEE466F57}" = NI USI 1.7.0
"{58760EEC-8B6A-43F4-81AA-696E381DFADD}" = Autodesk Material Library Medium Resolution Image Library 2013
"{5C0BBD9F-2D3F-4093-AD7B-3F7377E0EDCA}" = NI LabVIEW Real-Time NBFifo
"{604D1BD4-7EE3-4704-8D53-0675FA94AE57}" = NI MDF Support
"{606E12B9-641F-4644-A22A-FF38AE980AFD}" = Autodesk Material Library Base Resolution Image Library 2013
"{62F029AB-85F2-0000-866A-9FC0DD99DDBC}" = Autodesk Content Service
"{62F029AB-85F2-0001-866A-9FC0DD99DDBC}" = Autodesk Content Service Language Pack
"{63E19B33-DD24-4EAB-9E77-6735C2171CE4}" = NI VC2005MSMs x86
"{64452561-169F-4A36-A2FF-B5E118EC65F5}" = ASUS FaceLogon
"{644DAD90-2083-4871-BD49-721BF8FAE295}" = NI LabVIEW Run-Time Engine 8.6.1
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{65246CE4-17F2-4896-8828-696086BED5F6}" = NI TDMS
"{65CB4C08-C47B-4A7E-A6A4-50C06ADA5FC6}" = Adobe AIR
"{6C520D64-E109-4A73-82A3-7808592051BC}" = NI Circuit Design Suite 11.0.1 Core
"{6DA2B636-698A-3294-BF4A-B5E11B238CDD}" = Microsoft Visual C++ 2008 x64 MFC Runtime 9.0.30729
"{6F7D11DC-DE87-45C8-A37E-A35B724FC771}" = NI Help Assistant
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{749F674B-2674-47E8-879C-5626A06B2A91}" = InstantOn for NB
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{7ACFB216-29F7-4331-A5ED-2563AEB51F21}" = NI Trace Engine
"{7BE5AA0C-E564-430F-B297-2B01121A1C5A}" = NI LabVIEW Real-Time NBFifo
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159
"{7CD0F3A4-AA2F-4F6E-84F4-BFC2905D4BA3}" = NI EULA Depot
"{7D916FA5-DAE9-4A25-B089-655C70EAF607}" = Qualcomm Atheros WiFi Driver Installation
"{84FAE06F-A199-4991-8526-AF57A2A0D779}" = NI Circuit Design Suite 11.0.1 Pro
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8CCEA24C-51AE-3B71-9092-7D0C44DDA2DF}" = Microsoft Visual C++ 2008 x64 OpenMP Runtime 9.0.30729
"{8F21291E-0444-4B1D-B9F9-4370A73E346D}" = WinFlash
"{91221AAC-F2A0-4028-8016-C7DAF63CB6CC}" = FARO LS 1.1.408.2
"{938CFBD4-0652-49E5-BB8B-153948865941}" = ASUS Virtual Touch
"{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}" = FARO LS 1.1.406.58
"{965D4A7F-25FE-4D0E-8729-43C6236FB03C}" = Unified Remote
"{9866E5F0-121F-E018-E2D1-2E1770847ABF}" = Adobe Download Assistant
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A6C48A9F-694A-4234-B3AA-62590B668927}" = Intel® Manageability Engine Firmware Recovery Agent
"{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}" = ASUS USB Charger Plus
"{A95A76C9-6F65-477E-83A0-9F884B6DC21B}" = TuneUp Utilities Language Pack (en-US)
"{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}" = ATK Package
"{ABD79E99-F9E3-413B-8D18-11070754355F}" = NI Math Kernel Libraries
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
"{AC76D478-1033-0000-3478-000000000004}" = Mathcad PDSi viewable support
"{B226F936-42E3-402E-8CF8-C1D92F255A17}" = NI Uninstaller
"{B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}" = Microsoft Visual C++ 2008 x86 MFC Runtime 9.0.30729
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BE95841B-D741-4B72-B79B-1EC61240F10E}" = NI Service Locator
"{C0FF3C38-FC96-4575-8A7B-89DDA3F9C79D}" = NI Update Service
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C3A57BB3-9AA6-3F6F-9395-6C062BDD5FC4}" = Microsoft Visual C++ 2008 x64 ATL Runtime 9.0.30729
"{C547F361-5750-4CD1-9FB6-BC93827CB6C1}" = RegCure Pro
"{C65ABF2A-1B82-4F34-8C74-E4FE373F3BE4}" = 'PTC Places' Namespace Shell Extension
"{CCF298AF-9CE1-4B26-B251-486E98A34789}" = Windows 7 USB/DVD Download Tool
"{CFF55EAB-5A2F-4A95-99D4-EF3E585F03FD}" = NI Logos XT Support
"{D265C4DB-8F68-4264-BA9C-BCEFF134A8B8}" = NI Circuit Design Suite 11.0.1 Pro Licenses
"{D361B9E5-E918-48CB-BEC3-8E44A5F6E624}" = NI LabVIEW 2009 SP1 Run-Time Engine Web Services
"{D39F0676-163E-4595-A917-E28F99BBD4D2}" = ASUS AI Recovery
"{D581FB60-4827-4AB0-9BF0-A1159C1D0579}" = NI License Manager
"{DB2C5648-700D-4AEF-83E1-70C72F0C34FA}" = NI Math Kernel Libraries
"{DC8F6C78-7231-44A2-B66E-6C4FCB3A3364}" = Mathcad 15 F000
"{E37CCD6C-56C1-43C7-B2FA-24A32B6B09F7}" = NI Example Finder 9.0
"{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera
"{EC8BF669-EFEA-40D9-8894-9074E407FC07}" = NI VC2008MSMs x86
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F11F2CA2-F45F-4CC2-8962-28A0F5DC625A}" = NI Update Service Full
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6F09DD8-F39B-3A16-ADB9-C9E6B56903F9}" = Microsoft Visual C++ 2008 x64 CRT Runtime 9.0.30729
"{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}" = ASUS Live Update
"{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel® OpenCL CPU Runtime
"{FE24BCDF-9231-450D-AA08-D3550B81EE41}" = NI LabVIEW Web Server for Run-Time Engine
"{FEFA778A-05D2-4D0F-80A3-7AE24B8161C0}" = NI LabVIEW Web Server for Run-Time Engine
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AnyToISO_is1" = AnyToISO
"ASUS K5 Series ScreenSaver" = ASUS K5 Series ScreenSaver
"Autodesk Content Service" = Autodesk Content Service
"avast" = avast! Free Antivirus
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"FARO LS_is1" = FARO LS 4.8.2.25521
"Garena" = Garena 2010
"HC51 9.60PL0" = HI-TECH C51-lite V9.60PL0
"HoN" = Garena - Heroes of Newerth
"im" = Garena Plus
"ImgBurn" = ImgBurn
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"Internet Download Manager" = Internet Download Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300
"Mathcad PDSi viewable support" = Mathcad PDSi viewable support
"Mobile Partner" = Mobile Partner
"Mozilla Firefox 13.0.1 (x86 en-US)" = Mozilla Firefox 13.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NetCut_is1" = NetCut 2.1.4
"Network Updater" = Network Updater
"NI Uninstaller" = National Instruments Software
"Notepad++" = Notepad++
"Novarm DipTrace" = Novarm DipTrace
"PICC 9.60PL0" = HI-TECH PICC lite V9.60PL0
"Pointblank" = Pointblank
"Steam App 570" = Dota 2
"TuneUp Utilities 2012" = TuneUp Utilities 2012
"UltimateDefrag" = UltimateDefrag
"USB Disk Security_is1" = USB Disk Security
"uTorrent" = µTorrent
"VLC media player" = VLC media player 2.0.2
"WinPcapInst" = WinPcap 4.1.2
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"BB108A893815B64BF41C4574C3324FB7371AA244" = Atheros Outlook Addin 2010
"Google Chrome" = Google Chrome
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 8/4/2012 12:06:08 AM | Computer Name = Rhomel-PC | Source = Application Error | ID = 1000
Description = Faulting application name: DllHost.exe, version: 6.1.7600.16385, time
stamp: 0x4a5bca54 Faulting module name: igdumd64.dll, version: 8.15.10.2653, time
stamp: 0x4f3aac44 Exception code: 0xc000041d Fault offset: 0x000000000030eb06 Faulting
process id: 0x1750 Faulting application start time: 0x01cd71e13ff646ee Faulting application
path: C:\Windows\system32\DllHost.exe Faulting module path: C:\Windows\system32\igdumd64.dll
Report
Id: b7bfbbb2-dde9-11e1-8a96-94dbc9ab461d
Error - 8/7/2012 1:36:52 PM | Computer Name = Rhomel-PC | Source = Windows Search Service | ID = 9002
Description =
Error - 8/7/2012 1:36:52 PM | Computer Name = Rhomel-PC | Source = Windows Search Service | ID = 3029
Description =
Error - 8/7/2012 1:36:53 PM | Computer Name = Rhomel-PC | Source = Windows Search Service | ID = 3029
Description =
Error - 8/7/2012 1:36:53 PM | Computer Name = Rhomel-PC | Source = Windows Search Service | ID = 3028
Description =
Error - 8/7/2012 1:36:53 PM | Computer Name = Rhomel-PC | Source = Windows Search Service | ID = 3058
Description =
Error - 8/7/2012 1:36:53 PM | Computer Name = Rhomel-PC | Source = Windows Search Service | ID = 7010
Description =
Error - 8/7/2012 1:36:53 PM | Computer Name = Rhomel-PC | Source = Windows Search Service | ID = 7040
Description =
Error - 8/7/2012 1:36:53 PM | Computer Name = Rhomel-PC | Source = Windows Search Service | ID = 7042
Description =
Error - 8/7/2012 9:55:17 PM | Computer Name = Rhomel-PC | Source = Application Hang | ID = 1002
Description = The program OTL.exe version 3.2.56.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 12d0 Start Time:
01cd7508a37e8b3d Termination Time: 3 Application Path: C:\Users\Rhomel\Desktop\OTL.exe
Report
Id:
[ System Events ]
Error - 8/6/2012 2:13:50 PM | Computer Name = Rhomel-PC | Source = Service Control Manager | ID = 7022
Description = The Autodesk Content Service service hung on starting.
Error - 8/6/2012 6:21:37 PM | Computer Name = Rhomel-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Autodesk
Content Service service to connect.
Error - 8/6/2012 6:21:37 PM | Computer Name = Rhomel-PC | Source = Service Control Manager | ID = 7000
Description = The Autodesk Content Service service failed to start due to the following
error: %%1053
Error - 8/6/2012 9:26:28 PM | Computer Name = Rhomel-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Autodesk
Content Service service to connect.
Error - 8/6/2012 9:26:28 PM | Computer Name = Rhomel-PC | Source = Service Control Manager | ID = 7000
Description = The Autodesk Content Service service failed to start due to the following
error: %%1053
Error - 8/6/2012 10:59:51 PM | Computer Name = Rhomel-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the lmhosts service.
Error - 8/7/2012 12:57:21 AM | Computer Name = Rhomel-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Autodesk
Content Service service to connect.
Error - 8/7/2012 12:57:21 AM | Computer Name = Rhomel-PC | Source = Service Control Manager | ID = 7000
Description = The Autodesk Content Service service failed to start due to the following
error: %%1053
Error - 8/7/2012 1:36:53 PM | Computer Name = Rhomel-PC | Source = Service Control Manager | ID = 7024
Description = The Windows Search service terminated with service-specific error
%%-1073473535.
Error - 8/7/2012 1:36:53 PM | Computer Name = Rhomel-PC | Source = Service Control Manager | ID = 7031
Description = The Windows Search service terminated unexpectedly. It has done this
1 time(s). The following corrective action will be taken in 30000 milliseconds:
Restart the service.
< End of report >
Edited by rhomel, 07 August 2012 - 05:14 AM.