Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:51:37 AM, on 8/2/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18928)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\D-Link\RangeBooster G WUA-2340\AirPlusCFG.exe
C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\MediaMonkey2\MediaMonkey.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.ez-tracks.com/?fromOMB=1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.ez-tracks.com/?fromOMB=1
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - {da30eff8-ccc6-4162-a20d-67402a26a215} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: wit for ie - {75ED56AF-4DC9-4243-A30C-4EF4DD0CA28F} - C:\Program Files (x86)\ChameleonTom\wit4ie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: (no name) - {da30eff8-ccc6-4162-a20d-67402a26a215} - (no file)
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll
O3 - Toolbar: (no name) - {da30eff8-ccc6-4162-a20d-67402a26a215} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [D-Link RangeBooster G WUA-2340] "C:\Program Files (x86)\D-Link\RangeBooster G WUA-2340\AirPlusCFG.exe"
O4 - HKLM\..\Run: [ANIWZCS2Service] "C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [FileHippo.com] "C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files (x86)\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Mojicon Dispenser - {3B3628FF-E084-47ef-8797-FA36FC2571EA} - C:\Program Files (x86)\Mojicon\Mojicon\mojiwin.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O16 - DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88} (WNICheck2 Class) - http://www.convergysworkathome.com/AppHardT.CAB
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} (PCMaticVer Class) - http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\avgfws9.exe
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files (x86)\D-Link\RangeBooster G WUA-2340\JSWUtilVst\jswpsapi.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: lxdcCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\x64\3\\lxdcserv.exe
O23 - Service: lxdc_device - - C:\Windows\system32\lxdccoms.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Stardock WindowBlinds (WindowBlinds) - Stardock Corporation - C:\Program Files (x86)\Stardock\MyColors\VistaSrv.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11567 bytes
Sorry, I saw it slipping a few pages behind and thought I needed to bring attention to it but I will not bump it again though I noticed all the missing files and looked it up and someone online said to run ots for 64 bit:
Current Boot Mode: Normal
Scan Mode: All users
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
[Processes - All]
ots.exe -> C:\Users\The Snappy Sneezer\Downloads\OTS.exe -> [2010/08/03 10:00:12 | 000,641,536 | ---- | M] (OldTimer Tools)
realsched.exe -> C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe -> [2010/08/01 20:05:20 | 000,202,256 | ---- | M] (RealNetworks, Inc.)
plugin-container.exe -> C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe -> [2010/07/23 10:19:16 | 000,014,808 | ---- | M] (Mozilla Corporation)
firefox.exe -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe -> [2010/07/23 10:19:15 | 000,910,296 | ---- | M] (Mozilla Corporation)
avgwdsvc.exe -> C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe -> [2010/07/15 10:52:52 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgfws9.exe -> C:\Program Files (x86)\AVG\AVG9\avgfws9.exe -> [2010/07/15 10:51:39 | 002,331,032 | ---- | M] (AVG Technologies CZ, s.r.o.)
mediamonkey.exe -> C:\Program Files (x86)\MediaMonkey2\MediaMonkey.exe -> [2010/06/25 00:38:54 | 008,112,272 | ---- | M] (Ventis Media Inc.)
mdnsresponder.exe -> C:\Program Files (x86)\Bonjour\mDNSResponder.exe -> [2010/05/18 16:35:14 | 000,345,376 | ---- | M] (Apple Inc.)
jusched.exe -> C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe -> [2010/02/18 11:43:18 | 000,248,040 | ---- | M] (Sun Microsystems, Inc.)
teatimer.exe -> C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe -> [2009/03/05 16:07:20 | 002,260,480 | ---- | M] (Safer-Networking Ltd.)
sdwinsec.exe -> C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe -> [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.)
seaport.exe -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -> [2009/01/14 17:53:02 | 000,226,656 | ---- | M] (Microsoft Corp.)
applemobiledeviceservice.exe -> C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/11/07 15:28:16 | 000,132,424 | ---- | M] (Apple Inc.)
airpluscfg.exe -> C:\Program Files (x86)\D-Link\RangeBooster G WUA-2340\AirPlusCFG.exe -> [2007/11/12 09:49:42 | 001,662,976 | ---- | M] (D-Link)
[Modules - Safe List]
ots.exe -> C:\Users\The Snappy Sneezer\Downloads\OTS.exe -> [2010/08/03 10:00:12 | 000,641,536 | ---- | M] (OldTimer Tools)
rpchromebrowserrecordhelper.dll -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll -> [2010/08/01 20:06:28 | 000,040,960 | ---- | M] ()
mmhelper.dll -> C:\Program Files (x86)\MediaMonkey2\MMHelper.dll -> [2010/06/25 00:39:46 | 000,053,904 | ---- | M] ()
wblind.dll -> C:\Program Files (x86)\Stardock\MyColors\wblind.dll -> [2009/10/20 16:36:40 | 000,633,192 | ---- | M] (Stardock Corporation)
wbhelp.dll -> C:\Program Files (x86)\Stardock\MyColors\wbhelp.dll -> [2009/06/09 10:56:14 | 000,034,168 | ---- | M] (Stardock.Net, Inc)
wbload.dll -> C:\Windows\SysWOW64\wbload.dll -> [2009/06/09 10:55:58 | 000,057,904 | ---- | M] ()
msscript.ocx -> C:\Windows\SysWOW64\msscript.ocx -> [2008/01/19 02:33:00 | 000,110,592 | ---- | M] (Microsoft Corporation)
msvcp71.dll -> C:\Windows\SysWOW64\msvcp71.dll -> [2003/04/06 15:41:32 | 000,499,712 | ---- | M] (Microsoft Corporation)
msvcr71.dll -> C:\Windows\SysWOW64\msvcr71.dll -> [2003/04/06 15:41:32 | 000,348,160 | ---- | M] (Microsoft Corporation)
[Win32 Services - Safe List]
64bit-(wlidsvc) [Auto | Running] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -> [2009/08/18 12:48:02 | 002,291,568 | ---- | M] (Microsoft Corporation)
64bit-(UmRdpService) [On_Demand | Stopped] -> C:\Windows\SysNative\umrdp.dll -> [2009/04/11 02:11:27 | 000,252,928 | ---- | M] (Microsoft Corporation)
64bit-(CscService) [Auto | Running] -> C:\Windows\SysNative\cscsvc.dll -> [2009/04/11 02:11:14 | 000,604,672 | ---- | M] (Microsoft Corporation)
64bit-(WinDefend) [Auto | Stopped] -> C:\Program Files\Windows Defender\MpSvc.dll -> [2008/01/19 03:06:50 | 000,383,544 | ---- | M] (Microsoft Corporation)
64bit-(AppMgmt) [On_Demand | Stopped] -> C:\Windows\SysNative\appmgmts.dll -> [2008/01/19 03:00:52 | 000,195,584 | ---- | M] (Microsoft Corporation)
64bit-(lxdcCATSCustConnectService) [Auto | Stopped] -> C:\Windows\SysNative\spool\DRIVERS\x64\3\\lxdcserv.exe -> [2007/05/25 09:39:04 | 000,034,224 | ---- | M] ()
64bit-(lxdc_device) [Auto | Running] -> C:\Windows\SysNative\lxdccoms.exe -> [2007/05/25 09:38:54 | 000,567,216 | ---- | M] ( )
(avg9wd) AVG WatchDog [Auto | Running] -> C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe -> [2010/07/15 10:52:52 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.)
(AVGIDSAgent) AVG9IDSAgent [Auto | Stopped] -> C:\Program Files (x86)\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe -> [2010/07/15 10:52:37 | 005,897,808 | ---- | M] (AVG Technologies CZ, s.r.o.)
(avgfws9) AVG Firewall [Auto | Running] -> C:\Program Files (x86)\AVG\AVG9\avgfws9.exe -> [2010/07/15 10:51:39 | 002,331,032 | ---- | M] (AVG Technologies CZ, s.r.o.)
(WindowBlinds) Stardock WindowBlinds [Auto | Running] -> C:\Program Files (x86)\Stardock\MyColors\VistaSrv.exe -> [2009/06/09 10:56:16 | 000,337,200 | ---- | M] (Stardock Corporation)
(SBSDWSCService) SBSD Security Center Service [Auto | Running] -> C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe -> [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.)
(SeaPort) SeaPort [Auto | Running] -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -> [2009/01/14 17:53:02 | 000,226,656 | ---- | M] (Microsoft Corp.)
(Microsoft Office Groove Audit Service) Microsoft Office Groove Audit Service [On_Demand | Stopped] -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe -> [2008/10/25 12:44:08 | 000,065,888 | ---- | M] (Microsoft Corporation)
(jswpsapi) Jumpstart Wifi Protected Setup [On_Demand | Stopped] -> C:\Program Files (x86)\D-Link\RangeBooster G WUA-2340\JSWUtilVst\jswpsapi.exe -> [2007/09/21 00:24:52 | 000,942,080 | ---- | M] (Atheros Communications, Inc.)
(lxdc_device) lxdc_device [Auto | Running] -> C:\Windows\SysWow64\lxdccoms.exe -> [2007/05/25 09:38:20 | 000,537,520 | ---- | M] ( )
[Driver Services - Safe List]
64bit-(NwlnkFwd) IPX Traffic Forwarder Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys -> File not found
64bit-(NwlnkFlt) IPX Traffic Filter Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\DRIVERS\nwlnkflt.sys -> File not found
64bit-(IpInIp) IP in IP Tunnel Driver [Kernel | On_Demand | Stopped] -> C:\Windows\SysNative\DRIVERS\ipinip.sys -> File not found
64bit-(AvgTdiA) AVG Network Redirector x64 [Kernel | System | Running] -> C:\Windows\SysNative\Drivers\avgtdia.sys -> [2010/07/15 10:53:08 | 000,317,520 | ---- | M] (AVG Technologies CZ, s.r.o.)
64bit-(AVGIDSErHrvta) AVG9IDSErHr [Kernel | Boot | Running] -> C:\Windows\SysNative\Drivers\AVGIDSva.sys -> [2010/07/15 10:52:42 | 000,027,216 | ---- | M] (AVG Technologies CZ, s.r.o. )
64bit-(AvgLdx64) AVG AVI Loader Driver x64 [Kernel | System | Running] -> C:\Windows\SysNative\Drivers\avgldx64.sys -> [2010/07/15 10:51:36 | 000,269,904 | ---- | M] (AVG Technologies CZ, s.r.o.)
64bit-(AvgMfx64) AVG On-access Scanner Minifilter Driver x64 [File_System | System | Running] -> C:\Windows\SysNative\Drivers\avgmfx64.sys -> [2010/06/02 08:01:46 | 000,035,536 | ---- | M] (AVG Technologies CZ, s.r.o.)
64bit-(AvgRkx64) avgrkx64.sys [File_System | Boot | Running] -> C:\Windows\SysNative\Drivers\avgrkx64.sys -> [2010/03/12 10:23:57 | 000,056,008 | ---- | M] (AVG Technologies CZ, s.r.o.)
64bit-(Avgfwfd) AVG network filter service [Kernel | System | Stopped] -> C:\Windows\SysNative\DRIVERS\avgfwd6a.sys -> [2010/01/05 11:59:02 | 000,029,976 | ---- | M] (AVG Technologies CZ, s.r.o.)
64bit-(CSC) Offline Files Driver [Kernel | System | Running] -> C:\Windows\SysNative\drivers\csc.sys -> [2009/04/10 23:56:24 | 000,460,800 | ---- | M] (Microsoft Corporation)
64bit-(Amusbprt) USB HID-compliant Mouse Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\Amusbx64.sys -> [2008/02/13 08:20:16 | 000,017,920 | ---- | M] (A4Tech Co.,Ltd.)
64bit-(Amfilter) Compatible Mouse Filter Driver [Kernel | System | Running] -> C:\Windows\SysNative\DRIVERS\Amfltx64.sys -> [2007/10/15 03:37:22 | 000,012,288 | ---- | M] ((Standard mouse types))
64bit-(A5AGU) D-Link Wireless LAN 802.11 USB device driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\DRIVERS\AGUx64.sys -> [2007/10/08 17:54:56 | 001,063,936 | ---- | M] (D-Link Corporation)
64bit-(JSWPSLWF) JumpStart Wireless Filter Driver [Kernel | System | Running] -> C:\Windows\SysNative\DRIVERS\jswpslwfx.sys -> [2007/08/31 17:43:38 | 000,026,624 | ---- | M] (Atheros Communications, Inc.)
64bit-(UsbFltr) WayTech USB Filter Driver [Kernel | On_Demand | Running] -> C:\Windows\SysNative\Drivers\UsbFltr.sys -> [2007/04/09 11:09:46 | 000,012,288 | ---- | M] (Waytech Development, Inc.)
64bit-(Ntfs) Ntfs [File_System | On_Demand | Running] -> C:\Windows\SysNative\Wbem\ntfs.mof -> [2006/09/18 16:36:24 | 000,000,308 | ---- | M] ()
(AVGIDSDrivervta) AVG9IDSDriver [Kernel | On_Demand | Running] -> C:\Program Files (x86)\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista64\AVGIDSDriver.sys -> [2010/07/15 10:52:41 | 000,132,688 | ---- | M] (AVG Technologies CZ, s.r.o. )
(AVGIDSFiltervta) AVG9IDSFilter [Kernel | On_Demand | Running] -> C:\Program Files (x86)\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista64\AVGIDSFilter.sys -> [2010/07/15 10:52:41 | 000,035,920 | ---- | M] (AVG Technologies CZ, s.r.o. )
[Registry - Safe List]
< 64bit-Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://home.ez-tracks.com/?fromOMB=1 ->
HKEY_LOCAL_MACHINE\: URLSearchHooks\\"{da30eff8-ccc6-4162-a20d-67402a26a215}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> ->
HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> ->
HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\] > -> ->
HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\: Main\\"Start Page" -> http://home.ez-tracks.com/?fromOMB=1 ->
HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\: Main\\"StartPageCache" -> 1 ->
HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\: URLSearchHooks\\"{A3BC75A2-1F87-4686-AA43-5347D756017C}" [HKLM] -> C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll [AVG Security Toolbar BHO] -> [2010/04/19 10:25:32 | 002,117,704 | ---- | M] ()
HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\: URLSearchHooks\\"{da30eff8-ccc6-4162-a20d-67402a26a215}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\: "ProxyEnable" -> 0 ->
HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\: "ProxyOverride" -> *.local ->
< FireFox Settings [Prefs.js] > -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\FireFox\Profiles\h61s3vof.default\prefs.js ->
browser.search.defaultenginename -> "Search" ->
browser.search.defaultthis.engineName -> "Playdom Customized Web Search" ->
browser.search.defaulturl -> "http://search.conduit.com/ResultsExt.aspx?ctid=CT2464976&SearchSource=3&q={searchTerms}" ->
browser.search.selectedEngine -> "Google" ->
browser.search.useDBForOrder -> true ->
browser.startup.homepage -> "http://home.ez-tracks.com/?fromOMB=1" ->
extensions.enabledItems -> {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.1 ->
extensions.enabledItems -> {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10 ->
extensions.enabledItems -> smarterwiki@wikiatic.com:4.1.5 ->
extensions.enabledItems -> {35106bca-6c78-48c7-ac28-56df30b51d2a}:1.3.8 ->
extensions.enabledItems -> personas@christopher.beard:1.5.3 ->
extensions.enabledItems -> {53A03D43-5363-4669-8190-99061B2DEBA5}:1.3.7 ->
extensions.enabledItems -> {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.9.23 ->
extensions.enabledItems -> moveplayer@movenetworks.com:7 ->
extensions.enabledItems -> {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20 ->
extensions.enabledItems -> {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.5 ->
extensions.enabledItems -> {12bc3590-67a6-11de-8a39-0800200c9a66}:3.6 ->
extensions.enabledItems -> info@djzig.com:1.1.7 ->
extensions.enabledItems -> {586bd060-22d6-11de-8c30-0800200c9a66}:3.6.3 ->
< FireFox Settings [User.js] > -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\FireFox\Profiles\h61s3vof.default\user.js ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions -> ->
HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71} -> C:\Program Files (x86)\AVG\AVG9\Firefox [C:\PROGRAM FILES (X86)\AVG\AVG9\FIREFOX] -> [2010/07/20 20:06:46 | 000,000,000 | ---D | M]
HKLM\software\mozilla\Firefox\Extensions\\avg@igeared -> C:\Program Files (x86)\AVG\AVG9\Toolbar\Firefox\avg@igeared [C:\PROGRAM FILES (X86)\AVG\AVG9\TOOLBAR\FIREFOX\AVG@IGEARED] -> [2010/01/09 21:16:18 | 000,000,000 | ---D | M]
HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758} -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT] -> [2010/08/01 20:06:28 | 000,000,000 | ---D | M]
HKLM\software\mozilla\Flock 2.5.6\extensions -> ->
HKLM\software\mozilla\Flock 2.5.6\extensions\\Components -> C:\Program Files (x86)\Flock\components [C:\PROGRAM FILES (X86)\FLOCK\COMPONENTS] -> [2010/08/01 20:06:21 | 000,000,000 | ---D | M]
HKLM\software\mozilla\Flock 2.5.6\extensions\\Plugins -> C:\Program Files (x86)\Flock\plugins [C:\PROGRAM FILES (X86)\FLOCK\PLUGINS] -> [2010/08/01 20:06:51 | 000,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.6.7\extensions -> ->
HKLM\software\mozilla\Mozilla Firefox 3.6.7\extensions\\Components -> C:\Program Files (x86)\Mozilla Firefox\components [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\COMPONENTS] -> [2010/08/01 20:06:21 | 000,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.6.7\extensions\\Plugins -> C:\Program Files (x86)\Mozilla Firefox\plugins [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\PLUGINS] -> [2010/08/01 20:06:51 | 000,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 4.0b2\extensions -> ->
HKLM\software\mozilla\Mozilla Firefox 4.0b2\extensions\\Components -> C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 2\components [C:\PROGRAM FILES (X86)\MOZILLA FIREFOX 4.0 BETA 2\COMPONENTS] -> [2010/08/01 20:06:21 | 000,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 4.0b2\extensions\\Plugins -> C:\PROGRAM FILES (X86)\MOZILLA FIREFOX 4.0 BETA 2\PLUGINS ->
HKLM\software\mozilla\Mozilla Thunderbird 3.1.1\extensions -> ->
HKLM\software\mozilla\Mozilla Thunderbird 3.1.1\extensions\\Components -> C:\Program Files (x86)\Mozilla Thunderbird\components [C:\PROGRAM FILES (X86)\MOZILLA THUNDERBIRD\COMPONENTS] -> [2010/08/01 20:06:21 | 000,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Thunderbird 3.1.1\extensions\\Plugins -> C:\PROGRAM FILES (X86)\MOZILLA THUNDERBIRD\PLUGINS ->
< FireFox Extensions [User Folders] > ->
-> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Extensions -> [2010/07/23 10:21:43 | 000,000,000 | ---D | M]
No name found -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} -> [2010/07/23 10:21:43 | 000,000,000 | ---D | M]
No name found -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Extensions\{a463f10c-3994-11da-9945-000d60ca027b} -> [2010/04/16 21:34:16 | 000,000,000 | ---D | M]
-> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions -> [2010/08/02 13:50:40 | 000,000,000 | ---D | M]
Eclipse -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66} -> [2010/01/10 14:14:16 | 000,000,000 | ---D | M]
Microsoft .NET Framework Assistant -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} -> [2010/04/27 20:10:13 | 000,000,000 | ---D | M]
Linkification -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a} -> [2010/02/26 10:17:30 | 000,000,000 | ---D | M]
FoxyTunes -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374} -> [2082/09/15 20:58:59 | 000,000,000 | ---D | M]
ScrapBook -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5} -> [2002/12/31 23:50:12 | 000,000,000 | ---D | M]
Revelation -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{586bd060-22d6-11de-8c30-0800200c9a66} -> [2010/02/26 10:17:16 | 000,000,000 | ---D | M]
PitchDark -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{c1dffba0-628e-11d9-9669-0800200c9a66} -> [2010/01/10 13:38:08 | 000,000,000 | ---D | M]
Adblock Plus -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} -> [2010/08/01 13:13:04 | 000,000,000 | ---D | M]
DownThemAll! -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8} -> [2010/05/29 13:33:03 | 000,000,000 | ---D | M]
No name found -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360} -> [2010/05/31 17:28:25 | 000,000,000 | ---D | M]
-> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\info@djzig.com -> [2010/06/14 11:40:00 | 000,000,000 | ---D | M]
-> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\personas@christopher.beard -> [2010/04/13 16:59:08 | 000,000,000 | ---D | M]
-> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\redshift_V2@shift-themes.com -> [2010/01/10 14:10:50 | 000,000,000 | ---D | M]
-> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\smarterwiki@wikiatic.com -> [2010/06/14 11:39:54 | 000,000,000 | ---D | M]
No name found -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}\chrome\mac\browser\extensions -> [2010/01/10 14:14:21 | 000,000,000 | ---D | M]
No name found -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}\chrome\mac\mozapps\extensions -> [2010/01/10 14:14:21 | 000,000,000 | ---D | M]
No name found -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}\chrome\win\browser\extensions -> [2010/01/10 14:14:21 | 000,000,000 | ---D | M]
No name found -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{12bc3590-67a6-11de-8a39-0800200c9a66}\chrome\win\mozapps\extensions -> [2010/01/10 14:14:21 | 000,000,000 | ---D | M]
No name found -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{586bd060-22d6-11de-8c30-0800200c9a66}\chrome\mac\browser\extensions -> [2010/02/26 10:17:16 | 000,000,000 | ---D | M]
No name found -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{586bd060-22d6-11de-8c30-0800200c9a66}\chrome\mac\mozapps\extensions -> [2010/02/26 10:17:16 | 000,000,000 | ---D | M]
No name found -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{586bd060-22d6-11de-8c30-0800200c9a66}\chrome\win\browser\extensions -> [2010/02/26 10:17:16 | 000,000,000 | ---D | M]
No name found -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{586bd060-22d6-11de-8c30-0800200c9a66}\chrome\win\mozapps\extensions -> [2010/02/26 10:17:16 | 000,000,000 | ---D | M]
No name found -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{c1dffba0-628e-11d9-9669-0800200c9a66}\browser\extensions -> [2010/01/10 13:38:07 | 000,000,000 | ---D | M]
No name found -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{c1dffba0-628e-11d9-9669-0800200c9a66}\browser\extensions\FacebookToolbar -> [2010/01/10 13:38:07 | 000,000,000 | ---D | M]
No name found -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{c1dffba0-628e-11d9-9669-0800200c9a66}\browser\extensions\GoogleToolbar -> [2010/01/10 13:38:07 | 000,000,000 | ---D | M]
No name found -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{c1dffba0-628e-11d9-9669-0800200c9a66}\browser\extensions\inspector -> [2010/01/10 13:38:07 | 000,000,000 | ---D | M]
No name found -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{c1dffba0-628e-11d9-9669-0800200c9a66}\browser\extensions\KwiClick -> [2010/01/10 13:38:07 | 000,000,000 | ---D | M]
No name found -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{c1dffba0-628e-11d9-9669-0800200c9a66}\browser\extensions\LiveHTTP -> [2010/01/10 13:38:07 | 000,000,000 | ---D | M]
No name found -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{c1dffba0-628e-11d9-9669-0800200c9a66}\browser\extensions\ReminderFox -> [2010/01/10 13:38:07 | 000,000,000 | ---D | M]
No name found -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{c1dffba0-628e-11d9-9669-0800200c9a66}\browser\extensions\UpdateNotifier -> [2010/01/10 13:38:08 | 000,000,000 | ---D | M]
No name found -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\extensions\{c1dffba0-628e-11d9-9669-0800200c9a66}\mozapps\extensions -> [2010/01/10 13:38:08 | 000,000,000 | ---D | M]
< FireFox SearchPlugins [User Folders] > ->
ask.xml -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\searchplugins\ask.xml -> [2010/04/13 17:01:19 | 000,002,273 | ---- | M] ()
bing.xml -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\searchplugins\bing.xml -> [2010/04/13 17:01:19 | 000,001,028 | ---- | M] ()
conduit.xml -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\searchplugins\conduit.xml -> [2010/06/08 11:30:50 | 000,000,917 | ---- | M] ()
imdb.xml -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\searchplugins\imdb.xml -> [2010/01/10 14:02:06 | 000,002,841 | ---- | M] ()
Search.xml -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\searchplugins\Search.xml -> [2010/01/29 07:38:22 | 000,005,389 | ---- | M] ()
youtube.xml -> C:\Users\The Snappy Sneezer\AppData\Roaming\Mozilla\Firefox\Profiles\h61s3vof.default\searchplugins\youtube.xml -> [2010/01/13 00:34:44 | 000,004,153 | ---- | M] ()
< FireFox Extensions [Program Folders] > ->
-> C:\Program Files (x86)\Mozilla Firefox\extensions -> [2010/08/02 13:50:40 | 000,000,000 | ---D | M]
Java Console -> C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} -> [2010/05/23 09:30:33 | 000,000,000 | ---D | M]
< HOSTS File > ([2010/08/01 20:23:40 | 000,416,180 | R--- | M] - 14411 lines) -> C:\Windows\SysNative\Drivers\etc\hosts ->
First 25 entries...
Reset Hosts
127.0.0.1 localhost
::1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.100888290cs.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.10sek.com
127.0.0.1 10sek.com
127.0.0.1 www.123topsearch.com
127.0.0.1 123topsearch.com
127.0.0.1 www.132.com
127.0.0.1 132.com
127.0.0.1 www.136136.net
127.0.0.1 136136.net
< 64bit-BHO's [HKEY_LOCAL_MACHINE] > -> 64bit-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> C:\Program Files (x86)\AVG\AVG9\avgssiea.dll [AVG Safe Search] -> [2010/07/20 20:04:27 | 002,326,368 | ---- | M] (AVG Technologies CZ, s.r.o.)
{9030D464-4C02-4ABF-8ECC-5164760863C6} [HKLM] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [Windows Live ID Sign-in Helper] -> [2009/08/18 12:50:40 | 000,532,336 | ---- | M] (Microsoft Corporation)
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{02478D38-C3F9-4efb-9B51-7695ECA05670} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{3049C3E9-B461-4BC5-8870-4C09146192CA} [HKLM] -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [RealPlayer Download and Record Plugin for Internet Explorer] -> [2010/08/01 20:06:28 | 000,341,600 | ---- | M] (RealPlayer)
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> C:\Program Files (x86)\AVG\AVG9\avgssie.dll [AVG Safe Search] -> [2010/07/20 20:04:27 | 001,619,296 | ---- | M] (AVG Technologies CZ, s.r.o.)
{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll [Spybot-S&D IE Protection] -> [2009/01/26 15:31:02 | 001,879,896 | ---- | M] (Safer Networking Limited)
{6EBF7485-159F-4bff-A14F-B9E3AAC4465B} [HKLM] -> C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll [Search Helper] -> [2009/01/14 17:49:24 | 000,092,504 | ---- | M] (Microsoft Corp.)
{72853161-30C5-4D22-B7F9-0BBC1D38A37E} [HKLM] -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [Groove GFS Browser Helper] -> [2009/02/12 16:19:32 | 002,217,848 | ---- | M] (Microsoft Corporation)
{75ED56AF-4DC9-4243-A30C-4EF4DD0CA28F} [HKLM] -> C:\Program Files (x86)\ChameleonTom\wit4ie.dll [WitBHO Class] -> [2009/06/12 05:21:38 | 000,215,552 | ---- | M] (ChameleonTom)
{A3BC75A2-1F87-4686-AA43-5347D756017C} [HKLM] -> C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll [AVG Security Toolbar BHO] -> [2010/04/19 10:25:32 | 002,117,704 | ---- | M] ()
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{da30eff8-ccc6-4162-a20d-67402a26a215} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}" [HKLM] -> C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll [AVG Security Toolbar] -> [2010/04/19 10:25:32 | 002,117,704 | ---- | M] ()
"{da30eff8-ccc6-4162-a20d-67402a26a215}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\] > -> HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\Software\Microsoft\Internet Explorer\Toolbar\ ->
WebBrowser\\"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}" [HKLM] -> C:\Program Files (x86)\AVG\AVG9\Toolbar\IEToolbar.dll [AVG Security Toolbar] -> [2010/04/19 10:25:32 | 002,117,704 | ---- | M] ()
WebBrowser\\"{DA30EFF8-CCC6-4162-A20D-67402A26A215}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< 64bit-Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"Windows Defender" -> C:\Program Files\Windows Defender\MSASCui.exe [%ProgramFiles%\Windows Defender\MSASCui.exe -hide] -> [2008/01/19 03:07:02 | 001,584,184 | ---- | M] (Microsoft Corporation)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"ANIWZCS2Service" -> C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe ["C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe"] -> [2007/01/19 11:49:04 | 000,049,152 | ---- | M] (Wireless Service)
"D-Link RangeBooster G WUA-2340" -> C:\Program Files (x86)\D-Link\RangeBooster G WUA-2340\AirPlusCFG.exe ["C:\Program Files (x86)\D-Link\RangeBooster G WUA-2340\AirPlusCFG.exe"] -> [2007/11/12 09:49:42 | 001,662,976 | ---- | M] (D-Link)
"GrooveMonitor" -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe ["C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"] -> [2008/10/25 12:44:34 | 000,031,072 | ---- | M] (Microsoft Corporation)
"TkBellExe" -> C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe ["C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot] -> [2010/08/01 20:05:20 | 000,202,256 | ---- | M] (RealNetworks, Inc.)
< Run [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"Sidebar" -> C:\Program Files (x86)\Windows Sidebar\Sidebar.exe [%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem] -> [2009/04/11 01:28:03 | 001,233,920 | ---- | M] (Microsoft Corporation)
"WindowsWelcomeCenter" -> C:\Windows\SysWow64\oobefldr.dll [rundll32.exe oobefldr.dll,ShowWelcomeCenter] -> [2009/04/11 01:28:23 | 002,153,472 | ---- | M] (Microsoft Corporation)
< Run [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"Sidebar" -> C:\Program Files (x86)\Windows Sidebar\Sidebar.exe [%ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem] -> [2009/04/11 01:28:03 | 001,233,920 | ---- | M] (Microsoft Corporation)
"WindowsWelcomeCenter" -> C:\Windows\SysWow64\oobefldr.dll [rundll32.exe oobefldr.dll,ShowWelcomeCenter] -> [2009/04/11 01:28:23 | 002,153,472 | ---- | M] (Microsoft Corporation)
< Run [HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\] > -> HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"FileHippo.com" -> C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe ["C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe" /background] -> [2010/04/29 07:57:16 | 000,248,832 | ---- | M] (FileHippo.com)
"SpybotSD TeaTimer" -> C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe] -> [2009/03/05 16:07:20 | 002,260,480 | ---- | M] (Safer-Networking Ltd.)
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoActiveDesktop" -> [1] -> File not found
\\"NoActiveDesktopChanges" -> [1] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"EnableLUA" -> [0] -> File not found
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000] > -> HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll [Button: Send to OneNote] -> [2009/02/26 19:45:52 | 000,603,040 | ---- | M] (Microsoft Corporation)
{2670000A-7350-4f3c-8081-5663EE0C6C49}:{48E73304-E1D6-4330-914C-F5F514E3486C} [HKLM] -> C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll [Menu: S&end to OneNote] -> [2009/02/26 19:45:52 | 000,603,040 | ---- | M] (Microsoft Corporation)
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}:{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll [Menu: Spybot - Search & Destroy Configuration] -> [2009/01/26 15:31:02 | 001,879,896 | ---- | M] (Safer Networking Limited)
< 64bit-Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< 64bit-Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 7383 domain(s) found. ->
< 64bit-Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. ->
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 7383 domain(s) found. ->
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 7383 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 7383 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 0 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\] > -> HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 7384 domain(s) found. ->
free_aol.com [http] -> Trusted sites ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\] > -> HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. ->
< 64bit-Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab [Java Plug-in 1.6.0_21] ->
{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab [Java Plug-in 1.6.0_21] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab [Reg Error: Key error.] ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab [Java Plug-in 1.6.0_20] ->
{A27C56D2-3F58-4ABB-AA31-1168EDA6636F} [HKLM] -> http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab [PCMaticVer Class] ->
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab [Java Plug-in 1.6.0_20] ->
{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [HKLM] -> Reg Error: Value error. [Reg Error: Key error.] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab [Java Plug-in 1.6.0_20] ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ ->
DhcpNameServer -> 192.168.2.1 ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{290BD338-6214-4BCC-9DD7-C8E988E8393F}\\DhcpNameServer -> 192.168.2.1 (D-Link WUA-2340 USB Adapter) ->
< 64bit-AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs ->
64bit-*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls ->
avgrssta.dll -> C:\Windows\SysNative\avgrssta.dll -> [2010/07/15 10:53:04 | 000,013,048 | ---- | M] (AVG Technologies CZ, s.r.o.)
*MultiFile Done* -> ->
< 64bit-Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
64bit-*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
explorer.exe -> C:\Windows\explorer.exe -> [2009/04/11 02:10:17 | 003,079,168 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
Explorer.exe -> C:\Windows\SysWow64\explorer.exe -> [2009/04/11 01:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Winlogon settings [HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000] > -> HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
Explorer.exe -> C:\Windows\SysWow64\explorer.exe -> [2009/04/11 01:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< 64bit-Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
WB -> C:\Program Files (x86)\Stardock\MyColors\fast64.dll -> File not found
< 64bit-SharedTaskScheduler [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler ->
"{E31004D1-A431-41B8-826F-E902F9D95C81}" [HKLM] -> C:\Windows\SysNative\DreamScene.dll [Windows DreamScene] -> [2007/07/19 18:55:46 | 000,275,360 | ---- | M] (Microsoft Corporation)
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" [HKLM] -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [Groove GFS Stub Execution Hook] -> [2009/02/12 16:19:32 | 002,217,848 | ---- | M] (Microsoft Corporation)
< Vista Active Firewall Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules ->
{0BD4000B-D5A3-4D94-AF94-F8298E5F4F3B} -> lport=137 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-28519 | app=system |
{30161166-31BD-49FD-9CA7-E7087EDB9CCA} -> lport=rpc | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28535 | app=%systemroot%\system32\spoolsv.exe | svc=spooler |
{45102A8D-FB42-45BA-9EF5-37DACD205839} -> lport=2177 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31261 | app=%systemroot%\system32\svchost.exe | svc=qwave |
{454299F0-52E8-4AA2-AAF4-2519434B6803} -> lport=10243 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31285 | app=system |
{462A3FB6-B5F5-4E2C-BAB9-C890A8C30408} -> lport=139 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28503 | app=system |
{589033A1-A5BB-452C-ABA8-EF1D5F7F0FA1} -> lport=rpc-epmap | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28539 | svc=rpcss |
{6341E769-87DC-4FF1-8067-9F4E1F6B8F5F} -> rport=137 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-28523 | app=system |
{6759BAD2-5556-4595-A24C-90DB5D037057} -> lport=1900 | profile=domain | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31269 | app=%systemroot%\system32\svchost.exe | svc=ssdpsrv |
{694E3763-D296-41EF-9060-A84B6A33C699} -> rport=138 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-28531 | app=system |
{728BBB7E-C97B-4A9A-A705-7A2CE795F074} -> lport=138 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-28527 | app=system |
{8495A905-2E2B-4DE3-AE94-35758D8DB1D4} -> lport=2177 | profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31253 | app=%systemroot%\system32\svchost.exe | svc=qwave |
{9F96E466-A9A5-4BA5-A91D-69FF07C7D70C} -> rport=445 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-28515 | app=system |
{AD8C1A1B-6FE1-46B6-86D6-7DDC5FC86B54} -> lport=2869 | profile=domain | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31277 | app=system |
{BF521253-6580-4545-9B3F-222A9A2B8B59} -> rport=1900 | profile=domain | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31273 | app=%systemroot%\system32\svchost.exe | svc=ssdpsrv |
{BFDA5C34-82BD-4D89-BEE4-89D1D17FFFD2} -> lport=6004 | profile=private | protocol=17 | dir=in | action=allow | name=microsoft office outlook | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
{CB37A0C7-86E0-4449-B097-2588289D89FB} -> rport=2177 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31265 | app=%systemroot%\system32\svchost.exe | svc=qwave |
{D43FC4CA-8517-47DA-8ABB-C2EC306FBB0D} -> rport=139 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-28507 | app=system |
{DA4A5BCF-0BE5-48D4-A835-877974386EA8} -> lport=445 | profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-28511 | app=system |
{E4A39614-B4B5-4F44-B015-F0C998024044} -> rport=2177 | profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31257 | app=%systemroot%\system32\svchost.exe | svc=qwave |
{F67FCB4A-AC84-4597-B7D2-26628EDD56E8} -> rport=10243 | profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31289 | app=system |
< Vista Active Application Exception Rules > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules ->
{05148C7E-D1AE-4C61-9D1D-D697CF6507C2} -> profile=domain | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31025 | app=%programfiles(x86)%\windows media player\wmplayer.exe |
{07218C52-B831-40B6-AF68-7745B6665C4A} -> profile=private | protocol=6 | dir=in | action=allow | name=microsoft office groove | app=c:\program files (x86)\microsoft office\office12\groove.exe |
{0B14C7BA-FAB6-41AC-B597-44A0EE1C4F8C} -> profile=private | protocol=58 | dir=in | action=allow | name=@firewallapi.dll,-28545 |
{0E789FDC-3ECA-434E-84E8-001474BA699E} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31323 | app=%programfiles(x86)%\windows media player\wmplayer.exe |
{1175A259-CE11-4742-89D1-37789E175E17} -> profile=public | protocol=6 | dir=in | action=allow | name=bonjour | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
{22432406-614A-4A63-B804-444B404130BF} -> profile=public | protocol=6 | dir=in | action=allow | name= | app=c:\windows\system32\spool\drivers\x64\3\lxdcpswx.exe |
{259AF828-96BC-47B0-8DE7-7B2EB654C7F2} -> profile=private | protocol=17 | dir=in | action=allow | name=bonjour service | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
{29E7A791-4472-4EDF-9F79-D83CB5DE9E6A} -> profile=public | dir=in | action=allow | name=skype | app=c:\program files (x86)\skype\phone\skype.exe |
{29ED7539-37F7-49C9-AEFD-5C98F77E6AF4} -> profile=private | protocol=17 | dir=in | action=allow | name=orbir | app=c:\program files (x86)\winamp remote\bin\orbir.exe |
{2AA2AE69-3B76-4AAE-B19A-657CF5ACEBBA} -> profile=private | protocol=6 | dir=in | action=allow | name=microsoft office onenote | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
{2C1BA777-7648-4412-9186-3CEEF5B0DF54} -> profile=domain | dir=in | action=allow | name=skype extras manager | app=c:\program files (x86)\skype\plugin manager\skypepm.exe |
{2CF9D411-19D0-4E0A-A16F-56F8F7F3960B} -> profile=private | protocol=1 | dir=in | action=allow | name=@firewallapi.dll,-28543 |
{32157E50-4998-4F19-879B-A4590E28DC6D} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31305 | app=%programfiles%\windows media player\wmpnetwk.exe |
{32E7ACD1-3D7E-45D5-9203-85AEFD292433} -> profile=public | dir=in | action=allow | name=avgdiagex.exe | app=c:\program files (x86)\avg\avg9\avgdiagex.exe |
{3FD4EAAD-9CDA-4E21-A892-C4DAEC19FB9F} -> profile=public | protocol=6 | dir=in | action=allow | name=itunes | app=c:\program files (x86)\itunes\itunes.exe |
{41C59E6F-1864-4B10-B66A-C3B7145CA4BB} -> profile=public | protocol=17 | dir=in | action=allow | name=itunes | app=c:\program files (x86)\itunes\itunes.exe |
{42DA947F-C370-4820-A8FC-918EA6468086} -> profile=private | protocol=17 | dir=in | action=allow | name=orb stream client | app=c:\program files (x86)\winamp remote\bin\orbstreamerclient.exe |
{430F99AA-7A89-453A-B0CA-75991DB833E8} -> profile=domain | dir=in | action=allow | name=skype | app=c:\program files (x86)\skype\phone\skype.exe |
{47B881FE-6220-4D23-9AC1-2C0AD91EF510} -> profile=domain | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31281 | app=system |
{4BB7D4DF-39C5-4721-91A6-7161D8DA1B47} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31301 | app=%programfiles%\windows media player\wmplayer.exe |
{4ED9E3D1-5F8F-4CC4-BFED-0DE08402ACF4} -> profile=private | protocol=17 | dir=in | action=allow | name=microsoft office onenote | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
{4FBACE54-B509-4A37-BA10-CA18FB7E9713} -> profile=private | protocol=6 | dir=in | action=allow | name=orb stream client | app=c:\program files (x86)\winamp remote\bin\orbstreamerclient.exe |
{5EDD20A1-A62E-4E3F-957F-4243F710D08C} -> profile=public | dir=in | action=allow | name=avgnsa.exe | app=c:\program files (x86)\avg\avg9\avgnsa.exe |
{71F4B9E7-D880-4402-9C6B-D638EA94227C} -> profile=domain | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31024 | app=%programfiles(x86)%\windows media player\wmplayer.exe |
{74158668-05CB-4C74-BB69-35D884337186} -> profile=public | protocol=17 | dir=in | action=allow | name=bittorrent (udp-in) | app=c:\program files (x86)\bittorrent\bittorrent.exe |
{7418AEAB-BC55-489B-B05E-5D359B4C382D} -> profile=public | protocol=17 | dir=in | action=allow | name=bittorrent | app=c:\program files (x86)\bittorrent\bittorrent.exe |
{760EA576-8E09-44DA-B1D5-CB7C55CDE567} -> profile=private | protocol=6 | dir=in | action=allow | name=orbir | app=c:\program files (x86)\winamp remote\bin\orbir.exe |
{86AAE600-7798-4A54-844B-30A5738758CB} -> profile=public | protocol=6 | dir=in | action=allow | name=bittorrent (tcp-in) | app=c:\program files (x86)\bittorrent\bittorrent.exe |
{87099167-BBE3-41FD-B7B5-05B910AB13F0} -> profile=domain | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31003 | app=%programfiles%\windows media player\wmplayer.exe |
{8F7FB5B7-9C8F-4FB9-A062-E3D02EE74018} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31325 | app=%programfiles(x86)%\windows media player\wmplayer.exe |
{97CCD644-5A32-4FCC-B74A-DFE360CE4393} -> profile=domain | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31011 | app=%programfiles%\windows media player\wmplayer.exe |
{9CF03AE0-DFBA-4835-B452-87D711413E71} -> profile=public | protocol=6 | dir=in | action=allow | name=bittorrent | app=c:\program files (x86)\bittorrent\bittorrent.exe |
{A60C1991-A48C-4F96-8A33-5C3A228CF5E9} -> profile=public | dir=in | action=allow | name=avgupd.exe | app=c:\program files (x86)\avg\avg9\avgupd.exe |
{A67E23EA-7D53-4550-9D05-AC85A7C8B905} -> profile=private | protocol=6 | dir=in | action=allow | name=orbtray | app=c:\program files (x86)\winamp remote\bin\orbtray.exe |
{AC4D75B0-CDB1-41B8-B042-6C660ABF427D} -> profile=private | protocol=17 | dir=in | action=allow | name=orb | app=c:\program files (x86)\winamp remote\bin\orb.exe |
{B05F229D-7C4E-4674-AE35-44AB6D4EA32C} -> profile=private | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31317 | app=%programfiles%\windows media player\wmpnetwk.exe |
{BB019224-6812-4C39-B307-477B4842B690} -> profile=private | protocol=6 | dir=in | action=allow | name=bonjour service | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
{BBDF4A5B-DFB5-40AF-809C-4490573AEF6F} -> profile=public | protocol=17 | dir=in | action=allow | name= | app=c:\windows\system32\spool\drivers\x64\3\lxdcpswx.exe |
{C0815551-619A-43AC-ABB6-3EB059E26580} -> profile=public | dir=in | action=allow | name=avgam.exe | app=c:\program files (x86)\avg\avg9\avgam.exe |
{CA0FC667-8830-48F1-9F51-C54662CE61B1} -> profile=public | protocol=6 | dir=in | action=allow | name= | app=c:\windows\system32\spool\drivers\x64\3\lxdcjswx.exe |
{CCEA2EE6-8EA7-473F-88B0-ED5A443FD7DF} -> profile=private | protocol=6 | dir=in | action=allow | name=orb | app=c:\program files (x86)\winamp remote\bin\orb.exe |
{CDBDDCF3-9E46-474E-8F81-560D568863F3} -> profile=private | protocol=17 | dir=in | action=allow | name=orbtray | app=c:\program files (x86)\winamp remote\bin\orbtray.exe |
{D06EA434-F651-46D1-B751-F07062A4BC21} -> profile=public | protocol=17 | dir=in | action=allow | name=bonjour | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
{D900259E-F2B3-488A-AC15-E13FE88A81E1} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31324 | app=%programfiles(x86)%\windows media player\wmplayer.exe |
{D92E9EAD-97D3-4AD0-AEDD-6A9A2A46698E} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31309 | app=%programfiles%\windows media player\wmpnetwk.exe |
{DE1FFB5A-0768-44F6-BD76-448462129FEF} -> profile=domain | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31007 | app=%programfiles%\windows media player\wmplayer.exe |
{E02BF45D-45A5-4F18-B621-597830C906DB} -> profile=private | protocol=17 | dir=out | action=allow | name=@firewallapi.dll,-31297 | app=%programfiles%\windows media player\wmplayer.exe |
{E061780B-D714-4453-B059-A6C83AC99EE6} -> profile=public | protocol=17 | dir=in | action=allow | name= | app=c:\windows\system32\spool\drivers\x64\3\lxdcjswx.exe |
{E0DA6D4B-EBC2-409E-B486-B5E28C5B59BC} -> profile=domain | protocol=6 | dir=out | action=allow | name=@firewallapi.dll,-31321 | app=%systemroot%\system32\svchost.exe | svc=upnphost |
{E42FF11B-293F-4CC2-BA82-93EA4F7682C9} -> profile=private | protocol=17 | dir=in | action=allow | name=microsoft office groove | app=c:\program files (x86)\microsoft office\office12\groove.exe |
{E5D0A758-28DC-4858-B6B9-1C16DF2174E6} -> profile=public | protocol=17 | dir=in | action=allow | name= | app=c:\windows\system32\spool\drivers\x64\3\lxdctime.exe |
{EA48CFD3-12FA-4CAF-A0A4-E7C4736F102C} -> profile=private | protocol=1 | dir=out | action=allow | name=@firewallapi.dll,-28544 |
{ED14F891-595E-44B7-AAD2-A9A53B051191} -> profile=private | protocol=58 | dir=out | action=allow | name=@firewallapi.dll,-28546 |
{EFE2739D-0CE8-43FF-9E36-7A3D9565F8CB} -> profile=public | protocol=6 | dir=in | action=allow | name= | app=c:\windows\system32\spool\drivers\x64\3\lxdctime.exe |
{F5FEF716-33DF-4F1C-B9BC-F399BD99C281} -> profile=domain | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31023 | app=%programfiles(x86)%\windows media player\wmplayer.exe |
{F751963D-656C-447A-9E9B-DB7E0D0E16D8} -> profile=private | protocol=6 | dir=in | action=allow | name=@firewallapi.dll,-31313 | app=%programfiles%\windows media player\wmpnetwk.exe |
{F8987141-3A72-43B6-8D5B-1E7C0090BE4E} -> profile=private | protocol=17 | dir=in | action=allow | name=@firewallapi.dll,-31293 | app=%programfiles%\windows media player\wmplayer.exe |
TCP Query User{08D4B649-8872-4512-A254-764E3D1535AD}C:\users\the snappy sneezer\appdata\local\temp\pyl3c29.tmp\pyrun.exe -> profile=private | protocol=6 | dir=in | action=allow | name=pyrun.exe | app=c:\users\the snappy sneezer\appdata\local\temp\pyl3c29.tmp\pyrun.exe |
TCP Query User{2475C8B0-E7D8-463C-99B9-D12D34C051F2}C:\program files (x86)\mozilla firefox\firefox.exe -> profile=public | protocol=6 | dir=in | action=block | name=firefox | app=c:\program files (x86)\mozilla firefox\firefox.exe |
TCP Query User{9F0A8D8D-6C4E-43DC-A2EB-38261D0298EC}C:\program files (x86)\winamp remote\bin\orbtray.exe -> profile=public | protocol=6 | dir=in | action=block | name=orb | app=c:\program files (x86)\winamp remote\bin\orbtray.exe |
TCP Query User{B0AFA5D0-337D-4C0E-A5DB-BF379DAE5FBE}C:\program files (x86)\mozilla firefox\firefox.exe -> profile=private | protocol=6 | dir=in | action=allow | name=firefox | app=c:\program files (x86)\mozilla firefox\firefox.exe |
TCP Query User{B7D0BED4-9FA7-4B5B-B7FA-98B2E6D49C3E}C:\program files (x86)\bittorrent\bittorrent.exe -> profile=private | protocol=6 | dir=in | action=allow | name=bittorrent | app=c:\program files (x86)\bittorrent\bittorrent.exe |
UDP Query User{0BBD33E6-A4D3-40DD-82FB-E91FBDCB0970}C:\program files (x86)\bittorrent\bittorrent.exe -> profile=private | protocol=17 | dir=in | action=allow | name=bittorrent | app=c:\program files (x86)\bittorrent\bittorrent.exe |
UDP Query User{67B94B13-AD26-4C7B-8866-3F33A06212EB}C:\program files (x86)\winamp remote\bin\orbtray.exe -> profile=public | protocol=17 | dir=in | action=block | name=orb | app=c:\program files (x86)\winamp remote\bin\orbtray.exe |
UDP Query User{8C257E4D-CA1A-4542-95AF-8E0467D01A8A}C:\users\the snappy sneezer\appdata\local\temp\pyl3c29.tmp\pyrun.exe -> profile=private | protocol=17 | dir=in | action=allow | name=pyrun.exe | app=c:\users\the snappy sneezer\appdata\local\temp\pyl3c29.tmp\pyrun.exe |
UDP Query User{C9821126-0306-4733-84C4-C7FDC9A4713D}C:\program files (x86)\mozilla firefox\firefox.exe -> profile=private | protocol=17 | dir=in | action=allow | name=firefox | app=c:\program files (x86)\mozilla firefox\firefox.exe |
UDP Query User{FA730E38-C4C9-4DA8-BD87-91A6DE0EF2F4}C:\program files (x86)\mozilla firefox\firefox.exe -> profile=public | protocol=17 | dir=in | action=block | name=firefox | app=c:\program files (x86)\mozilla firefox\firefox.exe |
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> CD-ROM Driver ->
"ImagePath" -> C:\Windows\SysNative\DRIVERS\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2009/04/11 00:34:39 | 000,079,872 | ---- | M] (Microsoft Corporation)
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
\F
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\shell
\F\shell\\"" -> [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\shell\AutoRun\command
\F\shell\AutoRun\command\\"" -> F:\LaunchU3.exe [F:\LaunchU3.exe -a] -> File not found
\{08735578-8a15-11de-9691-001558a3bf4b}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{08735578-8a15-11de-9691-001558a3bf4b}\shell
\{08735578-8a15-11de-9691-001558a3bf4b}\shell\\"" -> [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{08735578-8a15-11de-9691-001558a3bf4b}\shell\AutoRun\command
\{08735578-8a15-11de-9691-001558a3bf4b}\shell\AutoRun\command\\"" -> E:\LaunchU3.exe [E:\LaunchU3.exe -a] -> File not found
\{410266f8-8d97-11de-b0be-001558a3bf4b}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{410266f8-8d97-11de-b0be-001558a3bf4b}\shell
\{410266f8-8d97-11de-b0be-001558a3bf4b}\shell\\"" -> [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{410266f8-8d97-11de-b0be-001558a3bf4b}\shell\AutoRun\command
\{410266f8-8d97-11de-b0be-001558a3bf4b}\shell\AutoRun\command\\"" -> E:\LaunchU3.exe [E:\LaunchU3.exe -a] -> File not found
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command ->
64bit-comfile [open] -> "%1" %* -> File not found
64bit-exefile [open] -> "%1" %* -> File not found
comfile [open] -> "%1" %* ->
exefile [open] -> "%1" %* ->
< 64bit-File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>\ ->
.com [@ = comfile] -> "%1" %* ->
.exe [@ = exefile] -> "%1" %* ->
< File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>\ ->
.com [@ = comfile] -> "%1" %* ->
.exe [@ = exefile] -> "%1" %* ->
[Registry - Additional Scans - Safe List]
< Desktop WallPaper > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\General ->
WallPaper -> C:\Users\The Snappy Sneezer\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg ->
BackupWallPaper -> C:\Users\The Snappy Sneezer\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg ->
< 64bit-Disabled MSConfig Folder Items [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\ ->
C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^NkbMonitor.exe.lnk -> C:\Program Files (x86)\Nikon\PictureProject\NkbMonitor.exe -> [2006/10/16 16:10:22 | 000,118,784 | ---- | M] (Nikon Corporation)
C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^StupAssist.lnk -> C:\Program Files (x86)\Common Files\Nikon\Utilities\StupAssist.exe -> [2004/04/29 16:46:22 | 000,031,744 | ---- | M] (Nikon)
C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Supersonic Download Accelerator.lnk -> C:\PROGRA~2\SUPERS~1\SUPERS~1.EXE -> File not found
C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk -> C:\PROGRA~2\WinZip\WZQKPICK.EXE -> File not found
C:^Users^The Snappy Sneezer^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk -> C:\PROGRA~2\OPENOF~1.3\program\QUICKS~1.EXE -> File not found
< 64bit-Disabled MSConfig Registry Items [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ ->
Adobe Reader Speed Launcher hkey=HKLM key=SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe -> [2010/06/19 21:04:47 | 000,035,760 | ---- | M] (Adobe Systems Incorporated)
AVG9_TRAY hkey=HKLM key=SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files (x86)\AVG\AVG9\avgtray.exe -> [2010/07/20 20:04:28 | 002,065,760 | ---- | M] (AVG Technologies CZ, s.r.o.)
ClearAllHistory hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files (x86)\ClearAllHistory\cah.exe -> File not found
lxdcamon hkey=HKLM key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files (x86)\Lexmark 1300 Series\lxdcamon.exe -> [2007/04/30 08:19:54 | 000,020,480 | ---- | M] ()
QuickTime Task hkey=HKLM key=SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files (x86)\QuickTime\QTTask.exe -> [2010/03/17 21:53:36 | 000,421,888 | ---- | M] (Apple Inc.)
SpybotSD TeaTimer hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe -> [2009/03/05 16:07:20 | 002,260,480 | ---- | M] (Safer-Networking Ltd.)
SunJavaUpdateSched hkey=HKLM key=SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe -> File not found
swg hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files (x86)\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe -> File not found
TkBellExe hkey=HKLM key=SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe -> [2010/08/01 20:05:20 | 000,202,256 | ---- | M] (RealNetworks, Inc.)
WinampAgent hkey=HKLM key=SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files (x86)\Winamp\winampa.exe -> [2008/07/09 16:33:34 | 000,036,352 | ---- | M] ()
YSearchProtection hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> C:\Program Files (x86)\Yahoo!\Search Protection\SearchProtection.exe -> File not found
< 64bit-Disabled MSConfig State [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state ->
"services" -> 2 ->
"startup" -> 2 ->
< 64bit-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost > -> ->
*netsvcs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs ->
AppMgmt -> C:\Windows\SysNative\appmgmts.dll -> [2008/01/19 03:00:52 | 000,195,584 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command ->
64bit-batfile [open] -> "%1" %* -> File not found
64bit-cmdfile [open] -> "%1" %* -> File not found
64bit-comfile [open] -> "%1" %* -> File not found
64bit-exefile [open] -> "%1" %* -> File not found
64bit-htmlfile [edit] -> "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 -> [2008/11/10 11:50:30 | 000,068,472 | ---- | M] (Microsoft Corporation)
64bit-htmlfile [print] -> "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 -> [2008/11/10 11:50:30 | 000,068,472 | ---- | M] (Microsoft Corporation)
64bit-http [open] -> "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" -> [2010/07/22 17:02:16 | 000,945,720 | ---- | M] (Google Inc.)
64bit-https [open] -> "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" -> [2010/07/22 17:02:16 | 000,945,720 | ---- | M] (Google Inc.)
64bit-inffile [install] -> %SystemRoot%\System32\InfDefaultInstall.exe "%1" -> [2006/11/02 06:15:54 | 000,011,264 | ---- | M] (Microsoft Corporation)
64bit-InternetShortcut [print] -> "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" -> [2010/05/04 00:56:28 | 005,950,976 | ---- | M] (Microsoft Corporation)
64bit-piffile [open] -> "%1" %* -> File not found
64bit-scrfile [config] -> "%1" -> File not found
64bit-scrfile [install] -> rundll32.exe desk.cpl,InstallScreenSaver %l -> [2008/01/19 02:59:48 | 000,371,200 | ---- | M] (Microsoft Corporation)
64bit-scrfile [open] -> "%1" /S -> File not found
64bit-Unknown [openas] -> %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 -> File not found
64bit-Directory [AddToPlaylistVLC] -> "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" -> [2010/07/29 05:32:34 | 000,107,008 | ---- | M] ()
64bit-Directory [Browse with &IrfanView] -> "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" -> [2010/08/01 19:54:43 | 000,494,080 | ---- | M] (Irfan Skiljan)
64bit-Directory [cmd] -> cmd.exe /s /k pushd "%V" -> [2008/01/19 03:00:10 | 000,363,008 | ---- | M] (Microsoft Corporation)
64bit-Directory [find] -> %SystemRoot%\Explorer.exe -> [2009/04/11 02:10:17 | 003,079,168 | ---- | M] (Microsoft Corporation)
64bit-Directory [MediaMonkey.1Play] -> "C:\Program Files (x86)\MediaMonkey2\MediaMonkey.exe" "%1" -> [2010/06/25 00:38:54 | 008,112,272 | ---- | M] (Ventis Media Inc.)
64bit-Directory [MediaMonkey.2PlayNext] -> "C:\Program Files (x86)\MediaMonkey2\MediaMonkey.exe" /NEXT "%1" -> [2010/06/25 00:38:54 | 008,112,272 | ---- | M] (Ventis Media Inc.)
64bit-Directory [MediaMonkey.3Enqueue] -> "C:\Program Files (x86)\MediaMonkey2\MediaMonkey.exe" /ADD "%1" -> [2010/06/25 00:38:54 | 008,112,272 | ---- | M] (Ventis Media Inc.)
64bit-Directory [OneNote.Open] -> C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" -> [2009/02/26 15:24:50 | 001,001,840 | ---- | M] (Microsoft Corporation)
64bit-Directory [PlayWithVLC] -> "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" -> [2010/07/29 05:32:34 | 000,107,008 | ---- | M] ()
64bit-Directory [Winamp.Bookmark] -> "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" -> [2008/07/09 16:34:30 | 001,343,840 | ---- | M] (Nullsoft)
64bit-Directory [Winamp.Enqueue] -> "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" -> [2008/07/09 16:34:30 | 001,343,840 | ---- | M] (Nullsoft)
64bit-Directory [Winamp.Play] -> "C:\Program Files (x86)\Winamp\winamp.exe" "%1" -> [2008/07/09 16:34:30 | 001,343,840 | ---- | M] (Nullsoft)
64bit-Folder [open] -> %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L -> [2009/04/11 02:10:17 | 003,079,168 | ---- | M] (Microsoft Corporation)
64bit-Folder [explore] -> %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L -> [2009/04/11 02:10:17 | 003,079,168 | ---- | M] (Microsoft Corporation)
64bit-Drive [find] -> %SystemRoot%\Explorer.exe -> [2009/04/11 02:10:17 | 003,079,168 | ---- | M] (Microsoft Corporation)
batfile [open] -> "%1" %* ->
cmdfile [open] -> "%1" %* ->
comfile [open] -> "%1" %* ->
cplfile [cplopen] -> %SystemRoot%\System32\control.exe "%1",%* -> [2006/11/02 04:44:59 | 000,211,968 | ---- | M] (Microsoft Corporation)
exefile [open] -> "%1" %* ->
htmlfile [edit] -> "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 -> [2008/11/10 11:50:30 | 000,068,472 | ---- | M] (Microsoft Corporation)
htmlfile [print] -> "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 -> [2008/11/10 11:50:30 | 000,068,472 | ---- | M] (Microsoft Corporation)
http [open] -> "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" -> [2010/07/22 17:02:16 | 000,945,720 | ---- | M] (Google Inc.)
https [open] -> "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" -> [2010/07/22 17:02:16 | 000,945,720 | ---- | M] (Google Inc.)
inffile [install] -> %SystemRoot%\System32\InfDefaultInstall.exe "%1" -> [2008/01/19 02:33:12 | 000,011,776 | ---- | M] (Microsoft Corporation)
piffile [open] -> "%1" %* ->
scrfile [config] -> "%1" ->
scrfile [install] -> rundll32.exe desk.cpl,InstallScreenSaver %l -> [2008/01/19 02:32:56 | 000,368,640 | ---- | M] (Microsoft Corporation)
scrfile [open] -> "%1" /S ->
Unknown [openas] -> %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 ->
Directory [AddToPlaylistVLC] -> "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" -> [2010/07/29 05:32:34 | 000,107,008 | ---- | M] ()
Directory [Browse with &IrfanView] -> "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" -> [2010/08/01 19:54:43 | 000,494,080 | ---- | M] (Irfan Skiljan)
Directory [cmd] -> cmd.exe /s /k pushd "%V" -> [2008/01/19 02:33:04 | 000,318,976 | ---- | M] (Microsoft Corporation)
Directory [find] -> %SystemRoot%\Explorer.exe -> [2009/04/11 02:10:17 | 003,079,168 | ---- | M] (Microsoft Corporation)
Directory [MediaMonkey.1Play] -> "C:\Program Files (x86)\MediaMonkey2\MediaMonkey.exe" "%1" -> [2010/06/25 00:38:54 | 008,112,272 | ---- | M] (Ventis Media Inc.)
Directory [MediaMonkey.2PlayNext] -> "C:\Program Files (x86)\MediaMonkey2\MediaMonkey.exe" /NEXT "%1" -> [2010/06/25 00:38:54 | 008,112,272 | ---- | M] (Ventis Media Inc.)
Directory [MediaMonkey.3Enqueue] -> "C:\Program Files (x86)\MediaMonkey2\MediaMonkey.exe" /ADD "%1" -> [2010/06/25 00:38:54 | 008,112,272 | ---- | M] (Ventis Media Inc.)
Directory [OneNote.Open] -> C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" -> [2009/02/26 15:24:50 | 001,001,840 | ---- | M] (Microsoft Corporation)
Directory [PlayWithVLC] -> "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" -> [2010/07/29 05:32:34 | 000,107,008 | ---- | M] ()
Directory [Winamp.Bookmark] -> "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" -> [2008/07/09 16:34:30 | 001,343,840 | ---- | M] (Nullsoft)
Directory [Winamp.Enqueue] -> "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" -> [2008/07/09 16:34:30 | 001,343,840 | ---- | M] (Nullsoft)
Directory [Winamp.Play] -> "C:\Program Files (x86)\Winamp\winamp.exe" "%1" -> [2008/07/09 16:34:30 | 001,343,840 | ---- | M] (Nullsoft)
Folder [open] -> %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L -> [2009/04/11 02:10:17 | 003,079,168 | ---- | M] (Microsoft Corporation)
Folder [explore] -> %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L -> [2009/04/11 02:10:17 | 003,079,168 | ---- | M] (Microsoft Corporation)
Drive [find] -> %SystemRoot%\Explorer.exe -> [2009/04/11 02:10:17 | 003,079,168 | ---- | M] (Microsoft Corporation)
< 64bit-Uninstall List [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ ->
{26A24AE4-039D-4CA4-87B4-2F86416021FF} -> Java 6 Update 21 (64-bit)
{3D3E663D-4E7E-4577-A560-7ECDDD45548A} -> PVSonyDll
{52784483-7088-4A4C-81E2-808303AD98F5} -> Apple Mobile Device Support
{90120000-002A-0000-1000-0000000FF1CE} -> Microsoft Office Office 64-bit Components 2007
{90120000-002A-0409-1000-0000000FF1CE} -> Microsoft Office Shared 64-bit MUI (English) 2007
{90120000-0116-0409-1000-0000000FF1CE} -> Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
{9B48B0AC-C813-4174-9042-476A887592C7} -> Windows Live ID Sign-in Assistant
{B91110FB-33B4-468B-90C2-4D5E8AE3FAE1} -> Bonjour
{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} -> Microsoft .NET Framework 3.5 SP1
Lexmark 1300 Series -> Lexmark 1300 Series
Microsoft .NET Framework 3.5 SP1 -> Microsoft .NET Framework 3.5 SP1
NVIDIA Display Control Panel -> NVIDIA Display Control Panel
NVIDIA Drivers -> NVIDIA Drivers
UltSounds -> Windows Sound Schemes
UltSounds2 -> Ultimate Extras sounds from Microsoft® Tinker™
< Uninstall List [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ ->
{188CEE76-0503-4910-A845-E1DC45685DA0} -> RangeBooster G WUA-2340
{26A24AE4-039D-4CA4-87B4-2F83216017FF} -> Java 6 Update 20
{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD} -> QuickTime
{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} -> Rhapsody Player Engine
{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D} -> Visual C++ 8.0 Runtime Setup Package (x64)
{45A66726-69BC-466B-A7A4-12FCBA4883D7} -> HiJackThis
{48A25E19-D9AE-4BBE-9411-6F4C5D328B39} -> Skype™ Beta 5.0
{4A03706F-666A-4037-7777-5F2748764D10} -> Java Auto Updater
{4C590030-7469-453E-8589-D15DA9D03F52} -> ANIWZCS2 Service
{542EFC02-7803-4DC1-880D-221E9C13D404} -> Mojicon
{6956856F-B6B3-4BE0-BA0B-8F495BE32033} -> Apple Software Update
{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4} -> Windows Media Player Firefox Plugin
{6F7614CC-F33A-4877-8814-49856F441F3C} -> Stardock MyColors
{716E0306-8318-4364-8B8F-0CC4E9376BAC} -> MSXML 4.0 SP2 Parser and SDK
{7299052b-02a4-4627-81f2-1818da5d550d} -> Microsoft Visual C++ 2005 Redistributable
{7D101E90-36DD-439D-846A-C044621BD435} -> VOB2MPG v3
{837b34e3-7c30-493c-8f6a-2b0f04e2912c} -> Microsoft Visual C++ 2005 Redistributable
{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00} -> Microsoft Silverlight
{90120000-0015-0409-0000-0000000FF1CE} -> Microsoft Office Access MUI (English) 2007
{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E} -> Microsoft Office 2007 Service Pack 2 (SP2)
{90120000-0016-0409-0000-0000000FF1CE} -> Microsoft Office Excel MUI (English) 2007
{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E} -> Microsoft Office 2007 Service Pack 2 (SP2)
{90120000-0018-0409-0000-0000000FF1CE} -> Microsoft Office PowerPoint MUI (English) 2007
{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E} -> Microsoft Office 2007 Service Pack 2 (SP2)
{90120000-0019-0409-0000-0000000FF1CE} -> Microsoft Office Publisher MUI (English) 2007
{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E} -> Microsoft Office 2007 Service Pack 2 (SP2)
{90120000-001A-0409-0000-0000000FF1CE} -> Microsoft Office Outlook MUI (English) 2007
{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E} -> Microsoft Office 2007 Service Pack 2 (SP2)
{90120000-001B-0409-0000-0000000FF1CE} -> Microsoft Office Word MUI (English) 2007
{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E} -> Microsoft Office 2007 Service Pack 2 (SP2)
{90120000-001F-0409-0000-0000000FF1CE} -> Microsoft Office Proof (English) 2007
{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045} -> Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
{90120000-001F-040C-0000-0000000FF1CE} -> Microsoft Office Proof (French) 2007
{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787} -> Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
{90120000-001F-0C0A-0000-0000000FF1CE} -> Microsoft Office Proof (Spanish) 2007
{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9} -> Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{E64BA721-2310-4B55-BE5A-2925F9706192} -> Microsoft Office 2007 Service Pack 2 (SP2)
{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E} -> Microsoft Office 2007 Service Pack 2 (SP2)
{90120000-002C-0409-0000-0000000FF1CE} -> Microsoft Office Proofing (English) 2007
{90120000-0030-0000-0000-0000000FF1CE} -> Microsoft Office Enterprise 2007
{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B} -> Microsoft Office 2007 Service Pack 2 (SP2)
{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF} -> Security Update for Microsoft Office system 2007 (972581)
{90120000-0044-0409-0000-0000000FF1CE} -> Microsoft Office InfoPath MUI (English) 2007
{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E} -> Microsoft Office 2007 Service Pack 2 (SP2)
{90120000-006E-0409-0000-0000000FF1CE} -> Microsoft Office Shared MUI (English) 2007
{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E} -> Microsoft Office 2007 Service Pack 2 (SP2)
{90120000-00A1-0409-0000-0000000FF1CE} -> Microsoft Office OneNote MUI (English) 2007
{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E} -> Microsoft Office 2007 Service Pack 2 (SP2)
{90120000-00BA-0409-0000-0000000FF1CE} -> Microsoft Office Groove MUI (English) 2007
{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E} -> Microsoft Office 2007 Service Pack 2 (SP2)
{90120000-0114-0409-0000-0000000FF1CE} -> Microsoft Office Groove Setup Metadata MUI (English) 2007
{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E} -> Microsoft Office 2007 Service Pack 2 (SP2)
{90120000-0115-0409-0000-0000000FF1CE} -> Microsoft Office Shared Setup Metadata MUI (English) 2007
{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E} -> Microsoft Office 2007 Service Pack 2 (SP2)
{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E} -> Microsoft Office 2007 Service Pack 2 (SP2)
{90120000-0117-0409-0000-0000000FF1CE} -> Microsoft Office Access Setup Metadata MUI (English) 2007
{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E} -> Microsoft Office 2007 Service Pack 2 (SP2)
{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E} -> Microsoft Search Enhancement Pack
{9F73FDEF-DDC1-4307-9D96-13AB3254641A}_is1 -> Doctor Who: The Adventure Games
{A0BCF90F-B4E4-435C-A48D-8FAAE10554F9} -> Pixia
{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2} -> Google Update Helper
{A93944F2-D2D4-4750-BFE7-9A288FEAF2CF} -> Apple Application Support
{AC76BA86-7AD7-1033-7B44-A93000000001} -> Adobe Reader 9.3.3
{B194272D-1F92-46DF-99EB-8D5CE91CB4EC} -> Adobe AIR
{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 -> Spybot - Search & Destroy
{BEFBEDDF-1417-4C8A-92FB-F003C0D41199} -> OpenOffice.org 3.2
{D2FCC1AE-6311-47C5-8130-C6C66D77DD71} -> Nikon Message Center
{EAFEF30E-3789-49C7-A6D9-77C12E005BAC} -> Safari
{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262} -> Microsoft Office Live Add-in 1.5
{F4F4F84E-804F-4E9A-84D7-C34283F0088F} -> RealUpgrade 1.0
{FF3999BE-1A7B-4738-88AA-97BF14094A4A} -> PictureProject
7-Zip -> 7-Zip 9.15 beta
Adobe Acrobat 4.0 -> Adobe Acrobat 4.0
Adobe AIR -> Adobe AIR
Adobe Flash Player Plugin -> Adobe Flash Player 10 Plugin
Audacity_is1 -> Audacity 1.2.6
AutoItv3 -> AutoIt v3.3.6.1
AVG9Uninstall -> AVG 9.0
BitTorrent -> BitTorrent
CCleaner -> CCleaner
Doctor Who - The Adventure Games -> Doctor Who - The Adventure Games 2.0
DVD Audio Extractor_is1 -> DVD Audio Extractor 4.5.5
DVD Decrypter -> DVD Decrypter (Remove Only)
DVD Shrink_is1 -> DVD Shrink 3.2
ENTERPRISE -> Microsoft Office Enterprise 2007
FileHippo.com -> FileHippo.com Update Checker
Flock (2.5.6) -> Flock (2.5.6)
FoxyTunesForFirefox -> FoxyTunes for Firefox
Google Chrome -> Google Chrome
GPL Ghostscript 8.57 -> GPL Ghostscript 8.57
GPL Ghostscript Fonts -> GPL Ghostscript Fonts
IrfanView -> IrfanView (remove only)
Kazoo Player -> Kazoo Player
LADSPA_plugins-win_is1 -> LADSPA_plugins-win-0.4.15
MediaMonkey_is1 -> MediaMonkey 3.2
Mozilla Firefox (3.6.7) -> Mozilla Firefox (3.6.7)
Mozilla Firefox (4.0b2) -> Mozilla Firefox (4.0b2)
Mozilla Thunderbird (3.1.1) -> Mozilla Thunderbird (3.1.1)
PrimoPDF4.1.0.9 -> PrimoPDF
RealPlayer 12.0 -> RealPlayer
S5 -> Serenade 5 Beta 5 (remove only)
Stardock MyColors -> Stardock MyColors
TomeRaider3_is1 -> TomeRaider3 v3.3.9
Uninstall_is1 -> Uninstall 1.0.0.1
Vize -> Vize 1.1 BETA
VLC media player -> VLC media player 1.1.2
Winamp -> Winamp
< Uninstall List [HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\] > -> HKEY_USERS\S-1-5-21-2517189832-1248643285-16043602-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ ->
Facebook Plug-In -> Facebook Plug-In
Move Media Player -> Move Media Player
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Application [ Error ] 8/3/2010 4:28:23 AM Computer Name = PandorasBox | Source = Bonjour Service | ID = 100 -> Description = Task Scheduling Error: m->NextScheduledEvent 10140
Application [ Error ] 8/3/2010 4:28:23 AM Computer Name = PandorasBox | Source = Bonjour Service | ID = 100 -> Description = Task Scheduling Error: m->NextScheduledSPRetry 10140
Application [ Error ] 8/3/2010 4:32:48 AM Computer Name = PandorasBox | Source = Bonjour Service | ID = 100 -> Description = Task Scheduling Error: Continuously busy for more than a second
Application [ Error ] 8/3/2010 4:32:48 AM Computer Name = PandorasBox | Source = Bonjour Service | ID = 100 -> Description = Task Scheduling Error: m->NextScheduledEvent 275592
Application [ Error ] 8/3/2010 4:32:48 AM Computer Name = PandorasBox | Source = Bonjour Service | ID = 100 -> Description = Task Scheduling Error: m->NextScheduledSPRetry 275592
Application [ Error ] 8/3/2010 4:32:49 AM Computer Name = PandorasBox | Source = Bonjour Service | ID = 100 -> Description = Task Scheduling Error: Continuously busy for more than a second
Application [ Error ] 8/3/2010 4:32:49 AM Computer Name = PandorasBox | Source = Bonjour Service | ID = 100 -> Description = Task Scheduling Error: m->NextScheduledEvent 276887
Application [ Error ] 8/3/2010 4:32:49 AM Computer Name = PandorasBox | Source = Bonjour Service | ID = 100 -> Description = Task Scheduling Error: m->NextScheduledSPRetry 276887
Application [ Error ] 8/3/2010 4:32:50 AM Computer Name = PandorasBox | Source = Bonjour Service | ID = 100 -> Description = Task Scheduling Error: Continuously busy for more than a second
Application [ Error ] 8/3/2010 4:32:50 AM Computer Name = PandorasBox | Source = Bonjour Service | ID = 100 -> Description = Task Scheduling Error: m->NextScheduledEvent 277932
Media Center [ Error ] 5/15/2009 6:00:18 AM Computer Name = BradfordCurse | Source = Media Center Guide | ID = 0 -> Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Process: DefaultDomain Object Name: Media Center Guide
Media Center [ Error ] 5/15/2009 6:00:35 AM Computer Name = BradfordCurse | Source = Media Center Guide | ID = 0 -> Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Process: DefaultDomain Object Name: Media Center Guide
Media Center [ Error ] 6/11/2009 12:05:25 AM Computer Name = BradfordCurse | Source = Media Center Guide | ID = 0 -> Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Process: DefaultDomain Object Name: Media Center Guide
Media Center [ Error ] 8/1/2009 9:42:28 AM Computer Name = BradfordCurse | Source = Media Center Guide | ID = 0 -> Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError returned 10000105 Process: DefaultDomain Object Name: Media Center Guide
Media Center [ Error ] 9/26/2009 7:27:24 PM Computer Name = BradfordCurse | Source = Media Center Guide | ID = 0 -> Description = Event Info: ERROR: SqmApiWrapper.TimerAccumulate failed; Win32 GetLastError returned 10000105 Process: DefaultDomain Object Name: Media Center Guide
System [ Error ] 8/2/2010 9:07:05 AM Computer Name = PandorasBox | Source = EventLog | ID = 6008 -> Description = The previous system shutdown at 8:03:47 AM on 8/2/2010 was unexpected.
System [ Error ] 8/2/2010 9:07:47 AM Computer Name = PandorasBox | Source = Service Control Manager | ID = 7009 -> Description =
System [ Error ] 8/2/2010 9:07:47 AM Computer Name = PandorasBox | Source = Service Control Manager | ID = 7000 -> Description =
System [ Error ] 8/2/2010 9:07:52 AM Computer Name = PandorasBox | Source = Service Control Manager | ID = 7026 -> Description =
System [ Error ] 8/2/2010 9:12:26 AM Computer Name = PandorasBox | Source = Service Control Manager | ID = 7022 -> Description =
System [ Error ] 8/2/2010 2:20:42 PM Computer Name = PandorasBox | Source = Service Control Manager | ID = 7011 -> Description =
System [ Error ] 8/2/2010 7:20:13 PM Computer Name = PandorasBox | Source = Service Control Manager | ID = 7009 -> Description =
System [ Error ] 8/2/2010 7:20:13 PM Computer Name = PandorasBox | Source = Service Control Manager | ID = 7000 -> Description =
System [ Error ] 8/2/2010 7:20:18 PM Computer Name = PandorasBox | Source = Service Control Manager | ID = 7026 -> Description =
System [ Error ] 8/3/2010 4:24:34 AM Computer Name = PandorasBox | Source = DCOM | ID = 10010 -> Description =
[Files/Folders - Created Within 30 Days]
XPero -> C:\Program Files (x86)\XPero -> [2081/12/08 11:12:45 | 000,000,000 | ---D | C]
Config.Msi -> C:\Config.Msi -> [2010/08/02 09:13:17 | 000,000,000 | -HSD | C]
Trend Micro -> C:\Program Files (x86)\Trend Micro -> [2010/08/02 08:49:48 | 000,000,000 | ---D | C]
tmcomm.sys -> C:\Windows\SysWow64\drivers\tmcomm.sys -> [2010/08/02 08:24:00 | 000,157,712 | ---- | C] (Trend Micro Inc.)
skypePM -> C:\Users\The Snappy Sneezer\AppData\Roaming\skypePM -> [2010/08/01 21:18:30 | 000,000,000 | ---D | C]
Skype -> C:\Program Files (x86)\Common Files\Skype -> [2010/08/01 21:15:40 | 000,000,000 | ---D | C]
Skype -> C:\Program Files (x86)\Skype -> [2010/08/01 21:15:39 | 000,000,000 | R--D | C]
OpenOffice.org 3 -> C:\Program Files (x86)\OpenOffice.org 3 -> [2010/08/01 21:05:47 | 000,000,000 | ---D | C]
OpenOffice.org 3.2 (en-US) Installation Files -> C:\Users\The Snappy Sneezer\Desktop\OpenOffice.org 3.2 (en-US) Installation Files -> [2010/08/01 20:58:14 | 000,000,000 | ---D | C]
Bonjour -> C:\Program Files\Bonjour -> [2010/08/01 20:53:28 | 000,000,000 | ---D | C]
Bonjour -> C:\Program Files (x86)\Bonjour -> [2010/08/01 20:53:28 | 000,000,000 | ---D | C]
rmoc3260.dll -> C:\Windows\SysWow64\rmoc3260.dll -> [2010/08/01 20:06:21 | 000,185,920 | ---- | C] (RealNetworks, Inc.)
pndx5016.dll -> C:\Windows\SysWow64\pndx5016.dll -> [2010/08/01 20:06:11 | 000,006,656 | ---- | C] (RealNetworks, Inc.)
pndx5032.dll -> C:\Windows\SysWow64\pndx5032.dll -> [2010/08/01 20:06:11 | 000,005,632 | ---- | C] (RealNetworks, Inc.)
xing shared -> C:\Program Files (x86)\Common Files\xing shared -> [2010/08/01 20:06:00 | 000,000,000 | ---D | C]
pncrt.dll -> C:\Windows\SysWow64\pncrt.dll -> [2010/08/01 20:05:24 | 000,278,528 | ---- | C] (Real Networks, Inc)
Real -> C:\ProgramData\Real -> [2010/08/01 20:04:37 | 000,000,000 | ---D | C]
deployJava1.dll -> C:\Windows\SysNative\deployJava1.dll -> [2010/08/01 20:00:59 | 000,468,480 | ---- | C] (Oracle)
javaws.exe -> C:\Windows\SysNative\javaws.exe -> [2010/08/01 20:00:59 | 000,183,296 | ---- | C] (Oracle)
javaw.exe -> C:\Windows\SysNative\javaw.exe -> [2010/08/01 20:00:59 | 000,165,888 | ---- | C] (Oracle)
java.exe -> C:\Windows\SysNative\java.exe -> [2010/08/01 20:00:59 | 000,165,888 | ---- | C] (Oracle)
Java -> C:\Program Files\Java -> [2010/08/01 20:00:15 | 000,000,000 | ---D | C]
Google -> C:\Program Files\Google -> [2010/08/01 19:55:03 | 000,000,000 | ---D | C]
FileHippo.com -> C:\Program Files (x86)\FileHippo.com -> [2010/08/01 19:52:22 | 000,000,000 | ---D | C]
7-Zip -> C:\Program Files (x86)\7-Zip -> [2010/08/01 19:49:28 | 000,000,000 | ---D | C]
vlc -> C:\Users\The Snappy Sneezer\AppData\Roaming\vlc -> [2010/08/01 19:40:01 | 000,000,000 | ---D | C]
Mozilla Firefox 4.0 Beta 2 -> C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 2 -> [2010/08/01 14:40:40 | 000,000,000 | ---D | C]
Thunderbird -> C:\Users\The Snappy Sneezer\AppData\Roaming\Thunderbird -> [2010/07/23 10:21:40 | 000,000,000 | ---D | C]
Thunderbird -> C:\Users\The Snappy Sneezer\AppData\Local\Thunderbird -> [2010/07/23 10:21:40 | 000,000,000 | ---D | C]
Mozilla Thunderbird -> C:\Program Files (x86)\Mozilla Thunderbird -> [2010/07/23 10:21:24 | 000,000,000 | ---D | C]
avgrssta.dll -> C:\Windows\SysNative\avgrssta.dll -> [2010/07/15 10:53:04 | 000,013,048 | ---- | C] (AVG Technologies CZ, s.r.o.)
ezt -> C:\Program Files (x86)\ezt -> [2010/07/14 11:55:19 | 000,000,000 | ---D | C]
XAudio2_5.dll -> C:\Windows\SysNative\XAudio2_5.dll -> [2010/07/13 17:45:38 | 000,517,960 | ---- | C] (Microsoft Corporation)
XAudio2_5.dll -> C:\Windows\SysWow64\XAudio2_5.dll -> [2010/07/13 17:45:38 | 000,515,416 | ---- | C] (Microsoft Corporation)
XAPOFX1_3.dll -> C:\Windows\SysNative\XAPOFX1_3.dll -> [2010/07/13 17:45:38 | 000,073,544 | ---- | C] (Microsoft Corporation)
XAPOFX1_3.dll -> C:\Windows\SysWow64\XAPOFX1_3.dll -> [2010/07/13 17:45:38 | 000,069,464 | ---- | C] (Microsoft Corporation)
xactengine3_5.dll -> C:\Windows\SysWow64\xactengine3_5.dll -> [2010/07/13 17:45:31 | 000,238,936 | ---- | C] (Microsoft Corporation)
xactengine3_5.dll -> C:\Windows\SysNative\xactengine3_5.dll -> [2010/07/13 17:45:31 | 000,176,968 | ---- | C] (Microsoft Corporation)
D3DCompiler_42.dll -> C:\Windows\SysNative\D3DCompiler_42.dll -> [2010/07/13 17:45:29 | 002,582,888 | ---- | C] (Microsoft Corporation)
D3DCompiler_42.dll -> C:\Windows\SysWow64\D3DCompiler_42.dll -> [2010/07/13 17:45:29 | 001,974,616 | ---- | C] (Microsoft Corporation)
d3dcsx_42.dll -> C:\Windows\SysNative\d3dcsx_42.dll -> [2010/07/13 17:45:26 | 005,554,512 | ---- | C] (Microsoft Corporation)
d3dcsx_42.dll -> C:\Windows\SysWow64\d3dcsx_42.dll -> [2010/07/13 17:45:26 | 005,501,792 | ---- | C] (Microsoft Corporation)
d3dx11_42.dll -> C:\Windows\SysNative\d3dx11_42.dll -> [2010/07/13 17:45:23 | 000,285,024 | ---- | C] (Microsoft Corporation)
d3dx11_42.dll -> C:\Windows\SysWow64\d3dx11_42.dll -> [2010/07/13 17:45:23 | 000,235,344 | ---- | C] (Microsoft Corporation)
d3dx10_42.dll -> C:\Windows\SysNative\d3dx10_42.dll -> [2010/07/13 17:45:21 | 000,523,088 | ---- | C] (Microsoft Corporation)
d3dx10_42.dll -> C:\Windows\SysWow64\d3dx10_42.dll -> [2010/07/13 17:45:21 | 000,453,456 | ---- | C] (Microsoft Corporation)
D3DX9_42.dll -> C:\Windows\SysNative\D3DX9_42.dll -> [2010/07/13 17:45:13 | 002,475,352 | ---- | C] (Microsoft Corporation)
AutoIt3 -> C:\Program Files (x86)\AutoIt3 -> [2010/07/12 18:24:38 | 000,000,000 | ---D | C]
lxdcserv.dll -> C:\Windows\SysWow64\lxdcserv.dll -> [2009/04/17 09:19:30 | 001,232,896 | ---- | C] ( )
lxdcusb1.dll -> C:\Windows\SysWow64\lxdcusb1.dll -> [2009/04/17 09:19:30 | 000,999,424 | ---- | C] ( )
lxdchbn3.dll -> C:\Windows\SysWow64\lxdchbn3.dll -> [2009/04/17 09:19:30 | 000,700,416 | ---- | C] ( )
lxdccomc.dll -> C:\Windows\SysWow64\lxdccomc.dll -> [2009/04/17 09:19:30 | 000,684,032 | ---- | C] ( )
lxdcpmui.dll -> C:\Windows\SysWow64\lxdcpmui.dll -> [2009/04/17 09:19:30 | 000,643,072 | ---- | C] ( )
lxdclmpm.dll -> C:\Windows\SysWow64\lxdclmpm.dll -> [2009/04/17 09:19:30 | 000,585,728 | ---- | C] ( )
lxdccomm.dll -> C:\Windows\SysWow64\lxdccomm.dll -> [2009/04/17 09:19:30 | 000,425,984 | ---- | C] ( )
lxdcinpa.dll -> C:\Windows\SysWow64\lxdcinpa.dll -> [2009/04/17 09:19:30 | 000,413,696 | ---- | C] ( )
lxdciesc.dll -> C:\Windows\SysWow64\lxdciesc.dll -> [2009/04/17 09:19:30 | 000,397,312 | ---- | C] ( )
lxdcprox.dll -> C:\Windows\SysWow64\lxdcprox.dll -> [2009/04/17 09:19:30 | 000,163,840 | ---- | C] ( )
lxdcpplc.dll -> C:\Windows\SysWow64\lxdcpplc.dll -> [2009/04/17 09:19:30 | 000,094,208 | ---- | C] ( )
3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp ->
3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp ->
1 C:\Users\The Snappy Sneezer\Desktop\*.tmp files -> C:\Users\The Snappy Sneezer\Desktop\*.tmp ->
[Files/Folders - Modified Within 30 Days]
ntuser.dat{370d6715-7a40-1230-8133-001558a3bf4b}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\The Snappy Sneezer\ntuser.dat{370d6715-7a40-1230-8133-001558a3bf4b}.TMContainer00000000000000000002.regtrans-ms -> [2082/09/15 22:19:27 | 000,524,288 | -HS- | M] ()
ntuser.dat{166d4bb9-0b0a-11df-947f-001558a3bf4b}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\The Snappy Sneezer\ntuser.dat{166d4bb9-0b0a-11df-947f-001558a3bf4b}.TMContainer00000000000000000001.regtrans-ms -> [2082/09/15 20:51:06 | 000,524,288 | -HS- | M] ()
ntuser.dat{166d4bb9-0b0a-11df-947f-001558a3bf4b}.TM.blf -> C:\Users\The Snappy Sneezer\ntuser.dat{166d4bb9-0b0a-11df-947f-001558a3bf4b}.TM.blf -> [2082/09/15 20:51:06 | 000,065,536 | -HS- | M] ()
User_Feed_Synchronization-{2AA8CDC9-044F-4892-AA03-7FF9A2A76CA8}.job -> C:\Windows\tasks\User_Feed_Synchronization-{2AA8CDC9-044F-4892-AA03-7FF9A2A76CA8}.job -> [2010/08/03 10:05:42 | 000,000,444 | -H-- | M] ()
User_Feed_Synchronization-{43E3E63F-0764-4155-9501-BB842B477FE2}.job -> C:\Windows\tasks\User_Feed_Synchronization-{43E3E63F-0764-4155-9501-BB842B477FE2}.job -> [2010/08/03 10:04:59 | 000,000,416 | -H-- | M] ()
ntuser.dat -> C:\Users\The Snappy Sneezer\ntuser.dat -> [2010/08/03 10:04:43 | 009,175,040 | -HS- | M] ()
incavi.avm -> C:\Windows\SysNative\drivers\Avg\incavi.avm -> [2010/08/03 09:48:27 | 062,896,912 | ---- | M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -> [2010/08/03 09:43:07 | 000,004,048 | -H-- | M] ()
7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -> [2010/08/03 09:43:07 | 000,004,048 | -H-- | M] ()
nvModes.dat -> C:\ProgramData\nvModes.dat -> [2010/08/03 09:43:03 | 000,128,341 | ---- | M] ()
GoogleUpdateTaskMachineUA.job -> C:\Windows\tasks\GoogleUpdateTaskMachineUA.job -> [2010/08/03 09:43:03 | 000,000,922 | ---- | M] ()
nvModes.001 -> C:\ProgramData\nvModes.001 -> [2010/08/03 09:43:02 | 000,128,341 | ---- | M] ()
bootstat.dat -> C:\Windows\bootstat.dat -> [2010/08/03 09:42:53 | 000,067,584 | --S- | M] ()
ANIWZCS{290BD338-6214-4BCC-9DD7-C8E988E8393F} -> C:\Windows\SysWow64\ANIWZCS{290BD338-6214-4BCC-9DD7-C8E988E8393F} -> [2010/08/03 03:33:03 | 000,003,284 | ---- | M] ()
ANIWZCSUSERNAME{290BD338-6214-4BCC-9DD7-C8E988E8393F} -> C:\Windows\SysWow64\ANIWZCSUSERNAME{290BD338-6214-4BCC-9DD7-C8E988E8393F} -> [2010/08/03 03:32:57 | 000,000,019 | ---- | M] ()
GoogleUpdateTaskMachineCore.job -> C:\Windows\tasks\GoogleUpdateTaskMachineCore.job -> [2010/08/02 18:19:57 | 000,000,918 | ---- | M] ()
SA.DAT -> C:\Windows\tasks\SA.DAT -> [2010/08/02 18:19:46 | 000,000,006 | -H-- | M] ()
hiberfil.sys -> C:\hiberfil.sys -> [2010/08/02 18:19:41 | 2147,016,704 | -HS- | M] ()
ntuser.dat{a8670c0b-9d35-11df-a41f-001558a3bf4b}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\The Snappy Sneezer\ntuser.dat{a8670c0b-9d35-11df-a41f-001558a3bf4b}.TMContainer00000000000000000001.regtrans-ms -> [2010/08/02 18:18:02 | 000,524,288 | -HS- | M] ()
ntuser.dat{a8670c0b-9d35-11df-a41f-001558a3bf4b}.TM.blf -> C:\Users\The Snappy Sneezer\ntuser.dat{a8670c0b-9d35-11df-a41f-001558a3bf4b}.TM.blf -> [2010/08/02 18:18:02 | 000,065,536 | -HS- | M] ()
IconCache.db -> C:\Users\The Snappy Sneezer\AppData\Local\IconCache.db -> [2010/08/02 18:16:44 | 002,683,509 | -H-- | M] ()
gswin32.ini -> C:\Windows\gswin32.ini -> [2010/08/02 09:18:52 | 000,000,043 | ---- | M] ()
HiJackThis.lnk -> C:\Users\The Snappy Sneezer\Desktop\HiJackThis.lnk -> [2010/08/02 08:49:48 | 000,001,986 | ---- | M] ()
MEMORY.DMP -> C:\Windows\MEMORY.DMP -> [2010/08/02 08:06:54 | 423,107,059 | ---- | M] ()
GDIPFONTCACHEV1.DAT -> C:\Users\The Snappy Sneezer\AppData\Local\GDIPFONTCACHEV1.DAT -> [2010/08/01 22:58:58 | 000,112,120 | ---- | M] ()
FNTCACHE.DAT -> C:\Windows\SysNative\FNTCACHE.DAT -> [2010/08/01 22:28:46 | 000,411,784 | ---- | M] ()
ezsidmv.dat -> C:\Windows\SysWow64\ezsidmv.dat -> [2010/08/01 21:18:32 | 000,000,056 | -H-- | M] ()
OpenOffice.org 3.2.lnk -> C:\Users\Public\Desktop\OpenOffice.org 3.2.lnk -> [2010/08/01 21:10:58 | 000,001,027 | ---- | M] ()
Safari.lnk -> C:\Users\Public\Desktop\Safari.lnk -> [2010/08/01 20:56:43 | 000,001,866 | ---- | M] ()
Apple Safari.lnk -> C:\Users\The Snappy Sneezer\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk -> [2010/08/01 20:56:43 | 000,001,866 | ---- | M] ()
hosts -> C:\Windows\SysNative\drivers\etc\hosts -> [2010/08/01 20:23:40 | 000,416,180 | R--- | M] ()
CDPlayer.ini -> C:\Windows\CDPlayer.ini -> [2010/08/01 20:19:51 | 000,055,946 | ---- | M] ()
Spybot - Search & Destroy.lnk -> C:\Users\The Snappy Sneezer\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk -> [2010/08/01 20:17:18 | 000,001,121 | ---- | M] ()
Spybot - Search & Destroy.lnk -> C:\Users\The Snappy Sneezer\Desktop\Spybot - Search & Destroy.lnk -> [2010/08/01 20:17:18 | 000,001,097 | ---- | M] ()
rmoc3260.dll -> C:\Windows\SysWow64\rmoc3260.dll -> [2010/08/01 20:06:21 | 000,185,920 | ---- | M] (RealNetworks, Inc.)
pndx5016.dll -> C:\Windows\SysWow64\pndx5016.dll -> [2010/08/01 20:06:11 | 000,006,656 | ---- | M] (RealNetworks, Inc.)
pndx5032.dll -> C:\Windows\SysWow64\pndx5032.dll -> [2010/08/01 20:06:11 | 000,005,632 | ---- | M] (RealNetworks, Inc.)
pncrt.dll -> C:\Windows\SysWow64\pncrt.dll -> [2010/08/01 20:05:24 | 000,278,528 | ---- | M] (Real Networks, Inc)
deployJava1.dll -> C:\Windows\SysNative\deployJava1.dll -> [2010/08/01 20:00:20 | 000,468,480 | ---- | M] (Oracle)
javaws.exe -> C:\Windows\SysNative\javaws.exe -> [2010/08/01 20:00:20 | 000,183,296 | ---- | M] (Oracle)
javaw.exe -> C:\Windows\SysNative\javaw.exe -> [2010/08/01 20:00:20 | 000,165,888 | ---- | M] (Oracle)
java.exe -> C:\Windows\SysNative\java.exe -> [2010/08/01 20:00:20 | 000,165,888 | ---- | M] (Oracle)
IrfanView Thumbnails.lnk -> C:\Users\The Snappy Sneezer\Desktop\IrfanView Thumbnails.lnk -> [2010/08/01 19:54:44 | 000,001,729 | ---- | M] ()
IrfanView.lnk -> C:\Users\The Snappy Sneezer\Desktop\IrfanView.lnk -> [2010/08/01 19:54:44 | 000,000,837 | ---- | M] ()
Update Checker.lnk -> C:\Users\The Snappy Sneezer\Desktop\Update Checker.lnk -> [2010/08/01 19:52:22 | 000,001,808 | ---- | M] ()
VLC media player.lnk -> C:\Users\Public\Desktop\VLC media player.lnk -> [2010/08/01 19:39:37 | 000,000,901 | ---- | M] ()
iavifw.avm -> C:\Windows\SysNative\drivers\Avg\iavifw.avm -> [2010/08/01 17:22:04 | 000,606,588 | ---- | M] ()
Mozilla Firefox 4.0 Beta 2.lnk -> C:\Users\The Snappy Sneezer\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox 4.0 Beta 2.lnk -> [2010/08/01 14:49:22 | 000,002,006 | ---- | M] ()
CCleaner.lnk -> C:\Users\The Snappy Sneezer\Desktop\CCleaner.lnk -> [2010/08/01 14:23:09 | 000,000,846 | ---- | M] ()
ntuser.dat{a8670c0b-9d35-11df-a41f-001558a3bf4b}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\The Snappy Sneezer\ntuser.dat{a8670c0b-9d35-11df-a41f-001558a3bf4b}.TMContainer00000000000000000002.regtrans-ms -> [2010/08/01 13:17:09 | 000,524,288 | -HS- | M] ()
ntuser.dat_previous -> C:\Users\The Snappy Sneezer\ntuser.dat_previous -> [2010/08/01 13:14:04 | 008,912,896 | -HS- | M] ()
ntuser.dat{f547abbf-90e7-11df-b059-001558a3bf4b}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\The Snappy Sneezer\ntuser.dat{f547abbf-90e7-11df-b059-001558a3bf4b}.TMContainer00000000000000000001.regtrans-ms -> [2010/08/01 13:14:04 | 000,524,288 | -HS- | M] ()
ntuser.dat{f547abbf-90e7-11df-b059-001558a3bf4b}.TM.blf -> C:\Users\The Snappy Sneezer\ntuser.dat{f547abbf-90e7-11df-b059-001558a3bf4b}.TM.blf -> [2010/08/01 13:14:04 | 000,065,536 | -HS- | M] ()
Google Chrome.lnk -> C:\Users\Public\Desktop\Google Chrome.lnk -> [2010/07/27 19:41:01 | 000,002,025 | ---- | M] ()
Mozilla Thunderbird.lnk -> C:\Users\The Snappy Sneezer\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk -> [2010/07/23 10:21:35 | 000,001,868 | ---- | M] ()
Mozilla Thunderbird.lnk -> C:\Users\Public\Desktop\Mozilla Thunderbird.lnk -> [2010/07/23 10:21:35 | 000,001,844 | ---- | M] ()
hosts.20100801-202340.backup -> C:\Windows\SysNative\drivers\etc\hosts.20100801-202340.backup -> [2010/07/21 18:09:29 | 000,415,295 | R--- | M] ()
ntuser.dat{f547abbf-90e7-11df-b059-001558a3bf4b}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\The Snappy Sneezer\ntuser.dat{f547abbf-90e7-11df-b059-001558a3bf4b}.TMContainer00000000000000000002.regtrans-ms -> [2010/07/20 19:55:00 | 000,524,288 | -HS- | M] ()
ntuser.dat{77f1937d-7ab2-11df-bb7d-001558a3bf4b}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\The Snappy Sneezer\ntuser.dat{77f1937d-7ab2-11df-bb7d-001558a3bf4b}.TMContainer00000000000000000001.regtrans-ms -> [2010/07/20 19:44:36 | 000,524,288 | -HS- | M] ()
ntuser.dat{77f1937d-7ab2-11df-bb7d-001558a3bf4b}.TM.blf -> C:\Users\The Snappy Sneezer\ntuser.dat{77f1937d-7ab2-11df-bb7d-001558a3bf4b}.TM.blf -> [2010/07/20 19:44:36 | 000,065,536 | -HS- | M] ()
hosts.20100721-180929.backup -> C:\Windows\SysNative\drivers\etc\hosts.20100721-180929.backup -> [2010/07/15 11:08:00 | 000,412,695 | R--- | M] ()
avgtdia.sys -> C:\Windows\SysNative\drivers\avgtdia.sys -> [2010/07/15 10:53:08 | 000,317,520 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgrssta.dll -> C:\Windows\SysNative\avgrssta.dll -> [2010/07/15 10:53:04 | 000,013,048 | ---- | M] (AVG Technologies CZ, s.r.o.)
AVGIDSva.sys -> C:\Windows\SysNative\drivers\AVGIDSva.sys -> [2010/07/15 10:52:42 | 000,027,216 | ---- | M] (AVG Technologies CZ, s.r.o. )
avgldx64.sys -> C:\Windows\SysNative\drivers\avgldx64.sys -> [2010/07/15 10:51:36 | 000,269,904 | ---- | M] (AVG Technologies CZ, s.r.o.)
Doctor Who - The Adventure Games.lnk -> C:\Users\The Snappy Sneezer\Desktop\Doctor Who - The Adventure Games.lnk -> [2010/07/13 17:42:44 | 000,001,034 | ---- | M] ()
SciTE.session -> C:\Users\The Snappy Sneezer\SciTE.session -> [2010/07/12 18:34:20 | 000,000,281 | ---- | M] ()
Adobe Reader 9.lnk -> C:\Users\Public\Desktop\Adobe Reader 9.lnk -> [2010/07/07 22:02:16 | 000,001,917 | ---- | M] ()
PerfStringBackup.INI -> C:\Windows\SysNative\PerfStringBackup.INI -> [2010/07/04 21:50:35 | 001,171,298 | ---- | M] ()
perfh009.dat -> C:\Windows\SysNative\perfh009.dat -> [2010/07/04 21:50:35 | 000,598,350 | ---- | M] ()
perfh011.dat -> C:\Windows\SysNative\perfh011.dat -> [2010/07/04 21:50:35 | 000,384,738 | ---- | M] ()
perfc011.dat -> C:\Windows\SysNative\perfc011.dat -> [2010/07/04 21:50:35 | 000,101,988 | ---- | M] ()
perfc009.dat -> C:\Windows\SysNative\perfc009.dat -> [2010/07/04 21:50:35 | 000,101,988 | ---- | M] ()
8 C:\Users\The Snappy Sneezer\AppData\Local\Temp\*.tmp files -> C:\Users\The Snappy Sneezer\AppData\Local\Temp\*.tmp ->
3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp ->
3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp ->
1 C:\Users\The Snappy Sneezer\Desktop\*.tmp files -> C:\Users\The Snappy Sneezer\Desktop\*.tmp ->
1 C:\Users\The Snappy Sneezer\AppData\Local\Temp\HouseCall32\*.tmp files -> C:\Users\The Snappy Sneezer\AppData\Local\Temp\HouseCall32\*.tmp ->
1 C:\Users\The Snappy Sneezer\AppData\Local\Temp\HouseCall32\*.tmp files -> C:\Users\The Snappy Sneezer\AppData\Local\Temp\HouseCall32\*.tmp ->
1 C:\Users\The Snappy Sneezer\AppData\Local\Temp\HCBackup\*.tmp files -> C:\Users\The Snappy Sneezer\AppData\Local\Temp\HCBackup\*.tmp ->
[Files - No Company Name]
ntuser.dat{370d6715-7a40-1230-8133-001558a3bf4b}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\The Snappy Sneezer\ntuser.dat{370d6715-7a40-1230-8133-001558a3bf4b}.TMContainer00000000000000000002.regtrans-ms -> [2082/09/15 22:07:33 | 000,524,288 | -HS- | C] ()
ntuser.dat{370d6715-7a40-1230-8133-001558a3bf4b}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\The Snappy Sneezer\ntuser.dat{370d6715-7a40-1230-8133-001558a3bf4b}.TMContainer00000000000000000001.regtrans-ms -> [2082/09/15 22:07:32 | 000,524,288 | -HS- | C] ()
ntuser.dat{370d6715-7a40-1230-8133-001558a3bf4b}.TM.blf -> C:\Users\The Snappy Sneezer\ntuser.dat{370d6715-7a40-1230-8133-001558a3bf4b}.TM.blf -> [2082/09/15 22:07:32 | 000,065,536 | -HS- | C] ()
IconCache.db -> C:\Users\The Snappy Sneezer\AppData\Local\IconCache.db -> [2010/08/02 18:16:43 | 002,683,509 | -H-- | C] ()
gswin32.ini -> C:\Windows\gswin32.ini -> [2010/08/02 09:18:52 | 000,000,043 | ---- | C] ()
HiJackThis.lnk -> C:\Users\The Snappy Sneezer\Desktop\HiJackThis.lnk -> [2010/08/02 08:49:48 | 000,001,986 | ---- | C] ()
MEMORY.DMP -> C:\Windows\MEMORY.DMP -> [2010/08/01 22:26:50 | 423,107,059 | ---- | C] ()
ezsidmv.dat -> C:\Windows\SysWow64\ezsidmv.dat -> [2010/08/01 21:18:32 | 000,000,056 | -H-- | C] ()
OpenOffice.org 3.2.lnk -> C:\Users\Public\Desktop\OpenOffice.org 3.2.lnk -> [2010/08/01 21:10:58 | 000,001,027 | ---- | C] ()
dd_vcredistMSI711C.txt -> C:\Users\The Snappy Sneezer\AppData\Local\dd_vcredistMSI711C.txt -> [2010/08/01 20:59:49 | 000,549,334 | ---- | C] ()
dd_vcredistUI711C.txt -> C:\Users\The Snappy Sneezer\AppData\Local\dd_vcredistUI711C.txt -> [2010/08/01 20:59:47 | 000,023,272 | ---- | C] ()
Safari.lnk -> C:\Users\Public\Desktop\Safari.lnk -> [2010/08/01 20:56:43 | 000,001,866 | ---- | C] ()
Apple Safari.lnk -> C:\Users\The Snappy Sneezer\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk -> [2010/08/01 20:56:43 | 000,001,866 | ---- | C] ()
Spybot - Search & Destroy.lnk -> C:\Users\The Snappy Sneezer\Desktop\Spybot - Search & Destroy.lnk -> [2010/08/01 20:17:18 | 000,001,097 | ---- | C] ()
IrfanView Thumbnails.lnk -> C:\Users\The Snappy Sneezer\Desktop\IrfanView Thumbnails.lnk -> [2010/08/01 19:54:44 | 000,001,729 | ---- | C] ()
IrfanView.lnk -> C:\Users\The Snappy Sneezer\Desktop\IrfanView.lnk -> [2010/08/01 19:54:44 | 000,000,837 | ---- | C] ()
Update Checker.lnk -> C:\Users\The Snappy Sneezer\Desktop\Update Checker.lnk -> [2010/08/01 19:52:22 | 000,001,808 | ---- | C] ()
VLC media player.lnk -> C:\Users\Public\Desktop\VLC media player.lnk -> [2010/08/01 19:39:37 | 000,000,901 | ---- | C] ()
Mozilla Firefox 4.0 Beta 2.lnk -> C:\Users\The Snappy Sneezer\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox 4.0 Beta 2.lnk -> [2010/08/01 14:49:20 | 000,002,006 | ---- | C] ()
ntuser.dat{a8670c0b-9d35-11df-a41f-001558a3bf4b}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\The Snappy Sneezer\ntuser.dat{a8670c0b-9d35-11df-a41f-001558a3bf4b}.TMContainer00000000000000000002.regtrans-ms -> [2010/08/01 13:17:08 | 000,524,288 | -HS- | C] ()
ntuser.dat{a8670c0b-9d35-11df-a41f-001558a3bf4b}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\The Snappy Sneezer\ntuser.dat{a8670c0b-9d35-11df-a41f-001558a3bf4b}.TMContainer00000000000000000001.regtrans-ms -> [2010/08/01 13:17:08 | 000,524,288 | -HS- | C] ()
ntuser.dat{a8670c0b-9d35-11df-a41f-001558a3bf4b}.TM.blf -> C:\Users\The Snappy Sneezer\ntuser.dat{a8670c0b-9d35-11df-a41f-001558a3bf4b}.TM.blf -> [2010/08/01 13:17:07 | 000,065,536 | -HS- | C] ()
Mozilla Thunderbird.lnk -> C:\Users\The Snappy Sneezer\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk -> [2010/07/23 10:21:35 | 000,001,868 | ---- | C] ()
Mozilla Thunderbird.lnk -> C:\Users\Public\Desktop\Mozilla Thunderbird.lnk -> [2010/07/23 10:21:35 | 000,001,844 | ---- | C] ()
ntuser.dat{f547abbf-90e7-11df-b059-001558a3bf4b}.TMContainer00000000000000000002.regtrans-ms -> C:\Users\The Snappy Sneezer\ntuser.dat{f547abbf-90e7-11df-b059-001558a3bf4b}.TMContainer00000000000000000002.regtrans-ms -> [2010/07/20 19:47:05 | 000,524,288 | -HS- | C] ()
ntuser.dat{f547abbf-90e7-11df-b059-001558a3bf4b}.TMContainer00000000000000000001.regtrans-ms -> C:\Users\The Snappy Sneezer\ntuser.dat{f547abbf-90e7-11df-b059-001558a3bf4b}.TMContainer00000000000000000001.regtrans-ms -> [2010/07/20 19:47:05 | 000,524,288 | -HS- | C] ()
ntuser.dat{f547abbf-90e7-11df-b059-001558a3bf4b}.TM.blf -> C:\Users\The Snappy Sneezer\ntuser.dat{f547abbf-90e7-11df-b059-001558a3bf4b}.TM.blf -> [2010/07/20 19:47:05 | 000,065,536 | -HS- | C] ()
Doctor Who - The Adventure Games.lnk -> C:\Users\The Snappy Sneezer\Desktop\Doctor Who - The Adventure Games.lnk -> [2010/07/13 17:42:44 | 000,001,034 | ---- | C] ()
SciTE.session -> C:\Users\The Snappy Sneezer\SciTE.session -> [2010/07/12 18:34:20 | 000,000,281 | ---- | C] ()
MSVCRT10.DLL -> C:\Windows\SysWow64\MSVCRT10.DLL -> [2010/02/25 19:28:42 | 000,210,944 | ---- | C] ()
EhStorAuthn.dll -> C:\Windows\SysWow64\EhStorAuthn.dll -> [2010/01/06 01:05:57 | 000,117,248 | ---- | C] ()
msjetoledb40.dll -> C:\Windows\SysWow64\msjetoledb40.dll -> [2010/01/06 01:04:14 | 000,368,640 | ---- | C] ()
BlendSettings.ini -> C:\Windows\BlendSettings.ini -> [2009/06/17 09:43:18 | 000,000,023 | ---- | C] ()
lxdccomx.dll -> C:\Windows\SysWow64\lxdccomx.dll -> [2009/04/17 09:19:30 | 000,385,024 | ---- | C] ()
LXDCinst.dll -> C:\Windows\SysWow64\LXDCinst.dll -> [2009/04/17 09:19:30 | 000,286,720 | ---- | C] ()
PerfStringBackup.INI -> C:\Windows\SysWow64\PerfStringBackup.INI -> [2009/04/10 09:20:54 | 001,199,104 | ---- | C] ()
CDPlayer.ini -> C:\Windows\CDPlayer.ini -> [2009/04/10 06:32:56 | 000,055,946 | ---- | C] ()
WlanApp.dll -> C:\Windows\SysWow64\WlanApp.dll -> [2009/03/26 00:35:33 | 000,233,472 | ---- | C] ()
JJAKEn.dll -> C:\Windows\SysWow64\JJAKEn.dll -> [2009/03/26 00:35:33 | 000,049,152 | ---- | C] ()
CPPanel.INI -> C:\Windows\CPPanel.INI -> [2008/08/10 12:18:28 | 000,000,226 | ---- | C] ()
tcpmon.ini -> C:\Windows\SysWow64\tcpmon.ini -> [2008/07/21 15:20:04 | 000,060,124 | ---- | C] ()
primopdf.ini -> C:\Windows\primopdf.ini -> [2008/04/28 11:13:33 | 000,000,310 | ---- | C] ()
ODBC.INI -> C:\Windows\ODBC.INI -> [2008/03/08 11:56:30 | 000,000,140 | ---- | C] ()
wbload.dll -> C:\Windows\SysWow64\wbload.dll -> [2008/02/01 14:55:10 | 000,057,904 | ---- | C] ()
GlobalUserInterface.CompositeFont -> C:\Windows\Fonts\GlobalUserInterface.CompositeFont -> [2006/11/02 10:06:34 | 000,037,665 | ---- | C] ()
GlobalSerif.CompositeFont -> C:\Windows\Fonts\GlobalSerif.CompositeFont -> [2006/11/02 10:06:34 | 000,029,779 | ---- | C] ()
GlobalSansSerif.CompositeFont -> C:\Windows\Fonts\GlobalSansSerif.CompositeFont -> [2006/11/02 10:06:34 | 000,026,489 | ---- | C] ()
GlobalMonospace.CompositeFont -> C:\Windows\Fonts\GlobalMonospace.CompositeFont -> [2006/11/02 10:06:34 | 000,026,040 | ---- | C] ()
DMFileMan.dll -> C:\Windows\SysWow64\DMFileMan.dll -> [2006/05/10 06:47:52 | 000,045,056 | ---- | C] ()
SetBrowser.ini -> C:\Windows\SetBrowser.ini -> [2006/05/02 17:38:24 | 000,000,748 | ---- | C] ()
winamp.ini -> C:\Windows\winamp.ini -> [2003/04/02 10:18:22 | 000,000,024 | ---- | C] ()
[File - Lop Check]
360desktop -> C:\Users\The Snappy Sneezer\AppData\Roaming\360desktop -> [2009/12/11 00:34:12 | 000,000,000 | ---D | M]
Amazon -> C:\Users\The Snappy Sneezer\AppData\Roaming\Amazon -> [2008/08/20 17:05:53 | 000,000,000 | ---D | M]
Astro Gemini Software -> C:\Users\The Snappy Sneezer\AppData\Roaming\Astro Gemini Software -> [2010/03/03 16:18:28 | 000,000,000 | ---D | M]
BitTorrent -> C:\Users\The Snappy Sneezer\AppData\Roaming\BitTorrent -> [2010/02/07 15:37:42 | 000,000,000 | ---D | M]
Crazy Browser -> C:\Users\The Snappy Sneezer\AppData\Roaming\Crazy Browser -> [2008/09/07 21:40:01 | 000,000,000 | ---D | M]
cYo -> C:\Users\The Snappy Sneezer\AppData\Roaming\cYo -> [2010/01/30 10:30:51 | 000,000,000 | ---D | M]
Doctor Who -> C:\Users\The Snappy Sneezer\AppData\Roaming\Doctor Who -> [2010/06/03 00:08:13 | 000,000,000 | ---D | M]
DVD Profiler -> C:\Users\The Snappy Sneezer\AppData\Roaming\DVD Profiler -> [2009/09/26 19:25:51 | 000,000,000 | ---D | M]
Facebook -> C:\Users\The Snappy Sneezer\AppData\Roaming\Facebook -> [2010/05/05 17:47:34 | 000,000,000 | ---D | M]
Flock -> C:\Users\The Snappy Sneezer\AppData\Roaming\Flock -> [2010/04/16 21:34:03 | 000,000,000 | ---D | M]
foobar2000 -> C:\Users\The Snappy Sneezer\AppData\Roaming\foobar2000 -> [1982/09/15 19:39:18 | 000,000,000 | ---D | M]
IrfanView -> C:\Users\The Snappy Sneezer\AppData\Roaming\IrfanView -> [2010/01/20 10:22:39 | 000,000,000 | ---D | M]
Lexmark Productivity Studio -> C:\Users\The Snappy Sneezer\AppData\Roaming\Lexmark Productivity Studio -> [2009/04/17 09:26:02 | 000,000,000 | ---D | M]
Maxthon2 -> C:\Users\The Snappy Sneezer\AppData\Roaming\Maxthon2 -> [2010/01/05 09:29:03 | 000,000,000 | ---D | M]
MxBoost -> C:\Users\The Snappy Sneezer\AppData\Roaming\MxBoost -> [1980/01/29 12:49:30 | 000,000,000 | ---D | M]
Nikon -> C:\Users\The Snappy Sneezer\AppData\Roaming\Nikon -> [2008/10/13 19:41:47 | 000,000,000 | ---D | M]
PeerNetworking -> C:\Users\The Snappy Sneezer\AppData\Roaming\PeerNetworking -> [2010/02/07 13:50:12 | 000,000,000 | ---D | M]
QuickScan -> C:\Users\The Snappy Sneezer\AppData\Roaming\QuickScan -> [2010/02/01 23:37:42 | 000,000,000 | ---D | M]
RipIt4Me -> C:\Users\The Snappy Sneezer\AppData\Roaming\RipIt4Me -> [2008/12/01 08:16:25 | 000,000,000 | ---D | M]
SlimBrowser -> C:\Users\The Snappy Sneezer\AppData\Roaming\SlimBrowser -> [2009/12/08 11:55:52 | 000,000,000 | ---D | M]
Thunderbird -> C:\Users\The Snappy Sneezer\AppData\Roaming\Thunderbird -> [2010/08/01 13:13:12 | 000,000,000 | ---D | M]
Unity -> C:\Users\The Snappy Sneezer\AppData\Roaming\Unity -> [2010/03/30 02:56:01 | 000,000,000 | ---D | M]
SCHEDLGU.TXT -> C:\Windows\Tasks\SCHEDLGU.TXT -> [2010/08/02 18:17:42 | 000,032,616 | ---- | M] ()
User_Feed_Synchronization-{2AA8CDC9-044F-4892-AA03-7FF9A2A76CA8}.job -> C:\Windows\Tasks\User_Feed_Synchronization-{2AA8CDC9-044F-4892-AA03-7FF9A2A76CA8}.job -> [2010/08/03 10:05:42 | 000,000,444 | -H-- | M] ()
User_Feed_Synchronization-{43E3E63F-0764-4155-9501-BB842B477FE2}.job -> C:\Windows\Tasks\User_Feed_Synchronization-{43E3E63F-0764-4155-9501-BB842B477FE2}.job -> [2010/08/03 10:04:59 | 000,000,416 | -H-- | M] ()
[File - Purity Scan]
[Alternate Data Streams]
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:EBC2DB92
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:8331D35A
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:D1B5B4F1
< End of report >
[/code]
Merged 2 posts and removed one. ~ OB
Edited by Orange Blossom, 04 August 2010 - 11:56 PM.