Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Random audio ads


  • This topic is locked This topic is locked
39 replies to this topic

#1 LAFitzou

LAFitzou

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:04:51 PM

Posted 27 July 2014 - 10:38 AM

Suddenly I start hearing random audio ads playing on my 64 bit Windows 7...so I ran FRST and turned up the following.  Can anyone advise me on what to do now?

 

Laurie

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-07-2014
Ran by Laurie (ATTENTION: The logged in user is not administrator) on ORGMIND on 27-07-2014 09:28:52
Running from C:\Users\Laurie\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Emsisoft GmbH) C:\Program Files (x86)\Online Armor\OAui.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Emsisoft GmbH) C:\Program Files (x86)\Online Armor\OAhlp.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\BT\BTTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\V9\TeamViewer.exe
() C:\Users\test\Desktop\Laurie\AppData\Local\GVMateApp\RTCBrowser\RTCBrowser.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
(Mozilla Corporation) C:\Program Files (x86)\MozFirefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\MozFirefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2538280 2011-01-13] (Synaptics Incorporated)
HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [862088 2011-01-28] (Acer Incorporated)
HKLM\...\Run: [@OnlineArmor GUI] => C:\Program Files (x86)\Online Armor\OAui.exe [7558464 2013-10-15] (Emsisoft GmbH)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1081424 2011-03-14] (Dritek System Inc.)
HKLM-x32\...\Run: [emsisoft anti-malware] => c:\program files (x86)\emsisoft anti-malware\a2guard.exe [4841824 2014-07-09] (Emsisoft GmbH)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-03] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-07-08] (Apple Inc.)
HKU\.DEFAULT\...\Run: [cdloader] => "C:\Windows\system32\config\systemprofile\AppData\Roaming\mjusbsp\cdloader2.exe" MAGICJACK
HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-206095162-3907483975-2766088746-1014\...\Run: [Google Update] => C:\Users\Laurie\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-06-10] (Google Inc.)
HKU\S-1-5-21-206095162-3907483975-2766088746-1014\...\Run: [VideoDownloaderUltimate] => C:\ProgramData\VideoDownloaderUltimateWinApp\VideoDownloaderUltimate.exe [697976 2014-06-28] (Link64 GmbH)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\BT\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\setup2.exe (magicJack L.P.)
Startup: C:\Users\Laurie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GVMateApp.lnk
ShortcutTarget: GVMateApp.lnk -> C:\Users\Laurie\AppData\Local\GVMateApp\GVMateApp.exe ()
ShellIconOverlayIdentifiers:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers: GDriveSharedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  No File
ShellIconOverlayIdentifiers: ShellExt1 -> {2012DE06-50C0-48BD-ACDE-88F95D4CAD1F} => C:\PROGRA~2\4Sync\ShellExt.dll No File
ShellIconOverlayIdentifiers: ShellExt2 -> {C72C6188-BEF2-46E5-A89A-52F0ED75219E} => C:\PROGRA~2\4Sync\ShellExt.dll No File
ShellIconOverlayIdentifiers: ShellExt3 -> {C92F6BC2-AF61-4C0E-80E0-939B8282DDB7} => C:\PROGRA~2\4Sync\ShellExt.dll No File
ShellIconOverlayIdentifiers: ShellExt4 -> {CB1EFEF8-D5E0-49D1-B768-41B48B1D7803} => C:\PROGRA~2\4Sync\ShellExt.dll No File
ShellIconOverlayIdentifiers-x32:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
BootExecute:

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 205.171.2.25
Tcpip\..\Interfaces\{0D01DE1E-0EFC-41CC-AE51-F14B0A22E4F6}: [NameServer]192.168.0.1,205.171.3.25

FireFox:
========
FF ProfilePath: C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rj5y4zuc.default-1404055395082
FF Homepage: hxxp://www.google.com
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @java.com/DTPlugin,version=10.65.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.65.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Laurie\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Laurie\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Laurie\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Laurie\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Laurie\AppData\Roaming\mozilla\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\Laurie\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Laurie\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF Extension: Flash Video Downloader - Full HD Download - C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rj5y4zuc.default-1404055395082\Extensions\artur.dubovoy@gmail.com [2014-07-15]
FF Extension: 1-Click YouTube Video Downloader - C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rj5y4zuc.default-1404055395082\Extensions\YoutubeDownloader@PeterOlayev.com.xpi [2014-07-15]
FF Extension: Easy Youtube Video Downloader Express - C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rj5y4zuc.default-1404055395082\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2014-07-16]
FF Extension: Fast Video Download - C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rj5y4zuc.default-1404055395082\Extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}.xpi [2014-07-16]
FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\MozFirefox\firefox.exe

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 a2AntiMalware; C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [4741384 2014-07-09] (Emsisoft GmbH)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 ftpsvc; C:\Windows\system32\inetsrv\ftpsvc.dll [350720 2012-05-31] (Microsoft Corporation)
R2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2013-11-18] (Nero AG)
R2 OAcat; C:\Program Files (x86)\Online Armor\OAcat.exe [584864 2013-10-15] (Emsisoft GmbH)
S3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [36352 2010-08-20] () [File not signed]
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed]
R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-29] (Acer Incorporated)
R2 Srvany Service; C:\Windows\System32\srvany.exe [8192 2003-04-18] () [File not signed]
R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [728328 2014-04-11] (DEVGURU Co., LTD.)
R2 SvcOnlineArmor; C:\Program Files (x86)\Online Armor\oasrv.exe [4457688 2013-10-15] (Emsisoft GmbH)
R2 TeamViewer9; C:\Program Files (x86)\TeamViewer\V9\TeamViewer_Service.exe [5037888 2014-07-02] (TeamViewer GmbH)
R2 UTSCSI; C:\Windows\SysWOW64\UTSCSI.EXE [45056 2012-10-16] () [File not signed]
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 a2acc; C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [71472 2014-05-12] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [26176 2013-04-03] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys [45208 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys [23088 2014-05-12] (Emsisoft GmbH)
S3 ampa; C:\Windows\system32\ampa.sys [15288 2011-12-26] () [File not signed]
S3 ampa; C:\Windows\SysWOW64\ampa.sys [12728 2011-12-26] () [File not signed]
S2 Aspi32; C:\Windows\SysWOW64\drivers\aspi32.sys [16877 2002-07-17] (Adaptec) [File not signed]
S3 bthav; C:\Windows\System32\drivers\bthav.sys [40448 2008-07-10] (CSR, plc)
R3 cleanhlp; C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [57024 2013-12-04] (Emsisoft GmbH)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [32512 2013-09-16] ()
R3 k57nd; C:\Windows\System32\DRIVERS\k57amd64.sys [333864 2009-12-11] (Broadcom Corporation)
R1 OADevice; C:\Windows\SysWow64\Drivers\OADriver.sys [64720 2013-10-15] ()
R1 oahlpXX; C:\Windows\syswow64\drivers\oahlp64.sys [62008 2013-10-15] ()
R1 OAmon; C:\Windows\SysWOW64\Drivers\OAmon.sys [52360 2013-10-15] (Emsisoft)
R3 OAnet; C:\Windows\System32\DRIVERS\oanet.sys [35368 2013-10-15] (Emsisoft)
S3 ptun0901; C:\Windows\System32\DRIVERS\ptun0901.sys [40664 2014-03-10] (The OpenVPN Project)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
S3 tap0801; C:\Windows\System32\DRIVERS\tap0801.sys [30720 2005-04-13] (The OpenVPN Project) [File not signed]
S3 AthBTPort; system32\DRIVERS\btath_flt.sys [X]
S3 BTATH_A2DP; system32\drivers\btath_a2dp.sys [X]
S3 BTATH_BUS; system32\DRIVERS\btath_bus.sys [X]
S3 BTATH_HCRP; system32\DRIVERS\btath_hcrp.sys [X]
S3 BTATH_LWFLT; system32\DRIVERS\btath_lwflt.sys [X]
S3 BTATH_RCP; system32\DRIVERS\btath_rcp.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-07-27 09:28 - 2014-07-27 09:28 - 00017502 _____ () C:\Users\Laurie\Desktop\FRST.txt
2014-07-27 09:14 - 2014-07-27 09:14 - 02093568 _____ (Farbar) C:\Users\Laurie\Desktop\FRST64.exe
2014-07-27 08:52 - 2014-07-27 08:52 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\Laurie\Desktop\tdsskiller.exe
2014-07-25 15:52 - 2014-07-25 15:57 - 27226082 _____ (PCPhoneSoft.com ) C:\Users\Laurie\Desktop\gvjackappsetup110.exe
2014-07-25 14:27 - 2014-07-25 14:27 - 00895120 _____ (Google Inc.) C:\Users\Laurie\Desktop\GoogleVoiceAndVideoSetup(1).exe
2014-07-25 14:23 - 2014-07-25 14:23 - 00003948 _____ () C:\Users\Laurie\Desktop\gvmateapp2notes.txt
2014-07-25 11:59 - 2014-07-25 11:59 - 00417792 _____ () C:\Users\Laurie\Downloads\GVMateApp.exe
2014-07-25 11:39 - 2014-07-25 14:22 - 00001074 _____ () C:\Users\Laurie\Desktop\GVMateApp.lnk
2014-07-25 11:31 - 2014-07-25 11:36 - 24295422 _____ (PCPhoneSoft.com ) C:\Users\Laurie\Desktop\gvmateapp2setup.exe
2014-07-25 11:13 - 2014-07-25 11:13 - 00012257 _____ () C:\Users\Laurie\Desktop\GVJack LicDeny.bmp
2014-07-25 10:24 - 2014-07-25 10:24 - 00895120 _____ (Google Inc.) C:\Users\Laurie\Desktop\GoogleVoiceAndVideoSetup.exe
2014-07-23 08:09 - 2014-07-23 08:10 - 00000000 ____D () C:\Program Files (x86)\MozFirefox
2014-07-19 09:45 - 2014-07-19 09:44 - 00319912 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-07-19 09:45 - 2014-07-19 09:44 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-07-19 09:45 - 2014-07-19 09:44 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-07-19 08:19 - 2014-07-19 08:19 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-ORGMIND-Microsoft-Windows-7-Home-Premium-(64-bit).dat
2014-07-19 08:18 - 2014-07-19 08:18 - 00000000 ____D () C:\RegBackup
2014-07-19 08:16 - 2014-07-19 08:16 - 00001844 _____ () C:\Users\Laurie\Desktop\WinRepair.lnk
2014-07-19 08:16 - 2014-07-19 08:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2014-07-19 08:16 - 2014-07-19 08:16 - 00000000 ____D () C:\Program Files (x86)\Win Repair
2014-07-19 08:12 - 2014-07-19 08:16 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-07-19 07:32 - 2014-07-19 09:44 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-07-19 07:17 - 2014-07-19 07:17 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-07-19 07:10 - 2014-07-19 07:17 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-07-19 07:10 - 2014-07-19 07:17 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-07-19 07:10 - 2014-07-19 07:17 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-19 07:10 - 2014-07-19 07:10 - 00004191 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-18 09:30 - 2014-07-18 09:30 - 00000000 ____D () C:\ProgramData\Reimage Protector
2014-07-18 09:23 - 2014-07-18 09:23 - 00000000 ____D () C:\Program Files\Reimage
2014-07-18 09:20 - 2014-07-19 06:52 - 00000000 ____D () C:\rei
2014-07-16 09:52 - 2014-07-16 09:52 - 00000000 ____D () C:\Program Files (x86)\Trusteer
2014-07-16 09:49 - 2014-07-16 09:49 - 00000000 ____D () C:\ProgramData\Trusteer
2014-07-16 08:05 - 2014-07-19 06:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-07-16 08:05 - 2014-07-16 08:05 - 00001750 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-07-16 08:04 - 2014-07-16 08:05 - 00000000 ____D () C:\Program Files\iTunes
2014-07-13 18:59 - 2014-07-27 09:28 - 00000000 ____D () C:\FRST
2014-07-13 15:08 - 2014-07-19 06:53 - 00000000 ____D () C:\EEK
2014-07-13 15:08 - 2014-07-13 15:08 - 00000553 _____ () C:\Users\Laurie\Desktop\Emsisoft E-Kit.lnk
2014-07-10 23:27 - 2014-07-12 00:27 - 05659136 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-07-09 22:14 - 2014-06-29 20:09 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-09 22:14 - 2014-06-29 20:04 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-09 22:14 - 2014-05-30 02:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-09 22:14 - 2014-05-30 02:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-09 22:14 - 2014-05-30 02:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-09 22:14 - 2014-05-30 02:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-09 22:14 - 2014-05-30 02:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-09 22:14 - 2014-05-30 02:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-09 22:14 - 2014-05-30 01:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-09 22:14 - 2014-05-30 01:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-09 22:14 - 2014-05-30 01:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-09 22:14 - 2014-05-30 01:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-09 22:14 - 2014-05-30 01:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-09 22:14 - 2014-05-30 01:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-09 22:13 - 2014-06-20 14:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-09 22:13 - 2014-06-20 13:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-09 22:13 - 2014-06-18 19:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 22:13 - 2014-06-18 19:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 22:13 - 2014-06-18 19:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-09 22:13 - 2014-06-18 18:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 22:13 - 2014-06-18 18:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 22:13 - 2014-06-18 18:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-09 22:13 - 2014-06-18 18:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-09 22:13 - 2014-06-18 18:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-09 22:13 - 2014-06-18 18:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 22:13 - 2014-06-18 18:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-09 22:13 - 2014-06-18 18:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 22:13 - 2014-06-18 18:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 22:13 - 2014-06-18 18:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-09 22:13 - 2014-06-18 18:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-09 22:13 - 2014-06-18 18:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-09 22:13 - 2014-06-18 18:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-09 22:13 - 2014-06-18 18:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 22:13 - 2014-06-18 17:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 22:13 - 2014-06-18 17:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-09 22:13 - 2014-06-18 17:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-09 22:13 - 2014-06-18 17:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 22:13 - 2014-06-18 17:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 22:13 - 2014-06-18 17:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 22:13 - 2014-06-18 17:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-09 22:13 - 2014-06-18 17:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-09 22:13 - 2014-06-18 17:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-09 22:13 - 2014-06-18 17:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-09 22:13 - 2014-06-18 17:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-09 22:13 - 2014-06-18 17:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 22:13 - 2014-06-18 17:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-09 22:13 - 2014-06-18 17:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-09 22:13 - 2014-06-18 17:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-09 22:13 - 2014-06-18 17:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 22:13 - 2014-06-18 17:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-09 22:13 - 2014-06-18 17:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-09 22:13 - 2014-06-18 17:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-09 22:13 - 2014-06-18 17:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-09 22:13 - 2014-06-18 17:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-09 22:13 - 2014-06-18 17:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-09 22:13 - 2014-06-18 17:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-09 22:13 - 2014-06-18 16:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-09 22:13 - 2014-06-18 16:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 22:13 - 2014-06-18 16:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-09 22:13 - 2014-06-18 16:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-09 22:13 - 2014-06-18 16:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 22:13 - 2014-06-18 16:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-09 22:13 - 2014-06-18 16:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-09 22:13 - 2014-06-18 16:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-09 22:13 - 2014-06-18 16:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-09 22:13 - 2014-06-18 16:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 22:13 - 2014-06-18 16:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-09 22:13 - 2014-06-18 16:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-09 22:13 - 2014-06-18 16:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-09 22:13 - 2014-06-18 16:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-09 22:13 - 2014-06-17 20:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-09 22:13 - 2014-06-17 19:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-09 22:13 - 2014-06-17 19:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 22:13 - 2014-06-05 08:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-09 22:13 - 2014-06-05 08:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-09 22:13 - 2014-06-05 08:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-07-09 22:13 - 2014-05-30 02:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-09 22:13 - 2014-05-30 01:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-09 22:11 - 2014-06-06 04:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 22:11 - 2014-06-06 03:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-09 22:11 - 2014-05-30 00:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-03 14:39 - 2014-07-26 15:03 - 00014568 _____ () C:\Windows\SysWOW64\devmon.log
2014-07-03 14:37 - 2014-07-26 15:02 - 00001261 _____ () C:\Windows\setupact.log
2014-07-03 14:37 - 2014-07-03 14:37 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-03 14:36 - 2014-07-15 07:38 - 00000908 _____ () C:\Windows\PFRO.log
2014-07-03 11:01 - 2014-07-03 11:19 - 00000000 ____D () C:\Users\Laurie\AppData\Roaming\Wise Registry Cleaner
2014-07-03 10:23 - 2014-07-03 11:01 - 00000000 ____D () C:\Users\Laurie\AppData\Roaming\Wise Disk Cleaner
2014-07-02 08:42 - 2014-07-26 15:12 - 00000000 ____D () C:\Users\Laurie\Desktop\Dearborn
2014-07-01 09:12 - 2014-07-01 09:12 - 00000000 ___RD () C:\Users\Laurie\Google Drive
2014-06-30 11:08 - 2014-06-30 11:09 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-30 11:02 - 2014-06-30 11:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-30 11:02 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-30 11:02 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-30 10:59 - 2014-06-30 11:02 - 00000000 ____D () C:\Users\Laurie\AppData\Roaming\Malwarebytes
2014-06-30 10:31 - 2014-06-30 10:31 - 00000000 ____D () C:\Windows\ERUNT
2014-06-30 10:03 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-30 08:39 - 2014-06-30 08:40 - 20910613 _____ () C:\Users\Laurie\Downloads\moonshine_m7_1.26.502.12.zip
2014-06-29 13:37 - 2014-06-29 13:37 - 00000000 ____D () C:\Users\Laurie\AppData\Roaming\WinRAR
2014-06-29 13:35 - 2014-06-29 20:01 - 00000664 _____ () C:\Users\Public\Desktop\Mini-ADB-FB.lnk
2014-06-29 12:57 - 2014-06-29 13:04 - 289716525 _____ () C:\Users\Laurie\Downloads\pa_gapps-stock-4.4.4-20140629-signed.zip
2014-06-29 02:55 - 2014-06-29 02:55 - 00000000 ____D () C:\ProgramData\Emsisoft
2014-06-28 11:12 - 2014-06-28 11:31 - 00000000 ____D () C:\Users\Laurie\Desktop\VidMP3
2014-06-28 11:05 - 2014-06-28 11:21 - 00000000 ____D () C:\ProgramData\VideoDownloaderUltimateWinApp
2014-06-28 11:05 - 2014-06-28 11:17 - 00000897 _____ () C:\Users\Laurie\Desktop\VidDown.lnk

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-07-27 09:29 - 2014-07-27 09:28 - 00017502 _____ () C:\Users\Laurie\Desktop\FRST.txt
2014-07-27 09:29 - 2014-06-15 17:08 - 00000000 ____D () C:\Temp
2014-07-27 09:28 - 2014-07-13 18:59 - 00000000 ____D () C:\FRST
2014-07-27 09:27 - 2014-01-20 17:44 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-27 09:21 - 2014-06-10 12:10 - 00000912 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1014UA.job
2014-07-27 09:17 - 2014-05-12 17:11 - 00000912 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1001UA.job
2014-07-27 09:14 - 2014-07-27 09:14 - 02093568 _____ (Farbar) C:\Users\Laurie\Desktop\FRST64.exe
2014-07-27 09:04 - 2012-07-15 15:55 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Anti-Malware
2014-07-27 08:52 - 2014-07-27 08:52 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\Laurie\Desktop\tdsskiller.exe
2014-07-27 08:50 - 2012-11-29 13:14 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-27 08:45 - 2014-05-12 17:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GVMateApp
2014-07-27 05:58 - 2012-07-15 11:22 - 01405462 _____ () C:\Windows\WindowsUpdate.log
2014-07-27 02:50 - 2012-11-29 13:14 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-27 02:00 - 2013-05-18 14:42 - 00000000 ____D () C:\Users\DefaultAppPool.IIS APPPOOL.000
2014-07-26 17:20 - 2014-05-12 17:11 - 00000860 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1001Core.job
2014-07-26 15:12 - 2014-07-02 08:42 - 00000000 ____D () C:\Users\Laurie\Desktop\Dearborn
2014-07-26 15:03 - 2014-07-03 14:39 - 00014568 _____ () C:\Windows\SysWOW64\devmon.log
2014-07-26 15:02 - 2014-07-03 14:37 - 00001261 _____ () C:\Windows\setupact.log
2014-07-26 11:21 - 2014-06-10 12:10 - 00000860 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1014Core.job
2014-07-25 19:01 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\tracing
2014-07-25 15:57 - 2014-07-25 15:52 - 27226082 _____ (PCPhoneSoft.com ) C:\Users\Laurie\Desktop\gvjackappsetup110.exe
2014-07-25 15:42 - 2009-07-13 22:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-25 15:42 - 2009-07-13 22:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-25 14:27 - 2014-07-25 14:27 - 00895120 _____ (Google Inc.) C:\Users\Laurie\Desktop\GoogleVoiceAndVideoSetup(1).exe
2014-07-25 14:23 - 2014-07-25 14:23 - 00003948 _____ () C:\Users\Laurie\Desktop\gvmateapp2notes.txt
2014-07-25 14:22 - 2014-07-25 11:39 - 00001074 _____ () C:\Users\Laurie\Desktop\GVMateApp.lnk
2014-07-25 11:59 - 2014-07-25 11:59 - 00417792 _____ () C:\Users\Laurie\Downloads\GVMateApp.exe
2014-07-25 11:36 - 2014-07-25 11:31 - 24295422 _____ (PCPhoneSoft.com ) C:\Users\Laurie\Desktop\gvmateapp2setup.exe
2014-07-25 11:13 - 2014-07-25 11:13 - 00012257 _____ () C:\Users\Laurie\Desktop\GVJack LicDeny.bmp
2014-07-25 10:24 - 2014-07-25 10:24 - 00895120 _____ (Google Inc.) C:\Users\Laurie\Desktop\GoogleVoiceAndVideoSetup.exe
2014-07-25 10:07 - 2012-10-19 16:49 - 00000326 _____ () C:\Windows\Tasks\GlaryInitialize.job
2014-07-25 10:06 - 2012-10-17 16:52 - 00000346 _____ () C:\Windows\Tasks\UpdateDetector.job
2014-07-25 10:05 - 2012-07-17 08:21 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-07-25 10:05 - 2009-07-13 23:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-25 10:03 - 2012-09-10 05:18 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-07-25 10:03 - 2012-09-10 05:18 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-07-25 10:03 - 2012-07-15 13:46 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-07-25 09:04 - 2012-09-10 05:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-07-23 08:10 - 2014-07-23 08:09 - 00000000 ____D () C:\Program Files (x86)\MozFirefox
2014-07-22 06:57 - 2013-02-09 21:19 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-07-21 09:36 - 2012-11-05 10:49 - 00000432 _____ () C:\Windows\Tasks\Wise Disk Cleaner Schedule Task.job
2014-07-19 09:44 - 2014-07-19 09:45 - 00319912 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-07-19 09:44 - 2014-07-19 09:45 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-07-19 09:44 - 2014-07-19 09:45 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-07-19 09:44 - 2014-07-19 07:32 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-07-19 09:13 - 2009-07-13 22:45 - 00288904 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-19 08:19 - 2014-07-19 08:19 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-ORGMIND-Microsoft-Windows-7-Home-Premium-(64-bit).dat
2014-07-19 08:18 - 2014-07-19 08:18 - 00000000 ____D () C:\RegBackup
2014-07-19 08:18 - 2013-10-08 10:06 - 00000000 ____D () C:\ProgramData\Oracle
2014-07-19 08:16 - 2014-07-19 08:16 - 00001844 _____ () C:\Users\Laurie\Desktop\WinRepair.lnk
2014-07-19 08:16 - 2014-07-19 08:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2014-07-19 08:16 - 2014-07-19 08:16 - 00000000 ____D () C:\Program Files (x86)\Win Repair
2014-07-19 08:16 - 2014-07-19 08:12 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-07-19 07:17 - 2014-07-19 07:17 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-07-19 07:17 - 2014-07-19 07:10 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-07-19 07:17 - 2014-07-19 07:10 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-07-19 07:17 - 2014-07-19 07:10 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-19 07:10 - 2014-07-19 07:10 - 00004191 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-19 07:10 - 2013-03-16 07:51 - 00000000 ____D () C:\Program Files (x86)\Java
2014-07-19 07:03 - 2014-06-09 19:22 - 00000000 ____D () C:\Users\Laurie\Desktop\Mal-Fix
2014-07-19 07:02 - 2014-06-09 19:12 - 00000000 ____D () C:\Users\Laurie
2014-07-19 06:53 - 2014-07-16 08:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-07-19 06:53 - 2014-07-13 15:08 - 00000000 ____D () C:\EEK
2014-07-19 06:53 - 2014-06-09 17:41 - 00000000 ____D () C:\Users\test
2014-07-19 06:53 - 2013-12-18 13:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-07-19 06:53 - 2013-10-08 10:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-19 06:52 - 2014-07-18 09:20 - 00000000 ____D () C:\rei
2014-07-19 06:52 - 2013-05-09 16:01 - 00000000 ____D () C:\Windows\Minidump
2014-07-19 06:52 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\registration
2014-07-18 09:30 - 2014-07-18 09:30 - 00000000 ____D () C:\ProgramData\Reimage Protector
2014-07-18 09:23 - 2014-07-18 09:23 - 00000000 ____D () C:\Program Files\Reimage
2014-07-16 09:52 - 2014-07-16 09:52 - 00000000 ____D () C:\Program Files (x86)\Trusteer
2014-07-16 09:49 - 2014-07-16 09:49 - 00000000 ____D () C:\ProgramData\Trusteer
2014-07-16 08:05 - 2014-07-16 08:05 - 00001750 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-07-16 08:05 - 2014-07-16 08:04 - 00000000 ____D () C:\Program Files\iTunes
2014-07-16 08:05 - 2013-12-24 10:09 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-07-16 08:05 - 2013-12-24 10:09 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-07-16 08:04 - 2013-12-24 10:09 - 00000000 ____D () C:\Program Files\iPod
2014-07-15 07:38 - 2014-07-03 14:36 - 00000908 _____ () C:\Windows\PFRO.log
2014-07-15 07:36 - 2013-09-16 09:19 - 00000000 ____D () C:\AdwCleaner
2014-07-13 15:08 - 2014-07-13 15:08 - 00000553 _____ () C:\Users\Laurie\Desktop\Emsisoft E-Kit.lnk
2014-07-12 00:28 - 2014-01-20 17:44 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-12 00:28 - 2014-01-20 17:44 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-12 00:27 - 2014-07-10 23:27 - 05659136 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-07-10 08:25 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\rescache
2014-07-10 06:59 - 2014-04-28 08:23 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-10 06:59 - 2010-11-21 01:17 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-10 06:59 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-10 06:59 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-09 22:23 - 2013-07-15 14:12 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-09 22:22 - 2013-12-12 19:16 - 00014022 _____ () C:\Windows\system32\TeamViewer9_Hooks.log
2014-07-09 22:20 - 2014-06-26 23:16 - 00001021 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-07-09 22:16 - 2012-07-17 19:02 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-03 19:01 - 2009-07-13 23:13 - 00826254 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-03 14:37 - 2014-07-03 14:37 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-03 11:19 - 2014-07-03 11:01 - 00000000 ____D () C:\Users\Laurie\AppData\Roaming\Wise Registry Cleaner
2014-07-03 11:01 - 2014-07-03 10:23 - 00000000 ____D () C:\Users\Laurie\AppData\Roaming\Wise Disk Cleaner
2014-07-01 10:28 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\TAPI
2014-07-01 09:16 - 2012-07-23 10:56 - 00000000 ____D () C:\Program Files (x86)\Google
2014-07-01 09:12 - 2014-07-01 09:12 - 00000000 ___RD () C:\Users\Laurie\Google Drive
2014-06-30 21:08 - 2012-07-15 17:06 - 00000000 ____D () C:\Program Files (x86)\Wise
2014-06-30 11:09 - 2014-06-30 11:08 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-30 11:03 - 2013-09-16 09:51 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes
2014-06-30 11:02 - 2014-06-30 11:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-30 11:02 - 2014-06-30 10:59 - 00000000 ____D () C:\Users\Laurie\AppData\Roaming\Malwarebytes
2014-06-30 11:02 - 2013-09-16 09:51 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-30 10:31 - 2014-06-30 10:31 - 00000000 ____D () C:\Windows\ERUNT
2014-06-30 08:40 - 2014-06-30 08:39 - 20910613 _____ () C:\Users\Laurie\Downloads\moonshine_m7_1.26.502.12.zip
2014-06-29 20:09 - 2014-07-09 22:14 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-29 20:04 - 2014-07-09 22:14 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-29 20:01 - 2014-06-29 13:35 - 00000664 _____ () C:\Users\Public\Desktop\Mini-ADB-FB.lnk
2014-06-29 13:37 - 2014-06-29 13:37 - 00000000 ____D () C:\Users\Laurie\AppData\Roaming\WinRAR
2014-06-29 13:04 - 2014-06-29 12:57 - 289716525 _____ () C:\Users\Laurie\Downloads\pa_gapps-stock-4.4.4-20140629-signed.zip
2014-06-29 12:31 - 2012-02-21 15:57 - 00000000 ____D () C:\ruu_log
2014-06-29 08:24 - 2014-06-09 19:23 - 00000000 ____D () C:\Users\Laurie\Desktop\Tunes
2014-06-29 08:05 - 2014-06-15 15:20 - 00000000 ____D () C:\Program Files (x86)\MP3to MP3
2014-06-29 02:55 - 2014-06-29 02:55 - 00000000 ____D () C:\ProgramData\Emsisoft
2014-06-28 11:31 - 2014-06-28 11:12 - 00000000 ____D () C:\Users\Laurie\Desktop\VidMP3
2014-06-28 11:22 - 2013-12-11 09:56 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-06-28 11:21 - 2014-06-28 11:05 - 00000000 ____D () C:\ProgramData\VideoDownloaderUltimateWinApp
2014-06-28 11:17 - 2014-06-28 11:05 - 00000897 _____ () C:\Users\Laurie\Desktop\VidDown.lnk

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

==================== End Of Log ============================


Edited by hamluis, 27 July 2014 - 11:33 AM.
Moved from Win 7 to Malware Removal Logs - Hamluis.


BC AdBot (Login to Remove)

 


#2 LAFitzou

LAFitzou
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:04:51 PM

Posted 27 July 2014 - 06:25 PM

I'm not sure what this all means.  I don't see any instructions.  Am I clean...or what?

 

Laurie



#3 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 38,133 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:51 AM

Posted 31 July 2014 - 06:02 PM

Greetings Laurie and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met. :)
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
  • Now let's get started :thumbup2:
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far and I apologize for the delay. We are quite busy these days. While I review our situation please run the below for me as I need current FRST logs.

===================================================

Farbar Recovery Scan Tool (FRST)

--------------------
  • Download Farbar Recover Scan Tool for either 32 bit or 64 bit systems and save it to your desktop <<< Important
  • If you are unsure if you have 32 bit or 64 bit simply download and try one. If that doesn't run properly the other one should
  • Double click the icon
  • Click Yes to the disclaimer
  • Make sure the Addition.txt box is checked
  • Click Scan and allow the program to run
  • Click OK on the Scan complete screen, then OK on the Addition.txt pop up screen
  • 2 Notepad documents should now be open on your desktop.
  • Please copy and paste the contents of both in your reply
  • Copy/paste the following in the Search Field
rpcss.dll
  • Click Search File(s) button
  • When completed click OK and a Search.txt document will open on your desktop
  • Copy and paste the contents of that document your reply
===================================================

System Summary Information

--------------------
  • Press the windows key Windows_Logo_key.gif + r on your keyboard at the same time
  • Type msinfo32 and press Enter
  • Left click on System Summary
  • Click File, Save, and name the file Summary
  • Zip and attach the file to your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • FRST results
  • Addition log
  • Search log
  • System Summary Information

Edited by Oh My!, 31 July 2014 - 06:04 PM.

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#4 LAFitzou

LAFitzou
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:04:51 PM

Posted 01 August 2014 - 11:09 AM

Thanks in advance Gary.  I promise to be patient and appreciate your help.  Hopefully the following is what you asked to be pasted.  In addition to the ZIP file, I have also attached a screen image (bmp) of the first of 7 error messages that appear while running FRST64.  I'm not sure whether these are significant since the program seems to run ok after I dismiss them.

 

Laurie

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-07-2014 02
Ran by Laurie (ATTENTION: The logged in user is not administrator) on ORGMIND on 01-08-2014 09:29:11
Running from C:\Users\Laurie\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Emsisoft GmbH) C:\Program Files (x86)\Online Armor\OAui.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Emsisoft GmbH) C:\Program Files (x86)\Online Armor\OAhlp.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\BT\BTTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
() C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\V9\TeamViewer.exe
(Privax) C:\Program Files (x86)\HMA! Pro VPN\bin\HMA! Pro VPN.exe
(Mozilla Corporation) C:\Program Files (x86)\MozFirefox\firefox.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2538280 2011-01-13] (Synaptics Incorporated)
HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [862088 2011-01-28] (Acer Incorporated)
HKLM\...\Run: [@OnlineArmor GUI] => C:\Program Files (x86)\Online Armor\OAui.exe [7558464 2013-10-15] (Emsisoft GmbH)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1081424 2011-03-14] (Dritek System Inc.)
HKLM-x32\...\Run: [emsisoft anti-malware] => c:\program files (x86)\emsisoft anti-malware\a2guard.exe [4841824 2014-07-09] (Emsisoft GmbH)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-03] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-07-08] (Apple Inc.)
HKU\.DEFAULT\...\Run: [cdloader] => "C:\Windows\system32\config\systemprofile\AppData\Roaming\mjusbsp\cdloader2.exe" MAGICJACK
HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-206095162-3907483975-2766088746-1014\...\Run: [Google Update] => C:\Users\Laurie\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-06-10] (Google Inc.)
HKU\S-1-5-21-206095162-3907483975-2766088746-1014\...\Run: [VideoDownloaderUltimate] => C:\ProgramData\VideoDownloaderUltimateWinApp\VideoDownloaderUltimate.exe [697976 2014-06-28] (Link64 GmbH)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\BT\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\setup2.exe (magicJack L.P.)
ShellIconOverlayIdentifiers:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers: GDriveSharedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  No File
ShellIconOverlayIdentifiers: ShellExt1 -> {2012DE06-50C0-48BD-ACDE-88F95D4CAD1F} => C:\PROGRA~2\4Sync\ShellExt.dll No File
ShellIconOverlayIdentifiers: ShellExt2 -> {C72C6188-BEF2-46E5-A89A-52F0ED75219E} => C:\PROGRA~2\4Sync\ShellExt.dll No File
ShellIconOverlayIdentifiers: ShellExt3 -> {C92F6BC2-AF61-4C0E-80E0-939B8282DDB7} => C:\PROGRA~2\4Sync\ShellExt.dll No File
ShellIconOverlayIdentifiers: ShellExt4 -> {CB1EFEF8-D5E0-49D1-B768-41B48B1D7803} => C:\PROGRA~2\4Sync\ShellExt.dll No File
ShellIconOverlayIdentifiers-x32:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
BootExecute:

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 205.171.2.25
Tcpip\..\Interfaces\{0D01DE1E-0EFC-41CC-AE51-F14B0A22E4F6}: [NameServer]192.168.0.1,205.171.3.25

FireFox:
========
FF ProfilePath: C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rj5y4zuc.default-1404055395082
FF Homepage: hxxp://www.google.com
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @java.com/DTPlugin,version=10.65.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.65.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Laurie\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Laurie\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Laurie\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Laurie\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Laurie\AppData\Roaming\mozilla\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Users\Laurie\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Laurie\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF Extension: Flash Video Downloader - Full HD Download - C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rj5y4zuc.default-1404055395082\Extensions\artur.dubovoy@gmail.com [2014-07-15]
FF Extension: No Name - C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rj5y4zuc.default-1404055395082\Extensions\staged [2014-07-31]
FF Extension: 1-Click YouTube Video Downloader - C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rj5y4zuc.default-1404055395082\Extensions\YoutubeDownloader@PeterOlayev.com.xpi [2014-07-15]
FF Extension: Easy Youtube Video Downloader Express - C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rj5y4zuc.default-1404055395082\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2014-07-16]
FF Extension: Fast Video Download - C:\Users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rj5y4zuc.default-1404055395082\Extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}.xpi [2014-07-16]
FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\MozFirefox\firefox.exe

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 a2AntiMalware; C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [4741384 2014-07-09] (Emsisoft GmbH)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
R2 ftpsvc; C:\Windows\system32\inetsrv\ftpsvc.dll [350720 2012-05-31] (Microsoft Corporation)
R2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2013-11-18] (Nero AG)
R2 OAcat; C:\Program Files (x86)\Online Armor\OAcat.exe [584864 2013-10-15] (Emsisoft GmbH)
S3 OpenVPNService; C:\Program Files (x86)\HMA! Pro VPN\bin\openvpnserv.exe [37176 2014-04-14] (The OpenVPN Project)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed]
R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-29] (Acer Incorporated)
R2 Srvany Service; C:\Windows\System32\srvany.exe [8192 2003-04-18] () [File not signed]
R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [728328 2014-04-11] (DEVGURU Co., LTD.)
R2 SvcOnlineArmor; C:\Program Files (x86)\Online Armor\oasrv.exe [4457688 2013-10-15] (Emsisoft GmbH)
R2 TeamViewer9; C:\Program Files (x86)\TeamViewer\V9\TeamViewer_Service.exe [5037888 2014-07-02] (TeamViewer GmbH)
R2 UTSCSI; C:\Windows\SysWOW64\UTSCSI.EXE [45056 2012-10-16] () [File not signed]
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 a2acc; C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [71472 2014-05-12] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [26176 2013-04-03] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files (x86)\Emsisoft Anti-Malware\a2dix64.sys [45208 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys [23088 2014-05-12] (Emsisoft GmbH)
S3 ampa; C:\Windows\system32\ampa.sys [15288 2011-12-26] () [File not signed]
S3 ampa; C:\Windows\SysWOW64\ampa.sys [12728 2011-12-26] () [File not signed]
S2 Aspi32; C:\Windows\SysWOW64\drivers\aspi32.sys [16877 2002-07-17] (Adaptec) [File not signed]
S3 bthav; C:\Windows\System32\drivers\bthav.sys [40448 2008-07-10] (CSR, plc)
R3 cleanhlp; C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [57024 2013-12-04] (Emsisoft GmbH)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [32512 2013-09-16] ()
R3 k57nd; C:\Windows\System32\DRIVERS\k57amd64.sys [333864 2009-12-11] (Broadcom Corporation)
R1 OADevice; C:\Windows\SysWow64\Drivers\OADriver.sys [64720 2013-10-15] ()
R1 oahlpXX; C:\Windows\syswow64\drivers\oahlp64.sys [62008 2013-10-15] ()
R1 OAmon; C:\Windows\SysWOW64\Drivers\OAmon.sys [52360 2013-10-15] (Emsisoft)
R3 OAnet; C:\Windows\System32\DRIVERS\oanet.sys [35368 2013-10-15] (Emsisoft)
S3 ptun0901; C:\Windows\System32\DRIVERS\ptun0901.sys [40664 2014-03-10] (The OpenVPN Project)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
S3 tap0801; C:\Windows\System32\DRIVERS\tap0801.sys [30720 2005-04-13] (The OpenVPN Project) [File not signed]
S3 AthBTPort; system32\DRIVERS\btath_flt.sys [X]
S3 BTATH_A2DP; system32\drivers\btath_a2dp.sys [X]
S3 BTATH_BUS; system32\DRIVERS\btath_bus.sys [X]
S3 BTATH_HCRP; system32\DRIVERS\btath_hcrp.sys [X]
S3 BTATH_LWFLT; system32\DRIVERS\btath_lwflt.sys [X]
S3 BTATH_RCP; system32\DRIVERS\btath_rcp.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-01 09:29 - 2014-08-01 09:29 - 00017072 _____ () C:\Users\Laurie\Desktop\FRST.txt
2014-08-01 09:28 - 2014-08-01 09:28 - 00031374 _____ () C:\Users\Laurie\Desktop\FRST error.bmp
2014-08-01 09:21 - 2014-08-01 09:21 - 02094080 _____ (Farbar) C:\Users\Laurie\Desktop\FRST64.exe
2014-07-30 09:32 - 2014-07-30 09:32 - 00000504 _____ () C:\Users\Laurie\Desktop\PPTP-VPN.lnk
2014-07-30 09:15 - 2014-07-30 09:18 - 00000000 ____D () C:\Program Files (x86)\HMA! Pro VPN
2014-07-30 09:15 - 2014-07-30 09:15 - 00001118 _____ () C:\Users\Public\Desktop\HMA! Pro VPN.lnk
2014-07-30 09:15 - 2014-07-30 09:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HMA! Pro VPN
2014-07-29 16:45 - 2014-07-29 16:46 - 00000000 ____D () C:\Program Files (x86)\MozFirefox
2014-07-29 16:41 - 2014-07-29 16:42 - 00000000 ____D () C:\Users\Laurie\Desktop\ADI-Auto
2014-07-29 16:22 - 2014-07-29 16:22 - 00001266 _____ () C:\Users\Laurie\Desktop\Windows Update.lnk
2014-07-19 09:45 - 2014-07-19 09:44 - 00319912 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-07-19 09:45 - 2014-07-19 09:44 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-07-19 09:45 - 2014-07-19 09:44 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-07-19 08:19 - 2014-07-19 08:19 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-ORGMIND-Microsoft-Windows-7-Home-Premium-(64-bit).dat
2014-07-19 08:18 - 2014-07-19 08:18 - 00000000 ____D () C:\RegBackup
2014-07-19 08:16 - 2014-07-19 08:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2014-07-19 08:16 - 2014-07-19 08:16 - 00000000 ____D () C:\Program Files (x86)\Win Repair
2014-07-19 08:12 - 2014-07-19 08:16 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-07-19 07:32 - 2014-07-19 09:44 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-07-19 07:17 - 2014-07-19 07:17 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-07-19 07:10 - 2014-07-19 07:17 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-07-19 07:10 - 2014-07-19 07:17 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-07-19 07:10 - 2014-07-19 07:17 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-19 07:10 - 2014-07-19 07:10 - 00004191 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-18 09:30 - 2014-07-18 09:30 - 00000000 ____D () C:\ProgramData\Reimage Protector
2014-07-18 09:23 - 2014-07-18 09:23 - 00000000 ____D () C:\Program Files\Reimage
2014-07-18 09:20 - 2014-07-19 06:52 - 00000000 ____D () C:\rei
2014-07-16 09:52 - 2014-07-16 09:52 - 00000000 ____D () C:\Program Files (x86)\Trusteer
2014-07-16 09:49 - 2014-07-16 09:49 - 00000000 ____D () C:\ProgramData\Trusteer
2014-07-16 08:05 - 2014-07-19 06:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-07-16 08:05 - 2014-07-16 08:05 - 00001750 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-07-16 08:04 - 2014-07-16 08:05 - 00000000 ____D () C:\Program Files\iTunes
2014-07-13 18:59 - 2014-08-01 09:29 - 00000000 ____D () C:\FRST
2014-07-13 15:08 - 2014-07-19 06:53 - 00000000 ____D () C:\EEK
2014-07-10 23:27 - 2014-07-12 00:27 - 05659136 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-07-09 22:14 - 2014-06-29 20:09 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-09 22:14 - 2014-06-29 20:04 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-09 22:14 - 2014-05-30 02:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-09 22:14 - 2014-05-30 02:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-09 22:14 - 2014-05-30 02:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-09 22:14 - 2014-05-30 02:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-09 22:14 - 2014-05-30 02:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-09 22:14 - 2014-05-30 02:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-09 22:14 - 2014-05-30 01:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-09 22:14 - 2014-05-30 01:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-09 22:14 - 2014-05-30 01:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-09 22:14 - 2014-05-30 01:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-09 22:14 - 2014-05-30 01:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-09 22:14 - 2014-05-30 01:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-09 22:13 - 2014-06-20 14:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-09 22:13 - 2014-06-20 13:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-09 22:13 - 2014-06-18 19:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 22:13 - 2014-06-18 19:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 22:13 - 2014-06-18 19:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-09 22:13 - 2014-06-18 18:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 22:13 - 2014-06-18 18:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 22:13 - 2014-06-18 18:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-09 22:13 - 2014-06-18 18:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-09 22:13 - 2014-06-18 18:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-09 22:13 - 2014-06-18 18:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 22:13 - 2014-06-18 18:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-09 22:13 - 2014-06-18 18:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 22:13 - 2014-06-18 18:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 22:13 - 2014-06-18 18:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-09 22:13 - 2014-06-18 18:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-09 22:13 - 2014-06-18 18:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-09 22:13 - 2014-06-18 18:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-09 22:13 - 2014-06-18 18:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 22:13 - 2014-06-18 17:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 22:13 - 2014-06-18 17:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-09 22:13 - 2014-06-18 17:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-09 22:13 - 2014-06-18 17:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 22:13 - 2014-06-18 17:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 22:13 - 2014-06-18 17:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 22:13 - 2014-06-18 17:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-09 22:13 - 2014-06-18 17:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-09 22:13 - 2014-06-18 17:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-09 22:13 - 2014-06-18 17:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-09 22:13 - 2014-06-18 17:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-09 22:13 - 2014-06-18 17:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 22:13 - 2014-06-18 17:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-09 22:13 - 2014-06-18 17:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-09 22:13 - 2014-06-18 17:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-09 22:13 - 2014-06-18 17:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 22:13 - 2014-06-18 17:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-09 22:13 - 2014-06-18 17:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-09 22:13 - 2014-06-18 17:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-09 22:13 - 2014-06-18 17:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-09 22:13 - 2014-06-18 17:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-09 22:13 - 2014-06-18 17:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-09 22:13 - 2014-06-18 17:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-09 22:13 - 2014-06-18 16:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-09 22:13 - 2014-06-18 16:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 22:13 - 2014-06-18 16:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-09 22:13 - 2014-06-18 16:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-09 22:13 - 2014-06-18 16:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 22:13 - 2014-06-18 16:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-09 22:13 - 2014-06-18 16:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-09 22:13 - 2014-06-18 16:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-09 22:13 - 2014-06-18 16:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-09 22:13 - 2014-06-18 16:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 22:13 - 2014-06-18 16:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-09 22:13 - 2014-06-18 16:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-09 22:13 - 2014-06-18 16:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-09 22:13 - 2014-06-18 16:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-09 22:13 - 2014-06-17 20:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-09 22:13 - 2014-06-17 19:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-09 22:13 - 2014-06-17 19:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 22:13 - 2014-06-05 08:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-09 22:13 - 2014-06-05 08:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-09 22:13 - 2014-06-05 08:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-07-09 22:13 - 2014-05-30 02:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-09 22:13 - 2014-05-30 01:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-09 22:11 - 2014-06-06 04:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 22:11 - 2014-06-06 03:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-09 22:11 - 2014-05-30 00:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-03 14:39 - 2014-07-31 15:39 - 00003010 _____ () C:\Windows\SysWOW64\devmon.log
2014-07-03 14:37 - 2014-07-31 15:33 - 00000999 _____ () C:\Windows\setupact.log
2014-07-03 14:37 - 2014-07-03 14:37 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-03 14:36 - 2014-07-30 17:43 - 00002106 _____ () C:\Windows\PFRO.log
2014-07-03 11:01 - 2014-07-03 11:19 - 00000000 ____D () C:\Users\Laurie\AppData\Roaming\Wise Registry Cleaner
2014-07-03 10:23 - 2014-07-03 11:01 - 00000000 ____D () C:\Users\Laurie\AppData\Roaming\Wise Disk Cleaner

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-01 09:29 - 2014-08-01 09:29 - 00017072 _____ () C:\Users\Laurie\Desktop\FRST.txt
2014-08-01 09:29 - 2014-07-13 18:59 - 00000000 ____D () C:\FRST
2014-08-01 09:29 - 2014-06-15 17:08 - 00000000 ____D () C:\Temp
2014-08-01 09:28 - 2014-08-01 09:28 - 00031374 _____ () C:\Users\Laurie\Desktop\FRST error.bmp
2014-08-01 09:27 - 2014-01-20 17:44 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-01 09:21 - 2014-08-01 09:21 - 02094080 _____ (Farbar) C:\Users\Laurie\Desktop\FRST64.exe
2014-08-01 09:21 - 2014-06-10 12:10 - 00000912 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1014UA.job
2014-08-01 09:17 - 2014-05-12 17:11 - 00000912 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1001UA.job
2014-08-01 09:07 - 2012-07-15 15:55 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Anti-Malware
2014-08-01 08:50 - 2012-11-29 13:14 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-01 08:46 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\tracing
2014-08-01 03:13 - 2012-07-15 11:22 - 01484746 _____ () C:\Windows\WindowsUpdate.log
2014-08-01 02:50 - 2012-11-29 13:14 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-31 17:18 - 2014-05-12 17:11 - 00000860 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1001Core.job
2014-07-31 15:43 - 2009-07-13 22:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-31 15:43 - 2009-07-13 22:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-31 15:39 - 2014-07-03 14:39 - 00003010 _____ () C:\Windows\SysWOW64\devmon.log
2014-07-31 15:37 - 2012-10-19 16:49 - 00000326 _____ () C:\Windows\Tasks\GlaryInitialize.job
2014-07-31 15:36 - 2012-10-17 16:52 - 00000346 _____ () C:\Windows\Tasks\UpdateDetector.job
2014-07-31 15:35 - 2012-07-17 08:21 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-07-31 15:35 - 2009-07-13 23:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-31 15:33 - 2014-07-03 14:37 - 00000999 _____ () C:\Windows\setupact.log
2014-07-31 15:33 - 2012-09-10 05:18 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-07-31 15:33 - 2012-09-10 05:18 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-07-31 11:21 - 2014-06-10 12:10 - 00000860 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1014Core.job
2014-07-30 17:57 - 2012-09-10 05:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-07-30 17:43 - 2014-07-03 14:36 - 00002106 _____ () C:\Windows\PFRO.log
2014-07-30 10:00 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-07-30 09:32 - 2014-07-30 09:32 - 00000504 _____ () C:\Users\Laurie\Desktop\PPTP-VPN.lnk
2014-07-30 09:18 - 2014-07-30 09:15 - 00000000 ____D () C:\Program Files (x86)\HMA! Pro VPN
2014-07-30 09:15 - 2014-07-30 09:15 - 00001118 _____ () C:\Users\Public\Desktop\HMA! Pro VPN.lnk
2014-07-30 09:15 - 2014-07-30 09:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HMA! Pro VPN
2014-07-29 17:54 - 2012-07-15 13:46 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-07-29 16:46 - 2014-07-29 16:45 - 00000000 ____D () C:\Program Files (x86)\MozFirefox
2014-07-29 16:42 - 2014-07-29 16:41 - 00000000 ____D () C:\Users\Laurie\Desktop\ADI-Auto
2014-07-29 16:22 - 2014-07-29 16:22 - 00001266 _____ () C:\Users\Laurie\Desktop\Windows Update.lnk
2014-07-29 16:22 - 2014-06-09 19:22 - 00000000 ____D () C:\Users\Laurie\Desktop\Mal-Fix
2014-07-29 16:15 - 2014-06-09 19:12 - 00000000 ____D () C:\Users\Laurie
2014-07-23 10:52 - 2010-11-20 21:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-07-19 09:44 - 2014-07-19 09:45 - 00319912 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-07-19 09:44 - 2014-07-19 09:45 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-07-19 09:44 - 2014-07-19 09:45 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-07-19 09:44 - 2014-07-19 07:32 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-07-19 09:13 - 2009-07-13 22:45 - 00288904 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-19 08:19 - 2014-07-19 08:19 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-ORGMIND-Microsoft-Windows-7-Home-Premium-(64-bit).dat
2014-07-19 08:18 - 2014-07-19 08:18 - 00000000 ____D () C:\RegBackup
2014-07-19 08:18 - 2013-10-08 10:06 - 00000000 ____D () C:\ProgramData\Oracle
2014-07-19 08:16 - 2014-07-19 08:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2014-07-19 08:16 - 2014-07-19 08:16 - 00000000 ____D () C:\Program Files (x86)\Win Repair
2014-07-19 08:16 - 2014-07-19 08:12 - 00000000 ____D () C:\Program Files (x86)\Tweaking.com
2014-07-19 07:17 - 2014-07-19 07:17 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-07-19 07:17 - 2014-07-19 07:10 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-07-19 07:17 - 2014-07-19 07:10 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-07-19 07:17 - 2014-07-19 07:10 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-19 07:10 - 2014-07-19 07:10 - 00004191 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-19 07:10 - 2013-03-16 07:51 - 00000000 ____D () C:\Program Files (x86)\Java
2014-07-19 06:53 - 2014-07-16 08:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-07-19 06:53 - 2014-07-13 15:08 - 00000000 ____D () C:\EEK
2014-07-19 06:53 - 2014-06-09 17:41 - 00000000 ____D () C:\Users\test
2014-07-19 06:53 - 2013-12-18 13:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-07-19 06:53 - 2013-10-08 10:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-19 06:53 - 2013-05-18 14:42 - 00000000 ____D () C:\Users\DefaultAppPool.IIS APPPOOL.000
2014-07-19 06:52 - 2014-07-18 09:20 - 00000000 ____D () C:\rei
2014-07-19 06:52 - 2013-05-09 16:01 - 00000000 ____D () C:\Windows\Minidump
2014-07-19 06:52 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\registration
2014-07-18 09:30 - 2014-07-18 09:30 - 00000000 ____D () C:\ProgramData\Reimage Protector
2014-07-18 09:23 - 2014-07-18 09:23 - 00000000 ____D () C:\Program Files\Reimage
2014-07-16 09:52 - 2014-07-16 09:52 - 00000000 ____D () C:\Program Files (x86)\Trusteer
2014-07-16 09:49 - 2014-07-16 09:49 - 00000000 ____D () C:\ProgramData\Trusteer
2014-07-16 08:05 - 2014-07-16 08:05 - 00001750 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-07-16 08:05 - 2014-07-16 08:04 - 00000000 ____D () C:\Program Files\iTunes
2014-07-16 08:05 - 2013-12-24 10:09 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-07-16 08:05 - 2013-12-24 10:09 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-07-16 08:04 - 2013-12-24 10:09 - 00000000 ____D () C:\Program Files\iPod
2014-07-15 07:36 - 2013-09-16 09:19 - 00000000 ____D () C:\AdwCleaner
2014-07-14 09:36 - 2012-11-05 10:49 - 00000432 _____ () C:\Windows\Tasks\Wise Disk Cleaner Schedule Task.job
2014-07-12 00:28 - 2014-01-20 17:44 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-12 00:28 - 2014-01-20 17:44 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-12 00:27 - 2014-07-10 23:27 - 05659136 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-07-10 08:25 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\rescache
2014-07-10 06:59 - 2014-04-28 08:23 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-10 06:59 - 2010-11-21 01:17 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-10 06:59 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-10 06:59 - 2009-07-13 21:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-09 22:23 - 2013-07-15 14:12 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-09 22:22 - 2013-12-12 19:16 - 00014022 _____ () C:\Windows\system32\TeamViewer9_Hooks.log
2014-07-09 22:20 - 2014-06-26 23:16 - 00001021 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-07-09 22:16 - 2012-07-17 19:02 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-03 19:01 - 2009-07-13 23:13 - 00826254 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-03 14:37 - 2014-07-03 14:37 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-03 11:19 - 2014-07-03 11:01 - 00000000 ____D () C:\Users\Laurie\AppData\Roaming\Wise Registry Cleaner
2014-07-03 11:01 - 2014-07-03 10:23 - 00000000 ____D () C:\Users\Laurie\AppData\Roaming\Wise Disk Cleaner
2014-07-03 10:31 - 2014-05-12 17:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GVMateApp

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

==================== End Of Log ============================

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-07-2014 02
Ran by Laurie at 2014-08-01 09:30:16
Running from C:\Users\Laurie\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Emsisoft Anti-Malware (Enabled - Up to date) {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Emsisoft Anti-Malware (Enabled - Up to date) {3E653F0B-EA3E-10F8-1B87-CAD78F211367}
FW: Online Armor Firewall (Enabled) {BD3F5FCA-866B-1E2E-0A68-58900A751EA1}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acer Crystal Eye Webcam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1306 - CyberLink Corp.)
Acer Crystal Eye Webcam (x32 Version: 1.0.1306 - CyberLink Corp.) Hidden
Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3004 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3002 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.0413.2011 - Acer Incorporated)
Acer Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3502 - Acer Incorporated)
Acer VCM (HKLM-x32\...\{047F790A-7A2A-4B6A-AD02-38092BA63DAC}) (Version: 4.05.3004 - Acer Incorporated)
Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe Flash Player 14 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.)
Android Manager WiFi (HKLM-x32\...\{EDE1736D-94BA-0200-0000-000000000000}) (Version: 10.10.846 - Mobile Action)
AOMEI Partition Assistant Home Edition 5.1 (HKLM-x32\...\{02F850ED-FD0E-4ED1-BE0B-54981f5BD3D4}_is1) (Version:  - Aomei Technology Co., Ltd.)
Apple Application Support (HKLM-x32\...\{21ECABC3-40B2-42DF-8E21-ACF3A4D0D95A}) (Version: 3.0.5 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}) (Version: 7.1.2.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.39 - Atheros Communications Inc.)
ATI Catalyst Install Manager (HKLM\...\{4292776A-4F23-E108-83B2-2C27398E8BCF}) (Version: 3.0.804.0 - ATI Technologies, Inc.)
AviSynth 2.5 (HKLM-x32\...\AviSynth) (Version:  - )
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom 802.11 Network Adapter (HKLM\...\Broadcom 802.11 Network Adapter) (Version: 5.60.48.35 - Broadcom Corporation)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2011.0111.1350.24756 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2011.0111.1350.24756 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2011.0111.1350.24756 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
CCC Help Czech (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
CCC Help Danish (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
CCC Help Dutch (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
CCC Help English (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
CCC Help Finnish (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
CCC Help French (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
CCC Help German (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
CCC Help Greek (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
CCC Help Italian (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
CCC Help Japanese (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
CCC Help Korean (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
CCC Help Polish (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
CCC Help Russian (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
CCC Help Spanish (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
CCC Help Swedish (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
CCC Help Thai (x32 Version: 2011.0111.1349.24756 - ATI) Hidden
ccc-core-static (x32 Version: 2011.0111.1350.24756 - ATI) Hidden
ccc-utility64 (Version: 2011.0111.1350.24756 - ATI) Hidden
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.1.4003 - CDBurnerXP)
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.6.0 - Conexant)
CutePDF Writer 3.0 (HKLM\...\CutePDF Writer Installation) (Version:  3.0 - Acro Software Inc.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
doubleTwist Sync (HKLM-x32\...\doubleTwist) (Version: 4.0.3.0 - doubleTwist Corporation)
Emsisoft Anti-Malware (HKLM-x32\...\{BC30E5E7-047D-4232-A7E8-F2CB7CC7B2E0}_is1) (Version: 6.6 - Emsisoft GmbH)
Evernote v. 5.4 (HKLM-x32\...\{59071464-DAEE-11E3-9080-00163E98E7D0}) (Version: 5.4.0.3698 - Evernote Corp.)
Free SWF to AVI Converter (HKLM-x32\...\{44327031-4B00-4D21-8D25-620B6B476005}_is1) (Version:  - Recool Software Co., LTD)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 36.0.1985.125 - Google Inc.)
Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Talk Plugin (HKLM-x32\...\{C1E3DFE7-4EAD-3E9E-A826-E06055BA5921}) (Version: 5.4.2.18903 - Google)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
gpedt.msc 1.0 (HKLM-x32\...\{10B9C608-BF7C-4CCF-A658-C01D969DCA21}_is1) (Version:  - Richard)
HMA! Pro VPN 2.8.6.0 (HKLM-x32\...\HMA! Pro VPN) (Version: 2.8.6.0 - Privax Ltd)
HTC BMP USB Driver (HKLM-x32\...\{31A559C1-9E4D-423B-9DD3-34A6C5398752}) (Version: 1.0.5375 - HTC)
HTC Driver Installer (HKLM-x32\...\{4CEEE5D0-F905-4688-B9F9-ECC710507796}) (Version: 4.11.0.001 - HTC Corporation)
HTC Sync Manager (HKLM-x32\...\{231D0C79-98A6-4693-A366-36DE7D7346EC}) (Version: 3.1.13.0 - HTC)
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.7.0 - LIGHTNING UK!)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation)
Intel® Turbo Boost Technology Driver (HKLM-x32\...\{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}) (Version: 01.00.01.1002 - Intel Corporation)
IPTInstaller (HKLM-x32\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.9 - HTC)
iTunes (HKLM\...\{33E28B58-7BA0-47B7-AA01-9225ABA2B8A9}) (Version: 11.3.0.54 - Apple Inc.)
Java 7 Update 65 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F06417065FF}) (Version: 7.0.650 - Oracle)
Java 7 Update 65 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217065FF}) (Version: 7.0.650 - Oracle)
Java Auto Updater (x32 Version: 2.1.65.20 - Oracle, Inc.) Hidden
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
K-Lite Mega Codec Pack 9.0.2 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 9.0.2 - )
Launch Manager (HKLM-x32\...\LManager) (Version: 5.1.4 - Acer Inc.)
Lexmark IP Setup Utility Uninstaller (HKLM\...\Lexmark IP Setup Utility) (Version:  - Lexmark International, Inc.)
Lexmark Network TWAIN Driver Uninstaller (HKLM\...\Lexmark Network TWAIN Driver) (Version:  - Lexmark International, Inc.)
Lexmark Phone Book Uninstaller (HKLM\...\Lexmark Fax Phonebook) (Version:  - Lexmark International, Inc.)
Lexmark S310 Series Uninstaller (HKLM\...\Lexmark S310 Series) (Version:  - Lexmark International, Inc.)
Lexmark S310 Series Uninstaller (HKLM-x32\...\Lexmark S310 Series) (Version:  - Lexmark International, Inc.)
Lexmark ScanBack Uninstaller (HKLM\...\Lexmark ScanBack) (Version:  - Lexmark International, Inc.)
Lexmark Universal v2 Uninstaller (HKLM\...\Lexmark Universal v2) (Version:  - Lexmark International, Inc.)
Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM-x32\...\{90110409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Office Visio Professional 2003 (HKLM-x32\...\{91510409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Office XP Professional with FrontPage (HKLM-x32\...\{90280409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Sync Framework 2.0 Core Components (x64) ENU  (HKLM\...\{8CCBEC22-D2DB-4DC9-A58A-E1A1F3A38C8A}) (Version: 2.0.1578.0 - Microsoft Corporation)
Microsoft Sync Framework 2.0 Provider Services (x64) ENU  (HKLM\...\{03AC245F-4C64-425C-89CF-7783C1D3AB2C}) (Version: 2.0.1578.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (HKLM-x32\...\{8e70e4e1-06d7-470b-9f74-a51bef21088e}) (Version: 11.0.51106.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106 - Microsoft Corporation) Hidden
Minimal ADB and Fastboot version 1.1.3 (HKLM-x32\...\{DE46417A-9E9E-4BCD-BBDD-DA21943193BB}_is1) (Version: 1.1.3 - )
MiniTool Drive Wipe 5.0 (HKLM-x32\...\{185285A1-82FC-4D8D-AC98-AB6E318F8E33}_is1) (Version:  - MiniTool Solution Ltd.)
MozBackup 1.5.1 (HKLM-x32\...\MozBackup) (Version:  - Pavel Cvrcek)
Mozilla Firefox 31.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 en-US)) (Version: 31.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MP3MyMP3 4.2 (HKLM-x32\...\MP3MyMP3_is1) (Version:  - Bruce McArthur)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Online Armor 6.0 (HKLM-x32\...\OnlineArmor_is1) (Version: 6.0 - Emsisoft GmbH)
OpenVPN 2.1.3 (HKLM-x32\...\OpenVPN) (Version: 2.1.3 - )
PdaNet+ for Android 4.12 (HKLM-x32\...\PdaNet_is1) (Version:  - June Fabrics Technology Inc)
Product Key Finder 2012 (HKLM-x32\...\{8993561D-6EF8-4DD1-BD5E-515362CBB2A7}) (Version: 1.3 - Atlantic Software)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30127 - Realtek Semiconductor Corp.)
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.43.0 - SAMSUNG Electronics Co., Ltd.)
ScreenShot V1.1.0.0 (HKLM-x32\...\{1BBEB0C2-B5F6-4B8E-A4EA-1B13C45FCE7D}) (Version: 1.1.0 - MichaelFontana)
Skype Click to Call (HKLM-x32\...\{BB285C9F-C821-4770-8970-56C4AB52C87E}) (Version: 7.2.15747.10003 - Microsoft Corporation)
Skype™ 6.14 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.14.104 - Skype Technologies S.A.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.2.9.0 - Synaptics Incorporated)
SyncToy 2.1 (x64) (HKLM\...\{88DAAF05-5A72-46D2-A7C5-C3759697E943}) (Version: 2.1.0 - Microsoft)
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.29947 - TeamViewer)
Tweaking.com - Windows Repair (All in One) (HKLM-x32\...\Tweaking.com - Windows Repair (All in One)) (Version: 2.8.2 - Tweaking.com)
VC_CRT_x64 (Version: 1.02.0000 - Intel Corporation) Hidden
VideoDownloaderUltimate (HKCU\...\VideoDownloaderUltimateWinApp) (Version: 1.0.1.12 - Link64)
WIDCOMM Bluetooth Software 6.0.1.4900 (HKLM\...\{03D1988F-469F-4843-8E6E-E5FE9D17889D}) (Version: 6.0.1.4900 - Broadcom Corporation)
Windows Live Communications Platform (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Mobile Device Center (HKLM\...\{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}) (Version: 6.1.6965.0 - Microsoft Corporation)
Windows Mobile Device Center Driver Update (HKLM\...\{92DBCA36-9B41-4DD1-941A-AED149DD37F0}) (Version: 6.1.6965.0 - Microsoft Corporation)
Windows Movie Maker 2.6 (HKLM-x32\...\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4037.0 - Microsoft Corporation)
Windows Resource Kit Tools (HKLM-x32\...\{FA237125-51FF-408C-8BB8-30C2B3DFFF9C}) (Version: 5.2.3790 - Microsoft Corporation)
WinRAR 4.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH)
Wise Disk Cleaner 8.03 (HKLM-x32\...\Wise Disk Cleaner_is1) (Version: 8.03 - WiseCleaner.com, Inc.)
Wise Registry Cleaner 8.03 (HKLM-x32\...\Wise Registry Cleaner_is1) (Version: 8.03 - WiseCleaner.com, Inc.)
WMV9/VC-1 Video Playback (Version: 1.00.0000 - ATI Technologies Inc.) Hidden
Yahoo! Detect (HKLM-x32\...\YTdetect) (Version:  - )

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

Could not list Restore Points. Check "winmgmt" service or repair WMI.


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 20:34 - 2009-06-10 15:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {023A39CA-B81F-45BE-A533-EF9036D9CBA2} - \{46783191-2F47-47C7-9920-36199D125C45} No Task File <==== ATTENTION
Task: {03E6643C-2860-4B4E-8F05-920742ACDA30} - \UpdateDetector No Task File <==== ATTENTION
Task: {0C6D7540-2088-4BB2-BFAC-81E496DB96CE} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {11CC10FA-7369-457A-891D-6A6F9E5677EF} - \GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1001Core No Task File <==== ATTENTION
Task: {1390673C-0B36-4E7E-ACE1-5A1C343C8879} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1014UA => C:\Users\Laurie\AppData\Local\Google\Update\GoogleUpdate.exe [2014-06-10] (Google Inc.)
Task: {14F9F31C-98E3-4C5B-AD6A-234BD36B96C5} - \{8C9A90EF-DB0D-429E-AB71-A966CDB24853} No Task File <==== ATTENTION
Task: {17310746-4F8D-45FA-8F70-82C65A4E7E44} - \{B114C606-7D6F-465B-AF4B-F473639402D8} No Task File <==== ATTENTION
Task: {17BEBFA6-8150-46D2-B772-2EA886B0BB87} - \{EAAC4E7B-0449-41FE-9873-0288DE92C30F} No Task File <==== ATTENTION
Task: {203A8846-31EE-42E7-8C28-8BE544E9FB24} - System32\Tasks\UALU notificatin => C:\Program Files\Acer\Acer Updater\UALU.exe [2012-04-05] (Acer Incorporated)
Task: {227E1B82-3545-48D8-98EE-002C73D4A036} - \{DBEE4DE9-4152-4900-A5FD-C7AF58E34090} No Task File <==== ATTENTION
Task: {2BAA2D5F-23D1-4158-A675-18761E1B6934} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline
Task: {2E2B3DAC-250A-473C-B20A-2986842A341A} - \{D1E8FE10-C7FD-4E65-AAD1-4376B6F0099C} No Task File <==== ATTENTION
Task: {2ED33AE3-1693-4461-B299-14861E1ED401} - \WPD\SqmUpload_S-1-5-21-206095162-3907483975-2766088746-1001 No Task File <==== ATTENTION
Task: {31437387-CBA2-4F17-B330-521762B94B4F} - \{47F63112-15AA-46C8-9093-072903594547} No Task File <==== ATTENTION
Task: {33F2AEAE-26D6-4926-951C-CAD6A9C50E6E} - \Launch HTC Sync Loader No Task File <==== ATTENTION
Task: {393207A2-9536-4CA6-AE83-98F6591D7B77} - \GoogleUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {3C6F5617-E807-434E-BFD2-810775D58BB2} - \GlaryInitialize No Task File <==== ATTENTION
Task: {4517D62D-8A0E-4A9E-9ABE-7CE435AB385F} - \{F321CB4D-FB30-45DD-8561-5628E38837FF} No Task File <==== ATTENTION
Task: {469B426C-D10D-428C-A234-EA924A4B1317} - \MyDefrag v4.3.1 Monthly No Task File <==== ATTENTION
Task: {48A7249C-1D86-4CC0-B096-3DC8E0FEBBD3} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {512C5724-CB2A-4FA4-8751-1BD7511CFBAC} - \Your File Updater No Task File <==== ATTENTION
Task: {56F3838B-CCCD-457A-996B-C6337B263A53} - \{CFC8525B-6C8D-4282-9196-556052535301} No Task File <==== ATTENTION
Task: {5A40E926-9E86-4B89-9CFD-B12311724371} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig
Task: {5B789D7F-80E7-42C1-B32C-68FE67C2D486} - \{E546D740-9269-4B06-BA9C-E6CCF2C630A2} No Task File <==== ATTENTION
Task: {5DE919C7-F4E3-421B-B4F0-355BB6BD4B55} - System32\Tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask
Task: {670E5149-EA83-4D6E-A2DC-DD6BA350B1B3} - \{C580C09E-AD4F-4456-B54C-737B62D79990} No Task File <==== ATTENTION
Task: {6FC304C9-C8E0-4B35-97A8-3EECF3B054E7} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1014Core => C:\Users\Laurie\AppData\Local\Google\Update\GoogleUpdate.exe [2014-06-10] (Google Inc.)
Task: {72DB7465-BC54-491B-A92A-4637A28C9BBF} - System32\Tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck
Task: {74AD3DF6-5FD5-4828-851E-FDF96C252337} - \{78885173-A9B0-4ADE-8AF8-C0940749A0EF} No Task File <==== ATTENTION
Task: {75D4D80B-A007-4431-8445-3F2BA63D4FC3} - \GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1001UA No Task File <==== ATTENTION
Task: {78FFA950-D84A-4BDD-A708-BCABB5D6EBAA} - \{38E3A762-C88D-4CAF-B299-234C7AA1723D} No Task File <==== ATTENTION
Task: {7911F72F-836B-4A96-A078-782F310634C2} - \{D1E8F289-38A2-4B31-9E6A-B1658427B606} No Task File <==== ATTENTION
Task: {79A07BCD-E068-4B98-8BF2-69A57D6A56AA} - \{864696D7-6AA0-4927-8571-05D8CDFD7011} No Task File <==== ATTENTION
Task: {8848134F-FDE1-4849-BF5E-1276D37E4C74} - \{5C26FD86-1886-42AF-A780-96B17797AED8} No Task File <==== ATTENTION
Task: {8894C045-417A-43DC-80D9-35821A6B9D6D} - \{276C65B5-73F4-4310-B0BA-51650225A19C} No Task File <==== ATTENTION
Task: {900A4931-8344-411F-A66E-CA4F9C9A220E} - \{AF880A57-FD8F-4997-A643-DD5D04AF8D0C} No Task File <==== ATTENTION
Task: {90713902-E490-4D3E-834A-6D4484A5291C} - \{DCC8136D-0B71-4A25-A253-87AB91B5D3D3} No Task File <==== ATTENTION
Task: {93795EC4-223F-4418-B6DF-EE15C307230D} - \{FBFC1B7E-E577-4F51-AEF9-48DEEE7C6C7D} No Task File <==== ATTENTION
Task: {95C1A018-65D1-47FB-9109-3A4F4CADA495} - \{31B95A9F-5195-4B9E-839A-62781C73D702} No Task File <==== ATTENTION
Task: {97CE3BB8-02D5-48B4-B52E-B4C7EB38D142} - \{7D0B4C01-A1A1-4BE3-B028-793DA4E56287} No Task File <==== ATTENTION
Task: {9AD834B7-8A0A-4975-B36B-DB0D9F8E9AB5} - \{AA8ACD7D-E06A-411A-A724-91CA5D18AE6B} No Task File <==== ATTENTION
Task: {A48CABBF-24C8-4B87-B00F-9261807C3B43} - System32\Tasks\Microsoft\Windows\AppID\PolicyConverter
Task: {A4EE7BD8-0532-4F84-9CC7-3B91D93BED31} - \{B9360553-D111-4C5C-A8BD-9A132307C654} No Task File <==== ATTENTION
Task: {A8DAFAD8-35E8-4C4C-A5C6-BF857D9A6877} - \YourFile Update No Task File <==== ATTENTION
Task: {AADECE4B-E0B6-4350-BFCE-77E4A13B6CBB} - \{C311F751-0A59-4257-9F9E-67849DC68B61} No Task File <==== ATTENTION
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - System32\Tasks\Microsoft\Windows\Application Experience\AitAgent
Task: {B942CB64-8FE4-4CCA-9F05-3F823380FF9D} - \Start Evernote Client No Task File <==== ATTENTION
Task: {BB12048C-02D5-4C39-BB66-7D43148686ED} - \{1B2574BA-1D8E-4609-BF0C-8CDEDD53BECC} No Task File <==== ATTENTION
Task: {BE3705A9-C5D4-4E2E-8E7A-296B8CF1DE8D} - \{27F2279B-AB6E-4C3C-941B-3AA3BC61557A} No Task File <==== ATTENTION
Task: {CA3CB49C-9453-4FE1-8B77-0950E7D6A032} - \GoogleUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186} - System32\Tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask
Task: {D0E6FFF2-D2B7-47BE-ABA9-FBB3C89E9A05} - \{F2FB100C-F032-407F-A6E9-DD9FEFFE0D14} No Task File <==== ATTENTION
Task: {D3379FD9-5A4B-4CB0-BCEF-7B99D34588EE} - \Wise Disk Cleaner Schedule Task No Task File <==== ATTENTION
Task: {D4F24226-9E19-4EBA-A509-B2169DDFA4BF} - \Adobe Flash Player Updater No Task File <==== ATTENTION
Task: {D5BC93F9-E39D-4229-B6FE-205467E89230} - System32\Tasks\LexmarkPUDCTask => C:\Program Files\Lexmark\ProductUpdate\LMprodupdate.exe [2012-09-11] ()
Task: {DA05E22E-E0CB-4C48-AA2E-2C91EB7C4EC8} - \{6CD5B765-B8FA-4EF9-9783-AFDFC5A967BB} No Task File <==== ATTENTION
Task: {DB676F60-7DB8-448A-B40F-61B7CAF450A1} - \MyDefrag v4.3.1 Daily No Task File <==== ATTENTION
Task: {DBEA8735-643B-4DA1-AF6B-F4D5FA29870E} - \{AD167814-17F6-4FA2-ABF0-626D451AAA24} No Task File <==== ATTENTION
Task: {E3163C33-301D-4730-A266-5518C5ED3967} - System32\Tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask
Task: {FA54E18A-0F8C-4E19-ACCB-52E4F05B8C6B} - \{BCB50BFA-008A-4413-948F-7A1355AE1821} No Task File <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => ?
Task: C:\Windows\Tasks\GlaryInitialize.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1001Core.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1001UA.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1014Core.job => C:\Users\Laurie\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1014UA.job => C:\Users\Laurie\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\UpdateDetector.job => ?
Task: C:\Windows\Tasks\Wise Disk Cleaner Schedule Task.job => ?

==================== Loaded Modules (whitelisted) =============

2007-03-29 14:53 - 2007-03-29 14:53 - 00477184 _____ () C:\Windows\system32\btwhidcs.DLL
2007-03-29 15:11 - 2007-03-29 15:11 - 00167936 _____ () C:\Program Files\WIDCOMM\BT\btkeyind.dll
2014-05-27 12:33 - 2014-05-27 12:33 - 00821600 _____ () C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-05-16 07:40 - 2014-05-16 07:40 - 00236456 _____ () C:\Program Files (x86)\HMA! Pro VPN\bin\HMAClientEngine.dll
2014-05-16 07:40 - 2014-05-16 07:40 - 00083368 _____ () C:\Program Files (x86)\HMA! Pro VPN\bin\Util.dll
2014-05-16 07:40 - 2014-05-16 07:40 - 00106920 _____ () C:\Program Files (x86)\HMA! Pro VPN\bin\HMA.GUI.Controls.dll
2014-05-16 07:40 - 2014-05-16 07:40 - 00253864 _____ () C:\Program Files (x86)\HMA! Pro VPN\bin\System.ComponentModel.Composition.dll
2013-09-24 12:36 - 2013-09-24 12:36 - 00019456 _____ () C:\Program Files (x86)\HMA! Pro VPN\bin\TabStripsDLL.dll
2014-07-29 16:45 - 2014-07-29 16:46 - 03800688 _____ () C:\Program Files (x86)\MozFirefox\mozjs.dll
2014-03-31 21:35 - 2014-03-31 21:35 - 00270016 _____ () C:\Program Files (x86)\Windows Live\Writer\en\WindowsLive.Writer.Localization.resources.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Acer VCM.lnk => C:\Windows\pss\Acer VCM.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Dyn Updater Tray Icon.lnk => C:\Windows\pss\Dyn Updater Tray Icon.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Laurie^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^PdaNet Desktop.lnk => C:\Windows\pss\PdaNet Desktop.lnk.Startup
MSCONFIG\startupreg: A8FF474C6AFBC91E15C1D78C293639AF8B8C813B._service_run => "C:\Users\Laurie\AppData\Local\Google\Chrome\Application\chrome.exe" --type=service
MSCONFIG\startupreg: AtherosBtStack => "C:\Program Files (x86)\BT Suite\BtvStack.exe"
MSCONFIG\startupreg: cdloader => "C:\Users\Laurie\AppData\Roaming\mjusbsp\cdloader2.exe" MAGICJACK
MSCONFIG\startupreg: LMab1err => "C:\Program Files (x86)\Lexmark\ErrorApp\LMab1err.exe"
MSCONFIG\startupreg: LMADEmon => "C:\Program Files (x86)\Lexmark S310 Series\LMADEmon.exe"
MSCONFIG\startupreg: uTorrent => "C:\Program Files\Torrent\uTorrent.exe"  /MINIMIZED
MSCONFIG\startupreg: Windows Mobile Device Center => %windir%\WindowsMobile\wmdc.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (08/01/2014 09:25:50 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Explorer.EXE version 6.1.7601.17567 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 740

Start Time: 01cfad072b2a5e1a

Termination Time: 203

Application Path: C:\Windows\Explorer.EXE

Report Id: 19ba9934-1990-11e4-b054-f36299adee90

Error: (07/31/2014 03:35:55 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT AUTHORITY)
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (07/31/2014 03:34:01 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Skipping: Eap method DLL path name validation failed. Error: typeId=43, authorId=9, vendorId=0, vendorType=0

Error: (07/31/2014 03:34:01 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Skipping: Eap method DLL path name validation failed. Error: typeId=25, authorId=9, vendorId=0, vendorType=0

Error: (07/31/2014 03:34:01 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Skipping: Eap method DLL path name validation failed. Error: typeId=17, authorId=9, vendorId=0, vendorType=0

Error: (07/31/2014 02:17:14 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={5CF5BF99-78B4-4770-BD29-5F38A3D82085}: The user ORGMIND\Laurie dialed a connection named HMAVPN which has failed. The error code returned on failure is 720.

Error: (07/30/2014 05:46:56 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT AUTHORITY)
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (07/30/2014 05:44:32 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Skipping: Eap method DLL path name validation failed. Error: typeId=43, authorId=9, vendorId=0, vendorType=0

Error: (07/30/2014 05:44:32 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Skipping: Eap method DLL path name validation failed. Error: typeId=25, authorId=9, vendorId=0, vendorType=0

Error: (07/30/2014 05:44:32 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Skipping: Eap method DLL path name validation failed. Error: typeId=17, authorId=9, vendorId=0, vendorType=0


System errors:
=============
Error: (07/31/2014 03:39:38 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The HomeGroup Listener service terminated with service-specific error %%-2147023143.

Error: (07/31/2014 03:37:21 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (07/31/2014 03:35:22 PM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: The Net.Msmq Listener Adapter service depends the following service: msmq. This service might not be installed.

Error: (07/31/2014 03:35:17 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Aspi32 service failed to start due to the following error:
%%1275

Error: (07/31/2014 03:35:17 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \SystemRoot\SysWow64\drivers\aspi32.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

Error: (07/30/2014 05:49:19 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The HomeGroup Listener service terminated with service-specific error %%-2147023143.

Error: (07/30/2014 05:48:06 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (07/30/2014 05:45:51 PM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: The Net.Msmq Listener Adapter service depends the following service: msmq. This service might not be installed.

Error: (07/30/2014 05:45:47 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Aspi32 service failed to start due to the following error:
%%1275

Error: (07/30/2014 05:45:47 PM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \SystemRoot\SysWow64\drivers\aspi32.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.


Microsoft Office Sessions:
=========================
Error: (08/01/2014 09:25:50 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Explorer.EXE6.1.7601.1756774001cfad072b2a5e1a203C:\Windows\Explorer.EXE19ba9934-1990-11e4-b054-f36299adee90

Error: (07/31/2014 03:35:55 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT AUTHORITY)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/31/2014 03:34:01 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Eap method DLL path name43900

Error: (07/31/2014 03:34:01 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Eap method DLL path name25900

Error: (07/31/2014 03:34:01 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Eap method DLL path name17900

Error: (07/31/2014 02:17:14 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: {5CF5BF99-78B4-4770-BD29-5F38A3D82085}ORGMIND\LaurieHMAVPN720

Error: (07/30/2014 05:46:56 PM) (Source: Microsoft-Windows-WMI) (EventID: 10) (User: NT AUTHORITY)
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/30/2014 05:44:32 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Eap method DLL path name43900

Error: (07/30/2014 05:44:32 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Eap method DLL path name25900

Error: (07/30/2014 05:44:32 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Eap method DLL path name17900


==================== Memory info ===========================

Percentage of memory in use: 49%
Total physical RAM: 3956.43 MB
Available physical RAM: 1998.99 MB
Total Pagefile: 7911.05 MB
Available Pagefile: 4917.48 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: (Orgmind) (Fixed) (Total:113.79 GB) (Free:18.31 GB) NTFS
Drive d: (DATA) (Fixed) (Total:368.08 GB) (Free:302.57 GB) NTFS
Drive g: (BU-Drive) (Fixed) (Total:465.76 GB) (Free:133 GB) NTFS
Drive s: () (Fixed) (Total:100.84 GB) (Free:86.05 GB) NTFS

==================== MBR & Partition Table ==================

==================== End Of Log ============================

 

 

Farbar Recovery Scan Tool (x64) Version: 31-07-2014 02
Ran by Laurie at 2014-08-01 09:31:27
Running from C:\Users\Laurie\Desktop
Boot Mode: Normal

================== Search Files: "rpcss.dll" =============

C:\Windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.1.7601.17514_none_c7f0e16b547f887d\rpcss.dll
[2010-11-20 21:24][2010-11-20 21:24] 0512000 ____A (Microsoft Corporation) 5C627D1B1138676C0A7AB2C2C190D123 [File is signed]

C:\Windows\System32\rpcss.dll
[2010-11-20 21:24][2010-11-20 21:24] 0512000 ____A (Microsoft Corporation) 5C627D1B1138676C0A7AB2C2C190D123 [File is signed]

====== End Of Search ======

 

 

Attached Files



#5 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 38,133 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:51 AM

Posted 01 August 2014 - 08:52 PM

Hi Laurie,

Sorry for the delay, I was never notified you replied. Thank you for the screen shot. The log is indicating a problem as well.

Please consider and complete the following for me.

===================================================

Use of Registry Cleaner Not Recommended

--------------------

BleepingComputer DOES NOT recommend the use of registry cleaners/optimizers or the registry cleaner component of software for several reasons:
  • Registry cleaners are extremely powerful applications that can damage the registry by using aggressive cleaning routines and cause your computer to become unbootable.
    • The Windows registry is a central repository (database) for storing configuration data, user settings and machine-dependent settings, and options for the operating system. It contains information and settings for all hardware, software, users, and preferences. Whenever a user makes changes to settings, file associations, system policies, or installed software, the changes are reflected and stored in this repository. The registry is a crucial component because it is where Windows "remembers" all this information, how it works together, how Windows boots the system and what files it uses when it does. The registry is also a vulnerable subsystem, in that relatively small changes done incorrectly can render the system inoperable. For a more detailed explanation, read Understanding The Registry.
  • Not all registry cleaners are created equal. There are a number of them available but they do not all work entirely the same way. Each vendor uses different criteria as to what constitutes a "bad entry". One cleaner may find entries on your system that will not cause problems when removed, another may not find the same entries, and still another may want to remove entries required for a program to work.
  • Not all registry cleaners create a backup of the registry before making changes. If the changes prevent the system from booting up, then there is no backup available to restore it in order to regain functionality. A backup of the registry is essential BEFORE making any changes to the registry.
  • Improperly removing registry entries can hamper malware disinfection and make the removal process more difficult if your computer becomes infected. For example, removing malware related registry entries before the infection is properly identified can contribute to system instability and even make the malware undetectable to removal tools.
  • The usefulness of cleaning the registry is highly overrated and can be dangerous. In most cases, using a cleaner to remove obsolete, invalid, and erroneous entries does not affect system performance but it can result in "unpredictable results".
  • Unless you have a particular problem that requires a registry edit to correct it, I would suggest you leave the registry alone. Using registry cleaning tools unnecessarily or incorrectly could lead to disastrous effects on your operating system such as preventing it from ever starting again. For routine use, the benefits to your computer are negligible while the potential risks are great.
If you persist in using a registry cleaner you should always backup the registry before doing so.

===================================================

Please download and run Microsoft Fix it 50688 to fix a non-malware related technical issue with Windows.

===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode

--------------------
  • Press the windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter
  • Please copy and paste the contents of the below code box into the open notepad and save it to your desktop (<<<Important) as fixlist.txt
ShellIconOverlayIdentifiers:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers: GDriveSharedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  No File
ShellIconOverlayIdentifiers: ShellExt1 -> {2012DE06-50C0-48BD-ACDE-88F95D4CAD1F} => C:\PROGRA~2\4Sync\ShellExt.dll No File
ShellIconOverlayIdentifiers: ShellExt2 -> {C72C6188-BEF2-46E5-A89A-52F0ED75219E} => C:\PROGRA~2\4Sync\ShellExt.dll No File
ShellIconOverlayIdentifiers: ShellExt3 -> {C92F6BC2-AF61-4C0E-80E0-939B8282DDB7} => C:\PROGRA~2\4Sync\ShellExt.dll No File
ShellIconOverlayIdentifiers: ShellExt4 -> {CB1EFEF8-D5E0-49D1-B768-41B48B1D7803} => C:\PROGRA~2\4Sync\ShellExt.dll No File
ShellIconOverlayIdentifiers-x32:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} -  No File
S3 AthBTPort; system32\DRIVERS\btath_flt.sys [X]
S3 BTATH_A2DP; system32\drivers\btath_a2dp.sys [X]
S3 BTATH_BUS; system32\DRIVERS\btath_bus.sys [X]
S3 BTATH_HCRP; system32\DRIVERS\btath_hcrp.sys [X]
S3 BTATH_LWFLT; system32\DRIVERS\btath_lwflt.sys [X]
S3 BTATH_RCP; system32\DRIVERS\btath_rcp.sys [X]
Task: {023A39CA-B81F-45BE-A533-EF9036D9CBA2} - \{46783191-2F47-47C7-9920-36199D125C45} No Task File <==== ATTENTION
Task: {03E6643C-2860-4B4E-8F05-920742ACDA30} - \UpdateDetector No Task File <==== ATTENTION
Task: {11CC10FA-7369-457A-891D-6A6F9E5677EF} - \GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1001Core No Task File <==== ATTENTION
Task: {14F9F31C-98E3-4C5B-AD6A-234BD36B96C5} - \{8C9A90EF-DB0D-429E-AB71-A966CDB24853} No Task File <==== ATTENTION
Task: {17310746-4F8D-45FA-8F70-82C65A4E7E44} - \{B114C606-7D6F-465B-AF4B-F473639402D8} No Task File <==== ATTENTION
Task: {17BEBFA6-8150-46D2-B772-2EA886B0BB87} - \{EAAC4E7B-0449-41FE-9873-0288DE92C30F} No Task File <==== ATTENTION
Task: {227E1B82-3545-48D8-98EE-002C73D4A036} - \{DBEE4DE9-4152-4900-A5FD-C7AF58E34090} No Task File <==== ATTENTION
Task: {227E1B82-3545-48D8-98EE-002C73D4A036} - \{DBEE4DE9-4152-4900-A5FD-C7AF58E34090} No Task File <==== ATTENTION
Task: {2E2B3DAC-250A-473C-B20A-2986842A341A} - \{D1E8FE10-C7FD-4E65-AAD1-4376B6F0099C} No Task File <==== ATTENTION
Task: {2ED33AE3-1693-4461-B299-14861E1ED401} - \WPD\SqmUpload_S-1-5-21-206095162-3907483975-2766088746-1001 No Task File <==== ATTENTION
Task: {31437387-CBA2-4F17-B330-521762B94B4F} - \{47F63112-15AA-46C8-9093-072903594547} No Task File <==== ATTENTION
Task: {33F2AEAE-26D6-4926-951C-CAD6A9C50E6E} - \Launch HTC Sync Loader No Task File <==== ATTENTION
Task: {393207A2-9536-4CA6-AE83-98F6591D7B77} - \GoogleUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {3C6F5617-E807-434E-BFD2-810775D58BB2} - \GlaryInitialize No Task File <==== ATTENTION
Task: {4517D62D-8A0E-4A9E-9ABE-7CE435AB385F} - \{F321CB4D-FB30-45DD-8561-5628E38837FF} No Task File <==== ATTENTION
Task: {469B426C-D10D-428C-A234-EA924A4B1317} - \MyDefrag v4.3.1 Monthly No Task File <==== ATTENTION
Task: {512C5724-CB2A-4FA4-8751-1BD7511CFBAC} - \Your File Updater No Task File <==== ATTENTION
Task: {56F3838B-CCCD-457A-996B-C6337B263A53} - \{CFC8525B-6C8D-4282-9196-556052535301} No Task File <==== ATTENTION
Task: {5B789D7F-80E7-42C1-B32C-68FE67C2D486} - \{E546D740-9269-4B06-BA9C-E6CCF2C630A2} No Task File <==== ATTENTION
Task: {74AD3DF6-5FD5-4828-851E-FDF96C252337} - \{78885173-A9B0-4ADE-8AF8-C0940749A0EF} No Task File <==== ATTENTION
Task: {75D4D80B-A007-4431-8445-3F2BA63D4FC3} - \GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1001UA No Task File <==== ATTENTION
Task: {78FFA950-D84A-4BDD-A708-BCABB5D6EBAA} - \{38E3A762-C88D-4CAF-B299-234C7AA1723D} No Task File <==== ATTENTION
Task: {7911F72F-836B-4A96-A078-782F310634C2} - \{D1E8F289-38A2-4B31-9E6A-B1658427B606} No Task File <==== ATTENTION
Task: {79A07BCD-E068-4B98-8BF2-69A57D6A56AA} - \{864696D7-6AA0-4927-8571-05D8CDFD7011} No Task File <==== ATTENTION
Task: {8848134F-FDE1-4849-BF5E-1276D37E4C74} - \{5C26FD86-1886-42AF-A780-96B17797AED8} No Task File <==== ATTENTION
Task: {8894C045-417A-43DC-80D9-35821A6B9D6D} - \{276C65B5-73F4-4310-B0BA-51650225A19C} No Task File <==== ATTENTION
Task: {900A4931-8344-411F-A66E-CA4F9C9A220E} - \{AF880A57-FD8F-4997-A643-DD5D04AF8D0C} No Task File <==== ATTENTION
Task: {90713902-E490-4D3E-834A-6D4484A5291C} - \{DCC8136D-0B71-4A25-A253-87AB91B5D3D3} No Task File <==== ATTENTION
Task: {93795EC4-223F-4418-B6DF-EE15C307230D} - \{FBFC1B7E-E577-4F51-AEF9-48DEEE7C6C7D} No Task File <==== ATTENTION
Task: {95C1A018-65D1-47FB-9109-3A4F4CADA495} - \{31B95A9F-5195-4B9E-839A-62781C73D702} No Task File <==== ATTENTION
Task: {97CE3BB8-02D5-48B4-B52E-B4C7EB38D142} - \{7D0B4C01-A1A1-4BE3-B028-793DA4E56287} No Task File <==== ATTENTION
Task: {9AD834B7-8A0A-4975-B36B-DB0D9F8E9AB5} - \{AA8ACD7D-E06A-411A-A724-91CA5D18AE6B} No Task File <==== ATTENTION
Task: {A4EE7BD8-0532-4F84-9CC7-3B91D93BED31} - \{B9360553-D111-4C5C-A8BD-9A132307C654} No Task File <==== ATTENTION
Task: {A8DAFAD8-35E8-4C4C-A5C6-BF857D9A6877} - \YourFile Update No Task File <==== ATTENTION
Task: {AADECE4B-E0B6-4350-BFCE-77E4A13B6CBB} - \{C311F751-0A59-4257-9F9E-67849DC68B61} No Task File <==== ATTENTION
Task: {B942CB64-8FE4-4CCA-9F05-3F823380FF9D} - \Start Evernote Client No Task File <==== ATTENTION
Task: {BB12048C-02D5-4C39-BB66-7D43148686ED} - \{1B2574BA-1D8E-4609-BF0C-8CDEDD53BECC} No Task File <==== ATTENTION
Task: {BE3705A9-C5D4-4E2E-8E7A-296B8CF1DE8D} - \{27F2279B-AB6E-4C3C-941B-3AA3BC61557A} No Task File <==== ATTENTION
Task: {CA3CB49C-9453-4FE1-8B77-0950E7D6A032} - \GoogleUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {D0E6FFF2-D2B7-47BE-ABA9-FBB3C89E9A05} - \{F2FB100C-F032-407F-A6E9-DD9FEFFE0D14} No Task File <==== ATTENTION
Task: {D3379FD9-5A4B-4CB0-BCEF-7B99D34588EE} - \Wise Disk Cleaner Schedule Task No Task File <==== ATTENTION
Task: {D4F24226-9E19-4EBA-A509-B2169DDFA4BF} - \Adobe Flash Player Updater No Task File <==== ATTENTION
Task: {DA05E22E-E0CB-4C48-AA2E-2C91EB7C4EC8} - \{6CD5B765-B8FA-4EF9-9783-AFDFC5A967BB} No Task File <==== ATTENTION
Task: {DB676F60-7DB8-448A-B40F-61B7CAF450A1} - \MyDefrag v4.3.1 Daily No Task File <==== ATTENTION
Task: {DBEA8735-643B-4DA1-AF6B-F4D5FA29870E} - \{AD167814-17F6-4FA2-ABF0-626D451AAA24} No Task File <==== ATTENTION
Task: {E3163C33-301D-4730-A266-5518C5ED3967} - System32\Tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask
Task: {FA54E18A-0F8C-4E19-ACCB-52E4F05B8C6B} - \{BCB50BFA-008A-4413-948F-7A1355AE1821} No Task File <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => ?
Task: C:\Windows\Tasks\GlaryInitialize.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1001Core.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1001UA.job => ?
Task: C:\Windows\Tasks\UpdateDetector.job => ?
Task: C:\Windows\Tasks\Wise Disk Cleaner Schedule Task.job => ?
  • Launch FRST and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

ListParts by Farbar for 64 bit Systems Including BCD Information

--------------------
  • Please download ListParts64.exe (for 64 bit systems), or and save it to your desktop
  • Double click the icon to launch the program
  • Select Run
  • Place a check mark in the List BCD box
  • Select Scan
  • Select OK and wait for a Result - Notepad document to open on your desktop
  • Please copy and paste the contents in your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Fixlog
  • ListParts log

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#6 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 38,133 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:51 AM

Posted 07 August 2014 - 08:18 PM

Greetings,

===================================================

3 Day Bump

It has been more than 3 days since my last post.
  • Do you still need help with this?
  • If after 48hrs you have not replied to this thread then it will have to be closed.

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#7 LAFitzou

LAFitzou
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:04:51 PM

Posted 08 August 2014 - 09:18 AM

So sorry Gary.  I have been waiting for your reply but did not receive any notice until your 'nudge' this morning.  In any case, the results you requested are below.  Please note that I have uninstalled my registry cleaner and run the MS fix as well. 

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-08-2014
Ran by Laurie at 2014-08-08 07:59:57 Run:2
Running from C:\Users\Laurie\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
ShellIconOverlayIdentifiers:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers: GDriveSharedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  No File
ShellIconOverlayIdentifiers: ShellExt1 -> {2012DE06-50C0-48BD-ACDE-88F95D4CAD1F} => C:\PROGRA~2\4Sync\ShellExt.dll No File
ShellIconOverlayIdentifiers: ShellExt2 -> {C72C6188-BEF2-46E5-A89A-52F0ED75219E} => C:\PROGRA~2\4Sync\ShellExt.dll No File
ShellIconOverlayIdentifiers: ShellExt3 -> {C92F6BC2-AF61-4C0E-80E0-939B8282DDB7} => C:\PROGRA~2\4Sync\ShellExt.dll No File
ShellIconOverlayIdentifiers: ShellExt4 -> {CB1EFEF8-D5E0-49D1-B768-41B48B1D7803} => C:\PROGRA~2\4Sync\ShellExt.dll No File
ShellIconOverlayIdentifiers-x32:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} -  No File
S3 AthBTPort; system32\DRIVERS\btath_flt.sys [X]
S3 BTATH_A2DP; system32\drivers\btath_a2dp.sys [X]
S3 BTATH_BUS; system32\DRIVERS\btath_bus.sys [X]
S3 BTATH_HCRP; system32\DRIVERS\btath_hcrp.sys [X]
S3 BTATH_LWFLT; system32\DRIVERS\btath_lwflt.sys [X]
S3 BTATH_RCP; system32\DRIVERS\btath_rcp.sys [X]
Task: {023A39CA-B81F-45BE-A533-EF9036D9CBA2} - \{46783191-2F47-47C7-9920-36199D125C45} No Task File <==== ATTENTION
Task: {03E6643C-2860-4B4E-8F05-920742ACDA30} - \UpdateDetector No Task File <==== ATTENTION
Task: {11CC10FA-7369-457A-891D-6A6F9E5677EF} - \GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1001Core No Task File <==== ATTENTION
Task: {14F9F31C-98E3-4C5B-AD6A-234BD36B96C5} - \{8C9A90EF-DB0D-429E-AB71-A966CDB24853} No Task File <==== ATTENTION
Task: {17310746-4F8D-45FA-8F70-82C65A4E7E44} - \{B114C606-7D6F-465B-AF4B-F473639402D8} No Task File <==== ATTENTION
Task: {17BEBFA6-8150-46D2-B772-2EA886B0BB87} - \{EAAC4E7B-0449-41FE-9873-0288DE92C30F} No Task File <==== ATTENTION
Task: {227E1B82-3545-48D8-98EE-002C73D4A036} - \{DBEE4DE9-4152-4900-A5FD-C7AF58E34090} No Task File <==== ATTENTION
Task: {227E1B82-3545-48D8-98EE-002C73D4A036} - \{DBEE4DE9-4152-4900-A5FD-C7AF58E34090} No Task File <==== ATTENTION
Task: {2E2B3DAC-250A-473C-B20A-2986842A341A} - \{D1E8FE10-C7FD-4E65-AAD1-4376B6F0099C} No Task File <==== ATTENTION
Task: {2ED33AE3-1693-4461-B299-14861E1ED401} - \WPD\SqmUpload_S-1-5-21-206095162-3907483975-2766088746-1001 No Task File <==== ATTENTION
Task: {31437387-CBA2-4F17-B330-521762B94B4F} - \{47F63112-15AA-46C8-9093-072903594547} No Task File <==== ATTENTION
Task: {33F2AEAE-26D6-4926-951C-CAD6A9C50E6E} - \Launch HTC Sync Loader No Task File <==== ATTENTION
Task: {393207A2-9536-4CA6-AE83-98F6591D7B77} - \GoogleUpdateTaskMachineCore No Task File <==== ATTENTION
Task: {3C6F5617-E807-434E-BFD2-810775D58BB2} - \GlaryInitialize No Task File <==== ATTENTION
Task: {4517D62D-8A0E-4A9E-9ABE-7CE435AB385F} - \{F321CB4D-FB30-45DD-8561-5628E38837FF} No Task File <==== ATTENTION
Task: {469B426C-D10D-428C-A234-EA924A4B1317} - \MyDefrag v4.3.1 Monthly No Task File <==== ATTENTION
Task: {512C5724-CB2A-4FA4-8751-1BD7511CFBAC} - \Your File Updater No Task File <==== ATTENTION
Task: {56F3838B-CCCD-457A-996B-C6337B263A53} - \{CFC8525B-6C8D-4282-9196-556052535301} No Task File <==== ATTENTION
Task: {5B789D7F-80E7-42C1-B32C-68FE67C2D486} - \{E546D740-9269-4B06-BA9C-E6CCF2C630A2} No Task File <==== ATTENTION
Task: {74AD3DF6-5FD5-4828-851E-FDF96C252337} - \{78885173-A9B0-4ADE-8AF8-C0940749A0EF} No Task File <==== ATTENTION
Task: {75D4D80B-A007-4431-8445-3F2BA63D4FC3} - \GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1001UA No Task File <==== ATTENTION
Task: {78FFA950-D84A-4BDD-A708-BCABB5D6EBAA} - \{38E3A762-C88D-4CAF-B299-234C7AA1723D} No Task File <==== ATTENTION
Task: {7911F72F-836B-4A96-A078-782F310634C2} - \{D1E8F289-38A2-4B31-9E6A-B1658427B606} No Task File <==== ATTENTION
Task: {79A07BCD-E068-4B98-8BF2-69A57D6A56AA} - \{864696D7-6AA0-4927-8571-05D8CDFD7011} No Task File <==== ATTENTION
Task: {8848134F-FDE1-4849-BF5E-1276D37E4C74} - \{5C26FD86-1886-42AF-A780-96B17797AED8} No Task File <==== ATTENTION
Task: {8894C045-417A-43DC-80D9-35821A6B9D6D} - \{276C65B5-73F4-4310-B0BA-51650225A19C} No Task File <==== ATTENTION
Task: {900A4931-8344-411F-A66E-CA4F9C9A220E} - \{AF880A57-FD8F-4997-A643-DD5D04AF8D0C} No Task File <==== ATTENTION
Task: {90713902-E490-4D3E-834A-6D4484A5291C} - \{DCC8136D-0B71-4A25-A253-87AB91B5D3D3} No Task File <==== ATTENTION
Task: {93795EC4-223F-4418-B6DF-EE15C307230D} - \{FBFC1B7E-E577-4F51-AEF9-48DEEE7C6C7D} No Task File <==== ATTENTION
Task: {95C1A018-65D1-47FB-9109-3A4F4CADA495} - \{31B95A9F-5195-4B9E-839A-62781C73D702} No Task File <==== ATTENTION
Task: {97CE3BB8-02D5-48B4-B52E-B4C7EB38D142} - \{7D0B4C01-A1A1-4BE3-B028-793DA4E56287} No Task File <==== ATTENTION
Task: {9AD834B7-8A0A-4975-B36B-DB0D9F8E9AB5} - \{AA8ACD7D-E06A-411A-A724-91CA5D18AE6B} No Task File <==== ATTENTION
Task: {A4EE7BD8-0532-4F84-9CC7-3B91D93BED31} - \{B9360553-D111-4C5C-A8BD-9A132307C654} No Task File <==== ATTENTION
Task: {A8DAFAD8-35E8-4C4C-A5C6-BF857D9A6877} - \YourFile Update No Task File <==== ATTENTION
Task: {AADECE4B-E0B6-4350-BFCE-77E4A13B6CBB} - \{C311F751-0A59-4257-9F9E-67849DC68B61} No Task File <==== ATTENTION
Task: {B942CB64-8FE4-4CCA-9F05-3F823380FF9D} - \Start Evernote Client No Task File <==== ATTENTION
Task: {BB12048C-02D5-4C39-BB66-7D43148686ED} - \{1B2574BA-1D8E-4609-BF0C-8CDEDD53BECC} No Task File <==== ATTENTION
Task: {BE3705A9-C5D4-4E2E-8E7A-296B8CF1DE8D} - \{27F2279B-AB6E-4C3C-941B-3AA3BC61557A} No Task File <==== ATTENTION
Task: {CA3CB49C-9453-4FE1-8B77-0950E7D6A032} - \GoogleUpdateTaskMachineUA No Task File <==== ATTENTION
Task: {D0E6FFF2-D2B7-47BE-ABA9-FBB3C89E9A05} - \{F2FB100C-F032-407F-A6E9-DD9FEFFE0D14} No Task File <==== ATTENTION
Task: {D3379FD9-5A4B-4CB0-BCEF-7B99D34588EE} - \Wise Disk Cleaner Schedule Task No Task File <==== ATTENTION
Task: {D4F24226-9E19-4EBA-A509-B2169DDFA4BF} - \Adobe Flash Player Updater No Task File <==== ATTENTION
Task: {DA05E22E-E0CB-4C48-AA2E-2C91EB7C4EC8} - \{6CD5B765-B8FA-4EF9-9783-AFDFC5A967BB} No Task File <==== ATTENTION
Task: {DB676F60-7DB8-448A-B40F-61B7CAF450A1} - \MyDefrag v4.3.1 Daily No Task File <==== ATTENTION
Task: {DBEA8735-643B-4DA1-AF6B-F4D5FA29870E} - \{AD167814-17F6-4FA2-ABF0-626D451AAA24} No Task File <==== ATTENTION
Task: {E3163C33-301D-4730-A266-5518C5ED3967} - System32\Tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask
Task: {FA54E18A-0F8C-4E19-ACCB-52E4F05B8C6B} - \{BCB50BFA-008A-4413-948F-7A1355AE1821} No Task File <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => ?
Task: C:\Windows\Tasks\GlaryInitialize.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1001Core.job => ?
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1001UA.job => ?
Task: C:\Windows\Tasks\UpdateDetector.job => ?
Task: C:\Windows\Tasks\Wise Disk Cleaner Schedule Task.job => ?
*****************

"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive1" => Key deleted successfully.
"HKCR\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive2" => Key deleted successfully.
"HKCR\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive3" => Key deleted successfully.
"HKCR\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}" => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\GDriveSharedOverlay" => Key deleted successfully.
"HKCR\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}" => Key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ShellExt1" => Key deleted successfully.
"HKCR\CLSID\{2012DE06-50C0-48BD-ACDE-88F95D4CAD1F}" => Key deleted successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ShellExt2" => Key deleted successfully.
"HKCR\CLSID\{C72C6188-BEF2-46E5-A89A-52F0ED75219E}" => Key deleted successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ShellExt3" => Key deleted successfully.
"HKCR\CLSID\{C92F6BC2-AF61-4C0E-80E0-939B8282DDB7}" => Key deleted successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ShellExt4" => Key deleted successfully.
"HKCR\CLSID\{CB1EFEF8-D5E0-49D1-B768-41B48B1D7803}" => Key deleted successfully.
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive1" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}" => Key not found.
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive2" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}" => Key not found.
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive3" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}" => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
"HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found.
"HKCR\PROTOCOLS\Filter\text/xml" => Key deleted successfully.
"HKCR\CLSID\{807553E5-5146-11D5-A672-00B0D022E945}" => Key not found.
AthBTPort => Service deleted successfully.
BTATH_A2DP => Service deleted successfully.
BTATH_BUS => Service deleted successfully.
BTATH_HCRP => Service deleted successfully.
BTATH_LWFLT => Service deleted successfully.
BTATH_RCP => Service deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{023A39CA-B81F-45BE-A533-EF9036D9CBA2}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{023A39CA-B81F-45BE-A533-EF9036D9CBA2}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{46783191-2F47-47C7-9920-36199D125C45}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{03E6643C-2860-4B4E-8F05-920742ACDA30}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03E6643C-2860-4B4E-8F05-920742ACDA30}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UpdateDetector" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{11CC10FA-7369-457A-891D-6A6F9E5677EF}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{11CC10FA-7369-457A-891D-6A6F9E5677EF}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1001Core" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{14F9F31C-98E3-4C5B-AD6A-234BD36B96C5}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{14F9F31C-98E3-4C5B-AD6A-234BD36B96C5}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8C9A90EF-DB0D-429E-AB71-A966CDB24853}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{17310746-4F8D-45FA-8F70-82C65A4E7E44}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{17310746-4F8D-45FA-8F70-82C65A4E7E44}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B114C606-7D6F-465B-AF4B-F473639402D8}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{17BEBFA6-8150-46D2-B772-2EA886B0BB87}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{17BEBFA6-8150-46D2-B772-2EA886B0BB87}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{EAAC4E7B-0449-41FE-9873-0288DE92C30F}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{227E1B82-3545-48D8-98EE-002C73D4A036}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{227E1B82-3545-48D8-98EE-002C73D4A036}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{DBEE4DE9-4152-4900-A5FD-C7AF58E34090}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{227E1B82-3545-48D8-98EE-002C73D4A036}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{DBEE4DE9-4152-4900-A5FD-C7AF58E34090}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2E2B3DAC-250A-473C-B20A-2986842A341A}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2E2B3DAC-250A-473C-B20A-2986842A341A}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D1E8FE10-C7FD-4E65-AAD1-4376B6F0099C}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2ED33AE3-1693-4461-B299-14861E1ED401}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2ED33AE3-1693-4461-B299-14861E1ED401}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WPD\SqmUpload_S-1-5-21-206095162-3907483975-2766088746-1001" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{31437387-CBA2-4F17-B330-521762B94B4F}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{31437387-CBA2-4F17-B330-521762B94B4F}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{47F63112-15AA-46C8-9093-072903594547}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{33F2AEAE-26D6-4926-951C-CAD6A9C50E6E}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{33F2AEAE-26D6-4926-951C-CAD6A9C50E6E}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Launch HTC Sync Loader" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{393207A2-9536-4CA6-AE83-98F6591D7B77}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{393207A2-9536-4CA6-AE83-98F6591D7B77}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3C6F5617-E807-434E-BFD2-810775D58BB2}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3C6F5617-E807-434E-BFD2-810775D58BB2}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GlaryInitialize" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4517D62D-8A0E-4A9E-9ABE-7CE435AB385F}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4517D62D-8A0E-4A9E-9ABE-7CE435AB385F}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F321CB4D-FB30-45DD-8561-5628E38837FF}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{469B426C-D10D-428C-A234-EA924A4B1317}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{469B426C-D10D-428C-A234-EA924A4B1317}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MyDefrag v4.3.1 Monthly" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{512C5724-CB2A-4FA4-8751-1BD7511CFBAC}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{512C5724-CB2A-4FA4-8751-1BD7511CFBAC}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Your File Updater" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{56F3838B-CCCD-457A-996B-C6337B263A53}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{56F3838B-CCCD-457A-996B-C6337B263A53}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CFC8525B-6C8D-4282-9196-556052535301}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5B789D7F-80E7-42C1-B32C-68FE67C2D486}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5B789D7F-80E7-42C1-B32C-68FE67C2D486}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{E546D740-9269-4B06-BA9C-E6CCF2C630A2}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{74AD3DF6-5FD5-4828-851E-FDF96C252337}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{74AD3DF6-5FD5-4828-851E-FDF96C252337}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{78885173-A9B0-4ADE-8AF8-C0940749A0EF}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{75D4D80B-A007-4431-8445-3F2BA63D4FC3}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{75D4D80B-A007-4431-8445-3F2BA63D4FC3}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1001UA" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{78FFA950-D84A-4BDD-A708-BCABB5D6EBAA}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{78FFA950-D84A-4BDD-A708-BCABB5D6EBAA}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{38E3A762-C88D-4CAF-B299-234C7AA1723D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7911F72F-836B-4A96-A078-782F310634C2}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7911F72F-836B-4A96-A078-782F310634C2}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{D1E8F289-38A2-4B31-9E6A-B1658427B606}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{79A07BCD-E068-4B98-8BF2-69A57D6A56AA}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79A07BCD-E068-4B98-8BF2-69A57D6A56AA}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{864696D7-6AA0-4927-8571-05D8CDFD7011}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8848134F-FDE1-4849-BF5E-1276D37E4C74}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8848134F-FDE1-4849-BF5E-1276D37E4C74}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5C26FD86-1886-42AF-A780-96B17797AED8}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8894C045-417A-43DC-80D9-35821A6B9D6D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8894C045-417A-43DC-80D9-35821A6B9D6D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{276C65B5-73F4-4310-B0BA-51650225A19C}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{900A4931-8344-411F-A66E-CA4F9C9A220E}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{900A4931-8344-411F-A66E-CA4F9C9A220E}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AF880A57-FD8F-4997-A643-DD5D04AF8D0C}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{90713902-E490-4D3E-834A-6D4484A5291C}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{90713902-E490-4D3E-834A-6D4484A5291C}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{DCC8136D-0B71-4A25-A253-87AB91B5D3D3}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{93795EC4-223F-4418-B6DF-EE15C307230D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{93795EC4-223F-4418-B6DF-EE15C307230D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{FBFC1B7E-E577-4F51-AEF9-48DEEE7C6C7D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{95C1A018-65D1-47FB-9109-3A4F4CADA495}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{95C1A018-65D1-47FB-9109-3A4F4CADA495}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{31B95A9F-5195-4B9E-839A-62781C73D702}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{97CE3BB8-02D5-48B4-B52E-B4C7EB38D142}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{97CE3BB8-02D5-48B4-B52E-B4C7EB38D142}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{7D0B4C01-A1A1-4BE3-B028-793DA4E56287}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9AD834B7-8A0A-4975-B36B-DB0D9F8E9AB5}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9AD834B7-8A0A-4975-B36B-DB0D9F8E9AB5}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AA8ACD7D-E06A-411A-A724-91CA5D18AE6B}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A4EE7BD8-0532-4F84-9CC7-3B91D93BED31}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A4EE7BD8-0532-4F84-9CC7-3B91D93BED31}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B9360553-D111-4C5C-A8BD-9A132307C654}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A8DAFAD8-35E8-4C4C-A5C6-BF857D9A6877}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A8DAFAD8-35E8-4C4C-A5C6-BF857D9A6877}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YourFile Update" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AADECE4B-E0B6-4350-BFCE-77E4A13B6CBB}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AADECE4B-E0B6-4350-BFCE-77E4A13B6CBB}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C311F751-0A59-4257-9F9E-67849DC68B61}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B942CB64-8FE4-4CCA-9F05-3F823380FF9D}" => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Start Evernote Client" => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BB12048C-02D5-4C39-BB66-7D43148686ED}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BB12048C-02D5-4C39-BB66-7D43148686ED}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1B2574BA-1D8E-4609-BF0C-8CDEDD53BECC}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BE3705A9-C5D4-4E2E-8E7A-296B8CF1DE8D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BE3705A9-C5D4-4E2E-8E7A-296B8CF1DE8D}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{27F2279B-AB6E-4C3C-941B-3AA3BC61557A}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CA3CB49C-9453-4FE1-8B77-0950E7D6A032}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CA3CB49C-9453-4FE1-8B77-0950E7D6A032}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D0E6FFF2-D2B7-47BE-ABA9-FBB3C89E9A05}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D0E6FFF2-D2B7-47BE-ABA9-FBB3C89E9A05}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{F2FB100C-F032-407F-A6E9-DD9FEFFE0D14}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D3379FD9-5A4B-4CB0-BCEF-7B99D34588EE}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D3379FD9-5A4B-4CB0-BCEF-7B99D34588EE}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Wise Disk Cleaner Schedule Task" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D4F24226-9E19-4EBA-A509-B2169DDFA4BF}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D4F24226-9E19-4EBA-A509-B2169DDFA4BF}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DA05E22E-E0CB-4C48-AA2E-2C91EB7C4EC8}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DA05E22E-E0CB-4C48-AA2E-2C91EB7C4EC8}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6CD5B765-B8FA-4EF9-9783-AFDFC5A967BB}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DB676F60-7DB8-448A-B40F-61B7CAF450A1}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DB676F60-7DB8-448A-B40F-61B7CAF450A1}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MyDefrag v4.3.1 Daily" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DBEA8735-643B-4DA1-AF6B-F4D5FA29870E}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DBEA8735-643B-4DA1-AF6B-F4D5FA29870E}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AD167814-17F6-4FA2-ABF0-626D451AAA24}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E3163C33-301D-4730-A266-5518C5ED3967}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3163C33-301D-4730-A266-5518C5ED3967}" => Key deleted successfully.
C:\Windows\System32\Tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Bluetooth\UninstallDeviceTask" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FA54E18A-0F8C-4E19-ACCB-52E4F05B8C6B}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FA54E18A-0F8C-4E19-ACCB-52E4F05B8C6B}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{BCB50BFA-008A-4413-948F-7A1355AE1821}" => Key deleted successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\GlaryInitialize.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1001Core.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1001UA.job => Moved successfully.
C:\Windows\Tasks\UpdateDetector.job => Moved successfully.
C:\Windows\Tasks\Wise Disk Cleaner Schedule Task.job => Moved successfully.

==== End of Fixlog ====

 

ListParts by Farbar Version: 31-07-2014
Ran by Laurie (administrator) on 08-08-2014 at 08:11:44
Windows 7 (X64)
Running From: C:\Users\Laurie\Desktop
Language: English (United States)
************************************************************

========================= Memory info ======================

Percentage of memory in use: 58%
Total physical RAM: 3956.43 MB
Available physical RAM: 1648.02 MB
Total Pagefile: 7911.05 MB
Available Pagefile: 4528.46 MB
Total Virtual: 8192 MB
Available Virtual: 8191.91 MB

======================= Partitions =========================

1 Drive c: (Orgmind) (Fixed) (Total:113.79 GB) (Free:36.66 GB) NTFS
2 Drive d: (DATA) (Fixed) (Total:368.08 GB) (Free:303.33 GB) NTFS
4 Drive g: (BU-Drive) (Fixed) (Total:465.76 GB) (Free:23.79 GB) NTFS
6 Drive s: () (Fixed) (Total:100.84 GB) (Free:86.05 GB) NTFS

  Disk ###  Status         Size     Free     Dyn  Gpt
  --------  -------------  -------  -------  ---  ---
  Disk 0    Online          596 GB      0 B         
  Disk 1    No Media           0 B      0 B         
  Disk 2    Online          465 GB  1024 KB         

Partitions of Disk 0:
===============

Disk ID: 893FA5EF

  Partition ###  Type              Size     Offset
  -------------  ----------------  -------  -------
  Partition 1    Recovery            13 GB  1024 KB
  Partition 2    Primary            100 MB    13 GB
  Partition 3    Primary            113 GB    13 GB
  Partition 0    Extended           468 GB   126 GB
  Partition 4    Logical            368 GB   126 GB
  Partition 5    Logical            100 GB   494 GB

======================================================================================================

Disk: 0
Partition 1
Type  : 27
Hidden: Yes
Active: No

  Volume ###  Ltr  Label        Fs     Type        Size     Status     Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 5         PQSERVICE    NTFS   Partition     13 GB  Healthy    Hidden  

======================================================================================================

Disk: 0
Partition 2
Type  : 07
Hidden: No
Active: Yes

  Volume ###  Ltr  Label        Fs     Type        Size     Status     Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 1         SYSTEM RESE  NTFS   Partition    100 MB  Healthy    System (partition with boot components)  

======================================================================================================

Disk: 0
Partition 3
Type  : 07
Hidden: No
Active: No

  Volume ###  Ltr  Label        Fs     Type        Size     Status     Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 2     C   Orgmind      NTFS   Partition    113 GB  Healthy    Boot    

======================================================================================================

Disk: 0
Partition 4
Type  : 07
Hidden: No
Active: No

  Volume ###  Ltr  Label        Fs     Type        Size     Status     Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 3     D   DATA         NTFS   Partition    368 GB  Healthy            

======================================================================================================

Disk: 0
Partition 5
Type  : 07
Hidden: No
Active: No

  Volume ###  Ltr  Label        Fs     Type        Size     Status     Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 4     S                NTFS   Partition    100 GB  Healthy            

======================================================================================================

Partitions of Disk 2:
===============

Disk ID: CB4A53FB

  Partition ###  Type              Size     Offset
  -------------  ----------------  -------  -------
  Partition 1    Primary            465 GB    31 KB

======================================================================================================

Disk: 2
Partition 1
Type  : 07
Hidden: No
Active: No

  Volume ###  Ltr  Label        Fs     Type        Size     Status     Info
  ----------  ---  -----------  -----  ----------  -------  ---------  --------
* Volume 7     G   BU-Drive     NTFS   Partition    465 GB  Healthy            

======================================================================================================
============================== MBR Partition Table ==================

==============================
Partitions of Disk 0:
===============
Disk ID: 893FA5EF
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=114 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=469 GB) - (Type=OF Extended)

==============================
Partitions of Disk 2:
===============
Disk ID: CB4A53FB
Partition 1: (Not Active) - (Size=466 GB) - (Type=07 NTFS)


Windows Boot Manager
--------------------
identifier              {bootmgr}
device                  partition=\Device\HarddiskVolume2
description             Windows Boot Manager
locale                  en-US
inherit                 {globalsettings}
default                 {current}
resumeobject            {86f51ae7-cea7-11e1-bd86-a06aa74c7411}
displayorder            {86f51aee-cea7-11e1-bd86-a06aa74c7411}
                        {current}
toolsdisplayorder       {memdiag}
timeout                 30

Windows Boot Loader
-------------------
identifier              {current}
device                  partition=C:
path                    \Windows\system32\winload.exe
description             Windows 7
locale                  en-US
inherit                 {bootloadersettings}
recoverysequence        {86f51af1-cea7-11e1-bd86-a06aa74c7411}
recoveryenabled         Yes
osdevice                partition=C:
systemroot              \Windows
resumeobject            {86f51ae7-cea7-11e1-bd86-a06aa74c7411}
nx                      OptIn

Windows Boot Loader
-------------------
identifier              {86f51aeb-cea7-11e1-bd86-a06aa74c7411}
device                  ramdisk=[C:]\Recovery\5ef36299-f46f-11e0-9f35-8fef9377b769\Winre.wim,{86f51aec-cea7-11e1-bd86-a06aa74c7411}
path                    \windows\system32\winload.exe
description             Windows Recovery Environment (recovered)
locale                  
osdevice                ramdisk=[C:]\Recovery\5ef36299-f46f-11e0-9f35-8fef9377b769\Winre.wim,{86f51aec-cea7-11e1-bd86-a06aa74c7411}
systemroot              \windows
winpe                   Yes

Windows Boot Loader
-------------------
identifier              {86f51aee-cea7-11e1-bd86-a06aa74c7411}
device                  partition=S:
path                    \Windows\system32\winload.exe
description             Windows Server 2008 R2
locale                  en-US
inherit                 {bootloadersettings}
recoverysequence        {86f51aef-cea7-11e1-bd86-a06aa74c7411}
recoveryenabled         Yes
osdevice                partition=S:
systemroot              \Windows
resumeobject            {86f51aed-cea7-11e1-bd86-a06aa74c7411}
nx                      OptOut

Windows Boot Loader
-------------------
identifier              {86f51aef-cea7-11e1-bd86-a06aa74c7411}
device                  ramdisk=[S:]\Recovery\86f51aef-cea7-11e1-bd86-a06aa74c7411\Winre.wim,{86f51af0-cea7-11e1-bd86-a06aa74c7411}
path                    \windows\system32\winload.exe
description             Windows Recovery Environment
inherit                 {bootloadersettings}
osdevice                ramdisk=[S:]\Recovery\86f51aef-cea7-11e1-bd86-a06aa74c7411\Winre.wim,{86f51af0-cea7-11e1-bd86-a06aa74c7411}
systemroot              \windows
nx                      OptIn
winpe                   Yes

Windows Boot Loader
-------------------
identifier              {86f51af1-cea7-11e1-bd86-a06aa74c7411}
device                  ramdisk=[C:]\Recovery\86f51af1-cea7-11e1-bd86-a06aa74c7411\Winre.wim,{86f51af2-cea7-11e1-bd86-a06aa74c7411}
path                    \windows\system32\winload.exe
description             Windows Recovery Environment
inherit                 {bootloadersettings}
osdevice                ramdisk=[C:]\Recovery\86f51af1-cea7-11e1-bd86-a06aa74c7411\Winre.wim,{86f51af2-cea7-11e1-bd86-a06aa74c7411}
systemroot              \windows
nx                      OptIn
winpe                   Yes

Resume from Hibernate
---------------------
identifier              {86f51ae7-cea7-11e1-bd86-a06aa74c7411}
device                  partition=C:
path                    \Windows\system32\winresume.exe
description             Windows Resume Application
locale                  en-US
inherit                 {resumeloadersettings}
filedevice              partition=C:
filepath                \hiberfil.sys
debugoptionenabled      No

Resume from Hibernate
---------------------
identifier              {86f51aed-cea7-11e1-bd86-a06aa74c7411}
device                  partition=S:
path                    \Windows\system32\winresume.exe
description             Windows Resume Application
locale                  en-US
inherit                 {resumeloadersettings}
filedevice              partition=S:
filepath                \hiberfil.sys
debugoptionenabled      No

Windows Memory Tester
---------------------
identifier              {memdiag}
device                  partition=\Device\HarddiskVolume2
path                    \boot\memtest.exe
description             Windows Memory Diagnostic
locale                  en-US
inherit                 {globalsettings}
badmemoryaccess         Yes

EMS Settings
------------
identifier              {emssettings}
bootems                 Yes

Debugger Settings
-----------------
identifier              {dbgsettings}
debugtype               Serial
debugport               1
baudrate                115200

RAM Defects
-----------
identifier              {badmemory}

Global Settings
---------------
identifier              {globalsettings}
inherit                 {dbgsettings}
                        {emssettings}
                        {badmemory}

Boot Loader Settings
--------------------
identifier              {bootloadersettings}
inherit                 {globalsettings}
                        {hypervisorsettings}

Hypervisor Settings
-------------------
identifier              {hypervisorsettings}
hypervisordebugtype     Serial
hypervisordebugport     1
hypervisorbaudrate      115200

Resume Loader Settings
----------------------
identifier              {resumeloadersettings}
inherit                 {globalsettings}

Device options
--------------
identifier              {86f51aec-cea7-11e1-bd86-a06aa74c7411}
ramdisksdidevice        partition=C:
ramdisksdipath          \Recovery\5ef36299-f46f-11e0-9f35-8fef9377b769\boot.sdi

Device options
--------------
identifier              {86f51af0-cea7-11e1-bd86-a06aa74c7411}
description             Ramdisk Options
ramdisksdidevice        partition=S:
ramdisksdipath          \Recovery\86f51aef-cea7-11e1-bd86-a06aa74c7411\boot.sdi

Device options
--------------
identifier              {86f51af2-cea7-11e1-bd86-a06aa74c7411}
description             Ramdisk Options
ramdisksdidevice        partition=C:
ramdisksdipath          \Recovery\86f51af1-cea7-11e1-bd86-a06aa74c7411\boot.sdi


****** End Of Log ******

 

 



#8 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 38,133 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:51 AM

Posted 08 August 2014 - 10:00 AM

Hi Laurie,

You can pretty much assume I will be replying every single day so if you aren't notified of a reply feel free to check. Outside of sleeping hours I pretty much reply very quickly or within hours.

Are you still getting audio ads?
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#9 LAFitzou

LAFitzou
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:04:51 PM

Posted 08 August 2014 - 10:22 AM

Haven't had one in about 6 days.  Am I fixed?  If so, thank you very much Gary.



#10 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 38,133 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:51 AM

Posted 08 August 2014 - 10:27 AM

Well I don't know if it is fixed or not. Either way we are not quite done yet. Please run this.

===================================================

Run Combofix in Vista/7

--------------------

Combofix is a very powerful tool and special attention must be taken to allow it to work properly. Please pay careful attention to the following instructions.

sUBs, the author of Combofix, recommends you to uninstall AVG or CA Internet Security before running the program. If you have either of these programs on your computer please uninstall them using AppRemover which can be downloaded here. We will be sure to reinstall the Antivirus program once we are finished using Combofix.

  • Please download ComboFix from one of these locations:

BleepingComputer
ForoSpyware

  • Save Combofix.exe to your Desktop <-- Important!!!
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Double click on Combofix.exe and follow the prompts. It is important you do not mouseclick while the program is running or it may stall.

Note #1: Often times it may appear as if ComboFix has stopped working. To verify it is still running please do one of the following below. If, based on the below, you have concluded ComboFix has stopped running please stop and advise me.

  • Check your computer clock. If it is still running then so is ComboFix
  • Open Task Manager and select the Applications Tab. If the status of AutoScan is Running, then ComboFix is running
  • Open Task Manager and select the Processes Tab. Under Image Name look for files ending in .3xe. If there are fluctuating numbers under CPU and Mem Usage then ComboFix is running

Note #2: If you receive the following error "Illegal operation attempted on a registery key that has been marked for deletion" please just restart your computer to resolve this issue

If Combofix fails to run properly using the above instructions please attempt the following:

  • Right click on the Combofix icon on your desktop and select Delete
  • Download a new copy but rename it to freshcopy.exe first, then save it to your desktop
  • Now download RKill.exe (or RKill renamed as iExplore.exe if the first one doesn't work properly) and save it to your desktop
  • Restart your computer in Safe Mode
  • Right click on RKill (or iExplore) and select Run as Administrator. If you are using Windows XP simply double click the icon
  • A black DOS screen should flash and disappear. If not, try to launch the program with the second file. If neither works please stop and let me know
  • When RKill is finished running you will be presented with a text file and a copy will be saved on your desktop. Copy and paste the contents of this report in your reply
  • Do not reboot your computer
  • Double click the freshcopy.exe icon (renamed Combofix file)
  • When finished, it will produce a log. Please copy and paste the C:\Combofix.txt log information in your next reply
  • If you disabled your antivirus please enable it again. If you uninstalled it please wait for instructions to reinstall it

===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:

  • Combofix log
  • Are you experiencing any issues?

Edited by Oh My!, 09 August 2014 - 02:14 PM.

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#11 LAFitzou

LAFitzou
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:04:51 PM

Posted 10 August 2014 - 01:16 PM

Hi Gary,

 

I don't know what's happening with this but I posted a response including the Combofix log and a note saying I wasn't experiencing any issues several days ago.  But now I see that it did not get posted.  I'm trying again here:

 

ComboFix 14-08-06.02 - Laurie 08/08/2014  14:12:30.1.4 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.3956.1938 [GMT -6:00]
Running from: c:\users\Laurie\Desktop\ComboFix.exe
AV: Emsisoft Anti-Malware *Enabled/Updated* {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
FW: Online Armor Firewall *Enabled* {BD3F5FCA-866B-1E2E-0A68-58900A751EA1}
SP: Emsisoft Anti-Malware *Enabled/Updated* {3E653F0B-EA3E-10F8-1B87-CAD78F211367}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\msoffice
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\1033\CAGCAT10.MML
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\CAGCAT10.DLL
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\CAGCAT10.MMW
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\ELPHRG01.WAV
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0088542.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0090070.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0090386.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0149407.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0149481.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0149627.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0149887.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0157763.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0157995.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0158007.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0183168.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0183290.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0183328.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0185604.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0186002.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0186348.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0187423.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0195384.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0195534.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0195812.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0196164.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0196374.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0196400.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0199036.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0199283.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0199549.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0199661.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0199727.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0199755.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0199805.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0205462.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0205466.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0205582.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0211949.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0212219.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0212661.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0212701.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0212957.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0214098.WAV
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0215086.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0216516.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0216588.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0216724.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0216858.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0217698.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0221903.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0222015.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0222017.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0222019.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0222021.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0229385.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0229389.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0230876.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0233018.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0233070.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0233312.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0234131.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0234266.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0234657.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0234687.GIF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0235241.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0235319.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0240695.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0240719.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0251301.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0251871.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0251925.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0252349.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0278882.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0281904.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0283209.GIF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0284916.JPG
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0285360.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0285410.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0285444.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0285698.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0285750.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0285926.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0286034.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0286068.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0287005.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0291984.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0292020.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0292152.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0292982.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0293234.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0293236.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0293238.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0293240.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0293570.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0293828.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0293844.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0295241.GIF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0297185.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0297551.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0297707.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0297749.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0298653.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0298897.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0299125.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0299171.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0299587.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0299611.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0299763.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0300520.GIF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0300840.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0300912.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0301050.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0301076.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0301252.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0301480.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0302827.JPG
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0302953.JPG
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0304933.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0305257.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0305493.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0315447.JPG
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0332268.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0332364.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0335112.WMF
c:\program files (x86)\msoffice\2003\MEDIA\CAGCAT10\J0336075.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\1033\OFFICE10.MML
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\AUTOSHAP.DLL
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18180_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18181_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18182_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18184_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18185_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18187_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18189_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18190_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18191_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18192_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18193_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18194_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18196_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18197_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18198_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18199_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18200_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18201_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18202_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18203_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18204_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18205_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18206_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18207_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18208_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18209_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18210_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18211_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18212_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18213_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18214_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18215_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18216_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18217_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18218_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18219_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18220_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18221_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18222_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18223_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18224_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18225_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18226_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18227_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18228_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18229_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18230_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18231_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18232_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18233_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18234_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18235_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18236_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18237_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18238_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18239_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18241_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18242_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18243_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18244_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18245_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18246_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18247_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18248_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18249_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18250_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18251_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18252_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18253_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18254_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18255_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18256_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\AUTOSHAP\BD18257_.WMF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD10253_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD10254_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD10255_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD10263_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD10264_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD10265_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD10266_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD10267_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD10268_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD10297_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD10298_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD10299_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD10300_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD10301_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD10302_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD10335_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD10336_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD10337_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14513_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14514_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14515_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14528_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14529_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14530_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14531_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14532_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14533_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14565_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14578_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14579_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14580_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14581_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14582_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14583_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14654_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14655_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14656_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14691_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14692_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14693_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14752_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14753_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14754_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14755_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14756_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14757_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14790_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14791_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14792_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14793_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14794_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14795_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14828_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14829_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14830_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14831_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14832_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14833_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14866_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14867_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14868_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14869_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14870_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14871_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14980_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14981_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14982_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14983_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14984_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD14985_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15018_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15019_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15020_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15021_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15022_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15023_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15056_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15057_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15058_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15059_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15060_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15061_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15132_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15133_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15134_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15135_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15136_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15168_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15169_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15170_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15171_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15172_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15173_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15272_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15273_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15274_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15275_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15276_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD15277_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21294_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21295_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21296_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21297_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21298_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21299_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21300_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21301_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21302_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21304_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21306_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21308_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21310_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21312_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21314_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21316_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21327_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21329_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21331_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21333_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21335_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21337_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21339_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21342_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21343_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21344_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21364_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21365_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21366_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21375_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21376_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21377_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21398_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21399_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21400_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21421_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21422_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21423_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21433_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21434_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21435_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21480_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21481_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21482_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21503_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21504_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21505_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21518_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21519_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21520_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21533_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21534_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BD21535_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\BULLETS.DLL
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\J0115834.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\J0115835.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\J0115836.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\J0115839.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\J0115840.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\J0115841.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\J0115842.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\J0115843.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\J0115844.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\J0115863.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\J0115864.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\J0115865.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\J0115866.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\J0115867.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\BULLETS\J0115868.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD10219_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD10256_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD10289_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD10290_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD10307_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD10308_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD10358_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD14516_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD14538_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD14539_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD14594_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD14595_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD14677_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD14710_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD14711_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD14768_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD14769_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD14800_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD14801_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD14844_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD14845_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD14882_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD14883_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD14996_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD14997_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD15034_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD15035_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD15072_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD15073_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD15155_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD15156_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD15184_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD15185_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD15301_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD15302_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21303_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21305_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21307_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21309_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21311_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21313_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21315_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21318_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21319_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21320_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21321_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21322_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21323_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21324_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21325_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21326_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21328_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21330_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21332_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21334_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21336_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21338_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21340_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21348_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21370_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21390_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21413_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21427_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21448_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21495_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21512_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21527_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\BD21548_.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\J0115855.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\J0115856.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\J0115875.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\J0115876.GIF
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\LINES\LINES.DLL
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\OFFICE10.DLL
c:\program files (x86)\msoffice\2003\MEDIA\OFFICE11\OFFICE10.MMW
c:\program files (x86)\msoffice\2003\OFFICE11\1033\011\SKU011.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\ADO.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\2COLCMA.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\2COLFRM.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\BARS.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\BRACKETS.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\BULTITL.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\COMMAS.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\COMPNT.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\DOTS.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\DRPDWN.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\HISTORY.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\HORZTITL.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\LSTVIEWS.INI
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\MOREDOTS.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\NAVBARS.INI
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\NUMTITL.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\PLNTITL.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\REPFORM1.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\REPFORM2.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\REPFORM3.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\SLASHES.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\TABLE.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\TABULAR.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\BOTSTYLE\UNDRLINE.GIF
c:\program files (x86)\msoffice\2003\OFFICE11\1033\CATOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\DAO.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\DataServices\+Connect to New Data Source.odc
c:\program files (x86)\msoffice\2003\OFFICE11\1033\DataServices\+New SQL Server Connection.odc
c:\program files (x86)\msoffice\2003\OFFICE11\1033\DataServices\DATACONN.HTC
c:\program files (x86)\msoffice\2003\OFFICE11\1033\DataServices\DESKTOP.INI
c:\program files (x86)\msoffice\2003\OFFICE11\1033\DataServices\FOLDER.ICO
c:\program files (x86)\msoffice\2003\OFFICE11\1033\EMAIL.DOT
c:\program files (x86)\msoffice\2003\OFFICE11\1033\EXPTOOWS.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\EXPTOOWS.XLA
c:\program files (x86)\msoffice\2003\OFFICE11\1033\FM20.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\GR8GALRY.GRA
c:\program files (x86)\msoffice\2003\OFFICE11\1033\GRAPH10.AW
c:\program files (x86)\msoffice\2003\OFFICE11\1033\GRAPH10.CHM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\GRINTL32.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\HTMLREF.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\HTMMINTL.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\HTMQINTL.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\ID_011.DPC
c:\program files (x86)\msoffice\2003\OFFICE11\1033\JETSQL.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\JSCRIPT.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\MF_CATOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\MF_OITOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\MF_PPTOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\MF_WDTOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\MF_XGTOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\MF_XLTOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\MSE10.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\MSETOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\MSO.ACL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\MSOAUTUI.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\MSOHELP.EXE
c:\program files (x86)\msoffice\2003\OFFICE11\1033\MSOHLP11.CHM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\MSOWCWI.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\MSTINTL.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\MSTORE10.AW
c:\program files (x86)\msoffice\2003\OFFICE11\1033\MSTORE10.CHM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\MSWBCLNG.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\OBALLOON.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\OCLTINT.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\OFMAIN11.CHM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\OFREADME.HTM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\OISINTL.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\OISMAIN.AW
c:\program files (x86)\msoffice\2003\OFFICE11\1033\OISMAIN.CHM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\OISTOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\OMFCSAT.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\OWHTOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\OWSHLP10.CHM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\PPINTL.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\PPMAIN10.AW
c:\program files (x86)\msoffice\2003\OFFICE11\1033\PPMAIN10.CHM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\PPREADME.HTM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\PPTOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\PPVWINTL.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\PROTTPLN.DOC
c:\program files (x86)\msoffice\2003\OFFICE11\1033\PROTTPLN.PPT
c:\program files (x86)\msoffice\2003\OFFICE11\1033\PROTTPLN.XLS
c:\program files (x86)\msoffice\2003\OFFICE11\1033\PROTTPLV.DOC
c:\program files (x86)\msoffice\2003\OFFICE11\1033\PROTTPLV.PPT
c:\program files (x86)\msoffice\2003\OFFICE11\1033\PROTTPLV.XLS
c:\program files (x86)\msoffice\2003\OFFICE11\1033\PSS10O.CHM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\PSS10R.CHM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\PVREADME.HTM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\QUIKANIM.PPT
c:\program files (x86)\msoffice\2003\OFFICE11\1033\SETUP.CHM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\SPLTOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\STSLIST.CHM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\STSLISTI.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\STSUCRES.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\VB_GRTOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\VB_PPTOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\VB_WDTOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\VB_XLTOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\VBAOWS10.CHM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\VBCN.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\VBETOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\VBHW.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\VBLR.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\VBOB.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\VBOFTOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\VBOWSTOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\VBSCRIP.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\VBSETOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\WDMAIN10.AW
c:\program files (x86)\msoffice\2003\OFFICE11\1033\WDMAIN11.CHM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\WDREADME.HTM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\WDTOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\WORKFUNC.AW
c:\program files (x86)\msoffice\2003\OFFICE11\1033\WWASUM.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\WWINTL.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\XGTOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\XL8GALRY.XLS
c:\program files (x86)\msoffice\2003\OFFICE11\1033\XLADDIN.CHM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\XLATOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\XLINTL32.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\XLMACRO.CHM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\XLMAIN10.AW
c:\program files (x86)\msoffice\2003\OFFICE11\1033\XLMAIN11.CHM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\XLREADME.HTM
c:\program files (x86)\msoffice\2003\OFFICE11\1033\XLSLICER.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\1033\XLTOC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\1033\XMLSDK.XML
c:\program files (x86)\msoffice\2003\OFFICE11\ADDINS\MSOSEC.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\ADDINS\MSOSEC.XML
c:\program files (x86)\msoffice\2003\OFFICE11\ADDINS\MSVCR71.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\ADDINS\OTKLOADR.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\AUTHZAX.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\AW.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\BIDI32.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\CDLMSO.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\DSITF.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\DSSM.EXE
c:\program files (x86)\msoffice\2003\OFFICE11\EXCEL.EXE
c:\program files (x86)\msoffice\2003\OFFICE11\EXCEL.PIP
c:\program files (x86)\msoffice\2003\OFFICE11\EXLPRTID.XML
c:\program files (x86)\msoffice\2003\OFFICE11\FPCUTL.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\FPDTC.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\GDIPLUS.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\GRAPH.EXE
c:\program files (x86)\msoffice\2003\OFFICE11\HLP95EN.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\HTML\HTMLMARQ.OCX
c:\program files (x86)\msoffice\2003\OFFICE11\HTML\HTMLMM.OCX
c:\program files (x86)\msoffice\2003\OFFICE11\IEAWSDC.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\INTLBAND.HTM
c:\program files (x86)\msoffice\2003\OFFICE11\INTLDATE.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\Library\HTML.XLA
c:\program files (x86)\msoffice\2003\OFFICE11\MCPS.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\Migration\MIGRATE.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\MSN.ICO
c:\program files (x86)\msoffice\2003\OFFICE11\MSOAUTH.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\MSOCF.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\MSOCFU.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\MSODCW.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\MSOHEV.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\MSOHTMED.EXE
c:\program files (x86)\msoffice\2003\OFFICE11\MSOSTYLE.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\MSOWCW.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\MSPPT.OLB
c:\program files (x86)\msoffice\2003\OFFICE11\MSTORDB.EXE
c:\program files (x86)\msoffice\2003\OFFICE11\MSTORE.EXE
c:\program files (x86)\msoffice\2003\OFFICE11\MSTORES.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\MSWEBCAP.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\MSWORD.OLB
c:\program files (x86)\msoffice\2003\OFFICE11\MULTIMGR.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\MULTIQ.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\NAME.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\NPOFFICE.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\OIS.EXE
c:\program files (x86)\msoffice\2003\OFFICE11\OIS.PIP
c:\program files (x86)\msoffice\2003\OFFICE11\OISAPP.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\oisctrl.dll
c:\program files (x86)\msoffice\2003\OFFICE11\OISGRAPH.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\OMFC.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\OPW11USR.INI
c:\program files (x86)\msoffice\2003\OFFICE11\OWSCLT.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\OWSSUPP.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\POWERPNT.EXE
c:\program files (x86)\msoffice\2003\OFFICE11\POWERPOI.PIP
c:\program files (x86)\msoffice\2003\OFFICE11\PPTPRTID.XML
c:\program files (x86)\msoffice\2003\OFFICE11\PPTVIEW.EXE
c:\program files (x86)\msoffice\2003\OFFICE11\PROFLWIZ.EXE
c:\program files (x86)\msoffice\2003\OFFICE11\QUERIES\MSN MoneyCentral Investor Currency Rates.iqy
c:\program files (x86)\msoffice\2003\OFFICE11\QUERIES\MSN MoneyCentral Investor Major Indicies.iqy
c:\program files (x86)\msoffice\2003\OFFICE11\QUERIES\MSN MoneyCentral Investor Stock Quotes.iqy
c:\program files (x86)\msoffice\2003\OFFICE11\REFBAR.ICO
c:\program files (x86)\msoffice\2003\OFFICE11\REFBARH.ICO
c:\program files (x86)\msoffice\2003\OFFICE11\REFEDIT.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\REFIEBAR.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\RESETO11.OPS
c:\program files (x86)\msoffice\2003\OFFICE11\SAEXT.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\SAMPLES\SOLVSAMP.XLS
c:\program files (x86)\msoffice\2003\OFFICE11\SEQCHK10.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\SMSW.CHM
c:\program files (x86)\msoffice\2003\OFFICE11\STSLIST.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\STSUPLD.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\UCSCRIBE.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\UNICOWS.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\WAVTOASF.EXE
c:\program files (x86)\msoffice\2003\OFFICE11\WDBIMP.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\WINWORD.EXE
c:\program files (x86)\msoffice\2003\OFFICE11\WORD.PIP
c:\program files (x86)\msoffice\2003\OFFICE11\WORDMAIL.PIP
c:\program files (x86)\msoffice\2003\OFFICE11\WRDPRTID.XML
c:\program files (x86)\msoffice\2003\OFFICE11\WWPAB.CNV
c:\program files (x86)\msoffice\2003\OFFICE11\XL5EN32.OLB
c:\program files (x86)\msoffice\2003\OFFICE11\XLATORS\PP4X322.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\XLATORS\PP7X32.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\XLCALL32.DLL
c:\program files (x86)\msoffice\2003\OFFICE11\XML2WORD.XSL
c:\program files (x86)\msoffice\2003\Templates\1033\Business Plan.pot
c:\program files (x86)\msoffice\2003\Templates\1033\Communicating Bad News.pot
c:\program files (x86)\msoffice\2003\Templates\1033\Contemporary Fax.dot
c:\program files (x86)\msoffice\2003\Templates\1033\Contemporary Letter.dot
c:\program files (x86)\msoffice\2003\Templates\1033\Contemporary Memo.dot
c:\program files (x86)\msoffice\2003\Templates\1033\Contemporary Report.dot
c:\program files (x86)\msoffice\2003\Templates\1033\Contemporary Resume.dot
c:\program files (x86)\msoffice\2003\Templates\1033\Elegant Fax.dot
c:\program files (x86)\msoffice\2003\Templates\1033\Elegant Letter.dot
c:\program files (x86)\msoffice\2003\Templates\1033\Elegant Memo.dot
c:\program files (x86)\msoffice\2003\Templates\1033\Elegant Report.dot
c:\program files (x86)\msoffice\2003\Templates\1033\Elegant Resume.dot
c:\program files (x86)\msoffice\2003\Templates\1033\Envelope Wizard.wiz
c:\program files (x86)\msoffice\2003\Templates\1033\Fax Wizard.wiz
c:\program files (x86)\msoffice\2003\Templates\1033\FAX\Business Fax.dot
c:\program files (x86)\msoffice\2003\Templates\1033\FAX\Personal Fax.dot
c:\program files (x86)\msoffice\2003\Templates\1033\FAX\Standard Fax.dot
c:\program files (x86)\msoffice\2003\Templates\1033\Financial Overview.pot
c:\program files (x86)\msoffice\2003\Templates\1033\Generic.pot
c:\program files (x86)\msoffice\2003\Templates\1033\LABEL.WIZ
c:\program files (x86)\msoffice\2003\Templates\1033\Letter Wizard.wiz
c:\program files (x86)\msoffice\2003\Templates\1033\Marketing Plan.pot
c:\program files (x86)\msoffice\2003\Templates\1033\Memo Wizard.wiz
c:\program files (x86)\msoffice\2003\Templates\1033\Products And Services Overview.pot
c:\program files (x86)\msoffice\2003\Templates\1033\Professional Fax.dot
c:\program files (x86)\msoffice\2003\Templates\1033\Professional Letter.dot
c:\program files (x86)\msoffice\2003\Templates\1033\Professional Memo.dot
c:\program files (x86)\msoffice\2003\Templates\1033\Professional Report.dot
c:\program files (x86)\msoffice\2003\Templates\1033\Professional Resume.dot
c:\program files (x86)\msoffice\2003\Templates\1033\Project Overview.pot
c:\program files (x86)\msoffice\2003\Templates\1033\Recommending A Strategy.pot
c:\program files (x86)\msoffice\2003\Templates\1033\Reporting Progress or Status.pot
c:\program files (x86)\msoffice\2003\Templates\1033\Resume Wizard.wiz
c:\program files (x86)\msoffice\2003\Templates\1033\Selling a Product or Service.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Balance.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Blends.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Capsules.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Compass.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Crayons.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Curtain Call.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Digital Dots.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Edge.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Fading Grid.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Fireworks.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Glass Layers.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Globe.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Kimono.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Maple.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Mountain Top.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Network.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Ocean.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Pixel.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Profile.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Proposal.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Slit.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Stream.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Textured.pot
c:\program files (x86)\msoffice\2003\Templates\Presentation Designs\Watermark.pot
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\151\SKU151.XML
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\ADO.XML
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\DAO.XML
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\DataServices\+Connect to New Data Source.odc
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\DataServices\+New SQL Server Connection.odc
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\DataServices\DATACONN.HTC
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\DataServices\DESKTOP.INI
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\DataServices\FOLDER.ICO
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\FM20.XML
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\HTMLREF.XML
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\ID_151.DPC
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\JETSQL.XML
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\JSCRIPT.XML
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\MSE10.XML
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\MSETOC.XML
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\MSO.ACL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\MSOAUTUI.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\MSOHELP.EXE
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\MSOHLP11.CHM
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\OBALLOON.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\OFMAIN11.CHM
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\PSS10O.CHM
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\PSS10R.CHM
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\SLINTL.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\VBCN.XML
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\VBETOC.XML
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\VBHW.XML
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\VBLR.XML
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\VBOB.XML
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\VBOFTOC.XML
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\VBSCRIP.XML
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\VBSETOC.XML
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\1033\XMLSDK.XML
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\3082\WWASUM.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\AUTHZAX.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\AW.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\BIDI32.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\DSITF.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\DSSM.EXE
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\GDIPLUS.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\HLP95EN.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\IEAWSDC.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\INTLDATE.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\Migration\MIGRATE.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\MSOAUTH.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\MSODCW.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\MSOHEV.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\MSOHTMED.EXE
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\MSOSTYLE.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\MULTIQ.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\NPOFFICE.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\OPW11USR.INI
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\PROFLWIZ.EXE
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\REFEDIT.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\RESETO11.OPS
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\SAEXT.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\SEQCHK10.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\SETLANG.EXE
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\SMSW.CHM
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\UCSCRIBE.DLL
c:\program files (x86)\msoffice\2003\Visio\OFFICE11\WDBIMP.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ACTDIR_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ACTDIR_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ADO_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ADO_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ADS_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ADS_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\AEC.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\AECUTILS.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ALARM_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ALARM_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ANNOT_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ANNOT_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\APPL_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\APPL_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ARROWS_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ARROWS_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ASSET.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\AUDIT_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\AUDIT_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\AUDIT_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\AUDIT_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BACKGR_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BACKGR_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BASFLO_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BASFLO_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BASFLO_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BASFLO_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BASIC.HTM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BASIC_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BASIC_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BASICD_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BASICD_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BLDCOR_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BLDCOR_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BLNKDG_M.VSD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BLNKDG_U.VSD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BLOCK_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BLOCK_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BLOCK_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BLOCK_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BLOCK3_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BLOCK3_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BLOCKP_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BLOCKP_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BLOCKP_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BLOCKP_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BORDER_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BORDER_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BPDFLO_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BPDFLO_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BPFLO_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BPFLO_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BPRES_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BPRES_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BPXFUN_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BPXFUN_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BSTORM.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BSTORM_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BSTORM_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BSTORM_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BSTORM_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BTHKT_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BTHKT_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\BW.CSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CABNT_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CABNT_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CALEVENT.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CALNDR_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CALNDR_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CALNDR_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CALNDR_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CALOUT_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CALOUT_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CAUSEF_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CAUSEF_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CAUSEF_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CAUSEF_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CEILPL_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CEILPL_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CHART_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CHART_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CHART_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CHART_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CMAXRES.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\COFFEE.CSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\COMOLE_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\COMOLE_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\COMOLE_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\COMOLE_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\COMPS_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\COMPS_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CONLOG_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CONLOG_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CONNEC_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CONNEC_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CS_VOTOC.XML
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CUBICL_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\CUBICL_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DATFLO_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DATFLO_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DATFLO_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DATFLO_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DATMOD_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DATMOD_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DBENGR.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DBMODL_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DBMODL_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DBSAMPLE.MDB
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DBWIZ.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DEFAULT.CSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DIMARC_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DIMENG_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DIMENG_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DOORSCHD.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DRAWTL_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DRAWTL_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DTLNET_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DTLNET_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DTLNET_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\DTLNET_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EDITRES.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EECHIP_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EECHIP_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EECHIP_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EECHIP_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EECOMP_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EECOMP_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EEFUND_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EEFUND_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EEGENR_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EEGENR_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EEICS_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EEICS_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EEMAIN_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EEMAIN_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EEMAPS_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EEMAPS_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EEMECH_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EEMECH_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EEPATH_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EEPATH_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EEQUAL_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EEQUAL_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EESEMI_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EESEMI_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EESWCH_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EESWCH_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EESYS_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EESYS_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EETCOM_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EETCOM_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EETERM_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EETERM_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EETRAN_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EETRAN_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EEVHF_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EEVHF_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ELETEL_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ELETEL_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ELETEL_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ELETEL_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EMBELL_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EMBELL_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ENTAPP_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ENTAPP_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ENTAPP_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ENTAPP_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ENTITY_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ENTITY_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EPC_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EPC_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EPC_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EPC_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EQPLIST.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EXCOBJ_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EXCOBJ_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EXPRG_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EXPRG_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EXPRG_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\EXPRG_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FACILITY.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FASTN1_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FASTN1_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FASTN2_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FASTN2_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FAULT_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FAULT_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FAULT_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FAULT_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FLOCH.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FLOSHP_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FLOSHP_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FLRPLN_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FLRPLN_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FOREST.CSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FPALL_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FPALL_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FPASSM_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FPASSM_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FPEQP_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FPEQP_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FPVALV_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FPVALV_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FREEQP_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FREEQP_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FURN_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\FURN_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\GANESA_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\GANESA_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\GANTT.CSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\GANTT.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\GANTT.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\GANTT_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\GANTT_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\GANTT_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\GANTT_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\GARDEN_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\GARDEN_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\GDT_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\GDT_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\HOMPLN_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\HOMPLN_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\HVAC.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\HVAC_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\HVAC_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\HVACC_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\HVACC_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\HVACCE_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\HVACCE_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\HVACD_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\HVACD_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\HVACDIFF.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\HVACDUCT.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\HVACEQ_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\HVACEQ_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\IDEF0_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\IDEF0_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\IDEF0_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\IDEF0_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\INSTLIST.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\INTANN_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\INTANN_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\INVENTRY.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\IRRIG_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\IRRIG_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\JACKSN_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\JACKSN_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\JACKSN_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\JACKSN_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\JADE.CSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\LANGLV_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\LANGLV_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\LDAPDR_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\LDAPDR_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\LDAPOB_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\LDAPOB_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\LGND.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\LGND_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\LGND_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\LNDMRK_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\LNDMRK_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\LOGIC_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\LOGIC_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MAP_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MAP_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MAP3D_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MAP3D_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MAP3D_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MAP3D_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MEALL_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MEALL_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MEMOBJ_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MEMOBJ_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MERES.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\METRO_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\METRO_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MF_VOTOC.XML
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MF_VPTOC.XML
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MF_VRTOC.XML
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MOVE.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MPXRES.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MRKTDG_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MRKTDG_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MRKTDG_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MRKTDG_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MRKTNG_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\MRKTNG_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NDSADD_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NDSADD_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NDSGRP_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NDSGRP_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NDSOBJ_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NDSOBJ_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NDSPRT_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NDSPRT_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NDSZEN_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NDSZEN_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NETLOC_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NETLOC_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NETRM_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NETRM_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NETSYM_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NETSYM_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NETW_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NETW_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NETWORK.CSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NETWORK1.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NETWORK2.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NETWORK3.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NOVELL_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\NOVELL_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\OBJREL_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\OBJREL_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\OCCMPVRD.XML
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\OCMODVRD.XML
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\OFFACC_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\OFFACC_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\OFFEQP_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\OFFEQP_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\OFFFRN_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\OFFFRN_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\OFFLYT_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\OFFLYT_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\OMFCSAT.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ORGCH.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ORGCH_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ORGCH_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ORGCH_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ORGCH_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ORGCHART.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ORGPOS.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ORGWIZ.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ORGWIZ_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ORGWIZ_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ORM_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ORM_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ORM_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ORM_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PASSPORT.CSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PASTEL.CSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PE.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PEANNT_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PEANNT_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PEDG_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PEDG_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PEEQP_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PEEQP_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PEHEAT_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PEHEAT_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PEINST_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PEINST_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PEPIPE_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PEPIPE_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PEPIPE_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PEPIPE_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PEPUMP_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PEPUMP_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PERIPH_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PERIPH_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PERT_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PERT_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PERT_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PERT_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PEVALV_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PEVALV_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PEVESS_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PEVESS_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PIPE1_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PIPE1_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PIPE2_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PIPE2_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PIPELINE.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PLANT_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PLANT_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PLMPIP_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PLMPIP_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PLTLYT_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PLTLYT_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PLUMB_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PLUMB_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PMENURES.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PRIMARY.CSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PRKRD_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PRKRD_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PROPRPT.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PROPRPT.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PSTRCT_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PSTRCT_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PTSINT_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\PTSINT_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\RACK_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\RACK_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\RCKEQP_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\RCKEQP_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\RECRT_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\RECRT_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\RECSHP_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\RECSHP_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\REGSTR_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\REGSTR_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ROAD_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ROAD_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ROOM_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ROOM_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ROOM_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ROOM_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\ROSE.CSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SAVASWEB.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SDL_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SDL_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SDL_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SDL_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SECACC_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SECACC_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SERVER_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SERVER_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SETUP.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SGRES.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SHAPNUM.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SHPMCH_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SHPMCH_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SHPREC_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SHPREC_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SHPSTR_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SHPSTR_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SITACC_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SITACC_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SITPLN_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SITPLN_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SKY.CSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SMIGRATE.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SPACE.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SPCPLN_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SPCPLN_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SPRBR_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SPRBR_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SPRING.CSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SPS.CSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\STEEL.CSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SUNNY.CSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\SUNSET.CSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\TERRCOTT.CSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\TIMELN_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\TIMELN_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\TIMELN_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\TIMELN_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\TIMESOLN.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\TITLE_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\TITLE_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\TQM_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\TQM_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\TQM_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\TQM_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\TRANSP_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\TRANSP_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UICTRL_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UICTRL_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UIDLGS_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UIDLGS_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UIICON_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UIICON_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UIMENU_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UIMENU_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UIWNXP_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UIWNXP_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UIWZRD_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UIWZRD_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UML.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLACT_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLACT_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLCOL_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLCOL_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLCOM_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLCOM_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLDEP_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLDEP_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLDG_M.VSD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLDG_U.VSD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLMOD_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLMOD_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLSEQ_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLSEQ_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLSTA_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLSTA_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLSTR_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLSTR_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLUSE_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLUSE_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLVBRES.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLVC60R.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\UMLVSUI.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VALVE.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VALVE1_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VALVE1_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VALVE2_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VALVE2_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VB_VOTOC.XML
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VEHICL_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VEHICL_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIDSUR_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIDSUR_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIREADME.HTM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D112.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D112.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D120.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D120.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D121.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D121.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D200.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D200.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D21.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D21.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D27.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D27.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D31.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D31.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D36.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D36.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D50.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D50.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D61.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D61.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D76.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D76.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D81.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D81.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D88.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_D88.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_DG.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_DSS.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_DSS.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_DSSD.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_GS.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_PE.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_PE.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_PEA.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_PEA.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_PSHR.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_PSHR.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SAD.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SAD.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SAEC.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SAEC.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SBA.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SBA.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SBL.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SBL.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SBLP.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SBLP.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SBN.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SBN.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SC.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SC.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SCED.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SCED.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SCFF.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SCFF.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SCG.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SCG.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SDFD.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SDFD.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SDM.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SDM.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SDM3.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SDM3.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SDR.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SDR.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SDRD.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SE.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SE.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SFB.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SFB.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SGC.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SGC.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SIDE.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SIDE.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SMD.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SMD.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SMMD.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SMMD.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SOC.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SOC.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SOFL.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SOFL.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SPC.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SPC.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SSDL.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SSDL.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SSH2.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SSH2.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SSHR.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SSHR.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_STL.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_STL.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_STQM.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_STQM.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SWFD.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_SWFD.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TDWG.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TDWG.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TETP.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TETP.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TFM.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TFM.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TFP.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TFP.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TFPL.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TFPL.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TFS.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TFS.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TGEE.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TGEE.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_THP.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_THP.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_THVC.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_THVC.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_THVP.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_THVP.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TME.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TME.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TPE.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TPE.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TPL.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TPL.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TPP.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TPP.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TRCP.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TRCP.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TSPL.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VIS_TSPL.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VISBRRES.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VISCOLOR.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VISINTL.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VISIO.AW
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VISIO.CHM
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VISIO.CSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VISUTILS.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VISWEB.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VOTOC.XML
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\VPTOC.XML
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\Vsdir\Visfilem.vsdir
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\Vsdir\Visfileu.vsdir
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WADOWI_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WADOWI_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WALL_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WALL_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WDALLLNK.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WDCMPVRD.XML
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WDERRLNK.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WEBMAP_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WEBMAP_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WEBMAP_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WEBMAP_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WEBSIT_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WEBSIT_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WEBSIT_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WEBSIT_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WELD_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WELD_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WINSCHD.VRD
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WRKFLO_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WRKFLO_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WRKFLO_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\WRKFLO_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\XFUNC.VSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\XFUNC_M.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\XFUNC_U.VST
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\XFUNCH_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\XFUNCH_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\XFUNCV_M.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\1033\XFUNCV_U.VSS
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\AEC.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\AECUTILS.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\BRTVIEW.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\BSTORM.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\CMAX20.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\CODEEDIT.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\DATAGATH.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\DBENGR.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\DBSHARE.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\DBWIZ.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\DWGCNV.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\DWGDP.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\EDITOR.EXE
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\EDITORS.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\ELEMENTS.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\ELEMUTIL.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\ERXIMP.ADD
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\EXTRACT.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\FACILITY.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\GANTT.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\HVAC.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\IMCOMMON.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\IMDIMP.ADD
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\IMUTIL.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\IMWDD.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\IMWIZ.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\IXACS.PDL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\IXDB2.PDL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\IXGENERC.PDL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\IXINFX.PDL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\IXOLEDB.PDL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\IXORACLE.PDL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\IXSSRV.PDL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\IXSYBASE.PDL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\IXUTIL.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\LGND.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\LOGELEMS.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\LOGMODEL.MDL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\LOGVIEW.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\MODELENG.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\MPXINT.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\MSBSC60.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\OMFC.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\ORGCHART.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\ORGCHWIZ.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\ORGWIZ.EXE
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\ORMELEMS.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\ORMMODEL.MDL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\PDSBASE.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\PE.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\PROJIMPT.EXE
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\PROJMODL.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\PROPMGR.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\PROPRPT.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\REPORT.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\SAVASWEB.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\SAVWBHF.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\SAVWBRAS.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\SAVWBVML.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\SG.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\SHAPNUM.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\SMIGRATE.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\SOLUTILS.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\SQLSHARE.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\STYLEMGR.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\SUMINFO.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\TIMESOLN.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\TLIMPT.EXE
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\UML.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\UMLSYS.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\VAOSOLX.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\VBLZ0007.TLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\VBLZ0009.TLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\VBLZ000C.TLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\VBLZ0011.TLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\VBS2EXCL.XSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\VBS2WORD.XSL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\VERBWIND.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\VIEWMODL.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\VISCOLOR.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\VISIO.PIP
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\VISSUPP.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\VISUTILS.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\VISWEB.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\VISXDATA.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\DLL\XFUNC.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\MSOUTLS.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\OMFCU.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\Samples\1033\BLDGPLAN.DWG
c:\program files (x86)\msoffice\2003\Visio\Visio11\Samples\1033\BLDGPLAN.JPG
c:\program files (x86)\msoffice\2003\Visio\Visio11\Samples\1033\BLOCKS.DWG
c:\program files (x86)\msoffice\2003\Visio\Visio11\Samples\1033\BRAINSTM.XML
c:\program files (x86)\msoffice\2003\Visio\Visio11\Samples\1033\ORGDATA.TXT
c:\program files (x86)\msoffice\2003\Visio\Visio11\Samples\1033\ORGDATA.XLS
c:\program files (x86)\msoffice\2003\Visio\Visio11\Samples\1033\TIMELINE.MPP
c:\program files (x86)\msoffice\2003\Visio\Visio11\UMLVB.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\UMLVC60.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\UMLVS.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\VISBRGR.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\VISDLGU.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\VISGRF.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\VISIO.EXE
c:\program files (x86)\msoffice\2003\Visio\Visio11\VISLIB.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\VISOCX.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\VISPRX32.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\VISSHE.DLL
c:\program files (x86)\msoffice\2003\Visio\Visio11\XMLRW.DLL
c:\programdata\app
c:\programdata\app\drivers.ini
C:\rundll32.exe
c:\users\Laurie\AppData\Roaming\Microsoft\1eaadjc.dll
c:\users\Laurie\AppData\Roaming\Microsoft\bass.dll
c:\users\Laurie\AppData\Roaming\Microsoft\kfgresk.dll
c:\users\Laurie\AppData\Roaming\Microsoft\mjcriu.dll
c:\users\Laurie\AppData\Roaming\Microsoft\peaadje.dll
c:\users\Laurie\AppData\Roaming\Microsoft\qwadjb.dll
c:\users\Laurie\AppData\Roaming\Microsoft\rsaadjd.dll
c:\windows\159174216.exe
c:\windows\7102647.exe
c:\windows\SysWow64\ntdll(103)(364).dll.0
c:\windows\SysWow64\ntdll.dll.7
.
.
(((((((((((((((((((((((((   Files Created from 2014-07-08 to 2014-08-08  )))))))))))))))))))))))))))))))
.
.
2014-08-08 20:31 . 2014-08-08 20:31    --------    d-----w-    c:\users\Laurie\AppData\Local\temp
2014-08-08 10:19 . 2014-08-08 10:19    75888    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{9DCFF773-6F8C-4634-A728-E9D5ED48AC37}\offreg.dll
2014-08-08 10:17 . 2014-07-14 10:12    10924376    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{9DCFF773-6F8C-4634-A728-E9D5ED48AC37}\mpengine.dll
2014-08-03 18:15 . 2014-08-03 18:15    --------    d-----w-    c:\program files (x86)\WinResourceKit
2014-08-03 15:34 . 2014-08-03 15:34    --------    d-----w-    c:\users\Laurie\AppData\Local\Evernote
2014-08-03 03:16 . 2014-08-03 03:21    --------    d-----w-    c:\windows\system32\catroot2
2014-08-03 02:47 . 2014-08-03 02:47    --------    d-----w-    c:\windows\SysWow64\wbem\Performance
2014-08-02 21:16 . 2014-08-02 21:16    --------    d-----w-    c:\program files (x86)\Windows Repair
2014-08-02 18:54 . 2014-08-07 17:51    --------    d-----w-    c:\users\Laurie\AppData\Local\GVMateApp
2014-08-02 16:17 . 2014-08-02 16:24    --------    d-----w-    c:\users\Laurie\AppData\Roaming\WiseUpdate
2014-07-29 23:32 . 2014-07-29 23:32    --------    d-----w-    c:\users\Laurie\AppData\Local\IsolatedStorage
2014-07-29 23:30 . 2014-07-29 23:31    --------    d-----w-    c:\program files (x86)\HMA-Pro VPN
2014-07-29 22:45 . 2014-08-02 16:23    --------    d-----w-    c:\program files (x86)\MozFirefox
2014-07-19 15:45 . 2014-07-19 15:44    319912    ----a-w-    c:\windows\system32\javaws.exe
2014-07-19 15:45 . 2014-07-19 15:44    189352    ----a-w-    c:\windows\system32\javaw.exe
2014-07-19 15:45 . 2014-07-19 15:44    189352    ----a-w-    c:\windows\system32\java.exe
2014-07-19 14:18 . 2014-07-19 14:18    --------    d-----w-    C:\RegBackup
2014-07-19 14:16 . 2014-07-19 14:16    --------    d-----w-    c:\program files (x86)\Win Repair
2014-07-19 14:12 . 2014-08-02 21:16    --------    d-----w-    c:\program files (x86)\Tweaking.com
2014-07-19 13:32 . 2014-07-19 15:44    111016    ----a-w-    c:\windows\system32\WindowsAccessBridge-64.dll
2014-07-19 13:18 . 2014-07-19 13:18    --------    d-----w-    c:\program files (x86)\Common Files\Java
2014-07-19 13:10 . 2014-07-19 13:17    98216    ----a-w-    c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-07-18 15:30 . 2014-07-18 15:30    --------    d-----w-    c:\programdata\Reimage Protector
2014-07-18 15:23 . 2014-07-18 15:23    --------    d-----w-    c:\program files\Reimage
2014-07-18 15:20 . 2014-07-19 12:52    --------    d-----w-    C:\rei
2014-07-16 15:52 . 2014-07-16 15:52    --------    d-----w-    c:\users\Laurie\AppData\Local\Trusteer
2014-07-16 15:52 . 2014-07-16 15:52    --------    d-----w-    c:\program files (x86)\Trusteer
2014-07-16 15:49 . 2014-07-16 15:49    --------    d-----w-    c:\programdata\Trusteer
2014-07-16 14:04 . 2014-07-16 14:05    --------    d-----w-    c:\program files\iTunes
2014-07-14 00:59 . 2014-08-08 14:00    --------    d-----w-    C:\FRST
2014-07-13 21:08 . 2014-07-19 12:53    --------    d-----w-    C:\EEK
2014-07-11 05:27 . 2014-07-12 06:27    5659136    ----a-w-    c:\windows\SysWow64\FlashPlayerInstaller.exe
2014-07-10 04:13 . 2014-05-30 08:08    22016    ----a-w-    c:\windows\system32\credssp.dll
2014-07-10 04:11 . 2014-06-06 10:10    624128    ----a-w-    c:\windows\system32\qedit.dll
2014-07-10 04:11 . 2014-06-06 09:44    509440    ----a-w-    c:\windows\SysWow64\qedit.dll
2014-07-10 04:11 . 2014-05-30 06:45    497152    ----a-w-    c:\windows\system32\drivers\afd.sys
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-08-05 20:03 . 2012-07-17 20:37    23256    ----a-w-    c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-08-02 21:26 . 2014-06-30 17:08    122584    ----a-w-    c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-07-23 16:52 . 2010-11-21 03:27    270496    ------w-    c:\windows\system32\MpSigStub.exe
2014-07-12 06:28 . 2014-01-20 23:44    699056    ----a-w-    c:\windows\SysWow64\FlashPlayerApp.exe
2014-07-12 06:28 . 2014-01-20 23:44    71344    ----a-w-    c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-07-10 04:16 . 2012-07-18 01:02    96441528    ----a-w-    c:\windows\system32\MRT.exe
2014-05-25 18:14 . 2014-05-25 18:06    707354    ----a-w-    c:\windows\unins001.exe
2014-05-12 13:26 . 2014-06-30 17:02    63704    ----a-w-    c:\windows\system32\drivers\mwac.sys
2014-05-12 13:26 . 2014-06-30 17:02    91352    ----a-w-    c:\windows\system32\drivers\mbamchameleon.sys
2014-05-12 13:25 . 2013-09-16 15:51    25816    ----a-w-    c:\windows\system32\drivers\mbam.sys
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"VideoDownloaderUltimate"="c:\programdata\VideoDownloaderUltimateWinApp\VideoDownloaderUltimate.exe" [2014-08-04 718456]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2011-03-14 1081424]
"emsisoft anti-malware"="c:\program files (x86)\emsisoft anti-malware\a2guard.exe" [2014-07-10 4841824]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\windows\system32\config\systemprofile\AppData\Roaming\mjusbsp\cdloader2.exe" [2012-02-01 50592]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"IsMyWinLockerReboot"="msiexec.exe" [2010-11-21 73216]
.
c:\users\Laurie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
EvernoteClipper.lnk - c:\program files (x86)\Evernote\Evernote\EvernoteClipper.exe [2014-7-25 1109344]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\BT\BTTray.exe [2007-3-29 984368]
setup2.exe [2012-2-1 11301776]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"HideFastUserSwitching"= 1
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute    REG_MULTI_SZ       \0
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R3 ampa;ampa;c:\windows\system32\ampa.sys;c:\windows\SYSNATIVE\ampa.sys [x]
S1 A2DDA;A2 Direct Disk Access Support Driver;c:\program files (x86)\Emsisoft Anti-Malware\a2ddax64.sys;c:\program files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [x]
S1 a2injectiondriver;a2injectiondriver;c:\program files (x86)\Emsisoft Anti-Malware\a2dix64.sys;c:\program files (x86)\Emsisoft Anti-Malware\a2dix64.sys [x]
S1 a2util;a-squared Malware-IDS utility driver;c:\program files (x86)\Emsisoft Anti-Malware\a2util64.sys;c:\program files (x86)\Emsisoft Anti-Malware\a2util64.sys [x]
S2 a2AntiMalware;Emsisoft Anti-Malware 6.6 - Service;c:\program files (x86)\Emsisoft Anti-Malware\a2service.exe;c:\program files (x86)\Emsisoft Anti-Malware\a2service.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S3 a2acc;a2acc;c:\program files (x86)\EMSISOFT ANTI-MALWARE\a2accx64.sys;c:\program files (x86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
iissvcs    REG_MULTI_SZ       w3svc was
apphost    REG_MULTI_SZ       apphostsvc
.
Contents of the 'Scheduled Tasks' folder
.
2014-08-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1014Core.job
- c:\users\Laurie\AppData\Local\Google\Update\GoogleUpdate.exe [2014-06-10 18:09]
.
2014-08-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-206095162-3907483975-2766088746-1014UA.job
- c:\users\Laurie\AppData\Local\Google\Update\GoogleUpdate.exe [2014-06-10 18:09]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2011-01-28 862088]
"@OnlineArmor GUI"="c:\program files (x86)\Online Armor\OAui.exe" [2013-10-16 7558464]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = https://mail.google.com/mail/u/0/#inbox
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Clip image - c:\program files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=4
IE: Clip selection - c:\program files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=3
IE: Clip this page - c:\program files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=1
IE: Clip URL - c:\program files (x86)\Evernote\Evernote\EvernoteIERes\Clip.html?clipAction=0
IE: E&xport to Microsoft Excel - c:\progra~2\OFFICE~1\Office10\EXCEL.EXE/3000
IE: New note - c:\program files (x86)\Evernote\Evernote\EvernoteIERes\NewNote.html
TCP: DhcpNameServer = 192.168.0.1 205.171.2.25
TCP: Interfaces\{0D01DE1E-0EFC-41CC-AE51-F14B0A22E4F6}: NameServer = 192.168.0.1,205.171.3.25
FF - ProfilePath - c:\users\Laurie\AppData\Roaming\Mozilla\Firefox\Profiles\rj5y4zuc.default-1404055395082\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
.
.
------- File Associations -------
.
vbefile\shell\open2\command="%SystemRoot%\System32\CScript.exe" "%1" %*
vbsfile\shell\open2\command="%SystemRoot%\System32\CScript.exe" "%1" %*
jsefile\shell\open2\command=c:\windows\System32\CScript.exe "%1" %*
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
SafeBoot-CleanHlp
SafeBoot-CleanHlp.sys
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows CE Services]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
Completion time: 2014-08-08  14:35:20
ComboFix-quarantined-files.txt  2014-08-08 20:35
.
Pre-Run: 39,386,161,152 bytes free
Post-Run: 42,403,467,264 bytes free
.
- - End Of File - - D7B85C0442A463EF5ED86C324DE96788
A36C5E4F47E84449FF07ED3517B43A31
 



#12 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 38,133 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:51 AM

Posted 10 August 2014 - 02:15 PM

I know there were problems with the web site over the last few days and you may have gotten caught up in that.

It looks like Combofix deleted your Microsoft Office. Can you tell me if that program was running correctly before and if so does it run now?

 

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\msoffice

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#13 LAFitzou

LAFitzou
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:04:51 PM

Posted 10 August 2014 - 03:56 PM

Well...that's strange.  MS Office is running just fine.  However, my screenshot program is now giving me this error message:  "A device attached to the system is not functioning."  I tried to reinstall it but it produces the same error.  Any ideas?

 

Laurie



#14 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 38,133 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:11:51 AM

Posted 10 August 2014 - 04:01 PM

my screenshot program

What is the name of this particular program?


Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#15 LAFitzou

LAFitzou
  • Topic Starter

  • Members
  • 30 posts
  • OFFLINE
  •  
  • Local time:04:51 PM

Posted 10 August 2014 - 04:22 PM

It's called Screenshot from CNet Download ( http://download.cnet.com/ScreenShot/3055-2192_4-10423334.html?tag=pdl-redir ).  I installed it in 2011 and it's been working without an issue since then.

 

Laurie






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users