1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Internet connection problems

Discussion in 'Malware Removal Help' started by PickleCommander, Apr 4, 2013.

Thread Status:
Not open for further replies.
  1. PickleCommander

    PickleCommander Foul Mouthed Idiot-Banned

    Apr 4, 2013
    Operating System:
    Windows 7
    Ok, but I'm not using it for any super-important things.
    But after reinstalling the drivers without windows letting to install them, it helped, but still happens. It reconnects now around once in 5-10 minutes instead of once or more in a minute.
  2. KenB

    KenB Registered Members

    Oct 21, 2010
    Wirral UK
    Operating System:
    Windows Vista Home Premium
    Let's sort the malware first - this is most important.
    It could be this that is causing your problem - and even if it isn't your system needs to be checked over.

    I have sent a message to two of our experts - one of them will advise you further.
    Please be patient. One is 7 hours behind GMT.
  3. etavares

    etavares Malware Removal Specialist - Moderator

    Aug 6, 2011
    USA (GMT -5)
    I'm only 4 hours behind, thankfully. :) That will change back to 5 when we're both on DST.

    One or more of the identified infections is very bad news and is a backdoor trojan.

    This allows hackers to remotely control your computer, steal critical system information and passwords and download and execute files.

    I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

    Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

    How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
    When Should I Format, How Should I Reinstall

    We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do. If you do decide to proceed, please follow the instructions in the link below and post the requested logs in a reply to this thread. I will move it to the malware removal sub-forum when you reply.
    Preparation for Malware removal help

  4. PickleCommander

    PickleCommander Foul Mouthed Idiot-Banned

    Apr 4, 2013
    Operating System:
    Windows 7
    This far I haven't noticed anything that's out of place, and as I said previously, I don't have anything important except about 500 bucks of games and stuff like facebook, skype etc. I don't have anything that has to do with all of my money. The worst that can happen is that I won't be able to do schoolwork...which is essentially a good thing :cool-21:

    If possible I would try to remove it without reinstalling my OS, since I did it once on one of my two drivers, and it was a pain and a half to get everything back and running again.
    But in worse case scenario, I do have a backup available that was made before anything else on this laptop as well as a CD copy of windows 7.
  5. PickleCommander

    PickleCommander Foul Mouthed Idiot-Banned

    Apr 4, 2013
    Operating System:
    Windows 7
    I just now saw the link for "Preparation for Malware removal help"
    So I have to post all of the logs the programs created? I know You are some hours behind me so I will post just in case. (when the scans are done)
  6. PickleCommander

    PickleCommander Foul Mouthed Idiot-Banned

    Apr 4, 2013
    Operating System:
    Windows 7

    aswMBR version Copyright(c) 2011 AVAST Software
    Run date: 2013-04-06 11:46:08
    11:46:08.928 OS Version: Windows x64 6.1.7601 Service Pack 1
    11:46:08.928 Number of processors: 8 586 0x3A09
    11:46:08.929 ComputerName: KLETTENBERGARE UserName: Eric
    11:46:08.956 Initialze error 1
    11:46:32.836 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
    11:46:32.838 Disk 0 Vendor: ST975042 0002 Size: 715404MB BusType: 3
    11:46:32.862 Disk 0 MBR read successfully
    11:46:32.864 Disk 0 MBR scan
    11:46:32.866 Disk 0 unknown MBR code
    11:46:32.868 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1
    11:46:32.870 Disk 0 scanning C:\Windows\system32\drivers
    11:46:32.871 Service scanning
    11:46:33.397 Modules scanning
    11:46:33.400 Disk 0 trace - called modules:
    11:46:33.422 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
    11:46:33.425 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8009a42790]
    11:46:33.427 3 CLASSPNP.SYS[fffff88001d7343f] -> nt!IofCallDriver -> [0xfffffa80071ef7e0]
    11:46:33.430 5 ACPI.sys[fffff88000ee37a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8007217050]
    11:46:33.433 Scan finished successfully
    11:46:49.468 Disk 0 MBR has been saved successfully to "C:\Users\Eric\Desktop\MBR.dat"
    11:46:49.471 The log file has been saved successfully to "C:\Users\Eric\Desktop\aswMBR.txt"



    OTL logfile created on: 2013-04-06 11:50:00 - Run 1
    OTL by OldTimer - Version Folder = C:\Users\Eric\Desktop
    64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.10.9200.16521)
    Locale: 0000041D | Country: Sweden | Language: SVE | Date Format: yyyy-MM-dd

    7,96 Gb Total Physical Memory | 2,72 Gb Available Physical Memory | 34,22% Memory free
    15,92 Gb Paging File | 11,36 Gb Available in Paging File | 71,36% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 279,46 Gb Total Space | 20,76 Gb Free Space | 7,43% Space Free | Partition Type: NTFS
    Drive D: | 394,45 Gb Total Space | 56,28 Gb Free Space | 14,27% Space Free | Partition Type: NTFS

    Computer Name: KLETTENBERGARE | User Name: Eric | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - C:\Users\Eric\Desktop\OTL.exe (OldTimer Tools)
    PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
    PRC - C:\Windows\SysWOW64\PnkBstrB.exe ()
    PRC - C:\ProgramData\eSafe\eGdpSvc.exe (eSafe Security Co., Ltd.)
    PRC - C:\Program Files (x86)\Desk 365\deskSvc.exe (337 Technology Limited.)
    PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
    PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
    PRC - C:\Program Files (x86)\Origin\Origin.exe (Electronic Arts)
    PRC - C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe (Aeria Games & Entertainment)
    PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
    PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
    PRC - C:\Users\Eric\AppData\Local\Smartbar\Application\QuickShare.exe (Smartbar)
    PRC - C:\Users\Eric\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
    PRC - C:\Windows\AsScrPro.exe (ASUS)
    PRC - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (Power Software Ltd)
    PRC - C:\Users\Eric\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
    PRC - C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
    PRC - C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe (VMware, Inc.)
    PRC - C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
    PRC - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
    PRC - C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (ASUSTeK Computer Inc.)
    PRC - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE (Microsoft Corporation.)
    PRC - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
    PRC - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS)
    PRC - C:\Windows\SysWOW64\ACEngSvr.exe (ASUSTeK)
    PRC - C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe (ASUS)
    PRC - C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe (ASUS)
    PRC - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (ASUSTeK Computer Inc.)
    PRC - C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUSTek Computer Inc.)
    PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
    PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
    PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
    PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe ()
    PRC - C:\Program Files (x86)\ASUS\ASUS Fan Filter Checker\FanChkSrv.exe (ASUSTek Computer Inc.)
    PRC - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
    PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUSTek Computer Inc.)
    PRC - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe ()
    PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.)
    PRC - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe (Intel Corporation)
    PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS)
    PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
    PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
    PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
    PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
    PRC - C:\Program Files (x86)\Roxio\CinePlayer\5.0\CPMonitor.exe ()
    PRC - C:\Program Files\ASUS\Rotation Desktop for G Series\AsusUacSvc.exe ()
    PRC - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
    PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
    PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS)
    PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (ASUS)
    PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUS)

    ========== Modules (No Company Name) ==========

    MOD - C:\Windows\assembly\GAC_32\System.Data.SQLite\\System.Data.SQLite.dll ()
    MOD - C:\Windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll ()
    MOD - C:\Windows\assembly\GAC_MSIL\Interop.SHDocVw\\Interop.SHDocVw.dll ()
    MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
    MOD - C:\Program Files (x86)\Origin\tufao.dll ()
    MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
    MOD - C:\Program Files (x86)\Steam\SDL2.dll ()
    MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
    MOD - C:\Users\Eric\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll ()
    MOD - C:\Users\Eric\AppData\Local\Smartbar\Application\Smartbar.Resources.AutomaticUpdates.dll ()
    MOD - C:\Users\Eric\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll ()
    MOD - C:\Users\Eric\AppData\Local\Smartbar\Application\Smartbar.GUI.Multimedia.Loader.dll ()
    MOD - C:\Users\Eric\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll ()
    MOD - C:\Users\Eric\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll ()
    MOD - C:\Users\Eric\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll ()
    MOD - C:\Users\Eric\AppData\Local\Smartbar\Application\MACTrackBarLib.dll ()
    MOD - C:\Users\Eric\AppData\Local\Smartbar\Application\Smartbar.Personalization.BusinessLogic.dll ()
    MOD - C:\Users\Eric\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.EventManager.dll ()
    MOD - C:\Users\Eric\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll ()
    MOD - C:\Users\Eric\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll ()
    MOD - C:\Users\Eric\AppData\Local\Smartbar\Application\Smartbar.Resources.Utilities.dll ()
    MOD - C:\Users\Eric\AppData\Local\Smartbar\Application\Smartbar.Resources.SideBySide.dll ()
    MOD - C:\Users\Eric\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll ()
    MOD - C:\Users\Eric\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll ()
    MOD - C:\Users\Eric\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll ()
    MOD - C:\Users\Eric\AppData\Local\Smartbar\Application\Smartbar.Resources.ProcessDownMonitor.dll ()
    MOD - C:\Users\Eric\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\64cf6c356be66bb17c4667d6d8aa467b\System.Web.Services.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\806c4ba7d696ab586ffd774a31f1a66b\System.Windows.Forms.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\5baea82888a13fa558004b24e3b107cf\CustomMarshalers.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7d20811a7ce7cc589153648cbb1ce5c\PresentationFramework.Aero.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\01c6cb58745f397c9b7ccf3ab7bfc9cd\System.EnterpriseServices.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\536d704e93ffec9b54e4a0312fb5b996\System.Transactions.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\dd20416f723ee13ffb4173ec1afc4ec4\System.Data.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ff7c9a4f41f7cccc47e696c11b9f8469\PresentationFramework.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\19b3d17c3ce0e264c4fb62028161adf7\PresentationCore.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c1a66b44c4780c039576eaf18f4cd8dc\System.Xml.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\2024a7339aa5ad2712d239d454d3c355\System.Management.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\d340a103e8f063a3771cbeaaec58d157\System.EnterpriseServices.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\d340a103e8f063a3771cbeaaec58d157\System.EnterpriseServices.Wrapper.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\9253eb314ef2f5adada0d5fdf1d4a839\System.Transactions.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\48ee0e1de873152ec7e85d7456c1cc09\System.Runtime.Serialization.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\cbb7db665b3ba25a931258eb702527f5\System.Xaml.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\f28a346ae10e2eec581608f591cf7116\PresentationFramework.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\8983c040161b34c64474f195bff5e2de\PresentationCore.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\8167f7d08668a5859e76aa9a1124a42f\System.Data.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\08bebcf66ad666dfdf2a4a934d79c0f9\System.Core.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\5dbabea688adfc665e3453561736699a\WindowsBase.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d884c684ee3f738a60e3c50dd5d88caa\System.Xml.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\b83993cc955262507c8ead67567c8060\System.Drawing.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\cb72ac8478a5ea7e2d570bb710ecb1c1\System.Configuration.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\7d6b122bee0977d953ee2409d74c3c25\PresentationFramework.Aero.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\df418085cedae9fa2efee87e20a419a4\System.ni.dll ()
    MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\60c214b6ad5691e368a16ec65d127c27\mscorlib.ni.dll ()
    MOD - C:\Program Files (x86)\Steam\bin\avcodec-53.dll ()
    MOD - C:\Program Files (x86)\Steam\bin\avformat-53.dll ()
    MOD - C:\Program Files (x86)\Steam\bin\avutil-51.dll ()
    MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
    MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
    MOD - C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll ()
    MOD - C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll ()
    MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe ()
    MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\plugin\PServerPlugin.dll ()
    MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\featureController.dll ()
    MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\DeviceProfile.dll ()
    MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\eventsSender.dll ()
    MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\log4cplus.dll ()
    MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\libgsoap.dll ()
    MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\sqlite3.dll ()
    MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtGui4.dll ()
    MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtXml4.dll ()
    MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtCore4.dll ()
    MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtNetwork4.dll ()
    MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\zlib1.dll ()
    MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\QtWebKit4.dll ()
    MOD - C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\phonon4.dll ()
    MOD - C:\Program Files (x86)\Roxio\CinePlayer\5.0\CPMonitor.exe ()
    MOD - C:\Windows\assembly\GAC_32\System.Data\\System.Data.dll ()
    MOD - C:\Windows\assembly\GAC_32\CustomMarshalers\\CustomMarshalers.dll ()
    MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll ()
    MOD - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll ()
    MOD - C:\Windows\assembly\GAC_32\System.Transactions\\System.Transactions.dll ()

    ========== Services (SafeList) ==========

    SRV:64bit: - (TurboBoost) -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel(R) Corporation)
    SRV:64bit: - (Intel(R) -- C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel(R) Corporation)
    SRV:64bit: - (VIAKaraokeService) -- C:\Windows\SysNative\ViakaraokeSrv.exe (VIA Technologies, Inc.)
    SRV:64bit: - (AsusUacSvc) -- C:\Program Files\ASUS\Rotation Desktop for G Series\AsusUacSvc.exe ()
    SRV:64bit: - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
    SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
    SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
    SRV - (PnkBstrB) -- C:\Windows\SysWOW64\PnkBstrB.exe ()
    SRV - (eSafeSvc) -- C:\ProgramData\eSafe\eGdpSvc.exe (eSafe Security Co., Ltd.)
    SRV - (desksvc) -- C:\Program Files (x86)\Desk 365\deskSvc.exe (337 Technology Limited.)
    SRV - (BEService) -- C:\Program Files (x86)\Common Files\BattlEye\BEService.exe ()
    SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
    SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
    SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
    SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
    SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
    SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
    SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
    SRV - (VMnetDHCP) -- C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
    SRV - (VMware NAT Service) -- C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
    SRV - (VMwareHostd) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe ()
    SRV - (VMAuthdService) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
    SRV - (VMUSBArbService) -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe (VMware, Inc.)
    SRV - (BBUpdate) -- C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE (Microsoft Corporation.)
    SRV - (BBSvc) -- C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.EXE (Microsoft Corporation.)
    SRV - (ASUS InstantOn) -- C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe (ASUS)
    SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
    SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
    SRV - (jhi_service) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
    SRV - (Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe ()
    SRV - (FanChkService) -- C:\Program Files (x86)\ASUS\ASUS Fan Filter Checker\FanChkSrv.exe (ASUSTek Computer Inc.)
    SRV - (ZAtheros Bt&Wlan Coex Agent) -- C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
    SRV - (AtherosSvc) -- C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Atheros Commnucations)
    SRV - (ASLDRService) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS)
    SRV - (ATKGFNEXSrv) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
    SRV - (sftvsa) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
    SRV - (sftlist) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
    SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
    SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)

    ========== Driver Services (SafeList) ==========

    DRV:64bit: - (VBoxNetAdp) -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys (Oracle Corporation)
    DRV:64bit: - (SCDEmu) -- C:\Windows\SysNative\drivers\scdemu.sys (Power Software Ltd)
    DRV:64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
    DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
    DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
    DRV:64bit: - (vmx86) -- C:\Windows\SysNative\drivers\vmx86.sys (VMware, Inc.)
    DRV:64bit: - (VMnetuserif) -- C:\Windows\SysNative\drivers\vmnetuserif.sys (VMware, Inc.)
    DRV:64bit: - (VMnetBridge) -- C:\Windows\SysNative\drivers\vmnetbridge.sys (VMware, Inc.)
    DRV:64bit: - (VMnetAdapter) -- C:\Windows\SysNative\drivers\vmnetadapter.sys (VMware, Inc.)
    DRV:64bit: - (vsock) -- C:\Windows\SysNative\drivers\vsock.sys (VMware, Inc.)
    DRV:64bit: - (vmci) -- C:\Windows\SysNative\drivers\vmci.sys (VMware, Inc.)
    DRV:64bit: - (hcmon) -- C:\Windows\SysNative\drivers\hcmon.sys (VMware, Inc.)
    DRV:64bit: - (Netaapl) -- C:\Windows\SysNative\drivers\netaapl64.sys (Apple Inc.)
    DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
    DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
    DRV:64bit: - (iusb3xhc) -- C:\Windows\SysNative\drivers\iusb3xhc.sys (Intel Corporation)
    DRV:64bit: - (iusb3hub) -- C:\Windows\SysNative\drivers\iusb3hub.sys (Intel Corporation)
    DRV:64bit: - (iusb3hcs) -- C:\Windows\SysNative\drivers\iusb3hcs.sys (Intel Corporation)
    DRV:64bit: - (AiCharger) -- C:\Windows\SysNative\drivers\AiCharger.sys (ASUSTek Computer Inc.)
    DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
    DRV:64bit: - (SmbDrv) -- C:\Windows\SysNative\drivers\Smb_driver.sys (Synaptics Incorporated)
    DRV:64bit: - (TurboB) -- C:\Windows\SysNative\drivers\TurboB.sys (Intel(R) Corporation)
    DRV:64bit: - (VIAHdAudAddService) -- C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.)
    DRV:64bit: - (BtFilter) -- C:\Windows\SysNative\drivers\btfilter.sys (Atheros)
    DRV:64bit: - (BTATH_RCP) -- C:\Windows\SysNative\drivers\btath_rcp.sys (Atheros)
    DRV:64bit: - (BTATH_LWFLT) -- C:\Windows\SysNative\drivers\btath_lwflt.sys (Atheros)
    DRV:64bit: - (BTATH_HCRP) -- C:\Windows\SysNative\drivers\btath_hcrp.sys (Atheros)
    DRV:64bit: - (AthBTPort) -- C:\Windows\SysNative\drivers\btath_flt.sys (Atheros)
    DRV:64bit: - (BTATH_BUS) -- C:\Windows\SysNative\drivers\btath_bus.sys (Atheros)
    DRV:64bit: - (btath_avdt) -- C:\Windows\SysNative\drivers\btath_avdt.sys (Atheros)
    DRV:64bit: - (BTATH_A2DP) -- C:\Windows\SysNative\drivers\btath_a2dp.sys (Atheros)
    DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
    DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
    DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
    DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
    DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
    DRV:64bit: - (Sftvol) -- C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
    DRV:64bit: - (Sftplay) -- C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
    DRV:64bit: - (Sftredir) -- C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
    DRV:64bit: - (Sftfs) -- C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
    DRV:64bit: - (L1C) -- C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
    DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
    DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
    DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
    DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
    DRV:64bit: - (RMCAST) -- C:\Windows\SysNative\drivers\rmcast.sys (Microsoft Corporation)
    DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
    DRV:64bit: - (USBMULCD) -- C:\Windows\SysNative\drivers\CM10664.sys (C-Media Electronics Inc)
    DRV:64bit: - (kbfiltr) -- C:\Windows\SysNative\drivers\kbfiltr.sys ( )
    DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
    DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
    DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
    DRV:64bit: - (SiSGbeLH) -- C:\Windows\SysNative\drivers\SiSG664.sys (Silicon Integrated Systems Corp.)
    DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
    DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
    DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
    DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
    DRV:64bit: - (WimFltr) -- C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
    DRV - (slb) -- C:\AeriaGames\ScarletBlade\avital\scarlb64.sys ()
    DRV - (AiCharger) -- C:\Windows\SysWOW64\drivers\AiCharger.sys (ASUSTek Computer Inc.)
    DRV - (ATKWMIACPIIO) -- C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys (ASUS)
    DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
    DRV - (ASMMAP64) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys (ASUS)

    ========== Standard Registry (SafeList) ==========

    ========== Internet Explorer ==========

    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&u...T9750420AS_5WS3Z559XXXX5WS3Z559&ts=1365001777
    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&u...T9750420AS_5WS3Z559XXXX5WS3Z559&ts=1365001777
    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
    IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
    IE:64bit: - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.qvo6.com/web/?utm_sou...d=ST9750420AS_5WS3Z559XXXX5WS3Z559&ts=4390966
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&u...T9750420AS_5WS3Z559XXXX5WS3Z559&ts=1365001777
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&u...T9750420AS_5WS3Z559XXXX5WS3Z559&ts=1365001777
    IE - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=ASUTDF&pc=NP06&src=IE-SearchBox
    IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.qvo6.com/web/?utm_sou...d=ST9750420AS_5WS3Z559XXXX5WS3Z559&ts=4390966

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&u...T9750420AS_5WS3Z559XXXX5WS3Z559&ts=1365001777
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.qvo6.com/?utm_source=b&u...T9750420AS_5WS3Z559XXXX5WS3Z559&ts=1365001777
    IE - HKCU\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
    IE - HKCU\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.qvo6.com/web/?utm_sou...d=ST9750420AS_5WS3Z559XXXX5WS3Z559&ts=4390966
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local

    ========== FireFox ==========

    FF - prefs.js..browser.startup.homepage: "https://www.youtube.com/"
    FF - user.js - File not found

    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.13.2: C:\Windows\system32\npDeployJava1.dll File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
    FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.3: C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll (ESN Social Software AB)
    FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
    FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
    FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
    FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll ()
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
    FF - HKLM\Software\MozillaPlugins\ZEON/PDF,version=2.0: C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
    FF - HKCU\Software\MozillaPlugins\@nsroblox.roblox.com/launcher: C:\Users\Eric\AppData\Local\Roblox\Versions\version-3789d377c3ab4ee1\\NPRobloxProxy.dll ()

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Waterfox 18.0.1\extensions\\Components: C:\Program Files\\Waterfox\components [2013-02-25 19:26:48 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Waterfox 18.0.1\extensions\\Plugins: C:\Program Files\\Waterfox\plugins

    [2013-02-03 12:51:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eric\AppData\Roaming\Mozilla\Extensions
    [2013-03-11 17:42:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\c4jg7yyv.default\extensions
    [2013-02-14 19:41:33 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\c4jg7yyv.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
    [2013-02-22 21:33:53 | 000,000,985 | ---- | M] () -- C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\c4jg7yyv.default\searchplugins\conduit.xml

    ========== Chrome ==========

    CHR - default_search_provider: Google (Enabled)
    CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:eek:riginalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
    CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
    CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.43\PepperFlash\pepflashplayer.dll
    CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
    CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.43\ppGoogleNaClPluginChrome.dll
    CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.43\pdf.dll
    CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
    CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
    CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
    CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
    CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
    CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
    CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
    CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
    CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\2.1.3\npesnlaunch.dll
    CHR - plugin: ESN Sonar API (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
    CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll
    CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
    CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
    CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
    CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
    CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
    CHR - plugin: Zeon Plus (Enabled) = C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll
    CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
    CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
    CHR - plugin: Roblox Launcher Plugin (Enabled) = C:\Users\Eric\AppData\Local\Roblox\Versions\version-3789d377c3ab4ee1\\NPRobloxProxy.dll
    CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll
    CHR - Extension: Google Dokument = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
    CHR - Extension: Google Drive = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
    CHR - Extension: YouTube = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
    CHR - Extension: S\u00F6k p\u00E5 Google = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\\
    CHR - Extension: Gmail = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

    O1 HOSTS File: ([2009-06-10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
    O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O2:64bit: - BHO: (DVDVideoSoft WebPageAdjuster Class) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
    O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
    O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
    O2 - BHO: (DVDVideoSoft WebPageAdjuster Class) - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
    O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll (Yontoo LLC)
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Alcor Micro Corp.)
    O4:64bit: - HKLM..\Run: [AthBtTray] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations)
    O4:64bit: - HKLM..\Run: [AtherosBtStack] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations)
    O4:64bit: - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
    O4 - HKLM..\Run: [ACMON] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS)
    O4 - HKLM..\Run: [Aeria Ignite] C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe (Aeria Games & Entertainment)
    O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe (ASUS)
    O4 - HKLM..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\\AsusWSPanel.exe (ecareme)
    O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS)
    O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTek Computer Inc.)
    O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
    O4 - HKLM..\Run: [CPMonitor] C:\Program Files (x86)\Roxio\CinePlayer\5.0\CPMonitor.exe ()
    O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS)
    O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
    O4 - HKLM..\Run: [Nuance PDF Reader-reminder] C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe (Nuance Communications, Inc.)
    O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (Power Software Ltd)
    O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
    O4 - HKLM..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (ASUSTeK Computer Inc.)
    O4 - HKLM..\Run: [vmware-tray.exe] C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe (VMware, Inc.)
    O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Eric\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
    O4 - HKCU..\Run: [Browser Infrastructure Helper] C:\Users\Eric\AppData\Local\Smartbar\Application\QuickShare.exe (Smartbar)
    O4 - HKCU..\Run: [Desk 365] C:\Program Files (x86)\Desk 365\desk365.exe (337 Technology Limited.)
    O4 - HKCU..\Run: [EADM] C:\Program Files (x86)\Origin\Origin.exe (Electronic Arts)
    O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
    O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
    O4 - HKCU..\Run: [uTorrent] C:\Users\Eric\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
    O4 - Startup: C:\Users\Eric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel(R) Turbo Boost Technology Monitor 2.5.lnk = File not found
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O8:64bit: - Extra context menu item: Free YouTube Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm ()
    O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm ()
    O8 - Extra context menu item: Free YouTube Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm ()
    O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm ()
    O9:64bit: - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
    O9:64bit: - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
    O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
    O9 - Extra Button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
    O9 - Extra 'Tools' menuitem : Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000013 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
    O1364bit: - gopher Prefix: missing
    O13 - gopher Prefix: missing
    O15 - HKCU\..Trusted Domains: aeriagames.com ([]http in Trusted sites)
    O15 - HKCU\..Trusted Domains: aeriagames.com ([]https in Trusted sites)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{06A3628D-5C1B-414D-8983-75756DC64E56}: DhcpNameServer =
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ABC1EC37-FC2F-4C34-801B-EA35198A8D2D}: DhcpNameServer =
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E12FF640-18B3-497B-948B-C8B2242394F3}: DhcpNameServer =
    O18:64bit: - Protocol\Handler\livecall - No CLSID value found
    O18:64bit: - Protocol\Handler\msnim - No CLSID value found
    O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
    O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
    O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O32 - HKLM CDRom: AutoRun - 1
    O33 - MountPoints2\{064a1718-819a-11e2-a23e-005056c00008}\Shell - "" = AutoRun
    O33 - MountPoints2\{064a1718-819a-11e2-a23e-005056c00008}\Shell\AutoRun\command - "" = N:\LaunchU3.exe -a
    O33 - MountPoints2\E\Shell - "" = AutoRun
    O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\setup.exe
    O33 - MountPoints2\I\Shell - "" = AutoRun
    O33 - MountPoints2\I\Shell\AutoRun\command - "" = I:\setup.exe
    O33 - MountPoints2\J\Shell - "" = AutoRun
    O33 - MountPoints2\J\Shell\AutoRun\command - "" = J:\ck.exe
    O33 - MountPoints2\K\Shell - "" = AutoRun
    O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\Setup.exe
    O33 - MountPoints2\L\Shell - "" = AutoRun
    O33 - MountPoints2\L\Shell\AutoRun\command - "" = L:\Setup.exe
    O33 - MountPoints2\M\Shell - "" = AutoRun
    O33 - MountPoints2\M\Shell\AutoRun\command - "" = M:\setup.exe
    O34 - HKLM BootExecute: (autocheck autochk *)
    O34 - HKLM BootExecute: (MACHINE BootExecut)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
    O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

    Restore point Set: OTL Restore Point

    ========== Files/Folders - Created Within 30 Days ==========

    [2013-04-06 11:47:35 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Eric\Desktop\OTL.exe
    [2013-04-06 11:43:34 | 004,745,728 | ---- | C] (AVAST Software) -- C:\Users\Eric\Desktop\aswMBR.exe
    [2013-04-05 21:43:09 | 000,000,000 | ---D | C] -- C:\Users\Eric\Desktop\DarkStorm3.3.7
    [2013-04-05 12:32:30 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\CrashRpt
    [2013-04-05 12:31:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Chart Controls
    [2013-04-05 11:19:23 | 000,000,000 | ---D | C] -- C:\Users\Eric\Documents\BioWare
    [2013-04-05 09:52:26 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Atheros_L1e
    [2013-04-05 09:51:15 | 000,108,656 | ---- | C] (Atheros Communications, Inc.) -- C:\Windows\SysNative\drivers\L1C62x64.sys
    [2013-04-05 09:51:15 | 000,089,128 | ---- | C] (Atheros Communications Inc.) -- C:\Users\Eric\Desktop\DriUpdate64.exe
    [2013-04-05 09:51:15 | 000,082,472 | ---- | C] (Atheros Communications Inc.) -- C:\Users\Eric\Desktop\DriUpdate32.exe
    [2013-04-05 09:51:15 | 000,000,000 | ---D | C] -- C:\Users\Eric\Desktop\RIS
    [2013-04-05 09:51:15 | 000,000,000 | ---D | C] -- C:\Users\Eric\Desktop\Readme
    [2013-04-05 09:51:15 | 000,000,000 | ---D | C] -- C:\Users\Eric\Desktop\Common_Dri
    [2013-04-04 21:56:46 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Roaming\Malwarebytes
    [2013-04-04 21:56:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
    [2013-04-04 21:56:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
    [2013-04-04 21:56:39 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2013-04-04 21:56:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    [2013-04-04 19:21:14 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\Diagnostics
    [2013-04-04 19:00:31 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\ElevatedDiagnostics
    [2013-04-03 17:15:15 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\'Full Speed' Internet Booster
    [2013-04-03 17:15:14 | 000,000,000 | ---D | C] -- C:\Windows\'Full Speed' Internet Booster
    [2013-04-03 17:15:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\'Full Speed' Internet Booster
    [2013-04-03 17:11:08 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\Smartbar
    [2013-04-03 17:10:30 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\SwvUpdater
    [2013-04-03 17:10:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PlayMillion
    [2013-04-03 17:09:50 | 000,000,000 | ---D | C] -- C:\ProgramData\eSafe
    [2013-04-03 17:09:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desk 365
    [2013-04-03 17:09:43 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Roaming\Desk 365
    [2013-04-03 17:09:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Desk 365
    [2013-04-03 17:06:03 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Roaming\eIntaller
    [2013-04-03 12:20:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\BattlEye
    [2013-04-03 12:07:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Bohemia Interactive Studio
    [2013-04-03 11:43:49 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\ArmA 2
    [2013-04-03 11:20:10 | 000,000,000 | ---D | C] -- C:\Users\Eric\Documents\ArmA 2
    [2013-04-03 11:20:09 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\ArmA 2 OA
    [2013-04-03 11:18:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
    [2013-04-03 11:18:38 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
    [2013-04-03 11:16:03 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\DayZCommander
    [2013-04-03 11:15:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dotjosh Studios
    [2013-04-03 11:15:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dotjosh Studios
    [2013-04-03 10:58:14 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Roaming\Play withSIX
    [2013-04-03 10:58:14 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\Play withSIX
    [2013-04-03 10:58:14 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\IsolatedStorage
    [2013-04-03 10:57:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SIX Networks
    [2013-04-03 10:57:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SIX Networks
    [2013-04-03 10:56:36 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\Downloaded Installations
    [2013-04-02 13:55:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)
    [2013-03-31 21:06:46 | 000,000,000 | ---D | C] -- C:\Users\Eric\Documents\My Cheat Tables
    [2013-03-31 21:06:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.2
    [2013-03-31 21:06:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cheat Engine 6.2
    [2013-03-31 14:42:22 | 000,000,000 | ---D | C] -- C:\Users\Eric\Documents\Bioshock
    [2013-03-31 14:42:22 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Roaming\Bioshock
    [2013-03-31 14:42:18 | 000,000,000 | RH-D | C] -- C:\Users\Eric\AppData\Roaming\SecuROM
    [2013-03-31 11:51:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
    [2013-03-31 11:51:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AGEIA Technologies
    [2013-03-31 11:50:09 | 000,061,216 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
    [2013-03-31 11:50:09 | 000,053,024 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
    [2013-03-31 11:48:55 | 000,194,488 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\drivers\nvhda64v.sys
    [2013-03-31 11:48:55 | 000,031,672 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvhdap64.dll
    [2013-03-31 11:48:52 | 025,256,736 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll
    [2013-03-31 11:48:52 | 017,560,352 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll
    [2013-03-31 11:48:52 | 009,414,456 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll
    [2013-03-31 11:48:52 | 002,539,128 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll
    [2013-03-31 11:48:52 | 001,807,136 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6431422.dll
    [2013-03-31 11:48:52 | 001,510,176 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco6431422.dll
    [2013-03-31 11:48:51 | 007,959,000 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll
    [2013-03-31 11:48:51 | 002,913,056 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll
    [2013-03-31 11:48:51 | 002,728,736 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll
    [2013-03-31 11:48:51 | 002,355,488 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll
    [2013-03-31 11:48:51 | 001,995,552 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll
    [2013-03-31 11:48:50 | 026,956,576 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll
    [2013-03-31 11:48:50 | 020,542,752 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll
    [2013-03-31 11:48:50 | 007,573,816 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvopencl.dll
    [2013-03-31 11:48:50 | 006,271,872 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvopencl.dll
    [2013-03-31 11:48:49 | 013,088,000 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll
    [2013-03-30 14:46:30 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Roaming\FLEXnet
    [2013-03-30 14:46:28 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Roaming\Nuance
    [2013-03-30 14:46:26 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Roaming\Zeon
    [2013-03-30 13:05:20 | 000,000,000 | ---D | C] -- C:\Users\Eric\Desktop\Millenaire Installer
    [2013-03-30 13:01:10 | 000,000,000 | ---D | C] -- C:\Users\Eric\Desktop\MCNostalgia2.1.2
    [2013-03-30 12:58:45 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Roaming\.minecraft
    [2013-03-29 23:06:34 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\Apple Computer
    [2013-03-29 23:06:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    [2013-03-29 23:06:08 | 000,033,240 | ---- | C] (GEAR Software Inc.) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys
    [2013-03-29 23:05:41 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
    [2013-03-29 23:05:40 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
    [2013-03-29 23:05:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
    [2013-03-29 23:05:40 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
    [2013-03-29 23:03:35 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
    [2013-03-29 23:03:26 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
    [2013-03-29 23:03:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
    [2013-03-29 22:47:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CamStudio 2.7
    [2013-03-29 22:47:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CamStudio 2.7
    [2013-03-29 04:02:58 | 001,054,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
    [2013-03-29 04:02:58 | 000,226,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
    [2013-03-29 04:02:58 | 000,185,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
    [2013-03-29 04:02:58 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
    [2013-03-29 04:02:57 | 003,958,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
    [2013-03-29 04:02:57 | 001,509,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
    [2013-03-29 04:02:57 | 001,441,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
    [2013-03-29 04:02:57 | 001,400,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
    [2013-03-29 04:02:57 | 001,400,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
    [2013-03-29 04:02:57 | 000,905,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
    [2013-03-29 04:02:57 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
    [2013-03-29 04:02:57 | 000,762,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
    [2013-03-29 04:02:57 | 000,719,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
    [2013-03-29 04:02:57 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
    [2013-03-29 04:02:57 | 000,629,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
    [2013-03-29 04:02:57 | 000,603,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
    [2013-03-29 04:02:57 | 000,599,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
    [2013-03-29 04:02:57 | 000,526,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
    [2013-03-29 04:02:57 | 000,452,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
    [2013-03-29 04:02:57 | 000,441,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
    [2013-03-29 04:02:57 | 000,391,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
    [2013-03-29 04:02:57 | 000,361,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
    [2013-03-29 04:02:57 | 000,281,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
    [2013-03-29 04:02:57 | 000,235,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
    [2013-03-29 04:02:57 | 000,232,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
    [2013-03-29 04:02:57 | 000,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
    [2013-03-29 04:02:57 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
    [2013-03-29 04:02:57 | 000,173,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
    [2013-03-29 04:02:57 | 000,167,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
    [2013-03-29 04:02:57 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
    [2013-03-29 04:02:57 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
    [2013-03-29 04:02:57 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
    [2013-03-29 04:02:57 | 000,144,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
    [2013-03-29 04:02:57 | 000,138,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
    [2013-03-29 04:02:57 | 000,137,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
    [2013-03-29 04:02:57 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
    [2013-03-29 04:02:57 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
    [2013-03-29 04:02:57 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
    [2013-03-29 04:02:57 | 000,125,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
    [2013-03-29 04:02:57 | 000,117,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
    [2013-03-29 04:02:57 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
    [2013-03-29 04:02:57 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
    [2013-03-29 04:02:57 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
    [2013-03-29 04:02:57 | 000,097,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
    [2013-03-29 04:02:57 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
    [2013-03-29 04:02:57 | 000,089,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
    [2013-03-29 04:02:57 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
    [2013-03-29 04:02:57 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
    [2013-03-29 04:02:57 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
    [2013-03-29 04:02:57 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
    [2013-03-29 04:02:57 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
    [2013-03-29 04:02:57 | 000,069,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
    [2013-03-29 04:02:57 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
    [2013-03-29 04:02:57 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
    [2013-03-29 04:02:57 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
    [2013-03-29 04:02:57 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
    [2013-03-29 04:02:57 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
    [2013-03-29 04:02:57 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
    [2013-03-29 04:02:57 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
    [2013-03-29 04:02:57 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
    [2013-03-29 04:02:57 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
    [2013-03-29 04:02:57 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
    [2013-03-29 04:02:57 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
    [2013-03-29 04:02:57 | 000,027,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
    [2013-03-29 04:02:57 | 000,023,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
    [2013-03-29 04:02:57 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
    [2013-03-29 04:02:57 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
    [2013-03-29 04:02:57 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
    [2013-03-29 00:00:38 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\Aeria Games
    [2013-03-28 23:59:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Aeria Games
    [2013-03-28 23:55:33 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\directx
    [2013-03-28 23:55:32 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AeriaGames
    [2013-03-28 23:47:16 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\AI_RecycleBin
    [2013-03-28 23:47:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AeriaGames
    [2013-03-28 23:47:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Aeria Games
    [2013-03-28 23:33:50 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\Akamai
    [2013-03-28 23:33:48 | 000,000,000 | ---D | C] -- C:\AeriaGames
    [2013-03-27 21:28:42 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\FLT
    [2013-03-27 19:50:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BioShock Infinite
    [2013-03-27 19:35:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BioShock Infinite
    [2013-03-26 21:11:45 | 000,000,000 | ---D | C] -- C:\Users\Eric\Documents\BFBC2
    [2013-03-26 18:39:43 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usb8023.sys
    [2013-03-22 20:26:12 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Roaming\vlc
    [2013-03-22 20:25:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
    [2013-03-22 20:25:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN
    [2013-03-21 19:49:46 | 000,000,000 | ---D | C] -- C:\Users\Eric\Documents\MOHW
    [2013-03-21 19:21:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Medal of Honor™ Warfighter
    [2013-03-19 20:00:09 | 000,000,000 | ---D | C] -- C:\Users\Eric\Documents\Rockstar Games
    [2013-03-19 19:56:34 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\Rockstar Games
    [2013-03-14 22:07:52 | 000,559,904 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvStreaming.exe
    [2013-03-14 19:16:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    [2013-03-14 19:15:43 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
    [2013-03-14 19:15:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
    [2013-03-12 20:31:54 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\ESN
    [2013-03-12 20:31:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Battlelog Web Plugins
    [2013-03-12 20:29:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    [2013-03-12 20:29:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
    [2013-03-12 20:29:10 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\Google
    [2013-03-11 18:41:05 | 000,000,000 | ---D | C] -- C:\Users\Eric\Documents\SimCity
    [2013-03-11 18:39:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SimCity™
    [2013-03-10 22:36:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Digipen
    [2013-03-10 22:35:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DigiPen
    [2013-03-10 22:35:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DigiPen
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2013-04-06 11:47:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Eric\Desktop\OTL.exe
    [2013-04-06 11:46:49 | 000,000,512 | ---- | M] () -- C:\Users\Eric\Desktop\MBR.dat
    [2013-04-06 11:45:02 | 004,745,728 | ---- | M] (AVAST Software) -- C:\Users\Eric\Desktop\aswMBR.exe
    [2013-04-06 11:34:02 | 000,000,990 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2013-04-06 10:59:01 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2013-04-05 22:36:29 | 000,000,902 | ---- | M] () -- C:\Users\Eric\AppData\Local\_settings.ini
    [2013-04-05 21:59:17 | 000,000,380 | ---- | M] () -- C:\Users\Eric\AppData\Roaming\sp_data.sys
    [2013-04-05 19:34:01 | 000,000,986 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2013-04-05 17:39:42 | 000,019,656 | ---- | M] () -- C:\1082470 - Asari Commander_Shepard FemShep Kelly_Chambers Liara_T'Soni Mass_Effect Miranda_Lawson Samara nesoun.jpg
    [2013-04-05 17:36:20 | 000,018,428 | ---- | M] () -- C:\ssdsd.jpg
    [2013-04-05 17:26:38 | 000,116,249 | ---- | M] () -- C:\nude-ebony-girl-kriss-tefur.jpg
    [2013-04-05 16:16:01 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
    [2013-04-05 12:34:42 | 000,076,888 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
    [2013-04-05 12:34:35 | 000,280,792 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
    [2013-04-05 12:34:35 | 000,280,792 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
    [2013-04-05 12:33:52 | 000,281,032 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
    [2013-04-05 09:55:03 | 000,799,336 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2013-04-05 09:55:03 | 000,666,734 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2013-04-05 09:55:03 | 000,126,274 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2013-04-05 09:50:24 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2013-04-05 09:50:24 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2013-04-05 09:43:46 | 000,000,828 | ---- | M] () -- C:\Windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
    [2013-04-05 09:43:03 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2013-04-05 09:43:01 | 2115,952,639 | -HS- | M] () -- C:\hiberfil.sys
    [2013-04-05 09:23:32 | 002,428,917 | -H-- | M] () -- C:\Users\Eric\AppData\Roaming\Ericlog.dat
    [2013-04-04 22:12:24 | 080,528,901 | ---- | M] () -- C:\Users\Eric\Desktop\WiFi_Intel_Win7_64_Z15011.zip
    [2013-04-04 22:12:23 | 055,232,506 | ---- | M] () -- C:\Users\Eric\Desktop\WiMax_Intel_BBYCM30068_Win7_64_Z65103526.zip
    [2013-04-04 22:12:03 | 011,637,805 | ---- | M] () -- C:\Users\Eric\Desktop\WiMAX_Intel_Win7_64_Z71100126.zip
    [2013-04-04 22:12:02 | 023,879,167 | ---- | M] () -- C:\Users\Eric\Desktop\WLAN_Atheros_Win7_64_Z920469.zip
    [2013-04-04 22:11:15 | 005,346,636 | ---- | M] () -- C:\Users\Eric\Desktop\LAN_Atheros_Win7_64_Z2088.zip
    [2013-04-04 21:56:40 | 000,001,115 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2013-04-03 17:09:41 | 000,002,403 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
    [2013-04-03 17:09:37 | 000,002,503 | ---- | M] () -- C:\Users\Eric\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
    [2013-04-03 17:09:37 | 000,001,661 | ---- | M] () -- C:\Users\Eric\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
    [2013-04-03 11:15:56 | 000,001,338 | ---- | M] () -- C:\Users\Public\Desktop\DayZ Commander.lnk
    [2013-03-31 21:06:43 | 000,001,091 | ---- | M] () -- C:\Users\Eric\Desktop\Cheat Engine.lnk
    [2013-03-29 23:55:27 | 000,004,523 | ---- | M] () -- C:\Users\Eric\AppData\Roaming\CamStudio.cfg
    [2013-03-29 23:55:27 | 000,000,408 | ---- | M] () -- C:\Users\Eric\AppData\Roaming\CamShapes.ini
    [2013-03-29 23:55:27 | 000,000,408 | ---- | M] () -- C:\Users\Eric\AppData\Roaming\CamLayout.ini
    [2013-03-29 23:55:27 | 000,000,096 | ---- | M] () -- C:\Users\Eric\AppData\Roaming\Camdata.ini
    [2013-03-29 23:06:31 | 000,001,785 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
    [2013-03-29 23:04:17 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_netaapl64_01009.Wdf
    [2013-03-29 23:00:37 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
    [2013-03-29 04:02:58 | 001,054,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
    [2013-03-29 04:02:58 | 000,226,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\elshyph.dll
    [2013-03-29 04:02:58 | 000,185,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\elshyph.dll
    [2013-03-29 04:02:58 | 000,071,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
    [2013-03-29 04:02:57 | 003,958,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
    [2013-03-29 04:02:57 | 001,509,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
    [2013-03-29 04:02:57 | 001,441,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
    [2013-03-29 04:02:57 | 001,400,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
    [2013-03-29 04:02:57 | 001,400,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
    [2013-03-29 04:02:57 | 000,905,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
    [2013-03-29 04:02:57 | 000,855,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
    [2013-03-29 04:02:57 | 000,762,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
    [2013-03-29 04:02:57 | 000,719,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
    [2013-03-29 04:02:57 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
    [2013-03-29 04:02:57 | 000,629,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
    [2013-03-29 04:02:57 | 000,603,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
    [2013-03-29 04:02:57 | 000,599,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
    [2013-03-29 04:02:57 | 000,526,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
    [2013-03-29 04:02:57 | 000,452,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
    [2013-03-29 04:02:57 | 000,441,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
    [2013-03-29 04:02:57 | 000,391,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
    [2013-03-29 04:02:57 | 000,361,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
    [2013-03-29 04:02:57 | 000,281,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
    [2013-03-29 04:02:57 | 000,235,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
    [2013-03-29 04:02:57 | 000,232,960 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
    [2013-03-29 04:02:57 | 000,216,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
    [2013-03-29 04:02:57 | 000,197,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
    [2013-03-29 04:02:57 | 000,173,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
    [2013-03-29 04:02:57 | 000,167,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
    [2013-03-29 04:02:57 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
    [2013-03-29 04:02:57 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
    [2013-03-29 04:02:57 | 000,149,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
    [2013-03-29 04:02:57 | 000,144,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
    [2013-03-29 04:02:57 | 000,138,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
    [2013-03-29 04:02:57 | 000,137,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
    [2013-03-29 04:02:57 | 000,136,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
    [2013-03-29 04:02:57 | 000,136,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
    [2013-03-29 04:02:57 | 000,135,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
    [2013-03-29 04:02:57 | 000,125,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
    [2013-03-29 04:02:57 | 000,117,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
    [2013-03-29 04:02:57 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
    [2013-03-29 04:02:57 | 000,109,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
    [2013-03-29 04:02:57 | 000,102,912 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
    [2013-03-29 04:02:57 | 000,097,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
    [2013-03-29 04:02:57 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
    [2013-03-29 04:02:57 | 000,089,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
    [2013-03-29 04:02:57 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
    [2013-03-29 04:02:57 | 000,081,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
    [2013-03-29 04:02:57 | 000,079,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
    [2013-03-29 04:02:57 | 000,077,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
    [2013-03-29 04:02:57 | 000,073,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
    [2013-03-29 04:02:57 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
    [2013-03-29 04:02:57 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
    [2013-03-29 04:02:57 | 000,062,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
    [2013-03-29 04:02:57 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
    [2013-03-29 04:02:57 | 000,061,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
    [2013-03-29 04:02:57 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
    [2013-03-29 04:02:57 | 000,051,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
    [2013-03-29 04:02:57 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
    [2013-03-29 04:02:57 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
    [2013-03-29 04:02:57 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
    [2013-03-29 04:02:57 | 000,039,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
    [2013-03-29 04:02:57 | 000,033,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
    [2013-03-29 04:02:57 | 000,027,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
    [2013-03-29 04:02:57 | 000,025,185 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
    [2013-03-29 04:02:57 | 000,025,185 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
    [2013-03-29 04:02:57 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
    [2013-03-29 04:02:57 | 000,013,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
    [2013-03-29 04:02:57 | 000,012,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
    [2013-03-29 04:02:57 | 000,011,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
    [2013-03-28 23:55:33 | 000,001,709 | ---- | M] () -- C:\Users\Eric\Desktop\Scarlet Blade.lnk
    [2013-03-28 23:47:15 | 000,002,030 | ---- | M] () -- C:\Users\Public\Desktop\Aeria Ignite.lnk
    [2013-03-27 19:50:34 | 000,002,241 | ---- | M] () -- C:\Users\Public\Desktop\Launch BioShock Infinite.lnk
    [2013-03-27 19:50:34 | 000,002,206 | ---- | M] () -- C:\Users\Public\Desktop\Launch BioShock Infinite Benchmarking Utility.lnk
    [2013-03-26 21:09:25 | 002,434,856 | ---- | M] () -- C:\Windows\SysWow64\pbsvc_bc2.exe
    [2013-03-24 20:25:35 | 000,000,630 | ---- | M] () -- C:\Users\Public\Desktop\Hitman Absolution.lnk
    [2013-03-22 20:25:57 | 000,001,072 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
    [2013-03-21 19:21:29 | 000,001,267 | ---- | M] () -- C:\Users\Public\Desktop\Medal of Honor™ Warfighter.lnk
    [2013-03-15 07:53:06 | 026,956,576 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll
    [2013-03-15 07:53:06 | 025,256,736 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll
    [2013-03-15 07:53:06 | 020,542,752 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll
    [2013-03-15 07:53:06 | 017,990,800 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvd3dumx.dll
    [2013-03-15 07:53:06 | 017,560,352 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll
    [2013-03-15 07:53:06 | 015,508,512 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvwgf2umx.dll
    [2013-03-15 07:53:06 | 015,042,928 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll
    [2013-03-15 07:53:06 | 013,088,000 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll
    [2013-03-15 07:53:06 | 009,414,456 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll
    [2013-03-15 07:53:06 | 007,959,000 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll
    [2013-03-15 07:53:06 | 007,573,816 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvopencl.dll
    [2013-03-15 07:53:06 | 006,271,872 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvopencl.dll
    [2013-03-15 07:53:06 | 002,913,056 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll
    [2013-03-15 07:53:06 | 002,864,144 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvapi64.dll
    [2013-03-15 07:53:06 | 002,728,736 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll
    [2013-03-15 07:53:06 | 002,539,128 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll
    [2013-03-15 07:53:06 | 002,355,488 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll
    [2013-03-15 07:53:06 | 001,995,552 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll
    [2013-03-15 07:53:06 | 001,807,136 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco6431422.dll
    [2013-03-15 07:53:06 | 001,510,176 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispgenco6431422.dll
    [2013-03-15 07:53:06 | 000,061,216 | ---- | M] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
    [2013-03-15 07:53:06 | 000,053,024 | ---- | M] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
    [2013-03-15 07:53:06 | 000,017,738 | ---- | M] () -- C:\Windows\SysNative\nvinfo.pb
    [2013-03-15 06:16:18 | 003,477,280 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvc64.dll
    [2013-03-15 06:16:17 | 006,398,240 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcpl.dll
    [2013-03-15 06:16:10 | 002,555,680 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvcr.dll
    [2013-03-15 06:16:10 | 000,237,856 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvmctray.dll
    [2013-03-15 06:16:10 | 000,063,776 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysNative\nvshext.dll
    [2013-03-14 22:07:52 | 000,559,904 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvStreaming.exe
    [2013-03-13 07:52:23 | 000,693,976 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
    [2013-03-13 07:52:23 | 000,073,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    [2013-03-11 18:40:11 | 000,001,278 | ---- | M] () -- C:\Users\Public\Desktop\SimCity™.lnk
    [2013-03-10 22:35:19 | 000,001,171 | ---- | M] () -- C:\Users\Public\Desktop\Perspective.lnk
    [2013-03-08 17:49:35 | 000,000,622 | ---- | M] () -- C:\Users\Public\Desktop\Tombraider.lnk
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2013-04-06 11:46:49 | 000,000,512 | ---- | C] () -- C:\Users\Eric\Desktop\MBR.dat
    [2013-04-05 22:24:08 | 000,000,902 | ---- | C] () -- C:\Users\Eric\AppData\Local\_settings.ini
    [2013-04-05 21:49:28 | 000,073,728 | ---- | C] () -- C:\Users\Eric\Desktop\TF2Base.exe
    [2013-04-05 21:39:57 | 000,002,681 | ---- | C] () -- C:\Users\Eric\Desktop\info.htm
    [2013-04-05 21:39:57 | 000,000,185 | ---- | C] () -- C:\Users\Eric\Desktop\More free cheats and hacks!.url
    [2013-04-05 17:39:11 | 000,019,656 | ---- | C] () -- C:\1082470 - Asari Commander_Shepard FemShep Kelly_Chambers Liara_T'Soni Mass_Effect Miranda_Lawson Samara nesoun.jpg
    [2013-04-05 17:36:20 | 000,018,428 | ---- | C] () -- C:\ssdsd.jpg
    [2013-04-05 17:26:34 | 000,116,249 | ---- | C] () -- C:\nude-ebony-girl-kriss-tefur.jpg
    [2013-04-05 09:51:15 | 003,270,485 | ---- | C] () -- C:\Users\Eric\Desktop\data1.cab
    [2013-04-05 09:51:15 | 000,032,920 | ---- | C] () -- C:\Users\Eric\Desktop\data1.hdr
    [2013-04-05 09:51:15 | 000,006,400 | ---- | C] () -- C:\Users\Eric\Desktop\README.htm
    [2013-04-05 09:51:15 | 000,000,512 | ---- | C] () -- C:\Users\Eric\Desktop\data2.cab
    [2013-04-05 09:51:15 | 000,000,473 | ---- | C] () -- C:\Users\Eric\Desktop\layout.bin
    [2013-04-04 22:12:14 | 055,232,506 | ---- | C] () -- C:\Users\Eric\Desktop\WiMax_Intel_BBYCM30068_Win7_64_Z65103526.zip
    [2013-04-04 22:12:04 | 080,528,901 | ---- | C] () -- C:\Users\Eric\Desktop\WiFi_Intel_Win7_64_Z15011.zip
    [2013-04-04 22:11:58 | 023,879,167 | ---- | C] () -- C:\Users\Eric\Desktop\WLAN_Atheros_Win7_64_Z920469.zip
    [2013-04-04 22:11:49 | 011,637,805 | ---- | C] () -- C:\Users\Eric\Desktop\WiMAX_Intel_Win7_64_Z71100126.zip
    [2013-04-04 22:10:55 | 005,346,636 | ---- | C] () -- C:\Users\Eric\Desktop\LAN_Atheros_Win7_64_Z2088.zip
    [2013-04-04 21:56:40 | 000,001,115 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2013-04-03 11:15:56 | 000,001,338 | ---- | C] () -- C:\Users\Public\Desktop\DayZ Commander.lnk
    [2013-03-31 21:06:43 | 000,001,091 | ---- | C] () -- C:\Users\Eric\Desktop\Cheat Engine.lnk
    [2013-03-29 23:06:31 | 000,001,785 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
    [2013-03-29 23:04:17 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_netaapl64_01009.Wdf
    [2013-03-29 23:00:37 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
    [2013-03-29 22:50:20 | 000,004,523 | ---- | C] () -- C:\Users\Eric\AppData\Roaming\CamStudio.cfg
    [2013-03-29 22:50:20 | 000,000,408 | ---- | C] () -- C:\Users\Eric\AppData\Roaming\CamShapes.ini
    [2013-03-29 22:50:20 | 000,000,408 | ---- | C] () -- C:\Users\Eric\AppData\Roaming\CamLayout.ini
    [2013-03-29 22:50:20 | 000,000,096 | ---- | C] () -- C:\Users\Eric\AppData\Roaming\Camdata.ini
    [2013-03-29 04:02:57 | 000,025,185 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
    [2013-03-29 04:02:57 | 000,025,185 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
    [2013-03-28 23:55:33 | 000,001,709 | ---- | C] () -- C:\Users\Eric\Desktop\Scarlet Blade.lnk
    [2013-03-28 23:47:15 | 000,002,030 | ---- | C] () -- C:\Users\Public\Desktop\Aeria Ignite.lnk
    [2013-03-27 19:50:34 | 000,002,241 | ---- | C] () -- C:\Users\Public\Desktop\Launch BioShock Infinite.lnk
    [2013-03-27 19:50:34 | 000,002,206 | ---- | C] () -- C:\Users\Public\Desktop\Launch BioShock Infinite Benchmarking Utility.lnk
    [2013-03-26 21:09:25 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe
    [2013-03-24 20:25:35 | 000,000,630 | ---- | C] () -- C:\Users\Public\Desktop\Hitman Absolution.lnk
    [2013-03-22 20:25:57 | 000,001,072 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
    [2013-03-21 19:21:29 | 000,001,267 | ---- | C] () -- C:\Users\Public\Desktop\Medal of Honor™ Warfighter.lnk
    [2013-03-12 20:29:33 | 000,002,503 | ---- | C] () -- C:\Users\Eric\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
    [2013-03-12 20:29:33 | 000,002,403 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
    [2013-03-12 20:29:14 | 000,000,990 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2013-03-12 20:29:13 | 000,000,986 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2013-03-11 18:39:30 | 000,001,278 | ---- | C] () -- C:\Users\Public\Desktop\SimCity™.lnk
    [2013-03-10 22:35:19 | 000,001,171 | ---- | C] () -- C:\Users\Public\Desktop\Perspective.lnk
    [2013-03-08 17:49:35 | 000,000,622 | ---- | C] () -- C:\Users\Public\Desktop\Tombraider.lnk
    [2013-03-01 22:12:55 | 000,703,117 | ---- | C] () -- C:\Users\Eric\AppData\Roaming\technic-launcher.jar
    [2013-03-01 18:04:44 | 000,000,757 | ---- | C] () -- C:\Users\Eric\AppData\Roaming\Eric3SQLite3.dll
    [2013-02-28 19:30:48 | 000,000,000 | ---- | C] () -- C:\Users\Eric\__ng3d.lock
    [2013-02-28 14:40:32 | 003,130,440 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_blr.exe
    [2013-02-25 19:22:41 | 000,000,000 | ---- | C] () -- C:\Windows\PowerReg.dat
    [2013-02-24 12:46:54 | 000,036,892 | ---- | C] () -- C:\Windows\SysWow64\bassmod.dll
    [2013-02-16 23:06:21 | 000,022,064 | ---- | C] () -- C:\Windows\DCEBoot64.exe
    [2013-02-07 22:37:59 | 000,280,792 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
    [2013-02-07 22:37:58 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
    [2013-02-03 03:43:22 | 000,000,380 | ---- | C] () -- C:\Users\Eric\AppData\Roaming\sp_data.sys
    [2012-01-11 06:39:16 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll
    [2011-10-20 11:59:10 | 000,131,984 | ---- | C] () -- C:\ProgramData\FullRemove.exe
    [2011-10-20 11:48:36 | 000,804,590 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2005-03-27 23:00:29 | 002,428,917 | -H-- | C] () -- C:\Users\Eric\AppData\Roaming\Ericlog.dat

    ========== ZeroAccess Check ==========

    [2009-07-14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

    [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64


    [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64


    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
    "" = C:\Windows\SysNative\shell32.dll -- [2012-06-09 07:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    "" = %SystemRoot%\system32\shell32.dll -- [2012-06-09 06:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    "" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 14:19:04 | 000,606,208 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Both


    ========== LOP Check ==========

    [2013-04-03 17:18:16 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\.minecraft
    [2013-03-16 14:27:48 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\.techniclauncher
    [2013-02-03 03:43:29 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\ASUS WebStorage
    [2013-03-31 15:13:46 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\Bioshock
    [2013-04-03 17:09:49 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\Desk 365
    [2013-02-25 16:38:25 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\DVDVideoSoft
    [2013-02-25 16:38:25 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\DVDVideoSoftIEHelpers
    [2013-04-03 17:06:03 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\eIntaller
    [2013-02-26 10:38:01 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\Lionhead Studios
    [2013-03-16 14:27:29 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\logs
    [2013-02-15 23:21:13 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\LolClient
    [2013-03-30 14:46:29 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\Nuance
    [2013-02-25 16:37:50 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\OpenCandy
    [2013-02-11 17:39:35 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\Origin
    [2013-04-03 10:58:48 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\Play withSIX
    [2013-02-08 23:04:35 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\PowerISO
    [2013-03-29 04:23:23 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\SoftGrid Client
    [2013-02-13 10:34:45 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\TP
    [2013-02-23 20:09:07 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\Ubisoft
    [2013-02-10 12:06:04 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\uMod
    [2013-04-06 11:55:04 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\uTorrent
    [2013-02-03 12:50:43 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\Waterfox Limited
    [2013-04-05 09:25:10 | 000,000,000 | RHSD | M] -- C:\Users\Eric\AppData\Roaming\WinDir
    [2013-03-30 14:46:26 | 000,000,000 | ---D | M] -- C:\Users\Eric\AppData\Roaming\Zeon

    ========== Purity Check ==========

    ========== Custom Scans ==========

    ========== Drive Information ==========

    Physical Drives

    Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
    Interface type: IDE
    Media Type: Fixed hard disk media
    Model: ST9750420AS
    Partitions: 4
    Status: OK
    Status Info: 0


    DeviceID: Disk #0, Partition #0
    PartitionType: GPT: System
    Bootable: True
    BootPartition: True
    PrimaryPartition: True
    Size: 200,00MB
    Starting Offset: 1048576
    Hidden sectors: 0

    DeviceID: Disk #0, Partition #1
    PartitionType: GPT: Basic Data
    Bootable: False
    BootPartition: False
    PrimaryPartition: True
    Size: 279,00GB
    Starting Offset: 344981504
    Hidden sectors: 0

    DeviceID: Disk #0, Partition #2
    PartitionType: GPT: Basic Data
    Bootable: False
    BootPartition: False
    PrimaryPartition: True
    Size: 394,00GB
    Starting Offset: 300407586816
    Hidden sectors: 0

    DeviceID: Disk #0, Partition #3
    PartitionType: GPT: Unknown
    Bootable: False
    BootPartition: False
    PrimaryPartition: False
    Size: 24,00GB
    Starting Offset: 723942113280
    Hidden sectors: 0

    < %SYSTEMDRIVE%\*.* >
    [2013-04-05 17:39:42 | 000,019,656 | ---- | M] () -- C:\1082470 - Asari Commander_Shepard FemShep Kelly_Chambers Liara_T'Soni Mass_Effect Miranda_Lawson Samara nesoun.jpg
    [2011-10-11 23:56:25 | 000,000,044 | ---- | M] () -- C:\ASUS.md5
    [2009-07-14 03:38:58 | 000,383,562 | RHS- | M] () -- C:\bootmgr
    [2009-07-29 08:03:37 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
    [2013-02-03 12:31:11 | 000,018,878 | ---- | M] () -- C:\devlist.txt
    [2013-02-03 12:31:11 | 000,000,009 | ---- | M] () -- C:\Finish.log
    [2012-02-16 03:42:26 | 006,293,504 | -H-- | M] () -- C:\G75VW.BIN
    [2012-02-16 04:26:17 | 000,000,019 | ---- | M] () -- C:\G75VW_WIN7.20
    [2013-04-05 09:43:01 | 2115,952,639 | -HS- | M] () -- C:\hiberfil.sys
    [2013-04-05 17:26:38 | 000,116,249 | ---- | M] () -- C:\nude-ebony-girl-kriss-tefur.jpg
    [2013-04-05 09:42:57 | 4252,925,951 | -HS- | M] () -- C:\pagefile.sys
    [2012-02-16 04:26:17 | 000,000,007 | ---- | M] () -- C:\RECOVERY.DAT
    [2011-12-07 08:21:32 | 000,000,876 | ---- | M] () -- C:\setup.iss
    [2013-02-03 20:04:51 | 000,000,086 | ---- | M] () -- C:\setup.log
    [2013-04-05 17:36:20 | 000,018,428 | ---- | M] () -- C:\ssdsd.jpg

    < %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >

    < %systemroot%\*. /mp /s >

    < %systemroot%\system32\*.dll /lockedfiles >

    < %systemroot%\Tasks\*.job /lockedfiles >

    < %systemroot%\system32\drivers\*.sys /lockedfiles >

    < %systemroot%\system32\*.exe /lockedfiles >

    < %systemroot%\System32\config\*.sav >

    < %PROGRAMFILES%\* >
    [2009-07-14 06:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini

    < %USERPROFILE%\..|smtmp;true;true;true /FP >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

    < hklm\software\clients\startmenuinternet|command /rs >
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [2013-03-22 00:50:35 | 001,312,720 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --hide-icons [2013-03-22 00:50:35 | 001,312,720 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --show-icons [2013-03-22 00:50:35 | 001,312,720 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" http://www.qvo6.com/?utm_source=b&u...T9750420AS_5WS3Z559XXXX5WS3Z559&ts=1365001777 [2013-03-22 00:50:35 | 001,312,720 | ---- | M] (Google Inc.)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2013-03-29 04:02:57 | 000,775,184 | ---- | M] (Microsoft Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_source=b&u...T9750420AS_5WS3Z559XXXX5WS3Z559&ts=1365001777 [2013-03-29 04:02:57 | 000,775,184 | ---- | M] (Microsoft Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Waterfox\uninstall\helper.exe" /HideShortcuts [2013-01-20 00:26:16 | 000,844,016 | ---- | M] (waterfoxproject.org)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Waterfox\uninstall\helper.exe" /ShowShortcuts [2013-01-20 00:26:16 | 000,844,016 | ---- | M] (waterfoxproject.org)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Waterfox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2013-01-20 00:26:16 | 000,844,016 | ---- | M] (waterfoxproject.org)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\shell\open\command\\: C:\Program Files\Waterfox\waterfox.exe http://www.qvo6.com/?utm_source=b&u...T9750420AS_5WS3Z559XXXX5WS3Z559&ts=1365001777 [2013-01-20 00:26:15 | 000,718,960 | ---- | M] (Mozilla Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\shell\properties\command\\: "C:\Program Files\Waterfox\waterfox.exe" -preferences [2013-01-20 00:26:15 | 000,718,960 | ---- | M] (Mozilla Corporation)
    HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\shell\safemode\command\\: "C:\Program Files\Waterfox\waterfox.exe" -safe-mode [2013-01-20 00:26:15 | 000,718,960 | ---- | M] (Mozilla Corporation)

    < hklm\software\clients\startmenuinternet|command /64 /rs >
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --MAKE-DEFAULT-BROWSER [2013-03-22 00:50:35 | 001,312,720 | ---- | M] (Google Inc.)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --HIDE-ICONS [2013-03-22 00:50:35 | 001,312,720 | ---- | M] (Google Inc.)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --SHOW-ICONS [2013-03-22 00:50:35 | 001,312,720 | ---- | M] (Google Inc.)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" HTTP://WWW.QVO6.COM/?UTM_SOURCE=B&U...T9750420AS_5WS3Z559XXXX5WS3Z559&TS=1365001777 [2013-03-22 00:50:35 | 001,312,720 | ---- | M] (Google Inc.)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -SHOW [2013-03-29 04:02:57 | 000,051,712 | ---- | M] (Microsoft Corporation)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -REINSTALL [2013-03-29 04:02:57 | 000,051,712 | ---- | M] (Microsoft Corporation)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -HIDE [2013-03-29 04:02:57 | 000,051,712 | ---- | M] (Microsoft Corporation)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE" -EXTOFF [2013-03-29 04:02:57 | 000,775,184 | ---- | M] (Microsoft Corporation)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE HTTP://WWW.QVO6.COM/?UTM_SOURCE=B&U...T9750420AS_5WS3Z559XXXX5WS3Z559&TS=1365001777 [2013-03-29 04:02:57 | 000,775,184 | ---- | M] (Microsoft Corporation)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\InstallInfo\\HideIconsCommand: "C:\PROGRAM FILES\WATERFOX\UNINSTALL\HELPER.EXE" /HIDESHORTCUTS [2013-01-20 00:26:16 | 000,844,016 | ---- | M] (waterfoxproject.org)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\PROGRAM FILES\WATERFOX\UNINSTALL\HELPER.EXE" /SHOWSHORTCUTS [2013-01-20 00:26:16 | 000,844,016 | ---- | M] (waterfoxproject.org)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\InstallInfo\\ReinstallCommand: "C:\PROGRAM FILES\WATERFOX\UNINSTALL\HELPER.EXE" /SETASDEFAULTAPPGLOBAL [2013-01-20 00:26:16 | 000,844,016 | ---- | M] (waterfoxproject.org)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\shell\open\command\\: C:\PROGRAM FILES\WATERFOX\WATERFOX.EXE HTTP://WWW.QVO6.COM/?UTM_SOURCE=B&U...T9750420AS_5WS3Z559XXXX5WS3Z559&TS=1365001777 [2013-01-20 00:26:15 | 000,718,960 | ---- | M] (Mozilla Corporation)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\shell\properties\command\\: "C:\PROGRAM FILES\WATERFOX\WATERFOX.EXE" -PREFERENCES [2013-01-20 00:26:15 | 000,718,960 | ---- | M] (Mozilla Corporation)
    64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\shell\safemode\command\\: "C:\PROGRAM FILES\WATERFOX\WATERFOX.EXE" -SAFE-MODE [2013-01-20 00:26:15 | 000,718,960 | ---- | M] (Mozilla Corporation)

    < End of report >


    OTL Extras logfile created on: 2013-04-06 11:50:00 - Run 1
    OTL by OldTimer - Version Folder = C:\Users\Eric\Desktop
    64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.10.9200.16521)
    Locale: 0000041D | Country: Sweden | Language: SVE | Date Format: yyyy-MM-dd

    7,96 Gb Total Physical Memory | 2,72 Gb Available Physical Memory | 34,22% Memory free
    15,92 Gb Paging File | 11,36 Gb Available in Paging File | 71,36% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 279,46 Gb Total Space | 20,76 Gb Free Space | 7,43% Space Free | Partition Type: NTFS
    Drive D: | 394,45 Gb Total Space | 56,28 Gb Free Space | 14,27% Space Free | Partition Type: NTFS

    Computer Name: KLETTENBERGARE | User Name: Eric | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========

    ========== File Associations ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
    .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

    .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
    .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

    .html [@ = ChromeHTML] -- Reg Error: Key error. File not found

    ========== Shell Spawning ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    htmlfile [edit] -- Reg Error: Key error.
    htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
    http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    htmlfile [edit] -- Reg Error: Key error.
    htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
    http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
    CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

    ========== Security Center Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

    ========== Firewall Settings ==========

    "DisableNotifications" = 0
    "EnableFirewall" = 1

    "DisableNotifications" = 0
    "EnableFirewall" = 1

    "DisableNotifications" = 0
    "EnableFirewall" = 1

    ========== Authorized Applications List ==========

    ========== Vista Active Open Ports Exception List ==========

    "{84EA4680-AF54-479E-AB56-8756AE607ADF}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
    "{CB5A6695-A95E-45D3-98B1-F9E727EA1CD8}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |

    ========== Vista Active Application Exception List ==========

    "{003CE10B-1EB6-41EF-80A4-154535ADD3BB}" = protocol=6 | dir=in | app=c:\users\eric\appdata\roaming\utorrent\utorrent.exe |
    "{06FD01F3-73B8-4C62-A5BC-4DFF72CB384B}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe |
    "{09095A23-7183-4AEE-9B45-62ACF2D8E863}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
    "{12DF2664-E45C-4A93-B872-EE9B5B41C1FE}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
    "{16AC3C03-D4CE-47EE-B684-CCD9226D9000}" = protocol=17 | dir=in | app=c:\program files (x86)\kingdoms of amalur reckoning\reckoning.exe |
    "{1C22EA19-C656-424F-BA2D-FDB7C7D88E1C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\regnum\rolaunchersteam.exe |
    "{1DE87692-C972-444F-98CC-304ACE8CD1D5}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
    "{26605201-A6E7-4764-B89A-1777257E9401}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
    "{28BA882B-1A93-446A-A2C5-ADC1FAAF0B8B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
    "{29C1BB23-3523-4039-84C3-0BD78123F3D9}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-hostd.exe |
    "{2ACB7E06-D909-4466-B038-FAB598C2438B}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
    "{2B4E5145-A2A8-4B63-BCA4-C5B1F4B222C4}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-hostd.exe |
    "{2E06E22A-051D-40ED-9020-61CA0C50CD15}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
    "{2E43A8C3-0AEC-4166-855A-76F532FA655D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\regnum\liveserver\roclientgame.exe |
    "{408D87F0-1913-446C-AC74-9BE026194B69}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
    "{41AFD700-4BCA-4A6E-8C07-99ECEBCA3833}" = protocol=17 | dir=in | app=c:\users\eric\appdata\roaming\utorrent\utorrent.exe |
    "{41E2001F-C2E2-45B8-9818-53CBF390F411}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{42D2D319-8879-4D9B-B55B-037D1473B58D}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\mond_wow.exe |
    "{42ED4FEF-51E3-4725-BEC8-38F37097C802}" = protocol=17 | dir=in | app=c:\users\eric\appdata\local\akamai\netsession_win.exe |
    "{472041F8-8AF6-4761-ADEC-8865844DF079}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
    "{4CA3FF00-DC3F-4AB6-98E9-6E3BA8CD7BD4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star conflict\game.exe |
    "{56CA5235-8EE9-476A-B37B-D5DA8DB96ADB}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe |
    "{56EBA468-514C-46D5-A486-967521A0AF1C}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
    "{570BA7D5-F590-40B1-9D2B-F25586791264}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\simcity\simcity\simcity.exe |
    "{57C1D7DA-701A-402B-98C2-0597E3A79AE9}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\battlefield 3\bf3.exe |
    "{58FA2EDA-41E8-42EE-B5FA-9C269896E9DB}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\medal of honor warfighter\mohw.exe |
    "{65ACBB58-4E12-47C3-8083-3833EFF1E575}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
    "{69F0CE2D-3FE7-4888-9246-6B23C85306B6}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe |
    "{6E13503E-706C-4726-A95C-3A90DDC07F8A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\blacklightretribution\blacklight retribution.exe |
    "{762594D5-0EF8-4B54-BBAF-BC02902374BE}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
    "{82600E4F-E319-4BCF-A682-70333F5A771B}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe |
    "{87CD00E1-7788-4BE2-A582-F5C55A2743DE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
    "{9A51D108-E83D-4F57-8726-B0C316FD1276}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2\arma2.exe |
    "{A2A81D81-21F6-44F1-94DA-F31ED411138B}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
    "{A3D32D08-6605-4C30-AED3-6644B8505A7E}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
    "{A3F577DE-F904-4B09-9775-73F730198E59}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\star conflict\game.exe |
    "{AE430662-3189-4C67-B512-DB949CD26DAE}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\mond_wow.exe |
    "{B049BC77-3AF6-4842-A1FD-EBD3BCE3C59D}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\medal of honor warfighter\mohw.exe |
    "{B27CD211-87A0-4694-940D-F6152E3536DE}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
    "{B3C69289-9666-4C4D-8E8C-325CCA5E226F}" = protocol=6 | dir=in | app=d:\steamlibrarys\steamapps\common\gotham city impostors f2p\engine.exe |
    "{B62295B6-28B3-4D40-B6B5-19103A61B29E}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
    "{BAD39E07-CFE8-47D2-A553-D8507A01006B}" = protocol=6 | dir=in | app=c:\program files (x86)\kingdoms of amalur reckoning\reckoning.exe |
    "{BDC8FEC2-C60C-4C2F-91A4-8D2C100805FD}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
    "{C80A3454-DFC3-40B0-8D30-9C983A768FE7}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\simcity\simcity\simcity.exe |
    "{C9FA3CB7-9020-4398-AE15-C54FE44541B6}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
    "{CAC06F7A-F7DE-41A3-B531-7285361FADCA}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{CB082D3A-805B-4F03-A70D-3B2BCB0542AA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\regnum\rolaunchersteam.exe |
    "{DA972964-7C0A-4D47-8031-EB8B4BCB6438}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\crysis 3 mp open beta\bin32\crysis 3 mp open beta.exe |
    "{DD4F38AA-863E-45B5-98AC-5894B7C1E063}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
    "{DEFA9165-8577-4DE9-9CD4-A0CA31F83D63}" = protocol=6 | dir=in | app=c:\users\eric\appdata\local\akamai\netsession_win.exe |
    "{DF8263A1-F181-406B-8A6C-2C3D31F015E0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2\arma2.exe |
    "{E58546F5-4D32-41EB-95AB-718CDFBA7351}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-authd.exe |
    "{E5EDA455-E4D8-4AFC-B67C-126D56ADA059}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\blacklightretribution\blacklight retribution.exe |
    "{E71DE6FC-FBCB-4C24-9202-6243067585CD}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
    "{ED095A24-DD3C-4D5F-843F-6886988B64EB}" = dir=in | app=c:\program files (x86)\vmware\vmware workstation\vmware-authd.exe |
    "{ED3E122D-12B0-4202-A738-D9722966F28D}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
    "{EEE8BC74-EDAE-49EA-BAAD-70E425E56E2B}" = protocol=17 | dir=in | app=d:\steamlibrarys\steamapps\common\gotham city impostors f2p\engine.exe |
    "{F1325073-0B14-455F-AF07-11AA6876E445}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
    "{F2D1C92E-792F-45C0-8A97-A284B87ADFDD}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
    "{F3BE4670-904D-470F-9F61-DDAC30B67474}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\regnum\liveserver\roclientgame.exe |
    "{F6B8C897-8F62-45ED-891B-46B4AFB2EBBF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
    "{FD1E340B-145E-43E6-8407-FA1FD49C749F}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
    "{FF1582E3-42B6-49CC-9CE0-39718072EE0F}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\crysis 3 mp open beta\bin32\crysis 3 mp open beta.exe |
    "TCP Query User{0A215BDD-EB63-4AB9-822E-2EC2C6D78FC9}C:\program files (x86)\steam\steamapps\supermannduden\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\supermannduden\team fortress 2\hl2.exe |
    "TCP Query User{252620BA-0643-4145-AEE2-83EBFCF8C692}D:\tera\tera-launcher.exe" = protocol=6 | dir=in | app=d:\tera\tera-launcher.exe |
    "TCP Query User{26628DFB-B4E0-4C10-BCAA-35F018BC4826}C:\program files (x86)\kingdoms of amalur reckoning\reckoning.exe" = protocol=6 | dir=in | app=c:\program files (x86)\kingdoms of amalur reckoning\reckoning.exe |
    "TCP Query User{435AAA29-6C9D-4C45-9CC5-C39A7560B6F8}C:\users\eric\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\eric\appdata\local\akamai\netsession_win.exe |
    "TCP Query User{53700DD1-8F7B-4926-B044-C795ECEFB129}D:\steamlibrarys\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe" = protocol=6 | dir=in | app=d:\steamlibrarys\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe |
    "TCP Query User{58B824B9-DBFE-4448-A6F8-EDA723C55943}C:\program files (x86)\steam\steamapps\eriklettenberg\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\eriklettenberg\team fortress 2\hl2.exe |
    "TCP Query User{5FCC21E7-3279-4401-ADB5-903CE913114D}C:\program files (x86)\steam\steam.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
    "TCP Query User{670BBB58-2026-48FA-BEDA-92CCE24F9B76}D:\dishonored\binaries\win32\dishonored.exe" = protocol=6 | dir=in | app=d:\dishonored\binaries\win32\dishonored.exe |
    "TCP Query User{860D0E08-CA00-4E20-904E-0418C5536711}C:\program files (x86)\origin games\battlefield bad company 2\bfbc2game.exe" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\battlefield bad company 2\bfbc2game.exe |
    "TCP Query User{A1E4C2D2-4C89-4F6B-9F3B-F557FBEA7AA1}C:\programdata\battle.net\agent\agent.1040\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
    "TCP Query User{BAD2795A-E36F-4197-B3DA-BF8162DC25A2}D:\steamlibrarys\steamapps\common\sourcefilmmaker\game\sfm.exe" = protocol=6 | dir=in | app=d:\steamlibrarys\steamapps\common\sourcefilmmaker\game\sfm.exe |
    "TCP Query User{BD2E290C-3A75-4F65-B145-11D80F979F67}D:\steamlibrarys\steamapps\common\arma 2 operation arrowhead\arma2oa.exe" = protocol=6 | dir=in | app=d:\steamlibrarys\steamapps\common\arma 2 operation arrowhead\arma2oa.exe |
    "TCP Query User{C1EC49E2-A5A4-4DBD-A64A-0A308499D3D1}C:\program files\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
    "UDP Query User{040028F6-1466-469E-9D6B-0BB5CE349A9D}C:\program files (x86)\steam\steamapps\supermannduden\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\supermannduden\team fortress 2\hl2.exe |
    "UDP Query User{09E84323-F5AE-4DAA-8037-40E59881AEE4}C:\programdata\battle.net\agent\agent.1040\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
    "UDP Query User{0DF2028F-565A-4AC2-8538-06C85EEB7917}D:\steamlibrarys\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe" = protocol=17 | dir=in | app=d:\steamlibrarys\steamapps\common\arma 2 operation arrowhead\expansion\beta\arma2oa.exe |
    "UDP Query User{3ED540AF-A8C2-4CD5-8082-CAD7EED63217}D:\steamlibrarys\steamapps\common\arma 2 operation arrowhead\arma2oa.exe" = protocol=17 | dir=in | app=d:\steamlibrarys\steamapps\common\arma 2 operation arrowhead\arma2oa.exe |
    "UDP Query User{4A977C72-12B9-4B0E-ADA0-856508F4ED89}D:\dishonored\binaries\win32\dishonored.exe" = protocol=17 | dir=in | app=d:\dishonored\binaries\win32\dishonored.exe |
    "UDP Query User{61E8D253-3B54-4D6C-8E2C-0C12BECED021}C:\program files (x86)\steam\steam.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
    "UDP Query User{747372FE-423B-48D6-A84A-F51B86BD44D4}D:\steamlibrarys\steamapps\common\sourcefilmmaker\game\sfm.exe" = protocol=17 | dir=in | app=d:\steamlibrarys\steamapps\common\sourcefilmmaker\game\sfm.exe |
    "UDP Query User{8156A290-6991-4222-9F8F-59FA3EB8C837}C:\program files (x86)\kingdoms of amalur reckoning\reckoning.exe" = protocol=17 | dir=in | app=c:\program files (x86)\kingdoms of amalur reckoning\reckoning.exe |
    "UDP Query User{B076A848-6143-42ED-9419-821928F3CE5B}C:\users\eric\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\eric\appdata\local\akamai\netsession_win.exe |
    "UDP Query User{B36F9722-7C40-4094-BBEC-EB74F85719DE}C:\program files\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre7\bin\javaw.exe |
    "UDP Query User{BF61E4AB-FA44-42E2-AC4C-DEDC7C019371}C:\program files (x86)\origin games\battlefield bad company 2\bfbc2game.exe" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\battlefield bad company 2\bfbc2game.exe |
    "UDP Query User{DA64799A-BDDD-4208-81BE-78E09E58FA8A}D:\tera\tera-launcher.exe" = protocol=17 | dir=in | app=d:\tera\tera-launcher.exe |
    "UDP Query User{E5805BA6-7028-4886-8A64-A10E42E2B71E}C:\program files (x86)\steam\steamapps\eriklettenberg\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\eriklettenberg\team fortress 2\hl2.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{0225AD21-F3E2-4916-BFF3-65D3F9052582}" = iTunes
    "{03C25EFD-136E-482C-88A0-F083F0C13E65}" = Windows Live Family Safety
    "{0D94F75A-0EA6-4951-B3AF-B145FA9E05C6}" = VMware Workstation
    "{1685AE50-97ED-485B-80F6-145071EE14B0}" = Windows Live Remote Service Resources
    "{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
    "{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
    "{1FB31F44-D4D0-4D76-944A-A1A5D79FD321}" = Windows Live Family Safety
    "{230D1595-57DA-4933-8C4E-375797EBB7E1}" = Atheros Bluetooth Suite (64)
    "{26A24AE4-039D-4CA4-87B4-2F86417013FF}" = Java 7 Update 13 (64-bit)
    "{2C1A6191-9804-4FDC-AB01-6F9183C91A13}" = Windows Live Remote Client Resources
    "{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support
    "{44C0A094-769D-4C5C-B6E9-563AC1220FA3}" = Windows Live Family Safety
    "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
    "{4C2E49C0-9276-4324-841D-774CCCE5DB48}" = Windows Live Remote Client Resources
    "{538B98C3-773F-4F20-9C66-802D104DCBE2}" = Intel® Trusted Connect Service Client
    "{57F2BD1C-14A3-4785-8E48-2075B96EB2DF}" = Windows Live Remote Service Resources
    "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
    "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
    "{699204D1-231D-45FB-98AE-8BC89A32B04F}" = Windows Live Family Safety
    "{6C9365EB-1F9E-4893-9196-3EC77C88D0C5}" = Intel(R) Turbo Boost Technology Monitor 2.5
    "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
    "{7456EDA4-0A8A-47B0-883C-430D88D3FBD5}" = Windows Live Family Safety
    "{7AEC844D-448A-455E-A34E-E1032196BBCD}" = Windows Live Remote Service Resources
    "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
    "{850B8072-2EA7-4EDC-B930-7FE569495E76}" = Windows Live Remote Client Resources
    "{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.03
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
    "{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
    "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}" = ASUS Power4Gear Hybrid
    "{A060182D-CDBE-4AD6-B9B4-860B435D6CBD}" = Windows Live Remote Client Resources
    "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 314.22
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 314.22
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 314.22
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.1031
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.12.12
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
    "{C017D5C7-E2C0-4276-8C8A-0CB6D5914DDD}" = Oracle VM VirtualBox 4.2.8
    "{CEA21F20-DBF4-464C-8B81-28B8508AFDDD}" = Windows Live Family Safety
    "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
    "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
    "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
    "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
    "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
    "{F6CB2C5F-B2C1-4DF1-BF44-39D0DC06FE6F}" = Windows Live Remote Service Resources
    "{FD7DEB7B-8CEA-44E5-AB2D-7C66786C0563}" = Waterfox
    "6af12c54-643b-4752-87d0-8335503010de_is1" = Nexus Mod Manager
    "GameFast_is1" = GameFast.exe
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
    "Rotation Desktop for G Series_is1" = Rotation Desktop for G Series.exe
    "SynTPDeinstKey" = Synaptics Pointing Device Driver
    "UDK-cd1a9e5c-646a-4d8e-a0de-0ff284874409" = My Game Long Name
    "WinRAR archiver" = WinRAR 4.20 (64-bit)

    "{003BFBBD-6C67-419E-A24D-0DCAFC3A5249}" = tools-freebsd
    "{00884F14-05BD-4D8E-90E5-1ABF78948CA4}" = Windows Live Mesh
    "{0170930E-68D6-4E85-88B2-82761CDE1F94}" = DayZ Commander
    "{02454664-23E6-46B3-9CB3-30870AE3645E}" = Crysis®3 MP Open Beta
    "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
    "{04B83666-3A62-452B-85D3-70F8117F2329}_is1" = CamStudio version 2.7
    "{0969AF05-4FF6-4C00-9406-43599238DE0D}" = ASUS Splendid Video Enhancement Technology
    "{09B7C7EB-3140-4B5E-842F-9C79A7137139}" = Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger
    "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
    "{0C4FF2FE-9E75-4DBF-B2DA-11CE1F10C4B5}" = Roxio AACS Certificate
    "{0C975FCC-A06E-4CB6-8F54-A9B52CF37781}" = Windows Liven sähköposti
    "{10186F1A-6A14-43DF-A404-F0105D09BB07}" = Windows Live Mail
    "{1040143F-FEFB-4B90-8E51-E47D40E14C4E}" = Medal of Honor™ Warfighter
    "{110668B7-54C6-47C9-BAC4-1CE77F156AF5}" = Windows Live Mesh
    "{11417707-1F72-4279-95A3-01E0B898BBF5}" = Windows Live Mesh
    "{1146E8F3-4057-4F46-B39C-D18AB4BB1523}_is1" = Deus Ex - Human Revolution version 1.0
    "{133D9D67-D475-4407-AC3C-D558087B2453}" = Windows Live Movie Maker
    "{197597A7-AD33-4898-9D8E-73066818B464}" = tools-netware
    "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
    "{19EA33FB-B34E-40EA-8B8A-61743AEB795A}" = Wireless Console 3
    "{1A72337E-D126-4BAF-AC89-E6122DB71866}" = Windows Liven valokuvavalikoima
    "{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}" = Bing Bar
    "{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
    "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite
    "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
    "{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
    "{220C7F8C-929D-4F71-9DC7-F7A6823B38E4}" = Windows Live UX Platform Language Pack
    "{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel(R) USB 3.0 eXtensible Host Controller Driver
    "{24DF33E0-F924-4D0D-9B96-11F28F0D602D}" = Windows Live UX Platform Language Pack
    "{25CD4B12-8CC5-433E-B723-C9CB41FA8C5A}" = Windows Live Writer
    "{28B9D2D8-4304-483F-AD71-51890A063A74}" = Windows Live Photo Common
    "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
    "{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
    "{2B0E8920-47D0-4F4D-BE03-76397409B837}" = ASUS Fan Filter Checker
    "{2E50E321-4747-4EB5-9ECB-BBC6C3AC0F31}" = Windows Live Writer Resources
    "{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
    "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
    "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
    "{376D59B1-42D9-4FA2-B6CC-E346B6BE14F5}" = ActiveX-kontroll för fjärranslutningar för Windows Live Mesh
    "{39F95B0B-A0B7-4FA7-BB6C-197DA2546468}" = Windows Live Mesh
    "{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
    "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
    "{429DF1A0-3610-4E9E-8ACE-3C8AC1BA8FCA}" = Windows Live Photo Gallery
    "{42DCB650-F003-4535-A5CD-32AD815CD2DD}" = Play withSIX
    "{45C56AA7-ED1B-4800-A97F-EDDF3F3520B1}" = Apple-programstöd
    "{4A04DB63-8F81-4EF4-9D09-61A2057EF419}" = Windows Live Essentials
    "{4B35F00C-E63D-40DC-9839-DF15A33EAC46}" = Grand Theft Auto Vice City
    "{4B744C85-DBB1-4038-B989-4721EB22C582}" = Windows Live Messenger
    "{4CF6F287-5121-483C-A5A2-07BDE19D8B4E}" = Windows Live Meshin etäyhteyksien ActiveX-komponentti
    "{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.1
    "{57220148-3B2B-412A-A2E0-82B9DF423696}" = Windows Live Mesh ActiveX-objekt til fjernforbindelser
    "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
    "{57EA96CA-4648-4CB3-8594-3E1A9E37E86F}" = QuickShare
    "{5C2F5C1B-9732-4F81-8FBF-6711627DC508}" = Windows Live Fotogalleri
    "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
    "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
    "{69CAC24D-B1DC-4B97-A1BE-FE21843108FE}" = Windows Live Writer Resources
    "{6A67578E-095B-4661-88F7-0B199CEC3371}" = Windows Live Messenger
    "{6EF2BE2C-3121-48B7-B7A6-C56046B3A588}" = Windows Live Movie Maker
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{734104DE-C2BF-412F-BB97-FCCE1EC94229}" = Windows Live Writer Resources
    "{749F674B-2674-47E8-879C-5626A06B2A91}" = InstantOn for NB
    "{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
    "{7ADFA72D-2A9F-4DEC-80A5-2FAA27E23F0F}" = Windows Live Photo Common
    "{827D3E4A-0186-48B7-9801-7D1E9DD40C07}" = Windows Live Essentials
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111249233}" = Dream Vacation Solitaire
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}" = Galapago
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}" = Dream Day First Home
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115065740}" = Bubbletown
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115290153}" = Go Go Gourmet Chef of the Year
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115320460}" = Turbo Fiesta
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-116672750}" = World of Goo
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117080787}" = Plants vs Zombies
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-117948443}" = Mahjong Memoirs
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-118716773}" = Deadtime Stories
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-119205603}" = Farm Frenzy 3 - Madagascar
    "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
    "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
    "{885F1BCD-C344-4758-85BD-09640CF449A5}" = Windows Live Photo Gallery
    "{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
    "{8909CFA8-97BF-4077-AC0F-6925243FFE08}" = Windows Liven asennustyökalu
    "{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX
    "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
    "{8CF5D47D-27B7-49D6-A14F-10550B92749D}" = Windows Live UX Platform Language Pack
    "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
    "{8F21291E-0444-4B1D-B9F9-4370A73E346D}" = WinFlash
    "{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
    "{924B4D82-1B97-48EB-8F1E-55C4353C22DB}" = Windows Live Mail
    "{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
    "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
    "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
    "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
    "{A104C276-2B05-41A7-8263-7F7BF6C70D04}" = Alcor Micro USB Card Reader
    "{A2S166A0-F031-4E27-A057-C69733219434}_is1" = TERA
    "{A6C48A9F-694A-4234-B3AA-62590B668927}" = Intel(R) Manageability Engine Firmware Recovery Agent
    "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
    "{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}" = ASUS USB Charger Plus
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
    "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
    "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
    "{AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4}" = tools-solaris
    "{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}" = ATK Package
    "{AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D}" = tools-winPre2k
    "{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
    "{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime
    "{B480904D-F73F-4673-B034-8A5F492C9184}" = Nuance PDF Reader
    "{B48E264C-C8CD-4617-B0BE-46E977BAD694}" = ANNO 2070
    "{BFC47A0B-D487-4DF0-889E-D6D392DF31E0}" = Windows Live Messenger
    "{C03F3D5B-0D83-4F81-A324-32F4E7F1BF6A}" = Roxio CinePlayer
    "{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
    "{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
    "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
    "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
    "{CD442136-9115-4236-9C14-278F6A9DCB3F}" = Windows Live Movie Maker
    "{CD7CB1E6-267A-408F-877D-B532AD2C882E}" = Windows Live Photo Common
    "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
    "{CF671BFE-6BA3-44E7-98C1-500D9C51D947}" = Windows Live Photo Gallery
    "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
    "{D102611A-6466-4101-A51D-51069303AC65}" = tools-linux
    "{D31169F2-CD71-4337-B783-3E53F29F4CAD}" = Windows Live Mail
    "{D39F0676-163E-4595-A917-E28F99BBD4D2}" = ASUS AI Recovery
    "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
    "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
    "{D9577427-2D9D-4580-BDB3-FFDDE06A9554}" = Riven
    "{DA29F644-2420-4448-8128-1331BE588999}" = Windows Live Writer
    "{DB1208F4-B2FE-44E9-BFE6-8824DBD7891B}" = Windows Live Movie Maker
    "{DCAB6BA7-6533-44BF-9235-E5BF33B7431C}" = Windows Live Writer
    "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
    "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
    "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
    "{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
    "{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
    "{E5DD4723-FE0B-436E-A815-DC23CF902A0B}" = Windows Live UX Platform Language Pack
    "{E8524B28-3BBB-4763-AC83-0E83FE31C350}" = Windows Live Writer
    "{E9D98402-21AB-4E9F-BF6B-47AF36EF7E97}" = Windows Live Writer Resources
    "{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera
    "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
    "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    "{F0F9505B-3ACF-4158-9311-D0285136AA00}" = Windows Live Essentials
    "{F6D8331A-FC4F-4EC6-834E-BAE578E5D93F}" = Roxio CinePlayer
    "{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}" = SimCity™
    "{F7CCDC79-57C2-498F-ABFA-AE15D44117B5}" = Aeria Ignite
    "{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}" = ASUS Live Update
    "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
    "{FFD9383C-01D5-4897-A954-43AF599AED30}" = tools-windows
    "{FFFA0584-8E3D-4195-8283-CCA3AD73C746}" = Windows Live Messenger
    "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
    "Aeria Ignite" = Aeria Ignite
    "Aeria Ignite 1.12.2400" = Aeria Ignite
    "AmUStor" = Alcor Micro USB Card Reader
    "ASUS WebStorage" = ASUS WebStorage
    "Asus Vibe2.0" = AsusVibe2.0
    "AsusScr_G75 Series_ENG" = AsusScr_G75 Series_ENG
    "Battlelog Web Plugins" = Battlelog Web Plugins
    "BattlEye for A2" = BattlEye Uninstall
    "BattlEye for OA" = BattlEye for OA Uninstall
    "BioShock Infinite_is1" = BioShock Infinite
    "Cheat Engine 6.2_is1" = Cheat Engine 6.2
    "Desk 365" = Desk 365
    "Dishonored_is1" = Dishonored
    "eSafeSecControl" = eSafe Security Control
    "ESN Sonar-0.70.4" = ESN Sonar
    "Free YouTube Download_is1" = Free YouTube Download version
    "'Full Speed' Internet Booster5.1" = 'Full Speed' Internet Booster
    "Game Park Console" = Game Park Console
    "Google Chrome" = Google Chrome
    "Hitman Absolution_is1" = Hitman Absolution
    "InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite
    "InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
    "InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
    "InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
    "Kingdoms of Amalur Reckoning_is1" = Kingdoms of Amalur Reckoning
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version
    "Microsoft DirectX SDK (June 2010)" = Microsoft DirectX SDK (June 2010)
    "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
    "Office14.Click2Run" = Microsoft Office Click-to-Run 2010
    "Origin" = Origin
    "Perspective" = Perspective 1.0
    "PowerISO" = PowerISO
    "PunkBusterSvc" = PunkBuster Services
    "Scarlet Blade" = Scarlet Blade
    "Steam App 1840" = Source Filmmaker
    "Steam App 209870" = Blacklight: Retribution
    "Steam App 224580" = Arma 2: DayZ Mod
    "Steam App 33910" = Arma 2
    "Steam App 33930" = Arma 2: Operation Arrowhead
    "Steam App 440" = Team Fortress 2
    "The Bridge_is1" = The Bridge
    "The Elder Scrolls V Skyrim Dragonborn (c) Bethes~300CD4A2_is1" = The Elder Scrolls V Skyrim Dragonborn (c) Bethesda Softworks version 1
    "Tombraider_is1" = Tombraider
    "Tricky Truck 2.33" = Tricky Truck 2.33
    "uTorrent" = µTorrent
    "WinLiveSuite" = Windows Live Essentials
    "VLC media player" = VLC media player 2.0.5
    "VMware_Workstation" = VMware Workstation
    "World of Warcraft" = World of Warcraft
    "World of Warcraft Mists of Pandaria ..." = World of Warcraft Mists of Pandaria ...

    ========== HKEY_CURRENT_USER Uninstall List ==========

    "{373B1718-8CC5-4567-8EE2-9033AD08A680}" = ROBLOX Player for Eric
    "Akamai" = Akamai NetSession Interface

    ========== Last 20 Event Log Errors ==========

    [ Application Events ]
    Error - 2013-02-27 17:06:44 | Computer Name = Klettenbergare | Source = Application Error | ID = 1000
    Description = Faulting application name: plugin-container.exe, version:,
    time stamp: 0x50fb1c61 Faulting module name: xul.dll, version:, time
    stamp: 0x50fb1c5a Exception code: 0xc0000005 Fault offset: 0x00000000013b3a51 Faulting
    process id: 0x32bc Faulting application start time: 0x01ce1526d1f8a10c Faulting application
    path: C:\Program Files\Waterfox\plugin-container.exe Faulting module path: C:\Program
    Files\Waterfox\xul.dll Report Id: 9697dd34-8121-11e2-a2ab-94dbc949a772

    Error - 2013-02-28 08:40:48 | Computer Name = Klettenbergare | Source = MsiInstaller | ID = 1013
    Description =

    Error - 2013-03-01 12:08:08 | Computer Name = Klettenbergare | Source = Application Error | ID = 1000
    Description = Faulting application name: swtor.exe, version:, time stamp:
    0x5127b4fe Faulting module name: MemoryMan.dll, version:, time stamp: 0x5127b099
    code: 0xc0000005 Fault offset: 0x00005b73 Faulting process id: 0x4c8c Faulting application
    start time: 0x01ce168e9a87c73a Faulting application path: D:\Star Wars-The Old Republic\swtor\RetailClient\swtor.exe
    module path: D:\Star Wars-The Old Republic\swtor\RetailClient\MemoryMan.dll Report
    Id: 34a504a5-828a-11e2-a23e-005056c00008

    Error - 2013-03-03 13:07:45 | Computer Name = Klettenbergare | Source = CVHSVC | ID = 100
    Description = Information only. (Patch task for {90140011-0066-0409-0000-0000000FF1CE}):
    DownloadLatest Failed:

    Error - 2013-03-05 16:17:51 | Computer Name = Klettenbergare | Source = Application Error | ID = 1000
    Description = Faulting application name: dxhr.exe, version: 1.0.618.8, time stamp:
    0x4e4a9c63 Faulting module name: dxhr.exe, version: 1.0.618.8, time stamp: 0x4e4a9c63
    code: 0xc0000005 Fault offset: 0x0018abb0 Faulting process id: 0x64e4 Faulting application
    start time: 0x01ce19bd86391b98 Faulting application path: C:\Program Files (x86)\Square
    Enix\Deus Ex - Human Revolution\dxhr.exe Faulting module path: C:\Program Files
    (x86)\Square Enix\Deus Ex - Human Revolution\dxhr.exe Report Id: c0eb9505-85d1-11e2-a23e-005056c00008

    Error - 2013-03-08 15:02:09 | Computer Name = Klettenbergare | Source = Application Error | ID = 1000
    Description = Faulting application name: hl2.exe, version:, time stamp:
    0x51266142 Faulting module name: MMDevAPI.DLL, version: 6.1.7601.17514, time stamp:
    0x4ce7b892 Exception code: 0xc0000005 Fault offset: 0x00018d99 Faulting process id:
    0x9efc Faulting application start time: 0x01ce1c14dfc39d13 Faulting application path:
    c:\program files (x86)\steam\steamapps\supermannduden\team fortress 2\hl2.exe Faulting
    module path: C:\Windows\system32\MMDevAPI.DLL Report Id: acd3726e-8822-11e2-a23e-005056c00008

    Error - 2013-03-08 17:04:52 | Computer Name = Klettenbergare | Source = Application Error | ID = 1000
    Description = Faulting application name: TombRaider.exe, version: 1.0.716.5, time
    stamp: 0x5131eb70 Faulting module name: d3d11.dll, version: 6.2.9200.16492, time
    stamp: 0x50f31443 Exception code: 0xc0000005 Fault offset: 0x0008eb9e Faulting process
    id: 0x9d88 Faulting application start time: 0x01ce1c333a0e8137 Faulting application
    path: D:\Tombraider\TombRaider.exe Faulting module path: C:\Windows\system32\d3d11.dll
    Id: d1889462-8833-11e2-a23e-005056c00008

    Error - 2013-03-09 04:50:41 | Computer Name = Klettenbergare | Source = Application Error | ID = 1000
    Description = Faulting application name: plugin-container.exe, version:,
    time stamp: 0x50fb1c61 Faulting module name: nvd3dumx.dll, version:,
    time stamp: 0x4f2305ec Exception code: 0xc0000005 Fault offset: 0x0000000000984440
    process id: 0x1be8 Faulting application start time: 0x01ce15a78e921412 Faulting application
    path: C:\Program Files\Waterfox\plugin-container.exe Faulting module path: C:\Windows\system32\nvd3dumx.dll
    Id: 6b829c93-8896-11e2-a23e-005056c00008

    Error - 2013-03-09 09:15:44 | Computer Name = Klettenbergare | Source = Application Error | ID = 1000
    Description = Faulting application name: plugin-container.exe, version:,
    time stamp: 0x50fb1c61 Faulting module name: NPSWF64_11_6_602_171.dll, version:
    11.6.602.171, time stamp: 0x511ee5bd Exception code: 0xc0000005 Fault offset: 0x00000000002c2b54
    process id: 0xa564 Faulting application start time: 0x01ce1ca362b79df3 Faulting application
    path: C:\Program Files\Waterfox\plugin-container.exe Faulting module path: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_171.dll
    Id: 725ba97b-88bb-11e2-a23e-005056c00008

    Error - 2013-03-09 09:16:15 | Computer Name = Klettenbergare | Source = Application Error | ID = 1000
    Description = Faulting application name: plugin-container.exe, version:,
    time stamp: 0x50fb1c61 Faulting module name: NPSWF64_11_6_602_171.dll, version:
    11.6.602.171, time stamp: 0x511ee5bd Exception code: 0xc0000005 Fault offset: 0x00000000002c2b54
    process id: 0x5bac Faulting application start time: 0x01ce1cc8407f10c9 Faulting application
    path: C:\Program Files\Waterfox\plugin-container.exe Faulting module path: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_171.dll
    Id: 84c7f73a-88bb-11e2-a23e-005056c00008

    [ Media Center Events ]
    Error - 2013-03-04 00:43:50 | Computer Name = Klettenbergare | Source = MCUpdate | ID = 0
    Description = 05:43:49 - Error connecting to the internet. 05:43:50 - Unable
    to contact server..

    Error - 2013-03-04 00:43:58 | Computer Name = Klettenbergare | Source = MCUpdate | ID = 0
    Description = 05:43:55 - Error connecting to the internet. 05:43:55 - Unable
    to contact server..

    Error - 2013-03-04 01:44:05 | Computer Name = Klettenbergare | Source = MCUpdate | ID = 0
    Description = 06:44:05 - Error connecting to the internet. 06:44:05 - Unable
    to contact server..

    Error - 2013-03-04 01:44:11 | Computer Name = Klettenbergare | Source = MCUpdate | ID = 0
    Description = 06:44:10 - Error connecting to the internet. 06:44:10 - Unable
    to contact server..

    Error - 2013-03-04 02:44:18 | Computer Name = Klettenbergare | Source = MCUpdate | ID = 0
    Description = 07:44:18 - Error connecting to the internet. 07:44:18 - Unable
    to contact server..

    Error - 2013-03-04 02:44:24 | Computer Name = Klettenbergare | Source = MCUpdate | ID = 0
    Description = 07:44:23 - Error connecting to the internet. 07:44:23 - Unable
    to contact server..

    Error - 2013-03-04 03:44:31 | Computer Name = Klettenbergare | Source = MCUpdate | ID = 0
    Description = 08:44:31 - Error connecting to the internet. 08:44:31 - Unable
    to contact server..

    Error - 2013-03-04 03:44:37 | Computer Name = Klettenbergare | Source = MCUpdate | ID = 0
    Description = 08:44:36 - Error connecting to the internet. 08:44:36 - Unable
    to contact server..

    [ System Events ]
    Error - 2013-03-28 22:52:30 | Computer Name = Klettenbergare | Source = volsnap | ID = 393252
    Description = The shadow copies of volume C: were aborted because the shadow copy
    storage could not grow due to a user imposed limit.

    Error - 2013-03-28 23:02:28 | Computer Name = Klettenbergare | Source = volsnap | ID = 393252
    Description = The shadow copies of volume C: were aborted because the shadow copy
    storage could not grow due to a user imposed limit.

    Error - 2013-03-29 04:54:58 | Computer Name = Klettenbergare | Source = Service Control Manager | ID = 7009
    Description = A timeout was reached (30000 milliseconds) while waiting for the Steam
    Client Service service to connect.

    Error - 2013-03-29 04:54:58 | Computer Name = Klettenbergare | Source = Service Control Manager | ID = 7000
    Description = The Steam Client Service service failed to start due to the following
    error: %%1053

    Error - 2013-03-29 17:06:29 | Computer Name = Klettenbergare | Source = iaStor | ID = 262153
    Description = The device, \Device\Ide\iaStor0, did not respond within the timeout

    Error - 2013-03-29 17:21:53 | Computer Name = Klettenbergare | Source = volsnap | ID = 393252
    Description = The shadow copies of volume C: were aborted because the shadow copy
    storage could not grow due to a user imposed limit.

    Error - 2013-03-31 11:56:38 | Computer Name = Klettenbergare | Source = EventLog | ID = 6008
    Description = The previous system shutdown at 17:55:02 on ?2013-?03-?31 was unexpected.

    Error - 2013-04-01 06:48:30 | Computer Name = Klettenbergare | Source = volsnap | ID = 393252
    Description = The shadow copies of volume C: were aborted because the shadow copy
    storage could not grow due to a user imposed limit.

    Error - 2013-04-02 03:45:37 | Computer Name = Klettenbergare | Source = Service Control Manager | ID = 7009
    Description = A timeout was reached (30000 milliseconds) while waiting for the Steam
    Client Service service to connect.

    Error - 2013-04-02 03:45:37 | Computer Name = Klettenbergare | Source = Service Control Manager | ID = 7000
    Description = The Steam Client Service service failed to start due to the following
    error: %%1053

    < End of report >
  7. etavares

    etavares Malware Removal Specialist - Moderator

    Aug 6, 2011
    USA (GMT -5)
    Hello, PickleCommander.

    P2P Warning and Request
    The log shows that you have been using so called peer-to-peer or file-sharing programmes (in your case uTorrent). These programmes allow to share files between users as the name(s) suggest. In today's world the cyber crime has come a long way and any means is used to infect personal computers to make use of their stored data or machine power for further propagation of their malware files. A popular means is the use of file-sharing tools as a tremendous amount of prospective victims can be reached through it.

    It is therefore possible to be infected by downloading manipulated files via peer-to-peer tools and thus suggested to be used with intense care. I recommend that you uninstall this program. That is optional, however. If you decide to not uninstall, please refrain from using it until I let you know your computer is clean.

    Step 1

    Please ZIP up C:\Users\Eric\Desktop\MBR.dat and attach in your reply.

    Step 2

    Next, please download ComboFix from one of these locations:
    * IMPORTANT !!! Save ComboFix.exe to your Desktop as etavaresCF.exe
    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
    • Double click on etavaresCF.exe & follow the prompts.
    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


    Click on Yes, to continue scanning for malware.

    When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply, along with any symptoms that are present after it runs.

    Note: After running Combofix, you may receive an error about "illegal operation on a registry key that has been marked for deletion." If you receive this error, please reboot and it should disappear.

  8. PickleCommander

    PickleCommander Foul Mouthed Idiot-Banned

    Apr 4, 2013
    Operating System:
    Windows 7
    The reason why i dont post anything is because i did not make this thread to remove malware. If I would be concerned about that, I would make another thread. I've had not a single problem with any viruses on this pc in about a year. My biggest concern is the flippin' reconnection problems I have every second, making me not being able to game online or watch videos online and poorly even see any pictures, actually the only thing I can do with the internet now is to just browse through the internet, which is boring as That is the reason why I wont anymore be active on this post nor this website.
    EDIT Remove bad language DSTM
  9. DSTM (Dougie)

    DSTM (Dougie) Registered Members

    May 3, 2009
    Operating System:
    Windows 7
    For your information it is normal practice to first check your OS for possible Malware as a process of elimination with issues such as yours, PickelCommander.

    This thread is now closed.
  10. BeeCeeBee


    Apr 20, 2009
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    We will try to suffer through the loss!
Thread Status:
Not open for further replies.

Share This Page