Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

BSOD Crash - Unknown cause [Solved]


  • This topic is locked This topic is locked

#61
GhostLoad

GhostLoad

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 419 posts
Extras.txt
 
OTL Extras logfile created on: 6/24/2014 2:01:48 AM - Run 4
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Miz\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17126)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
15.97 Gb Total Physical Memory | 11.45 Gb Available Physical Memory | 71.69% Memory free
31.93 Gb Paging File | 27.20 Gb Available in Paging File | 85.18% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 416.35 Gb Free Space | 44.70% Space Free | Partition Type: NTFS
Drive D: | 100.00 Mb Total Space | 61.86 Mb Free Space | 61.86% Space Free | Partition Type: NTFS
Drive F: | 931.41 Gb Total Space | 430.17 Gb Free Space | 46.18% Space Free | Partition Type: NTFS
Drive L: | 3.73 Gb Total Space | 2.41 Gb Free Space | 64.79% Space Free | Partition Type: FAT32
Drive M: | 1863.01 Gb Total Space | 1160.75 Gb Free Space | 62.31% Space Free | Partition Type: NTFS
 
Computer Name: MIZ-PC | User Name: Miz | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
 
[HKEY_USERS\S-1-5-21-1038818363-2529734610-2198295289-1000\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS6\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [Bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS6\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{081E36BE-8F65-4911-8C46-F58E4132C396}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{0C7616BC-D707-4AF6-B628-A9A2383EB962}" = lport=7935 | protocol=6 | dir=in | name=adobe flash builder 4.6 | 
"{0DC168FC-F247-44D8-B229-D1A1334A625B}" = lport=138 | protocol=17 | dir=in | app=system | 
"{0DF35411-DD9B-4924-8BA3-A7E8C38044F4}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | 
"{122285EE-FB8E-494E-8B6F-2D97B24E26C0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{173F801C-B36B-4405-8DE5-FDFDEA4E64B5}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | 
"{26F44EEA-3329-45D2-94F0-C980B6C67D9D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{2B90F1C7-DC0D-4127-8519-D418AA03D54E}" = lport=445 | protocol=6 | dir=in | app=system | 
"{2FA15A1E-20FE-4EA2-A3A2-9116C896F1A1}" = lport=443 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | 
"{3555E9E2-AA8E-4428-8EB5-727316FE4FA5}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | 
"{43D01833-A7AB-4534-84CC-D8BB8697FF62}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{4BE098BB-C11D-4482-AF5F-1B976DD50C5D}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | 
"{51CFD253-42E3-4C7A-A909-AAA171A38460}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{5246CC0F-FD7E-430E-BA9B-2FD36AC1F11F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 | 
"{55A98FD1-CA27-4E00-9F18-559A8DF2907F}" = rport=445 | protocol=6 | dir=out | app=system | 
"{56DC5F74-6662-48EB-9AC8-C149E29C3A31}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{5A6B3CBA-AA7E-4F09-A7AB-F2779055E6BA}" = rport=137 | protocol=17 | dir=out | app=system | 
"{6C019BFB-FDE3-431E-9E17-D4D73CEB4611}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{73B50DB9-991B-4488-AD95-20FD884B79AD}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{81FB5E8F-6BBE-4E35-BF71-DF5CCB3DAEF6}" = rport=139 | protocol=6 | dir=out | app=system | 
"{89A93431-0A00-499C-BAB4-82A8D3F2BC45}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{8E783C85-6A16-4F4F-9BED-1F57DD555106}" = rport=138 | protocol=17 | dir=out | app=system | 
"{8FB2DBD3-A6D0-4026-8647-E899312C9822}" = lport=139 | protocol=6 | dir=in | app=system | 
"{95819754-3877-4325-806F-9B049E37BF5E}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | 
"{9EC7AC6F-6F7C-43A8-9621-944021C57C15}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office15\outlook.exe | 
"{A102FB54-21B9-4B83-AD66-46A76C442787}" = lport=137 | protocol=17 | dir=in | app=system | 
"{A95F2BB5-D8CE-4186-B2CE-15696052706C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{D3CFF354-0F04-4DA6-9918-1ACCDB0F1B3D}" = lport=47984 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | 
"{D77F17AD-25BB-43E5-8597-9403FFB15ABE}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{E00EAEBF-A79A-41C8-B529-6EDDAFA7966A}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{E9A122BA-FA54-4396-AC73-AF17A9ACE0D1}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{F7B31606-62F2-443B-9CF7-042F5711C4E7}" = lport=80 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | 
"{F7D4738A-0D50-4708-9B4D-CF588697D6EE}" = lport=2869 | protocol=6 | dir=in | app=system | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0053BEC8-7933-4CE5-8573-C6338C0FF45C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{006251EE-88A0-4691-860A-635BB7A7A04D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{0177A9A1-7BF5-4A64-BD22-D0B7B51CF1E5}" = protocol=17 | dir=in | app=c:\users\miz\desktop\unreal tournament 2004\system\ut2004.exe | 
"{01D38215-6B58-43E6-8FEF-BC9775A2CCB9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
"{0376EE1B-8472-4C77-9FFA-58692D1EED9E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{054DAD62-0A14-4B40-BA69-78460D820643}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{086CFF10-07C9-451E-9D2C-15B18BF0A139}" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of the storm\support\heroesswitcher.exe | 
"{08CBEC9D-3EB0-4986-B8CD-C56467308C5D}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2006\agent.exe | 
"{0A995A08-9A1E-4AE2-A67A-72AE84634CAF}" = protocol=17 | dir=in | app=c:\users\miz\appdata\roaming\utorrent\utorrent.exe | 
"{0BEF6EF7-19CC-4B9B-8306-34EA4979534A}" = protocol=6 | dir=in | app=c:\program files\autodesk\3ds max 2012\3dsmax.exe | 
"{0BF8DF84-00BA-442A-A204-3B27AE60C71E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{0DAF587A-1B5A-44E2-B33E-CF8DE83707B7}" = protocol=17 | dir=in | app=c:\program files\autodesk\3ds max 2012\3dsmax.exe | 
"{0DBBCA10-ADEF-4536-B3EA-DB9A0ED8AFC9}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe | 
"{0E1015CB-495E-4818-AD16-A643D62431FC}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{0FFA5D4D-1057-41A9-86F4-45BC44CE0CFD}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2717\agent.exe | 
"{104FC6B4-B08E-45ED-95F9-697FD075496F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe | 
"{13F44A95-312D-4E9F-B42C-CC937CE54EEE}" = protocol=17 | dir=in | app=c:\users\miz\appdata\roaming\utorrent\utorrent.exe | 
"{17E03A6F-0C00-47C6-9B82-F55D662429CD}" = dir=in | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\support\bin\win\rosettastoneltdservices.exe | 
"{1A0A9EC4-9123-4D04-978A-18BC596D1175}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{1B0DD3C8-A3FA-4D39-A866-91564638F9C1}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgmfapx.exe | 
"{1B641DD4-2EB6-4431-AF70-A539608E6E9F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{1D7E2853-1464-4D29-9009-4FADDFF9EB20}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{1DCFA1E7-CAC3-4090-A6C3-69AB981B4F7A}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\sniper elite v2 demo\bin\sniperelitev2demo.exe | 
"{20E08312-BC73-4520-98AB-774E7D4D098D}" = protocol=6 | dir=in | app=c:\program files (x86)\asus\ai suite ii\asus mobilink\iphone simulator\pnsvc.exe | 
"{23F2EF7E-BC88-4961-B561-9195A5CDBDF0}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2880\agent.exe | 
"{247B5481-DFFE-41ED-8F3A-54B32D88BD80}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe | 
"{27955226-93FB-468A-B0D9-9E534EF7E3B2}" = protocol=6 | dir=in | app=c:\program files\autodesk\3ds max 2012\mentalimages\satellite\raysat_3dsmax2012_64server.exe | 
"{27A3186F-BF0D-45A4-930F-3147832C42FD}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2787\agent.exe | 
"{29372271-D0CB-4604-B821-44EDBD4DBA18}" = dir=in | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\rosettastoneversion3.exe | 
"{29E56E68-B7B8-44EC-867E-FD2E072A3038}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{2C4C7FDC-6955-434C-94DF-FC6C18D272A2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{2D3CEEDD-62BA-4623-9D09-1EA28603FFF7}" = protocol=6 | dir=in | app=c:\program files\autodesk\3ds max 2012\mentalimages\satellite\raysat_3dsmax2012_64.exe | 
"{2DA47B0E-0B6B-4D5A-B8CE-83EACFED1793}" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of the storm\support\heroesswitcher.exe | 
"{2F0E47EE-0998-493B-8EC2-8907A99317A2}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2880\agent.exe | 
"{309E1B1C-7BC9-4C58-8B3C-C6922818A174}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe | 
"{327AABB1-E19F-4525-9779-8BA9B96011FA}" = protocol=6 | dir=out | app=system | 
"{376427E4-17FD-460F-867F-E3855E7579F9}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe | 
"{38F6BCC8-1121-491D-A877-5D66F2569381}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{3998646F-9435-42C9-B584-0EC59205BE59}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe | 
"{3A69E04D-DC90-48D4-B6F2-A7A66F816337}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2328\agent.exe | 
"{3ADDE2DA-2DCD-4DA5-AEDB-BF4FA3BE3B79}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
"{3E3B8BE5-E380-401C-864B-DB29233C609D}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\quantum conundrum demo\binaries\win32\trygame-win32-shipping.exe | 
"{3F97D615-9C95-42D4-A78B-9FD924EC8A33}" = protocol=17 | dir=in | app=c:\program files (x86)\diablo iii beta\diablo iii.exe | 
"{4062921E-CA2F-4835-A456-7D7AA7BD796E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{4194EB59-FD75-4B76-A78E-E4D0DB963E76}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2816\agent.exe | 
"{4219E071-283B-40A7-96A1-0594F77E059E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{44858E4E-122B-4A28-8AAD-28E826EC8395}" = protocol=17 | dir=in | app=c:\program files (x86)\adobe\adobe flash builder 4.6\flashbuilder.exe | 
"{454E9623-33ED-4B1B-9812-40E1B84A175B}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe | 
"{45532388-24D5-41F2-8739-2A99BBEFF67D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\emeril322\source sdk base 2007\hl2.exe | 
"{46DCECAF-1A3D-4AD0-B5EE-AC3B86B9999C}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe | 
"{48B2A1CF-CE38-4AF2-8459-68AC4BF03B0A}" = protocol=17 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe | 
"{4D26BB43-47EF-462D-93E2-76D6DBE306B8}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dungeon defenders demo\binaries\win32\dungeondefenders.exe | 
"{4D34DC64-89E7-4D67-B35A-9A36181215C8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{50B60DEA-FC27-420D-AEE6-4E7E9B32F39F}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{554130AC-7ED0-4CBA-86FD-C18F2ED8598E}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe | 
"{574E1D53-4F11-40A9-ABFE-44949322063A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{58FFC9B8-5D67-4AC7-B99F-736F82BF8B21}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{592D0E4E-24B6-4C42-8BB5-BAFFEF7F5340}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2737\agent.exe | 
"{5CC9F727-C367-4604-98F9-DBA3915CB27F}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe | 
"{5CE8BA70-251A-47F5-A8AB-AD8D808F3F51}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1225\agent.exe | 
"{5E1D4FC2-2FAB-49A4-BCBF-868610FF1652}" = protocol=6 | dir=in | app=c:\programdata\esafe\egdpsvc.exe | 
"{5FD02183-C88E-4931-BE09-AFC69D116E68}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe | 
"{60758565-D9EA-486E-8154-9DFEE3404C3A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dark souls ii\game\darksoulsii.exe | 
"{634406E4-AF7C-41E1-9809-5E97F2ED0AC8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\chivlauncher.exe | 
"{666F9BBF-BBA5-4C72-A007-17555E79C3C5}" = protocol=1 | dir=in | [email protected],-28543 | 
"{6747F969-45BA-40AF-9B1C-467CDBA0CC58}" = protocol=6 | dir=out | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\support\bin\win\rosettastoneltdservices.exe | 
"{6AC8886F-7253-423C-8E2F-D4FB54B56F5E}" = protocol=6 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe | 
"{6AEB5626-F4FC-424F-9626-CE1E6E10C33D}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2717\agent.exe | 
"{6BFD2D44-AEB1-48E6-8A4C-E1AE7045F123}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe | 
"{6C5381E3-42EF-4E9B-A1B8-104D0FE67FD2}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe | 
"{6C9B8C76-F294-476D-A7F6-5BFBFE59C5D0}" = protocol=6 | dir=in | app=c:\users\miz\appdata\roaming\utorrent\utorrent.exe | 
"{6D2F5DC7-9BDF-4D11-BE9D-583EB0A5E50C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\emeril322\source sdk base 2007\hl2.exe | 
"{6FED3E01-8BAA-4A61-9C8D-D27A5C8530D1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{712EBA2A-870D-4E9E-8577-962B12BB747D}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgmfapx.exe | 
"{715A9FBB-51A5-404F-9AC0-B687896743EF}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2328\agent.exe | 
"{71CA97D3-5DF3-4E97-BEA4-98EA9924D2EA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{727FEA61-1C58-446D-A30C-903B64319751}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2006\agent.exe | 
"{757337B3-4EE0-4686-BFCB-C55E4B32BDA0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{757AC51B-39B9-4143-9B40-78AB4836206A}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2737\agent.exe | 
"{781F2B5D-344C-44A3-AF98-BC1E76862214}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe | 
"{78EC1D50-0480-47AC-A89E-8E1C7B98198E}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | 
"{7B6D6AA3-D807-4599-94F0-F8BC527BE285}" = protocol=17 | dir=in | app=c:\program files (x86)\disney interactive studios\split second\splitsecond.exe | 
"{7BAF8D0D-3F48-4A69-A98F-80A8C3F980FD}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\just cause 2 demo\justcause2.exe | 
"{7BBDE725-035C-44AF-9FF9-7A1870E265E2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{7C047E96-3D9A-4D92-A9AB-D8996FBB4587}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{7D92134B-49E5-4843-B20B-639A46F8DD02}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe | 
"{80C8C56C-CC98-40DB-9A0D-3478BEF2CC09}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\vindictus\en-us\vslauncher.exe | 
"{81660110-96B2-4577-85CD-5F48F3D014E5}" = protocol=6 | dir=in | app=c:\program files (x86)\clockworkmod\tether\win32\node.exe | 
"{83E1E3CD-839D-4FD3-B10E-1F59BE142D53}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | 
"{84152B01-B7FE-494E-9746-8BD97678E472}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.patch.exe | 
"{880592C2-088E-4298-BC71-260AA52AA0EC}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe | 
"{8B3DF3AD-2A27-46B7-B057-AE5266430691}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{8BA771DE-FA05-4610-86A6-4E3354077263}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe | 
"{8C0AA7CD-5B3A-49B8-AA94-9E2618AF02B3}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe | 
"{8C863A28-88BF-4812-B8A0-67AC77521962}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{8C86E2CD-D137-4D10-BD3A-CE6D16018BAD}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | 
"{8DD617A3-3489-426C-A009-3E0E3445B3CA}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{8DF8F4CC-55DE-46F8-BE6B-72A9ABD20D9D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{8E62D213-FCF8-4B80-A47A-9EA4E1E9904F}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\sniper elite v2 demo\bin\sniperelitev2demo.exe | 
"{90433296-8240-4A92-87EA-C5D87F7997EC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{9059411C-C517-4EF5-82DB-762930318154}" = protocol=6 | dir=in | app=c:\users\miz\appdata\roaming\utorrent\utorrent.exe | 
"{996A85F2-D5ED-448F-97F5-11DAC0394D14}" = protocol=58 | dir=in | [email protected],-28545 | 
"{99E5CE12-B750-4227-9D6D-DA05E290F9E7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{9A56C22B-8424-45B8-BB29-0C6BB30068BC}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe | 
"{9B32DF47-9176-473C-A1C4-17B1BE2803E7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{9EC80AB9-92B5-49AA-942D-1AD6CA4D7500}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe | 
"{9EEE7B01-F08A-4E13-958F-D95C5AEF8435}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{A3857D8F-6E77-409F-8DEB-B4C9C32299CB}" = protocol=17 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe | 
"{A4AC4436-55AF-4D07-AF6E-4A32F0D10A0C}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\rusty hearts\clientlauncher.exe | 
"{A5478D7A-F7D3-42F6-942E-C2CB059A877D}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe | 
"{A56F5025-9050-4794-9E29-0E9F91EE1F68}" = protocol=17 | dir=in | app=c:\program files\autodesk\3ds max 2012\mentalimages\satellite\raysat_3dsmax2012_64server.exe | 
"{A5AF96CD-8687-430C-9C6E-2AD4AC179FF9}" = protocol=17 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe | 
"{A62A7403-3451-4C2E-9E0A-4B45B2AC4F16}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\darksouls.exe | 
"{A799B35F-46AE-455E-BC56-FC15464EE420}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe | 
"{A9CFABA8-9ADA-4DE7-9FEF-ABD2AC1E72DB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
"{AC118EB3-3BB3-4113-83A7-33F26656FFD7}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.868\agent.exe | 
"{AC544183-B7FD-46ED-8229-48904B26202A}" = protocol=1 | dir=out | [email protected],-28544 | 
"{AC847EA8-7835-413D-8E5B-2F61E1F8BBFF}" = protocol=6 | dir=in | app=c:\program files (x86)\adobe\adobe flash builder 4.6\flashbuilder.exe | 
"{AD5EED4F-07BC-445E-8432-33453727162A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\darksouls.exe | 
"{AE7A994B-5012-4406-ACB9-F1C1D7CE98AD}" = protocol=6 | dir=in | app=c:\program files (x86)\diablo iii beta\diablo iii.exe | 
"{AE7BE913-08E3-43CC-AC82-EB268DCF1A43}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\supermnc\binaries\win32\supermncgameclient.exe | 
"{AED46DAD-D5E8-4A52-BDBE-39A1F2F43B5E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{B0404FE8-8C3A-4931-8C81-A2E6823D792A}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe | 
"{B1186C7C-B2D7-4539-B499-4EC4C4200378}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\call of duty modern warfare 3\iw5sp.exe | 
"{B193D7EC-0E8D-4D2F-8F6C-5DC002AD6A10}" = protocol=6 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe | 
"{B1DAE976-9850-41CF-B06B-37C228D18BDE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{B56CF880-846C-4A92-9D71-B514AC134820}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\quantum conundrum demo\binaries\win32\trygame-win32-shipping.exe | 
"{B6176B0B-245F-4994-A70C-76C8315FD18B}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe | 
"{B7AD9714-F8D4-46A2-A57E-E36A8B736C7B}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dungeon defenders\binaries\win32\dungeondefenders.exe | 
"{BB747B39-D688-4AAD-9708-BB57BBB8749B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{BC07003C-648D-44DE-9629-D9BD4B48CFFB}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\just cause 2 demo\justcause2.exe | 
"{BD8B36AB-4DDF-49A1-85EE-F1F6CDF48C62}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dungeon defenders\binaries\win32\dungeondefenders.exe | 
"{BECCDC7E-7D24-4225-8B4F-920164F24150}" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\supermnc\binaries\win32\supermncgameclient.exe | 
"{BF3EA2F6-C8ED-453B-8299-D7D8C1EA49CF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{BF596EEB-1C5C-47D9-9506-C18AA42F5FEB}" = protocol=17 | dir=in | app=c:\program files (x86)\clockworkmod\tether\win32\node.exe | 
"{BF728AC4-6025-4C32-AEF6-D2F812306104}" = protocol=17 | dir=in | app=c:\program files\autodesk\3ds max 2012\mentalimages\satellite\raysat_3dsmax2012_64.exe | 
"{BFB9FCE9-FC21-4F6E-A676-0A90BD0729F8}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii public test.exe | 
"{C1334B26-D68C-4220-B889-4F5CDBECC9C2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{C2FAD0F0-7070-4F4B-BEEE-1B0E7CC77AF0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{C3400FBD-217D-4A8E-ADC6-6A6BDA7AD7C7}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe | 
"{C3C55D48-FAF4-456E-B252-5A62BD063F0D}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe | 
"{C4BAA49C-3E70-4FA1-9D8A-889B0E3914BF}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe | 
"{C5326927-DAC1-4E7D-8D1D-79076B704F98}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe | 
"{C63F0EA2-332C-485F-A89E-D8144F758D89}" = protocol=6 | dir=in | app=c:\program files (x86)\hearthstone\hearthstone.exe | 
"{C6C7A632-D314-4793-A801-19C479DB3918}" = protocol=6 | dir=in | app=e:\program files\steam\steam.exe | 
"{C709B784-B78C-4B41-9732-969D44822D8F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2753\agent.exe | 
"{C8B18639-70F6-4502-90DE-17FF7702CF85}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{C948571C-6AAD-4751-B46D-BD0AAADE3766}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | 
"{CAB99DD9-6714-4628-AD95-AD030B488DD2}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1199\agent.exe | 
"{CBA2673C-63F9-4840-9F45-145900B7D6E5}" = protocol=58 | dir=out | [email protected],-28546 | 
"{CBC866F9-70EF-4CB7-9225-0D04D964F74B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the walking dead\walkingdead101.exe | 
"{CBE641BA-AD10-4E51-93D1-1BE73E3967F9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{CD715E1B-F34C-40D4-9686-E0F856833EBF}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe | 
"{CD84B21A-640C-4FE6-9268-25ED99056B58}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\chivlauncher.exe | 
"{CE1DFC46-FFA4-4350-BC34-C97F691A48A8}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dungeon defenders demo\binaries\win32\dungeondefenders.exe | 
"{CF7F3DC7-6B80-4751-BB1E-A8B9E1B7EF82}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1199\agent.exe | 
"{D4322B29-CF1E-4041-A70C-A7DC93AFA3F9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{D484E97F-A8DE-4897-AA75-7AB981E907F6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{D680BA61-9847-42D0-9D88-3C0F0CEAD37D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{D72EEAE5-1ED5-4EB5-9B4E-11ECEF9C103E}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2753\agent.exe | 
"{DA8CEE66-0432-4A37-AE40-3E65E6565471}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{DA9E7F9C-AEEE-4CFA-9196-31EE562D9257}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe | 
"{DDB2C2A2-64B5-4706-BB99-54F05266DDF7}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\vindictus\en-us\vslauncher.exe | 
"{DEBB35C9-AD56-4FEA-8A6A-242FEEF747E3}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe | 
"{E07BA82E-C6FB-4123-84E9-ADE554C36DEE}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
"{E090E0E3-F3A6-4B83-BB37-0666E8AAFC92}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | 
"{E320D59C-265D-46F6-B57A-B410501655E3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the walking dead\walkingdead101.exe | 
"{E4273F89-B01D-41B0-9083-E39E976C47A7}" = protocol=6 | dir=in | app=c:\program files (x86)\disney interactive studios\split second\splitsecond.exe | 
"{E5758AE2-5E9E-40BB-9BEA-7F63B0D2B237}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{E6669DF9-95D8-4802-B330-6568C8A09B2E}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{E670DF43-3451-4560-99FC-3C639FFB3FEC}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.patch.exe | 
"{E77C3614-3799-4091-AE1C-7BB0E4EEBA33}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.868\agent.exe | 
"{E811C164-5DEB-456F-AF14-F73F3F0E0D77}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{E81E1A09-9234-4FB1-B973-BFB9E806E7E4}" = protocol=6 | dir=in | app=c:\users\miz\desktop\unreal tournament 2004\system\ut2004.exe | 
"{E93A634E-AA3E-4DC5-B56E-95AB7E6831A6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{E9872836-CE85-401C-A27C-868A8EF3CB9F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{EAE2D7F9-E857-44F8-9D6B-7F0063A4331F}" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\rusty hearts\clientlauncher.exe | 
"{EB75AA14-8E9F-4BC7-B615-A4E392862271}" = protocol=17 | dir=in | app=e:\program files\steam\steam.exe | 
"{EC1F03B4-E2D9-41C9-BCFC-B5E1204AE5A0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{EDA3497F-C13D-4925-BE35-2294063D2FF1}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2787\agent.exe | 
"{EFAF88AE-FC78-48D5-8B45-ECAC9BED15B0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{F2343FC6-8FB3-4D02-A207-86A04C8641A9}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2816\agent.exe | 
"{F3E8BA9D-CFD2-4419-AD54-68979243A1B6}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | 
"{F70F0D5D-AE1E-41E7-BC3C-6B69D92D2B06}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe | 
"{F745C737-9A23-45A3-8A2C-29B661CC6CBF}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1225\agent.exe | 
"{F773FF2A-5643-491A-B2D9-FAFFDDA28143}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe | 
"{F87CDEE3-7482-4C35-B4DE-0746D428632B}" = protocol=6 | dir=out | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\rosettastoneversion3.exe | 
"{FABE77DE-F67A-43EB-A7AB-D4090ABB7459}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{FB3D1828-6D87-44E5-9621-08CD11E8EFF6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe | 
"{FBBB2AEE-F819-40F5-B3C3-0F2859E009CE}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe | 
"{FC6DBE52-A0C3-46DC-8BB1-A8236F23221B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dark souls ii\game\darksoulsii.exe | 
"{FF6A3693-D71B-4000-8561-DB58EC621188}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"TCP Query User{04E7E2C6-DAE5-48BF-B75F-BC76813A31DB}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe | 
"TCP Query User{09B52BB2-98EE-4A47-B543-FBBF0C4A4D7E}C:\programdata\battle.net\agent\agent.976\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe | 
"TCP Query User{0D2DC01D-2728-4F2D-8D70-0AE3F957B959}C:\program files (x86)\battlefield 4\bf4.exe" = protocol=6 | dir=in | app=c:\program files (x86)\battlefield 4\bf4.exe | 
"TCP Query User{0F5EF933-2131-46AF-9A9A-10123BFCDB9B}C:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\cdw\binaries\win64\cdw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\cdw\binaries\win64\cdw.exe | 
"TCP Query User{10BDFA3E-B57C-4B4B-899D-413CFFEC623E}C:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe | 
"TCP Query User{1447537C-EE84-487F-A273-DD249BB31C0A}C:\program files (x86)\croteam\serious sam\bin\serioussam.exe" = protocol=6 | dir=in | app=c:\program files (x86)\croteam\serious sam\bin\serioussam.exe | 
"TCP Query User{147F0591-0986-4017-9630-B5FF2DB9397C}C:\program files (x86)\secret identity studios\marvel heroes beta\unrealengine3\binaries\win32\marvelgame.exe" = protocol=6 | dir=in | app=c:\program files (x86)\secret identity studios\marvel heroes beta\unrealengine3\binaries\win32\marvelgame.exe | 
"TCP Query User{1C526E51-E785-4DB9-B4BE-E5781339F0F1}C:\program files (x86)\altitude\altitude.exe" = protocol=6 | dir=in | app=c:\program files (x86)\altitude\altitude.exe | 
"TCP Query User{1D9BD7BF-78EA-4676-847B-32DA37834972}C:\program files (x86)\starcraft ii\versions\base23260\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base23260\sc2.exe | 
"TCP Query User{241B23A9-849C-42A8-828D-FD43DFE1271F}C:\gog games\fallout tactics\bos.exe" = protocol=6 | dir=in | app=c:\gog games\fallout tactics\bos.exe | 
"TCP Query User{2D63B04F-A05A-4D57-A78A-11C7D5A9CE24}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe | 
"TCP Query User{2DFFB351-9D67-4EB9-AE91-57232297DA0B}C:\program files (x86)\armagetron advanced\armagetronad.exe" = protocol=6 | dir=in | app=c:\program files (x86)\armagetron advanced\armagetronad.exe | 
"TCP Query User{3831E979-EA59-47CA-B950-D74606C3042C}C:\program files (x86)\bv2 proclient\bv2p.exe" = protocol=6 | dir=in | app=c:\program files (x86)\bv2 proclient\bv2p.exe | 
"TCP Query User{3C67BA93-4234-4CAA-BAB2-44E9FEA9068A}C:\users\miz\desktop\neverwinter_nw.1.20130416a.6.exe" = protocol=6 | dir=in | app=c:\users\miz\desktop\neverwinter_nw.1.20130416a.6.exe | 
"TCP Query User{429F4417-B683-4274-9A2D-0EF79E77C477}C:\program files (x86)\remote control server\remote control server.exe" = protocol=6 | dir=in | app=c:\program files (x86)\remote control server\remote control server.exe | 
"TCP Query User{47D7A89B-28EC-491E-AE78-589065251688}C:\program files (x86)\fox\aliens versus predator 2 - primal hunt\lithtech.exe" = protocol=6 | dir=in | app=c:\program files (x86)\fox\aliens versus predator 2 - primal hunt\lithtech.exe | 
"TCP Query User{4B4D00D8-9BA7-492C-B4D1-B682FB5CA9D0}C:\program files (x86)\avid\pro tools\protools.exe" = protocol=6 | dir=in | app=c:\program files (x86)\avid\pro tools\protools.exe | 
"TCP Query User{55205174-798F-457F-B25D-DACD6043EC72}E:\program files\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe | 
"TCP Query User{57372A21-203E-40AE-8664-E25D58FCE371}C:\users\miz\appdata\local\temp\iesearchprovider.exe" = protocol=6 | dir=in | app=c:\users\miz\appdata\local\temp\iesearchprovider.exe | 
"TCP Query User{6185B5F6-838A-4119-97A8-2CCC07241C5F}C:\soldat\soldat.exe" = protocol=6 | dir=in | app=c:\soldat\soldat.exe | 
"TCP Query User{64386C51-7D54-418C-A1A3-7D057D944C3B}C:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe | 
"TCP Query User{76D4D8EA-1E5F-4C53-B0A8-21CBFE025E6C}C:\program files (x86)\phoenix viewer\slvoice.exe" = protocol=6 | dir=in | app=c:\program files (x86)\phoenix viewer\slvoice.exe | 
"TCP Query User{775275A9-75C1-409F-86D0-C0290565001D}C:\program files (x86)\starcraft ii\support\blizzarddownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\support\blizzarddownloader.exe | 
"TCP Query User{7D3040DE-16C4-4E3D-8D9D-3B91A09BB8DB}C:\program files (x86)\starcraft ii\versions\base21029\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base21029\sc2.exe | 
"TCP Query User{823632E5-4AA0-41E7-B50D-E07655FFFBE9}C:\program files (x86)\meteorentertainment\hawken\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe" = protocol=6 | dir=in | app=c:\program files (x86)\meteorentertainment\hawken\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe | 
"TCP Query User{888433E5-A44D-419B-96FD-64BFA9948FAA}C:\program files (x86)\dishonored\binaries\win32\dishonored.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dishonored\binaries\win32\dishonored.exe | 
"TCP Query User{89CF3C3E-CEC9-4D56-9F5F-86366D47AB55}C:\program files (x86)\starcraft ii\versions\base24944\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base24944\sc2.exe | 
"TCP Query User{8A7A3AF8-7682-4BEF-8D7E-454A92D0C98E}E:\program files\steam\steamapps\common\dungeon defenders demo\binaries\win32\dundefgame.exe" = protocol=6 | dir=in | app=e:\program files\steam\steamapps\common\dungeon defenders demo\binaries\win32\dundefgame.exe | 
"TCP Query User{9A2FE03C-4C45-4F20-901C-410438CF9BA7}C:\users\miz\desktop\lan games\soldat\soldat.exe" = protocol=6 | dir=in | app=c:\users\miz\desktop\lan games\soldat\soldat.exe | 
"TCP Query User{A277530F-6063-492F-BF6B-9DFDB67FB478}C:\users\miz\desktop\lan games\haloce\haloceded.exe" = protocol=6 | dir=in | app=c:\users\miz\desktop\lan games\haloce\haloceded.exe | 
"TCP Query User{A6876491-BDC8-42C7-B915-D3504BB6CF7D}C:\users\miz\desktop\diablo-iii-8370-enus-installer-downloader.exe" = protocol=6 | dir=in | app=c:\users\miz\desktop\diablo-iii-8370-enus-installer-downloader.exe | 
"TCP Query User{A7F4189F-8F00-4942-A7D6-556EA408F37F}C:\program files (x86)\dmc devil may cry\binaries\win32\dmc-devilmaycry.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dmc devil may cry\binaries\win32\dmc-devilmaycry.exe | 
"TCP Query User{AC43B407-30A6-4206-A102-9205B2E7BC3C}C:\users\miz\desktop\iaa_sriv\saintsrowiv.exe" = protocol=6 | dir=in | app=c:\users\miz\desktop\iaa_sriv\saintsrowiv.exe | 
"TCP Query User{B3B0E54E-0767-40D0-9787-FF72B2EBFF82}C:\program files (x86)\heroes of the storm\versions\base30509\heroesofthestorm.exe" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base30509\heroesofthestorm.exe | 
"TCP Query User{B431CCE6-2162-45BC-8500-E2D18DDA045C}C:\users\public\games\cryptic studios\neverwinter\live\gameclient.exe" = protocol=6 | dir=in | app=c:\users\public\games\cryptic studios\neverwinter\live\gameclient.exe | 
"TCP Query User{BBAB2E35-E498-4714-8993-BC0FD337F25A}C:\users\miz\desktop\lan games\chivalry medieval warfare - content update 1\binaries\win32\udk.exe" = protocol=6 | dir=in | app=c:\users\miz\desktop\lan games\chivalry medieval warfare - content update 1\binaries\win32\udk.exe | 
"TCP Query User{BD4E442A-B5FD-4B64-8A3F-8E12FA424C9E}C:\users\miz\desktop\enmstoffcppls1364bnewvl\kmsmicro-wo-en\kmsmicro-wo-en\qemu\qemu.exe" = protocol=6 | dir=in | app=c:\users\miz\desktop\enmstoffcppls1364bnewvl\kmsmicro-wo-en\kmsmicro-wo-en\qemu\qemu.exe | 
"TCP Query User{C2988DBC-B46B-4AB0-BEDA-CE959D625D7B}C:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\binaries\win64\cmw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\binaries\win64\cmw.exe | 
"TCP Query User{C7C8872D-049D-48A6-AA3F-A6148846CE2A}C:\users\miz\desktop\lan games\haloce\haloce.exe" = protocol=6 | dir=in | app=c:\users\miz\desktop\lan games\haloce\haloce.exe | 
"TCP Query User{CA2D2335-0586-4D0B-86FD-F99BE30B71FC}C:\program files (x86)\infinitecrisis\infinitecrisis.exe" = protocol=6 | dir=in | app=c:\program files (x86)\infinitecrisis\infinitecrisis.exe | 
"TCP Query User{CC5E3709-BAC3-4A72-B722-8A7C6A97908A}C:\users\miz\documents\lan games\soldat\soldat.exe" = protocol=6 | dir=in | app=c:\users\miz\documents\lan games\soldat\soldat.exe | 
"TCP Query User{CEDB4D54-D87E-4478-A255-435B15BE8D97}C:\program files\starcraft\starcraft.exe" = protocol=6 | dir=in | app=c:\program files\starcraft\starcraft.exe | 
"TCP Query User{D8BF3FA5-5139-4640-B2DE-E4C6BBD6F0D3}C:\program files (x86)\meteorentertainment\hawkenadvancebattalion\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe" = protocol=6 | dir=in | app=c:\program files (x86)\meteorentertainment\hawkenadvancebattalion\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe | 
"TCP Query User{D9C0FE61-9F71-42D7-A018-171AE6A7313C}C:\program files (x86)\firestorm-release\slvoice.exe" = protocol=6 | dir=in | app=c:\program files (x86)\firestorm-release\slvoice.exe | 
"TCP Query User{DD4390F8-7C55-48E5-929F-6AD5E99EDD33}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe | 
"TCP Query User{DD4C9BFA-D311-4AEC-A181-72C7D53A2756}C:\program files (x86)\heroes of the storm\versions\base30414\heroesofthestorm.exe" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base30414\heroesofthestorm.exe | 
"TCP Query User{E1E91321-347C-427D-8A01-72F2C6D1C0DC}C:\users\miz\desktop\saints row iv\saintsrowiv.exe" = protocol=6 | dir=in | app=c:\users\miz\desktop\saints row iv\saintsrowiv.exe | 
"TCP Query User{E4533606-1C45-4DD2-A805-8F82F5DD6DEE}C:\programdata\battle.net\agent\agent.1040\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe | 
"TCP Query User{E63DE831-BD65-4B62-9783-DF0885F3207C}C:\program files (x86)\xfire\xfire.exe" = protocol=6 | dir=in | app=c:\program files (x86)\xfire\xfire.exe | 
"TCP Query User{EDE72AEC-9BB8-455A-BD6D-37BB5D852C7B}C:\program files (x86)\heroes of the storm tech alpha\versions\base30027\play.exe" = protocol=6 | dir=in | app=c:\program files (x86)\heroes of the storm tech alpha\versions\base30027\play.exe | 
"TCP Query User{EE9967A7-ED39-4007-92CA-1E7C38E4A2C9}C:\program files (x86)\battlefield 4\bf4_x86.exe" = protocol=6 | dir=in | app=c:\program files (x86)\battlefield 4\bf4_x86.exe | 
"TCP Query User{F0484A5C-5F89-4599-8883-29F40490265A}C:\program files (x86)\google\chrome\application\chrome.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | 
"TCP Query User{F3CCA270-C7F3-4801-8462-31EB6CF75469}C:\programdata\battle.net\agent\agent.998\agent.exe" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe | 
"TCP Query User{F872AC90-55BA-422C-89AE-22220A71B64F}C:\users\miz\desktop\starcraft_2_na_en-us.exe" = protocol=6 | dir=in | app=c:\users\miz\desktop\starcraft_2_na_en-us.exe | 
"TCP Query User{FA869A02-513B-4716-B55D-92019423F41D}C:\users\miz\desktop\lan games\the ship\ship.exe" = protocol=6 | dir=in | app=c:\users\miz\desktop\lan games\the ship\ship.exe | 
"TCP Query User{FEDA5664-0197-4CA2-8DE0-328CE4BA004A}C:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe" = protocol=6 | dir=in | app=c:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe | 
"TCP Query User{FFC4C856-462C-4421-BB47-DE67D7E312DF}C:\program files (x86)\unified remote\remoteserver.exe" = protocol=6 | dir=in | app=c:\program files (x86)\unified remote\remoteserver.exe | 
"UDP Query User{0006B673-259A-45F3-A8F1-06B965576507}C:\gog games\fallout tactics\bos.exe" = protocol=17 | dir=in | app=c:\gog games\fallout tactics\bos.exe | 
"UDP Query User{066964D4-DA3D-4A40-A5CC-231FA4C8AAFD}C:\program files (x86)\meteorentertainment\hawkenadvancebattalion\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe" = protocol=17 | dir=in | app=c:\program files (x86)\meteorentertainment\hawkenadvancebattalion\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe | 
"UDP Query User{0949020B-894B-4785-968E-64739D0C3F23}C:\users\miz\documents\lan games\soldat\soldat.exe" = protocol=17 | dir=in | app=c:\users\miz\documents\lan games\soldat\soldat.exe | 
"UDP Query User{0DD27ADE-5168-4C73-81AC-082A48C3F33B}C:\program files (x86)\avid\pro tools\protools.exe" = protocol=17 | dir=in | app=c:\program files (x86)\avid\pro tools\protools.exe | 
"UDP Query User{0EC0A12C-856E-4054-90CC-E51B571CFC94}C:\users\miz\appdata\local\temp\iesearchprovider.exe" = protocol=17 | dir=in | app=c:\users\miz\appdata\local\temp\iesearchprovider.exe | 
"UDP Query User{1191AF98-0223-4978-B247-47CFA209DCE9}C:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe" = protocol=17 | dir=in | app=c:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe | 
"UDP Query User{1567A5B1-F6A2-4F99-84B2-9945048293D8}C:\program files (x86)\armagetron advanced\armagetronad.exe" = protocol=17 | dir=in | app=c:\program files (x86)\armagetron advanced\armagetronad.exe | 
"UDP Query User{159D1795-2AD0-43A3-B9FB-3E1C0BAE5504}C:\program files (x86)\altitude\altitude.exe" = protocol=17 | dir=in | app=c:\program files (x86)\altitude\altitude.exe | 
"UDP Query User{17E6801A-C3D3-4CBF-ACF4-98D3B36278AC}C:\program files (x86)\firestorm-release\slvoice.exe" = protocol=17 | dir=in | app=c:\program files (x86)\firestorm-release\slvoice.exe | 
"UDP Query User{18B86BA9-FDAA-42C5-B634-BA88DABCFBF8}C:\users\miz\desktop\diablo-iii-8370-enus-installer-downloader.exe" = protocol=17 | dir=in | app=c:\users\miz\desktop\diablo-iii-8370-enus-installer-downloader.exe | 
"UDP Query User{1CE36BB9-BCCB-4CA5-A724-85469228A2AB}C:\program files (x86)\croteam\serious sam\bin\serioussam.exe" = protocol=17 | dir=in | app=c:\program files (x86)\croteam\serious sam\bin\serioussam.exe | 
"UDP Query User{229B2E55-C830-4874-9BF1-088C4BFFB493}E:\program files\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe | 
"UDP Query User{254A0BBA-00E7-4BB2-81BB-9324B861E660}C:\program files (x86)\starcraft ii\support\blizzarddownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\support\blizzarddownloader.exe | 
"UDP Query User{2FCDAB73-46E4-4A20-9B19-54BBF8E9A2D2}C:\users\miz\desktop\neverwinter_nw.1.20130416a.6.exe" = protocol=17 | dir=in | app=c:\users\miz\desktop\neverwinter_nw.1.20130416a.6.exe | 
"UDP Query User{313ABF18-10D3-4E91-ADB5-27ECB200C425}C:\users\miz\desktop\iaa_sriv\saintsrowiv.exe" = protocol=17 | dir=in | app=c:\users\miz\desktop\iaa_sriv\saintsrowiv.exe | 
"UDP Query User{3166C769-2192-47EF-A248-254902BD2840}C:\program files (x86)\unified remote\remoteserver.exe" = protocol=17 | dir=in | app=c:\program files (x86)\unified remote\remoteserver.exe | 
"UDP Query User{33436015-9F2E-4FA4-BF88-7050769D7835}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe | 
"UDP Query User{33D8C2F8-D053-48BA-9500-27C8E6EFE590}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.2.1.2756-enus-tools-downloader.exe | 
"UDP Query User{3799A028-BCCF-4713-90BD-6359A2382555}C:\users\miz\desktop\enmstoffcppls1364bnewvl\kmsmicro-wo-en\kmsmicro-wo-en\qemu\qemu.exe" = protocol=17 | dir=in | app=c:\users\miz\desktop\enmstoffcppls1364bnewvl\kmsmicro-wo-en\kmsmicro-wo-en\qemu\qemu.exe | 
"UDP Query User{38B6B8FD-C675-4944-95BC-3FB2EFDEE7E5}C:\programdata\battle.net\agent\agent.976\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe | 
"UDP Query User{439882EF-DAA7-4041-86A5-B9906FAFE5A8}C:\programdata\battle.net\agent\agent.998\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe | 
"UDP Query User{4FE8E6CB-8A51-496E-A02E-94B2D171DA85}C:\program files (x86)\xfire\xfire.exe" = protocol=17 | dir=in | app=c:\program files (x86)\xfire\xfire.exe | 
"UDP Query User{4FF921A3-54A8-4F47-8175-79A22DF3773C}C:\users\miz\desktop\lan games\soldat\soldat.exe" = protocol=17 | dir=in | app=c:\users\miz\desktop\lan games\soldat\soldat.exe | 
"UDP Query User{508BBB5D-A9E9-461D-B89F-3887EC4801C4}C:\users\miz\desktop\lan games\haloce\haloceded.exe" = protocol=17 | dir=in | app=c:\users\miz\desktop\lan games\haloce\haloceded.exe | 
"UDP Query User{53483A49-36B9-4C73-BA9B-9CA43081D04F}C:\users\miz\desktop\saints row iv\saintsrowiv.exe" = protocol=17 | dir=in | app=c:\users\miz\desktop\saints row iv\saintsrowiv.exe | 
"UDP Query User{5737F56B-AED5-4BD7-BED0-1A5B222471E7}C:\program files (x86)\starcraft ii\versions\base23260\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base23260\sc2.exe | 
"UDP Query User{5AB33D29-4DA8-4E7A-A258-CA724AC2493B}C:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\binaries\win64\cmw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\binaries\win64\cmw.exe | 
"UDP Query User{613C4878-CB93-410E-AAF4-F3BF4B10ADCB}C:\program files (x86)\remote control server\remote control server.exe" = protocol=17 | dir=in | app=c:\program files (x86)\remote control server\remote control server.exe | 
"UDP Query User{62482C80-9ABE-44D1-91B2-6C931E031506}C:\users\miz\desktop\lan games\haloce\haloce.exe" = protocol=17 | dir=in | app=c:\users\miz\desktop\lan games\haloce\haloce.exe | 
"UDP Query User{634B1773-47FB-43AA-B88C-7F3DE59B864B}C:\program files (x86)\heroes of the storm\versions\base30509\heroesofthestorm.exe" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base30509\heroesofthestorm.exe | 
"UDP Query User{64422455-3D72-41ED-94D3-8E27F1AB699E}C:\users\miz\desktop\lan games\chivalry medieval warfare - content update 1\binaries\win32\udk.exe" = protocol=17 | dir=in | app=c:\users\miz\desktop\lan games\chivalry medieval warfare - content update 1\binaries\win32\udk.exe | 
"UDP Query User{6914ACB7-3B5F-4098-80FF-ABB96FD6E776}C:\program files (x86)\dishonored\binaries\win32\dishonored.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dishonored\binaries\win32\dishonored.exe | 
"UDP Query User{7119D515-A15C-4F71-8363-FF0A46A6D12F}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe | 
"UDP Query User{7287CB67-0105-420C-8906-1568EB41AFF1}C:\programdata\battle.net\agent\agent.1040\agent.exe" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe | 
"UDP Query User{75C03A52-8DC2-4C4A-82A9-D146FC711FD6}C:\program files (x86)\infinitecrisis\infinitecrisis.exe" = protocol=17 | dir=in | app=c:\program files (x86)\infinitecrisis\infinitecrisis.exe | 
"UDP Query User{7F2F0AE9-F086-4134-91A2-B9CD082A391D}C:\program files (x86)\dmc devil may cry\binaries\win32\dmc-devilmaycry.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dmc devil may cry\binaries\win32\dmc-devilmaycry.exe | 
"UDP Query User{80DB6F14-441B-43A8-BD26-4418C484DF9D}C:\program files (x86)\google\chrome\application\chrome.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | 
"UDP Query User{98F65D5E-7092-446D-B1BD-E4FD2DC0466A}E:\program files\steam\steamapps\common\dungeon defenders demo\binaries\win32\dundefgame.exe" = protocol=17 | dir=in | app=e:\program files\steam\steamapps\common\dungeon defenders demo\binaries\win32\dundefgame.exe | 
"UDP Query User{9C14E9E0-8F35-4DB0-B993-F478689B53BD}C:\program files (x86)\starcraft ii\versions\base21029\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base21029\sc2.exe | 
"UDP Query User{A61365A1-7978-4129-A5FB-7BF8DF3496A3}C:\soldat\soldat.exe" = protocol=17 | dir=in | app=c:\soldat\soldat.exe | 
"UDP Query User{A7563251-943C-4413-9FB3-4A5304988E96}C:\program files\starcraft\starcraft.exe" = protocol=17 | dir=in | app=c:\program files\starcraft\starcraft.exe | 
"UDP Query User{A7FC6A86-E13D-40F1-98D5-24379D64B9D0}C:\program files (x86)\starcraft ii\versions\base24944\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base24944\sc2.exe | 
"UDP Query User{AE3FC0CE-AB43-4F21-BDBB-7E234F5EF002}C:\users\miz\desktop\lan games\the ship\ship.exe" = protocol=17 | dir=in | app=c:\users\miz\desktop\lan games\the ship\ship.exe | 
"UDP Query User{B057A036-EE7F-4AE0-9370-CB83B7B09270}C:\games\blur nosteam\blur.exe" = protocol=17 | dir=in | app=c:\games\blur nosteam\blur.exe | 
"UDP Query User{C4868ECF-48D9-43BF-9D00-5FC1FB0FDDCE}C:\program files (x86)\phoenix viewer\slvoice.exe" = protocol=17 | dir=in | app=c:\program files (x86)\phoenix viewer\slvoice.exe | 
"UDP Query User{C5B56949-45B6-4592-98FC-1A0AF046EC5F}C:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\cdw\binaries\win64\cdw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chivalrymedievalwarfare\cdw\binaries\win64\cdw.exe | 
"UDP Query User{C81812FD-E190-494B-9427-1AECE849AA8C}C:\program files (x86)\bv2 proclient\bv2p.exe" = protocol=17 | dir=in | app=c:\program files (x86)\bv2 proclient\bv2p.exe | 
"UDP Query User{CA1EB75B-DDC0-4415-A21F-7DD71F2CFB98}C:\program files (x86)\heroes of the storm tech alpha\versions\base30027\play.exe" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of the storm tech alpha\versions\base30027\play.exe | 
"UDP Query User{D581A9BA-D95A-40C4-8CB1-9550A5F77D31}C:\users\miz\desktop\starcraft_2_na_en-us.exe" = protocol=17 | dir=in | app=c:\users\miz\desktop\starcraft_2_na_en-us.exe | 
"UDP Query User{D867DB39-495E-4916-BF3B-DC0C2702F362}C:\program files (x86)\heroes of the storm\versions\base30414\heroesofthestorm.exe" = protocol=17 | dir=in | app=c:\program files (x86)\heroes of the storm\versions\base30414\heroesofthestorm.exe | 
"UDP Query User{DBE17E14-E778-4546-B1F3-CF46FAF2FD67}C:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dark souls prepare to die edition\data\data.exe | 
"UDP Query User{DC83465D-7D0C-4FB6-BD2D-0F9CDC30671D}C:\program files (x86)\meteorentertainment\hawken\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe" = protocol=17 | dir=in | app=c:\program files (x86)\meteorentertainment\hawken\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe | 
"UDP Query User{E0E0BFED-5618-4404-A024-2D11D4A7EF4A}C:\program files (x86)\secret identity studios\marvel heroes beta\unrealengine3\binaries\win32\marvelgame.exe" = protocol=17 | dir=in | app=c:\program files (x86)\secret identity studios\marvel heroes beta\unrealengine3\binaries\win32\marvelgame.exe | 
"UDP Query User{E1627F92-8E2B-44FA-8938-4F5AD086DFE2}C:\users\public\games\cryptic studios\neverwinter\live\gameclient.exe" = protocol=17 | dir=in | app=c:\users\public\games\cryptic studios\neverwinter\live\gameclient.exe | 
"UDP Query User{E343BA60-5B97-45B5-9094-AE583A50AD31}C:\program files (x86)\battlefield 4\bf4_x86.exe" = protocol=17 | dir=in | app=c:\program files (x86)\battlefield 4\bf4_x86.exe | 
"UDP Query User{F0C14FAB-4C3E-4F89-8215-C004233FD0E9}C:\program files (x86)\fox\aliens versus predator 2 - primal hunt\lithtech.exe" = protocol=17 | dir=in | app=c:\program files (x86)\fox\aliens versus predator 2 - primal hunt\lithtech.exe | 
"UDP Query User{FB934328-6907-4B0C-AFA5-0AA07E36561C}C:\program files (x86)\battlefield 4\bf4.exe" = protocol=17 | dir=in | app=c:\program files (x86)\battlefield 4\bf4.exe | 
"UDP Query User{FE12DC4D-B2B1-45A1-879F-3BAF5EF64FCA}C:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\sc2-x.x.x.x-1.5.0.22342-enus-downloader.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.1 (r518)
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{21B133D6-5979-47F0-BE1C-F6A6B304693F}" = Visual Studio 2010 x64 Redistributables
"{230D1595-57DA-4933-8C4E-375797EBB7E1}" = Bluetooth Win7 Suite (64)
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{2EDC2FA3-1F34-34E5-9085-588C9EFD1CC6}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610
"{3165EA9B-36CC-499B-96FF-36FC30E10EF4}" = License Support
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5A68A656-979F-4168-8795-E2E368AA4DC2}" = iTunes
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{690285C2-2481-44FB-8402-162EA970A6DD}" = Logitech Gaming Software
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{764384C5-BCA9-307C-9AAC-FD443662686A}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610
"{787136D2-F0F8-4625-AA3F-72D7795AC842}" = Apple Mobile Device Support
"{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90150000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2013
"{90150000-0015-0409-1000-0000000FF1CE}" = Microsoft Access MUI (English) 2013
"{90150000-0016-0409-1000-0000000FF1CE}" = Microsoft Excel MUI (English) 2013
"{90150000-0018-0409-1000-0000000FF1CE}" = Microsoft PowerPoint MUI (English) 2013
"{90150000-0019-0409-1000-0000000FF1CE}" = Microsoft Publisher MUI (English) 2013
"{90150000-001A-0409-1000-0000000FF1CE}" = Microsoft Outlook MUI (English) 2013
"{90150000-001B-0409-1000-0000000FF1CE}" = Microsoft Word MUI (English) 2013
"{90150000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - English
"{90150000-001F-040C-1000-0000000FF1CE}" = Outils de vérification linguistique 2013 de Microsoft Office - Français
"{90150000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - Español
"{90150000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2013
"{90150000-0044-0409-1000-0000000FF1CE}" = Microsoft InfoPath MUI (English) 2013
"{90150000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2013
"{90150000-0090-0409-1000-0000000FF1CE}" = Microsoft DCF MUI (English) 2013
"{90150000-00A1-0409-1000-0000000FF1CE}" = Microsoft OneNote MUI (English) 2013
"{90150000-00BA-0409-1000-0000000FF1CE}" = Microsoft Groove MUI (English) 2013
"{90150000-00C1-0000-1000-0000000FF1CE}" = Microsoft Office 32-bit Components 2013
"{90150000-00C1-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2013
"{90150000-00E1-0409-1000-0000000FF1CE}" = Microsoft Office OSM MUI (English) 2013
"{90150000-00E2-0409-1000-0000000FF1CE}" = Microsoft Office OSM UX MUI (English) 2013
"{90150000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2013
"{90150000-0117-0409-1000-0000000FF1CE}" = Microsoft Access Setup Metadata MUI (English) 2013
"{90150000-012B-0409-1000-0000000FF1CE}" = Microsoft Lync MUI (English) 2013
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031" = Microsoft .NET Framework 4.5.1 (Deutsch)
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 337.88
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 337.88
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 337.88
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 2.0.1
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 337.88
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.13.1220
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 12.4.67
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer" = NVIDIA LED Visualizer 1.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.3.30.1
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service" = NVIDIA Network Service
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay" = NVIDIA ShadowPlay 12.4.67
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 1.2.23
"{BCCC97EE-E162-448C-8847-59718FF29B04}" = Intel® Network Connections 15.6.25.0
"{C513739C-5F16-37B5-9ACF-99925FF1C1F3}" = Microsoft .NET Framework 4.5.1 (DEU)
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant
"{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64
"{FB03650C-B373-4B20-ACA5-B7BA1A8EEE33}" = Visual C++ 64-bit Redistributables
"C-Media CM106 Like Sound Driver" = ARCTIC SOUND P531
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.60
"Logitech Gaming Software" = Logitech Gaming Software 8.20
"Office15.PROPLUS" = Microsoft Office Professional Plus 2013
"PROSetDX" = Intel® Network Connections 15.6.25.0
"sp6" = Logitech SetPoint 6.32
"Speccy" = Speccy
"Virtual Audio Cable 4.10" = Virtual Audio Cable 4.10
"WinRAR archiver" = WinRAR 4.11 (64-bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01E9B2FF-DAF4-4529-9CC9-2101625517C7}" = nero.prerequisites.msi
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{034DCAF9-96E7-4936-9A07-712F80B5181E}" = Nero RescueAgent 11
"{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{05A6B1CD-AA10-46A0-8D5C-6AD2A9EEFC8B}" = Nero Burning ROM 11
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{11D3EF85-63E1-4AE4-A7C1-9241BDB16B51}" = Nero ControlCenter 11
"{18272881-CFC0-434D-A975-E5BE44206AA0}" = Windows Live UX Platform Language Pack
"{185F9795-9663-4F13-9EF9-307A282ADB5A}" = ph
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 21
"{26DB09BC-6EB5-4CE0-A05D-D4DECE60E189}_is1" = Phoenix Viewer 1.6.0.1691
"{28526951-55EF-4901-A0CA-B9AC966D1DD1}" = Split/Second
"{2A075BB4-E976-4278-BF3F-E5C6945D84C0}" = bl
"{30F99474-EBE3-4134-A02B-F6CD38CFE243}" = Photo Gallery
"{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{34D3688E-A737-44C5-9E2A-FF73618728E1}" = AI Suite II
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMicron JMB36X Driver
"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF017}" = Smite
"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}" = Hi-Rez Studios Authenticate and Update Service
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{3FD0C489-0F02-481a-A3E1-9754CD396761}" = Intel® Watchdog Timer Driver (Intel® WDT)
"{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}" = Microsoft Games for Windows - LIVE Redistributable
"{461A5021-EE14-4E57-9A06-8ABCE9C38FE4}" = Mumble 1.2.6
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4BF62C05-3943-4ECB-B233-6E37E3FB5BCF}" = ZBrush 4
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform
"{53F7746A-96AA-49A5-86B8-59989680DAC5}" = Nero Burning ROM 11 Help (CHM)
"{5BABDA39-61CF-41EE-992D-4054B6649A9B}" = Movie Maker
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{755C6515-9FEA-490C-B15E-22BB6519E57E}" = Remote Control Server
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79BF4901-1EC4-4726-B3C2-A7859706C6E7}" = League of Legends
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.16
"{80407BA7-7763-4395-AB98-5233F1B34E65}" = NVIDIA PhysX
"{80F7CA44-F3A5-4853-8BA6-DDF57CD4F078}" = Rosetta Stone Version 3
"{815050E5-F545-11D4-9569-004095812ACC}" = Serious Sam: The First Encounter
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{a1909659-0a08-4554-8af1-2175904903a1}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610
"{A7A70E54-4678-4E66-A2BA-F135AAAB70A8}" = Guncraft
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1033-F400-7760-000000000005}" = Adobe Acrobat X Pro - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.06)
"{AF37176A-78CA-545B-34EF-8B6A21514DD1}" = Adobe Help Manager
"{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
"{B1846721-A8E6-46C7-83B6-0DCF7ADB4267}" = Nero Burning ROM 11
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
"{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}" = Nero Core Components 11
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}" = PDF Settings CS6
"{C034A6F9-6569-491B-B3BF-F5D15221A708}" = Windows Live Essentials
"{C1E3DFE7-4EAD-3E9E-A826-E06055BA5921}" = Google Talk Plugin
"{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer
"{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common
"{D01CE99A-8802-483C-A79F-298B691EB432}" = Nero RescueAgent 11 Help (CHM)
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D4D66270-9147-4BDF-9946-FCA2B303AA8F}" = Nero ControlCenter 11 Help (CHM)
"{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}" = Microsoft XNA Framework Redistributable 4.0 Refresh
"{D888F114-7537-4D48-AF03-5DA9C82D7540}" = Photo Common
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{D9DAD0FF-495A-472B-9F10-BAE430A26682}" = Apple Application Support
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}" = Asmedia ASM104x USB 3.0 Host Controller Driver
"{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}" = Adobe Creative Suite 6 Master Collection
"{EA2DB6E0-72C5-4ef9-A3A0-E6705F4A6A9E}" = Nexon Game Manager
"{ED6C77F9-4D7E-447C-9EC0-9A212D075535}" = Movie Maker
"{EFBE6DD5-B224-96E5-72B9-68D328CB12A6}" = Adobe Widget Browser
"{F03117FA-9270-46B0-9666-0B4BC2CDEBF5}" = Visual C++ Redistributables
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FC6C7107-7D72-41A1-A031-3CE751159BAB}" = Photo Gallery
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"4578-0181-0549-1546" = Altitude 1.1
"Adobe AIR" = Adobe AIR
"Adobe Creative Cloud" = Adobe Creative Cloud
"Adobe Flash Player ActiveX" = Adobe Flash Player 13 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 13 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Armagetron Advanced" = Armagetron Advanced 0.2.8.3.2
"ASIO4ALL" = ASIO4ALL
"Avast" = avast! Free Antivirus
"Battle.net" = Battle.net
"CDisplay_is1" = CDisplay 1.8
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Help Manager
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.WidgetBrowser" = Adobe Widget Browser
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2011-11-11
"Convert Audio Free FLAC to MP3_is1" = Convert Audio Free FLAC to MP3 version 1.0
"DAEMON Tools Lite" = DAEMON Tools Lite
"Dark Souls II_is1" = Dark Souls II
"Diablo III" = Diablo III
"e" = a
"Firestorm-Release" = Firestorm-Release (remove only)
"Free Video Flip and Rotate_is1" = Free Video Flip and Rotate version 2.1.6.128
"GOGPACKROGUELEGACY_is1" = Rogue Legacy
"GoldenEye: Source" = GoldenEye: Source
"Google Chrome" = Google Chrome
"Hearthstone" = Hearthstone
"Heroes of the Storm" = Heroes of the Storm
"ImgBurn" = ImgBurn
"InstallShield_{3165EA9B-36CC-499B-96FF-36FC30E10EF4}" = License Support
"InstallShield_{4BF62C05-3943-4ECB-B233-6E37E3FB5BCF}" = ZBrush 4
"InstallShield_{F03117FA-9270-46B0-9666-0B4BC2CDEBF5}" = Visual C++ Redistributables
"InstallShield_{FB03650C-B373-4B20-ACA5-B7BA1A8EEE33}" = Visual C++ 64-bit Redistributables
"IrfanView" = IrfanView (remove only)
"jass-pub-2.3.8" = jass-pub-2.3.8 (remove only)
"League of Legends 3.0.0" = League of Legends
"Magic Workstation_is1" = Magic Workstation 0.94f
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Mozilla Firefox 30.0 (x86 en-US)" = Mozilla Firefox 30.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MTG GamePack for Magic Workstation_is1" = MTG GamePack for Magic Workstation
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"optimizer_chrome" = Widevine Media Optimizer Chrome 6.0.0
"PdaNet_is1" = PdaNet for Android 3.50
"PowerISO" = PowerISO
"Radegast" = Radegast
"RaidCall" = RaidCall
"Scorched3D" = Scorched3D 43.3d
"StarCraft II" = StarCraft II
"Steam App 205700" = Quantum Conundrum Demo
"Steam App 207610" = The Walking Dead
"Steam App 211420" = Dark Souls: Prepare to Die Edition
"Steam App 218" = Source SDK Base 2007
"Steam App 219640" = Chivalry: Medieval Warfare
"Steam App 271290" = HAWKEN
"Steam App 570" = Dota 2
"Steam App 65800" = Dungeon Defenders
"TeamViewer 8" = TeamViewer 8
"Transistor_is1" = Transistor
"VLC media player" = VLC media player 2.1.3
"WinLiveSuite" = Windows Live Essentials
"World of Warcraft" = World of Warcraft
"Xfire" = Xfire (remove only)
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
"ZBrush 4R4 4R4" = ZBrush 4R4
 
========== HKEY_USERS Uninstall List ==========
 
[HKEY_USERS\S-1-5-21-1038818363-2529734610-2198295289-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Hawken" = Hawken
"optimizer_chrome" = Widevine Media Optimizer Chrome 6.0.0
"UnityWebPlayer" = Unity Web Player
"uTorrent" = µTorrent
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 6/20/2014 4:40:27 AM | Computer Name = Miz-PC | Source = Application Hang | ID = 1002
Description = The program AlertHelper.exe version 1.0.0.5 stopped interacting with
 Windows and was closed. To see if more information about the problem is available,
 check the problem history in the Action Center control panel.    Process ID: e78    Start
 Time: 01cf8c632737cf88    Termination Time: 1    Application Path: C:\Program Files (x86)\ASUS\AI
 Suite II\Sensor\AlertHelper\AlertHelper.exe    Report Id: 7b0eb838-f856-11e3-85d1-0026833c0a21
 
 
Error - 6/20/2014 4:44:18 AM | Computer Name = Miz-PC | Source = Office 2013 Licensing Service | ID = 0
Description = 
 
Error - 6/21/2014 3:46:31 AM | Computer Name = Miz-PC | Source = Office 2013 Licensing Service | ID = 0
Description = 
 
Error - 6/21/2014 8:11:20 PM | Computer Name = Miz-PC | Source = Application Hang | ID = 1002
Description = The program AI Suite II.exe version 1.0.0.40 stopped interacting with
 Windows and was closed. To see if more information about the problem is available,
 check the problem history in the Action Center control panel.    Process ID: 1a7c    Start
 Time: 01cf8dadfdc229f6    Termination Time: 1    Application Path: C:\Program Files (x86)\ASUS\AI
 Suite II\AI Suite II.exe    Report Id: b53cf895-f9a1-11e3-bcba-c86000307b32  
 
Error - 6/22/2014 4:34:13 AM | Computer Name = Miz-PC | Source = NvStreamSvc | ID = 131073
Description = 
 
Error - 6/22/2014 4:34:15 AM | Computer Name = Miz-PC | Source = NvStreamSvc | ID = 131073
Description = 
 
Error - 6/22/2014 4:34:15 AM | Computer Name = Miz-PC | Source = NvStreamSvc | ID = 131073
Description = 
 
Error - 6/22/2014 4:43:42 AM | Computer Name = Miz-PC | Source = Office 2013 Licensing Service | ID = 0
Description = 
 
Error - 6/23/2014 4:44:10 AM | Computer Name = Miz-PC | Source = Office 2013 Licensing Service | ID = 0
Description = 
 
[ System Events ]
Error - 6/23/2014 2:08:39 PM | Computer Name = Miz-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
 Protocol service which failed to start because of the following error:   %%-2140993535
 
Error - 6/23/2014 2:08:39 PM | Computer Name = Miz-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
 error:   %%-2140993535
 
Error - 6/23/2014 2:08:39 PM | Computer Name = Miz-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
 Protocol service which failed to start because of the following error:   %%-2140993535
 
Error - 6/23/2014 2:08:39 PM | Computer Name = Miz-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
 error:   %%-2140993535
 
Error - 6/23/2014 6:48:37 PM | Computer Name = Miz-PC | Source = PNRPSvc | ID = 102
Description = 
 
Error - 6/23/2014 6:48:37 PM | Computer Name = Miz-PC | Source = PNRPSvc | ID = 102
Description = 
 
Error - 6/23/2014 6:48:37 PM | Computer Name = Miz-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
 Protocol service which failed to start because of the following error:   %%-2140993535
 
Error - 6/23/2014 6:48:37 PM | Computer Name = Miz-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
 error:   %%-2140993535
 
Error - 6/23/2014 6:48:37 PM | Computer Name = Miz-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
 Protocol service which failed to start because of the following error:   %%-2140993535
 
Error - 6/23/2014 6:48:37 PM | Computer Name = Miz-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
 error:   %%-2140993535
 
 
< End of report >

  • 0

Advertisements


#62
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts

I've asked you to stay away from downloading anything to your machine, especially with uTorrent.

First of all, I suspect the files are illegal.

Second, at this point, it can only add to your issues.

 

 

 

 

 

we'll run OTL Fix.
 

icon_exclaim.gifWARNING icon_exclaim.gif
The following fix is only relevant for this system and no other, running the script on another computer will not work and may cause problems!

  • Right-click on the 51a5d669693dd-icon_OTL.png icon and select Run as Administrator to execute the tool. Make sure all other windows are closed.
  • Do not change any other settings unless otherwise told to do so.
  • Under the CustomScanBox.png box at the bottom, paste in the following:

    :Commands
    [createrestorepoint]
    
    :Files
    @C:\Users\Miz\AppData\Local\Temporary Internet Files:7u0WhrXaHzIqGRTnCVUHU3ME
    C:\Users\Miz\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]
    C:\Users\Miz\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]
    
    :OTL
    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: File not found
    O2:64bit: - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
    O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {E9DF9360-97F8-4690-AFE6-996C80790DA4} - No CLSID value found.
    O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {E9DF9360-97F8-4690-AFE6-996C80790DA4} - No CLSID value found.
    O4 - HKU\S-1-5-21-1038818363-2529734610-2198295289-1000..\Run: [AdobeBridge] File not found
    O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
    O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
    
    :Commands
    [emptytemp]
    
     
  • click the Run Fix button at the top. Let the program run uninterrupted.
  • click OK if prompted for reboot.

icon_idea.gif

  • When OTL executes the Fix it can shutdown all running processes and you may lose the Desktop and icons, but they will return on reboot
  • OTL may ask to reboot the machine. Please agree if prompted.
  • The report should appear in Notepad after the reboot. Copy & Paste that report in your next reply and not as attachment.
  • The OTL fix log will be saved in the following location: C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log - where mmddyyy _hhmmss is the date and time when the fix run.

 

After that please post me fresh FRST report, with addition option checked.

 

Regards,

Naat


  • 0

#63
GhostLoad

GhostLoad

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 419 posts

OTL Fix Log

 

All processes killed

========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== FILES ==========
Unable to delete ADS C:\Users\Miz\AppData\Local\Temporary Internet Files:7u0WhrXaHzIqGRTnCVUHU3ME .
C:\Users\Miz\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]\META-INF folder moved successfully.
C:\Users\Miz\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]\content\imgs\flgs folder moved successfully.
C:\Users\Miz\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]\content\imgs folder moved successfully.
C:\Users\Miz\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]\content\images folder moved successfully.
C:\Users\Miz\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]\content folder moved successfully.
C:\Users\Miz\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected] folder moved successfully.
C:\Users\Miz\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected] moved successfully.
========== OTL ==========
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E9DF9360-97F8-4690-AFE6-996C80790DA4} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E9DF9360-97F8-4690-AFE6-996C80790DA4}\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E9DF9360-97F8-4690-AFE6-996C80790DA4} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E9DF9360-97F8-4690-AFE6-996C80790DA4}\ not found.
Registry value HKEY_USERS\S-1-5-21-1038818363-2529734610-2198295289-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge deleted successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Miz
->Temp folder emptied: 3045520 bytes
->Temporary Internet Files folder emptied: 9254111 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 383014019 bytes
->Google Chrome cache emptied: 373406229 bytes
->Flash cache emptied: 6711 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 4302 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 1532440 bytes
 
Total Files Cleaned = 735.00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 06242014_125638
 
Files\Folders moved on Reboot...
File move failed. C:\Users\Miz\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\6d1026b4fa6d4c49d77d65f8805a9c0_fce8395c8fd8a860_6229ccd76215aea1_0_0.bin scheduled to be moved on reboot.
File move failed. C:\Users\Miz\AppData\Local\Temp\NVIDIA Corporation\NV_Cache\6d1026b4fa6d4c49d77d65f8805a9c0_fce8395c8fd8a860_6229ccd76215aea1_0_0.toc scheduled to be moved on reboot.
C:\Users\Miz\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Miz\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
File move failed. C:\Windows\temp\_avast_\AvastLock.txt scheduled to be moved on reboot.
 
PendingFileRenameOperations files...
 
Registry entries deleted on Reboot...

  • 0

#64
GhostLoad

GhostLoad

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 419 posts

FRST.txt

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-06-2014
Ran by Miz (administrator) on MIZ-PC on 24-06-2014 13:05:36
Running from C:\Users\Miz\Desktop
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
 
The only official download link for FRST:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
 
==================== Processes (Whitelisted) =================
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe
() C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe
() C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
(PACE Anti-Piracy, Inc.) C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\iPhone Simulator\pnSvc.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\EC Simulator.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\USB 3.0 Boost\U3BoostSvr64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\MSOSYNC.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
 
 
==================== Registry (Whitelisted) ==================
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11613288 2010-11-19] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [558496 2014-02-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3873704 2014-04-30] (AVAST Software)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2688920 2014-05-26] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-1038818363-2529734610-2198295289-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [1754816 2014-05-29] (Valve Corporation)
HKU\S-1-5-21-1038818363-2529734610-2198295289-1000\...\Run: [Messenger (Yahoo!)] => C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe [6595928 2012-05-25] (Yahoo! Inc.)
HKU\S-1-5-21-1038818363-2529734610-2198295289-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21444224 2014-05-08] (Skype Technologies S.A.)
HKU\S-1-5-21-1038818363-2529734610-2198295289-1000\...\Run: [GoogleChromeAutoLaunch_D30BA0C625A5A2A6D1452AE610495547] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [860488 2014-06-05] (Google Inc.)
HKU\S-1-5-21-1038818363-2529734610-2198295289-1000\...\Run: [Google Update] => C:\Users\Miz\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2012-07-17] (Google Inc.)
HKU\S-1-5-21-1038818363-2529734610-2198295289-1000\...\MountPoints2: N - N:\Setup.exe
HKU\S-1-5-21-1038818363-2529734610-2198295289-1000\...\MountPoints2: {01cb3c68-c4d5-11e1-bfc5-0026833c0a21} - O:\MotoCastSetup.exe -a
HKU\S-1-5-21-1038818363-2529734610-2198295289-1000\...\MountPoints2: {aa83fab1-4704-11e3-a338-c86000307b32} - K:\setup.exe
ShellIconOverlayIdentifiers:  AccExtIco1 -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers:  AccExtIco2 -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers:  AccExtIco3 -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers:  SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers:  SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers:  SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers-x32:  SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32:  SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32:  SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
 
==================== Internet (Whitelisted) ====================
 
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xB951E59BA731CD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
URLSearchHook: HKCU - YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
BHO-x32: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SmartSelect Class - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
DPF: HKLM {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 65.32.5.111 65.32.5.112
 
FireFox:
========
FF ProfilePath: C:\Users\Miz\AppData\Roaming\Mozilla\Firefox\Profiles\gkl27u1m.default
FF Homepage: google.com
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 - C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 - C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nexon.net/NxGame - C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @raidcall.en/RCplugin - C:\Users\Miz\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Acrobat - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin-x32: adobe.com/AdobeExManDetect - C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Miz\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Miz\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Miz\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Miz\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF user.js: detected! => C:\Users\Miz\AppData\Roaming\Mozilla\Firefox\Profiles\gkl27u1m.default\user.js
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Miz\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Miz\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF Extension: Widevine Media Optimizer - C:\Users\Miz\AppData\Roaming\Mozilla\Firefox\Profiles\gkl27u1m.default\Extensions\{2d3fbcf7-be69-4433-8858-c621a8d0e58d} [2014-06-23]
FF Extension: Yahoo! Toolbar - C:\Users\Miz\AppData\Roaming\Mozilla\Firefox\Profiles\gkl27u1m.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2014-06-09]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013-03-26]
 
Chrome: 
=======
CHR HomePage: 
CHR StartupUrls: "hxxp://google.com/"
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Miz\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-06-03]
CHR Extension: (AdBlock) - C:\Users\Miz\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-05-20]
CHR Extension: (Google Mail Checker) - C:\Users\Miz\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2014-05-20]
CHR Extension: (Tiësto) - C:\Users\Miz\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnmeobddjkkgkglnogihcaejaleikhdh [2014-05-20]
CHR Extension: (Google Wallet) - C:\Users\Miz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21]
CHR Extension: (Picasa) - C:\Users\Miz\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2014-05-20]
CHR Extension: (Gmail) - C:\Users\Miz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-20]
 
==================== Services (Whitelisted) =================
 
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe [922240 2011-06-13] ()
R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [915584 2010-12-01] ()
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [586880 2010-10-21] ()
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [74912 2011-03-13] (Atheros Commnucations) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-30] (AVAST Software)
U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9216 2014-02-28] (Hi-Rez Studios) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1617696 2014-04-30] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21007192 2014-04-30] (NVIDIA Corporation)
R2 PaceLicenseDServices; C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe [2938880 2012-05-18] (PACE Anti-Piracy, Inc.) [File not signed]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
 
==================== Drivers (Whitelisted) ====================
 
R0 AiChargerPlus; C:\Windows\System32\DRIVERS\AiChargerPlus.sys [14464 2010-11-08] (ASUSTek Computer Inc.)
S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [36256 2009-11-13] (Google Inc) [File not signed]
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2010-08-24] ()
S3 ASPI; C:\Windows\SysWOW64\DRIVERS\ASPI32.sys [84832 2002-07-17] (Adaptec) [File not signed]
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2010-08-03] ()
R3 ASUSFILTER; C:\Windows\SysWow64\drivers\ASUSFILTER.sys [46152 2011-09-20] (MCCI Corporation)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-04-30] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-04-30] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-04-30] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-04-30] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-05-15] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-05-15] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-05-15] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-04-30] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-11-06] (Disc Soft Ltd)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [18776 2014-04-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-13] (Brother Industries Ltd.)
R3 USBMULCD; C:\Windows\System32\drivers\CM10664.sys [1307648 2010-01-29] (C-Media Electronics Inc)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
 
==================== One Month Created Files and Folders ========
 
2014-06-24 12:56 - 2014-06-24 12:56 - 00000000 ____D () C:\_OTL
2014-06-23 04:46 - 2014-06-23 04:47 - 108486450 _____ () C:\Users\Miz\Desktop\Robot.Chicken.S07E11.HDTV.x264-KILLERS.mp4
2014-06-23 04:46 - 2014-06-23 04:46 - 00000000 ____D () C:\Users\Miz\Desktop\Superjail.S04E02.HDTV.x264-KILLERS[rarbg]
2014-06-22 21:51 - 2014-06-22 21:52 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-22 16:36 - 2014-06-22 16:37 - 00003752 _____ () C:\Users\Miz\Desktop\aswMBR.txt
2014-06-22 16:11 - 2014-06-22 16:11 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-06-22 16:04 - 2014-06-22 16:04 - 05185536 _____ (AVAST Software) C:\Users\Miz\Desktop\aswMBR.exe
2014-06-21 16:01 - 2014-06-21 16:01 - 00448512 _____ (OldTimer Tools) C:\Users\Miz\Desktop\TFC.exe
2014-06-19 02:39 - 2014-06-19 02:39 - 00293952 _____ () C:\Windows\Minidump\061914-19312-01.dmp
2014-06-18 13:49 - 2014-06-18 13:49 - 00000000 __SHD () C:\Users\Miz\AppData\Local\EmieUserList
2014-06-18 13:49 - 2014-06-18 13:49 - 00000000 __SHD () C:\Users\Miz\AppData\Local\EmieSiteList
2014-06-18 13:43 - 2014-06-18 13:43 - 00000000 ___RD () C:\Users\Miz\Creative Cloud Files
2014-06-18 13:41 - 2014-06-18 13:41 - 00001313 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2014-06-18 04:22 - 2014-06-18 04:22 - 00001139 _____ () C:\Users\Miz\Desktop\Transistor (x86).lnk
2014-06-18 04:22 - 2014-06-18 04:22 - 00001139 _____ () C:\Users\Miz\Desktop\Transistor (x64).lnk
2014-06-18 04:22 - 2014-06-18 04:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Transistor
2014-06-17 15:46 - 2014-06-17 15:47 - 00294024 _____ () C:\Windows\Minidump\061714-20872-01.dmp
2014-06-17 13:11 - 2014-06-18 04:22 - 00000000 ____D () C:\Program Files (x86)\Transistor
2014-06-17 13:04 - 2014-06-17 13:06 - 00000000 ____D () C:\Users\Miz\Desktop\Transistor
2014-06-11 21:29 - 2014-05-30 06:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-11 21:29 - 2014-05-30 06:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-11 21:29 - 2014-05-30 06:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-11 21:29 - 2014-05-30 05:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-11 21:29 - 2014-05-30 05:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-11 21:29 - 2014-05-30 05:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-11 21:29 - 2014-05-30 05:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-11 21:29 - 2014-05-30 05:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-11 21:29 - 2014-05-30 05:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-11 21:29 - 2014-05-30 05:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-11 21:29 - 2014-05-30 05:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-11 21:29 - 2014-05-30 05:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-11 21:29 - 2014-05-30 05:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-11 21:29 - 2014-05-30 05:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-11 21:29 - 2014-05-30 05:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-11 21:29 - 2014-05-30 05:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-11 21:29 - 2014-05-30 05:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-11 21:29 - 2014-05-30 05:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-11 21:29 - 2014-05-30 04:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-11 21:29 - 2014-05-30 04:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-11 21:29 - 2014-05-30 04:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-11 21:29 - 2014-05-30 04:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-11 21:29 - 2014-05-30 04:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-11 21:29 - 2014-05-30 04:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-11 21:29 - 2014-05-30 04:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-11 21:29 - 2014-05-30 04:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-11 21:29 - 2014-05-30 04:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-11 21:29 - 2014-05-30 04:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-11 21:29 - 2014-05-30 04:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-11 21:29 - 2014-05-30 04:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-11 21:29 - 2014-05-30 04:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-11 21:29 - 2014-05-30 04:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-11 21:29 - 2014-05-30 04:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-11 21:29 - 2014-05-30 04:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-11 21:29 - 2014-05-30 04:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-11 21:29 - 2014-05-30 04:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-11 21:29 - 2014-05-30 04:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-11 21:29 - 2014-05-30 04:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-11 21:29 - 2014-05-30 04:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-11 21:29 - 2014-05-30 04:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-11 21:29 - 2014-05-30 03:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-11 21:29 - 2014-05-30 03:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-11 21:29 - 2014-05-30 03:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-11 21:29 - 2014-05-30 03:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-11 21:29 - 2014-05-30 03:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-11 21:29 - 2014-05-30 03:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-11 21:29 - 2014-05-30 03:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-11 21:29 - 2014-05-30 03:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-11 21:29 - 2014-05-30 03:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-11 21:29 - 2014-05-30 03:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-11 21:29 - 2014-05-30 03:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-11 21:29 - 2014-05-30 03:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-11 21:14 - 2014-04-04 22:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-11 21:14 - 2014-04-04 22:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-11 21:10 - 2014-04-24 22:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-11 21:10 - 2014-04-24 22:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-11 21:10 - 2014-03-26 10:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-11 21:10 - 2014-03-26 10:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-11 21:10 - 2014-03-26 10:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-11 21:10 - 2014-03-26 10:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-11 21:10 - 2014-03-26 10:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-11 21:10 - 2014-03-26 10:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-11 21:10 - 2014-03-26 10:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-06-11 21:10 - 2014-03-26 10:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-06-11 21:09 - 2014-05-08 05:32 - 03178496 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-11 21:09 - 2014-05-08 05:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-06-11 05:22 - 2014-06-19 13:01 - 00005396 _____ () C:\Users\Miz\Desktop\ckfiles.txt
2014-06-11 05:19 - 2014-06-11 05:19 - 00000000 ____D () C:\ProgramData\Office Genuine Advantage
2014-06-11 05:19 - 2014-06-11 05:19 - 00000000 ____D () C:\MGADiagToolOutput
2014-06-11 05:18 - 2014-06-11 05:18 - 02031992 _____ (Microsoft Corporation) C:\Users\Miz\Desktop\MGADiag.exe
2014-06-11 05:18 - 2014-06-11 05:18 - 00468480 _____ () C:\Users\Miz\Desktop\CKScanner.exe
2014-06-10 12:58 - 2014-06-23 14:31 - 00049290 _____ () C:\Users\Miz\Desktop\Addition.txt
2014-06-10 12:57 - 2014-06-24 13:06 - 00023353 _____ () C:\Users\Miz\Desktop\FRST.txt
2014-06-10 12:57 - 2014-06-24 13:05 - 00000000 ____D () C:\FRST
2014-06-10 12:44 - 2014-06-24 02:10 - 00152988 _____ () C:\Users\Miz\Desktop\OTL.Txt
2014-06-10 12:24 - 2014-06-23 13:45 - 02082816 _____ (Farbar) C:\Users\Miz\Desktop\FRST64.exe
2014-06-10 01:52 - 2014-06-10 04:11 - 00000000 ____D () C:\Users\Miz\AppData\Local\NVIDIA Corporation
2014-06-10 01:51 - 2014-06-10 01:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-06-10 01:51 - 2014-06-10 01:51 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-06-10 01:51 - 2014-04-30 14:27 - 01081112 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2014-06-10 01:51 - 2014-04-30 14:26 - 01225920 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2014-06-10 01:50 - 2014-05-19 19:10 - 00601432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2014-06-10 01:48 - 2014-05-19 22:44 - 31387936 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 24025376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 17561544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 17480432 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 16003912 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 12688328 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-06-10 01:48 - 2014-05-19 22:44 - 11644928 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 11599072 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 09735256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 09697640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 03141976 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 02953672 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 02785568 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 02412376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 01889112 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433788.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 01541576 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433788.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 00895776 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 00892704 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 00867784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 00861128 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 00837056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 00354016 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2014-06-10 01:48 - 2014-05-19 22:44 - 00166568 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 00146480 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2014-06-10 01:48 - 2014-05-19 22:44 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2014-06-10 01:45 - 2014-03-31 12:42 - 00040392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-06-10 01:45 - 2014-03-31 12:42 - 00037320 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2014-06-10 01:45 - 2014-03-31 12:42 - 00034760 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-06-10 01:37 - 2014-06-10 01:37 - 00293952 _____ () C:\Windows\Minidump\061014-22495-01.dmp
2014-06-08 14:30 - 2014-06-08 14:30 - 00293984 _____ () C:\Windows\Minidump\060814-19999-01.dmp
2014-06-08 12:46 - 2014-06-24 02:11 - 00168722 _____ () C:\Users\Miz\Desktop\Extras.Txt
2014-06-08 12:27 - 2014-06-08 12:27 - 00602112 _____ (OldTimer Tools) C:\Users\Miz\Desktop\OTL.exe
2014-06-07 18:59 - 2014-06-07 18:59 - 00291832 _____ () C:\Windows\Minidump\060714-17643-01.dmp
2014-06-07 18:55 - 2014-06-07 18:55 - 00293664 _____ () C:\Windows\Minidump\060714-17565-01.dmp
2014-06-07 18:52 - 2014-06-07 18:53 - 00290840 _____ () C:\Windows\Minidump\060714-21309-01.dmp
2014-06-07 18:49 - 2014-06-07 18:50 - 00294016 _____ () C:\Windows\Minidump\060714-19656-01.dmp
2014-06-05 16:32 - 2014-06-05 16:32 - 00293984 _____ () C:\Windows\Minidump\060514-15428-01.dmp
2014-06-05 01:31 - 2014-06-05 01:31 - 00293976 _____ () C:\Windows\Minidump\060514-15412-01.dmp
2014-06-04 05:52 - 2014-06-04 05:52 - 00293224 _____ () C:\Windows\Minidump\060414-24991-01.dmp
2014-06-03 13:14 - 2014-06-03 13:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-06-03 13:13 - 2014-06-03 13:14 - 00000000 ____D () C:\Program Files\iTunes
2014-06-03 13:13 - 2014-06-03 13:14 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-06-03 13:13 - 2014-06-03 13:13 - 00000000 ____D () C:\Program Files\iPod
2014-06-03 03:21 - 2014-06-03 03:21 - 00292056 _____ () C:\Windows\Minidump\060314-17643-01.dmp
2014-06-03 03:14 - 2014-06-03 03:14 - 00291424 _____ () C:\Windows\Minidump\060314-16957-01.dmp
2014-06-03 03:12 - 2014-06-03 03:12 - 00292568 _____ () C:\Windows\Minidump\060314-19281-01.dmp
2014-06-03 03:09 - 2014-06-03 03:09 - 00291976 _____ () C:\Windows\Minidump\060314-20748-01.dmp
2014-06-03 03:07 - 2014-06-03 03:07 - 00294024 _____ () C:\Windows\Minidump\060314-19593-01.dmp
2014-06-03 02:04 - 2014-06-03 02:04 - 00294008 _____ () C:\Windows\Minidump\060314-19921-01.dmp
2014-06-03 02:01 - 2014-06-03 02:01 - 00292720 _____ () C:\Windows\Minidump\060314-18174-01.dmp
2014-06-02 15:46 - 2014-06-18 23:58 - 00000000 ____D () C:\Users\Miz\Desktop\Comics
2014-06-01 14:16 - 2014-06-01 14:16 - 00000000 ____D () C:\Users\Miz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Black_Box
2014-05-29 01:37 - 2014-05-29 01:37 - 00002378 _____ () C:\Users\Miz\Documents\MumbleAutomaticCertificateBackup.p12
2014-05-29 01:34 - 2014-05-29 01:41 - 00000000 ____D () C:\Users\Miz\AppData\Roaming\Mumble
2014-05-29 01:34 - 2014-05-29 01:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mumble
2014-05-29 01:34 - 2014-05-29 01:34 - 00000000 ____D () C:\Program Files (x86)\Mumble
2014-05-28 20:34 - 2014-05-28 20:34 - 00000000 ____D () C:\Users\Miz\AppData\Roaming\IDM
2014-05-28 20:34 - 2014-05-28 20:34 - 00000000 ____D () C:\ProgramData\IDM
2014-05-28 12:29 - 2014-05-28 12:29 - 00000000 ____D () C:\Program Files\Bonjour
2014-05-28 12:29 - 2014-05-28 12:29 - 00000000 ____D () C:\Program Files (x86)\Bonjour
 
==================== One Month Modified Files and Folders =======
 
2014-06-24 13:06 - 2014-06-10 12:57 - 00023353 _____ () C:\Users\Miz\Desktop\FRST.txt
2014-06-24 13:06 - 2012-03-16 08:45 - 00000892 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-24 13:05 - 2014-06-10 12:57 - 00000000 ____D () C:\FRST
2014-06-24 13:05 - 2013-04-11 09:08 - 00004942 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Miz-PC-Miz Miz-PC
2014-06-24 13:05 - 2012-03-18 08:26 - 01266775 _____ () C:\Windows\WindowsUpdate.log
2014-06-24 13:02 - 2012-12-14 11:32 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-24 13:02 - 2012-09-09 11:44 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-06-24 13:01 - 2012-03-16 11:49 - 00000000 ____D () C:\Users\Miz\AppData\Roaming\Skype
2014-06-24 12:59 - 2013-08-26 04:18 - 00052103 _____ () C:\Windows\setupact.log
2014-06-24 12:59 - 2012-03-16 08:45 - 00000888 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-24 12:58 - 2012-03-16 09:27 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-06-24 12:58 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-24 12:56 - 2014-06-24 12:56 - 00000000 ____D () C:\_OTL
2014-06-24 12:34 - 2009-07-14 00:45 - 00023504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-24 12:34 - 2009-07-14 00:45 - 00023504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-24 12:29 - 2012-08-14 14:08 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1038818363-2529734610-2198295289-1000UA.job
2014-06-24 12:26 - 2014-04-30 12:26 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-06-24 04:02 - 2012-03-25 10:16 - 00000000 ____D () C:\Users\Miz\AppData\Local\Firestorm
2014-06-24 03:27 - 2012-03-20 12:39 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-06-24 02:11 - 2014-06-08 12:46 - 00168722 _____ () C:\Users\Miz\Desktop\Extras.Txt
2014-06-24 02:10 - 2014-06-10 12:44 - 00152988 _____ () C:\Users\Miz\Desktop\OTL.Txt
2014-06-24 02:00 - 2012-03-20 12:35 - 00000000 ____D () C:\Users\Miz\AppData\Local\Adobe
2014-06-23 19:28 - 2012-08-14 14:08 - 00000848 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1038818363-2529734610-2198295289-1000Core.job
2014-06-23 14:31 - 2014-06-10 12:58 - 00049290 _____ () C:\Users\Miz\Desktop\Addition.txt
2014-06-23 13:45 - 2014-06-10 12:24 - 02082816 _____ (Farbar) C:\Users\Miz\Desktop\FRST64.exe
2014-06-23 13:27 - 2013-08-24 02:13 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-23 04:50 - 2012-03-16 11:46 - 00000000 ____D () C:\Users\Miz\AppData\Roaming\uTorrent
2014-06-23 04:47 - 2014-06-23 04:46 - 108486450 _____ () C:\Users\Miz\Desktop\Robot.Chicken.S07E11.HDTV.x264-KILLERS.mp4
2014-06-23 04:46 - 2014-06-23 04:46 - 00000000 ____D () C:\Users\Miz\Desktop\Superjail.S04E02.HDTV.x264-KILLERS[rarbg]
2014-06-22 21:52 - 2014-06-22 21:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-22 17:11 - 2013-01-26 17:34 - 00000524 _____ () C:\Users\Miz\Desktop\expenses.txt
2014-06-22 17:00 - 2012-03-16 08:45 - 00003888 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-06-22 17:00 - 2012-03-16 08:45 - 00003636 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-06-22 16:37 - 2014-06-22 16:36 - 00003752 _____ () C:\Users\Miz\Desktop\aswMBR.txt
2014-06-22 16:11 - 2014-06-22 16:11 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-06-22 16:04 - 2014-06-22 16:04 - 05185536 _____ (AVAST Software) C:\Users\Miz\Desktop\aswMBR.exe
2014-06-21 19:41 - 2013-11-02 18:36 - 00000000 ____D () C:\Users\Miz\AppData\Local\Battle.net
2014-06-21 19:25 - 2012-03-18 08:24 - 00000000 ____D () C:\Users\Miz
2014-06-21 16:01 - 2014-06-21 16:01 - 00448512 _____ (OldTimer Tools) C:\Users\Miz\Desktop\TFC.exe
2014-06-21 15:11 - 2014-05-22 18:07 - 00000000 ____D () C:\Program Files (x86)\Heroes of the Storm
2014-06-20 04:33 - 2013-08-26 04:18 - 00188130 _____ () C:\Windows\PFRO.log
2014-06-19 18:54 - 2013-08-02 00:18 - 00000827 _____ () C:\Users\Miz\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-06-19 14:24 - 2012-03-16 14:25 - 00000000 ____D () C:\Users\Miz\AppData\Local\CrashDumps
2014-06-19 13:01 - 2014-06-11 05:22 - 00005396 _____ () C:\Users\Miz\Desktop\ckfiles.txt
2014-06-19 12:56 - 2012-03-16 08:52 - 00000000 ____D () C:\Users\Miz\AppData\Roaming\Adobe
2014-06-19 12:55 - 2012-03-20 12:37 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-06-19 02:39 - 2014-06-19 02:39 - 00293952 _____ () C:\Windows\Minidump\061914-19312-01.dmp
2014-06-19 02:39 - 2014-02-18 02:20 - 1177200135 _____ () C:\Windows\MEMORY.DMP
2014-06-19 02:39 - 2012-05-21 05:44 - 00000000 ____D () C:\Windows\Minidump
2014-06-19 02:20 - 2012-03-17 04:16 - 00000000 ____D () C:\Users\Miz\AppData\Roaming\vlc
2014-06-18 23:58 - 2014-06-02 15:46 - 00000000 ____D () C:\Users\Miz\Desktop\Comics
2014-06-18 19:23 - 2012-08-14 14:08 - 00003866 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1038818363-2529734610-2198295289-1000UA
2014-06-18 19:23 - 2012-08-14 14:08 - 00003470 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1038818363-2529734610-2198295289-1000Core
2014-06-18 13:55 - 2009-07-14 00:45 - 05069088 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-06-18 13:50 - 2013-02-12 05:38 - 00000000 ____D () C:\Windows\System32\Tasks\Leader Technologies
2014-06-18 13:49 - 2014-06-18 13:49 - 00000000 __SHD () C:\Users\Miz\AppData\Local\EmieUserList
2014-06-18 13:49 - 2014-06-18 13:49 - 00000000 __SHD () C:\Users\Miz\AppData\Local\EmieSiteList
2014-06-18 13:49 - 2012-03-16 09:32 - 00115736 _____ () C:\Users\Miz\AppData\Local\GDIPFONTCACHEV1.DAT
2014-06-18 13:43 - 2014-06-18 13:43 - 00000000 ___RD () C:\Users\Miz\Creative Cloud Files
2014-06-18 13:43 - 2012-03-20 12:36 - 00000000 ____D () C:\ProgramData\Adobe
2014-06-18 13:41 - 2014-06-18 13:41 - 00001313 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2014-06-18 13:41 - 2014-04-23 17:47 - 00000000 ____D () C:\ProgramData\Package Cache
2014-06-18 13:32 - 2014-04-30 18:49 - 00697256 _____ () C:\Windows\system32\perfh007.dat
2014-06-18 13:32 - 2014-04-30 18:49 - 00149224 _____ () C:\Windows\system32\perfc007.dat
2014-06-18 13:32 - 2009-07-14 01:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-18 04:22 - 2014-06-18 04:22 - 00001139 _____ () C:\Users\Miz\Desktop\Transistor (x86).lnk
2014-06-18 04:22 - 2014-06-18 04:22 - 00001139 _____ () C:\Users\Miz\Desktop\Transistor (x64).lnk
2014-06-18 04:22 - 2014-06-18 04:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Transistor
2014-06-18 04:22 - 2014-06-17 13:11 - 00000000 ____D () C:\Program Files (x86)\Transistor
2014-06-17 15:47 - 2014-06-17 15:46 - 00294024 _____ () C:\Windows\Minidump\061714-20872-01.dmp
2014-06-17 13:06 - 2014-06-17 13:04 - 00000000 ____D () C:\Users\Miz\Desktop\Transistor
2014-06-13 17:52 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\rescache
2014-06-13 05:56 - 2014-04-30 12:58 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-13 05:55 - 2014-04-30 12:58 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-12 17:46 - 2012-03-16 08:45 - 00002146 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-06-11 05:19 - 2014-06-11 05:19 - 00000000 ____D () C:\ProgramData\Office Genuine Advantage
2014-06-11 05:19 - 2014-06-11 05:19 - 00000000 ____D () C:\MGADiagToolOutput
2014-06-11 05:18 - 2014-06-11 05:18 - 02031992 _____ (Microsoft Corporation) C:\Users\Miz\Desktop\MGADiag.exe
2014-06-11 05:18 - 2014-06-11 05:18 - 00468480 _____ () C:\Users\Miz\Desktop\CKScanner.exe
2014-06-10 17:07 - 2013-11-02 18:36 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-06-10 13:09 - 2012-05-15 00:23 - 00000000 ____D () C:\Program Files (x86)\Diablo III
2014-06-10 04:11 - 2014-06-10 01:52 - 00000000 ____D () C:\Users\Miz\AppData\Local\NVIDIA Corporation
2014-06-10 04:11 - 2012-03-16 09:27 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-06-10 01:51 - 2014-06-10 01:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-06-10 01:51 - 2014-06-10 01:51 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-06-10 01:51 - 2012-03-16 09:27 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-06-10 01:51 - 2012-03-16 09:26 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-06-10 01:37 - 2014-06-10 01:37 - 00293952 _____ () C:\Windows\Minidump\061014-22495-01.dmp
2014-06-08 14:30 - 2014-06-08 14:30 - 00293984 _____ () C:\Windows\Minidump\060814-19999-01.dmp
2014-06-08 12:27 - 2014-06-08 12:27 - 00602112 _____ (OldTimer Tools) C:\Users\Miz\Desktop\OTL.exe
2014-06-08 05:07 - 2012-03-16 11:46 - 00000000 ____D () C:\Users\Miz\AppData\Roaming\Mozilla
2014-06-07 18:59 - 2014-06-07 18:59 - 00291832 _____ () C:\Windows\Minidump\060714-17643-01.dmp
2014-06-07 18:55 - 2014-06-07 18:55 - 00293664 _____ () C:\Windows\Minidump\060714-17565-01.dmp
2014-06-07 18:53 - 2014-06-07 18:52 - 00290840 _____ () C:\Windows\Minidump\060714-21309-01.dmp
2014-06-07 18:50 - 2014-06-07 18:49 - 00294016 _____ () C:\Windows\Minidump\060714-19656-01.dmp
2014-06-05 18:02 - 2012-03-17 03:05 - 00000000 ____D () C:\Program Files (x86)\StarCraft II
2014-06-05 16:32 - 2014-06-05 16:32 - 00293984 _____ () C:\Windows\Minidump\060514-15428-01.dmp
2014-06-05 16:11 - 2012-09-16 03:11 - 00011571 _____ () C:\Windows\system32\lvcoinst.log
2014-06-05 01:31 - 2014-06-05 01:31 - 00293976 _____ () C:\Windows\Minidump\060514-15412-01.dmp
2014-06-04 05:52 - 2014-06-04 05:52 - 00293224 _____ () C:\Windows\Minidump\060414-24991-01.dmp
2014-06-03 13:14 - 2014-06-03 13:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-06-03 13:14 - 2014-06-03 13:13 - 00000000 ____D () C:\Program Files\iTunes
2014-06-03 13:14 - 2014-06-03 13:13 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-06-03 13:13 - 2014-06-03 13:13 - 00000000 ____D () C:\Program Files\iPod
2014-06-03 03:21 - 2014-06-03 03:21 - 00292056 _____ () C:\Windows\Minidump\060314-17643-01.dmp
2014-06-03 03:16 - 2009-07-14 01:08 - 00032654 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-06-03 03:14 - 2014-06-03 03:14 - 00291424 _____ () C:\Windows\Minidump\060314-16957-01.dmp
2014-06-03 03:12 - 2014-06-03 03:12 - 00292568 _____ () C:\Windows\Minidump\060314-19281-01.dmp
2014-06-03 03:09 - 2014-06-03 03:09 - 00291976 _____ () C:\Windows\Minidump\060314-20748-01.dmp
2014-06-03 03:07 - 2014-06-03 03:07 - 00294024 _____ () C:\Windows\Minidump\060314-19593-01.dmp
2014-06-03 02:04 - 2014-06-03 02:04 - 00294008 _____ () C:\Windows\Minidump\060314-19921-01.dmp
2014-06-03 02:01 - 2014-06-03 02:01 - 00292720 _____ () C:\Windows\Minidump\060314-18174-01.dmp
2014-06-01 14:16 - 2014-06-01 14:16 - 00000000 ____D () C:\Users\Miz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Black_Box
2014-05-30 06:21 - 2014-06-11 21:29 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-30 06:02 - 2014-06-11 21:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-30 06:02 - 2014-06-11 21:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-30 05:45 - 2014-06-11 21:29 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-30 05:39 - 2014-06-11 21:29 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-30 05:39 - 2014-06-11 21:29 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-30 05:38 - 2014-06-11 21:29 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-30 05:28 - 2014-06-11 21:29 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-30 05:27 - 2014-06-11 21:29 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-30 05:24 - 2014-06-11 21:29 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-30 05:21 - 2014-06-11 21:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-30 05:21 - 2014-06-11 21:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-30 05:20 - 2014-06-11 21:29 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-30 05:18 - 2014-06-11 21:29 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-30 05:11 - 2014-06-11 21:29 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-30 05:08 - 2014-06-11 21:29 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-30 05:06 - 2014-06-11 21:29 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-30 05:02 - 2014-06-11 21:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-30 04:55 - 2014-06-11 21:29 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-30 04:49 - 2014-06-11 21:29 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-30 04:46 - 2014-06-11 21:29 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-30 04:44 - 2014-06-11 21:29 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-30 04:44 - 2014-06-11 21:29 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-30 04:43 - 2014-06-11 21:29 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-30 04:42 - 2014-06-11 21:29 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-30 04:38 - 2014-06-11 21:29 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-30 04:35 - 2014-06-11 21:29 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-30 04:34 - 2014-06-11 21:29 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-30 04:33 - 2014-06-11 21:29 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-30 04:30 - 2014-06-11 21:29 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-30 04:29 - 2014-06-11 21:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-30 04:28 - 2014-06-11 21:29 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-30 04:27 - 2014-06-11 21:29 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-30 04:24 - 2014-06-11 21:29 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-05-30 04:23 - 2014-06-11 21:29 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-30 04:16 - 2014-06-11 21:29 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-30 04:10 - 2014-06-11 21:29 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-30 04:06 - 2014-06-11 21:29 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-30 04:04 - 2014-06-11 21:29 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-30 04:02 - 2014-06-11 21:29 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-30 03:56 - 2014-06-11 21:29 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-30 03:56 - 2014-06-11 21:29 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-30 03:54 - 2014-06-11 21:29 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-30 03:50 - 2014-06-11 21:29 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-05-30 03:49 - 2014-06-11 21:29 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-30 03:43 - 2014-06-11 21:29 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-30 03:40 - 2014-06-11 21:29 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-30 03:30 - 2014-06-11 21:29 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-30 03:21 - 2014-06-11 21:29 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-30 03:15 - 2014-06-11 21:29 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-30 03:13 - 2014-06-11 21:29 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-30 03:13 - 2014-06-11 21:29 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-29 01:41 - 2014-05-29 01:34 - 00000000 ____D () C:\Users\Miz\AppData\Roaming\Mumble
2014-05-29 01:37 - 2014-05-29 01:37 - 00002378 _____ () C:\Users\Miz\Documents\MumbleAutomaticCertificateBackup.p12
2014-05-29 01:34 - 2014-05-29 01:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mumble
2014-05-29 01:34 - 2014-05-29 01:34 - 00000000 ____D () C:\Program Files (x86)\Mumble
2014-05-28 20:34 - 2014-05-28 20:34 - 00000000 ____D () C:\Users\Miz\AppData\Roaming\IDM
2014-05-28 20:34 - 2014-05-28 20:34 - 00000000 ____D () C:\ProgramData\IDM
2014-05-28 12:29 - 2014-05-28 12:29 - 00000000 ____D () C:\Program Files\Bonjour
2014-05-28 12:29 - 2014-05-28 12:29 - 00000000 ____D () C:\Program Files (x86)\Bonjour
 
==================== Bamital & volsnap Check =================
 
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-06-20 18:23
 

 

==================== End Of Log ============================

  • 0

#65
GhostLoad

GhostLoad

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 419 posts

Addition.txt

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-06-2014
Ran by Miz at 2014-06-24 13:06:20
Running from C:\Users\Miz\Desktop
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
AV: avast! Antivirus (Disabled - Out of date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Out of date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
 
==================== Installed Programs ======================
 
µTorrent (HKCU\...\uTorrent) (Version: 3.4.2.31893 - BitTorrent Inc.)
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
a (HKLM-x32\...\e) (Version: t - s)
Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.1 - Adobe Systems)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 3.1.0.4880 - Adobe Systems Incorporated) Hidden
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 2.6.0.393 - Adobe Systems Incorporated)
Adobe Creative Suite 6 Master Collection (HKLM-x32\...\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}) (Version: 6 - Adobe Systems Incorporated)
Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Help Manager (x32 Version: 4.0.244 - Adobe Systems Incorporated) Hidden
Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
Adobe Media Player (x32 Version: 1.8 - Adobe Systems Incorporated) Hidden
Adobe Reader XI (11.0.06) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.5.635 - Adobe Systems, Inc.)
Adobe Widget Browser (HKLM-x32\...\com.adobe.WidgetBrowser) (Version: 2.0 Build 348 - Adobe Systems Incorporated.)
Adobe Widget Browser (x32 Version: 2.0.348 - Adobe Systems Incorporated.) Hidden
AI Suite II (HKLM-x32\...\{34D3688E-A737-44C5-9E2A-FF73618728E1}) (Version: 1.02.03 - ASUSTeK Computer Inc.)
Altitude 1.1 (HKLM-x32\...\4578-0181-0549-1546) (Version: 1.1 - Nimbly Games)
Apple Application Support (HKLM-x32\...\{D9DAD0FF-495A-472B-9F10-BAE430A26682}) (Version: 3.0.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ARCTIC SOUND P531 (HKLM\...\C-Media CM106 Like Sound Driver) (Version:  - )
Armagetron Advanced 0.2.8.3.2 (HKLM-x32\...\Armagetron Advanced) (Version: 0.2.8.3.2 - Armagetron Advanced Team)
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.10 - Michael Tippach)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\...\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.14.1.0 - Asmedia Technology)
avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2018 - Avast Software)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
bl (x32 Version: 1.0.0 - Your Company Name) Hidden
Bluetooth Win7 Suite (64) (HKLM\...\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.2.0.65 - Atheros Communications)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CDisplay 1.8 (HKLM-x32\...\CDisplay_is1) (Version:  - dvd8n)
Chivalry: Medieval Warfare (HKLM-x32\...\Steam App 219640) (Version:  - Torn Banner Studios)
Combined Community Codec Pack 2011-11-11 (HKLM-x32\...\Combined Community Codec Pack_is1) (Version: 2011.11.11.0 - CCCP Project)
Convert Audio Free FLAC to MP3 version 1.0 (HKLM-x32\...\Convert Audio Free FLAC to MP3_is1) (Version: 1.0 - )
CPUID CPU-Z 1.60 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.48.1.0347 - Disc Soft Ltd)
Dark Souls II (HKLM-x32\...\Dark Souls II_is1) (Version:  - Namco Bandai)
Dark Souls: Prepare to Die Edition (HKLM-x32\...\Steam App 211420) (Version:  - FromSoftware)
Diablo III (HKLM-x32\...\Diablo III) (Version:  - Blizzard Entertainment)
Dota 2 (HKLM-x32\...\Steam App 570) (Version:  - )
Dungeon Defenders (HKLM-x32\...\Steam App 65800) (Version:  - )
eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Firestorm-Release (remove only) (HKLM-x32\...\Firestorm-Release) (Version: 4.6.5.40833 - The Phoenix Firestorm Project, Inc.)
Free Video Flip and Rotate version 2.1.6.128 (HKLM-x32\...\Free Video Flip and Rotate_is1) (Version: 2.1.6.128 - DVDVideoSoft Ltd.)
Futuremark SystemInfo (HKLM-x32\...\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}) (Version: 4.0.0.0 - Futuremark Corporation)
GoldenEye: Source (HKLM-x32\...\GoldenEye: Source) (Version: 4.2 - Team GoldenEye: Source)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.)
Google Talk Plugin (HKLM-x32\...\{C1E3DFE7-4EAD-3E9E-A826-E06055BA5921}) (Version: 5.4.2.18903 - Google)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
Guncraft (HKLM-x32\...\{A7A70E54-4678-4E66-A2BA-F135AAAB70A8}) (Version: 1.07.0.0 - Exato Game Studios)
Hawken (HKCU\...\Hawken) (Version:  - Meteor Entertainment)
HAWKEN (HKLM-x32\...\Steam App 271290) (Version:  - )
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version:  - Blizzard Entertainment)
Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.7.0 - LIGHTNING UK!)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel® Network Connections 15.6.25.0 (HKLM\...\PROSetDX) (Version: 15.6.25.0 - Intel)
Intel® Network Connections 15.6.25.0 (Version: 15.6.25.0 - Intel) Hidden
Intel® Watchdog Timer Driver (Intel® WDT) (HKLM-x32\...\{3FD0C489-0F02-481a-A3E1-9754CD396761}) (Version:  - Intel Corporation)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.32 - Irfan Skiljan)
iTunes (HKLM\...\{5A68A656-979F-4168-8795-E2E368AA4DC2}) (Version: 11.2.2.3 - Apple Inc.)
jass-pub-2.3.8 (remove only) (HKLM-x32\...\jass-pub-2.3.8) (Version:  - )
Java 7 Update 21 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217017FF}) (Version: 7.0.210 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.5 - Sun Microsystems, Inc.) Hidden
JMicron JMB36X Driver (HKLM-x32\...\{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}) (Version: 1.17.58.2 - JMicron Technology Corp.)
League of Legends (HKLM-x32\...\League of Legends 3.0.0) (Version: 3.0.0 - Riot Games)
League of Legends (x32 Version: 3.0.0 - Riot Games) Hidden
License Support (HKLM-x32\...\InstallShield_{3165EA9B-36CC-499B-96FF-36FC30E10EF4}) (Version: 1.2.0.5555 - PACE Anti-Piracy, Inc.)
License Support (Version: 1.2.0.5555 - PACE Anti-Piracy, Inc.) Hidden
Logitech Gaming Software (Version: 8.20.74 - Logitech Inc.) Hidden
Logitech Gaming Software 8.20 (HKLM\...\Logitech Gaming Software) (Version: 8.20.74 - Logitech Inc.)
Logitech SetPoint 6.32 (HKLM\...\sp6) (Version: 6.32.20 - Logitech)
Magic Workstation 0.94f (HKLM-x32\...\Magic Workstation_is1) (Version:  - Magic Technology)
Malwarebytes Anti-Malware version 1.75.0.1300 (HKLM-x32\...\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Access MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Access Setup Metadata MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft DCF MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Excel MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Groove MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft InfoPath MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Lync MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office 32-bit Components 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office OSM MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office OSM UX MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2013 - English (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2013 - Español (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Shared 32-bit MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft OneNote MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Outlook MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft PowerPoint MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Publisher MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20513.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.60610 (Version: 11.0.60610 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (x32 Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (x32 Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Word MUI (English) 2013 (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053 - Adobe) Hidden
Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053 - Adobe) Hidden
Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000 - Adobe) Hidden
Microsoft_VC90_MFCLOC_x86 (x32 Version: 1.00.0000 - Adobe) Hidden
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 30.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 30.0 (x86 en-US)) (Version: 30.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
MTG GamePack for Magic Workstation (HKLM-x32\...\MTG GamePack for Magic Workstation_is1) (Version:  - Magic Technology)
Mumble 1.2.6 (HKLM-x32\...\{461A5021-EE14-4E57-9A06-8ABCE9C38FE4}) (Version: 1.2.6 - Thorvald Natvig)
Nero Burning ROM 11 (HKLM-x32\...\{05A6B1CD-AA10-46A0-8D5C-6AD2A9EEFC8B}) (Version: 11.2.00400 - Nero AG)
Nero Burning ROM 11 (x32 Version: 11.2.10300.0.0 - Nero AG) Hidden
Nero Burning ROM 11 Help (CHM) (x32 Version: 11.0.10300 - Nero AG) Hidden
Nero ControlCenter 11 (x32 Version: 11.0.12700.0.27 - Nero AG) Hidden
Nero ControlCenter 11 Help (CHM) (x32 Version: 11.0.10300 - Nero AG) Hidden
Nero Core Components 11 (x32 Version: 11.0.16300.1.23 - Nero AG) Hidden
Nero RescueAgent 11 (x32 Version: 4.0.10600.10.100 - Nero AG) Hidden
Nero RescueAgent 11 Help (CHM) (x32 Version: 11.0.10400 - Nero AG) Hidden
Nero Update (x32 Version: 11.0.11500.28.0 - Nero AG) Hidden
nero.prerequisites.msi (x32 Version: 11.0.20010 - Nero AG) Hidden
Nexon Game Manager (HKLM-x32\...\{EA2DB6E0-72C5-4ef9-A3A0-E6705F4A6A9E}) (Version:  - )
NVIDIA 3D Vision Controller Driver 337.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 337.88 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 337.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 337.88 - NVIDIA Corporation)
NVIDIA Control Panel 337.88 (Version: 337.88 - NVIDIA Corporation) Hidden
NVIDIA GeForce Experience 2.0.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.0.1 - NVIDIA Corporation)
NVIDIA Graphics Driver 337.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 337.88 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.154.1168 - NVIDIA Corporation) Hidden
NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden
NVIDIA PhysX System Software 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
NVIDIA ShadowPlay 12.4.67 (Version: 12.4.67 - NVIDIA Corporation) Hidden
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.12.6514 - NVIDIA Corporation) Hidden
NVIDIA Update 12.4.67 (Version: 12.4.67 - NVIDIA Corporation) Hidden
NVIDIA Update Core (Version: 12.4.67 - NVIDIA Corporation) Hidden
NVIDIA Virtual Audio 1.2.23 (Version: 1.2.23 - NVIDIA Corporation) Hidden
Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
PdaNet for Android 3.50 (HKLM-x32\...\PdaNet_is1) (Version:  - June Fabrics Technology Inc)
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
PeerBlock 1.1 (r518) (HKLM\...\{015C5B35-B678-451C-9AEE-821E8D69621C}_is1) (Version: 1.1.0.518 - PeerBlock, LLC)
ph (x32 Version: 1.0.0 - Your Company Name) Hidden
Phoenix Viewer 1.6.0.1691 (HKLM-x32\...\{26DB09BC-6EB5-4CE0-A05D-D4DECE60E189}_is1) (Version:  - PhoenixViewer.com)
Photo Gallery (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
PowerISO (HKLM-x32\...\PowerISO) (Version: 5.3 - Power Software Ltd)
Quantum Conundrum Demo (HKLM-x32\...\Steam App 205700) (Version:  - )
QuickTime (HKLM-x32\...\{B67BAFBA-4C9F-48FA-9496-933E3B255044}) (Version: 7.74.80.86 - Apple Inc.)
Radegast (HKLM-x32\...\Radegast) (Version:  - )
RaidCall (HKLM-x32\...\RaidCall) (Version: 7.2.0-1.0.5185.0 - raidcall.com)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6251 - Realtek Semiconductor Corp.)
Remote Control Server (HKLM-x32\...\{755C6515-9FEA-490C-B15E-22BB6519E57E}) (Version: 1.8.0.0 - Steppschuh)
Rogue Legacy (HKLM-x32\...\GOGPACKROGUELEGACY_is1) (Version: 2.1.0.9 - GOG.com)
Rosetta Stone Version 3 (HKLM-x32\...\{80F7CA44-F3A5-4853-8BA6-DDF57CD4F078}) (Version: 3.4.7.0 - Rosetta Stone Ltd.)
Scorched3D 43.3d (HKLM-x32\...\Scorched3D) (Version: 43.3d - Scorched)
Serious Sam: The First Encounter (HKLM-x32\...\{815050E5-F545-11D4-9569-004095812ACC}) (Version:  - )
SHIELD Streaming (Version: 2.1.108 - NVIDIA Corporation) Hidden
Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.)
Smite (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF017}) (Version: 1.0.2107.0 - Hi-Rez Studios)
Source SDK Base 2007 (HKLM-x32\...\Steam App 218) (Version:  - Valve)
Speccy (HKLM\...\Speccy) (Version: 1.26 - Piriform)
Split/Second (HKLM-x32\...\{28526951-55EF-4901-A0CA-B9AC966D1DD1}) (Version: 1.00.0000 - Disney Interactive Studios)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
StarCraft II (HKLM-x32\...\StarCraft II) (Version:  - Blizzard Entertainment)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamViewer 8 (HKLM-x32\...\TeamViewer 8) (Version: 8.0.19617 - TeamViewer)
The Walking Dead (HKLM-x32\...\Steam App 207610) (Version:  - )
Transistor (HKLM-x32\...\Transistor_is1) (Version:  - )
Unity Web Player (HKCU\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Virtual Audio Cable 4.10 (HKLM\...\Virtual Audio Cable 4.10) (Version:  - )
Visual C++ 64-bit Redistributables (HKLM-x32\...\InstallShield_{FB03650C-B373-4B20-ACA5-B7BA1A8EEE33}) (Version: 1.2.0.5555 - PACE Anti-Piracy, Inc.)
Visual C++ 64-bit Redistributables (Version: 1.2.0.5555 - PACE Anti-Piracy, Inc.) Hidden
Visual C++ Redistributables (HKLM-x32\...\InstallShield_{F03117FA-9270-46B0-9666-0B4BC2CDEBF5}) (Version: 1.2.0.5555 - PACE Anti-Piracy, Inc.)
Visual C++ Redistributables (x32 Version: 1.2.0.5555 - PACE Anti-Piracy, Inc.) Hidden
Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies)
Visual Studio 2010 x64 Redistributables (HKLM\...\{21B133D6-5979-47F0-BE1C-F6A6B304693F}) (Version: 13.0.0.1 - AVG Technologies)
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Widevine Media Optimizer Chrome 6.0.0 (HKCU\...\optimizer_chrome) (Version: 6.0.0.12442 - Widevine Technologies)
Widevine Media Optimizer Chrome 6.0.0 (HKLM-x32\...\optimizer_chrome) (Version: 6.0.0.12442 - Widevine Technologies)
Windows Live Communications Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
WinRAR 4.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.11.0 - win.rar GmbH)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version:  - Blizzard Entertainment)
Xfire (remove only) (HKLM-x32\...\Xfire) (Version:  - )
Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
Yahoo! Software Update (HKLM-x32\...\Yahoo! Software Update) (Version:  - )
Yahoo! Toolbar (HKLM-x32\...\Yahoo! Companion) (Version:  - Yahoo! Inc.)
ZBrush 4 (HKLM-x32\...\InstallShield_{4BF62C05-3943-4ECB-B233-6E37E3FB5BCF}) (Version: 4.0 - Pixologic)
ZBrush 4 (x32 Version: 4.0 - Pixologic) Hidden
ZBrush 4R4 (HKLM-x32\...\ZBrush 4R4 4R4) (Version: 4R4 - Pixologic)
 
==================== Restore Points  =========================
 
20-06-2014 18:52:31 Windows Update
24-06-2014 16:31:29 Windows Update
24-06-2014 16:56:49 OTL Restore Point - 6/24/2014 12:56:49 PM
 
==================== Hosts content: ==========================
 
2009-07-13 22:34 - 2014-06-21 19:25 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
Task: {04D1B5D7-8199-4989-9560-3BDAF0EC8071} - System32\Tasks\ASUS\ASUS DigiVRM Help => C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe [2011-04-13] (ASUSTeK Computer Inc.)
Task: {1BC1064B-9385-4C38-A0A7-4C6EC41A2EAF} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {1D53B560-DD0F-418B-A63B-073908C92434} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-13] (Adobe Systems Incorporated)
Task: {2BD4629B-4A83-4D0C-81FE-95D4214EA8DD} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {2C6A7286-68B3-4761-A0D6-66AE43E4F9B8} - System32\Tasks\Core Temp Autostart Miz => C:\Program Files\Core Temp\Core Temp.exe
Task: {36889BFE-9046-45E3-B2AC-B206EEA67060} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-03-16] (Google Inc.)
Task: {42AEAFF4-0A2D-45F8-ABE2-5FAD803BC366} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-04-30] (AVAST Software)
Task: {4CF52559-AB37-4F0A-835B-6C2AB69A5FF8} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1038818363-2529734610-2198295289-1000UA => C:\Users\Miz\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-17] (Google Inc.)
Task: {5BA2AC12-FE19-4C32-835A-38A69CC5D1CF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-03-16] (Google Inc.)
Task: {64161521-FEE8-4D0A-94C4-94623E00A2C8} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1038818363-2529734610-2198295289-1000Core => C:\Users\Miz\AppData\Local\Google\Update\GoogleUpdate.exe [2012-07-17] (Google Inc.)
Task: {652FD5B3-6127-4457-83A4-7A9890469B72} - System32\Tasks\{044C14E6-9F25-48BD-8071-97A618879E2E} => Chrome.exe http://ui.skype.com/...;LastError=1618
Task: {7319FE75-2C02-4F0B-A731-09BA2F0BFF99} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {760651FA-23EE-4C90-A4C8-98A114E9BB17} - System32\Tasks\ASUS\USB 3.0 Boost Service => C:\Program Files (x86)\ASUS\AI Suite II\USB 3.0 Boost\U3BoostSvr.exe [2011-09-09] ()
Task: {7CFCE21C-EAB3-44DF-BACF-B58C83433F2A} - System32\Tasks\AdobeAAMUpdater-1.0-Miz-PC-Miz => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27] (Adobe Systems Incorporated)
Task: {86FD0441-1EB4-46D5-B5DE-CD65DB50C458} - System32\Tasks\ASUS\ASUS AI Suite II Execute => C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe [2010-11-26] (ASUSTeK Computer Inc.)
Task: {A67AD9F1-0CBA-4DF8-B93F-C9CF7DA9ADD8} - System32\Tasks\ASUS\ASUS Mobilink Execute => C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\ASUS Mobilink.exe [2010-11-25] (ASUSTeK Computer Inc.)
Task: {AB582BEF-7DD7-4E9C-9A9F-B3412B92EBC1} - System32\Tasks\Microsoft Office 15 Sync Maintenance for Miz-PC-Miz Miz-PC => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2012-10-01] (Microsoft Corporation)
Task: {C11B0A7C-5382-4716-B65F-1ADD8B23368E} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation)
Task: {D1CC5770-3874-4D7E-992A-198B1F7AB712} - System32\Tasks\PC Meter\Startup => C:\Users\Miz\Desktop\PCMeter\PCMeter.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1038818363-2529734610-2198295289-1000Core.job => C:\Users\Miz\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1038818363-2529734610-2198295289-1000UA.job => C:\Users\Miz\AppData\Local\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) =============
 
2012-03-16 09:27 - 2014-05-19 21:25 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2011-06-13 04:36 - 2011-06-13 04:36 - 00922240 ____R () C:\Program Files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe
2010-12-01 22:15 - 2010-12-01 22:15 - 00915584 ____R () C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe
2012-03-18 08:35 - 2010-10-21 05:52 - 00586880 ____R () C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe
2014-05-23 02:10 - 2014-05-23 02:10 - 00671904 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
2012-10-01 20:36 - 2012-10-01 20:36 - 06522480 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2012-04-26 12:21 - 2012-02-17 20:55 - 00193536 _____ () C:\Program Files\WinRAR\rarext.dll
2014-06-24 12:25 - 2014-06-24 12:25 - 02783744 _____ () C:\Program Files\AVAST Software\Avast\defs\14062400\algo.dll
2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2012-03-18 08:34 - 2014-06-24 12:58 - 00025600 _____ () C:\Program Files (x86)\ASUS\AXSP\1.00.14\PEbiosinterface32.dll
2012-03-18 08:34 - 2010-06-28 22:58 - 00104448 ____R () C:\Program Files (x86)\ASUS\AXSP\1.00.14\ATKEX.dll
2012-03-18 08:36 - 2010-11-25 15:12 - 00086016 _____ () C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\iPhone Simulator\AsNetlib.dll
2012-03-18 08:36 - 2010-11-25 15:12 - 00661504 _____ () C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\iPhone Simulator\aaHMLib.dll
2012-03-18 08:36 - 2010-11-25 15:12 - 00253952 _____ () C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\iPhone Simulator\pngio.dll
2012-03-18 08:36 - 2010-11-25 15:12 - 00208896 _____ () C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\iPhone Simulator\ImageHelper.dll
2012-03-18 08:36 - 2010-11-25 03:12 - 00061440 ____R () C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\AsMultiLang.dll
2012-03-18 08:36 - 2010-11-25 03:12 - 00661504 ____R () C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\aaHMLib.dll
2012-03-18 08:36 - 2010-11-25 03:12 - 00703488 ____R () C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\CpuFreq.dll
2012-03-18 08:36 - 2010-11-25 03:12 - 00114688 ____R () C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\AssistFunc.dll
2012-03-16 08:40 - 2011-03-04 04:33 - 00053248 ____N () C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\HookKey32.dll
2012-03-16 08:40 - 2009-05-21 10:14 - 00253952 _____ () C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\pngio.dll
2012-03-18 08:34 - 2010-08-22 22:17 - 00662016 ____R () C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMLib.dll
2012-03-18 08:35 - 2011-02-24 10:19 - 00143360 _____ () C:\Program Files (x86)\ASUS\AI Suite II\AssistFunc.dll
2012-03-18 08:35 - 2010-06-21 15:21 - 00208896 _____ () C:\Program Files (x86)\ASUS\AI Suite II\ImageHelper.dll
2012-03-18 08:35 - 2009-08-12 20:15 - 00253952 _____ () C:\Program Files (x86)\ASUS\AI Suite II\pngio.dll
2012-03-18 08:36 - 2011-02-09 09:02 - 00873472 _____ () C:\Program Files (x86)\ASUS\AI Suite II\AI Charger+\AIChargerPlus.dll
2012-03-18 08:37 - 2010-10-15 17:40 - 01031680 _____ () C:\Program Files (x86)\ASUS\AI Suite II\ASUS Update\Update.dll
2012-03-18 08:35 - 2011-05-16 17:35 - 00965632 _____ () C:\Program Files (x86)\ASUS\AI Suite II\BarGadget\BarGadget.dll
2012-03-18 08:37 - 2011-01-19 21:23 - 01655296 _____ () C:\Program Files (x86)\ASUS\AI Suite II\Bluetooth Go!\BluetoothGo.dll
2012-03-16 08:39 - 2010-12-01 12:33 - 01244672 _____ () C:\Program Files (x86)\ASUS\AI Suite II\MyLogo\MyLogo.dll
2012-03-16 08:39 - 2011-01-06 10:38 - 01027072 _____ () C:\Program Files (x86)\ASUS\AI Suite II\Probe_II\ProbeII.dll
2012-03-18 08:35 - 2011-05-20 09:12 - 00881152 _____ () C:\Program Files (x86)\ASUS\AI Suite II\Sensor\Sensor.dll
2012-03-18 08:35 - 2011-04-07 17:33 - 01607168 _____ () C:\Program Files (x86)\ASUS\AI Suite II\Sensor Graph\SensorGraph.dll
2012-03-18 08:35 - 2011-01-07 16:39 - 01246208 _____ () C:\Program Files (x86)\ASUS\AI Suite II\Settings\Settings.dll
2012-03-18 08:35 - 2010-08-06 18:11 - 00850944 _____ () C:\Program Files (x86)\ASUS\AI Suite II\Splitter\Splitter.dll
2012-03-18 08:35 - 2010-08-06 18:13 - 00886272 _____ () C:\Program Files (x86)\ASUS\AI Suite II\TabGadget\TabGadget.dll
2012-03-18 08:35 - 2010-06-21 15:21 - 00208896 _____ () C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\ImageHelper.dll
2014-05-20 13:37 - 2012-05-25 04:25 - 00921600 _____ () C:\Program Files (x86)\Yahoo!\Messenger\yui.dll
2014-05-20 13:36 - 2012-05-25 04:25 - 00078336 _____ () C:\Program Files (x86)\Yahoo!\Messenger\pcre.dll
2012-10-01 20:37 - 2012-10-01 20:37 - 06522480 _____ () C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2014-04-30 12:25 - 2014-04-30 12:25 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-06-12 07:01 - 2014-06-05 09:58 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\libglesv2.dll
2014-06-12 07:01 - 2014-06-05 09:58 - 00126280 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\libegl.dll
2014-06-12 07:01 - 2014-06-05 09:58 - 04217672 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\pdf.dll
2014-06-12 07:01 - 2014-06-05 09:58 - 00414536 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\ppGoogleNaClPluginChrome.dll
2014-06-12 07:01 - 2014-06-05 09:58 - 01732424 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\ffmpegsumo.dll
2014-05-21 16:39 - 2014-04-29 20:08 - 01135104 _____ () C:\Program Files (x86)\Steam\libavcodec-55.dll
2014-04-23 04:39 - 2014-04-29 20:08 - 00471552 _____ () C:\Program Files (x86)\Steam\libavutil-53.dll
2014-05-21 16:39 - 2014-04-29 20:08 - 00404992 _____ () C:\Program Files (x86)\Steam\libavformat-55.dll
2014-01-08 05:47 - 2014-04-29 20:08 - 00340992 _____ () C:\Program Files (x86)\Steam\libavresample-1.dll
2013-03-12 17:10 - 2014-05-16 21:36 - 00756224 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2014-05-21 16:39 - 2014-05-29 13:37 - 02139840 _____ () C:\Program Files (x86)\Steam\video.dll
2014-05-21 16:39 - 2014-04-28 20:37 - 00519168 _____ () C:\Program Files (x86)\Steam\libswscale-2.dll
2012-09-09 12:09 - 2014-05-29 13:36 - 01116864 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2012-09-09 12:09 - 2014-05-01 19:35 - 20628160 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
2012-09-09 12:09 - 2013-06-14 19:49 - 01100800 _____ () C:\Program Files (x86)\Steam\bin\avcodec-53.dll
2012-09-09 12:09 - 2013-06-14 19:49 - 00124416 _____ () C:\Program Files (x86)\Steam\bin\avutil-51.dll
2012-09-09 12:09 - 2013-06-14 19:49 - 00192000 _____ () C:\Program Files (x86)\Steam\bin\avformat-53.dll
2014-06-12 07:01 - 2014-06-05 09:58 - 14612296 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\PepperFlash\pepflashplayer.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
AlternateDataStreams: C:\Users\Miz\AppData\Local\Temporary Internet Files:7u0WhrXaHzIqGRTnCVUHU3ME
 
==================== Safe Mode (whitelisted) ===================
 
 
==================== EXE Association (whitelisted) =============
 
 
==================== MSCONFIG/TASK MANAGER disabled items =========
 
MSCONFIG\startupfolder: C:^Users^Miz^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Core Temp.lnk => C:\Windows\pss\Core Temp.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Miz^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^PdaNet Desktop.lnk => C:\Windows\pss\PdaNet Desktop.lnk.Startup
MSCONFIG\startupreg: Acrobat Assistant 8.0 => "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
MSCONFIG\startupreg: Adobe Acrobat Speed Launcher => "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: AdobeCS5ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: AdobeCS6ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: Advanced SystemCare 6 => "C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCTray.exe" /AutoStart
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: ASUS AiChargerPlus Execute => C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
MSCONFIG\startupreg: ASUS ShellProcess Execute => C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\AsShellProcess.exe
MSCONFIG\startupreg: AthBtTray => "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
MSCONFIG\startupreg: AtherosBtStack => "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
MSCONFIG\startupreg: AVG_UI => "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
MSCONFIG\startupreg: Cm106Sound => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm106.dll,CMICtrlWnd
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: EvtMgr6 => C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
MSCONFIG\startupreg: Google Update => "C:\Users\Miz\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: GoogleChromeAutoLaunch_D30BA0C625A5A2A6D1452AE610495547 => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: JMB36X IDE Setup => C:\Windows\RaidTool\xInsIDE.exe
MSCONFIG\startupreg: Launch LCore => C:\Program Files\Logitech Gaming Software\LCore.exe /minimized
MSCONFIG\startupreg: Messenger (Yahoo!) => "C:\PROGRA~2\Yahoo!\Messenger\YahooMessenger.exe" -quiet
MSCONFIG\startupreg: NvBackend => "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RaidCall => C:\Program Files (x86)\RaidCall\raidcall.exe
MSCONFIG\startupreg: Remote Control Server => C:\Program Files (x86)\Remote Control Server\Remote Control Server.exe
MSCONFIG\startupreg: ROC_ROC_APR2013_AV => C:\Users\Miz\AppData\Roaming\AVG April 2013 Campaign\AVG-Secure-Search-Update.exe /PROMPT --mid 014049c4a18547d0a6a5d16fc5d8e3d2-a0d6eb6e8b357088b298aee1fbe985bc07685bbf --CMPID ROC_APR2013_AV --CMPIDEXTRA 2013
MSCONFIG\startupreg: ShadowPlay => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: SwitchBoard => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
MSCONFIG\startupreg: Unified Remote v2 => C:\Program Files (x86)\Unified Remote\RemoteServer.exe
MSCONFIG\startupreg: uTorrent => "C:\Users\Miz\AppData\Roaming\uTorrent\uTorrent.exe"  /MINIMIZED
 
==================== Faulty Device Manager Devices =============
 
Name: Bluetooth Peripheral Device
Description: Bluetooth Peripheral Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Bluetooth Peripheral Device
Description: Bluetooth Peripheral Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Bluetooth Peripheral Device
Description: Bluetooth Peripheral Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Bluetooth Peripheral Device
Description: Bluetooth Peripheral Device
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (06/24/2014 03:32:56 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
 
Error: (06/23/2014 04:44:10 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
 
Error: (06/22/2014 04:43:42 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
 
Error: (06/22/2014 04:34:15 AM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcNvVAD initialization failed [6]
 
Error: (06/22/2014 04:34:15 AM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]
 
Error: (06/22/2014 04:34:13 AM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcNvVAD endpoint registration failed [0]
 
Error: (06/21/2014 08:11:20 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program AI Suite II.exe version 1.0.0.40 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1a7c
 
Start Time: 01cf8dadfdc229f6
 
Termination Time: 1
 
Application Path: C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
 
Report Id: b53cf895-f9a1-11e3-bcba-c86000307b32
 
Error: (06/21/2014 03:46:31 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
 
Error: (06/20/2014 04:44:18 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
 
Error: (06/20/2014 04:40:27 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program AlertHelper.exe version 1.0.0.5 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: e78
 
Start Time: 01cf8c632737cf88
 
Termination Time: 1
 
Application Path: C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
 
Report Id: 7b0eb838-f856-11e3-85d1-0026833c0a21
 
 
System errors:
=============
Error: (06/24/2014 01:01:38 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Peer Name Resolution Protocol service terminated with the following error: 
%%-2140993535
 
Error: (06/24/2014 01:01:38 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Peer Networking Grouping service depends on the Peer Name Resolution Protocol service which failed to start because of the following error: 
%%-2140993535
 
Error: (06/24/2014 01:01:38 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Peer Name Resolution Protocol service terminated with the following error: 
%%-2140993535
 
Error: (06/24/2014 01:01:38 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Peer Networking Grouping service depends on the Peer Name Resolution Protocol service which failed to start because of the following error: 
%%-2140993535
 
Error: (06/24/2014 01:01:38 PM) (Source: PNRPSvc) (EventID: 102) (User: )
Description: 0x80630801
 
Error: (06/24/2014 01:01:38 PM) (Source: PNRPSvc) (EventID: 102) (User: )
Description: 0x80630801
 
Error: (06/24/2014 01:01:29 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Peer Name Resolution Protocol service terminated with the following error: 
%%-2140993535
 
Error: (06/24/2014 01:01:29 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Peer Networking Grouping service depends on the Peer Name Resolution Protocol service which failed to start because of the following error: 
%%-2140993535
 
Error: (06/24/2014 01:01:29 PM) (Source: PNRPSvc) (EventID: 102) (User: )
Description: 0x80630801
 
Error: (06/24/2014 00:57:57 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Peer Name Resolution Protocol service terminated with the following error: 
%%-2140993535
 
 
Microsoft Office Sessions:
=========================
Error: (06/24/2014 03:32:56 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
 
Error: (06/23/2014 04:44:10 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
 
Error: (06/22/2014 04:43:42 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
 
Error: (06/22/2014 04:34:15 AM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcNvVAD initialization failed [6]
 
Error: (06/22/2014 04:34:15 AM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcFailed to set NvVAD endpoint as default Audio endpoint [0]
 
Error: (06/22/2014 04:34:13 AM) (Source: NvStreamSvc) (EventID: 1) (User: )
Description: NvStreamSvcNvVAD endpoint registration failed [0]
 
Error: (06/21/2014 08:11:20 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: AI Suite II.exe1.0.0.401a7c01cf8dadfdc229f61C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exeb53cf895-f9a1-11e3-bcba-c86000307b32
 
Error: (06/21/2014 03:46:31 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
 
Error: (06/20/2014 04:44:18 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Subscription licensing service failed: -1073418154
 
Error: (06/20/2014 04:40:27 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: AlertHelper.exe1.0.0.5e7801cf8c632737cf881C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe7b0eb838-f856-11e3-85d1-0026833c0a21
 
 
==================== Memory info =========================== 
 
Percentage of memory in use: 20%
Total physical RAM: 16351.14 MB
Available physical RAM: 13051.82 MB
Total Pagefile: 32700.46 MB
Available Pagefile: 29087.02 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:931.41 GB) (Free:416.2 GB) NTFS
Drive d: () (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive f: () (Fixed) (Total:931.41 GB) (Free:430.17 GB) NTFS
Drive l: (DIABLO II) (Removable) (Total:3.73 GB) (Free:2.41 GB) FAT32
Drive m: (Seagate Expansion Drive) (Fixed) (Total:1863.01 GB) (Free:1160.75 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 90777CAD)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 570EA1E3)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS)
 
========================================================
Disk: 6 (MBR Code: Windows XP) (Size: 4 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=4 GB) - (Type=0B)
Attempted reading MBR returned 0 bytes.
 Could not read MBR for disk 7.
 

 

==================== End Of Log ============================

  • 0

#66
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts

Hi,

 

We will proceed with ComboFix.

 

This is a very powerful tool that should be used only if advised by Malware Analyst.
Do not run ComboFix on your own!


Please read carefully the instruction located here.
Next download ComboFix by sUBs and save it to your Desktop.

  • Make sure that all your antivirus programs ale switched off.
    If you don't know how to do it, take a look at this topic.
     
  • Save your work and close any open applications.
     
  • Run ComboFix by right-clicking the 51a5bf3d99e8a-ComboFixlogo16.png icon and choosing Run as Administrator.
    (Users of Windows XP please just double-click).
     
  • Please read through the disclaimer and agree to it.
     
  • This part is for Windows XP users only:
    Please agree when prompted to install the Recovery Console!
     
  • ComboFix will start it's scanning. Do not mouse-click, it may cause ComboFix to stall.

    NSIS_extraction.png

    still-scanning-clockchanges.jpg
     
  • When ComboFix has finished, it will automatically close the program and then display the log file automatically.
     
  • Post this log as a reply to this topic.

icon_idea.gif If you'll encounter any issues with internet connection after running ComboFix, please visit this link.
icon_idea.gif If an error about operation on the key marked for deletion will appear after running the tool, please reboot your machine.

 

Regards,

Naat


  • 0

#67
GhostLoad

GhostLoad

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 419 posts

I sure hope we're making progress.  >.<

 

I'll do this as soon as I get home (like an hour).


  • 0

#68
GhostLoad

GhostLoad

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 419 posts

Combofix.txt

 

ComboFix 14-06-24.01 - Miz 06/25/2014  12:52:44.1.4 - x64

Microsoft Windows 7 Ultimate   6.1.7601.1.1252.1.1033.18.16351.12953 [GMT -4:00]
Running from: c:\users\Miz\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Outdated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Outdated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\program files (x86)\Java\jre7\bin\jp2ssv.dll
c:\windows\ico.ico
c:\windows\wininit.ini
M:\Autorun.inf
M:\Setup.exe
.
.
(((((((((((((((((((((((((   Files Created from 2014-05-25 to 2014-06-25  )))))))))))))))))))))))))))))))
.
.
28193-05-05 19:18 . 2014-06-15 21:34 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\CrashDumps
2014-06-25 17:08 . 2014-06-25 17:08 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-06-24 16:56 . 2014-06-24 16:56 -------- d-----w- C:\_OTL
2014-06-24 16:32 . 2014-06-05 10:54 10779000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F4E690FC-835B-47CA-8DAD-E633CCA6E36A}\mpengine.dll
2014-06-22 20:11 . 2014-06-22 20:11 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-06-18 17:49 . 2014-06-18 17:49 -------- d-sh--w- c:\users\Miz\AppData\Local\EmieUserList
2014-06-18 17:49 . 2014-06-18 17:49 -------- d-sh--w- c:\users\Miz\AppData\Local\EmieSiteList
2014-06-18 17:43 . 2014-06-18 17:43 -------- d-----r- c:\users\Miz\Creative Cloud Files
2014-06-17 17:11 . 2014-06-18 08:22 -------- d-----w- c:\program files (x86)\Transistor
2014-06-12 01:14 . 2014-04-05 02:47 1903552 ----a-w- c:\windows\system32\drivers\tcpip.sys
2014-06-12 01:14 . 2014-04-05 02:47 288192 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2014-06-12 01:10 . 2014-04-25 02:34 801280 ----a-w- c:\windows\system32\usp10.dll
2014-06-12 01:10 . 2014-04-25 02:06 626688 ----a-w- c:\windows\SysWow64\usp10.dll
2014-06-12 01:10 . 2014-03-26 14:44 2002432 ----a-w- c:\windows\system32\msxml6.dll
2014-06-12 01:10 . 2014-03-26 14:44 1882112 ----a-w- c:\windows\system32\msxml3.dll
2014-06-12 01:10 . 2014-03-26 14:27 1389056 ----a-w- c:\windows\SysWow64\msxml6.dll
2014-06-12 01:10 . 2014-03-26 14:41 2048 ----a-w- c:\windows\system32\msxml6r.dll
2014-06-12 01:10 . 2014-03-26 14:27 1237504 ----a-w- c:\windows\SysWow64\msxml3.dll
2014-06-12 01:10 . 2014-03-26 14:25 2048 ----a-w- c:\windows\SysWow64\msxml6r.dll
2014-06-12 01:10 . 2014-03-26 14:41 2048 ----a-w- c:\windows\system32\msxml3r.dll
2014-06-12 01:10 . 2014-03-26 14:25 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll
2014-06-12 01:09 . 2014-05-08 09:32 3178496 ----a-w- c:\windows\system32\rdpcorets.dll
2014-06-12 01:09 . 2014-05-08 09:32 16384 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2014-06-11 09:19 . 2014-06-11 09:19 -------- d-----w- C:\MGADiagToolOutput
2014-06-11 09:19 . 2014-06-11 09:19 -------- d-----w- c:\programdata\Office Genuine Advantage
2014-06-10 16:57 . 2014-06-24 17:07 -------- d-----w- C:\FRST
2014-06-10 05:52 . 2014-06-10 08:11 -------- d-----w- c:\users\Miz\AppData\Local\NVIDIA Corporation
2014-06-10 05:51 . 2014-04-30 18:27 1081112 ----a-w- c:\windows\SysWow64\nvspcap.dll
2014-06-10 05:51 . 2014-04-30 18:26 1225920 ----a-w- c:\windows\system32\nvspcap64.dll
2014-06-10 05:51 . 2014-06-10 05:51 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2014-06-10 05:50 . 2014-05-19 23:10 601432 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2014-06-10 05:45 . 2014-03-31 16:42 40392 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2014-06-10 05:45 . 2014-03-31 16:42 37320 ----a-w- c:\windows\system32\nvaudcap64v.dll
2014-06-10 05:45 . 2014-03-31 16:42 34760 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2014-06-03 17:13 . 2014-06-03 17:13 -------- d-----w- c:\program files\iPod
2014-06-03 17:13 . 2014-06-03 17:14 -------- d-----w- c:\program files\iTunes
2014-06-03 17:13 . 2014-06-03 17:14 -------- d-----w- c:\program files (x86)\iTunes
2014-05-29 05:34 . 2014-05-29 05:41 -------- d-----w- c:\users\Miz\AppData\Roaming\Mumble
2014-05-29 05:34 . 2014-05-29 05:34 -------- d-----w- c:\program files (x86)\Mumble
2014-05-29 00:34 . 2014-05-29 00:34 -------- d-----w- c:\programdata\IDM
2014-05-29 00:34 . 2014-05-29 00:34 -------- d-----w- c:\users\Miz\AppData\Roaming\IDM
2014-05-28 16:29 . 2014-05-28 16:29 -------- d-----w- c:\program files\Bonjour
2014-05-28 16:29 . 2014-05-28 16:29 -------- d-----w- c:\program files (x86)\Bonjour
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-06-13 09:55 . 2014-04-30 16:58 95414520 ----a-w- c:\windows\system32\MRT.exe
2014-05-20 02:44 . 2012-08-03 09:38 2730208 ----a-w- c:\windows\SysWow64\nvapi.dll
2014-05-20 02:44 . 2012-03-16 13:27 952952 ----a-w- c:\windows\system32\nvumdshimx.dll
2014-05-20 02:44 . 2012-03-16 13:27 3109248 ----a-w- c:\windows\system32\nvapi64.dll
2014-05-20 02:44 . 2012-03-16 13:27 18531568 ----a-w- c:\windows\system32\nvwgf2umx.dll
2014-05-20 02:44 . 2012-03-16 13:27 1515296 ----a-w- c:\windows\system32\nvhdagenco6420103.dll
2014-05-20 02:44 . 2012-03-16 13:27 14434704 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2014-05-20 01:25 . 2012-03-16 13:27 6769096 ----a-w- c:\windows\system32\nvcpl.dll
2014-05-20 01:25 . 2012-03-16 13:27 3514144 ----a-w- c:\windows\system32\nvsvc64.dll
2014-05-20 01:25 . 2012-03-16 13:27 927520 ----a-w- c:\windows\system32\nvvsvc.exe
2014-05-20 01:25 . 2012-03-16 13:27 62808 ----a-w- c:\windows\system32\nvshext.dll
2014-05-20 01:25 . 2012-03-16 13:27 387528 ----a-w- c:\windows\system32\nvmctray.dll
2014-05-15 16:41 . 2014-04-30 16:26 85328 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-05-15 16:41 . 2014-04-30 16:26 1039096 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-05-15 16:41 . 2014-04-30 16:25 423240 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-05-14 23:49 . 2012-03-16 13:27 3774821 ----a-w- c:\windows\system32\nvcoproc.bin
2014-05-13 20:02 . 2012-08-14 18:46 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-05-13 20:02 . 2012-03-16 15:47 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-04-30 21:58 . 2014-04-30 21:58 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2014-04-30 21:58 . 2014-04-30 21:58 942592 ----a-w- c:\windows\system32\jsIntl.dll
2014-04-30 21:58 . 2014-04-30 21:58 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-04-30 21:58 . 2014-04-30 21:58 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2014-04-30 21:58 . 2014-04-30 21:58 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2014-04-30 21:58 . 2014-04-30 21:58 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2014-04-30 21:58 . 2014-04-30 21:58 81408 ----a-w- c:\windows\system32\icardie.dll
2014-04-30 21:58 . 2014-04-30 21:58 774144 ----a-w- c:\windows\system32\jscript.dll
2014-04-30 21:58 . 2014-04-30 21:58 77312 ----a-w- c:\windows\system32\tdc.ocx
2014-04-30 21:58 . 2014-04-30 21:58 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2014-04-30 21:58 . 2014-04-30 21:58 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2014-04-30 21:58 . 2014-04-30 21:58 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2014-04-30 21:58 . 2014-04-30 21:58 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2014-04-30 21:58 . 2014-04-30 21:58 62464 ----a-w- c:\windows\system32\pngfilt.dll
2014-04-30 21:58 . 2014-04-30 21:58 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2014-04-30 21:58 . 2014-04-30 21:58 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2014-04-30 21:58 . 2014-04-30 21:58 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2014-04-30 21:58 . 2014-04-30 21:58 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2014-04-30 21:58 . 2014-04-30 21:58 48640 ----a-w- c:\windows\system32\mshtmler.dll
2014-04-30 21:58 . 2014-04-30 21:58 48128 ----a-w- c:\windows\system32\imgutil.dll
2014-04-30 21:58 . 2014-04-30 21:58 413696 ----a-w- c:\windows\system32\html.iec
2014-04-30 21:58 . 2014-04-30 21:58 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2014-04-30 21:58 . 2014-04-30 21:58 337408 ----a-w- c:\windows\SysWow64\html.iec
2014-04-30 21:58 . 2014-04-30 21:58 30208 ----a-w- c:\windows\system32\licmgr10.dll
2014-04-30 21:58 . 2014-04-30 21:58 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2014-04-30 21:58 . 2014-04-30 21:58 247808 ----a-w- c:\windows\system32\msls31.dll
2014-04-30 21:58 . 2014-04-30 21:58 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2014-04-30 21:58 . 2014-04-30 21:58 243200 ----a-w- c:\windows\system32\webcheck.dll
2014-04-30 21:58 . 2014-04-30 21:58 235520 ----a-w- c:\windows\system32\url.dll
2014-04-30 21:58 . 2014-04-30 21:58 235008 ----a-w- c:\windows\system32\elshyph.dll
2014-04-30 21:58 . 2014-04-30 21:58 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2014-04-30 21:58 . 2014-04-30 21:58 167424 ----a-w- c:\windows\system32\iexpress.exe
2014-04-30 21:58 . 2014-04-30 21:58 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2014-04-30 21:58 . 2014-04-30 21:58 147968 ----a-w- c:\windows\system32\occache.dll
2014-04-30 21:58 . 2014-04-30 21:58 143872 ----a-w- c:\windows\system32\wextract.exe
2014-04-30 21:58 . 2014-04-30 21:58 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2014-04-30 21:58 . 2014-04-30 21:58 13824 ----a-w- c:\windows\system32\mshta.exe
2014-04-30 21:58 . 2014-04-30 21:58 135680 ----a-w- c:\windows\system32\iepeers.dll
2014-04-30 21:58 . 2014-04-30 21:58 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2014-04-30 21:58 . 2014-04-30 21:58 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2014-04-30 21:58 . 2014-04-30 21:58 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2014-04-30 21:58 . 2014-04-30 21:58 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2014-04-30 21:58 . 2014-04-30 21:58 105984 ----a-w- c:\windows\system32\iesysprep.dll
2014-04-30 21:58 . 2014-04-30 21:58 101376 ----a-w- c:\windows\system32\inseng.dll
2014-04-30 17:18 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2014-04-30 17:18 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2014-04-30 16:25 . 2014-04-30 16:26 208416 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-04-30 16:25 . 2014-04-30 16:25 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-04-30 16:25 . 2014-04-30 16:25 79184 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-04-30 16:25 . 2014-04-30 16:25 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-04-30 16:25 . 2014-04-30 16:25 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-04-30 16:25 . 2014-04-30 16:25 334648 ----a-w- c:\windows\system32\aswBoot.exe
2014-04-30 16:25 . 2014-04-30 16:25 43152 ----a-w- c:\windows\avastSS.scr
2014-04-20 04:29 . 2014-04-20 04:29 2962432 ----a-r- c:\users\Miz\AppData\Roaming\Microsoft\Installer\{A7A70E54-4678-4E66-A2BA-F135AAAB70A8}\StartMenuIcon.exe
2014-04-20 04:29 . 2014-04-20 04:29 2962432 ----a-r- c:\users\Miz\AppData\Roaming\Microsoft\Installer\{A7A70E54-4678-4E66-A2BA-F135AAAB70A8}\DesktopIcon.exe
2014-04-14 02:24 . 2014-04-30 18:43 465408 ----a-w- c:\windows\system32\aepdu.dll
2014-04-14 02:19 . 2014-04-30 18:43 424448 ----a-w- c:\windows\system32\aeinv.dll
2014-04-12 19:51 . 2014-04-12 19:51 16896 ----a-w- c:\windows\AsTaskSched.dll
2014-04-12 02:22 . 2014-05-15 04:45 155072 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2014-04-12 02:22 . 2014-05-15 04:45 95680 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2014-04-12 02:19 . 2014-05-15 04:45 29184 ----a-w- c:\windows\system32\sspisrv.dll
2014-04-12 02:19 . 2014-05-15 04:45 136192 ----a-w- c:\windows\system32\sspicli.dll
2014-04-12 02:19 . 2014-05-15 04:45 28160 ----a-w- c:\windows\system32\secur32.dll
2014-04-12 02:19 . 2014-05-15 04:45 1460736 ----a-w- c:\windows\system32\lsasrv.dll
2014-04-12 02:19 . 2014-05-15 04:45 31232 ----a-w- c:\windows\system32\lsass.exe
2014-04-12 02:12 . 2014-05-15 04:45 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2014-04-12 02:10 . 2014-05-15 04:45 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2014-03-31 13:35 . 2014-04-30 16:57 270496 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll" [2014-02-11 1565464]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2012-10-02 00:38 1720976 ----a-w- c:\progra~2\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2012-10-02 00:38 1720976 ----a-w- c:\progra~2\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2012-10-02 00:38 1720976 ----a-w- c:\progra~2\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2014-05-29 1754816]
"Messenger (Yahoo!)"="c:\program files (x86)\Yahoo!\Messenger\YahooMessenger.exe" [2012-05-25 6595928]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2014-05-08 21444224]
"GoogleChromeAutoLaunch_D30BA0C625A5A2A6D1452AE610495547"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2014-06-05 860488]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-04-30 3873704]
"Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2014-05-26 2688920]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2014-05-26 152392]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys;c:\windows\SYSNATIVE\Drivers\androidusb.sys [x]
R3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\System32\DRIVERS\ASPI32.sys;c:\windows\SYSNATIVE\DRIVERS\ASPI32.sys [x]
R3 ATHDFU;Atheros Valkyrie USB BootROM;c:\windows\system32\Drivers\AthDfu.sys;c:\windows\SYSNATIVE\Drivers\AthDfu.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys;c:\windows\SYSNATIVE\DRIVERS\pneteth.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 AiChargerPlus;ASUS Charger Plus Driver;c:\windows\system32\DRIVERS\AiChargerPlus.sys;c:\windows\SYSNATIVE\DRIVERS\AiChargerPlus.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys;SysWow64\drivers\AsUpIO.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe;c:\program files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe [x]
S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe;c:\program files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [x]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys;c:\windows\SYSNATIVE\drivers\cpuz135_x64.sys [x]
S2 DigiNet;Digidesign Ethernet Support;c:\windows\system32\DRIVERS\diginet.sys;c:\windows\SYSNATIVE\DRIVERS\diginet.sys [x]
S2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe;c:\windows\SYSNATIVE\IProsetMonitor.exe [x]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 PaceLicenseDServices;PACE License Services;c:\program files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe;c:\program files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x]
S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [x]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys;c:\windows\SYSNATIVE\DRIVERS\asmthub3.sys [x]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys;c:\windows\SYSNATIVE\DRIVERS\asmtxhci.sys [x]
S3 ASUSFILTER;ASUSFILTER;SysWow64\drivers\ASUSFILTER.sys;SysWow64\drivers\ASUSFILTER.sys [x]
S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys;c:\windows\SYSNATIVE\DRIVERS\btath_bus.sys [x]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_hcrp.sys [x]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_rcp.sys [x]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
S3 CompFilter64;UVCCompositeFilter;c:\windows\system32\DRIVERS\lvbflt64.sys;c:\windows\SYSNATIVE\DRIVERS\lvbflt64.sys [x]
S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys;c:\windows\SYSNATIVE\DRIVERS\vrtaucbl.sys [x]
S3 ICCWDT;Intel® Watchdog Timer Driver (Intel® WDT);c:\windows\system32\DRIVERS\ICCWDT.sys;c:\windows\SYSNATIVE\DRIVERS\ICCWDT.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]
S3 LVUVC64;Logitech HD Webcam C510(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 pnetmdm;PdaNet Modem;c:\windows\system32\DRIVERS\pnetmdm64.sys;c:\windows\SYSNATIVE\DRIVERS\pnetmdm64.sys [x]
S3 USBMULCD;USB Multi-Channel Audio Device Interface;c:\windows\system32\drivers\CM10664.sys;c:\windows\SYSNATIVE\drivers\CM10664.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-06-12 10:59 1091912 ----a-w- c:\program files (x86)\Google\Chrome\Application\35.0.1916.153\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-06-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-14 20:02]
.
2014-06-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-16 12:45]
.
2014-06-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-16 12:45]
.
2014-06-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1038818363-2529734610-2198295289-1000Core.job
- c:\users\Miz\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-14 08:01]
.
2014-06-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1038818363-2529734610-2198295289-1000UA.job
- c:\users\Miz\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-14 08:01]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1]
@="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}"
[HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}]
2014-05-23 06:10 671904 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2]
@="{853B7E05-C47D-4985-909A-D0DC5C6D7303}"
[HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}]
2014-05-23 06:10 671904 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3]
@="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}"
[HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}]
2014-05-23 06:10 671904 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2012-10-02 00:37 2322576 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2012-10-02 00:37 2322576 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2012-10-02 00:37 2322576 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-04-30 16:25 290888 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-19 11613288]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2014-02-28 558496]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = localhost; 127.0.0.1; <local>;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office15\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office15\ONBttnIE.dll/105
TCP: DhcpNameServer = 65.32.5.111 65.32.5.112
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
FF - ProfilePath - c:\users\Miz\AppData\Roaming\Mozilla\Firefox\Profiles\gkl27u1m.default\
FF - prefs.js: browser.startup.homepage - google.com
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
.
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-e - c:\programdata\bitraider\brwc.exe
AddRemove-Fallout Tactics - c:\gog games\Fallout Tactics\unins000.exe
AddRemove-Steam App 205700 - e:\program files\Steam\steam.exe
AddRemove-Steam App 65800 - e:\program files\Steam\steam.exe
AddRemove-{3C6054C0-A1E7-BB16-DFA5-56BBDADAFDE6} - c:\progra~3\INSTAL~1\{0C689~1\Setup.exe
AddRemove-{B14AF48B-6324-6D1C-0A89-009B4851535E} - c:\progra~3\INSTAL~1\{770B5~1\Setup.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1038818363-2529734610-2198295289-1000\Software\SecuROM\License information*]
"datasecu"=hex:9b,b5,49,f3,14,44,9b,71,80,27,21,e7,a4,1a,91,d0,45,cf,80,98,0f,
   72,98,7d,07,84,6b,63,f5,9e,1b,cf,d8,18,55,13,40,ad,16,51,3a,c6,19,d9,09,9a,\
"rkeysecu"=hex:db,d8,3f,21,a6,43,db,fa,56,c5,e1,83,30,1d,68,85
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.13"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2014-06-25  13:10:48
ComboFix-quarantined-files.txt  2014-06-25 17:10
.
Pre-Run: 445,591,588,864 bytes free
Post-Run: 445,423,063,040 bytes free
.
- - End Of File - - 6A807D672DF61C99E730E5735011BE98
A36C5E4F47E84449FF07ED3517B43A31

  • 0

#69
GhostLoad

GhostLoad

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 419 posts

Looks like Windows Defender was active at the time (I didn't even know it was running).  Should I do it again or is it fine?


  • 0

#70
GhostLoad

GhostLoad

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 419 posts

Okay so I just had a BSOD.  Wasn't able to take a picture of the blue screen before it went away though.


  • 0

Advertisements


#71
Naathim

Naathim

    GeekU Minion

  • Expert
  • 4,568 posts
We'll proceed with ComboFix.
  • Close any open browsers.
  • Close/disable all antivirus and antimalware programs so they do not interfere with the running of ComboFix.
    If you don't know how to do it, take a look at this topic.
  • Push both Windows and R buttons - this will start the "Run" window.
    Type in notepad.exe and press Enter
  • Copy the text in the codebox below and paste it into the notepad:
    ADS::
    C:\Users\Miz\AppData\Local\Temporary Internet Files
    
  • Save this as CFScript, in the same location as ComboFix.exe.
  • Refering to the picture below, drag CFScript into ComboFix.exe:
    CFScriptB-4.gif 
     
    This will run ComboFix.
icon_arrow.gif When finished, it shall produce a log for you at C:\ComboFix.txt. Please post this log in your next reply.
  • 0

#72
GhostLoad

GhostLoad

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 419 posts

Log.txt

 

ComboFix 14-06-27.01 - Miz 06/27/2014   4:57.2.4 - x64
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.1.1033.18.16351.13151 [GMT -4:00]
Running from: c:\users\Miz\Desktop\ComboFix.exe
Command switches used :: c:\users\Miz\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((   Files Created from 2014-05-27 to 2014-06-27  )))))))))))))))))))))))))))))))
.
.
28193-05-05 19:18 . 2014-06-15 21:34 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\CrashDumps
2014-06-27 09:13 . 2014-06-27 09:13 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2014-06-27 09:13 . 2014-06-27 09:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-06-24 16:56 . 2014-06-24 16:56 -------- d-----w- C:\_OTL
2014-06-24 16:32 . 2014-06-05 10:54 10779000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F4E690FC-835B-47CA-8DAD-E633CCA6E36A}\mpengine.dll
2014-06-22 20:11 . 2014-06-22 20:11 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-06-18 17:49 . 2014-06-18 17:49 -------- d-sh--w- c:\users\Miz\AppData\Local\EmieUserList
2014-06-18 17:49 . 2014-06-18 17:49 -------- d-sh--w- c:\users\Miz\AppData\Local\EmieSiteList
2014-06-18 17:43 . 2014-06-18 17:43 -------- d-----r- c:\users\Miz\Creative Cloud Files
2014-06-17 17:11 . 2014-06-18 08:22 -------- d-----w- c:\program files (x86)\Transistor
2014-06-12 01:14 . 2014-04-05 02:47 1903552 ----a-w- c:\windows\system32\drivers\tcpip.sys
2014-06-12 01:14 . 2014-04-05 02:47 288192 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2014-06-12 01:10 . 2014-04-25 02:34 801280 ----a-w- c:\windows\system32\usp10.dll
2014-06-12 01:10 . 2014-04-25 02:06 626688 ----a-w- c:\windows\SysWow64\usp10.dll
2014-06-12 01:10 . 2014-03-26 14:44 2002432 ----a-w- c:\windows\system32\msxml6.dll
2014-06-12 01:10 . 2014-03-26 14:44 1882112 ----a-w- c:\windows\system32\msxml3.dll
2014-06-12 01:10 . 2014-03-26 14:27 1389056 ----a-w- c:\windows\SysWow64\msxml6.dll
2014-06-12 01:10 . 2014-03-26 14:41 2048 ----a-w- c:\windows\system32\msxml6r.dll
2014-06-12 01:10 . 2014-03-26 14:27 1237504 ----a-w- c:\windows\SysWow64\msxml3.dll
2014-06-12 01:10 . 2014-03-26 14:25 2048 ----a-w- c:\windows\SysWow64\msxml6r.dll
2014-06-12 01:10 . 2014-03-26 14:41 2048 ----a-w- c:\windows\system32\msxml3r.dll
2014-06-12 01:10 . 2014-03-26 14:25 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll
2014-06-12 01:09 . 2014-05-08 09:32 3178496 ----a-w- c:\windows\system32\rdpcorets.dll
2014-06-12 01:09 . 2014-05-08 09:32 16384 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2014-06-11 09:19 . 2014-06-11 09:19 -------- d-----w- C:\MGADiagToolOutput
2014-06-11 09:19 . 2014-06-11 09:19 -------- d-----w- c:\programdata\Office Genuine Advantage
2014-06-10 16:57 . 2014-06-24 17:07 -------- d-----w- C:\FRST
2014-06-10 05:52 . 2014-06-10 08:11 -------- d-----w- c:\users\Miz\AppData\Local\NVIDIA Corporation
2014-06-10 05:51 . 2014-04-30 18:27 1081112 ----a-w- c:\windows\SysWow64\nvspcap.dll
2014-06-10 05:51 . 2014-04-30 18:26 1225920 ----a-w- c:\windows\system32\nvspcap64.dll
2014-06-10 05:51 . 2014-06-10 05:51 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2014-06-10 05:50 . 2014-05-19 23:10 601432 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2014-06-10 05:45 . 2014-03-31 16:42 40392 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2014-06-10 05:45 . 2014-03-31 16:42 37320 ----a-w- c:\windows\system32\nvaudcap64v.dll
2014-06-10 05:45 . 2014-03-31 16:42 34760 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2014-06-03 17:13 . 2014-06-03 17:13 -------- d-----w- c:\program files\iPod
2014-06-03 17:13 . 2014-06-03 17:14 -------- d-----w- c:\program files\iTunes
2014-06-03 17:13 . 2014-06-03 17:14 -------- d-----w- c:\program files (x86)\iTunes
2014-05-29 05:34 . 2014-05-29 05:41 -------- d-----w- c:\users\Miz\AppData\Roaming\Mumble
2014-05-29 05:34 . 2014-05-29 05:34 -------- d-----w- c:\program files (x86)\Mumble
2014-05-29 00:34 . 2014-05-29 00:34 -------- d-----w- c:\programdata\IDM
2014-05-29 00:34 . 2014-05-29 00:34 -------- d-----w- c:\users\Miz\AppData\Roaming\IDM
2014-05-28 16:29 . 2014-05-28 16:29 -------- d-----w- c:\program files\Bonjour
2014-05-28 16:29 . 2014-05-28 16:29 -------- d-----w- c:\program files (x86)\Bonjour
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-06-13 09:55 . 2014-04-30 16:58 95414520 ----a-w- c:\windows\system32\MRT.exe
2014-05-20 02:44 . 2012-08-03 09:38 2730208 ----a-w- c:\windows\SysWow64\nvapi.dll
2014-05-20 02:44 . 2012-03-16 13:27 952952 ----a-w- c:\windows\system32\nvumdshimx.dll
2014-05-20 02:44 . 2012-03-16 13:27 3109248 ----a-w- c:\windows\system32\nvapi64.dll
2014-05-20 02:44 . 2012-03-16 13:27 18531568 ----a-w- c:\windows\system32\nvwgf2umx.dll
2014-05-20 02:44 . 2012-03-16 13:27 1515296 ----a-w- c:\windows\system32\nvhdagenco6420103.dll
2014-05-20 02:44 . 2012-03-16 13:27 14434704 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2014-05-20 01:25 . 2012-03-16 13:27 6769096 ----a-w- c:\windows\system32\nvcpl.dll
2014-05-20 01:25 . 2012-03-16 13:27 3514144 ----a-w- c:\windows\system32\nvsvc64.dll
2014-05-20 01:25 . 2012-03-16 13:27 927520 ----a-w- c:\windows\system32\nvvsvc.exe
2014-05-20 01:25 . 2012-03-16 13:27 62808 ----a-w- c:\windows\system32\nvshext.dll
2014-05-20 01:25 . 2012-03-16 13:27 387528 ----a-w- c:\windows\system32\nvmctray.dll
2014-05-15 16:41 . 2014-04-30 16:26 85328 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-05-15 16:41 . 2014-04-30 16:26 1039096 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2014-05-15 16:41 . 2014-04-30 16:25 423240 ----a-w- c:\windows\system32\drivers\aswsp.sys
2014-05-14 23:49 . 2012-03-16 13:27 3774821 ----a-w- c:\windows\system32\nvcoproc.bin
2014-05-13 20:02 . 2012-08-14 18:46 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-05-13 20:02 . 2012-03-16 15:47 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-04-30 21:58 . 2014-04-30 21:58 194048 ----a-w- c:\windows\SysWow64\elshyph.dll
2014-04-30 21:58 . 2014-04-30 21:58 942592 ----a-w- c:\windows\system32\jsIntl.dll
2014-04-30 21:58 . 2014-04-30 21:58 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2014-04-30 21:58 . 2014-04-30 21:58 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll
2014-04-30 21:58 . 2014-04-30 21:58 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2014-04-30 21:58 . 2014-04-30 21:58 83968 ----a-w- c:\windows\system32\MshtmlDac.dll
2014-04-30 21:58 . 2014-04-30 21:58 81408 ----a-w- c:\windows\system32\icardie.dll
2014-04-30 21:58 . 2014-04-30 21:58 774144 ----a-w- c:\windows\system32\jscript.dll
2014-04-30 21:58 . 2014-04-30 21:58 77312 ----a-w- c:\windows\system32\tdc.ocx
2014-04-30 21:58 . 2014-04-30 21:58 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2014-04-30 21:58 . 2014-04-30 21:58 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe
2014-04-30 21:58 . 2014-04-30 21:58 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll
2014-04-30 21:58 . 2014-04-30 21:58 62464 ----a-w- c:\windows\SysWow64\tdc.ocx
2014-04-30 21:58 . 2014-04-30 21:58 62464 ----a-w- c:\windows\system32\pngfilt.dll
2014-04-30 21:58 . 2014-04-30 21:58 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
2014-04-30 21:58 . 2014-04-30 21:58 616104 ----a-w- c:\windows\system32\ieapfltr.dat
2014-04-30 21:58 . 2014-04-30 21:58 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2014-04-30 21:58 . 2014-04-30 21:58 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2014-04-30 21:58 . 2014-04-30 21:58 48640 ----a-w- c:\windows\system32\mshtmler.dll
2014-04-30 21:58 . 2014-04-30 21:58 48128 ----a-w- c:\windows\system32\imgutil.dll
2014-04-30 21:58 . 2014-04-30 21:58 413696 ----a-w- c:\windows\system32\html.iec
2014-04-30 21:58 . 2014-04-30 21:58 36352 ----a-w- c:\windows\SysWow64\imgutil.dll
2014-04-30 21:58 . 2014-04-30 21:58 337408 ----a-w- c:\windows\SysWow64\html.iec
2014-04-30 21:58 . 2014-04-30 21:58 30208 ----a-w- c:\windows\system32\licmgr10.dll
2014-04-30 21:58 . 2014-04-30 21:58 263376 ----a-w- c:\windows\system32\iedkcs32.dll
2014-04-30 21:58 . 2014-04-30 21:58 247808 ----a-w- c:\windows\system32\msls31.dll
2014-04-30 21:58 . 2014-04-30 21:58 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll
2014-04-30 21:58 . 2014-04-30 21:58 243200 ----a-w- c:\windows\system32\webcheck.dll
2014-04-30 21:58 . 2014-04-30 21:58 235520 ----a-w- c:\windows\system32\url.dll
2014-04-30 21:58 . 2014-04-30 21:58 235008 ----a-w- c:\windows\system32\elshyph.dll
2014-04-30 21:58 . 2014-04-30 21:58 182272 ----a-w- c:\windows\SysWow64\msls31.dll
2014-04-30 21:58 . 2014-04-30 21:58 167424 ----a-w- c:\windows\system32\iexpress.exe
2014-04-30 21:58 . 2014-04-30 21:58 151552 ----a-w- c:\windows\SysWow64\iexpress.exe
2014-04-30 21:58 . 2014-04-30 21:58 147968 ----a-w- c:\windows\system32\occache.dll
2014-04-30 21:58 . 2014-04-30 21:58 143872 ----a-w- c:\windows\system32\wextract.exe
2014-04-30 21:58 . 2014-04-30 21:58 139264 ----a-w- c:\windows\SysWow64\wextract.exe
2014-04-30 21:58 . 2014-04-30 21:58 13824 ----a-w- c:\windows\system32\mshta.exe
2014-04-30 21:58 . 2014-04-30 21:58 135680 ----a-w- c:\windows\system32\iepeers.dll
2014-04-30 21:58 . 2014-04-30 21:58 13312 ----a-w- c:\windows\SysWow64\mshta.exe
2014-04-30 21:58 . 2014-04-30 21:58 13312 ----a-w- c:\windows\system32\msfeedssync.exe
2014-04-30 21:58 . 2014-04-30 21:58 131072 ----a-w- c:\windows\system32\IEAdvpack.dll
2014-04-30 21:58 . 2014-04-30 21:58 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2014-04-30 21:58 . 2014-04-30 21:58 105984 ----a-w- c:\windows\system32\iesysprep.dll
2014-04-30 21:58 . 2014-04-30 21:58 101376 ----a-w- c:\windows\system32\inseng.dll
2014-04-30 17:18 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2014-04-30 17:18 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2014-04-30 16:25 . 2014-04-30 16:26 208416 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-04-30 16:25 . 2014-04-30 16:25 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-04-30 16:25 . 2014-04-30 16:25 79184 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-04-30 16:25 . 2014-04-30 16:25 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2014-04-30 16:25 . 2014-04-30 16:25 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-04-30 16:25 . 2014-04-30 16:25 334648 ----a-w- c:\windows\system32\aswBoot.exe
2014-04-30 16:25 . 2014-04-30 16:25 43152 ----a-w- c:\windows\avastSS.scr
2014-04-20 04:29 . 2014-04-20 04:29 2962432 ----a-r- c:\users\Miz\AppData\Roaming\Microsoft\Installer\{A7A70E54-4678-4E66-A2BA-F135AAAB70A8}\StartMenuIcon.exe
2014-04-20 04:29 . 2014-04-20 04:29 2962432 ----a-r- c:\users\Miz\AppData\Roaming\Microsoft\Installer\{A7A70E54-4678-4E66-A2BA-F135AAAB70A8}\DesktopIcon.exe
2014-04-14 02:24 . 2014-04-30 18:43 465408 ----a-w- c:\windows\system32\aepdu.dll
2014-04-14 02:19 . 2014-04-30 18:43 424448 ----a-w- c:\windows\system32\aeinv.dll
2014-04-12 19:51 . 2014-04-12 19:51 16896 ----a-w- c:\windows\AsTaskSched.dll
2014-04-12 02:22 . 2014-05-15 04:45 155072 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2014-04-12 02:22 . 2014-05-15 04:45 95680 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2014-04-12 02:19 . 2014-05-15 04:45 29184 ----a-w- c:\windows\system32\sspisrv.dll
2014-04-12 02:19 . 2014-05-15 04:45 136192 ----a-w- c:\windows\system32\sspicli.dll
2014-04-12 02:19 . 2014-05-15 04:45 28160 ----a-w- c:\windows\system32\secur32.dll
2014-04-12 02:19 . 2014-05-15 04:45 1460736 ----a-w- c:\windows\system32\lsasrv.dll
2014-04-12 02:19 . 2014-05-15 04:45 31232 ----a-w- c:\windows\system32\lsass.exe
2014-04-12 02:12 . 2014-05-15 04:45 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2014-04-12 02:10 . 2014-05-15 04:45 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2014-03-31 13:35 . 2014-04-30 16:57 270496 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll" [2014-02-11 1565464]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2012-10-02 00:38 1720976 ----a-w- c:\progra~2\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2012-10-02 00:38 1720976 ----a-w- c:\progra~2\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2012-10-02 00:38 1720976 ----a-w- c:\progra~2\MICROS~3\Office15\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2014-05-29 1754816]
"Messenger (Yahoo!)"="c:\program files (x86)\Yahoo!\Messenger\YahooMessenger.exe" [2012-05-25 6595928]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2014-05-08 21444224]
"GoogleChromeAutoLaunch_D30BA0C625A5A2A6D1452AE610495547"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2014-06-05 860488]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-04-30 3873704]
"Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2014-05-26 2688920]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2014-05-26 152392]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys;c:\windows\SYSNATIVE\Drivers\androidusb.sys [x]
R3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\System32\DRIVERS\ASPI32.sys;c:\windows\SYSNATIVE\DRIVERS\ASPI32.sys [x]
R3 ATHDFU;Atheros Valkyrie USB BootROM;c:\windows\system32\Drivers\AthDfu.sys;c:\windows\SYSNATIVE\Drivers\AthDfu.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys;c:\windows\SYSNATIVE\DRIVERS\pneteth.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S0 AiChargerPlus;ASUS Charger Plus Driver;c:\windows\system32\DRIVERS\AiChargerPlus.sys;c:\windows\SYSNATIVE\DRIVERS\AiChargerPlus.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys;SysWow64\drivers\AsUpIO.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe;c:\program files (x86)\ASUS\AXSP\1.00.14\atkexComSvc.exe [x]
S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe;c:\program files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe [x]
S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.11\AsSysCtrlService.exe [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys;c:\windows\SYSNATIVE\drivers\cpuz135_x64.sys [x]
S2 DigiNet;Digidesign Ethernet Support;c:\windows\system32\DRIVERS\diginet.sys;c:\windows\SYSNATIVE\DRIVERS\diginet.sys [x]
S2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe;c:\windows\SYSNATIVE\IProsetMonitor.exe [x]
S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 PaceLicenseDServices;PACE License Services;c:\program files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe;c:\program files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
S2 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x]
S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [x]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys;c:\windows\SYSNATIVE\DRIVERS\asmthub3.sys [x]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys;c:\windows\SYSNATIVE\DRIVERS\asmtxhci.sys [x]
S3 ASUSFILTER;ASUSFILTER;SysWow64\drivers\ASUSFILTER.sys;SysWow64\drivers\ASUSFILTER.sys [x]
S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys;c:\windows\SYSNATIVE\DRIVERS\btath_bus.sys [x]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_hcrp.sys [x]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_rcp.sys [x]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
S3 CompFilter64;UVCCompositeFilter;c:\windows\system32\DRIVERS\lvbflt64.sys;c:\windows\SYSNATIVE\DRIVERS\lvbflt64.sys [x]
S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys;c:\windows\SYSNATIVE\DRIVERS\vrtaucbl.sys [x]
S3 ICCWDT;Intel® Watchdog Timer Driver (Intel® WDT);c:\windows\system32\DRIVERS\ICCWDT.sys;c:\windows\SYSNATIVE\DRIVERS\ICCWDT.sys [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]
S3 LVUVC64;Logitech HD Webcam C510(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 pnetmdm;PdaNet Modem;c:\windows\system32\DRIVERS\pnetmdm64.sys;c:\windows\SYSNATIVE\DRIVERS\pnetmdm64.sys [x]
S3 USBMULCD;USB Multi-Channel Audio Device Interface;c:\windows\system32\drivers\CM10664.sys;c:\windows\SYSNATIVE\drivers\CM10664.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-06-12 10:59 1091912 ----a-w- c:\program files (x86)\Google\Chrome\Application\35.0.1916.153\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-06-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-14 20:02]
.
2014-06-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-16 12:45]
.
2014-06-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-03-16 12:45]
.
2014-06-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1038818363-2529734610-2198295289-1000Core.job
- c:\users\Miz\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-14 08:01]
.
2014-06-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1038818363-2529734610-2198295289-1000UA.job
- c:\users\Miz\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-14 08:01]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1]
@="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}"
[HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}]
2014-05-23 06:10 671904 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2]
@="{853B7E05-C47D-4985-909A-D0DC5C6D7303}"
[HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}]
2014-05-23 06:10 671904 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3]
@="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}"
[HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}]
2014-05-23 06:10 671904 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2012-10-02 00:37 2322576 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2012-10-02 00:37 2322576 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2012-10-02 00:37 2322576 ----a-w- c:\progra~1\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-04-30 16:25 290888 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-19 11613288]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2014-02-28 558496]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = localhost; 127.0.0.1; <local>;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office15\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office15\ONBttnIE.dll/105
TCP: DhcpNameServer = 65.32.5.111 65.32.5.112
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
FF - ProfilePath - c:\users\Miz\AppData\Roaming\Mozilla\Firefox\Profiles\gkl27u1m.default\
FF - prefs.js: browser.startup.homepage - google.com
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-e - c:\programdata\bitraider\brwc.exe
AddRemove-Fallout Tactics - c:\gog games\Fallout Tactics\unins000.exe
AddRemove-Steam App 205700 - e:\program files\Steam\steam.exe
AddRemove-Steam App 65800 - e:\program files\Steam\steam.exe
AddRemove-{3C6054C0-A1E7-BB16-DFA5-56BBDADAFDE6} - c:\progra~3\INSTAL~1\{0C689~1\Setup.exe
AddRemove-{B14AF48B-6324-6D1C-0A89-009B4851535E} - c:\progra~3\INSTAL~1\{770B5~1\Setup.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1038818363-2529734610-2198295289-1000\Software\SecuROM\License information*]
"datasecu"=hex:9b,b5,49,f3,14,44,9b,71,80,27,21,e7,a4,1a,91,d0,45,cf,80,98,0f,
   72,98,7d,07,84,6b,63,f5,9e,1b,cf,d8,18,55,13,40,ad,16,51,3a,c6,19,d9,09,9a,\
"rkeysecu"=hex:db,d8,3f,21,a6,43,db,fa,56,c5,e1,83,30,1d,68,85
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.13"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2014-06-27  05:15:17
ComboFix-quarantined-files.txt  2014-06-27 09:15
ComboFix2.txt  2014-06-25 17:10
.
Pre-Run: 453,122,412,544 bytes free
Post-Run: 452,643,041,280 bytes free
.
- - End Of File - - 634679E1D2606EC9D8E8E2B3A911E435

 

A36C5E4F47E84449FF07ED3517B43A31

  • 0

#73
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi Nat is incommunicado for the next few days. How is the computer behaving now ?
  • 0

#74
GhostLoad

GhostLoad

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 419 posts

Haven't had any crashes as of yet, but like I said it was sporadic before, happening on random intervals of a few days.


  • 0

#75
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
What I will do now is remove the tools and then wait until the next BSOD occurs

In that case methinks I will send you on your merry way :)

Subject to no further problems :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset System Restore points:

Download and run Delfix

delfix.JPG


: Keep Java Updated :

WARNING: Java is the #1 exploited program at this time. The Department of Homeland Security recommends that computer users disable Java
See this article and this article.
I would recommend that you completely uninstall Java unless you need it to run an important software.
In that instance I would recommend that you disable Java in your browsers until you need it for that software and then enable it. (See How to diasble Java in your web browser and How to unplug Java from the browser)

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

CryptoPrevent install this programme to lock down and prevent crypto ransome ware

CryptoPrevent.JPG

Malwarebytes.

Update and run weekly to keep your system clean


It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To learn more about how to protect yourself while on the internet read this little guide Best security practices Keep safe :wave:
  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP