Solved Weird adio commercials playing / computer running slow

Here is the Junkware removal tool log
Too long for one message, I will break it and put in two replies

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.3 (09.27.2013:1)
OS: Windows 7 Home Premium x64
Ran by motulken on Sun 10/06/2013 at 0:53:46.78
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


~~~ Services

~~~ Registry Values

~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\aol toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\aol toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\firstsearch
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0B8C8703-7D10-481E-9165-A7C679EA2231}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2726EAAE-E2F9-413D-9BB8-BD280A0E30FC}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{2726EAAE-E2F9-413D-9BB8-BD280A0E30FC}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{E19F948A-E196-43DB-A88E-91E9D1A0BF1B}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3EF64538-8B54-4573-B48F-4D34B0238AB2}

~~~ Files
Successfully deleted: [File] C:\Windows\syswow64\sho1C61.tmp

~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\aol toolbar"
Successfully deleted: [Folder] "C:\Users\motulken\appdata\local\aol toolbar"
Successfully deleted: [Folder] "C:\Program Files (x86)\aol toolbar"
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0029A11F-97CC-4C61-9EB9-F9560231592B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0072A17E-5B85-4D56-A5FE-07CDCDD151CA}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{00F99824-ED72-4BEA-8C02-403818BD332D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{01DA5647-DB2A-4F1D-BB06-1B73C4D92830}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{02708C17-1D06-4D7C-BCB6-85FF8704A798}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{027F1803-BFAE-4D61-9699-5D090C136772}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{03459DA1-A91C-48B9-8C13-4ED50D443F20}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{042C7A9B-E068-43F9-B497-E972B2CE99CF}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{046EEBC0-E94D-47B6-909E-62FB1CD28278}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{048E5D4A-44F8-4ABB-9C7B-7F426D697591}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0494662C-BD8E-43D1-996F-9B58E5296A1D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{050A6117-D363-4B0B-BECC-3D127D19D1AB}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{05A2274E-E429-49DF-BBEE-AA85DE000C85}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{05AFDBCD-0B54-4DEF-99C2-53DF65304B65}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{05C47372-15E0-4F99-818C-B4049973BB0E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{064D4FE1-0316-4744-BBC3-F6D93F4AA6B3}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{07810F02-0F61-4BCE-B399-8F1E21DC4083}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{07DA704C-A4B1-41AB-A5AA-79FCD79B6418}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0863F336-476C-4A63-8135-98E1E679760F}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{08E3250A-7F71-4048-B5D0-2992BBCECD13}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0905D414-6848-4908-8DD5-801FD6A76E23}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0907EB9E-8855-4753-AA0F-F4201E5E6084}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{09166C5B-6D09-450D-A0BA-5BDC30D145ED}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{098BE757-C3C7-4275-92A6-2EE690DD03C1}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0A0DA55F-AEA8-4C54-84D2-89225AAA9A29}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0AA6C075-ACFD-41EF-A7A1-400DC9AC21AF}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0AAA6034-4B21-4ECF-B3B7-4207B9396AA9}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0B247DB1-97EF-4A08-8D49-42D31E44BE1E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0B7C644C-4FA5-46A9-A10A-A7CB9CF5E9E8}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0BD0EC56-4989-4580-A5CE-2B0EB4CF36E5}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0BFEBA04-0A02-4BBB-A765-4258D15ED783}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0C0976B3-DCD0-4C53-9329-59742280C042}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0C12651E-1705-4FB3-B4BF-E283953E5231}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0C930202-91AD-44AF-A5F3-0A6C34D6F9A8}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0E054D7E-C8FF-4DFC-BB07-F8A180C4037D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0E18BF98-CED9-4723-B858-742200A452B0}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0E2AF646-F070-42B7-8A8A-706CEB4FE40B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0F2BB287-1E9C-4E9B-B896-0C98D0FFB4C6}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0FED9030-F890-416A-A350-553B6DEE47F1}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{0FF38059-9485-48E9-BE8F-D1AFEA91270D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{10198B86-9515-4749-9CE9-51BD3B35F9DB}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{105A6C06-54E2-419B-AB30-0A588016CB1D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{10ACE710-1570-43FB-B336-E6FD7DC111EB}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1145F531-1775-43BA-9CD0-16088CE10CF6}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{11986EC1-03D4-46A9-8A5A-7B45CEAA3997}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{11D33D49-FF7E-4E88-B034-E322A943369E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{11F55F55-E288-439B-A35B-1032B931365D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1229F948-7EED-4EC5-920C-60163279CAD9}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{122FC341-DC44-4B9A-9B40-07B6E2F702B2}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1251850E-88C3-4141-9BF1-B0C2F318188A}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{13121887-F80B-4228-AC08-0199C0FECD52}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{13317F44-3B2E-4B54-9376-34966788F164}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{13446578-DCD8-4576-BD6E-E329BEA41A18}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{13D09601-D125-4A5F-8AE1-422F21F0442D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{13E126AB-AEC6-4378-89EF-F1AD533604C6}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{149C35AC-4385-455C-A3A9-C9A06D1D3153}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{14B4BB7C-A294-471E-8192-5C0881C29810}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{15B30EF3-D0DE-4AB5-A6B2-08351E36F43C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{15EBAEE3-3234-4147-AEAC-60F58D103B7D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{164ABDE7-CA92-49E9-B780-C173A2EA4EC9}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{176BB998-9459-44C3-9E90-D10DDEB17D26}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{17BDBEF5-FE07-401E-A47A-91D41F4F8212}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{17DAE54F-B826-4D24-A6CC-31C5C4B13636}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{19468741-685A-45C4-B2FB-74CD95FA125A}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1A588456-8370-4E4C-85F2-9B8DA11AAD21}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1A8A89EB-2D71-4655-B879-FD4BC8D6F2D2}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1AB87B6C-5D6C-49FB-BDB2-3D58ECFAAF3E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1B025685-A33A-4919-A077-9CAB16F190D6}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1B244838-8E15-4D78-8418-D911110714DC}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1B2C7AFE-A569-4FA8-8A90-215FD7D0DA59}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1BBE8CB7-B3B1-4532-8BE9-E8FA64756670}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1BE892F1-8A0A-4A9C-AA67-7EEF18D0A12D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1CD908DF-FD5F-45FB-BDA2-DCE2637ADEE7}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1D1F2CBE-A54D-4C17-B577-CEB24CF38FED}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1D6E6ACF-8887-4FB1-9BE3-8CAD7B4DE7DB}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1DD4606E-139D-456A-ABCE-E77BECA6B1CD}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1E200D5C-CB98-44B6-B594-ED3430F05DCD}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1E235717-49DF-46D7-9D04-78A827D12201}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1E47B77D-BB7F-46A7-9E2E-A2DD47AC62D1}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1EB5CD76-5B5E-4A4E-9561-C8CD0C68F618}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1EE7AAC2-F17E-4F17-AF7F-1576547007E8}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1FA8AAB0-BF5A-4D63-BC65-AD915D6912DB}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{1FCD7D82-32C7-46FB-B8DB-4406FF4A042E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{20D607F9-B35F-4415-B7E2-C0C9100D9344}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{20E8B56D-135A-4489-9632-035D93A3272B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{2159B0C0-2EAE-42E1-8D2D-3E6D5AA5294E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{21C97F5F-BDC6-493B-9376-8725E47E31E1}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{21DBC081-381D-4257-9DC7-31FC5B111A23}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{2239E518-4E30-427D-8915-3C4C038E07CA}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{22642778-4A46-4254-B812-C1E09F0792E1}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{22E93847-9AE3-4AC0-B2E6-67B5F305CA89}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{23B79EEC-E703-46AB-833F-C3E4BEFF7BDC}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{2422B047-C008-4F3D-BCE7-A3AF535C21EC}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{24A2F607-7F8D-4C18-8769-72D04720BE73}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{24C21B11-E4DE-496B-9790-1C807C805532}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{2506AF53-EADF-41E3-AF3B-3895A5DFE1EF}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{26585290-BF3C-4C11-ABA6-508BDE7B93ED}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{26B345EC-2FAB-4BBB-9CD3-B4B32E2B8B14}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{26EE8665-B3E3-4845-8A35-0A90F0562598}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{27644496-35E8-43A8-A9A2-1EA38DC3A633}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{2856D07D-98A9-4940-B44A-84774598A771}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{28D44E81-E1B3-4464-8211-EFA9AD705134}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{29298D61-1818-4975-8321-868D7A0626D0}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{29A72AD7-E7C5-4F06-9761-702B2A544D10}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{29C0ED6E-76F4-4E7B-9C47-EA2EA3771456}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{2AB1CD09-2DAD-40D5-9CDB-C086CEDA47E0}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{2B4D3A46-0C76-4F38-BBAD-AAA3BC15E871}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{2BAF6154-F209-4CAF-A57E-8E6EFE34A8E1}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{2C020B33-D9C9-413B-A42D-7BA26F5D68B8}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{2C24D3FC-8B29-482E-8831-DF71F1F565EB}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{2C4FD297-94EC-4338-93F0-F280C74E8654}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{2E36D81A-E7EA-49CC-9476-017026C044E7}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{2F5AE740-C3FD-4776-8318-1DB848A2B2A8}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{2FC2D353-A6BB-4176-8EC4-F5230010C7D7}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{306FB708-5FB7-470C-A4B9-DB684ECC1ACD}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{30E121D0-402A-4326-92CE-3973267349C7}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3117D979-2792-4CD4-A165-C00BF220584E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{31193577-836C-49C3-92BF-DAF91C33EDE4}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{32EFAD64-66DF-4842-8980-F2EB8EE108EE}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{32F39C1B-145B-4E02-864A-E55C4AFC6DDF}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{33219E1A-0F7B-4A23-B52D-541FA23F936A}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{332CE014-ED6E-43B8-9CAD-BCBBD902124F}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{33F85702-925B-4182-926D-567AABE4A28F}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3414A4B9-BD40-4F3B-A329-88E537FF24CF}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{350A9FDF-300D-475B-B399-2849D698FF74}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{357A3433-1ED4-4E1B-9C2F-8335728EA2AC}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3614104B-6FAC-4D1A-8811-74E5855EE88D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3639D23F-6889-4BD7-B204-FEC7D9A45D91}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3716FACB-B8CC-431B-984F-D54D517F8AA6}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{372D5D4D-EABA-40B9-8322-5310F722DE50}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{37BED396-402C-48A7-9D46-7AEA4DCDE60E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{383239F2-238C-48F1-89F6-666D5D4FA0F3}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{38B42B14-8CAA-4D62-A74D-AC870CCF84FC}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{38D3C153-7A27-4C55-9774-F4A9A0A1CE5E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{38FAFF24-139F-49D1-A6C6-AA920B6C4971}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3A58BB9C-9107-484E-94CD-67D11CBD86C8}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3B8E1A8E-399E-4FAE-9B8D-95441A876202}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3BDD0C34-BCD4-4125-B439-26AB86B1EEE1}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3BF9C109-2CDD-44EB-8DEB-B80C1BF2B683}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3C177710-A2BA-4093-8308-ADA92EAB1B80}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3C5F18D9-537B-45B0-A6F7-EB2AADB52F4D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3C61E68D-C81F-45AE-A299-28B3D675D326}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3D150984-D497-4D8C-B607-2F92604E1211}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3D2FE314-7A46-4D55-92A0-37BF027E9DE2}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3D38B942-26BC-4582-A175-625F2810B105}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3DBAF0C0-D03B-4CBF-92B2-D44F2B53C168}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3E0AC1FB-EE8B-4A97-91C6-4DF071C0F825}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3E5BA2E4-C386-4234-965C-02A9F2210F1D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3E890D0C-978E-4731-A416-F9C12F863301}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3EFFDCFB-B426-4D97-8321-F262CA384837}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{3FC465DE-4662-48BA-A985-E0A140BDC084}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{4045DC42-EDEF-4FF2-B23A-FB467A250401}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{4081BB06-CC61-4A32-A1F2-1F9E87C025CF}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{4193A7AD-07D7-4D13-9C5E-F6AC6CABF29A}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{447E5116-862E-4F04-9415-B37D9B1D2D8F}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{44F8EE48-ABA6-42D2-B715-E87B24F1CD12}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{450E562F-F831-414C-83EA-EF77726777D9}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{45F8D992-E7D7-4B64-8AD6-49214FA796C2}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{45F957EB-8FBD-46A1-B9FA-0C977756A72D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{460399CF-04A2-4059-A9CB-7A4D22618B15}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{4646B61B-464F-4B0E-8507-6FF3FD806978}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{46C93E76-CF27-40EE-A34B-2D13DA96ADD4}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{4705C21B-13D7-448E-A5FF-D8ABABBD9306}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{4727FFB7-477E-42C0-9E8A-B3BA8068D8B3}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{48C8EB3A-AC22-4DB3-AB03-09939E10FA8A}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{49F27187-2265-4580-901D-8906AC55F48C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{4A5156A0-7D83-418E-9002-8E66F8857A29}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{4A7412AA-68A0-40CC-9C20-5CFD6E8270D1}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{4B131330-315C-403A-98AC-BC08BC872A79}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{4BE80DDF-1AC6-41C2-B178-E7F07415D1C6}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{4BFEAC85-1F40-4ADD-B31E-7389F5E1FDB3}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{4C736ADA-63A7-4F42-8318-EB61704907AB}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{4D309BE4-7CDE-4A73-8761-AC4728000AB9}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{4D36DF9F-2CD1-4ECD-9367-823DE4DC0549}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{4D6EF0EB-738B-4739-848E-6AE885630782}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{4E7BA577-F1D8-4B6C-B164-E3E6A15A6187}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{4EF7F91C-884D-4952-B3F8-4AB09D1364B9}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{4F44EE75-0A24-46F9-A0A4-A715D3B16C05}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{4F8E01EB-1DBA-428E-89F2-909BE1E7F1B9}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{4F8FC94B-AAB8-4F71-8B8B-46C13E6F6670}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{5153FD1E-BB74-49A5-BD81-0CE6DDAB2604}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{517BF1A9-9DC2-42CC-B38C-B4848359FB70}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{517F9605-CDA7-425E-AE83-46D7F814012E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{51835C19-1C58-4A19-9A4C-F07894119A77}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{52293DAB-1373-400B-8ACB-47D421F6D31E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{52FB1B60-800E-4A21-BB38-F17D59B702C7}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{53865F30-FC7A-4429-888C-FBA57E0F17F1}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{53E6F1E8-7EE1-48B3-BBF6-B58C1A542347}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{54601336-FBA8-49D5-B9AC-E546035D168B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{573AE0C9-58A3-43AD-94ED-A407DC4E929C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{5980FA89-79E9-4CCA-AE3B-FBBA897C64C5}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{59E54AAF-3CB7-409D-AA67-1232CFDE5DA2}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{5A2EA1A4-75AE-45DE-94A4-FA59D67C2DBB}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{5D89F7A2-09AB-4D6A-9084-F2E9BF0434C9}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{5D8AC56D-18C2-48E3-B382-6A0A085D2860}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{5EAEFCF3-5C87-41A0-80E6-4A641AD88620}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{5EB8485D-4C1D-4B52-B6C0-7D256746B28C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{5EBE0D4C-F835-4F18-B121-1F33A0B02303}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{5EBEFCCE-A2A3-420B-96DD-6AAEB1F0AFD8}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{5F97F498-C4D6-4240-9B5A-EB6218657087}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{610F9C5C-DA73-43E6-815A-C3D50C269968}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{61242263-B241-42DD-9BA6-0E6EDFF97031}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{62D8C0D3-46E8-4715-9890-A36AA23AD8EB}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{6317FF80-CFE4-4666-842B-81E754F6D2D7}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{6334F89A-A7B8-45EE-9EC6-991C4CE2ADC4}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{63627129-B101-425B-8E02-B095A8FB4AF6}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{636E3609-E668-4136-9975-0D7394112FA8}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{63AE4ED3-D95E-4163-89D0-827ACE6DA634}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{63CA42FC-6E26-4AA1-91F2-396C1AE124E2}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{64623E7A-EC37-4530-87E5-23C9379CB4C4}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{64AF81B6-816E-49A9-8A71-FA8AF3A90425}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{6521C8E6-A722-4D68-A78B-6618F7625B0F}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{65370337-397F-4034-A7A7-330B02A8C923}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{657AFC2F-E8F1-4F81-8807-819A9A91D0BA}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{65C64D8B-50F4-4657-8314-27896239D2A8}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{661685B8-1D55-438F-8B3B-9993E30BE0C6}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{666BDD8F-DB55-447D-9C26-546B4BFF5ABE}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{68499A69-C9C3-419A-8127-28A31E0B35F9}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{685DDEF7-89C8-41CF-A6FB-120A25529243}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{686E8292-4FC9-4E91-A10B-3E43C1D20D10}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{69112D45-11DD-460B-BD75-1E6CCCE14DD3}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{697CA6A5-D21E-47DC-928E-A713CF274704}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{69BCD8C2-4CCD-45A3-A54D-1FB0294B3C50}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{6B08917A-E1AD-46E1-829C-3CFD62EE387B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{6B5AD6DE-0206-4D7C-B617-66AADC2CC04F}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{6B60173B-ED21-460B-9DB5-4A480D13B450}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{6B9C9396-E283-4B21-A872-EB6CBD220839}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{6BCA49B3-3D70-4D14-92E0-F5DE824DC9EE}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{6C27BDA1-2222-4375-9BB6-63233A880286}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{6C6BAF81-2A0B-459E-8416-A14C1DD45FA4}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{6D3C3674-663B-420F-8217-35EE728D539D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{6D9465A5-0F4A-418A-B937-138B77A16F1D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{6DB1C0AF-1BCC-4023-AFB5-6D7156164215}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{6E4C519B-8103-4D86-80AE-7F74A5463063}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{6E82CF79-583F-4173-BE28-E0DDC47B5DDD}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{6F714281-EDE0-4BCE-9D1C-2271DEDDEFB5}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{7052EB16-47C8-4ADF-AD4D-8812C136146F}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{70789989-9100-4B7E-9552-22EADE86F6D8}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{70FB5C91-C46E-417C-80B5-4AA9E41B2F54}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{71180394-DE35-4F62-B5D4-367E997038C1}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{7148404F-6B59-4389-923E-9931994E5995}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{71CC81D2-C037-4CEF-85E7-75185D5B2660}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{720CF69D-21B6-458E-9960-ECB31F2341FD}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{72F4FF96-6E6E-49D7-895A-CAFE6751D1A7}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{74D35B37-188B-40C5-96D7-251D496263BF}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{790CDEC2-3E24-47F0-8A52-26C5F00A63B5}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{79803DA8-2E61-477A-B154-07064F8EE43E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{799A82B9-7948-4011-9BD0-1DE8AF75C968}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{79C73DF1-CE7A-40D3-829A-911A75EC694C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{7A2F9895-A673-4DB4-8D42-DF1B9C63564C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{7BD43801-B846-49F9-94C3-AFD04C6CCA74}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{7C28A47D-071B-4BFE-9434-D53D88A8978B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{7C9C11CB-B572-476C-9CBF-3311C8BB7DA3}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{7D097BCA-F390-4FF3-A031-8AD8E7D910AE}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{7D474E9A-42F1-4740-B3AE-13CB85AAFF7B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{7E8BE216-82A0-41AA-B535-489AAA311C0B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{7EAB8C28-5B7B-494D-9A07-C2300450F4B2}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{7EE0AC75-BC4F-452C-A77C-53CE81D5E590}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{7F0678A3-6FC7-4C51-AE8F-DD9CEB5398A4}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{7FC6753B-E721-4A3F-AE7D-5031C640E2A4}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{806DA8BC-4794-495F-912F-15C048D8E80B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{81426BF5-9F84-4D84-A670-19EDD555B411}
Successfully deleted: [Empty Folder]
 
C:\Users\motulken\appdata\local\{81613458-A44F-442D-AFD4-785AA7C6F9C6}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{8195068B-C6D9-4DA1-ADE2-BBAA5AE7671C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{82672DA9-EE8A-4451-AE1F-05172C37F926}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{82B0CF58-38DD-4698-AB33-EDB8F1EBC6A5}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{82D5E32F-58A6-45F2-825A-A983FC187A4A}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{834B7065-1DC1-4219-8B43-DF7C00D98289}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{83659DFA-9882-4045-983D-F3723027B533}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{846350C2-928F-4B43-94B9-D78032292E6B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{8489962A-6C16-42DC-B6DA-B63386D552CA}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{84A5FD33-F380-4344-BA9A-05CA61DA3B59}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{853F002B-2351-4627-87E0-ABF573C5D185}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{85B57DF8-DE1B-4CEA-A56E-CDA6F87EF8BA}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{861B94C9-9424-4180-B483-880335EE7389}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{8660545E-B96D-46BB-855C-9545A97BA8D9}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{8699FB32-2241-4F28-BD42-8D5B24F24D08}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{86AD1D28-851D-4E74-8709-0A27A6990D5E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{87B7F3A0-484F-4463-A0CD-87ED4A1CC230}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{87F7D18C-838F-49CB-95DD-F529B319E5EF}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{88386125-BBF0-4D6E-A945-A9AA0539BA14}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{88B7220E-2228-47F1-BCCE-202FD176E7BC}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{8992A96C-D718-4927-8F0E-DC7754ECBC5C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{89D34C0A-79E6-4AE1-A79D-9F1EB605B175}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{8A7C8E3C-9FFF-40FA-9B2C-804A77DD04A9}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{8AD21269-F6CA-42D1-AA5B-0E24ACD0EFAE}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{8B3C1A7C-8492-4FA4-8C3E-3543AC5ED603}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{8BD8644B-1BD6-4AB5-9E38-BF7052E90325}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{8D0EEC7A-A1AF-432B-8037-7ED8C32BD101}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{8D63CD54-AF95-46AF-A32B-AC163D39B7DE}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{8DBABE17-E14F-4FD6-930F-ABCEA9D5EB64}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{8E3712E4-3CA4-463F-9312-545445FF157D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{8E9E9C3B-18BF-4401-9290-7BC35B236470}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{8EF2B946-603F-48E0-8FE2-100FBD32A471}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{8FE75A93-F7C8-4A90-8235-BB19CC06C123}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{904656BE-D5BA-4C17-A16A-FCED3D979F82}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{906761E5-1882-4229-AE21-7EE2DAFFE0DD}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{9082ACBD-C705-427D-AA98-9E7E09E335FD}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{91583BA7-38DF-464A-8885-B48CDD43AA16}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{926726D9-7959-4F2E-A7AF-59C21F31E87E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{9285F60A-B395-495C-84F9-16F126084B22}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{92F065AC-4879-4374-B79F-F504A23011DF}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{93283AEB-A548-4EFA-B738-8FBF0AB81B3E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{9411A93B-30E4-4043-9DBE-AF2E9F2AED55}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{9497293B-DD8C-452E-A74A-E10E577A84E9}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{953A289C-675E-4460-81D7-0A50ACBD2EE1}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{95DB50CB-F98F-42A5-82D3-93264AB51ECE}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{96D0A0BB-B14E-45B7-8455-A42DDDCDD588}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{96E45B86-409F-479F-BC22-7FDACF4044EB}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{97390D0D-835B-4041-A5C0-BFF7A7BABD58}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{97F02547-EEE4-47AD-837C-82EB139BB879}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{9839786C-3158-4DCA-B1EB-5C55E06DFCB0}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{986F56D0-9DBF-4279-A0BB-3E47E69FB8EF}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{99704321-7D3F-4C95-946F-9653BF8DE02F}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{9B25F35B-F26B-46F9-B98C-213D6C9076F3}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{9B754D82-ECFF-4AC2-86C0-604D924B99F8}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{9C2E89FE-175D-4A53-B95F-E98BC90C91FB}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{9C47F190-CB99-47BC-ACE9-99E149284B48}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{9C8D411F-B690-4EDE-AA10-FF2CC30839C5}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{9C998E2E-2781-40C9-ADE2-0289929DC9D8}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{9D97B455-B532-4BAB-9E86-3094E0550075}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{9E011070-9F6A-4987-BCF9-4B8B307AA5F3}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{9E5DB844-4604-4326-A0E1-951452C4EFEE}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{9E78BED0-41EA-4E01-84DF-7EC6378A2D48}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{9EC0C46A-7201-409A-9B06-36B239736682}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{9EFE4F60-8A8A-434E-9AE0-593AE59F2DB5}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{9FB51090-879B-43E8-8AF7-413676D8640A}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{9FE7BD12-21AA-478D-917E-C56A4260F7FE}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A0197E76-61E0-45BF-BA00-D93FEEEB2C4D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A01F023E-B407-4430-A423-76D90684C660}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A08C70DA-A0EF-4AD3-BBA5-097A1DB26D64}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A0A291BC-602C-49B7-A9E7-C3E9DA925D76}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A0CB487A-8D8B-44B3-B854-439132FEF50A}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A14545BA-C519-44AE-97BA-4CA162F0FCAC}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A167D6C4-AAB9-492C-9D2B-F5153BC7107B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A1A4CA61-777A-4344-A536-EEEF3DFEF00E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A26750FE-9D4B-4752-8319-20D4E6049C7E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A2C272F8-6C18-48B7-92B5-57E15A879078}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A3CD89AC-FCB5-4BD4-A47D-72FF58A64253}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A416B53C-96F5-42C0-A4CE-8A9B4A674745}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A445DC47-6049-4567-872D-AD7F253F15E7}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A469B60A-C11B-44D7-A97F-B588B399E698}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A664321E-C9EF-4FA7-BA72-5B0A0A81E50A}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A66EDD08-FE8A-4F57-8B91-E0D5E571411B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A72B3836-7710-4B66-9DD3-0232C5693A44}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A749FF6E-546C-461E-B949-8626B5BBFB8B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A7756F48-4646-4347-83C0-04336E35010C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A7AD9B19-4FCB-4356-AF1B-93DE0AC82BA6}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A81C52EE-3A08-4A9F-AA9F-1F77F791F86D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A85CB4A1-0F05-499E-BCCB-C21580D59B1C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A939C86F-2F84-4C80-8463-1113CCE47B24}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A963C171-3851-497B-AE7F-B5EC9655F6B0}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{A97A9973-4E8F-4E51-9FEC-5FBD9B1B727A}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{AA1CFDD5-552A-4374-93F9-0FD79BE53A17}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{AA3BF3B5-B900-4F2E-913B-D8B29E49B3CF}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{AB31B15B-9BBA-4888-8773-7E3E585A3E28}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{AB3CC95D-0E64-499B-8E68-B773E76B0919}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{ABC04CEC-770F-4384-8C44-2FE3DEA829CB}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{AC0E62AA-7EDD-45B0-B5C7-CB8E0979237F}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{AC22A064-1C39-4D86-8DA4-075BB79252E6}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{AC738087-EF61-4CD2-9C42-E1539FBC0B2E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{AC7F9E0C-F851-499B-BA0A-84B08CCD43F7}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{ACE7F3B3-F68B-401F-9650-7628AAB2D453}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{ACF7BA05-D4C1-48EC-B0B3-8574C7BD2D1E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{AD79636A-5EE6-4AB5-A527-BC4ADDAD0130}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{AD9B8F5B-9D4A-4E72-AD77-C923D33C3D05}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{AE0B8A71-0366-4A83-9966-6BF56EB405DE}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{AE5173D5-77E6-4C04-9658-4784350D8CDB}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{AE5D4481-6C36-487E-9407-8D11404CAE2B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{AE7E9116-F42C-48FE-A49B-16775FDB18F3}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{AF90B1F5-8B6A-4420-9CC4-C0637D5D663A}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B0D1D5F7-9684-4D84-B35E-3352CFCF14EF}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B133BF85-38A3-43EB-AE3E-AD68F46D82D1}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B14E40C8-CFB7-4335-BDC6-7441177E17C1}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B1D5BBF5-CB08-4881-A59B-FC749C9B0BCF}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B274A2DB-C2BA-4078-ACBC-A1787C621886}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B2867FB5-F05A-48A3-9283-EBCAFBFBEF8C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B29D92D6-275B-470A-B893-F231B4D54FBE}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B2CB13DD-A0E1-45F4-95D4-22BD111B2576}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B2FD52F5-58B4-417E-8DAD-40B29100EA47}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B3680316-4277-4FBB-B18C-A76437BADDE1}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B39019D7-3109-491A-BEB2-24A615C339D9}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B45D9A26-41DA-4C02-8EAA-DCE7A8BDE0D3}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B50DB584-B2F6-43E2-BBEA-A270ADA436EA}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B5AF051E-1AC9-42A2-A626-0B0DC7D273AD}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B64B3CBA-8259-43F4-9B08-97C92CA642C2}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B6A1D717-C3D0-432B-9012-4FAFF5A3348B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B6D75356-E768-47F0-BA7A-5E7722BD6132}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B70602D5-8525-4641-896F-B94E4B15C19C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B744C7B9-CC28-4A18-A613-4CF34DEA9679}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B896E309-0163-48B3-96EA-3A7F41C02E71}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{B937B9DA-0B4F-47FE-B196-4AA588BB4B01}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{BA348C1C-CF15-4106-9D98-C25EC8953430}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{BA92EF2A-D1CA-4B35-939A-99E303CABFA2}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{BA9FBDBF-4FD4-4369-BC50-E25CBA599ACE}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{BB121C3C-A29A-4769-8087-19547C5930F0}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{BB2B2999-D309-48FD-BD4B-638AD80703A7}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{BB3C1F50-6300-4354-837E-E09B58A17771}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{BC9AEF40-E3EA-4BEA-B4A8-D2C438622D36}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{BE31947F-E973-41B0-A0EE-D0FFD341E4A7}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{BEE61B8A-CD9D-4C12-98E4-1EFDEBEF91B9}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{C096A463-EBD9-4979-B582-A7696E8F76C0}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{C0A936AC-9871-4781-889A-92FA592FB7A0}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{C0E4E70E-ABD6-4400-AFF7-7E4918B291E9}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{C10CA7A6-D11D-4291-A92A-1F5BD08917E5}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{C17E545B-D659-47F0-AA56-D3CCA0A11744}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{C21F9A58-9992-46AB-A420-351C9B36BC71}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{C21FE976-40DD-41AC-945B-02D896A143C6}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{C242C60E-73A4-406F-B11A-A4B291910BE2}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{C3F6AD3D-2311-43FB-BAA2-960C3E8FA2E7}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{C465D2BB-99E2-43BE-B7D0-50C06F79F14A}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{C46A1F87-9C3F-424F-A4EB-2BA0EA95D05F}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{C6306D8C-E288-4502-A82F-55DA2DD8719B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{C6462A2C-C690-404E-81E5-84B9E89A8EE2}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{C65F3B0D-2B4B-4825-8BDF-E8F270A34344}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{C85E201F-E1CE-4A55-B0DD-73135BF15CC9}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{C992B716-92B3-4D8C-9F4D-FBBAB0006184}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{C9D94385-8017-4B78-9996-5D6CDA6EB526}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{CA976BCB-8DB6-4779-ACDB-BB86C62A8C02}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{CB26CF6F-0C7A-470F-9688-B71E785E5D5C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{CBBCC49D-E1FD-4762-94BB-3EC510A711ED}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{CC9ABF17-0617-4542-8519-09EAFFB30E2E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{CD173225-89A0-487D-99EE-2783A745EA4D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{CD47B4A0-56C0-4934-94CB-EC6E56E7EAAF}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{CDEE70A1-4E8F-4F9D-9161-C7673D94CA6B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{CE269419-DD27-42C9-BB66-C39DF4AF35F2}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{CE2F5441-6017-4E8E-B0D3-B8AEB4E1D2AD}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{CEDFD224-3FFE-4536-93E2-83DBE3C4DEED}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{CF3F1A4C-CA38-4E87-A412-ECF19D4BDA8E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{CF999226-016D-4ADD-9AD6-71938B22EED6}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{CFCB177B-F34D-4C92-A935-28B9098277A8}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{CFE16AD8-3A8B-4126-B686-7211DBACA3ED}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D0BCD634-052C-423E-B295-58291FD1075C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D11AB1AF-24A4-490C-B4EF-54C275F0825A}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D18DD773-5966-4A62-9024-B0243B6E7C6D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D1EADF58-5EED-4394-AC1C-9A881585199C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D23C61BB-A6F9-4CDB-8A8A-1736D503D706}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D280A6D3-BB0D-440F-BC67-2E46EE7CE07C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D2F57D72-1BE7-46A0-ACA6-DB113AF36C4C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D311F44E-0C04-40C1-B84B-9C30BD88F04E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D325C3EF-0705-4F60-88A7-A8E9A26771A6}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D35EA15F-CD52-4F3B-8953-75663722BD2B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D36B358E-A899-488A-85B7-94A78F8C0C62}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D39DEC4B-2575-4F0F-B62A-CC49EE945C53}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D441DDAE-443C-443D-AFBD-0E81789902E5}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D4C00861-DCDC-48DE-BA7C-CDD540E54800}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D54031DF-72E2-4ED5-B648-858FC984654C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D5A5A400-C1E8-42C8-AC94-8719022CBA0F}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D5E0CEF1-969B-4D28-BBF9-43A61AD001C6}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D6C9C124-A556-47ED-8F41-A54AC20D41EF}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D7BBF9E0-057C-4626-A2B1-5A2E5F028F5E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D8B58B60-E634-4DD5-B00D-892484BD488C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D8C8473F-139C-4BE2-AAEF-A7CA717DBD86}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D8D13ED2-BA7E-409C-9D57-BB1923616DAE}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D9300B06-472D-42CB-AA22-2332B9F5367C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D95989E6-7A52-419C-BBA4-3740F9A6F8D2}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{D9D95E82-AC6B-470F-8E52-FD70C982ACF4}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{DA0022E8-DDC7-4254-82DA-98DB131ED4C2}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{DA035150-0212-4866-811D-870D1C42FA52}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{DAFCBFB4-9F4B-4926-9F38-83686C1BFB9F}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{DB852409-DB7C-44FD-A0DF-2EF4957CD105}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{DCAB67FB-4439-41AE-A736-D918D9DC572C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{DDBF241D-2F45-47F7-860F-77E31320040A}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{DE7A1B48-7CC2-44A2-8FE6-6613C23A668B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{DF282AC0-6F5B-42E7-9BC6-36CA885EB603}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{DF9A6176-5832-4631-812C-8FB0A3ACA260}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E006EA7E-A485-4C15-AD75-9C5E17B673CC}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E02523B9-F08D-4233-B03A-2ED0B94D694D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E08289F1-F851-461B-B4D1-ED292840E13C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E0B89C90-B900-4FE2-9EE5-92AFB8993F86}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E0DD1967-821C-4D4D-96A2-A3CE43AF7C70}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E0E41D80-60A9-4AE4-92C6-75EC7675EA6B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E119C29F-3B43-4E99-B7A8-FA477E132D72}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E1420A03-4C2D-46FC-A579-FD9CA858B9C3}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E1C97F75-AEBC-4BA9-9B83-AECCED0E79F8}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E1E396D4-AD8F-4C7F-BDD0-E2AD0D851C23}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E2116D16-0A10-4C54-A54C-C6720A97F5E5}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E27DD76F-124B-4FBD-9BC5-E8F0CEDC2B91}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E2942E7B-AFB4-4920-B017-62CEFA9CEC5A}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E29863D6-3889-4DB9-B9C7-D4102A660751}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E2F580EE-A1E5-4C80-BFD2-3B87417C6886}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E35BF0DC-F019-4423-83E7-E53309BBA6FE}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E37138C5-608E-490A-8DA8-F9B5C8D6A465}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E38FEE21-DD30-4BE9-B30E-3D08A3DED2A8}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E4766529-72F5-406E-8DA0-2B54398F90EF}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E55F12AF-137F-4A94-9995-486389DEB423}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E57DA5D9-1FA2-4467-AB52-4E57F445683A}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E5819082-A10C-407A-A6B5-C35AA5008227}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E60537D0-5EB5-4928-82E5-365807D1F1B9}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E69BF922-F455-42AE-993D-AC825B144253}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E69FB747-E5D9-4EA0-ACAD-C1C66E60B5B5}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E6A1A7C1-698E-408E-AAB2-89837ADE57FC}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E7A2F8B2-1758-4DA5-946D-67AEF296BD9E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E8CBAC23-9BEC-444C-A8E7-606FEB79C318}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E8DDBE45-C02A-4DC7-9AC1-4BCE081D770B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{E99DBC32-3257-4A50-BD8B-D9C9D16F9C34}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{EA40E5E2-FF2A-4A6C-A8FB-25FEFFE73D78}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{EA740B50-58BD-4D4A-BA84-891636BE1522}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{EAFBB6C6-7340-41EC-9119-D64CF15AF71F}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{EB1EFF66-20B9-4AF8-968E-E46CDCBAA3B9}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{EB2D8290-61F8-4FAE-ACEA-6A0684FED855}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{EB9B4E3E-30F3-4D91-8E3F-CABA30315899}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{EB9F8B19-D3DA-4225-A92D-D9E4C4814486}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{EBC14A97-97FF-4DAC-8799-B16CB97427A9}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{EBF2687E-ED05-4BD2-8128-26F1059D26C9}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{EBFD2E1E-BF38-4B4F-8001-8538F6B1FD08}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{ECD0169E-284D-4D8E-BE6D-8FE2086B5E10}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{EE90FE11-ED0B-4777-8631-A9370ACAE5B0}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{EECECF17-0608-4844-A633-DBC92FC77453}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{EED63122-1362-4DD2-AA84-401239D021B8}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F062CB35-02BE-4E98-9D6E-7DE235079987}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F09498E6-D7B8-4137-825C-992D43817E06}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F09991C4-60EB-4199-A398-FB1F084180C7}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F0F60E20-AE35-4845-87F4-7F8CAA7C7BFA}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F13F0255-6E64-4546-8FE0-9AE2674E2FE6}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F21FF6A1-EF8A-4A0C-BB28-4770F4C93191}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F2273294-4E3D-4376-89DC-9A8095913D66}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F339C51B-9452-4EDE-99BA-F2AD6F7EF7F0}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F341783B-152A-4C29-9ED3-4F642E57064B}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F389C25C-252A-428B-8CDC-220CC2B6807C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F40F22E7-187A-43A0-B572-69E0BE04D8EA}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F458B848-EBB9-4427-B2CE-72240170383A}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F47FB216-3918-4B92-BDEF-003C5401FC3F}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F49F1700-1C66-4A7F-9547-A1452025BF08}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F52D83AD-6162-4DAE-BE96-F8EABCD497D0}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F52DEDF1-8636-46DD-8E24-4C0D9AAE370C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F5784A8A-B01B-4594-B201-34AC304E5606}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F64E8583-BC70-440B-87DC-41005E883C44}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F66D9558-EB1F-4E3A-8DAA-5C23A6A2A48E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F694AB5F-DBE0-41F5-9D47-6A0C9DF5DBEF}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F6B722CC-53B9-4AB2-9406-1C64C134F16C}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F72D292E-0BC9-4ADC-BD5D-C5BD8BBC6319}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F78E9726-1D80-4F64-824B-B3B20206FEB0}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{F9351999-6933-4834-92FA-A03364AE41E4}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{FA0452DC-99C7-4E1A-AE3C-1EBF7576A904}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{FAC98243-E3A1-4B46-8BB4-08617BA596F4}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{FAE0E986-7470-4BE1-8736-A6C1BDC60164}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{FB03D145-DF8F-467D-A104-A7386AD23FB4}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{FC36EF55-C499-4340-8593-0E3D1A24C8CB}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{FCF0FA1B-92F1-4AF2-81E0-60371EB613EF}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{FD0F4E71-24F0-463B-A0BD-FC8FA1CDCDE1}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{FD2D719E-7DF0-4687-8FF2-666F25F6FC7E}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{FD778EB0-F578-4642-986D-1D606B3B55B5}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{FDED5C4F-69C3-4A53-88BF-04349EBF511D}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{FE293A24-ECEA-491B-BDF5-0A3FD1F892EC}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{FEA6F6C2-FE7F-4BD7-AE2B-4F9A406E46D3}
Successfully deleted: [Empty Folder] C:\Users\motulken\appdata\local\{FFE4BA53-7CA6-4B09-9B67-AACFAE696732}

~~~ Event Viewer Logs were cleared


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sun 10/06/2013 at 1:02:50.77
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
Here is the OTL log have to split to two replies


OTL logfile created on: 10/6/2013 1:25:33 AM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\motulken\Documents
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16686)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 1.83 Gb Available Physical Memory | 48.91% Memory free
7.49 Gb Paging File | 5.44 Gb Available in Paging File | 72.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 450.76 Gb Total Space | 328.91 Gb Free Space | 72.97% Space Free | Partition Type: NTFS
Drive D: | 14.71 Gb Total Space | 1.64 Gb Free Space | 11.15% Space Free | Partition Type: NTFS

Computer Name: MOTULKEN-HP | User Name: motulken | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found -- C:\Users\motulken\My Documents\OTL.exe
PRC - [2013/10/03 11:58:29 | 000,570,264 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Family\Engine\2.9.0.26\nf.exe
PRC - [2013/09/05 10:04:00 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/08/31 11:19:48 | 000,264,360 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.0.1.3\N360.exe
PRC - [2013/06/26 19:21:50 | 000,207,528 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2013/06/26 19:21:46 | 000,523,944 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2013/04/18 14:04:53 | 000,071,224 | ---- | M] (AOL Inc.) -- C:\Program Files (x86)\AOL Desktop 9.7a\waol.exe
PRC - [2013/04/18 14:04:49 | 000,045,624 | ---- | M] (AOL Inc.) -- C:\Program Files (x86)\AOL Desktop 9.7a\shellmon.exe
PRC - [2013/04/11 20:22:31 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2013/04/04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2013/03/12 23:38:36 | 002,213,944 | ---- | M] (AOL Inc.) -- C:\Program Files (x86)\AOL Desktop 9.7a\AOLBrowser\aolbrowser.exe
PRC - [2012/12/04 21:40:03 | 000,143,928 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\ccsvchst.exe
PRC - [2012/03/05 14:38:38 | 000,578,944 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
PRC - [2012/03/05 14:38:38 | 000,035,200 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
PRC - [2011/08/19 15:48:44 | 000,379,960 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
PRC - [2011/05/23 11:45:58 | 001,098,296 | ---- | M] (Hewlett-Packard Development Company L.P.) -- C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
PRC - [2011/03/22 14:42:40 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
PRC - [2010/11/26 10:09:12 | 000,399,344 | ---- | M] (Roxio) -- C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
PRC - [2010/06/09 16:09:20 | 000,104,424 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\EPSON Projector\EPSON USB Display V1.4\EMP_UDSA.exe
PRC - [2010/04/23 15:00:00 | 000,514,232 | ---- | M] (EasyBits Software AS) -- C:\Windows\SysWOW64\ezSharedSvcHost.exe
PRC - [2010/04/23 15:00:00 | 000,514,232 | ---- | M] (EasyBits Software AS) -- C:\Windows\SysWOW64\ezSharedSvcHost.exe
PRC - [2010/04/23 15:00:00 | 000,514,232 | ---- | M] (EasyBits Software AS) -- C:\Windows\SysWOW64\ezSharedSvcHost.exe
PRC - [2010/03/23 13:19:32 | 001,528,616 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe
PRC - [2010/03/08 03:27:49 | 000,041,800 | ---- | M] (AOL Inc.) -- C:\Program Files (x86)\Common Files\AOL\1310957960\ee\aolsoftware.exe
PRC - [2006/10/23 08:50:35 | 000,046,640 | R--- | M] (AOL LLC) -- C:\Program Files (x86)\Common Files\AOL\acs\AOLacsd.exe


========== Modules (No Company Name) ==========

MOD - [2013/04/18 14:04:54 | 000,048,640 | ---- | M] () -- C:\Program Files (x86)\AOL Desktop 9.7a\zlib.dll
MOD - [2013/04/18 14:04:28 | 022,152,704 | ---- | M] () -- C:\Program Files (x86)\AOL Desktop 9.7a\libcef.dll
MOD - [2013/04/18 14:04:27 | 000,648,704 | ---- | M] () -- C:\Program Files (x86)\AOL Desktop 9.7a\libGLESv2.dll
MOD - [2013/04/18 14:04:26 | 000,122,880 | ---- | M] () -- C:\Program Files (x86)\AOL Desktop 9.7a\libEGL.dll
MOD - [2013/04/18 14:04:17 | 000,094,208 | ---- | M] () -- C:\Program Files (x86)\AOL Desktop 9.7a\components\Tier2Svc.dll
MOD - [2013/04/18 14:04:17 | 000,060,928 | ---- | M] () -- C:\Program Files (x86)\AOL Desktop 9.7a\components\DataSvcs.dll
MOD - [2013/04/18 14:04:16 | 001,195,022 | ---- | M] () -- C:\Program Files (x86)\AOL Desktop 9.7a\avcodec-54.dll
MOD - [2013/04/18 14:04:16 | 000,217,614 | ---- | M] () -- C:\Program Files (x86)\AOL Desktop 9.7a\avformat-54.dll
MOD - [2013/04/18 14:04:16 | 000,138,766 | ---- | M] () -- C:\Program Files (x86)\AOL Desktop 9.7a\avutil-51.dll
MOD - [2013/04/04 01:09:40 | 004,300,456 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF


========== Services (SafeList) ==========

SRV:64bit: - [2013/05/27 01:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2013/05/16 03:14:56 | 000,333,824 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Program Files\IDT\WDM\stacsv64.exe -- (STacSV)
SRV:64bit: - [2011/08/05 12:53:12 | 000,467,680 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\ZuneWlanCfgSvc.exe -- (ZuneWlanCfgSvc)
SRV:64bit: - [2011/08/05 12:53:12 | 000,306,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\WMZuneComm.exe -- (WMZuneComm)
SRV:64bit: - [2011/08/05 12:53:06 | 008,277,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Zune\ZuneNss.exe -- (ZuneNetworkSvc)
SRV:64bit: - [2011/02/28 15:52:00 | 000,203,776 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011/02/28 15:02:10 | 000,354,304 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2010/10/11 05:48:14 | 000,346,168 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe -- (HPClientSvc)
SRV:64bit: - [2010/09/22 21:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/06/17 08:23:36 | 000,194,496 | ---- | M] (Advanced Micro Devices) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe -- (AMD Reservation Manager)
SRV - [2013/10/03 11:58:29 | 000,570,264 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton Family\Engine\2.9.0.26\NF.exe -- (NSM)
SRV - [2013/09/21 14:35:00 | 000,565,672 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2013/09/20 07:05:16 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/09/05 10:04:00 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/08/31 11:19:48 | 000,264,360 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.0.1.3\N360.exe -- (N360)
SRV - [2013/06/26 19:21:50 | 000,207,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2013/06/26 19:21:46 | 000,523,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2013/04/11 20:22:31 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/12/04 21:40:03 | 000,143,928 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\ccSvcHst.exe -- (MCLIENT)
SRV - [2012/09/27 12:55:16 | 000,086,528 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe -- (HP Support Assistant Service)
SRV - [2012/07/13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/03/05 14:38:38 | 000,035,200 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe -- (HPWMISVC)
SRV - [2011/05/23 11:45:58 | 001,098,296 | ---- | M] (Hewlett-Packard Development Company L.P.) [On_Demand | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe -- (hpCMSrv)
SRV - [2011/03/07 20:43:30 | 002,375,168 | ---- | M] (Realsil Microelectronics Inc.) [Auto | Running] -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe -- (IconMan_R)
SRV - [2010/11/26 10:09:12 | 000,399,344 | ---- | M] (Roxio) [Auto | Running] -- C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe -- (RoxioNow Service)
SRV - [2010/10/22 13:08:18 | 001,039,360 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)
SRV - [2010/10/12 13:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010/06/09 16:09:20 | 000,104,424 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files (x86)\EPSON Projector\EPSON USB Display V1.4\EMP_UDSA.exe -- (EMP_UDSA)
SRV - [2010/03/23 13:19:32 | 001,528,616 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2007/05/31 17:11:54 | 000,443,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 17:11:46 | 000,225,672 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2006/10/23 08:50:35 | 000,046,640 | R--- | M] (AOL LLC) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\AOL\acs\AOLacsd.exe -- (AOL ACS)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/09/23 22:57:33 | 000,245,848 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NSMx64\0209000.01A\symrdrs.sys -- (SYMRDR_{78CA3BF0-9C3B-40e1-B46D-38C877EF059A})
DRV:64bit: - [2013/09/22 21:19:38 | 000,177,752 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent)
DRV:64bit: - [2013/08/04 21:33:19 | 001,147,480 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\N360x64\1500010.003\SymEFA64.sys -- (SymEFA)
DRV:64bit: - [2013/07/31 23:19:50 | 000,493,656 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\N360x64\1500010.003\SymDS64.sys -- (SymDS)
DRV:64bit: - [2013/07/31 00:45:54 | 000,590,424 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\1500010.003\symnets.sys -- (SymNetS)
DRV:64bit: - [2013/07/31 00:13:30 | 000,264,280 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\1500010.003\Ironx64.sys -- (SymIRON)
DRV:64bit: - [2013/07/30 23:44:44 | 000,854,616 | R--- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\N360x64\1500010.003\srtsp64.sys -- (SRTSP)
DRV:64bit: - [2013/07/30 23:44:44 | 000,036,952 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\1500010.003\srtspx64.sys -- (SRTSPX)
DRV:64bit: - [2013/07/29 21:24:22 | 000,150,104 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\1500010.003\ccSetx64.sys -- (ccSet_N360)
DRV:64bit: - [2013/07/29 21:24:22 | 000,150,104 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NSMx64\0209000.01A\ccsetx64.sys -- (ccSet_NSM)
DRV:64bit: - [2013/06/26 19:21:50 | 000,023,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2013/06/26 19:21:48 | 000,028,840 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2013/06/26 19:21:46 | 000,273,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2013/06/26 19:21:44 | 000,767,144 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2013/05/16 11:34:46 | 000,354,376 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsPStor.sys -- (RSPCIESTOR)
DRV:64bit: - [2013/05/16 03:14:56 | 000,546,304 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
DRV:64bit: - [2013/04/24 12:31:10 | 000,096,768 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2013/04/04 14:50:32 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2013/02/12 00:12:06 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2012/12/06 09:42:12 | 002,350,176 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)
DRV:64bit: - [2012/10/12 04:49:10 | 000,042,664 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV:64bit: - [2012/10/12 04:49:08 | 000,082,600 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV:64bit: - [2012/10/03 13:19:14 | 000,168,096 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\MCLIENTx64\0302020.00C\ccsetx64.sys -- (ccSet_MCLIENT)
DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/08/01 15:59:06 | 000,045,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)
DRV:64bit: - [2011/07/28 18:37:10 | 000,052,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d)
DRV:64bit: - [2011/04/13 15:04:38 | 000,023,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nuidfltr.sys -- (NuidFltr)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/03/05 03:16:20 | 000,436,840 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/02/28 16:23:06 | 009,079,296 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011/02/28 15:17:20 | 000,299,520 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010/12/23 00:19:58 | 001,407,024 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010/11/29 07:50:38 | 000,044,672 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2010/11/24 08:41:00 | 000,125,456 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2010/11/20 23:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 23:23:47 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2010/11/20 23:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 23:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/07/28 12:13:50 | 000,031,088 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
DRV:64bit: - [2010/06/17 09:15:36 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie64.sys -- (AtiPcie)
DRV:64bit: - [2010/03/23 13:29:46 | 000,304,784 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CVPNDRVA.sys -- (CVPNDRVA)
DRV:64bit: - [2010/02/18 12:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2010/02/08 08:32:00 | 000,014,992 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CVirtA64.sys -- (CVirtA)
DRV:64bit: - [2010/01/18 16:40:26 | 000,004,608 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rcmirror.sys -- (rcmirror)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 20:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2009/07/13 20:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009/06/10 17:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
DRV:64bit: - [2009/06/10 17:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
DRV:64bit: - [2009/06/10 17:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
DRV:64bit: - [2009/06/10 16:35:35 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvm62x64.sys -- (NVENETFD)
DRV:64bit: - [2009/06/10 16:34:38 | 001,311,232 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2008/11/16 18:39:44 | 000,157,968 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dne64x.sys -- (DNE)
DRV:64bit: - [2006/11/29 18:24:49 | 000,024,064 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wanatw64.sys -- (wanatw)
DRV - [2013/09/24 00:37:14 | 001,525,848 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Norton 360 Premier Edition\NortonData\21.0.1.3\Definitions\BASHDefs\20130924.001\BHDrvx64.sys -- (BHDrvx64)
DRV - [2013/09/22 01:00:00 | 002,099,288 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Norton 360 Premier Edition\NortonData\21.0.1.3\Definitions\VirusDefs\20131005.007\ex64.sys -- (NAVEX15)
DRV - [2013/09/22 01:00:00 | 000,484,952 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)
DRV - [2013/09/22 01:00:00 | 000,140,376 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2013/09/22 01:00:00 | 000,126,040 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Norton 360 Premier Edition\NortonData\21.0.1.3\Definitions\VirusDefs\20131005.007\eng64.sys -- (NAVENG)
DRV - [2013/09/21 00:37:40 | 000,520,280 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Norton 360 Premier Edition\NortonData\21.0.1.3\Definitions\IPSDefs\20131004.001\IDSviA64.sys -- (IDSVia64)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{2726EAAE-E2F9-413D-9BB8-BD280A0E30FC}: "URL" = http://www.amazon.com/s/ref=azs_osd...code=qs&index=aps&field-keywords={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-30572-11896-2/4?mpre=http://shop.ebay.com/?_nkw={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-30572-11896-2/4?mpre=http://shop.ebay.com/?_nkw={searchTerms}


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-2848903972-3699595445-501089177-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/hpnot/1
IE - HKU\S-1-5-21-2848903972-3699595445-501089177-1001\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2848903972-3699595445-501089177-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
IE - HKU\S-1-5-21-2848903972-3699595445-501089177-1001\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-30572-11896-2/4?mpre=http://shop.ebay.com/?_nkw={searchTerms}
IE - HKU\S-1-5-21-2848903972-3699595445-501089177-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\motulken\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/07/18 00:34:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6D5C8FC4-DE46-41bf-9092-93F0F78E9115}: C:\ProgramData\Norton\{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}\NSM_2.6.0.52\coFFFw\ [2013/10/06 00:45:10 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.0.1.3\IPSFFPlgn\ [2013/09/22 21:29:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.0.1.3\coFFPlgn\ [2013/10/06 00:45:06 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/07/18 00:34:12 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2013/10/05 00:29:10 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.0.1.3\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.0.1.3\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Norton Family BHO) - {B8E07826-0971-4f16-B133-047B88034E89} - C:\Program Files (x86)\Norton Family\Engine\2.9.0.26\coieplg.dll (Symantec Corporation)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.0.1.3\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - No CLSID value found.
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll File not found
O3 - HKU\S-1-5-21-2848903972-3699595445-501089177-1001\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.0.1.3\CoIEPlg.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-2848903972-3699595445-501089177-1001\..\Toolbar\WebBrowser: (AOL Toolbar) - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll File not found
O4:64bit: - HKLM..\Run: [Logitech Download Assistant] C:\Windows\SysNative\LogiLDA.dll (Logitech, Inc.)
O4 - HKLM..\Run: [EPSON_UD_START] C:\Program Files (x86)\EPSON Projector\EPSON USB Display V1.4\EMP_UD.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe (Hewlett-Packard Development Company L.P.)
O4 - HKLM..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKU\.DEFAULT..\Run: [Norton Download Manager{N360P21013-SHPD-FSD40014}] C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\ccSvcHst.exe (Symantec Corporation)
O4 - HKU\S-1-5-18..\Run: [Norton Download Manager{N360P21013-SHPD-FSD40014}] C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\ccSvcHst.exe (Symantec Corporation)
O4 - HKU\S-1-5-21-2848903972-3699595445-501089177-1001..\Run: [AOL Fast Start] C:\Program Files (x86)\AOL Desktop 9.7a\AOL.EXE (AOL Inc.)
O4 - HKLM..\RunOnce: [*TampMon] C:\Program Files (x86)\Norton Family\Engine\2.9.0.26\tampmon.exe (Symantec Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 -
 
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2848903972-3699595445-501089177-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2848903972-3699595445-501089177-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-2848903972-3699595445-501089177-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKU\S-1-5-21-2848903972-3699595445-501089177-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-2848903972-3699595445-501089177-1001\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} https://h20364.www2.hp.com/CSMWeb/Customer/cabs/HPISDataManager.CAB (Reg Error: Key error.)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect1263.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/3.0.1.0/GarminAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2E313954-EA41-4580-B222-A43372EAD6DB}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/10/06 01:12:22 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\motulken\Documents\OTL.exe
[2013/10/06 00:53:43 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013/10/05 01:04:13 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2013/10/05 00:53:05 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013/10/05 00:08:37 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013/10/05 00:08:37 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013/10/05 00:08:37 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013/10/05 00:03:47 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/10/05 00:00:40 | 005,130,782 | R--- | C] (Swearware) -- C:\Users\motulken\Documents\ComboFix.exe
[2013/10/04 23:37:23 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013/10/04 20:21:02 | 000,000,000 | ---D | C] -- C:\Users\motulken\Desktop\mbar
[2013/10/04 20:09:08 | 000,000,000 | ---D | C] -- C:\Windows\snack
[2013/10/04 20:05:21 | 000,000,000 | ---D | C] -- C:\Users\motulken\Desktop\RK_Quarantine
[2013/09/30 11:59:39 | 000,000,000 | ---D | C] -- C:\Users\motulken\Documents\ttr90s italjet WP_000770
[2013/09/30 11:44:46 | 000,000,000 | ---D | C] -- C:\Users\motulken\Documents\ttr90 WP_000767
[2013/09/28 09:13:35 | 000,000,000 | ---D | C] -- C:\Users\motulken\Documents\jeep WP_000798
[2013/09/22 21:23:21 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360 Premier Edition
[2013/09/22 20:25:28 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013/09/22 20:17:17 | 000,000,000 | ---D | C] -- C:\Users\motulken\AppData\Roaming\Malwarebytes
[2013/09/22 20:17:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/09/22 20:17:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013/09/22 20:17:05 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013/09/22 20:17:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/09/22 18:50:50 | 000,000,000 | ---D | C] -- C:\ProgramData\iolo
[2013/09/21 13:06:24 | 000,000,000 | ---D | C] -- C:\Users\motulken\Documents\MailingInsert_Page-1
[2013/09/21 10:41:41 | 000,000,000 | ---D | C] -- C:\Users\motulken\Documents\FallWinterProgram1(Aug14)update2
[2013/09/19 16:48:33 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZipDisabled
[2013/09/19 04:33:59 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013/09/19 04:33:58 | 000,526,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013/09/19 04:33:57 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2013/09/19 04:33:57 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2013/09/19 04:33:57 | 000,089,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/09/19 04:33:57 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/09/19 04:33:57 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2013/09/19 04:33:57 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2013/09/19 04:33:57 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2013/09/19 04:33:57 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2013/09/19 04:33:57 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2013/09/19 04:33:55 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013/09/19 04:33:55 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013/09/19 04:33:55 | 000,603,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013/09/19 04:33:54 | 003,959,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013/09/19 04:30:44 | 000,546,304 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\drivers\stwrt64.sys
[2013/09/19 04:30:41 | 000,499,200 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stcplx64.dll
[2013/09/19 04:30:40 | 002,194,432 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stapo64.dll
[2013/09/19 04:30:40 | 000,693,760 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\stapi64.dll
[2013/09/19 04:30:39 | 000,256,000 | ---- | C] (IDT, Inc.) -- C:\Windows\SysNative\st646479.dll
[2013/09/19 04:30:28 | 000,000,000 | ---D | C] -- C:\Program Files\IDT
[2013/09/19 03:39:45 | 000,082,600 | ---- | C] (Advanced Micro Devices) -- C:\Windows\SysNative\drivers\amd_sata.sys
[2013/09/19 03:39:45 | 000,042,664 | ---- | C] (Advanced Micro Devices) -- C:\Windows\SysNative\drivers\amd_xata.sys
[2013/09/19 01:59:43 | 000,000,000 | ---D | C] -- C:\Windows\Repair
[2013/09/18 22:41:44 | 000,045,856 | ---- | C] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/09/18 22:26:58 | 000,000,000 | ---D | C] -- C:\Users\motulken\AppData\Roaming\Nico Mak Computing
[2013/09/18 22:26:50 | 000,000,000 | ---D | C] -- C:\Users\motulken\AppData\Local\Programs
[2013/09/18 16:09:57 | 000,000,000 | ---D | C] -- C:\Users\motulken\Documents\brick11-12
[2013/09/17 10:25:48 | 000,000,000 | ---D | C] -- C:\Users\motulken\Documents\NewCSR2Helmets(email)
[2013/09/12 01:39:56 | 000,155,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\ataport.sys
[2013/09/12 01:39:53 | 003,968,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2013/09/12 01:39:52 | 003,913,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2013/09/12 01:39:51 | 005,550,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2013/09/12 01:39:51 | 001,732,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2013/09/12 01:39:51 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
[2013/09/12 01:39:51 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2013/09/12 01:39:51 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2013/09/12 01:39:50 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
[2013/09/12 01:39:50 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe
[2013/09/12 01:39:50 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2013/09/12 01:39:50 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\smss.exe
[2013/09/12 01:39:50 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2013/09/12 01:39:50 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2013/09/12 01:39:50 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll
[2013/09/12 01:39:50 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2013/09/12 01:39:50 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
[2013/09/12 01:39:50 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2013/09/12 01:39:50 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\apisetschema.dll
[2013/09/12 01:39:50 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\apisetschema.dll
[2013/09/12 01:39:50 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2013/09/12 01:39:50 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2013/09/12 01:39:50 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2013/09/12 01:39:50 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2013/09/12 01:39:50 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2013/09/12 01:39:50 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2013/09/12 01:39:50 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2013/09/12 01:39:50 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2013/09/12 01:39:50 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2013/09/12 01:39:50 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/09/12 01:39:50 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/09/12 01:39:50 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2013/09/12 01:39:50 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2013/09/12 01:39:50 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2013/09/12 01:39:50 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2013/09/12 01:39:50 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2013/09/12 01:39:50 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2013/09/12 01:39:50 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2013/09/12 01:39:50 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2013/09/12 01:39:50 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2013/09/12 01:39:44 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\shdocvw.dll
[2013/09/06 18:01:40 | 000,000,000 | ---D | C] -- C:\Users\motulken\Documents\WP_000762
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\motulken\Documents\*.tmp files -> C:\Users\motulken\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/10/06 01:12:27 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\motulken\Documents\OTL.exe
[2013/10/06 01:05:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/10/06 00:52:27 | 000,032,064 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/10/06 00:52:27 | 000,032,064 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/10/06 00:44:44 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/10/06 00:44:35 | 3015,888,896 | -HS- | M] () -- C:\hiberfil.sys
[2013/10/05 12:20:09 | 000,797,568 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/10/05 12:20:09 | 000,672,708 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/10/05 12:20:09 | 000,126,544 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/10/05 00:29:10 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013/10/04 23:45:10 | 005,130,782 | R--- | M] (Swearware) -- C:\Users\motulken\Documents\ComboFix.exe
[2013/10/04 21:21:11 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleFormotulken.job
[2013/10/04 20:09:08 | 000,096,768 | ---- | M] () -- C:\Windows\SysNative\drivers\AtihdW76.sys.dump
[2013/10/04 20:02:42 | 000,099,608 | ---- | M] () -- C:\Users\motulken\Documents\RogueKiller.exe
[2013/10/04 20:00:20 | 000,001,977 | ---- | M] () -- C:\Users\motulken\Desktop\malware scan dds - Shortcut.lnk
[2013/10/04 19:57:56 | 674,311,148 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2013/10/03 18:01:18 | 000,384,289 | ---- | M] () -- C:\Users\motulken\Documents\FederalGovernmentShutsDown-NowWhatHappens.pdf
[2013/10/03 11:58:23 | 000,000,172 | ---- | M] () -- C:\Windows\SysNative\drivers\NSMx64\0209000.01A\isolate.ini
[2013/10/03 07:40:17 | 000,001,668 | ---- | M] () -- C:\Windows\SysNative\ASOROSet.bin
[2013/10/03 00:08:59 | 000,002,487 | ---- | M] () -- C:\StartUpManager_scandataOUTPUT.xml
[2013/10/03 00:08:55 | 000,004,017 | ---- | M] () -- C:\StartUpManager_scandataINPUT.xml
[2013/10/02 16:57:41 | 000,015,033 | ---- | M] () -- C:\Windows\SysNative\drivers\N360x64\1500010.003\VT20131002.007
[2013/10/01 10:20:07 | 000,007,535 | ---- | M] () -- C:\Users\motulken\Documents\INVOICE_RECAP_131001_T1C.pdf
[2013/09/30 17:15:34 | 000,603,841 | ---- | M] () -- C:\Users\motulken\Documents\img004.jpg
[2013/09/30 11:44:46 | 003,501,673 | ---- | M] () -- C:\Users\motulken\Documents\ttr90 WP_000767.zip
[2013/09/28 09:13:34 | 002,028,618 | ---- | M] () -- C:\Users\motulken\Documents\jeep WP_000798.zip
[2013/09/27 18:11:41 | 000,008,192 | ---- | M] () -- C:\Windows\SysNative\drivers\NSMx64\0209000.01A\symrdr64.cat
[2013/09/25 21:11:25 | 000,007,432 | ---- | M] () -- C:\Users\motulken\Documents\INVOICE_RECAP_130925_T1Y.pdf
[2013/09/24 21:18:48 | 001,320,731 | ---- | M] () -- C:\Users\motulken\Documents\8pageflyerHondaSep12-13.pdf
[2013/09/24 19:52:24 | 000,372,015 | ---- | M] () -- C:\Users\motulken\Documents\SALES_RANK_REPORT_T1Y.pdf
[2013/09/23 22:57:33 | 000,245,848 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\NSMx64\0209000.01A\symrdrs.sys
[2013/09/23 21:07:06 | 000,001,455 | ---- | M] () -- C:\Windows\SysNative\drivers\NSMx64\0209000.01A\symrdr.inf
[2013/09/23 18:18:24 | 000,008,594 | ---- | M] () -- C:\Users\motulken\Documents\Ralph DEALER_PERFORMANCE_REPORT_TL.pdf
[2013/09/23 17:44:19 | 000,002,019 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2013/09/23 17:21:47 | 000,006,775 | ---- | M] () -- C:\Users\motulken\Documents\SALES_RANK_REPORT_TL.pdf
[2013/09/22 21:23:23 | 000,002,486 | ---- | M] () -- C:\Users\Public\Desktop\Norton 360.lnk
[2013/09/22 21:21:50 | 002,044,956 | ---- | M] () -- C:\Windows\SysNative\drivers\N360x64\1500010.003\Cat.DB
[2013/09/22 21:19:38 | 000,177,752 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2013/09/22 21:19:38 | 000,008,222 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2013/09/22 21:19:38 | 000,000,854 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2013/09/22 20:17:07 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/09/22 18:51:01 | 000,074,703 | ---- | M] () -- C:\Windows\SysWow64\mfc45.dat
[2013/09/22 12:14:25 | 000,001,297 | ---- | M] () -- C:\Users\motulken\Desktop\Norton Installation Files.lnk
[2013/09/21 22:00:43 | 000,513,024 | ---- | M] () -- C:\Users\motulken\Documents\family pic.jpg
[2013/09/21 13:57:30 | 003,772,142 | ---- | M] () -- C:\Users\motulken\Documents\Military-Handout(email).pdf
[2013/09/21 13:56:27 | 001,137,226 | ---- | M] () -- C:\Users\motulken\Documents\FreeShield-RKTLid(June13).pdf
[2013/09/21 13:47:30 | 005,038,229 | ---- | M] () -- C:\Users\motulken\Documents\JoeRocket-Liners(email).pdf
[2013/09/21 13:40:23 | 000,511,976 | ---- | M] () -- C:\Users\motulken\Documents\AdvertisingPolicy07-01-13revised07-15-13.pdf
[2013/09/21 13:06:24 | 002,620,845 | ---- | M] () -- C:\Users\motulken\Documents\MailingInsert_Page-1.zip
[2013/09/21 12:53:01 | 007,478,529 | ---- | M] () -- C:\Users\motulken\Documents\SullivansPrograms.pdf
[2013/09/21 12:30:56 | 001,008,405 | ---- | M] () -- C:\Users\motulken\Documents\CL17Info-A.pdf
[2013/09/21 10:41:41 | 000,921,726 | ---- | M] () -- C:\Users\motulken\Documents\FallWinterProgram1(Aug14)update2.zip
[2013/09/21 10:40:33 | 001,151,043 | ---- | M] () -- C:\Users\motulken\Documents\RTCommuterCover(Email).pdf
[2013/09/21 10:35:03 | 000,485,945 | ---- | M] () -- C:\Users\motulken\Documents\HelmetWeights(9-18-13).pdf
[2013/09/21 01:00:00 | 001,944,909 | ---- | M] () -- C:\Users\motulken\Documents\MailingInsert_Page-3.pdf
[2013/09/21 01:00:00 | 000,662,612 | ---- | M] () -- C:\Users\motulken\Documents\FallWinterProgram2(Aug14)update2.pdf
[2013/09/21 01:00:00 | 000,652,765 | ---- | M] () -- C:\Users\motulken\Documents\FallWinterProgram1(Aug14)update2.pdf
[2013/09/20 07:05:14 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/09/20 07:05:14 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/09/19 23:57:11 | 000,208,481 | ---- | M] () -- C:\Windows\hpoins43.dat
[2013/09/19 04:33:34 | 000,814,264 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013/09/18 22:41:18 | 000,045,856 | ---- | M] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/09/18 16:09:57 | 002,073,390 | ---- | M] () -- C:\Users\motulken\Documents\brick11-12.zip
[2013/09/17 10:25:48 | 002,920,326 | ---- | M] () -- C:\Users\motulken\Documents\NewCSR2Helmets(email).zip
[2013/09/17 10:25:00 | 003,588,831 | ---- | M] () -- C:\Users\motulken\Documents\NewFGXHelmets(email).pdf
[2013/09/17 10:24:16 | 001,585,578 | ---- | M] () -- C:\Users\motulken\Documents\NewCLXY_CSMXHelmets(email).pdf
[2013/09/12 10:02:11 | 000,345,840 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013/09/09 12:36:23 | 002,540,707 | ---- | M] () -- C:\Users\motulken\Documents\NewIS17Helmets(email).pdf
[2013/09/06 18:01:39 | 002,936,122 | ---- | M] () -- C:\Users\motulken\Documents\WP_000762.zip
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\motulken\Documents\*.tmp files -> C:\Users\motulken\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/10/05 00:08:37 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013/10/05 00:08:37 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013/10/05 00:08:37 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013/10/05 00:08:37 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013/10/05 00:08:37 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013/10/04 20:09:08 | 000,096,768 | ---- | C] () -- C:\Windows\SysNative\drivers\AtihdW76.sys.dump
[2013/10/04 20:00:20 | 000,001,977 | ---- | C] () -- C:\Users\motulken\Desktop\malware scan dds - Shortcut.lnk
[2013/10/04 19:30:32 | 000,099,608 | ---- | C] () -- C:\Users\motulken\Documents\RogueKiller.exe
[2013/10/03 18:01:17 | 000,384,289 | ---- | C] () -- C:\Users\motulken\Documents\FederalGovernmentShutsDown-NowWhatHappens.pdf
[2013/10/01 10:20:07 | 000,007,535 | ---- | C] () -- C:\Users\motulken\Documents\INVOICE_RECAP_131001_T1C.pdf
[2013/09/30 17:15:31 | 000,603,841 | ---- | C] () -- C:\Users\motulken\Documents\img004.jpg
[2013/09/30 11:44:37 | 003,501,673 | ---- | C] () -- C:\Users\motulken\Documents\ttr90 WP_000767.zip
[2013/09/30 11:01:29 | 000,070,666 | ---- | C] () -- C:\Users\motulken\Documents\nolandracePicture.jpg
[2013/09/28 09:13:28 | 002,028,618 | ---- | C] () -- C:\Users\motulken\Documents\jeep WP_000798.zip
[2013/09/25 21:11:19 | 000,007,432 | ---- | C] () -- C:\Users\motulken\Documents\INVOICE_RECAP_130925_T1Y.pdf
[2013/09/24 21:17:17 | 001,320,731 | ---- | C] () -- C:\Users\motulken\Documents\8pageflyerHondaSep12-13.pdf
[2013/09/24 19:52:07 | 000,372,015 | ---- | C] () -- C:\Users\motulken\Documents\SALES_RANK_REPORT_T1Y.pdf
[2013/09/23 18:18:24 | 000,008,594 | ---- | C] () -- C:\Users\motulken\Documents\Ralph DEALER_PERFORMANCE_REPORT_TL.pdf
[2013/09/23 17:44:18 | 000,002,019 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader XI.lnk
[2013/09/23 17:44:16 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
[2013/09/23 17:21:45 | 000,006,775 | ---- | C] () -- C:\Users\motulken\Documents\SALES_RANK_REPORT_TL.pdf
[2013/09/22 21:19:36 | 000,002,486 | ---- | C] () -- C:\Users\Public\Desktop\Norton 360.lnk
[2013/09/22 20:17:07 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/09/22 18:51:01 | 000,074,703 | ---- | C] () -- C:\Windows\SysWow64\mfc45.dat
[2013/09/21 13:56:24 | 001,137,226 | ---- | C] () -- C:\Users\motulken\Documents\FreeShield-RKTLid(June13).pdf
[2013/09/21 13:47:19 | 005,038,229 | ---- | C] () -- C:\Users\motulken\Documents\JoeRocket-Liners(email).pdf
[2013/09/21 13:40:22 | 000,511,976 | ---- | C] () -- C:\Users\motulken\Documents\AdvertisingPolicy07-01-13revised07-15-13.pdf
[2013/09/21 13:10:43 | 001,944,909 | ---- | C] () -- C:\Users\motulken\Documents\MailingInsert_Page-3.pdf
[2013/09/21 13:10:43 | 001,357,428 | ---- | C] () -- C:\Users\motulken\Documents\JoeRocketClothingRackDisplay.pdf
[2013/09/21 13:10:43 | 000,662,612 | ---- | C] () -- C:\Users\motulken\Documents\FallWinterProgram2(Aug14)update2.pdf
[2013/09/21 13:10:43 | 000,652,765 | ---- | C] () -- C:\Users\motulken\Documents\FallWinterProgram1(Aug14)update2.pdf
[2013/09/21 13:10:43 | 000,203,381 | ---- | C] () -- C:\Users\motulken\Documents\BestSellingProducts08-12.pdf
[2013/09/21 13:06:18 | 002,620,845 | ---- | C] () -- C:\Users\motulken\Documents\MailingInsert_Page-1.zip
[2013/09/21 12:52:42 | 007,478,529 | ---- | C] () -- C:\Users\motulken\Documents\SullivansPrograms.pdf
[2013/09/21 12:30:54 | 001,008,405 | ---- | C] () -- C:\Users\motulken\Documents\CL17Info-A.pdf
[2013/09/21 10:41:39 | 000,921,726 | ---- | C] () -- C:\Users\motulken\Documents\FallWinterProgram1(Aug14)update2.zip
[2013/09/21 10:40:29 | 001,151,043 | ---- | C] () -- C:\Users\motulken\Documents\RTCommuterCover(Email).pdf
[2013/09/21 10:35:01 | 000,485,945 | ---- | C] () -- C:\Users\motulken\Documents\HelmetWeights(9-18-13).pdf
[2013/09/19 16:43:18 | 000,002,487 | ---- | C] () -- C:\StartUpManager_scandataOUTPUT.xml
[2013/09/19 16:43:04 | 000,004,017 | ---- | C] () -- C:\StartUpManager_scandataINPUT.xml
[2013/09/19 02:36:35 | 000,001,668 | ---- | C] () -- C:\Windows\SysNative\ASOROSet.bin
[2013/09/18 16:09:49 | 002,073,390 | ---- | C] () -- C:\Users\motulken\Documents\brick11-12.zip
[2013/09/17 10:25:41 | 002,920,326 | ---- | C] () -- C:\Users\motulken\Documents\NewCSR2Helmets(email).zip
[2013/09/17 10:24:51 | 003,588,831 | ---- | C] () -- C:\Users\motulken\Documents\NewFGXHelmets(email).pdf
[2013/09/17 10:24:12 | 001,585,578 | ---- | C] () -- C:\Users\motulken\Documents\NewCLXY_CSMXHelmets(email).pdf
[2013/09/09 12:36:16 | 002,540,707 | ---- | C] () -- C:\Users\motulken\Documents\NewIS17Helmets(email).pdf
[2013/09/06 18:01:30 | 002,936,122 | ---- | C] () -- C:\Users\motulken\Documents\WP_000762.zip
[2013/04/29 11:31:40 | 000,000,017 | ---- | C] () -- C:\Windows\SysWow64\shortcut_ex.dat
[2013/03/11 21:28:39 | 003,130,440 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_blr.exe
[2013/01/27 22:00:55 | 000,283,032 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013/01/27 22:00:54 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012/11/21 12:21:55 | 003,130,440 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_blr[1].exe
[2012/09/08 22:13:07 | 000,007,605 | ---- | C] () -- C:\Users\motulken\AppData\Local\resmon.resmoncfg
[2012/09/08 21:49:47 | 003,380,224 | ---- | C] () -- C:\Windows\SysWow64\CrypticError.exe
[2012/04/05 15:28:05 | 038,863,416 | ---- | C] () -- C:\Users\motulken\Advertising items catalogue 2012 + Price list.zip
[2012/03/05 22:46:45 | 000,014,119 | ---- | C] () -- C:\Windows\SysWow64\RaCoInst.dat
[2011/10/09 10:23:41 | 000,201,475 | ---- | C] () -- C:\Windows\hpoins43.dat.temp
[2011/08/01 22:18:52 | 000,000,096 | ---- | C] () -- C:\Users\motulken\AppData\Local\fusioncache.dat

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/07/25 22:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/25 21:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 21:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 23:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 21:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
< End of report >
 
Here is the OTL Extra log
split into twp replies

OTL Extras logfile created on: 10/6/2013 1:12:47 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\motulken\Documents
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16686)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 2.21 Gb Available Physical Memory | 58.97% Memory free
7.49 Gb Paging File | 5.67 Gb Available in Paging File | 75.71% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 450.76 Gb Total Space | 328.92 Gb Free Space | 72.97% Space Free | Partition Type: NTFS
Drive D: | 14.71 Gb Total Space | 1.64 Gb Free Space | 11.15% Space Free | Partition Type: NTFS

Computer Name: MOTULKEN-HP | User Name: motulken | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = aolfile_HTM] -- C:\Program Files (x86)\AOL Desktop 9.7a\aol.exe (AOL Inc.)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00978057-685C-4054-A7CA-CA4A10EF44D8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{050C7415-9788-4270-B4BC-3073CFB16B70}" = lport=2869 | protocol=6 | dir=in | app=system |
"{08090274-7F62-49A7-BE93-0B341C2687EB}" = lport=26675 | protocol=6 | dir=in | name=@%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{0F5393BD-7C0D-4F38-98C3-7E45DF76DE0B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1E8352F6-C3F0-457A-9AF4-24CD22550ECF}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{1FA1A0A5-8D59-4465-B51A-8DF924729B64}" = lport=138 | protocol=17 | dir=in | app=system |
"{1FCAF848-7498-4949-B60A-0F0C97FD62C8}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{21212155-E01C-4192-9493-CCFA5732600F}" = lport=137 | protocol=17 | dir=in | app=system |
"{233CD7A9-566E-4596-AD81-855B8221A66B}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{23586BDB-DFCA-427A-A9DA-C5FE091CD1CE}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{2CB569EE-C788-4BCB-BD28-95F2882847A6}" = rport=137 | protocol=17 | dir=out | app=system |
"{328A4CA5-3D8D-4DEB-B6ED-3F0BBE5D9FAA}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4E5090B1-55E7-4A05-A766-4FB31AEA704C}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4FF6E336-C888-4888-8C9F-52A38A51F155}" = rport=445 | protocol=6 | dir=out | app=system |
"{55BCC87F-4E88-48E6-AAA8-1FA7B29BAE89}" = lport=445 | protocol=6 | dir=in | app=system |
"{5A07DEC9-AB96-46D2-B416-E4F792598501}" = lport=10243 | protocol=6 | dir=in | app=system |
"{5F07A200-46E4-40BD-97E1-50F87B0A9F93}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe |
"{689BF7C2-40FF-475C-BDC4-B6E4CED2426E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6CAF9DEB-12D0-4271-B2A1-C243F672F98D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6E83484B-0C7C-4127-B217-54BCA6D2D4DE}" = lport=139 | protocol=6 | dir=in | app=system |
"{830D6188-72B4-489C-ABA7-7A6F711CBEB3}" = rport=138 | protocol=17 | dir=out | app=system |
"{92CB9D56-82F0-4366-A99B-A14CE2860FB3}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{92ED094D-5D83-419A-946C-4B08F49E9AB5}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{A6749C26-9463-47B1-82F6-6223E8E0C318}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A7230F3E-374B-4893-8ED6-8967DCF470E3}" = rport=10243 | protocol=6 | dir=out | app=system |
"{ABE86BE8-8772-486B-8D3D-81A7E02D2F52}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B5806BE0-47D9-48D5-B2DF-4ABA139FBBFC}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{B58DE479-59DE-451A-9E9A-9BAE220B7913}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{BCA98E97-9F5A-4A07-A637-0A207042BF17}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{EBFB7B4B-CF21-4926-99D8-DC4DF3013F49}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{ED8E1763-61DF-4AFC-B01F-49A63614E8C7}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FA423F7D-98B0-43B4-B1C2-54BB7616DA64}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{FB31E41A-518E-4DB8-8882-585B94890618}" = rport=139 | protocol=6 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{049851F3-E45F-48FA-B5CE-068D4AB3F3D1}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe |
"{0568BA21-86E5-4A41-86DD-59D467C51BE0}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe |
"{0A397812-C513-4850-9AB4-6AC395E08DBB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0AD44C3D-C589-42DE-B025-7468FF650A5A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0B6B9896-E1B0-42E4-BC97-5F98948A8040}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{0C9103A5-A4E7-40B1-94CF-FBFC6DBB302B}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\topspeed\3.0\aoltpsd3.exe |
"{0DFBC9C3-F0F0-4ACB-9E79-2C350F2BF7C3}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{16CF247F-A741-48F4-8938-1C74E4B3AAC7}" = dir=in | app=c:\program files (x86)\easybits for kids\ezdesktop.exe |
"{1822EC1A-C918-4808-A4EC-C73D188BA9A2}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{1D693BB2-761F-4BD2-8CF5-346D106E8529}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{1FA85ED1-8B1C-4819-AE88-B9F5BAD04255}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\acs\aoldial.exe |
"{21DC7635-4D1F-4DA1-B036-DA15900BDB2E}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe |
"{2264205F-0C13-40DE-BD0A-87C77A6E348F}" = dir=in | app=c:\users\motulken\appdata\local\temp\7zs2883\setup\hpznui40.exe |
"{232E1353-F70A-4DD1-A056-02EA1DC8FA7B}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{272C0F9C-BD2D-448F-96BE-ACEDEC0E5810}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe |
"{2EE1CFE5-21E1-441D-AC28-AA8487AA1261}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{31CC8511-36A6-43B3-9893-ED983B53F47F}" = protocol=6 | dir=in | app=c:\program files (x86)\aol desktop 9.7\waol.exe |
"{32F0D298-B4DC-47BA-9BEB-B35D73C579FD}" = protocol=17 | dir=in | app=c:\program files (x86)\aol desktop 9.7a\waol.exe |
"{35788D79-BECA-4593-9FED-814201DEBC36}" = dir=in | app=c:\windows\system32\ezsharedsvchost.exe |
"{37779C04-EC25-4C4E-B23A-5FED7BA4139B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\soldierfront2\dfubg.exe |
"{380360B6-D0FD-4FF7-8617-2067649080C5}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3999733E-8C90-427A-860E-1575A0991D00}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3A2A807B-5EE4-4DAF-884F-6B056786E230}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{3E015E06-0791-440E-BD7B-80CC595ED29B}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\1310957960\ee\aolsoftware.exe |
"{3E181EEE-90C2-4863-99AE-36858C3AB168}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{4016F0C6-FA7B-45F5-9B84-32109805D0BA}" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe |
"{428D3E1B-D727-4D03-B743-0F3A6DA2FB34}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{43F9A9F3-7582-475B-B782-E345CFB8E453}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{44C573A5-7B8F-4C21-A726-96F04C48C2AF}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\system information\sinf.exe |
"{4555BE85-7E44-4B32-88DC-DE8068D3969C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ava\nwzlauncher.exe |
"{45BB7E3D-D54E-4FFC-A042-5544E9DAD105}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{47D912B2-C82D-44DE-8DDB-A92ABFCAD6AB}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe |
"{48EDE948-C8EF-4BCF-BAF1-76B3729E6ED6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{4B49604E-12C1-4CD6-B636-B2B31730961F}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{4C441A14-920E-40DB-BDD8-B9EA800439ED}" = protocol=6 | dir=in | app=c:\program files (x86)\aol desktop 9.7a\waol.exe |
"{55227DB4-8B32-466B-9F0F-64216AF5BDD0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\soldierfront2\binaries\win32\sf2.exe |
"{5539C2D8-18D5-4268-B921-A2C8FDC214FA}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{5553282E-5758-487A-9FF1-D2D17DD84779}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ava\nwzlauncher.exe |
"{579D05FD-E9B5-4645-8E02-F6526F32B119}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe |
"{5BC681D2-1A56-4B7F-ABEA-C75C9E717D11}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{5CF0811C-6117-4D20-9042-45B9AAEB279F}" = protocol=17 | dir=in | app=c:\program files (x86)\aol desktop 9.7\aolbrowser\aolbrowser.exe |
"{5EA80F16-3A86-43CA-9510-ACF6C06AC98F}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{61E4C8B8-36E3-441B-A5D9-BDEDE9A63C2C}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{64B8F929-A5B1-4ACE-86FC-223AB4679926}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{6524AE11-0193-4004-817B-E37F13D12A9E}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe |
"{65EB0C1F-8A12-495E-9A8E-05E68C0022D4}" = dir=in | app=c:\program files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{6855EC5F-9644-4C9F-88C4-FE96AE3E0F7B}" = protocol=17 | dir=in | app=c:\program files (x86)\aol desktop 9.7a\aolbrowser\aolbrowser.exe |
"{693ED6A3-B821-4E98-82E6-A697FE50FBED}" = protocol=17 | dir=in | app=c:\program files (x86)\aol desktop 9.6\waol.exe |
"{6BA1CD3C-F3BD-4A20-98CD-C7D25C19E097}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{702FE45A-2ABE-4D22-927B-FFA3FB6656AA}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\acs\aoldial.exe |
"{70AABC40-64F7-4A24-BB55-A84C7ECD79A3}" = protocol=6 | dir=in | app=c:\program files (x86)\raptr\raptr_im.exe |
"{71305B45-B0E0-4616-AF0A-0523F2FA59AF}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{72014CDD-FD38-4006-B3DD-6A0EA09A884E}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe |
"{72DDA913-B7D2-4073-992D-B0E66AD1C7A6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\soldierfront2\dfubg.exe |
"{73641EF8-805F-4F3E-9EEF-2C0E23604B9F}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{7469F0A8-4D1D-4683-AD1E-73FDAFCA6347}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{74A7B8E7-36D8-4F15-B9A7-412EB9FC2691}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{75C55363-9C8B-48E8-A67F-64683ED6C072}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7664B475-A3B6-459F-B9E1-596D0E490FC8}" = protocol=17 | dir=in | app=c:\program files (x86)\aol desktop 9.6\aolbrowser\aolbrowser.exe |
"{799123FD-9FC5-4606-AF66-626921F3EC10}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7C691C44-0333-46C8-B63B-8F4594153471}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe |
"{7EEDAEC8-26A4-499C-8C34-5DBE575680C8}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\acs\aolacsd.exe |
"{83BB57CB-F2E6-4A19-86B0-29B6E3B60430}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpwarrantychecker.exe |
"{84459F92-C99B-4FB4-A022-FC9659652360}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{85C030D8-6573-400B-A12C-47958F8266B1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\blacklightretribution\blacklight retribution.exe |
"{8BA40AAA-FF24-4A26-A4F1-F25E1BF91F30}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\acs\aolacsd.exe |
"{91803447-188C-46E2-A413-1388FC1DE3B0}" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe |
"{958B3F19-4A23-491E-9950-1D1A8BD2973C}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{95FFA750-BC8F-47DE-80DE-A9457DB45B14}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\1310957960\ee\aolsoftware.exe |
"{98212D8B-1283-44FF-B8EA-B1C7DAB313AB}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{991650EB-AE4B-410E-8EC6-AB53F844BBCE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\blacklightretribution\blacklight retribution.exe |
"{9A317BBF-F470-4A3D-9F3D-292BE8E21491}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{A182CBC8-253A-4D9E-8F5A-C95A6C91D25F}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{A2083E66-516F-40D2-B7D0-D4D40872771D}" = protocol=6 | dir=in | app=c:\program files (x86)\roxio\roxionow player\rnowshell.exe |
"{A43CA14E-430C-4DE0-87F1-43C008432487}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{A82602FC-7315-4BE3-8CD5-0D14EF9C05C3}" = protocol=17 | dir=in | app=c:\program files (x86)\roxio\roxionow player\rnowshell.exe |
"{B1F0DEF0-7811-4B0D-B572-D5587B3E157B}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{B3C62381-394C-4AC8-96ED-E2663C2B7477}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe |
"{B540D842-808C-4D18-BC6C-3BE669ADB6D1}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{BF5ABD3C-F6A2-4BF5-B4E5-00E69F280514}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{BF717D4A-37B8-4B1D-8A71-971EC0F8903F}" = protocol=6 | dir=in | app=c:\program files (x86)\aol desktop 9.6\waol.exe |
"{C04191C7-16F1-4A95-9371-4312B6FDE0FC}" = protocol=6 | dir=in | app=c:\program files (x86)\aol desktop 9.7\aolbrowser\aolbrowser.exe |
"{C28BFB64-CDFD-4336-9DFB-8D8FE9991D89}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{C80D2377-98E8-4505-A429-B6B19E705995}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D0AAEC8A-CD5D-405F-A04A-0E2B85EC9EF0}" = protocol=17 | dir=in | app=c:\program files (x86)\raptr\raptr.exe |
"{D48F7BF5-E1F1-47E4-B5D5-B12622DCDD9F}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\topspeed\3.0\aoltpsd3.exe |
"{D738D730-AFF5-4CF8-8572-7900F3590632}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{DA2AE8D3-ACA4-465C-BF9E-12E78362EA87}" = protocol=6 | dir=in | app=c:\program files (x86)\aol desktop 9.6\aolbrowser\aolbrowser.exe |
"{DCCB860D-9C1E-4B73-A443-66C23BA6DF2B}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{E1315489-47C4-418A-9A7C-9C0420D5522E}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{E1E00AEE-B1E8-40B1-9CB9-1D25F5D04C60}" = protocol=17 | dir=in | app=c:\program files (x86)\aol desktop 9.7\waol.exe |
"{E293D4FF-AB0E-4048-86F0-7000A35AE4E3}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\system information\sinf.exe |
"{E38185A2-84D6-43F5-BA9E-CB3A13766347}" = protocol=6 | dir=out | app=system |
"{E4E0CC67-A1CB-4758-A965-197D6A387AD2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\soldierfront2\binaries\win32\sf2.exe |
"{E5EC4939-EC56-4D68-8DD3-1185ECED2339}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe |
"{E7DD5246-0980-4DA8-B786-F931C3BD6F2A}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{EABD8DD8-7E05-41D1-82B8-97D9C954B99B}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{ECB20208-6E41-461D-B3E1-F8171753448B}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{EDE304CC-BF7E-4F35-AE26-EB0A713B1A89}" = protocol=17 | dir=in | app=c:\program files (x86)\raptr\raptr_im.exe |
"{F1F7E832-19C3-4088-A91F-50B7A45DA5F6}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{FAB7CE5D-0188-4DF7-AC75-113A2179CFB7}" = protocol=6 | dir=in | app=c:\program files (x86)\aol desktop 9.7a\aolbrowser\aolbrowser.exe |
"{FCA02A8F-8AA5-4C41-8AF3-93A4416B7887}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe |
"{FE218E7E-C481-4441-A6CD-2E86F7FCFF7A}" = protocol=6 | dir=in | app=c:\program files (x86)\raptr\raptr.exe |
"{FEB229E4-E5A7-485A-9E01-92805F847F0E}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpdevicedetection3.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}" = Network64
"{07EEE598-5F21-4B57-B40B-46592625B3D9}" = Zune Language Pack (PTB)
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{26A24AE4-039D-4CA4-87B4-2F86416024FF}" = Java(TM) 6 Update 24 (64-bit)
"{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}" = HP Client Services
"{2A9DFFD8-4E09-4B91-B957-454805B0D7C4}" = Zune Language Pack (CHS)
"{3589A659-F732-4E65-A89A-5438C332E59D}" = Zune Language Pack (ELL)
"{40DB28C5-3C37-72E8-BE8F-82104E97EFCC}" = AMD Fuel
"{42A2FD03-F0C7-6DD5-8D7B-EBAA992F12AA}" = WMV9/VC-1 Video Playback
"{467D5E81-8349-4892-9E81-C3674ED8E451}" = Cisco Systems VPN Client 5.0.07.0290
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{51C839E1-2BE4-4E77-A1BA-CCEA5DAFA741}" = Zune Language Pack (KOR)
"{57C51D56-B287-4C11-9192-EC3C46EF76A4}" = Zune Language Pack (RUS)
"{5C93E291-A1CC-4E51-85C6-E194209FCDB4}" = Zune Language Pack (PTG)
"{5DEFD397-4012-46C3-B6DA-E8013E660772}" = Zune Language Pack (NOR)
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{624C7F0A-89B2-4C49-9CAB-9D69613EC95A}" = Microsoft IntelliPoint 8.2
"{626672CD-BFCF-49A9-AEFE-AB0FED3BFC5B}" = Windows Mobile Device Center
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6740BCB0-5863-47F4-80F4-44F394DE4FE2}" = Zune Language Pack (NLD)
"{68550918-63B5-4762-85CB-3C160AA4B213}" = HP Photosmart C4700 All-in-One Driver Software 14.0 Rel. 6
"{6B33492E-FBBC-4EC3-8738-09E16E395A10}" = Zune Language Pack (ESP)
"{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}" = Network64
"{6E53B80F-4137-5F27-B4C4-88641B1E7F10}" = ccc-utility64
"{6EB931CD-A7DA-4A44-B74A-89C8EB50086F}" = Zune Language Pack (SVE)
"{76BA306B-2AA0-47C0-AB6B-F313AB56C136}" = Zune Language Pack (MSL)
"{7FBA6627-88F8-0AE0-9326-FB8488DD26E0}" = ATI Catalyst Install Manager
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{8960A0A1-BB5A-479E-92CF-65AB9D684B43}" = Zune Language Pack (PLK)
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B112338-2B08-4851-AF84-E7CAD74CEB32}" = Zune Language Pack (DAN)
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{92ECE3F9-591E-4C12-8A62-B9FCE38BF646}" = Zune Language Pack (IND)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B75648B-6C30-4A0D-9DE6-0D09D20AF5A5}" = Zune
"{A5A53EA8-A11E-49F0-BDF5-AE536426A31A}" = Zune Language Pack (CHT)
"{A8F2E50B-86E2-4D96-9BD2-9758BCC6F9B3}" = Zune Language Pack (CSY)
"{B4870774-5F3A-46D9-9DFE-06FB5599E26B}" = Zune Language Pack (FIN)
"{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}" = Zune Language Pack (DEU)
"{C5D37FFA-7483-410B-982B-91E93FD3B7DA}" = Zune Language Pack (ITA)
"{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}" = Zune Language Pack (FRA)
"{C6BE19C6-B102-4038-B2A6-1C313872DBB4}" = Zune Language Pack (HUN)
"{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}" = HP Auto
"{D8A781C9-3892-4E2E-9320-480CF896CFBB}" = Zune Language Pack (JPN)
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F2CB8C3C-9C9E-4FAB-9067-655601C5F748}" = Windows Mobile Device Updater Component
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"HP Imaging Device Functions" = HP Imaging Device Functions 14.0
"HP Print Projects" = HP Print Projects 1.0
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 14.0
"HPExtendedCapabilities" = HP Customer Participation Program 14.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft IntelliPoint 8.2" = Microsoft IntelliPoint 8.2
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Zune" = Zune

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
 
"{0EDEB615-1A60-425E-8306-0E10519C7B55}" = RoxioNow Player
"{120262A6-7A4B-4889-AE85-F5E5688D3683}" = HP MovieStore
"{143774AF-ED46-EF8E-A9C5-516D67A484C2}" = CCC Help Korean
"{1458BB78-1DC5-4BC0-B9A3-2B644F5A8105}" = DeviceDiscovery
"{150B6201-E9E6-4DFB-960E-CCBD53FBDDED}" = HPProductAssistant
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{210A03F5-B2ED-4947-B27E-516F50CBB292}" = HP Setup
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
"{28B8E509-8E2A-A274-B59F-1D892778CBB6}" = CCC Help Chinese Traditional
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2C93DDCA-E6BB-977B-8C55-724C1DA25C21}" = CCC Help Norwegian
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{2FB9EA69-51D4-4913-9AD5-762C034DE811}" = Status
"{30DDA988-6BCC-8B14-E0BB-026DA821EC23}" = CCC Help Czech
"{311295C1-80F9-D8B6-06E4-5CBD2492460E}" = CCC Help Dutch
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34A59718-E873-CE8E-718C-D56B341DD14D}" = CCC Help German
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{371794E8-423C-52DD-ED06-9385469EA274}" = CCC Help Swedish
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Windows 7
"{39EAEE16-AF24-CF47-3BD1-7B048A5DABD3}" = CCC Help English
"{3C7F25C6-6BCB-7F39-BC81-48A8B5F38EDD}" = CCC Help French
"{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX
"{3FE1B94B-FB1C-1AF3-4DC2-EB5F4DB56A30}" = CCC Help Chinese Standard
"{45160C56-61F6-468D-A5B0-9FAE2C3E68D6}" = Catalyst Control Center - Branding
"{456D64EB-7E2A-FF45-EFA9-439EB529A105}" = CCC Help Greek
"{4798F9E7-BE3A-3EBF-BDF2-6751C8C38503}" = CCC Help Italian
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5184A194-BA95-0411-A13C-468097CD4A06}" = Catalyst Control Center InstallProxy
"{537DB9D6-1AB1-4CE9-8DE7-312256B49A98}" = PS_AIO_06_C4700_SW_Min
"{53B17A98-5BF0-40BC-AAFF-850A357975AC}" = HP Quick Launch
"{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries
"{56CFA833-F44F-4199-8C58-7F8B38F2BC7B}" = Medal of Honor Pacific Assault(tm)
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{58327844-EEAB-8C79-CA64-6C3623DEF11B}" = CCC Help Polish
"{5DCF0E4B-F8EA-4229-A0BD-5CA6D4AFB749}" = SolutionCenter
"{601E6B37-4FF1-FC93-F48F-F73D29040AD4}" = CCC Help Japanese
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6C453C9C-38AE-494D-BF89-7AA0DE87F3E5}" = HP Documentation
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.1.1
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp" = WildTangent Games App (HP Games)
"{710870E4-16ED-AC81-71CF-8941963E0776}" = Catalyst Control Center Localization All
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72737A9E-FAC6-01F9-C0F3-88F6DB538607}" = CCC Help Russian
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7650F538-6274-44EA-8F50-843479073333}" = EPSON USB Display
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{78E5E045-D6EB-57CD-02F8-F55E79882790}" = CCC Help Danish
"{7A6B4340-7090-418F-8976-EE9650B35550}" = HP Connection Manager
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8A9FC225-75F6-4B5D-911C-0ED230565643}" = HP Product Detection
"{8BE8CC83-C423-BF43-C1A0-9C072E3785B7}" = ccc-core-static
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8EE94FD8-5F52-4463-A340-185D16328158}" = WebReg
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Ralink RT5390 802.11b/g/n WiFi Adapter
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{9008D736-35CA-40DB-A2BE-5F32D954E5AA}" = HP MovieStore
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{9368DDD5-CE7F-4BD7-A83A-F00FABE338EC}" = Blio
"{95140000-00AF-0409-0000-0000000FF1CE}" = Microsoft PowerPoint Viewer
"{962CB079-85E6-405F-8704-1C62365AE46F}" = HP Software Framework
"{97486FBE-A3FC-4783-8D55-EA37E9D171CC}" = HP Update
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9AAD03E8-4F65-4DE2-8F6C-1B079C0C8521}" = Garmin Lifetime Updater
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA027AE9-DD20-4677-AA72-D760A358320B}" = Microsoft VC9 runtime libraries
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.04)
"{AE856388-AFAD-4753-81DF-D96B19D0A17C}" = HP Setup Manager
"{B35FC82A-6C05-45B0-DDE5-8DF62422E703}" = CCC Help Turkish
"{B5978DF3-8A04-4F22-AF67-8CCE52E04B13}" = C4700
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BB3447F6-9553-4AA9-960E-0DB5310C5779}" = GPBaseService2
"{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}" = Energy Star Digital Logo
"{BD3F5161-C40B-CA50-F82A-1F4417EE722D}" = CCC Help Spanish
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C0BD6A24-3110-E1DE-45B2-C7FC14F4DC76}" = CCC Help Thai
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CD31E63D-47FD-491C-8117-CF201D0AFAB5}" = TrayApp
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D360FA88-17C8-4F14-B67F-13AAF9607B12}" = MarketResearch
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D4414765-E8CD-518B-91E8-FA7C76CD2AE2}" = CCC Help Hungarian
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DBCD5E64-7379-4648-9444-8A6558DCB614}" = Recovery Manager
"{DC6B510F-7EA2-8171-55E0-6A76B46CA17D}" = CCC Help Portuguese
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E44578C7-4667-4124-8BC2-1161BCA54978}" = HP Power Manager
"{E517094C-06B6-419F-8FFD-EF4F57972130}" = QuickTransfer
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EB120C5A-42D2-C901-FF0C-D0DBDD07E9BD}" = Catalyst Control Center Graphics Previews Common
"{ED1BD69A-07E3-418C-91F1-D856582581BF}" = HP On Screen Display
"{EE202411-2C26-49E8-9784-1BC1DBF7DE96}" = HP Support Assistant
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EEF4EAB8-D049-FD0A-02BD-F9F42C49551F}" = CCC Help Finnish
"{EF8CA7A3-2113-4141-B07A-255CAB910509}" = AnzioLite163
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F761359C-9CED-45AE-9A51-9D6605CD55C4}" = Evernote v. 4.2.2
"{FA0FF682-CC70-4C57-93CD-E276F3E7537E}" = BufferChm
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AOL Toolbar" = AOL Toolbar
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"HP Photo Creations" = HP Photo Creations
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"MCLIENT" = Norton Management
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"N360" = Norton 360
"NSM" = Norton Family
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"Office14.SingleImage" = Microsoft Office Home and Business 2010
"PunkBusterSvc" = PunkBuster Services
"Raptr" = Raptr
"Steam App 102700" = Alliance of Valiant Arms
"Steam App 209870" = Blacklight: Retribution
"Steam App 239660" = Soldier Front 2
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite" = Windows Live Essentials
"WT087328" = Blackhawk Striker 2
"WT087330" = Bounce Symphony
"WT087335" = Build-a-lot 2
"WT087343" = Dora's World Adventure
"WT087393" = Mah Jong Medley
"WT087394" = Penguins!
"WT087395" = Poker Superstars III
"WT087396" = Polar Bowler
"WT087397" = Polar Golfer
"WT087415" = Wheel of Fortune 2
"WT087536" = Diner Dash 2 Restaurant Rescue
"WT089307" = Virtual Villagers 4 - The Tree of Life
"WT089308" = Blasterball 3
"WT089328" = Farm Frenzy
"WT089359" = Cake Mania
"WT089362" = Agatha Christie - Peril at End House
"WT089453" = Bejeweled 2 Deluxe
"WT089454" = Chuzzle Deluxe
"WT089455" = Zuma Deluxe
"WT089457" = Slingo Supreme
"WT089458" = Plants vs. Zombies - Game of the Year
"WT089470" = FATE - The Traitor Soul
"WT089484" = Namco All-Stars PAC-MAN
"WT089496" = Mystery P.I. - Stolen in San Francisco
"WT089498" = Bejeweled 3

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ActiveTouchMeetingClient" = Cisco WebEx Meetings
"AOL Toolbar" = AOL Toolbar
"UnityWebPlayer" = Unity Web Player

========== Last 20 Event Log Errors ==========

[ Hewlett-Packard Events ]
Error - 7/9/2012 11:13:13 PM | Computer Name = motulken-HP | Source = HPSF.exe | ID = 4000
Description =

Error - 9/3/2012 9:48:35 PM | Computer Name = motulken-HP | Source = HPSF.exe | ID = 4000
Description =

Error - 9/3/2012 9:48:35 PM | Computer Name = motulken-HP | Source = HPSF.exe | ID = 4000
Description =

Error - 9/3/2012 9:48:35 PM | Computer Name = motulken-HP | Source = HPSF.exe | ID = 4000
Description =

Error - 10/16/2012 12:29:08 PM | Computer Name = motulken-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
en-US RAM: 3834 Ram Utilization: 40 TargetSite: Void UpdateAndDetect()

Error - 10/22/2012 9:04:14 PM | Computer Name = motulken-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
en-US RAM: 3834 Ram Utilization: 60 TargetSite: Void UpdateAndDetect()

Error - 10/30/2012 9:02:44 AM | Computer Name = motulken-HP | Source = HPSF.exe | ID = 4000
Description =

Error - 10/30/2012 9:03:43 AM | Computer Name = motulken-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088hpsa_service.exe at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
en-US RAM: 3834 Ram Utilization: 50 TargetSite: Void UpdateAndDetect()

Error - 11/6/2012 9:21:46 AM | Computer Name = motulken-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
en-US RAM: 3834 Ram Utilization: 50 TargetSite: Void UpdateAndDetect()

Error - 11/12/2012 10:49:47 PM | Computer Name = motulken-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
en-US RAM: 3834 Ram Utilization: 60 TargetSite: Void UpdateAndDetect()

[ HP Connection Manager Events ]
Error - 10/6/2013 12:43:17 AM | Computer Name = motulken-HP | Source = hpCMSrv | ID = 5
Description = 2013/10/06 00:43:17.819|00000C68|Error |CWLAN::SignalStrengthChanged|Fire_SignalStrengthChanged
failed [hr:0x800706BA]

Error - 10/6/2013 12:43:19 AM | Computer Name = motulken-HP | Source = hpCMSrv | ID = 5
Description = 2013/10/06 00:43:19.816|00000C68|Error |CWLAN::SignalStrengthChanged|Fire_SignalStrengthChanged
failed [hr:0x800706BA]

Error - 10/6/2013 12:43:21 AM | Computer Name = motulken-HP | Source = hpCMSrv | ID = 5
Description = 2013/10/06 00:43:21.828|00000C68|Error |CWLAN::SignalStrengthChanged|Fire_SignalStrengthChanged
failed [hr:0x800706BA]

Error - 10/6/2013 12:43:23 AM | Computer Name = motulken-HP | Source = hpCMSrv | ID = 5
Description = 2013/10/06 00:43:23.825|00000C68|Error |CWLAN::SignalStrengthChanged|Fire_SignalStrengthChanged
failed [hr:0x800706BA]

Error - 10/6/2013 12:43:31 AM | Computer Name = motulken-HP | Source = hpCMSrv | ID = 5
Description = 2013/10/06 00:43:31.828|00000C68|Error |CWLAN::SignalStrengthChanged|Fire_SignalStrengthChanged
failed [hr:0x800706BA]

Error - 10/6/2013 12:43:35 AM | Computer Name = motulken-HP | Source = hpCMSrv | ID = 5
Description = 2013/10/06 00:43:35.821|00000C68|Error |CWLAN::SignalStrengthChanged|Fire_SignalStrengthChanged
failed [hr:0x800706BA]

Error - 10/6/2013 12:43:40 AM | Computer Name = motulken-HP | Source = hpCMSrv | ID = 5
Description = 2013/10/06 00:43:40.954|00000C68|Error |CWLAN::SignalStrengthChanged|Fire_SignalStrengthChanged
failed [hr:0x800706BA]

Error - 10/6/2013 12:43:41 AM | Computer Name = motulken-HP | Source = hpCMSrv | ID = 5
Description = 2013/10/06 00:43:41.827|00000C68|Error |CWLAN::SignalStrengthChanged|Fire_SignalStrengthChanged
failed [hr:0x800706BA]

Error - 10/6/2013 12:43:48 AM | Computer Name = motulken-HP | Source = hpCMSrv | ID = 5
Description = 2013/10/06 00:43:48.254|00000C68|Error |CWLAN::SignalStrengthChanged|Fire_SignalStrengthChanged
failed [hr:0x800706BA]

Error - 10/6/2013 12:48:03 AM | Computer Name = motulken-HP | Source = hpMobile | ID = 5
Description = 2013/10/06 00:48:03.097|00001730|Error |[HP.Mobile]Notifications::ShowPopup{bool(HP.Mobile.Presentation.Notifications+PopupID,string,string,string,string,string)}|HP
Software framework Failed from popup: e_INVALID_HP_SIGNATURE

[ HP Software Framework Events ]
Error - 5/28/2012 9:41:17 PM | Computer Name = motulken-HP | Source = CaslSmBios | ID = 5
Description = 2012/05/28 21:41:17.767|000022F0|Error |[CaslWmi]CommandPanelBrightness::GetCurrentPanelBrightnessFromOS{hpCasl.enReturnCode(CaslWmi.enPanelBrightnessDataType,ushort&)}|Exception
occurred in querying WMI for WmiMonitorBrightness: 'Not supported '

Error - 6/18/2012 11:44:09 PM | Computer Name = motulken-HP | Source = CaslSmBios | ID = 5
Description = 2012/06/18 23:44:09.166|00002748|Error |[CaslWmi]CommandPanelBrightness::GetCurrentPanelBrightnessFromOS{hpCasl.enReturnCode(CaslWmi.enPanelBrightnessDataType,ushort&)}|Exception
occurred in querying WMI for WmiMonitorBrightness: 'Not supported '

Error - 6/18/2012 11:44:13 PM | Computer Name = motulken-HP | Source = CaslSmBios | ID = 5
Description = 2012/06/18 23:44:13.124|00001B78|Error |[CaslWmi]CommandPanelBrightness::GetCurrentPanelBrightnessFromOS{hpCasl.enReturnCode(CaslWmi.enPanelBrightnessDataType,ushort&)}|Exception
occurred in querying WMI for WmiMonitorBrightness: 'Not supported '

Error - 11/6/2012 9:21:53 AM | Computer Name = motulken-HP | Source = CaslSmBios | ID = 5
Description = 2012/11/06 08:21:53.784|000014D8|Error |[CaslWmi]CommandPanelBrightness::GetCurrentPanelBrightnessFromOS{hpCasl.enReturnCode(CaslWmi.enPanelBrightnessDataType,ushort&)}|Exception
occurred in querying WMI for WmiMonitorBrightness: 'Not supported '

Error - 11/6/2012 9:21:56 AM | Computer Name = motulken-HP | Source = CaslSmBios | ID = 5
Description = 2012/11/06 08:21:56.884|00000E20|Error |[CaslWmi]CommandPanelBrightness::GetCurrentPanelBrightnessFromOS{hpCasl.enReturnCode(CaslWmi.enPanelBrightnessDataType,ushort&)}|Exception
occurred in querying WMI for WmiMonitorBrightness: 'Not supported '

Error - 11/20/2012 8:25:15 AM | Computer Name = motulken-HP | Source = CaslSmBios | ID = 5
Description = 2012/11/20 07:25:15.149|00000CB8|Error |[CaslWmi]CommandPanelBrightness::GetCurrentPanelBrightnessFromOS{hpCasl.enReturnCode(CaslWmi.enPanelBrightnessDataType,ushort&)}|Exception
occurred in querying WMI for WmiMonitorBrightness: 'Not supported '

Error - 11/20/2012 8:25:18 AM | Computer Name = motulken-HP | Source = CaslSmBios | ID = 5
Description = 2012/11/20 07:25:18.011|00001C64|Error |[CaslWmi]CommandPanelBrightness::GetCurrentPanelBrightnessFromOS{hpCasl.enReturnCode(CaslWmi.enPanelBrightnessDataType,ushort&)}|Exception
occurred in querying WMI for WmiMonitorBrightness: 'Not supported '

Error - 9/3/2013 10:13:39 AM | Computer Name = motulken-HP | Source = CaslSmBios | ID = 5
Description = 2013/09/03 10:13:39.924|00000CD0|Error |[CaslSmBios]hpSMBIOS::D{bool(byte[]&)}|Call
was canceled by the message filter. (Exception from HRESULT: 0x80010002 (RPC_E_CALL_CANCELED))

Error - 9/4/2013 4:01:00 PM | Computer Name = motulken-HP | Source = CaslSmBios | ID = 5
Description = 2013/09/04 16:01:00.074|0000129C|Error |[CaslSmBios]hpSMBIOS::D{bool(byte[]&)}|Call
was canceled by the message filter. (Exception from HRESULT: 0x80010002 (RPC_E_CALL_CANCELED))

Error - 9/5/2013 10:37:59 AM | Computer Name = motulken-HP | Source = CaslSmBios | ID = 5
Description = 2013/09/05 10:37:59.743|0000158C|Error |[CaslWmi]CommandSmartAdapter::GetSmartAdapterStatusFromBIOS{hpCasl.enReturnCode(bool&,int&)}|Error
597 from BIOS WMI call Read/0Fh while getting SmartAdapter state

[ System Events ]
Error - 10/6/2013 1:13:31 AM | Computer Name = motulken-HP | Source = DCOM | ID = 10010
Description =


< End of report >
 
redtarget.gif
Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
Code:
:OTL
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
O3 - HKLM\..\Toolbar: (no name) - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - No CLSID value found.
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll File not found
O3 - HKU\S-1-5-21-2848903972-3699595445-501089177-1001\..\Toolbar\WebBrowser: (AOL Toolbar) - {BA00B7B1-0351-477A-B948-23E3EE5A73D4} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll File not found
O15 - HKU\S-1-5-21-2848903972-3699595445-501089177-1001\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} https://h20364.www2.hp.com/CSMWeb/Customer/cabs/HPISDataManager.CAB (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/3.0.1.0/GarminAxControl.CAB (Reg Error: Key error.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.


:Services

:Reg

:Files
C:\FRST

:Commands
[purity]
[emptytemp]
[emptyjava]
[emptyflash]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • You will get a log that shows the results of the fix. Please post it.

NOTE. If for any reason OTL stalls (most likely at "killing processes..." step) run the fix from safe mode.
Last scans...

redtarget.gif
Download Security Check from here or here and save it to your Desktop.
  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
NOTE 2 SecurityCheck may produce some false warning(s), so leave the results reading to me.


redtarget.gif
Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.

redtarget.gif
Download Temp File Cleaner (TFC)
Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
  • Double click on TFC.exe to run the program.
  • Click on Start button to begin cleaning process.
  • TFC will close all running programs, and it may ask you to restart computer.

redtarget.gif
Please run a free online scan with the ESET Online Scanner

  • Disable your antivirus program
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • Accept any security warnings from your browser.
  • Check Scan archives
  • Click Start
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click on List of found threats
  • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • NOTE. If Eset won't find any threats, it won't produce any log.
 
Did step one. I t looked like it stalled and I shut it down
This what I got:

[FONT=Calibri]Files\Folders moved on Reboot...[/FONT]

[FONT=Calibri]File move failed. C:\Users\motulken\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be moved on reboot.[/FONT]

[FONT=Calibri]File move failed. C:\Users\motulken\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat scheduled to be moved on reboot.[/FONT]



[FONT=Calibri]PendingFileRenameOperations files...[/FONT]

[FONT=Calibri]Registry entries deleted on Reboot...[/FONT]
[FONT=Calibri]It looked like it failed.[/FONT]



[FONT=Calibri]I ran again, it also looked like it stalled too but this was the report:[/FONT]

Files\Folders moved on Reboot...
C:\Users\motulken\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\Users\motulken\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{264F3C12-399B-452A-AED6-01DC383A30DC}.tmp not found!
File\Folder C:\Users\motulken\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{5174437A-5D1E-48C1-ACCD-433BC0AC40C5}.tmp not found!
File\Folder C:\Users\motulken\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{F8167B78-B692-4F33-AFB7-DA34FF40E948}.tmp not found!
C:\Users\motulken\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...

Not sure whether to go to the next step.
Am I good to go onto Security Check and do the next step?
 
Ok so I felt brave. It looked like the post above was successful so I did the next step. here is the log from Security check:

Results of screen317's Security Check version 0.99.74
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Norton 360 Premier Edition
[size=1]WMI entry may not exist for antivirus; attempting automatic update.[/size]
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.75.0.1300
Java(TM) 6 Update 31
Java version out of Date!
Adobe Reader XI
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 2%
````````````````````End of Log``````````````````````
 
Here is the [FONT=Calibri][FONT=Arial]Farbar Service Scanner[/FONT][/FONT][FONT=Arial] (FSS) log[/FONT]

[FONT=Arial][FONT=Arial]Farbar Service Scanner Version: 13-09-2013
Ran by motulken (administrator) on 06-10-2013 at 23:55:26
Running from "C:\Users\motulken\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U83KJASP"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************
[/FONT]
[/FONT]
[FONT=Arial][FONT=Arial]Internet Services:
============
[/FONT]
[/FONT]
[FONT=Arial][FONT=Arial]Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.
[/FONT]
[/FONT]

Windows Firewall:
=============

Firewall Disabled Policy:
==================

System Restore:
============
System Restore Disabled Policy:
========================

Action Center:
============

Windows Update:
============
Windows Autoupdate Disabled Policy:
============================

Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.

Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1

Other Services:
==============

File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\iphlpsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit

**** End of log ****
 
Hi
. Never got the TFC scan to finish. It ran for 2.5 hours, I went to sleep. Next morning it was still running. I had to shut down.
On the road working this week and will have trouble doing anything else until I get home on Friday.

Please don't close this thread out. I will comeback and try to finish.
Any thought on why the TFC scan would not finish?
If I get a chance to do anything during the week I will post it.
 
Hi,
I am back
Here is what I got from the TFC scan.
Getting user folders.

Stopping running processes.

Emptying Temp folders.


User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: motulken
->Temp folder emptied: 227624 bytes
->Temporary Internet Files folder emptied: 54257873 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 827 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1262555 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 1416008135 bytes

Emptying RecycleBin. Do not interrupt.

RecycleBin emptied: 5848396 bytes
Process complete!

Total Files Cleaned = 1,409.00 mb
 
Running now. It's working but slow, it's been almost 2 hours but only 31% complete. Will post if it finds anything ASAP
 
redtarget.gif
1. Update your Java version here: https://www.techspot.com/downloads/6463-java-se.html

Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Note 2: If you're running 64-bit system make sure you install BOTH, 32-bit and 64-bit Java.

Note 3: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

2. Now, we need to remove old Java version and its remnants...

Download JavaRa to your desktop and unzip it.
  • Run JavaRa.exe (Vista and 7 users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Do NOT post JavaRa log.

===============================

Your computer is clean

1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following:

Code:
:OTL
:Commands
[purity]
[emptytemp]
[EMPTYFLASH]
[emptyjava]
[CLEARALLRESTOREPOINTS]
[Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Post resulting log.

2. Now, we'll remove all tools, we used during our cleaning process

Clean up with OTL:

  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.

If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

3. Make sure Windows Updates are current.

4. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

5. Check if your browser plugins are up to date.
Firefox - https://www.mozilla.org/en-US/plugincheck/
other browsers: https://browsercheck.qualys.com/ (click on "Launch a quick scan now" link)

6. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

7. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

8. Run Temporary File Cleaner (TFC), AdwCleaner and Junkware Removal Tool (JRT) weekly.

9. Download and install Secunia Personal Software Inspector (PSI): https://www.techspot.com/downloads/4898-secunia-personal-software-inspector-psi.html. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

10. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

11. (Windows XP only) Run defrag at your convenience.

12. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

13. Read:
How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/

14. Please, let me know, how your computer is doing.
 
Your link you give for JAVA works, but then the link from that to the install does not work.
Looks like this:
Windows Offline (32-bit)
filesize: 27.6 MB Instructions
After installing Java, restart your browser and verify Java has been installed correctly.

Windows Offline (64-bit)
filesize: 29.2 MB

When I click on it It goes to a screen that says

The web address you entered could not be found

[more information]
You were trying to go to http://javadl.sun.com/webapps/download/AutoDL?BundleId=80814

What do I do?
 
I got the JAVA both 32 and 64 to run and got rid of the old version.
Here is the log for OTL
All processes killed
========== OTL ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: motulken
->Temp folder emptied: 1855139 bytes
->Temporary Internet Files folder emptied: 193103111 bytes
->Java cache emptied: 19538 bytes
->Flash cache emptied: 1353 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 258421 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 76336 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 186.00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: motulken
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb


[EMPTYJAVA]

User: All Users

User: Default

User: Default User

User: motulken
->Java cache emptied: 0 bytes

User: Public

Total Java Files Cleaned = 0.00 mb

System Restore Service not available.

OTL by OldTimer - Version 3.2.69.0 log created on 10132013_091617
Files\Folders moved on Reboot...
C:\Users\motulken\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\motulken\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\%20-%201102_LiveRail%20request%20for%20ad-sources%20has%20timed%20out.%20httpStatus=0%20Error_%20HTTP%20request%20timed%20out%20in%2010000ms[10].json not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\%20-%201102_LiveRail%20request%20for%20ad-sources%20has%20timed%20out.%20httpStatus=0%20Error_%20HTTP%20request%20timed%20out%20in%2010000ms[11].json not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\%22,%20%22enabled%22_%20%22true%22%7D%7D,%20%22type%22_%20%22custom%22,%20%22id%22_%20%22vcl-grab-list-block-healthywaytocook_jb-0%22%7D%7D%7D[10].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\%22,%20%22enabled%22_%20%22true%22%7D%7D,%20%22type%22_%20%22custom%22,%20%22id%22_%20%22vcl-grab-list-block-healthywaytocook_jb-0%22%7D%7D%7D[11].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\%22,%20%22enabled%22_%20%22true%22%7D%7D,%20%22type%22_%20%22custom%22,%20%22id%22_%20%22vcl-grab-list-block-healthywaytocook_jb-1%22%7D%7D%7D[10].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\%22,%20%22enabled%22_%20%22true%22%7D%7D,%20%22type%22_%20%22custom%22,%20%22id%22_%20%22vcl-grab-list-block-healthywaytocook_jb-1%22%7D%7D%7D[11].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\%22,%20%22enabled%22_%20%22true%22%7D%7D,%20%22type%22_%20%22custom%22,%20%22id%22_%20%22vcl-grab-list-block-healthywaytocook_jb-3%22%7D%7D%7D[10].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\%22,%20%22enabled%22_%20%22true%22%7D%7D,%20%22type%22_%20%22custom%22,%20%22id%22_%20%22vcl-grab-list-block-healthywaytocook_jb-3%22%7D%7D%7D[11].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\%22,%20%22enabled%22_%20%22true%22%7D%7D,%20%22type%22_%20%22custom%22,%20%22id%22_%20%22vcl-grab-list-block-healthywaytocook_jb-4%22%7D%7D%7D[10].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\%22,%20%22enabled%22_%20%22true%22%7D%7D,%20%22type%22_%20%22custom%22,%20%22id%22_%20%22vcl-grab-list-block-healthywaytocook_jb-4%22%7D%7D%7D[11].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ource%253D65687978%2526utm_medium%253Dcpc%2526utm_campaign%253D65687978_576384_288487_114851_301_70001%2526click%253D52352bae9b289f596126fd4.2[10].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ource%253D65687978%2526utm_medium%253Dcpc%2526utm_campaign%253D65687978_576384_288487_114851_301_70001%2526click%253D52352bae9b289f596126fd4.2[11].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ource%253D65687978%2526utm_medium%253Dcpc%2526utm_campaign%253D65687978_576384_288900_114851_301_70001%2526click%253D5226209315f289f5961ca7b.2[10].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ource%253D65687978%2526utm_medium%253Dcpc%2526utm_campaign%253D65687978_576384_288900_114851_301_70001%2526click%253D5226209315f289f5961ca7b.2[11].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ource%253D65687978%2526utm_medium%253Dcpc%2526utm_campaign%253D65687978_576384_288901_114851_301_70001%2526click%253D5229c0733e289f59616416f.2[10].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ource%253D65687978%2526utm_medium%253Dcpc%2526utm_campaign%253D65687978_576384_288901_114851_301_70001%2526click%253D5229c0733e289f59616416f.2[11].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\source%253D65687978%2526utm_medium%253Dcpc%2526utm_campaign%253D65687978_576384_288900_114851_301_70001%2526click%253D52289673f1289f59615aff.2[10].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\urce%253D65687978%2526utm_medium%253Dcpc%2526utm_campaign%253D65687978_576133_284131_114851_301_70001%2526click%253D523538d32e5289f59611964e.2[10].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\urce%253D65687978%2526utm_medium%253Dcpc%2526utm_campaign%253D65687978_576133_284131_114851_301_70001%2526click%253D523538d32e5289f59611964e.2[11].js not found!
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
I will do the OTL clean up and follow the rest of the promps in you last reply with instructions.

As of now I have not had the audio playing in a few days, but the computer still seems to not be moving as fast as it used to. It seems to take longer when waiting for a page to open. ( like when I am on Ebay )
Also seems to take longer to open up after start up

I will finish up everything and post again.
 
I'm not familiar with AOL browser so the only thing I can suggest is to reinstall it.
 
Back