1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Blue Screen of Death running GMER

Discussion in 'Malware and Virus Removal Archive' started by jayman34, 2012/05/21.

  1. 2012/05/21
    jayman34

    jayman34 Inactive Thread Starter

    Joined:
    2009/02/25
    Messages:
    65
    Likes Received:
    0
    [Resolved] Blue Screen of Death running GMER

    I have Run my AVG virus and Malwarebytes as per instructions

    When i run step 2. GMER it scans for about half an hour and then i get blue screen of death and my machine reboots!

    Any suggestions as i have run twice and both time its done the same thing!

    BLUE SCREEN INFORMATION

    BAD_POOL_HEADER

    *** STOP: 0X00000019 (0X0000000003,0X83589818,0X0050E0C2,0X83589818)

    AVG LOG

    Scan "Whole computer scan" completed.
    Warnings; "65 "; "65 "; "0 "
    Information; "933 "
    Folders selected for scanning:; "Whole computer scan "
    Scan started:; "Saturday, 19 May 2012, 7:57:38 AM "
    Scan finished:; "Saturday, 19 May 2012, 11:19:43 AM (3 hour(s) 22 minute(s) 4 second(s)) "
    Total object scanned:; "2004990 "
    User who launched the scan:; "Sean "

    Warnings
    ; "File "; "Infection "; "Result "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZVNQ04JA.txt:\msnportal.112.2o7.net.7225be6f "; "Found Tracking cookie.2o7 "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\ZVNQ04JA.txt "; "Found Tracking cookie.2o7 "; "Healed "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\ULFUE0YK.txt:\questionmarket.com.767e4302 "; "Found Tracking cookie.Questionmarket "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\ULFUE0YK.txt:\questionmarket.com.4dd5e426 "; "Found Tracking cookie.Questionmarket "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\ULFUE0YK.txt:\questionmarket.com.3eb5a9f1 "; "Found Tracking cookie.Questionmarket "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\ULFUE0YK.txt:\questionmarket.com.27f47a45 "; "Found Tracking cookie.Questionmarket "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\ULFUE0YK.txt "; "Found Tracking cookie.Questionmarket "; "Healed "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\U2PHXIDV.txt:\ru4.com.5a5e0633 "; "Found Tracking cookie.Ru4 "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\U2PHXIDV.txt "; "Found Tracking cookie.Ru4 "; "Healed "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\RMI57FU0.txt:\adbrite.com.d5e309c2 "; "Found Tracking cookie.Adbrite "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\RMI57FU0.txt:\adbrite.com.37283d89 "; "Found Tracking cookie.Adbrite "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\RMI57FU0.txt "; "Found Tracking cookie.Adbrite "; "Healed "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\OF5UEWXY.txt:\zedo.com.dab23eee "; "Found Tracking cookie.Zedo "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\OF5UEWXY.txt:\zedo.com.c1dd09f2 "; "Found Tracking cookie.Zedo "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\OF5UEWXY.txt:\zedo.com.a5b6a132 "; "Found Tracking cookie.Zedo "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\OF5UEWXY.txt:\zedo.com.27f1639b "; "Found Tracking cookie.Zedo "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\OF5UEWXY.txt "; "Found Tracking cookie.Zedo "; "Healed "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\O09H3UMB.txt:\mediaplex.com.f652b123 "; "Found Tracking cookie.Mediaplex "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\O09H3UMB.txt:\mediaplex.com.dc30fb3c "; "Found Tracking cookie.Mediaplex "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\O09H3UMB.txt "; "Found Tracking cookie.Mediaplex "; "Healed "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\I70N0MVV.txt:\statse.webtrendslive.com.b4ca7df0 "; "Found Tracking cookie.Webtrendslive "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\I70N0MVV.txt "; "Found Tracking cookie.Webtrendslive "; "Healed "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\I3RJZNIX.txt:\liveperson.net.8db0737c "; "Found Tracking cookie.Liveperson "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\I3RJZNIX.txt "; "Found Tracking cookie.Liveperson "; "Healed "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\HK76H18M.txt:\casalemedia.com.987e6b46 "; "Found Tracking cookie.Casalemedia "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\HK76H18M.txt:\casalemedia.com.80ad4799 "; "Found Tracking cookie.Casalemedia "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\HK76H18M.txt:\casalemedia.com.350339d4 "; "Found Tracking cookie.Casalemedia "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\HK76H18M.txt:\casalemedia.com.2d37ad26 "; "Found Tracking cookie.Casalemedia "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\HK76H18M.txt:\casalemedia.com.1e1e0e23 "; "Found Tracking cookie.Casalemedia "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\HK76H18M.txt:\casalemedia.com.1773afc "; "Found Tracking cookie.Casalemedia "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\HK76H18M.txt "; "Found Tracking cookie.Casalemedia "; "Healed "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\CFU8LM3T.txt:\adtech.de.a9245469 "; "Found Tracking cookie.Adtech "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\CFU8LM3T.txt "; "Found Tracking cookie.Adtech "; "Healed "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\C7Q5FSZN.txt:\advertising.com.27dc11af "; "Found Tracking cookie.Advertising "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\C7Q5FSZN.txt:\advertising.com.203aa218 "; "Found Tracking cookie.Advertising "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\C7Q5FSZN.txt "; "Found Tracking cookie.Advertising "; "Healed "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\BWXBAS0S.txt:\serving-sys.com.db46cecc "; "Found Tracking cookie.Serving-sys "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\BWXBAS0S.txt:\serving-sys.com.bb39fa8c "; "Found Tracking cookie.Serving-sys "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\BWXBAS0S.txt:\serving-sys.com.a222cbcd "; "Found Tracking cookie.Serving-sys "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\BWXBAS0S.txt:\serving-sys.com.841298c4 "; "Found Tracking cookie.Serving-sys "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\BWXBAS0S.txt:\serving-sys.com.176b0dad "; "Found Tracking cookie.Serving-sys "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\BWXBAS0S.txt "; "Found Tracking cookie.Serving-sys "; "Healed "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\BL3XIH10.txt:\revsci.net.fb487293 "; "Found Tracking cookie.Revsci "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\BL3XIH10.txt:\revsci.net.80ab30e9 "; "Found Tracking cookie.Revsci "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\BL3XIH10.txt:\revsci.net.55564293 "; "Found Tracking cookie.Revsci "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\BL3XIH10.txt:\revsci.net.44927ec "; "Found Tracking cookie.Revsci "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\BL3XIH10.txt:\revsci.net.3983b30a "; "Found Tracking cookie.Revsci "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\BL3XIH10.txt:\revsci.net.1ecc4d24 "; "Found Tracking cookie.Revsci "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\BL3XIH10.txt:\revsci.net.1d1a4fbf "; "Found Tracking cookie.Revsci "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\BL3XIH10.txt "; "Found Tracking cookie.Revsci "; "Healed "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\9V68WJ18.txt:\atdmt.com.b3e33b5f "; "Found Tracking cookie.Atdmt "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\9V68WJ18.txt:\atdmt.com.9e6d7fd3 "; "Found Tracking cookie.Atdmt "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\9V68WJ18.txt:\atdmt.com.74c5668 "; "Found Tracking cookie.Atdmt "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\9V68WJ18.txt:\atdmt.com.7247c262 "; "Found Tracking cookie.Atdmt "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\9V68WJ18.txt "; "Found Tracking cookie.Atdmt "; "Healed "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\5VZM73GZ.txt:\bs.serving-sys.com.5bf1f00f "; "Found Tracking cookie.Serving-sys "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\5VZM73GZ.txt "; "Found Tracking cookie.Serving-sys "; "Healed "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\5G83C9IT.txt:\overture.com.e626e6be "; "Found Tracking cookie.Overture "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\5G83C9IT.txt:\overture.com.52ca467a "; "Found Tracking cookie.Overture "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\5G83C9IT.txt "; "Found Tracking cookie.Overture "; "Healed "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\26WZ2LTO.txt:\weborama.fr.9fbfedb3 "; "Found Tracking cookie.Weborama "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\26WZ2LTO.txt:\weborama.fr.30104bcb "; "Found Tracking cookie.Weborama "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\26WZ2LTO.txt "; "Found Tracking cookie.Weborama "; "Healed "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\1W008V6S.txt:\tribalfusion.com.dcc03271 "; "Found Tracking cookie.Tribalfusion "; "Moved to Virus Vault "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Cookies\Low\1W008V6S.txt "; "Found Tracking cookie.Tribalfusion "; "Healed "

    Information
    ; "File "; "Information "; "Result "
    ; "H:\WD SmartWare.swstor\SD-PC\Volume.c1c345a0.2693.11df.87e8.806e6f6e6963\Users\Sean\Documents\My Documents orig\electric use.doc "; "Contains macros ";" "
    ; "H:\WD SmartWare.swstor\SD-PC\Volume.c1c345a0.2693.11df.87e8.806e6f6e6963\Users\Sean\Documents\My Documents orig\ALARMMANUALS\SEDCO Nurse Call\drawings\Drawing Register.xls "; "Contains macros ";" "
    ; "H:\WD SmartWare.swstor\SD-PC\Volume.c1c345a0.2693.11df.87e8.806e6f6e6963\Users\Sean\Documents\1LQ_PriceList.xls "; "Contains macros ";" "
    ; "C:\Windows\Installer\a2d23b9.msp:\PATCH_CAB:\PROCDB.XLAM_1033 "; "Contains macros ";" "
    ; "C:\Windows\Installer\a2d23b9.msp:\PATCH_CAB:\FUNCRES.XLAM_1033 "; "Contains macros ";" "
    ; "C:\Windows\Installer\a2d23b9.msp:\PATCH_CAB "; "Contains macros ";" "
    ; "C:\Windows\Installer\a2d23b9.msp "; "Contains macros ";" "
    ; "C:\Windows\Installer\25db7f6.msp:\PATCH_CAB:\EXPTOOWS.XLA_1033 "; "Contains macros ";" "
    ; "C:\Windows\Installer\25db7f6.msp:\PATCH_CAB "; "Contains macros ";" "
    ; "C:\Windows\Installer\25db7f6.msp "; "Contains macros ";" "
    ; "C:\Windows\Installer\2454d87.msp:\PATCH_CAB:\EXPTOOWS.XLA_1033 "; "Contains macros ";" "
    ; "C:\Windows\Installer\2454d87.msp:\PATCH_CAB "; "Contains macros ";" "
    ; "C:\Windows\Installer\2454d87.msp "; "Contains macros ";" "
    ; "C:\Windows\Installer\$PatchCache$\Managed\00004109610090400000000000F01FEC\14.0.4763\PROCDB.XLAM_1033 "; "Contains macros ";" "
    ; "C:\Windows\Installer\$PatchCache$\Managed\00004109610090400000000000F01FEC\14.0.4763\FUNCRES.XLAM_1033 "; "Contains macros ";" "
    ; "C:\Windows\Installer\$PatchCache$\Managed\00002109E60090400000000000F01FEC\12.0.4518\EXPTOOWS.XLA_1033 "; "Contains macros ";" "
    ; "C:\Users\Sean\Documents\My Documents orig\electric use.doc "; "Contains macros ";" "
    ; "C:\Users\Sean\Documents\My Documents orig\ALARMMANUALS\SEDCO Nurse Call\drawings\Drawing Register.xls "; "Contains macros ";" "
    ; "C:\Users\Sean\Documents\1LQ_PriceList.xls "; "Contains macros ";" "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Templates\MN_ReceptionistResume.dotm "; "Contains macros ";" "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Templates\MN_MilitaryToCivilianResume.dotm "; "Contains macros ";" "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Templates\MN_InsurClaimsProcessorResume.dotm "; "Contains macros ";" "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Templates\MN_HighSchoolResume.dotm "; "Contains macros ";" "
    ; "C:\Users\Sean\AppData\Roaming\Microsoft\Templates\MN_ChronResumeWithBorder.dotm "; "Contains macros ";" "
    ; "C:\ProgramData\AVG2012\IDS\Quarantine\adcbcb48-ffff-ffff-8000-000000000000.zip "; "Password-protected ";" "
    ; "C:\ProgramData\AVG2012\IDS\config\userList.zip.bak "; "Password-protected ";" "
    ; "C:\ProgramData\AVG2012\IDS\config\userList.zip "; "Password-protected ";" "
    ; "C:\ProgramData\AVG2012\IDS\config\quarantinedList.zip.bak "; "Password-protected ";" "
    ; "C:\ProgramData\AVG2012\IDS\config\quarantinedList.zip "; "Password-protected ";" "
    ; "C:\ProgramData\AVG2012\IDS\config\md5Cache.dat "; "Password-protected ";" "
    ; "C:\ProgramData\AVG2012\IDS\config\internalList.zip.bak "; "Password-protected ";" "
    ; "C:\ProgramData\AVG2012\IDS\config\internalList.zip "; "Password-protected ";" "
    ; "C:\Program Files\ScanSoft\OmniPageSE4\aware_pptSE4.ppa "; "Contains macros ";" "
    ; "C:\Program Files\ScanSoft\OmniPageSE4\aware_excelSE4.xla "; "Contains macros ";" "
    ; "C:\Program Files\Microsoft Office\Office14\SAMPLES\SOLVSAMP.XLS "; "Contains macros ";" "
    ; "C:\Program Files\Microsoft Office\Office14\Library\SOLVER\SOLVER.XLAM "; "Contains macros ";" "
    ; "C:\Program Files\Microsoft Office\Office14\Library\EUROTOOL.XLAM "; "Contains macros ";" "
    ; "C:\Program Files\Microsoft Office\Office14\Library\Analysis\PROCDB.XLAM "; "Contains macros ";" "
    ; "C:\Program Files\Microsoft Office\Office14\Library\Analysis\FUNCRES.XLAM "; "Contains macros ";" "
    ; "C:\Program Files\Microsoft Office\Office14\Library\Analysis\ATPVBAEN.XLAM "; "Contains macros ";" "
    ; "C:\Program Files\Microsoft Office\Office14\1033\EXPTOOWS.XLA "; "Contains macros ";" "
    ; "C:\Program Files\Microsoft Office\Office12\1033\EXPTOOWS.XLA "; "Contains macros ";" "
    ; "X:\System Volume Information\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "X:\RECYCLER\S-1-5-21-1547161642-436374069-725345543-1003\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "X:\4181790244a472aec88a\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "X:\1cbc72a5613de5ed132f5fd9ba\MRT.exe "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "X:\$RECYCLE.BIN\S-1-5-21-759393751-1481746019-3899478243-1004\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "X:\$RECYCLE.BIN\S-1-5-21-759393751-1481746019-3899478243-1003\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "X:\$RECYCLE.BIN\S-1-5-21-509800153-4212288920-1158910735-500\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "X:\$RECYCLE.BIN\S-1-5-21-509800153-4212288920-1158910735-1005\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "X:\$RECYCLE.BIN\S-1-5-21-509800153-4212288920-1158910735-1004\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "X:\$RECYCLE.BIN\S-1-5-21-509800153-4212288920-1158910735-1003\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "X:\$RECYCLE.BIN\S-1-5-21-509800153-4212288920-1158910735-1001\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "X:\$RECYCLE.BIN\S-1-5-21-2253134997-3456679846-2574380953-501\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "X:\$RECYCLE.BIN\S-1-5-21-2253134997-3456679846-2574380953-1001\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "X:\$RECYCLE.BIN\S-1-5-20\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "H:\WindowsImageBackup\SD-PC\SPPMetadataCache\{009c28a2-af71-4cc2-9097-a60567fd70f9} "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "H:\WindowsImageBackup\SD-PC\MediaId "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "H:\WindowsImageBackup\SD-PC\Catalog\GlobalCatalog "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "H:\WindowsImageBackup\SD-PC\Catalog\BackupGlobalCatalog "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "H:\WindowsImageBackup\SD-PC\Backup 2011-11-30 150113\c1c345a0-2693-11df-87e8-806e6f6e6963.vhd "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "H:\WindowsImageBackup\SD-PC\Backup 2011-11-30 150113\BackupSpecs.xml "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "H:\WindowsImageBackup\SD-PC\Backup 2011-11-30 150113\009c28a2-af71-4cc2-9097-a60567fd70f9_RegistryExcludes.xml "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "H:\WindowsImageBackup\SD-PC\Backup 2011-11-30 150113\009c28a2-af71-4cc2-9097-a60567fd70f9_Components.xml "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "H:\WindowsImageBackup\SD-PC\Backup 2011-11-30 150113\009c28a2-af71-4cc2-9097-a60567fd70f9_AdditionalFilesc3b9f3c7-5e52-4d5e-8b20-19adc95a34c7.xml "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "H:\WD SmartWare.swstor\SD-PC\Volume.e61678e7.cac3.496f.a7a8.bbd7363c6772\bd7b9e158a53aa4869427874c91b\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "H:\WD SmartWare.swstor\SD-PC\Volume.e61678e7.cac3.496f.a7a8.bbd7363c6772\85d43e3767e0c5a493fe2f2fc912\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "H:\WD SmartWare.swstor\SD-PC\Volume.e61678e7.cac3.496f.a7a8.bbd7363c6772\55cac9ad7f771f12ce50c3422693\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "H:\WD SmartWare.swstor\SD-PC\Volume.e61678e7.cac3.496f.a7a8.bbd7363c6772\28dfaecc9e0b3eb256\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "H:\System Volume Information\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "H:\SD-PC\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "H:\f620fe064286a6a18f2f3132f5c96b\MRT.exe "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "H:\3fd949e398c406464e11d1db3c0a8d1e\MRT.exe "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "H:\$RECYCLE.BIN\S-1-5-21-759393751-1481746019-3899478243-1003\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "D:\System Volume Information\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "D:\$RECYCLE.BIN\S-1-5-21-759393751-1481746019-3899478243-1005\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "D:\$RECYCLE.BIN\S-1-5-21-759393751-1481746019-3899478243-1004\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "D:\$RECYCLE.BIN\S-1-5-21-759393751-1481746019-3899478243-1003\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "D:\$RECYCLE.BIN\S-1-5-21-509800153-4212288920-1158910735-1005\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "D:\$RECYCLE.BIN\S-1-5-21-509800153-4212288920-1158910735-1004\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "D:\$RECYCLE.BIN\S-1-5-21-509800153-4212288920-1158910735-1003\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "D:\$RECYCLE.BIN\S-1-5-21-509800153-4212288920-1158910735-1001\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "D:\$RECYCLE.BIN\S-1-5-20\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\winsxs\x86_microsoft-windows-n..n_service_datastore_31bf3856ad364e35_6.1.7601.17514_none_d335fa979441d05e\dnary.xsd "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Temp\{766bb3e4-e202-6314-5fda-3265d0497776}\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Temp\SPL814F.tmp "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Temp\SDIAG_83f20889-720a-4b2d-91dc-84eb18ed5ca7\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Temp\SDIAG_4aa0aa96-39e1-4f84-bc31-83d053722ee9\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Temp\SDIAG_48bee79c-bb99-4aab-b84e-8b76634080eb\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Temp\SDIAG_42578e63-5b97-4a9c-83ad-0db990371902\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Temp\fwtsqmfile03.sqm "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Temp\fwtsqmfile02.sqm "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Temp\fwtsqmfile01.sqm "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Temp\fwtsqmfile00.sqm "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Temp\avg-f4436819-849e-4327-a1ce-1a68c13ed048.tmp "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Temp\avg-b805b162-2eff-4f2a-8fd1-5c46469d0e6a.tmp "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Temp\avg-9b7ced36-f732-420e-adff-9433b60d9714.tmp "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Temp\avg-5408104f-6330-4a4d-906e-ef24c9418228.tmp "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Temp\avg-46adef6f-a347-424f-b32f-011ab4363b36.tmp "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Temp\avg-38905f0b-35c2-4748-9eb0-9454a13ed418.tmp "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Temp\avg-2ec09c04-2871-4041-9c54-e11b911c7063.tmp "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Temp\avg-09e9f110-48cb-4959-a88b-1532a4d0231c.tmp "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Temp\avg-04551e47-c699-4c03-9389-9b5bdc98152e.tmp "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Tasks\Adobe Flash Player Updater.job "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Windows PowerShell.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\System.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Setup.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Security.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\OSession.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\ODiag.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\OAlerts.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-WPD-MTPClassDriver%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-WPD-CompositeClassDriver%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-WPD-ClassInstaller%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Wired-AutoConfig%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Winsock-WS2HELP%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-WinRM%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Winlogon%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsSystemAssessmentTool%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsBackup%4ActionCenter.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-WFP%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-WER-Diag%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-VHDMP%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-VDRVROOT%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC-FileVirtualization%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-TZUtil%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-TerminalServices-RDPClient%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-TerminalServices-ClientUSBDevices%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-TerminalServices-ClientUSBDevices%4Admin.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Security-Audit-Configuration-Client%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\microsoft-windows-RemoteDesktopServices-RemoteDesktopSessionManager%4Admin.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-RemoteAssistance%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-RemoteAssistance%4Admin.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-RemoteApp and Desktop Connections%4Admin.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Recovery%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoostDriver%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-PrintService%4Admin.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-PowerShell%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-PeopleNearMe%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-ParentalControls%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-NTLM%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-NlaSvc%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkLocationWizard%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4WHC.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-NCSI%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-MUI%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-MUI%4Admin.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-MemoryDiagnostics-Results%4Debug.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-MCT%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Known Folders API Service.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WDI%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Iphlpsvc%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-International-RegionalOptionsControlPanel%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-IKE%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-HomeGroup Provider Service%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-HomeGroup Listener Service%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-HomeGroup Control Panel%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Help%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Forwarding%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Folder Redirection%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-FMS%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Fault-Tolerant-Heap%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-EventCollector%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-EapHost%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-DiskDiagnosticResolver%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-DiskDiagnosticDataCollector%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-DiskDiagnostic%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Networking%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-ScriptedDiagnosticsProvider%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-Scripted%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-Scripted%4Admin.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-Scheduled%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-PLA%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-PCW%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-DhcpNap%4Admin.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-DeviceSync%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-DateTimeControlPanel%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-CorruptedFileRecovery-Server%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-CorruptedFileRecovery-Client%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bluetooth-MTPEnum%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Backup.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Authentication User Interface%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Audio%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Audio%4CaptureMonitor.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Program-Telemetry.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Program-Inventory.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Troubleshooter.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-Application-Experience%4Problem-Steps-Recorder.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-AppID%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Microsoft-Windows-API-Tracing%4Operational.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Media Center.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Key Management Service.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Internet Explorer.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\HardwareEvents.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\winevt\Logs\Application.evtx "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\wfp\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\wdi\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\wbem\MOF\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\wbem\AutoRecover\F5E2A66F8CD81F282CEFFB9E8125CC6F.mof "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\wbem\AutoRecover\F1326650D965B0087F10C6AA6C049D46.mof "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\wbem\AutoRecover\EDB534A0AD75CF6CD3441C25046B8E9A.mof "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\wbem\AutoRecover\E9D8A460B2C986DD5FF19F299F4A27EC.mof "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\wbem\AutoRecover\E478A5DB75C9721E744C05D78DBACFD3.mof "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\wbem\AutoRecover\DFB9AD54AC2D3B8122567AAD3BF3EB7F.mof "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\wbem\AutoRecover\D361F8B496FD6DAF7BEEF497E09C0DC1.mof "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\wbem\AutoRecover\99A0139C6E79D7AD8910304DC76ADDCE.mof "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\wbem\AutoRecover\97823DC673AD0F92AB9B83F4C177678B.mof "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\wbem\AutoRecover\844A429FB6680A32838047A6271F8CD9.mof "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\wbem\AutoRecover\75054C3771DF289038069A9BB1C1FB6E.mof "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\wbem\AutoRecover\6F8564A71977AE6B940705DCC4847A8D.mof "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\wbem\AutoRecover\5774C77265BE4C55B5C6C9718979E015.mof "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\wbem\AutoRecover\14C5A2A3C41254184B007011E5565E5B.mof "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\Tasks\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\sysprep\Panther\IE\setuperr.log "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\sysprep\Panther\IE\setupact.log "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\sysprep\Panther\IE\diagwrn.xml "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\sysprep\Panther\IE\diagerr.xml "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\spool\PRINTERS\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\restore\MachineGuid.txt "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\NetworkList\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\Msdtc\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\LogFiles\WMI\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\LogFiles\HTTPERR\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\LogFiles\Firewall\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\LogFiles\Fax\Outgoing\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\LogFiles\Fax\Incoming\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\ias\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\GroupPolicyUsers\S-1-5-21-759393751-1481746019-3899478243-1005\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\GroupPolicyUsers\S-1-5-21-759393751-1481746019-3899478243-1004\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\GroupPolicyUsers\S-1-5-21-759393751-1481746019-3899478243-1003\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\config\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\com\dmp\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\System32\catroot2\edb.log "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\ServiceProfiles\NetworkService\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\ServiceProfiles\LocalService\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\security\database\secedit.sdb "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\security\audit\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Prefetch\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\PLA\Templates\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\PLA\System\System Performance.xml "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\PLA\System\System Diagnostics.xml "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\PLA\Rules\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\PLA\Reports\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Panther\UnattendGC\setuperr.log "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Panther\UnattendGC\setupact.log "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Panther\UnattendGC\diagwrn.xml "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Panther\UnattendGC\diagerr.xml "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\ModemLogs\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Minidump\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe.config "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Logs\WindowsBackup\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Logs\SystemRestore\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Logs\HomeGroup\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Logs\DPX\setuperr.log "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Logs\DPX\setupact.log "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\Logs\CBS\CBS.log "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\LiveKernelReports\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Windows\AppCompat\Programs\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\Videos\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\Templates\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\Start Menu\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\SendTo\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\Searches\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\Saved Games\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\Recent\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\PrintHood\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\ntuser.pol "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\ntuser.ini "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\NTUSER.DAT{706d99a7-fd3a-11e0-a9a4-00241d238624}.TMContainer00000000000000000002.regtrans-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\NTUSER.DAT{706d99a7-fd3a-11e0-a9a4-00241d238624}.TMContainer00000000000000000001.regtrans-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\NTUSER.DAT{706d99a7-fd3a-11e0-a9a4-00241d238624}.TM.blf "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\NTUSER.DAT{5a05e7e9-30e9-11e0-b5c8-00241d238624}.TMContainer00000000000000000002.regtrans-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\NTUSER.DAT{5a05e7e9-30e9-11e0-b5c8-00241d238624}.TMContainer00000000000000000001.regtrans-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\NTUSER.DAT{5a05e7e9-30e9-11e0-b5c8-00241d238624}.TM.blf "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\ntuser.dat.LOG2 "; "Locked file. Not tested. "; "Locked file. Not tested. "
     
  2. 2012/05/21
    jayman34

    jayman34 Inactive Thread Starter

    Joined:
    2009/02/25
    Messages:
    65
    Likes Received:
    0
    ; "C:\Users\Wendy.SD-PC\ntuser.dat.LOG1 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\NTUSER.DAT "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\NetHood\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\My Documents\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\Music\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\Local Settings\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\Links\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\Favorites\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\Downloads\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\Documents\My Videos\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\Documents\My Pictures\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\Documents\My Music\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\Cookies\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\Contacts\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\Application Data\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\vlc\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Real\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Realtime Soft\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\PC Suite\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Word\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Windows\Themes\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Windows\Templates\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Windows\Start Menu\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Windows\SendTo\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Windows\Recent\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Windows\PrivacIE\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Windows\Network Shortcuts\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Windows\Libraries\Videos.library-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Windows\Libraries\Pictures.library-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Windows\Libraries\Music.library-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Windows\IETldCache\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Windows\IEDownloadHistory\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Windows\IECompatCache\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Windows\Cookies\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\UProof\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Templates\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\SystemCertificates\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Sticky Notes\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Stationery\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Speech\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Signatures\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Protect\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Proof\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Outlook\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Office\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Network\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Internet Explorer\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Installer\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\IMJP9_0\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\IMJP8_1\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\IMJP12\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\IME12\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\HTML Help\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Excel\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Document Building Blocks\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Crypto\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Credentials\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\CLView\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\CLR Security Config\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\Clip Organizer\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Microsoft\AddIns\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Media Center Programs\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Macromedia\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Logitech\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Identities\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Garmin\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\fenglei\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\DivX\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\DisplayTune\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Canon\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\AVG9\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\AVG2012\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Roaming\Adobe\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\Local\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Wendy.SD-PC\AppData\LocalLow\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\UpdatusUser\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Sean\ntuser.dat.LOG2 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Sean\ntuser.dat.LOG1 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Sean\NTUSER.DAT "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Sean\AppData\Local\Temp\msdtadmin\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Sean\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Sean\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Sean\AppData\Local\Microsoft\Windows\UsrClass.dat "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Sean\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{BAC1C29D-A133-11E1-B9D8-00241D238624}.dat "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Sean\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{ACC91757-A133-11E1-B9D8-00241D238624}.dat "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Sean\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{8368E097-A133-11E1-B9D8-00241D238624}.dat "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Sean\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{8368E096-A133-11E1-B9D8-00241D238624}.dat "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Sean\AppData\Local\ElevatedDiagnostics\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Public\Documents\My Videos\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Public\Documents\My Pictures\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Public\Documents\My Music\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\Videos\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\Searches\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\Saved Games\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\Music\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\Links\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\Favorites\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\Downloads\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\Desktop\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\Contacts\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Realtime Soft\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Nero\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\Windows\Themes\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\Windows\Templates\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\Windows\Start Menu\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\Windows\PrivacIE\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\Windows\Network Shortcuts\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\Windows\Libraries\Videos.library-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\Windows\Libraries\Pictures.library-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\Windows\Libraries\Music.library-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\Windows\IETldCache\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\Windows\IECompatCache\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\Windows Live\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\SystemCertificates\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\Protect\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\Network\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\Internet Explorer\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\HTML Help\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\eHome\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\Crypto\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Microsoft\Credentials\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Media Center Programs\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Macromedia\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\downloads.m3u "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\default.rss "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Roaming\Adobe\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\Local\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly\AppData\LocalLow\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\Videos\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\Templates\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\Start Menu\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\SendTo\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\Searches\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\Saved Games\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\Recent\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\PrintHood\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\Pictures\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\ntuser.pol "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\ntuser.ini "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\NTUSER.DAT{c483a698-0942-11e1-a621-00241d238624}.TMContainer00000000000000000002.regtrans-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\NTUSER.DAT{c483a698-0942-11e1-a621-00241d238624}.TMContainer00000000000000000001.regtrans-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\NTUSER.DAT{c483a698-0942-11e1-a621-00241d238624}.TM.blf "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\NTUSER.DAT{706d99a9-fd3a-11e0-a9a4-00241d238624}.TMContainer00000000000000000002.regtrans-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\NTUSER.DAT{706d99a9-fd3a-11e0-a9a4-00241d238624}.TMContainer00000000000000000001.regtrans-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\NTUSER.DAT{706d99a9-fd3a-11e0-a9a4-00241d238624}.TM.blf "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\ntuser.dat.LOG2 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\ntuser.dat.LOG1 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\NTUSER.DAT "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\NetHood\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\My Documents\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\Music\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\Local Settings\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\Links\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\Favorites\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\Downloads\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\Documents\My Videos\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\Documents\My Pictures\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\Documents\My Music\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\Desktop\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\Cookies\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\Contacts\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\Application Data\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Softland\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Real\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\PC Suite\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Word\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Windows\Themes\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Windows\Templates\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Windows\Start Menu\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Windows\SendTo\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Windows\Recent\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Windows\PrivacIE\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Windows\Network Shortcuts\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Windows\Libraries\Videos.library-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Windows\Libraries\Pictures.library-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Windows\Libraries\Music.library-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Windows\IETldCache\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Windows\IEDownloadHistory\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Windows\IECompatCache\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Windows\Cookies\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\UProof\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Templates\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\SystemCertificates\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Sticky Notes\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Protect\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Proof\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Office\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Network\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\MSN Messenger\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Internet Explorer\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Document Building Blocks\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Crypto\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\Credentials\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\CLR Security Config\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Microsoft\AddIns\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Media Center Programs\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Macromedia\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Logitech\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Garmin\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\AVG2012\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Roaming\Adobe\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\Local\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Holly.SD-PC\AppData\LocalLow\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\Videos\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\Searches\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\Saved Games\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\Pictures\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\Music\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\Links\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\Favorites\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\Downloads\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\Documents\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\Desktop\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\Contacts\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Themes\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Templates\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Microsoft\Windows\PrivacIE\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Network Shortcuts\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Libraries\Videos.library-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Libraries\Pictures.library-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Libraries\Music.library-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Microsoft\Windows\IETldCache\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Microsoft\Windows\IECompatCache\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Microsoft\Windows Live\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Microsoft\SystemCertificates\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Microsoft\Protect\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Microsoft\Outlook\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Microsoft\Office\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Microsoft\Network\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Microsoft\Internet Explorer\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Media Center Programs\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Macromedia\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Identities\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Roaming\Adobe\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\Local\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Guest\AppData\LocalLow\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\GuestAccount\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Default\Templates\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Default\PrintHood\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Default\NetHood\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Default\Documents\My Videos\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Default\Documents\My Pictures\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Default\Documents\My Music\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Default\AppData\Local\History\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Beyonwiz\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Users\Administrator\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752} "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\System Volume Information\{20cd9400-a0bd-11e1-b9d8-00241d238624}{3808876b-c176-4e48-b7ae-04046e6cc752} "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\System Volume Information\WindowsImageBackup\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\System Volume Information\Windows Backup\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\System Volume Information\tracking.log "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\System Volume Information\Syscache.hve.LOG2 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\System Volume Information\Syscache.hve.LOG1 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\System Volume Information\Syscache.hve "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\System Volume Information\SPP\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\System Volume Information\MountPointManagerRemoteDatabase "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\System Volume Information\Chkdsk\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Recovery\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Western Digital\WDFME\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Templates\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Real\RealUpgrade\upgradeconfiginfo_9531819.xml "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Real\RealUpgrade\upgradeconfiginfo_8576129.xml "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Real\RealUpgrade\upgradeconfiginfo_3302639.xml "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_x86_c6bde7cad6a871516f2319a469f3a789709158_2d76f2bf\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_x86_4db34fbf1889bb144bb43d19b7adbbfb2a24126e_34462b1c\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_x86_4a223fbcecdff7379503369e2624b127ebf3e6_15fbe2a9\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_HostProblem_911f6d4e6d91ce6c7b232a64788dd649629d54_0673619f\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_cf2a44b12a5356e18687809cb38d3fb91aadc476_3e5305da\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_cf2a44b12a5356e18687809cb38d3fb91aadc476_04a1525a\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_cb9c4552cbf1c541f27c3fbfaa135969a63ace2_19bad238\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_a22ae0ab93b9edcb78c738a4e7d595ace9f81e6_1f505dd2\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_a1a75baf9c8c8f72365695a3bb4b77e6f947eae_29b67b6e\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_37c94a3f7f9dc50e1a69c36b71e2ccbefec74cf_73e98e9e\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_Backup_37c94a3f7f9dc50e1a69c36b71e2ccbefec74cf_1b4bb06c\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_8f7a6a1fe6923a3af752a7124a1a45da2ee6af57_5cea11b4\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_7cedaa31ff22678c835bfa11ef9ae14c2706f10_4c1975d7\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_7c2b7e81e8e37af903744f826b4b2a9be374b9e_13bb8f16\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_2eba5dc997f2d328b71e4f86cb5fbc4d9bbdb14_01bced0a\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_2adaa4b9626f2e1f58e83b6dc4885a8b8abbef0_3f4b070e\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_26d49a36e0e7bf2b5a39b3d0cd321ffa1e717_1fa555f9\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_266418e40566a4299d32a972c38c7633cf657a_619d218c\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\NonCritical_7.5.7601.17514_266418e40566a4299d32a972c38c7633cf657a_18404f64\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_6fb46498b640173bffc081d941b0fbc3149b20_6f793e91\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_6fb46498b640173bffc081d941b0fbc3149b20_1a072d09\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_031c0bfb09e75551725847f9561a67c452d7df_5e10fa2e\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601_031c0bfb09e75551725847f9561a67c452d7df_1ef3440e\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17592_ee8d625cb151f3ebdb26dab6d2f1872089dc93_689d5f5a\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17592_82a397f8fd4365482c817ebbb8bfcb2c2bc77d27_6460fa2e\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17592_82a397f8fd4365482c817ebbb8bfcb2c2bc77d27_17c78755\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_6.1.7601.17592_61736e9746b1f21d0f452c2365e13833f5a5d_086b3f04\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_nvSCPAPISvr.exe_cfa347982e19bf927899ca6dcb7659cfefb95f_061802a0\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv_SID_S-1-5-21-759393751-1481746019-3899478243-1005\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv_SID_S-1-5-20\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows NT\MSFax\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows Live\Family Safety\fss.dat "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Windows Defender\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\User Account Pictures\Wendy.dat "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\User Account Pictures\UpdatusUser.dat "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\User Account Pictures\Holly.dat "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\User Account Pictures\Beyonwiz.dat "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Search\Data\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\PlayReady\Cache\S-1-5-20\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Network\Downloader\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\eHome\Cache\S-1-5-20\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ffcce28e3b9679c915141cbd90d6d114_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ff91aac5a475f9b6a1f20bc98f6da263_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ff05368251b1e7ab3b09dc66320e427f_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fe7811609e767b910e37fcf8a65a1c60_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fe6c7dbe53b3d38e5b2d3aaae27da090_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f944a7ad301bf90110803de7cd50b31d_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f63133cfe8649eff077741074ee343a2_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f56ff8dab5f1472bf4953455c191cc95_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f51666cfff64b0f1597527192a627199_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f3bd1339b6d70e754df4f3da091fcd43_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f310748605c1677cf3c94af16ec1e0fd_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f1f175dcec96925f1c942cc018489366_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f118deb6a2ff26af7861c69b8a2cc1e2_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\eff349854ebda193692775cb9554e80c_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\efce14bd014702c3d750cee19eb46630_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\efb27140dee6a52910982ea455033ade_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\eed2a7b69ecdefc5269636bb0b769086_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ede28ce9d487a276089a30c27f3195d1_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ed68b4f7a940b363aede5cd313ba54f1_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\eb39f1e341555aa92302325ec91e2582_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\eaa1414a12b21894923f49bb84b0d0d4_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ea18014ee72939dd5670d5bae5179dc9_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e9726be3b3c2a5063c29ed0d4912f2ab_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e9685712e6e239c0990679ea60b2d0fd_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e8f3f4dc942958c61c69fbe52e1de28e_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e8dd4b89dff1ed76b2ee20efea6bc428_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e7e562f16e07cb53b3d38456fe7975b7_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e6d48b4750f236a1c4d4b4f162f1c6b6_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e61fdb076e916aaa590c376651f5992a_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e505f5371f049e617aa2b234f2b90072_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e4a554266e4a6855c0f266c6a0bc40db_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e08a9b428055e2c818d3e321f2c1bd48_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e00d5116ff889a8a05532629fa07cac8_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dfea040172dd2b734e9649ef9054ec1a_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\df75e6754a2e10a5c0f292d08be63f70_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\df10952323ca0782b6c86eab6cca214b_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\de641a4abd1a2047ee5809b89a37fea2_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\de51ce4ba0b2172d987c880a679eb0f5_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dd0a1d655b2af18af41b4b628ff6c0b2_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\daf7a956966c71ee41940b1f89d13324_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\da0674360cd10dfa1bb2f85b32150682_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d77e1d07f77d323cdb17951fe521a8e8_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d7465324c4a8ed34a50faed712128969_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d5d5bfd4e86b299b1f737eaa5b53d5a6_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d4ff7a7f3948aadaf29945d3a643312f_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d3159c906f1598e9ba5391d6512dc3dc_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d2c562853282e207a340578875b6ceb6_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d289ddca71ed274de56a13d5641695c4_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d0cf6457bfafe663a5d4900ff25cc3f5_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cd298c33f9fe781231b41344df0ca906_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cd212dc6e9c6562f6aa29f3c38840f56_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cca3fc83a19a7fd5ccf37c22f429af5c_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cc34a05255988abb4e779800cd81ae4b_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c953ae2c53f1488838e624584cf3e619_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c84d5fc056f6eaf7e7bdcea926474aae_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c7fe5d34b142647ea8fcdbe21ffc022b_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c77f2351a30108fe04dd8597eaecbfd9_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c708a6edcec1515321bc284a2c53a90f_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c6f6a5d82e84f85d1b4936c30933a7b1_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c6c99f864e145042a51e6c57800107e6_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c5512e7b368520f44a40afcbd8216362_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c36b2c71d8c227557c9b904498ac8f9f_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c36a0c8721e1d527f161c3e0713e6fa6_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c31181471946271f96757affb8ea07c8_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c2d5d19e79a773c0e187a2a5593b38e3_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c2a9ef5686acc6b63295de98db9f95b2_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c016112119edb75fce534825792c3939_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bffbefc63522706d957ed4179c804b35_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bfb957085d73f1377dc9e12f481a3427_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bf1d1f83671db9916011f7d1852483cc_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\be1ee1a202c76cfb8f3a5d63c05b9634_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bbfae52a482163cf832d8bce8c5d9662_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bb5d46dc25d3fd3c8799ebce66cad683_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b9c4e9023d6e2948d58a7e622331a63b_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b8f2d45fa555f748621ff290770d7858_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b8d702de5c7a53a98fa6cef6dbfc1e48_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b74d3ee111bda17b9d7c6f9714269c19_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b73fd832249d30d188510b1f61668712_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b6d4b5a606a71dee720d75601be220be_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b5b796bfb5a4762055b3fcc18c69ffe9_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b33bab8e7c75e9e101f4186ca73fe59c_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b3294fd2b6af90430ffd5224ea1fe756_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
     

  3. to hide this advert.

  4. 2012/05/21
    jayman34

    jayman34 Inactive Thread Starter

    Joined:
    2009/02/25
    Messages:
    65
    Likes Received:
    0
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b23fe8623e5526dc59aeb2d016b4910e_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b19db601601c07a2e91b51344b37e958_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b18af92bb777f8f87c69fa4e191106fe_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b1566d3b4854b522a3b9cda251327df0_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b02ba2682735bba710443414aa5cd36f_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\afce922cd893c0356a97de696fdcb48a_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\af8a6daabeba84803a69e3197fc359b0_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ae56472c1e86e7935ae915ca38d2a9a2_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ae510cd426c03f5b6339659d1880cf9d_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\adc9137e11aeb73da1b040ddc7fa15c5_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ad4f972fc16ce370c62650910109d14b_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\abb28e83274a1053451aa77a0fc2abe2_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ab87083d36b997f1bbb18834f54b6f70_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ab2b75ff32b398973300f1f5cd5f95fc_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aae60dd54c168ed6225bb898820283b8_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aadbf4b0525e04e2a3c7011cb35a7c10_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aa5d1cd43d2570f34ded0b802810ba07_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aa3b3ddbb2c2b6b6cb20f370bf81f9b9_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\aa1de32e51482a3fc679749554114dc6_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a92b756c45b0bb3ae9d50430872d5a2c_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a8448293fc8e6bd7c8cdf4a0946dccdd_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a7e1ab27aed101095e8c9904fe7f93e2_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a7583ad4f1b37583f5084516a84d2e36_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a69b8ef7f502056692f9d80f9b98e208_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a6444480a3aa60d8ebb02550b5bfefb5_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a547814b77e1d3efacfe9bc7d916f035_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a45a604a59bb5d952c18c2a98e0296ef_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a1b57564b7bd4837452f2a58adbb56b2_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a0fc13a1dd6cc5764fe1f5e2a691fd4b_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a040ddd3b3a35852bcd32bf9bec10f0c_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9e84fb9d4d4a388524a24cd3ab074b33_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9b7eadace99a2333e1c43ff8030fb4fc_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\99a9c608e645d3f46e38c8182abcdf89_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\98fda0fd278b2d4dfc9ea9ddc2d58d9a_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\98b8626d19b3988a992cc5f44099bd1a_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\97c8e138c44b155d4f9f32af5e476139_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\96469263dd66bcc3fa2a6ef49e69abcb_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\93d4f79c765b8e376e768ff6a8aaf375_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9357fa8c6f04e8caffe28776b7a59f1e_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9354d09e583b4c7ddbabac7114e9c1a6_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\92e38c7ea589fd6b330af2aa12030537_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\916ce864474d6eba1d9ac5c34f1e961b_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\916032f631915389a346fdccc5b7998b_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\908e93aa57b1047ea49befc381a9bc75_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9078933c0e27526c022453517f04840f_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\902d3c0a0c36c5ae1d466f724d26d364_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8f740add6efc81dadc53ed1b00329982_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8f2cbce95d80a7263287a3cf53b2c9ac_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8f09bfc81696f61afddfb98cfe49134d_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8d45a4bdfb9bb2e7fc73e52d1a89f4ec_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8c15a04baf86c956b89f3ccafc2a25c7_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8bc249c8e80ca6dcc09dbac1f9d0de1b_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8b11477908704ab9fe37892d985f1c0d_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8a1617aa85d84426510e39d529c3cbae_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\891dfdafadd9a04523b7216919092353_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8914a9fd825f75f3d061cd6766b29f0c_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\88ff5b19d361fa85f1be48b91b40ef88_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\88c770c259c14a09abe48ae35d5b4e7c_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\87503741725e18b25d721ce2d190c9bc_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8722cf46833c1dc3fb6a77306e526474_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\86abb5d350330501294587cc16e064c4_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\858886fc77fe6ae5e42b4b8daaa5304b_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\843a762c4f90031b1008f43432fda976_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\82c0c806b9b31c15cea12d8e6fb12265_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\80c73d37570fc29e57e30e903091155a_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\804e1b72e7f2e396fb8716f6f835750e_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\80035fb017bd1af14e616e5c3cef74af_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7da4d7fd150ad67b09083427327468ad_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7d1f771698b29261a32749a65debead5_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7c684e2df6e777e12b7e4be8b804c7f4_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7b25dfcdee48b667efc4bba095351371_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7afecb37b620264a9200aa196f143c44_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7ab70295a1bbdbf17dbf7fe74089618e_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7a4d123cd177f9fdf6b293f0a303f4bc_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\783be3dec24a919cfad72b13e6f1adfc_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\77cd16a59a530f995dad9a05e0c670ef_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\775ee4e97f6dd563f6da00df4553ac35_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\76da033e6d043ad042bd0640b45d0beb_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\764174d4f0168353658b2fda38aff1d6_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\745d36e8b749beb4c92eba6871078261_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\73b5c68a56d9010a3e61cc2fdc43457f_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7329c570e726bdcb9831dd4c0f733f17_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\70ea03cd26724c3bdc019ee4a9ec3f50_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\70b10b210925ab16b15548e8ddef511a_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6fe615614da8d7c09e0f262869e5672a_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6f9a37e092d3147bc1ce657fd6b45d97_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6e27d7542b1d7814f4d692f1db1241e4_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6d5e7a8df7859fd66d6cda909ad264d1_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6c6300e7eeea2238e26a0fbde332a93d_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6b62677fdad439bacb9b465fc51081eb_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6ae22d6ad60c66bd47282a70ca4d20e4_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6a687747ab9a79c43a3cc5f8733a3f1e_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\68e6bdf1fc8e991ef102f7f88d5acea9_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\685dcc21854902b02cd56b1c3405ad21_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6294c1fba0f7095e7996790b8d1f8118_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6279522839c19684838ed5efee36219a_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5e6b19244260ce2a8060696620b91158_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5a88ff48937a374b2a479eada3f0b408_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5a7f85281a130b96a62751027df90ff5_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\591d3e0343b2311325401f835153538a_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5882f9af692d444640ffa33834a77ee7_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5588fdcce32ce00ac25b7e7e8979b793_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5412c4d6e467900a85adfcb3491f0bdd_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\534a373dcefb0e73ee76343e774a895a_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5326041ac641e12d65d61d3dfea3f1a3_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\509123a5e683a5f4525ba5c10798d477_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5027a4e28ade739abc508db19414f072_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4fec9463a23d7dea6a5826b6c00b1026_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4f58777ef4995a5c21266e69e1207880_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4eac6fd989c5922453d76ce03060555e_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4e2afd1d8edca1d5b2b3812d2329d54e_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4dc71d4f14b57f867e35e6c51e8bc6ba_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4cbd0819ece27f69face5fb6eafed190_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\495a8f8c42a3ec0e542832608bb68a69_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\48a87e3f80c19bfc682827292ad71e56_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\47bb0857c40842191602fca2f26a2917_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\46c3eb8bd8147c2192c79a2dc2970803_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\46927c124f45d794c25d83ae58543ae4_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\44e21052896b420389a7c13eafbf0e48_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\44af2ab020640a351f3b6bcd58560c89_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\42f3ca416be9e397cfa8f13a1e5f0b20_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\422face181a222d99afcb9662d0995e4_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\41996a83f5bcd4581415845b4f50b9ff_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\40b6c45219dd84c4cd2a9001a160dfe6_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3f7b19362547f543dfbf1fb7d05c30ab_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3e8482bd2dcd933a664bbb0e5df24e0c_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3e11f9e757df108b32ffd6c571ca4b8b_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3dfb6919fd6998c860311b996a68db0a_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3ca97fc84800dfe0bbe3c4128239193d_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3c1d03e5fa3ceabd28a62c49c73c6ffc_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3a021742193f048262cd18e575a50e25_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3998b9cc4c1fae1f7f2a4162ec85e039_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3981fc58ff6395e8551c105657ba883e_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\38d8bee1d3324a488d4f0541739ee4c0_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\386702f53289cead5c6dc5af407c60d1_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\38457a241969fc3da193a54f90ba0a0d_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\37a1abe4c40db7213baa6d75d54d070a_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\36fb6beeb999f376760f10c8f3aaeb76_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\36c081423e6cbbcc7ca7bce0bdf460ce_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\35f7277b19eb33e45f42ea0c380ae3b5_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\30b575a12dad5e2c0f244f660f82abb5_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\301ed70cf38ebe06713cd07bf8797a1d_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3002354a0d368f2477995701307012f1_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2ffb30e70b7757b2d5a9cdcf18819130_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2ecc004cc5821354f6b36ee7ecb06eeb_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2e4f1e3c5cc6751e1ce516a8bd56f822_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2e3022b1ca08273df804411d9c86a968_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2e0457bccbcbc984f496c0f2eb566866_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2cbd668515605cf4cc45baebcfc061e5_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2c38e43b4f161700ebe046ed0bc993a2_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2bf125d06cf8991a063b3a850a78a23a_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\29eb4151b6c25fbed20ff57b6dce0d11_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\29d69df3d5f3021a16f7b85de4a3d051_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\29475bb860ea648ab6d66645e8432604_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\28eecad27015510ad145f632d166d573_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\28c45e4f5a49e810096308bc49c6064c_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\288b04385f769f5cc1fb54f8bd97f9eb_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\284d93d39a80ef9ae2d6173257060bdd_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\271ea0995aa3f74ced506b4758625be7_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\26db8146fd9cf59051f8ff462452af10_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2533fb61a21aef8b6dce4f9094042fdf_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\244825e170cefa335e8bcd859fd11abb_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\22fbbf4cdc1729994f5c53007b2eeddc_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\221188275d86606c658af9f9b03d532f_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2186dad217b83a92ec4a9de09ccfee36_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2159d340951e6cef2e541299e840fdf0_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2036c8e7cb239f6daf2d29d629b6e8df_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1f15111f37cf2afc83b1372c9118945d_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1e333defe2af620374b6b0e3639c1847_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1a7408cd52bbdcf0fa9a25a9c00235dd_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\19e118bea8175bc3e790211d4eea5b0b_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\18e47f725b80a357ba2dfe5456952eba_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1889bff9d11a74fa2d6ad687f6c0d86d_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\185a15b5f87c8648ae00917c48609e38_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\17e02d8a27c358be6cbafb3badba509f_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\169c4e2cd423dfb8ca6b136a24cb1b8f_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\16921de2c237314d87b421dc8605200f_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1679a33d3f9472c3a7329b5444816db5_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\16727bbe604fb9ecb0e1f933fb5b95e6_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\15ad7699d5aeedd77579f29a3ae609e5_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\10e1902f727575fad9230a99b375891c_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0f0202ce795bfa5a4bc2ff11e0b913d5_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\09fe85cb7f27297ef9006c86c08c0750_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0875f96bcf7b41487f8f2d17b892a5a6_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\081f4f652f03331321df8a93aceab84d_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\075a0b98f2feec3d95a9e48a0fe47e42_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\065c16b017c35f170ede877bcd2d6474_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\028a637622b56e9b8132770c329f6617_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\025fff869cbb9ff4225eacc07b687fac_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\018414b9d5b8d3f45bccec28595973fa_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Microsoft\Crypto\Keys\83248373b159cb3f36612e7dc9d0fb83_30a1cef4-8d00-4811-8c3b-75b582d50399 "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\MFAData\msistorg.dat "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Favorites\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Documents\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\Desktop\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\avg9\Temp\file9514.tmp "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\AVG2012\Temp\file9514.tmp "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\ProgramData\AVG2012\Temp\file3196.tmp "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Program Files\Google\CrashReports\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\pagefile.sys "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\MSOCache\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\hiberfil.sys "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Documents and Settings\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Config.Msi\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Boot\BCD.LOG "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\Boot\BCD "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\bf26f80fe802027dda5f4ab0c3d7ce72\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\3cea9c0ce97d259610292b384d\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\0886a31514149f145e\MRT.exe "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\$Recycle.Bin\S-1-5-21-759393751-1481746019-3899478243-1005\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\$Recycle.Bin\S-1-5-21-759393751-1481746019-3899478243-1004\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\$Recycle.Bin\S-1-5-21-759393751-1481746019-3899478243-1003\ "; "Locked file. Not tested. "; "Locked file. Not tested. "
    ; "C:\$Recycle.Bin\S-1-5-20\ "; "Locked file. Not tested. "; "Locked file. Not tested. "


    Malwarebytes LOG

    Malwarebytes Anti-Malware 1.61.0.1400
    www.malwarebytes.org

    Database version: v2012.05.19.07

    Windows 7 Service Pack 1 x86 NTFS
    Internet Explorer 9.0.8112.16421
    Sean :: SD-PC [administrator]

    20/05/2012 9:43:10 AM
    mbam-log-2012-05-20 (09-43-10).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 373227
    Time elapsed: 23 minute(s), 39 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
     
  5. 2012/05/21
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    =================================================================================

    Skip GMER and proceed with other scans.

    Also, you're not saying what your computer issues are.
     
  6. 2012/05/22
    jayman34

    jayman34 Inactive Thread Starter

    Joined:
    2009/02/25
    Messages:
    65
    Likes Received:
    0
    The problem is in my other post

    "Windows 7 Hangs/Slow Explorer not responding "

    I was told to come here with the new problem. Sorry

    I will try skipping GMER and see if everything else works
     
  7. 2012/05/22
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I need to see other logs...

    Please, complete all steps listed HERE
     
  8. 2012/05/24
    jayman34

    jayman34 Inactive Thread Starter

    Joined:
    2009/02/25
    Messages:
    65
    Likes Received:
    0
    aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
    Run date: 2012-05-24 06:05:29
    -----------------------------
    06:05:29.004 OS Version: Windows 6.1.7601 Service Pack 1
    06:05:29.004 Number of processors: 4 586 0x1707
    06:05:29.005 ComputerName: SD-PC UserName: Sean
    06:05:31.155 Initialize success
    06:09:37.605 AVAST engine defs: 12051401
    06:09:51.393 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2
    06:09:51.396 Disk 0 Vendor: Maxtor_6L160M0 BANC1G10 Size: 156333MB BusType: 3
    06:09:51.399 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T1L0-6
    06:09:51.402 Disk 1 Vendor: Maxtor_6L200M0 BANC1E00 Size: 194479MB BusType: 3
    06:09:51.405 Disk 2 \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP3T0L0-3
    06:09:51.408 Disk 2 Vendor: WDC_WD1001FALS-00J7B1 05.00K05 Size: 953869MB BusType: 3
    06:09:51.429 Disk 0 MBR read successfully
    06:09:51.433 Disk 0 MBR scan
    06:09:51.444 Disk 0 Windows 7 default MBR code
    06:09:51.448 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 156327 MB offset 63
    06:09:51.456 Disk 0 scanning sectors +320159385
    06:09:51.511 Disk 0 scanning C:\Windows\system32\drivers
    06:10:04.134 Service scanning
    06:10:33.368 Modules scanning
    06:10:40.979 Disk 0 trace - called modules:
    06:10:41.002 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys
    06:10:41.007 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x869eb630]
    06:10:41.014 3 CLASSPNP.SYS[8bbad59e] -> nt!IofCallDriver -> [0x864aa898]
    06:10:41.019 5 ACPI.sys[8b6b33d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-2[0x864ee030]
    06:10:43.668 AVAST engine scan C:\Windows
    06:10:47.538 AVAST engine scan C:\Windows\system32
    06:13:56.379 AVAST engine scan C:\Windows\system32\drivers
    06:14:13.834 AVAST engine scan C:\Users\Sean
    07:02:50.359 AVAST engine scan C:\ProgramData
    07:08:06.713 Scan finished successfully
    17:33:27.169 Disk 0 MBR has been saved successfully to "C:\Users\Sean\Desktop\MBR.dat "
    17:33:27.175 The log file has been saved successfully to "C:\Users\Sean\Desktop\aswMBR.txt "
     
  9. 2012/05/24
    jayman34

    jayman34 Inactive Thread Starter

    Joined:
    2009/02/25
    Messages:
    65
    Likes Received:
    0
    .
    DDS (Ver_2011-08-26.01) - NTFSx86
    Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_30
    Run by Sean at 17:34:02 on 2012-05-24
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.61.1033.18.3070.1327 [GMT 10:00]
    .
    AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
    SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
    C:\Program Files\AVG\AVG2012\avgcsrvx.exe
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\System32\spoolsv.exe
    C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
    C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Program Files\AVG\AVG2012\avgwdsvc.exe
    C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files\Windows Live\Family Safety\fsssvc.exe
    C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
    C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
    C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
    C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe
    C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
    C:\Program Files\AVG\AVG2012\avgnsx.exe
    C:\Program Files\AVG\AVG2012\avgemcx.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Windows Live\Family Safety\fsui.exe
    C:\Program Files\AVG\AVG2012\avgtray.exe
    C:\Program Files\Garmin\Lifetime Updater\GarminLifetime.exe
    C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
    C:\Program Files\Global Graphics\gDoc\DocCreatorClient.exe
    C:\Program Files\DivX\DivX Update\DivXUpdate.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Portrait Displays\Pivot Pro Plugin\wpctrl.exe
    C:\Program Files\Portrait Displays\Pivot Pro Plugin\floater.exe
    C:\Windows\System32\DCMessages.exe
    C:\Program Files\SanDisk\SanDisk Media Manager\SanDiskMediaManager-Launcher.EXE
    C:\Windows\STK02H\STK02HM.exe
    C:\Windows\STK02N\STK02NM.exe
    C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
    C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\svchost.exe -k SDRSVC
    C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
    C:\Program Files\Sony\Sony PC Companion\PCCService.exe
    C:\Windows\system32\taskhost.exe
    C:\Program Files\Real\RealPlayer\update\realsched.exe
    C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\system32\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uSearch Bar = Preserve
    uStart Page = hxxp://au.yahoo.com/
    mURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\tbVuze.dll
    mURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
    mURLSearchHooks: H - No File
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Canon Easy-WebPrint EX BHO: {3785d0ad-bfff-47f6-bf5b-a587c162fed9} - c:\program files\canon\easy-webprint ex\ewpexbho.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
    BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
    BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    TB: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\tbVuze.dll
    TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
    TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
    TB: Canon Easy-WebPrint EX: {759d9886-0c6f-4498-bab6-4a5f47c6c72f} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll
    {e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
    EB: Canon Easy-WebPrint EX: {21347690-ec41-4f9a-8887-1f4aee672439} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll
    uRun: [<NO NAME>]
    mRun: [fssui] "c:\program files\windows live\family safety\fsui.exe" -autorun
    mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe "
    mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
    mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
    mRun: [DT ACR] c:\program files\common files\portrait displays\shared\DT_startup.exe -ACR
    mRun: [Garmin Lifetime Updater] c:\program files\garmin\lifetime updater\GarminLifetime.exe /StartMinimized
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe "
    mRun: [USBToolTip] c:\progra~1\pinnacle\shared~1\programs\usbtip\USBTip.exe
    mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe "
    mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
    mRun: [PivotSoftware] "c:\program files\portrait displays\pivot pro plugin\Pivot_startup.exe" -delay=10
    mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4\OpwareSE4.exe "
    mRun: [NSU_agent] "c:\program files\nokia\nokia software updater\nsu3ui_agent.exe "
    mRun: [DocCreatorClient] "c:\program files\global graphics\gdoc\DocCreatorClient.exe "
    mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
    mRun: [CanonSolutionMenuEx] c:\program files\canon\solution menu ex\CNSEMAIN.EXE /logon
    mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
    mRun: [EvtMgr6] c:\program files\logitech\setpointp\SetPoint.exe /launchGaming
    StartupFolder: c:\users\sean\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office14\ONENOTEM.EXE
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\SANDIS~1.LNK -
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\stk02h~1.lnk - c:\windows\stk02h\STK02HM.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\stk02n~1.lnk - c:\windows\stk02n\STK02NM.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\wddmst~1.lnk - c:\program files\western digital\wd smartware\wd drive manager\WDDMStatus.exe
    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
    IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
    DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/4.0.1.0/GarminAxControl_32.CAB
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
    DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.5.0.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: DhcpNameServer = 192.168.1.254
    TCP: Interfaces\{1B020E4F-2E7C-4BD9-96F8-639E8CA84316} : DhcpNameServer = 192.168.1.254
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
    Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
    Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
    SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\users\sean\appdata\roaming\mozilla\firefox\profiles\7yn18sj5.default\
    FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4b8e473b&v=6.103.018.001&i=23&tp=ab&iy=&ychte=au&lng=en-GB&q=
    FF - prefs.js: network.proxy.type - 0
    FF - plugin: c:\progra~1\micros~2\office14\NPAUTHZ.DLL
    FF - plugin: c:\progra~1\micros~2\office14\NPSPWRAP.DLL
    FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
    FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
    FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
    FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
    FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
    FF - plugin: c:\program files\logitech\harmony remote driver\NprtHarmonyPlugin.dll
    FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
    FF - plugin: c:\program files\microsoft\office live\npOLW.dll
    FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
    FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
    FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
    FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-7-11 23120]
    R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-9-13 32592]
    R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-10-7 230608]
    R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-8-8 40016]
    R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-7-11 295248]
    R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2009-11-11 12880]
    R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-11-11 67664]
    R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCORE.EXE [2011-4-22 116608]
    R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928]
    R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
    R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
    R2 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2012-4-12 39272]
    R2 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2012-3-8 1492840]
    R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-8-13 2255464]
    R2 PdiService;Portrait Displays SDK Service;c:\program files\common files\portrait displays\drivers\pdisrvc.exe [2012-2-2 109168]
    R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2011-8-3 379496]
    R2 UltraMonUtility;UltraMon Utility Driver;c:\program files\common files\realtime soft\ultramonmirrordrv\x32\UltraMonUtility.sys [2008-11-14 17184]
    R2 WDDMService;WDDMService;c:\program files\western digital\wd smartware\wd drive manager\WDDMService.exe [2011-3-9 238592]
    R2 WDFME;WD File Management Engine;c:\program files\western digital\wd smartware\front parlor\wdfme\WDFME.exe [2011-3-9 1060864]
    R2 WDSC;WD File Management Shadow Engine;c:\program files\western digital\wd smartware\front parlor\WDSC.exe [2011-3-9 484352]
    R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-7-11 134736]
    R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-7-11 24272]
    R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-10-4 16720]
    R3 DCMessages;DCMessages;c:\windows\system32\DCMessages.exe [2010-6-15 87432]
    R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2011-8-14 139368]
    R3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
    R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-3-1 139776]
    R3 Sony PC Companion;Sony PC Companion;c:\program files\sony\sony pc companion\PCCService.exe [2012-2-12 155320]
    R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2009-2-13 11520]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-12-24 136176]
    S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-2-29 158856]
    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-13 257696]
    S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
    S3 CTL511Plus;Video Blaster WebCam 3/WebCam Plus (WDM);c:\windows\system32\drivers\webc3vid.sys [2001-11-7 166504]
    S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [2012-4-20 23456]
    S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [2011-2-19 198656]
    S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2012-2-12 13224]
    S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-12-24 136176]
    S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\drivers\ivusb.sys [2010-3-10 25112]
    S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2011-11-1 137600]
    S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2011-11-1 8576]
    S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-11-11 12872]
    S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-4-15 52224]
    S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-3-5 1343400]
    S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
    .
    =============== Created Last 30 ================
    .
    2012-05-22 20:21:15 -------- d-----w- c:\users\sean\appdata\local\{245CDA0B-1636-4164-B450-53D27956BADC}
    2012-05-22 07:52:50 -------- d-----w- c:\users\sean\appdata\local\{8648A399-71EE-4EC7-8808-FC67F40CFBF7}
    2012-05-21 08:24:18 -------- d-----w- c:\users\sean\appdata\local\Sony
    2012-05-21 05:57:29 -------- d-----w- c:\users\sean\appdata\local\{EB642816-08AB-4D32-BA52-691B6CAB3ACB}
    2012-05-21 05:57:17 -------- d-----w- c:\users\sean\appdata\local\{185D03B8-96C5-4BE2-BF03-B6EE6F138F76}
    2012-05-19 23:42:04 -------- d-----w- c:\program files\MALWAREBYTES ANTI-MALWARE
    2012-05-19 22:53:55 -------- d-----w- c:\users\sean\appdata\local\{057EE8EC-3FD1-4492-88A3-2B076E473EF3}
    2012-05-19 09:10:03 -------- d-----w- c:\users\sean\appdata\local\{163AA453-A275-440E-9A9A-1E53A5BD51E8}
    2012-05-18 21:09:33 -------- d-----w- c:\users\sean\appdata\local\{C9F4F167-3307-4FAB-AAC0-76654F92C658}
    2012-05-18 08:23:47 -------- d-----w- c:\users\sean\appdata\local\{587B9F84-DC26-4A1F-B3E9-B9844BB33E89}
    2012-05-18 08:23:34 -------- d-----w- c:\users\sean\appdata\local\{AFC208FD-CBC2-43D0-BA4B-CE72A8C8DA22}
    2012-05-17 09:51:27 936960 ----a-w- c:\program files\common files\microsoft shared\ink\journal.dll
    2012-05-17 09:51:24 1291632 ----a-w- c:\windows\system32\drivers\tcpip.sys
    2012-05-17 09:51:19 3968368 ----a-w- c:\windows\system32\ntkrnlpa.exe
    2012-05-17 09:51:19 3913072 ----a-w- c:\windows\system32\ntoskrnl.exe
    2012-05-17 09:51:18 2343424 ----a-w- c:\windows\system32\win32k.sys
    2012-05-17 09:49:10 56176 ----a-w- c:\windows\system32\drivers\partmgr.sys
    2012-05-17 09:49:08 1077248 ----a-w- c:\windows\system32\DWrite.dll
    2012-05-17 09:22:37 -------- d-----w- c:\users\sean\appdata\local\{6884FA74-EDC9-4C1E-98C3-F380C13DA16C}
    2012-05-16 08:32:05 -------- d-----w- c:\users\sean\appdata\local\{8D24B59D-F475-41E2-A8F9-191E021C98C7}
    2012-05-15 20:30:05 -------- d-----w- c:\users\sean\appdata\local\{BCDD33E4-7FF6-49EB-8975-4A0237EDAC54}
    2012-05-15 08:14:44 -------- d-----w- c:\users\sean\appdata\local\{3774B5CA-77EB-49DC-854A-28D81C0F7192}
    2012-05-14 20:14:10 -------- d-----w- c:\users\sean\appdata\local\{A34E2E2B-AD65-479A-98E1-01BE84D6B4F0}
    2012-05-14 08:13:33 -------- d-----w- c:\users\sean\appdata\local\{B6637F0E-FA5C-4B16-A539-43E78DB89C1B}
    2012-05-13 20:13:02 -------- d-----w- c:\users\sean\appdata\local\{6719270B-CD32-4820-A01B-9B7CE9C7EEF0}
    2012-05-13 08:12:25 -------- d-----w- c:\users\sean\appdata\local\{A2E08C80-3AE1-4221-AB3A-EF47E45D39B5}
    2012-05-12 20:11:51 -------- d-----w- c:\users\sean\appdata\local\{CCEDAEF2-A4D0-4955-AE1B-66281FEB3341}
    2012-05-11 20:23:00 -------- d-----w- c:\users\sean\appdata\local\{021333D7-BD3D-47B6-9D50-056251643F11}
    2012-05-11 08:22:29 -------- d-----w- c:\users\sean\appdata\local\{1757C076-317E-47CC-A2F4-2C22C332DC87}
    2012-05-10 20:21:58 -------- d-----w- c:\users\sean\appdata\local\{6239CFEA-4456-4F58-99BE-4611F024E524}
    2012-05-10 08:21:28 -------- d-----w- c:\users\sean\appdata\local\{B728A172-E001-4500-998C-05C38B95C826}
    2012-05-09 20:20:59 -------- d-----w- c:\users\sean\appdata\local\{56A9A498-C5E9-4F0E-B544-CB2A70CCD34B}
    2012-05-09 08:20:32 -------- d-----w- c:\users\sean\appdata\local\{89AF3F02-C84F-45A5-84FA-D4287CAD2D57}
    2012-05-08 20:20:02 -------- d-----w- c:\users\sean\appdata\local\{5C78E62F-DDF1-4559-AB50-B537BBD1CDEC}
    2012-05-08 08:19:28 -------- d-----w- c:\users\sean\appdata\local\{0192CFDB-1EA9-4A26-8214-916A07FDA584}
    2012-05-07 20:18:54 -------- d-----w- c:\users\sean\appdata\local\{13A77478-82E8-4142-8A48-0F4E40CD6AFE}
    2012-05-07 08:18:17 -------- d-----w- c:\users\sean\appdata\local\{4023421B-F81B-4231-A587-3E4D0C763359}
    2012-05-06 20:17:41 -------- d-----w- c:\users\sean\appdata\local\{DBE9326A-F129-4EED-82AD-7308F88125A3}
    2012-05-06 08:17:09 -------- d-----w- c:\users\sean\appdata\local\{8B43E165-7218-485A-A540-B06EF0A46324}
    2012-05-05 20:16:42 -------- d-----w- c:\users\sean\appdata\local\{28945EE2-3BD4-4652-A64D-EAA2AE9F5F85}
    2012-05-05 08:16:12 -------- d-----w- c:\users\sean\appdata\local\{1F94C4B5-58F1-425B-A47F-3B19F462572F}
    2012-05-04 20:15:40 -------- d-----w- c:\users\sean\appdata\local\{20787EF8-FFE8-471B-AFAC-06A0297BF42A}
    2012-05-04 08:15:11 -------- d-----w- c:\users\sean\appdata\local\{79C6E95C-B8F6-49F9-8AF7-768E583D967A}
    2012-05-03 20:14:44 -------- d-----w- c:\users\sean\appdata\local\{20B7FE4D-050D-4B53-AA57-B7E5B951AC17}
    2012-05-03 08:14:17 -------- d-----w- c:\users\sean\appdata\local\{F4E45433-26A9-4B08-AC75-08A8587B543C}
    2012-05-02 20:13:50 -------- d-----w- c:\users\sean\appdata\local\{9E154B57-7FAB-49F5-ABF4-21DBE96A9601}
    2012-05-02 08:13:24 -------- d-----w- c:\users\sean\appdata\local\{624C252E-897D-4CFC-BA48-F3E68CC69B6D}
    2012-05-01 20:12:10 -------- d-----w- c:\users\sean\appdata\local\{BF3D2BAD-39FC-437C-8CAF-6C32CCB23142}
    2012-05-01 20:11:47 -------- d-----w- c:\users\sean\appdata\local\{E22E0B71-B9EA-475F-95B4-1BDFD40296C4}
    2012-05-01 08:07:40 -------- d-----w- c:\users\sean\appdata\local\{68D99E17-3659-409C-B07C-973F1C8433DF}
    2012-04-30 20:07:08 -------- d-----w- c:\users\sean\appdata\local\{678477EE-766E-4B60-B406-D4C8DFC5B129}
    2012-04-30 08:06:35 -------- d-----w- c:\users\sean\appdata\local\{4485517B-CD4D-4086-B034-4C0945D49A7C}
    2012-04-29 20:06:06 -------- d-----w- c:\users\sean\appdata\local\{FEF33B1C-1C77-4878-8EC3-219FEC27AE41}
    2012-04-29 08:04:55 -------- d-----w- c:\users\sean\appdata\local\{B7172D2A-CCD0-4704-9AC5-D18B1A0A6810}
    2012-04-28 20:03:53 -------- d-----w- c:\users\sean\appdata\local\{26C21210-F743-4070-9103-1B7A6C701C32}
    2012-04-28 08:03:26 -------- d-----w- c:\users\sean\appdata\local\{B4A6E34E-302F-4FB5-BDF8-04B2B5FB9E8C}
    2012-04-27 20:02:58 -------- d-----w- c:\users\sean\appdata\local\{A0CE1DD8-6499-45F7-B863-163E0D619DC8}
    2012-04-27 08:02:27 -------- d-----w- c:\users\sean\appdata\local\{3FA354AB-854D-4F08-B273-59FE744B2345}
    2012-04-26 20:02:01 -------- d-----w- c:\users\sean\appdata\local\{DDCE0DF5-D8FF-48E5-BB03-F3595F06323A}
    2012-04-26 08:01:30 -------- d-----w- c:\users\sean\appdata\local\{16B6BDA6-A183-4AEA-B96A-C6217091F03F}
    2012-04-25 20:01:02 -------- d-----w- c:\users\sean\appdata\local\{6DA25253-4C71-41BF-BD89-C9466753802A}
    2012-04-25 08:00:35 -------- d-----w- c:\users\sean\appdata\local\{6F7D3616-F450-45BF-83C2-CBC3ABEA2AF8}
    2012-04-25 08:00:23 -------- d-----w- c:\users\sean\appdata\local\{5A563442-5551-4E65-BBA0-8B7E6EADDB2B}
    2012-04-24 21:52:10 -------- d-----w- c:\users\sean\appdata\roaming\AVG
    2012-04-24 19:59:55 -------- d-----w- c:\users\sean\appdata\local\{69D816C8-BC0A-461E-8522-5F751EBEC5CB}
    .
    ==================== Find3M ====================
    .
    2012-05-05 04:07:18 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2012-05-05 04:07:18 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
    2012-04-20 21:01:48 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
    2012-04-20 08:48:04 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
    2012-04-04 05:56:40 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-03-22 19:12:12 4435968 ----a-w- c:\windows\system32\GPhotos.scr
    2012-03-08 08:50:28 49016 ----a-w- c:\windows\system32\sirenacm.dll
    2012-03-08 08:37:20 302448 ----a-w- c:\windows\WLXPGSS.SCR
    2012-03-08 08:32:24 39272 ----a-w- c:\windows\system32\drivers\fssfltr.sys
    2012-03-01 05:46:57 19824 ----a-w- c:\windows\system32\drivers\fs_rec.sys
    2012-03-01 05:37:41 172544 ----a-w- c:\windows\system32\wintrust.dll
    2012-03-01 05:33:23 159232 ----a-w- c:\windows\system32\imagehlp.dll
    2012-03-01 05:29:16 5120 ----a-w- c:\windows\system32\wmi.dll
    2012-02-29 12:07:17 32256 ----a-w- c:\windows\system32\ntrights.exe
    2012-02-28 01:18:55 1799168 ----a-w- c:\windows\system32\jscript9.dll
    2012-02-28 01:11:21 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
    2012-02-28 01:11:07 1127424 ----a-w- c:\windows\system32\wininet.dll
    2012-02-28 01:03:16 2382848 ----a-w- c:\windows\system32\mshtml.tlb
    .
    ============= FINISH: 17:34:46.14 ===============
     
  10. 2012/05/24
    jayman34

    jayman34 Inactive Thread Starter

    Joined:
    2009/02/25
    Messages:
    65
    Likes Received:
    0
    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-08-26.01)
    .
    Microsoft Windows 7 Home Premium
    Boot Device: \Device\HarddiskVolume1
    Install Date: 03/03/2010 6:21:26 PM
    System Uptime: 23/05/2012 3:17:28 AM (38 hours ago)
    .
    Motherboard: Gigabyte Technology Co., Ltd. | | EP45-UD3R
    Processor: Intel(R) Core(TM)2 Quad CPU Q8200 @ 2.33GHz | Socket 775 | 2333/333mhz
    .
    ==== Disk Partitions =========================
    .
    A: is Removable
    C: is FIXED (NTFS) - 153 GiB total, 7.947 GiB free.
    D: is FIXED (NTFS) - 190 GiB total, 5.641 GiB free.
    E: is CDROM (UDF)
    F: is CDROM ()
    X: is FIXED (NTFS) - 932 GiB total, 0.139 GiB free.
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    RP807: 24/05/2012 - Scheduled Checkpoint
    .
    ==== Installed Programs ======================
    .
    .
    Update for Microsoft Office 2007 (KB2508958)
    AC3Filter (remove only)
    Acer eDisplay Management
    Acrobat.com
    Adobe AIR
    Adobe Flash Player 11 ActiveX
    Adobe Flash Player 11 Plugin
    Adobe Reader X (10.1.3)
    Aide PDF to DXF Converter 9.6
    µTorrent
    AVG 2012
    AVG PC Tuneup
    Avidemux 2.5
    AVL680HD Driver
    Canon Easy-PhotoPrint EX
    Canon Easy-WebPrint EX
    Canon Inkjet Printer/Scanner/Fax Extended Survey Program
    Canon MP Navigator EX 4.1
    Canon MX880 series MP Drivers
    Canon My Printer
    Canon Solution Menu EX
    Canon Speed Dial Utility
    Canon Utilities Solution Menu
    CD-LabelPrint
    Conduit Engine
    Creative Video Blaster WebCam 3 USB/WebCam Plus Driver
    D3DX10
    Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
    DivX Setup
    doPDF 7.2 printer
    DraftSight
    DriverAgent by eSupport.com
    DVD Flick 1.3.0.7
    DVD Shrink 3.2
    e-tax 2011
    Easy Blue Print
    eReg
    Garmin City Navigator Australia & New Zealand NT 2011.30 Update
    Garmin City Navigator Australia And New Zealand NT 2011.20 Update
    Garmin Communicator Plugin
    Garmin Lifetime Updater
    Garmin POI Loader
    Garmin USB Drivers
    gDoc
    gDoc Installer
    gDocExcel2007AddIn
    gDocPowerPoint2007AddIn
    gDocWord2007AddIn
    Google Earth
    Google SketchUp 8
    Google Update Helper
    HijackThis 2.0.2
    ImgBurn
    inSSIDer 2.0
    Java Auto Updater
    Java(TM) 6 Update 30
    Junk Mail filter update
    Knoll Light Factory EZ Studio
    Korean Fonts Support For Adobe Reader 9
    Logitech Harmony Remote Software
    Logitech Harmony Remote Software 7
    Logitech SetPoint 6.32
    Magic Bullet Looks Studio
    Malwarebytes Anti-Malware version 1.61.0.1400
    Mesh Runtime
    Messenger Companion
    Microsoft .NET Framework 4 Client Profile
    Microsoft Application Error Reporting
    Microsoft Office 2007 Service Pack 3 (SP3)
    Microsoft Office 2010 Service Pack 1 (SP1)
    Microsoft Office Access MUI (English) 2010
    Microsoft Office Access Setup Metadata MUI (English) 2010
    Microsoft Office Excel MUI (English) 2010
    Microsoft Office File Validation Add-In
    Microsoft Office Live Add-in 1.5
    Microsoft Office OneNote MUI (English) 2010
    Microsoft Office Outlook MUI (English) 2010
    Microsoft Office PowerPoint MUI (English) 2010
    Microsoft Office Professional 2010
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (English) 2010
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (French) 2010
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proof (Spanish) 2010
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing (English) 2010
    Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    Microsoft Office Publisher MUI (English) 2010
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared MUI (English) 2010
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2010
    Microsoft Office SharePoint Designer 2007
    Microsoft Office SharePoint Designer 2007 Service Pack 3 (SP3)
    Microsoft Office SharePoint Designer MUI (English) 2007
    Microsoft Office Single Image 2010
    Microsoft Office Word MUI (English) 2010
    Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
    Microsoft Visual Studio 2005 Tools for Office Runtime
    Microsoft_VC100_CRT_SP1_x86
    MKVToolNix 5.2.1
    Mozilla Firefox 4.0.1 (x86 en-GB)
    MSVC80_x86_v2
    MSVC90_x86
    MSVCRT
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 4.0 SP3 Parser
    MSXML 4.0 SP3 Parser (KB973685)
    Nokia Connectivity Cable Driver
    Nokia PC Suite
    Nokia Software Updater
    Nokia Suite
    NVIDIA 3D Vision Controller Driver
    NVIDIA 3D Vision Controller Driver 280.19
    NVIDIA 3D Vision Driver 280.26
    NVIDIA Control Panel 295.73
    NVIDIA Graphics Driver 280.26
    NVIDIA HD Audio Driver 1.2.23.3
    NVIDIA Install Application
    NVIDIA PhysX
    NVIDIA PhysX System Software 9.10.0514
    NVIDIA Stereoscopic 3D Driver
    NVIDIA Update 1.4.28
    NVIDIA Update Components
    OGA Notifier 2.0.0048.0
    Paint.NET v3.5.10
    PC Connectivity Solution
    PCFriendly
    PDF Download for Internet Explorer
    PeerBlock 1.1 (r518)
    Picasa 3
    Pinnacle Studio 14
    Pinnacle Studio Ultimate Collection Plugins
    Pinnacle Video Driver
    Pivot Pro Plugin
    PlayReady PC Runtime x86
    PowerISO
    proDAD Heroglyph 2.5
    proDAD Mercalli 1.0
    proDAD Vitascene 1.0
    PVSonyDll
    RealNetworks - Microsoft Visual C++ 2008 Runtime
    RealPlayer
    Realtek High Definition Audio Driver
    RealUpgrade 1.1
    Red Giant ToonIt Studio
    Remote Control USB Driver
    SanDisk ® Media Manager
    ScanSoft OmniPage SE 4
    SDK
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
    Security Update for Microsoft Excel 2010 (KB2597166) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596880) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2598041) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2553091)
    Security Update for Microsoft Office 2010 (KB2553096)
    Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2598039) 32-Bit Edition
    Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition
    Security Update for Microsoft Visio Viewer 2010 (KB2597981) 32-Bit Edition
    Skype™ 5.8
    Sony Ericsson Update Engine
    Sony PC Companion 2.10.053
    SoundSoap PE
    STK02H 2.3
    STK02N 2.4
    Studio 11 Bonus DVD
    Studio 11 Ultimate
    Super Finder XT 1.6.3.2
    SUPERAntiSpyware Free Edition
    SureThing Express Labeler
    System Requirements Lab
    System Requirements Lab for Intel
    Trapcode 3DStroke Studio
    Trapcode Particular Studio
    Trapcode Shine Studio
    UltraMon
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office 2010 (KB2494150)
    Update for Microsoft Office 2010 (KB2553065)
    Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553385) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2566458)
    Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2597091) 32-Bit Edition
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Sharepoint Designer 2007 Help (KB963675)
    Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
    Update for Microsoft OneNote 2010 (KB2589345) 32-Bit Edition
    Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition
    Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
    uTorrentBar Toolbar
    VC80CRTRedist - 8.0.50727.4053
    Virgin Mobile
    Visual Studio 2005 Tools for Office Second Edition Runtime
    VLC media player 2.0.1
    Vuze
    Vuze_Remote Toolbar
    WD SmartWare
    WebCam Monitor
    Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
    Windows Driver Package - Nokia Modem (06/09/2010 7.01.0.8)
    Windows Driver Package - Nokia Modem (10/07/2010 4.6)
    Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Family Safety
    Windows Live ID Sign-in Assistant
    Windows Live Installer
    Windows Live Mail
    Windows Live Mesh
    Windows Live Mesh ActiveX Control for Remote Connections
    Windows Live Messenger
    Windows Live Messenger Companion Core
    Windows Live MIME IFilter
    Windows Live Movie Maker
    Windows Live Photo Common
    Windows Live Photo Gallery
    Windows Live PIMT Platform
    Windows Live Remote Client
    Windows Live Remote Client Resources
    Windows Live Remote Service
    Windows Live Remote Service Resources
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live Sync
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    Windows Live Writer
    Windows Live Writer Resources
    WinRAR 4.01 (32-bit)
    WinZip 11.1
    .
    ==== Event Viewer Messages From Past Week ========
    .
    23/05/2012 9:57:52 PM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
    22/05/2012 5:51:46 PM, Error: Service Control Manager [7034] - The Google Update Service (gupdate) service terminated unexpectedly. It has done this 1 time(s).
    20/05/2012 6:48:36 PM, Error: Microsoft-Windows-HAL [12] - The platform firmware has corrupted memory across the previous system power transition. Please check for updated firmware for your system.
    20/05/2012 6:11:07 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000019 (0x00000003, 0x83589818, 0x0050e0c2, 0x83589818). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 052012-56799-01.
    20/05/2012 3:57:39 PM, Error: Ntfs [137] - The default transaction resource manager on volume H: encountered a non-retryable error and could not start. The data contains the error code.
    20/05/2012 12:38:04 PM, Error: Microsoft-Windows-Application-Experience [205] - The Program Compatibility Assistant service failed to perform the phase two initialization.
    20/05/2012 12:36:12 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000019 (0x00000003, 0x8357c840, 0x8357c840, 0x0157c840). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 052012-38126-01.
    20/05/2012 11:32:35 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000019 (0x00000003, 0x85b3ea40, 0x00030030, 0x85b3ea40). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 052012-41028-01.
    19/05/2012 7:12:27 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user SD-PC\Sean SID (S-1-5-21-759393751-1481746019-3899478243-1001) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    19/05/2012 3:27:39 PM, Error: Microsoft-Windows-WMPNSS-Service [14365] - Proximity detection failed due to unknown error '0x80004004'. The best proximity time detected was -1 milliseconds.
    19/05/2012 11:33:40 AM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk3\DR3.
    19/05/2012 11:07:30 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Error Reporting Service service to connect.
    .
    ==== End Of File ===========================
     
  11. 2012/05/24
    jayman34

    jayman34 Inactive Thread Starter

    Joined:
    2009/02/25
    Messages:
    65
    Likes Received:
    0
    I have completed and attached all logs as requested

    Thanks for taking the time to look
     
  12. 2012/05/24
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I still need GMER log.
     
  13. 2012/05/25
    jayman34

    jayman34 Inactive Thread Starter

    Joined:
    2009/02/25
    Messages:
    65
    Likes Received:
    0
    Hi Broni

    You said to skip GMER as it keeps casusing blue screen of death, see previous comments above #1 & #4, and it doesn't complete anyway?

    Any suggestions

    Thanks again for your time
     
    Last edited: 2012/05/25
  14. 2012/05/25
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Oooops...sorry about it :)

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Never rename Combofix unless instructed.
    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    • Double click on combofix.exe & follow the prompts.

    • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results ". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion ", restart computer to fix the issue.
    **Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.
    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.
    Vista and Win7 users need to right click Rkill and choose Run as Administrator
    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    * Rkill.com
    * Rkill.scr
    * Rkill.exe
    • Double-click on the Rkill icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.
    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  15. 2012/05/25
    jayman34

    jayman34 Inactive Thread Starter

    Joined:
    2009/02/25
    Messages:
    65
    Likes Received:
    0
    combofix report

    ComboFix 12-05-25.03 - Sean 26/05/2012 9:22.2.4 - x86
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.61.1033.18.3070.1760 [GMT 10:00]
    Running from: c:\users\Sean\Desktop\ComboFix.exe
    AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
    SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    * Created a new restore point
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    ---- Previous Run -------
    .
    c:\users\Holly.SD-PC\AppData\Local\assembly\tmp
    c:\users\Sean\AppData\Local\assembly\tmp
    c:\users\Wendy.SD-PC\AppData\Local\assembly\tmp
    c:\windows\system32\AF15BDAEX.dll
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-04-25 to 2012-05-25 )))))))))))))))))))))))))))))))
    .
    .
    2012-05-25 23:35 . 2012-05-25 23:35 -------- d-----w- c:\users\Wendy.SD-PC\AppData\Local\temp
    2012-05-25 23:35 . 2012-05-25 23:35 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
    2012-05-25 23:35 . 2012-05-25 23:35 -------- d-----w- c:\users\Holly.SD-PC\AppData\Local\temp
    2012-05-25 23:35 . 2012-05-25 23:35 -------- d-----w- c:\users\Default\AppData\Local\temp
    2012-05-25 23:35 . 2012-05-25 23:35 -------- d-----w- c:\users\Beyonwiz\AppData\Local\temp
    2012-05-21 08:24 . 2012-05-21 08:24 -------- d-----w- c:\users\Sean\AppData\Local\Sony
    2012-05-19 23:42 . 2012-05-23 12:09 -------- d-----w- c:\program files\MALWAREBYTES ANTI-MALWARE
    2012-05-17 09:51 . 2012-03-31 04:29 936960 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
    2012-05-17 09:51 . 2012-03-30 10:23 1291632 ----a-w- c:\windows\system32\drivers\tcpip.sys
    2012-05-17 09:51 . 2012-03-31 04:39 3968368 ----a-w- c:\windows\system32\ntkrnlpa.exe
    2012-05-17 09:51 . 2012-03-31 04:39 3913072 ----a-w- c:\windows\system32\ntoskrnl.exe
    2012-05-17 09:51 . 2012-03-31 02:36 2343424 ----a-w- c:\windows\system32\win32k.sys
    2012-05-17 09:49 . 2012-03-17 07:27 56176 ----a-w- c:\windows\system32\drivers\partmgr.sys
    2012-05-17 09:49 . 2012-03-03 05:31 1077248 ----a-w- c:\windows\system32\DWrite.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-05-05 04:07 . 2012-04-12 23:35 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
    2012-05-05 04:07 . 2011-07-15 08:21 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2012-04-20 21:03 . 2012-04-20 21:03 53248 ----a-r- c:\users\Sean\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
    2012-04-20 21:01 . 2010-08-19 12:15 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
    2012-04-20 08:48 . 2012-04-20 08:48 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
    2012-04-04 05:56 . 2010-03-13 23:02 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-03-22 19:12 . 2012-03-22 19:12 4435968 ----a-w- c:\windows\system32\GPhotos.scr
    2012-03-08 08:50 . 2012-03-08 08:50 49016 ----a-w- c:\windows\system32\sirenacm.dll
    2012-03-08 08:37 . 2012-03-08 08:37 302448 ----a-w- c:\windows\WLXPGSS.SCR
    2012-03-08 08:32 . 2012-04-12 08:34 39272 ----a-w- c:\windows\system32\drivers\fssfltr.sys
    2012-03-01 05:46 . 2012-04-12 08:32 19824 ----a-w- c:\windows\system32\drivers\fs_rec.sys
    2012-03-01 05:37 . 2012-04-12 08:32 172544 ----a-w- c:\windows\system32\wintrust.dll
    2012-03-01 05:33 . 2012-04-12 08:32 159232 ----a-w- c:\windows\system32\imagehlp.dll
    2012-03-01 05:29 . 2012-04-12 08:32 5120 ----a-w- c:\windows\system32\wmi.dll
    2012-02-29 12:07 . 2012-02-29 12:10 32256 ----a-w- c:\windows\system32\ntrights.exe
    2012-02-28 01:18 . 2012-04-12 08:50 1799168 ----a-w- c:\windows\system32\jscript9.dll
    2012-02-28 01:11 . 2012-04-12 08:50 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
    2012-02-28 01:11 . 2012-04-12 08:50 1127424 ----a-w- c:\windows\system32\wininet.dll
    2012-02-28 01:03 . 2012-04-12 08:50 2382848 ----a-w- c:\windows\system32\mshtml.tlb
    2011-05-15 08:33 . 2011-04-07 02:35 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{ba14329e-9550-4989-b3f2-9732e92d17cc} "= "c:\program files\Vuze_Remote\tbVuze.dll" [2010-05-20 2675296]
    "{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} "= "c:\program files\uTorrentBar\tbuTor.dll" [2010-12-09 3911776]
    "{30F9B915-B755-4826-820B-08FBA6BD249D} "= "c:\program files\ConduitEngine\ConduitEngine.dll" [2010-12-09 3911776]
    .
    [HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
    .
    [HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
    .
    [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
    .
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{BA14329E-9550-4989-B3F2-9732E92D17CC} "= "c:\program files\Vuze_Remote\tbVuze.dll" [2010-05-20 2675296]
    .
    [HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "fssui "= "c:\program files\Windows Live\Family Safety\fsui.exe" [2012-03-08 884584]
    "AVG_TRAY "= "c:\program files\AVG\AVG2012\avgtray.exe" [2012-01-24 2416480]
    "SSBkgdUpdate "= "c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-24 210472]
    "CanonSolutionMenu "= "c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
    "DT ACR "= "c:\program files\Common Files\Portrait Displays\Shared\DT_startup.exe" [2010-06-30 121456]
    "Garmin Lifetime Updater "= "c:\program files\Garmin\Lifetime Updater\GarminLifetime.exe" [2012-01-06 1446760]
    "Adobe ARM "= "c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
    "USBToolTip "= "c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe" [2007-02-20 199752]
    "TkBellExe "= "c:\program files\Real\RealPlayer\Update\realsched.exe" [2011-04-05 273544]
    "SunJavaUpdateSched "= "c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
    "RtHDVCpl "= "c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-01-19 8452640]
    "PivotSoftware "= "c:\program files\Portrait Displays\Pivot Pro Plugin\Pivot_startup.exe" [2010-05-13 110192]
    "OpwareSE4 "= "c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
    "NSU_agent "= "c:\program files\Nokia\Nokia Software Updater\nsu3ui_agent.exe" [2011-12-13 190768]
    "DocCreatorClient "= "c:\program files\Global Graphics\gDoc\DocCreatorClient.exe" [2010-05-19 284056]
    "DivXUpdate "= "c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-16 1164584]
    "CanonSolutionMenuEx "= "c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-09-14 1213848]
    "CanonMyPrinter "= "c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-07-25 2569616]
    "EvtMgr6 "= "c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1387288]
    .
    c:\users\Sean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2011-9-2 227712]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    SanDisk Media Manager.lnk - [N/A]
    STK02H 2.3 PNP Monitor.lnk - c:\windows\STK02H\STK02HM.exe [2011-2-17 163840]
    STK02N 2.4 PNP Monitor.lnk - c:\windows\STK02N\STK02NM.exe [2011-2-17 163840]
    WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2011-3-9 3986944]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin "= 5 (0x5)
    "ConsentPromptBehaviorUser "= 3 (0x3)
    "EnableUIADesktopToggle "= 0 (0x0)
    .
    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} "= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-12-03 113024]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2009-09-03 04:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
    2011-09-27 19:03 66328 ----a-w- c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
    @=" "
    .
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-24 136176]
    R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2012-02-28 158856]
    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 257696]
    R3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [2011-10-11 4433248]
    R3 CTL511Plus;Video Blaster WebCam 3/WebCam Plus (WDM);c:\windows\system32\DRIVERS\webc3vid.sys [2001-11-06 166504]
    R3 DrvAgent32;DrvAgent32;c:\windows\system32\Drivers\DrvAgent32.sys [2012-04-20 23456]
    R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2009-10-21 198656]
    R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2012-02-12 13224]
    R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-24 136176]
    R3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys [2010-03-10 25112]
    R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2011-11-01 137600]
    R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2011-11-01 8576]
    R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2011-04-22 12872]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-05 1343400]
    R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
    S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-10 23120]
    S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2011-09-12 32592]
    S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2011-10-06 230608]
    S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2011-07-10 295248]
    S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-12-03 12880]
    S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2011-12-03 67664]
    S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-12-03 116608]
    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
    S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2011-08-01 192776]
    S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]
    S2 PdiService;Portrait Displays SDK Service;c:\program files\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2010-04-16 109168]
    S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-08-02 379496]
    S2 UltraMonUtility;UltraMon Utility Driver;c:\program files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys [2008-11-13 17184]
    S2 WDDMService;WDDMService;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2011-03-09 238592]
    S2 WDFME;WD File Management Engine;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe [2011-03-09 1060864]
    S2 WDSC;WD File Management Shadow Engine;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe [2011-03-09 484352]
    S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-10 134736]
    S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-10 24272]
    S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\AVGIDSShim.Sys [2011-10-03 16720]
    S3 DCMessages;DCMessages;c:\windows\System32\DCMessages.exe [2010-05-19 87432]
    S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2011-05-10 139368]
    S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776]
    S3 Sony PC Companion;Sony PC Companion;c:\program files\Sony\Sony PC Companion\PCCService.exe [2012-01-18 155320]
    S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2009-02-13 11520]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *NewlyCreated* - ASWMBR
    *Deregistered* - aswMBR
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-05-25 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-12 04:07]
    .
    2012-05-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-12-24 08:38]
    .
    2012-05-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-12-24 08:38]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://au.yahoo.com/
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    TCP: DhcpNameServer = 192.168.1.254
    DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/4.0.1.0/GarminAxControl_32.CAB
    FF - ProfilePath - c:\users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\7yn18sj5.default\
    FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4b8e473b&v=6.103.018.001&i=23&tp=ab&iy=&ychte=au&lng=en-GB&q=
    FF - prefs.js: network.proxy.type - 0
    .
    - - - - ORPHANS REMOVED - - - -
    .
    WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
    AddRemove-WebCam Plus - c:\windows\ctdrvins.exe -uninstall usb\vid_05a9&pid_0511 -plugin webc3pin.dll
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial "=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial "=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    Completion time: 2012-05-26 09:36:49
    ComboFix-quarantined-files.txt 2012-05-25 23:36
    .
    Pre-Run: 12,022,202,368 bytes free
    Post-Run: 11,816,218,624 bytes free
    .
    - - End Of File - - C93D5C1B086D71D5D1CA0C5F09CEF81C
     
  16. 2012/05/25
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Looks good.

    How is computer doing?

    You can reinstall AVG now.

    Download OTL to your Desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Under the Custom Scan box paste this in:


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\tasks\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    %systemroot%\system32\config\*.bak2
    %systemroot%\system32\Computers\*.*
    %SystemRoot%\system32\Sound\*.*
    %SystemRoot%\system32\SpecialImg\*.*
    %SystemRoot%\system32\code\*.*
    %SystemRoot%\system32\draft\*.*
    %SystemRoot%\system32\MSSSys\*.*
    %ProgramFiles%\Javascript\*.*
    %systemroot%\pchealth\helpctr\System\*.exe /s
    %systemroot%\Web\*.exe
    %systemroot%\system32\msn\*.*
    %systemroot%\system32\*.tro
    %AppData%\Microsoft\Installer\msupdates\*.*
    %ProgramFiles%\Messenger\*.*
    %systemroot%\system32\systhem32\*.*
    %systemroot%\system\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    /md5stop


    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  17. 2012/05/26
    jayman34

    jayman34 Inactive Thread Starter

    Joined:
    2009/02/25
    Messages:
    65
    Likes Received:
    0
    OTL logfile created on: 27/05/2012 7:34:20 AM - Run 1
    OTL by OldTimer - Version 3.2.43.1 Folder = C:\Users\Sean\Desktop
    Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: dd/MM/yyyy

    3.00 Gb Total Physical Memory | 1.96 Gb Available Physical Memory | 65.50% Memory free
    6.06 Gb Paging File | 4.04 Gb Available in Paging File | 66.63% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 152.66 Gb Total Space | 10.39 Gb Free Space | 6.80% Space Free | Partition Type: NTFS
    Drive D: | 189.91 Gb Total Space | 5.64 Gb Free Space | 2.97% Space Free | Partition Type: NTFS
    Drive E: | 665.70 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
    Drive X: | 931.51 Gb Total Space | 0.14 Gb Free Space | 0.01% Space Free | Partition Type: NTFS

    Computer Name: SD-PC | User Name: Sean | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2012/05/27 07:13:05 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Sean\Desktop\OTL.exe
    PRC - [2012/02/10 13:02:07 | 000,857,408 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
    PRC - [2012/01/24 17:24:26 | 002,416,480 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe
    PRC - [2012/01/18 14:38:28 | 000,155,320 | ---- | M] (Avanquest Software) -- C:\Program Files\Sony\Sony PC Companion\PCCService.exe
    PRC - [2012/01/06 16:30:00 | 001,446,760 | ---- | M] (Garmin) -- C:\Program Files\Garmin\Lifetime Updater\GarminLifetime.exe
    PRC - [2012/01/03 23:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
    PRC - [2011/12/03 16:38:00 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
    PRC - [2011/11/28 01:19:04 | 001,229,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe
    PRC - [2011/10/12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
    PRC - [2011/10/10 06:23:34 | 000,973,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgemcx.exe
    PRC - [2011/09/08 20:53:26 | 000,743,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe
    PRC - [2011/09/02 01:15:40 | 000,227,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
    PRC - [2011/08/15 06:21:40 | 000,337,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe
    PRC - [2011/08/03 21:50:00 | 002,255,464 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
    PRC - [2011/08/03 03:31:42 | 000,379,496 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    PRC - [2011/08/02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe
    PRC - [2011/04/05 10:33:09 | 000,273,544 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe
    PRC - [2011/03/09 11:18:06 | 001,060,864 | ---- | M] () -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe
    PRC - [2011/03/09 11:16:56 | 000,484,352 | ---- | M] () -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe
    PRC - [2011/03/09 11:09:54 | 003,986,944 | ---- | M] (Western Digital Technologies, Inc.) -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
    PRC - [2011/03/09 11:07:54 | 000,238,592 | ---- | M] (WDC) -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
    PRC - [2011/02/25 15:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
    PRC - [2011/01/20 13:04:14 | 000,370,688 | -H-- | M] (SanDisk Corporation) -- C:\Program Files\SanDisk\SanDisk Media Manager\SanDiskMediaManager-Launcher.EXE
    PRC - [2010/11/20 22:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
    PRC - [2010/09/17 06:04:06 | 001,164,584 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
    PRC - [2010/07/27 10:44:03 | 000,137,680 | ---- | M] () -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe
    PRC - [2010/06/30 16:46:32 | 000,121,456 | ---- | M] () -- C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
    PRC - [2010/05/20 08:48:12 | 000,087,432 | ---- | M] (Global Graphics Software Ltd) -- C:\Windows\System32\DCMessages.exe
    PRC - [2010/05/13 16:34:48 | 000,711,792 | ---- | M] () -- C:\Program Files\Portrait Displays\Pivot Pro Plugin\Floater.exe
    PRC - [2010/05/13 16:34:42 | 000,674,928 | ---- | M] () -- C:\Program Files\Portrait Displays\Pivot Pro Plugin\wpCtrl.exe
    PRC - [2010/04/16 15:34:34 | 000,109,168 | ---- | M] (Portrait Displays, Inc.) -- C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
    PRC - [2007/03/21 18:50:00 | 000,163,840 | ---- | M] (Syntek Ltd.) -- C:\Windows\STK02N\STK02NM.exe
    PRC - [2007/03/21 18:38:00 | 000,163,840 | ---- | M] (Syntek Ltd.) -- C:\Windows\STK02H\STK02HM.exe
    PRC - [2007/02/20 11:07:40 | 000,199,752 | ---- | M] (Pinnacle Systems GmbH) -- C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
    PRC - [2007/02/04 12:02:14 | 000,079,400 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe


    ========== Modules (No Company Name) ==========

    MOD - [2012/05/18 17:56:56 | 000,393,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\8f0cf05d2b1e46a772312143227cb6ed\System.Xml.Linq.ni.dll
    MOD - [2012/05/18 17:56:55 | 001,782,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\a181199f8dec15116e1c2eb4a79ec22b\System.Xaml.ni.dll
    MOD - [2012/05/17 20:10:18 | 018,000,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\142c428042c2dba4d5ac72495142f58c\PresentationFramework.ni.dll
    MOD - [2012/05/17 20:10:00 | 011,451,904 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\5c18a8cca40f5abb3617826e529a4be9\PresentationCore.ni.dll
    MOD - [2012/05/17 20:09:45 | 003,858,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\dac2093a24d7582eaee5ebd24ba1d06a\WindowsBase.ni.dll
    MOD - [2012/05/17 20:09:43 | 000,595,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\3263fe38362543170c1682381eeac25a\PresentationFramework.Aero.ni.dll
    MOD - [2012/05/17 20:04:09 | 013,197,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\71109720564155295fbaaff1202a33c0\System.Windows.Forms.ni.dll
    MOD - [2012/05/17 20:03:54 | 001,665,536 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\5be779e4d55a04c3b86644505facbe9a\System.Drawing.ni.dll
    MOD - [2012/05/17 20:03:50 | 007,069,184 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\3e4f9b3b78f0f13b7469a14e69d756ef\System.Core.ni.dll
    MOD - [2012/05/17 20:03:46 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\bd2433e160ce2f19acc8ebe10babae8d\System.Xml.ni.dll
    MOD - [2012/05/17 20:03:42 | 000,736,768 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Security\4278bedb3086448c94c1e7f563325052\System.Security.ni.dll
    MOD - [2012/05/17 20:03:40 | 009,091,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\9cf67ed1b743fbc3dd6b78fbc0595236\System.ni.dll
    MOD - [2012/05/17 20:03:32 | 014,413,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\1bdf7de454340e0ea9fc455aeaec49d9\mscorlib.ni.dll
    MOD - [2010/09/17 06:04:50 | 000,095,528 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
    MOD - [2010/09/17 06:04:06 | 001,164,584 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
    MOD - [2010/05/13 16:34:48 | 000,711,792 | ---- | M] () -- C:\Program Files\Portrait Displays\Pivot Pro Plugin\Floater.exe
    MOD - [2010/05/13 16:34:42 | 000,674,928 | ---- | M] () -- C:\Program Files\Portrait Displays\Pivot Pro Plugin\wpCtrl.exe


    ========== Win32 Services (SafeList) ==========

    SRV - [2012/05/05 14:07:18 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
    SRV - [2012/02/29 08:50:48 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
    SRV - [2012/01/18 14:38:28 | 000,155,320 | ---- | M] (Avanquest Software) [On_Demand | Running] -- C:\Program Files\Sony\Sony PC Companion\PCCService.exe -- (Sony PC Companion)
    SRV - [2012/01/04 13:32:36 | 000,718,888 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
    SRV - [2012/01/03 23:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
    SRV - [2011/12/03 16:38:00 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE -- (!SASCORE)
    SRV - [2011/10/12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
    SRV - [2011/09/28 05:03:28 | 000,295,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
    SRV - [2011/08/03 21:50:00 | 002,255,464 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
    SRV - [2011/08/03 03:31:42 | 000,379,496 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
    SRV - [2011/08/02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
    SRV - [2011/03/09 11:18:06 | 001,060,864 | ---- | M] () [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe -- (WDFME)
    SRV - [2011/03/09 11:16:56 | 000,484,352 | ---- | M] () [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe -- (WDSC)
    SRV - [2011/03/09 11:07:54 | 000,238,592 | ---- | M] (WDC) [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe -- (WDDMService)
    SRV - [2010/07/27 10:44:03 | 000,137,680 | ---- | M] () [Auto | Running] -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)
    SRV - [2010/06/30 16:46:32 | 000,121,456 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe -- (DTSRVC)
    SRV - [2010/05/20 08:48:12 | 000,087,432 | ---- | M] (Global Graphics Software Ltd) [On_Demand | Running] -- C:\Windows\System32\DCMessages.exe -- (DCMessages)
    SRV - [2010/04/16 15:34:34 | 000,109,168 | ---- | M] (Portrait Displays, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe -- (PdiService)
    SRV - [2010/03/05 18:29:26 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
    SRV - [2009/07/14 11:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
    SRV - [2009/07/14 11:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)


    ========== Driver Services (SafeList) ==========

    DRV - File not found [Kernel | On_Demand | Unknown] -- C:\ComboFix\mbr.sys -- (mbr)
    DRV - File not found [Kernel | On_Demand | Unknown] -- C:\Users\Sean\AppData\Local\Temp\catchme.sys -- (catchme)
    DRV - File not found [Kernel | On_Demand | Unknown] -- C:\Users\Sean\AppData\Local\Temp\aswMBR.sys -- (aswMBR)
    DRV - [2012/04/20 18:48:04 | 000,023,456 | ---- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\DrvAgent32.sys -- (DrvAgent32)
    DRV - [2012/02/12 15:32:32 | 000,025,512 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggsemc.sys -- (ggsemc)
    DRV - [2012/02/12 15:32:32 | 000,013,224 | ---- | M] (Sony Ericsson Mobile Communications) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ggflt.sys -- (ggflt)
    DRV - [2012/02/09 22:43:00 | 010,816,832 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
    DRV - [2011/12/03 16:37:42 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
    DRV - [2011/12/03 16:37:41 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV)
    DRV - [2011/11/01 10:07:26 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)
    DRV - [2011/11/01 10:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
    DRV - [2011/11/01 10:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev)
    DRV - [2011/11/01 10:07:24 | 000,137,600 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
    DRV - [2011/11/01 10:07:24 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc)
    DRV - [2011/11/01 10:07:24 | 000,008,576 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc)
    DRV - [2011/10/07 06:23:48 | 000,230,608 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86)
    DRV - [2011/10/04 06:21:28 | 000,016,720 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
    DRV - [2011/09/13 06:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avgrkx86.sys -- (Avgrkx86)
    DRV - [2011/09/02 16:31:28 | 000,039,192 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
    DRV - [2011/09/02 16:31:20 | 000,041,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
    DRV - [2011/08/08 06:08:58 | 000,040,016 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86)
    DRV - [2011/07/11 01:14:38 | 000,295,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix)
    DRV - [2011/07/11 01:14:14 | 000,024,272 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
    DRV - [2011/07/11 01:14:12 | 000,134,736 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
    DRV - [2011/07/11 01:14:12 | 000,023,120 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\AVGIDSEH.sys -- (AVGIDSEH)
    DRV - [2011/06/15 18:23:56 | 000,060,156 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\scdemu.sys -- (SCDEmu)
    DRV - [2011/05/10 19:41:28 | 000,139,368 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
    DRV - [2011/04/22 10:39:52 | 000,012,872 | ---- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
    DRV - [2010/11/20 20:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
    DRV - [2010/11/20 19:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
    DRV - [2010/04/16 15:34:10 | 000,017,136 | ---- | M] (Portrait Displays, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\PdiPorts.sys -- (PdiPorts)
    DRV - [2010/03/10 16:16:12 | 000,025,112 | ---- | M] (Initio Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ivusb.sys -- (ivusb)
    DRV - [2010/03/06 17:35:41 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\gdrv.sys -- (gdrv)
    DRV - [2009/10/21 17:16:08 | 000,198,656 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet)
    DRV - [2009/09/10 15:31:48 | 000,102,912 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
    DRV - [2009/07/14 09:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | System | Running] -- C:\Windows\System32\drivers\serial.sys -- (Serial)
    DRV - [2009/02/13 12:02:52 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wdcsam.sys -- (WDC_SAM)
    DRV - [2008/11/14 02:11:30 | 000,017,184 | ---- | M] (Realtime Soft Ltd) [Kernel | Auto | Running] -- C:\Program Files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys -- (UltraMonUtility)
    DRV - [2008/08/26 09:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
    DRV - [2007/12/06 13:41:38 | 000,327,296 | ---- | M] (AfaTech ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AF15BDA.sys -- (AF15BDA)
    DRV - [2005/09/23 22:18:32 | 000,171,520 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\MarvinBus.sys -- (MarvinBus)
    DRV - [2001/11/07 02:00:00 | 000,166,504 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\webc3vid.sys -- (CTL511Plus) Video Blaster WebCam 3/WebCam Plus (WDM)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
    IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
    IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


    IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



    IE - HKU\S-1-5-21-759393751-1481746019-3899478243-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://au.yahoo.com/
    IE - HKU\S-1-5-21-759393751-1481746019-3899478243-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-AU
    IE - HKU\S-1-5-21-759393751-1481746019-3899478243-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 72 64 45 22 64 AB CC 01 [binary data]
    IE - HKU\S-1-5-21-759393751-1481746019-3899478243-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKU\S-1-5-21-759393751-1481746019-3899478243-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


    ========== FireFox ==========

    FF - prefs.js..keyword.URL: "http://search.avg.com/route/?d=4b8e473b&v=6.103.018.001&i=23&tp=ab&iy=&ychte=au&lng=en-GB&q= "
    FF - prefs.js..network.proxy.type: 0
    FF - user.js - File not found

    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
    FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
    FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
    FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@logitech.com/HarmonyRemote,version=1.0.0: C:\Program Files\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
    FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
    FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.633: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.633: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
    FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/04/05 10:33:46 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/02/01 09:06:13 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fe_4.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_4.0 [2012/02/27 19:57:05 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/15 18:33:29 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0 [2012/02/27 19:57:06 | 000,000,000 | ---D | M]

    [2011/04/07 12:36:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sean\AppData\Roaming\Mozilla\Extensions
    [2011/11/24 21:25:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\7yn18sj5.default\extensions
    [2011/04/22 09:13:50 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\7yn18sj5.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
    [2011/04/22 09:13:51 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\7yn18sj5.default\extensions\engine@conduit.com
    [2012/02/12 15:31:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
    [2012/02/12 15:31:22 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
    [2012/02/01 09:06:13 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES\AVG\AVG2012\FIREFOX4
    File not found (No name found) -- C:\PROGRAM FILES\NOKIA\NOKIA OVI SUITE\CONNECTORS\BOOKMARKS CONNECTOR\FIREFOXEXTENSION
    [2011/04/05 10:33:46 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
    [2011/05/15 18:33:26 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
    [2010/01/01 18:00:00 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
    [2010/01/01 18:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
    [2010/01/01 18:00:00 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
    [2010/01/01 18:00:00 | 000,001,180 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
    [2010/01/01 18:00:00 | 000,001,135 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

    O1 HOSTS File: ([2012/05/26 08:31:57 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
    O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
    O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
    O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
    O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
    O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
    O3 - HKU\S-1-5-21-759393751-1481746019-3899478243-1001\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\tbVuze.dll (Conduit Ltd.)
    O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
    O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
    O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
    O4 - HKLM..\Run: [CanonSolutionMenuEx] C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.)
    O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
    O4 - HKLM..\Run: [DocCreatorClient] C:\Program Files\Global Graphics\gDoc\DocCreatorClient.exe (Global Graphics Software Ltd.)
    O4 - HKLM..\Run: [DT ACR] C:\Program Files\Common Files\Portrait Displays\Shared\DT_startup.exe ()
    O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
    O4 - HKLM..\Run: [Garmin Lifetime Updater] C:\Program Files\Garmin\Lifetime Updater\GarminLifetime.exe (Garmin)
    O4 - HKLM..\Run: [NSU_agent] C:\Program Files\Nokia\Nokia Software Updater\nsu3ui_agent.exe ()
    O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
    O4 - HKLM..\Run: [PivotSoftware] C:\Program Files\Portrait Displays\Pivot Pro Plugin\Pivot_startup.exe ()
    O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
    O4 - HKLM..\Run: [USBToolTip] C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe (Pinnacle Systems GmbH)
    O4 - HKU\S-1-5-21-759393751-1481746019-3899478243-1006..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
    O4 - Startup: C:\Users\Sean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-759393751-1481746019-3899478243-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-759393751-1481746019-3899478243-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-21-759393751-1481746019-3899478243-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O7 - HKU\S-1-5-21-759393751-1481746019-3899478243-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
    O7 - HKU\S-1-5-21-759393751-1481746019-3899478243-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
    O7 - HKU\S-1-5-21-759393751-1481746019-3899478243-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
    O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
    O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
    O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
    O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
    O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.5.0.cab (SysInfo Class)
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/4.0.1.0/GarminAxControl_32.CAB (Reg Error: Key error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1B020E4F-2E7C-4BD9-96F8-639E8CA84316}: DhcpNameServer = 192.168.1.254
    O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
    O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
    O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2009/06/11 07:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
    O32 - AutoRun File - [2010/07/30 08:44:07 | 000,000,088 | ---- | M] () - E:\autorun.inf -- [ UDF ]
    O34 - HKLM BootExecute: (autocheck autochk *)
    O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
    O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

    NetSvcs: FastUserSwitchingCompatibility - File not found
    NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
    NetSvcs: Nla - File not found
    NetSvcs: Ntmssvc - File not found
    NetSvcs: NWCWorkstation - File not found
    NetSvcs: Nwsapagent - File not found
    NetSvcs: SRService - File not found
    NetSvcs: WmdmPmSp - File not found
    NetSvcs: LogonHours - File not found
    NetSvcs: PCAudit - File not found
    NetSvcs: helpsvc - File not found
    NetSvcs: uploadmgr - File not found

    Drivers32: msacm.ac3filter - C:\Windows\System32\ac3filter.acm ()
    Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
    Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
    Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
    Drivers32: VIDC.I420 - msh263.drv File not found
    Drivers32: vidc.mjpg - pvmjpg30.dll File not found
    Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
     
  18. 2012/05/26
    jayman34

    jayman34 Inactive Thread Starter

    Joined:
    2009/02/25
    Messages:
    65
    Likes Received:
    0
    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/05/27 07:13:03 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Sean\Desktop\OTL.exe
    [2012/05/27 07:07:27 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{B0CA3B80-CB80-491C-93CE-F3F140158EAB}
    [2012/05/26 18:49:32 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{6A097868-9C1E-4BFF-82D8-7F005045D62D}
    [2012/05/26 09:36:54 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
    [2012/05/26 08:09:44 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
    [2012/05/26 08:09:44 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
    [2012/05/26 08:09:44 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
    [2012/05/26 08:09:34 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
    [2012/05/26 08:09:30 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2012/05/26 08:03:07 | 004,527,289 | R--- | C] (Swearware) -- C:\Users\Sean\Desktop\ComboFix.exe
    [2012/05/26 06:49:05 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{09E2E452-2494-41EE-8797-BF06E7CAC3BF}
    [2012/05/24 18:22:51 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{F725EEA0-EFBA-46C5-AAC8-6765A7E6C2C0}
    [2012/05/23 06:21:15 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{245CDA0B-1636-4164-B450-53D27956BADC}
    [2012/05/22 17:52:50 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{8648A399-71EE-4EC7-8808-FC67F40CFBF7}
    [2012/05/21 18:42:21 | 000,000,000 | ---D | C] -- C:\Users\Sean\Documents\school run.el6.Data
    [2012/05/21 18:24:18 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\Sony
    [2012/05/21 15:57:29 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{EB642816-08AB-4D32-BA52-691B6CAB3ACB}
    [2012/05/21 15:57:17 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{185D03B8-96C5-4BE2-BF03-B6EE6F138F76}
    [2012/05/20 09:42:04 | 000,000,000 | ---D | C] -- C:\Program Files\MALWAREBYTES ANTI-MALWARE
    [2012/05/20 08:53:55 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{057EE8EC-3FD1-4492-88A3-2B076E473EF3}
    [2012/05/19 19:10:03 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{163AA453-A275-440E-9A9A-1E53A5BD51E8}
    [2012/05/19 07:09:33 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{C9F4F167-3307-4FAB-AAC0-76654F92C658}
    [2012/05/18 18:23:47 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{587B9F84-DC26-4A1F-B3E9-B9844BB33E89}
    [2012/05/18 18:23:34 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{AFC208FD-CBC2-43D0-BA4B-CE72A8C8DA22}
    [2012/05/17 19:22:37 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{6884FA74-EDC9-4C1E-98C3-F380C13DA16C}
    [2012/05/16 18:32:05 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{8D24B59D-F475-41E2-A8F9-191E021C98C7}
    [2012/05/16 06:30:05 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{BCDD33E4-7FF6-49EB-8975-4A0237EDAC54}
    [2012/05/15 18:14:44 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{3774B5CA-77EB-49DC-854A-28D81C0F7192}
    [2012/05/15 06:14:10 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{A34E2E2B-AD65-479A-98E1-01BE84D6B4F0}
    [2012/05/14 18:13:33 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{B6637F0E-FA5C-4B16-A539-43E78DB89C1B}
    [2012/05/14 06:13:02 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{6719270B-CD32-4820-A01B-9B7CE9C7EEF0}
    [2012/05/13 18:12:25 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{A2E08C80-3AE1-4221-AB3A-EF47E45D39B5}
    [2012/05/13 06:11:51 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{CCEDAEF2-A4D0-4955-AE1B-66281FEB3341}
    [2012/05/12 08:29:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
    [2012/05/12 06:23:00 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{021333D7-BD3D-47B6-9D50-056251643F11}
    [2012/05/11 18:22:29 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{1757C076-317E-47CC-A2F4-2C22C332DC87}
    [2012/05/11 06:21:58 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{6239CFEA-4456-4F58-99BE-4611F024E524}
    [2012/05/10 18:21:28 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{B728A172-E001-4500-998C-05C38B95C826}
    [2012/05/10 06:20:59 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{56A9A498-C5E9-4F0E-B544-CB2A70CCD34B}
    [2012/05/09 18:20:32 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{89AF3F02-C84F-45A5-84FA-D4287CAD2D57}
    [2012/05/09 06:20:02 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{5C78E62F-DDF1-4559-AB50-B537BBD1CDEC}
    [2012/05/08 18:19:28 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{0192CFDB-1EA9-4A26-8214-916A07FDA584}
    [2012/05/08 06:18:54 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{13A77478-82E8-4142-8A48-0F4E40CD6AFE}
    [2012/05/07 18:18:17 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{4023421B-F81B-4231-A587-3E4D0C763359}
    [2012/05/07 06:17:41 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{DBE9326A-F129-4EED-82AD-7308F88125A3}
    [2012/05/06 18:17:09 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{8B43E165-7218-485A-A540-B06EF0A46324}
    [2012/05/06 06:16:42 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{28945EE2-3BD4-4652-A64D-EAA2AE9F5F85}
    [2012/05/05 18:16:12 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{1F94C4B5-58F1-425B-A47F-3B19F462572F}
    [2012/05/05 06:15:40 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{20787EF8-FFE8-471B-AFAC-06A0297BF42A}
    [2012/05/04 18:15:11 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{79C6E95C-B8F6-49F9-8AF7-768E583D967A}
    [2012/05/04 06:14:44 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{20B7FE4D-050D-4B53-AA57-B7E5B951AC17}
    [2012/05/03 18:14:17 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{F4E45433-26A9-4B08-AC75-08A8587B543C}
    [2012/05/03 06:13:50 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{9E154B57-7FAB-49F5-ABF4-21DBE96A9601}
    [2012/05/02 18:13:24 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{624C252E-897D-4CFC-BA48-F3E68CC69B6D}
    [2012/05/02 06:12:10 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{BF3D2BAD-39FC-437C-8CAF-6C32CCB23142}
    [2012/05/02 06:11:47 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{E22E0B71-B9EA-475F-95B4-1BDFD40296C4}
    [2012/05/01 18:07:40 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{68D99E17-3659-409C-B07C-973F1C8433DF}
    [2012/05/01 06:07:08 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{678477EE-766E-4B60-B406-D4C8DFC5B129}
    [2012/04/30 18:06:35 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{4485517B-CD4D-4086-B034-4C0945D49A7C}
    [2012/04/30 06:06:06 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{FEF33B1C-1C77-4878-8EC3-219FEC27AE41}
    [2012/04/29 18:04:55 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{B7172D2A-CCD0-4704-9AC5-D18B1A0A6810}
    [2012/04/29 06:03:53 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{26C21210-F743-4070-9103-1B7A6C701C32}
    [2012/04/28 18:03:26 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{B4A6E34E-302F-4FB5-BDF8-04B2B5FB9E8C}
    [2012/04/28 06:02:58 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{A0CE1DD8-6499-45F7-B863-163E0D619DC8}
    [2012/04/27 18:02:27 | 000,000,000 | ---D | C] -- C:\Users\Sean\AppData\Local\{3FA354AB-854D-4F08-B273-59FE744B2345}
    [1 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\*.tmp files -> C:\ProgramData\Microsoft\Windows\Start Menu\Programs\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2012/05/27 07:14:55 | 000,000,878 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2012/05/27 07:13:05 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Sean\Desktop\OTL.exe
    [2012/05/27 07:10:26 | 099,176,094 | ---- | M] () -- C:\Windows\System32\drivers\AVG\incavi.avm
    [2012/05/27 07:07:11 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2012/05/27 07:07:11 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2012/05/27 07:05:35 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2012/05/26 23:21:14 | 000,631,538 | ---- | M] () -- C:\Windows\System32\perfh009.dat
    [2012/05/26 23:21:14 | 000,111,848 | ---- | M] () -- C:\Windows\System32\perfc009.dat
    [2012/05/26 13:11:49 | 000,000,632 | RHS- | M] () -- C:\Users\Sean\ntuser.pol
    [2012/05/26 08:31:57 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
    [2012/05/26 08:03:25 | 004,527,289 | R--- | M] (Swearware) -- C:\Users\Sean\Desktop\ComboFix.exe
    [2012/05/26 07:03:43 | 000,015,152 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2012/05/26 07:03:43 | 000,015,152 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2012/05/24 17:33:27 | 000,000,512 | ---- | M] () -- C:\Users\Sean\Desktop\MBR.dat
    [2012/05/23 22:07:34 | 000,256,892 | ---- | M] () -- C:\Users\Sean\Desktop\AVG scan 23052012.csv
    [2012/05/22 17:54:58 | 000,181,973 | ---- | M] () -- C:\Windows\System32\drivers\AVG\iavichjg.avm
    [2012/05/21 18:42:21 | 000,140,728 | ---- | M] () -- C:\Users\Sean\Documents\school run.el6
    [2012/05/20 18:31:12 | 000,207,156 | ---- | M] () -- C:\Users\Sean\Desktop\blue screen.jpg
    [2012/05/20 18:10:37 | 2414,731,264 | -HS- | M] () -- C:\hiberfil.sys
    [2012/05/19 15:24:58 | 000,275,934 | ---- | M] () -- C:\Users\Sean\Desktop\avg scan 19052012.csv
    [2012/05/18 06:13:35 | 000,482,504 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
    [2012/05/11 17:24:40 | 000,002,042 | -H-- | M] () -- C:\Users\Sean\Documents\Default.rdp
    [2012/05/08 17:56:48 | 000,013,688 | ---- | M] () -- C:\Users\Sean\Documents\tatts.com_goldencasket_buy-lotto_ticketdetails_serialNumber=534727998&trolley=true.pdf
    [2012/05/07 08:28:41 | 000,049,664 | ---- | M] () -- C:\Users\Sean\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2012/05/07 08:28:23 | 000,198,360 | ---- | M] () -- C:\Users\Sean\Documents\Close Enc.mp3
    [2012/05/07 08:26:48 | 000,209,844 | ---- | M] () -- C:\Users\Sean\Documents\Tardis.mp3
    [2012/05/07 08:25:48 | 000,336,168 | ---- | M] () -- C:\Users\Sean\Documents\celeb.mp3
    [2012/05/07 08:23:38 | 000,144,072 | ---- | M] () -- C:\Users\Sean\Documents\Twilight Zone.mp3
    [2012/05/06 15:29:34 | 000,000,349 | ---- | M] () -- C:\Users\Public\Documents\PCLECHAL.INI
    [2012/05/04 06:17:55 | 000,000,566 | ---- | M] () -- C:\Users\Sean\Documents\anit virus scan.csv
    [2012/04/28 09:34:28 | 000,108,349 | ---- | M] () -- C:\Users\Sean\Documents\clipsal fan control W0001429.pdf

    ========== Files Created - No Company Name ==========

    [2012/05/26 08:09:44 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
    [2012/05/26 08:09:44 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
    [2012/05/26 08:09:44 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
    [2012/05/26 08:09:44 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
    [2012/05/26 08:09:44 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
    [2012/05/24 17:33:27 | 000,000,512 | ---- | C] () -- C:\Users\Sean\Desktop\MBR.dat
    [2012/05/23 22:07:34 | 000,256,892 | ---- | C] () -- C:\Users\Sean\Desktop\AVG scan 23052012.csv
    [2012/05/21 18:42:21 | 000,140,728 | ---- | C] () -- C:\Users\Sean\Documents\school run.el6
    [2012/05/20 18:31:12 | 000,207,156 | ---- | C] () -- C:\Users\Sean\Desktop\blue screen.jpg
    [2012/05/19 15:23:31 | 000,275,934 | ---- | C] () -- C:\Users\Sean\Desktop\avg scan 19052012.csv
    [2012/05/08 17:56:48 | 000,013,688 | ---- | C] () -- C:\Users\Sean\Documents\tatts.com_goldencasket_buy-lotto_ticketdetails_serialNumber=534727998&trolley=true.pdf
    [2012/05/07 08:34:56 | 000,336,168 | ---- | C] () -- C:\Users\Sean\Documents\celeb.mp3
    [2012/05/07 08:34:56 | 000,209,844 | ---- | C] () -- C:\Users\Sean\Documents\Tardis.mp3
    [2012/05/07 08:34:56 | 000,198,360 | ---- | C] () -- C:\Users\Sean\Documents\Close Enc.mp3
    [2012/05/07 08:34:56 | 000,144,072 | ---- | C] () -- C:\Users\Sean\Documents\Twilight Zone.mp3
    [2012/05/04 06:17:55 | 000,000,566 | ---- | C] () -- C:\Users\Sean\Documents\anit virus scan.csv
    [2012/04/28 09:34:28 | 000,108,349 | ---- | C] () -- C:\Users\Sean\Documents\clipsal fan control W0001429.pdf
    [2012/02/29 22:10:06 | 000,032,256 | ---- | C] () -- C:\Windows\System32\ntrights.exe
    [2012/02/02 20:32:05 | 000,007,432 | ---- | C] () -- C:\Windows\System32\Machnm32.sys
    [2011/09/04 08:30:39 | 000,007,680 | ---- | C] () -- C:\Users\Sean\AppData\Local\Resmon.ResmonCfg
    [2011/08/03 03:31:54 | 000,311,912 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe
    [2011/04/26 16:45:52 | 000,027,136 | ---- | C] () -- C:\Windows\System32\HiDvrOcxESN.dll
    [2011/04/26 16:45:44 | 000,026,624 | ---- | C] () -- C:\Windows\System32\HiDvrOcxITA.dll
    [2011/04/26 16:45:44 | 000,026,624 | ---- | C] () -- C:\Windows\System32\HiDvrOcxBRG.dll
    [2011/04/26 16:45:36 | 000,026,624 | ---- | C] () -- C:\Windows\System32\HiDvrOcxPTG.dll
    [2011/04/26 16:45:36 | 000,020,992 | ---- | C] () -- C:\Windows\System32\HiDvrOcxJPN.dll
    [2011/04/26 16:45:26 | 000,027,136 | ---- | C] () -- C:\Windows\System32\HiDvrOcxFRA.dll
    [2011/04/26 16:45:26 | 000,026,112 | ---- | C] () -- C:\Windows\System32\HiDvrOcxDEU.dll
    [2011/04/26 16:45:18 | 000,026,112 | ---- | C] () -- C:\Windows\System32\HiDvrOcxPLK.dll
    [2011/04/26 16:45:18 | 000,025,088 | ---- | C] () -- C:\Windows\System32\HiDvrOcxTHA.dll
    [2011/04/05 11:56:24 | 000,000,049 | ---- | C] () -- C:\Users\Sean\AppData\Roaming\edltmp_57
    [2010/12/29 07:17:17 | 000,004,096 | -H-- | C] () -- C:\Users\Sean\AppData\Local\keyfile3.drm
    [2010/11/26 18:42:53 | 000,000,278 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
    [2010/11/20 07:03:24 | 000,000,161 | ---- | C] () -- C:\Windows\AutoKMS.ini
    [2010/11/03 19:18:05 | 000,000,017 | ---- | C] () -- C:\Windows\MovingPicture.ini
    [2010/11/01 20:55:11 | 000,237,568 | R--- | C] () -- C:\Windows\System32\qtmlClient.dll
    [2010/11/01 20:55:11 | 000,000,000 | ---- | C] () -- C:\Windows\Graffiti5.2Pin.ini
    [2010/10/10 09:07:15 | 000,000,000 | ---- | C] () -- C:\Windows\pcfriend.INI
    [2010/09/19 11:56:04 | 000,000,082 | ---- | C] () -- C:\Users\Sean\AppData\Roaming\edltmp_265
    [2010/06/15 21:13:42 | 000,015,760 | ---- | C] () -- C:\Windows\System32\DCMessagesPS.dll
    [2010/06/15 21:13:42 | 000,000,737 | ---- | C] () -- C:\Windows\System32\oemsetup.ini

    ========== LOP Check ==========

    [2010/09/07 21:03:37 | 000,000,000 | ---D | M] -- C:\Users\Beyonwiz\AppData\Roaming\PC Suite
    [2011/11/19 14:34:10 | 000,000,000 | ---D | M] -- C:\Users\Holly.SD-PC\AppData\Roaming\AVG2012
    [2011/11/19 14:33:31 | 000,000,000 | ---D | M] -- C:\Users\Holly.SD-PC\AppData\Roaming\Garmin
    [2012/05/13 07:15:11 | 000,000,000 | ---D | M] -- C:\Users\Holly.SD-PC\AppData\Roaming\PC Suite
    [2012/03/25 09:42:36 | 000,000,000 | ---D | M] -- C:\Users\Holly.SD-PC\AppData\Roaming\Softland
    [2012/04/25 07:57:45 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\AVG
    [2011/10/23 19:01:20 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\AVG2012
    [2010/03/06 08:25:44 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\AVG9
    [2010/04/09 22:17:31 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\avidemux
    [2010/05/29 17:43:24 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\Azureus
    [2012/04/25 17:52:47 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\Canon
    [2010/04/10 16:14:14 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\CD-LabelPrint
    [2010/06/06 17:45:59 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    [2012/02/02 20:56:30 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\DisplayTune
    [2011/10/17 20:54:47 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\DraftSight
    [2011/08/13 09:40:40 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\GARMIN
    [2010/03/03 22:28:05 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\GetRightToGo
    [2010/06/15 21:18:22 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\Global Graphics
    [2010/05/11 14:26:05 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\ImgBurn
    [2011/10/17 20:39:56 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\IMSIDesign
    [2011/08/09 21:10:43 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\jaws
    [2010/08/19 22:15:32 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\Leadertech
    [2012/01/10 21:59:34 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\mkvtoolnix
    [2012/02/27 19:58:01 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\Nokia
    [2010/07/26 22:08:13 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\Nokia Ovi Suite
    [2011/12/05 22:14:48 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\Nokia Suite
    [2011/02/24 20:24:46 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\NUUO
    [2011/04/08 21:24:44 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\PC Suite
    [2010/11/03 20:24:53 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\proDAD
    [2010/07/26 21:01:02 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\ROUTE 66 Sync
    [2010/03/03 21:52:13 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\ScanSoft
    [2011/08/16 14:57:33 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\Softland
    [2012/05/15 22:05:29 | 000,000,000 | ---D | M] -- C:\Users\Sean\AppData\Roaming\uTorrent
    [2011/10/24 14:27:14 | 000,000,000 | ---D | M] -- C:\Users\Wendy.SD-PC\AppData\Roaming\AVG2012
    [2010/04/17 10:08:22 | 000,000,000 | ---D | M] -- C:\Users\Wendy.SD-PC\AppData\Roaming\AVG9
    [2012/02/12 15:06:51 | 000,000,000 | ---D | M] -- C:\Users\Wendy.SD-PC\AppData\Roaming\Canon
    [2012/02/03 08:10:06 | 000,000,000 | ---D | M] -- C:\Users\Wendy.SD-PC\AppData\Roaming\DisplayTune
    [2011/02/23 21:15:57 | 000,000,000 | ---D | M] -- C:\Users\Wendy.SD-PC\AppData\Roaming\fenglei
    [2011/09/25 15:04:17 | 000,000,000 | ---D | M] -- C:\Users\Wendy.SD-PC\AppData\Roaming\Garmin
    [2010/04/10 16:51:31 | 000,000,000 | ---D | M] -- C:\Users\Wendy.SD-PC\AppData\Roaming\PC Suite
    [2012/03/17 09:44:27 | 000,032,594 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========



    ========== Custom Scans ==========

    < %SYSTEMDRIVE%\*.* >
    [2009/06/11 07:42:20 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
    [2010/03/07 14:11:20 | 000,011,256 | ---- | M] () -- C:\az.log
    [2010/11/20 22:40:07 | 000,383,786 | RHS- | M] () -- C:\bootmgr
    [2010/03/04 12:08:53 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
    [2012/05/26 09:36:49 | 000,015,634 | ---- | M] () -- C:\ComboFix.txt
    [2009/06/11 07:42:20 | 000,000,010 | ---- | M] () -- C:\config.sys
    [2012/05/20 18:10:37 | 2414,731,264 | -HS- | M] () -- C:\hiberfil.sys
    [2010/03/14 08:44:59 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
    [2011/04/22 15:46:30 | 000,000,109 | ---- | M] () -- C:\mbam-error.txt
    [2010/03/14 08:44:59 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
    [2012/05/26 07:59:03 | 3288,666,112 | -HS- | M] () -- C:\pagefile.sys

    < %systemroot%\Fonts\*.com >
    [2009/07/14 14:52:25 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
    [2009/07/14 14:52:25 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
    [2009/07/14 14:52:25 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
    [2009/07/14 14:52:25 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont

    < %systemroot%\Fonts\*.dll >

    < %systemroot%\Fonts\*.ini >
    [2009/06/11 07:31:19 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini

    < %systemroot%\Fonts\*.ini2 >

    < %systemroot%\Fonts\*.exe >

    < %systemroot%\system32\spool\prtprocs\w32x86\*.* >
    [2010/10/18 05:00:00 | 000,028,672 | ---- | M] (CANON INC.) -- C:\Windows\system32\spool\prtprocs\w32x86\1_CNMPDAN.DLL
    [2009/07/14 11:15:05 | 000,071,168 | ---- | M] (CANON INC.) -- C:\Windows\system32\spool\prtprocs\w32x86\CNBPP4.DLL
    [2007/04/16 06:00:00 | 000,027,136 | ---- | M] (CANON INC.) -- C:\Windows\system32\spool\prtprocs\w32x86\CNMPD93.DLL
    [2010/10/18 05:00:00 | 000,028,672 | ---- | M] (CANON INC.) -- C:\Windows\system32\spool\prtprocs\w32x86\CNMPDAN.DLL
    [2007/04/16 06:00:00 | 000,069,632 | ---- | M] (CANON INC.) -- C:\Windows\system32\spool\prtprocs\w32x86\CNMPP93.DLL
    [2010/10/18 05:00:00 | 000,074,752 | ---- | M] (CANON INC.) -- C:\Windows\system32\spool\prtprocs\w32x86\CNMPPAN.DLL
    [2010/11/20 22:21:36 | 000,030,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

    < %systemroot%\REPAIR\*.bak1 >

    < %systemroot%\REPAIR\*.ini >

    < %systemroot%\system32\*.jpg >

    < %systemroot%\*.jpg >

    < %systemroot%\*.png >

    < %systemroot%\*.scr >
    [2010/02/14 02:52:34 | 000,240,128 | ---- | M] (Realtime Soft Ltd) -- C:\Windows\UltraMon.scr
    [2012/03/08 18:37:20 | 000,302,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR

    < %systemroot%\*._sy >

    < %APPDATA%\Adobe\Update\*.* >

    < %ALLUSERSPROFILE%\Favorites\*.* >

    < %APPDATA%\Microsoft\*.* >

    < %PROGRAMFILES%\*.* >
    [2009/07/14 14:41:57 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini

    < %APPDATA%\Update\*.* >

    < %systemroot%\*. /mp /s >

    < %systemroot%\System32\config\*.sav >

    < %PROGRAMFILES%\bak. /s >

    < %systemroot%\system32\bak. /s >

    < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

    < %systemroot%\system32\config\systemprofile\*.dat /x >

    < %systemroot%\*.config >

    < %systemroot%\system32\*.db >

    < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
    [2011/04/15 08:17:01 | 000,000,221 | -HS- | M] () -- C:\Users\Sean\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

    < %USERPROFILE%\Desktop\*.exe >
    [2012/05/26 08:03:25 | 004,527,289 | R--- | M] (Swearware) -- C:\Users\Sean\Desktop\ComboFix.exe
    [2004/08/25 17:36:12 | 000,085,552 | ---- | M] (Realtime Soft) -- C:\Users\Sean\Desktop\MirrorMon.exe
    [2012/05/27 07:13:05 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Sean\Desktop\OTL.exe
    [2009/06/09 12:24:52 | 005,449,187 | ---- | M] (Beyonwiz. Co., Ltd.) -- C:\Users\Sean\Desktop\WizFX.exe

    < %PROGRAMFILES%\Common Files\*.* >

    < %systemroot%\*.src >
    [1998/09/21 02:05:00 | 000,005,870 | ---- | M] () -- C:\Windows\DEFAULT.SRC

    < %systemroot%\install\*.* >

    < %systemroot%\system32\DLL\*.* >

    < %systemroot%\system32\HelpFiles\*.* >

    < %systemroot%\tasks\*.* >
    [2012/05/27 07:07:11 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2012/05/27 07:14:55 | 000,000,878 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2012/05/27 07:07:11 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2012/05/20 18:11:09 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
    [2012/03/17 09:44:27 | 000,032,594 | ---- | M] () -- C:\Windows\tasks\SCHEDLGU.TXT

    < %systemroot%\system32\rundll\*.* >

    < %systemroot%\winn32\*.* >

    < %systemroot%\Java\*.* >

    < %systemroot%\system32\test\*.* >

    < %systemroot%\system32\Rundll32\*.* >

    < %systemroot%\AppPatch\Custom\*.* >

    < %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

    < %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

    < %PROGRAMFILES%\Internet Explorer\*.tmp >

    < %PROGRAMFILES%\Internet Explorer\*.dat >

    < %USERPROFILE%\My Documents\*.exe >
    [2007/02/22 21:08:08 | 000,925,696 | ---- | M] (GSpot Appliance Corp, a unit of GSp0t Heavy Industries) -- C:\Users\Sean\My Documents\GSpot.exe
    [2009/12/20 12:15:25 | 024,403,616 | ---- | M] () -- C:\Users\Sean\My Documents\NokiaSoftwareUpdaterSetup_en.exe
    [2010/12/07 23:23:43 | 096,383,980 | ---- | M] () -- C:\Users\Sean\My Documents\osm_routable_mapsource.exe
    [2010/03/21 15:19:07 | 000,173,408 | ---- | M] () -- C:\Users\Sean\My Documents\UltraMonHelp.exe
    [2011/07/11 14:29:55 | 000,000,000 | ---- | M] () -- C:\Users\Sean\My Documents\vlc-1.1.10-win32.exe

    < %USERPROFILE%\*.exe >

    < %systemroot%\ADDINS\*.* >
    [2009/06/11 07:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf

    < %systemroot%\assembly\*.bak2 >

    < %systemroot%\Config\*.* >

    < %systemroot%\REPAIR\*.bak2 >

    < %systemroot%\SECURITY\Database\*.sdb /x >
    [2011/08/14 11:28:03 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
    [2011/08/14 11:28:03 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
    [2010/03/03 22:05:57 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
    [2010/03/03 22:05:57 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
    [2011/08/14 11:28:03 | 001,056,768 | ---- | M] () -- C:\Windows\SECURITY\Database\tmp.edb

    < %systemroot%\SYSTEM\*.bak2 >

    < %systemroot%\Web\*.bak2 >

    < %systemroot%\Driver Cache\*.* >

    < %PROGRAMFILES%\Mozilla Firefox\0*.exe >

    < %ProgramFiles%\Microsoft Common\*.* >

    < %ProgramFiles%\TinyProxy. >

    < %USERPROFILE%\Favorites\*.url /x >
    [2012/02/15 18:58:21 | 000,000,402 | -HS- | M] () -- C:\Users\Sean\Favorites\desktop.ini

    < %systemroot%\system32\*.bk >

    < %systemroot%\*.te >

    < %systemroot%\system32\system32\*.* >

    < %ALLUSERSPROFILE%\*.dat /x >
    [2010/12/12 07:25:04 | 000,000,278 | ---- | M] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
    [2010/11/03 19:38:15 | 000,001,812 | ---- | M] () -- C:\ProgramData\__wdump.txt

    < %systemroot%\system32\drivers\*.rmv >

    < dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

    < dir /b "%systemroot%\*.exe" | find /i " " /c >

    < %PROGRAMFILES%\Microsoft\*.* >

    < %systemroot%\System32\Wbem\proquota.exe >

    < %PROGRAMFILES%\Mozilla Firefox\*.dat >

    < %USERPROFILE%\Cookies\*.txt /x >
    [2012/02/28 18:07:24 | 000,000,067 | -HS- | M] () -- C:\Users\Sean\Cookies\desktop.ini
    [2012/05/27 07:33:19 | 000,081,920 | -HS- | M] () -- C:\Users\Sean\Cookies\index.dat

    < %SystemRoot%\system32\fonts\*.* >

    < %systemroot%\system32\winlog\*.* >

    < %systemroot%\system32\Language\*.* >

    < %systemroot%\system32\Settings\*.* >

    < %systemroot%\system32\*.quo >

    < %SYSTEMROOT%\AppPatch\*.exe >

    < %SYSTEMROOT%\inf\*.exe >

    < %SYSTEMROOT%\Installer\*.exe >

    < %systemroot%\system32\config\*.bak2 >

    < %systemroot%\system32\Computers\*.* >

    < %SystemRoot%\system32\Sound\*.* >

    < %SystemRoot%\system32\SpecialImg\*.* >

    < %SystemRoot%\system32\code\*.* >

    < %SystemRoot%\system32\draft\*.* >

    < %SystemRoot%\system32\MSSSys\*.* >

    < %ProgramFiles%\Javascript\*.* >

    < %systemroot%\pchealth\helpctr\System\*.exe /s >

    < %systemroot%\Web\*.exe >

    < %systemroot%\system32\msn\*.* >

    < %systemroot%\system32\*.tro >

    < %AppData%\Microsoft\Installer\msupdates\*.* >

    < %ProgramFiles%\Messenger\*.* >

    < %systemroot%\system32\systhem32\*.* >

    < %systemroot%\system\*.exe >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >

    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:0B4227B4

    < End of report >
     
  19. 2012/05/26
    jayman34

    jayman34 Inactive Thread Starter

    Joined:
    2009/02/25
    Messages:
    65
    Likes Received:
    0
    OTL Extras logfile created on: 27/05/2012 7:34:20 AM - Run 1
    OTL by OldTimer - Version 3.2.43.1 Folder = C:\Users\Sean\Desktop
    Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000c09 | Country: Australia | Language: ENA | Date Format: dd/MM/yyyy

    3.00 Gb Total Physical Memory | 1.96 Gb Available Physical Memory | 65.50% Memory free
    6.06 Gb Paging File | 4.04 Gb Available in Paging File | 66.63% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 152.66 Gb Total Space | 10.39 Gb Free Space | 6.80% Space Free | Partition Type: NTFS
    Drive D: | 189.91 Gb Total Space | 5.64 Gb Free Space | 2.97% Space Free | Partition Type: NTFS
    Drive E: | 665.70 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
    Drive X: | 931.51 Gb Total Space | 0.14 Gb Free Space | 0.01% Space Free | Partition Type: NTFS

    Computer Name: SD-PC | User Name: Sean | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
    .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1 ",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
    htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
    htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1 "
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Directory [SuperFinder] -- "C:\Program Files\FSL\SuperFinder\SuperFinder.exe" "%1" (FSL)
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "VistaSp1" = Reg Error: Unknown registry data type -- File not found
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe" = C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 -- ()


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{0C0A3A39-8DC8-4E8B-8C1C-C1963D3DD94E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{0CC10F3B-B03A-4A54-BDCD-929B2EC8C10D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
    "{11DC084E-9F06-499F-B33A-76CD6903E9E9}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
    "{139566D4-0710-4FD4-B7EA-CA81422B3436}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
    "{1627C3DD-B040-4BCB-A235-61997AA0C952}" = lport=138 | protocol=17 | dir=in | app=system |
    "{16282A56-3033-47D0-8BAA-F68AC9726C61}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{19422BFE-09B8-4283-BB13-09986176A2B0}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{21DC0B77-2359-468A-A204-DD4053E0B6B8}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
    "{24A9A0EA-22E9-4288-92CB-892B4A7FB8FB}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{277A62FF-2394-4497-AE2E-9E6B191C6F37}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{34DC302F-1F00-4EE7-95A5-F9BB0E72F6DB}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{3A8D1827-7187-410E-9620-19C0376CFAB3}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{40A22DDB-83F5-4E57-B746-81E2E398EC4C}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{41CEC81A-19B2-4342-807A-44CE345E3BBE}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{4BB04B7D-E071-437A-9CD4-76BBE81A2768}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{5639009C-3AEE-4830-99EA-AF1760297831}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
    "{60C22A2E-E611-41EF-A67F-3CC42C5644FC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{63713E20-5EF5-40D7-8231-053C9E85CD69}" = rport=445 | protocol=6 | dir=out | app=system |
    "{68548232-EC47-4B27-A851-313AA030D9E4}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{773A219B-8ED8-42E9-92BD-D8B9A1146873}" = rport=10243 | protocol=6 | dir=out | app=system |
    "{7A8EA14A-0C52-4D86-9B4A-AC9A31CD5353}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
    "{84681009-23B8-4789-83B4-2B706A50E65F}" = lport=10243 | protocol=6 | dir=in | app=system |
    "{8D13150C-5E25-4FC0-8D72-A53D372EA1A8}" = lport=445 | protocol=6 | dir=in | app=system |
    "{98767222-9AFB-4502-88C9-6AA92830C195}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
    "{A43817E8-1A8A-46BF-A58C-CA6C6A3FC101}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{B7E6D28D-BA3B-43F2-A64A-29CEB1965477}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{BD57EAE9-5E82-4525-B4FC-78D6E3742197}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{BFDE9731-A794-4601-B75F-5FC650A0E27C}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{C4E8F401-33C1-4ADA-8CE4-973A752CF708}" = rport=139 | protocol=6 | dir=out | app=system |
    "{C6FC5737-D167-40BA-8788-DE6D4A3A1AC3}" = rport=138 | protocol=17 | dir=out | app=system |
    "{CE541BEA-48FF-4912-9128-13EFDE5BA162}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
    "{E8FAAA63-864B-4AEA-BC09-39BE1447CD0D}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
    "{ED9E5D0E-9927-49A2-8019-28A3DE6AB0E7}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
    "{F1C66297-B337-43D7-84B7-E4166BC907EA}" = lport=139 | protocol=6 | dir=in | app=system |
    "{F9C22646-0607-4754-8FAB-C26A241CB268}" = rport=137 | protocol=17 | dir=out | app=system |
    "{FCA62084-078C-4099-8918-8406BD9E68B2}" = lport=137 | protocol=17 | dir=in | app=system |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{0416956B-0D0E-42BE-B184-A254D407B78E}" = protocol=17 | dir=in | app=c:\program files\pinnacle\studio 14\programs\umi.exe |
    "{0EFB5DDA-F6DF-4FE7-A0FD-B11C86CA087A}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
    "{0F3AFD33-A0DB-4B01-A115-3FEEA4C1E4D4}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
    "{125E440C-75C7-4FF7-83A6-630529905276}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{14832067-B170-4817-AECF-0E34B1447B0B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{1B0259AF-9A9A-472C-9301-43FF7F58B6F2}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgemcx.exe |
    "{1D418CE4-F74C-43FE-B630-E0BF40357BA9}" = protocol=6 | dir=in | app=c:\program files\pinnacle\studio 14\programs\rm.exe |
    "{310C5162-12CD-45F4-B329-7CF43AD44364}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{379B679A-3C46-471C-85AA-298C27AE1C72}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
    "{380C077D-E54E-40DC-B7E0-4D707AC506A0}" = protocol=17 | dir=in | app=c:\program files\pinnacle\studio 14\programs\rm.exe |
    "{3EA80208-AAC9-4A50-B020-473B800755D3}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgdiagex.exe |
    "{3F55B3DC-ABCB-435A-8F49-3388881CD434}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{462B2036-5BBE-4F07-9BF3-6583237AF490}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgmfapx.exe |
    "{5A620862-110B-4F19-A96E-9CB87F02EB6E}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgdiagex.exe |
    "{5DD1C801-5635-442C-B91A-D6F3FC2C7428}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgmfapx.exe |
    "{747FF0C4-20D2-4C21-A7D0-EDC544AC1122}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgnsx.exe |
    "{78C8003F-23EE-4F0F-9B56-02DFFD42BA4D}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
    "{79505380-7D1C-4CC9-BBD8-62D2322E3F14}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
    "{7D5AD9B2-3943-4C67-BD48-52C3FF2BA3A1}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
    "{80B344F0-CD55-4001-8376-5341824F022A}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
    "{8401F78D-1429-4C8F-8A81-4610627360B1}" = protocol=6 | dir=in | app=c:\program files\pinnacle\studio 14\programs\umi.exe |
    "{915517D6-A5A7-4DCA-94DF-DB499577FD3C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{9A98FF61-8C76-48FE-8627-822E79BB4E4F}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
    "{9F69BD76-2352-4A1D-88F5-4EE70EEA1AE8}" = protocol=17 | dir=in | app=c:\program files\sony ericsson\update engine\sony ericsson update engine.exe |
    "{A00CB15A-03F3-4F41-BD52-E81C1E14EAF1}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{A129F86C-BFAA-4219-8729-CF008469865D}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
    "{AB5E1146-DA1D-4B7C-BBE8-8264B26FC7A8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{AD085B47-05F9-42D0-81D8-09794E90E252}" = protocol=6 | dir=in | app=c:\program files\sony ericsson\update engine\sony ericsson update engine.exe |
    "{B24718D5-E7BE-40DB-BD76-9D566B7B1367}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
    "{B6A3A4F4-EBF3-4ACF-BA57-79C69C1C70C0}" = dir=in | app=c:\program files\nokia\nokia suite\nokiasuite.exe |
    "{B8799906-F3B9-4358-9663-C8B409CA2229}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
    "{B88A7406-8138-487C-AA42-C958137842B3}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgemcx.exe |
    "{BC133A6F-E779-43E1-A8AB-1D0D7D91F47E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
    "{C8F9DDBC-CCCF-4BFC-BDF9-03509F3DB6DF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{CAF78E1C-CB9C-49A2-B81F-B5C94A8AA4CF}" = dir=in | app=c:\program files\nokia\nokia suite\nokiasuite.exe |
    "{CD9A16F2-B6A7-47EA-8927-4CF7D54A2D66}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{CFCF623C-7A1B-47CB-B172-652CEC016DA4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{D2AAD4AE-0C2C-4625-B73F-B65B08B206AD}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{D661ED96-8BE4-42F5-A1A9-B8050885F62D}" = protocol=6 | dir=in | app=c:\program files\pinnacle\studio 14\programs\studio.exe |
    "{E1DB99B7-6035-4FAD-86F5-EECDACCA2C06}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgnsx.exe |
    "{E5C727B7-9547-4E16-AB6B-930E5D5FC87B}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{F4B7F670-B0CD-46A3-9F95-0A7551AC21B9}" = protocol=17 | dir=in | app=c:\program files\pinnacle\studio 14\programs\studio.exe |
    "{FF6C0129-FDC3-40DD-BA9F-68E209930EE3}" = protocol=6 | dir=out | app=system |
    "{FFA575F6-D3D7-4BED-8098-7262BC59510E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "TCP Query User{6938A060-DC32-4B6E-B461-516460100EF9}C:\program files\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
    "TCP Query User{C03A45D3-2B9F-40CF-AD7D-C98530F8B965}C:\program files\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files\videolan\vlc\vlc.exe |
    "TCP Query User{D796394C-B445-4612-A599-ECF1C0B3B2AF}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
    "UDP Query User{4BFD2E45-0F87-4EA4-A28D-6B795BE54D00}C:\program files\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\client\googleearth.exe |
    "UDP Query User{BCA0B62E-0D2D-4EC8-8CFA-9FDA40871858}C:\program files\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files\videolan\vlc\vlc.exe |
    "UDP Query User{BCA32D8B-E355-4D76-A941-DFADDD0887E4}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    "{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.1 (r518)
    "{0217E1D1-BCEF-4A61-AF6D-F7740F65A066}" = Pivot Pro Plugin
    "{08687996-DF1F-4DD5-83B4-D73CAE115292}" = gDocPowerPoint2007AddIn
    "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
    "{0DEA342C-15CB-4F52-97B6-06A9C4B9C06F}" = SDK
    "{0E13CAA3-B5FC-48C0-AA4A-26F5CD0C371C}" = Garmin Lifetime Updater
    "{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX880_series" = Canon MX880 series MP Drivers
    "{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
    "{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
    "{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
    "{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
    "{19B2713A-8AF3-431B-B63E-D2EA52343AB0}" = gDocWord2007AddIn
    "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
    "{1A22A15D-E88A-427A-90E2-137245143239}" = Garmin Lifetime Updater
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
    "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
    "{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
    "{247C5DDA-FFD7-44E0-8BF7-79BC80A0BF87}" = Windows Live Family Safety
    "{26A24AE4-039D-4CA4-87B4-2F83216030FF}" = Java(TM) 6 Update 30
    "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
    "{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
    "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
    "{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
    "{2D6E3D97-1FDF-4993-AC75-72F59EC445C5}" = Windows Live Family Safety
    "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
    "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
    "{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
    "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
    "{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
    "{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
    "{3FED8672-36F6-4E46-B508-482DF7B0E24B}" = Easy Blue Print
    "{45A1BF92-700A-4408-B95E-79F462E3D67D}" = Studio 11 Bonus DVD
    "{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4AA68A73-DB9C-439D-9481-981C82BD008B}" = Nokia Connectivity Cable Driver
    "{4EFC72DA-2314-4E5D-AC8E-1C954CDB8BBF}" = AVG 2012
    "{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup
    "{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
    "{529125EF-E3AC-4B74-97E6-F688A7C0F1BF}" = Paint.NET v3.5.10
    "{52A451F3-94FB-410B-9EC2-6B57C8887708}" = gDocExcel2007AddIn
    "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
    "{5C6F884D-680C-448B-B4C9-22296EE1B206}" = Logitech Harmony Remote Software 7
    "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
    "{60DDF5DB-1D28-4C93-BD23-BAF440D0BB67}" = PDF Download for Internet Explorer
    "{634F79E1-2A41-4C40-9E8D-89EC740AC9D6}" = Logitech Harmony Remote Software
    "{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
    "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
    "{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
    "{6DE721A5-5E89-4D74-994C-652BB3C0672E}" = Pinnacle Video Driver
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
    "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
    "{7E6BEBCB-4E52-4BB3-A33E-3302B31E3B17}" = Garmin City Navigator Australia & New Zealand NT 2011.30 Update
    "{80F19EAA-44C4-47C2-AE87-1C7628E858D6}" = Logitech Harmony Remote Software 7
    "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
    "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
    "{8471021C-F529-43DE-84DF-3612E10F58C4}" = Remote Control USB Driver
    "{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
    "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    "{889D48DA-457F-4C8B-9095-6458F2793B12}" = Nokia Software Updater
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8BAF591E-B0E0-4DF6-B73C-AD10826E0DB7}" = SanDisk ® Media Manager
    "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
    "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
    "{8ED02445-D491-414C-A56D-2ED6BBB7239A}" = Garmin Communicator Plugin
    "{90120000-0017-0000-0000-0000000FF1CE}" = Microsoft Office SharePoint Designer 2007
    "{90120000-0017-0000-0000-0000000FF1CE}_SharePointDesigner_{4B4DF6E2-5E40-422B-82DD-205FD7E79226}" = Microsoft Office SharePoint Designer 2007 Service Pack 3 (SP3)
    "{90120000-0017-0409-0000-0000000FF1CE}" = Microsoft Office SharePoint Designer MUI (English) 2007
    "{90120000-0017-0409-0000-0000000FF1CE}_SharePointDesigner_{C00A9857-850C-4C68-A583-2EF4F24706F5}" = Microsoft Office SharePoint Designer 2007 Service Pack 3 (SP3)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_SharePointDesigner_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}_SharePointDesigner_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
    "{90120000-001F-0C0A-0000-0000000FF1CE}_SharePointDesigner_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}_SharePointDesigner_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
    "{90120000-0115-0409-0000-0000000FF1CE}_SharePointDesigner_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
    "{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
    "{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
    "{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
    "{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
    "{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
    "{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
    "{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
    "{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
    "{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
    "{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
    "{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
    "{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
    "{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
    "{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
    "{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
    "{92D1CEBC-7C72-4ECF-BFC6-C131EF3FE6A7}" = Nokia Suite
    "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
    "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{95140000-007D-0409-0000-0000000FF1CE}" = Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit
    "{992C78CB-AAC3-421F-8A9D-901AEE26FEF1}" = gDoc Installer
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
    "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
    "{A2AA4204-C05A-4013-888A-AD153139297F}" = PC Connectivity Solution
    "{A586DC50-B18D-48FB-B7CC-A598200457C2}" = Acer eDisplay Management
    "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
    "{A7836FF5-7293-40A4-B86E-E2038F82E8F3}" = AVG 2012
    "{A7E24CE8-F9D0-408F-A37C-5BF0716D3E91}" = DraftSight
    "{A83C6C4E-3C10-4431-A008-6AC5A14C9940}" = gDoc Installer
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
    "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
    "{AADD1C8F-D59F-4D55-A726-768C71A205A8}" = Pinnacle Studio 14
    "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
    "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
    "{AC76BA86-7AD7-5670-0000-900000000003}" = Korean Fonts Support For Adobe Reader 9
    "{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
    "{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
    "{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
    "{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 280.26
    "{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 295.73
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 280.26
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 280.19
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.4.28
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.2.23.3
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
    "{B49673F8-7AB6-4A14-8213-C8A7BE370010}" = UltraMon
    "{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
    "{BC3804E5-77CC-47A0-8BD5-797355A26BA3}" = WD SmartWare
    "{C078C299-C2C2-4110-A6EF-8D5E66C228DA}" = e-tax 2011
    "{C5DA59CF-2BB8-48D5-8E5B-17F2E0F0FEE4}" = System Requirements Lab for Intel
    "{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
    "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
    "{C735206E-A8D7-2DC8-EADF-744C18174654}" = Acrobat.com
    "{CBF78A5F-7950-4CF1-A063-C4C7B2B82CE6}" = SoundSoap PE
    "{CC874CBB-BD87-4126-9465-AE73BB62D6E0}" = Studio 11 Ultimate
    "{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
    "{CD95F661-A5C4-44F5-A6AA-ECDD91C240B5}" = WinZip 11.1
    "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
    "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
    "{D181A318-28DF-4B83-8F13-24C2D0BDA12D}" = Garmin POI Loader
    "{D22002ED-EE2A-4CB1-A63D-430E62A2E8D8}" = Google SketchUp 8
    "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
    "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
    "{D984A737-6615-4C2C-8A0D-B7A56B06C3A0}" = inSSIDer 2.0
    "{DA48EC21-CC7C-4808-A6B9-2BE06044D2FA}" = STK02H 2.3
    "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
    "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
    "{DEE88727-779B-47A9-ACEF-F87CA5F92A65}" = ScanSoft OmniPage SE 4
    "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
    "{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86
    "{E40520C9-9468-4CE7-B899-90EE136FB4CB}" = Garmin City Navigator Australia And New Zealand NT 2011.20 Update
    "{E42E07F5-5A90-4BA9-B55A-79FCF9EAF9B5}" = STK02N 2.4
    "{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
    "{EABCE84D-314C-4D47-8B8D-2743B45A4686}" = gDoc
    "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8
    "{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony PC Companion 2.10.053
    "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{F38FD0E4-B991-462B-873D-F2115EADD093}" = Nokia PC Suite
    "{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
    "{F5C372A1-40F3-49DA-A049-F75CDE9177DC}" = Pinnacle Studio Ultimate Collection Plugins
    "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
    "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    "49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
    "504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
    "6DA48AFDE796708D5A4C9121A83E7617A63A9A15" = Windows Driver Package - Nokia Modem (10/07/2010 4.6)
    "8461-7759-5462-8226" = Vuze
    "AC3Filter" = AC3Filter (remove only)
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
    "Aide PDF to DXF Converter_is1" = Aide PDF to DXF Converter 9.6
    "AVG" = AVG 2012
    "Avidemux 2.5" = Avidemux 2.5
    "AVL680HD Driver_is1" = AVL680HD Driver
    "CANONIJPLM100" = Canon Inkjet Printer/Scanner/Fax Extended Survey Program
    "CanonMyPrinter" = Canon My Printer
    "CanonSolutionMenu" = Canon Utilities Solution Menu
    "CanonSolutionMenuEX" = Canon Solution Menu EX
    "com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
    "conduitEngine" = Conduit Engine
    "Creative WebCam Monitor" = WebCam Monitor
    "DivX Setup.divx.com" = DivX Setup
    "doPDF 7 printer_is1" = doPDF 7.2 printer
    "DriverAgent.exe" = DriverAgent by eSupport.com
    "DVD Flick_is1" = DVD Flick 1.3.0.7
    "DVD Shrink_is1" = DVD Shrink 3.2
    "E5372C32E8562C76C24DBA6525002B1031495F34" = Windows Driver Package - Nokia Modem (06/09/2010 7.01.0.8)
    "Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
    "Easy-WebPrint EX" = Canon Easy-WebPrint EX
    "HijackThis" = HijackThis 2.0.2
    "ImgBurn" = ImgBurn
    "Knoll Light Factory EZ Studio" = Knoll Light Factory EZ Studio
    "Magic Bullet Looks Studio" = Magic Bullet Looks Studio
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
    "MediaNavigation.CDLabelPrint" = CD-LabelPrint
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
    "MKVToolNix" = MKVToolNix 5.2.1
    "Mozilla Firefox 4.0.1 (x86 en-GB)" = Mozilla Firefox 4.0.1 (x86 en-GB)
    "MP Navigator EX 4.1" = Canon MP Navigator EX 4.1
    "Nokia PC Suite" = Nokia PC Suite
    "Nokia Suite" = Nokia Suite
    "NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
    "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
    "Office14.SingleImage" = Microsoft Office Professional 2010
    "PCFriendly" = PCFriendly
    "Picasa 3" = Picasa 3
    "PowerISO" = PowerISO
    "proDAD-Heroglyph-2.5" = proDAD Heroglyph 2.5
    "proDAD-Mercalli-1.0" = proDAD Mercalli 1.0
    "proDAD-Vitascene-1.0" = proDAD Vitascene 1.0
    "RealPlayer 12.0" = RealPlayer
    "Red Giant ToonIt Studio" = Red Giant ToonIt Studio
    "SharePointDesigner" = Microsoft Office SharePoint Designer 2007
    "SP6" = Logitech SetPoint 6.32
    "Speed Dial Utility" = Canon Speed Dial Utility
    "stax-Pinnacle_is1" = SureThing Express Labeler
    "Super Finder XT_is1" = Super Finder XT 1.6.3.2
    "SystemRequirementsLab" = System Requirements Lab
    "Trapcode 3DStroke Studio" = Trapcode 3DStroke Studio
    "Trapcode Particular Studio" = Trapcode Particular Studio
    "Trapcode Shine Studio" = Trapcode Shine Studio
    "TVAfaDrv" = AVL680HD Driver
    "Update Engine" = Sony Ericsson Update Engine
    "uTorrent" = µTorrent
    "uTorrentBar Toolbar" = uTorrentBar Toolbar
    "Virgin Mobile" = Virgin Mobile
    "VLC media player" = VLC media player 2.0.1
    "Vuze_Remote Toolbar" = Vuze_Remote Toolbar
    "WinLiveSuite" = Windows Live Essentials
    "WinRAR archiver" = WinRAR 4.01 (32-bit)

    ========== HKEY_USERS Uninstall List ==========

    [HKEY_USERS\S-1-5-21-759393751-1481746019-3899478243-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 16/05/2012 6:02:05 AM | Computer Name = SD-PC | Source = SideBySide | ID = 16842785
    Description = Activation context generation failed for "C:\Program Files\Nokia\Nokia
    PC Suite 7\TIS_Windows7PIM.dll ". Dependent Assembly Microsoft.VC80.DebugCRT,processorArchitecture= "x86 ",publicKeyToken= "1fc8b3b9a1e18e3b ",type= "win32 ",version= "8.0.50608.0 "
    could not be found. Please use sxstrace.exe for detailed diagnosis.

    Error - 16/05/2012 4:12:27 PM | Computer Name = SD-PC | Source = Application Hang | ID = 1002
    Description = The program iexplore.exe version 9.0.8112.16421 stopped interacting
    with Windows and was closed. To see if more information about the problem is available,
    check the problem history in the Action Center control panel. Process ID: 91c Start
    Time: 01cd2fc5b57ef916 Termination Time: 540 Application Path: C:\Program Files\Internet
    Explorer\iexplore.exe Report Id:

    Error - 18/05/2012 4:56:12 AM | Computer Name = SD-PC | Source = SideBySide | ID = 16842785
    Description = Activation context generation failed for "C:\Program Files\Nokia\Nokia
    PC Suite 7\TIS_Windows7PIM.dll ". Dependent Assembly Microsoft.VC80.DebugCRT,processorArchitecture= "x86 ",publicKeyToken= "1fc8b3b9a1e18e3b ",type= "win32 ",version= "8.0.50608.0 "
    could not be found. Please use sxstrace.exe for detailed diagnosis.

    Error - 18/05/2012 9:16:36 PM | Computer Name = SD-PC | Source = Microsoft Office 14 | ID = 2001
    Description = Microsoft Outlook: Rejected Safe Mode action : Outlook failed to start
    correctly last time. Starting Outlook in safe mode will help you correct or isolate
    a startup problem in order to successfully start the program. Some functionality
    may be disabled in this mode. Do you want to start Outlook in safe mode?.

    Error - 18/05/2012 11:19:53 PM | Computer Name = SD-PC | Source = SideBySide | ID = 16842785
    Description = Activation context generation failed for "C:\Program Files\Nokia\Nokia
    PC Suite 7\TIS_Windows7PIM.dll ". Dependent Assembly Microsoft.VC80.DebugCRT,processorArchitecture= "x86 ",publicKeyToken= "1fc8b3b9a1e18e3b ",type= "win32 ",version= "8.0.50608.0 "
    could not be found. Please use sxstrace.exe for detailed diagnosis.

    Error - 19/05/2012 11:36:17 PM | Computer Name = SD-PC | Source = SideBySide | ID = 16842785
    Description = Activation context generation failed for "C:\Program Files\Nokia\Nokia
    PC Suite 7\TIS_Windows7PIM.dll ". Dependent Assembly Microsoft.VC80.DebugCRT,processorArchitecture= "x86 ",publicKeyToken= "1fc8b3b9a1e18e3b ",type= "win32 ",version= "8.0.50608.0 "
    could not be found. Please use sxstrace.exe for detailed diagnosis.

    Error - 21/05/2012 3:02:46 AM | Computer Name = SD-PC | Source = SideBySide | ID = 16842785
    Description = Activation context generation failed for "C:\Program Files\Nokia\Nokia
    PC Suite 7\TIS_Windows7PIM.dll ". Dependent Assembly Microsoft.VC80.DebugCRT,processorArchitecture= "x86 ",publicKeyToken= "1fc8b3b9a1e18e3b ",type= "win32 ",version= "8.0.50608.0 "
    could not be found. Please use sxstrace.exe for detailed diagnosis.

    Error - 23/05/2012 7:32:31 AM | Computer Name = SD-PC | Source = SideBySide | ID = 16842785
    Description = Activation context generation failed for "C:\Program Files\Nokia\Nokia
    PC Suite 7\TIS_Windows7PIM.dll ". Dependent Assembly Microsoft.VC80.DebugCRT,processorArchitecture= "x86 ",publicKeyToken= "1fc8b3b9a1e18e3b ",type= "win32 ",version= "8.0.50608.0 "
    could not be found. Please use sxstrace.exe for detailed diagnosis.

    Error - 23/05/2012 11:00:16 AM | Computer Name = SD-PC | Source = Windows Backup | ID = 4103
    Description =

    Error - 25/05/2012 6:58:22 PM | Computer Name = SD-PC | Source = SideBySide | ID = 16842785
    Description = Activation context generation failed for "C:\Program Files\Nokia\Nokia
    PC Suite 7\TIS_Windows7PIM.dll ". Dependent Assembly Microsoft.VC80.DebugCRT,processorArchitecture= "x86 ",publicKeyToken= "1fc8b3b9a1e18e3b ",type= "win32 ",version= "8.0.50608.0 "
    could not be found. Please use sxstrace.exe for detailed diagnosis.


    ========== Last 10 Event Log Errors ==========

    Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

    < End of report >
     
  20. 2012/05/26
    jayman34

    jayman34 Inactive Thread Starter

    Joined:
    2009/02/25
    Messages:
    65
    Likes Received:
    0
    Please see log files in post

    Computer still slow but haven't been using it really that much at the moment because of the issues. So couldn't really say it was better/worse or the same at the moment

    One query though. I noticed in one of the report it says memeory 3gb. I have 4gb installed? Is this an issue or just a windows thing?
     
    Last edited by a moderator: 2012/05/26
  21. 2012/05/26
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Yes.

    Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following

      Code:
      :OTL
      IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
      IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
      O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/...Control_32.CAB (Reg Error: Key error.)
      @Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:0B4227B4
      
      :Commands
      [purity]
      [emptytemp]
      [emptyjava]
      [emptyflash]
      [Reboot]
      
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    ==================================================================

    1. Update your Java version here: http://www.java.com/en/download/installed.jsp

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    2. Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it.
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.
    • Do NOT post JavaRa log.

    ============================================================

    Last scans....

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.

    2. Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    • Make sure the following options are checked:
      • Internet Services
      • Windows Firewall
      • System Restore
      • Security Center
      • Windows Update
      • Windows Defender
    • Press "Scan ".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.


    3. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    4. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click on List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.