1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Funmoods

Discussion in 'Virus & Other Malware Removal' started by gobob, Oct 3, 2012.

Thread Status:
Not open for further replies.
Advertisement
  1. gobob

    gobob Thread Starter

    Joined:
    Oct 3, 2012
    Messages:
    25
    I cannot get rid of funmoods. I have read just about every post on this and I still cannot get rid of this beast. I have run malwarebytes and a host of other spyware programs but it still is in there somewhere. I don't know how I acquired this program but I certainly want to get rid of it. I am using IE9 What should i do?


    Tech Support Guy System Info Utility version 1.0.0.2
    OS Version: Microsoft Windows 7 Home Premium, Service Pack 1, 64 bit
    Processor: Intel(R) Core(TM)2 Duo CPU P7550 @ 2.26GHz, Intel64 Family 6 Model 23 Stepping 10
    Processor Count: 2
    RAM: 4063 Mb
    Graphics Card: ATI Mobility Radeon HD 4650, 1024 Mb
    Hard Drives: C: Total - 289698 MB, Free - 49543 MB; D: Total - 305242 MB, Free - 108367 MB; E: Total - 15344 MB, Free - 2523 MB;
    Motherboard: Hewlett-Packard, 3624
    Antivirus: Microsoft Security Essentials, Updated and Enabled
     
  2. Gizzy

    Gizzy Malware Specialist

    Joined:
    Aug 2, 2005
    Messages:
    3,832
    Hello gobob and Welcome to Tech Support Guy! :)
    My name is Gizzy and I'll be glad to help you with your malware problems.

    Please note the following while we work:
    • The fixes are specific to your problem and should only be used for this issue on this computer.
    • Perform all actions in the order given.
    • If you don't know or understand something stop and ask! Don't keep going on.
    • Please DO NOT uninstall/install any programs unless asked to. It is more difficult when files/programs appear or disappear from the logs.
    • Please DO NOT run any tools or scans unless I ask you to.
    • It is important that you reply to this thread. Do not start a new topic.
    • Your security programs may give warnings for some of the tools I will ask you to use, Be assured, any links I give are safe.
    • The process is not instant, Please continue to respond to this thread until I give you the All Clean!. Absence of symptoms does not mean that everything is clear.
    • Topics not replied to within 3 days will be removed from my Subscribed Threads List.
    Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

    Because of this, I advise you to backup any personal files and folders before you start.
    Backup your data - windows 7



    UAC Advice
    • All applications I ask to be used will require to be run in Administrator mode. i.e. Right-click on and select Run as administrator.
    • The Operating System (Windows 7) in use comes with an inbuilt utility called User Account Control (UAC).
    • When prompted by this with anything I ask you to carry out please select the option Allow.


    Download and run OTL
    1. Download OTL to your desktop.
    2. Right-click on OTL.exe and select Run as administrator to run it. Make sure all other windows are closed and let it run uninterrupted.
    3. Check the box beside Scan All Users
    4. Ensure Use SafeList is selected under Extra Registry
    5. Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    6. When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    7. Please copy (Edit > Select All -- Edit > Copy) the contents of these files, one at a time, and post them with your next reply.


    Please reply with:
    • OTL logs (OTL.txt and Extras.txt)
     
  3. gobob

    gobob Thread Starter

    Joined:
    Oct 3, 2012
    Messages:
    25
    I'm having trouble posting a reply so I will try doing two replays and see if that will work
     
  4. gobob

    gobob Thread Starter

    Joined:
    Oct 3, 2012
    Messages:
    25
    OTL Extras logfile created on: 10/5/2012 9:12:04 AM - Run 1
    OTL by OldTimer - Version 3.2.70.2 Folder = C:\Users\Robert Jameson\Desktop
    64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.97 Gb Total Physical Memory | 1.61 Gb Available Physical Memory | 40.63% Memory free
    6.95 Gb Paging File | 4.00 Gb Available in Paging File | 57.50% Paging File free
    Paging file location(s): c:\pagefile.sys 3055 4096 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 282.91 Gb Total Space | 48.80 Gb Free Space | 17.25% Space Free | Partition Type: NTFS
    Drive D: | 298.09 Gb Total Space | 105.78 Gb Free Space | 35.49% Space Free | Partition Type: NTFS
    Drive E: | 14.99 Gb Total Space | 2.46 Gb Free Space | 16.45% Space Free | Partition Type: NTFS
    Drive G: | 465.76 Gb Total Space | 65.35 Gb Free Space | 14.03% Space Free | Partition Type: NTFS

    Computer Name: ROBERTJAMESON | User Name: Robert Jameson | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\SOFTWARE\Classes\<extension>]
    .html [@ = htmlfile] -- Reg Error: Unable to open value key File not found

    ========== Shell Spawning ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Unable to open value key
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Unable to open value key
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Unable to open value key
    Unknown [openas] -- "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
    Directory [AddToPlaylistVLC] -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" ()
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [PlayWithVLC] -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" ()
    Directory [Print_Directory_Listing] -- Printdir.bat "%1" ()
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Unable to open value key
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Unable to open value key
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Unable to open value key
    Unknown [openas] -- "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
    Directory [AddToPlaylistVLC] -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" ()
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [PlayWithVLC] -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" ()
    Directory [Print_Directory_Listing] -- Printdir.bat "%1" ()
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
    "9000:TCP" = 9000:TCP:*:Enabled:Logitech Media Server 9000 tcp (UI)
    "9001:TCP" = 9001:TCP:*:Enabled:Logitech Media Server 9001 tcp (UI)
    "9002:TCP" = 9002:TCP:*:Enabled:Logitech Media Server 9002 tcp (UI)
    "9003:TCP" = 9003:TCP:*:Enabled:Logitech Media Server 9003 tcp (UI)
    "9004:TCP" = 9004:TCP:*:Enabled:Logitech Media Server 9004 tcp (UI)
    "9005:TCP" = 9005:TCP:*:Enabled:Logitech Media Server 9005 tcp (UI)
    "9006:TCP" = 9006:TCP:*:Enabled:Logitech Media Server 9006 tcp (UI)
    "9007:TCP" = 9007:TCP:*:Enabled:Logitech Media Server 9007 tcp (UI)
    "9008:TCP" = 9008:TCP:*:Enabled:Logitech Media Server 9008 tcp (UI)
    "9009:TCP" = 9009:TCP:*:Enabled:Logitech Media Server 9009 tcp (UI)
    "9010:TCP" = 9010:TCP:*:Enabled:Logitech Media Server 9010 tcp (UI)
    "9100:TCP" = 9100:TCP:*:Enabled:Logitech Media Server 9100 tcp (UI)
    "8000:TCP" = 8000:TCP:*:Enabled:Logitech Media Server 8000 tcp (UI)
    "10000:TCP" = 10000:TCP:*:Enabled:Logitech Media Server 10000 tcp (UI)
    "9090:TCP" = 9090:TCP:*:Enabled:Logitech Media Server 9090 tcp (UI)
    "3483:UDP" = 3483:UDP:*:Enabled:Logitech Media Server 3483 udp
    "3483:TCP" = 3483:TCP:*:Enabled:Logitech Media Server 3483 tcp

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
    "9000:TCP" = 9000:TCP:*:Enabled:Logitech Media Server 9000 tcp (UI)
    "9001:TCP" = 9001:TCP:*:Enabled:Logitech Media Server 9001 tcp (UI)
    "9002:TCP" = 9002:TCP:*:Enabled:Logitech Media Server 9002 tcp (UI)
    "9003:TCP" = 9003:TCP:*:Enabled:Logitech Media Server 9003 tcp (UI)
    "9004:TCP" = 9004:TCP:*:Enabled:Logitech Media Server 9004 tcp (UI)
    "9005:TCP" = 9005:TCP:*:Enabled:Logitech Media Server 9005 tcp (UI)
    "9006:TCP" = 9006:TCP:*:Enabled:Logitech Media Server 9006 tcp (UI)
    "9007:TCP" = 9007:TCP:*:Enabled:Logitech Media Server 9007 tcp (UI)
    "9008:TCP" = 9008:TCP:*:Enabled:Logitech Media Server 9008 tcp (UI)
    "9009:TCP" = 9009:TCP:*:Enabled:Logitech Media Server 9009 tcp (UI)
    "9010:TCP" = 9010:TCP:*:Enabled:Logitech Media Server 9010 tcp (UI)
    "9100:TCP" = 9100:TCP:*:Enabled:Logitech Media Server 9100 tcp (UI)
    "8000:TCP" = 8000:TCP:*:Enabled:Logitech Media Server 8000 tcp (UI)
    "10000:TCP" = 10000:TCP:*:Enabled:Logitech Media Server 10000 tcp (UI)
    "9090:TCP" = 9090:TCP:*:Enabled:Logitech Media Server 9090 tcp (UI)
    "3483:UDP" = 3483:UDP:*:Enabled:Logitech Media Server 3483 udp
    "3483:TCP" = 3483:TCP:*:Enabled:Logitech Media Server 3483 tcp

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    ========== Authorized Applications List ==========


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{06F18693-4CEF-4388-9F45-151EDB72C284}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{091B6ADD-B200-43FD-99D7-ED330B05CCF1}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{0DC2FCE2-6036-4155-90F0-40ACD79AA707}" = lport=5353 | protocol=17 | dir=in | name=bonjour |
    "{0F82B244-AA45-4B6B-9FD3-3824BB96F1C3}" = lport=10243 | protocol=6 | dir=in | app=system |
    "{19372D23-DE32-4A0D-A86F-A8E83BE71545}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{1A141CFB-9A83-46DF-88F9-FA713E7569ED}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
    "{1AAAB694-745C-41A3-95F3-8E6B0D641A30}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
    "{20D541CF-8BAE-4438-946A-A29FCF40542E}" = rport=10243 | protocol=6 | dir=out | app=system |
    "{21D1B5D7-BC40-43BC-BCCA-5C7079FE55D6}" = lport=138 | protocol=17 | dir=in | app=system |
    "{2F312D1E-1F49-41A0-95C4-E6DE50E14C4D}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
    "{30000E25-A558-471E-B83B-B1426CF6C41F}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe |
    "{498BC124-8BFE-4BA1-A96E-FE4B07E9A90D}" = rport=138 | protocol=17 | dir=out | app=system |
    "{4D9805E1-E219-48EE-8C61-F1792E0AB19C}" = lport=445 | protocol=6 | dir=in | app=system |
    "{5726B361-100F-45EE-9141-C607EFE21A89}" = rport=80 | protocol=6 | dir=out | app=c:\program files (x86)\common files\intuit\update service\intuitupdater.exe |
    "{583CE2F0-BA6E-439B-B5F6-D74AF3579D69}" = lport=54925 | protocol=17 | dir=in | name=brothernetwork scanner |
    "{5D76D739-2BC9-440D-8281-01BCC34CB274}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{634C6699-060E-45D8-B870-124E9109AA90}" = rport=139 | protocol=6 | dir=out | app=system |
    "{6842D4E3-B867-4546-A4C3-4CA661D010FD}" = rport=2869 | protocol=6 | dir=out | app=system |
    "{686562DB-98D1-4B70-85BE-B79D7F95F0A5}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{6B1D499E-B9D9-4488-BB10-E16BA06FFA8E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{75711528-3D24-4159-8263-53EB677799C6}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{7B1E8344-E58E-4584-8672-3C508BA7ABB1}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{8313FC60-2FAF-44DA-9605-B524A2D1F2F0}" = rport=445 | protocol=6 | dir=out | app=system |
    "{8B9B3E25-2AD3-4030-92BA-626385B598AA}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
    "{99792EC1-F1B8-4D21-A5BB-E831631D3A35}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{9CF94812-0010-431E-98D9-101C7562DE7D}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{A32E0932-9803-488C-9E6E-A4CF697352B4}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{B5DB8C13-90B7-426C-9DB9-93F7007047C2}" = lport=139 | protocol=6 | dir=in | app=system |
    "{BEAC55F0-2EF4-4968-A8EF-56922E2988B0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{C071848F-B46E-43C1-84E5-EAD7D1AAA41E}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{C20A84E9-736D-4FF3-ADB9-E87C5962D92E}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
    "{C8BB6A96-A0F0-4BBE-8D68-D2ED81A3F788}" = lport=137 | protocol=17 | dir=in | app=system |
    "{CCB8107A-7436-474E-96BD-D234D4C25286}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{D4BC4E01-95AD-4F87-B2D1-03CEF66CF531}" = rport=137 | protocol=17 | dir=out | app=system |
    "{D6AEEF31-82DB-4667-802C-C79422FA33BB}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
    "{D835E0C5-AE18-4D49-AB8F-45D6F40EF375}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{E0785E81-DB96-4DAC-9188-8E9E131867D0}" = rport=80 | protocol=6 | dir=out | app=c:\program files (x86)\common files\intuit\update service\intuitupdateservice.exe |
    "{E09D851D-0EE9-4423-B9F9-F23BEA0A2509}" = lport=5353 | protocol=17 | dir=in | name=bonjour |
    "{E7E2C00D-D80C-485D-B85F-8454B478D527}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
    "{EA054ABE-89C5-4827-90D4-AB1C6244D4C9}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
    "{EB083B66-10F4-4379-A12A-FD4859495418}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{F1AE7F7B-5939-48FB-A245-D04539CC3F34}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{F556F175-BBB1-429A-8409-8A70B3552298}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
    "{F847D0BF-72BD-420F-8408-3E06BD5C7B88}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{FCEAE1E1-13ED-4BA6-91EE-4A7CDFF47055}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
    "{FFDD649E-C5B5-4100-AB0A-2F716F4FB107}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{05824789-8B8D-4744-B8E2-1B1BA0A6F3C8}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
    "{06FAA491-9B8C-4A68-A1AB-3757CBC929D1}" = protocol=17 | dir=out | app=hpqtra08.exe |
    "{0F898A09-A5AA-4DE4-B231-0463A0698745}" = protocol=6 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe |
    "{12063129-C66E-4738-BE38-69A4EB2524B5}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
    "{1BAF6E9F-C6F4-431F-8ABF-6257A35764F5}" = protocol=17 | dir=in | app=hpqste08.exe |
    "{1D326CF3-6047-4AEB-B433-FE726DB14966}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
    "{1F4D042B-5F4A-4EE2-839F-ACBC28DAD8CD}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartmusic.exe |
    "{20C482D5-500A-429E-BD42-C22FF50FDE43}" = protocol=6 | dir=out | app=hpqste08.exe |
    "{229A3CA7-B979-487E-A726-D26A79F656FD}" = protocol=17 | dir=in | app=hpqkygrp.exe |
    "{23094CA7-2D41-4755-975B-5756ADE76341}" = protocol=6 | dir=out | app=hpqthb08.exe |
    "{24DBF4BA-E2DE-400D-8273-60BC55F0DA72}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{2503AA0F-F0DF-4F5B-B4AB-302A424645DA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{2A28F728-FCA7-4D79-9391-930E65FB903A}" = dir=in | app=c:\program files (x86)\seagate\seagate dashboard\hipservagent\hipservagent.exe |
    "{2B479050-9628-4C65-9435-21466FCF1C7C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{33E5BBB8-156E-4105-93E6-3623279E3040}" = protocol=17 | dir=in | app=hpqscnvw.exe |
    "{3625D67E-A01F-4BBA-ACE5-AF9E85D63088}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{38D17AAC-803F-483C-A572-33E4C3079FF9}" = protocol=6 | dir=out | app=hpqscnvw.exe |
    "{3F21F00E-4B92-4E52-9744-7E33EBE28E1C}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartvideo.exe |
    "{407D341D-B957-4784-8292-1A8A639EB2BF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{40B8EA92-B7A8-42E8-9EDA-A2AD85AEC696}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\tsmagent.exe |
    "{41572B15-105B-4828-94AE-B7005D69DFC3}" = protocol=17 | dir=in | app=c:\program files (x86)\bucksbee loyalty plugin - 100815\troubleshooter.exe |
    "{4F08DE23-A528-43A8-9E83-493422A5C06F}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
    "{527479CC-2BC7-467F-A2B6-A2011E221E88}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{5BBDDA1E-5C73-40DF-A785-28889610D3CD}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{6AA0DEE0-4A1B-419E-8163-0345F4EC4CE5}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{74DAABAD-F241-4F13-8718-7FFF28E0B29D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{7DC88F2F-9BDF-4289-A898-695EBDEEC481}" = protocol=6 | dir=in | app=c:\program files (x86)\brother\brmfl11a\faxrx.exe |
    "{7FD53A80-1CA0-4D95-9F24-2657F14FBCF7}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe |
    "{903A76BF-701A-488B-A415-334EDE157A7C}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
    "{9282588D-8CF3-4FAB-B6E8-752A225548B4}" = protocol=6 | dir=in | app=hpqtra08.exe |
    "{966B6742-008F-4EED-BA3D-9507880CFE31}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{99DE5DBC-648F-4AFF-A685-F251D8F3F85E}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{9AD0C48C-0763-483A-8D9C-593EE252B354}" = protocol=17 | dir=out | app=hpqkygrp.exe |
    "{9B825B49-9B8E-4186-8A96-CAD27A63341B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{9E0EC6DC-E662-466D-9718-E80B38121E3D}" = protocol=17 | dir=out | app=hpqscnvw.exe |
    "{A524025A-C82E-4910-9016-7D4A35B2611E}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
    "{A9922D2C-7AD6-4436-962F-C64DEC6C72F9}" = protocol=17 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe |
    "{B22CAFA7-F66A-4CF4-8940-E8850507936C}" = protocol=17 | dir=out | app=hpqthb08.exe |
    "{B6F08B06-8F8B-4535-AA79-F7882FC4A319}" = dir=in | app=c:\program files (x86)\file type assistant\tsassist.exe |
    "{BA1065B5-7D29-4F67-9EF2-756E0FC67FF6}" = dir=in | app=c:\program files (x86)\hp\digital imaging\{71c4f928-136a-4222-a191-310e081fb96b}\setup\hpznui40.exe |
    "{BBC679F5-FDFC-4BD6-8D49-254C36B75B0C}" = protocol=6 | dir=in | app=c:\program files (x86)\bucksbee loyalty plugin - 100815\troubleshooter.exe |
    "{BC916E58-A83F-485B-99AE-7E810A7F836E}" = protocol=17 | dir=out | app=hpqste08.exe |
    "{BE0C5131-FFB6-4696-BFD1-17555F3655F6}" = protocol=6 | dir=in | app=c:\program files (x86)\airport\apagent.exe |
    "{C54FA0EE-312D-46DC-898A-DB2D6EF37363}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
    "{C5DF2BFD-DE63-4B23-96D7-8598BB2A7D62}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{C797CEBA-1427-46A5-B327-BD3FA6217C65}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
    "{C7FBAC53-B56A-4466-93C7-B7C38261D6DF}" = protocol=6 | dir=out | app=hpqkygrp.exe |
    "{CFFC2EC7-4C48-4198-A5EE-7F4CF4958DB9}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{D05A738B-2FBA-4F2E-93F8-282664BD15BE}" = dir=in | app=c:\program files (x86)\squeezebox\server\squeezesvr.exe |
    "{D090ADDB-7438-46CF-913F-BED7BF03E5D0}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
    "{D10960BC-52F6-4E39-B804-90706F099377}" = protocol=6 | dir=out | app=hpqtra08.exe |
    "{D413E600-6775-4111-B18E-A0835319DC74}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{D9569398-3707-447C-A534-70CFC7D8B3A2}" = protocol=6 | dir=in | app=hpqthb08.exe |
    "{DB054F91-3253-40BA-ACFE-4D92C7861EED}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{DCE315AB-84A8-4369-B1FB-5B99917F5C4F}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
    "{DDD7F443-E5AB-4E4D-B1EF-D65CDDF92F57}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{DEF21E8B-3A15-47D7-AB92-D0619A4A8392}" = protocol=6 | dir=in | app=hpqste08.exe |
    "{E055DBD0-4F28-4944-ACE8-E1AE85D99694}" = protocol=6 | dir=in | app=hpqkygrp.exe |
    "{E09DC2EE-E94D-4144-B28A-DDC8CFD00C2B}" = protocol=6 | dir=in | app=hpqscnvw.exe |
    "{E2E4F49E-B5DA-4807-83D0-061114CB445D}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
    "{E60C535D-2B32-461B-B876-2C1794E6A6DE}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
    "{E85735E7-42BA-4E1C-AAE4-031922EFE702}" = protocol=17 | dir=in | app=hpqtra08.exe |
    "{EB1C32AF-552F-446A-BB84-50598ED18C22}" = protocol=6 | dir=out | app=system |
    "{EEAD645E-5FDF-4C3E-BA1F-3A7097F305E1}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{F0A6C869-D911-4935-B6C8-A68DA5CF6CE7}" = protocol=17 | dir=in | app=c:\program files (x86)\brother\brmfl11a\faxrx.exe |
    "{F3C26343-C75F-4930-9C58-F661DF206C92}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\clml\clmlsvc.exe |
    "{F649E565-8390-4333-8B53-63D9181FF110}" = protocol=17 | dir=in | app=hpqthb08.exe |
    "{FA92E273-F93B-4C18-957A-78ABA300A46C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
    "TCP Query User{08094D2A-7AAC-4550-B3F4-85C1B2E2829E}C:\program files (x86)\encore\hoyle casino 2009\hoyle casino.exe" = protocol=6 | dir=in | app=c:\program files (x86)\encore\hoyle casino 2009\hoyle casino.exe |
    "TCP Query User{12C03CD4-2085-475A-AB5F-8495CC679E24}C:\program files\schwab\sspro\sspro.exe" = protocol=6 | dir=in | app=c:\program files\schwab\sspro\sspro.exe |
    "TCP Query User{5E020459-7BA2-45F7-8C31-F6155E0D4889}C:\program files\schwab\sspro\sspro.exe" = protocol=6 | dir=in | app=c:\program files\schwab\sspro\sspro.exe |
    "TCP Query User{64E9B47B-C2B7-4CF2-B14D-968D7078998C}C:\program files (x86)\airport\aputil.exe" = protocol=6 | dir=in | app=c:\program files (x86)\airport\aputil.exe |
    "TCP Query User{B4783208-C5CE-43A9-8667-3EBE6CEAE65D}C:\program files (x86)\myihome\app\myihome-server.exe" = protocol=6 | dir=in | app=c:\program files (x86)\myihome\app\myihome-server.exe |
    "TCP Query User{D1B97AEB-D3D8-4F48-B9CF-4E8557089D02}C:\program files (x86)\airport\aputil.exe" = protocol=6 | dir=in | app=c:\program files (x86)\airport\aputil.exe |
    "TCP Query User{E3FBE50B-FFF9-4F32-B273-A87C81681DD5}C:\program files (x86)\nero\nero 9\nero showtime\showtime.exe" = protocol=6 | dir=in | app=c:\program files (x86)\nero\nero 9\nero showtime\showtime.exe |
    "TCP Query User{FA452F4C-F454-481A-AAAD-355C49FFF4E7}C:\program files (x86)\myihome\app\myihome-server.exe" = protocol=6 | dir=in | app=c:\program files (x86)\myihome\app\myihome-server.exe |
    "UDP Query User{03BB4DAA-E55F-4F94-98F9-DF83EEBB8D9B}C:\program files (x86)\myihome\app\myihome-server.exe" = protocol=17 | dir=in | app=c:\program files (x86)\myihome\app\myihome-server.exe |
    "UDP Query User{0710FBAD-2F2E-42E9-980B-C5EBA33A24F4}C:\program files (x86)\nero\nero 9\nero showtime\showtime.exe" = protocol=17 | dir=in | app=c:\program files (x86)\nero\nero 9\nero showtime\showtime.exe |
    "UDP Query User{209E0C67-A40E-447C-A7AC-DA1C062A46BB}C:\program files\schwab\sspro\sspro.exe" = protocol=17 | dir=in | app=c:\program files\schwab\sspro\sspro.exe |
    "UDP Query User{2ABC622A-FC0C-47C8-875B-626A8F939EB7}C:\program files (x86)\encore\hoyle casino 2009\hoyle casino.exe" = protocol=17 | dir=in | app=c:\program files (x86)\encore\hoyle casino 2009\hoyle casino.exe |
    "UDP Query User{5C083AA3-B082-4E4D-98A0-8188608DE75D}C:\program files (x86)\airport\aputil.exe" = protocol=17 | dir=in | app=c:\program files (x86)\airport\aputil.exe |
    "UDP Query User{98BFC357-3A52-4C6A-8D54-2DC10442689C}C:\program files\schwab\sspro\sspro.exe" = protocol=17 | dir=in | app=c:\program files\schwab\sspro\sspro.exe |
    "UDP Query User{C9A2FBD7-97B2-40EE-8404-42038040DF89}C:\program files (x86)\myihome\app\myihome-server.exe" = protocol=17 | dir=in | app=c:\program files (x86)\myihome\app\myihome-server.exe |
    "UDP Query User{E59A742C-780F-4183-AA93-9A984A639CC3}C:\program files (x86)\airport\aputil.exe" = protocol=17 | dir=in | app=c:\program files (x86)\airport\aputil.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{16AD84C0-E7A0-F64D-D55A-15D274C4439A}" = ccc-utility64
    "{26A24AE4-039D-4CA4-87B4-2F86416014FF}" = Java(TM) 6 Update 14 (64-bit)
    "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
    "{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}" = Apple Mobile Device Support
    "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{6DD01FF3-63CE-436B-96DB-61363EAA4EB8}" = MobileMe Control Panel
    "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
    "{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}" = PaperPort Image Printer 64-bit
    "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
    "{83715090-142B-D305-36EC-7538A007D336}" = ATI Catalyst Install Manager
    "{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes
    "{85A42FF0-F0D0-44A3-B226-C124D6E8B1D5}" = HP 3D DriveGuard
    "{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.02
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8B485965-8EFE-464A-842F-CF8F18C3DFD7}" = iCloud
    "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
    "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
    "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
    "{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}" = Microsoft Security Client
    "{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = HP Integrated Module with Bluetooth wireless technology
    "{A3B12CDE-4385-41CF-B0C7-BC1BF29EC93D}" = HP MediaSmart SmartMenu
    "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{AEF6C676-D7A2-4487-BD4B-1BED17B229B5}" = Microsoft Mouse and Keyboard Center
    "{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
    "{B820C985-D9F1-45B5-A7F5-0C5863CBEA04}_is1" = Privacy SafeGuard version 1.1
    "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
    "{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
    "A-WIN-WTB 1.0.0 1269103_is1" = Wolfram Toolbar 1.0 (1269103)
    "CCleaner" = CCleaner
    "FFE7D41DF3C645075BB149E21988B63996C34187" = ENE CIR Receiver Driver
    "LSI Soft Modem" = LSI HDA Modem
    "MediaInfo" = MediaInfo 0.7.27
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
    "Microsoft Mouse and Keyboard Center" = Microsoft Mouse and Keyboard Center
    "Microsoft Security Client" = Microsoft Security Essentials
    "OfficeTrial" = Microsoft Office Home and Student 60 day trial
    "Recuva" = Recuva
    "SynTPDeinstKey" = Synaptics Pointing Device Driver

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
    "{026AAEDB-AAF9-497D-806D-B5FE75264F6D}" = Songverter
    "{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}" = Scansoft PDF Professional
    "{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
    "{0F5ADA2F-C0B2-4AD6-8FF7-7DFA9D6B4CBA}" = FreeUndelete 2.1.36867.1
    "{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
    "{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
    "{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
    "{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
    "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
    "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
    "{23170F69-40C1-2701-0921-000001000000}" = 7-Zip 9.21
    "{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
    "{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron Flash Media Controller Driver
    "{266D0EEA-E5A6-4A08-A0EE-5391D4EA44A7}" = Catalyst Control Center - Branding
    "{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
    "{27B0C2FD-9739-8D7D-6552-307C786D9097}" = Catalyst Control Center InstallProxy
    "{28656860-4728-433C-8AD4-D1A930437BC8}" = Nuance PDF Viewer Plus
    "{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
    "{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
    "{2EBA8202-FBD5-4004-81EA-BDC38C054CE2}" = HP User Guides 0153
    "{3023EBDA-BF1B-4831-B347-E5018555F26E}" = HP MediaSmart Movie Themes
    "{33CF58F5-48D8-4575-83D6-96F574E4D83A}" = Nero DriveSpeed
    "{349A5E6B-EE96-48B5-85DA-85F782CF51B0}" = Karaoke Home Producer
    "{359CFC0A-BEB1-440D-95BA-CF63A86DA34F}" = Nero Recode
    "{360EDFB0-EAA2-012B-AD16-000000000000}" = TurboTax 2009 wcaiper
    "{368BA326-73AD-4351-84ED-3C0A7A52CC53}" = Nero Rescue Agent
    "{3744B641-61DE-417F-BCDC-9CCED4224DF8}" = LightScribe System Software
    "{38022B5C-0C69-389F-DA48-B87480B5705A}" = CCC Help Turkish
    "{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
    "{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
    "{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
    "{38A3B04E-9AC9-4AB4-B72C-94A259EF622B}" = Keyrite
    "{3BBBF379-6C7E-0985-18F6-6C60D6C36EC6}" = CCC Help Portuguese
    "{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
    "{3E7F5E50-6956-4446-87BF-F422A8736B7F}" = Secure Online Account Numbers
    "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
    "{4313E16C-811B-469F-8815-6EB98085F8B2}" = SlingBoxWatchYourTVAnyWhere
    "{43E39830-1826-415D-8BAE-86845787B54B}" = Nero Vision
    "{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = PowerRecover
    "{48AC1C1D-5C35-41BC-B66B-E4A4A2C29BD9}" = Vogone
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4B2F56AC-C043-C84F-3EF1-E6D6F21E934F}" = Catalyst Control Center Graphics Full Existing
    "{4F2C2E34-5A3E-0E70-BDFC-A5B1E3C2FFAC}" = Catalyst Control Center Graphics Light
    "{532715CE-CFD6-E4F8-53C3-2F1DE31C04DA}" = CCC Help Hungarian
    "{5543C9C8-4F56-4E84-BD4F-454942043964}" = Microstudio
    "{558CC8A3-F1A2-9C31-7B90-F61E476B8622}" = CCC Help Dutch
    "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
    "{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress
    "{5D76ABD5-262B-6D65-6C13-F38175C7A5AF}" = CCC Help Korean
    "{5D92E608-E454-0C8C-D577-7F7C06151117}" = CCC Help Greek
    "{612AD33D-9824-4E87-8396-92374E91C4BB}_is1" = Inbox Toolbar
    "{62AC81F6-BDD3-4110-9D36-3E9EAAB40999}" = Nero CoverDesigner
    "{65980EBF-C4B5-4555-823A-94DB7F709E53}" = Secure Online Account Numbers
    "{664708B3-C730-11D5-ADE7-00B0D07D157A}" = StreetSmart Pro
    "{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart Live TV
    "{6C0A559F-8583-4B5A-8B50-20BEE15D8E64}" = Nuance PaperPort 12
    "{6D172D0A-B9F1-4046-AFAB-8599288545BF}" = Safari
    "{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.2.0
    "{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}" = HP Support Assistant
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
    "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    "{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
    "{7829DB6F-A066-4E40-8912-CB07887C20BB}" = Nero BurnRights
    "{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
    "{786CF17A-66A5-4A35-B24A-178D3B39F86A}_is1" = Womble EasyDVD 1.0.1.26 (07/2011)
    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
    "{79EECA21-CDFA-6012-5E8B-6CF2623D647A}" = Catalyst Control Center Graphics Full New
    "{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
    "{7BE6BC10-6737-CD9D-8363-F919B8D6D917}" = Catalyst Control Center Core Implementation
    "{80FBA7A7-ABD1-4910-A916-023075C45593}" = CCC Help Danish
    "{82A213BD-B6AA-4281-A2D3-59D51893CC56}" = HP MediaSmart Software Notebook Demo
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110265407}" = Bejeweled 2 Deluxe
    "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
    "{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
    "{869200DB-287A-4DC0-B02B-2B6787FBCD4C}" = Nero DiscSpeed
    "{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
    "{8797DE34-22BC-CA33-6B67-A0CC2765B545}" = CCC Help German
    "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver
    "{89D1C17B-90DE-650A-073A-A7FA7BC6ECE5}" = CCC Help French
    "{8C664716-FD23-9902-A29E-863D056F46FC}" = CCC Help Russian
    "{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
    "{8F36B221-F483-B7CE-4DDA-7BDA4D81E306}" = CCC Help English
    "{8FB16749-1235-D027-AF25-1D22A9FEC0D5}" = CCC Help Thai
    "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
    "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
    "{90F6051D-A69F-4159-9203-7E20430E1056}" = HP MediaSmart SlingPlayer
    "{91130409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
    "{91A3A4DE-656A-5C7A-5B61-75FB6D167A6A}" = CCC Help Polish
    "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{9C411DC9-B8B8-45F3-B688-073BF4B59094}" = Virtual Account Numbers
    "{9D318C86-AF4C-409F-A6AC-7183FF4CF424}" = Internet TV for Windows Media Center
    "{9E82B934-9A25-445B-B8DF-8012808074AC}" = Nero PhotoSnap
    "{9EDB805A-E11C-8842-2393-FDFDA17963AC}" = CCC Help Chinese Traditional
    "{A16D1BBD-BE86-0183-4152-2E85FECC31F7}" = CCC Help Finnish
    "{A19856E3-C9D7-988E-5B8C-70C87342B8DD}" = Catalyst Control Center Localization All
    "{A1B36B88-AF90-43A3-8906-6DBEE89B4FBD}" = Brother MFL-Pro Suite MFC-J835DW
    "{A209525B-3377-43F4-B886-32F6B6E7356F}" = Nero WaveEditor
    "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
    "{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{AA68AAAE-41F0-40B5-8896-5947F5FD6889}" = AirPort
    "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
    "{AD777154-A573-4FCA-C730-D7C33437262C}" = CCC Help Czech
    "{AF72E557-0647-4DE5-ACDA-ECFB38D5D732}" = Licensing Service Install
    "{B1ADF008-E898-4FE2-8A1F-690D9A06ACAF}" = DolbyFiles
    "{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
    "{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
    "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
    "{B66D2CC9-652D-EBE5-497F-74BBC1029FB4}" = CCC Help Japanese
    "{B6A4D07E-725F-07CD-DE49-8AB76939631D}" = CCC Help Norwegian
    "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
    "{B74D4E10-6884-0000-0000-000000000103}" = Adobe Bridge 1.0
    "{B78120A0-CF84-4366-A393-4D0A59BC546C}" = Menu Templates - Starter Kit
    "{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
    "{BEC98926-4238-4846-A2E3-56A96B217BDD}" = Hoster
    "{BF930A5D-4F36-5158-C8DA-DECD5B51A78E}" = CCC Help Chinese Standard
    "{C3A11907-930D-41AC-A135-CC3B12F92011}" = Seagate Dashboard
    "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
    "{C5A7CB6C-E76D-408F-BA0E-85605420FE9D}" = SoundTrax
    "{c5d5a1f0-7106-4d53-9486-0d86f9f4a764}" = Nero 9
    "{C6FCE95C-0072-40C0-9AB2-3EF88DA6CED9}" = Catalyst Control Center Graphics Previews Common
    "{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
    "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
    "{CCF6F57B-F6B4-4508-BF45-63AAC9DE416A}" = Quicken 2010
    "{D025A639-B9C9-417D-8531-208859000AF8}" = NeroBurningROM
    "{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
    "{D9DCF92E-72EB-412D-AC71-3B01276E5F8B}" = Nero ShowTime
    "{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
    "{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
    "{DE700910-58F7-4D2E-B7E6-3BA2DA1B6806}" = Virtual Account Numbers
    "{DF166A93-835F-DF13-E974-FD73E8D7F4F6}" = CCC Help Swedish
    "{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar
    "{E09F7D2B-C1C1-D80B-7775-6FFE9D713C60}" = CCC Help Spanish
    "{E26EEBF8-3A50-8095-5877-AE243C8852EF}" = Catalyst Control Center Graphics Previews Vista
    "{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
    "{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
    "{E498385E-1C51-459A-B45F-1721E37AA1A0}" = Movie Templates - Starter Kit
    "{E553760D-D7F7-48BF-BD8B-C7E23BA04CB5}" = HP MediaSmart Internet TV
    "{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
    "{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
    "{EC8049FF-B0E3-A963-408C-1B1D8F20DD55}" = CCC Help Italian
    "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype&#8482; 5.10
    "{F0FDF9C9-1DDC-401F-B638-36F1CAE8A875}" = VideoStudio
    "{F1861F30-3419-44DB-B2A1-C274825698B3}" = Nero Disc Copy Gadget
    "{F1D7AC58-554A-4A58-B784-B61558B1449A}" = QLBCASL
    "{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
    "{F9A43C0C-F274-4EC0-B02E-202C15C09C00}" = HP Wireless Assistant
    "{FBCDFD61-7DCF-4E71-9226-873BA0053139}" = Nero InfoTool
    "{FD1D88FA-E5E0-BA76-73C8-7362E9703842}" = ccc-core-static
    "1Click DVD Copy Pro_is1" = 1Click DVD Copy Pro 4.1.7.0
    "Ad-Aware Browsing Protection" = Ad-Aware Browsing Protection
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
    "Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
    "Audacity_is1" = Audacity 1.2.6
    "BitTorrent" = BitTorrent
    "Bucksbee Loyalty Plugin - 100815" = Bucksbee Loyalty Plugin - 100815
    "ChampHearts" = Championship Hearts All-Stars 7.40
    "conduitEngine" = Conduit Engine
    "Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
    "D-Link Toolbar" = D-Link Toolbar
    "DVDFab 8 Qt_is1" = DVDFab 8.2.1.0 (07/09/2012) Qt
    "DVDFab 8_is1" = DVDFab 8.0.8.5 (19/03/2011)
    "EarthDesk" = EarthDesk
    "eSupport UndeletePlus_is1" = eSupport UndeletePlus 3.0.2.1214
    "Freecorder4.1" = Freecorder
    "Hardware Helper_is1" = Hardware Helper
    "Homepage Protection" = Homepage Protection
    "Hoyle Casino 2009" = Hoyle Casino 2009
    "ieSpell" = ieSpell
    "ImgBurn" = ImgBurn
    "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
    "InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
    "InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = HP MediaSmart Movie Themes
    "InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
    "InstallShield_{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart Live TV
    "InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
    "InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
    "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
    "InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
    "InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
    "InstallShield_{E553760D-D7F7-48BF-BD8B-C7E23BA04CB5}" = HP MediaSmart Internet TV
    "InstallShield_{F0FDF9C9-1DDC-401F-B638-36F1CAE8A875}" = Corel VideoStudio 12
    "iPhoneBackupExtractor" = iPhone Backup Extractor
    "iSkysoft DVD Ripper_is1" = iSkysoft DVD Ripper(Build 2.3.4.0)
    "jZip" = jZip
    "LAME for Audacity_is1" = LAME v3.98.2 for Audacity
    "MakeMKV" = MakeMKV v1.5.6_beta
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.0.1400
    "myiHome_is1" = myiHome v5.1.4
    "Playbryte" = PlayBryte
    "Productivity_3 Toolbar" = Productivity 3 Toolbar
    "Rocket Division Software Grab & Burn_is1" = Grab & Burn, Version 4.0.1 ( Build 2005-09-21, Win32, CSS )
    "SimpUtil_Maps_1 Toolbar" = SimpUtil Maps 1 Toolbar
    "sl-adk" = SelectionLinks
    "SMPlayer" = SMPlayer 0.6.7
    "SoftwareUpdUtility" = Download Updater (AOL LLC)
    "SoundTaxi_is1" = SoundTaxi 3.9.4
    "STMediaSuite" = SoundTaxi Media Suite 3.9.4
    "Trusted Software Assistant_is1" = File Type Assistant
    "TurboTax 2009" = TurboTax 2009
    "Tweaks FileOpener" = FileOpener
    "VLC media player" = VLC media player 0.9.2
    "WildTangent hp Master Uninstall" = HP Games
    "Windows Media Encoder 9" = Windows Media Encoder 9 Series
    "Womble EasyDVD" = Womble EasyDVD 1.0.1.26 (07/2011)
    "Yahoo! Companion" = Yahoo! Toolbar
    "Yahoo! Software Update" = Yahoo! Software Update
    "YInstHelper" = Yahoo! Install Manager

    ========== Last 20 Event Log Errors ==========

    [ Application Events ]
    Error - 10/2/2012 3:34:13 AM | Computer Name = RobertJameson | Source = SideBySide | ID = 16842815
    Description = Activation context generation failed for "c:\Program Files (x86)\Common
    Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
    Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
    "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
    "version" in element "assemblyIdentity" is invalid.

    Error - 10/3/2012 3:34:43 AM | Computer Name = RobertJameson | Source = SideBySide | ID = 16842815
    Description = Activation context generation failed for "c:\Program Files (x86)\Common
    Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
    Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
    "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
    "version" in element "assemblyIdentity" is invalid.

    Error - 10/3/2012 2:17:04 PM | Computer Name = RobertJameson | Source = Application Error | ID = 1000
    Description = Faulting application name: iexplore.exe, version: 9.0.8112.16450,
    time stamp: 0x503723f6 Faulting module name: Toolbar.dll, version: 3.1.0.0, time
    stamp: 0x4f5a80de Exception code: 0xc0000005 Fault offset: 0x0002a8c2 Faulting process
    id: 0xecc Faulting application start time: 0x01cda19309f808db Faulting application
    path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
    C:\Users\Robert Jameson\AppData\LocalLow\FCTB000100815\Toolbar\Toolbar.dll Report
    Id: 886877ee-0d86-11e2-b688-0027134ffaa6

    Error - 10/3/2012 2:35:49 PM | Computer Name = RobertJameson | Source = Application Error | ID = 1000
    Description = Faulting application name: BtStackServer.exe, version: 6.2.0.9602,
    time stamp: 0x4a723b26 Faulting module name: BtStackServer.exe, version: 6.2.0.9602,
    time stamp: 0x4a723b26 Exception code: 0xc0000005 Fault offset: 0x000000000014c6b7
    Faulting
    process id: 0xd04 Faulting application start time: 0x01cda192f53daffa Faulting application
    path: C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe Faulting module
    path: C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe Report Id: 26ef1f77-0d89-11e2-b688-0027134ffaa6

    Error - 10/3/2012 2:50:00 PM | Computer Name = RobertJameson | Source = Application Hang | ID = 1002
    Description = The program jre-6u35-windows-i586-iftw.exe version 6.0.350.10 stopped
    interacting with Windows and was closed. To see if more information about the problem
    is available, check the problem history in the Action Center control panel. Process
    ID: 9c4 Start Time: 01cda193c5c7249b Termination Time: 15 Application Path: C:\Users\ROBERT~1\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe
    Report
    Id:

    Error - 10/4/2012 3:34:58 AM | Computer Name = RobertJameson | Source = SideBySide | ID = 16842815
    Description = Activation context generation failed for "c:\Program Files (x86)\Common
    Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
    Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
    "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
    "version" in element "assemblyIdentity" is invalid.

    Error - 10/4/2012 2:53:23 PM | Computer Name = RobertJameson | Source = Application Hang | ID = 1002
    Description = The program Skype.exe version 5.10.0.116 stopped interacting with
    Windows and was closed. To see if more information about the problem is available,
    check the problem history in the Action Center control panel. Process ID: 1024 Start
    Time: 01cda1b0f691159c Termination Time: 15 Application Path: C:\Program Files (x86)\Skype\Phone\Skype.exe
    Report
    Id:

    Error - 10/4/2012 9:49:20 PM | Computer Name = RobertJameson | Source = VSS | ID = 8194
    Description =

    Error - 10/5/2012 3:18:44 AM | Computer Name = RobertJameson | Source = Windows Backup | ID = 4104
    Description =

    Error - 10/5/2012 7:03:01 AM | Computer Name = RobertJameson | Source = SideBySide | ID = 16842815
    Description = Activation context generation failed for "c:\Program Files (x86)\Common
    Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
    Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
    "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
    "version" in element "assemblyIdentity" is invalid.

    [ Hewlett-Packard Events ]
    Error - 5/30/2012 5:36:42 AM | Computer Name = RobertJameson | Source = HPSF.exe | ID = 4000
    Description =

    Error - 5/31/2012 5:59:38 PM | Computer Name = RobertJameson | Source = HPSF.exe | ID = 4000
    Description =

    Error - 5/31/2012 5:59:40 PM | Computer Name = RobertJameson | Source = HPSF.exe | ID = 4000
    Description =

    Error - 5/31/2012 6:01:15 PM | Computer Name = RobertJameson | Source = HPSF.exe | ID = 4000
    Description =

    Error - 6/23/2012 2:19:14 PM | Computer Name = RobertJameson | Source = HPSF.exe | ID = 4000
    Description =

    Error - 7/3/2012 7:14:26 AM | Computer Name = RobertJameson | Source = hpsa_service.exe | ID = 2000
    Description = HP Error ID: -2146233088 at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateDetail(String
    category) at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetectCore()
    at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
    Boolean localScan) Message: Failed to perform update. StackTrace: at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateDetail(String
    category) at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetectCore()
    at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
    Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager InnerException.Message:
    Object '/bb8391cb_b2f0_46af_8786_b39a17d36c10/avaqoye09pvm+1s7edj0+t3w_45.rem'
    has been disconnected or does not exist at the server. Name: hpsa_service.exe Version:
    06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
    Format:
    en-US RAM: 4063 Ram Utilization: 50 TargetSite: Void UpdateDetail(System.String)

    Error - 8/16/2012 7:59:53 AM | Computer Name = RobertJameson | Source = HPSF.exe | ID = 4000
    Description =

    Error - 8/20/2012 7:27:25 AM | Computer Name = RobertJameson | Source = HPSF.exe | ID = 4000
    Description =

    Error - 8/22/2012 5:08:49 PM | Computer Name = RobertJameson | Source = HPSF.exe | ID = 4000
    Description =

    Error - 9/28/2012 4:23:39 PM | Computer Name = RobertJameson | Source = HPSFMsgr.exe | ID = 4000
    Description = HP Error ID: -2147221164 at System.RuntimeTypeHandle.CreateInstance(RuntimeType
    type, Boolean publicOnly, Boolean noCheck, Boolean& canBeCached, RuntimeMethodHandle&
    ctor, Boolean& bNeedSecurityCheck) at System.RuntimeType.CreateInstanceSlow(Boolean
    publicOnly, Boolean fillCache) at System.RuntimeType.CreateInstanceImpl(Boolean
    publicOnly, Boolean skipVisibilityChecks, Boolean fillCache) at System.Activator.CreateInstance(Type
    type, Boolean nonPublic) at HPSA_Messenger.MessengerCom.TrayDeskBand.isTaskbarDisplayed()
    StackTrace:
    at System.RuntimeTypeHandle.CreateInstance(RuntimeType type, Boolean publicOnly,
    Boolean noCheck, Boolean& canBeCached, RuntimeMethodHandle& ctor, Boolean& bNeedSecurityCheck)
    at System.RuntimeType.CreateInstanceSlow(Boolean publicOnly, Boolean fillCache)
    at System.RuntimeType.CreateInstanceImpl(Boolean publicOnly, Boolean skipVisibilityChecks,
    Boolean fillCache) at System.Activator.CreateInstance(Type type, Boolean nonPublic)
    at HPSA_Messenger.MessengerCom.TrayDeskBand.isTaskbarDisplayed() Source: mscorlib
    Name:
    HPSFMsgr.exe Version: 01.00.00.00 Path: C:\Program Files (x86)\Hewlett-Packard\HP
    Support Framework\Resources\HPSFMessenger\HPSFMsgr.exe Format: en-US RAM: 4063 Ram
    Utilization: 30 TargetSite: System.Object CreateInstance(System.RuntimeType, Boolean,
    Boolean, Boolean ByRef, System.RuntimeMethodHandle ByRef, Boolean ByRef)

    [ Media Center Events ]
    Error - 8/5/2011 9:04:51 AM | Computer Name = RobertJameson | Source = MCUpdate | ID = 0
    Description = 6:04:49 AM - Error connecting to the internet. 6:04:49 AM - Unable
    to contact server..

    Error - 8/5/2011 10:05:32 AM | Computer Name = RobertJameson | Source = MCUpdate | ID = 0
    Description = 7:05:30 AM - Error connecting to the internet. 7:05:30 AM - Unable
    to contact server..

    Error - 8/5/2011 11:07:46 AM | Computer Name = RobertJameson | Source = MCUpdate | ID = 0
    Description = 8:07:44 AM - Error connecting to the internet. 8:07:44 AM - Unable
    to contact server..

    Error - 8/9/2011 9:03:13 PM | Computer Name = RobertJameson | Source = MCUpdate | ID = 0
    Description = 6:03:13 PM - Failed to retrieve MCESpotlight (Error: The operation
    has timed out)

    Error - 8/19/2011 11:05:02 AM | Computer Name = RobertJameson | Source = MCUpdate | ID = 0
    Description = 8:04:53 AM - Error connecting to the internet. 8:04:53 AM - Unable
    to contact server..

    Error - 8/31/2011 8:09:48 AM | Computer Name = RobertJameson | Source = MCUpdate | ID = 0
    Description = 5:09:44 AM - Error connecting to the internet. 5:09:44 AM - Unable
    to contact server..

    Error - 9/14/2011 8:11:52 AM | Computer Name = RobertJameson | Source = MCUpdate | ID = 0
    Description = 5:11:48 AM - Error connecting to the internet. 5:11:48 AM - Unable
    to contact server..

    Error - 9/14/2011 9:12:31 AM | Computer Name = RobertJameson | Source = MCUpdate | ID = 0
    Description = 6:12:31 AM - Error connecting to the internet. 6:12:31 AM - Unable
    to contact server..

    Error - 9/14/2011 10:16:29 AM | Computer Name = RobertJameson | Source = MCUpdate | ID = 0
    Description = 7:16:28 AM - Error connecting to the internet. 7:16:28 AM - Unable
    to contact server..

    Error - 9/14/2011 11:17:08 AM | Computer Name = RobertJameson | Source = MCUpdate | ID = 0
    Description = 8:17:08 AM - Error connecting to the internet. 8:17:08 AM - Unable
    to contact server..

    [ System Events ]
    Error - 10/3/2012 5:48:38 PM | Computer Name = RobertJameson | Source = Application Popup | ID = 1060
    Description = \SystemRoot\SysWow64\drivers\pfc.sys has been blocked from loading
    due to incompatibility with this system. Please contact your software vendor for
    a compatible version of the driver.

    Error - 10/3/2012 5:49:02 PM | Computer Name = RobertJameson | Source = Service Control Manager | ID = 7009
    Description = A timeout was reached (120000 milliseconds) while waiting for the
    Seagate Dashboard Service service to connect.

    Error - 10/3/2012 5:49:02 PM | Computer Name = RobertJameson | Source = Service Control Manager | ID = 7000
    Description = The Seagate Dashboard Service service failed to start due to the following
    error: %%1053

    Error - 10/3/2012 5:49:22 PM | Computer Name = RobertJameson | Source = Service Control Manager | ID = 7026
    Description = The following boot-start or system-start driver(s) failed to load:
    SBRE

    Error - 10/3/2012 5:51:23 PM | Computer Name = RobertJameson | Source = Service Control Manager | ID = 7009
    Description = A timeout was reached (120000 milliseconds) while waiting for the
    Microsoft .NET Framework NGEN v4.0.30319_X86 service to connect.

    Error - 10/3/2012 5:51:35 PM | Computer Name = RobertJameson | Source = Service Control Manager | ID = 7009
    Description = A timeout was reached (120000 milliseconds) while waiting for the
    Intuit Update Service service to connect.

    Error - 10/3/2012 5:51:35 PM | Computer Name = RobertJameson | Source = Service Control Manager | ID = 7000
    Description = The Intuit Update Service service failed to start due to the following
    error: %%1053

    Error - 10/4/2012 3:00:40 PM | Computer Name = RobertJameson | Source = Application Popup | ID = 1060
    Description = \SystemRoot\SysWow64\drivers\pfc.sys has been blocked from loading
    due to incompatibility with this system. Please contact your software vendor for
    a compatible version of the driver.

    Error - 10/4/2012 3:01:21 PM | Computer Name = RobertJameson | Source = Microsoft Antimalware | ID = 2004
    Description = %%860 has encountered an error trying to load signatures and will
    attempt reverting back to a known-good set of signatures. Signatures Attempted: %%824
    Error
    Code: 0x80070002 Error description: The system cannot find the file specified. Signature
    version: 1.137.1001.0;1.137.1001.0 Engine version: 1.1.8800.0

    Error - 10/4/2012 3:01:45 PM | Computer Name = RobertJameson | Source = Service Control Manager | ID = 7026
    Description = The following boot-start or system-start driver(s) failed to load:
    SBRE


    < End of report >
     
  5. gobob

    gobob Thread Starter

    Joined:
    Oct 3, 2012
    Messages:
    25
    OTL Extras logfile created on: 10/5/2012 9:12:04 AM - Run 1
    OTL by OldTimer - Version 3.2.70.2 Folder = C:\Users\Robert Jameson\Desktop
    64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.97 Gb Total Physical Memory | 1.61 Gb Available Physical Memory | 40.63% Memory free
    6.95 Gb Paging File | 4.00 Gb Available in Paging File | 57.50% Paging File free
    Paging file location(s): c:\pagefile.sys 3055 4096 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 282.91 Gb Total Space | 48.80 Gb Free Space | 17.25% Space Free | Partition Type: NTFS
    Drive D: | 298.09 Gb Total Space | 105.78 Gb Free Space | 35.49% Space Free | Partition Type: NTFS
    Drive E: | 14.99 Gb Total Space | 2.46 Gb Free Space | 16.45% Space Free | Partition Type: NTFS
    Drive G: | 465.76 Gb Total Space | 65.35 Gb Free Space | 14.03% Space Free | Partition Type: NTFS

    Computer Name: ROBERTJAMESON | User Name: Robert Jameson | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\SOFTWARE\Classes\<extension>]
    .html [@ = htmlfile] -- Reg Error: Unable to open value key File not found

    ========== Shell Spawning ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Unable to open value key
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Unable to open value key
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Unable to open value key
    Unknown [openas] -- "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
    Directory [AddToPlaylistVLC] -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" ()
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [PlayWithVLC] -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" ()
    Directory [Print_Directory_Listing] -- Printdir.bat "%1" ()
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Unable to open value key
    inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Unable to open value key
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Unable to open value key
    Unknown [openas] -- "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
    Directory [AddToPlaylistVLC] -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" ()
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [PlayWithVLC] -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" ()
    Directory [Print_Directory_Listing] -- Printdir.bat "%1" ()
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
    "9000:TCP" = 9000:TCP:*:Enabled:Logitech Media Server 9000 tcp (UI)
    "9001:TCP" = 9001:TCP:*:Enabled:Logitech Media Server 9001 tcp (UI)
    "9002:TCP" = 9002:TCP:*:Enabled:Logitech Media Server 9002 tcp (UI)
    "9003:TCP" = 9003:TCP:*:Enabled:Logitech Media Server 9003 tcp (UI)
    "9004:TCP" = 9004:TCP:*:Enabled:Logitech Media Server 9004 tcp (UI)
    "9005:TCP" = 9005:TCP:*:Enabled:Logitech Media Server 9005 tcp (UI)
    "9006:TCP" = 9006:TCP:*:Enabled:Logitech Media Server 9006 tcp (UI)
    "9007:TCP" = 9007:TCP:*:Enabled:Logitech Media Server 9007 tcp (UI)
    "9008:TCP" = 9008:TCP:*:Enabled:Logitech Media Server 9008 tcp (UI)
    "9009:TCP" = 9009:TCP:*:Enabled:Logitech Media Server 9009 tcp (UI)
    "9010:TCP" = 9010:TCP:*:Enabled:Logitech Media Server 9010 tcp (UI)
    "9100:TCP" = 9100:TCP:*:Enabled:Logitech Media Server 9100 tcp (UI)
    "8000:TCP" = 8000:TCP:*:Enabled:Logitech Media Server 8000 tcp (UI)
    "10000:TCP" = 10000:TCP:*:Enabled:Logitech Media Server 10000 tcp (UI)
    "9090:TCP" = 9090:TCP:*:Enabled:Logitech Media Server 9090 tcp (UI)
    "3483:UDP" = 3483:UDP:*:Enabled:Logitech Media Server 3483 udp
    "3483:TCP" = 3483:TCP:*:Enabled:Logitech Media Server 3483 tcp

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
    "9000:TCP" = 9000:TCP:*:Enabled:Logitech Media Server 9000 tcp (UI)
    "9001:TCP" = 9001:TCP:*:Enabled:Logitech Media Server 9001 tcp (UI)
    "9002:TCP" = 9002:TCP:*:Enabled:Logitech Media Server 9002 tcp (UI)
    "9003:TCP" = 9003:TCP:*:Enabled:Logitech Media Server 9003 tcp (UI)
    "9004:TCP" = 9004:TCP:*:Enabled:Logitech Media Server 9004 tcp (UI)
    "9005:TCP" = 9005:TCP:*:Enabled:Logitech Media Server 9005 tcp (UI)
    "9006:TCP" = 9006:TCP:*:Enabled:Logitech Media Server 9006 tcp (UI)
    "9007:TCP" = 9007:TCP:*:Enabled:Logitech Media Server 9007 tcp (UI)
    "9008:TCP" = 9008:TCP:*:Enabled:Logitech Media Server 9008 tcp (UI)
    "9009:TCP" = 9009:TCP:*:Enabled:Logitech Media Server 9009 tcp (UI)
    "9010:TCP" = 9010:TCP:*:Enabled:Logitech Media Server 9010 tcp (UI)
    "9100:TCP" = 9100:TCP:*:Enabled:Logitech Media Server 9100 tcp (UI)
    "8000:TCP" = 8000:TCP:*:Enabled:Logitech Media Server 8000 tcp (UI)
    "10000:TCP" = 10000:TCP:*:Enabled:Logitech Media Server 10000 tcp (UI)
    "9090:TCP" = 9090:TCP:*:Enabled:Logitech Media Server 9090 tcp (UI)
    "3483:UDP" = 3483:UDP:*:Enabled:Logitech Media Server 3483 udp
    "3483:TCP" = 3483:TCP:*:Enabled:Logitech Media Server 3483 tcp

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    ========== Authorized Applications List ==========


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{06F18693-4CEF-4388-9F45-151EDB72C284}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{091B6ADD-B200-43FD-99D7-ED330B05CCF1}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{0DC2FCE2-6036-4155-90F0-40ACD79AA707}" = lport=5353 | protocol=17 | dir=in | name=bonjour |
    "{0F82B244-AA45-4B6B-9FD3-3824BB96F1C3}" = lport=10243 | protocol=6 | dir=in | app=system |
    "{19372D23-DE32-4A0D-A86F-A8E83BE71545}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{1A141CFB-9A83-46DF-88F9-FA713E7569ED}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
    "{1AAAB694-745C-41A3-95F3-8E6B0D641A30}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
    "{20D541CF-8BAE-4438-946A-A29FCF40542E}" = rport=10243 | protocol=6 | dir=out | app=system |
    "{21D1B5D7-BC40-43BC-BCCA-5C7079FE55D6}" = lport=138 | protocol=17 | dir=in | app=system |
    "{2F312D1E-1F49-41A0-95C4-E6DE50E14C4D}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
    "{30000E25-A558-471E-B83B-B1426CF6C41F}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe |
    "{498BC124-8BFE-4BA1-A96E-FE4B07E9A90D}" = rport=138 | protocol=17 | dir=out | app=system |
    "{4D9805E1-E219-48EE-8C61-F1792E0AB19C}" = lport=445 | protocol=6 | dir=in | app=system |
    "{5726B361-100F-45EE-9141-C607EFE21A89}" = rport=80 | protocol=6 | dir=out | app=c:\program files (x86)\common files\intuit\update service\intuitupdater.exe |
    "{583CE2F0-BA6E-439B-B5F6-D74AF3579D69}" = lport=54925 | protocol=17 | dir=in | name=brothernetwork scanner |
    "{5D76D739-2BC9-440D-8281-01BCC34CB274}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{634C6699-060E-45D8-B870-124E9109AA90}" = rport=139 | protocol=6 | dir=out | app=system |
    "{6842D4E3-B867-4546-A4C3-4CA661D010FD}" = rport=2869 | protocol=6 | dir=out | app=system |
    "{686562DB-98D1-4B70-85BE-B79D7F95F0A5}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{6B1D499E-B9D9-4488-BB10-E16BA06FFA8E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{75711528-3D24-4159-8263-53EB677799C6}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{7B1E8344-E58E-4584-8672-3C508BA7ABB1}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{8313FC60-2FAF-44DA-9605-B524A2D1F2F0}" = rport=445 | protocol=6 | dir=out | app=system |
    "{8B9B3E25-2AD3-4030-92BA-626385B598AA}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
    "{99792EC1-F1B8-4D21-A5BB-E831631D3A35}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{9CF94812-0010-431E-98D9-101C7562DE7D}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{A32E0932-9803-488C-9E6E-A4CF697352B4}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{B5DB8C13-90B7-426C-9DB9-93F7007047C2}" = lport=139 | protocol=6 | dir=in | app=system |
    "{BEAC55F0-2EF4-4968-A8EF-56922E2988B0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{C071848F-B46E-43C1-84E5-EAD7D1AAA41E}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{C20A84E9-736D-4FF3-ADB9-E87C5962D92E}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
    "{C8BB6A96-A0F0-4BBE-8D68-D2ED81A3F788}" = lport=137 | protocol=17 | dir=in | app=system |
    "{CCB8107A-7436-474E-96BD-D234D4C25286}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{D4BC4E01-95AD-4F87-B2D1-03CEF66CF531}" = rport=137 | protocol=17 | dir=out | app=system |
    "{D6AEEF31-82DB-4667-802C-C79422FA33BB}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
    "{D835E0C5-AE18-4D49-AB8F-45D6F40EF375}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{E0785E81-DB96-4DAC-9188-8E9E131867D0}" = rport=80 | protocol=6 | dir=out | app=c:\program files (x86)\common files\intuit\update service\intuitupdateservice.exe |
    "{E09D851D-0EE9-4423-B9F9-F23BEA0A2509}" = lport=5353 | protocol=17 | dir=in | name=bonjour |
    "{E7E2C00D-D80C-485D-B85F-8454B478D527}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
    "{EA054ABE-89C5-4827-90D4-AB1C6244D4C9}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
    "{EB083B66-10F4-4379-A12A-FD4859495418}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{F1AE7F7B-5939-48FB-A245-D04539CC3F34}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{F556F175-BBB1-429A-8409-8A70B3552298}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
    "{F847D0BF-72BD-420F-8408-3E06BD5C7B88}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{FCEAE1E1-13ED-4BA6-91EE-4A7CDFF47055}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
    "{FFDD649E-C5B5-4100-AB0A-2F716F4FB107}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{05824789-8B8D-4744-B8E2-1B1BA0A6F3C8}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
    "{06FAA491-9B8C-4A68-A1AB-3757CBC929D1}" = protocol=17 | dir=out | app=hpqtra08.exe |
    "{0F898A09-A5AA-4DE4-B231-0463A0698745}" = protocol=6 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe |
    "{12063129-C66E-4738-BE38-69A4EB2524B5}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
    "{1BAF6E9F-C6F4-431F-8ABF-6257A35764F5}" = protocol=17 | dir=in | app=hpqste08.exe |
    "{1D326CF3-6047-4AEB-B433-FE726DB14966}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
    "{1F4D042B-5F4A-4EE2-839F-ACBC28DAD8CD}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartmusic.exe |
    "{20C482D5-500A-429E-BD42-C22FF50FDE43}" = protocol=6 | dir=out | app=hpqste08.exe |
    "{229A3CA7-B979-487E-A726-D26A79F656FD}" = protocol=17 | dir=in | app=hpqkygrp.exe |
    "{23094CA7-2D41-4755-975B-5756ADE76341}" = protocol=6 | dir=out | app=hpqthb08.exe |
    "{24DBF4BA-E2DE-400D-8273-60BC55F0DA72}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{2503AA0F-F0DF-4F5B-B4AB-302A424645DA}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{2A28F728-FCA7-4D79-9391-930E65FB903A}" = dir=in | app=c:\program files (x86)\seagate\seagate dashboard\hipservagent\hipservagent.exe |
    "{2B479050-9628-4C65-9435-21466FCF1C7C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{33E5BBB8-156E-4105-93E6-3623279E3040}" = protocol=17 | dir=in | app=hpqscnvw.exe |
    "{3625D67E-A01F-4BBA-ACE5-AF9E85D63088}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{38D17AAC-803F-483C-A572-33E4C3079FF9}" = protocol=6 | dir=out | app=hpqscnvw.exe |
    "{3F21F00E-4B92-4E52-9744-7E33EBE28E1C}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartvideo.exe |
    "{407D341D-B957-4784-8292-1A8A639EB2BF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{40B8EA92-B7A8-42E8-9EDA-A2AD85AEC696}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\tsmagent.exe |
    "{41572B15-105B-4828-94AE-B7005D69DFC3}" = protocol=17 | dir=in | app=c:\program files (x86)\bucksbee loyalty plugin - 100815\troubleshooter.exe |
    "{4F08DE23-A528-43A8-9E83-493422A5C06F}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
    "{527479CC-2BC7-467F-A2B6-A2011E221E88}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{5BBDDA1E-5C73-40DF-A785-28889610D3CD}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{6AA0DEE0-4A1B-419E-8163-0345F4EC4CE5}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{74DAABAD-F241-4F13-8718-7FFF28E0B29D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{7DC88F2F-9BDF-4289-A898-695EBDEEC481}" = protocol=6 | dir=in | app=c:\program files (x86)\brother\brmfl11a\faxrx.exe |
    "{7FD53A80-1CA0-4D95-9F24-2657F14FBCF7}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe |
    "{903A76BF-701A-488B-A415-334EDE157A7C}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
    "{9282588D-8CF3-4FAB-B6E8-752A225548B4}" = protocol=6 | dir=in | app=hpqtra08.exe |
    "{966B6742-008F-4EED-BA3D-9507880CFE31}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{99DE5DBC-648F-4AFF-A685-F251D8F3F85E}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{9AD0C48C-0763-483A-8D9C-593EE252B354}" = protocol=17 | dir=out | app=hpqkygrp.exe |
    "{9B825B49-9B8E-4186-8A96-CAD27A63341B}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{9E0EC6DC-E662-466D-9718-E80B38121E3D}" = protocol=17 | dir=out | app=hpqscnvw.exe |
    "{A524025A-C82E-4910-9016-7D4A35B2611E}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
    "{A9922D2C-7AD6-4436-962F-C64DEC6C72F9}" = protocol=17 | dir=in | app=c:\program files (x86)\bittorrent\bittorrent.exe |
    "{B22CAFA7-F66A-4CF4-8940-E8850507936C}" = protocol=17 | dir=out | app=hpqthb08.exe |
    "{B6F08B06-8F8B-4535-AA79-F7882FC4A319}" = dir=in | app=c:\program files (x86)\file type assistant\tsassist.exe |
    "{BA1065B5-7D29-4F67-9EF2-756E0FC67FF6}" = dir=in | app=c:\program files (x86)\hp\digital imaging\{71c4f928-136a-4222-a191-310e081fb96b}\setup\hpznui40.exe |
    "{BBC679F5-FDFC-4BD6-8D49-254C36B75B0C}" = protocol=6 | dir=in | app=c:\program files (x86)\bucksbee loyalty plugin - 100815\troubleshooter.exe |
    "{BC916E58-A83F-485B-99AE-7E810A7F836E}" = protocol=17 | dir=out | app=hpqste08.exe |
    "{BE0C5131-FFB6-4696-BFD1-17555F3655F6}" = protocol=6 | dir=in | app=c:\program files (x86)\airport\apagent.exe |
    "{C54FA0EE-312D-46DC-898A-DB2D6EF37363}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
    "{C5DF2BFD-DE63-4B23-96D7-8598BB2A7D62}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{C797CEBA-1427-46A5-B327-BD3FA6217C65}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
    "{C7FBAC53-B56A-4466-93C7-B7C38261D6DF}" = protocol=6 | dir=out | app=hpqkygrp.exe |
    "{CFFC2EC7-4C48-4198-A5EE-7F4CF4958DB9}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{D05A738B-2FBA-4F2E-93F8-282664BD15BE}" = dir=in | app=c:\program files (x86)\squeezebox\server\squeezesvr.exe |
    "{D090ADDB-7438-46CF-913F-BED7BF03E5D0}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
    "{D10960BC-52F6-4E39-B804-90706F099377}" = protocol=6 | dir=out | app=hpqtra08.exe |
    "{D413E600-6775-4111-B18E-A0835319DC74}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{D9569398-3707-447C-A534-70CFC7D8B3A2}" = protocol=6 | dir=in | app=hpqthb08.exe |
    "{DB054F91-3253-40BA-ACFE-4D92C7861EED}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{DCE315AB-84A8-4369-B1FB-5B99917F5C4F}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
    "{DDD7F443-E5AB-4E4D-B1EF-D65CDDF92F57}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{DEF21E8B-3A15-47D7-AB92-D0619A4A8392}" = protocol=6 | dir=in | app=hpqste08.exe |
    "{E055DBD0-4F28-4944-ACE8-E1AE85D99694}" = protocol=6 | dir=in | app=hpqkygrp.exe |
    "{E09DC2EE-E94D-4144-B28A-DDC8CFD00C2B}" = protocol=6 | dir=in | app=hpqscnvw.exe |
    "{E2E4F49E-B5DA-4807-83D0-061114CB445D}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
    "{E60C535D-2B32-461B-B876-2C1794E6A6DE}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
    "{E85735E7-42BA-4E1C-AAE4-031922EFE702}" = protocol=17 | dir=in | app=hpqtra08.exe |
    "{EB1C32AF-552F-446A-BB84-50598ED18C22}" = protocol=6 | dir=out | app=system |
    "{EEAD645E-5FDF-4C3E-BA1F-3A7097F305E1}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{F0A6C869-D911-4935-B6C8-A68DA5CF6CE7}" = protocol=17 | dir=in | app=c:\program files (x86)\brother\brmfl11a\faxrx.exe |
    "{F3C26343-C75F-4930-9C58-F661DF206C92}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\clml\clmlsvc.exe |
    "{F649E565-8390-4333-8B53-63D9181FF110}" = protocol=17 | dir=in | app=hpqthb08.exe |
    "{FA92E273-F93B-4C18-957A-78ABA300A46C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
    "TCP Query User{08094D2A-7AAC-4550-B3F4-85C1B2E2829E}C:\program files (x86)\encore\hoyle casino 2009\hoyle casino.exe" = protocol=6 | dir=in | app=c:\program files (x86)\encore\hoyle casino 2009\hoyle casino.exe |
    "TCP Query User{12C03CD4-2085-475A-AB5F-8495CC679E24}C:\program files\schwab\sspro\sspro.exe" = protocol=6 | dir=in | app=c:\program files\schwab\sspro\sspro.exe |
    "TCP Query User{5E020459-7BA2-45F7-8C31-F6155E0D4889}C:\program files\schwab\sspro\sspro.exe" = protocol=6 | dir=in | app=c:\program files\schwab\sspro\sspro.exe |
    "TCP Query User{64E9B47B-C2B7-4CF2-B14D-968D7078998C}C:\program files (x86)\airport\aputil.exe" = protocol=6 | dir=in | app=c:\program files (x86)\airport\aputil.exe |
    "TCP Query User{B4783208-C5CE-43A9-8667-3EBE6CEAE65D}C:\program files (x86)\myihome\app\myihome-server.exe" = protocol=6 | dir=in | app=c:\program files (x86)\myihome\app\myihome-server.exe |
    "TCP Query User{D1B97AEB-D3D8-4F48-B9CF-4E8557089D02}C:\program files (x86)\airport\aputil.exe" = protocol=6 | dir=in | app=c:\program files (x86)\airport\aputil.exe |
    "TCP Query User{E3FBE50B-FFF9-4F32-B273-A87C81681DD5}C:\program files (x86)\nero\nero 9\nero showtime\showtime.exe" = protocol=6 | dir=in | app=c:\program files (x86)\nero\nero 9\nero showtime\showtime.exe |
    "TCP Query User{FA452F4C-F454-481A-AAAD-355C49FFF4E7}C:\program files (x86)\myihome\app\myihome-server.exe" = protocol=6 | dir=in | app=c:\program files (x86)\myihome\app\myihome-server.exe |
    "UDP Query User{03BB4DAA-E55F-4F94-98F9-DF83EEBB8D9B}C:\program files (x86)\myihome\app\myihome-server.exe" = protocol=17 | dir=in | app=c:\program files (x86)\myihome\app\myihome-server.exe |
    "UDP Query User{0710FBAD-2F2E-42E9-980B-C5EBA33A24F4}C:\program files (x86)\nero\nero 9\nero showtime\showtime.exe" = protocol=17 | dir=in | app=c:\program files (x86)\nero\nero 9\nero showtime\showtime.exe |
    "UDP Query User{209E0C67-A40E-447C-A7AC-DA1C062A46BB}C:\program files\schwab\sspro\sspro.exe" = protocol=17 | dir=in | app=c:\program files\schwab\sspro\sspro.exe |
    "UDP Query User{2ABC622A-FC0C-47C8-875B-626A8F939EB7}C:\program files (x86)\encore\hoyle casino 2009\hoyle casino.exe" = protocol=17 | dir=in | app=c:\program files (x86)\encore\hoyle casino 2009\hoyle casino.exe |
    "UDP Query User{5C083AA3-B082-4E4D-98A0-8188608DE75D}C:\program files (x86)\airport\aputil.exe" = protocol=17 | dir=in | app=c:\program files (x86)\airport\aputil.exe |
    "UDP Query User{98BFC357-3A52-4C6A-8D54-2DC10442689C}C:\program files\schwab\sspro\sspro.exe" = protocol=17 | dir=in | app=c:\program files\schwab\sspro\sspro.exe |
    "UDP Query User{C9A2FBD7-97B2-40EE-8404-42038040DF89}C:\program files (x86)\myihome\app\myihome-server.exe" = protocol=17 | dir=in | app=c:\program files (x86)\myihome\app\myihome-server.exe |
    "UDP Query User{E59A742C-780F-4183-AA93-9A984A639CC3}C:\program files (x86)\airport\aputil.exe" = protocol=17 | dir=in | app=c:\program files (x86)\airport\aputil.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{16AD84C0-E7A0-F64D-D55A-15D274C4439A}" = ccc-utility64
    "{26A24AE4-039D-4CA4-87B4-2F86416014FF}" = Java(TM) 6 Update 14 (64-bit)
    "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
    "{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}" = Apple Mobile Device Support
    "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{6DD01FF3-63CE-436B-96DB-61363EAA4EB8}" = MobileMe Control Panel
    "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
    "{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}" = PaperPort Image Printer 64-bit
    "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
    "{83715090-142B-D305-36EC-7538A007D336}" = ATI Catalyst Install Manager
    "{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes
    "{85A42FF0-F0D0-44A3-B226-C124D6E8B1D5}" = HP 3D DriveGuard
    "{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.02
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8B485965-8EFE-464A-842F-CF8F18C3DFD7}" = iCloud
    "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
    "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
    "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
    "{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}" = Microsoft Security Client
    "{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = HP Integrated Module with Bluetooth wireless technology
    "{A3B12CDE-4385-41CF-B0C7-BC1BF29EC93D}" = HP MediaSmart SmartMenu
    "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{AEF6C676-D7A2-4487-BD4B-1BED17B229B5}" = Microsoft Mouse and Keyboard Center
    "{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
    "{B820C985-D9F1-45B5-A7F5-0C5863CBEA04}_is1" = Privacy SafeGuard version 1.1
    "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
    "{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
    "A-WIN-WTB 1.0.0 1269103_is1" = Wolfram Toolbar 1.0 (1269103)
    "CCleaner" = CCleaner
    "FFE7D41DF3C645075BB149E21988B63996C34187" = ENE CIR Receiver Driver
    "LSI Soft Modem" = LSI HDA Modem
    "MediaInfo" = MediaInfo 0.7.27
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
    "Microsoft Mouse and Keyboard Center" = Microsoft Mouse and Keyboard Center
    "Microsoft Security Client" = Microsoft Security Essentials
    "OfficeTrial" = Microsoft Office Home and Student 60 day trial
    "Recuva" = Recuva
    "SynTPDeinstKey" = Synaptics Pointing Device Driver

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
    "{026AAEDB-AAF9-497D-806D-B5FE75264F6D}" = Songverter
    "{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}" = Scansoft PDF Professional
    "{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
    "{0F5ADA2F-C0B2-4AD6-8FF7-7DFA9D6B4CBA}" = FreeUndelete 2.1.36867.1
    "{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
    "{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
    "{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
    "{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
    "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
    "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
    "{23170F69-40C1-2701-0921-000001000000}" = 7-Zip 9.21
    "{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
    "{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron Flash Media Controller Driver
    "{266D0EEA-E5A6-4A08-A0EE-5391D4EA44A7}" = Catalyst Control Center - Branding
    "{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java(TM) 6 Update 31
    "{27B0C2FD-9739-8D7D-6552-307C786D9097}" = Catalyst Control Center InstallProxy
    "{28656860-4728-433C-8AD4-D1A930437BC8}" = Nuance PDF Viewer Plus
    "{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
    "{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
    "{2EBA8202-FBD5-4004-81EA-BDC38C054CE2}" = HP User Guides 0153
    "{3023EBDA-BF1B-4831-B347-E5018555F26E}" = HP MediaSmart Movie Themes
    "{33CF58F5-48D8-4575-83D6-96F574E4D83A}" = Nero DriveSpeed
    "{349A5E6B-EE96-48B5-85DA-85F782CF51B0}" = Karaoke Home Producer
    "{359CFC0A-BEB1-440D-95BA-CF63A86DA34F}" = Nero Recode
    "{360EDFB0-EAA2-012B-AD16-000000000000}" = TurboTax 2009 wcaiper
    "{368BA326-73AD-4351-84ED-3C0A7A52CC53}" = Nero Rescue Agent
    "{3744B641-61DE-417F-BCDC-9CCED4224DF8}" = LightScribe System Software
    "{38022B5C-0C69-389F-DA48-B87480B5705A}" = CCC Help Turkish
    "{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
    "{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
    "{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
    "{38A3B04E-9AC9-4AB4-B72C-94A259EF622B}" = Keyrite
    "{3BBBF379-6C7E-0985-18F6-6C60D6C36EC6}" = CCC Help Portuguese
    "{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
    "{3E7F5E50-6956-4446-87BF-F422A8736B7F}" = Secure Online Account Numbers
    "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
    "{4313E16C-811B-469F-8815-6EB98085F8B2}" = SlingBoxWatchYourTVAnyWhere
    "{43E39830-1826-415D-8BAE-86845787B54B}" = Nero Vision
    "{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = PowerRecover
    "{48AC1C1D-5C35-41BC-B66B-E4A4A2C29BD9}" = Vogone
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4B2F56AC-C043-C84F-3EF1-E6D6F21E934F}" = Catalyst Control Center Graphics Full Existing
    "{4F2C2E34-5A3E-0E70-BDFC-A5B1E3C2FFAC}" = Catalyst Control Center Graphics Light
    "{532715CE-CFD6-E4F8-53C3-2F1DE31C04DA}" = CCC Help Hungarian
    "{5543C9C8-4F56-4E84-BD4F-454942043964}" = Microstudio
    "{558CC8A3-F1A2-9C31-7B90-F61E476B8622}" = CCC Help Dutch
    "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
    "{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress
    "{5D76ABD5-262B-6D65-6C13-F38175C7A5AF}" = CCC Help Korean
    "{5D92E608-E454-0C8C-D577-7F7C06151117}" = CCC Help Greek
    "{612AD33D-9824-4E87-8396-92374E91C4BB}_is1" = Inbox Toolbar
    "{62AC81F6-BDD3-4110-9D36-3E9EAAB40999}" = Nero CoverDesigner
    "{65980EBF-C4B5-4555-823A-94DB7F709E53}" = Secure Online Account Numbers
    "{664708B3-C730-11D5-ADE7-00B0D07D157A}" = StreetSmart Pro
    "{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart Live TV
    "{6C0A559F-8583-4B5A-8B50-20BEE15D8E64}" = Nuance PaperPort 12
    "{6D172D0A-B9F1-4046-AFAB-8599288545BF}" = Safari
    "{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.2.0
    "{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}" = HP Support Assistant
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
    "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    "{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
    "{7829DB6F-A066-4E40-8912-CB07887C20BB}" = Nero BurnRights
    "{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
    "{786CF17A-66A5-4A35-B24A-178D3B39F86A}_is1" = Womble EasyDVD 1.0.1.26 (07/2011)
    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
    "{79EECA21-CDFA-6012-5E8B-6CF2623D647A}" = Catalyst Control Center Graphics Full New
    "{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
    "{7BE6BC10-6737-CD9D-8363-F919B8D6D917}" = Catalyst Control Center Core Implementation
    "{80FBA7A7-ABD1-4910-A916-023075C45593}" = CCC Help Danish
    "{82A213BD-B6AA-4281-A2D3-59D51893CC56}" = HP MediaSmart Software Notebook Demo
    "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110265407}" = Bejeweled 2 Deluxe
    "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
    "{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
    "{869200DB-287A-4DC0-B02B-2B6787FBCD4C}" = Nero DiscSpeed
    "{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
    "{8797DE34-22BC-CA33-6B67-A0CC2765B545}" = CCC Help German
    "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver
    "{89D1C17B-90DE-650A-073A-A7FA7BC6ECE5}" = CCC Help French
    "{8C664716-FD23-9902-A29E-863D056F46FC}" = CCC Help Russian
    "{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
    "{8F36B221-F483-B7CE-4DDA-7BDA4D81E306}" = CCC Help English
    "{8FB16749-1235-D027-AF25-1D22A9FEC0D5}" = CCC Help Thai
    "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
    "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
    "{90F6051D-A69F-4159-9203-7E20430E1056}" = HP MediaSmart SlingPlayer
    "{91130409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
    "{91A3A4DE-656A-5C7A-5B61-75FB6D167A6A}" = CCC Help Polish
    "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{9C411DC9-B8B8-45F3-B688-073BF4B59094}" = Virtual Account Numbers
    "{9D318C86-AF4C-409F-A6AC-7183FF4CF424}" = Internet TV for Windows Media Center
    "{9E82B934-9A25-445B-B8DF-8012808074AC}" = Nero PhotoSnap
    "{9EDB805A-E11C-8842-2393-FDFDA17963AC}" = CCC Help Chinese Traditional
    "{A16D1BBD-BE86-0183-4152-2E85FECC31F7}" = CCC Help Finnish
    "{A19856E3-C9D7-988E-5B8C-70C87342B8DD}" = Catalyst Control Center Localization All
    "{A1B36B88-AF90-43A3-8906-6DBEE89B4FBD}" = Brother MFL-Pro Suite MFC-J835DW
    "{A209525B-3377-43F4-B886-32F6B6E7356F}" = Nero WaveEditor
    "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
    "{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{AA68AAAE-41F0-40B5-8896-5947F5FD6889}" = AirPort
    "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
    "{AD777154-A573-4FCA-C730-D7C33437262C}" = CCC Help Czech
    "{AF72E557-0647-4DE5-ACDA-ECFB38D5D732}" = Licensing Service Install
    "{B1ADF008-E898-4FE2-8A1F-690D9A06ACAF}" = DolbyFiles
    "{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
    "{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
    "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
    "{B66D2CC9-652D-EBE5-497F-74BBC1029FB4}" = CCC Help Japanese
    "{B6A4D07E-725F-07CD-DE49-8AB76939631D}" = CCC Help Norwegian
    "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
    "{B74D4E10-6884-0000-0000-000000000103}" = Adobe Bridge 1.0
    "{B78120A0-CF84-4366-A393-4D0A59BC546C}" = Menu Templates - Starter Kit
    "{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
    "{BEC98926-4238-4846-A2E3-56A96B217BDD}" = Hoster
    "{BF930A5D-4F36-5158-C8DA-DECD5B51A78E}" = CCC Help Chinese Standard
    "{C3A11907-930D-41AC-A135-CC3B12F92011}" = Seagate Dashboard
    "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
    "{C5A7CB6C-E76D-408F-BA0E-85605420FE9D}" = SoundTrax
    "{c5d5a1f0-7106-4d53-9486-0d86f9f4a764}" = Nero 9
    "{C6FCE95C-0072-40C0-9AB2-3EF88DA6CED9}" = Catalyst Control Center Graphics Previews Common
    "{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
    "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
    "{CCF6F57B-F6B4-4508-BF45-63AAC9DE416A}" = Quicken 2010
    "{D025A639-B9C9-417D-8531-208859000AF8}" = NeroBurningROM
    "{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
    "{D9DCF92E-72EB-412D-AC71-3B01276E5F8B}" = Nero ShowTime
    "{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
    "{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
    "{DE700910-58F7-4D2E-B7E6-3BA2DA1B6806}" = Virtual Account Numbers
    "{DF166A93-835F-DF13-E974-FD73E8D7F4F6}" = CCC Help Swedish
    "{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar
    "{E09F7D2B-C1C1-D80B-7775-6FFE9D713C60}" = CCC Help Spanish
    "{E26EEBF8-3A50-8095-5877-AE243C8852EF}" = Catalyst Control Center Graphics Previews Vista
    "{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
    "{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
    "{E498385E-1C51-459A-B45F-1721E37AA1A0}" = Movie Templates - Starter Kit
    "{E553760D-D7F7-48BF-BD8B-C7E23BA04CB5}" = HP MediaSmart Internet TV
    "{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
    "{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
    "{EC8049FF-B0E3-A963-408C-1B1D8F20DD55}" = CCC Help Italian
    "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
    "{F0FDF9C9-1DDC-401F-B638-36F1CAE8A875}" = VideoStudio
    "{F1861F30-3419-44DB-B2A1-C274825698B3}" = Nero Disc Copy Gadget
    "{F1D7AC58-554A-4A58-B784-B61558B1449A}" = QLBCASL
    "{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
    "{F9A43C0C-F274-4EC0-B02E-202C15C09C00}" = HP Wireless Assistant
    "{FBCDFD61-7DCF-4E71-9226-873BA0053139}" = Nero InfoTool
    "{FD1D88FA-E5E0-BA76-73C8-7362E9703842}" = ccc-core-static
    "1Click DVD Copy Pro_is1" = 1Click DVD Copy Pro 4.1.7.0
    "Ad-Aware Browsing Protection" = Ad-Aware Browsing Protection
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
    "Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
    "Audacity_is1" = Audacity 1.2.6
    "BitTorrent" = BitTorrent
    "Bucksbee Loyalty Plugin - 100815" = Bucksbee Loyalty Plugin - 100815
    "ChampHearts" = Championship Hearts All-Stars 7.40
    "conduitEngine" = Conduit Engine
    "Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
    "D-Link Toolbar" = D-Link Toolbar
    "DVDFab 8 Qt_is1" = DVDFab 8.2.1.0 (07/09/2012) Qt
    "DVDFab 8_is1" = DVDFab 8.0.8.5 (19/03/2011)
    "EarthDesk" = EarthDesk
    "eSupport UndeletePlus_is1" = eSupport UndeletePlus 3.0.2.1214
    "Freecorder4.1" = Freecorder
    "Hardware Helper_is1" = Hardware Helper
    "Homepage Protection" = Homepage Protection
    "Hoyle Casino 2009" = Hoyle Casino 2009
    "ieSpell" = ieSpell
    "ImgBurn" = ImgBurn
    "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
    "InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
    "InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = HP MediaSmart Movie Themes
    "InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
    "InstallShield_{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart Live TV
    "InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
    "InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
    "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
    "InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
    "InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
    "InstallShield_{E553760D-D7F7-48BF-BD8B-C7E23BA04CB5}" = HP MediaSmart Internet TV
    "InstallShield_{F0FDF9C9-1DDC-401F-B638-36F1CAE8A875}" = Corel VideoStudio 12
    "iPhoneBackupExtractor" = iPhone Backup Extractor
    "iSkysoft DVD Ripper_is1" = iSkysoft DVD Ripper(Build 2.3.4.0)
    "jZip" = jZip
    "LAME for Audacity_is1" = LAME v3.98.2 for Audacity
    "MakeMKV" = MakeMKV v1.5.6_beta
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.0.1400
    "myiHome_is1" = myiHome v5.1.4
    "Playbryte" = PlayBryte
    "Productivity_3 Toolbar" = Productivity 3 Toolbar
    "Rocket Division Software Grab & Burn_is1" = Grab & Burn, Version 4.0.1 ( Build 2005-09-21, Win32, CSS )
    "SimpUtil_Maps_1 Toolbar" = SimpUtil Maps 1 Toolbar
    "sl-adk" = SelectionLinks
    "SMPlayer" = SMPlayer 0.6.7
    "SoftwareUpdUtility" = Download Updater (AOL LLC)
    "SoundTaxi_is1" = SoundTaxi 3.9.4
    "STMediaSuite" = SoundTaxi Media Suite 3.9.4
    "Trusted Software Assistant_is1" = File Type Assistant
    "TurboTax 2009" = TurboTax 2009
    "Tweaks FileOpener" = FileOpener
    "VLC media player" = VLC media player 0.9.2
    "WildTangent hp Master Uninstall" = HP Games
    "Windows Media Encoder 9" = Windows Media Encoder 9 Series
    "Womble EasyDVD" = Womble EasyDVD 1.0.1.26 (07/2011)
    "Yahoo! Companion" = Yahoo! Toolbar
    "Yahoo! Software Update" = Yahoo! Software Update
    "YInstHelper" = Yahoo! Install Manager

    ========== Last 20 Event Log Errors ==========

    [ Application Events ]
    Error - 10/2/2012 3:34:13 AM | Computer Name = RobertJameson | Source = SideBySide | ID = 16842815
    Description = Activation context generation failed for "c:\Program Files (x86)\Common
    Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
    Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
    "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
    "version" in element "assemblyIdentity" is invalid.

    Error - 10/3/2012 3:34:43 AM | Computer Name = RobertJameson | Source = SideBySide | ID = 16842815
    Description = Activation context generation failed for "c:\Program Files (x86)\Common
    Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
    Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
    "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
    "version" in element "assemblyIdentity" is invalid.

    Error - 10/3/2012 2:17:04 PM | Computer Name = RobertJameson | Source = Application Error | ID = 1000
    Description = Faulting application name: iexplore.exe, version: 9.0.8112.16450,
    time stamp: 0x503723f6 Faulting module name: Toolbar.dll, version: 3.1.0.0, time
    stamp: 0x4f5a80de Exception code: 0xc0000005 Fault offset: 0x0002a8c2 Faulting process
    id: 0xecc Faulting application start time: 0x01cda19309f808db Faulting application
    path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
    C:\Users\Robert Jameson\AppData\LocalLow\FCTB000100815\Toolbar\Toolbar.dll Report
    Id: 886877ee-0d86-11e2-b688-0027134ffaa6

    Error - 10/3/2012 2:35:49 PM | Computer Name = RobertJameson | Source = Application Error | ID = 1000
    Description = Faulting application name: BtStackServer.exe, version: 6.2.0.9602,
    time stamp: 0x4a723b26 Faulting module name: BtStackServer.exe, version: 6.2.0.9602,
    time stamp: 0x4a723b26 Exception code: 0xc0000005 Fault offset: 0x000000000014c6b7
    Faulting
    process id: 0xd04 Faulting application start time: 0x01cda192f53daffa Faulting application
    path: C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe Faulting module
    path: C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe Report Id: 26ef1f77-0d89-11e2-b688-0027134ffaa6

    Error - 10/3/2012 2:50:00 PM | Computer Name = RobertJameson | Source = Application Hang | ID = 1002
    Description = The program jre-6u35-windows-i586-iftw.exe version 6.0.350.10 stopped
    interacting with Windows and was closed. To see if more information about the problem
    is available, check the problem history in the Action Center control panel. Process
    ID: 9c4 Start Time: 01cda193c5c7249b Termination Time: 15 Application Path: C:\Users\ROBERT~1\AppData\Local\Temp\jre-6u35-windows-i586-iftw.exe
    Report
    Id:

    Error - 10/4/2012 3:34:58 AM | Computer Name = RobertJameson | Source = SideBySide | ID = 16842815
    Description = Activation context generation failed for "c:\Program Files (x86)\Common
    Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
    Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
    "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
    "version" in element "assemblyIdentity" is invalid.

    Error - 10/4/2012 2:53:23 PM | Computer Name = RobertJameson | Source = Application Hang | ID = 1002
    Description = The program Skype.exe version 5.10.0.116 stopped interacting with
    Windows and was closed. To see if more information about the problem is available,
    check the problem history in the Action Center control panel. Process ID: 1024 Start
    Time: 01cda1b0f691159c Termination Time: 15 Application Path: C:\Program Files (x86)\Skype\Phone\Skype.exe
    Report
    Id:

    Error - 10/4/2012 9:49:20 PM | Computer Name = RobertJameson | Source = VSS | ID = 8194
    Description =

    Error - 10/5/2012 3:18:44 AM | Computer Name = RobertJameson | Source = Windows Backup | ID = 4104
    Description =

    Error - 10/5/2012 7:03:01 AM | Computer Name = RobertJameson | Source = SideBySide | ID = 16842815
    Description = Activation context generation failed for "c:\Program Files (x86)\Common
    Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
    Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
    "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
    "version" in element "assemblyIdentity" is invalid.

    [ Hewlett-Packard Events ]
    Error - 5/30/2012 5:36:42 AM | Computer Name = RobertJameson | Source = HPSF.exe | ID = 4000
    Description =

    Error - 5/31/2012 5:59:38 PM | Computer Name = RobertJameson | Source = HPSF.exe | ID = 4000
    Description =

    Error - 5/31/2012 5:59:40 PM | Computer Name = RobertJameson | Source = HPSF.exe | ID = 4000
    Description =

    Error - 5/31/2012 6:01:15 PM | Computer Name = RobertJameson | Source = HPSF.exe | ID = 4000
    Description =

    Error - 6/23/2012 2:19:14 PM | Computer Name = RobertJameson | Source = HPSF.exe | ID = 4000
    Description =

    Error - 7/3/2012 7:14:26 AM | Computer Name = RobertJameson | Source = hpsa_service.exe | ID = 2000
    Description = HP Error ID: -2146233088 at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateDetail(String
    category) at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetectCore()
    at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
    Boolean localScan) Message: Failed to perform update. StackTrace: at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateDetail(String
    category) at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetectCore()
    at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
    Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager InnerException.Message:
    Object '/bb8391cb_b2f0_46af_8786_b39a17d36c10/avaqoye09pvm+1s7edj0+t3w_45.rem'
    has been disconnected or does not exist at the server. Name: hpsa_service.exe Version:
    06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
    Format:
    en-US RAM: 4063 Ram Utilization: 50 TargetSite: Void UpdateDetail(System.String)

    Error - 8/16/2012 7:59:53 AM | Computer Name = RobertJameson | Source = HPSF.exe | ID = 4000
    Description =

    Error - 8/20/2012 7:27:25 AM | Computer Name = RobertJameson | Source = HPSF.exe | ID = 4000
    Description =

    Error - 8/22/2012 5:08:49 PM | Computer Name = RobertJameson | Source = HPSF.exe | ID = 4000
    Description =

    Error - 9/28/2012 4:23:39 PM | Computer Name = RobertJameson | Source = HPSFMsgr.exe | ID = 4000
    Description = HP Error ID: -2147221164 at System.RuntimeTypeHandle.CreateInstance(RuntimeType
    type, Boolean publicOnly, Boolean noCheck, Boolean& canBeCached, RuntimeMethodHandle&
    ctor, Boolean& bNeedSecurityCheck) at System.RuntimeType.CreateInstanceSlow(Boolean
    publicOnly, Boolean fillCache) at System.RuntimeType.CreateInstanceImpl(Boolean
    publicOnly, Boolean skipVisibilityChecks, Boolean fillCache) at System.Activator.CreateInstance(Type
    type, Boolean nonPublic) at HPSA_Messenger.MessengerCom.TrayDeskBand.isTaskbarDisplayed()
    StackTrace:
    at System.RuntimeTypeHandle.CreateInstance(RuntimeType type, Boolean publicOnly,
    Boolean noCheck, Boolean& canBeCached, RuntimeMethodHandle& ctor, Boolean& bNeedSecurityCheck)
    at System.RuntimeType.CreateInstanceSlow(Boolean publicOnly, Boolean fillCache)
    at System.RuntimeType.CreateInstanceImpl(Boolean publicOnly, Boolean skipVisibilityChecks,
    Boolean fillCache) at System.Activator.CreateInstance(Type type, Boolean nonPublic)
    at HPSA_Messenger.MessengerCom.TrayDeskBand.isTaskbarDisplayed() Source: mscorlib
    Name:
    HPSFMsgr.exe Version: 01.00.00.00 Path: C:\Program Files (x86)\Hewlett-Packard\HP
    Support Framework\Resources\HPSFMessenger\HPSFMsgr.exe Format: en-US RAM: 4063 Ram
    Utilization: 30 TargetSite: System.Object CreateInstance(System.RuntimeType, Boolean,
    Boolean, Boolean ByRef, System.RuntimeMethodHandle ByRef, Boolean ByRef)

    [ Media Center Events ]
    Error - 8/5/2011 9:04:51 AM | Computer Name = RobertJameson | Source = MCUpdate | ID = 0
    Description = 6:04:49 AM - Error connecting to the internet. 6:04:49 AM - Unable
    to contact server..

    Error - 8/5/2011 10:05:32 AM | Computer Name = RobertJameson | Source = MCUpdate | ID = 0
    Description = 7:05:30 AM - Error connecting to the internet. 7:05:30 AM - Unable
    to contact server..

    Error - 8/5/2011 11:07:46 AM | Computer Name = RobertJameson | Source = MCUpdate | ID = 0
    Description = 8:07:44 AM - Error connecting to the internet. 8:07:44 AM - Unable
    to contact server..

    Error - 8/9/2011 9:03:13 PM | Computer Name = RobertJameson | Source = MCUpdate | ID = 0
    Description = 6:03:13 PM - Failed to retrieve MCESpotlight (Error: The operation
    has timed out)

    Error - 8/19/2011 11:05:02 AM | Computer Name = RobertJameson | Source = MCUpdate | ID = 0
    Description = 8:04:53 AM - Error connecting to the internet. 8:04:53 AM - Unable
    to contact server..

    Error - 8/31/2011 8:09:48 AM | Computer Name = RobertJameson | Source = MCUpdate | ID = 0
    Description = 5:09:44 AM - Error connecting to the internet. 5:09:44 AM - Unable
    to contact server..

    Error - 9/14/2011 8:11:52 AM | Computer Name = RobertJameson | Source = MCUpdate | ID = 0
    Description = 5:11:48 AM - Error connecting to the internet. 5:11:48 AM - Unable
    to contact server..

    Error - 9/14/2011 9:12:31 AM | Computer Name = RobertJameson | Source = MCUpdate | ID = 0
    Description = 6:12:31 AM - Error connecting to the internet. 6:12:31 AM - Unable
    to contact server..

    Error - 9/14/2011 10:16:29 AM | Computer Name = RobertJameson | Source = MCUpdate | ID = 0
    Description = 7:16:28 AM - Error connecting to the internet. 7:16:28 AM - Unable
    to contact server..

    Error - 9/14/2011 11:17:08 AM | Computer Name = RobertJameson | Source = MCUpdate | ID = 0
    Description = 8:17:08 AM - Error connecting to the internet. 8:17:08 AM - Unable
    to contact server..

    [ System Events ]
    Error - 10/3/2012 5:48:38 PM | Computer Name = RobertJameson | Source = Application Popup | ID = 1060
    Description = \SystemRoot\SysWow64\drivers\pfc.sys has been blocked from loading
    due to incompatibility with this system. Please contact your software vendor for
    a compatible version of the driver.

    Error - 10/3/2012 5:49:02 PM | Computer Name = RobertJameson | Source = Service Control Manager | ID = 7009
    Description = A timeout was reached (120000 milliseconds) while waiting for the
    Seagate Dashboard Service service to connect.

    Error - 10/3/2012 5:49:02 PM | Computer Name = RobertJameson | Source = Service Control Manager | ID = 7000
    Description = The Seagate Dashboard Service service failed to start due to the following
    error: %%1053

    Error - 10/3/2012 5:49:22 PM | Computer Name = RobertJameson | Source = Service Control Manager | ID = 7026
    Description = The following boot-start or system-start driver(s) failed to load:
    SBRE

    Error - 10/3/2012 5:51:23 PM | Computer Name = RobertJameson | Source = Service Control Manager | ID = 7009
    Description = A timeout was reached (120000 milliseconds) while waiting for the
    Microsoft .NET Framework NGEN v4.0.30319_X86 service to connect.

    Error - 10/3/2012 5:51:35 PM | Computer Name = RobertJameson | Source = Service Control Manager | ID = 7009
    Description = A timeout was reached (120000 milliseconds) while waiting for the
    Intuit Update Service service to connect.

    Error - 10/3/2012 5:51:35 PM | Computer Name = RobertJameson | Source = Service Control Manager | ID = 7000
    Description = The Intuit Update Service service failed to start due to the following
    error: %%1053

    Error - 10/4/2012 3:00:40 PM | Computer Name = RobertJameson | Source = Application Popup | ID = 1060
    Description = \SystemRoot\SysWow64\drivers\pfc.sys has been blocked from loading
    due to incompatibility with this system. Please contact your software vendor for
    a compatible version of the driver.

    Error - 10/4/2012 3:01:21 PM | Computer Name = RobertJameson | Source = Microsoft Antimalware | ID = 2004
    Description = %%860 has encountered an error trying to load signatures and will
    attempt reverting back to a known-good set of signatures. Signatures Attempted: %%824
    Error
    Code: 0x80070002 Error description: The system cannot find the file specified. Signature
    version: 1.137.1001.0;1.137.1001.0 Engine version: 1.1.8800.0

    Error - 10/4/2012 3:01:45 PM | Computer Name = RobertJameson | Source = Service Control Manager | ID = 7026
    Description = The following boot-start or system-start driver(s) failed to load:
    SBRE


    < End of report >
     
  6. Gizzy

    Gizzy Malware Specialist

    Joined:
    Aug 2, 2005
    Messages:
    3,832
    Hi gobob,

    You posted the Extras.txt log twice, Please post the OTL.txt log.
    It should be saved in the same place.
     
  7. gobob

    gobob Thread Starter

    Joined:
    Oct 3, 2012
    Messages:
    25
    Sorry about that but I have had problem trying to reply. So here goes the otl log
    OTL logfile created on: 10/5/2012 9:12:04 AM - Run 1
    OTL by OldTimer - Version 3.2.70.2 Folder = C:\Users\Robert Jameson\Desktop
    64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.97 Gb Total Physical Memory | 1.61 Gb Available Physical Memory | 40.63% Memory free
    6.95 Gb Paging File | 4.00 Gb Available in Paging File | 57.50% Paging File free
    Paging file location(s): c:\pagefile.sys 3055 4096 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 282.91 Gb Total Space | 48.80 Gb Free Space | 17.25% Space Free | Partition Type: NTFS
    Drive D: | 298.09 Gb Total Space | 105.78 Gb Free Space | 35.49% Space Free | Partition Type: NTFS
    Drive E: | 14.99 Gb Total Space | 2.46 Gb Free Space | 16.45% Space Free | Partition Type: NTFS
    Drive G: | 465.76 Gb Total Space | 65.35 Gb Free Space | 14.03% Space Free | Partition Type: NTFS

    Computer Name: ROBERTJAMESON | User Name: Robert Jameson | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - File not found --
    PRC - [2012/10/05 09:10:23 | 000,601,088 | ---- | M] (OldTimer Tools) -- C:\Users\Robert Jameson\Desktop\OTL.exe
    PRC - [2012/09/07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    PRC - [2012/09/07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    PRC - [2012/09/07 17:04:44 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    PRC - [2012/07/27 13:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    PRC - [2012/07/05 18:41:46 | 003,048,136 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
    PRC - [2012/04/11 12:22:30 | 002,327,632 | ---- | M] (Xeric Design, Ltd.) -- C:\Program Files (x86)\XericDesign\EarthDesk\EarthDesk.exe
    PRC - [2012/02/23 10:30:40 | 000,059,240 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
    PRC - [2011/06/01 09:42:28 | 000,071,432 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoDashboard.exe
    PRC - [2011/06/01 09:42:28 | 000,014,088 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe
    PRC - [2011/06/01 09:16:54 | 002,260,992 | ---- | M] (Axentra Corporation) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe
    PRC - [2011/05/17 12:29:46 | 000,395,144 | ---- | M] (Ask) -- C:\Program Files (x86)\Ask.com\Updater\Updater.exe
    PRC - [2011/03/28 16:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
    PRC - [2011/03/03 20:09:54 | 001,204,224 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
    PRC - [2011/03/03 20:05:00 | 000,335,872 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
    PRC - [2010/06/02 16:22:38 | 000,077,656 | ---- | M] (Intuit Inc.) -- C:\Program Files (x86)\Quicken\bagent.exe
    PRC - [2010/03/09 00:42:02 | 000,029,984 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe
    PRC - [2010/03/09 00:40:36 | 000,144,672 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
    PRC - [2010/03/05 20:11:30 | 000,636,192 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
    PRC - [2010/03/05 16:02:02 | 000,145,920 | ---- | M] (Orbiscom Ltd.) -- C:\Windows\SysWOW64\OBroker.exe
    PRC - [2010/03/05 15:03:26 | 000,376,832 | ---- | M] (Orbiscom Ltd. All rights reserved.) -- C:\Program Files (x86)\Discover\SOAN\DiscoverSOAN.exe
    PRC - [2010/01/25 08:22:56 | 000,245,760 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files (x86)\Browny02\BrYNSvc.exe
    PRC - [2009/11/11 16:17:02 | 000,771,360 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\AirPort\APAgent.exe
    PRC - [2009/09/29 07:17:50 | 000,013,088 | ---- | M] (Intuit Inc.) -- C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    PRC - [2009/09/23 12:38:18 | 000,935,208 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
    PRC - [2009/09/10 13:12:10 | 000,185,632 | ---- | M] (Protexis Inc.) -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
    PRC - [2009/07/30 17:42:34 | 000,013,600 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
    PRC - [2009/07/23 20:45:52 | 000,128,296 | ---- | M] (CyberLink Corp.) -- c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
    PRC - [2009/07/23 11:37:16 | 000,206,120 | ---- | M] (CyberLink) -- c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
    PRC - [2009/07/10 16:53:52 | 000,372,736 | ---- | M] (Orbiscom Ltd. All rights reserved.) -- C:\Program Files (x86)\Virtual Account Numbers\CitiVAN.exe
    PRC - [2009/06/04 19:03:32 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    PRC - [2009/06/04 19:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
    PRC - [2009/05/05 16:06:06 | 000,222,496 | ---- | M] (Acresso Corporation) -- C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
    PRC - [2009/03/13 15:14:04 | 010,584,629 | ---- | M] () -- C:\Program Files (x86)\myiHome\app\myiHome-server.exe
    PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
    PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
    PRC - [2008/11/09 13:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe


    ========== Modules (No Company Name) ==========

    MOD - [2012/10/03 11:10:48 | 000,135,168 | ---- | M] () -- C:\Windows\assembly\GAC\SHDocVw\1.1.0.0__51b6fa9a48c79a9e\SHDocVw.dll
    MOD - [2012/10/03 11:10:22 | 000,378,880 | ---- | M] () -- C:\Users\Robert Jameson\AppData\LocalLow\FCTB000100815\Toolbar\Helper.dll
    MOD - [2012/10/03 11:10:22 | 000,378,880 | ---- | M] () -- C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\Helper.dll
    MOD - [2012/10/03 11:10:21 | 001,615,360 | ---- | M] () -- C:\Users\Robert Jameson\AppData\LocalLow\FCTB000100815\Toolbar\Toolbar.dll
    MOD - [2012/10/03 11:10:21 | 001,615,360 | ---- | M] () -- C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\Toolbar.dll
    MOD - [2012/06/14 03:41:22 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\69ca4a43ba14b66689715ad62aed70e6\System.ServiceProcess.ni.dll
    MOD - [2012/06/14 03:41:14 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll
    MOD - [2012/06/14 03:40:44 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
    MOD - [2012/06/14 03:40:36 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
    MOD - [2012/05/10 03:52:24 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
    MOD - [2012/05/10 03:51:28 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\2ec98ab0193d64e95b7d09d094deed97\Accessibility.ni.dll
    MOD - [2012/05/10 03:50:59 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
    MOD - [2012/05/10 03:50:52 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
    MOD - [2012/05/10 03:50:51 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
    MOD - [2012/05/10 03:50:37 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
    MOD - [2012/03/27 14:49:18 | 000,843,776 | ---- | M] () -- C:\Program Files (x86)\XericDesign\EarthDesk\libeay32.dll
    MOD - [2012/03/27 14:47:32 | 000,094,208 | ---- | M] () -- C:\Program Files (x86)\XericDesign\EarthDesk\CrashRpt1300.dll
    MOD - [2011/06/24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    MOD - [2011/06/24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    MOD - [2011/06/01 09:46:02 | 000,030,984 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SeagateSharePlusPlugin.dll
    MOD - [2011/06/01 09:42:24 | 000,108,296 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Progress.dll
    MOD - [2011/06/01 09:16:54 | 000,971,776 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\libxml2.dll
    MOD - [2011/06/01 09:16:54 | 000,241,664 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\libupnp.dll
    MOD - [2010/03/19 10:45:36 | 007,745,536 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll
    MOD - [2010/03/19 10:45:36 | 002,121,728 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll
    MOD - [2010/03/19 10:45:36 | 000,135,168 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
    MOD - [2010/03/05 14:59:44 | 000,071,680 | ---- | M] () -- C:\Program Files (x86)\Discover\SOAN\DiscoverSOAN.dll
    MOD - [2009/07/23 11:37:14 | 000,931,112 | ---- | M] () -- c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll
    MOD - [2009/07/10 16:50:24 | 000,039,424 | ---- | M] () -- C:\Program Files (x86)\Virtual Account Numbers\VANRes.dll
    MOD - [2009/03/13 15:14:04 | 010,584,629 | ---- | M] () -- C:\Program Files (x86)\myiHome\app\myiHome-server.exe
    MOD - [2009/02/27 16:38:20 | 000,139,264 | R--- | M] () -- C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
    MOD - [2006/09/05 16:24:04 | 000,058,368 | ---- | M] () -- C:\Program Files (x86)\myiHome\app\jshortcut.dll
    MOD - [2006/09/05 16:24:04 | 000,053,248 | ---- | M] () -- C:\Program Files (x86)\myiHome\app\jRegistryKey.dll
    MOD - [2006/09/05 16:24:04 | 000,051,200 | ---- | M] () -- C:\Program Files (x86)\myiHome\app\TrayIcon12.dll


    ========== Services (SafeList) ==========

    SRV:64bit: - [2012/03/26 18:49:56 | 000,291,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
    SRV:64bit: - [2012/03/26 18:49:56 | 000,012,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
    SRV:64bit: - [2011/05/13 17:58:10 | 000,030,520 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Windows\SysNative\hpservice.exe -- (hpsrv)
    SRV:64bit: - [2010/03/23 14:53:06 | 000,247,808 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\stacsv64.exe -- (STacSV)
    SRV:64bit: - [2009/07/30 17:42:34 | 000,864,032 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
    SRV:64bit: - [2009/07/13 18:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV:64bit: - [2009/07/13 18:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\CISVC.EXE -- (CISVC)
    SRV:64bit: - [2009/07/02 14:16:00 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
    SRV:64bit: - [2009/03/27 19:10:16 | 000,016,896 | ---- | M] (LSI Corporation) [Auto | Running] -- C:\Program Files\LSI SoftModem\agr64svc.exe -- (AgereModemAudio)
    SRV:64bit: - [2009/03/02 18:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe -- (AESTFilters)
    SRV:64bit: - [2008/05/07 16:29:38 | 000,122,880 | ---- | M] (CrypKey (Canada) Ltd.) [Auto | Running] -- C:\Windows\SysNative\Crypserv.exe -- (Crypkey License)
    SRV - [2012/09/21 00:07:07 | 000,250,288 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
    SRV - [2012/09/07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
    SRV - [2012/09/07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
    SRV - [2012/07/27 13:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
    SRV - [2012/07/13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
    SRV - [2012/07/05 18:41:46 | 003,048,136 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
    SRV - [2011/09/09 16:10:28 | 000,086,072 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe -- (HP Support Assistant Service)
    SRV - [2011/06/01 09:42:28 | 000,014,088 | ---- | M] (Memeo) [Auto | Running] -- C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe -- (SeagateDashboardService)
    SRV - [2011/03/28 16:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe -- (HPDrvMntSvc.exe)
    SRV - [2010/03/23 14:53:06 | 000,247,808 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\STacSV64.exe -- (STacSV)
    SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2010/03/09 00:40:36 | 000,144,672 | ---- | M] (Nuance Communications, Inc.) [Auto | Running] -- C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe -- (PDFProFiltSrvPP)
    SRV - [2010/01/25 08:22:56 | 000,245,760 | ---- | M] (Brother Industries, Ltd.) [On_Demand | Running] -- C:\Program Files (x86)\Browny02\BrYNSvc.exe -- (BrYNSvc)
    SRV - [2009/11/19 13:15:42 | 000,249,856 | ---- | M] (SMServer) [On_Demand | Stopped] -- C:\Windows\SysWOW64\snmvtsvc.exe -- (SMServer)
    SRV - [2009/11/19 07:52:48 | 000,335,872 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\SoundTaxi Media Suite\STSService.exe -- (STSService)
    SRV - [2009/09/29 07:17:50 | 000,013,088 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe -- (IntuitUpdateService)
    SRV - [2009/09/23 12:38:18 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
    SRV - [2009/09/10 13:12:10 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
    SRV - [2009/06/10 14:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
    SRV - [2009/06/04 19:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
    SRV - [2009/05/22 11:02:20 | 000,250,616 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe -- (GameConsoleService)
    SRV - [2009/03/02 18:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe -- (AESTFilters)
    SRV - [2008/11/09 13:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - [2012/09/07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
    DRV:64bit: - [2012/06/26 21:38:30 | 000,046,176 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)
    DRV:64bit: - [2012/06/24 22:24:48 | 000,052,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d)
    DRV:64bit: - [2012/03/20 20:44:12 | 000,098,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
    DRV:64bit: - [2012/02/29 23:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
    DRV:64bit: - [2012/02/15 09:01:50 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
    DRV:64bit: - [2011/10/14 04:37:44 | 000,396,848 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
    DRV:64bit: - [2011/05/13 17:58:16 | 000,030,008 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\hpdskflt.sys -- (hpdskflt)
    DRV:64bit: - [2011/05/13 17:57:58 | 000,043,320 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Accelerometer.sys -- (Accelerometer)
    DRV:64bit: - [2011/05/10 06:06:14 | 000,022,528 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl)
    DRV:64bit: - [2011/04/07 23:13:34 | 000,035,840 | R--- | M] (Avanquest Software) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BVRPMPR5a64.SYS -- (BVRPMPR5a64)
    DRV:64bit: - [2011/03/10 23:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
    DRV:64bit: - [2011/03/10 23:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
    DRV:64bit: - [2010/11/20 06:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
    DRV:64bit: - [2010/11/20 04:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
    DRV:64bit: - [2010/11/20 02:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
    DRV:64bit: - [2010/06/12 10:07:46 | 007,680,512 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETw5s64.sys -- (NETw5s64)
    DRV:64bit: - [2010/03/23 14:53:06 | 000,505,344 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
    DRV:64bit: - [2010/03/10 15:16:36 | 000,029,720 | ---- | M] (Initio Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ivusb.sys -- (ivusb)
    DRV:64bit: - [2010/01/11 22:39:01 | 000,082,816 | ---- | M] (VSO Software) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pcouffin.sys -- (pcouffin)
    DRV:64bit: - [2009/11/19 16:04:32 | 000,033,336 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SndTAudio.sys -- (SndTAudio)
    DRV:64bit: - [2009/07/23 10:02:38 | 005,435,904 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NETw5v64.sys -- (netw5v64)
    DRV:64bit: - [2009/07/20 20:39:00 | 000,140,712 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\jmcr.sys -- (JMCR)
    DRV:64bit: - [2009/07/13 18:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
    DRV:64bit: - [2009/07/13 18:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
    DRV:64bit: - [2009/07/13 18:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
    DRV:64bit: - [2009/07/13 17:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
    DRV:64bit: - [2009/07/13 17:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
    DRV:64bit: - [2009/07/13 17:06:48 | 000,067,072 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BTHPRINT.SYS -- (BTHprint)
    DRV:64bit: - [2009/07/13 15:31:00 | 000,233,472 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
    DRV:64bit: - [2009/07/02 14:51:00 | 006,036,480 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
    DRV:64bit: - [2009/07/01 13:46:52 | 000,098,344 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
    DRV:64bit: - [2009/07/01 13:46:48 | 000,132,648 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
    DRV:64bit: - [2009/07/01 13:46:40 | 000,021,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
    DRV:64bit: - [2009/06/29 11:17:00 | 000,070,656 | ---- | M] (ENE TECHNOLOGY INC.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\enecir.sys -- (enecir)
    DRV:64bit: - [2009/06/29 10:00:00 | 000,116,752 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
    DRV:64bit: - [2009/06/10 14:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
    DRV:64bit: - [2009/06/10 14:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
    DRV:64bit: - [2009/06/10 14:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
    DRV:64bit: - [2009/06/10 13:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
    DRV:64bit: - [2009/06/10 13:35:33 | 000,389,120 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
    DRV:64bit: - [2009/06/10 13:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
    DRV:64bit: - [2009/06/10 13:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
    DRV:64bit: - [2009/06/10 13:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
    DRV:64bit: - [2009/06/10 13:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
    DRV:64bit: - [2009/06/04 17:54:36 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
    DRV:64bit: - [2009/05/18 12:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
    DRV:64bit: - [2009/04/29 08:48:32 | 000,018,432 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
    DRV:64bit: - [2009/04/07 16:33:08 | 000,035,104 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
    DRV:64bit: - [2009/04/06 18:31:08 | 001,208,320 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\agrsm64.sys -- (AgereSoftModem)
    DRV:64bit: - [2009/02/13 10:02:52 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
    DRV:64bit: - [2008/10/09 09:17:06 | 000,005,120 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rcmirror.sys -- (rcmirror)
    DRV:64bit: - [2008/03/17 10:12:26 | 000,028,664 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\Ckldrv.sys -- (NetworkX)
    DRV - [2009/07/23 20:45:28 | 000,146,928 | ---- | M] (CyberLink Corp.) [2009/08/25 01:58:21] [Kernel | Auto | Running] -- c:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl -- ({55662437-DA8C-40c0-AADA-2C816A897A49})
    DRV - [2009/07/13 18:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
    DRV - [2009/03/30 09:45:50 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\pfc.sys -- (pfc)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cnnb
    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=ir...tByCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=436995085
    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sea...putEncoding}&oe={outputEncoding}&sourceid=ie7
    IE:64bit: - HKLM\..\SearchScopes\{BEC2075C-8E0A-4EB6-8D5D-A840665B39C9}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
    IE:64bit: - HKLM\..\SearchScopes\{CC778948-1EA5-4599-AE7A-9807D211DCF4}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=HPNTDF&pc=HPNTDF&src=IE-SearchBox
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=ir...tByCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=436995085
    IE - HKLM\..\URLSearchHook: {19da1ae4-a403-4535-8e93-63b3aa7f1d8e} - C:\Program Files (x86)\SimpUtil_Maps_1\prxtbSim0.dll (Conduit Ltd.)
    IE - HKLM\..\URLSearchHook: {1fca4df8-9acd-4dfb-89cc-ddd0082fc588} - C:\Program Files (x86)\Productivity_3\prxtbProd.dll (Conduit Ltd.)
    IE - HKLM\..\URLSearchHook: {e917fc61-7f80-4f1f-a882-cdffffbe4c8d} - C:\Program Files (x86)\D-Link Toolbar\dlinktb.dll (AOL LLC.)
    IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE - HKLM\..\SearchScopes,DefaultScope = {7E1A6753-E4DE-6627-B8AD-44AD9999F6D6}
    IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com...invocationType=tb50-ie-dlink-chromesbox-en-us
    IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://start.funmoods.com/results.p...tByCzztN1L2XzutBtFtCtFtCtFtAtCtB&cr=436995085
    IE - HKLM\..\SearchScopes\{7E1A6753-E4DE-6627-B8AD-44AD9999F6D6}: "URL" = http://www.google.com/search?q={sea...putEncoding}&oe={outputEncoding}&sourceid=ie7
    IE - HKLM\..\SearchScopes\{BEC2075C-8E0A-4EB6-8D5D-A840665B39C9}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
    IE - HKLM\..\SearchScopes\{CC778948-1EA5-4599-AE7A-9807D211DCF4}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=HPNTDF&pc=HPNTDF&src=IE-SearchBox


    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



    IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://my.yahoo.com/
    IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?ocid=OIE9MSE&PC=UP09
    IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
    IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\URLSearchHook: - No CLSID value found
    IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\URLSearchHook: {4d95229d-bcd1-51b4-d184-411b9857a1f4} - C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\Helper.dll ()
    IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sea...putEncoding}&sourceid=ie7&rlz=1I7ADRA_enUS502
    IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\SearchScopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}: "URL" = Playbryte-fa-bndl/search/redirect/?type=default&user_id=bd2cb4d6-b56d-4e30-9244-522037568cee&query={searchTerms}
    IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


    ========== FireFox ==========

    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\citius@orbiscom: C:\Program Files (x86)\Virtual Account Numbers [2010/07/29 12:27:45 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\discoversoan@orbiscom: C:\Program Files (x86)\Discover\SOAN [2012/01/19 09:07:14 | 000,000,000 | ---D | M]

    [2012/10/03 11:10:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robert Jameson\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions
    [2012/10/03 11:10:44 | 000,000,000 | ---D | M] (PlayBryte) -- C:\Users\Robert Jameson\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]
    [2012/06/21 14:56:33 | 000,086,818 | ---- | M] () (No name found) -- C:\Users\Robert Jameson\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]

    O1 HOSTS File: ([2012/09/28 12:44:48 | 000,444,411 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 www.007guard.com
    O1 - Hosts: 127.0.0.1 007guard.com
    O1 - Hosts: 127.0.0.1 008i.com
    O1 - Hosts: 127.0.0.1 www.008k.com
    O1 - Hosts: 127.0.0.1 008k.com
    O1 - Hosts: 127.0.0.1 www.00hq.com
    O1 - Hosts: 127.0.0.1 00hq.com
    O1 - Hosts: 127.0.0.1 010402.com
    O1 - Hosts: 127.0.0.1 www.032439.com
    O1 - Hosts: 127.0.0.1 032439.com
    O1 - Hosts: 127.0.0.1 www.0scan.com
    O1 - Hosts: 127.0.0.1 0scan.com
    O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
    O1 - Hosts: 127.0.0.1 1000gratisproben.com
    O1 - Hosts: 127.0.0.1 1001namen.com
    O1 - Hosts: 127.0.0.1 www.1001namen.com
    O1 - Hosts: 127.0.0.1 100888290cs.com
    O1 - Hosts: 127.0.0.1 www.100888290cs.com
    O1 - Hosts: 127.0.0.1 www.100sexlinks.com
    O1 - Hosts: 127.0.0.1 100sexlinks.com
    O1 - Hosts: 127.0.0.1 www.10sek.com
    O1 - Hosts: 127.0.0.1 10sek.com
    O1 - Hosts: 127.0.0.1 www.1-2005-search.com
    O1 - Hosts: 127.0.0.1 1-2005-search.com
    O1 - Hosts: 127.0.0.1 www.123fporn.info
    O1 - Hosts: 15262 more lines...
    O2:64bit: - BHO: (Privacy Safeguard BHO) - {1036AD63-AEAC-460B-9060-C96005D4DC86} - C:\Program Files\PrivacySafeGuard\PrivacySafeGuard-x64.dll (PrivacySafeguard)
    O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
    O2 - BHO: (no name) - {1036AD63-AEAC-460B-9060-C96005D4DC86} - No CLSID value found.
    O2 - BHO: (Virtual Account Numbers Helper) - {17424104-1444-4810-85D7-B4DA413C5A9A} - C:\Program Files (x86)\Virtual Account Numbers\CitiVANHelper.dll (Orbiscom Ltd. All rights reserved.)
    O2 - BHO: (SimpUtil Maps 1 Toolbar) - {19da1ae4-a403-4535-8e93-63b3aa7f1d8e} - C:\Program Files (x86)\SimpUtil_Maps_1\prxtbSim0.dll (Conduit Ltd.)
    O2 - BHO: (Productivity 3 Toolbar) - {1fca4df8-9acd-4dfb-89cc-ddd0082fc588} - C:\Program Files (x86)\Productivity_3\prxtbProd.dll (Conduit Ltd.)
    O2 - BHO: (Secure Online Account Numbers Helper) - {435EAA86-D32B-484F-869C-53745FCB1642} - C:\Program Files (x86)\Discover\SOAN\DiscoverSOANHelper.dll (Orbiscom Ltd. All rights reserved.)
    O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
    O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Viewer Plus\bin\PlusIEContextMenu.dll (Zeon Corporation)
    O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
    O2 - BHO: (DiscoverSOANBrowserHelper Class) - {8DB3D69D-DA5E-4165-B781-72A761790672} - C:\Program Files (x86)\Discover\SOAN\DiscoverSOANBHO.dll (Orbiscom Ltd. All rights reserved.)
    O2 - BHO: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll ()
    O2 - BHO: (Privacy Safeguard BHO) - {A42D2EB4-DD31-4BB5-8AA5-8D4E04806DBE} - C:\Program Files\PrivacySafeGuard\PrivacySafeGuard.dll (PrivacySafeguard)
    O2 - BHO: (hpBHO Class) - {ABD3B5E1-B268-407B-A150-2641DAB8D898} - C:\Program Files (x86)\Common Files\Homepage Protection\HomepageProtection.dll (AOL Products)
    O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O2 - BHO: (Inbox Toolbar) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\Program Files (x86)\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
    O2 - BHO: (eSupport Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
    O2 - BHO: (Bucksbee Loyalty Plugin - 100815) - {E5C2A1FE-86DB-87B4-11F0-1AA2579E81DD} - C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\BucksBee Loyalty Plugin.dll (Freecause Inc.)
    O2 - BHO: (D-Link Toolbar Loader) - {f01858c7-2a68-4d93-9e22-502eae3917c2} - C:\Program Files (x86)\D-Link Toolbar\dlinktb.dll (AOL LLC.)
    O2 - BHO: (SelectionLinks) - {F90A5A0D-CD98-49CC-9AA7-9CD11C7478BF} - C:\Program Files (x86)\OApps\bho.dll (SelectionLinks)
    O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
    O3:64bit: - HKLM\..\Toolbar: (Wolfram Toolbar) - {9E709AEF-74F7-4DA3-A7FC-F3E2D5A8D793} - C:\Program Files\Wolfram Research\WolframToolbar\1.0\WolframBands64.dll (Wolfram Research, Inc.)
    O3 - HKLM\..\Toolbar: (SimpUtil Maps 1 Toolbar) - {19da1ae4-a403-4535-8e93-63b3aa7f1d8e} - C:\Program Files (x86)\SimpUtil_Maps_1\prxtbSim0.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (Productivity 3 Toolbar) - {1fca4df8-9acd-4dfb-89cc-ddd0082fc588} - C:\Program Files (x86)\Productivity_3\prxtbProd.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (D-Link Toolbar) - {61874dfa-9adf-44e5-8e61-f3913707e7d7} - C:\Program Files (x86)\D-Link Toolbar\dlinktb.dll (AOL LLC.)
    O3 - HKLM\..\Toolbar: (Virtual Account Numbers) - {7A21A046-B886-4A62-9D69-EF2059B0A27B} - C:\Program Files (x86)\Virtual Account Numbers\CitiVANToolbar.dll (Orbiscom Ltd. All rights reserved.)
    O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll ()
    O3 - HKLM\..\Toolbar: (Wolfram Toolbar) - {9E709AEF-74F7-4DA3-A7FC-F3E2D5A8D793} - C:\Program Files\Wolfram Research\WolframToolbar\1.0\WolframBands32.dll (Wolfram Research, Inc.)
    O3 - HKLM\..\Toolbar: (Secure Online Account Numbers) - {A8C7C2CA-6DFD-4E16-8458-592361564D38} - C:\Program Files (x86)\Discover\SOAN\DiscoverSOANToolbar.dll (Orbiscom Ltd. All rights reserved.)
    O3 - HKLM\..\Toolbar: (no name) - {b278d9f8-0fa9-465e-9938-0c392605d8e3} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (eSupport Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
    O3 - HKLM\..\Toolbar: (&Inbox Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\Program Files (x86)\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
    O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (no name) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No CLSID value found.
    O3 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (SimpUtil Maps 1 Toolbar) - {19DA1AE4-A403-4535-8E93-63B3AA7F1D8E} - C:\Program Files (x86)\SimpUtil_Maps_1\prxtbSim0.dll (Conduit Ltd.)
    O3 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (Productivity 3 Toolbar) - {1FCA4DF8-9ACD-4DFB-89CC-DDD0082FC588} - C:\Program Files (x86)\Productivity_3\prxtbProd.dll (Conduit Ltd.)
    O3 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (D-Link Toolbar) - {61874DFA-9ADF-44E5-8E61-F3913707E7D7} - C:\Program Files (x86)\D-Link Toolbar\dlinktb.dll (AOL LLC.)
    O3 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll ()
    O3:64bit: - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (Wolfram Toolbar) - {9E709AEF-74F7-4DA3-A7FC-F3E2D5A8D793} - C:\Program Files\Wolfram Research\WolframToolbar\1.0\WolframBands64.dll (Wolfram Research, Inc.)
    O3 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (Wolfram Toolbar) - {9E709AEF-74F7-4DA3-A7FC-F3E2D5A8D793} - C:\Program Files\Wolfram Research\WolframToolbar\1.0\WolframBands32.dll (Wolfram Research, Inc.)
    O3 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (eSupport Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
    O3 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (&Inbox Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\Program Files (x86)\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
    O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
    O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft Device Center\ipoint.exe (Microsoft Corporation)
    O4:64bit: - HKLM..\Run: [IntelliType Pro] C:\Program Files\Microsoft Device Center\itype.exe (Microsoft Corporation)
    O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
    O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
    O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
    O4 - HKLM..\Run: [AirPort Base Station Agent] C:\Program Files (x86)\AirPort\APAgent.exe (Apple Inc.)
    O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
    O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
    O4 - HKLM..\Run: [Citi Virtual Account Numbers] C:\Program Files (x86)\Virtual Account Numbers\CitiVAN.exe (Orbiscom Ltd. All rights reserved.)
    O4 - HKLM..\Run: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe (Brother Industries, Ltd.)
    O4 - HKLM..\Run: [Freecorder FLV Service] "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run File not found
    O4 - HKLM..\Run: [HPCam_Menu] c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
    O4 - HKLM..\Run: [IndexSearch] C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
    O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
    O4 - HKLM..\Run: [PDF5 Registry Controller] C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe (Nuance Communications, Inc.)
    O4 - HKLM..\Run: [PDFHook] C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (Nuance Communications, Inc.)
    O4 - HKLM..\Run: [PPort12reminder] C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
    O4 - HKLM..\Run: [Seagate Dashboard] C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoLauncher.exe ()
    O4 - HKLM..\Run: [Secure Online Account Numbers] C:\Program Files (x86)\Discover\SOAN\DiscoverSOAN.exe (Orbiscom Ltd. All rights reserved.)
    O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
    O4 - HKLM..\Run: [TaskTray] File not found
    O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
    O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
    O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
    O4 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
    O4 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
    O4 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001..\Run: [QuickenScheduledUpdates] C:\Program Files (x86)\Quicken\bagent.exe (Intuit Inc.)
    O4 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
    O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
    O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
    O4 - Startup: C:\Users\Robert Jameson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
    O4 - Startup: C:\Users\Robert Jameson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EarthDesk.lnk = C:\Program Files (x86)\XericDesign\EarthDesk\EarthDesk.exe (Xeric Design, Ltd.)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Main present
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: WallpaperStyle = 2
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Main present
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: WallpaperStyle = 2
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Main present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Main present
    O7 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Policies\Microsoft\Internet Explorer\Main present
    O7 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: WallpaperStyle = 2
    O8:64bit: - Extra context menu item: Open with PDF Viewer Plus - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
    O8 - Extra context menu item: Open with PDF Viewer Plus - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
    O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
    O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
    O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
    O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
    O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
    O9 - Extra Button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files (x86)\SoundTaxi\YouTubeRipper.dll ()
    O9 - Extra 'Tools' menuitem : Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files (x86)\SoundTaxi\YouTubeRipper.dll ()
    O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
    O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
    O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O1364bit: - gopher Prefix: missing
    O13 - gopher Prefix: missing
    O15 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
    O15 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..Trusted Domains: usgs.gov ([sslearthquake] https in Trusted sites)
    O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab (Reg Error: Unable to open value key)
    O16 - DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} http://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab (Device Detection)
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files (x86)\Yahoo!\Common\Yinsthelper.dll (Installation Support)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
    O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C68FBD48-8592-447B-B418-2824F47484D0}: DhcpNameServer = 172.18.64.215 172.18.64.215 8.8.8.8
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DD57E82F-EB9C-47D1-BFA8-44646E82965A}: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F850D49B-D327-49FA-9395-588C21B47909}: DhcpNameServer = 192.168.1.1
    O18:64bit: - Protocol\Handler\inbox - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
    O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
    O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
    O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
    O18 - Protocol\Handler\inbox {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\Program Files (x86)\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
    O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
    O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O32 - HKLM CDRom: AutoRun - 1
    O33 - MountPoints2\{1f0b330d-2d1b-11df-94bd-0027134ffaa6}\Shell - "" = AutoRun
    O33 - MountPoints2\{1f0b330d-2d1b-11df-94bd-0027134ffaa6}\Shell\AutoRun\command - "" = "H:\WD SmartWare.exe" autoplay=true
    O33 - MountPoints2\{60c0f62a-19c8-11df-a9ff-0027134ffaa6}\Shell - "" = AutoRun
    O33 - MountPoints2\{60c0f62a-19c8-11df-a9ff-0027134ffaa6}\Shell\AutoRun\command - "" = "H:\WD SmartWare.exe" autoplay=true
    O33 - MountPoints2\{ab68575a-1e68-11e0-901c-0027134ffaa6}\Shell - "" = AutoRun
    O33 - MountPoints2\{ab68575a-1e68-11e0-901c-0027134ffaa6}\Shell\AutoRun\command - "" = "G:\WD SmartWare.exe" autoplay=true
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
    O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/10/05 09:10:23 | 000,601,088 | ---- | C] (OldTimer Tools) -- C:\Users\Robert Jameson\Desktop\OTL.exe
    [2012/10/03 11:10:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Playbryte
    [2012/10/03 11:10:04 | 000,000,000 | ---D | C] -- C:\Users\Robert Jameson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bucksbee Loyalty Plugin - 100815
    [2012/10/03 11:09:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815
    [2012/10/03 11:08:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OApps
    [2012/10/03 10:22:53 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\Robert Jameson\Desktop\HijackThis.exe
    [2012/09/29 04:20:34 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
    [2012/09/28 12:36:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
    [2012/09/28 12:36:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
    [2012/09/28 12:36:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
    [2012/09/28 10:42:32 | 000,000,000 | ---D | C] -- C:\Users\Robert Jameson\AppData\Roaming\Malwarebytes
    [2012/09/28 10:42:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
    [2012/09/28 10:42:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
    [2012/09/28 10:42:12 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2012/09/28 10:42:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    [2012/09/25 13:58:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Mouse and Keyboard Center
    [2012/09/25 13:57:48 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Device Center
    [2012/09/25 13:41:59 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll
    [2012/09/25 13:41:59 | 000,366,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll
    [2012/09/25 13:39:36 | 000,245,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\OxpsConverter.exe
    [2012/09/25 11:49:24 | 000,000,000 | ---D | C] -- C:\ProgramData\GFI Software
    [2012/09/25 11:20:55 | 000,000,000 | ---D | C] -- C:\Users\Robert Jameson\AppData\Local\Downloaded Installations
    [2012/09/25 11:19:23 | 000,000,000 | ---D | C] -- C:\Users\Robert Jameson\AppData\Local\adawarebp
    [2012/09/24 22:29:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
    [2012/09/24 22:29:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\7-Zip
    [2012/09/24 22:29:16 | 000,000,000 | ---D | C] -- C:\Program Files\PrivacySafeGuard
    [2012/09/24 22:29:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Privacy SafeGuard
    [2012/09/24 22:26:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileOpener
    [2012/09/24 22:25:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Tweaks
    [2012/09/23 14:43:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reincubate
    [2012/09/23 14:43:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reincubate
    [2012/09/23 13:53:36 | 000,000,000 | ---D | C] -- C:\Users\Robert Jameson\AppData\Roaming\Google
    [2012/09/22 03:00:45 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
    [2012/09/22 03:00:45 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
    [2012/09/22 03:00:44 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
    [2012/09/22 03:00:43 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
    [2012/09/22 03:00:43 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
    [2012/09/22 03:00:43 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
    [2012/09/22 03:00:43 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
    [2012/09/22 03:00:43 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
    [2012/09/22 03:00:42 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
    [2012/09/22 03:00:42 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
    [2012/09/22 03:00:41 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
    [2012/09/22 03:00:41 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
    [2012/09/22 03:00:40 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
    [2012/09/22 03:00:39 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
    [2012/09/22 03:00:39 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
    [2012/09/20 16:31:01 | 000,000,000 | ---D | C] -- C:\Users\Robert Jameson\Desktop\Jenny's Pictures
    [2012/09/14 17:52:57 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\RNDISMP.sys
    [2012/09/14 17:52:56 | 000,574,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10level9.dll
    [2012/09/14 17:52:55 | 000,376,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netio.sys
    [2012/09/14 17:52:55 | 000,288,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS
    [2012/09/06 07:32:34 | 000,025,299 | ---- | C] (Brother Industries, Ltd) -- C:\Windows\SysWow64\BRLM03A.DLL
    [2010/01/11 22:39:01 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\Robert Jameson\AppData\Roaming\pcouffin.sys
    [3 C:\Users\Robert Jameson\Desktop\*.tmp files -> C:\Users\Robert Jameson\Desktop\*.tmp -> ]
    [3 C:\Users\Robert Jameson\*.tmp files -> C:\Users\Robert Jameson\*.tmp -> ]
    [21 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2012/10/05 09:10:23 | 000,601,088 | ---- | M] (OldTimer Tools) -- C:\Users\Robert Jameson\Desktop\OTL.exe
    [2012/10/05 09:06:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2012/10/05 08:36:01 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2012/10/05 04:46:34 | 000,000,368 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForRobert Jameson.job
    [2012/10/05 03:56:47 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2012/10/05 03:56:47 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2012/10/04 12:07:17 | 000,791,420 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2012/10/04 12:07:17 | 000,668,180 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2012/10/04 12:07:17 | 000,124,676 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2012/10/04 12:01:46 | 000,000,443 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.ics
    [2012/10/04 12:01:32 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2012/10/04 12:01:29 | 000,000,422 | ---- | M] () -- C:\Windows\tasks\FileCure Startup.job
    [2012/10/04 12:01:09 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2012/10/04 12:00:45 | 3195,420,672 | -HS- | M] () -- C:\hiberfil.sys
    [2012/10/03 10:22:03 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\Robert Jameson\Desktop\HijackThis.exe
    [2012/10/03 09:05:32 | 000,000,508 | ---- | M] () -- C:\Users\Robert Jameson\Desktop\hijackthis.lnk
    [2012/10/02 01:57:00 | 000,000,406 | ---- | M] () -- C:\Windows\tasks\FileCure.job
    [2012/09/28 12:44:48 | 000,444,411 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
    [2012/09/28 12:36:37 | 000,001,244 | ---- | M] () -- C:\Users\Robert Jameson\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
    [2012/09/28 11:07:52 | 000,021,050 | ---- | M] () -- C:\Users\Robert Jameson\Documents\cc_20120928_110738.reg
    [2012/09/25 14:06:19 | 000,377,664 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
    [2012/09/25 11:41:04 | 000,000,105 | ---- | M] () -- C:\prefs.js
    [2012/09/24 22:29:18 | 000,000,258 | RHS- | M] () -- C:\Users\Robert Jameson\ntuser.pol
    [2012/09/24 09:33:23 | 000,000,456 | ---- | M] () -- C:\Users\Robert Jameson\Documents\Allow_Changing_IE_Home_Page.reg
    [2012/09/23 14:43:17 | 000,001,270 | ---- | M] () -- C:\Users\Robert Jameson\Documents\iPhone Backup Extractor.lnk
    [2012/09/21 00:07:06 | 000,696,240 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
    [2012/09/21 00:07:06 | 000,073,136 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    [2012/09/21 00:06:52 | 009,573,296 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerInstaller.exe
    [2012/09/07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2012/09/06 16:19:06 | 000,001,399 | ---- | M] () -- C:\Users\Robert Jameson\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
    [2012/09/06 10:19:52 | 000,173,588 | -H-- | M] () -- C:\Windows\SysWow64\mlfcache.dat
    [2012/09/06 07:32:34 | 000,025,299 | ---- | M] (Brother Industries, Ltd) -- C:\Windows\SysWow64\BRLM03A.DLL
    [3 C:\Users\Robert Jameson\Desktop\*.tmp files -> C:\Users\Robert Jameson\Desktop\*.tmp -> ]
    [3 C:\Users\Robert Jameson\*.tmp files -> C:\Users\Robert Jameson\*.tmp -> ]
    [21 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2012/10/03 10:55:09 | 000,002,061 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
    [2012/10/03 10:55:09 | 000,001,383 | ---- | C] () -- C:\Users\Robert Jameson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
    [2012/10/03 10:55:09 | 000,001,146 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\myiHome Server.lnk
    [2012/10/03 09:05:32 | 000,000,508 | ---- | C] () -- C:\Users\Robert Jameson\Desktop\hijackthis.lnk
    [2012/09/28 12:36:37 | 000,001,244 | ---- | C] () -- C:\Users\Robert Jameson\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
    [2012/09/28 11:07:42 | 000,021,050 | ---- | C] () -- C:\Users\Robert Jameson\Documents\cc_20120928_110738.reg
    [2012/09/25 11:41:04 | 000,000,105 | ---- | C] () -- C:\prefs.js
    [2012/09/24 22:29:18 | 000,000,258 | RHS- | C] () -- C:\Users\Robert Jameson\ntuser.pol
    [2012/09/24 09:33:23 | 000,000,456 | ---- | C] () -- C:\Users\Robert Jameson\Documents\Allow_Changing_IE_Home_Page.reg
    [2012/09/23 14:43:17 | 000,001,282 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iPhone Backup Extractor.lnk
    [2012/09/23 14:43:17 | 000,001,270 | ---- | C] () -- C:\Users\Robert Jameson\Documents\iPhone Backup Extractor.lnk
    [2012/07/08 10:55:15 | 000,000,000 | ---- | C] () -- C:\Users\Robert Jameson\ipconfig
    [2012/06/23 13:46:14 | 000,000,130 | ---- | C] () -- C:\Windows\SysWow64\lp3codec32win.dll
    [2012/06/23 13:34:36 | 000,000,075 | ---- | C] () -- C:\Windows\SysWow64\mp3codec32win.dll
    [2012/05/09 15:07:09 | 000,000,795 | ---- | C] () -- C:\Windows\Brpfx04a.ini
    [2012/05/09 15:07:09 | 000,000,093 | ---- | C] () -- C:\Windows\brpcfx.ini
    [2012/05/09 15:06:12 | 000,006,615 | ---- | C] () -- C:\Windows\BRPARAM.INI
    [2012/05/09 15:04:17 | 000,000,066 | ---- | C] () -- C:\Windows\Brfaxrx.ini
    [2012/05/09 15:04:16 | 000,000,000 | ---- | C] () -- C:\Windows\brdfxspd.dat
    [2012/05/09 15:03:57 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\BRTCPCON.DLL
    [2012/05/09 15:03:51 | 000,000,114 | ---- | C] () -- C:\Windows\SysWow64\BRLMW03A.INI
    [2012/03/12 11:21:19 | 000,000,068 | ---- | C] () -- C:\Windows\spwdr.INI
    [2012/03/12 11:19:57 | 000,000,077 | ---- | C] () -- C:\Windows\Crypkey.ini
    [2012/03/12 11:19:54 | 000,027,648 | R--- | C] () -- C:\Windows\Setup_ck.exe
    [2012/03/12 11:19:54 | 000,018,432 | ---- | C] () -- C:\Windows\Setup_ck.dll
    [2012/03/12 11:19:54 | 000,011,776 | ---- | C] () -- C:\Windows\Ckrfresh.exe
    [2011/09/30 14:13:14 | 000,219,911 | ---- | C] () -- C:\Windows\hpoins35.dat.temp
    [2011/08/25 10:46:15 | 000,077,883 | ---- | C] () -- C:\Windows\hpqins05.dat.temp
    [2011/08/25 10:45:19 | 000,073,409 | ---- | C] () -- C:\Windows\hpqins11.dat
    [2011/08/25 10:44:26 | 000,023,117 | ---- | C] () -- C:\Windows\hpqins15.dat.temp
    [2011/08/25 10:41:12 | 000,076,014 | ---- | C] () -- C:\Windows\hpqins01.dat.temp
    [2011/08/19 14:02:15 | 000,077,883 | ---- | C] () -- C:\Windows\hpqins05.dat
    [2011/08/19 14:00:36 | 000,076,014 | ---- | C] () -- C:\Windows\hpqins01.dat
    [2011/08/10 09:51:25 | 000,000,778 | ---- | C] () -- C:\Windows\hpomdl35.dat.temp
    [2011/08/09 15:55:22 | 000,005,474 | ---- | C] () -- C:\Windows\hpomdl21.dat.temp
    [2011/01/13 16:12:36 | 000,001,854 | ---- | C] () -- C:\Users\Robert Jameson\AppData\Roaming\GhostObjGAFix.xml
    [2010/11/05 08:23:31 | 000,000,053 | ---- | C] () -- C:\Windows\DVDFab.INI
    [2010/09/23 13:38:43 | 000,000,016 | ---- | C] () -- C:\Users\Robert Jameson\persistent_state
    [2010/08/28 17:26:45 | 000,099,384 | ---- | C] () -- C:\Users\Robert Jameson\AppData\Roaming\inst.exe
    [2010/01/22 13:57:04 | 000,000,000 | ---- | C] () -- C:\Users\Robert Jameson\AppData\Roaming\downloads.m3u
    [2010/01/19 15:57:35 | 000,000,159 | ---- | C] () -- C:\Users\Robert Jameson\AppData\Roaming\default.rss
    [2010/01/19 11:13:18 | 000,000,678 | ---- | C] () -- C:\ProgramData\ProgramData - Shortcut.lnk
    [2010/01/12 10:06:44 | 000,007,598 | ---- | C] () -- C:\Users\Robert Jameson\AppData\Local\Resmon.ResmonCfg
    [2010/01/11 22:39:01 | 000,099,384 | ---- | C] () -- C:\Users\Robert Jameson\AppData\Roaming\ezpinst.exe
    [2010/01/11 22:39:01 | 000,007,796 | ---- | C] () -- C:\Users\Robert Jameson\AppData\Roaming\pcouffin.cat
    [2010/01/11 22:39:01 | 000,001,167 | ---- | C] () -- C:\Users\Robert Jameson\AppData\Roaming\pcouffin.inf

    ========== ZeroAccess Check ==========

    [2009/07/13 21:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

    [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

    [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
    "" = C:\Windows\SysNative\shell32.dll -- [2012/06/08 22:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
    "" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 21:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 18:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
    "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 05:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 18:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Both

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:C46995DA
    < End of report >
     
  8. Gizzy

    Gizzy Malware Specialist

    Joined:
    Aug 2, 2005
    Messages:
    3,832
    Hi gobob, :)
    Apologies for the delay.

    Important: There's a problem with the version of OTL you're using, before following the OTL instructions below,
    Please delete OTL.exe from your desktop and download a fresh copy from Here

    You have a lot of toolbars/browser addons installed, They will often hijack/change your home page and default search engine as well as redirect your searches.
    I wouldn't recommend the use of any toolbars, They are mostly for the benefit of the purveyor, not you.


    Disable Spybot TeaTimer
    Spybot will interfere with fixes so will need to be disabled, You may re-enable it once we're finished.

    1. Open Spybot-S&D in Advanced Mode.
    2. If it is not already set to do this go to the Mode menu and select Advanced Mode.
    3. On the left hand side, click on Tools.
    4. Then click on the Resident Icon in the List.
    5. Uncheck Resident TeaTimer and OK any prompts.
    6. Restart your computer.


    P2P Software
    IMPORTANT: I notice there are signs of one or more P2P (Person to Person) File Sharing Programs on your computer.

    BitTorrent

    Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

    I strongly recommend you go to Control Panel > Programs and Features and uninstall the programs listed above (in red). If you cannot find them in Programs and Features and would like them removed, let me know in your next reply.

    If you wish to keep them, please do not use them until your computer is cleaned.


    Uninstall Programs
    If some programs listed are not present, please do not panic.
    1. Go to Start > Control Panel > Programs and Features
    2. Right click on each instance of:
      • Advertising Center
      • Ask Toolbar
      • Bucksbee Loyalty Plugin - 100815
      • PlayBryte
      • Privacy SafeGuard version 1.1
      • SelectionLinks
      • Yontoo 1.10.02


      I also highly recommend you uninstall the following, But it's up to you.

      • Conduit Engine
      • Coupon Printer for Windows
      • D-Link Toolbar
      • Homepage Protection
      • Inbox Toolbar
      • Productivity 3 Toolbar
      • SimpUtil Maps 1 Toolbar
      • Yahoo! Toolbar

    3. Click Uninstall & then follow the prompts to remove it.


    Run OTL Script
    If you didn't download a new copy of OTL do not continue with the instructions below

    1. Right-click OTL.exe and select Run as administrator to start the program
    2. Copy and Paste everything from the Code box below into the Custom Scans/Fixes box in OTL
      Code:
      :Commands
      [CREATERESTOREPOINT]
      
      :OTL
      MOD - [2012/10/03 11:10:22 | 000,378,880 | ---- | M] () -- C:\Users\Robert Jameson\AppData\LocalLow\FCTB000100815\Toolbar\Helper.dll
      MOD - [2012/10/03 11:10:22 | 000,378,880 | ---- | M] () -- C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\Helper.dll
      MOD - [2012/10/03 11:10:21 | 001,615,360 | ---- | M] () -- C:\Users\Robert Jameson\AppData\LocalLow\FCTB000100815\Toolbar\Toolbar.dll
      MOD - [2012/10/03 11:10:21 | 001,615,360 | ---- | M] () -- C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\Toolbar.dll
      IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\URLSearchHook: {4d95229d-bcd1-51b4-d184-411b9857a1f4} - C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\Helper.dll ()
      [2012/10/03 11:10:44 | 000,000,000 | ---D | M] (PlayBryte) -- C:\Users\Robert Jameson\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\playbryte@pla ybryte.com
      IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=iro...B&cr=436995085
      O2 - BHO: (eSupport Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
      IE:64bit: - HKLM\..\SearchScopes\{BEC2075C-8E0A-4EB6-8D5D-A840665B39C9}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
      IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=iro...B&cr=436995085
      IE - HKLM\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://slirsredirect.search.aol.com/...romesbox-en-us
      IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://start.funmoods.com/results.ph...B&cr=436995085
      IE - HKLM\..\SearchScopes\{BEC2075C-8E0A-4EB6-8D5D-A840665B39C9}: "URL" = http://www.ask.com/web?q={searchterms}&l=dis&o=ushpl
      IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\URLSearchHook: - No CLSID value found
      IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\SearchScopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}: "URL" = Playbryte-fa-bndl/search/redirect/?type=default&user_id=bd2cb4d6-b56d-4e30-9244-522037568cee&query={searchTerms}
      O2:64bit: - BHO: (Privacy Safeguard BHO) - {1036AD63-AEAC-460B-9060-C96005D4DC86} - C:\Program Files\PrivacySafeGuard\PrivacySafeGuard-x64.dll (PrivacySafeguard)
      O2 - BHO: (no name) - {1036AD63-AEAC-460B-9060-C96005D4DC86} - No CLSID value found.
      O2 - BHO: (Bucksbee Loyalty Plugin - 100815) - {E5C2A1FE-86DB-87B4-11F0-1AA2579E81DD} - C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\BucksBee Loyalty Plugin.dll (Freecause Inc.)
      O2 - BHO: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll ()
      O2 - BHO: (Privacy Safeguard BHO) - {A42D2EB4-DD31-4BB5-8AA5-8D4E04806DBE} - C:\Program Files\PrivacySafeGuard\PrivacySafeGuard.dll (PrivacySafeguard)
      O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll ()
      O3 - HKLM\..\Toolbar: (eSupport Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
      O3 - HKLM\..\Toolbar: (no name) - {b278d9f8-0fa9-465e-9938-0c392605d8e3} - No CLSID value found.
      O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
      O3 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (eSupport Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
      O3 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (no name) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No CLSID value found.
      O3 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll ()
      O4 - HKLM..\Run: [ApnUpdater] C:\Program Files (x86)\Ask.com\Updater\Updater.exe (Ask)
      O15 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
      O15 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..Trusted Domains: usgs.gov ([sslearthquake] https in Trusted sites)
      O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Reg Error: Unable to open value key)
      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_31)
      O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_31)
      O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_31)
      [2012/06/23 13:46:14 | 000,000,130 | ---- | C] () -- C:\Windows\SysWow64\lp3codec32win.dll
      [2012/06/23 13:34:36 | 000,000,075 | ---- | C] () -- C:\Windows\SysWow64\mp3codec32win.dll
      [3 C:\Users\Robert Jameson\*.tmp files -> C:\Users\Robert Jameson\*.tmp -> ]
      [21 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
      [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
      @Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:C46995DA
      
      :Files
      C:\Program Files (x86)\Playbryte
      C:\Users\Robert Jameson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bucksbee Loyalty Plugin - 100815
      C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815
      C:\Program Files (x86)\OApps
      C:\Program Files\PrivacySafeGuard
      C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Privacy SafeGuard
      
      :Commands
      [EMPTYTEMP]
    3. Then click the Run Fix button at the top.
    4. If prompted, Click OK
    5. OTL may ask to reboot the computer. Please do so if asked
    6. When finished a report should appear in Notepad. Copy and Paste that report in your next reply.

      Note: The log can also be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log


    Please reply with:
    • OTL log
    • Update on computer's performance
     
  9. gobob

    gobob Thread Starter

    Joined:
    Oct 3, 2012
    Messages:
    25
    OTL log
    Update on computer's performance

    Was able to remove all listed programs that were installed except for Conduit. This program refuses to uninstall. I tried through the control panel and also by going to the uninstall exe. in the program file. It just won't go away. Here is log file.

    All processes killed
    Error: Unable to interpret <Code:> in the current context!
    ========== COMMANDS ==========
    Restore point Set: OTL Restore Point
    ========== OTL ==========
    Registry value HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{4d95229d-bcd1-51b4-d184-411b9857a1f4} not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4d95229d-bcd1-51b4-d184-411b9857a1f4}\ not found.
    File C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\Helper.dll not found.
    Folder C:\Users\Robert Jameson\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\playbryte@pla ybryte.com\ not found.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ deleted successfully.
    C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll moved successfully.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BEC2075C-8E0A-4EB6-8D5D-A840665B39C9}\ deleted successfully.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEC2075C-8E0A-4EB6-8D5D-A840665B39C9}\ not found.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BEC2075C-8E0A-4EB6-8D5D-A840665B39C9}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEC2075C-8E0A-4EB6-8D5D-A840665B39C9}\ not found.
    Registry value HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
    Registry key HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Microsoft\Internet Explorer\SearchScopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}\ not found.
    64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1036AD63-AEAC-460B-9060-C96005D4DC86}\ not found.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1036AD63-AEAC-460B-9060-C96005D4DC86}\ not found.
    File C:\Program Files\PrivacySafeGuard\PrivacySafeGuard-x64.dll not found.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1036AD63-AEAC-460B-9060-C96005D4DC86}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1036AD63-AEAC-460B-9060-C96005D4DC86}\ not found.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E5C2A1FE-86DB-87B4-11F0-1AA2579E81DD}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E5C2A1FE-86DB-87B4-11F0-1AA2579E81DD}\ not found.
    File C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\BucksBee Loyalty Plugin.dll not found.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D425283-D487-4337-BAB6-AB8354A81457}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9D425283-D487-4337-BAB6-AB8354A81457}\ deleted successfully.
    C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll moved successfully.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A42D2EB4-DD31-4BB5-8AA5-8D4E04806DBE}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A42D2EB4-DD31-4BB5-8AA5-8D4E04806DBE}\ not found.
    File C:\Program Files\PrivacySafeGuard\PrivacySafeGuard.dll not found.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{9D425283-D487-4337-BAB6-AB8354A81457} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9D425283-D487-4337-BAB6-AB8354A81457}\ not found.
    File C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll not found.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
    File C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll not found.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{b278d9f8-0fa9-465e-9938-0c392605d8e3} not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b278d9f8-0fa9-465e-9938-0c392605d8e3}\ not found.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
    Registry value HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
    File C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll not found.
    Registry value HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{1392B8D2-5C05-419F-A8F6-B9F15A596612} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1392B8D2-5C05-419F-A8F6-B9F15A596612}\ not found.
    Registry value HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{9D425283-D487-4337-BAB6-AB8354A81457} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9D425283-D487-4337-BAB6-AB8354A81457}\ not found.
    File C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll not found.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ApnUpdater deleted successfully.
    C:\Program Files (x86)\Ask.com\Updater\Updater.exe moved successfully.
    Registry key HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\intuit.com\ttlc\ deleted successfully.
    Registry key HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\usgs.gov\sslearthquake\ deleted successfully.
    Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
    64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
    Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
    Starting removal of ActiveX control {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ not found.
    Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
    C:\Windows\SysWOW64\lp3codec32win.dll moved successfully.
    C:\Windows\SysWOW64\mp3codec32win.dll moved successfully.
    C:\Users\Robert Jameson\2558.tmp\MakeExecutableAction_zg_ia_sf.jar6822.tmp deleted successfully.
    C:\Users\Robert Jameson\2558.tmp\MakeExecutableAction_zg_ia_sf.jar7300.tmp deleted successfully.
    C:\Users\Robert Jameson\2558.tmp folder deleted successfully.
    C:\Users\Robert Jameson\3286.tmp\MakeExecutableAction_zg_ia_sf.jar2679.tmp deleted successfully.
    C:\Users\Robert Jameson\3286.tmp\MakeExecutableAction_zg_ia_sf.jar5206.tmp deleted successfully.
    C:\Users\Robert Jameson\3286.tmp folder deleted successfully.
    C:\Users\Robert Jameson\7778.tmp\MakeExecutableAction_zg_ia_sf.jar0596.tmp deleted successfully.
    C:\Users\Robert Jameson\7778.tmp\MakeExecutableAction_zg_ia_sf.jar4071.tmp deleted successfully.
    C:\Users\Robert Jameson\7778.tmp folder deleted successfully.
    C:\Windows\SysWow64\SET29F5.tmp deleted successfully.
    C:\Windows\SysWow64\SET393C.tmp deleted successfully.
    C:\Windows\SysWow64\SET3AE8.tmp deleted successfully.
    C:\Windows\SysWow64\SET3D86.tmp deleted successfully.
    C:\Windows\SysWow64\SET4458.tmp deleted successfully.
    C:\Windows\SysWow64\SET44B9.tmp deleted successfully.
    C:\Windows\SysWow64\SET45A7.tmp deleted successfully.
    C:\Windows\SysWow64\SET4969.tmp deleted successfully.
    C:\Windows\SysWow64\SET4D7D.tmp deleted successfully.
    C:\Windows\SysWow64\SET5B16.tmp deleted successfully.
    C:\Windows\SysWow64\SET73D0.tmp deleted successfully.
    C:\Windows\SysWow64\SET7F08.tmp deleted successfully.
    C:\Windows\SysWow64\SET823.tmp deleted successfully.
    C:\Windows\SysWow64\SET9FC.tmp deleted successfully.
    C:\Windows\SysWow64\SETA4B.tmp deleted successfully.
    C:\Windows\SysWow64\SETB114.tmp deleted successfully.
    C:\Windows\SysWow64\SETB5C3.tmp deleted successfully.
    C:\Windows\SysWow64\SETB765.tmp deleted successfully.
    C:\Windows\SysWow64\SETED3F.tmp deleted successfully.
    C:\Windows\SysWow64\SETF018.tmp deleted successfully.
    C:\Windows\SysWow64\SETF901.tmp deleted successfully.
    C:\Windows\msdownld.tmp folder deleted successfully.
    ADS C:\ProgramData\Temp:C46995DA deleted successfully.
    ========== FILES ==========
    File\Folder C:\Program Files (x86)\Playbryte not found.
    File\Folder C:\Users\Robert Jameson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bucksbee Loyalty Plugin - 100815 not found.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\util folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\weatherplugin\proppage folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\weatherplugin folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\searchcomponent folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\rssreader\proppage\images folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\rssreader\proppage folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\rssreader folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\radioplugin\proppage\widgets folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\radioplugin\proppage\images folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\radioplugin\proppage folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\radioplugin\js folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\radioplugin\images folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\radioplugin\css folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\radioplugin folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\msgboxplugin folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\emailchecker\proppage\widgets folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\emailchecker\proppage folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\emailchecker folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\common\proppage folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\common folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\bookmarksplugin\proppage\images folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\bookmarksplugin\proppage folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res\bookmarksplugin folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components\res folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815\js_components folder moved successfully.
    C:\Program Files (x86)\Bucksbee Loyalty Plugin - 100815 folder moved successfully.
    C:\Program Files (x86)\OApps folder moved successfully.
    File\Folder C:\Program Files\PrivacySafeGuard not found.
    File\Folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Privacy SafeGuard not found.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 33170 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Public

    User: Robert Jameson
    ->Temp folder emptied: 341391465 bytes
    ->Temporary Internet Files folder emptied: 43505124 bytes
    ->Java cache emptied: 35262004 bytes
    ->Flash cache emptied: 41572 bytes

    User: Robert_Jameson

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 153884174 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50199 bytes
    RecycleBin emptied: 3079119 bytes

    Total Files Cleaned = 551.00 mb


    OTL by OldTimer - Version 3.2.69.0 log created on 10072012_221606
    Files\Folders moved on Reboot...
    C:\Users\Robert Jameson\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    C:\Users\Robert Jameson\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
    C:\Users\Robert Jameson\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VY2OV9ON\1071265-funmoods[2].htm moved successfully.
    C:\Users\Robert Jameson\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3G1KAUAT\si[3].htm moved successfully.
    File move failed. C:\Windows\temp\Temporary Internet Files\Content.IE5\ZRANX1SX\desktop.ini scheduled to be moved on reboot.
    C:\Windows\temp\Temporary Internet Files\Content.IE5\ZRANX1SX\IDR_XML_DEFAULT_TRANSFORM[1] moved successfully.
    File move failed. C:\Windows\temp\Temporary Internet Files\Content.IE5\O81V39A4\desktop.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\Temporary Internet Files\Content.IE5\AD7FRXD8\desktop.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\Temporary Internet Files\Content.IE5\75NU619D\desktop.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\Temporary Internet Files\Content.IE5\desktop.ini scheduled to be moved on reboot.
    C:\Windows\temp\Nuance\OmniPageCSDK16\007044\temp11111121.ct2 moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\007044\temp11111122.ct2 moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\007044\temp11111124.ct0 moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\007044\temp11111125.ct0 moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\006812\temp11111223.pfb moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\006812\temp11111224.pfb moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\006812\temp11111225.pfb moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\006812\temp11111226.pfb moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\006812\temp11111227.pfb moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\006812\temp11111228.pfb moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\006812\temp11111229.pfb moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\006520\temp11111111.ttf moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\006520\temp11111112.ttf moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\006140\temp11111125.ttf moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\006140\temp11111126.ttf moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\006140\temp11111127.ttf moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\006140\temp11111128.ttf moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\005924\temp11111111.pfb moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\005924\temp11111112.pfb moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\005924\temp11111113.pfb moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\005684\temp11111115.pfb moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\005684\temp11111116.pfb moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\005684\temp11111117.pfb moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\004672\temp11111111.pfb moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\003700\temp11111122.ct0 moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\003700\temp11111123.ct0 moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\003700\temp11111124.ct0 moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\003136\temp11111120.ct2 moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\003136\temp11111122.ct0 moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\003136\temp11111123.ct0 moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\003136\temp11111124.ct0 moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\002496\temp11111111.pfb moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\001728\temp11111115.ttf moved successfully.
    C:\Windows\temp\Nuance\OmniPageCSDK16\001728\temp11111116.ttf moved successfully.
    File move failed. C:\Windows\temp\Low\MSI\SkypeToolbars.msi scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\History\History.IE5\desktop.ini scheduled to be moved on reboot.
    File\Folder C:\Windows\temp\ACLM\ACLMLog.txt not found!
    File\Folder C:\Windows\temp\ACLM\CPSSMasterCatalog.ini not found!
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_common.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off_overlay.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off_overlay.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off_overlay.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off_overlay.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off_overlay.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off_overlay.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off_overlay.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off_overlay.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on_overlay.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on_overlay.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on_overlay.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on_overlay.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on_overlay.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on_overlay.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on_overlay.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on_overlay.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_off.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_off.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_off.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_off.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_off.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_off.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_off.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_off.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_on.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_on.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_on.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_on.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_on.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_on.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_on.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_on.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_no_atmosphere.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_no_atmosphere.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_no_atmosphere.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_no_atmosphere.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_no_atmosphere.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_no_atmosphere.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_sun_no_atmosphere.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_sun_no_atmosphere.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_sun_no_atmosphere.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_sun_no_atmosphere.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_sun_no_atmosphere.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_sun_no_atmosphere.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\ground_overlay_no_atmosphere.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\ground_overlay_no_atmosphere.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\ground_overlay_no_atmosphere.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\ground_overlay_no_atmosphere.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\ground_overlay_no_atmosphere.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\ground_overlay_no_atmosphere.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\ground_overlay_no_atmosphere.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\ground_overlay_no_atmosphere.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on_overlay.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on_overlay.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on_overlay.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on_overlay.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on_overlay.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on_overlay.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on_overlay.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on_overlay.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_sky_sun_on.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_sky_sun_on.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_sky_sun_on.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_sky_sun_on.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_sky_sun_on.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_sky_sun_on.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\precipitation_double_cone.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\precipitation_double_cone.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\precipitation_double_cone.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\precipitation_double_cone.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\precipitation_double_cone.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\precipitation_double_cone.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbillboard.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbillboard.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbillboard.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbillboard.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbillboard.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbillboard.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbranch.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbranch.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbranch.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbranch.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbranch.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbranch.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stcommonobjects.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stfrond.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stfrond.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stfrond.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stfrond.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stfrond.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stfrond.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafcard.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafcard.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafcard.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafcard.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafcard.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafcard.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafmesh.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafmesh.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafmesh.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafmesh.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafmesh.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafmesh.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\watersurface.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\watersurface.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\watersurface.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\watersurface.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\watersurface.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\watersurface.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\watersurface.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\watersurface.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\planet\earth.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\keyboard\generic.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\keyboard\sr22.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\hud\generic.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\hud\sr22.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\generic.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\genius_maxfighter_f16u.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\logitech_attack3.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\logitech_extreme_3d.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\logitech_force_3d.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\logitech_freedom.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\saitek_cyborg_evo.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\saitek_x52.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\speed_link_black_hawk.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\speed_link_black_widow.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\speed_link_cougar_flightstick.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\speed_link_dark_tornado.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\xbox_360.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\aircraft\f16.acf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\aircraft\sr22.acf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\flightsim.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\application.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\balloons.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\builtin_webdata.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\cursor_crosshair_inverse.png scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\cursor_crosshair_thick.png scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\doppler.txt scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\effects.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\leftpanel-common.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\leftpanel-layer.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\localshapes.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\navcontrols.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\notifications.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\progress.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\renderui.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\search.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\spin_icon.png scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\statusbar.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\terrainmgr.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\tmcontrols.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\toolbar.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\tourcontrols.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\unknown_plugin.png scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\userpalette.kml scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\webbrowser.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\ar.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\bg.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\ca.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\cs.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\da.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\de.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\el.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\en.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\es-419.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\es.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\fa.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\fi.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\fil.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\fr.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\he.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\hi.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\hr.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\hu.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\id.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\it.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\ja.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\ko.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\lt.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\lv.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\nl.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\no.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\pl.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\pt-PT.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\pt.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\ro.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\ru.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\sk.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\sl.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\sr.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\sv.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\th.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\tr.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\uk.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\vi.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\zh-Hans.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\zh-Hant-HK.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\zh-Hant.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\drivers.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\earthps.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\geplugin.exe scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\ge_expat.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\googleearth.exe.local scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\googleearth_free.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\google_earth.ico scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\gpl.txt scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\ImporterGlobalSettings.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\ImporterUISettings.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\kh20 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\msvcp100.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\msvcr100.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\npgeplugin.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\PCOptimizations.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\plugin_ax.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\uninstall.ico scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_common.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off_overlay.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off_overlay.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off_overlay.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off_overlay.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off_overlay.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off_overlay.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off_overlay.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off_overlay.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on_overlay.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on_overlay.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on_overlay.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on_overlay.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on_overlay.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on_overlay.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on_overlay.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on_overlay.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_off.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_off.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_off.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_off.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_off.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_off.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_off.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_off.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_on.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_on.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_on.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_on.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_on.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_on.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_on.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_on.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_no_atmosphere.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_no_atmosphere.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_no_atmosphere.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_no_atmosphere.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_no_atmosphere.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_no_atmosphere.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_sun_no_atmosphere.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_sun_no_atmosphere.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_sun_no_atmosphere.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_sun_no_atmosphere.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_sun_no_atmosphere.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_sun_no_atmosphere.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\ground_overlay_no_atmosphere.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\ground_overlay_no_atmosphere.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\ground_overlay_no_atmosphere.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\ground_overlay_no_atmosphere.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\ground_overlay_no_atmosphere.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\ground_overlay_no_atmosphere.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\ground_overlay_no_atmosphere.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\ground_overlay_no_atmosphere.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on_overlay.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on_overlay.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on_overlay.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on_overlay.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on_overlay.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on_overlay.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on_overlay.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on_overlay.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_sky_sun_on.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_sky_sun_on.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_sky_sun_on.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_sky_sun_on.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_sky_sun_on.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_sky_sun_on.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\precipitation_double_cone.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\precipitation_double_cone.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\precipitation_double_cone.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\precipitation_double_cone.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\precipitation_double_cone.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\precipitation_double_cone.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbillboard.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbillboard.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbillboard.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbillboard.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbillboard.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbillboard.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbranch.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbranch.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbranch.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbranch.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbranch.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbranch.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stcommonobjects.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stfrond.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stfrond.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stfrond.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stfrond.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stfrond.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stfrond.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafcard.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafcard.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafcard.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafcard.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafcard.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafcard.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafmesh.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafmesh.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafmesh.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafmesh.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafmesh.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafmesh.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\watersurface.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\watersurface.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\watersurface.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\watersurface.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\watersurface.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\watersurface.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\watersurface.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\watersurface.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\planet\earth.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\keyboard\generic.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\keyboard\sr22.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\hud\generic.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\hud\sr22.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\generic.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\genius_maxfighter_f16u.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\logitech_attack3.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\logitech_extreme_3d.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\logitech_force_3d.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\logitech_freedom.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\saitek_cyborg_evo.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\saitek_x52.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\speed_link_black_hawk.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\speed_link_black_widow.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\speed_link_cougar_flightstick.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\speed_link_dark_tornado.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\xbox_360.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\aircraft\f16.acf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\aircraft\sr22.acf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\flightsim.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\application.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\balloons.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\builtin_webdata.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\cursor_crosshair_inverse.png scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\cursor_crosshair_thick.png scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\default_myplaces.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\doppler.txt scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\effects.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\leftpanel-common.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\leftpanel-layer.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\localshapes.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\navcontrols.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\notifications.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\progress.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\renderui.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\search.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\spin_icon.png scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\startinglocations-nonmac.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\startinglocations.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\statusbar.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\terrainmgr.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\tmcontrols.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\toolbar.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\tourcontrols.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\unknown_plugin.png scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\userpalette.kml scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\webbrowser.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\Plugins\npgeinprocessplugin.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\ar.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\bg.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\ca.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\cs.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\da.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\de.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\el.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\en.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\es-419.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\es.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\fa.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\fi.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\fil.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\fr.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\he.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\hi.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\hr.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\hu.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\id.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\it.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\ja.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\ko.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\lt.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\lv.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\nl.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\no.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\pl.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\pt-PT.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\pt.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\ro.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\ru.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\sk.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\sl.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\sr.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\sv.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\th.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\tr.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\uk.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\vi.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\zh-Hans.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\zh-Hant-HK.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\zh-Hant.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\drivers.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\earthflashsol.exe scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\earthps.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\ge_expat.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\googleearth.exe scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\googleearth.exe.local scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\googleearth_free.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\google_earth.ico scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\gpl.txt scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\gpsbabel.exe scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\ImporterGlobalSettings.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\ImporterUISettings.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\kh20 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\kml_file.ico scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\kmz_file.ico scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\msvcp100.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\msvcr100.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\PCOptimizations.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\uninstall.ico scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\wavdest.ax scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\LocalAppData\Google\Custom Buttons\toolbar.google.com_MXE8GT6B9RBHXCGLZ06L.xml scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0402.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0403.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0404.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0405.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0406.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0407.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0408.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0409.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x040a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x040b.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x040c.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x040d.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x040e.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0410.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0411.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0412.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0413.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0414.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0415.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0416.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0418.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0419.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x041a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x041b.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x041d.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x041e.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x041f.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0421.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0422.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0424.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0426.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0427.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x042a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0804.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0809.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x080a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0816.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0c01.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0c0a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0c1a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x100a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x140a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x180a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x1c0a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x200a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x240a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x280a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x2c0a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x300a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x340a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x380a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x3c0a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\10250.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1026.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1027.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1028.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1029.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1030.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1031.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1032.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1033.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1034.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1035.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1036.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1037.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1038.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1040.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1041.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1042.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1043.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1044.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1045.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1046.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1048.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1049.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1050.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1051.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1053.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1054.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1055.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1057.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1058.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1060.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1062.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1063.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1066.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\11274.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\12298.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\13322.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\14346.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\15370.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\2052.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\2057.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\2058.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\2070.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\3073.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\3082.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\3098.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\4106.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\5130.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\6154.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\7178.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\8202.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\9226.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\Google Earth.msi scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\GoogleEarth.exe scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\Setup.ini scheduled to be moved on reboot.
    PendingFileRenameOperations files...
    Registry entries deleted on Reboot...
     
  10. Gizzy

    Gizzy Malware Specialist

    Joined:
    Aug 2, 2005
    Messages:
    3,832
    Hi gobob,

    Toolbars don't always uninstall easily, We can remove it manually.


    Malwarebytes Anti-Malware
    1. Launch Malwarebytes Anti-Malware. (Right-click and select Run as administrator)
    2. Click the Update tab.
    3. Click Check for Updates and wait for it to finish updating.
    4. Click the Scanner tab, Select Perform quick scan, Then click Scan.
    5. When the scan is complete, click OK, then Show Results to view the results.
    6. Check all items, then click on Remove Selected.
    7. When completed, a log will open in Notepad. Please post that log in your next reply.

    The log is automatically saved and can be viewed by clicking the Logs tab in Malwarebytes' Anti-Malware. It can also be found here:
    • C:\Users\Username\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

    Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


    Run OTL Quick Scan
    1. Right-click on OTL.exe and select Run as administrator to run it. Make sure all other windows are closed and let it run uninterrupted.
    2. Check the box beside Scan All Users
    3. Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    4. When the scan completes, it will open a notepad window. OTL.Txt. This is saved in the same location as OTL.
    5. Please copy (Edit > Select All -- Edit > Copy) the contents of this file, and post it with your next reply.


    SystemLook
    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2
    1. Right-click SystemLook.exe and select Run as administrator to run it.
    2. Copy the contents of the following codebox into the main textfield:
      Code:
      :filefind
      *Conduit*
      *SimpUtil_Maps_1*
      *Productivity_3*
      *Search Toolbar*
      *playbryte*
      *PrivacySafeGuard*
      *Privacy SafeGuard*
      
      :folderfind
      *Conduit*
      *SimpUtil_Maps_1*
      *Productivity_3*
      *Search Toolbar*
      *playbryte*
      *PrivacySafeGuard*
      *Privacy SafeGuard*
      
      :Regfind
      Conduit
      SimpUtil_Maps_1
      Productivity_3
      Search Toolbar
      playbryte
      PrivacySafeGuard
      Privacy SafeGuard
    3. Click the Look button to start the scan.
    4. When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt


    Please reply with:
    • Malwarebytes' Anti-Malware log
    • OTL log
    • SystemLook log
     
  11. gobob

    gobob Thread Starter

    Joined:
    Oct 3, 2012
    Messages:
    25
    Malwarebytes' Anti-Malware log
    OTL log
    SystemLook log
    I'm having a problem replying so will post each log seperately:
    Malwarebytes Anti-Malware (Trial) 1.65.0.1400
    www.malwarebytes.org

    Database version: v2012.10.08.07

    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 9.0.8112.16421
    Robert Jameson :: ROBERTJAMESON [administrator]

    Protection: Enabled

    10/8/2012 1:02:42 PM
    mbam-log-2012-10-08 (13-02-42).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 220014
    Time elapsed: 7 minute(s), 24 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 1
    HKLM\SOFTWARE\Google\Chrome\Extensions\kincjchfokkeneeofpeefomkikfkiedl (PUP.FCTPlugin) -> Quarantined and deleted successfully.

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
     
  12. gobob

    gobob Thread Starter

    Joined:
    Oct 3, 2012
    Messages:
    25
    OTL logfile created on: 10/8/2012 1:27:51 PM - Run 2
    OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Robert Jameson\Desktop
    64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.97 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 50.33% Memory free
    6.95 Gb Paging File | 4.70 Gb Available in Paging File | 67.65% Paging File free
    Paging file location(s): c:\pagefile.sys 3055 4096 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 282.91 Gb Total Space | 46.89 Gb Free Space | 16.57% Space Free | Partition Type: NTFS
    Drive D: | 298.09 Gb Total Space | 106.57 Gb Free Space | 35.75% Space Free | Partition Type: NTFS
    Drive E: | 14.99 Gb Total Space | 2.46 Gb Free Space | 16.45% Space Free | Partition Type: NTFS

    Computer Name: ROBERTJAMESON | User Name: Robert Jameson | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - File not found --
    PRC - [2012/10/07 21:06:05 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Robert Jameson\Desktop\OTL.exe
    PRC - [2012/09/07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    PRC - [2012/09/07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    PRC - [2012/09/07 17:04:44 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    PRC - [2012/07/27 13:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    PRC - [2012/07/05 18:41:46 | 003,048,136 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
    PRC - [2012/04/11 12:22:30 | 002,327,632 | ---- | M] (Xeric Design, Ltd.) -- C:\Program Files (x86)\XericDesign\EarthDesk\EarthDesk.exe
    PRC - [2012/02/23 10:30:40 | 000,059,240 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
    PRC - [2011/06/01 09:42:28 | 000,071,432 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoDashboard.exe
    PRC - [2011/06/01 09:42:28 | 000,014,088 | ---- | M] (Memeo) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe
    PRC - [2011/06/01 09:16:54 | 002,260,992 | ---- | M] (Axentra Corporation) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe
    PRC - [2011/03/28 16:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
    PRC - [2011/03/03 20:09:54 | 001,204,224 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
    PRC - [2011/03/03 20:05:00 | 000,335,872 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
    PRC - [2010/12/23 15:36:46 | 002,629,632 | R--- | M] (Brother Industries, Ltd.) -- C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
    PRC - [2010/06/02 16:22:38 | 000,077,656 | ---- | M] (Intuit Inc.) -- C:\Program Files (x86)\Quicken\bagent.exe
    PRC - [2010/03/09 00:42:02 | 000,029,984 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe
    PRC - [2010/03/09 00:40:36 | 000,144,672 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
    PRC - [2010/03/05 20:11:30 | 000,636,192 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
    PRC - [2010/01/25 08:22:56 | 000,245,760 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files (x86)\Browny02\BrYNSvc.exe
    PRC - [2009/11/11 16:17:02 | 000,771,360 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\AirPort\APAgent.exe
    PRC - [2009/09/29 07:17:50 | 000,013,088 | ---- | M] (Intuit Inc.) -- C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe
    PRC - [2009/09/23 12:38:18 | 000,935,208 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
    PRC - [2009/09/10 13:12:10 | 000,185,632 | ---- | M] (Protexis Inc.) -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
    PRC - [2009/07/30 17:42:34 | 000,013,600 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
    PRC - [2009/07/23 20:45:52 | 000,128,296 | ---- | M] (CyberLink Corp.) -- c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
    PRC - [2009/07/23 11:37:16 | 000,206,120 | ---- | M] (CyberLink) -- c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
    PRC - [2009/06/04 19:03:32 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    PRC - [2009/06/04 19:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
    PRC - [2009/05/05 16:06:06 | 000,222,496 | ---- | M] (Acresso Corporation) -- C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
    PRC - [2009/03/13 15:14:04 | 010,584,629 | ---- | M] () -- C:\Program Files (x86)\myiHome\app\myiHome-server.exe
    PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
    PRC - [2008/11/09 13:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe


    ========== Modules (No Company Name) ==========

    MOD - [2012/06/14 03:41:22 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\69ca4a43ba14b66689715ad62aed70e6\System.ServiceProcess.ni.dll
    MOD - [2012/06/14 03:41:14 | 011,833,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll
    MOD - [2012/06/14 03:40:44 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
    MOD - [2012/06/14 03:40:36 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
    MOD - [2012/05/10 03:52:24 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
    MOD - [2012/05/10 03:51:28 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\2ec98ab0193d64e95b7d09d094deed97\Accessibility.ni.dll
    MOD - [2012/05/10 03:50:59 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
    MOD - [2012/05/10 03:50:52 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
    MOD - [2012/05/10 03:50:51 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
    MOD - [2012/05/10 03:50:37 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
    MOD - [2012/03/27 14:49:18 | 000,843,776 | ---- | M] () -- C:\Program Files (x86)\XericDesign\EarthDesk\libeay32.dll
    MOD - [2012/03/27 14:47:32 | 000,094,208 | ---- | M] () -- C:\Program Files (x86)\XericDesign\EarthDesk\CrashRpt1300.dll
    MOD - [2011/06/24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    MOD - [2011/06/24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    MOD - [2011/06/01 09:46:02 | 000,030,984 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SeagateSharePlusPlugin.dll
    MOD - [2011/06/01 09:42:24 | 000,108,296 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\Memeo.Progress.dll
    MOD - [2011/06/01 09:16:54 | 000,971,776 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\libxml2.dll
    MOD - [2011/06/01 09:16:54 | 000,241,664 | ---- | M] () -- C:\Program Files (x86)\Seagate\Seagate Dashboard\HipServAgent\libupnp.dll
    MOD - [2010/03/19 10:45:36 | 007,745,536 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll
    MOD - [2010/03/19 10:45:36 | 002,121,728 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll
    MOD - [2010/03/19 10:45:36 | 000,135,168 | ---- | M] () -- C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
    MOD - [2009/07/23 11:37:14 | 000,931,112 | ---- | M] () -- c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll
    MOD - [2009/03/13 15:14:04 | 010,584,629 | ---- | M] () -- C:\Program Files (x86)\myiHome\app\myiHome-server.exe
    MOD - [2009/02/27 16:38:20 | 000,139,264 | R--- | M] () -- C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
    MOD - [2006/09/05 16:24:04 | 000,058,368 | ---- | M] () -- C:\Program Files (x86)\myiHome\app\jshortcut.dll
    MOD - [2006/09/05 16:24:04 | 000,053,248 | ---- | M] () -- C:\Program Files (x86)\myiHome\app\jRegistryKey.dll
    MOD - [2006/09/05 16:24:04 | 000,051,200 | ---- | M] () -- C:\Program Files (x86)\myiHome\app\TrayIcon12.dll


    ========== Services (SafeList) ==========

    SRV:64bit: - [2012/03/26 18:49:56 | 000,291,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
    SRV:64bit: - [2012/03/26 18:49:56 | 000,012,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
    SRV:64bit: - [2011/05/13 17:58:10 | 000,030,520 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Windows\SysNative\hpservice.exe -- (hpsrv)
    SRV:64bit: - [2010/03/23 14:53:06 | 000,247,808 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\stacsv64.exe -- (STacSV)
    SRV:64bit: - [2009/07/30 17:42:34 | 000,864,032 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
    SRV:64bit: - [2009/07/13 18:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV:64bit: - [2009/07/13 18:38:59 | 000,019,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\CISVC.EXE -- (CISVC)
    SRV:64bit: - [2009/07/02 14:16:00 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
    SRV:64bit: - [2009/03/27 19:10:16 | 000,016,896 | ---- | M] (LSI Corporation) [Auto | Running] -- C:\Program Files\LSI SoftModem\agr64svc.exe -- (AgereModemAudio)
    SRV:64bit: - [2009/03/02 18:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe -- (AESTFilters)
    SRV:64bit: - [2008/05/07 16:29:38 | 000,122,880 | ---- | M] (CrypKey (Canada) Ltd.) [Auto | Running] -- C:\Windows\SysNative\Crypserv.exe -- (Crypkey License)
    SRV - [2012/09/21 00:07:07 | 000,250,288 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
    SRV - [2012/09/07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
    SRV - [2012/09/07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
    SRV - [2012/07/27 13:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
    SRV - [2012/07/13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
    SRV - [2012/07/05 18:41:46 | 003,048,136 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
    SRV - [2011/09/09 16:10:28 | 000,086,072 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe -- (HP Support Assistant Service)
    SRV - [2011/06/01 09:42:28 | 000,014,088 | ---- | M] (Memeo) [Auto | Running] -- C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe -- (SeagateDashboardService)
    SRV - [2011/03/28 16:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe -- (HPDrvMntSvc.exe)
    SRV - [2010/03/23 14:53:06 | 000,247,808 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\STacSV64.exe -- (STacSV)
    SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2010/03/09 00:40:36 | 000,144,672 | ---- | M] (Nuance Communications, Inc.) [Auto | Running] -- C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe -- (PDFProFiltSrvPP)
    SRV - [2010/01/25 08:22:56 | 000,245,760 | ---- | M] (Brother Industries, Ltd.) [On_Demand | Running] -- C:\Program Files (x86)\Browny02\BrYNSvc.exe -- (BrYNSvc)
    SRV - [2009/11/19 13:15:42 | 000,249,856 | ---- | M] (SMServer) [On_Demand | Stopped] -- C:\Windows\SysWOW64\snmvtsvc.exe -- (SMServer)
    SRV - [2009/11/19 07:52:48 | 000,335,872 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\SoundTaxi Media Suite\STSService.exe -- (STSService)
    SRV - [2009/09/29 07:17:50 | 000,013,088 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe -- (IntuitUpdateService)
    SRV - [2009/09/23 12:38:18 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
    SRV - [2009/09/10 13:12:10 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
    SRV - [2009/06/10 14:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
    SRV - [2009/06/04 19:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
    SRV - [2009/05/22 11:02:20 | 000,250,616 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe -- (GameConsoleService)
    SRV - [2009/03/02 18:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe -- (AESTFilters)
    SRV - [2008/11/09 13:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - [2012/09/07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
    DRV:64bit: - [2012/06/26 21:38:30 | 000,046,176 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)
    DRV:64bit: - [2012/06/24 22:24:48 | 000,052,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d)
    DRV:64bit: - [2012/03/20 20:44:12 | 000,098,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
    DRV:64bit: - [2012/02/29 23:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
    DRV:64bit: - [2012/02/15 09:01:50 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
    DRV:64bit: - [2011/10/14 04:37:44 | 000,396,848 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
    DRV:64bit: - [2011/05/13 17:58:16 | 000,030,008 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\hpdskflt.sys -- (hpdskflt)
    DRV:64bit: - [2011/05/13 17:57:58 | 000,043,320 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Accelerometer.sys -- (Accelerometer)
    DRV:64bit: - [2011/05/10 06:06:14 | 000,022,528 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl)
    DRV:64bit: - [2011/04/07 23:13:34 | 000,035,840 | R--- | M] (Avanquest Software) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BVRPMPR5a64.SYS -- (BVRPMPR5a64)
    DRV:64bit: - [2011/03/10 23:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
    DRV:64bit: - [2011/03/10 23:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
    DRV:64bit: - [2010/11/20 06:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
    DRV:64bit: - [2010/11/20 04:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
    DRV:64bit: - [2010/11/20 02:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
    DRV:64bit: - [2010/06/12 10:07:46 | 007,680,512 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETw5s64.sys -- (NETw5s64)
    DRV:64bit: - [2010/03/23 14:53:06 | 000,505,344 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
    DRV:64bit: - [2010/03/10 15:16:36 | 000,029,720 | ---- | M] (Initio Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ivusb.sys -- (ivusb)
    DRV:64bit: - [2010/01/11 22:39:01 | 000,082,816 | ---- | M] (VSO Software) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pcouffin.sys -- (pcouffin)
    DRV:64bit: - [2009/11/19 16:04:32 | 000,033,336 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SndTAudio.sys -- (SndTAudio)
    DRV:64bit: - [2009/07/23 10:02:38 | 005,435,904 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NETw5v64.sys -- (netw5v64)
    DRV:64bit: - [2009/07/20 20:39:00 | 000,140,712 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\jmcr.sys -- (JMCR)
    DRV:64bit: - [2009/07/13 18:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
    DRV:64bit: - [2009/07/13 18:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
    DRV:64bit: - [2009/07/13 18:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
    DRV:64bit: - [2009/07/13 17:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
    DRV:64bit: - [2009/07/13 17:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
    DRV:64bit: - [2009/07/13 17:06:48 | 000,067,072 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BTHPRINT.SYS -- (BTHprint)
    DRV:64bit: - [2009/07/13 15:31:00 | 000,233,472 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
    DRV:64bit: - [2009/07/02 14:51:00 | 006,036,480 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
    DRV:64bit: - [2009/07/01 13:46:52 | 000,098,344 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
    DRV:64bit: - [2009/07/01 13:46:48 | 000,132,648 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
    DRV:64bit: - [2009/07/01 13:46:40 | 000,021,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
    DRV:64bit: - [2009/06/29 11:17:00 | 000,070,656 | ---- | M] (ENE TECHNOLOGY INC.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\enecir.sys -- (enecir)
    DRV:64bit: - [2009/06/29 10:00:00 | 000,116,752 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
    DRV:64bit: - [2009/06/10 14:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
    DRV:64bit: - [2009/06/10 14:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
    DRV:64bit: - [2009/06/10 14:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
    DRV:64bit: - [2009/06/10 13:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
    DRV:64bit: - [2009/06/10 13:35:33 | 000,389,120 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
    DRV:64bit: - [2009/06/10 13:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
    DRV:64bit: - [2009/06/10 13:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
    DRV:64bit: - [2009/06/10 13:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
    DRV:64bit: - [2009/06/10 13:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
    DRV:64bit: - [2009/06/04 17:54:36 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
    DRV:64bit: - [2009/05/18 12:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
    DRV:64bit: - [2009/04/29 08:48:32 | 000,018,432 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
    DRV:64bit: - [2009/04/07 16:33:08 | 000,035,104 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
    DRV:64bit: - [2009/04/06 18:31:08 | 001,208,320 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\agrsm64.sys -- (AgereSoftModem)
    DRV:64bit: - [2009/02/13 10:02:52 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
    DRV:64bit: - [2008/10/09 09:17:06 | 000,005,120 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rcmirror.sys -- (rcmirror)
    DRV:64bit: - [2008/03/17 10:12:26 | 000,028,664 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\Ckldrv.sys -- (NetworkX)
    DRV - [2009/07/23 20:45:28 | 000,146,928 | ---- | M] (CyberLink Corp.) [2009/08/25 01:58:21] [Kernel | Auto | Running] -- c:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl -- ({55662437-DA8C-40c0-AADA-2C816A897A49})
    DRV - [2009/07/13 18:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
    DRV - [2009/03/30 09:45:50 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\pfc.sys -- (pfc)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cnnb
    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sea...putEncoding}&oe={outputEncoding}&sourceid=ie7
    IE:64bit: - HKLM\..\SearchScopes\{CC778948-1EA5-4599-AE7A-9807D211DCF4}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=HPNTDF&pc=HPNTDF&src=IE-SearchBox
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
    IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE - HKLM\..\SearchScopes,DefaultScope = {7E1A6753-E4DE-6627-B8AD-44AD9999F6D6}
    IE - HKLM\..\SearchScopes\{7E1A6753-E4DE-6627-B8AD-44AD9999F6D6}: "URL" = http://www.google.com/search?q={sea...putEncoding}&oe={outputEncoding}&sourceid=ie7
    IE - HKLM\..\SearchScopes\{CC778948-1EA5-4599-AE7A-9807D211DCF4}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=HPNTDF&pc=HPNTDF&src=IE-SearchBox


    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



    IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://my.yahoo.com/
    IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com/?ocid=OIE9MSE&PC=UP09
    IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
    IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sea...putEncoding}&sourceid=ie7&rlz=1I7ADRA_enUS502
    IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


    ========== FireFox ==========

    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\citius@orbiscom: C:\Program Files (x86)\Virtual Account Numbers [2010/07/29 12:27:45 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\discoversoan@orbiscom: C:\Program Files (x86)\Discover\SOAN [2012/01/19 09:07:14 | 000,000,000 | ---D | M]

    [2012/10/03 11:10:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robert Jameson\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions
    [2012/06/21 14:56:33 | 000,086,818 | ---- | M] () (No name found) -- C:\Users\Robert Jameson\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]

    O1 HOSTS File: ([2012/09/28 12:44:48 | 000,444,411 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 www.007guard.com
    O1 - Hosts: 127.0.0.1 007guard.com
    O1 - Hosts: 127.0.0.1 008i.com
    O1 - Hosts: 127.0.0.1 www.008k.com
    O1 - Hosts: 127.0.0.1 008k.com
    O1 - Hosts: 127.0.0.1 www.00hq.com
    O1 - Hosts: 127.0.0.1 00hq.com
    O1 - Hosts: 127.0.0.1 010402.com
    O1 - Hosts: 127.0.0.1 www.032439.com
    O1 - Hosts: 127.0.0.1 032439.com
    O1 - Hosts: 127.0.0.1 www.0scan.com
    O1 - Hosts: 127.0.0.1 0scan.com
    O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
    O1 - Hosts: 127.0.0.1 1000gratisproben.com
    O1 - Hosts: 127.0.0.1 1001namen.com
    O1 - Hosts: 127.0.0.1 www.1001namen.com
    O1 - Hosts: 127.0.0.1 100888290cs.com
    O1 - Hosts: 127.0.0.1 www.100888290cs.com
    O1 - Hosts: 127.0.0.1 www.100sexlinks.com
    O1 - Hosts: 127.0.0.1 100sexlinks.com
    O1 - Hosts: 127.0.0.1 www.10sek.com
    O1 - Hosts: 127.0.0.1 10sek.com
    O1 - Hosts: 127.0.0.1 www.1-2005-search.com
    O1 - Hosts: 127.0.0.1 1-2005-search.com
    O1 - Hosts: 127.0.0.1 www.123fporn.info
    O1 - Hosts: 15262 more lines...
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (Virtual Account Numbers Helper) - {17424104-1444-4810-85D7-B4DA413C5A9A} - C:\Program Files (x86)\Virtual Account Numbers\CitiVANHelper.dll (Orbiscom Ltd. All rights reserved.)
    O2 - BHO: (Secure Online Account Numbers Helper) - {435EAA86-D32B-484F-869C-53745FCB1642} - C:\Program Files (x86)\Discover\SOAN\DiscoverSOANHelper.dll (Orbiscom Ltd. All rights reserved.)
    O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
    O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Viewer Plus\bin\PlusIEContextMenu.dll (Zeon Corporation)
    O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
    O2 - BHO: (DiscoverSOANBrowserHelper Class) - {8DB3D69D-DA5E-4165-B781-72A761790672} - C:\Program Files (x86)\Discover\SOAN\DiscoverSOANBHO.dll (Orbiscom Ltd. All rights reserved.)
    O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O2 - BHO: (no name) - {F90A5A0D-CD98-49CC-9AA7-9CD11C7478BF} - No CLSID value found.
    O3:64bit: - HKLM\..\Toolbar: (Wolfram Toolbar) - {9E709AEF-74F7-4DA3-A7FC-F3E2D5A8D793} - C:\Program Files\Wolfram Research\WolframToolbar\1.0\WolframBands64.dll (Wolfram Research, Inc.)
    O3 - HKLM\..\Toolbar: (Virtual Account Numbers) - {7A21A046-B886-4A62-9D69-EF2059B0A27B} - C:\Program Files (x86)\Virtual Account Numbers\CitiVANToolbar.dll (Orbiscom Ltd. All rights reserved.)
    O3 - HKLM\..\Toolbar: (Wolfram Toolbar) - {9E709AEF-74F7-4DA3-A7FC-F3E2D5A8D793} - C:\Program Files\Wolfram Research\WolframToolbar\1.0\WolframBands32.dll (Wolfram Research, Inc.)
    O3 - HKLM\..\Toolbar: (Secure Online Account Numbers) - {A8C7C2CA-6DFD-4E16-8458-592361564D38} - C:\Program Files (x86)\Discover\SOAN\DiscoverSOANToolbar.dll (Orbiscom Ltd. All rights reserved.)
    O3 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (no name) - {19DA1AE4-A403-4535-8E93-63B3AA7F1D8E} - No CLSID value found.
    O3 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (no name) - {1FCA4DF8-9ACD-4DFB-89CC-DDD0082FC588} - No CLSID value found.
    O3 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O3 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
    O3:64bit: - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (Wolfram Toolbar) - {9E709AEF-74F7-4DA3-A7FC-F3E2D5A8D793} - C:\Program Files\Wolfram Research\WolframToolbar\1.0\WolframBands64.dll (Wolfram Research, Inc.)
    O3 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (Wolfram Toolbar) - {9E709AEF-74F7-4DA3-A7FC-F3E2D5A8D793} - C:\Program Files\Wolfram Research\WolframToolbar\1.0\WolframBands32.dll (Wolfram Research, Inc.)
    O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
    O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft Device Center\ipoint.exe (Microsoft Corporation)
    O4:64bit: - HKLM..\Run: [IntelliType Pro] C:\Program Files\Microsoft Device Center\itype.exe (Microsoft Corporation)
    O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
    O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
    O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
    O4 - HKLM..\Run: [AirPort Base Station Agent] C:\Program Files (x86)\AirPort\APAgent.exe (Apple Inc.)
    O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
    O4 - HKLM..\Run: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe (Brother Industries, Ltd.)
    O4 - HKLM..\Run: [Freecorder FLV Service] "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run File not found
    O4 - HKLM..\Run: [HPCam_Menu] c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
    O4 - HKLM..\Run: [IndexSearch] C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe (Nuance Communications, Inc.)
    O4 - HKLM..\Run: [PaperPort PTD] C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe (Nuance Communications, Inc.)
    O4 - HKLM..\Run: [PDF5 Registry Controller] C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe (Nuance Communications, Inc.)
    O4 - HKLM..\Run: [PDFHook] C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe (Nuance Communications, Inc.)
    O4 - HKLM..\Run: [PPort12reminder] C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe (Nuance Communications, Inc.)
    O4 - HKLM..\Run: [Seagate Dashboard] C:\Program Files (x86)\Seagate\Seagate Dashboard\MemeoLauncher.exe ()
    O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
    O4 - HKLM..\Run: [TaskTray] File not found
    O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
    O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
    O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
    O4 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe (Acresso Corporation)
    O4 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
    O4 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001..\Run: [QuickenScheduledUpdates] C:\Program Files (x86)\Quicken\bagent.exe (Intuit Inc.)
    O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
    O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
    O4 - Startup: C:\Users\Robert Jameson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
    O4 - Startup: C:\Users\Robert Jameson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EarthDesk.lnk = C:\Program Files (x86)\XericDesign\EarthDesk\EarthDesk.exe (Xeric Design, Ltd.)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Main present
    O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: WallpaperStyle = 2
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Main present
    O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: WallpaperStyle = 2
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Main present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Main present
    O7 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Policies\Microsoft\Internet Explorer\Main present
    O7 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: WallpaperStyle = 2
    O8:64bit: - Extra context menu item: Open with PDF Viewer Plus - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
    O8 - Extra context menu item: Open with PDF Viewer Plus - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
    O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
    O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
    O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
    O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
    O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
    O9 - Extra Button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files (x86)\SoundTaxi\YouTubeRipper.dll ()
    O9 - Extra 'Tools' menuitem : Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files (x86)\SoundTaxi\YouTubeRipper.dll ()
    O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
    O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
    O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O1364bit: - gopher Prefix: missing
    O13 - gopher Prefix: missing
    O16 - DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} http://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab (Device Detection)
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files (x86)\Yahoo!\Common\Yinsthelper.dll (Installation Support)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C68FBD48-8592-447B-B418-2824F47484D0}: DhcpNameServer = 172.18.64.215 172.18.64.215 8.8.8.8
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DD57E82F-EB9C-47D1-BFA8-44646E82965A}: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F850D49B-D327-49FA-9395-588C21B47909}: DhcpNameServer = 192.168.1.1
    O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
    O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
    O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
    O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
    O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
    O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O32 - HKLM CDRom: AutoRun - 1
    O33 - MountPoints2\{1f0b330d-2d1b-11df-94bd-0027134ffaa6}\Shell - "" = AutoRun
    O33 - MountPoints2\{1f0b330d-2d1b-11df-94bd-0027134ffaa6}\Shell\AutoRun\command - "" = "H:\WD SmartWare.exe" autoplay=true
    O33 - MountPoints2\{60c0f62a-19c8-11df-a9ff-0027134ffaa6}\Shell - "" = AutoRun
    O33 - MountPoints2\{60c0f62a-19c8-11df-a9ff-0027134ffaa6}\Shell\AutoRun\command - "" = "H:\WD SmartWare.exe" autoplay=true
    O33 - MountPoints2\{ab68575a-1e68-11e0-901c-0027134ffaa6}\Shell - "" = AutoRun
    O33 - MountPoints2\{ab68575a-1e68-11e0-901c-0027134ffaa6}\Shell\AutoRun\command - "" = "G:\WD SmartWare.exe" autoplay=true
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
    O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/10/07 22:16:06 | 000,000,000 | ---D | C] -- C:\_OTL
    [2012/10/07 21:06:04 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Robert Jameson\Desktop\OTL.exe
    [2012/10/05 16:06:51 | 000,000,000 | ---D | C] -- C:\Users\Robert Jameson\Documents\Airport Express
    [2012/10/03 10:22:53 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\Robert Jameson\Desktop\HijackThis.exe
    [2012/09/29 04:20:34 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
    [2012/09/28 12:36:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
    [2012/09/28 12:36:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
    [2012/09/28 12:36:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
    [2012/09/28 10:42:32 | 000,000,000 | ---D | C] -- C:\Users\Robert Jameson\AppData\Roaming\Malwarebytes
    [2012/09/28 10:42:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
    [2012/09/28 10:42:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
    [2012/09/28 10:42:12 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2012/09/28 10:42:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    [2012/09/25 13:58:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Mouse and Keyboard Center
    [2012/09/25 13:57:48 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Device Center
    [2012/09/25 13:41:59 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll
    [2012/09/25 13:41:59 | 000,366,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll
    [2012/09/25 13:39:36 | 000,245,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\OxpsConverter.exe
    [2012/09/25 11:49:24 | 000,000,000 | ---D | C] -- C:\ProgramData\GFI Software
    [2012/09/25 11:20:55 | 000,000,000 | ---D | C] -- C:\Users\Robert Jameson\AppData\Local\Downloaded Installations
    [2012/09/25 11:19:23 | 000,000,000 | ---D | C] -- C:\Users\Robert Jameson\AppData\Local\adawarebp
    [2012/09/24 22:29:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
    [2012/09/24 22:29:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\7-Zip
    [2012/09/24 22:26:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileOpener
    [2012/09/24 22:25:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Tweaks
    [2012/09/23 14:43:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reincubate
    [2012/09/23 14:43:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reincubate
    [2012/09/23 13:53:36 | 000,000,000 | ---D | C] -- C:\Users\Robert Jameson\AppData\Roaming\Google
    [2012/09/22 03:00:45 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
    [2012/09/22 03:00:45 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
    [2012/09/22 03:00:44 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
    [2012/09/22 03:00:43 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
    [2012/09/22 03:00:43 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
    [2012/09/22 03:00:43 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
    [2012/09/22 03:00:43 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
    [2012/09/22 03:00:43 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
    [2012/09/22 03:00:42 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
    [2012/09/22 03:00:42 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
    [2012/09/22 03:00:41 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
    [2012/09/22 03:00:41 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
    [2012/09/22 03:00:40 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
    [2012/09/22 03:00:39 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
    [2012/09/22 03:00:39 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
    [2012/09/20 16:31:01 | 000,000,000 | ---D | C] -- C:\Users\Robert Jameson\Desktop\Jenny's Pictures
    [2012/09/14 17:52:57 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\RNDISMP.sys
    [2012/09/14 17:52:56 | 000,574,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10level9.dll
    [2012/09/14 17:52:55 | 000,376,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\netio.sys
    [2012/09/14 17:52:55 | 000,288,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS
    [2010/01/11 22:39:01 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\Robert Jameson\AppData\Roaming\pcouffin.sys
    [3 C:\Users\Robert Jameson\Desktop\*.tmp files -> C:\Users\Robert Jameson\Desktop\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2012/10/08 13:06:05 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2012/10/08 12:36:00 | 000,000,914 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2012/10/08 10:36:00 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2012/10/08 04:36:38 | 000,000,368 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForRobert Jameson.job
    [2012/10/07 22:40:28 | 000,668,180 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2012/10/07 22:40:27 | 000,791,420 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2012/10/07 22:40:27 | 000,124,676 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2012/10/07 22:36:53 | 000,178,761 | ---- | M] () -- C:\SeagateAdapter
    [2012/10/07 22:29:15 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2012/10/07 22:29:15 | 000,023,248 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2012/10/07 22:20:19 | 000,000,443 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.ics
    [2012/10/07 22:20:00 | 000,000,422 | ---- | M] () -- C:\Windows\tasks\FileCure Startup.job
    [2012/10/07 22:19:41 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2012/10/07 22:19:36 | 3195,420,672 | -HS- | M] () -- C:\hiberfil.sys
    [2012/10/07 21:06:05 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Robert Jameson\Desktop\OTL.exe
    [2012/10/06 01:57:00 | 000,000,406 | ---- | M] () -- C:\Windows\tasks\FileCure.job
    [2012/10/03 10:22:03 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\Robert Jameson\Desktop\HijackThis.exe
    [2012/09/28 12:44:48 | 000,444,411 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
    [2012/09/28 12:36:37 | 000,001,244 | ---- | M] () -- C:\Users\Robert Jameson\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
    [2012/09/28 11:07:52 | 000,021,050 | ---- | M] () -- C:\Users\Robert Jameson\Documents\cc_20120928_110738.reg
    [2012/09/25 14:06:19 | 000,377,664 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
    [2012/09/25 11:41:04 | 000,000,105 | ---- | M] () -- C:\prefs.js
    [2012/09/24 22:29:18 | 000,000,258 | RHS- | M] () -- C:\Users\Robert Jameson\ntuser.pol
    [2012/09/24 09:33:23 | 000,000,456 | ---- | M] () -- C:\Users\Robert Jameson\Documents\Allow_Changing_IE_Home_Page.reg
    [2012/09/23 14:43:17 | 000,001,270 | ---- | M] () -- C:\Users\Robert Jameson\Documents\iPhone Backup Extractor.lnk
    [2012/09/21 00:07:06 | 000,696,240 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
    [2012/09/21 00:07:06 | 000,073,136 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    [2012/09/21 00:06:52 | 009,573,296 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerInstaller.exe
    [3 C:\Users\Robert Jameson\Desktop\*.tmp files -> C:\Users\Robert Jameson\Desktop\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2012/10/03 10:55:09 | 000,002,061 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
    [2012/10/03 10:55:09 | 000,001,383 | ---- | C] () -- C:\Users\Robert Jameson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
    [2012/10/03 10:55:09 | 000,001,146 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\myiHome Server.lnk
    [2012/09/28 12:36:37 | 000,001,244 | ---- | C] () -- C:\Users\Robert Jameson\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
    [2012/09/28 11:07:42 | 000,021,050 | ---- | C] () -- C:\Users\Robert Jameson\Documents\cc_20120928_110738.reg
    [2012/09/25 11:41:04 | 000,000,105 | ---- | C] () -- C:\prefs.js
    [2012/09/24 22:29:18 | 000,000,258 | RHS- | C] () -- C:\Users\Robert Jameson\ntuser.pol
    [2012/09/24 09:33:23 | 000,000,456 | ---- | C] () -- C:\Users\Robert Jameson\Documents\Allow_Changing_IE_Home_Page.reg
    [2012/09/23 14:43:17 | 000,001,282 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iPhone Backup Extractor.lnk
    [2012/09/23 14:43:17 | 000,001,270 | ---- | C] () -- C:\Users\Robert Jameson\Documents\iPhone Backup Extractor.lnk
    [2012/07/08 10:55:15 | 000,000,000 | ---- | C] () -- C:\Users\Robert Jameson\ipconfig
    [2012/05/09 15:07:09 | 000,000,795 | ---- | C] () -- C:\Windows\Brpfx04a.ini
    [2012/05/09 15:07:09 | 000,000,093 | ---- | C] () -- C:\Windows\brpcfx.ini
    [2012/05/09 15:06:12 | 000,006,615 | ---- | C] () -- C:\Windows\BRPARAM.INI
    [2012/05/09 15:04:17 | 000,000,066 | ---- | C] () -- C:\Windows\Brfaxrx.ini
    [2012/05/09 15:04:16 | 000,000,000 | ---- | C] () -- C:\Windows\brdfxspd.dat
    [2012/05/09 15:03:57 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\BRTCPCON.DLL
    [2012/05/09 15:03:51 | 000,000,114 | ---- | C] () -- C:\Windows\SysWow64\BRLMW03A.INI
    [2012/03/12 11:21:19 | 000,000,068 | ---- | C] () -- C:\Windows\spwdr.INI
    [2012/03/12 11:19:57 | 000,000,077 | ---- | C] () -- C:\Windows\Crypkey.ini
    [2012/03/12 11:19:54 | 000,027,648 | R--- | C] () -- C:\Windows\Setup_ck.exe
    [2012/03/12 11:19:54 | 000,018,432 | ---- | C] () -- C:\Windows\Setup_ck.dll
    [2012/03/12 11:19:54 | 000,011,776 | ---- | C] () -- C:\Windows\Ckrfresh.exe
    [2011/09/30 14:13:14 | 000,219,911 | ---- | C] () -- C:\Windows\hpoins35.dat.temp
    [2011/08/25 10:46:15 | 000,077,883 | ---- | C] () -- C:\Windows\hpqins05.dat.temp
    [2011/08/25 10:45:19 | 000,073,409 | ---- | C] () -- C:\Windows\hpqins11.dat
    [2011/08/25 10:44:26 | 000,023,117 | ---- | C] () -- C:\Windows\hpqins15.dat.temp
    [2011/08/25 10:41:12 | 000,076,014 | ---- | C] () -- C:\Windows\hpqins01.dat.temp
    [2011/08/19 14:02:15 | 000,077,883 | ---- | C] () -- C:\Windows\hpqins05.dat
    [2011/08/19 14:00:36 | 000,076,014 | ---- | C] () -- C:\Windows\hpqins01.dat
    [2011/08/10 09:51:25 | 000,000,778 | ---- | C] () -- C:\Windows\hpomdl35.dat.temp
    [2011/08/09 15:55:22 | 000,005,474 | ---- | C] () -- C:\Windows\hpomdl21.dat.temp
    [2011/01/13 16:12:36 | 000,001,854 | ---- | C] () -- C:\Users\Robert Jameson\AppData\Roaming\GhostObjGAFix.xml
    [2010/11/05 08:23:31 | 000,000,053 | ---- | C] () -- C:\Windows\DVDFab.INI
    [2010/09/23 13:38:43 | 000,000,016 | ---- | C] () -- C:\Users\Robert Jameson\persistent_state
    [2010/08/28 17:26:45 | 000,099,384 | ---- | C] () -- C:\Users\Robert Jameson\AppData\Roaming\inst.exe
    [2010/01/22 13:57:04 | 000,000,000 | ---- | C] () -- C:\Users\Robert Jameson\AppData\Roaming\downloads.m3u
    [2010/01/19 15:57:35 | 000,000,159 | ---- | C] () -- C:\Users\Robert Jameson\AppData\Roaming\default.rss
    [2010/01/19 11:13:18 | 000,000,678 | ---- | C] () -- C:\ProgramData\ProgramData - Shortcut.lnk
    [2010/01/12 10:06:44 | 000,007,598 | ---- | C] () -- C:\Users\Robert Jameson\AppData\Local\Resmon.ResmonCfg
    [2010/01/11 22:39:01 | 000,099,384 | ---- | C] () -- C:\Users\Robert Jameson\AppData\Roaming\ezpinst.exe
    [2010/01/11 22:39:01 | 000,007,796 | ---- | C] () -- C:\Users\Robert Jameson\AppData\Roaming\pcouffin.cat
    [2010/01/11 22:39:01 | 000,001,167 | ---- | C] () -- C:\Users\Robert Jameson\AppData\Roaming\pcouffin.inf

    ========== ZeroAccess Check ==========

    [2009/07/13 21:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

    [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

    [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
    "" = C:\Windows\SysNative\shell32.dll -- [2012/06/08 22:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
    "" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 21:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 18:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
    "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 05:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 18:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Both

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
    < End of report >
     
  13. gobob

    gobob Thread Starter

    Joined:
    Oct 3, 2012
    Messages:
    25
    SystemLook 30.07.11 by jpshortstuff
    Log created at 13:42 on 08/10/2012 by Robert Jameson
    Administrator - Elevation successful
    No Context: Code:
    No Context: ---------
    ========== filefind ==========
    Searching for "*Conduit*"
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\iSyncConduit.dll --a---- 1206120 bytes [18:44 20/01/2012] [18:44 20/01/2012] 976934130CD5C5DBD2DC977B298DF525
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\com.yahoo.go.sync.client.resources\PhoneConduit.plist --a---- 11408 bytes [03:20 11/06/2010] [03:20 11/06/2010] AB18CD2A656AE753C30E6276EC3DA0C2
    C:\Program Files (x86)\ConduitEngine\ConduitEngineHelper.exe --a---- 38496 bytes [16:25 27/02/2011] [19:37 25/03/2010] A320DF2B47CFCAF98D06EB59CD72084C
    C:\Program Files (x86)\ConduitEngine\ConduitEngineUninstall.exe --a---- 23648 bytes [16:25 27/02/2011] [16:17 05/09/2010] DF465BE110DC0F7E5329D1B8065A405F
    C:\Users\Robert Jameson\AppData\LocalLow\Conduit\Community Alerts\Feeds\http___alerts_conduit-services_com_root_1395223_1390882_US.xml --a---- 193 bytes [14:59 05/12/2011] [21:38 29/01/2012] 56EDB9E53D554552F224055AF1805C4E
    C:\Users\Robert Jameson\AppData\LocalLow\Conduit\Community Alerts\Feeds\http___alerts_conduit-services_com_root_1477347_1472999_US.xml --a---- 194 bytes [17:38 30/08/2011] [21:38 29/01/2012] 6710E0F98C7626597DA95DD9DC1D8C3D
    C:\Users\Robert Jameson\AppData\LocalLow\Conduit\Community Alerts\Feeds\http___alerts_conduit-services_com_root_15651_15317_US.xml --a---- 185 bytes [17:38 30/08/2011] [21:38 29/01/2012] 99AB7C9D57B1EB9D6634D16EE6056D6B
    C:\Users\Robert Jameson\AppData\LocalLow\Conduit\Community Alerts\Feeds\http___alerts_conduit-services_com_root_909619_905414_US.xml --a---- 191 bytes [17:38 30/08/2011] [21:38 29/01/2012] 43C93B80235159F037CEA9A173922F92
    C:\Users\Robert Jameson\AppData\LocalLow\Conduit\Toolbar\Facebook\http___facebook_conduit-services_com_Settings_ashx_locale=en&browserType=IE&toolbarVersion=6_8_2_0.xml --a---- 10909 bytes [15:07 05/12/2011] [13:55 25/01/2012] 1B3B574AA349758343D3C80787B9739E
    C:\Users\Robert Jameson\AppData\LocalLow\Conduit\Toolbar\Facebook\http___facebook_conduit-services_com_Settings_ashx_locale=en&browserType=IE&toolbarVersion=6_8_5_1.xml --a---- 10909 bytes [02:26 26/01/2012] [14:36 30/01/2012] 1B3B574AA349758343D3C80787B9739E
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_About_png.png --a---- 821 bytes [16:25 27/02/2011] [16:25 27/02/2011] 99D5F75C338F2A877CBF891E0F18746E
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_Browse_png.png --a---- 729 bytes [16:25 27/02/2011] [16:25 27/02/2011] F2291FAB46ED9291A1A2FFE9F88E9D84
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_Contact_png.png --a---- 531 bytes [16:25 27/02/2011] [16:25 27/02/2011] A847C5F6CE2C700048749892DD2E0619
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_Hide_png.png --a---- 669 bytes [16:25 27/02/2011] [16:25 27/02/2011] FED9E00C76F647EE6A0B7CC684C89F0C
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_LikeIcon_png.png --a---- 263 bytes [16:25 27/02/2011] [16:25 27/02/2011] 36BD416D16391EFAAAFB2C3C54EAE986
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_MoreFromPublisher_png.png --a---- 734 bytes [16:25 27/02/2011] [16:25 27/02/2011] 943ADFD9E0DF1507F7BC419802BF4303
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_More_png.png --a---- 562 bytes [16:25 27/02/2011] [16:25 27/02/2011] 36C6FB9C84D4AF5C5D7C5B277A0E4A01
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_MoveLeft_png.png --a---- 610 bytes [16:25 27/02/2011] [16:25 27/02/2011] 68E9E9252E45ED7BD51B8680E8DD4462
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_MoveRight_png.png --a---- 606 bytes [16:25 27/02/2011] [16:25 27/02/2011] 8D8D187BA99DBEF76E4286668B474A4E
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_Options_png.png --a---- 493 bytes [16:25 27/02/2011] [16:25 27/02/2011] 275C9DA2D536F18F528C80E050C3D705
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_Privacy_png.png --a---- 706 bytes [16:25 27/02/2011] [16:25 27/02/2011] 3AD88BD8E832DA39FAAEDF07AD595F94
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_Refresh_png.png --a---- 674 bytes [16:25 27/02/2011] [16:25 27/02/2011] 650731EEF807C292E699779B12CBE552
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_Share_png.png --a---- 696 bytes [16:25 27/02/2011] [16:25 27/02/2011] 70D43EC3F4BD7C10D5534EFCEC6D7AE5
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_Upgrade_png.png --a---- 607 bytes [16:25 27/02/2011] [16:25 27/02/2011] 9B4D914888BCFFCBAE6757A0E450551C
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\ExternalComponent\http___contextmenu_app_conduit-services_com_apps_TranslatedApps_ashx_productId=1&name=appContextMenu&locale=en-us.xml --a---- 6613 bytes [16:25 27/02/2011] [16:25 27/02/2011] FE3E6F69A41E7532957D7814E3E433E1
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\ExternalComponent\http___contextmenu_app_conduit-services_com_apps_TranslatedApps_ashx_productId=1&name=appContextMenu2_0&locale=en-us.xml --a---- 6819 bytes [16:25 27/02/2011] [14:41 05/05/2011] A278FCD81E7E9E287A0F8BB1C89CD2C6
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\ExternalComponent\http___contextmenu_engine_conduit-services_com_apps_TranslatedApps_ashx_productId=1&name=engineContextMenu&locale=en-us.xml --a---- 4060 bytes [16:25 27/02/2011] [16:25 27/02/2011] D36423CECBFE5F806725E13ED7101201
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\ExternalComponent\http___contextmenu_engine_conduit-services_com_apps_TranslatedApps_ashx_productId=1&name=engineContextMenu2_0&locale=en-us.xml --a---- 4475 bytes [16:25 27/02/2011] [14:41 05/05/2011] 74F81E98677EB434ADD4BC697F677185
    Searching for "*SimpUtil_Maps_1*"
    No files found.
    Searching for "*Productivity_3*"
    No files found.
    Searching for "*Search Toolbar*"
    No files found.
    Searching for "*playbryte*"
    No files found.
    Searching for "*PrivacySafeGuard*"
    No files found.
    Searching for "*Privacy SafeGuard*"
    No files found.
    ========== folderfind ==========
    Searching for "*Conduit*"
    C:\Program Files (x86)\ConduitEngine d------ [16:25 27/02/2011]
    C:\Users\Robert Jameson\AppData\Local\Conduit d------ [17:36 30/08/2011]
    C:\Users\Robert Jameson\AppData\LocalLow\Conduit d------ [16:25 27/02/2011]
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine d------ [16:25 27/02/2011]
    Searching for "*SimpUtil_Maps_1*"
    No folders found.
    Searching for "*Productivity_3*"
    No folders found.
    Searching for "*Search Toolbar*"
    C:\Program Files (x86)\Search Toolbar d------ [21:13 04/02/2011]
    C:\_OTL\MovedFiles\10072012_221606\C_Program Files (x86)\Search Toolbar d------ [05:17 08/10/2012]
    Searching for "*playbryte*"
    No folders found.
    Searching for "*PrivacySafeGuard*"
    No folders found.
    Searching for "*Privacy SafeGuard*"
    No folders found.
    ========== Regfind ==========
    Searching for "Conduit"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\conduitEngine]
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\conduitEngine\toolbar\Repository\conduit_ConduitEngine]
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\conduitEngine\toolbar\Repository\IndexTable\ConduitEngine]
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\conduitEngine\toolbar\Repository\MetaData\3816002102]
    "dbname"="conduit_ConduitEngine"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\ConduitSearchScopes]
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933]
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ABTestUsage]
    "ServiceUrl"="http://tb-test.conduit-data.com"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\AppRegisterUsage]
    "ServiceUrl"="http://apps.usage.conduit-services.com/AppOperations/AppRegistration.ashx"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\AppsMetaData]
    "ServiceUrl"="http://appsmetadata.toolbar.conduit-services.com/?ctid=EB_TOOLBAR_ID"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\AppsSettings]
    "ServiceUrl"="http://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_COMP_ID"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\AppTrackingFirstTime]
    "ServiceUrl"="http://tracking.usage.app.conduit-services.com/FirstTime.ashx?current=EB_APPTRACKING_CURRENT_STATE"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\AppTrackingUsage]
    "ServiceUrl"="http://tracking.usage.app.conduit-services.com/Usage.ashx"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\AppUninstallUsage]
    "ServiceUrl"="http://apps.usage.conduit-services.com/AppOperations/AppUninstall.ashx"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\BrowserToolbarsInfo]
    "ServiceUrl"="http://counting.usage.toolbar.conduit-services.com/usage.ashx"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ClientErrorLog]
    "ServiceUrl"="http://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\DynamicDialogs]
    "ServiceUrl"="http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=EB_TOOLBAR_VERSION"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\GottenAppsContextMenu]
    "ServiceUrl"="http://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=EB_LOCALE"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\HostingUsage]
    "ServiceUrl"="http://usage.hosting.toolbar.conduit-services.com/usage.ashx?ctid=EB_TOOLBAR_ID"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\LocationService]
    "ServiceUrl"="http://ip2location.conduit-services.com/ip/"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\OtherAppsContextMenu]
    "ServiceUrl"="http://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=EB_LOCALE"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\RecoveryService]
    "ServiceUrl"="http://recovery.conduit-services.com/toolbar"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\SearchInNewTabBlank]
    "ServiceUrl"="http://storage.conduit.com/SearchInNewTab/SearchInNewTabBlank.html"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\SearchSettings]
    "ServiceUrl"="http://API.search.conduit.com/Settings/?ctid=EB_TOOLBAR_ID"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\SharedAppsContextMenu]
    "ServiceUrl"="http://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=EB_LOCALE"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarAppComponentUsage]
    "ServiceUrl"="http://component.usage.toolbar.conduit-services.com/ToolbarComponentUsage.ashx"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarAppUsage]
    "ServiceUrl"="http://usage.toolbar.conduit-services.com/ToolbarUsage.ashx"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarComponentUsage]
    "ServiceUrl"="http://component.usage.toolbar.conduit-services.com/ToolbarComponentUsage.ashx"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarContextMenu]
    "ServiceUrl"="http://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=EB_LOCALE"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarGrouping]
    "ServiceUrl"="http://grouping.services.conduit.co...id=EB_ORIGINAL_CTID&lut=0&locale=EB_OS_LOCALE"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarHiddenLogin]
    "ServiceUrl"="http://login.hiddentoolbar.conduit-services.com/Login.ashx"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarHiddenSettings]
    "ServiceUrl"="http://Settings.toolbar.search.conduit.com/root/EB_TOOLBAR_ID/EB_ORIGINAL_CTID"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarHiddenSettingsForSB]
    "ServiceUrl"="http://settings.smartbar.conduit-se...INAL_CTID&protocolVersion=EB_PROTOCOL_VERSION"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarLogin]
    "ServiceUrl"="http://login.toolbar.conduit-services.com/Login.ashx"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarSettings]
    "ServiceUrl"="http://Settings.toolbar.search.conduit.com/root/EB_TOOLBAR_ID/EB_ORIGINAL_CTID"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarSettingsForPublisher]
    "ServiceUrl"="http://settings.publisher.toolbar.conduit-services.com/?ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarSettingsForSB]
    "ServiceUrl"="http://settings.smartbar.conduit-se...INAL_CTID&protocolVersion=EB_PROTOCOL_VERSION"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarSettingsPublisherForSB]
    "ServiceUrl"="http://settings.publisher.smartbar....INAL_CTID&protocolVersion=EB_PROTOCOL_VERSION"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarTranslation]
    "ServiceUrl"="http://translation.toolbar.conduit-services.com/?locale=EB_LOCALE"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarUninstall]
    "ServiceUrl"="http://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarUsage]
    "ServiceUrl"="http://usage.toolbar.conduit-services.com/ToolbarUsage.ashx"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\UninstallDialog]
    "ServiceUrl"="http://UninstallDialog.conduit-serv...ctid=EB_TOOLBAR_ID&version=EB_TOOLBAR_VERSION"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\UninstallDialogUsage]
    "ServiceUrl"="http://uninstalldialogusage.toolbar.conduit-services.com/Usage.ashx"
    [HKEY_CURRENT_USER\Software\Conduit]
    [HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\conduitEngine.ini]
    [HKEY_CURRENT_USER\Software\Nero\Nero 9\Shared\AudioEffects\VSTPlugins\Ignore]
    "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\iSyncConduit.dll"="Ignore"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Conduit.Engine]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966]
    "FAEB67A6F1D637247AB9AD48012A5EB6"="C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\iSyncConduit.dll"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966\FAEB67A6F1D637247AB9AD48012A5EB6]
    "File"="iSyncConduit.dll"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB1E579405BE28F46B2E7AAE9534B564]
    "FAEB67A6F1D637247AB9AD48012A5EB6"="C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\com.yahoo.go.sync.client.resources\PhoneConduit.plist"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Conduit]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Conduit\HomePage]
    "{19da1ae4-a403-4535-8e93-63b3aa7f1d8e}"="http://search.conduit.com?SearchSource=10&ctid=CT3085971"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\conduitEngine]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\conduitEngine\Communicator]
    "Url"="http://servicemap.conduit-services.com/Toolbar/"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\conduitEngine\toolbar]
    "Path"="C:\Program Files (x86)\ConduitEngine"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\conduitEngine\toolbar]
    "DisplayTitle"="Conduit Engine"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\conduitEngine\toolbar]
    "DisplayName"="Conduit Engine"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\conduitEngine\toolbar]
    "DefaultSettingsServiceURL"="http://settings.engine.conduit-services.com/?browser=EB_BROWSER_TYPE&lut=EB_LUT"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\conduitEngine\toolbar]
    "PlatformType"="ConduitEngine"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\conduitEngine\toolbar]
    "SponsorId"="ConduitEngine"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\conduitEngine\toolbar]
    "EngineHelperFileName"="C:\Program Files (x86)\ConduitEngine\ConduitEngineHelper.exe"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{14257DA7-382E-4FC7-B12C-F345F538A9D1}]
    "AppPath"="C:\Program Files (x86)\ConduitEngine"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{14257DA7-382E-4FC7-B12C-F345F538A9D1}]
    "AppName"="ConduitEngineHelper.exe"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\conduitinstaller_RASAPI32]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\conduitinstaller_RASMANCS]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine]
    "DisplayName"="Conduit Engine"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine]
    "UninstallString"="C:\Program Files (x86)\ConduitEngine\ConduitEngineUninstall.exe"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine]
    "DisplayIcon"="C:\Program Files (x86)\ConduitEngine\ConduitEngineUninstall.exe"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine]
    "Publisher"="Conduit Ltd."
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\conduitEngine]
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\conduitEngine\toolbar\Repository\conduit_ConduitEngine]
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\conduitEngine\toolbar\Repository\IndexTable\ConduitEngine]
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\conduitEngine\toolbar\Repository\MetaData\3816002102]
    "dbname"="conduit_ConduitEngine"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\ConduitSearchScopes]
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933]
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ABTestUsage]
    "ServiceUrl"="http://tb-test.conduit-data.com"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\AppRegisterUsage]
    "ServiceUrl"="http://apps.usage.conduit-services.com/AppOperations/AppRegistration.ashx"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\AppsMetaData]
    "ServiceUrl"="http://appsmetadata.toolbar.conduit-services.com/?ctid=EB_TOOLBAR_ID"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\AppsSettings]
    "ServiceUrl"="http://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_COMP_ID"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\AppTrackingFirstTime]
    "ServiceUrl"="http://tracking.usage.app.conduit-services.com/FirstTime.ashx?current=EB_APPTRACKING_CURRENT_STATE"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\AppTrackingUsage]
    "ServiceUrl"="http://tracking.usage.app.conduit-services.com/Usage.ashx"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\AppUninstallUsage]
    "ServiceUrl"="http://apps.usage.conduit-services.com/AppOperations/AppUninstall.ashx"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\BrowserToolbarsInfo]
    "ServiceUrl"="http://counting.usage.toolbar.conduit-services.com/usage.ashx"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ClientErrorLog]
    "ServiceUrl"="http://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\DynamicDialogs]
    "ServiceUrl"="http://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=EB_TOOLBAR_VERSION"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\GottenAppsContextMenu]
    "ServiceUrl"="http://contextmenu.toolbar.conduit-services.com/?name=GottenApps&locale=EB_LOCALE"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\HostingUsage]
    "ServiceUrl"="http://usage.hosting.toolbar.conduit-services.com/usage.ashx?ctid=EB_TOOLBAR_ID"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\LocationService]
    "ServiceUrl"="http://ip2location.conduit-services.com/ip/"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\OtherAppsContextMenu]
    "ServiceUrl"="http://contextmenu.toolbar.conduit-services.com/?name=OtherApps&locale=EB_LOCALE"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\RecoveryService]
    "ServiceUrl"="http://recovery.conduit-services.com/toolbar"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\SearchInNewTabBlank]
    "ServiceUrl"="http://storage.conduit.com/SearchInNewTab/SearchInNewTabBlank.html"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\SearchSettings]
    "ServiceUrl"="http://API.search.conduit.com/Settings/?ctid=EB_TOOLBAR_ID"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\SharedAppsContextMenu]
    "ServiceUrl"="http://contextmenu.toolbar.conduit-services.com/?name=SharedApps&locale=EB_LOCALE"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarAppComponentUsage]
    "ServiceUrl"="http://component.usage.toolbar.conduit-services.com/ToolbarComponentUsage.ashx"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarAppUsage]
    "ServiceUrl"="http://usage.toolbar.conduit-services.com/ToolbarUsage.ashx"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarComponentUsage]
    "ServiceUrl"="http://component.usage.toolbar.conduit-services.com/ToolbarComponentUsage.ashx"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarContextMenu]
    "ServiceUrl"="http://contextmenu.toolbar.conduit-services.com/?name=Toolbar&locale=EB_LOCALE"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarGrouping]
    "ServiceUrl"="http://grouping.services.conduit.co...id=EB_ORIGINAL_CTID&lut=0&locale=EB_OS_LOCALE"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarHiddenLogin]
    "ServiceUrl"="http://login.hiddentoolbar.conduit-services.com/Login.ashx"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarHiddenSettings]
    "ServiceUrl"="http://Settings.toolbar.search.conduit.com/root/EB_TOOLBAR_ID/EB_ORIGINAL_CTID"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarHiddenSettingsForSB]
    "ServiceUrl"="http://settings.smartbar.conduit-se...INAL_CTID&protocolVersion=EB_PROTOCOL_VERSION"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarLogin]
    "ServiceUrl"="http://login.toolbar.conduit-services.com/Login.ashx"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarSettings]
    "ServiceUrl"="http://Settings.toolbar.search.conduit.com/root/EB_TOOLBAR_ID/EB_ORIGINAL_CTID"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarSettingsForPublisher]
    "ServiceUrl"="http://settings.publisher.toolbar.conduit-services.com/?ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarSettingsForSB]
    "ServiceUrl"="http://settings.smartbar.conduit-se...INAL_CTID&protocolVersion=EB_PROTOCOL_VERSION"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarSettingsPublisherForSB]
    "ServiceUrl"="http://settings.publisher.smartbar....INAL_CTID&protocolVersion=EB_PROTOCOL_VERSION"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarTranslation]
    "ServiceUrl"="http://translation.toolbar.conduit-services.com/?locale=EB_LOCALE"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarUninstall]
    "ServiceUrl"="http://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\ToolbarUsage]
    "ServiceUrl"="http://usage.toolbar.conduit-services.com/ToolbarUsage.ashx"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\UninstallDialog]
    "ServiceUrl"="http://UninstallDialog.conduit-serv...ctid=EB_TOOLBAR_ID&version=EB_TOOLBAR_VERSION"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\Repository\conduit_CT1060933\UninstallDialogUsage]
    "ServiceUrl"="http://uninstalldialogusage.toolbar.conduit-services.com/Usage.ashx"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Conduit]
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\conduitEngine.ini]
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Nero\Nero 9\Shared\AudioEffects\VSTPlugins\Ignore]
    "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\iSyncConduit.dll"="Ignore"
    Searching for "SimpUtil_Maps_1"
    [HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\SimpUtil_Maps_1 Toolbar.ini]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SimpUtil_Maps_1_RASAPI32]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SimpUtil_Maps_1_RASMANCS]
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\SimpUtil_Maps_1 Toolbar.ini]
    Searching for "Productivity_3"
    [HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\Productivity_3 Toolbar.ini]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Productivity_3AutoUpdateHelper_RASAPI32]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Productivity_3AutoUpdateHelper_RASMANCS]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Productivity_3_RASAPI32]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Productivity_3_RASMANCS]
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\Productivity_3 Toolbar.ini]
    Searching for "Search Toolbar"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Search Toolbar]
    [HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\Search Toolbar.ini]
    [HKEY_CURRENT_USER\Software\Nero\Nero 9\Shared\AudioEffects\VSTPlugins\Ignore]
    "C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll"="Ignore"
    [HKEY_CURRENT_USER\Software\Zugo\Toolbars\ie\1]
    "Files"="C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll"
    [HKEY_CURRENT_USER\Software\Zugo\Toolbars\ie\1]
    "Path"="C:\Program Files (x86)\Search Toolbar"
    [HKEY_CURRENT_USER\Software\Zugo\Toolbars\ie\1]
    "Name"="Search Toolbar"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SearchToolbarLib.CSearchToolbarImpl]
    @="Search Toolbar"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SearchToolbarLib.CSearchToolbarImpl.1]
    @="Search Toolbar"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DF802C05-4660-418c-970C-B988ADB1D316}]
    "DisplayName"="Microsoft Live Search Toolbar"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DF802C05-4660-418c-970C-B988ADB1D316}]
    "Publisher"="Microsoft Live Search Toolbar"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Search Toolbar]
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Search Toolbar]
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\Search Toolbar.ini]
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Nero\Nero 9\Shared\AudioEffects\VSTPlugins\Ignore]
    "C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll"="Ignore"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Zugo\Toolbars\ie\1]
    "Files"="C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Zugo\Toolbars\ie\1]
    "Path"="C:\Program Files (x86)\Search Toolbar"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Zugo\Toolbars\ie\1]
    "Name"="Search Toolbar"
    Searching for "playbryte"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\playbryte_installer_RASAPI32]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\playbryte_installer_RASMANCS]
    Searching for "PrivacySafeGuard"
    No data found.
    Searching for "Privacy SafeGuard"
    No data found.
    -= EOF =-
     
  14. Gizzy

    Gizzy Malware Specialist

    Joined:
    Aug 2, 2005
    Messages:
    3,832
    Hi gobob,
    Let me know how your computer is running now after doing the following.


    Run OTL Script
    1. Right-click OTL.exe and select Run as administrator to start the program
    2. Copy and Paste everything from the Code box below into the Custom Scans/Fixes box in OTL
      Code:
      :Commands
      [CREATERESTOREPOINT]
      
      :OTL
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
      O2 - BHO: (no name) - {F90A5A0D-CD98-49CC-9AA7-9CD11C7478BF} - No CLSID value found.
      O3 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (no name) - {19DA1AE4-A403-4535-8E93-63B3AA7F1D8E} - No CLSID value found.
      O3 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (no name) - {1FCA4DF8-9ACD-4DFB-89CC-DDD0082FC588} - No CLSID value found.
      O3 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
      O3 - HKU\S-1-5-21-489030045-1748294620-2465218778-1001\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
      
      :Reg
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
      "{BBC679F5-FDFC-4BD6-8D49-254C36B75B0C}"=-
      "{41572B15-105B-4828-94AE-B7005D69DFC3}"=-
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
      "conduitEngine"=-
      [-HKEY_CURRENT_USER\Software\AppDataLow\Software\conduitEngine]
      [-HKEY_CURRENT_USER\Software\AppDataLow\Software\ConduitSearchScopes]
      [-HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar]
      [-HKEY_CURRENT_USER\Software\Conduit]
      [-HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\conduitEngine.ini]
      [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Conduit.Engine]
      [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Conduit]
      [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\conduitEngine]
      [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{14257DA7-382E-4FC7-B12C-F345F538A9D1}]
      [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\conduitinstaller_RASAPI32]
      [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\conduitinstaller_RASMANCS]
      [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine]
      [-HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\conduitEngine]
      [-HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\ConduitSearchScopes]
      [-HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar]
      [-HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Conduit]
      [-HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\conduitEngine.ini]
      [-HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\SimpUtil_Maps_1 Toolbar.ini]
      [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SimpUtil_Maps_1_RASAPI32]
      [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SimpUtil_Maps_1_RASMANCS]
      [-HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\SimpUtil_Maps_1 Toolbar.ini]
      [-HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\Productivity_3 Toolbar.ini]
      [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Productivity_3AutoUpdateHelper_RASAPI32]
      [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Productivity_3AutoUpdateHelper_RASMANCS]
      [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Productivity_3_RASAPI32]
      [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Productivity_3_RASMANCS]
      [-HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\Productivity_3 Toolbar.ini]
      [-HKEY_CURRENT_USER\Software\AppDataLow\Software\Search Toolbar]
      [-HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\Search Toolbar.ini]
      [HKEY_CURRENT_USER\Software\Nero\Nero 9\Shared\AudioEffects\VSTPlugins\Ignore]
      "C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll"=-
      [-HKEY_CURRENT_USER\Software\Zugo]
      [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SearchToolbarLib.CSearchToolbarImpl]
      [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SearchToolbarLib.CSearchToolbarImpl.1]
      [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Search Toolbar]
      [-HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Search Toolbar]
      [-HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\Search Toolbar.ini]
      [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Nero\Nero 9\Shared\AudioEffects\VSTPlugins\Ignore]
      "C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll"=-
      [-HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Zugo]
      [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\playbryte_installer_RASAPI32]
      [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\playbryte_installer_RASMANCS]
      
      :Files
      C:\Users\Robert Jameson\AppData\LocalLow\FCTB000100815
      C:\Users\Robert Jameson\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected]
      C:\Program Files (x86)\Ask.com
      C:\Program Files (x86)\Search Toolbar
      C:\Program Files (x86)\D-Link Toolbar
      C:\Program Files (x86)\Yahoo!\Companion
      C:\Program Files (x86)\Common Files\Homepage Protection
      C:\Program Files (x86)\Inbox Toolbar
      C:\Program Files (x86)\ConduitEngine
      C:\Users\Robert Jameson\AppData\Local\Conduit
      C:\Users\Robert Jameson\AppData\LocalLow\Conduit
      C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine
      
      :Commands
      [EMPTYTEMP]
    3. Then click the Run Fix button at the top.
    4. If prompted, Click OK
    5. OTL may ask to reboot the computer. Please do so if asked
    6. When finished a report should appear in Notepad. Copy and Paste that report in your next reply.

      Note: The log can also be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log


    SystemLook
    1. Right-click SystemLook.exe and select Run as administrator to run it.
    2. Copy the contents of the following codebox into the main textfield:
      Code:
      :filefind
      *Conduit*
      *SimpUtil_Maps_1*
      *Productivity_3*
      *Search Toolbar*
      *playbryte*
      *PrivacySafeGuard*
      *Privacy SafeGuard*
      
      :folderfind
      *Conduit*
      *SimpUtil_Maps_1*
      *Productivity_3*
      *Search Toolbar*
      *playbryte*
      *PrivacySafeGuard*
      *Privacy SafeGuard*
      
      :Regfind
      Conduit
      SimpUtil_Maps_1
      Productivity_3
      Search Toolbar
      playbryte
      PrivacySafeGuard
      Privacy SafeGuard
    3. Click the Look button to start the scan.
    4. When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt


    Please reply with:
    • OTL log
    • New SystemLook log
    • Update on computer's performance
     
  15. gobob

    gobob Thread Starter

    Joined:
    Oct 3, 2012
    Messages:
    25
    * OTL log
    * New SystemLook log
    * Update on computer's performance

    Still have funmoods, I get a new tab when I do a search. However, Conduit seems to be missing from control panel programs and features. I don't know if it is gone from the computer or not. Here are the logs files:
    SystemLook 30.07.11 by jpshortstuff
    Log created at 11:31 on 09/10/2012 by Robert Jameson
    Administrator - Elevation successful
    No Context: Code:
    No Context: ---------
    ========== filefind ==========
    Searching for "*Conduit*"
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\iSyncConduit.dll --a---- 1206120 bytes [18:44 20/01/2012] [18:44 20/01/2012] 976934130CD5C5DBD2DC977B298DF525
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\com.yahoo.go.sync.client.resources\PhoneConduit.plist --a---- 11408 bytes [03:20 11/06/2010] [03:20 11/06/2010] AB18CD2A656AE753C30E6276EC3DA0C2
    C:\Program Files (x86)\ConduitEngine\ConduitEngineHelper.exe --a---- 38496 bytes [16:25 27/02/2011] [19:37 25/03/2010] A320DF2B47CFCAF98D06EB59CD72084C
    C:\Program Files (x86)\ConduitEngine\ConduitEngineUninstall.exe --a---- 23648 bytes [16:25 27/02/2011] [16:17 05/09/2010] DF465BE110DC0F7E5329D1B8065A405F
    C:\Users\Robert Jameson\AppData\LocalLow\Conduit\Community Alerts\Feeds\http___alerts_conduit-services_com_root_1395223_1390882_US.xml --a---- 193 bytes [14:59 05/12/2011] [21:38 29/01/2012] 56EDB9E53D554552F224055AF1805C4E
    C:\Users\Robert Jameson\AppData\LocalLow\Conduit\Community Alerts\Feeds\http___alerts_conduit-services_com_root_1477347_1472999_US.xml --a---- 194 bytes [17:38 30/08/2011] [21:38 29/01/2012] 6710E0F98C7626597DA95DD9DC1D8C3D
    C:\Users\Robert Jameson\AppData\LocalLow\Conduit\Community Alerts\Feeds\http___alerts_conduit-services_com_root_15651_15317_US.xml --a---- 185 bytes [17:38 30/08/2011] [21:38 29/01/2012] 99AB7C9D57B1EB9D6634D16EE6056D6B
    C:\Users\Robert Jameson\AppData\LocalLow\Conduit\Community Alerts\Feeds\http___alerts_conduit-services_com_root_909619_905414_US.xml --a---- 191 bytes [17:38 30/08/2011] [21:38 29/01/2012] 43C93B80235159F037CEA9A173922F92
    C:\Users\Robert Jameson\AppData\LocalLow\Conduit\Toolbar\Facebook\http___facebook_conduit-services_com_Settings_ashx_locale=en&browserType=IE&toolbarVersion=6_8_2_0.xml --a---- 10909 bytes [15:07 05/12/2011] [13:55 25/01/2012] 1B3B574AA349758343D3C80787B9739E
    C:\Users\Robert Jameson\AppData\LocalLow\Conduit\Toolbar\Facebook\http___facebook_conduit-services_com_Settings_ashx_locale=en&browserType=IE&toolbarVersion=6_8_5_1.xml --a---- 10909 bytes [02:26 26/01/2012] [14:36 30/01/2012] 1B3B574AA349758343D3C80787B9739E
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_About_png.png --a---- 821 bytes [16:25 27/02/2011] [16:25 27/02/2011] 99D5F75C338F2A877CBF891E0F18746E
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_Browse_png.png --a---- 729 bytes [16:25 27/02/2011] [16:25 27/02/2011] F2291FAB46ED9291A1A2FFE9F88E9D84
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_Contact_png.png --a---- 531 bytes [16:25 27/02/2011] [16:25 27/02/2011] A847C5F6CE2C700048749892DD2E0619
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_Hide_png.png --a---- 669 bytes [16:25 27/02/2011] [16:25 27/02/2011] FED9E00C76F647EE6A0B7CC684C89F0C
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_LikeIcon_png.png --a---- 263 bytes [16:25 27/02/2011] [16:25 27/02/2011] 36BD416D16391EFAAAFB2C3C54EAE986
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_MoreFromPublisher_png.png --a---- 734 bytes [16:25 27/02/2011] [16:25 27/02/2011] 943ADFD9E0DF1507F7BC419802BF4303
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_More_png.png --a---- 562 bytes [16:25 27/02/2011] [16:25 27/02/2011] 36C6FB9C84D4AF5C5D7C5B277A0E4A01
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_MoveLeft_png.png --a---- 610 bytes [16:25 27/02/2011] [16:25 27/02/2011] 68E9E9252E45ED7BD51B8680E8DD4462
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_MoveRight_png.png --a---- 606 bytes [16:25 27/02/2011] [16:25 27/02/2011] 8D8D187BA99DBEF76E4286668B474A4E
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_Options_png.png --a---- 493 bytes [16:25 27/02/2011] [16:25 27/02/2011] 275C9DA2D536F18F528C80E050C3D705
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_Privacy_png.png --a---- 706 bytes [16:25 27/02/2011] [16:25 27/02/2011] 3AD88BD8E832DA39FAAEDF07AD595F94
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_Refresh_png.png --a---- 674 bytes [16:25 27/02/2011] [16:25 27/02/2011] 650731EEF807C292E699779B12CBE552
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_Share_png.png --a---- 696 bytes [16:25 27/02/2011] [16:25 27/02/2011] 70D43EC3F4BD7C10D5534EFCEC6D7AE5
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_Upgrade_png.png --a---- 607 bytes [16:25 27/02/2011] [16:25 27/02/2011] 9B4D914888BCFFCBAE6757A0E450551C
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\ExternalComponent\http___contextmenu_app_conduit-services_com_apps_TranslatedApps_ashx_productId=1&name=appContextMenu&locale=en-us.xml --a---- 6613 bytes [16:25 27/02/2011] [16:25 27/02/2011] FE3E6F69A41E7532957D7814E3E433E1
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\ExternalComponent\http___contextmenu_app_conduit-services_com_apps_TranslatedApps_ashx_productId=1&name=appContextMenu2_0&locale=en-us.xml --a---- 6819 bytes [16:25 27/02/2011] [14:41 05/05/2011] A278FCD81E7E9E287A0F8BB1C89CD2C6
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\ExternalComponent\http___contextmenu_engine_conduit-services_com_apps_TranslatedApps_ashx_productId=1&name=engineContextMenu&locale=en-us.xml --a---- 4060 bytes [16:25 27/02/2011] [16:25 27/02/2011] D36423CECBFE5F806725E13ED7101201
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine\ExternalComponent\http___contextmenu_engine_conduit-services_com_apps_TranslatedApps_ashx_productId=1&name=engineContextMenu2_0&locale=en-us.xml --a---- 4475 bytes [16:25 27/02/2011] [14:41 05/05/2011] 74F81E98677EB434ADD4BC697F677185
    Searching for "*SimpUtil_Maps_1*"
    No files found.
    Searching for "*Productivity_3*"
    No files found.
    Searching for "*Search Toolbar*"
    No files found.
    Searching for "*playbryte*"
    No files found.
    Searching for "*PrivacySafeGuard*"
    No files found.
    Searching for "*Privacy SafeGuard*"
    No files found.
    ========== folderfind ==========
    Searching for "*Conduit*"
    C:\Program Files (x86)\ConduitEngine d------ [16:25 27/02/2011]
    C:\Users\Robert Jameson\AppData\Local\Conduit d------ [17:36 30/08/2011]
    C:\Users\Robert Jameson\AppData\LocalLow\Conduit d------ [16:25 27/02/2011]
    C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine d------ [16:25 27/02/2011]
    Searching for "*SimpUtil_Maps_1*"
    No folders found.
    Searching for "*Productivity_3*"
    No folders found.
    Searching for "*Search Toolbar*"
    C:\_OTL\MovedFiles\10072012_221606\C_Program Files (x86)\Search Toolbar d------ [05:17 08/10/2012]
    C:\_OTL\MovedFiles\10092012_112436\C_Program Files (x86)\Search Toolbar d------ [21:13 04/02/2011]
    Searching for "*playbryte*"
    No folders found.
    Searching for "*PrivacySafeGuard*"
    No folders found.
    Searching for "*Privacy SafeGuard*"
    No folders found.
    ========== Regfind ==========
    Searching for "Conduit"
    [HKEY_CURRENT_USER\Software\Nero\Nero 9\Shared\AudioEffects\VSTPlugins\Ignore]
    "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\iSyncConduit.dll"="Ignore"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966]
    "FAEB67A6F1D637247AB9AD48012A5EB6"="C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\iSyncConduit.dll"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966\FAEB67A6F1D637247AB9AD48012A5EB6]
    "File"="iSyncConduit.dll"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB1E579405BE28F46B2E7AAE9534B564]
    "FAEB67A6F1D637247AB9AD48012A5EB6"="C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\com.yahoo.go.sync.client.resources\PhoneConduit.plist"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Nero\Nero 9\Shared\AudioEffects\VSTPlugins\Ignore]
    "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\iSyncConduit.dll"="Ignore"
    Searching for "SimpUtil_Maps_1"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SimpUtil_Maps_1_RASAPI32]
    Searching for "Productivity_3"
    [HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\Productivity_3 Toolbar.ini]
    [HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\Productivity_3 Toolbar.ini] [-HKEY_CURRENT_USER]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Productivity_3AutoUpdateHelper_RASAPI32]
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\Productivity_3 Toolbar.ini]
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\Productivity_3 Toolbar.ini] [-HKEY_CURRENT_USER]
    Searching for "Search Toolbar"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Search Toolbar]
    [HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\Productivity_3 Toolbar.ini] [-HKEY_CURRENT_USER\Software\AppDataLow\Software\Search Toolbar] [-HKEY_CURRENT_USER]
    [HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\Productivity_3 Toolbar.ini] [-HKEY_CURRENT_USER\Software\AppDataLow\Software\Search Toolbar] [-HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\Search Toolbar.ini] [HKEY_CURRENT_USER]
    [HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\Productivity_3 Toolbar.ini] [-HKEY_CURRENT_USER\Software\AppDataLow\Software\Search Toolbar] [-HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\Search Toolbar.ini] [HKEY_CURRENT_USER\Software\Nero\Nero 9\Shared\AudioEffects\VSTPlugins\Ignore]
    "C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll"="- [-HKEY_CURRENT_USER\Software\Zugo]"
    [HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\Search Toolbar.ini]
    [HKEY_CURRENT_USER\Software\Nero\Nero 9\Shared\AudioEffects\VSTPlugins\Ignore]
    "C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll"="Ignore"
    [HKEY_CURRENT_USER\Software\Zugo\Toolbars\ie\1]
    "Files"="C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll"
    [HKEY_CURRENT_USER\Software\Zugo\Toolbars\ie\1]
    "Path"="C:\Program Files (x86)\Search Toolbar"
    [HKEY_CURRENT_USER\Software\Zugo\Toolbars\ie\1]
    "Name"="Search Toolbar"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DF802C05-4660-418c-970C-B988ADB1D316}]
    "DisplayName"="Microsoft Live Search Toolbar"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DF802C05-4660-418c-970C-B988ADB1D316}]
    "Publisher"="Microsoft Live Search Toolbar"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Search Toolbar]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Wow6432Node\Search Toolbar] [-HKEY_USERS]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Wow6432Node\Search Toolbar] [-HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Search Toolbar] [-HKEY_USERS]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Wow6432Node\Search Toolbar] [-HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Search Toolbar] [-HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\Search Toolbar.ini] [HKEY_USERS]
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Search Toolbar]
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\Productivity_3 Toolbar.ini] [-HKEY_CURRENT_USER\Software\AppDataLow\Software\Search Toolbar] [-HKEY_CURRENT_USER]
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\Productivity_3 Toolbar.ini] [-HKEY_CURRENT_USER\Software\AppDataLow\Software\Search Toolbar] [-HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\Search Toolbar.ini] [HKEY_CURRENT_USER]
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\Productivity_3 Toolbar.ini] [-HKEY_CURRENT_USER\Software\AppDataLow\Software\Search Toolbar] [-HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\Search Toolbar.ini] [HKEY_CURRENT_USER\Software\Nero\Nero 9\Shared\AudioEffects\VSTPlugins\Ignore]
    "C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll"="- [-HKEY_CURRENT_USER\Software\Zugo]"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\Search Toolbar.ini]
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Nero\Nero 9\Shared\AudioEffects\VSTPlugins\Ignore]
    "C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll"="Ignore"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Zugo\Toolbars\ie\1]
    "Files"="C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Zugo\Toolbars\ie\1]
    "Path"="C:\Program Files (x86)\Search Toolbar"
    [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Zugo\Toolbars\ie\1]
    "Name"="Search Toolbar"
    Searching for "playbryte"
    No data found.
    Searching for "PrivacySafeGuard"
    No data found.
    Searching for "Privacy SafeGuard"
    No data found.
    -= EOF =-
    All processes killed
    Error: Unable to interpret <Code:> in the current context!
    Error: Unable to interpret <---------> in the current context!
    ========== COMMANDS ==========
    Restore point Set: OTL Restore Point
    ========== OTL ==========
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F90A5A0D-CD98-49CC-9AA7-9CD11C7478BF}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F90A5A0D-CD98-49CC-9AA7-9CD11C7478BF}\ not found.
    Registry value HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{19DA1AE4-A403-4535-8E93-63B3AA7F1D8E} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19DA1AE4-A403-4535-8E93-63B3AA7F1D8E}\ not found.
    Registry value HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{1FCA4DF8-9ACD-4DFB-89CC-DDD0082FC588} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1FCA4DF8-9ACD-4DFB-89CC-DDD0082FC588}\ not found.
    Registry value HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
    Registry value HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}\ not found.
    ========== REGISTRY ==========
    Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BBC679F5-FDFC-4BD6-8D49-254C36B75B0C} not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BBC679F5-FDFC-4BD6-8D49-254C36B75B0C}\ not found.
    Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{41572B15-105B-4828-94AE-B7005D69DFC3} not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41572B15-105B-4828-94AE-B7005D69DFC3}\ not found.
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\\conduitEngine not found.
    Registry key HKEY_CURRENT_USER\Software\AppDataLow\Software\conduitEngine\ deleted successfully.
    Registry key HKEY_CURRENT_USER\Software\AppDataLow\Software\ConduitSearchScopes\ deleted successfully.
    Registry key HKEY_CURRENT_USER\Software\AppDataLow\Software\Freecorder\toolbar\ deleted successfully.
    Registry key HKEY_CURRENT_USER\Software\Conduit\ deleted successfully.
    Registry key HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\conduitEngine.ini\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Conduit.Engine\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Conduit\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\conduitEngine\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{14257DA7-382E-4FC7-B12C-F345F538A9D1}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{14257DA7-382E-4FC7-B12C-F345F538A9D1}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\conduitinstaller_RASAPI32\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\conduitinstaller_RASMANCS\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine\ deleted successfully.
    Registry key HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\conduitEngine\ not found.
    Registry key HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\ConduitSearchScopes\ not found.
    Registry key HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Freecorder\toolbar\ not found.
    Registry key HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Conduit\ not found.
    Registry key HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\conduitEngine.ini\ not found.
    Registry key HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\SimpUtil_Maps_1 Toolbar.ini] [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SimpUtil_Maps_1_RASAPI32\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\SimpUtil_Maps_1_RASMANCS\ deleted successfully.
    Registry key HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\SimpUtil_Maps_1 Toolbar.ini\ deleted successfully.
    Registry key HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\Productivity_3 Toolbar.ini] [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Productivity_3AutoUpdateHelper_RASAPI32\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Productivity_3AutoUpdateHelper_RASMANCS\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Productivity_3_RASAPI32\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\Productivity_3_RASMANCS\ deleted successfully.
    Registry key HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\Productivity_3 Toolbar.ini] [-HKEY_CURRENT_USER\Software\AppDataLow\Software\Search Toolbar] [-HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\Search Toolbar.ini] [HKEY_CURRENT_USER\Software\Nero\Nero 9\Shared\AudioEffects\VSTPlugins\Ignore\ not found.
    HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\Productivity_3 Toolbar.ini] [-HKEY_CURRENT_USER\Software\AppDataLow\Software\Search Toolbar] [-HKEY_CURRENT_USER\Software\FLEXnet\Connect\db\Search Toolbar.ini] [HKEY_CURRENT_USER\Software\Nero\Nero 9\Shared\AudioEffects\VSTPlugins\Ignore\\"C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll"|- [-HKEY_CURRENT_USER\Software\Zugo] /E : value set successfully!
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SearchToolbarLib.CSearchToolbarImpl\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SearchToolbarLib.CSearchToolbarImpl.1\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Search Toolbar] [-HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Search Toolbar] [-HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\Search Toolbar.ini] [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Nero\Nero 9\Shared\AudioEffects\VSTPlugins\Ignore\ not found.
    Unable to set value : HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Search Toolbar] [-HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\AppDataLow\Software\Search Toolbar] [-HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\FLEXnet\Connect\db\Search Toolbar.ini] [HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Nero\Nero 9\Shared\AudioEffects\VSTPlugins\Ignore\\"C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll"|- [-HKEY_USERS\S-1-5-21-489030045-1748294620-2465218778-1001\Software\Zugo] /E!
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\playbryte_installer_RASAPI32\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\playbryte_installer_RASMANCS\ deleted successfully.
    ========== FILES ==========
    File\Folder C:\Users\Robert Jameson\AppData\LocalLow\FCTB000100815 not found.
    File\Folder C:\Users\Robert Jameson\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\[email protected] not found.
    C:\Program Files (x86)\Ask.com\Updater folder moved successfully.
    C:\Program Files (x86)\Ask.com\assets\oobe folder moved successfully.
    C:\Program Files (x86)\Ask.com\assets folder moved successfully.
    C:\Program Files (x86)\Ask.com folder moved successfully.
    C:\Program Files (x86)\Search Toolbar folder moved successfully.
    File\Folder C:\Program Files (x86)\D-Link Toolbar not found.
    File\Folder C:\Program Files (x86)\Yahoo!\Companion not found.
    File\Folder C:\Program Files (x86)\Common Files\Homepage Protection C:\Program Files (x86)\Inbox Toolbar C:\Program Files (x86)\ConduitEngine C:\Users\Robert Jameson\AppData\Local\Conduit C:\Users\Robert Jameson\AppData\LocalLow\Conduit C:\Users\Robert Jameson\AppData\LocalLow\ConduitEngine not found.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Public

    User: Robert Jameson
    ->Temp folder emptied: 310562198 bytes
    ->Temporary Internet Files folder emptied: 28050751 bytes
    ->Java cache emptied: 463 bytes
    ->Flash cache emptied: 291 bytes

    User: Robert_Jameson

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 129294907 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 134 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 446.00 mb


    OTL by OldTimer - Version 3.2.69.0 log created on 10092012_112436
    Files\Folders moved on Reboot...
    C:\Users\Robert Jameson\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    File move failed. C:\Windows\temp\Temporary Internet Files\Content.IE5\ZRANX1SX\desktop.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\Temporary Internet Files\Content.IE5\O81V39A4\desktop.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\Temporary Internet Files\Content.IE5\AD7FRXD8\desktop.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\Temporary Internet Files\Content.IE5\75NU619D\desktop.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\Temporary Internet Files\Content.IE5\desktop.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\Low\MSI\SkypeToolbars.msi scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\History\History.IE5\desktop.ini scheduled to be moved on reboot.
    File\Folder C:\Windows\temp\ACLM\ACLMLog.txt not found!
    File\Folder C:\Windows\temp\ACLM\CPSSMasterCatalog.ini not found!
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_common.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off_overlay.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off_overlay.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off_overlay.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off_overlay.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off_overlay.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off_overlay.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off_overlay.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_off_overlay.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on_overlay.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on_overlay.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on_overlay.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on_overlay.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on_overlay.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on_overlay.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on_overlay.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_ground_sun_on_overlay.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_off.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_off.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_off.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_off.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_off.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_off.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_off.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_off.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_on.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_on.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_on.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_on.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_on.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_on.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_on.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\atmosphere_sky_sun_on.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_no_atmosphere.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_no_atmosphere.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_no_atmosphere.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_no_atmosphere.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_no_atmosphere.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_no_atmosphere.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_sun_no_atmosphere.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_sun_no_atmosphere.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_sun_no_atmosphere.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_sun_no_atmosphere.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_sun_no_atmosphere.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\fade_sun_no_atmosphere.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\ground_overlay_no_atmosphere.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\ground_overlay_no_atmosphere.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\ground_overlay_no_atmosphere.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\ground_overlay_no_atmosphere.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\ground_overlay_no_atmosphere.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\ground_overlay_no_atmosphere.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\ground_overlay_no_atmosphere.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\ground_overlay_no_atmosphere.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on_overlay.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on_overlay.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on_overlay.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on_overlay.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on_overlay.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on_overlay.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on_overlay.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_ground_sun_on_overlay.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_sky_sun_on.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_sky_sun_on.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_sky_sun_on.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_sky_sun_on.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_sky_sun_on.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\mars_atmosphere_sky_sun_on.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\precipitation_double_cone.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\precipitation_double_cone.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\precipitation_double_cone.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\precipitation_double_cone.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\precipitation_double_cone.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\precipitation_double_cone.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbillboard.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbillboard.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbillboard.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbillboard.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbillboard.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbillboard.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbranch.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbranch.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbranch.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbranch.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbranch.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stbranch.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stcommonobjects.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stfrond.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stfrond.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stfrond.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stfrond.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stfrond.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stfrond.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafcard.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafcard.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafcard.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafcard.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafcard.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafcard.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafmesh.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafmesh.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafmesh.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafmesh.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafmesh.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\stleafmesh.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\watersurface.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\watersurface.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\watersurface.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\watersurface.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\watersurface.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\watersurface.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\watersurface.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\shaders\watersurface.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\planet\earth.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\keyboard\generic.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\keyboard\sr22.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\hud\generic.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\hud\sr22.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\generic.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\genius_maxfighter_f16u.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\logitech_attack3.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\logitech_extreme_3d.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\logitech_force_3d.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\logitech_freedom.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\saitek_cyborg_evo.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\saitek_x52.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\speed_link_black_hawk.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\speed_link_black_widow.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\speed_link_cougar_flightstick.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\speed_link_dark_tornado.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\controller\xbox_360.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\aircraft\f16.acf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\aircraft\sr22.acf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\flightsim\flightsim.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\application.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\balloons.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\builtin_webdata.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\cursor_crosshair_inverse.png scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\cursor_crosshair_thick.png scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\doppler.txt scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\effects.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\leftpanel-common.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\leftpanel-layer.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\localshapes.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\navcontrols.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\notifications.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\progress.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\renderui.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\search.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\spin_icon.png scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\statusbar.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\terrainmgr.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\tmcontrols.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\toolbar.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\tourcontrols.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\unknown_plugin.png scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\userpalette.kml scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\res\webbrowser.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\ar.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\bg.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\ca.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\cs.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\da.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\de.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\el.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\en.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\es-419.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\es.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\fa.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\fi.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\fil.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\fr.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\he.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\hi.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\hr.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\hu.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\id.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\it.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\ja.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\ko.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\lt.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\lv.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\nl.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\no.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\pl.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\pt-PT.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\pt.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\ro.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\ru.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\sk.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\sl.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\sr.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\sv.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\th.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\tr.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\uk.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\vi.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\zh-Hans.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\zh-Hant-HK.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\lang\zh-Hant.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\drivers.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\earthps.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\geplugin.exe scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\ge_expat.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\googleearth.exe.local scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\googleearth_free.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\google_earth.ico scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\gpl.txt scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\ImporterGlobalSettings.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\ImporterUISettings.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\kh20 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\msvcp100.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\msvcr100.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\npgeplugin.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\PCOptimizations.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\plugin_ax.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\plugin\uninstall.ico scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_common.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off_overlay.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off_overlay.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off_overlay.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off_overlay.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off_overlay.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off_overlay.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off_overlay.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_off_overlay.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on_overlay.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on_overlay.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on_overlay.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on_overlay.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on_overlay.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on_overlay.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on_overlay.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_ground_sun_on_overlay.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_off.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_off.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_off.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_off.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_off.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_off.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_off.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_off.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_on.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_on.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_on.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_on.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_on.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_on.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_on.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\atmosphere_sky_sun_on.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_no_atmosphere.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_no_atmosphere.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_no_atmosphere.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_no_atmosphere.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_no_atmosphere.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_no_atmosphere.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_sun_no_atmosphere.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_sun_no_atmosphere.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_sun_no_atmosphere.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_sun_no_atmosphere.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_sun_no_atmosphere.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\fade_sun_no_atmosphere.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\ground_overlay_no_atmosphere.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\ground_overlay_no_atmosphere.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\ground_overlay_no_atmosphere.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\ground_overlay_no_atmosphere.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\ground_overlay_no_atmosphere.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\ground_overlay_no_atmosphere.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\ground_overlay_no_atmosphere.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\ground_overlay_no_atmosphere.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on_overlay.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on_overlay.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on_overlay.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on_overlay.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on_overlay.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on_overlay.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on_overlay.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_ground_sun_on_overlay.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_sky_sun_on.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_sky_sun_on.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_sky_sun_on.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_sky_sun_on.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_sky_sun_on.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\mars_atmosphere_sky_sun_on.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\precipitation_double_cone.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\precipitation_double_cone.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\precipitation_double_cone.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\precipitation_double_cone.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\precipitation_double_cone.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\precipitation_double_cone.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbillboard.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbillboard.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbillboard.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbillboard.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbillboard.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbillboard.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbranch.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbranch.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbranch.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbranch.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbranch.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stbranch.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stcommonobjects.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stfrond.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stfrond.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stfrond.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stfrond.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stfrond.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stfrond.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafcard.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafcard.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafcard.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafcard.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafcard.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafcard.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafmesh.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafmesh.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafmesh.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafmesh.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafmesh.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\stleafmesh.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\watersurface.arbfp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\watersurface.arbvp1 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\watersurface.asd scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\watersurface.cfg scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\watersurface.glslesf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\watersurface.glslesv scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\watersurface.ps_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\shaders\watersurface.vs_2_0 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\planet\earth.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\keyboard\generic.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\keyboard\sr22.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\hud\generic.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\hud\sr22.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\generic.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\genius_maxfighter_f16u.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\logitech_attack3.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\logitech_extreme_3d.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\logitech_force_3d.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\logitech_freedom.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\saitek_cyborg_evo.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\saitek_x52.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\speed_link_black_hawk.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\speed_link_black_widow.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\speed_link_cougar_flightstick.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\speed_link_dark_tornado.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\controller\xbox_360.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\aircraft\f16.acf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\aircraft\sr22.acf scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\flightsim\flightsim.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\application.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\balloons.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\builtin_webdata.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\cursor_crosshair_inverse.png scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\cursor_crosshair_thick.png scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\default_myplaces.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\doppler.txt scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\effects.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\leftpanel-common.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\leftpanel-layer.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\localshapes.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\navcontrols.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\notifications.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\progress.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\renderui.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\search.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\spin_icon.png scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\startinglocations-nonmac.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\startinglocations.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\statusbar.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\terrainmgr.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\tmcontrols.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\toolbar.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\tourcontrols.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\unknown_plugin.png scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\userpalette.kml scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\res\webbrowser.rcc scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\Plugins\npgeinprocessplugin.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\ar.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\bg.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\ca.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\cs.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\da.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\de.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\el.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\en.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\es-419.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\es.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\fa.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\fi.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\fil.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\fr.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\he.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\hi.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\hr.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\hu.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\id.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\it.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\ja.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\ko.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\lt.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\lv.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\nl.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\no.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\pl.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\pt-PT.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\pt.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\ro.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\ru.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\sk.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\sl.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\sr.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\sv.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\th.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\tr.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\uk.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\vi.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\zh-Hans.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\zh-Hant-HK.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\lang\zh-Hant.qm scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\drivers.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\earthflashsol.exe scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\earthps.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\ge_expat.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\googleearth.exe scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\googleearth.exe.local scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\googleearth_free.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\google_earth.ico scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\gpl.txt scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\gpsbabel.exe scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\ImporterGlobalSettings.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\ImporterUISettings.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\kh20 scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\kml_file.ico scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\kmz_file.ico scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\msvcp100.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\msvcr100.dll scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\PCOptimizations.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\uninstall.ico scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\program files\Google\Google Earth\client\wavdest.ax scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\LocalAppData\Google\Custom Buttons\toolbar.google.com_MXE8GT6B9RBHXCGLZ06L.xml scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0402.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0403.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0404.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0405.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0406.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0407.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0408.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0409.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x040a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x040b.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x040c.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x040d.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x040e.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0410.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0411.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0412.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0413.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0414.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0415.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0416.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0418.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0419.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x041a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x041b.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x041d.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x041e.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x041f.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0421.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0422.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0424.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0426.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0427.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x042a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0804.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0809.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x080a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0816.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0c01.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0c0a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x0c1a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x100a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x140a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x180a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x1c0a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x200a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x240a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x280a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x2c0a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x300a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x340a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x380a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\0x3c0a.ini scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\10250.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1026.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1027.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1028.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1029.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1030.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1031.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1032.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1033.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1034.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1035.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1036.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1037.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1038.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1040.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1041.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1042.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1043.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1044.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1045.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1046.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1048.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1049.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1050.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1051.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1053.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1054.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1055.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1057.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1058.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1060.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1062.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1063.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\1066.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\11274.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\12298.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\13322.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\14346.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\15370.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\2052.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\2057.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\2058.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\2070.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\3073.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\3082.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\3098.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\4106.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\5130.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\6154.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\7178.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\8202.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\9226.mst scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\Google Earth.msi scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\GoogleEarth.exe scheduled to be moved on reboot.
    File move failed. C:\Windows\temp\._msige61\Setup.ini scheduled to be moved on reboot.
    PendingFileRenameOperations files...
    Registry entries deleted on Reboot...
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/1071265