Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Every program crashing and getting Blue Screen

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Re: Every program crashing and getting Blue Screen

Unread postby Eldest » February 25th, 2013, 4:36 pm

I actually did just that after googling a bit on the error message. It did not find any problems.
Eldest
Regular Member
 
Posts: 26
Joined: February 19th, 2013, 3:50 pm
Advertisement
Register to Remove

Re: Every program crashing and getting Blue Screen

Unread postby Gary R » February 25th, 2013, 6:20 pm

See if Windows created another minidump file in C:\Windows\Minidump and if it did, then please attach it like last time.
User avatar
Gary R
Administrator
Administrator
 
Posts: 21872
Joined: June 28th, 2005, 11:36 am
Location: Yorkshire

Re: Every program crashing and getting Blue Screen

Unread postby Eldest » February 25th, 2013, 7:47 pm

Nothing new in the Minidump-map, sorry to report.
Eldest
Regular Member
 
Posts: 26
Joined: February 19th, 2013, 3:50 pm

Re: Every program crashing and getting Blue Screen

Unread postby Gary R » February 26th, 2013, 2:33 am

There's a few things below I'd like you to try ...

1. There is a folder in World of Warcraft called errors that should provide a crash dump report of why it crashed .

2. From the wow launcher (not wow.exe) click the Help menu at the top then click repair tool. If it is a corrupted file it will replace that file, it usually takes 10-30 min to run.

3. If it is just WoW causing you issues then there is a cache folder that can be deleted ... World of warcraft > Cache (the entire folder is safe to delete as it should remake the folder on the next run).

4. Move the WTF folder to your desktop and start WoW up. This will force WoW to make another folder (Warning ... this WILL reset any and all addons installed).
User avatar
Gary R
Administrator
Administrator
 
Posts: 21872
Joined: June 28th, 2005, 11:36 am
Location: Yorkshire

Re: Every program crashing and getting Blue Screen

Unread postby Eldest » February 26th, 2013, 9:01 am

1. I saved the crash report after the crash, but I'll paste the one from the error map below.

2. I did the repair tool, but it did not seem to repair anything.

3. It is not just WoW, and I did a fresh install to see if it would help. Chrome extensions and tabs still crash, and yesterday MSE crashed again. Seem to affect everything in the computer.

4. I did backup my WTF after the fresh install. Will try with reseting it.

WoW error log:

==============================================================================
World of WarCraft: Retail Build (build 16357)

Exe: D:\Install\World of Warcraft\WoW-64.exe
Time: Feb 25, 2013 5:34:01.622 PM
User: Eldest
Computer: NORMANDY
------------------------------------------------------------------------------

This application has encountered a critical error:

ERROR #132 (0x85100084) Fatal exception!

Program: D:\Install\World of Warcraft\WoW-64.exe
ProcessID: 5160
Exception: 0xC0000005 (ACCESS_VIOLATION) at 0033:000000013FA2AEC0

The instruction at "0x000000013FA2AEC0" referenced memory at "0xFFFFFFFFFFFFFFFF".
The memory could not be "read".


WoWBuild: 16357
Version: 5.1.0
Type: WoW
Platform: X64
Session Time(hh:mm:ss): 00:06:10
Time in World(hh:mm:ss): 00:06:01
Number of Char Logins: 1
Realm: Ravencrest (195.12.240.181:3724)
Local Zone: Shrine of Seven Stars, Vale of Eternal Blossoms (area id = 6142)
Local Player: Qoob, 0200000005621850, (870, 776.444, 299.868, 633.855)
Total lua memory: 45317KB
Current Addon: (null)
Current Addon function: UNKNOWN
Current Addon object: (null)
Add Ons: _NPCScan ArkInventory ArkInventoryRules AtlasLoot_Loader AutoRepBar BagBrother EnhaPrio MapCoords Niggles OmniCC Postal Quartz ReforgeLite SexyMap TidyPlates TidyPlatesHub TidyPlatesWidgets TidyPlates_Graphite TidyPlates_Grey TidyPlates_Neon TidyPlates_Quatre Collectinator TomTom +Wowhead_Looter

Settings:
SET readTOS "1"
SET readEULA "1"
SET readScanning "-1"
SET readContest "-1"
SET locale "enGB"
SET showToolsUI "1"
SET accounttype "MP"
SET readTerminationWithoutNotice "1"
SET installType "Retail"
SET installLocale "enUS"
SET enterWorld "1"
SET hwDetect "0"
SET videoOptionsVersion "5"
SET gxApi "D3D11"
SET gxWindow "1"
SET gxMaximize "1"
SET graphicsQuality "5"
SET mouseSpeed "1"
SET Gamma "1.000000"
SET ChatMusicVolume "0.29999998211861"
SET ChatSoundVolume "0.39999997615814"
SET ChatAmbienceVolume "0.29999998211861"
SET VoiceActivationSensitivity "0.39999997615814"
SET Sound_MusicVolume "0.40000000596046"
SET Sound_AmbienceVolume "0.60000002384186"
SET farclip "1300"
SET waterDetail "3"
SET sunShafts "2"
SET groundEffectDensity "128"
SET groundEffectDist "260"
SET environmentDetail "150"
SET projectedTextures "1"
SET shadowMode "3"
SET shadowTextureSize "2048"
SET SSAO "1"
SET SSAOBlur "1"
SET textureFilteringMode "5"
SET terrainLodDist "650"
SET componentTextureLevel "0"
SET weatherDensity "3"
SET realmName "Ravencrest"
SET gameTip "43"
SET showNewbieTips "0"
SET repositionfrequency "0"
SET Sound_MasterVolume "0.20000000298023"
SET Sound_SFXVolume "1"
SET Sound_OutputDriverName "System Default"
SET checkAddonVersion "0"
SET questLogCollapseFilter "-1"
SET minimapTrackedInfo "MINIMAP_TRACKING_VENDOR_FOOD"

----------------------------------------
Installation settings:
----------------------------------------
UID: wow_engb
Expansion Level: 4
PTR: 0
Beta: 0
PatchURL: 'http://enGB.patch.battle.net:1119/patch'
ProductCode: 'WoW'

----------------------------------------
GxInfo
----------------------------------------
GxApi: D3D11
Shader Model: 5_0
Vertex: vs_5_0
Hull: hs_5_0
Domain: ds_5_0
Geometry: gs_5_0
Pixel: ps_5_0
Compute: cs_5_0

Adapter 0:
Description: AMD Radeon HD 7900 Series
PCI Identifier: VID=0x1002,DID=0x679A,REV=0x00,SSID=0x04261043
Vid Mem: 3045 MB
Sys Mem: 0 MB
Shared Mem: 7912 MB
Flags: 0x00000000
UMD Version: 8.17.0010.1172

Installed DX11 Version:
File Version: 6.1.7601.17514

------------------------------------------------------------------------------

----------------------------------------
x64 Registers
----------------------------------------

RAX=0000000000000140 RCX=120000003FB716E8 RDX=0000000021D7E3D1 RBX=0000000037FBC3B0
RSP=00000000002CF328 RBP=00000000002CF3B9 RSI=0000000021D7E0A0 RDI=0000000037FBC510
R8 =00000000000001F0 R9 =00000000000001F1 R10=0000000021D7E3D1 R11=0000000000000880
R12=000000007FFFFFFF R13=0000000000000000 R14=0000000000000000 R15=0000000000000000
RIP=000000013FA2AEC0 CSR=00001FB2 FLG=00010202
CS =0033 DS =002B ES =002B SS =002B FS =0053 GS =002B


----------------------------------------
Stack Trace (Manual)
----------------------------------------

Address Frame Logical addr Module

Showing 45/45 threads...

--- Thread ID: 2280 [Current Thread] ---
000000013FA2AEC0 00000000002CF328 0001:00179EC0 D:\Install\World of Warcraft\WoW-64.exe
00000001401C2227 00000000002CF330 0001:00911227 D:\Install\World of Warcraft\WoW-64.exe
00000001401C3C5B 00000000002CF420 0001:00912C5B D:\Install\World of Warcraft\WoW-64.exe
00000001401688E9 00000000002CF450 0001:008B78E9 D:\Install\World of Warcraft\WoW-64.exe
000000014014F602 00000000002CF4A0 0001:0089E602 D:\Install\World of Warcraft\WoW-64.exe
000000013FF64C55 00000000002CF520 0001:006B3C55 D:\Install\World of Warcraft\WoW-64.exe
000000013FF65508 00000000002CF640 0001:006B4508 D:\Install\World of Warcraft\WoW-64.exe
000000013FF682D9 00000000002CF770 0001:006B72D9 D:\Install\World of Warcraft\WoW-64.exe
000000013F950A17 00000000002CF8E0 0001:0009FA17 D:\Install\World of Warcraft\WoW-64.exe
000000013F987C9B 00000000002CFA00 0001:000D6C9B D:\Install\World of Warcraft\WoW-64.exe
000000013F988ED0 00000000002CFA50 0001:000D7ED0 D:\Install\World of Warcraft\WoW-64.exe
000000013FA88E36 00000000002CFA80 0001:001D7E36 D:\Install\World of Warcraft\WoW-64.exe
000000013F936DDF 00000000002CFBF0 0001:00085DDF D:\Install\World of Warcraft\WoW-64.exe
000000013F937561 00000000002CFC50 0001:00086561 D:\Install\World of Warcraft\WoW-64.exe
000000013F934911 00000000002CFC80 0001:00083911 D:\Install\World of Warcraft\WoW-64.exe
000000013F9352FC 00000000002CFCD0 0001:000842FC D:\Install\World of Warcraft\WoW-64.exe
000000013F8BBE39 00000000002CFD40 0001:0000AE39 D:\Install\World of Warcraft\WoW-64.exe
000000013F8C2B29 00000000002CFE80 0001:00011B29 D:\Install\World of Warcraft\WoW-64.exe
0000000140217138 00000000002CFEB0 0001:00966138 D:\Install\World of Warcraft\WoW-64.exe
00000000777F652D 00000000002CFF60 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 00000000002CFF90 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 4080 ---
000007FEFD723D38 0000000002A8F460 0001:00002D38 C:\Windows\system32\mswsock.dll
000007FEFD731F96 0000000002A8F4E0 0001:00010F96 C:\Windows\system32\mswsock.dll
000007FEFEB04EFC 0000000002A8F680 0001:00003EFC C:\Windows\system32\WS2_32.dll
000007FEFEB04E7D 0000000002A8F6C0 0001:00003E7D C:\Windows\system32\WS2_32.dll
000000007739962A 0000000002A8F7C0 0001:0002862A C:\Windows\system32\WININET.dll
00000000777F652D 0000000002A8FEA0 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 0000000002A8FED0 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 5268 ---
000007FEFDFA10DC 000000000320F9F0 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000007FEEDE81FAE 000000000320FA90 0001:00000FAE C:\Windows\system32\rasman.dll
00000000777F652D 000000000320FB20 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000000320FB50 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 4120 ---
0000000077A6B007 00000000036EF500 0001:0001A007 C:\Windows\SYSTEM32\ntdll.dll
00000000777F652D 00000000036EF7A0 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 00000000036EF7D0 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 4476 ---
000007FEFD725971 0000000003A4F8E0 0001:00004971 C:\Windows\system32\mswsock.dll
00000000777F652D 0000000003A4F940 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 0000000003A4F970 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 1984 ---
000007FEFDFA10DC 0000000002D2F8F0 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000013F9017C9 0000000002D2F990 0001:000507C9 D:\Install\World of Warcraft\WoW-64.exe
000000013F901478 0000000002D2F9F0 0001:00050478 D:\Install\World of Warcraft\WoW-64.exe
000000014021BE9F 0000000002D2FA20 0001:0096AE9F D:\Install\World of Warcraft\WoW-64.exe
000000014021BF33 0000000002D2FA50 0001:0096AF33 D:\Install\World of Warcraft\WoW-64.exe
00000000777F652D 0000000002D2FA80 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 0000000002D2FAB0 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 2788 ---
000007FEFDFA10DC 0000000003C8FAC0 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000013F9060B0 0000000003C8FB60 0001:000550B0 D:\Install\World of Warcraft\WoW-64.exe
000000013F901478 0000000003C8FBB0 0001:00050478 D:\Install\World of Warcraft\WoW-64.exe
000000014021BE9F 0000000003C8FBE0 0001:0096AE9F D:\Install\World of Warcraft\WoW-64.exe
000000014021BF33 0000000003C8FC10 0001:0096AF33 D:\Install\World of Warcraft\WoW-64.exe
00000000777F652D 0000000003C8FC40 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 0000000003C8FC70 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 3736 ---
000007FEFDFA10DC 0000000003DFF6F0 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000013F9015DF 0000000003DFF790 0001:000505DF D:\Install\World of Warcraft\WoW-64.exe
000000013F901478 0000000003DFF7F0 0001:00050478 D:\Install\World of Warcraft\WoW-64.exe
000000014021BE9F 0000000003DFF820 0001:0096AE9F D:\Install\World of Warcraft\WoW-64.exe
000000014021BF33 0000000003DFF850 0001:0096AF33 D:\Install\World of Warcraft\WoW-64.exe
00000000777F652D 0000000003DFF880 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 0000000003DFF8B0 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 1260 ---
000007FEFDFA10DC 00000000045DBB70 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000013F91053E 00000000045DBC10 0001:0005F53E D:\Install\World of Warcraft\WoW-64.exe
000000013F91536A 00000000045DC1D0 0001:0006436A D:\Install\World of Warcraft\WoW-64.exe
000000013F91F93E 00000000045DC250 0001:0006E93E D:\Install\World of Warcraft\WoW-64.exe
000000013F8F36CF 00000000045DC320 0001:000426CF D:\Install\World of Warcraft\WoW-64.exe
000000013F8F3949 00000000045DC3D0 0001:00042949 D:\Install\World of Warcraft\WoW-64.exe
000000013F900EEA 00000000045DC450 0001:0004FEEA D:\Install\World of Warcraft\WoW-64.exe
000000013F8D55FE 00000000045DC490 0001:000245FE D:\Install\World of Warcraft\WoW-64.exe
000000013F8D50EF 00000000045DC590 0001:000240EF D:\Install\World of Warcraft\WoW-64.exe
000000013F8D6999 00000000045DC620 0001:00025999 D:\Install\World of Warcraft\WoW-64.exe
000000013F914348 00000000045DC660 0001:00063348 D:\Install\World of Warcraft\WoW-64.exe
000000013F90E44E 00000000045DCBC0 0001:0005D44E D:\Install\World of Warcraft\WoW-64.exe
000000013F90E786 00000000045DD0E0 0001:0005D786 D:\Install\World of Warcraft\WoW-64.exe
000000013F90EA1B 00000000045DD140 0001:0005DA1B D:\Install\World of Warcraft\WoW-64.exe
000000013F90EB3E 00000000045DD580 0001:0005DB3E D:\Install\World of Warcraft\WoW-64.exe
000000013F8D6631 00000000045DD5B0 0001:00025631 D:\Install\World of Warcraft\WoW-64.exe
000000013F90F463 00000000045DD640 0001:0005E463 D:\Install\World of Warcraft\WoW-64.exe
000000013F90F7F9 00000000045DDAC0 0001:0005E7F9 D:\Install\World of Warcraft\WoW-64.exe
000000013F9151BE 00000000045DDF00 0001:000641BE D:\Install\World of Warcraft\WoW-64.exe
000000013F90D951 00000000045DE340 0001:0005C951 D:\Install\World of Warcraft\WoW-64.exe
000000013F8DE345 00000000045DE780 0001:0002D345 D:\Install\World of Warcraft\WoW-64.exe
000000013F91DA2D 00000000045DE820 0001:0006CA2D D:\Install\World of Warcraft\WoW-64.exe
000000013F8C90C3 00000000045DEE20 0001:000180C3 D:\Install\World of Warcraft\WoW-64.exe
000000013F8C9393 00000000045DF7B0 0001:00018393 D:\Install\World of Warcraft\WoW-64.exe
000000013FA9A9D6 00000000045DF7F0 0001:001E99D6 D:\Install\World of Warcraft\WoW-64.exe
000000013FA9B277 00000000045DF840 0001:001EA277 D:\Install\World of Warcraft\WoW-64.exe
000000013FB75107 00000000045DF870 0001:002C4107 D:\Install\World of Warcraft\WoW-64.exe
00000000777F652D 00000000045DF8C0 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 00000000045DF8F0 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 5180 ---
000007FEFDFA10DC 000000000477F9A0 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000013FA9B40C 000000000477FA40 0001:001EA40C D:\Install\World of Warcraft\WoW-64.exe
000000013FB75107 000000000477FA70 0001:002C4107 D:\Install\World of Warcraft\WoW-64.exe
00000000777F652D 000000000477FAC0 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000000477FAF0 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 5496 ---
000007FEFDFA10DC 0000000004B2FC90 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000007FEE6AB44AF 0000000004B2FD30 0001:000434AF C:\Windows\system32\atidxx64.dll
000007FEE6AB43C9 0000000004B2FD60 0001:000433C9 C:\Windows\system32\atidxx64.dll
000007FEE6AB321F 0000000004B2FD90 0001:0004221F C:\Windows\system32\atidxx64.dll
000007FEE6E9587F 0000000004B2FDC0 0001:0042487F C:\Windows\system32\atidxx64.dll
000007FEE6E95864 0000000004B2FDF0 0001:00424864 C:\Windows\system32\atidxx64.dll
00000000777F652D 0000000004B2FE20 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 0000000004B2FE50 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 3248 ---
000007FEFDFA1203 000000000324F9E0 0001:00000203 C:\Windows\system32\KERNELBASE.dll
000000013F8EC15B 000000000324FA80 0001:0003B15B D:\Install\World of Warcraft\WoW-64.exe
000000013F901478 000000000324FAB0 0001:00050478 D:\Install\World of Warcraft\WoW-64.exe
000000014021BE9F 000000000324FAE0 0001:0096AE9F D:\Install\World of Warcraft\WoW-64.exe
000000014021BF33 000000000324FB10 0001:0096AF33 D:\Install\World of Warcraft\WoW-64.exe
00000000777F652D 000000000324FB40 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000000324FB70 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 720 ---
000007FEFDFA10DC 000000000874FAA0 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000013FA1A658 000000000874FB40 0001:00169658 D:\Install\World of Warcraft\WoW-64.exe
000000013FB75107 000000000874FB70 0001:002C4107 D:\Install\World of Warcraft\WoW-64.exe
00000000777F652D 000000000874FBC0 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000000874FBF0 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 240 ---
000007FEFDFA1430 000000000959F350 0001:00000430 C:\Windows\system32\KERNELBASE.dll
00000000777F1220 000000000959F450 0001:00010220 C:\Windows\system32\kernel32.dll
000007FEF5FD2001 000000000959F4E0 0001:00001001 C:\Windows\system32\dsound.dll
000007FEF5FD2DF8 000000000959F710 0001:00001DF8 C:\Windows\system32\dsound.dll
000007FEF5FD20A5 000000000959F750 0001:000010A5 C:\Windows\system32\dsound.dll
00000000777F652D 000000000959F780 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000000959F7B0 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 3272 ---
000007FEFDFA1430 0000000009EBFBA0 0001:00000430 C:\Windows\system32\KERNELBASE.dll
0000000077802CE3 0000000009EBFCA0 0001:00021CE3 C:\Windows\system32\kernel32.dll
00000000776F8F7D 0000000009EBFD30 0001:00017F7D C:\Windows\system32\USER32.dll
00000000776F62B2 0000000009EBFDD0 0001:000152B2 C:\Windows\system32\USER32.dll
000007FEFC0D35BE 0000000009EBFE10 0001:000025BE C:\Windows\System32\MMDevApi.dll
00000000777F652D 0000000009EBFF60 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 0000000009EBFF90 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 1604 ---
000007FEFDFA1430 0000000009DAF8A0 0001:00000430 C:\Windows\system32\KERNELBASE.dll
00000000777F1220 0000000009DAF9A0 0001:00010220 C:\Windows\system32\kernel32.dll
000007FEF5FD2001 0000000009DAFA30 0001:00001001 C:\Windows\system32\dsound.dll
000007FEF5FD2132 0000000009DAFC60 0001:00001132 C:\Windows\system32\dsound.dll
000007FEF5FD20A5 0000000009DAFCF0 0001:000010A5 C:\Windows\system32\dsound.dll
00000000777F652D 0000000009DAFD20 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 0000000009DAFD50 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 4228 ---
000007FEFDFA1203 0000000009FCF6A0 0001:00000203 C:\Windows\system32\KERNELBASE.dll
000000013FAC36BA 0000000009FCF740 0001:002126BA D:\Install\World of Warcraft\WoW-64.exe
000000013FAC3AAA 0000000009FCF770 0001:00212AAA D:\Install\World of Warcraft\WoW-64.exe
00000000777F652D 0000000009FCF7A0 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 0000000009FCF7D0 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 1036 ---
000007FEFDFA1430 0000000009B5F710 0001:00000430 C:\Windows\system32\KERNELBASE.dll
00000000777F1220 0000000009B5F810 0001:00010220 C:\Windows\system32\kernel32.dll
000007FEF5FDACF4 0000000009B5F8A0 0001:00009CF4 C:\Windows\system32\dsound.dll
000007FEF5FDB89E 0000000009B5F8F0 0001:0000A89E C:\Windows\system32\dsound.dll
00000000777F652D 0000000009B5F920 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 0000000009B5F950 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 3984 ---
000007FEFDFA1203 000000000A33FAA0 0001:00000203 C:\Windows\system32\KERNELBASE.dll
000000013FAC36BA 000000000A33FB40 0001:002126BA D:\Install\World of Warcraft\WoW-64.exe
000000013FAC3AAA 000000000A33FB70 0001:00212AAA D:\Install\World of Warcraft\WoW-64.exe
00000000777F652D 000000000A33FBA0 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000000A33FBD0 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 2288 ---
000007FEFDFA10DC 000000000B54FB60 0001:000000DC C:\Windows\system32\KERNELBASE.dll
00000001401F6976 000000000B54FC00 0001:00945976 D:\Install\World of Warcraft\WoW-64.exe
00000001401F6B5F 000000000B54FC40 0001:00945B5F D:\Install\World of Warcraft\WoW-64.exe
000000013FB75107 000000000B54FC70 0001:002C4107 D:\Install\World of Warcraft\WoW-64.exe
00000000777F652D 000000000B54FCC0 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000000B54FCF0 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 1940 ---
000007FEFDFA1430 000000000B6BF170 0001:00000430 C:\Windows\system32\KERNELBASE.dll
00000000777F1220 000000000B6BF270 0001:00010220 C:\Windows\system32\kernel32.dll
00000001401F7367 000000000B6BF300 0001:00946367 D:\Install\World of Warcraft\WoW-64.exe
00000001401F67EE 000000000B6BF780 0001:009457EE D:\Install\World of Warcraft\WoW-64.exe
000000013FB75107 000000000B6BF7B0 0001:002C4107 D:\Install\World of Warcraft\WoW-64.exe
00000000777F652D 000000000B6BF800 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000000B6BF830 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 2812 ---
000007FEFDFA10DC 000000000D29FA20 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000007FEE6AB44AF 000000000D29FAC0 0001:000434AF C:\Windows\system32\atidxx64.dll
000007FEE6AB31F5 000000000D29FAF0 0001:000421F5 C:\Windows\system32\atidxx64.dll
000007FEE6E9587F 000000000D29FB20 0001:0042487F C:\Windows\system32\atidxx64.dll
000007FEE6E95864 000000000D29FB50 0001:00424864 C:\Windows\system32\atidxx64.dll
00000000777F652D 000000000D29FB80 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000000D29FBB0 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 6080 ---
000007FEFDFA10DC 000000000D50F810 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000013FB18058 000000000D50F8B0 0001:00267058 D:\Install\World of Warcraft\WoW-64.exe
000000013FAC3979 000000000D50F8E0 0001:00212979 D:\Install\World of Warcraft\WoW-64.exe
000000013FAC3A73 000000000D50F910 0001:00212A73 D:\Install\World of Warcraft\WoW-64.exe
00000000777F652D 000000000D50F940 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000000D50F970 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 5992 ---
000007FEFDFA10DC 000000000D66F8D0 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000013FB18058 000000000D66F970 0001:00267058 D:\Install\World of Warcraft\WoW-64.exe
000000013FAC3979 000000000D66F9A0 0001:00212979 D:\Install\World of Warcraft\WoW-64.exe
000000013FAC3A73 000000000D66F9D0 0001:00212A73 D:\Install\World of Warcraft\WoW-64.exe
00000000777F652D 000000000D66FA00 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000000D66FA30 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 3396 ---
0000000077B14EC4 000000000F15F890 0001:000C3EC4 C:\Windows\SYSTEM32\ntdll.dll
000000007782B258 000000000F15F8F0 0001:0004A258 C:\Windows\system32\kernel32.dll
000007FEE6AED1D4 000000000F15F920 0001:0007C1D4 C:\Windows\system32\atidxx64.dll
000007FEE6AECB2E 000000000F15F950 0001:0007BB2E C:\Windows\system32\atidxx64.dll
000007FEE6E9587F 000000000F15F980 0001:0042487F C:\Windows\system32\atidxx64.dll
000007FEE6E95864 000000000F15F9B0 0001:00424864 C:\Windows\system32\atidxx64.dll
00000000777F652D 000000000F15F9E0 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000000F15FA10 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 4792 ---
0000000077B14EC4 00000000121BF9D0 0001:000C3EC4 C:\Windows\SYSTEM32\ntdll.dll
000000007782B258 00000000121BFA30 0001:0004A258 C:\Windows\system32\kernel32.dll
000007FEE6AED1D4 00000000121BFA60 0001:0007C1D4 C:\Windows\system32\atidxx64.dll
000007FEE6AECB2E 00000000121BFA90 0001:0007BB2E C:\Windows\system32\atidxx64.dll
000007FEE6E9587F 00000000121BFAC0 0001:0042487F C:\Windows\system32\atidxx64.dll
000007FEE6E95864 00000000121BFAF0 0001:00424864 C:\Windows\system32\atidxx64.dll
00000000777F652D 00000000121BFB20 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 00000000121BFB50 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 6008 ---
000007FEFDFA10DC 000000001262FD70 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000006549C490 000000001262FE10 0001:0015B490 D:\Install\World of Warcraft\Battle.net-64.dll
000000006548FA1C 000000001262FE40 0001:0014EA1C D:\Install\World of Warcraft\Battle.net-64.dll
000000006549B19B 000000001262FE70 0001:0015A19B D:\Install\World of Warcraft\Battle.net-64.dll
00000000655947F7 000000001262FEA0 0001:002537F7 D:\Install\World of Warcraft\Battle.net-64.dll
00000000655948CF 000000001262FED0 0001:002538CF D:\Install\World of Warcraft\Battle.net-64.dll
00000000777F652D 000000001262FF00 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000001262FF30 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 4832 ---
000007FEFDFA10DC 000000000FF3F8F0 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000006549C490 000000000FF3F990 0001:0015B490 D:\Install\World of Warcraft\Battle.net-64.dll
000000006548FA1C 000000000FF3F9C0 0001:0014EA1C D:\Install\World of Warcraft\Battle.net-64.dll
000000006549B19B 000000000FF3F9F0 0001:0015A19B D:\Install\World of Warcraft\Battle.net-64.dll
00000000655947F7 000000000FF3FA20 0001:002537F7 D:\Install\World of Warcraft\Battle.net-64.dll
00000000655948CF 000000000FF3FA50 0001:002538CF D:\Install\World of Warcraft\Battle.net-64.dll
00000000777F652D 000000000FF3FA80 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000000FF3FAB0 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 1204 ---
000007FEFDFA10DC 000000001290F8B0 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000006549C490 000000001290F950 0001:0015B490 D:\Install\World of Warcraft\Battle.net-64.dll
000000006548FA1C 000000001290F980 0001:0014EA1C D:\Install\World of Warcraft\Battle.net-64.dll
000000006549B19B 000000001290F9B0 0001:0015A19B D:\Install\World of Warcraft\Battle.net-64.dll
00000000655947F7 000000001290F9E0 0001:002537F7 D:\Install\World of Warcraft\Battle.net-64.dll
00000000655948CF 000000001290FA10 0001:002538CF D:\Install\World of Warcraft\Battle.net-64.dll
00000000777F652D 000000001290FA40 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000001290FA70 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 3724 ---
000007FEFDFA10DC 00000000127AF990 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000006549C490 00000000127AFA30 0001:0015B490 D:\Install\World of Warcraft\Battle.net-64.dll
000000006548FA1C 00000000127AFA60 0001:0014EA1C D:\Install\World of Warcraft\Battle.net-64.dll
000000006549B19B 00000000127AFA90 0001:0015A19B D:\Install\World of Warcraft\Battle.net-64.dll
00000000655947F7 00000000127AFAC0 0001:002537F7 D:\Install\World of Warcraft\Battle.net-64.dll
00000000655948CF 00000000127AFAF0 0001:002538CF D:\Install\World of Warcraft\Battle.net-64.dll
00000000777F652D 00000000127AFB20 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 00000000127AFB50 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 4044 ---
000007FEFDFA10DC 0000000012AEFB30 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000006549C490 0000000012AEFBD0 0001:0015B490 D:\Install\World of Warcraft\Battle.net-64.dll
000000006548FA1C 0000000012AEFC00 0001:0014EA1C D:\Install\World of Warcraft\Battle.net-64.dll
000000006549B19B 0000000012AEFC30 0001:0015A19B D:\Install\World of Warcraft\Battle.net-64.dll
00000000655947F7 0000000012AEFC60 0001:002537F7 D:\Install\World of Warcraft\Battle.net-64.dll
00000000655948CF 0000000012AEFC90 0001:002538CF D:\Install\World of Warcraft\Battle.net-64.dll
00000000777F652D 0000000012AEFCC0 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 0000000012AEFCF0 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 5276 ---
000007FEFDFA10DC 0000000012C4F770 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000006549C490 0000000012C4F810 0001:0015B490 D:\Install\World of Warcraft\Battle.net-64.dll
000000006548FA1C 0000000012C4F840 0001:0014EA1C D:\Install\World of Warcraft\Battle.net-64.dll
000000006549B19B 0000000012C4F870 0001:0015A19B D:\Install\World of Warcraft\Battle.net-64.dll
00000000655947F7 0000000012C4F8A0 0001:002537F7 D:\Install\World of Warcraft\Battle.net-64.dll
00000000655948CF 0000000012C4F8D0 0001:002538CF D:\Install\World of Warcraft\Battle.net-64.dll
00000000777F652D 0000000012C4F900 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 0000000012C4F930 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 5136 ---
000007FEFDFA10DC 0000000012F2FDB0 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000006549C490 0000000012F2FE50 0001:0015B490 D:\Install\World of Warcraft\Battle.net-64.dll
000000006548FA1C 0000000012F2FE80 0001:0014EA1C D:\Install\World of Warcraft\Battle.net-64.dll
000000006549B19B 0000000012F2FEB0 0001:0015A19B D:\Install\World of Warcraft\Battle.net-64.dll
00000000655947F7 0000000012F2FEE0 0001:002537F7 D:\Install\World of Warcraft\Battle.net-64.dll
00000000655948CF 0000000012F2FF10 0001:002538CF D:\Install\World of Warcraft\Battle.net-64.dll
00000000777F652D 0000000012F2FF40 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 0000000012F2FF70 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 4428 ---
000007FEFDFA10DC 00000000130DFA70 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000006549C490 00000000130DFB10 0001:0015B490 D:\Install\World of Warcraft\Battle.net-64.dll
000000006548FA1C 00000000130DFB40 0001:0014EA1C D:\Install\World of Warcraft\Battle.net-64.dll
000000006549B19B 00000000130DFB70 0001:0015A19B D:\Install\World of Warcraft\Battle.net-64.dll
00000000655947F7 00000000130DFBA0 0001:002537F7 D:\Install\World of Warcraft\Battle.net-64.dll
00000000655948CF 00000000130DFBD0 0001:002538CF D:\Install\World of Warcraft\Battle.net-64.dll
00000000777F652D 00000000130DFC00 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 00000000130DFC30 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 4396 ---
000007FEFDFA10DC 000000001321F830 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000006549C490 000000001321F8D0 0001:0015B490 D:\Install\World of Warcraft\Battle.net-64.dll
000000006548FA1C 000000001321F900 0001:0014EA1C D:\Install\World of Warcraft\Battle.net-64.dll
000000006549B19B 000000001321F930 0001:0015A19B D:\Install\World of Warcraft\Battle.net-64.dll
00000000655947F7 000000001321F960 0001:002537F7 D:\Install\World of Warcraft\Battle.net-64.dll
00000000655948CF 000000001321F990 0001:002538CF D:\Install\World of Warcraft\Battle.net-64.dll
00000000777F652D 000000001321F9C0 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000001321F9F0 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 788 ---
000007FEFDFA10DC 000000001339FA30 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000006549C490 000000001339FAD0 0001:0015B490 D:\Install\World of Warcraft\Battle.net-64.dll
000000006548FA1C 000000001339FB00 0001:0014EA1C D:\Install\World of Warcraft\Battle.net-64.dll
000000006549B19B 000000001339FB30 0001:0015A19B D:\Install\World of Warcraft\Battle.net-64.dll
00000000655947F7 000000001339FB60 0001:002537F7 D:\Install\World of Warcraft\Battle.net-64.dll
00000000655948CF 000000001339FB90 0001:002538CF D:\Install\World of Warcraft\Battle.net-64.dll
00000000777F652D 000000001339FBC0 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000001339FBF0 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 4604 ---
000007FEFDFA10DC 000000001356F9F0 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000006549C490 000000001356FA90 0001:0015B490 D:\Install\World of Warcraft\Battle.net-64.dll
000000006548FA1C 000000001356FAC0 0001:0014EA1C D:\Install\World of Warcraft\Battle.net-64.dll
000000006549B19B 000000001356FAF0 0001:0015A19B D:\Install\World of Warcraft\Battle.net-64.dll
00000000655947F7 000000001356FB20 0001:002537F7 D:\Install\World of Warcraft\Battle.net-64.dll
00000000655948CF 000000001356FB50 0001:002538CF D:\Install\World of Warcraft\Battle.net-64.dll
00000000777F652D 000000001356FB80 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000001356FBB0 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 6124 ---
000007FEFDFA10DC 0000000012DCF8F0 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000006549C490 0000000012DCF990 0001:0015B490 D:\Install\World of Warcraft\Battle.net-64.dll
000000006548FA1C 0000000012DCF9C0 0001:0014EA1C D:\Install\World of Warcraft\Battle.net-64.dll
000000006549B19B 0000000012DCF9F0 0001:0015A19B D:\Install\World of Warcraft\Battle.net-64.dll
00000000655947F7 0000000012DCFA20 0001:002537F7 D:\Install\World of Warcraft\Battle.net-64.dll
00000000655948CF 0000000012DCFA50 0001:002538CF D:\Install\World of Warcraft\Battle.net-64.dll
00000000777F652D 0000000012DCFA80 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 0000000012DCFAB0 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 3428 ---
000007FEFDFA10DC 00000000137CF8B0 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000006549C490 00000000137CF950 0001:0015B490 D:\Install\World of Warcraft\Battle.net-64.dll
000000006548FA1C 00000000137CF980 0001:0014EA1C D:\Install\World of Warcraft\Battle.net-64.dll
000000006549B19B 00000000137CF9B0 0001:0015A19B D:\Install\World of Warcraft\Battle.net-64.dll
00000000655947F7 00000000137CF9E0 0001:002537F7 D:\Install\World of Warcraft\Battle.net-64.dll
00000000655948CF 00000000137CFA10 0001:002538CF D:\Install\World of Warcraft\Battle.net-64.dll
00000000777F652D 00000000137CFA40 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 00000000137CFA70 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 5360 ---
000007FEFDFA10DC 000000001391F970 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000006549C490 000000001391FA10 0001:0015B490 D:\Install\World of Warcraft\Battle.net-64.dll
000000006548FA1C 000000001391FA40 0001:0014EA1C D:\Install\World of Warcraft\Battle.net-64.dll
000000006549B19B 000000001391FA70 0001:0015A19B D:\Install\World of Warcraft\Battle.net-64.dll
00000000655947F7 000000001391FAA0 0001:002537F7 D:\Install\World of Warcraft\Battle.net-64.dll
00000000655948CF 000000001391FAD0 0001:002538CF D:\Install\World of Warcraft\Battle.net-64.dll
00000000777F652D 000000001391FB00 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000001391FB30 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 1792 ---
000007FEFDFA10DC 0000000013A4FC10 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000006549C490 0000000013A4FCB0 0001:0015B490 D:\Install\World of Warcraft\Battle.net-64.dll
000000006548FA1C 0000000013A4FCE0 0001:0014EA1C D:\Install\World of Warcraft\Battle.net-64.dll
000000006549B19B 0000000013A4FD10 0001:0015A19B D:\Install\World of Warcraft\Battle.net-64.dll
00000000655947F7 0000000013A4FD40 0001:002537F7 D:\Install\World of Warcraft\Battle.net-64.dll
00000000655948CF 0000000013A4FD70 0001:002538CF D:\Install\World of Warcraft\Battle.net-64.dll
00000000777F652D 0000000013A4FDA0 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 0000000013A4FDD0 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 2568 ---
000007FEFDFA10DC 0000000013C1F770 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000006549C490 0000000013C1F810 0001:0015B490 D:\Install\World of Warcraft\Battle.net-64.dll
000000006548FA1C 0000000013C1F840 0001:0014EA1C D:\Install\World of Warcraft\Battle.net-64.dll
000000006549B19B 0000000013C1F870 0001:0015A19B D:\Install\World of Warcraft\Battle.net-64.dll
00000000655947F7 0000000013C1F8A0 0001:002537F7 D:\Install\World of Warcraft\Battle.net-64.dll
00000000655948CF 0000000013C1F8D0 0001:002538CF D:\Install\World of Warcraft\Battle.net-64.dll
00000000777F652D 0000000013C1F900 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 0000000013C1F930 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 3264 ---
000007FEFDFA10DC 0000000016C7FC40 0001:000000DC C:\Windows\system32\KERNELBASE.dll
000000013FB93D91 0000000016C7FCE0 0001:002E2D91 D:\Install\World of Warcraft\WoW-64.exe
000000013FB75107 0000000016C7FD10 0001:002C4107 D:\Install\World of Warcraft\WoW-64.exe
00000000777F652D 0000000016C7FD60 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 0000000016C7FD90 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 3024 ---
0000000077A6FE0B 000000001DABFA40 0001:0001EE0B C:\Windows\SYSTEM32\ntdll.dll
00000000777F652D 000000001DABFD40 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000001DABFD70 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

--- Thread ID: 1764 ---
0000000077A6FE0B 000000003E1AF980 0001:0001EE0B C:\Windows\SYSTEM32\ntdll.dll
00000000777F652D 000000003E1AFC80 0001:0001552D C:\Windows\system32\kernel32.dll
0000000077A7C521 000000003E1AFCB0 0001:0002B521 C:\Windows\SYSTEM32\ntdll.dll

----------------------------------------
Stack Trace (Using DBGHELP.DLL)
----------------------------------------

Showing 45/45 threads...

--- Thread ID: 2280 [Current Thread] ---
000000013FA2AEC0 WoW-64.exe <unknown symbol>+0 (0000000000000000,000000014026B2A9,000000003E4CCCCD,0000000000000000)
00000001401C2227 WoW-64.exe <unknown symbol>+0 (0000000021D7E239,0000000000000000,0000000021D7E0A0,00000000000001F0)
00000001401C3C5B WoW-64.exe <unknown symbol>+0 (000000000ACFF7B0,000000001BB040AC,00000000002CF5B0,000000014014EFD2)
00000001401688E9 WoW-64.exe <unknown symbol>+0 (000000000ACFF7B0,0000000000000000,0000000080000000,0000000000000000)
000000014014F602 WoW-64.exe <unknown symbol>+0 (000000001BB04080,00000000002CF620,0000000000000000,0000000000000000)
000000013FF64C55 WoW-64.exe <unknown symbol>+0 (000000002DF2C690,0000000005586D98,000000000C71A838,000000002DC45038)
000000013FF65508 WoW-64.exe <unknown symbol>+0 (000000000C71A838,0000000000000000,0000000000000000,0000000000000000)
000000013FF682D9 WoW-64.exe <unknown symbol>+0 (BE7B03853F800000,3F5F1F9300000000,0000000000000000,0000000000000000)
000000013F950A17 WoW-64.exe <unknown symbol>+0 (0000000005586D98,000000013F987B5E,0000000000000000,000000000C25CD10)
000000013F987C9B WoW-64.exe <unknown symbol>+0 (0000000000000000,000000000C25B310,00000000002CFB80,00000000059D1DD0)
000000013F988ED0 WoW-64.exe <unknown symbol>+0 (0000000000000054,000000000C3DED30,00000000002CFB80,0000000000000000)
000000013FA88E36 WoW-64.exe <unknown symbol>+0 (0000000003E8A400,0000000000000000,0000000000000054,000000013F937561)
000000013F936DDF WoW-64.exe <unknown symbol>+0 (0000000003E8A400,0000000000000000,0000000003E8A400,0000000000000000)
000000013F937561 WoW-64.exe <unknown symbol>+0 (0000000000000000,0000000000000016,0000000000000000,0000000003E8A400)
000000013F934911 WoW-64.exe <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
000000013F9352FC WoW-64.exe <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,00000000002CFCE8)
000000013F8BBE39 WoW-64.exe <unknown symbol>+0 (0000000000000001,0000000000000001,0000000000000000,00000001403B1588)
000000013F8C2B29 WoW-64.exe <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000140217138 WoW-64.exe AssertAndCrash+87064 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 4080 ---
000007FEFD723D38 mswsock.dll <unknown symbol>+0 (0000000000000000,0000000000000080,00000000000B0308,0000000077AA3488)
000007FEFD731F96 mswsock.dll WSPStartup+36406 (00000000000021F8,000007FEFEB0D5A8,0000000000000001,0000000000000020)
000007FEFEB04EFC WS2_32.dll select+348 (0000000000000000,0000000000000000,000000000011B180,0000000000000000)
000007FEFEB04E7D WS2_32.dll select+221 (0000000000000002,0000000000000002,0000000000000001,0000000000000000)
000000007739962A WININET.dll InternetCrackUrlW+2350 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 5268 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (0000000000000000,00000000001246F0,0000000000000001,0000000000002250)
000007FEEDE81FAE rasman.dll RasAddNotification+1682 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 4120 ---
0000000077A6B007 ntdll.dll TpIsTimerSet+2311 (0000000000000000,0000000000000000,0000000000000000,00000002CCC184CC)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 4476 ---
000007FEFD725971 mswsock.dll <unknown symbol>+0 (000007FEFD7259E0,0000000002BEB910,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 1984 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (000000001CADFD40,000000001CAE6E90,0000000000000000,00000000000022A8)
000000013F8D7C86 WoW-64.exe <unknown symbol>+0 (00000000000000CE,0000000100004000,0000000000000018,0000000000000004)
000000013F901613 WoW-64.exe <unknown symbol>+0 (0000000001BAD190,0000000001BA8E78,0000000001BC2D30,0000000000000000)
000000013F901478 WoW-64.exe <unknown symbol>+0 (0000000001BAC110,0000000000000000,0000000000000000,0000000000000000)
000000014021BE9F WoW-64.exe AssertAndCrash+106879 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
000000014021BF33 WoW-64.exe AssertAndCrash+107027 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 2788 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (0000000005358170,0000000005358170,0000000000000000,0000000000002108)
000000013F9060B0 WoW-64.exe <unknown symbol>+0 (0000000001BB0C90,0000000000000000,000000014068F7B0,0000000005358170)
000000013F901478 WoW-64.exe <unknown symbol>+0 (0000000001BC5540,0000000000000000,0000000000000000,0000000000000000)
000000014021BE9F WoW-64.exe AssertAndCrash+106879 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
000000014021BF33 WoW-64.exe AssertAndCrash+107027 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 3736 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (0000000001BB1C30,0000000000000000,0000000000000000,000000000000000C)
000000013F9015DF WoW-64.exe <unknown symbol>+0 (0000000001BAD200,0000000000000000,0000000001BB1C30,0000000000000000)
000000013F901478 WoW-64.exe <unknown symbol>+0 (0000000001BC5A40,0000000000000000,0000000000000000,0000000000000000)
000000014021BE9F WoW-64.exe AssertAndCrash+106879 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
000000014021BF33 WoW-64.exe AssertAndCrash+107027 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 1260 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (000000003FD53FFF,000000005D168200,0000000000000000,00000000000028E0)
000000013F91053E WoW-64.exe <unknown symbol>+0 (0000000000000000,0000000002444050,00000000045DC210,0000000000004000)
000000013F91536A WoW-64.exe <unknown symbol>+0 (0000000001BAE6B0,00000000045DC288,00000000045DC2B9,00000000024323C0)
000000013F91F93E WoW-64.exe <unknown symbol>+0 (0000000000000000,0000000000000081,00000000024323C0,0000000002444050)
000000013F8F36CF WoW-64.exe <unknown symbol>+0 (0000000000000002,000000003FD50000,00000000045DC420,0000000000001645)
000000013F8F3949 WoW-64.exe <unknown symbol>+0 (000000003FD4D645,000000000005E035,000000003F1FD099,0000000000004000)
000000013F900EEA WoW-64.exe <unknown symbol>+0 (00000000045DC5B0,0000000005358170,0000000000000000,0000000000000000)
000000013F8D55FE WoW-64.exe <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
000000013F8D50EF WoW-64.exe <unknown symbol>+0 (0000000000000016,00000000045DC760,0000000000058000,000000003F1FD099)
000000013F8D6999 WoW-64.exe <unknown symbol>+0 (000000001E986D50,496B636F6C622035,00000001403BCEB0,0000000003EB0DD0)
000000013F914348 WoW-64.exe <unknown symbol>+0 (0000000000000160,0000000000000016,0000000000000000,0000000000000004)
000000013F90E44E WoW-64.exe <unknown symbol>+0 (0000000000003F88,000000003F1A9099,FFFFF88000000000,0000000000000015)
000000013F90E786 WoW-64.exe <unknown symbol>+0 (FFFFFFFFFFFFFF00,0000000000000001,000000003FD50000,000000013F8D7FAD)
000000013F90EA1B WoW-64.exe <unknown symbol>+0 (0000000036565DD0,0000000000000078,0000000000000002,0000000000000180)
000000013F90EB3E WoW-64.exe <unknown symbol>+0 (0000000036565DD0,000000001E986D50,000000000005DFBD,0000000000000001)
000000013F8D6631 WoW-64.exe <unknown symbol>+0 (000000000006F5BE,000000003F193B10,000000003F1A5111,000000001FC019C0)
000000013F90F463 WoW-64.exe <unknown symbol>+0 (000000001FC019C0,00000000045DE8A8,0000000000000000,00000000045DE8A8)
000000013F90F7F9 WoW-64.exe <unknown symbol>+0 (0006F5BE00000000,000000001FC019C0,000000003F193B10,0000000000000000)
000000013F9151BE WoW-64.exe <unknown symbol>+0 (000000001FC01820,00000000045DE920,00000000045DE8A8,000000000006F5BE)
000000013F90D951 WoW-64.exe <unknown symbol>+0 (00000000045DE920,000000001FC01820,00000000045DE850,000000013F9146E1)
000000013F8DE345 WoW-64.exe <unknown symbol>+0 (0000000000000000,00000001403BE2C8,0000000000000000,000000013F900043)
000000013F91DA2D WoW-64.exe <unknown symbol>+0 (0000000000000000,000000003F193B10,000014B500000000,00000000045DEE74)
000000013F8C90C3 WoW-64.exe <unknown symbol>+0 (000000014045B7A8,000000013FB6C0A8,0000000000000209,0000000000000000)
000000013F8C9393 WoW-64.exe <unknown symbol>+0 (0000000004E44D50,000000002DF6D310,000000002DF6D310,000000013FA9A6EE)
000000013FA9A9D6 WoW-64.exe <unknown symbol>+0 (0000000003EBA590,000000002DF6D310,000000014076A480,00000000000024E0)
000000013FA9B277 WoW-64.exe <unknown symbol>+0 (0000000000000000,0000000004E44D50,0000000000000000,0000000000000000)
000000013FB75107 WoW-64.exe <unknown symbol>+0 (00000000000024E4,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 5180 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (0000000000000000,0000000004E44DD0,0000000000000000,00000000000024E8)
000000013FA9B40C WoW-64.exe <unknown symbol>+0 (0000000000000000,0000000004E44DD0,0000000000000000,0000000000000000)
000000013FB75107 WoW-64.exe <unknown symbol>+0 (00000000000024EC,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 5496 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (0000000002E9DCC0,0000000000004FDA,0000000000000000,0000000000002554)
000007FEE6AB44AF atidxx64.dll XdxInitXopAdapterServices+267327 (0000000000000000,0000000002E9DCC0,0000000000000000,0000000000000000)
000007FEE6AB43C9 atidxx64.dll XdxInitXopAdapterServices+267097 (0000000002E9DCC0,0000000000000000,0000000002E9DCC0,0000000000000000)
000007FEE6AB321F atidxx64.dll XdxInitXopAdapterServices+262575 (0000000000175F40,0000000000000000,0000000000000000,0000000000000000)
000007FEE6E9587F atidxx64.dll AmdDxExtCreate11+25775 (000007FEE6FD22A0,0000000000175F40,0000000000000000,0000000000000000)
000007FEE6E95864 atidxx64.dll AmdDxExtCreate11+25748 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 3248 ---
000007FEFDFA1203 KERNELBASE.dll SleepEx+179 (000000000013F862,0000000000000000,0000000000000000,0000000000000000)
000000013F8EC15B WoW-64.exe <unknown symbol>+0 (00000000059D1A50,0000000000000000,0000000000000000,0000000000000000)
000000013F901478 WoW-64.exe <unknown symbol>+0 (00000000058094F0,0000000000000000,0000000000000000,0000000000000000)
000000014021BE9F WoW-64.exe AssertAndCrash+106879 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
000000014021BF33 WoW-64.exe AssertAndCrash+107027 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 720 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (00000001406BC080,000000000587E840,0000000000000000,00000000000020F0)
000000013FA1A658 WoW-64.exe <unknown symbol>+0 (000000000587E840,0000000000000000,0000000000000000,0000000000000000)
000000013FB75107 WoW-64.exe <unknown symbol>+0 (0000000000002584,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 240 ---
000007FEFDFA1430 KERNELBASE.dll GetCurrentProcess+64 (000000000959F488,000000000959F480,0000000000000000,0000000000000001)
00000000777F1220 kernel32.dll WaitForMultipleObjects+176 (0000000000000001,0000000000000000,0000000000000001,0000000009171598)
000007FEF5FD2001 dsound.dll <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000009171598)
000007FEF5FD2DF8 dsound.dll <unknown symbol>+0 (0000000009171598,0000000000000000,0000000000000000,0000000000000000)
000007FEF5FD20A5 dsound.dll <unknown symbol>+0 (0000000000002614,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 3272 ---
000007FEFDFA1430 KERNELBASE.dll GetCurrentProcess+64 (0000000009EBFCD8,0000000009EBFCD0,0000000000000000,0000000000000001)
0000000077802CE3 kernel32.dll WaitForMultipleObjectsEx+179 (0000000009EBFD60,00000000FFFFFFFF,0000000000000000,00000000000025F4)
00000000776F8F7D USER32.dll GetScrollBarInfo+477 (0000000000000001,0000000000169D18,0000000000000000,0000000000169CB0)
00000000776F62B2 USER32.dll MsgWaitForMultipleObjectsEx+46 (0000000000000001,0000000000169D18,0000000000000000,0000000000000000)
000007FEFC0D35BE MMDevApi.dll Ordinal9+7574 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 1604 ---
000007FEFDFA1430 KERNELBASE.dll GetCurrentProcess+64 (0000000009DAF9D8,0000000009DAF9D0,0000000000000000,0000000009BB0080)
00000000777F1220 kernel32.dll WaitForMultipleObjects+176 (0000000000000001,0000000000000000,0000000000000001,00000000091713B0)
000007FEF5FD2001 dsound.dll <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,00000000091713B0)
000007FEF5FD2132 dsound.dll <unknown symbol>+0 (00000000091713B0,0000000000000000,0000000000000000,0000000000000000)
000007FEF5FD20A5 dsound.dll <unknown symbol>+0 (00000000000025FC,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 4228 ---
000007FEFDFA1203 KERNELBASE.dll SleepEx+179 (0000000005D2F388,0000000100000000,0000000000000000,0000000000000000)
000000013FAC36BA WoW-64.exe <unknown symbol>+0 (0000000000000016,0000000000001000,0000000000000003,0000000000000000)
000000013FAC3AAA WoW-64.exe <unknown symbol>+0 (0000000000001084,0000000000001084,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 1036 ---
000007FEFDFA1430 KERNELBASE.dll GetCurrentProcess+64 (0000000009B5F850,0000000009B5F840,0000000000000000,0000000000000000)
00000000777F1220 kernel32.dll WaitForMultipleObjects+176 (0000000000000000,0000000000000002,000000000917E708,0000000000000000)
000007FEF5FDACF4 dsound.dll DirectSoundCreate8+17328 (00000000000001E0,000000000917E708,0000000000000000,0000000000000000)
000007FEF5FDB89E dsound.dll DirectSoundCreate8+20314 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 3984 ---
000007FEFDFA1203 KERNELBASE.dll SleepEx+179 (0000000005D2C820,0000000000000000,0000000000000000,0000000000000000)
000000013FAC36BA WoW-64.exe <unknown symbol>+0 (0000000000000001,00000001406D1810,0000000005D2C820,0000000000000000)
000000013FAC3AAA WoW-64.exe <unknown symbol>+0 (0000000000000F90,0000000000000F90,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 2288 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (0000000005EE9F78,0000000005EE9F68,0000000000000000,0000000000002654)
00000001401F6976 WoW-64.exe <unknown symbol>+0 (0000000000000000,000000014076A4F8,0000000005EE8FA0,0000000000000000)
00000001401F6B5F WoW-64.exe <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
000000013FB75107 WoW-64.exe <unknown symbol>+0 (00000000000026E0,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 1940 ---
000007FEFDFA1430 KERNELBASE.dll GetCurrentProcess+64 (000000000B6BF2C0,000000000B6BF2A0,0000000000000000,0000000000000002)
00000000777F1220 kernel32.dll WaitForMultipleObjects+176 (0000000000002734,0000000005EE9F30,0000000005EEAB79,0000000005EEAB79)
00000001401F7367 WoW-64.exe <unknown symbol>+0 (0000000005EE9F30,000000014076A520,000000014076A448,0000000000000000)
00000001401F67EE WoW-64.exe <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
000000013FB75107 WoW-64.exe <unknown symbol>+0 (00000000000026E4,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 2812 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (00000000048F5380,0000000000000000,0000000000000000,00000000000026FC)
000007FEE6AB44AF atidxx64.dll XdxInitXopAdapterServices+267327 (0000000000000000,00000000048F5380,0000000000000000,0000000000000000)
000007FEE6AB31F5 atidxx64.dll XdxInitXopAdapterServices+262533 (0000000009036290,0000000000000000,0000000000000000,0000000000000000)
000007FEE6E9587F atidxx64.dll AmdDxExtCreate11+25775 (000007FEE6FD22A0,0000000009036290,0000000000000000,0000000000000000)
000007FEE6E95864 atidxx64.dll AmdDxExtCreate11+25748 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 6080 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (000000000C27E2C0,0000000000000000,0000000000000000,000000000000274C)
000000013FB18058 WoW-64.exe <unknown symbol>+0 (000000000C9284F8,0000000000000001,0000000000000001,000000000D50F910)
000000013FAC3979 WoW-64.exe <unknown symbol>+0 (000000002E112340,000000000C9284F8,0000000000000001,0000000000000000)
000000013FAC3A73 WoW-64.exe <unknown symbol>+0 (00000000000017C0,00000000000017C0,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 5992 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (000000000C27E400,0000000000000000,0000000000000000,0000000000002764)
000000013FB18058 WoW-64.exe <unknown symbol>+0 (000000000CC02298,0000000000000001,0000000000000000,00000001406D1810)
000000013FAC3979 WoW-64.exe <unknown symbol>+0 (0000000000004000,000000000CC02298,0000000000000000,0000000000000000)
000000013FAC3A73 WoW-64.exe <unknown symbol>+0 (0000000000001768,0000000000001768,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 3396 ---
0000000077B14EC4 ntdll.dll RtlSleepConditionVariableCS+212 (000000000ED2C838,000000000F15F940,0000000000000000,000000003170AD80)
000000007782B258 kernel32.dll SleepConditionVariableCS+40 (000000000ED2C838,0000000000000000,000000003170AD80,0000000000000000)
000007FEE6AED1D4 atidxx64.dll AmdDxGsaFreeCompiledShader+152804 (0000000000000000,0000000009039950,0000000000000000,0000000000000000)
000007FEE6AECB2E atidxx64.dll AmdDxGsaFreeCompiledShader+151102 (0000000009039950,0000000000000000,0000000000000000,0000000000000000)
000007FEE6E9587F atidxx64.dll AmdDxExtCreate11+25775 (000007FEE6FD22A0,0000000009039950,0000000000000000,0000000000000000)
000007FEE6E95864 atidxx64.dll AmdDxExtCreate11+25748 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 4792 ---
0000000077B14EC4 ntdll.dll RtlSleepConditionVariableCS+212 (000000000ED2C860,00000000121BFA80,0000000000000000,00000000315DCA30)
000000007782B258 kernel32.dll SleepConditionVariableCS+40 (000000000ED2C860,0000000000000000,00000000315DCA30,0000000000000000)
000007FEE6AED1D4 atidxx64.dll AmdDxGsaFreeCompiledShader+152804 (0000000000000000,0000000009039DE0,0000000000000000,0000000000000000)
000007FEE6AECB2E atidxx64.dll AmdDxGsaFreeCompiledShader+151102 (0000000009039DE0,0000000000000000,0000000000000000,0000000000000000)
000007FEE6E9587F atidxx64.dll AmdDxExtCreate11+25775 (000007FEE6FD22A0,0000000009039DE0,0000000000000000,0000000000000000)
000007FEE6E95864 atidxx64.dll AmdDxExtCreate11+25748 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 6008 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (000000000C6DE490,0000000000000000,0000000000000000,0000000000002300)
000000006549C490 Battle.net-64.dll <unknown symbol>+0 (0000000000000000,00000000038973E0,0000000000000000,0000000000000000)
000000006548FA1C Battle.net-64.dll <unknown symbol>+0 (000000000C6DE490,0000000000000000,0000000000000000,000000006548FB40)
000000006549B19B Battle.net-64.dll <unknown symbol>+0 (00000000038973E0,0000000000000000,0000000000000000,0000000000000000)
00000000655947F7 Battle.net-64.dll <unknown symbol>+0 (00000000657768B0,00000000038973E0,0000000000000000,0000000000000000)
00000000655948CF Battle.net-64.dll <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 4832 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (000000000C6DE640,0000000000000000,0000000000000000,0000000000002300)
000000006549C490 Battle.net-64.dll <unknown symbol>+0 (0000000000000000,00000000038976C0,0000000000000000,0000000000000000)
000000006548FA1C Battle.net-64.dll <unknown symbol>+0 (000000000C6DE640,0000000000000000,0000000000000000,000000006548FB40)
000000006549B19B Battle.net-64.dll <unknown symbol>+0 (00000000038976C0,0000000000000000,0000000000000000,0000000000000000)
00000000655947F7 Battle.net-64.dll <unknown symbol>+0 (00000000657768B0,00000000038976C0,0000000000000000,0000000000000000)
00000000655948CF Battle.net-64.dll <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 1204 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (000000000C6DE610,0000000000000000,0000000000000000,0000000000002300)
000000006549C490 Battle.net-64.dll <unknown symbol>+0 (0000000000000000,00000000038973E0,0000000000000000,0000000000000000)
000000006548FA1C Battle.net-64.dll <unknown symbol>+0 (000000000C6DE610,0000000000000000,0000000000000000,000000006548FB40)
000000006549B19B Battle.net-64.dll <unknown symbol>+0 (00000000038973E0,0000000000000000,0000000000000000,0000000000000000)
00000000655947F7 Battle.net-64.dll <unknown symbol>+0 (00000000657768B0,00000000038973E0,0000000000000000,0000000000000000)
00000000655948CF Battle.net-64.dll <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 3724 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (000000000C6DE6A0,0000000000000000,0000000000000000,0000000000002300)
000000006549C490 Battle.net-64.dll <unknown symbol>+0 (0000000000000000,00000000038976C0,0000000000000000,0000000000000000)
000000006548FA1C Battle.net-64.dll <unknown symbol>+0 (000000000C6DE6A0,0000000000000000,0000000000000000,000000006548FB40)
000000006549B19B Battle.net-64.dll <unknown symbol>+0 (00000000038976C0,0000000000000000,0000000000000000,0000000000000000)
00000000655947F7 Battle.net-64.dll <unknown symbol>+0 (00000000657768B0,00000000038976C0,0000000000000000,0000000000000000)
00000000655948CF Battle.net-64.dll <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 4044 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (000000000C6DE700,0000000000000000,0000000000000000,0000000000002300)
000000006549C490 Battle.net-64.dll <unknown symbol>+0 (0000000000000000,00000000038973E0,0000000000000000,0000000000000000)
000000006548FA1C Battle.net-64.dll <unknown symbol>+0 (000000000C6DE700,0000000000000000,0000000000000000,000000006548FB40)
000000006549B19B Battle.net-64.dll <unknown symbol>+0 (00000000038973E0,0000000000000000,0000000000000000,0000000000000000)
00000000655947F7 Battle.net-64.dll <unknown symbol>+0 (00000000657768B0,00000000038973E0,0000000000000000,0000000000000000)
00000000655948CF Battle.net-64.dll <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 5276 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (000000000C6DE760,0000000000000000,0000000000000000,0000000000002300)
000000006549C490 Battle.net-64.dll <unknown symbol>+0 (0000000000000000,00000000038976C0,0000000000000000,0000000000000000)
000000006548FA1C Battle.net-64.dll <unknown symbol>+0 (000000000C6DE760,0000000000000000,0000000000000000,000000006548FB40)
000000006549B19B Battle.net-64.dll <unknown symbol>+0 (00000000038976C0,0000000000000000,0000000000000000,0000000000000000)
00000000655947F7 Battle.net-64.dll <unknown symbol>+0 (00000000657768B0,00000000038976C0,0000000000000000,0000000000000000)
00000000655948CF Battle.net-64.dll <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 5136 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (000000000C6DE7C0,0000000000000000,0000000000000000,0000000000002300)
000000006549C490 Battle.net-64.dll <unknown symbol>+0 (0000000000000000,00000000038973E0,0000000000000000,0000000000000000)
000000006548FA1C Battle.net-64.dll <unknown symbol>+0 (000000000C6DE7C0,0000000000000000,0000000000000000,000000006548FB40)
000000006549B19B Battle.net-64.dll <unknown symbol>+0 (00000000038973E0,0000000000000000,0000000000000000,0000000000000000)
00000000655947F7 Battle.net-64.dll <unknown symbol>+0 (00000000657768B0,00000000038973E0,0000000000000000,0000000000000000)
00000000655948CF Battle.net-64.dll <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 4428 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (000000000C6DE820,0000000000000000,0000000000000000,0000000000002300)
000000006549C490 Battle.net-64.dll <unknown symbol>+0 (0000000000000000,00000000038976C0,0000000000000000,0000000000000000)
000000006548FA1C Battle.net-64.dll <unknown symbol>+0 (000000000C6DE820,0000000000000000,0000000000000000,000000006548FB40)
000000006549B19B Battle.net-64.dll <unknown symbol>+0 (00000000038976C0,0000000000000000,0000000000000000,0000000000000000)
00000000655947F7 Battle.net-64.dll <unknown symbol>+0 (00000000657768B0,00000000038976C0,0000000000000000,0000000000000000)
00000000655948CF Battle.net-64.dll <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 4396 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (000000000C467EA0,0000000000000000,0000000000000000,0000000000002300)
000000006549C490 Battle.net-64.dll <unknown symbol>+0 (0000000000000000,00000000038973E0,0000000000000000,0000000000000000)
000000006548FA1C Battle.net-64.dll <unknown symbol>+0 (000000000C467EA0,0000000000000000,0000000000000000,000000006548FB40)
000000006549B19B Battle.net-64.dll <unknown symbol>+0 (00000000038973E0,0000000000000000,0000000000000000,0000000000000000)
00000000655947F7 Battle.net-64.dll <unknown symbol>+0 (00000000657768B0,00000000038973E0,0000000000000000,0000000000000000)
00000000655948CF Battle.net-64.dll <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 788 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (000000000C467F00,0000000000000000,0000000000000000,0000000000002300)
000000006549C490 Battle.net-64.dll <unknown symbol>+0 (0000000000000000,00000000038976C0,0000000000000000,0000000000000000)
000000006548FA1C Battle.net-64.dll <unknown symbol>+0 (000000000C467F00,0000000000000000,0000000000000000,000000006548FB40)
000000006549B19B Battle.net-64.dll <unknown symbol>+0 (00000000038976C0,0000000000000000,0000000000000000,0000000000000000)
00000000655947F7 Battle.net-64.dll <unknown symbol>+0 (00000000657768B0,00000000038976C0,0000000000000000,0000000000000000)
00000000655948CF Battle.net-64.dll <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 4604 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (000000000C467FC0,0000000000000000,0000000000000000,0000000000002814)
000000006549C490 Battle.net-64.dll <unknown symbol>+0 (0000000000000000,00000000038976C0,0000000000000000,0000000000000000)
000000006548FA1C Battle.net-64.dll <unknown symbol>+0 (000000000C467FC0,0000000000000000,0000000000000000,000000006548FB40)
000000006549B19B Battle.net-64.dll <unknown symbol>+0 (00000000038976C0,0000000000000000,0000000000000000,0000000000000000)
00000000655947F7 Battle.net-64.dll <unknown symbol>+0 (00000000657768B0,00000000038976C0,0000000000000000,0000000000000000)
00000000655948CF Battle.net-64.dll <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 6124 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (000000000C467FF0,0000000005C11800,0000000000000000,000000000000281C)
000000006549C490 Battle.net-64.dll <unknown symbol>+0 (000000000C467FF0,0000000005C11800,0000000000000000,0000000000000000)
000000006548FA1C Battle.net-64.dll <unknown symbol>+0 (000000000C467FF0,0000000000000000,0000000000000000,000000006548FB40)
000000006549B19B Battle.net-64.dll <unknown symbol>+0 (00000000038976C0,0000000000000000,0000000000000000,0000000000000000)
00000000655947F7 Battle.net-64.dll <unknown symbol>+0 (00000000657768B0,00000000038976C0,0000000000000000,0000000000000000)
00000000655948CF Battle.net-64.dll <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 3428 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (000000000C468080,0000000021E5CF30,0000000000000000,000000000000281C)
000000006549C490 Battle.net-64.dll <unknown symbol>+0 (000000000C468080,0000000003899660,0000000000000000,0000000000000000)
000000006548FA1C Battle.net-64.dll <unknown symbol>+0 (000000000C468080,0000000000000000,0000000000000000,000000006548FB40)
000000006549B19B Battle.net-64.dll <unknown symbol>+0 (0000000003899660,0000000000000000,0000000000000000,0000000000000000)
00000000655947F7 Battle.net-64.dll <unknown symbol>+0 (00000000657768B0,0000000003899660,0000000000000000,0000000000000000)
00000000655948CF Battle.net-64.dll <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 5360 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (000000000C468050,0000000000000000,0000000000000000,000000000000281C)
000000006549C490 Battle.net-64.dll <unknown symbol>+0 (000000000C468050,00000000038976C0,0000000000000000,0000000000000000)
000000006548FA1C Battle.net-64.dll <unknown symbol>+0 (000000000C468050,0000000000000000,0000000000000000,000000006548FB40)
000000006549B19B Battle.net-64.dll <unknown symbol>+0 (00000000038976C0,0000000000000000,0000000000000000,0000000000000000)
00000000655947F7 Battle.net-64.dll <unknown symbol>+0 (00000000657768B0,00000000038976C0,0000000000000000,0000000000000000)
00000000655948CF Battle.net-64.dll <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 1792 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (000000000C4680E0,0000000021E5CF30,0000000000000000,000000000000281C)
000000006549C490 Battle.net-64.dll <unknown symbol>+0 (000000000C4680E0,0000000003899660,0000000000000000,0000000000000000)
000000006548FA1C Battle.net-64.dll <unknown symbol>+0 (000000000C4680E0,0000000000000000,0000000000000000,000000006548FB40)
000000006549B19B Battle.net-64.dll <unknown symbol>+0 (0000000003899660,0000000000000000,0000000000000000,0000000000000000)
00000000655947F7 Battle.net-64.dll <unknown symbol>+0 (00000000657768B0,0000000003899660,0000000000000000,0000000000000000)
00000000655948CF Battle.net-64.dll <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 2568 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (000000000C468300,0000000000000000,0000000000000000,0000000000002830)
000000006549C490 Battle.net-64.dll <unknown symbol>+0 (0000000000000000,000000000389A500,0000000000000000,0000000000000000)
000000006548FA1C Battle.net-64.dll <unknown symbol>+0 (000000000C468300,0000000000000000,0000000000000000,000000006548FB40)
000000006549B19B Battle.net-64.dll <unknown symbol>+0 (000000000389A500,0000000000000000,0000000000000000,0000000000000000)
00000000655947F7 Battle.net-64.dll <unknown symbol>+0 (00000000657768B0,000000000389A500,0000000000000000,0000000000000000)
00000000655948CF Battle.net-64.dll <unknown symbol>+0 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 3264 ---
000007FEFDFA10DC KERNELBASE.dll WaitForSingleObjectEx+156 (0000000000000000,0000000100000000,0000000100000000,00000000000020F8)
000000013FB93D91 WoW-64.exe <unknown symbol>+0 (0000000000000000,0000000014818960,0000000000000000,0000000000000000)
000000013FB75107 WoW-64.exe <unknown symbol>+0 (00000000000028F0,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 3024 ---
0000000077A6FE0B ntdll.dll RtlValidateHeap+955 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)

--- Thread ID: 1764 ---
0000000077A6FE0B ntdll.dll RtlValidateHeap+955 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
00000000777F652D kernel32.dll BaseThreadInitThunk+13 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)
0000000077A7C521 ntdll.dll RtlUserThreadStart+33 (0000000000000000,0000000000000000,0000000000000000,0000000000000000)



----------------------------------------
Loaded Modules
----------------------------------------

DBG-MODULE<0000000010000000 00041000 "HydraDMH64.dll" "" 0 {00000000-0000-0000-0000000000000000} 0 1343439331>
DBG-MODULE<0000000065340000 004A7000 "Battle.net-64.dll" "Battle.net-64.pdb" 0 {2c9d5aa3-db14-4efb-9a1c661a929870fb} 1 1350517284>
DBG-MODULE<00000000724D0000 00006000 "ksuser.dll" "ksuser.pdb" 0 {3d25b031-596a-4559-b09aafc11220f8fd} 2 1247535081>
DBG-MODULE<0000000073280000 00026000 "mdnsNSP.dll" "mdnsNSP.pdb" 0 {176c297a-e456-474f-b58be355bd484a80} 1 1314770037>
DBG-MODULE<0000000077370000 0015B000 "WININET.dll" "wininet.pdb" 0 {a1f93438-46b8-41ab-bfe21c5d03217f38} 2 1357693916>
DBG-MODULE<00000000774D0000 00210000 "iertutil.dll" "iertutil.pdb" 0 {70d80aaa-9cc5-4a4a-8c59f3d90cf1c4ae} 2 1357693538>
DBG-MODULE<00000000776E0000 000FA000 "USER32.dll" "user32.pdb" 0 {953b0479-2b8a-48b2-883930e36fd22a6a} 2 1290258929>
DBG-MODULE<00000000777E0000 0011F000 "kernel32.dll" "kernel32.pdb" 0 {c4312728-ba1f-4691-955e99b2e026fafc} 2 1354254234>
DBG-MODULE<0000000077900000 0014D000 "urlmon.dll" "urlmon.pdb" 0 {f022ed09-0e72-4f6f-a03fed21009cb1b1} 2 1357693944>
DBG-MODULE<0000000077A50000 001A9000 "ntdll.dll" "ntdll.pdb" 0 {15eb43e2-3b12-409c-84e3cc7635baf5a3} 2 1321511566>
DBG-MODULE<0000000077C10000 00003000 "Normaliz.dll" "normaliz.pdb" 0 {0c00c7f7-797e-44c5-82656f816b361804} 1 1247535138>
DBG-MODULE<0000000077C20000 00007000 "PSAPI.DLL" "psapi.pdb" 0 {0cabcb96-5961-4c45-a750fc85662a63d6} 2 1247527581>
DBG-MODULE<000000013F8B0000 012EF000 "WoW-64.exe" "Wow-64.pdb" 0 {967cf6d4-fdfa-4dad-a5eb38fe3166df27} 1 1354589263>
DBG-MODULE<000007FEE6A70000 00710000 "atidxx64.dll" "atidxx64.pdb" 0 {5ae8212e-f689-481d-a962ef51287db70e} 1 1355946540>
DBG-MODULE<000007FEE8D80000 0001F000 "atiu9p64.dll" "atiu9p64.pdb" 0 {f0dc9e5c-da54-49f4-be726b56e2fa5cec} 7 1355945461>
DBG-MODULE<000007FEE8DA0000 0011E000 "aticfx64.dll" "aticfx64.pdb" 0 {5a87c46e-7e7b-4c17-bab38a37a9fe8bc7} 1 1355947683>
DBG-MODULE<000007FEE8EC0000 001FF000 "d3d9.dll" "d3d9.pdb" 0 {6703f277-4abc-4684-b98e9358fff7177a} 2 1290257828>
DBG-MODULE<000007FEEDE80000 0001C000 "rasman.dll" "rasman.pdb" 0 {0661f5ea-f0cb-4c33-974e539fee164f24} 2 1247535158>
DBG-MODULE<000007FEEDEA0000 00062000 "RASAPI32.dll" "rasapi32.pdb" 0 {4e3894f2-26af-4196-a7cbccc570f2e54b} 2 1247535150>
DBG-MODULE<000007FEF5750000 0000B000 "winrnr.dll" "winrnr.pdb" 0 {09207717-7dfc-4b37-bd49e938377c8139} 2 1247535283>
DBG-MODULE<000007FEF5760000 00019000 "pnrpnsp.dll" "pnrpnsp.pdb" 0 {7346e3b8-3165-41fe-b959b0787f85cc9a} 2 1247535182>
DBG-MODULE<000007FEF5780000 00015000 "napinsp.dll" "NapiNSP.pdb" 0 {d77abf6d-8c46-43d6-a4a721aa53347ecb} 2 1247535046>
DBG-MODULE<000007FEF5BB0000 00018000 "MSACM32.dll" "msacm32.pdb" 0 {b361fed7-3d08-44be-8b71510dce670862} 2 1247534991>
DBG-MODULE<000007FEF5BD0000 0000A000 "msacm32.drv" "msacm32.pdb" 0 {b5e8926b-afd5-4782-85c0a6049a1b783b} 1 1247534992>
DBG-MODULE<000007FEF5C70000 0004F000 "AUDIOSES.DLL" "AudioSes.pdb" 0 {0206049e-ccb0-4076-b0c29d1108f52b2e} 2 1290257517>
DBG-MODULE<000007FEF5F10000 0003B000 "wdmaud.drv" "wdmaud.pdb" 0 {bd2eadeb-4b61-4cb1-bab35ee13a7d1be6} 1 1290258936>
DBG-MODULE<000007FEF5F60000 00007000 "d3d8thk.dll" "d3d8thk.pdb" 0 {6619fdb8-c8a4-43ed-9a907e7881cd1d0c} 1 1247534779>
DBG-MODULE<000007FEF5FB0000 00009000 "midimap.dll" "midimap.pdb" 0 {2b256fb8-0aab-4cd6-b52b45c2188da37f} 1 1247535038>
DBG-MODULE<000007FEF5FD0000 00088000 "dsound.dll" "dsound.pdb" 0 {e9e3be7b-f2d9-47a7-86c6162eccfadafa} 2 1247534873>
DBG-MODULE<000007FEF6B90000 00009000 "sensapi.dll" "SensApi.pdb" 0 {4e212975-f5b6-4c0f-ba9c37d8da1f91bc} 2 1247535211>
DBG-MODULE<000007FEF6D50000 00064000 "webio.dll" "webio.pdb" 0 {db1a7f86-a537-421f-b60f12c5003ef448} 2 1321511574>
DBG-MODULE<000007FEF6DC0000 00071000 "WINHTTP.dll" "winhttp.pdb" 0 {5b7f00bf-da50-4704-a2b0bc24b17f90d5} 2 1290258979>
DBG-MODULE<000007FEF8CF0000 0003B000 "WINMM.dll" "winmm.pdb" 0 {df6e9d24-11ce-4ddf-b398c369d05bc96b} 2 1247535280>
DBG-MODULE<000007FEF8E60000 00025000 "atiuxp64.dll" "atiuxp64.pdb" 0 {62060919-1eae-494d-86bc5b42e9e2e580} 7 1355945475>
DBG-MODULE<000007FEF9500000 000A7000 "dxgi.dll" "dxgi.pdb" 0 {680f077f-c99b-4685-81917614d1d2f1b6} 2 1290257969>
DBG-MODULE<000007FEF99E0000 00008000 "rasadhlp.dll" "rasadhlp.pdb" 0 {c6a5b28b-c3e7-48c4-aab480f6a760d8ba} 2 1247535149>
DBG-MODULE<000007FEF99F0000 0002F000 "WLIDNSP.DLL" "wlidNSP.pdb" 0 {373c12fb-a048-401a-aaf9b0292d1f0844} 1 1301371819>
DBG-MODULE<000007FEFA090000 00053000 "fwpuclnt.dll" "fwpuclnt.pdb" 0 {68573986-57e8-47f5-8f3275dbd1b06e03} 2 1247534874>
DBG-MODULE<000007FEFA5C0000 0000B000 "WINNSI.DLL" "winnsi.pdb" 0 {20d0e4c9-82ca-45af-a5260fa6e6c25618} 2 1247535281>
DBG-MODULE<000007FEFA5D0000 00027000 "iphlpapi.DLL" "iphlpapi.pdb" 0 {8b5a2d4e-17ef-425e-b27b7705d3bc92c7} 2 1290258138>
DBG-MODULE<000007FEFA720000 00011000 "rtutils.dll" "rtutils.pdb" 0 {72d7f10a-7406-419a-a2b27e14850021b7} 2 1290258814>
DBG-MODULE<000007FEFAC20000 0009C000 "mscms.dll" "mscms.pdb" 0 {5c4b7f74-93da-4dc9-834b5960fa6e62b5} 2 1290258380>
DBG-MODULE<000007FEFACC0000 000C6000 "d3d11.dll" "d3d11.pdb" 0 {b861747b-fa17-43b5-a41012e074038176} 1 1290257826>
DBG-MODULE<000007FEFAE00000 00042000 "icm32.dll" "icm32.pdb" 0 {2af69397-7fac-498e-86d9a10ab506a5ad} 1 1247534894>
DBG-MODULE<000007FEFAE50000 0003C000 "DINPUT8.dll" "dinput8.pdb" 0 {5090c9bd-b409-42e6-9ad3bcd73e34bb76} 2 1247534799>
DBG-MODULE<000007FEFAEC0000 00125000 "dbghelp.dll" "dbghelp.pdb" 0 {094e0157-61da-454e-b641c2328520cd6f} 2 1290257836>
DBG-MODULE<000007FEFB250000 00015000 "NLAapi.dll" "nlaapi.pdb" 0 {3edbfa33-d500-4a04-8b47639f392a6e98} 2 1349286261>
DBG-MODULE<000007FEFB5F0000 00018000 "dwmapi.dll" "dwmapi.pdb" 0 {8683ed0c-3dbe-4053-883ec22fd9b4f210} 2 1247534887>
DBG-MODULE<000007FEFB9C0000 00056000 "uxtheme.DLL" "UxTheme.pdb" 0 {b0692f27-b52c-454f-aca7380c075de863} 2 1247535251>
DBG-MODULE<000007FEFBA40000 001F4000 "comctl32.dll" "comctl32.pdb" 0 {943ba638-a2cd-4d88-a1c7e7418eaf796c} 1 1290257499>
DBG-MODULE<000007FEFBF30000 00009000 "avrt.dll" "avrt.pdb" 0 {440a2c04-82ec-4474-9e7857447b6350b0} 2 1247534742>
DBG-MODULE<000007FEFBF40000 0000B000 "HID.DLL" "hid.pdb" 0 {e94cf8ff-e34d-4948-a59d521718686541} 2 1247534873>
DBG-MODULE<000007FEFBFA0000 0012C000 "PROPSYS.dll" "propsys.pdb" 0 {df712cbf-a5ab-4df1-a5d17917b6f8f53f} 2 1290258762>
DBG-MODULE<000007FEFC0D0000 0004B000 "MMDevApi.dll" "MMDevAPI.pdb" 0 {9da7a0ca-9da4-45cf-b6de7711acb9d7d9} 2 1247534952>
DBG-MODULE<000007FEFCCE0000 0002C000 "POWRPROF.dll" "powrprof.pdb" 0 {c39d0c69-bf9c-4d30-b1579f2c269cdd73} 2 1247535202>
DBG-MODULE<000007FEFCE40000 0000C000 "VERSION.dll" "version.pdb" 0 {f7695888-add1-4d77-93d5425ac6717d01} 2 1247535234>
DBG-MODULE<000007FEFD090000 00007000 "wshtcpip.dll" "wshtcpip.pdb" 0 {cda0b508-b885-4b9a-929b4b8b06a1b385} 2 1247535287>
DBG-MODULE<000007FEFD1A0000 0001E000 "USERENV.dll" "userenv.pdb" 0 {9279a318-8c07-45e8-8bb89dfbd6b07106} 2 1290258932>
DBG-MODULE<000007FEFD480000 00047000 "rsaenh.dll" "rsaenh.pdb" 0 {2bfa66bb-f64f-4b12-b0b3e7a78ae54c2d} 2 1247535161>
DBG-MODULE<000007FEFD5A0000 0005B000 "dnsapi.DLL" "dnsapi.pdb" 0 {94b9dfed-96e6-487e-a1773f4814606dc3} 2 1299132657>
DBG-MODULE<000007FEFD710000 00007000 "wship6.dll" "wship6.pdb" 0 {be71ccca-2676-4d10-836e941b34dec9d2} 2 1247535281>
DBG-MODULE<000007FEFD720000 00055000 "mswsock.dll" "mswsock.pdb" 0 {47409b8d-0e6a-4dbf-8930d24404e9dc1b} 2 1290258493>
DBG-MODULE<000007FEFD780000 00017000 "CRYPTSP.dll" "cryptsp.pdb" 0 {66e52b1e-3251-4b16-acb0a2b5dfb173ff} 1 1247534998>
DBG-MODULE<000007FEFDB80000 0000B000 "Secur32.dll" "secur32.pdb" 0 {73111ba5-51fc-4d00-b27b28c843a11a45} 2 1321511571>
DBG-MODULE<000007FEFDD50000 00025000 "SSPICLI.DLL" "sspicli.pdb" 0 {d3e497fd-589b-438c-96419717eb62d5b8} 2 1321511600>
DBG-MODULE<000007FEFDDE0000 0000F000 "CRYPTBASE.dll" "cryptbase.pdb" 0 {f03e074b-b9e7-4c9f-9bbfb0e42ef3a0ab} 2 1247534993>
DBG-MODULE<000007FEFDEB0000 0000F000 "profapi.dll" "profapi.pdb" 0 {dc86d275-bbb0-437f-94b2cd4b06d4b934} 2 1247535135>
DBG-MODULE<000007FEFDF50000 0000F000 "MSASN1.dll" "msasn1.pdb" 0 {e973c31c-b039-43dc-af30541cbaeb9a05} 2 1290258373>
DBG-MODULE<000007FEFDF60000 00036000 "CFGMGR32.dll" "cfgmgr32.pdb" 0 {9fa5840a-4d3c-4187-99f62164e98c9de8} 2 1290257756>
DBG-MODULE<000007FEFDFA0000 0006B000 "KERNELBASE.dll" "kernelbase.pdb" 0 {91c72371-dd43-4481-92b7b46f5ed10aa0} 2 1354254235>
DBG-MODULE<000007FEFE010000 0016A000 "CRYPT32.dll" "crypt32.pdb" 0 {367db482-aa32-4de9-ac868a282568a9f3} 2 1338615351>
DBG-MODULE<000007FEFE220000 0001A000 "DEVOBJ.dll" "devobj.pdb" 0 {80698d17-ff4b-4b78-90dcc6322480a7f4} 2 1247534817>
DBG-MODULE<000007FEFE240000 00039000 "WINTRUST.dll" "wintrust.pdb" 0 {adff1d76-f89e-439d-8217ff238c7f3d6d} 2 1345831190>
DBG-MODULE<000007FEFE280000 0012D000 "RPCRT4.dll" "rpcrt4.pdb" 0 {7d748da6-d745-4c9e-a38c8cef1c9e75f2} 2 1290258798>
DBG-MODULE<000007FEFE3D0000 001D7000 "SETUPAPI.dll" "setupapi.pdb" 0 {59fe8950-4c23-4732-a39999043ca804fe} 2 1290258850>
DBG-MODULE<000007FEFE5B0000 00099000 "CLBCatQ.DLL" "CLBCatQ.pdb" 0 {60b9d310-c472-440b-a13f66bff0fc39e3} 2 1247534778>
DBG-MODULE<000007FEFE650000 000C9000 "USP10.dll" "usp10.pdb" 0 {4a7216ef-8fbc-466b-854d791b75cb4416} 1 1353563088>
DBG-MODULE<000007FEFE7A0000 0009F000 "msvcrt.dll" "msvcrt.pdb" 0 {5376efb7-d7e5-4b4d-a4156ff73543e6b0} 2 1324024639>
DBG-MODULE<000007FEFE840000 0001F000 "sechost.dll" "sechost.pdb" 0 {ed003490-6f9a-408c-92c4f32acfc57b29} 1 1247535198>
DBG-MODULE<000007FEFE860000 000DB000 "ADVAPI32.dll" "advapi32.pdb" 0 {6aefdcff-7f2a-429b-8532cd2bfddf85d1} 2 1247534699>
DBG-MODULE<000007FEFE940000 00109000 "MSCTF.dll" "msctf.pdb" 0 {6a5babb8-e886-44c6-96530bfe3c90f32f} 2 1247535018>
DBG-MODULE<000007FEFEAF0000 00008000 "NSI.dll" "nsi.pdb" 0 {dddd6b3d-710d-49d5-a01af692a91fcd26} 2 1247535145>
DBG-MODULE<000007FEFEB00000 0004D000 "WS2_32.dll" "ws2_32.pdb" 0 {348be7d2-2346-495b-841b7fa203996bd0} 2 1290258981>
DBG-MODULE<000007FEFEB50000 00D88000 "SHELL32.dll" "shell32.pdb" 0 {e77e03ff-f8d7-40ae-80dd837d808db5ff} 2 1339219948>
DBG-MODULE<000007FEFF8E0000 00071000 "SHLWAPI.dll" "shlwapi.pdb" 0 {0820a075-0c1a-4e25-97e17dea57d04954} 2 1290258859>
DBG-MODULE<000007FEFF9C0000 000D7000 "OLEAUT32.dll" "oleaut32.pdb" 0 {b72b1cee-a01b-4992-a56397ff5c52db3c} 2 1314422504>
DBG-MODULE<000007FEFFAA0000 00067000 "GDI32.dll" "gdi32.pdb" 0 {fb9403c3-b130-4da1-92c4d0e3485e25ed} 2 1290258001>
DBG-MODULE<000007FEFFB10000 0000E000 "LPK.dll" "lpk.pdb" 0 {b653b2b7-5141-4f90-be8a8bbe222f1778} 2 1247534943>
DBG-MODULE<000007FEFFB20000 00203000 "ole32.dll" "ole32.pdb" 0 {ee489189-724f-4d47-aeccfdb553482435} 2 1290258732>
DBG-MODULE<000007FEFFD30000 0002E000 "IMM32.dll" "imm32.pdb" 0 {98f27ba5-aee5-41ec-bee00cd03ad50fee} 2 1247534912>

----------------------------------------
Memory Dump
----------------------------------------

Code: 32 bytes starting at (RIP = 000000013FA2AEC0 - 10)

000000013FA2AEB0: D2 75 ED 4C 89 6F 40 48 83 C4 28 41 5D 5F C3 CC .u.L.o@H..(A]_..
* = addr ** *
000000013FA2AEC0: F6 41 14 10 74 20 F6 41 18 01 75 14 48 8B 41 48 .A..t .A..u.H.AH


Stack: 1024 bytes starting at (RSP = 00000000002CF328 - 20)

00000000002CF300: 00 00 00 00 00 00 00 00 D8 E4 1E 40 01 00 00 00 ...........@....
00000000002CF310: 01 52 0F 24 00 00 00 00 70 E3 D7 21 00 00 00 00 .R.$....p..!....
00000000002CF320: 39 E2 D7 21 00 00 00 00 27 22 1C 40 01 00 00 00 9..!....'".@....
* = addr ** *
00000000002CF320: 39 E2 D7 21 00 00 00 00 27 22 1C 40 01 00 00 00 9..!....'".@....
00000000002CF330: 00 00 00 00 00 00 00 00 A9 B2 26 40 01 00 00 00 ..........&@....
00000000002CF340: CD CC 4C 3E 00 00 00 00 00 00 00 00 00 00 00 00 ..L>............
00000000002CF350: 00 80 A2 44 00 00 00 00 00 00 00 00 00 00 00 00 ...D............
00000000002CF360: 00 00 7A 43 00 00 00 00 00 00 00 00 00 00 00 00 ..zC............
00000000002CF370: 01 00 00 00 00 00 00 00 FB 01 00 00 00 00 00 00 ................
00000000002CF380: 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000000002CF390: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000000002CF3A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000000002CF3B0: 1E 2E 56 40 00 00 00 00 00 00 00 00 00 00 00 00 ..V@............
00000000002CF3C0: CD CC 4C 3E 00 00 00 00 00 00 00 00 00 00 00 00 ..L>............
00000000002CF3D0: 00 80 A2 44 00 00 00 00 00 00 00 00 00 00 00 00 ...D............
00000000002CF3E0: 00 00 80 42 00 00 00 00 00 00 00 00 00 00 00 00 ...B............
00000000002CF3F0: 00 00 00 00 00 00 00 00 09 00 00 00 00 00 00 00 ................
00000000002CF400: 00 00 00 00 00 00 00 00 AC 40 B0 1B 00 00 00 00 .........@......
00000000002CF410: B0 F5 2C 00 00 00 00 00 5B 3C 1C 40 01 00 00 00 ..,.....[<.@....
00000000002CF420: 39 E2 D7 21 00 00 00 00 00 00 00 00 00 00 00 00 9..!............
00000000002CF430: A0 E0 D7 21 00 00 00 00 F0 01 00 00 00 00 00 00 ...!............
00000000002CF440: B0 F5 2C 00 00 00 00 00 E9 88 16 40 01 00 00 00 ..,........@....
00000000002CF450: B0 F7 CF 0A 00 00 00 00 AC 40 B0 1B 00 00 00 00 .........@......
00000000002CF460: B0 F5 2C 00 00 00 00 00 D2 EF 14 40 01 00 00 00 ..,........@....
00000000002CF470: DB 0F C9 3F 00 00 00 00 39 8E E3 3F 01 00 00 00 ...?....9..?....
00000000002CF480: 39 8E E3 3F 00 00 00 00 00 00 00 00 00 00 00 00 9..?............
00000000002CF490: 34 83 65 40 01 00 00 00 02 F6 14 40 01 00 00 00 4.e@.......@....
00000000002CF4A0: B0 F7 CF 0A 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000000002CF4B0: 00 00 00 80 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000000002CF4C0: DB 0F C9 3F 00 00 00 00 39 8E E3 3F 00 00 00 00 ...?....9..?....
00000000002CF4D0: CD CC 4C 3E 00 00 00 00 00 00 00 00 00 00 00 00 ..L>............
00000000002CF4E0: 00 80 A2 44 00 00 00 00 00 00 00 00 00 00 00 00 ...D............
00000000002CF4F0: DB 0F C9 3F 00 00 00 00 00 00 00 00 00 00 00 00 ...?............
00000000002CF500: C8 CC 25 0C 00 00 00 00 38 A8 71 0C 00 00 00 00 ..%.....8.q.....
00000000002CF510: 00 00 00 00 00 00 00 00 55 4C F6 3F 01 00 00 00 ........UL.?....
00000000002CF520: 80 40 B0 1B 00 00 00 00 20 F6 2C 00 00 00 00 00 .@...... .,.....
00000000002CF530: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000000002CF540: DB 0F C9 3F 86 3C CA 3F 39 8E E3 3F 00 00 00 00 ...?.<.?9..?....
00000000002CF550: C0 F5 2C 00 00 00 00 00 A0 F5 2C 00 00 00 00 00 ..,.......,.....
00000000002CF560: 90 F5 2C 00 00 00 00 00 1E 2E 56 40 00 00 00 00 ..,.......V@....
00000000002CF570: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000000002CF580: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000000002CF590: E7 E8 BA C1 91 6D 9B C0 A8 1D 7F 41 00 00 00 00 .....m.....A....
00000000002CF5A0: 66 1C 42 44 2B EF 95 43 B5 76 1E 44 01 00 00 00 f.BD+..C.v.D....
00000000002CF5B0: AB AD 42 44 91 2B 96 43 EA 88 1F 44 00 00 00 00 ..BD.+.C...D....
00000000002CF5C0: 66 1C 42 44 2B EF 95 43 B5 76 1E 44 00 00 00 00 f.BD+..C.v.D....
00000000002CF5D0: 96 43 8B 3C 00 00 00 00 00 00 00 00 00 00 00 00 .C.<............
00000000002CF5E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000000002CF5F0: 00 00 00 80 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000000002CF600: 00 00 80 3F 00 00 00 00 00 00 00 00 00 00 00 00 ...?............
00000000002CF610: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000000002CF620: 00 00 00 80 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000000002CF630: 40 F7 2C 00 00 00 00 00 08 55 F6 3F 01 00 00 00 @.,......U.?....
00000000002CF640: 90 C6 F2 2D 00 00 00 00 98 6D 58 05 00 00 00 00 ...-.....mX.....
00000000002CF650: 38 A8 71 0C 00 00 00 00 38 50 C4 2D 00 00 00 00 8.q.....8P.-....
00000000002CF660: 6F 88 42 44 E1 4F 96 43 38 51 20 44 00 00 00 00 o.BD.O.C8Q D....
00000000002CF670: 1D A4 7A BF C1 6C 50 BE 00 00 00 00 00 00 00 00 ..z..lP.........
00000000002CF680: 96 43 8B 3C 96 43 8B 3C 00 00 00 00 00 00 00 00 .C.<.C.<........
00000000002CF690: 00 00 00 00 00 00 00 00 91 F4 00 00 00 00 00 00 ................
00000000002CF6A0: 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000000002CF6B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000000002CF6C0: 54 03 48 44 63 63 98 43 E9 E4 1B 44 00 00 00 00 T.HDcc.C...D....
00000000002CF6D0: AB AD 42 44 91 2B 96 43 EA 88 1F 44 01 00 00 00 ..BD.+.C...D....
00000000002CF6E0: 66 1C 42 44 2B EF 95 43 B5 76 1E 44 00 00 00 00 f.BD+..C.v.D....
00000000002CF6F0: 6F 88 42 44 E1 4F 96 43 38 D1 1F 44 00 00 00 00 o.BD.O.C8..D....
00000000002CF700: 00 00 80 3F 00 00 00 00 00 00 00 00 00 00 00 00 ...?............
00000000002CF710: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
00000000002CF720: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................


------------------------------------------------------------------------------
Percent memory used: 23
Total physical memory: 17130921984
Free physical memory: 13029756928
Page file: 34259943424
Total virtual memory: 8796092891136
Free virtual memory: 8792786776064
------------------------------------------------------------------------------

List of running Wow-64.exe processes

Process: D:\Install\World of Warcraft\WoW-64.exe; pid: 5160

List of running Agent.exe processes
Eldest
Regular Member
 
Posts: 26
Joined: February 19th, 2013, 3:50 pm

Re: Every program crashing and getting Blue Screen

Unread postby Gary R » February 26th, 2013, 10:22 am

No real clues in the WoW crash report.

At this point I believe your problems are more likely to be hardware related than anything else, but before I direct you to someone who can help analyse any possible hardware issues, I'd like you to run a couple of new scans for me.

First

Please run a new scan for me with OTL ...

  • Double click OTL.exe to launch the programme.
  • Check the following.
    • Scan all users.
    • Standard Output.
    • Lop check.
    • Purity check.
  • Under Extra Registry section, select Use SafeList
  • Click the Run Scan button and wait for the scan to finish (usually about 10-15 mins).
  • When finished it will produce two logs.
    • OTL.txt (open on your desktop).
    • Extras.txt (minimised in your taskbar)
  • Please post me both logs.

Next

Download GMER to your Desktop. (It will have a randomly generated name, for example .... wjkl3ecz.exe)

  • Disconnect from the Internet, and close all running programmes.
  • There is a small chance this programme may crash your computer, so save any work you have open.
  • Double click on the randomly named GMER file (eg .... wjkl3ecz.exe) to launch GMER.
  • Let the gmer.sys driver load if asked.
  • If it gives you a warning at programme start about rootkit activity and asks if you want to run a scan ..... click OK.
  • If no warning:
    • Click Rootkit tab.
    • Ensure that All the boxes to the right of the program are checked except Show All.
    • Click Scan.
  • Do not use your computer while the scan is running.
  • Once scan is finished click Copy.
    • Click Start > Run then type Notepad.exe then click OK.
    • This will open a Notepad file.
    • Hit Ctrl+V to paste log into it.
    • Save the log to your Desktop.
  • Reconnect to internet and post the log please.

Summary of the logs I need from you in your next post:
  • OTL.txt
  • Extras.txt
  • GMER log


Please post each log separately to prevent it being cut off by the forum post size limiter. Check each after you've posted it to make sure it's all present, if any log is cut off you'll have to post it in sections.
User avatar
Gary R
Administrator
Administrator
 
Posts: 21872
Joined: June 28th, 2005, 11:36 am
Location: Yorkshire

Re: Every program crashing and getting Blue Screen

Unread postby Eldest » February 26th, 2013, 3:23 pm

Hey Gary.

I've done as instructed. Logs will follow.

I've also attached another minidump for a Blue Screen that occured today.

And to be clear, as you'll see I've reinstalled uTorrent (without toolbars, did not intend for them to be installed last time) as it did not seem that was the problem.


OTL log:

OTL logfile created on: 2013-02-26 18:45:19 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Eldest\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 0000041d | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

15,95 Gb Total Physical Memory | 14,22 Gb Available Physical Memory | 89,13% Memory free
31,91 Gb Paging File | 30,10 Gb Available in Paging File | 94,33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 119,14 Gb Total Space | 11,05 Gb Free Space | 9,27% Space Free | Partition Type: NTFS
Drive D: | 1863,01 Gb Total Space | 1312,69 Gb Free Space | 70,46% Space Free | Partition Type: NTFS

Computer Name: NORMANDY | User Name: Eldest | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013-02-26 17:31:10 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Eldest\Desktop\OTL.exe
PRC - [2012-12-18 15:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012-11-15 13:11:48 | 001,358,784 | ---- | M] (Technology Nexus AB) -- C:\Program Files (x86)\Personal\bin\Personal.exe
PRC - [2012-10-26 12:39:48 | 001,199,576 | ---- | M] (Spotify Ltd) -- C:\Users\Eldest\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
PRC - [2012-10-18 17:02:12 | 001,952,312 | ---- | M] (Micro-Star International) -- C:\Program Files (x86)\MSI\Live Update 5\LU5.exe
PRC - [2012-07-27 20:35:52 | 000,393,216 | ---- | M] (AMD) -- C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
PRC - [2012-01-26 18:40:44 | 000,291,608 | R--- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
PRC - [2012-01-20 09:35:24 | 000,363,800 | R--- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2012-01-20 09:35:22 | 000,277,784 | R--- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2012-01-20 09:35:08 | 000,161,560 | R--- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
PRC - [2011-12-09 09:15:24 | 000,252,432 | ---- | M] () -- C:\Program Files (x86)\MSI\OTPService\OTPService.exe


========== Modules (No Company Name) ==========

MOD - [2012-08-27 20:33:32 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012-08-27 20:33:08 | 001,242,512 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll


========== Services (SafeList) ==========

SRV:64bit: - [2013-01-27 11:34:32 | 000,379,360 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2013-01-27 11:34:32 | 000,022,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2012-12-19 20:56:00 | 000,240,640 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2012-01-10 20:01:52 | 000,627,936 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel(R)
SRV:64bit: - [2011-11-09 16:38:06 | 000,189,608 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\IPROSetMonitor.exe -- (Intel(R)
SRV:64bit: - [2009-07-14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009-07-14 02:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2013-02-19 17:20:12 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013-02-15 13:15:34 | 000,251,248 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012-12-18 15:28:08 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012-11-05 00:26:12 | 000,529,744 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012-07-13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012-01-20 09:35:24 | 000,363,800 | R--- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2012-01-20 09:35:22 | 000,277,784 | R--- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2012-01-20 09:35:08 | 000,161,560 | R--- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe -- (jhi_service)
SRV - [2011-12-09 09:15:24 | 000,252,432 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\MSI\OTPService\OTPService.exe -- (MSI_OTPService)
SRV - [2010-03-18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009-06-10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013-01-20 15:59:04 | 000,130,008 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012-12-19 21:48:48 | 011,278,336 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012-12-19 20:32:54 | 000,552,960 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012-11-06 12:11:52 | 000,096,256 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2012-09-28 10:32:56 | 000,053,760 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012-08-23 15:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012-08-23 15:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012-08-21 12:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012-07-17 18:12:08 | 000,062,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2012-03-01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012-01-26 18:39:34 | 000,787,736 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc)
DRV:64bit: - [2012-01-26 18:39:34 | 000,356,120 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub)
DRV:64bit: - [2012-01-26 18:39:34 | 000,016,152 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs)
DRV:64bit: - [2011-11-30 08:09:34 | 000,358,576 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1c62x64.sys -- (e1cexpress)
DRV:64bit: - [2011-11-10 18:32:02 | 000,115,272 | ---- | M] (MotioninJoy) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\MijXfilt.sys -- (MotioninJoyXFilter)
DRV:64bit: - [2011-03-11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011-03-11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011-03-02 16:58:58 | 000,036,448 | ---- | M] (Asmedia Technology) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\asahci64.sys -- (asahci64)
DRV:64bit: - [2010-11-20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010-08-19 19:24:34 | 000,074,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:64bit: - [2009-11-18 00:12:00 | 000,032,344 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\MBfilt64.sys -- (MBfilt)
DRV:64bit: - [2009-07-14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009-07-14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009-07-14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009-06-10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009-06-10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009-06-10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009-06-10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2010-10-22 10:37:36 | 000,014,136 | ---- | M] (MSI) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys -- (NTIOLib_1_0_4)
DRV - [2010-05-10 10:44:40 | 000,033,592 | ---- | M] (Your Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys -- (MSI_MSIBIOS_010507)
DRV - [2009-10-05 23:10:14 | 000,014,136 | ---- | M] (MSI) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\MSI\OTPService\NTIOLib_X64.sys -- (NTIOLib_1_0_T)
DRV - [2009-07-14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page =
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-178671379-1301378200-1053161076-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKU\S-1-5-21-178671379-1301378200-1053161076-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://se.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-178671379-1301378200-1053161076-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = sv-SE
IE - HKU\S-1-5-21-178671379-1301378200-1053161076-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 17 54 05 85 69 0F CE 01 [binary data]
IE - HKU\S-1-5-21-178671379-1301378200-1053161076-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-178671379-1301378200-1053161076-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-178671379-1301378200-1053161076-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-178671379-1301378200-1053161076-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://mail.ownit.se/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2fmail.ownit.se%2fowa%2f"
FF - prefs.js..extensions.enabledAddons: %7B5384767E-00D9-40E9-B72F-9CC39D655D6F%7D:1.4.2.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0
FF - prefs.js..browser.startup.homepage: "http://en.wikipedia.org/wiki/Special:Random"
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_168.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_168.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@se.nexus/Personal: C:\Program Files (x86)\Personal\bin\np_prsnl.dll (Technology Nexus AB)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Eldest\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013-02-19 17:20:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2012-09-25 14:55:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eldest\AppData\Roaming\Mozilla\Extensions
[2013-02-15 11:25:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eldest\AppData\Roaming\Mozilla\Firefox\Profiles\sg21ynug.default\extensions
[2012-12-24 02:38:38 | 000,000,000 | ---D | M] (EPUBReader) -- C:\Users\Eldest\AppData\Roaming\Mozilla\Firefox\Profiles\sg21ynug.default\extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}
[2013-02-15 11:25:12 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\Eldest\AppData\Roaming\Mozilla\Firefox\Profiles\sg21ynug.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013-02-19 17:19:58 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2013-02-19 17:20:13 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012-12-05 02:15:42 | 000,001,683 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\allaannonser-sv-SE.xml
[2012-09-06 03:42:44 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012-12-05 02:15:42 | 000,002,883 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\prisjakt-sv-SE.xml
[2012-12-05 02:15:42 | 000,001,161 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\tyda-sv-SE.xml
[2012-09-06 03:42:44 | 000,001,387 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-sv-SE.xml
[2012-09-06 03:42:45 | 000,001,164 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-sv-SE.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://en.wikipedia.org/wiki/Special:Random
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.97\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.97\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Nexus Personal (Enabled) = C:\Program Files (x86)\Personal\bin\np_prsnl.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Eldest\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_168.dll
CHR - Extension: Google Dokument = C:\Users\Eldest\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\Eldest\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Eldest\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Adblock Plus = C:\Users\Eldest\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.3.4_0\
CHR - Extension: S\u00F6k p\u00E5 Google = C:\Users\Eldest\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Dark Vibe = C:\Users\Eldest\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkckeanhmkjaechlhllmapjaaglgpcbj\1.1_0\
CHR - Extension: Reddit Enhancement Suite = C:\Users\Eldest\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb\4.1.5_0\
CHR - Extension: Cuevana Stream = C:\Users\Eldest\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfdckejfnkaemompfjhecfmhjgnchmjg\5.1_0\
CHR - Extension: Gmail = C:\Users\Eldest\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2013-02-20 13:44:01 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Live Update 5] C:\Program Files (x86)\MSI\Live Update 5\BootStartLiveupdate.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-178671379-1301378200-1053161076-1000..\Run: [HydraVisionDesktopManager] C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD)
O4 - HKU\S-1-5-21-178671379-1301378200-1053161076-1000..\Run: [Spotify Web Helper] C:\Users\Eldest\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKU\S-1-5-21-178671379-1301378200-1053161076-1000..\Run: [uTorrent] C:\Users\Eldest\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-178671379-1301378200-1053161076-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Open Client to monitor &1 - C:\Windows\web\AOpenClient.htm File not found
O8:64bit: - Extra context menu item: Open Client to monitor &2 - C:\Windows\web\AOpenClient.htm File not found
O8 - Extra context menu item: Open Client to monitor &1 - C:\Windows\web\AOpenClient.htm File not found
O8 - Extra context menu item: Open Client to monitor &2 - C:\Windows\web\AOpenClient.htm File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 84.246.88.10 84.246.88.20
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E3D756C6-771A-4D6A-A363-943883E55FDB}: DhcpNameServer = 84.246.88.10 84.246.88.20
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E3D756C6-771A-4D6A-A363-943883E55FDB}: NameServer = 8.8.8.8,8.8.4.4
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013-02-26 17:31:17 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Eldest\Desktop\OTL.exe
[2013-02-24 00:54:44 | 000,000,000 | ---D | C] -- C:\Users\Eldest\Documents\Internminne
[2013-02-22 23:33:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013-02-22 23:33:45 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2013-02-22 23:33:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2013-02-22 23:33:45 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013-02-22 23:33:45 | 000,000,000 | ---D | C] -- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013-02-22 02:14:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
[2013-02-22 01:53:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013-02-22 01:53:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2013-02-20 22:36:57 | 000,000,000 | ---D | C] -- C:\Users\Eldest\AppData\Roaming\uTorrent
[2013-02-20 13:50:43 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013-02-20 13:49:25 | 000,000,000 | ---D | C] -- C:\JRT
[2013-02-20 12:54:18 | 000,000,000 | ---D | C] -- C:\RegBackup
[2013-02-19 18:43:02 | 000,057,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys
[2013-02-19 18:43:02 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys
[2013-02-19 18:43:02 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RdpGroupPolicyExtension.dll
[2013-02-19 18:43:02 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
[2013-02-19 18:43:02 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
[2013-02-19 18:43:01 | 004,916,224 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2013-02-19 18:43:01 | 003,174,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorets.dll
[2013-02-19 18:43:01 | 001,123,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstsc.exe
[2013-02-19 18:43:01 | 001,048,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstsc.exe
[2013-02-19 18:43:01 | 000,384,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wksprt.exe
[2013-02-19 18:43:01 | 000,322,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aaclient.dll
[2013-02-19 18:43:01 | 000,269,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\aaclient.dll
[2013-02-19 18:43:01 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpudd.dll
[2013-02-19 18:43:01 | 000,228,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpendp_winip.dll
[2013-02-19 18:43:01 | 000,192,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpendp_winip.dll
[2013-02-19 18:43:01 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWbPrxy.exe
[2013-02-19 18:43:01 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsRdpWebAccess.dll
[2013-02-19 18:43:01 | 000,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MsRdpWebAccess.dll
[2013-02-19 18:43:01 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsgqec.dll
[2013-02-19 18:43:01 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbGDCoInstaller.dll
[2013-02-19 18:43:01 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tsgqec.dll
[2013-02-19 18:43:01 | 000,018,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wksprtPS.dll
[2013-02-19 18:43:01 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wksprtPS.dll
[2013-02-19 18:43:00 | 005,773,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2013-02-19 18:42:33 | 001,448,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2013-02-19 17:19:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013-02-17 18:19:52 | 000,328,712 | ---- | C] (Logitech Inc.) -- C:\Windows\SysNative\MijFrc.dll
[2013-02-17 18:19:52 | 000,115,272 | ---- | C] (MotioninJoy) -- C:\Windows\SysNative\drivers\MijXfilt.sys
[2013-02-17 18:19:52 | 000,074,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\xusb21.sys
[2013-02-17 18:19:52 | 000,000,000 | ---D | C] -- C:\Users\Eldest\AppData\Roaming\MotioninJoy
[2013-02-17 18:19:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MotioninJoy
[2013-02-17 18:19:52 | 000,000,000 | ---D | C] -- C:\Program Files\MotioninJoy
[2013-02-17 17:53:55 | 000,000,000 | ---D | C] -- C:\Users\Eldest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\project64 1.6
[2013-02-17 17:53:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Project64 1.6
[2013-02-16 01:56:48 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft
[2013-02-16 01:56:45 | 000,000,000 | ---D | C] -- C:\Users\Eldest\Documents\CAPCOM
[2013-02-16 01:56:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows - LIVE
[2013-02-16 01:56:01 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\xlive
[2013-02-16 01:56:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
[2013-02-14 03:00:21 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013-02-14 03:00:20 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013-02-14 03:00:20 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013-02-14 03:00:20 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013-02-14 03:00:20 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2013-02-14 03:00:20 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013-02-14 03:00:20 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013-02-14 03:00:19 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013-02-14 03:00:19 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2013-02-14 03:00:19 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013-02-14 03:00:19 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013-02-14 03:00:19 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013-02-14 03:00:18 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013-02-14 03:00:18 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013-02-14 03:00:18 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2013-02-13 06:15:38 | 005,553,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2013-02-13 06:15:37 | 003,967,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2013-02-13 06:15:37 | 003,913,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2013-02-13 06:15:35 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2013-02-13 06:15:35 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2013-02-13 06:15:34 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2013-02-13 06:15:34 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2013-02-13 06:15:34 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2013-02-13 06:15:34 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2013-02-13 06:15:33 | 000,288,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2013-02-11 16:07:12 | 000,000,000 | ---D | C] -- C:\Users\Eldest\AppData\Local\ElevatedDiagnostics
[2013-02-08 01:00:55 | 000,000,000 | ---D | C] -- C:\Users\Eldest\AppData\Local\My Games
[2013-02-07 01:42:11 | 000,000,000 | ---D | C] -- C:\Users\Eldest\Documents\Remedy
[2013-02-07 00:23:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StarCraft II Beta
[2013-02-07 00:23:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\StarCraft II 2012 Beta
[2013-02-06 16:10:36 | 000,000,000 | ---D | C] -- C:\Users\Eldest\Documents\Backup
[2013-02-05 02:03:33 | 000,000,000 | ---D | C] -- C:\Users\Eldest\AppData\Roaming\System
[2013-02-05 02:03:32 | 000,000,000 | -HSD | C] -- C:\Users\Eldest\AppData\Roaming\wyUpdate AU
[2013-02-05 02:03:32 | 000,000,000 | ---D | C] -- C:\Users\Eldest\Documents\Universe Sandbox
[2013-02-05 02:03:32 | 000,000,000 | ---D | C] -- C:\Users\Eldest\AppData\Local\Universe Sandbox
[2013-02-05 00:20:44 | 000,000,000 | ---D | C] -- C:\Users\Eldest\AppData\Roaming\Personal
[2013-02-05 00:20:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BankID säkerhetsprogram
[2013-02-05 00:20:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Personal
[2013-02-04 23:15:13 | 000,000,000 | -HSD | C] -- C:\found.000
[2013-02-03 21:06:44 | 000,000,000 | ---D | C] -- C:\Users\Eldest\Documents\My Games
[2013-02-03 20:54:37 | 000,000,000 | ---D | C] -- C:\Users\Eldest\AppData\Roaming\LucasArts
[2013-02-03 14:06:08 | 000,000,000 | RH-D | C] -- C:\ESD
[2013-01-31 23:12:43 | 000,000,000 | ---D | C] -- C:\Users\Eldest\AppData\Local\Unity
[2013-01-29 18:30:56 | 000,000,000 | ---D | C] -- C:\Users\Eldest\Documents\Telltale Games

========== Files - Modified Within 30 Days ==========

[2013-02-26 18:25:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013-02-26 17:58:00 | 000,000,994 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013-02-26 17:37:24 | 000,015,168 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013-02-26 17:37:24 | 000,015,168 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013-02-26 17:34:32 | 000,730,320 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013-02-26 17:34:32 | 000,618,714 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013-02-26 17:34:32 | 000,107,034 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013-02-26 17:31:10 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Eldest\Desktop\OTL.exe
[2013-02-26 17:30:22 | 000,000,990 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013-02-26 17:30:16 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013-02-26 17:30:15 | 4258,254,846 | -HS- | M] () -- C:\hiberfil.sys
[2013-02-26 16:37:06 | 000,158,282 | ---- | M] () -- C:\Users\Eldest\Desktop\Har följt sin stulna dator i över två veckor - Computer Sweden.pdf
[2013-02-26 16:34:23 | 001,649,666 | ---- | M] () -- C:\Users\Eldest\Desktop\Trådlös el_ Rymdkraftverk och trådlösa vägar - M3.pdf
[2013-02-26 16:32:52 | 001,029,134 | ---- | M] () -- C:\Users\Eldest\Desktop\Nes_ En legend tar sin början - IDG.pdf
[2013-02-23 21:09:08 | 000,002,279 | ---- | M] () -- C:\Users\Eldest\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013-02-20 13:44:01 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts
[2013-02-20 12:54:29 | 000,000,207 | ---- | M] () -- C:\Windows\tweaking.com-regbackup-NORMANDY-Microsoft-Windows-7-Professional-(64-bit).dat
[2013-02-19 18:42:57 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2013-02-17 18:20:33 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_xusb21_01009.Wdf
[2013-02-17 18:20:33 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_MijXfilt_01009.Wdf
[2013-02-17 18:19:52 | 000,000,947 | ---- | M] () -- C:\Users\Eldest\Application Data\Microsoft\Internet Explorer\Quick Launch\DS3 Tool.lnk
[2013-02-15 13:15:34 | 000,691,568 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013-02-15 13:15:34 | 000,071,024 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013-02-14 07:21:24 | 000,416,792 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013-02-05 00:20:43 | 000,001,165 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BankID säkerhetsprogram.lnk

========== Files Created - No Company Name ==========

[2013-02-26 16:37:06 | 000,158,282 | ---- | C] () -- C:\Users\Eldest\Desktop\Har följt sin stulna dator i över två veckor - Computer Sweden.pdf
[2013-02-26 16:34:23 | 001,649,666 | ---- | C] () -- C:\Users\Eldest\Desktop\Trådlös el_ Rymdkraftverk och trådlösa vägar - M3.pdf
[2013-02-26 16:32:52 | 001,029,134 | ---- | C] () -- C:\Users\Eldest\Desktop\Nes_ En legend tar sin början - IDG.pdf
[2013-02-22 01:53:44 | 000,002,279 | ---- | C] () -- C:\Users\Eldest\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013-02-22 01:53:23 | 000,000,994 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013-02-22 01:53:23 | 000,000,990 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013-02-20 12:54:29 | 000,000,207 | ---- | C] () -- C:\Windows\tweaking.com-regbackup-NORMANDY-Microsoft-Windows-7-Professional-(64-bit).dat
[2013-02-17 18:20:33 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_xusb21_01009.Wdf
[2013-02-17 18:20:33 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_MijXfilt_01009.Wdf
[2013-02-17 18:19:52 | 000,000,947 | ---- | C] () -- C:\Users\Eldest\Application Data\Microsoft\Internet Explorer\Quick Launch\DS3 Tool.lnk
[2013-02-05 00:20:43 | 000,001,165 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\BankID säkerhetsprogram.lnk
[2012-09-17 19:43:41 | 000,722,382 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012-09-17 19:14:44 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012-07-28 02:39:50 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012-07-28 02:39:50 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012-05-02 13:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2012-01-10 19:39:16 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll
[2011-09-28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011-09-12 23:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat

========== ZeroAccess Check ==========

[2009-07-14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012-06-09 06:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012-06-09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009-07-14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-20 13:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009-07-14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013-02-03 20:54:37 | 000,000,000 | ---D | M] -- C:\Users\Eldest\AppData\Roaming\LucasArts
[2013-02-17 18:19:52 | 000,000,000 | ---D | M] -- C:\Users\Eldest\AppData\Roaming\MotioninJoy
[2013-02-05 00:20:44 | 000,000,000 | ---D | M] -- C:\Users\Eldest\AppData\Roaming\Personal
[2013-02-26 17:17:40 | 000,000,000 | ---D | M] -- C:\Users\Eldest\AppData\Roaming\Spotify
[2013-02-05 02:03:33 | 000,000,000 | ---D | M] -- C:\Users\Eldest\AppData\Roaming\System
[2013-02-26 18:44:50 | 000,000,000 | ---D | M] -- C:\Users\Eldest\AppData\Roaming\uTorrent
[2013-02-05 02:32:23 | 000,000,000 | -HSD | M] -- C:\Users\Eldest\AppData\Roaming\wyUpdate AU

========== Purity Check ==========



< End of report >
You do not have the required permissions to view the files attached to this post.
Eldest
Regular Member
 
Posts: 26
Joined: February 19th, 2013, 3:50 pm

Re: Every program crashing and getting Blue Screen

Unread postby Eldest » February 26th, 2013, 3:24 pm

Extras log:

OTL Extras logfile created on: 2013-02-26 18:45:19 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Eldest\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 0000041d | Country: Sverige | Language: SVE | Date Format: yyyy-MM-dd

15,95 Gb Total Physical Memory | 14,22 Gb Available Physical Memory | 89,13% Memory free
31,91 Gb Paging File | 30,10 Gb Available in Paging File | 94,33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 119,14 Gb Total Space | 11,05 Gb Free Space | 9,27% Space Free | Partition Type: NTFS
Drive D: | 1863,01 Gb Total Space | 1312,69 Gb Free Space | 70,46% Space Free | Partition Type: NTFS

Computer Name: NORMANDY | User Name: Eldest | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_USERS\S-1-5-21-178671379-1301378200-1053161076-1000\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
http [open] -- "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
http [open] -- "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
https [open] -- "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -osint -url "%1" (Mozilla Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0B64227D-67A1-4DB8-AF8A-49184BBCBD42}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0C54D2D6-CA80-4C85-9261-BDAE1DE4542B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{18C99D2F-A606-4447-A79E-18F3B9D4709B}" = rport=445 | protocol=6 | dir=out | app=system |
"{1A810339-1511-4049-9BB8-DB29BB1615DA}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{1BBB1351-DB0D-4D22-8DE0-1401F7986622}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{301B5895-BF41-4ADB-94E8-A4EB389E8DB6}" = rport=139 | protocol=6 | dir=out | app=system |
"{40105BCF-3DCA-45D8-B909-83E6290A43F9}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
"{4CC68C3D-0EAF-481D-B889-E8B862F6A399}" = lport=10243 | protocol=6 | dir=in | app=system |
"{4CD54B7D-4E19-4684-8AFD-20C210B60EF9}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{4EFD04B5-646B-4CB8-8ACB-55A6C342D528}" = rport=10243 | protocol=6 | dir=out | app=system |
"{5D7516A6-F35B-4425-B67D-762AD1C4E01B}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{5DCB2CBD-25E6-4978-AFE3-CE7345FD1E14}" = lport=137 | protocol=17 | dir=in | app=system |
"{5E34F645-5521-4417-910E-394E5156C6C2}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6A2B3591-4D29-4C87-9419-AD482BC35FC3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8176ECE1-9631-4AEC-B7FD-0AE13C1FAEB3}" = lport=139 | protocol=6 | dir=in | app=system |
"{A9DD4A7F-0FAE-49A3-93EB-90ED2EA4ACAB}" = rport=138 | protocol=17 | dir=out | app=system |
"{ABA322F2-1C50-47C3-A7E5-1C13F26D2690}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{B06149CB-9BF1-4282-8E03-4E6D3952D5D6}" = lport=2869 | protocol=6 | dir=in | app=system |
"{B35E3EB6-43DD-4B93-95D5-B8F3B3217D86}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BE0D40C7-1575-4601-AB87-4F631C7D1E99}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{C92E7AE0-2EBD-4A2E-ADD4-E34D44214A76}" = lport=445 | protocol=6 | dir=in | app=system |
"{D512CF29-E5D0-4255-A60B-0A0F1E0CC061}" = lport=138 | protocol=17 | dir=in | app=system |
"{D6B2246F-79A7-4B46-A6A0-CD50C4964EA9}" = rport=137 | protocol=17 | dir=out | app=system |
"{DC4277CF-E4CA-4F95-9366-D1D5876028A0}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03F8726E-529F-4033-94A3-0C2CCA8673FE}" = protocol=6 | dir=in | app=c:\users\eldest\appdata\roaming\spotify\spotify.exe |
"{07F8C1EE-046D-4EEB-BFFC-3C9F04F6F4A7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{09025085-82A3-4D02-9B15-62A738930E25}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\mjobring\source sdk base 2007\hl2.exe |
"{09A905AF-D494-4FD2-949F-DF3745ECB398}" = protocol=17 | dir=in | app=c:\program files (x86)\funcom\the secret world\clientpatcher.exe |
"{09D6355A-E215-4772-B7C9-C029E00F6A12}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{0A7BC0F1-1452-4935-BBA7-23074E2EED08}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe |
"{0B62784C-E828-446F-9435-B2298DA53485}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\the secret of monkey island special edition\mise.exe |
"{0B8E0048-7C88-420C-A0A9-5BA17D62CE6B}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\sanctum\binaries\win32\sanctumgame-win32-shipping.exe |
"{0BE6C23F-229C-4948-AA3F-E7114718880B}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{15DD06F1-5A1E-4406-A34E-1745FDB7A0DF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{1777A9BB-77AB-4D13-9B98-60B1AFA7627E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{19BBF51A-A6ED-436E-B476-20ADBFCA7EA8}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\dota 2 beta\dota.exe |
"{19D31908-5843-41B3-AF6F-B6EE0E72A8CC}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe |
"{1EAB2A1E-B2DC-4A2D-B256-6E3EEF0DEBFD}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\max payne 3\max payne 3\maxpayne3.exe |
"{1EFE00F0-960A-44DE-9B2C-05B1B165F8C8}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{226D41AC-C872-4071-A043-053C8367141D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{22797BF9-1181-4B7F-B7F4-B0975A9B3573}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{26472A85-AF45-4DF0-A6F5-03D4A0A89A09}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2D10CE8E-F957-4092-B28F-C0A6BAE681F1}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\alan wake\alanwake.exe |
"{303D5478-4D69-4561-8774-9C400DDC0259}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\monopoly\monopolywin.exe |
"{313EB6DE-B7F6-4C41-9EA7-AA2BD3E2244A}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\dead space\dead space.exe |
"{33B682AF-3D3A-4751-B3C5-55A259F2CBF6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{344C3A02-2C73-417C-BBCF-5E87362FE115}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\dead space\dead space.exe |
"{3774594D-5087-4C99-BD37-89F44CABCF0B}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\max payne 3\max payne 3\maxpayne3.exe |
"{38F764BE-E1CF-42B3-9B4C-D6D8AD500F51}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{3E0F1BBB-7EA7-46D0-9BF8-A33A46607CD5}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{41DB932E-27EC-4BF7-90A8-FAEABC87C191}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{42A95BD5-8600-49BF-BED1-4E6A8BE38919}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{434CA5DC-4C02-4AFE-BED5-B40D018E870D}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{440CCDF1-7950-4453-97D0-9EBBF43CDCF7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{44238377-E41B-4853-B522-4164EBC98D14}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{447698FF-53C0-4D51-ADC9-8A8BD0B84BA1}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\sid meier's civilization v sdk\sid meier's civilization v sdk.exe |
"{47B65E3F-4707-455F-A2C6-6BB9A080179E}" = protocol=58 | dir=in | app=system |
"{4B236264-3055-46BC-9720-8DFFA0163CC7}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\sid meier's civilization v sdk\sid meier's civilization v sdk.exe |
"{4C26DCD7-00DE-42D3-A10A-E3B14006CEE5}" = protocol=6 | dir=in | app=d:\install\starcraft ii\starcraft ii public test.exe |
"{4CDB870D-AB02-4F4B-B4F1-98B59F83F4E8}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\counter-strike global offensive\csgo.exe |
"{50EED348-70EE-4994-9D7B-DCD3AEDD60D9}" = protocol=6 | dir=in | app=c:\users\eldest\appdata\roaming\utorrent\utorrent.exe |
"{517EDF5B-A595-46E0-8697-51CDDCA1F67E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5446DF75-8060-4D5A-A96D-07D2C9B4B5B8}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\sanctum\binaries\win32\sanctumgame-win32-shipping.exe |
"{55AC366B-576D-472D-9803-BCB86B3F15EB}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5744FFDB-F440-4402-B3DA-C99D95943ADE}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\dota 2 beta\dota.exe |
"{57A00B79-F315-4DAA-9339-10F031AC4033}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{57A60E11-A654-4F5C-9047-53FA4ACB1CB7}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\counter-strike global offensive\csgo.exe |
"{5AA5A4E8-E0AA-44B8-9BEE-BABD5C0D27ED}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\dark souls prepare to die edition\data\darksouls.exe |
"{5AB5F142-659A-4867-9A43-8AD207C166C7}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{5DB29C8C-11F1-44BF-A83E-C5C2077FD316}" = protocol=17 | dir=in | app=c:\users\eldest\appdata\roaming\spotify\spotify.exe |
"{60C0F212-E138-4812-A9A0-ED0EF018EE70}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\magicka\magicka.exe |
"{62C85573-C77A-43B8-8A5B-70C5DF3B3663}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\hitman absolution\hma.exe |
"{6A168711-4543-4E58-BF5A-F3DD3E7313CB}" = protocol=6 | dir=in | app=d:\install\starcraft ii\starcraft ii.exe |
"{6B8A66E5-BED1-4E9B-9A10-9EA9258D5A2F}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{6CA10663-5539-4818-86AC-B15BE07B0C33}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\counter-strike global offensive\csgo.exe |
"{6E008FAD-0E9E-4D26-B5D8-885388ACE3B1}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\dota 2 beta\dota.exe |
"{75CB89F8-D9BF-4081-B150-2E33539DD794}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\the walking dead\walkingdead101.exe |
"{7AE349DB-C373-437F-9788-FC51892AF7B9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{7C155072-0A44-42A1-BDF8-127D5ADA46E4}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\alan wake\alanwake.exe |
"{812B4E23-D0F5-4867-BA51-AC606F7FBA7E}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\resident evil 5\launcher.exe |
"{813CD0B9-7BC6-4A4F-9C56-FED0F8C605C7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{814937AA-3167-4314-B206-23AF5454113A}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\counter-strike global offensive\csgo.exe |
"{85D7CDBD-78F6-4565-AE63-A3800FAB5389}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\the walking dead\walkingdead101.exe |
"{871912DF-6A33-42B5-A614-DE3DFBA235FE}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\sid meier's civilization iv\civilization4.exe |
"{8B23152E-9320-42B8-94DD-C2B93BA1358E}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{8C138597-35C5-4639-9A4E-31FCC62FDE6F}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{8E128C76-9DCE-4A74-AA6E-4D909714E098}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\specops_theline\binaries\win32\specopstheline.exe |
"{8F2147D0-E9BF-492B-8232-1209E499DDE6}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\dragon age ultimate edition\daoriginslauncher.exe |
"{8FF44261-9D2D-4C62-9897-E0F7B76EEE61}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{910C63FE-5A99-47B6-9E09-BB755502DA7E}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |
"{92225062-DB89-4546-AB68-3FC8C2CBE5C1}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe |
"{9763F68B-EC67-47BB-85BD-1E6A35282CC4}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{9B286585-D38C-4A5D-846B-4ADDA264ADE9}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii 2012 beta\starcraft ii beta.exe |
"{9C5B007F-5059-4F79-B4CD-7DDD48E53F1C}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\alice madness returns\binaries\win32\alicemadnessreturns.exe |
"{9DB9580B-89FE-451D-95A4-857FC5C040F6}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{9F10445F-4E31-4264-923F-CC883E2F2DF8}" = protocol=17 | dir=in | app=d:\install\starcraft ii\versions\base23260\sc2.exe |
"{9FB6D252-F967-48D1-8FFB-4BAC8AF229B8}" = protocol=17 | dir=in | app=c:\users\eldest\appdata\roaming\utorrent\utorrent.exe |
"{A45FAAA8-0FDD-4152-9231-BE041460B250}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\max payne 3\max payne 3\maxpayne3.exe |
"{A8E34CDE-9F05-4124-AB60-3445684371B7}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{A8ED0812-DA14-4A34-9794-B268B1FB9803}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{A8F4E2A2-1EA9-406F-98CE-E513E611A699}" = protocol=17 | dir=in | app=d:\install\starcraft ii\starcraft ii.exe |
"{A9BE02EB-7447-4D8F-93BC-A004CB3B8BE7}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{AF22149E-F869-4EB5-94CC-07113C388EA2}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\max payne 3\max payne 3\maxpayne3.exe |
"{AF6CB4EB-9CCB-416D-8413-73BDF8140FE9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |
"{B46330B1-F1F2-46E1-B7F0-74BD8D7F2E4D}" = protocol=6 | dir=out | app=system |
"{B5A3994E-3813-4273-97BD-850E795CDA7A}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\hitman absolution\hma.exe |
"{B6728245-FEF9-44A6-80AC-89F60CEE44AF}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{BC1F354F-FD8C-49C2-8F99-93212CA8898A}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{BD776000-4634-443D-A81B-3C6B79651410}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\universe sandbox\universe sandbox.exe |
"{C9D1C0CE-5269-45CF-BBD6-D1A2670A23C1}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe |
"{CB210099-B5CA-4BE1-9CA3-1C0ADF7EABA9}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\sid meier's civilization v\launcher.exe |
"{CEFCEA7A-4802-4EB4-A8C5-D0C593907726}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\the secret of monkey island special edition\mise.exe |
"{CF79FF0B-14EF-45C3-8767-383BE22F7F6E}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\specops_theline\binaries\win32\specopstheline.exe |
"{D30C3FEE-6623-4053-A96A-DA59F9FE658B}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{D6EE28DA-A7DB-46EF-99EA-65746D19B3D9}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\sid meier's civilization iv\civilization4.exe |
"{D7DA0467-7130-4EDB-98CE-1FF0315520FC}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\sid meier's civilization v\launcher.exe |
"{D88765CB-CD6F-4B26-9D20-03484D87BB67}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\universe sandbox\universe sandbox.exe |
"{D90B9F3A-AE39-4C17-8BC8-3385B4F7DEF7}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\resident evil 5\launcher.exe |
"{DA4114C4-87F9-4A50-AFF6-F2E02741D7E0}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii 2012 beta\starcraft ii beta.exe |
"{DC74AB64-857E-46D2-9B16-1B4D32154769}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{DD43A918-F134-4346-9DB0-DCD8F835EE71}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{DDA9C5D3-8499-4B35-8C34-1A90A80B1E80}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{DEACE87F-EACA-44CB-88BD-3B5EB2F75CE7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E1CEBE25-BABF-432F-AD1D-86372D8133E7}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\dragon age ultimate edition\daoriginslauncher.exe |
"{E6641834-AE7B-48A0-9119-642871F7E188}" = protocol=17 | dir=in | app=c:\users\eldest\appdata\roaming\spotify\spotify.exe |
"{E6D9109B-4989-42C2-97FB-FB1FE77B48C5}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\mjobring\source sdk base 2007\hl2.exe |
"{E91D5FC8-4E7E-4471-BCF1-0A41C3DF854F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{E92D3E1D-0C37-4CEF-8F2B-949AAF3C037A}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{EA46D32D-3819-41F0-BB63-DEC56CA1C3EE}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\alice madness returns\binaries\win32\alicemadnessreturns.exe |
"{EB845F56-C09E-4D86-B0D9-6B87A4594FB0}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{ED297CBF-0EC4-4337-BB1B-A50041B8C4EA}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{EE0AC697-5825-4F4E-B010-45E43847CB0C}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{EFFECEC0-9388-4742-8409-DAA39E609190}" = protocol=6 | dir=in | app=c:\program files (x86)\funcom\the secret world\clientpatcher.exe |
"{F1CD8B97-CE6D-4699-8029-2EB067575C07}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{F2596C4D-8357-43EB-9908-1AA67B1C4F96}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\dark souls prepare to die edition\data\darksouls.exe |
"{F2E38F4B-689F-4A1E-9210-AAF108A26202}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{F3BD0B95-7E8E-4B61-BC8A-8BDF32CEED2C}" = protocol=6 | dir=in | app=d:\install\starcraft ii\versions\base23260\sc2.exe |
"{F676A75D-FF9F-49E3-B982-3CCBF482152D}" = protocol=6 | dir=in | app=c:\users\eldest\appdata\roaming\spotify\spotify.exe |
"{F6ACCAE2-13AF-4E5F-A8C2-C1EDA6656C70}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\magicka\magicka.exe |
"{F98B133B-EBBD-4BE2-A44D-BAE42DE5F1EE}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |
"{F9FBBAF2-9328-4606-A64B-094F088A5F5C}" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\dota 2 beta\dota.exe |
"{FBB1C393-DA70-48E3-91A5-B62329D2077B}" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\monopoly\monopolywin.exe |
"{FBB5197C-2CFA-487E-BF7A-AE31383AD878}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{FE3D5463-ED0B-47C3-8E03-DC7CCDECE2AE}" = protocol=17 | dir=in | app=d:\install\starcraft ii\starcraft ii public test.exe |
"TCP Query User{05880F0A-5DB6-48BC-B3D2-17C06F5CDE15}D:\install\steam\steamapps\mjobring\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=d:\install\steam\steamapps\mjobring\counter-strike source\hl2.exe |
"TCP Query User{21574CCE-D500-4478-BF8B-79A4D76664FD}D:\install\warcraft iii\war3.exe" = protocol=6 | dir=in | app=d:\install\warcraft iii\war3.exe |
"TCP Query User{422F8668-9394-4779-A7F5-C7B971F220FB}D:\install\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=6 | dir=in | app=d:\install\steam\steamapps\common\resident evil 5\re5dx10.exe |
"TCP Query User{6B50F7B3-04C9-458B-BA94-A4EF3C4644CC}D:\install\steam\steam.exe" = protocol=6 | dir=in | app=d:\install\steam\steam.exe |
"TCP Query User{9267212E-63D2-4221-8416-6471E9C51577}D:\install\steam\steamapps\mjobring\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=d:\install\steam\steamapps\mjobring\team fortress 2\hl2.exe |
"UDP Query User{B08BB265-95FA-4EAD-A464-868607023223}D:\install\steam\steamapps\mjobring\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=d:\install\steam\steamapps\mjobring\team fortress 2\hl2.exe |
"UDP Query User{B4783E12-21E4-41C7-9A6C-881DACC09FD1}D:\install\warcraft iii\war3.exe" = protocol=17 | dir=in | app=d:\install\warcraft iii\war3.exe |
"UDP Query User{BCC3437B-B654-4889-B472-72C125F4BFFD}D:\install\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=17 | dir=in | app=d:\install\steam\steamapps\common\resident evil 5\re5dx10.exe |
"UDP Query User{D9182221-B7FD-48CA-BD14-103658310335}D:\install\steam\steamapps\mjobring\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=d:\install\steam\steamapps\mjobring\counter-strike source\hl2.exe |
"UDP Query User{F95A8C0D-EF5B-4EAF-905A-9B3BACE45F46}D:\install\steam\steam.exe" = protocol=17 | dir=in | app=d:\install\steam\steam.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0225AD21-F3E2-4916-BFF3-65D3F9052582}" = iTunes
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support
"{330DAC67-5B62-452A-A0E4-6B4A5923940F}_is1" = MotioninJoy DS3 driver version 0.6.0005
"{4975DE61-6BF6-B9BC-1FDE-C04C5EC78E4C}" = AMD Media Foundation Decoders
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{538B98C3-773F-4F20-9C66-802D104DCBE2}" = Intel® Trusted Connect Service Client
"{5E03A267-415E-5383-FA8F-3CE4145663B9}" = AMD Catalyst Install Manager
"{6438A99C-A37E-4758-A0AE-95F8A63AAFF5}" = Intel(R) Network Connections 16.8.46.0
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{89EE4A30-080F-2C95-6F78-C98D18FBD74D}" = AMD Accelerated Video Transcoding
"{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0015-041D-1000-0000000FF1CE}" = Microsoft Office Access MUI (Swedish) 2010
"{90140000-0015-041D-1000-0000000FF1CE}_Office14.PROPLUS_{8CD9D6D6-B232-48F6-9C47-F4D8449C5BC2}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-041D-1000-0000000FF1CE}" = Microsoft Office Excel MUI (Swedish) 2010
"{90140000-0016-041D-1000-0000000FF1CE}_Office14.PROPLUS_{8CD9D6D6-B232-48F6-9C47-F4D8449C5BC2}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-041D-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Swedish) 2010
"{90140000-0018-041D-1000-0000000FF1CE}_Office14.PROPLUS_{8CD9D6D6-B232-48F6-9C47-F4D8449C5BC2}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-041D-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (Swedish) 2010
"{90140000-0019-041D-1000-0000000FF1CE}_Office14.PROPLUS_{8CD9D6D6-B232-48F6-9C47-F4D8449C5BC2}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-041D-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (Swedish) 2010
"{90140000-001A-041D-1000-0000000FF1CE}_Office14.PROPLUS_{8CD9D6D6-B232-48F6-9C47-F4D8449C5BC2}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-041D-1000-0000000FF1CE}" = Microsoft Office Word MUI (Swedish) 2010
"{90140000-001B-041D-1000-0000000FF1CE}_Office14.PROPLUS_{8CD9D6D6-B232-48F6-9C47-F4D8449C5BC2}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0407-1000-0000000FF1CE}" = Microsoft Office Proof (German) 2010
"{90140000-001F-0407-1000-0000000FF1CE}_Office14.PROPLUS_{70A3169E-288F-454F-A08D-20DF66639B50}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUS_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040B-1000-0000000FF1CE}" = Microsoft Office Proof (Finnish) 2010
"{90140000-001F-040B-1000-0000000FF1CE}_Office14.PROPLUS_{57652F4A-E8F7-4FE2-8FA9-97731AD0D184}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-041D-1000-0000000FF1CE}" = Microsoft Office Proof (Swedish) 2010
"{90140000-001F-041D-1000-0000000FF1CE}_Office14.PROPLUS_{735E1B03-44E8-4D55-A553-EA9E32C96F7C}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-041D-1000-0000000FF1CE}" = Microsoft Office Proofing (Swedish) 2010
"{90140000-002C-041D-1000-0000000FF1CE}_Office14.PROPLUS_{4209FECD-F119-4FE0-AAA6-8F8F9030C2B1}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-041D-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (Swedish) 2010
"{90140000-0043-041D-1000-0000000FF1CE}_Office14.PROPLUS_{6BF8BD7F-2425-4780-B9FC-004FD721BA74}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-041D-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Swedish) 2010
"{90140000-0044-041D-1000-0000000FF1CE}_Office14.PROPLUS_{8CD9D6D6-B232-48F6-9C47-F4D8449C5BC2}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-041D-1000-0000000FF1CE}" = Microsoft Office Shared MUI (Swedish) 2010
"{90140000-006E-041D-1000-0000000FF1CE}_Office14.PROPLUS_{8DE9F23B-C17D-465F-B0C2-B83CAEE0998D}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-041D-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (Swedish) 2010
"{90140000-00A1-041D-1000-0000000FF1CE}_Office14.PROPLUS_{8CD9D6D6-B232-48F6-9C47-F4D8449C5BC2}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-041D-1000-0000000FF1CE}" = Microsoft Office Groove MUI (Swedish) 2010
"{90140000-00BA-041D-1000-0000000FF1CE}_Office14.PROPLUS_{8CD9D6D6-B232-48F6-9C47-F4D8449C5BC2}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9CF11D16-ECEB-90A5-A028-CA9E068D848B}" = ccc-utility64
"{D954C6C2-544B-4091-A47F-11E77162883E}" = Microsoft Security Client
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{F55458B0-DCA9-38C9-6C8D-829F22463A55}" = AMD Drag and Drop Transcoding
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.20
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"PROSetDX" = Intel(R) Network Connections 16.8.46.0
"WinRAR archiver" = WinRAR 4.20 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{009E5DF2-3F97-480B-89DA-F2D5E672E14A}_is1" = Live Update 5
"{017F8447-2A1D-0DDB-B5D7-CA2BFACE2886}" = CCC Help French
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{054E9A1C-3EA2-C657-E787-FD8DCF5C3D3B}" = CCC Help Czech
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{1DE2BD51-0300-772D-5E18-F337D95D5687}" = CCC Help German
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{220C7F8C-929D-4F71-9DC7-F7A6823B38E4}" = Windows Live UX Platform Language Pack
"{224E8FEB-5C1F-077F-6FC5-602AC1AE644D}" = CCC Help Danish
"{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel(R) USB 3.0 eXtensible Host Controller Driver
"{275E9C49-C72F-D754-DEB7-77F10A9C00D8}" = CCC Help Japanese
"{28B9D2D8-4304-483F-AD71-51890A063A74}" = Windows Live Photo Common
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{30049739-BE95-6591-B504-E6D7057D49CC}" = CCC Help Spanish
"{3F1EB155-F96E-EB7B-2EF2-7375490E0FA9}" = CCC Help English
"{45C56AA7-ED1B-4800-A97F-EDDF3F3520B1}" = Apple-programstöd
"{4A04DB63-8F81-4EF4-9D09-61A2057EF419}" = Windows Live Essentials
"{4B023D7B-9E67-795D-FB31-B5E1F6DCA451}" = CCC Help Italian
"{4CF63D66-56F0-0224-6C62-FBCB4C68578C}" = Application Profiles
"{4D243BA7-9AC4-46D1-90E5-EEB88974F501}" = Microsoft Games for Windows - LIVE
"{55F6C486-8C75-2A72-DAFE-CE78A624C9F7}" = CCC Help Russian
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5AF23993-7152-1620-E43F-1B4542FB4F84}" = CCC Help Thai
"{61942EF5-2CD8-47D4-869C-2E9A8BB085F1}" = Asmedia ASM106x SATA Host Controller Driver
"{63326924-3CAF-C858-3A8F-8598C87019D7}" = Catalyst Control Center
"{63822E89-11AA-F8EC-D433-F72A85799EC0}" = CCC Help Greek
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{66361420-4905-AEB8-17AE-172FDD164A7E}" = CCC Help Polish
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A67578E-095B-4661-88F7-0B199CEC3371}" = Windows Live Messenger
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{769F2A4B-84A3-9486-ADD2-9E5AB4B4E1E3}" = Catalyst Control Center InstallProxy
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{81CF5153-38CF-41e2-AC3C-3D477C987D96}_is1" = Winki
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{8773DD1C-5FB2-95B5-5A93-0EFEAC900A4D}" = CCC Help Norwegian
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8CCBB0BF-9CC1-1A65-BB93-56012A460EE6}" = CCC Help Portuguese
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{929E7499-4B50-4C7A-8F15-D21E4061E046}" = BankID säkerhetsprogram
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A0A3CE05-96CB-52E9-434E-074F3BB7807E}" = CCC Help Turkish
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{A9C64319-932F-D02B-B14C-FFFC3EC49E77}" = CCC Help Chinese Standard
"{AC76BA86-7AD7-1053-7B44-AA1000000001}" = Adobe Reader X (10.1.6) - Svenska
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B05F7750-8800-4520-9732-9C841246C8E2}_is1" = OTPService
"{C09DB932-7619-7B56-30E3-C0454811D6D7}" = CCC Help Korean
"{C22A4697-BD77-ACB1-744F-1FD0A0BFF798}" = CCC Help Swedish
"{C35BBC64-E7B7-B699-E5D8-CE5989061F93}" = HydraVision
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D4B457B2-260F-C561-CA87-703BD3B724CA}" = Catalyst Control Center Graphics Previews Common
"{D6CDB506-297D-AE70-0EF6-DE5185F961BE}" = CCC Help Chinese Traditional
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{ECFD508E-68A2-91B2-46DD-1D03D783D94B}" = Catalyst Control Center Localization All
"{EDE361D5-35A5-DA7D-3462-C3DABD24029B}" = CCC Help Hungarian
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1E7DD6A-AE2D-D706-BEB3-937F76CA6AE9}" = CCC Help Finnish
"{F56F54DD-BCB2-1221-2CB7-E983A5CF9D15}" = CCC Help Dutch
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AudioGenie_is1" = AudioGenie
"Google Chrome" = Google Chrome
"hon" = Heroes of Newerth
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Mozilla Firefox 19.0 (x86 sv-SE)" = Mozilla Firefox 19.0 (x86 sv-SE)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Rockstar Games Social Club" = Rockstar Games Social Club
"StarCraft II" = StarCraft II
"StarCraft II Beta" = StarCraft II Beta
"Steam App 108710" = Alan Wake
"Steam App 12220" = Grand Theft Auto: Episodes from Liberty City
"Steam App 16830" = Sid Meier's Civilization V SDK
"Steam App 17470" = Dead Space
"Steam App 19680" = Alice: Madness Returns
"Steam App 203140" = Hitman: Absolution
"Steam App 204100" = Max Payne 3
"Steam App 207610" = The Walking Dead
"Steam App 211420" = Dark Souls: Prepare to Die Edition
"Steam App 21690" = Resident Evil 5
"Steam App 218" = Source SDK Base 2007
"Steam App 221300" = Monopoly
"Steam App 240" = Counter-Strike: Source
"Steam App 32360" = The Secret of Monkey Island: Special Edition
"Steam App 3900" = Sid Meier's Civilization IV
"Steam App 42910" = Magicka
"Steam App 440" = Team Fortress 2
"Steam App 47810" = Dragon Age: Origins - Ultimate Edition
"Steam App 50300" = Spec Ops: The Line
"Steam App 550" = Left 4 Dead 2
"Steam App 570" = Dota 2
"Steam App 72200" = Universe Sandbox
"Steam App 730" = Counter-Strike: Global Offensive
"Steam App 8930" = Sid Meier's Civilization V
"Steam App 91600" = Sanctum
"The Secret World_is1" = The Secret World
"uTorrent" = µTorrent
"WinLiveSuite" = Windows Live Essentials
"VLC media player" = VLC media player 2.0.5
"World of Warcraft" = World of Warcraft

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-178671379-1301378200-1053161076-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Spotify" = Spotify
"UnityWebPlayer" = Unity Web Player

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 2013-02-20 09:48:28 | Computer Name = Normandy | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\ESET\ESET
Online Scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 2013-02-23 19:56:43 | Computer Name = Normandy | Source = Application Hang | ID = 1002
Description = The program Explorer.EXE version 6.1.7601.17567 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 620 Start
Time: 01ce1201a3173f97 Termination Time: 10 Application Path: C:\Windows\Explorer.EXE

Report
Id: a34908fe-7e14-11e2-8804-8c89a5c15538

Error - 2013-02-23 19:57:30 | Computer Name = Normandy | Source = Application Hang | ID = 1002
Description = The program explorer.exe version 6.1.7601.17567 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 13f4 Start
Time: 01ce12216e7d5bac Termination Time: 0 Application Path: C:\Windows\explorer.exe

Report
Id:

Error - 2013-02-25 09:14:07 | Computer Name = Normandy | Source = Application Error | ID = 1000
Description = Faulting application name: MsMpEng.exe, version: 4.2.223.0, time stamp:
0x51023a8b Faulting module name: mpengine.dll, version: 1.1.9203.0, time stamp:
0x51144572 Exception code: 0xc0000005 Fault offset: 0x0000000000040f17 Faulting process
id: 0x390 Faulting application start time: 0x01ce12eb44b881c3 Faulting application
path: C:\Program Files\Microsoft Security Client\MsMpEng.exe Faulting module path:
C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{52903337-BB9F-4018-964E-1A201A7771D6}\mpengine.dll
Report
Id: 3bde1cf1-7f4d-11e2-962d-8c89a5c15538

[ System Events ]
Error - 2013-02-22 18:34:13 | Computer Name = Normandy | Source = Service Control Manager | ID = 7032
Description = The Service Control Manager tried to take a corrective action (Restart
the service) after the unexpected termination of the Apple Mobile Device service,
but this action failed with the following error: %%1056

Error - 2013-02-22 18:34:19 | Computer Name = Normandy | Source = Service Control Manager | ID = 7032
Description = The Service Control Manager tried to take a corrective action (Restart
the service) after the unexpected termination of the Apple Mobile Device service,
but this action failed with the following error: %%1056

Error - 2013-02-23 16:08:16 | Computer Name = Normandy | Source = DCOM | ID = 10010
Description =

Error - 2013-02-24 20:01:32 | Computer Name = Normandy | Source = EventLog | ID = 6008
Description = The previous system shutdown at 01:00:43 on ?2013-?02-?25 was unexpected.

Error - 2013-02-24 20:01:33 | Computer Name = Normandy | Source = BugCheck | ID = 1001
Description =

Error - 2013-02-25 09:14:06 | Computer Name = Normandy | Source = Microsoft Antimalware | ID = 5008
Description = %%860 engine has been terminated due to an unexpected error. Failure
Type: %%830 Exception code: 0xc0000005 Resource: file:C:\Users\Eldest\AppData\Local\Google\Chrome\User
Data\Default\JumpListIcons\DC3E.tmp

Error - 2013-02-25 09:14:13 | Computer Name = Normandy | Source = Service Control Manager | ID = 7031
Description = The Microsoft Antimalware Service service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
15000 milliseconds: Restart the service.

Error - 2013-02-25 09:14:28 | Computer Name = Normandy | Source = Service Control Manager | ID = 7032
Description = The Service Control Manager tried to take a corrective action (Restart
the service) after the unexpected termination of the Microsoft Antimalware Service
service, but this action failed with the following error: %%1056

Error - 2013-02-26 12:30:17 | Computer Name = Normandy | Source = EventLog | ID = 6008
Description = The previous system shutdown at 17:28:59 on ?2013-?02-?26 was unexpected.

Error - 2013-02-26 12:30:18 | Computer Name = Normandy | Source = BugCheck | ID = 1001
Description =


< End of report >
Eldest
Regular Member
 
Posts: 26
Joined: February 19th, 2013, 3:50 pm

Re: Every program crashing and getting Blue Screen

Unread postby Eldest » February 26th, 2013, 3:53 pm

The Gmer log was too long for the board to allow it. So I had to post in it sections. But I have posted it all together in this pastebin.


Gmer log part 1:

GMER 2.1.19115 - http://www.gmer.net
3rd party scan 2013-02-26 19:57:34
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 SAMSUNG_SSD_830_Series rev.CXM03B1Q 119,24GB
Running: 5xie9l6l.exe; Driver: C:\Users\Eldest\AppData\Local\Temp\uxliqpoc.sys


---- User code sections - GMER 2.1 ----

.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2244] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076291465 2 bytes [29, 76]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2244] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762914bb 2 bytes [29, 76]
.text ... * 2
.text C:\Program Files (x86)\Personal\bin\Personal.exe[2520] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076291465 2 bytes [29, 76]
.text C:\Program Files (x86)\Personal\bin\Personal.exe[2520] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762914bb 2 bytes [29, 76]
.text ... * 2
.text C:\Program Files (x86)\MSI\Live Update 5\LU5.exe[2876] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076291465 2 bytes [29, 76]
.text C:\Program Files (x86)\MSI\Live Update 5\LU5.exe[2876] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762914bb 2 bytes [29, 76]
.text ... * 2

---- Registry - GMER 2.1 ----

Reg HKLM\SYSTEM\CurrentControlSet\Enum\USB\VID_05AC&PID_1292&MI_00\0\Device Parameters@Icons C:\Windows\system32\usbaaplrc.dll (Apple Mobile Device USB Driver Resource DLL/Apple, Inc. SIGNED)(2012-09-28 09:32:56)
Reg HKLM\SYSTEM\CurrentControlSet\services\AdobeARMservice@ImagePath C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Acrobat Update Service/Adobe Systems Incorporated SIGNED)(2012-12-18 14:28:08)
Reg HKLM\SYSTEM\CurrentControlSet\services\AdobeFlashPlayerUpdateSvc@ImagePath C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe® Flash® Player Update Service 11.6 r602/Adobe Systems Incorporated SIGNED)(2012-09-27 10:12:43)
Reg HKLM\SYSTEM\CurrentControlSet\services\Apple Mobile Device@ImagePath C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (MobileDeviceService/Apple Inc. SIGNED)(2012-12-21 15:27:46)
Reg HKLM\SYSTEM\CurrentControlSet\services\Bonjour Service@ImagePath C:\Program Files\Bonjour\mDNSResponder.exe (Bonjour Service/Apple Inc. SIGNED)(2011-08-30 21:05:32)
Reg HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application\Intel(R) ME Application@CategoryMessageFile C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (User Notification Service/Intel Corporation SIGNED)(2012-09-17 17:58:45)
Reg HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application\IntelDalJhi@EventMessageFile C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel(R) Dynamic Application Loader Host Interface/Intel Corporation SIGNED)(2012-09-17 17:59:08)
Reg HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application\LMS@EventMessageFile C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Local Manageability Service/Intel Corporation SIGNED)(2012-09-17 17:58:29)
Reg HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application\Personal@CategoryMessageFile C:\Program Files (x86)\Personal\bin\Personal.exe (Nexus Personal/Technology Nexus AB SIGNED)(2012-11-15 12:11:48)
Reg HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application\SkypeUpdate@EventMessageFile C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Updater Service/Skype Technologies SIGNED)(2012-07-13 11:28:36)
Reg HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application\Spotify@EventMessageFile C:\Users\Eldest\AppData\Roaming\Spotify\spotify.exe (Spotify/Spotify Ltd SIGNED)(2012-09-18 10:12:56)
Reg HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application\Steam Client Service@EventMessageFile C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Steam Client Service (buildbot_winslave04_steam_steam_rel_client_hotfix_win32@winslave04)/Valve Corporation SIGNED)(2012-09-18 09:12:44)
Reg HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application\UNS@CategoryMessageFile C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (User Notification Service/Intel Corporation SIGNED)(2012-09-17 17:58:45)
Reg HKLM\SYSTEM\CurrentControlSet\services\eventlog\Application\XLive@EventMessageFile C:\Windows\SysWOW64\xlive.dll (Games for Windows - LIVE DLL/Microsoft Corporation SIGNED)(2011-09-28 16:45:42)
Reg HKLM\SYSTEM\CurrentControlSet\services\eventlog\System\Microsoft-Windows-Service Pack Installer@EventMessageFile C:\Windows\system32\EventProviders\spcmsg.dll (SP Installer Msg Dll/Microsoft Corporation)(2012-09-20 09:43:27)
Reg HKLM\SYSTEM\CurrentControlSet\services\gupdate@ImagePath C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Installer/Google Inc. SIGNED)(2013-02-22 00:53:22)
Reg HKLM\SYSTEM\CurrentControlSet\services\Intel(R) Capability Licensing Service Interface@ImagePath C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel(R) Capability Licensing Service Interface/Intel(R) Corporation SIGNED)(2012-01-10 19:01:52)
Reg HKLM\SYSTEM\CurrentControlSet\services\Intel(R) PROSet Monitoring Service@ImagePath C:\Windows\system32\IProsetMonitor.exe (Intel® PROSet Monitoring Service/Intel Corporation SIGNED)(2012-09-17 17:57:27)
Reg HKLM\SYSTEM\CurrentControlSet\services\iPod Service@ImagePath C:\Program Files\iPod\bin\iPodService.exe (iPodService Module (64-bit)/Apple Inc. SIGNED)(2013-02-20 11:35:32)
Reg HKLM\SYSTEM\CurrentControlSet\services\jhi_service@ImagePath C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel(R) Dynamic Application Loader Host Interface/Intel Corporation SIGNED)(2012-09-17 17:59:08)
Reg HKLM\SYSTEM\CurrentControlSet\services\LMS@ImagePath C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Local Manageability Service/Intel Corporation SIGNED)(2012-09-17 17:58:29)
Reg HKLM\SYSTEM\CurrentControlSet\services\MotioninJoyXFilter@ImagePath C:\Windows\system32\DRIVERS\MijXfilt.sys (MotioninJoy DS3 driver/MotioninJoy SIGNED)(2013-02-17 17:19:52)
Reg HKLM\SYSTEM\CurrentControlSet\services\MozillaMaintenance@ImagePath C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation SIGNED)(2012-09-25 13:55:22)
Reg HKLM\SYSTEM\CurrentControlSet\services\MSI_MSIBIOS_010507@ImagePath C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys (Description string for Msibios driver/Your Corporation SIGNED)(2012-09-18 08:49:00)
Reg HKLM\SYSTEM\CurrentControlSet\services\MSI_OTPService@ImagePath C:\Program Files (x86)\MSI\OTPService\OTPService.exe(2012-09-17 17:58:19)
Reg HKLM\SYSTEM\CurrentControlSet\services\NTIOLib_1_0_4@ImagePath C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys (NTIOLib/MSI SIGNED)(2012-09-18 08:49:00)
Reg HKLM\SYSTEM\CurrentControlSet\services\NTIOLib_1_0_T@ImagePath C:\Program Files (x86)\MSI\OTPService\NTIOLib_X64.sys (NTIOLib/MSI SIGNED)(2012-09-17 17:58:19)
Reg HKLM\SYSTEM\CurrentControlSet\services\SkypeUpdate@ImagePath C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Updater Service/Skype Technologies SIGNED)(2012-07-13 11:28:36)
Reg HKLM\SYSTEM\CurrentControlSet\services\Steam Client Service@ImagePath C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Steam Client Service (buildbot_winslave04_steam_steam_rel_client_hotfix_win32@winslave04)/Valve Corporation SIGNED)(2012-09-18 09:12:44)
Reg HKLM\SYSTEM\CurrentControlSet\services\UNS@ImagePath C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (User Notification Service/Intel Corporation SIGNED)(2012-09-17 17:58:45)
Reg HKLM\SYSTEM\CurrentControlSet\services\USBAAPL64@ImagePath C:\Windows\System32\Drivers\usbaapl64.sys (Apple Mobile Device USB Driver/Apple, Inc.)(2012-09-28 09:32:56)
Reg HKLM\SYSTEM\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000005@LibraryPath C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Bonjour Namespace Provider/Apple Inc. SIGNED)(2011-08-30 21:05:02)
Reg HKLM\SYSTEM\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005@LibraryPath C:\Program Files\Bonjour\mdnsNSP.dll (Bonjour Namespace Provider/Apple Inc. SIGNED)(2011-08-30 21:05:32)
Reg HKLM\SYSTEM\CurrentControlSet\services\xusb21@ImagePath C:\Windows\system32\DRIVERS\xusb21.sys (Windows Common Controller/Microsoft Corporation SIGNED)(2013-02-17 17:19:52)
Reg HKLM\SOFTWARE\Microsoft\HTMLHelp\2.0\LocalReg\CLSID\{0A9007AA-4076-11D3-8789-0000F8105754}\InprocServer32@ C:\Program Files\Common Files\Microsoft Shared\Help\msitss55.dll (Microsoft® InfoTech Storage System Library/Microsoft Corporation)(2008-05-23 12:03:06)
Reg HKLM\SOFTWARE\Microsoft\HTMLHelp\2.0\LocalReg\CLSID\{314111a0-a502-11d2-bbca-00c04f8ec294}\InprocServer32@ C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft® Help Data Services Module/Microsoft Corporation)(2008-05-23 12:03:06)
Reg HKLM\SOFTWARE\Microsoft\HTMLHelp\2.0\LocalReg\CLSID\{3E6C7FFD-743D-4265-8E3D-0D7EA889DFDB}\InprocServer32@ C:\Program Files\Common Files\Microsoft Shared\Help\ITIRCL55.DLL (Microsoft® InfoTech IR Local DLL/Microsoft Corporation)(2008-05-23 12:03:00)
Reg HKLM\SOFTWARE\Classes\acrobat\shell\open\command@ C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe (Adobe Reader /Adobe Systems Incorporated SIGNED)(2013-02-15 22:31:18)
Reg HKLM\SOFTWARE\Classes\Applications\csgo.exe\shell\open\command@ d:\install\steam\steamapps\common\counter-strike global offensive\csgo.exe(2012-11-04 23:34:19)
Reg HKLM\SOFTWARE\Classes\Applications\dota.exe\shell\open\command@ d:\install\steam\steamapps\common\dota 2 beta\dota.exe(2012-11-04 23:05:33)
Reg HKLM\SOFTWARE\Classes\Applications\iTunes.exe\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\Applications\left4dead2.exe\shell\open\command@ d:\install\steam\steamapps\common\left 4 dead 2\left4dead2.exe(2012-11-04 23:06:48)
Reg HKLM\SOFTWARE\Classes\Applications\SC2Editor.exe\shell\open\command@ C:\Program Files (x86)\StarCraft II 2012 Beta\Support\SC2Editor.exe (StarCraft II Editor/Blizzard Entertainment, Inc. SIGNED)(2013-02-06 23:23:17)
Reg HKLM\SOFTWARE\Classes\Applications\SC2Switcher.exe\shell\open\command@ C:\Program Files (x86)\StarCraft II 2012 Beta\Support\SC2Switcher.exe (StarCraft II/Blizzard Entertainment, Inc. SIGNED)(2013-02-06 23:23:17)
Reg HKLM\SOFTWARE\Classes\Applications\vlc.exe\shell\Open\command@ C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (VLC media player 2.0.5/VideoLAN)(2012-12-13 00:12:58)
Reg HKLM\SOFTWARE\Classes\AudioCD\shell\play\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\AudioCD\shell\PlayWithVLC\command@ C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (VLC media player 2.0.5/VideoLAN)(2012-12-13 00:12:58)
Reg HKLM\SOFTWARE\Classes\Blizzard.SC2Map\shell\open\command@ C:\Program Files (x86)\StarCraft II 2012 Beta\Support\SC2Editor.exe (StarCraft II Editor/Blizzard Entertainment, Inc. SIGNED)(2013-02-06 23:23:17)
Reg HKLM\SOFTWARE\Classes\Blizzard.SC2Replay\shell\open\command@ C:\Program Files (x86)\StarCraft II 2012 Beta\Support\SC2Switcher.exe (StarCraft II/Blizzard Entertainment, Inc. SIGNED)(2013-02-06 23:23:17)
Reg HKLM\SOFTWARE\Classes\callto\shell\open\command@ C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype /Skype Technologies S.A. SIGNED)(2012-07-13 11:33:24)
Reg HKLM\SOFTWARE\Classes\ChromeHTML\shell\open\command@ C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Chrome/Google Inc. SIGNED)(2013-02-22 00:53:44)
Last edited by Eldest on February 26th, 2013, 3:54 pm, edited 1 time in total.
Eldest
Regular Member
 
Posts: 26
Joined: February 19th, 2013, 3:50 pm

Re: Every program crashing and getting Blue Screen

Unread postby Eldest » February 26th, 2013, 3:53 pm

Gmer log part 2:

Reg HKLM\SOFTWARE\Classes\CLSID\{000D0E00-0000-0000-C000-000000001157}\InprocServer32@ C:\Program Files\Microsoft Office\Office14\VVIEWDWG.DLL (Microsoft Visio Viewer 2010/Microsoft Corporation)(2012-04-26 19:01:22)
Reg HKLM\SOFTWARE\Classes\CLSID\{063D34A4-BF84-4B8D-B699-E8CA06504DDE}\LocalServer32@ C:\Program Files\iPod\bin\iPodService.exe (iPodService Module (64-bit)/Apple Inc. SIGNED)(2013-02-20 11:35:32)
Reg HKLM\SOFTWARE\Classes\CLSID\{0A25C695-3765-4B37-9455-4B1C113C2C04}\InprocServer32@ C:\Program Files\iTunes\iTunesOutlookAddIn.dll (iTunes Outlook Add-in/Apple Inc. SIGNED)(2013-02-20 11:35:32)
Reg HKLM\SOFTWARE\Classes\CLSID\{0E799A91-CDDC-471B-A803-2DB82FAFB726}\InprocServer32@ C:\Program Files\Common Files\ATI Technologies\Multimedia\AMDMFTDecoder_64.dll(2012-12-19 14:40:58)
Reg HKLM\SOFTWARE\Classes\CLSID\{10A2EABA-6B77-4E1A-98C2-598B6299EB6D}\LocalServer32@ C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel(R) Capability Licensing Service Interface/Intel(R) Corporation SIGNED)(2012-01-10 19:01:52)
Reg HKLM\SOFTWARE\Classes\CLSID\{12E6A993-AE52-4F99-8B89-41F985E6C952}\InprocServer32@ C:\Program Files\Common Files\Apple\Mobile Device Support\OutlookChangeNotifierAddIn.dll (OutlookChangeNotifier/Apple Inc. SIGNED)(2012-12-06 11:53:56)
Reg HKLM\SOFTWARE\Classes\CLSID\{17796aeb-0f66-4663-b8fb-99cbee0224ce}\InProcServer32@ C:\Program Files\Common Files\ATI Technologies\Multimedia\AMDhwDecoder_64.dll (Accelerated Dx9 Dx11 Async MFT Video Decoder/Advanced Micro Devices)(2012-12-19 14:41:54)
Reg HKLM\SOFTWARE\Classes\CLSID\{208DD6A3-E12B-4755-9607-2E39EF84CFC5}\InprocServer32@ C:\Program Files\Common Files\Microsoft Shared\TRANSLAT\GEEN\MSB1GEEN.DLL (Microsoft Office Translation Dictionaries/Microsoft Corporation)(2007-11-08 02:05:06)
Reg HKLM\SOFTWARE\Classes\CLSID\{24CD4DE9-FF84-4701-9DC1-9B69E0D1090A}\InprocServer32@ C:\Windows\system32\dnssdX.dll (Bonjour COM Component Library/Apple Inc. SIGNED)(2011-08-30 21:05:32)
Reg HKLM\SOFTWARE\Classes\CLSID\{31411198-a502-11d2-bbca-00c04f8ec294}\InprocServer32@ C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft® Help Data Services Module/Microsoft Corporation)(2008-05-23 12:03:06)
Reg HKLM\SOFTWARE\Classes\CLSID\{368F81BC-9439-41A8-B532-39C8D7E7D147}\LocalServer32@ C:\Program Files\iPod\bin\iPodService.exe (iPodService Module (64-bit)/Apple Inc. SIGNED)(2013-02-20 11:35:32)
Reg HKLM\SOFTWARE\Classes\CLSID\{37A4D802-E76C-11D2-935C-00A024E52661}\InprocServer32@ C:\Program Files\Common Files\ATI Technologies\Multimedia\atimpenc64.dll (ATI MPEG Encoder/Advanced Micro Devices Inc.)(2012-12-19 14:29:48)
Reg HKLM\SOFTWARE\Classes\CLSID\{524B98BC-7B94-48cb-8F6E-CEC7D1B64522}\InprocServer32@ C:\Program Files (x86)\Personal\bin\np_prsnl64.dll (Nexus Personal Plug-Ins/Technology Nexus AB SIGNED)(2012-11-15 12:11:50)
Reg HKLM\SOFTWARE\Classes\CLSID\{550D0110-8DCD-11D1-8524-00A02495E426}\InprocServer32@ C:\Program Files\Microsoft Office\Office14\VVIEWDWG.DLL (Microsoft Visio Viewer 2010/Microsoft Corporation)(2012-04-26 19:01:22)
Reg HKLM\SOFTWARE\Classes\CLSID\{57CE581A-0CB6-4266-9CA0-19364C90A0B3}\InprocServer32@ D:\Install\Malwarebytes' Anti-Malware\mbamext.dll (Malwarebytes Anti-Malware/Malwarebytes Corporation SIGNED)(2013-01-23 01:17:22)
Reg HKLM\SOFTWARE\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\InprocServer32@ C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll (AMD Desktop Control Panel/Advanced Micro Devices, Inc.)(2012-12-19 14:14:30)
Reg HKLM\SOFTWARE\Classes\CLSID\{5E93C5A9-7516-4259-A67B-41A656F6E01C}\InprocServer32@ C:\Windows\system32\dnssdX.dll (Bonjour COM Component Library/Apple Inc. SIGNED)(2011-08-30 21:05:32)
Reg HKLM\SOFTWARE\Classes\CLSID\{63530157-314D-473F-BB48-9B1B18908300}\InProcServer32@ C:\Program Files\iTunes\iTunesOutlookAddIn.dll (iTunes Outlook Add-in/Apple Inc. SIGNED)(2013-02-20 11:35:32)
Reg HKLM\SOFTWARE\Classes\CLSID\{6467DD70-FBD5-11D2-B5B6-444553540000}\InprocServer32@ C:\Program Files\Common Files\ATI Technologies\Multimedia\atimpenc64.dll (ATI MPEG Encoder/Advanced Micro Devices Inc.)(2012-12-19 14:29:48)
Reg HKLM\SOFTWARE\Classes\CLSID\{6939BF8D-FF94-492C-9E4E-BD6439D8F867}\InprocServer32@ C:\Program Files\Microsoft Office\Office14\VVIEWDWG.DLL (Microsoft Visio Viewer 2010/Microsoft Corporation)(2012-04-26 19:01:22)
Reg HKLM\SOFTWARE\Classes\CLSID\{6969E7D5-223A-4982-9B79-CC4FAC2D5E5E}\InprocServer32@ C:\Program Files (x86)\Personal\bin\np_prsnl64.dll (Nexus Personal Plug-Ins/Technology Nexus AB SIGNED)(2012-11-15 12:11:50)
Reg HKLM\SOFTWARE\Classes\CLSID\{6988B430-8352-11D3-9BDA-CA86737C7168}\InprocServer32@ C:\Program Files\Common Files\ATI Technologies\Multimedia\atimpenc64.dll (ATI MPEG Encoder/Advanced Micro Devices Inc.)(2012-12-19 14:29:48)
Reg HKLM\SOFTWARE\Classes\CLSID\{7A7FB085-6068-4898-8CCA-480A9187277C}\LocalServer32@ C:\Program Files\iPod\bin\iPodService.exe (iPodService Module (64-bit)/Apple Inc. SIGNED)(2013-02-20 11:35:32)
Reg HKLM\SOFTWARE\Classes\CLSID\{7FD72324-63E1-45AD-B337-4D525BD98DAD}\InprocServer32@ C:\Windows\system32\dnssdX.dll (Bonjour COM Component Library/Apple Inc. SIGNED)(2011-08-30 21:05:32)
Reg HKLM\SOFTWARE\Classes\CLSID\{80570409-86F1-4482-B89F-43A925962874}\InprocServer32@ C:\PROGRA~1\MICROS~1\OFFICE14\PROOF\1033\MSGR3EN.DLL (Microsoft English Natural Language Server/Microsoft Corporation)(2009-11-09 12:27:48)
Reg HKLM\SOFTWARE\Classes\CLSID\{872A9397-E0D6-4e28-B64D-52B8D0A7EA35}\InprocServer32@ C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiama64.dll (AMD Desktop Control Panel/Advanced Micro Devices, Inc.)(2012-12-19 14:14:18)
Reg HKLM\SOFTWARE\Classes\CLSID\{878A81E0-D7CB-11D2-8E75-00104B93CF06}\InprocServer32@ C:\Program Files\Common Files\ATI Technologies\Multimedia\atimpenc64.dll (ATI MPEG Encoder/Advanced Micro Devices Inc.)(2012-12-19 14:29:48)
Reg HKLM\SOFTWARE\Classes\CLSID\{8C00C8CE-A6BA-442F-9185-2D68E4FCA8EB}\InprocServer32@ C:\Program Files\Common Files\ATI Technologies\Multimedia\AMDMFTVideoDecoder_64.dll(2012-07-27 22:09:38)
Reg HKLM\SOFTWARE\Classes\CLSID\{8D533A42-7A5F-11D3-8297-0050DA1A72D3}\InProcServer32@ C:\Windows\system32\MijFrc.dll (Logitech Force Feedback Driver/Logitech Inc. SIGNED)(2013-02-17 17:19:52)
Reg HKLM\SOFTWARE\Classes\CLSID\{8DA0A2A8-30CB-46F4-A28E-13B6B5AB926C}\InprocServer32@ C:\Program Files\Common Files\ATI Technologies\Multimedia\atimpenc64.dll (ATI MPEG Encoder/Advanced Micro Devices Inc.)(2012-12-19 14:29:48)
Reg HKLM\SOFTWARE\Classes\CLSID\{AC7AEFE1-E745-4D21-881C-D7B6F22275B8}\InprocServer32@ C:\Program Files (x86)\Personal\bin\np_prsnl64.dll (Nexus Personal Plug-Ins/Technology Nexus AB SIGNED)(2012-11-15 12:11:50)
Reg HKLM\SOFTWARE\Classes\CLSID\{ADC9BC80-0F41-46C6-AB75-D693D793597D}\InProcServer32@ C:\Program Files\Common Files\ATI Technologies\Multimedia\AMDh264Enc64.dll (AMD H.264 MF Encoder/Advanced Micro Devices)(2012-12-19 14:40:12)
Reg HKLM\SOFTWARE\Classes\CLSID\{AF7799A5-A3E7-455C-92B5-8F9D7C127B15}\LocalServer32@ C:\Program Files\Intel\NCS2\WMIProv\NCS2Prov.exe (NCS2Prov Module/Intel(R) Corporation SIGNED)(2011-11-18 15:06:22)
Reg HKLM\SOFTWARE\Classes\CLSID\{AFEE063C-05BA-4248-A26E-168477F49734}\InprocServer32@ C:\Windows\system32\dnssdX.dll (Bonjour COM Component Library/Apple Inc. SIGNED)(2011-08-30 21:05:32)
Reg HKLM\SOFTWARE\Classes\CLSID\{B2D171C8-6B69-487D-9267-806486775771}\InprocServer32@ C:\Program Files (x86)\Personal\bin\np_prsnl64.dll (Nexus Personal Plug-Ins/Technology Nexus AB SIGNED)(2012-11-15 12:11:50)
Reg HKLM\SOFTWARE\Classes\CLSID\{B33927D0-89E6-45D8-87C7-27F3DE3EFDE6}\LocalServer32@ C:\Program Files\iPod\bin\iPodService.exe (iPodService Module (64-bit)/Apple Inc. SIGNED)(2013-02-20 11:35:32)
Reg HKLM\SOFTWARE\Classes\CLSID\{B41DB860-64E4-11D2-9906-E49FADC173CA}\InProcServer32@ C:\Program Files\WinRAR\rarext.dll (WinRAR shell extension/Alexander Roshal)(2012-09-18 10:33:41)
Reg HKLM\SOFTWARE\Classes\CLSID\{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}\InprocServer32@ C:\Program Files\iTunes\iTunesMiniPlayer.dll (iTunes Miniplayer DLL (64-bit)/Apple Inc. SIGNED)(2013-02-20 11:35:32)
Reg HKLM\SOFTWARE\Classes\CLSID\{BEEB932A-8D4A-4619-AEFE-A836F988B221}\InprocServer32@ C:\Windows\system32\dnssdX.dll (Bonjour COM Component Library/Apple Inc. SIGNED)(2011-08-30 21:05:32)
Reg HKLM\SOFTWARE\Classes\CLSID\{DD137900-E4D7-4b86-92CC-2E968F846047}\InprocServer32@ C:\Program Files (x86)\Personal\bin\np_prsnl64.dll (Nexus Personal Plug-Ins/Technology Nexus AB SIGNED)(2012-11-15 12:11:50)
Reg HKLM\SOFTWARE\Classes\CLSID\{DF90FA9A-83F4-477D-861A-B7A1285ACEEE}\InprocServer32@ C:\Program Files\Common Files\ATI Technologies\Multimedia\atimpenc64.dll (ATI MPEG Encoder/Advanced Micro Devices Inc.)(2012-12-19 14:29:48)
Reg HKLM\SOFTWARE\Classes\CLSID\{E5C324CC-4029-43CA-8D57-4A10480B9016}\InprocServer32@ C:\Program Files (x86)\Personal\bin\np_prsnl64.dll (Nexus Personal Plug-Ins/Technology Nexus AB SIGNED)(2012-11-15 12:11:50)
Reg HKLM\SOFTWARE\Classes\CLSID\{F7A782D3-2DDD-4327-BB70-0D1D0F1E38B0}\InprocServer32@ C:\Program Files\iTunes\iPodUpdaterExt.dll (iPod Universal Updater Module/Apple Inc. SIGNED)(2013-02-20 11:35:32)
Reg HKLM\SOFTWARE\Classes\CLSID\{FB25B6FD-2119-4cef-A915-A056184C565E}\InprocServer32@ C:\Program Files (x86)\Personal\bin\np_prsnl64.dll (Nexus Personal Plug-Ins/Technology Nexus AB SIGNED)(2012-11-15 12:11:50)
Reg HKLM\SOFTWARE\Classes\daap\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\Directory\shell\AddToPlaylistVLC\command@ C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (VLC media player 2.0.5/VideoLAN)(2012-12-13 00:12:58)
Reg HKLM\SOFTWARE\Classes\dota2\Shell\Open\Command@ D:\Install\Steam\steamapps\common\dota 2 beta\dota.exe(2012-11-04 23:05:33)
Reg HKLM\SOFTWARE\Classes\DVD\shell\PlayWithVLC\command@ C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (VLC media player 2.0.5/VideoLAN)(2012-12-13 00:12:58)
Reg HKLM\SOFTWARE\Classes\FirefoxHTML\shell\open\command@ C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation SIGNED)(2013-02-19 16:19:58)
Reg HKLM\SOFTWARE\Classes\hon\shell\open\command@ C:\Program Files (x86)\Heroes of Newerth\hon.exe (Heroes of Newerth/S2 Games SIGNED)(2012-09-07 21:48:14)
Reg HKLM\SOFTWARE\Classes\http\shell\open\command@ C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation SIGNED)(2013-02-19 16:19:58)
Reg HKLM\SOFTWARE\Classes\Installer\Products\2A7527EE2A93F2D4D9CA9F2FB5A81E8D@ProductIcon C:\Windows\Installer\{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}\SkypeIcon.exe(2012-09-18 10:17:32)
Reg HKLM\SOFTWARE\Classes\Installer\Products\5FE249168DC24D7468C9E2A9B80B581F@ProductIcon C:\Windows\Installer\{61942EF5-2CD8-47D4-869C-2E9A8BB085F1}\ARPPRODUCTICON.exe (InstallShield/Flexera Software, Inc.)(2012-09-17 17:57:41)
Reg HKLM\SOFTWARE\Classes\Installer\Products\C99A8346E73A85740AEA598F6AA3FA5F@ProductIcon C:\Windows\Installer\{6438A99C-A37E-4758-A0AE-95F8A63AAFF5}\ARPPRODUCTICON.exe (InstallShield/Macrovision Corporation)(2012-09-17 17:57:25)
Reg HKLM\SOFTWARE\Classes\itls\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.aa@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.aa\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.aax@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.aax\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.aif@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.aif\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.aifc@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.aifc\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.aiff@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.aiff\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.daap@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.daap\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itls@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itls\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itms@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itms\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itmss@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itmss\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itpc@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itpc\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.pcast@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.pcast\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.cda@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.cda\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.cdda@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.cdda\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.ipa@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.ipa\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.ipg@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.ipg\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.ipsw@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.ipsw\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.itdb@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.itdb\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.ite@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.ite\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.itl@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.itl\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.itls@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.itls\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.itms@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.itms\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.itpc@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.itpc\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.m3u@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.m3u\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.m3u8@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.m3u8\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.m4a@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.m4a\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.m4b@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.m4b\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.m4p@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.m4p\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.m4r@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.m4r\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.m4v@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.m4v\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.mov@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.mov\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.mp2@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.mp2\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.mp3@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.mp3\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.mpg@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.mpg\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.pcast@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.pcast\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.pls@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.pls\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.rmp@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.rmp\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.wav@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.wav\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\iTunes.wave@FriendlyTypeName C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\iTunes.wave\shell\open\command@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\PDXFileType\shell\Read\command@ C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe (Adobe Reader /Adobe Systems Incorporated SIGNED)(2013-02-15 22:31:18)
Reg HKLM\SOFTWARE\Classes\QuickTime.3g2\shell\open\command@ C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe (QuickTime Player/Apple Inc. SIGNED)(2012-10-31 18:19:06)
Reg HKLM\SOFTWARE\Classes\QuickTime.bmp\shell\open\command@ C:\Program Files (x86)\QuickTime\PictureViewer.exe (PictureViewer/Apple Inc.)(2012-10-25 02:12:02)
Reg HKLM\SOFTWARE\Classes\QuickTime.bwf\shell\open\command@ C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe (QuickTime Player/Apple Inc. SIGNED)(2012-10-31 18:19:06)
Reg HKLM\SOFTWARE\Classes\QuickTime.dib\shell\open\command@ C:\Program Files (x86)\QuickTime\PictureViewer.exe (PictureViewer/Apple Inc.)(2012-10-25 02:12:02)
Reg HKLM\SOFTWARE\Classes\QuickTime.dif\shell\open\command@ C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe (QuickTime Player/Apple Inc. SIGNED)(2012-10-31 18:19:06)
Reg HKLM\SOFTWARE\Classes\QuickTime.jp2\shell\open\command@ C:\Program Files (x86)\QuickTime\PictureViewer.exe (PictureViewer/Apple Inc.)(2012-10-25 02:12:02)
Reg HKLM\SOFTWARE\Classes\QuickTime.kar\shell\open\command@ C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe (QuickTime Player/Apple Inc. SIGNED)(2012-10-31 18:19:06)
Reg HKLM\SOFTWARE\Classes\QuickTime.mac\shell\open\command@ C:\Program Files (x86)\QuickTime\PictureViewer.exe (PictureViewer/Apple Inc.)(2012-10-25 02:12:02)
Reg HKLM\SOFTWARE\Classes\QuickTime.mid\shell\open\command@ C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe (QuickTime Player/Apple Inc. SIGNED)(2012-10-31 18:19:06)
Reg HKLM\SOFTWARE\Classes\QuickTime.pct\shell\open\command@ C:\Program Files (x86)\QuickTime\PictureViewer.exe (PictureViewer/Apple Inc.)(2012-10-25 02:12:02)
Reg HKLM\SOFTWARE\Classes\QuickTime.qcp\shell\open\command@ C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe (QuickTime Player/Apple Inc. SIGNED)(2012-10-31 18:19:06)
Reg HKLM\SOFTWARE\Classes\QuickTime.qti\shell\open\command@ C:\Program Files (x86)\QuickTime\PictureViewer.exe (PictureViewer/Apple Inc.)(2012-10-25 02:12:02)
Reg HKLM\SOFTWARE\Classes\QuickTime.qtl\shell\open\command@ C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe (QuickTime Player/Apple Inc. SIGNED)(2012-10-31 18:19:06)
Reg HKLM\SOFTWARE\Classes\QuickTime.rgb\shell\open\command@ C:\Program Files (x86)\QuickTime\PictureViewer.exe (PictureViewer/Apple Inc.)(2012-10-25 02:12:02)
Reg HKLM\SOFTWARE\Classes\QuickTime.rts\shell\open\command@ C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe (QuickTime Player/Apple Inc. SIGNED)(2012-10-31 18:19:06)
Reg HKLM\SOFTWARE\Classes\QuickTime.sgi\shell\open\command@ C:\Program Files (x86)\QuickTime\PictureViewer.exe (PictureViewer/Apple Inc.)(2012-10-25 02:12:02)
Reg HKLM\SOFTWARE\Classes\QuickTime.smf\shell\open\command@ C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe (QuickTime Player/Apple Inc. SIGNED)(2012-10-31 18:19:06)
Reg HKLM\SOFTWARE\Classes\QuickTime.targa\shell\open\command@ C:\Program Files (x86)\QuickTime\PictureViewer.exe (PictureViewer/Apple Inc.)(2012-10-25 02:12:02)
Reg HKLM\SOFTWARE\Classes\QuickTime.ulw\shell\open\command@ C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe (QuickTime Player/Apple Inc. SIGNED)(2012-10-31 18:19:06)
Reg HKLM\SOFTWARE\Classes\skype\shell\open\command@ C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype /Skype Technologies S.A. SIGNED)(2012-07-13 11:33:24)
Reg HKLM\SOFTWARE\Classes\SOFTWARE\Adobe\Acrobat\Exe@ C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe (Adobe Reader /Adobe Systems Incorporated SIGNED)(2013-02-15 22:31:18)
Reg HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\HTMLHelp\2.0\LocalReg\CLSID\{314111bd-a502-11d2-bbca-00c04f8ec294}\InprocServer32@ C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft® Help Data Services Module/Microsoft Corporation)(2008-05-23 12:03:06)
Reg HKLM\SOFTWARE\Classes\spotify\shell\open\command@ C:\Users\Eldest\AppData\Roaming\Spotify\spotify.exe (Spotify/Spotify Ltd SIGNED)(2012-09-18 10:12:56)
Reg HKLM\SOFTWARE\Classes\steam\Shell\Open\Command@ D:\Install\Steam\steam.exe (Steam Client Bootstrapper (buildbot_winslave04_steam_steam_rel_client_win32@winslave04)/Valve Corporation SIGNED)(2012-11-04 23:13:56)
Reg HKLM\SOFTWARE\Classes\UniverseSandbox.Document\shell\Open\command@ D:\Install\Steam\steamapps\common\Universe Sandbox\Universe Sandbox.exe (Universe Sandbox/Giant Army)(2012-12-22 17:48:18)
Reg HKLM\SOFTWARE\Classes\VLC.3g2\shell\AddToPlaylistVLC\command@ C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (VLC media player 2.0.5/VideoLAN)(2012-12-13 00:12:58)
Reg HKLM\SOFTWARE\Classes\WinRAR\shell\open\command@ C:\Program Files\WinRAR\WinRAR.exe (WinRAR archiver/Alexander Roshal)(2012-09-18 10:33:41)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}\InprocServer32@ C:\Program Files (x86)\QuickTime\QTPlugin.ocx (The QuickTime Control allows you to view a wide variety of multimedia content in web pages./Apple Inc. SIGNED)(2012-10-31 18:19:06)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\InprocServer32@ C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe PDF Helper for Internet Explorer/Adobe Systems Incorporated SIGNED)(2012-12-18 14:28:18)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{08A6AF6A-8FF2-4a3b-BECF-C2FAC8630BBF}@LocalizedString C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{08A6AF6A-8FF2-4a3b-BECF-C2FAC8630BBF}\Elevation@IconReference C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{08A6AF6A-8FF2-4a3b-BECF-C2FAC8630BBF}\InprocServer32@ C:\Program Files (x86)\iTunes\iTunesAdmin.dll (iTunes Administrative DLL/Apple Inc. SIGNED)(2013-02-20 11:35:26)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{0A25C695-3765-4B37-9455-4B1C113C2C04}\InprocServer32@ C:\Program Files (x86)\iTunes\iTunesOutlookAddIn.dll (iTunes Outlook Add-in/Apple Inc. SIGNED)(2013-02-20 11:35:30)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{0A9BD4EB-DED5-4DF0-BAF6-2CEA23F57261}\InprocServer32@ C:\Program Files (x86)\ATI Technologies\ATI.ACE\Graphics-Previews-Common\MMACEFilters.dll(2012-12-19 14:13:10)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{0D68D6D0-D93D-4D08-A30D-F00DD1F45B24}\InProcServer32@ C:\Program Files (x86)\Mozilla Firefox\AccessibleMarshal.dll (Mozilla Foundation SIGNED)(2013-02-19 16:19:58)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{0E799A91-CDDC-471B-A803-2DB82FAFB726}\InprocServer32@ C:\Program Files (x86)\Common Files\ATI Technologies\Multimedia\AMDMFTDecoder_32.dll(2012-12-19 14:40:46)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{10AD8B9D-222E-44D1-881B-0EA79E1B2D6E}\InprocServer32@ C:\Program Files (x86)\ATI Technologies\ATI.ACE\Graphics-Previews-Common\Ticker.ax(2012-12-19 14:12:56)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{10DD084E-A5AE-456F-A3BE-DA67EBE6B090}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{11E4D223-C650-43F9-AB90-AB3AE4FB38F0}\InProcServer32@ C:\Program Files (x86)\iTunes\iTunesAdmin.dll (iTunes Administrative DLL/Apple Inc. SIGNED)(2013-02-20 11:35:26)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{12BA069D-0FC6-4577-97C6-5DF634CE6E84}\InProcServer32@ C:\Program Files (x86)\Adobe\Reader 10.0\Reader\ViewerPS.dll(2012-12-18 14:28:20)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{12E6A993-AE52-4F99-8B89-41F985E6C952}\InprocServer32@ C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\OutlookChangeNotifierAddIn.dll (OutlookChangeNotifier/Apple Inc. SIGNED)(2012-12-06 11:53:54)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{15B6FEE5-5FB3-4071-AC1F-7AEDC0E2A6BB}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{17796aeb-0f66-4663-b8fb-99cbee0224ce}\InProcServer32@ C:\Program Files (x86)\Common Files\ATI Technologies\Multimedia\AMDhwDecoder_32.dll (Accelerated Dx9 Dx11 Async MFT Video Decoder/Advanced Micro Devices)(2012-12-19 14:41:26)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{17F2E344-8227-4AA7-A25A-E89424566BBA}\InProcServer32@ C:\Program Files (x86)\Adobe\Reader 10.0\Reader\pdfprevhndlr.dll (Adobe PDF Preview Handler/Adobe Systems, Inc. SIGNED)(2012-12-18 14:28:20)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\InprocServer32@ C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe PDF Helper for Internet Explorer/Adobe Systems Incorporated SIGNED)(2012-12-18 14:28:18)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{1BCA4635-F1FC-44C8-B829-48229AEB32E3}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{1DBDFE75-A07C-4E0B-B38B-527BFA12CF0C}\InProcServer32@ C:\Program Files (x86)\QuickTime\QTSystem\ExportControllerPS.dll (Export Controller PS/Apple Inc.)(2012-10-25 02:12:04)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{20ADDA11-8287-44D0-8C63-27CDA87ACC46}@LocalizedString C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{20ADDA11-8287-44D0-8C63-27CDA87ACC46}\Elevation@IconReference C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{20ADDA11-8287-44D0-8C63-27CDA87ACC46}\InprocServer32@ C:\Program Files (x86)\iTunes\iTunesAdmin.dll (iTunes Administrative DLL/Apple Inc. SIGNED)(2013-02-20 11:35:26)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{222C0F35-3D78-4570-9F6D-BAEE289D0304}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{24BA3CAF-4BE8-4AEC-A7C8-6F47D5684602}\InprocServer32@ C:\Program Files (x86)\QuickTime\QTOControl.dll (QuickTime Control/Apple Inc. SIGNED)(2012-10-31 18:15:42)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{24CD4DE9-FF84-4701-9DC1-9B69E0D1090A}\InprocServer32@ C:\Windows\SysWOW64\dnssdX.dll (Bonjour COM Component Library/Apple Inc. SIGNED)(2011-08-30 21:05:04)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{24DA047B-40C0-4018-841B-6B7409F730FC}\InprocServer32@ C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroPDF.dll (PDF Browser Control/Adobe Systems, Inc. SIGNED)(2012-12-18 14:28:18)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{25461599-633D-42B1-84FB-7CD68D026E53}\LocalServer32@ C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleUpdateOnDemand.exe (Google Update/Google Inc. SIGNED)(2013-02-22 00:53:23)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{2692A9D5-61DF-46D5-A5A1-A6CCA921D578}\LocalServer32@ C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe (Apple Software Update/Apple Inc. SIGNED)(2011-06-01 15:57:16)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{27A59F19-C5CC-4B51-A6CA-A1DEBF81F022}\InprocServer32@ C:\Program Files (x86)\QuickTime\QTUIPanelControl.dll (QuickTime UI Panel Control/Apple Inc. SIGNED)(2012-10-31 18:15:46)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{29AAD3F2-F7A6-4F7E-A6C0-96F674F47142}\InProcServer32@ C:\Program Files (x86)\Google\Update\1.3.21.135\psmachine.dll (Google Update/Google Inc. SIGNED)(2013-02-22 00:53:22)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{29DCD339-D184-469B-8BFB-199A2CCF014E}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{30063361-BAE0-480A-BF2B-417D18530A0D}\InprocServer32@ C:\Program Files (x86)\QuickTime\QTOLibrary.dll (QuickTime Library/Apple Inc. SIGNED)(2012-10-31 18:15:42)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{307A6C42-0000-0010-8000-00AA00389B71}\InprocServer32@ d:\install\warcraft iii\blizzard.ax (DivX (TM) Decoder Filter/DivXNetworks, Inc.)(2013-01-19 20:42:42)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{3506CDB7-8BC6-40C0-B108-CEA0B9480130}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{37A4D802-E76C-11D2-935C-00A024E52661}\InprocServer32@ C:\Program Files (x86)\Common Files\ATI Technologies\Multimedia\atimpenc.dll (ATI MPEG Encoder/Advanced Micro Devices Inc.)(2012-12-19 14:25:14)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{3D3E7C1B-79A7-4CC7-8925-41FA813E9913}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{4063BE15-3B08-470D-A0D5-B37161CFFD69}\InprocServer32@ C:\Program Files (x86)\QuickTime\QTPlugin.ocx (The QuickTime Control allows you to view a wide variety of multimedia content in web pages./Apple Inc. SIGNED)(2012-10-31 18:19:06)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{428978C8-3E4D-4AD9-8096-2FE753FA47BC}\InprocServer32@ C:\Program Files (x86)\Common Files\ATI Technologies\Multimedia\atimpenc.dll (ATI MPEG Encoder/Advanced Micro Devices Inc.)(2012-12-19 14:25:14)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{42FE718B-A148-41D6-885B-01A0AFAE8723}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{4A6E162C-6F51-4956-86D0-A72729178B9B}\InprocServer32@ C:\Program Files (x86)\ATI Technologies\ATI.ACE\Graphics-Previews-Common\MMACEFilters.dll(2012-12-19 14:13:10)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{4B42750B-57A1-47E7-B340-8EAE0E3126A4}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{524B98BC-7B94-48CB-8F6E-CEC7D1B64522}\InprocServer32@ C:\Program Files (x86)\Personal\bin\np_prsnl.dll (Nexus Personal Plug-Ins/Technology Nexus AB SIGNED)(2012-11-15 12:11:48)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{5792FC7D-5E1D-4F1A-BD4F-A7A50F92BC6E}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{598FE0E5-E02D-465D-9A9D-37974A28FD42}@LocalizedString C:\Program Files (x86)\Google\Update\1.3.21.135\goopdate.dll (Google Update/Google Inc. SIGNED)(2013-02-22 00:53:22)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{598FE0E5-E02D-465D-9A9D-37974A28FD42}\LocalServer32@ C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleUpdateOnDemand.exe (Google Update/Google Inc. SIGNED)(2013-02-22 00:53:23)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{5AAABB05-F91B-4bce-AB18-D8319DEDABA8}\InprocServer32@ C:\Program Files (x86)\Adobe\Reader 10.0\Reader\adoberfp.dll (Adobe Reader File Preview/Adobe Systems, Inc. SIGNED)(2011-06-06 10:55:32)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{5BB2200E-5672-4A32-902A-5A98DB1C58DC}\InprocServer32@ C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroPDF.dll (PDF Browser Control/Adobe Systems, Inc. SIGNED)(2012-12-18 14:28:18)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\LocalServer32@ C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.97\delegate_execute.exe (Google Chrome/Google Inc. SIGNED)(2013-02-22 00:53:43)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{5E541E71-A474-4EAD-8FCB-24D400D023B7}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{5E628A96-1BE5-42FE-9117-EDAD9A9C479C}\InProcServer32@ C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\pdfshell.dll (PDF Shell Extension/Adobe Systems, Inc. SIGNED)(2012-12-18 14:28:20)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{5E93C5A9-7516-4259-A67B-41A656F6E01C}\InprocServer32@ C:\Windows\SysWOW64\dnssdX.dll (Bonjour COM Component Library/Apple Inc. SIGNED)(2011-08-30 21:05:04)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{60EB3672-E108-48E5-8F14-9E3DC7D618E0}\InprocServer32@ C:\Program Files (x86)\QuickTime\QTOLibrary.dll (QuickTime Library/Apple Inc. SIGNED)(2012-10-31 18:15:42)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{61F8FAF0-82D0-407C-AE97-31441483AE40}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{62A560B8-09DB-4cc6-AE1B-9D8F7ADDB8F3}@LocalizedString C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{62A560B8-09DB-4cc6-AE1B-9D8F7ADDB8F3}\Elevation@IconReference C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{62A560B8-09DB-4cc6-AE1B-9D8F7ADDB8F3}\InprocServer32@ C:\Program Files (x86)\iTunes\iTunesAdmin.dll (iTunes Administrative DLL/Apple Inc. SIGNED)(2013-02-20 11:35:26)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{63530157-314D-473F-BB48-9B1B18908300}\InProcServer32@ C:\Program Files (x86)\iTunes\iTunesOutlookAddIn.dll (iTunes Outlook Add-in/Apple Inc. SIGNED)(2013-02-20 11:35:30)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{64417EAE-2E0E-45E8-A8C1-03284E3D3587}\LocalServer32@ C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (User Notification Service/Intel Corporation SIGNED)(2012-09-17 17:58:45)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{6467DD70-FBD5-11D2-B5B6-444553540000}\InprocServer32@ C:\Program Files (x86)\Common Files\ATI Technologies\Multimedia\atimpenc.dll (ATI MPEG Encoder/Advanced Micro Devices Inc.)(2012-12-19 14:25:14)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{671B6145-4169-4ADD-9AF3-E6990EB2B325}\InProcServer32@ C:\Program Files (x86)\Adobe\Reader 10.0\Reader\adoberfp.dll (Adobe Reader File Preview/Adobe Systems, Inc. SIGNED)(2011-06-06 10:55:32)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{6812639B-FD61-4329-9901-22CFDBD690FE}\LocalServer32@ C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Push/Apple Inc. SIGNED)(2013-01-28 12:08:14)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{6969E7D5-223A-4982-9B79-CC4FAC2D5E5E}\InprocServer32@ C:\Program Files (x86)\Personal\bin\np_prsnl.dll (Nexus Personal Plug-Ins/Technology Nexus AB SIGNED)(2012-11-15 12:11:48)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{6988B430-8352-11D3-9BDA-CA86737C7168}\InprocServer32@ C:\Program Files (x86)\Common Files\ATI Technologies\Multimedia\atimpenc.dll (ATI MPEG Encoder/Advanced Micro Devices Inc.)(2012-12-19 14:25:14)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{6AC51E9C-7947-4B46-A978-0AD601C4EFC9}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{6C2589C3-96F8-4863-A511-9C33EB2C7E2A}@LocalizedString C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{6C2589C3-96F8-4863-A511-9C33EB2C7E2A}\Elevation@IconReference C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{6C2589C3-96F8-4863-A511-9C33EB2C7E2A}\InprocServer32@ C:\Program Files (x86)\iTunes\iTunesAdmin.dll (iTunes Administrative DLL/Apple Inc. SIGNED)(2013-02-20 11:35:26)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{6F8BD55B-E83D-4A47-85BE-81FFA8057A69}@LocalizedString C:\Program Files (x86)\Google\Update\1.3.21.135\goopdate.dll (Google Update/Google Inc. SIGNED)(2013-02-22 00:53:22)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{6F8BD55B-E83D-4A47-85BE-81FFA8057A69}\LocalServer32@ C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleUpdateBroker.exe (Google Update/Google Inc. SIGNED)(2013-02-22 00:53:23)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{6FA10A39-4760-4C94-A210-2398848618EC}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{71A1A612-F7B4-4092-8E0F-C79C8FB0391D}@LocalizedString C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{71A1A612-F7B4-4092-8E0F-C79C8FB0391D}\Elevation@IconReference C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{71A1A612-F7B4-4092-8E0F-C79C8FB0391D}\InprocServer32@ C:\Program Files (x86)\iTunes\iTunesAdmin.dll (iTunes Administrative DLL/Apple Inc. SIGNED)(2013-02-20 11:35:26)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{71A27032-C7D8-11D2-BEF8-525400DFB47A}\InprocServer32@ D:\Install\Malwarebytes' Anti-Malware\ssubtmr6.dll (Subclassing and Timer Assistant, modified for configurable message response, multi control support and bug fixed for timer errors./vbAccelerator SIGNED)(2013-01-23 01:17:23)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{72278E83-B0EF-4E49-9E10-6947602C1030}\LocalServer32@ C:\Program Files (x86)\QuickTime\QTSystem\ExportController.exe (Export Controller/Apple Inc. SIGNED)(2012-10-25 02:12:04)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{758C0F02-DF95-11D2-8E75-00104B93CF06}\InprocServer32@ C:\Program Files (x86)\Common Files\ATI Technologies\Multimedia\atimpenc.dll (ATI MPEG Encoder/Advanced Micro Devices Inc.)(2012-12-19 14:25:14)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{7ACDC5B4-76A1-4BDF-918D-6962FCABBAD3}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{7CAB7C36-4989-445D-9D74-DFF79A3C85FA}\LocalServer32@ C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe (QuickTime Player/Apple Inc. SIGNED)(2012-10-31 18:19:06)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{7CABC14E-7C51-4AAA-AE3F-CFEB42D5016A}\LocalServer32@ C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (User Notification Service/Intel Corporation SIGNED)(2012-09-17 17:58:45)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{7DE94008-8AFD-4C70-9728-C6FBFFF6A73E}\LocalServer32@ C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleUpdateBroker.exe (Google Update/Google Inc. SIGNED)(2013-02-22 00:53:23)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{7FD72324-63E1-45AD-B337-4D525BD98DAD}\InprocServer32@ C:\Windows\SysWOW64\dnssdX.dll (Bonjour COM Component Library/Apple Inc. SIGNED)(2011-08-30 21:05:04)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{80C25488-192B-4DE2-8150-5B2D2A2F835E}\LocalServer32@ C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (User Notification Service/Intel Corporation SIGNED)(2012-09-17 17:58:45)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{80EE9910-D470-4AED-AC5D-987046FDB574}\LocalServer32@ C:\PROGRA~2\iTunes\ITUNES~1.EXE (iTunesHelper/Apple Inc. SIGNED)(2013-02-20 11:35:28)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{815031F4-05E5-4269-830C-FD3C0EA9BA58}\InprocServer32@ C:\Program Files (x86)\QuickTime\QTOLibrary.dll (QuickTime Library/Apple Inc. SIGNED)(2012-10-31 18:15:42)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{8215BA54-B69F-4275-AE11-31CB63593B09}\InProcServer32@ C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRdIF.dll (PDF IFilter/Adobe Systems, Inc. SIGNED)(2012-12-18 14:28:22)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{830690FC-BF2F-47A6-AC2D-330BCB402664}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{854F4628-CE51-42C4-80E9-80DAE27FAAAE}\InprocServer32@ C:\Program Files (x86)\ATI Technologies\ATI.ACE\Graphics-Previews-Common\MMACEFilters.dll(2012-12-19 14:13:10)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{878A81E0-D7CB-11D2-8E75-00104B93CF06}\InprocServer32@ C:\Program Files (x86)\Common Files\ATI Technologies\Multimedia\atimpenc.dll (ATI MPEG Encoder/Advanced Micro Devices Inc.)(2012-12-19 14:25:14)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{88F48C4A-46DF-4236-A838-364BF1B3FD1E}\InProcServer32@ C:\Program Files (x86)\Apple Software Update\SoftwareUpdateAdmin.dll (Apple Software Update/Apple Inc. SIGNED)(2011-06-01 15:57:16)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{89DD2F9D-C325-48BF-A615-96BD039BBC83}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}@LocalizedString C:\Program Files (x86)\Google\Update\1.3.21.135\goopdate.dll (Google Update/Google Inc. SIGNED)(2013-02-22 00:53:22)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{8A1D4361-2C08-4700-A351-3EAA9CBFF5E4}\LocalServer32@ C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleUpdateBroker.exe (Google Update/Google Inc. SIGNED)(2013-02-22 00:53:23)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{8B59EE61-F430-11D2-8E75-00104B93CF06}\InprocServer32@ C:\Program Files (x86)\Common Files\ATI Technologies\Multimedia\atimpenc.dll (ATI MPEG Encoder/Advanced Micro Devices Inc.)(2012-12-19 14:25:14)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{8C00C8CE-A6BA-442F-9185-2D68E4FCA8EB}\InprocServer32@ C:\Program Files (x86)\Common Files\ATI Technologies\Multimedia\AMDMFTVideoDecoder_32.dll(2012-07-27 22:09:38)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{8DA0A2A8-30CB-46F4-A28E-13B6B5AB926C}\InprocServer32@ C:\Program Files (x86)\Common Files\ATI Technologies\Multimedia\atimpenc.dll (ATI MPEG Encoder/Advanced Micro Devices Inc.)(2012-12-19 14:25:14)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{9017071A-2E34-4C3A-9BBB-688CBB5A9FF2}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{91A9E6A9-3935-4A37-AFBA-F0904B166364}@LocalizedString C:\Program Files (x86)\Apple Software Update\SoftwareUpdateAdmin.dll (Apple Software Update/Apple Inc. SIGNED)(2011-06-01 15:57:16)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{95028000-A6DE-493B-B253-9E18B19610A2}@LocalizedString C:\Program Files (x86)\Skype\Updater\Updater.dll (Skype Updater Library/Skype Technologies SIGNED)(2012-07-13 11:28:38)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{95028000-A6DE-493B-B253-9E18B19610A2}\Elevation@IconReference C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Updater Service/Skype Technologies SIGNED)(2012-07-13 11:28:36)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{95028000-A6DE-493B-B253-9E18B19610A2}\InprocServer32@ C:\Program Files (x86)\Skype\Updater\Updater.dll (Skype Updater Library/Skype Technologies SIGNED)(2012-07-13 11:28:38)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{95F75C18-18BD-4B42-8C6C-CEC4B0EFB160}\InprocHandler32@ C:\Program Files (x86)\Google\Update\1.3.21.135\psmachine.dll (Google Update/Google Inc. SIGNED)(2013-02-22 00:53:22)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{965C65B5-8332-4B3B-8052-69CBF0D5090C}\LocalServer32@ C:\Program Files (x86)\Personal\bin\Personal.exe (Nexus Personal/Technology Nexus AB SIGNED)(2012-11-15 12:11:48)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{98D9A6F1-4696-4B5E-A2E8-36B3F9C1E12C}\LocalServer32@ C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32Info.exe (Adobe Reader /Adobe Systems Incorporated SIGNED)(2012-12-18 14:28:22)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{9B2340A0-4068-43D6-B404-32E27217859D}@LocalizedString C:\Program Files (x86)\Google\Update\1.3.21.135\goopdate.dll (Google Update/Google Inc. SIGNED)(2013-02-22 00:53:22)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{9B2340A0-4068-43D6-B404-32E27217859D}\LocalServer32@ C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleUpdateOnDemand.exe (Google Update/Google Inc. SIGNED)(2013-02-22 00:53:23)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{9BE31822-FDAD-461B-AD51-BE1D1C159921}\InprocServer32@ C:\Program Files (x86)\VideoLAN\VLC\axvlc.dll(2012-12-13 00:12:58)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{9D073235-D787-497D-8D1F-929559F1C621}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{9D6AA569-9F30-41AD-885A-346685C74928}\InprocServer32@ C:\Program Files (x86)\Google\Update\1.3.21.135\psmachine.dll (Google Update/Google Inc. SIGNED)(2013-02-22 00:53:22)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{9E665ED7-958C-410C-9C56-05DA783E7933}\InprocServer32@ C:\Program Files (x86)\ATI Technologies\ATI.ACE\Graphics-Previews-Common\MMACEFilters.dll(2012-12-19 14:13:10)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{A6C538C6-4A26-4839-B0D2-BF0406A4B299}\InprocServer32@ C:\Program Files (x86)\QuickTime\QTOControl.dll (QuickTime Control/Apple Inc. SIGNED)(2012-10-31 18:15:42)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{A7DF2611-D752-4C9F-A90A-B56F18485EE9}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{A80BD82B-4346-46C7-81E2-E1105F97AD0F}\InprocServer32@ C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\IntelWebAPIUpdaterActiveX.dll (Intel web components updater - Installs and updates the Intel web components/Intel Corporation SIGNED)(2012-09-17 17:59:08)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{A8109DB9-88E0-42FE-98EA-8A12BE5394C6}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{A882BDEE-BD01-4B16-9EAF-04B74A43DF7C}\InprocServer32@ C:\Program Files (x86)\QuickTime\QTOLibrary.dll (QuickTime Library/Apple Inc. SIGNED)(2012-10-31 18:15:42)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{A983C9EC-D73E-4364-B89B-ACD1E405674F}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{AAD4AE2E-D834-46D4-8B09-490FAC9C722B}\LocalServer32@ C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleUpdateBroker.exe (Google Update/Google Inc. SIGNED)(2013-02-22 00:53:23)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{ABC01078-F197-4B0B-ADBC-CFE684B39C82}\LocalServer32@ C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleUpdateOnDemand.exe (Google Update/Google Inc. SIGNED)(2013-02-22 00:53:23)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{AC7AEFE1-E745-4D21-881C-D7B6F22275B8}\InprocServer32@ C:\Program Files (x86)\Personal\bin\np_prsnl.dll (Nexus Personal Plug-Ins/Technology Nexus AB SIGNED)(2012-11-15 12:11:48)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{ADC9BC80-0F41-46C6-AB75-D693D793597D}\InProcServer32@ C:\Program Files (x86)\Common Files\ATI Technologies\Multimedia\AMDh264Enc32.dll (AMD H.264 MF Encoder/Advanced Micro Devices)(2012-12-19 14:39:46)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{AFEE063C-05BA-4248-A26E-168477F49734}\InprocServer32@ C:\Windows\SysWOW64\dnssdX.dll (Bonjour COM Component Library/Apple Inc. SIGNED)(2011-08-30 21:05:04)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{B09AC3FF-0D5D-41C6-A34E-7C3F58A3127C}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{B2D171C8-6B69-487D-9267-806486775771}\InprocServer32@ C:\Program Files (x86)\Personal\bin\np_prsnl.dll (Nexus Personal Plug-Ins/Technology Nexus AB SIGNED)(2012-11-15 12:11:48)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{B3D28DBD-0DFA-40E4-8071-520767BADC7E}@LocalizedString C:\Program Files (x86)\Google\Update\1.3.21.135\goopdate.dll (Google Update/Google Inc. SIGNED)(2013-02-22 00:53:22)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{B3D28DBD-0DFA-40E4-8071-520767BADC7E}\LocalServer32@ C:\Program Files (x86)\Google\Update\1.3.21.135\GoogleUpdateOnDemand.exe (Google Update/Google Inc. SIGNED)(2013-02-22 00:53:23)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA}\InProcServer32@ C:\Program Files\WinRAR\rarext32.dll (WinRAR shell extension/Alexander Roshal)(2012-09-18 10:33:41)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}\LocalServer32@ C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe (Adobe Reader /Adobe Systems Incorporated SIGNED)(2013-02-15 22:31:18)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{B89A1D42-E640-4CDC-9C06-FCF8AE041AA7}\LocalServer32@ C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (User Notification Service/Intel Corporation SIGNED)(2012-09-17 17:58:45)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{B8DF592B-DE05-49f5-BB21-084F548F12A9}@LocalizedString C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{B8DF592B-DE05-49f5-BB21-084F548F12A9}\Elevation@IconReference C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{B8DF592B-DE05-49f5-BB21-084F548F12A9}\InprocServer32@ C:\Program Files (x86)\iTunes\iTunesAdmin.dll (iTunes Administrative DLL/Apple Inc. SIGNED)(2013-02-20 11:35:26)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{BB46F03E-7CD2-489F-8F95-BB950F395FDB}@LocalizedString C:\Program Files (x86)\Apple Software Update\SoftwareUpdateAdmin.dll (Apple Software Update/Apple Inc. SIGNED)(2011-06-01 15:57:16)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{BD57A9B2-4E7D-4892-9107-9F4106472DA4}\LocalServer32@ C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroBroker.exe (Adobe PDF Broker Process for Internet Explorer/Adobe Systems Incorporated SIGNED)(2012-12-18 14:28:12)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{BDE0D630-7801-47cd-984E-1F0AFBC5ACBF}\InprocServer32@ C:\Program Files (x86)\Adobe\Reader 10.0\Reader\adoberfp.dll (Adobe Reader File Preview/Adobe Systems, Inc. SIGNED)(2011-06-06 10:55:32)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{BEEB932A-8D4A-4619-AEFE-A836F988B221}\InprocServer32@ C:\Windows\SysWOW64\dnssdX.dll (Bonjour COM Component Library/Apple Inc. SIGNED)(2011-08-30 21:05:04)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32@ C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Update/Google Inc. SIGNED)(2013-02-22 00:53:23)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{C523F39F-9C83-11D3-9094-00104BD0D535}\InprocServer32@ C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Accessibility.api (Adobe Acrobat Accessibility Plug-in/Adobe Systems Incorporated)(2012-12-18 14:28:18)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{C5DA1F2B-B2BF-4DFC-BC9A-439133543A67}\InprocServer32@ D:\Install\Malwarebytes' Anti-Malware\vbalsgrid6.ocx (vbAccelerator VB6 SGrid Control 2.0/vbAccelerator SIGNED)(2013-01-23 01:17:23)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{C69EBBD4-3B66-4BF6-BE1B-E2B44C5154B2}\InprocServer32@ C:\Program Files (x86)\QuickTime\QTOLibrary.dll (QuickTime Library/Apple Inc. SIGNED)(2012-10-31 18:15:42)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\InprocServer32@ C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroPDF.dll (PDF Browser Control/Adobe Systems, Inc. SIGNED)(2012-12-18 14:28:18)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{CB927D12-4FF7-4A9E-A169-56E4B8A75598}\InprocServer32@ C:\Program Files (x86)\QuickTime\QTPlugin.ocx (The QuickTime Control allows you to view a wide variety of multimedia content in web pages./Apple Inc. SIGNED)(2012-10-31 18:19:06)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{CC461FC3-C9BE-41FB-8E47-E0115CBC01CC}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{CC957078-B838-47C4-A7CF-626E7A82FC58}\LocalServer32@ C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Updater Service/Skype Technologies SIGNED)(2012-07-13 11:28:36)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{D1C8C854-223A-4716-B670-C21918E8207E}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{D38406DA-E8AA-484b-B80D-3D3DBDCC2FB2}\LocalServer32@ C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32Info.exe (Adobe Reader /Adobe Systems Incorporated SIGNED)(2012-12-18 14:28:22)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{D719897A-B07A-4C0C-AEA9-9B663A28DFCB}\InprocServer32@ C:\Program Files (x86)\iTunes\ITDetector.ocx (ITDetector Module/Apple Inc. SIGNED)(2013-02-20 12:16:00)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{D9114D1D-5BCB-4D03-8D33-88CEA9F7DD34}\InprocServer32@ C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\IntelWebAPIIPTActiveX.dll (Intel web components for Intel® Identity Protection Technology/Intel Corporation SIGNED)(2012-09-17 17:59:08)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{D97F7D8D-7610-4271-82C8-61A91BD796D1}\LocalServer32@ C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe (QuickTime Player/Apple Inc. SIGNED)(2012-10-31 18:19:06)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{D9E904CA-8865-42E7-B0F0-B7B8C4D54D70}\LocalServer32@ C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Push/Apple Inc. SIGNED)(2013-01-28 12:08:14)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{DC0C2640-1415-4644-875C-6F4D769839BA}\LocalServer32@ C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{DC6EFB56-9CFA-464D-8880-44885D7DC193}@DisplayName C:\Program Files (x86)\Adobe\Reader 10.0\Reader\pdfprevhndlr.dll (Adobe PDF Preview Handler/Adobe Systems, Inc. SIGNED)(2012-12-18 14:28:20)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{DD0E8ED5-1494-4B87-A35C-39F6ED4B1153}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{DD137900-E4D7-4B86-92CC-2E968F846047}\InprocServer32@ C:\Program Files (x86)\Personal\bin\np_prsnl.dll (Nexus Personal Plug-Ins/Technology Nexus AB SIGNED)(2012-11-15 12:11:48)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{DE4AF3B0-F4D4-11D3-B41A-0050DA2E6C21}\InprocServer32@ C:\Program Files (x86)\QuickTime\QTSystem\QuickTimeCheck.ocx (QuickTimeCheck Scriptable Object/Apple Inc. SIGNED)(2012-10-31 18:19:06)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{DF90FA9A-83F4-477D-861A-B7A1285ACEEE}\InprocServer32@ C:\Program Files (x86)\Common Files\ATI Technologies\Multimedia\atimpenc.dll (ATI MPEG Encoder/Advanced Micro Devices Inc.)(2012-12-19 14:25:14)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{DFEAF541-F3E1-4c24-ACAC-99C30715084A}@LocalizedString C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll (4.1.10329.0/ Microsoft Corporation)(2012-03-29 04:01:00)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{E16E184E-B171-46A7-9548-50E24941E0D7}\LocalServer32@ C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (User Notification Service/Intel Corporation SIGNED)(2012-09-17 17:58:45)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{E1BC9147-C3E3-4E8A-8304-5E6B5C1C0774}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{E23FE9C6-778E-49D4-B537-38FCDE4887D8}\InprocServer32@ C:\Program Files (x86)\VideoLAN\VLC\axvlc.dll(2012-12-13 00:12:58)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{E5C324CC-4029-43CA-8D57-4A10480B9016}\InprocServer32@ C:\Program Files (x86)\Personal\bin\np_prsnl.dll (Nexus Personal Plug-Ins/Technology Nexus AB SIGNED)(2012-11-15 12:11:48)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{E8978DA6-047F-4E3D-9C78-CDBE46041603}\InprocServer32@ C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRdIF.dll (PDF IFilter/Adobe Systems, Inc. SIGNED)(2012-12-18 14:28:22)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{E9D58BF1-0070-4fcd-B722-A0EE5A3ABCD6}@LocalizedString C:\Program Files (x86)\iTunes\iTunes.Resources\iTunesRegistry.dll (iTunes Resource Module/Apple Inc. SIGNED)(2013-02-20 12:16:14)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{E9D58BF1-0070-4fcd-B722-A0EE5A3ABCD6}\Elevation@IconReference C:\Program Files (x86)\iTunes\iTunes.exe (iTunes/Apple Inc. SIGNED)(2013-02-20 11:35:24)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{E9D58BF1-0070-4fcd-B722-A0EE5A3ABCD6}\InprocServer32@ C:\Program Files (x86)\iTunes\iTunesAdmin.dll (iTunes Administrative DLL/Apple Inc. SIGNED)(2013-02-20 11:35:26)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{EE5A151A-AD2A-4CEE-AD65-228B59F5B4AD}\InProcServer32@ C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroPDF.dll (PDF Browser Control/Adobe Systems, Inc. SIGNED)(2012-12-18 14:28:18)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{F278D870-7AF7-4957-96EE-E6AC72D0B109}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{F4817E4B-04B6-11D3-8862-00C04F72F303}\InProcServer32@ C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\objectps.dll (InstallShield (R) ObjectPS DLL/Macrovision Corporation)(2012-09-17 17:57:59)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{F7C41927-9415-4121-95D0-CBCC2202DA82}\LocalServer32@ C:\Program Files (x86)\QuickTime\QuickTimePlayer.exe (QuickTime Player/Apple Inc. SIGNED)(2012-10-31 18:19:06)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{F9DB5320-233E-11D1-9F84-707F02C10627}\InprocServer32@ C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll (PDF Shell Extension/Adobe Systems, Inc. SIGNED)(2012-12-18 14:28:20)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FA1F00CD-4445-401B-ADDF-FA4126EAA7C2}\LocalServer32@ C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (User Notification Service/Intel Corporation SIGNED)(2012-09-17 17:58:45)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FB25B6FD-2119-4CEF-A915-A056184C565E}\InprocServer32@ C:\Program Files (x86)\Personal\bin\np_prsnl.dll (Nexus Personal Plug-Ins/Technology Nexus AB SIGNED)(2012-11-15 12:11:48)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FDA6EEC2-325B-4E8A-A8C7-1C75DFBE72D5}\InProcServer32@ C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe PDF Helper for Internet Explorer/Adobe Systems Incorporated SIGNED)(2012-12-18 14:28:18)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{fdd068c2-d51a-4175-8a20-5cbc704ea3bd}\LocalServer32@ C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Push/Apple Inc. SIGNED)(2013-01-28 12:08:14)
Reg HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D}\InprocServer32@ C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype for COM API/Skype Technologies SIGNED)(2011-11-03 11:48:40)
Reg HKCU\Software\Microsoft\Installer\Products\AC7F955943E573242A9D8D6564A47D72@ProductIcon C:\Users\Eldest\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe (InstallShield/InstallShield Software Corp.)(2013-02-17 16:53:55)
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\KnownDevices\WpdDeviceHandler_USB#VID_05AC&PID_1292&MI_00#0@Icon C:\Windows\system32\usbaaplrc.dll (Apple Mobile Device USB Driver Resource DLL/Apple, Inc. SIGNED)(2012-09-28 09:32:56)
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Run@Spotify Web Helper C:\Users\Eldest\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (SpotifyWebHelper/Spotify Ltd SIGNED)(2012-09-18 10:12:55)
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Run@HydraVisionDesktopManager C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (HydraDM/AMD)(2012-07-27 19:35:52)
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Run@uTorrent C:\Users\Eldest\AppData\Roaming\uTorrent\uTorrent.exe (µTorrent/BitTorrent Inc. SIGNED)(2013-02-20 21:37:47)
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Spotify@DisplayIcon C:\Users\Eldest\AppData\Roaming\Spotify\Spotify.exe (Spotify/Spotify Ltd SIGNED)(2012-09-18 10:12:56)
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\UnityWebPlayer@UninstallString C:\Users\Eldest\AppData\Local\Unity\WebPlayer\Uninstall.exe (Unity Web Player Installer/Unity Technologies ApS)(2013-01-31 22:12:43)

---- EOF - GMER 2.1 ----
Eldest
Regular Member
 
Posts: 26
Joined: February 19th, 2013, 3:50 pm

Re: Every program crashing and getting Blue Screen

Unread postby Gary R » February 26th, 2013, 6:36 pm

It's going to take me a while to go through your logs, so it will probably be some time tomorrow morning before I get back to you.
User avatar
Gary R
Administrator
Administrator
 
Posts: 21872
Joined: June 28th, 2005, 11:36 am
Location: Yorkshire

Re: Every program crashing and getting Blue Screen

Unread postby Eldest » February 26th, 2013, 6:46 pm

No problem Gary, really appreciate the help.
Eldest
Regular Member
 
Posts: 26
Joined: February 19th, 2013, 3:50 pm

Re: Every program crashing and getting Blue Screen

Unread postby Gary R » February 27th, 2013, 5:55 am

Nothing in your latest logs to suggest there is a Malware related reason for your computer to crash so often. However your C:\ drive still needs some disk space freeing up, at the moment it's about 9%, and it really needs at least 15% free space, and preferably 20%. This alone may be the source of your problems.

Drive C: | 119,14 Gb Total Space | 11,05 Gb Free Space | 9,27% Space Free | Partition Type: NTFS


Your latest Minidump file shows pretty much the same reason for the crash as the last one ....

Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.

Loading Dump File [C:\Windows\Minidump\022613-7987-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.18044.amd64fre.win7sp1_gdr.130104-1431
Machine Name:
Kernel base = 0xfffff800`0300e000 PsLoadedModuleList = 0xfffff800`03252670
Debug session time: Tue Feb 26 16:29:41.882 2013 (UTC + 0:00)
System Uptime: 0 days 23:22:48.710
Loading Kernel Symbols
...............................................................
................................................................
.............................
Loading User Symbols
Loading unloaded module list
.............
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1A, {41790, fffffa80055a50b0, ffff, 0}

Probably caused by : win32k.sys ( win32k!SURFACE::bDeleteSurface+3c8 )

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041790, The subtype of the bugcheck.
Arg2: fffffa80055a50b0
Arg3: 000000000000ffff
Arg4: 0000000000000000

Debugging Details:
------------------

BUGCHECK_STR: 0x1a_41790

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

PROCESS_NAME: chrome.exe

CURRENT_IRQL: 0

LAST_CONTROL_TRANSFER: from fffff800030f4e10 to fffff80003083c40

STACK_TEXT:
fffff880`0a93b0b8 fffff800`030f4e10 : 00000000`0000001a 00000000`00041790 fffffa80`055a50b0 00000000`0000ffff : nt!KeBugCheckEx
fffff880`0a93b0c0 fffff800`0307042f : fffffa80`00000000 00000000`0b1b5fff 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x35084
fffff880`0a93b280 fffff800`03082ed3 : ffffffff`ffffffff fffff880`0a93b550 fffff880`0a93b5b8 00000000`00008000 : nt!NtFreeVirtualMemory+0x61f
fffff880`0a93b380 fffff800`0307f490 : fffff960`001170e4 00000000`00000001 00000000`00000000 fffff900`c42552e0 : nt!KiSystemServiceCopyEnd+0x13
fffff880`0a93b518 fffff960`001170e4 : 00000000`00000001 00000000`00000000 fffff900`c42552e0 00000000`00000001 : nt!KiServiceLinkage
fffff880`0a93b520 fffff960`0011f389 : 00000000`00000000 fffff880`00000001 fffff900`c42552e0 fffff900`00000000 : win32k!SURFACE::bDeleteSurface+0x3c8
fffff880`0a93b670 fffff960`00116920 : 00000000`000015b8 fffff880`0a93ba00 fffff900`c4554ce0 fffff880`00000000 : win32k!NtGdiCloseProcess+0x2c9
fffff880`0a93b6d0 fffff960`0011605f : 00000000`00000000 fffff880`0a93bae0 fffffa80`0f6ccb50 00000000`00000000 : win32k!GdiProcessCallout+0x200
fffff880`0a93b750 fffff800`0335bfc1 : 00000000`00000000 00000000`00000000 00000000`00000000 fffffa80`0f6ccb00 : win32k!W32pProcessCallout+0x6b
fffff880`0a93b780 fffff800`0334215d : 00000000`c0000005 00000000`00000101 00000000`78457300 fffffa80`0e9f6060 : nt!PspExitThread+0x4d1
fffff880`0a93b880 fffff800`0307675a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!PsExitSpecialApc+0x1d
fffff880`0a93b8b0 fffff800`03076aa0 : 00000000`00000246 fffff880`0a93b930 fffff800`033420d0 00000000`00000001 : nt!KiDeliverApc+0x2ca
fffff880`0a93b930 fffff800`03082f77 : 00000000`00000000 fffff8a0`0c822a00 00000000`746c6644 fffff8a0`0c822a00 : nt!KiInitiateUserApc+0x70
fffff880`0a93ba70 00000000`734d2e09 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x9c
00000000`024eee58 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x734d2e09

STACK_COMMAND: kb

FOLLOWUP_IP:
win32k!SURFACE::bDeleteSurface+3c8
fffff960`001170e4 e9b0010000 jmp win32k!SURFACE::bDeleteSurface+0x57d (fffff960`00117299)

SYMBOL_STACK_INDEX: 5

SYMBOL_NAME: win32k!SURFACE::bDeleteSurface+3c8

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: win32k

IMAGE_NAME: win32k.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 50e64bda

FAILURE_BUCKET_ID: X64_0x1a_41790_win32k!SURFACE::bDeleteSurface+3c8

BUCKET_ID: X64_0x1a_41790_win32k!SURFACE::bDeleteSurface+3c8

Followup: MachineOwner
---------



At this point I think your problems are caused by either hardware problems, or by system software corruption, neither of which is the province of this forum. We specialise solely in removing Malware, and as far as I can see there's no active Malware on your computer.

So, you have a couple of options ....

  • Backup your personal files and folders, then reformat your hard drive and re-install Windows.
  • I can hand you over to people who specialise in troubleshooting hardware and software issues.

Below (in no order of preferance) are a list of forums that specialise in hardware and software issues ...

http://www.bleepingcomputer.com/forums/f/167/windows-7/
http://www.bleepingcomputer.com/forums/ ... -hardware/

http://forums.whatthetech.com/index.php?showforum=119
http://forums.whatthetech.com/index.php?showforum=126

http://www.geekstogo.com/forum/forum/79 ... windows-7/
http://www.geekstogo.com/forum/forum/9- ... ripherals/

... the quality of help at each is usually of a high standard.

If any of them ask if you've checked your computer for Malware, please feel free to refer them to this topic.

I don't want you to feel that I'm deserting you, I'm just trying to direct you to what I believe is the quickest resolution to your problems. Hardware and Software problems are outside my areas of experience, and aside from the few basic checks I've had you run, the amount of help I can give is fairly limited. I believe it's better for you to be helped by people who specialise in those areas.

Before we finish here, I just want to give you some instructions for safely removing the programs we've used on your computer (if you haven't already removed them) ....

First

Let's clear out OTL and the files and folders it created. This will also remove GMER (apart from the randomly named file on your desktop)
  • Double click OTL.exe to launch the programme.
  • Click on the CleanUp! button.
  • OTL will download a list from the Internet, if your firewall or other defensive programmes alerts you, allow it access.
  • You will be prompted to allow the clean up procedure, click Yes
  • When finished exit out of OTL
  • Now delete OTL.exe (if still present).

Next

Please delete ...
JRT.exe
JRT.txt
VEW.exe
MiniToolbox.exe


Next

Please go to Control Panel > Programs > Uninstall a program and Uninstall the following:

Tweaking.com Registry Backup
User avatar
Gary R
Administrator
Administrator
 
Posts: 21872
Joined: June 28th, 2005, 11:36 am
Location: Yorkshire

Re: Every program crashing and getting Blue Screen

Unread postby Eldest » February 27th, 2013, 10:23 am

Hey Gary.

I've followed your instructions and removed the tools.

I wanted to thank you for the help sofar, I understand that much of the help was outside of your expertise and it's really appreciated that you went that far anyway. Thus I also understand that you need to point me somewhere else. And of course I want to say thanks for helping me clean out my computer.

I'll move on to some of the other forums and see if I can get any help there, otherwise I'll have to reformat.

Thanks alot for your time.
Eldest
Regular Member
 
Posts: 26
Joined: February 19th, 2013, 3:50 pm

Re: Every program crashing and getting Blue Screen

Unread postby Gary R » February 27th, 2013, 11:29 am

You're welcome, sorry I was unable to do more. :)

Good luck in getting your problem resolved.

Gary

This topic is now closed.
User avatar
Gary R
Administrator
Administrator
 
Posts: 21872
Joined: June 28th, 2005, 11:36 am
Location: Yorkshire
Advertisement
Register to Remove

Previous

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: random/random and 72 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware