This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Win32:Rootkit-gen[Rtk]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hello.. i hope someone can help me with this! i a very VERY inexperienced with computers.. so i'll need a lot of help :( i don't know how, but somehow i got this virus. i ran avast! and it found it. i clicked repair but it comes up with a message saying the file was not repaired. right now it is in the 'virus chest'. it is called a Win32:Rootkit-gen[Rtk]. it's messing up my computer really bad. i cannot open the internet at all. my computer died by accident and i had to recharge and restart it. before it shut down, when i tried to open anything, i would get a message saying it cannot open the program because it has a virus. now, after i restarted, when i try and open anything, like internet explorer, firefox, google chrome, itunes, skype, etc. i get a box with a message saying open with: choose the program you want to open this file with: and it has recommended programs, and under says internet explorer. but nothing opens. somehow i managed to get on firefox though so i've just been keeping it running and not closing it. that's how i'm online now. my friend told me another antivirus thing to download but i cannot download anything either. the virus showed up as one of those fake spyware removal ads i think. it was called something like Vaio Antivirus Pro 2010. please help.. i'm very lost! thank you, mollie
Hello there, mollie

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

**In any case where you happen to be busy or unable to give us a reply, we would be more than grateful if you keep us informed in advance and we will be more than happy to wait. :)
Hi,

Do you have access to another computer & a flash drive? This way you can download any tools we may need & transfer them to your infected computer until we can get back on line. If so do the following:

Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)

===================================================

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

On your next reply please post :
exeHelper log
OTL log
GMER log

Good Day!
Hi! Thank you so much; I really appreciate this :) Unfortunately I don't have access to another computer that I can download things on & transfer them to a flash drive. However the exeHelper download worked :) exeHelper by Raktor Build 20091220 Run at 14:17:48 on 03/11/10 Now searching… Checking for numerical processes… Checking for sysguard processes… Checking for bad processes… Checking for bad files… Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished– The OTL won't open, that box comes up again and recommends I open it with Avast. And when I try to extract files from the GMER Rootkit Scanner, it says they cannot be executed.
Hi,

If you have an active internet connection, copy/paste the links below into your browser, don't click them or the rogue might redirect. If you don't have an active internet connection, download the tools from another machine, and transfer them to the affected machine via USB flash drive.


Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 4 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.


http://download.bleepingcomputer.com/grinler/rkill.exe
http://download.bleepingcomputer.com/grinler/rkill.com
http://download.bleepingcomputer.com/grinler/rkill.scr
http://download.bleepingcomputer.com/grinler/rkill.pif


Note:

You will likely see a message from this rogue telling you the file is infected. Ignore the message. Leave the message OPEN, do not close the message. Run rkill repeatedly until it's able to do it's job. This may take a few tries. You'll be able to tell rkill has done it's job when your desktop (explorer.exe) cycles off and then on again.

At this point, you should now be able to run analysis tools.

Once the tool has run, do NOT reboot the machine, and then try once again to run OTL and GMER.

If for some reason the machine reboots, repeat the process. Again, try not to restart the machine.
The second link worked :)

OTL.txt

OTL logfile created on: 3/13/2010 4:07:46 AM - Run 1
OTL by OldTimer - Version 3.1.37.0 Folder = C:\Users\Mollz\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 56.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 222.78 Gb Total Space | 127.44 Gb Free Space | 57.20% Space Free | Partition Type: NTFS
Drive D: | 122.41 Mb Total Space | 111.73 Mb Free Space | 91.28% Space Free | Partition Type: FAT
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MOLLZ-PC
Current User Name: Mollz
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Mollz\Downloads\OTL(2).exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Google\Update\1.2.183.17\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Program Files (x86)\Microsoft Windows OneCare Live\winss.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Windows OneCare Live\winssnotify.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Windows OneCare Live\OcHealthMon.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
PRC - C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects\Magic-i Visual Effects.exe (ArcSoft, Inc.)
PRC - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
PRC - C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\Mollz\Downloads\OTL(2).exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV:64bit: - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV:64bit: - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV:64bit: - (VAIO Power Management) – C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Sony Corporation)
SRV:64bit: - (OneCareMP) – C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (VcmIAlzMgr) – C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe (Sony Corporation)
SRV:64bit: - (VcmXmlIfHelper) – C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe (Sony Corporation)
SRV:64bit: - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV:64bit: - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV:64bit: - (XAudioService) – C:\Windows\SysNative\DRIVERS\xaudio64.exe ()
SRV:64bit: - (BthServ) – C:\Windows\SysNative\bthserv.dll ()
SRV:64bit: - (usprserv) – C:\Windows\SysNative\svchost.exe ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (winss) – C:\Program Files (x86)\Microsoft Windows OneCare Live\winss.exe (Microsoft Corporation)
SRV - (OcHealthMon) – C:\Program Files (x86)\Microsoft Windows OneCare Live\OcHealthMon.exe (Microsoft Corporation)
SRV - (WinHttpAutoProxySvc) – winhttp.dll (Microsoft Corporation)
SRV - (VAIO Event Service) – C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (RtkAudioService) – C:\Windows\RTKAUDIOSERVICE.EXE (Realtek Semiconductor)
SRV - (VCFw) – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation)
SRV - (Vcsw) – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
SRV - (VzCdbSvc) – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
SRV - (VAIO Entertainment TV Device Arbitration Service) – C:\Program Files (x86)\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe (Sony Corporation)
SRV - (SOHDms) – C:\Program Files (x86)\Sony\VAIO Media plus\SOHDms.exe (Sony Corporation)
SRV - (SOHCImp) – C:\Program Files (x86)\Sony\VAIO Media plus\SOHCImp.exe (Sony Corporation)
SRV - (SOHDs) – C:\Program Files (x86)\Sony\VAIO Media plus\SOHDs.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (MSCSPTISRV) – C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (uCamMonitor) – C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe (ArcSoft, Inc.)
SRV - (msfwsvc) – C:\Program Files (x86)\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe (Microsoft Corporation)
SRV - (QBCFMonitorService) – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (QBFCService) – C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (IviRegMgr) – C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
SRV - (Viewpoint Manager Service) – C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2006/11/02 08:34:14 | 000,000,000 | —D | M]
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (VSS) – C:\Windows\SysWOW64\wbem\vss.mof ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys ()
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys ()
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr.sys ()
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys ()
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys ()
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys ()
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys ()
DRV:64bit: - (IntcHdmiAddService) Intel® – C:\Windows\SysNative\drivers\IntcHdmi.sys ()
DRV:64bit: - (igfx) – C:\Windows\SysNative\DRIVERS\igdkmd64.sys ()
DRV:64bit: - (btwrchid) – C:\Windows\SysNative\DRIVERS\btwrchid.sys ()
DRV:64bit: - (btwavdt) – C:\Windows\SysNative\drivers\btwavdt.sys ()
DRV:64bit: - (btwaudio) – C:\Windows\SysNative\drivers\btwaudio.sys ()
DRV:64bit: - (btwl2cap) – C:\Windows\SysNative\DRIVERS\btwl2cap.sys ()
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys ()
DRV:64bit: - (RTHDMIAzAudService) – C:\Windows\SysNative\drivers\RtHDMIVX.sys ()
DRV:64bit: - (ApfiltrService) – C:\Windows\SysNative\DRIVERS\Apfiltr.sys ()
DRV:64bit: - (risdptsk) – C:\Windows\SysNative\DRIVERS\risdsn64.sys ()
DRV:64bit: - (adfs) – C:\Windows\SysNative\drivers\adfs.sys ()
DRV:64bit: - (rimsptsk) – C:\Windows\SysNative\DRIVERS\rimssn64.sys ()
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\DRIVERS\wimfltr.sys ()
DRV:64bit: - (iaStor) – C:\Windows\SysNative\DRIVERS\iaStor.sys ()
DRV:64bit: - (NETw5v64) Intel® – C:\Windows\SysNative\DRIVERS\NETw5v64.sys ()
DRV:64bit: - (yukonx64) – C:\Windows\SysNative\DRIVERS\yk60x64.sys ()
DRV:64bit: - (XAudio) – C:\Windows\SysNative\DRIVERS\xaudio64.sys ()
DRV:64bit: - (HSF_DPV) – C:\Windows\SysNative\DRIVERS\CAX_DPV.sys ()
DRV:64bit: - (mdmxsdk) – C:\Windows\SysNative\DRIVERS\mdmxsdk.sys ()
DRV:64bit: - (winachsf) – C:\Windows\SysNative\DRIVERS\CAX_CNXT.sys ()
DRV:64bit: - (CAXHWAZL) – C:\Windows\SysNative\DRIVERS\CAXHWAZL.sys ()
DRV:64bit: - (BTHPORT) – C:\Windows\SysNative\Drivers\BTHport.sys ()
DRV:64bit: - (RFCOMM) Bluetooth Device (RFCOMM Protocol TDI) – C:\Windows\SysNative\DRIVERS\rfcomm.sys ()
DRV:64bit: - (BthEnum) – C:\Windows\SysNative\DRIVERS\BthEnum.sys ()
DRV:64bit: - (BTHUSB) – C:\Windows\SysNative\Drivers\BTHUSB.sys ()
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\Drivers\PxHlpa64.sys ()
DRV:64bit: - (SFEP) – C:\Windows\SysNative\DRIVERS\SFEP.sys ()
DRV:64bit: - (ArcSoftKsUFilter) – C:\Windows\SysNative\DRIVERS\ArcSoftKsUFilter.sys ()
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys ()
DRV:64bit: - (usbvideo) USB Video Device (WDM) – C:\Windows\SysNative\Drivers\usbvideo.sys ()
DRV:64bit: - (usbaudio) USB Audio Driver (WDM) – C:\Windows\SysNative\drivers\usbaudio.sys ()
DRV:64bit: - (BthPan) Bluetooth Device (Personal Area Network) – C:\Windows\SysNative\DRIVERS\bthpan.sys ()
DRV:64bit: - (HSFHWAZL) – C:\Windows\SysNative\DRIVERS\VSTAZL6.SYS ()
DRV:64bit: - (sdbus) – C:\Windows\SysNative\DRIVERS\sdbus.sys ()
DRV:64bit: - (CmBatt) – C:\Windows\SysNative\DRIVERS\CmBatt.sys ()
DRV:64bit: - (MSFWDrv) – C:\Windows\SysNative\DRIVERS\msfwdrv.sys ()
DRV:64bit: - (MSFWHLPR) – C:\Windows\SysNative\DRIVERS\msfwhlpr.sys ()
DRV:64bit: - (HdAudAddService) – C:\Windows\SysNative\drivers\HdAudio.sys ()
DRV - (DMICall) – C:\Windows\SysWOW64\drivers\DMICall.sys (Sony Corporation)
DRV - (mdmxsdk) – C:\Windows\SysWOW64\mdmxsdk.dll (Conexant)
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
DRV - (NPPTNT2) – C:\Windows\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople_f08
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople_f08
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll (AOL LLC.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople_f08
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sony.com/vaiopeople_f08
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll (AOL LLC.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AIM Search"
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrie7&query;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {000a9d1c-beef-4f90-9363-039d445309b8}:0.5.36.0
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrab&query;="


FF - HKLM\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files (x86)\Google\Google Gears\Firefox\ [2010/03/05 20:03:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/02/20 19:31:28 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/02/20 19:31:28 | 000,000,000 | —D | M]

[2009/06/26 15:51:15 | 000,000,000 | —D | M] – C:\Users\Mollz\AppData\Roaming\Mozilla\Extensions
[2009/06/26 15:51:15 | 000,000,000 | —D | M] – C:\Users\Mollz\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/03/12 12:51:18 | 000,000,000 | —D | M] – C:\Users\Mollz\AppData\Roaming\Mozilla\Firefox\Profiles\jw444m61.default\extensions
[2009/09/02 16:44:31 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Mollz\AppData\Roaming\Mozilla\Firefox\Profiles\jw444m61.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/07/20 16:54:06 | 000,004,207 | —- | M] () – C:\Users\Mollz\AppData\Roaming\Mozilla\Firefox\Profiles\jw444m61.default\searchplugins\aim-search.xml
[2009/03/23 22:08:39 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2007/04/16 12:07:12 | 000,180,293 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\plugins\npViewpoint.dll

O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AOL Toolbar BHO) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files (x86)\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll (AOL LLC.)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files (x86)\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files (x86)\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKCU\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files (x86)\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O4:64bit: - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe ()
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe ()
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AML] C:\Program Files (x86)\Sony\VAIO Launcher\AML.exe (Sony)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [OneCareUI] C:\Program Files (x86)\Microsoft Windows OneCare Live\winssnotify.exe (Microsoft Corporation)
O4 - HKLM..\Run: [SmartWiHelper] C:\Program Files\Sony Corporation\SmartWi Connection Utility\SmartWiHelper.exe (Sony Electronics Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Java\jre1.6.0\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [VAIOMyMemCenter] C:\Program Files\Sony\VAIO My Memory Center\VAIO MyMemCenter.exe File not found
O4 - HKLM..\Run: [VAIORegistration] C:\Program Files\Sony\First Experience\WelcomeLauncher.exe (Sony Electronics, Inc.)
O4 - HKLM..\Run: [VAIOSurvey] C:\Program Files (x86)\Sony\VAIO Survey\VAIO Sat Survey.exe ()
O4 - HKLM..\Run: [VWLASU] C:\Program Files\Sony\VAIO Wireless Wizard\AutoLaunchWLASU.exe (Sony Electronics, Inc.)
O4 - HKCU..\Run: [Aim6] File not found
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Mollz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O8:64bit: - Extra context menu item: &AIM; Toolbar Search - C:\ProgramData\AIM Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8:64bit: - Extra context menu item: &AOL; Toolbar Search - C:\ProgramData\AOL\ieToolbar\resources\en-US\local\search.html ()
O8:64bit: - Extra context menu item: Send image to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Send page to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: &AIM; Toolbar Search - C:\ProgramData\AIM Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: &AOL; Toolbar Search - C:\ProgramData\AOL\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: Send image to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : &Gears; Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files (x86)\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O9 - Extra Button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll (AOL LLC.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth; Device… - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysNative\wshbth.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysWOW64\wshbth.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\intu-help-qb1 {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\qbwc {FC598A64-626C-4447-85B8-53150405FD57} - Reg Error: Key error. File not found
O18 - Protocol\Handler\intu-help-qb1 {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - C:\Program Files (x86)\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll (TODO: )
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\qbwc {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - Explorer.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll ()
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - VESWinlogon.dll (Sony Corporation)
O24 - Desktop WallPaper: C:\Users\Mollz\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Mollz\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{a254a793-d289-11dd-a6fd-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{a254a793-d289-11dd-a6fd-806e6f6e6963}\Shell\AutoRun\command - "" = F:\autorun.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: Ias - C:\Windows\SysNative\ias [2008/01/20 22:06:38 | 000,000,000 | —D | M]
NetSvcs:64bit: Irmon - C:\Windows\SysNative\irmon.dll ()
NetSvcs:64bit: Wmi - C:\Windows\SysNative\wmi.dll ()
NetSvcs: Ias - C:\Windows\SysWOW64\ias [2008/01/20 22:08:35 | 000,000,000 | —D | M]
NetSvcs: Wmi - C:\Windows\SysWOW64\wmi.dll (Microsoft Corporation)

========== Files/Folders - Created Within 30 Days ==========

[2010/03/11 03:02:47 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\nshhttp.dll
[2010/03/11 03:02:39 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\httpapi.dll
[2010/02/23 20:03:46 | 000,523,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_isv.exe
[2010/02/23 20:03:45 | 000,511,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate.exe
[2010/02/23 20:03:41 | 000,347,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_ssp.exe
[2010/02/23 20:03:40 | 000,346,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2010/02/23 20:03:39 | 000,472,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc.dll
[2010/02/23 20:03:38 | 000,472,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_isv.dll
[2010/02/23 20:03:37 | 000,151,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_ssp.dll
[2010/02/23 20:03:36 | 000,329,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msdrm.dll
[2010/02/23 20:03:36 | 000,151,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\secproc_ssp_isv.dll
[2010/02/15 18:48:16 | 000,000,000 | —D | C] – C:\Users\Mollz\Documents\Downloads
[2010/02/15 18:37:04 | 000,153,184 | —- | C] (ALWIL Software) – C:\Windows\SysWow64\aswBoot.exe
[2010/02/15 18:37:04 | 000,038,848 | —- | C] (ALWIL Software) – C:\Windows\SysWow64\avastSS.scr
[2010/02/15 18:36:44 | 000,000,000 | —D | C] – C:\ProgramData\Alwil Software
[2010/02/15 18:36:44 | 000,000,000 | —D | C] – C:\Program Files\Alwil Software
[2010/02/15 13:33:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG
[2010/02/15 13:32:48 | 000,000,000 | —D | C] – C:\ProgramData\avg9

========== Files - Modified Within 30 Days ==========

[2010/03/13 04:03:01 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/13 03:50:16 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/03/12 21:38:58 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/03/12 21:38:57 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/03/12 13:16:31 | 000,001,074 | —- | M] () – C:\Users\Mollz\AppData\Roaming\wklnhst.dat
[2010/03/11 17:01:52 | 002,359,296 | -HS- | M] () – C:\Users\Mollz\ntuser.dat
[2010/03/11 03:29:25 | 000,690,960 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/03/11 03:29:25 | 000,595,684 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/03/11 03:29:25 | 000,101,350 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/03/11 03:22:34 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/11 03:21:12 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/03/11 03:20:17 | 4126,179,328 | -HS- | M] () – C:\hiberfil.sys
[2010/03/11 03:19:20 | 000,000,012 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/03/11 03:19:11 | 000,524,288 | -HS- | M] () – C:\Users\Mollz\ntuser.dat{1d670677-ecc6-11de-aad5-00214f580bde}.TMContainer00000000000000000001.regtrans-ms
[2010/03/11 03:19:11 | 000,065,536 | -HS- | M] () – C:\Users\Mollz\ntuser.dat{1d670677-ecc6-11de-aad5-00214f580bde}.TM.blf
[2010/03/11 03:19:10 | 003,209,365 | -H– | M] () – C:\Users\Mollz\AppData\Local\IconCache.db
[2010/03/10 21:18:06 | 000,076,066 | —- | M] () – C:\Users\Mollz\Desktop\molli.JPG
[2010/03/10 19:31:38 | 000,990,440 | —- | M] () – C:\Users\Mollz\Desktop\whyiseassasocute.jpg
[2010/03/09 19:08:01 | 000,059,828 | —- | M] () – C:\Users\Mollz\Desktop\80801360.jpg
[2010/03/06 19:57:36 | 000,010,766 | -HS- | M] () – C:\Users\Mollz\AppData\Local\fXsMq7BWv
[2010/03/05 19:55:43 | 000,064,715 | —- | M] () – C:\Users\Mollz\Desktop\draft_lens3130832module19807662photo_1236608494redneck_pool_safety_Please_n
ote_the_power_strip_between_the_two_flip_flops_hazard.jpeg
[2010/03/05 19:54:01 | 000,026,194 | —- | M] () – C:\Users\Mollz\Desktop\demotivationposter8.jpg
[2010/03/05 19:53:25 | 000,064,411 | —- | M] () – C:\Users\Mollz\Desktop\att1395137.jpg
[2010/03/05 19:50:03 | 000,040,436 | —- | M] () – C:\Users\Mollz\Desktop\FROHAT.jpg
[2010/03/03 22:35:46 | 000,092,229 | —- | M] () – C:\Users\Mollz\Desktop\jesticles.jpg
[2010/03/03 22:13:02 | 000,083,214 | —- | M] () – C:\Users\Mollz\Desktop\eassaloaf.jpg
[2010/03/03 21:02:20 | 000,091,433 | —- | M] () – C:\Users\Mollz\Desktop\sketchyme.jpg
[2010/03/03 19:07:11 | 000,229,762 | —- | M] () – C:\Users\Mollz\Desktop\eassaportrait.jpg
[2010/02/27 14:29:06 | 000,008,704 | —- | M] () – C:\Users\Mollz\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/27 11:43:24 | 000,026,524 | —- | M] () – C:\Users\Mollz\Desktop\mee.jpg
[2010/02/25 20:56:54 | 000,000,544 | —- | M] () – C:\Users\Mollz\Desktop\lololol - Shortcut.lnk
[2010/02/24 22:58:08 | 000,778,820 | —- | M] () – C:\Users\Mollz\Desktop\1264514357326.gif
[2010/02/24 22:55:23 | 000,026,766 | —- | M] () – C:\Users\Mollz\Desktop\2.jpg
[2010/02/24 22:51:27 | 000,022,951 | —- | M] () – C:\Users\Mollz\Desktop\mummies5.jpg
[2010/02/24 06:18:40 | 000,084,168 | —- | M] () – C:\Users\Mollz\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/02/24 06:17:16 | 002,947,168 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/02/20 18:44:53 | 000,032,768 | —- | M] () – C:\Windows\SysNative\nshhttp.dll
[2010/02/20 18:42:16 | 000,033,792 | —- | M] () – C:\Windows\SysNative\httpapi.dll
[2010/02/20 18:39:35 | 000,024,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\nshhttp.dll
[2010/02/20 18:37:20 | 000,031,232 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\httpapi.dll
[2010/02/15 18:38:42 | 000,002,025 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2010/02/15 18:38:09 | 000,001,796 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/02/15 18:38:07 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2010/02/11 13:53:57 | 000,038,848 | —- | M] (ALWIL Software) – C:\Windows\SysWow64\avastSS.scr
[2010/02/11 13:53:36 | 000,153,184 | —- | M] (ALWIL Software) – C:\Windows\SysWow64\aswBoot.exe
[2010/02/11 13:42:38 | 000,051,280 | —- | M] () – C:\Windows\SysNative\drivers\aswTdi.sys
[2010/02/11 13:42:19 | 000,120,912 | —- | M] () – C:\Windows\SysNative\drivers\aswSP.sys
[2010/02/11 13:39:04 | 000,028,752 | —- | M] () – C:\Windows\SysNative\drivers\aswRdr.sys
[2010/02/11 13:38:49 | 000,063,568 | —- | M] () – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2010/02/11 13:38:25 | 000,022,096 | —- | M] () – C:\Windows\SysNative\drivers\aswFsBlk.sys

========== Files Created - No Company Name ==========

[2010/03/11 03:02:48 | 000,032,768 | —- | C] () – C:\Windows\SysNative\nshhttp.dll
[2010/03/11 03:02:41 | 000,610,304 | —- | C] () – C:\Windows\SysNative\drivers\http.sys
[2010/03/11 03:02:40 | 000,033,792 | —- | C] () – C:\Windows\SysNative\httpapi.dll
[2010/03/10 21:17:18 | 000,076,066 | —- | C] () – C:\Users\Mollz\Desktop\molli.JPG
[2010/03/10 19:31:37 | 000,990,440 | —- | C] () – C:\Users\Mollz\Desktop\whyiseassasocute.jpg
[2010/03/09 19:08:00 | 000,059,828 | —- | C] () – C:\Users\Mollz\Desktop\80801360.jpg
[2010/03/05 22:43:26 | 000,010,766 | -HS- | C] () – C:\Users\Mollz\AppData\Local\fXsMq7BWv
[2010/03/05 19:55:43 | 000,064,715 | —- | C] () – C:\Users\Mollz\Desktop\draft_lens3130832module19807662photo_1236608494redneck_pool_safety_Please_n
ote_the_power_strip_between_the_two_flip_flops_hazard.jpeg
[2010/03/05 19:54:01 | 000,026,194 | —- | C] () – C:\Users\Mollz\Desktop\demotivationposter8.jpg
[2010/03/05 19:53:25 | 000,064,411 | —- | C] () – C:\Users\Mollz\Desktop\att1395137.jpg
[2010/03/05 19:50:03 | 000,040,436 | —- | C] () – C:\Users\Mollz\Desktop\FROHAT.jpg
[2010/03/03 22:35:45 | 000,092,229 | —- | C] () – C:\Users\Mollz\Desktop\jesticles.jpg
[2010/03/03 22:13:02 | 000,083,214 | —- | C] () – C:\Users\Mollz\Desktop\eassaloaf.jpg
[2010/03/03 21:02:20 | 000,091,433 | —- | C] () – C:\Users\Mollz\Desktop\sketchyme.jpg
[2010/03/03 19:07:11 | 000,229,762 | —- | C] () – C:\Users\Mollz\Desktop\eassaportrait.jpg
[2010/02/27 11:43:24 | 000,026,524 | —- | C] () – C:\Users\Mollz\Desktop\mee.jpg
[2010/02/25 20:56:54 | 000,000,544 | —- | C] () – C:\Users\Mollz\Desktop\lololol - Shortcut.lnk
[2010/02/24 22:58:03 | 000,778,820 | —- | C] () – C:\Users\Mollz\Desktop\1264514357326.gif
[2010/02/24 22:55:23 | 000,026,766 | —- | C] () – C:\Users\Mollz\Desktop\2.jpg
[2010/02/24 22:51:26 | 000,022,951 | —- | C] () – C:\Users\Mollz\Desktop\mummies5.jpg
[2010/02/23 20:06:25 | 000,002,048 | —- | C] () – C:\Windows\SysNative\tzres.dll
[2010/02/23 20:03:52 | 000,594,432 | —- | C] () – C:\Windows\SysNative\RMActivate.exe
[2010/02/23 20:03:51 | 000,594,944 | —- | C] () – C:\Windows\SysNative\RMActivate_isv.exe
[2010/02/23 20:03:43 | 000,413,696 | —- | C] () – C:\Windows\SysNative\RMActivate_ssp_isv.exe
[2010/02/23 20:03:42 | 000,409,600 | —- | C] () – C:\Windows\SysNative\RMActivate_ssp.exe
[2010/02/23 20:03:40 | 000,534,016 | —- | C] () – C:\Windows\SysNative\secproc_isv.dll
[2010/02/23 20:03:39 | 000,535,040 | —- | C] () – C:\Windows\SysNative\secproc.dll
[2010/02/23 20:03:37 | 000,159,232 | —- | C] () – C:\Windows\SysNative\secproc_ssp_isv.dll
[2010/02/23 20:03:37 | 000,158,720 | —- | C] () – C:\Windows\SysNative\secproc_ssp.dll
[2010/02/23 20:03:36 | 000,457,216 | —- | C] () – C:\Windows\SysNative\msdrm.dll
[2010/02/15 18:38:42 | 000,002,025 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2010/02/15 18:38:09 | 000,001,796 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/02/15 18:38:08 | 000,120,912 | —- | C] () – C:\Windows\SysNative\drivers\aswSP.sys
[2010/02/15 18:38:08 | 000,051,280 | —- | C] () – C:\Windows\SysNative\drivers\aswTdi.sys
[2010/02/15 18:38:08 | 000,028,752 | —- | C] () – C:\Windows\SysNative\drivers\aswRdr.sys
[2010/02/15 18:38:08 | 000,022,096 | —- | C] () – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2010/02/15 18:38:07 | 000,063,568 | —- | C] () – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2010/02/15 18:38:07 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\config.nt
[2010/02/15 18:37:33 | 000,422,232 | —- | C] () – C:\Users\Mollz\AppData\Local\dd_vcredistMSI0C06.txt
[2010/02/15 18:37:32 | 000,012,466 | —- | C] () – C:\Users\Mollz\AppData\Local\dd_vcredistUI0C06.txt
[2009/09/07 18:52:27 | 000,000,680 | —- | C] () – C:\Users\Mollz\AppData\Local\d3d9caps.dat
[2009/08/31 23:14:48 | 000,386,674 | —- | C] () – C:\Users\Mollz\AppData\Local\dd_vcredistMSI19E5.txt
[2009/08/31 23:14:48 | 000,011,156 | —- | C] () – C:\Users\Mollz\AppData\Local\dd_vcredistUI19E5.txt
[2009/01/08 01:56:34 | 000,570,406 | —- | C] () – C:\Users\Mollz\AppData\Local\dd_vcredistMSI0E48.txt
[2009/01/08 01:56:31 | 000,014,368 | —- | C] () – C:\Users\Mollz\AppData\Local\dd_vcredistUI0E48.txt
[2009/01/04 16:50:23 | 000,001,074 | —- | C] () – C:\Users\Mollz\AppData\Roaming\wklnhst.dat
[2008/12/25 17:31:44 | 000,008,704 | —- | C] () – C:\Users\Mollz\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/08/29 21:50:13 | 000,000,000 | —- | C] () – C:\Windows\VAIOUpdt.INI
[2008/01/20 21:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/01/20 21:49:49 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll

========== LOP Check ==========

[2009/04/12 12:46:31 | 000,000,000 | —D | M] – C:\Users\Mollz\AppData\Roaming\acccore
[2008/12/27 18:59:37 | 000,000,000 | —D | M] – C:\Users\Mollz\AppData\Roaming\InterVideo
[2010/02/07 17:59:08 | 000,000,000 | —D | M] – C:\Users\Mollz\AppData\Roaming\LimeWire
[2009/11/30 19:31:35 | 000,000,000 | —D | M] – C:\Users\Mollz\AppData\Roaming\Music Recognition
[2008/12/30 16:53:32 | 000,000,000 | —D | M] – C:\Users\Mollz\AppData\Roaming\Nexon
[2008/12/30 12:17:17 | 000,000,000 | —D | M] – C:\Users\Mollz\AppData\Roaming\SecondLife
[2009/01/04 16:50:27 | 000,000,000 | —D | M] – C:\Users\Mollz\AppData\Roaming\Template
[2010/03/11 03:19:18 | 000,032,574 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2007/11/07 07:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe


< MD5 for: AGP440.SYS >
[2008/01/20 21:46:51 | 000,064,568 | —- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008/01/20 21:46:51 | 000,064,568 | —- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys

< MD5 for: ATAPI.SYS >
[2008/01/20 21:46:50 | 000,022,584 | —- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2009/04/11 02:15:00 | 000,020,952 | —- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 – C:\Windows\SoftwareDistribution\Download\d15e0adcf011f7a00bde2023e8b74a00\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 06:16:48 | 000,014,848 | —- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006/11/02 04:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 04:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 04:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: IASTOR.SYS >
[2008/04/29 19:03:13 | 000,388,120 | —- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 – C:\Windows\Drivers\INF\SATA Driver (Intel) (Non-RAID)\IaStor.sys

< MD5 for: IASTORV.SYS >
[2008/01/20 21:46:59 | 000,290,872 | —- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2008/01/20 21:51:03 | 000,716,800 | —- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2009/04/11 01:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SoftwareDistribution\Download\d15e0adcf011f7a00bde2023e8b74a00\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009/04/11 02:11:16 | 000,717,312 | —- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB – C:\Windows\SoftwareDistribution\Download\d15e0adcf011f7a00bde2023e8b74a00\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008/01/20 21:48:28 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\SysWOW64\netlogon.dll
[2008/01/20 21:48:28 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\SysWOW64\netlogon.dll
[2008/01/20 21:48:28 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2008/01/20 21:46:54 | 000,054,328 | —- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008/01/20 21:50:28 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\SysWOW64\scecli.dll
[2008/01/20 21:50:28 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\SysWOW64\scecli.dll
[2008/01/20 21:50:28 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2008/01/20 21:49:49 | 000,235,520 | —- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2009/04/11 01:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SoftwareDistribution\Download\d15e0adcf011f7a00bde2023e8b74a00\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009/04/11 02:11:23 | 000,235,520 | —- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B – C:\Windows\SoftwareDistribution\Download\d15e0adcf011f7a00bde2023e8b74a00\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
< End of report >




Extras.Txt
OTL Extras logfile created on: 3/13/2010 4:07:47 AM - Run 1
OTL by OldTimer - Version 3.1.37.0 Folder = C:\Users\Mollz\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 56.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 222.78 Gb Total Space | 127.44 Gb Free Space | 57.20% Space Free | Partition Type: NTFS
Drive D: | 122.41 Mb Total Space | 111.73 Mb Free Space | 91.28% Space Free | Partition Type: FAT
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MOLLZ-PC
Current User Name: Mollz
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" ()
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l ()
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\iCall\iCall.exe" = C:\Program Files (x86)\iCall\iCall.exe:*:Enabled:iCall – File not found
"C:\Program Files (x86)\iCall\iCall.exe" = C:\Program Files (x86)\iCall\iCall.exe:*:Enabled:iCall – File not found


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1608C5EB-F021-44B8-AA39-D0A9A1E53C37}" = lport=2869 | protocol=6 | dir=in | app=system |
"{80D5277F-67E7-40AB-BE64-F837010408AD}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0897F53A-59D5-475A-9BB3-598CA748263D}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{1699CE71-C228-4DAC-8995-810A03CBDB36}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1D9834A9-0017-4CA9-B50A-4F87DA69569A}" = protocol=6 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"{32B64C4D-C91D-4383-9FEE-E92C57FC2829}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{39A12443-0CDC-4CB1-9BAF-BC361EA48219}" = protocol=6 | dir=in | app=c:\program files (x86)\aim6\aim6.exe |
"{3C670CD9-28E7-4E94-ABB6-D03CB4C73420}" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{4263693F-05AF-48B6-94A1-2EE0FCC6B259}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{43D33DF3-B7BD-4A5A-AC23-B3B90A0316BA}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{4E87202D-0258-45E6-8CCF-4BDC22ABA4FC}" = protocol=17 | dir=in | app=c:\program files (x86)\aim6\aim6.exe |
"{5EA30105-6C06-473C-8AA9-174DAC72DAF2}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{6DFBB25D-F53E-4278-9ECE-03DFB11BBE08}" = protocol=17 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{744DABDB-7FC7-410B-8648-5950C2243355}" = protocol=17 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"{97979725-72CA-4B34-990E-F34337C7A537}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{9F57BFF6-F576-4709-83CE-B0E2428B059D}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{A9FEB6AB-AA87-4547-A094-A1B005A78841}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{BF9BEBF9-6F2F-4ED4-BE49-567E98D24734}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{C038EEC0-C927-4E35-A119-92D75879E35B}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{DF58FA25-A810-45B1-9C81-C5CEF90D9C1E}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{F908DB88-6ABD-448A-8920-7D5A99AE1CD8}" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{FC472C33-843F-4FC3-A7D6-1A679CBF2D64}" = protocol=17 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{FCDCA6D8-0E91-46EF-AF41-449D5679C108}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{26921B2E-3E62-47F9-A514-1FC4A83BD738}" = Intel® PROSet/Wireless WiFi Software
"{5660022E-F3F2-4126-8CC5-9726C47150EB}" = Microsoft Windows Live OneCare Resources v2.5.2900.24
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9EFC40E3-5F31-4F75-8445-286273F74D8E}" = Apple Mobile Device Support
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Alps Pointing-device for VAIO
"{B812FCC0-6192-4BFA-A9C6-1E8578F255DA}" = iTunes
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D035FBF6-FDEF-487D-89CA-6F9DD07B783F}" = Dolby Control Center
"{D07A8E7E-D324-4945-BA8C-E532AD008FF3}" = Microsoft Windows OneCare Live v2.5.2900.24
"{D6F907C2-5264-4E01-B608-42A550378631}" = Microsoft Protection Service
"{DAE239CE-EB9D-4EB3-B0D4-528D6BAA48FD}" = Bonjour
"{E26B83D1-C0BB-41BC-8F44-31D5354DD6AF}" = Microsoft Windows OneCare Live AntiSpyware and AntiVirus
"{E464702F-5433-46EC-8F65-159276C0A54F}" = WIDCOMM Bluetooth Software 6.2.0.4500
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2BFA&SUBSYS;_104D0200" = HDAUDIO SoftV92 Data Fax Modem with SmartCP
"HDMI" = Intel® Graphics Media Accelerator Driver
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"ProInst" = Intel PROSet Wireless

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}" = Sony Video Shared Library
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Central Data
"{1316AEF2-E086-46C7-B1FB-8C9A39A2ABF9}" = VAIO Media plus
"{14291118-0C19-45EA-A4FA-5C1C0F5FDE09}" = Primo
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{15D5C238-4C2E-4AEA-A66D-D6989A4C586B}" = VAIO Launcher
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1B500D37-E7CF-480B-8054-8A563594EC4E}" = VAIO OOBE and Welcome Center
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Central Tools
"{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = WinDVD for VAIO
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{23825B69-36DF-4DAD-9CFD-118D11D80F16}" = VAIO Content Folder Setting
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{2B27EB8B-3AA6-438F-BCB0-719CE2C52E32}" = VAIO Content Metadata XML Interface Library
"{2FA41EBB-3F5A-35C3-85D6-51EC72A11FBD}" = Google Gears
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{34B37A74-125E-4406-87BA-E4BD3D097AE5}" = VAIO Survey
"{363611D9-1106-41F2-B74E-BD8481C41219}" = Click to Disc
"{36C5BBF0-E5BF-4DE1-B684-7E90B0C93FB5}" = VAIO Care
"{3851147E-5A91-4469-BA4D-13FFFCC8A920}" = Microsoft Windows OneCare Live v2.5.2900.20 Idcrl Install
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{4314FCA1-7D0D-45E7-B115-C142466BC60A}" = VAIO Content Metadata Manager Setting
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4DCEA9C1-4D6E-41BF-A854-28CFA8B56DBF}" = Click to Disc Editor
"{4EA55D20-27FB-45D7-8726-147E8A5F6C62}" = VAIO MusicBox
"{537BF16E-7412-448C-95D8-846E85A1D817}" = Roxio Easy Media Creator 10 LJ
"{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}" = VAIO Data Restore Tool
"{596BED91-A1D8-4DF1-8CD1-1C777F7588AC}" = VAIO DVD Menu Data Basic
"{5A3F6A80-7913-475E-8B96-477A952CFA43}" = SupportSoft Assisted Service
"{5C5EE8F2-0B38-4C13-AE4E-A87A237FE718}" =
"{5F5867F0-2D23-4338-A206-01A76C823924}" = VAIO Power Management
"{6513E869-647F-40FD-A55D-CFC92579B9BA}" = PX Engine
"{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works
"{68A69CFF-130D-4CDE-AB0E-7374ECB144C8}" = Click to Disc
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B1F20F2-6321-4669-A58C-33DF8E7517FF}" = VAIO Entertainment Platform
"{6C50525A-2D77-4C22-B058-9AA2F27ACFF2}" = VAIO Content Metadata Intelligent Analyzing Manager
"{6FA8BA2C-052B-4072-B8E2-2302C268BE9E}" = VAIO Movie Story Template Data
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{72042FA6-5609-489F-A8EA-3C2DD650F667}" = VAIO Control Center
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Central Audio
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7BB90344-0647-468E-925A-7F69F7983421}" = ArcSoft Magic-i Visual Effects
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83CDA18E-0BF3-4ACA-872C-B4CDABF2360E}" = VAIO Update 4
"{8B21B9EF-6DBF-4F63-8CC7-9F6A56D1EE8E}" = GTOneCare
"{8BD60AEF-3F9D-47AE-B80A-FB7FFCE335A0}" = VAIO Movie Story
"{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine
"{8ECB8220-F419-4BEB-9596-97033C533702}" = QuickBooks Simple Start 2008
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96D0B6C6-5A72-4B47-8583-A87E55F5FE81}" =
"{98FC7A64-774B-49B5-B046-4B4EBC053FA9}" = VAIO MusicBox Sample Music
"{9973498D-EA29-4A68-BE0B-C88D6E03E928}" = ArcSoft WebCam Companion 2
"{9B5F85CA-90D4-4AFC-BB37-32477FD0D2B9}" = SmartWi Connection Utility
"{A552C4EA-D41E-4C61-A0FB-C0E05440F7D7}" = VAIO Entertainment Platform
"{A63E7492-A0BC-4BB9-89A7-352965222380}" = VAIO Original Function Setting
"{A7DA438C-2E43-4C20-BFDA-C1F4A6208558}" = Setting Utility Series
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{B25563A0-41F4-4A81-A6C1-6DBC0911B1F3}" = VAIO Movie Story
"{B513C7B0-024A-498F-B0F5-00C67E2440A9}" = VAIO Content Metadata Intelligent Analyzing Manager
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Central Copy
"{BACD22AE-5B6B-4F23-B506-3FCFF13AC137}" = VAIO Media plus
"{BBBCAE4B-B416-4182-A6F2-438180894A81}" = Napster
"{BCED773C-99EE-48DD-8915-25733F69F0A8}" = VAIO Wireless Wizard
"{C1083DBC-C541-4E8C-91EA-D92397AB9A2C}" = OpenMG Secure Module 5.1.00
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C7477742-DDB4-43E5-AC8D-0259E1E661B1}" = VAIO Event Service
"{CB8A8696-93EC-414E-A752-850AB133F68A}" = VAIO Content Metadata XML Interface Library
"{CE2121C6-C94D-4A73-8EA4-6943F33EE335}" = Music Transfer
"{D47FE987-EA3D-424B-9886-B752501D7CE7}" = VAIO Help and Support
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{D60F97EC-EF06-4E1E-B0D1-C2CBABA62FA3}" = VAIO Wallpaper Contents
"{DFD0E9A9-F24A-492B-8975-8C938E32408F}" = VAIO Startup Assistant
"{E09A5851-B293-465E-A9FE-DFC11E0F4586}" = VAIO Content Metadata Intelligent Analyzing Manager
"{E1D25278-B51A-4163-BC3D-20A4D2D09F98}" = VAIO My Memory Center
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Central Core
"{EE59BBF9-415C-45DB-8C4B-EE43CF635FEA}" = VAIO Content Metadata XML Interface Library
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F570A6CC-53ED-4AA9-8B08-551CD3E38D8B}" =
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FD72E69E-CF34-4071-BFD6-FD081A365E2C}" = VAIO Content Metadata Intelligent Analyzing Manager
"{FE51662F-D8F6-43B5-99D9-D4894AF00F83}" = Roxio Easy Media Creator Home
"{FE697886-F392-4E0D-A0C0-47587BF60992}" = VAIO Content Metadata Manager Setting
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AIM Toolbar" = AIM Toolbar
"AIM_6" = AIM 6
"AOL Toolbar" = AOL Toolbar 5.0
"avast5" = avast! Free Antivirus
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Google Chrome" = Google Chrome
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = WinDVD for VAIO
"InstallShield_{4DCEA9C1-4D6E-41BF-A854-28CFA8B56DBF}" = Click to Disc Editor
"InstallShield_{C1083DBC-C541-4E8C-91EA-D92397AB9A2C}" = OpenMG Secure Module 5.1.00
"LimeWire" = LimeWire 5.1.4
"Mozilla Firefox (3.0.18)" = Mozilla Firefox (3.0.18)
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"ViewpointMediaPlayer" = Viewpoint Media Player
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WinSS" = Windows Live OneCare

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/18/2009 9:18:24 PM | Computer Name = Mollz-PC | Source = WinMgmt | ID = 10
Description =

Error - 10/18/2009 9:18:24 PM | Computer Name = Mollz-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 10/18/2009 9:18:25 PM | Computer Name = Mollz-PC | Source = VzCdbSvc | ID = 7
Description = Failed to load the plug-in module. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5})(Error
code = 0x80042019)

Error - 10/18/2009 9:18:30 PM | Computer Name = Mollz-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 10/18/2009 9:18:30 PM | Computer Name = Mollz-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 10/18/2009 9:18:30 PM | Computer Name = Mollz-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 10/18/2009 9:18:36 PM | Computer Name = Mollz-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 10/18/2009 11:38:13 PM | Computer Name = Mollz-PC | Source = WinMgmt | ID = 10
Description =

Error - 10/18/2009 11:38:13 PM | Computer Name = Mollz-PC | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =

Error - 10/18/2009 11:38:13 PM | Computer Name = Mollz-PC | Source = VzCdbSvc | ID = 7
Description = Failed to load the plug-in module. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5})(Error
code = 0x80042019)

[ System Events ]
Error - 3/6/2010 9:04:27 PM | Computer Name = Mollz-PC | Source = HTTP | ID = 15016
Description =

Error - 3/6/2010 9:04:42 PM | Computer Name = Mollz-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 3/11/2010 4:01:58 AM | Computer Name = Mollz-PC | Source = DCOM | ID = 10005
Description =

Error - 3/11/2010 4:01:58 AM | Computer Name = Mollz-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 3/11/2010 4:01:58 AM | Computer Name = Mollz-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 3/11/2010 4:01:58 AM | Computer Name = Mollz-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 3/11/2010 4:01:58 AM | Computer Name = Mollz-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 3/11/2010 4:20:05 AM | Computer Name = Mollz-PC | Source = Application Popup | ID = 1060
Description = \SystemRoot\SysWow64\DRIVERS\DMICall.sys has been blocked from loading
due to incompatibility with this system. Please contact your software vendor for
a compatible version of the driver.

Error - 3/11/2010 4:21:34 AM | Computer Name = Mollz-PC | Source = HTTP | ID = 15016
Description =

Error - 3/11/2010 4:22:04 AM | Computer Name = Mollz-PC | Source = Service Control Manager | ID = 7026
Description =

[ Windows OneCare Events ]
Error - 1/4/2010 10:34:46 PM | Computer Name = Mollz-PC | Source = WinSS | ID = 7001
Description = Failed executing wireless security check process. Error Code = 0x80020005.


< End of report >



The GMER file downloaded however, most of the boxes are grayed out so I can't click on them. It never asked me any of those questions either.
Hi,

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    SRV:64bit: - (usprserv) – C:\Windows\SysNative\svchost.exe ()
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O33 - MountPoints2\{a254a793-d289-11dd-a6fd-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{a254a793-d289-11dd-a6fd-806e6f6e6963}\Shell\AutoRun\command - "" = F:\autorun.exe – File not found
    [2010/03/06 19:57:36 | 000,010,766 | -HS- | M] () – C:\Users\Mollz\AppData\Local\fXsMq7BWv
    [2010/03/05 22:43:26 | 000,010,766 | -HS- | C] () – C:\Users\Mollz\AppData\Local\fXsMq7BWv
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
===================================================

Malwarebytes' Anti-Malware
Download Malwarebytes' Anti-Malware here and save to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program. (Note to Vista users, please right-click and select Run as Administrator.)
  • At the end, be sure a checkmark is placed next to:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

Eset online scannner

You can use either Internet Explorer or Mozilla FireFox for this scan.

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.
===================================================

On your next reply please post :
OTL log
MBAM log
ESET log

Good Day!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI