This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

FakeSpypro, Selace.X, Selace.Z, Selace.W, no browser capabili

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was surfing on what I thought was a reputable site when my Firefox browser started misbehaving. I thought it was automatically updating itself and I started typing passwords into my extensions. I saw a strange antivirus scanner start up by itself and I thought I was hijacked. I ran Malwarebytes Antimalware and it did not find anything. I panicked and uninstalled Firefox and Chrome.

I rebooted into safe mode and ran microsoft security essentials. I did not have Windows Defender on. It came across these viruses: Win32/FakeSpypro…Java/Selace.X…..Java/Selace.Z….Java/Selace.W….and another instance of Win32/FakeSpypro. I then uninstalled Java.

I ran another scan in safe mode from MBAM and it picked up one more file whose name I do not remember. :blush: I do not have any internet access currently. IE says that it cannot connect to the internet. I rebooted onto regular mode and now everything seems fine, although I still do not have IE working. (I am on a friend's computer).

I happened upon your site and I found a similarity with another user, mike83z , and I'm sorry but before I happened onto your site, I uninstalled irregularly-behaving programs and performed many MSE and MBAM scans until it seemed to be clean. I have not run any other scans that are more invasive. I downloaded highjack this since the other diagnostic does not like my OS…(Vista64). :pullhair:

Shall I just run a reinstall of Vista? (I have the original disc). Here's my data from HT:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:04:41 PM, on 6/12/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18928)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\Gary\AppData\Local\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
C:\Users\Gary\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:62747
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (file missing)
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [AsioThk32Reg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Users\Gary\AppData\Local\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O16 - DPF: {86A88967-7A20-11D2-8EDA-00600818EDB1} (ParallelGraphics Cortona Control) - http://www.parallelgraphics.com/l2/bin/cortvrml.cab
O16 - DPF: {B8A48F42-30E1-48f8-AE87-7BD7C75DB8AA} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_test.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Acronis Nonstop Backup service (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Samsung UPD Service - Unknown owner - C:\Windows\System32\SUPDSvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files (x86)\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 8315 bytes


Any help you provide would be greatly appreciated. Thanks in advance for your time and help :wavey:
Hi,

Please do the following:

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
    CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.
Hi there….I neglected to mention in my previous post that I ran Ccleaner several times, but you probably already knew that: :thumbup:

OTL Folder:

OTL logfile created on: 6/13/2010 11:27:37 AM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Users\Gary\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 186.30 Gb Total Space | 76.58 Gb Free Space | 41.11% Space Free | Partition Type: NTFS
Drive D: | 232.89 Gb Total Space | 104.70 Gb Free Space | 44.96% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 465.76 Gb Total Space | 71.65 Gb Free Space | 15.38% Space Free | Partition Type: NTFS
Drive G: | 1.86 Gb Total Space | 1.69 Gb Free Space | 90.55% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: GARY-PC
Current User Name: Gary
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\Gary\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
PRC - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Users\Gary\AppData\Local\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)


========== Modules (SafeList) ==========

MOD - C:\Users\Gary\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (MsMpSvc) – C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (FontCache) – C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:64bit: - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV:64bit: - (Samsung UPD Service) – C:\Windows\SysNative\SUPDSvc.exe (Samsung Electronics CO., LTD.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (afcdpsrv) – C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
SRV - (AcrSch2Svc) – C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (fsssvc) – C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (Creative ALchemy AL6 Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CTAudSvcService) – C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2006/11/02 09:34:14 | 000,000,000 | —D | M]
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (VSS) – C:\Windows\SysWOW64\wbem\vss.mof ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (afcdp) – C:\Windows\SysNative\DRIVERS\afcdp.sys (Acronis)
DRV:64bit: - (tdrpman258) Acronis Try&Decide; and Restore Points filter (build 258) – C:\Windows\SysNative\DRIVERS\tdrpm258.sys (Acronis)
DRV:64bit: - (timounter) – C:\Windows\SysNative\DRIVERS\timntr.sys (Acronis)
DRV:64bit: - (snapman) – C:\Windows\SysNative\DRIVERS\snapman.sys (Acronis)
DRV:64bit: - (Point64) – C:\Windows\SysNative\DRIVERS\point64k.sys (Microsoft Corporation)
DRV:64bit: - (LMouFilt) – C:\Windows\SysNative\DRIVERS\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) – C:\Windows\SysNative\DRIVERS\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\DRIVERS\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (usbaudio) USB Audio Driver (WDM) – C:\Windows\SysNative\drivers\usbaudio.sys (Microsoft Corporation)
DRV:64bit: - (SSPORT) – C:\Windows\SysNative\Drivers\SSPORT.sys (Samsung Electronics)
DRV:64bit: - (ha20x2k) – C:\Windows\SysNative\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV:64bit: - (emupia) – C:\Windows\SysNative\drivers\emupia2k.sys (Creative Technology Ltd)
DRV:64bit: - (ctsfm2k) – C:\Windows\SysNative\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV:64bit: - (ctprxy2k) – C:\Windows\SysNative\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV:64bit: - (ossrv) – C:\Windows\SysNative\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV:64bit: - (ctaud2k) Creative Audio Driver (WDM) – C:\Windows\SysNative\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV:64bit: - (ctac32k) – C:\Windows\SysNative\drivers\ctac32k.sys (Creative Technology Ltd)
DRV:64bit: - (CTEXFIFX.SYS) – C:\Windows\SysNative\drivers\CTEXFIFX.SYS (Creative Technology Ltd.)
DRV:64bit: - (CTEXFIFX) – C:\Windows\SysNative\drivers\CTEXFIFX.SYS (Creative Technology Ltd.)
DRV:64bit: - (CTHWIUT.SYS) – C:\Windows\SysNative\drivers\CTHWIUT.SYS (Creative Technology Ltd.)
DRV:64bit: - (CTHWIUT) – C:\Windows\SysNative\drivers\CTHWIUT.SYS (Creative Technology Ltd.)
DRV:64bit: - (CT20XUT.SYS) – C:\Windows\SysNative\drivers\CT20XUT.SYS (Creative Technology Ltd.)
DRV:64bit: - (CT20XUT) – C:\Windows\SysNative\drivers\CT20XUT.SYS (Creative Technology Ltd.)
DRV:64bit: - (tifsfilter) – C:\Windows\SysNative\DRIVERS\tifsfilt.sys (Acronis)
DRV:64bit: - (SaiNtBus) – C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:64bit: - (SaiMini) – C:\Windows\SysNative\DRIVERS\SaiMini.sys (Saitek)
DRV:64bit: - (SaiK0728) – C:\Windows\SysNative\DRIVERS\SaiK0728.sys (Saitek)
DRV:64bit: - (Alpham1) – C:\Windows\SysNative\DRIVERS\Alpham164.sys (Ideazon Corporation)
DRV:64bit: - (UsbFltr) – C:\Windows\SysNative\Drivers\UsbFltr.sys (Waytech Development, Inc.)
DRV:64bit: - (Alpham2) – C:\Windows\SysNative\DRIVERS\Alpham264.sys (Ideazon Corporation)
DRV:64bit: - (DgiVecp) – C:\Windows\SysNative\Drivers\DgiVecp.sys (Samsung Electronics)
DRV:64bit: - (BCM43XV) – C:\Windows\SysNative\DRIVERS\bcmwl664.sys (Broadcom Corporation)
DRV:64bit: - (athr) – C:\Windows\SysNative\DRIVERS\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (RTL85n64) – C:\Windows\SysNative\DRIVERS\RTL85n64.sys (Realtek)
DRV:64bit: - (FET5A64) – C:\Windows\SysNative\DRIVERS\fet5a64.sys (VIA Technologies, Inc. )
DRV - (gdrv) – C:\Windows\gdrv.sys (Windows ® Server 2003 DDK provider)
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:62747

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.usedbfororder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig"
FF - prefs.js..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:4.6
FF - prefs.js..extensions.enabledItems: [removed]:2.0.5
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.8
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7.3
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: morningCoffee@shaneliesegang:1.33
FF - prefs.js..extensions.enabledItems: {FBF6D7FB-F305-4445-BB3D-FEF66579A033}:4.9
FF - prefs.js..extensions.enabledItems: [removed]:3.76
FF - prefs.js..extensions.enabledItems: [removed]:2.0.6
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: [removed]:0.3.2
FF - prefs.js..extensions.enabledItems: [removed]:3.6.14
FF - prefs.js..extensions.enabledItems: {2a43f346-13de-4aad-adeb-00b61e5bcde3}:0.2
FF - prefs.js..extensions.enabledItems: {27182e60-b5f3-411c-b545-b44205977502}:1.0
FF - prefs.js..extensions.enabledItems: {29852C08-1E91-4889-A6BF-C77F91D6A8F3}:1.8.61
FF - prefs.js..extensions.enabledItems: {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}:3.76
FF - prefs.js..extensions.enabledItems: [removed]:1.9
FF - prefs.js..extensions.enabledItems: {07b2a769-ed19-4483-87ce-c643914c81bb}:3.0.0.91
FF - prefs.js..extensions.enabledItems: {e213bb8f-8ebd-11db-96b7-005056c00008}:3.0.0.91

FF - HKLM\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2010/06/08 18:54:47 | 000,000,000 | —D | M]

[2009/08/16 02:55:14 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Mozilla\Extensions
[2009/08/16 02:55:14 | 000,000,000 | —D | M] (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/06/09 22:18:23 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions
[2010/03/29 01:27:01 | 000,000,000 | —D | M] (Screengrab) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2010/05/07 22:01:10 | 000,000,000 | —D | M] (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2010/05/28 19:10:34 | 000,000,000 | —D | M] (Vista-aero) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}
[2010/04/27 20:20:21 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/06/02 00:14:34 | 000,000,000 | —D | M] (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{29852C08-1E91-4889-A6BF-C77F91D6A8F3}
[2010/06/06 02:36:20 | 000,000,000 | —D | M] (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{2a43f346-13de-4aad-adeb-00b61e5bcde3}
[2010/01/21 12:43:43 | 000,000,000 | —D | M] (FoxyTunes) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2010/04/03 00:03:45 | 000,000,000 | —D | M] (Surf Canyon - Search Engine Assistant) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{75623d5d-4683-402a-b610-ac4bab767c86}
[2010/02/22 22:30:21 | 000,000,000 | —D | M] (Noia 2.0 (eXtreme)) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
[2010/05/12 12:15:04 | 000,000,000 | —D | M] (WOT) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/04/15 17:35:07 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/04/12 14:35:04 | 000,000,000 | —D | M] (Download Statusbar) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2010/05/28 19:10:41 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/05/28 19:10:12 | 000,000,000 | —D | M] (myFireFox) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{e213bb8f-8ebd-11db-96b7-005056c00008}
[2010/05/28 19:10:14 | 000,000,000 | —D | M] (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{e213bb8f-8ebd-11db-96b7-005056c00008}-trash
[2010/04/09 16:48:01 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/03/18 10:25:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}
[2010/03/18 10:25:50 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\[removed]
[2010/04/20 19:56:23 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\[removed]
[2010/04/06 15:18:38 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\[removed]
[2009/09/10 16:09:54 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\morningCoffee@shaneliesegang
[2010/02/22 22:30:23 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\[removed]
[2010/05/22 19:19:19 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\[removed]
[2010/04/16 15:16:17 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\[removed]
[2010/05/28 19:10:33 | 000,000,000 | —D | M] (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}\chrome\mozapps\extensions
[2010/05/28 19:10:11 | 000,000,000 | —D | M] (No name found) – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\extensions\{e213bb8f-8ebd-11db-96b7-005056c00008}\chrome\mozapps\extensions
[2010/06/03 14:54:23 | 000,002,282 | —- | M] () – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\searchplugins\surf-canyon.xml
[2010/03/22 06:41:40 | 000,007,328 | —- | M] () – C:\Users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\gptqd0i1.default\searchplugins\thottbot-wow.xml
[2010/06/10 18:48:06 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/01/13 18:46:00 | 000,063,488 | —- | M] (Nullsoft, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll

O1 HOSTS File: ([2006/09/18 17:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg64.dll (Google Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [AsioReg] File not found
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AsioThk32Reg] C:\Windows\SysWow64\ctasio.dll (Creative Technology Ltd)
O4 - HKCU..\Run: [Octoshape Streaming Services] C:\Users\Gary\AppData\Local\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O8:64bit: - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {86A88967-7A20-11D2-8EDA-00600818EDB1} http://www.parallelgraphics.com/l2/bin/cortvrml.cab (ParallelGraphics Cortona Control)
O16 - DPF: {B8A48F42-30E1-48f8-AE87-7BD7C75DB8AA} http://www.srtest.com/srl_bin/sysreqlab_test.cab (System Requirements Lab Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - Reg Error: Key error. File not found
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img31.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img31.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: Ias - C:\Windows\SysNative\ias [2008/11/01 19:21:00 | 000,000,000 | —D | M]
NetSvcs:64bit: Irmon - C:\Windows\SysNative\irmon.dll (Microsoft Corporation)
NetSvcs:64bit: Wmi - C:\Windows\SysNative\wmi.dll (Microsoft Corporation)
NetSvcs: Ias - C:\Windows\SysWOW64\ias [2008/11/01 19:21:27 | 000,000,000 | —D | M]
NetSvcs: Wmi - C:\Windows\SysWOW64\wmi.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 90 Days ==========

[2010/06/13 11:24:18 | 000,572,416 | —- | C] (OldTimer Tools) – C:\Users\Gary\Desktop\OTL.exe
[2010/06/13 11:23:44 | 000,000,000 | —D | C] – C:\Users\Gary\Desktop\further instructions folder
[2010/06/12 19:03:16 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Gary\Desktop\HiJackThis.exe
[2010/06/12 19:02:42 | 000,000,000 | —D | C] – C:\Users\Gary\Desktop\new virus removal
[2010/06/11 03:57:49 | 000,000,000 | —D | C] – C:\Users\Gary\.SunDownloadManager
[2010/06/10 22:38:33 | 000,000,000 | —D | C] – C:\Users\Gary\Desktop\virus removal
[2010/06/03 16:50:30 | 000,000,000 | —D | C] – C:\Users\Gary\Desktop\paul2
[2010/06/03 16:43:20 | 000,000,000 | —D | C] – C:\Users\Gary\Desktop\paul
[2010/06/03 09:42:54 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/06/03 09:42:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/05/31 12:18:03 | 000,000,000 | —D | C] – C:\Users\Gary\Desktop\bieberhead
[2010/05/30 23:30:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Antimalware
[2010/05/30 23:29:51 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Essentials
[2010/05/29 01:11:29 | 000,000,000 | —D | C] – C:\Program Files\Ventrilo
[2010/05/17 20:31:46 | 000,000,000 | —D | C] – C:\Program Files\Microsoft IntelliPoint
[2010/05/07 13:03:04 | 000,000,000 | —D | C] – C:\Users\Gary\AppData\Roaming\Windows SideBar
[2010/05/07 00:46:44 | 000,000,000 | —D | C] – C:\Users\Gary\AppData\Roaming\Apple Computer
[2010/05/04 01:09:08 | 000,000,000 | —D | C] – C:\Users\Gary\AppData\Roaming\NCH Software
[2010/05/04 01:08:08 | 000,000,000 | —D | C] – C:\ProgramData\NCH Swift Sound
[2010/05/04 01:07:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\NCH Swift Sound
[2010/05/04 01:07:56 | 000,000,000 | —D | C] – C:\Users\Gary\AppData\Roaming\NCH Swift Sound
[2010/04/29 23:36:10 | 000,000,000 | —D | C] – C:\ProgramData\Real
[2010/04/28 01:57:56 | 000,000,000 | —D | C] – C:\Program Files\NVIDIA Corporation
[2010/04/21 18:46:44 | 000,000,000 | —D | C] – C:\Users\Gary\Documents\My Games
[2010/04/21 18:46:44 | 000,000,000 | —D | C] – C:\Users\Gary\AppData\Local\My Games
[2010/04/21 10:22:38 | 000,000,000 | —D | C] – C:\steam
[2010/04/15 13:12:49 | 000,000,000 | —D | C] – C:\Users\Gary\AppData\Roaming\Acronis
[2010/04/15 13:11:04 | 000,000,000 | —D | C] – C:\ProgramData\Acronis
[2010/04/15 12:57:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Acronis
[2010/04/15 12:57:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Acronis
[2010/04/03 22:55:32 | 000,064,616 | —- | C] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2010/04/03 22:55:32 | 000,056,424 | —- | C] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2010/04/03 10:07:23 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2010/03/22 06:14:28 | 000,000,000 | —D | C] – C:\Windows\Sun
[2008/10/07 23:42:42 | 000,060,928 | —- | C] ( ) – C:\Windows\SysWow64\a3d.dll
[8 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Users\Gary\*.tmp files -> C:\Users\Gary\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/06/13 11:29:59 | 000,000,432 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{D705618D-2A18-4B1D-B733-4F084BB0159C}.job
[2010/06/13 11:27:59 | 000,000,436 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{4F921297-886A-42B4-B743-9E6D5990E6A3}.job
[2010/06/13 11:27:39 | 003,407,872 | -HS- | M] () – C:\Users\Gary\ntuser.dat
[2010/06/13 11:24:12 | 000,694,964 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/06/13 11:24:12 | 000,598,350 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/06/13 11:24:12 | 000,101,988 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/06/13 11:24:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/13 11:23:06 | 000,070,389 | —- | M] () – C:\ProgramData\nvModes.001
[2010/06/13 11:21:59 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3942733629-2771798251-4067787467-1002UA.job
[2010/06/13 11:15:00 | 000,572,416 | —- | M] (OldTimer Tools) – C:\Users\Gary\Desktop\OTL.exe
[2010/06/13 11:11:59 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3942733629-2771798251-4067787467-1001UA.job
[2010/06/13 09:53:15 | 000,000,432 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{9C87E4B8-515C-4766-9808-5C3389C31BB5}.job
[2010/06/13 09:51:39 | 000,070,389 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/06/13 09:51:29 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/13 09:51:09 | 000,004,176 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/13 09:51:09 | 000,004,176 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/13 09:51:04 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/13 09:51:00 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/12 22:01:49 | 000,062,644 | —- | M] () – C:\Windows\SysNative\BMXStateBkp-{00000001-00000000-00000008-00001102-00000005-00211102}.rfx
[2010/06/12 22:01:49 | 000,062,644 | —- | M] () – C:\Windows\SysNative\BMXState-{00000001-00000000-00000008-00001102-00000005-00211102}.rfx
[2010/06/12 22:01:49 | 000,000,788 | —- | M] () – C:\Windows\SysNative\DVCState-{00000001-00000000-00000008-00001102-00000005-00211102}.rfx
[2010/06/12 22:01:35 | 000,524,288 | -HS- | M] () – C:\Users\Gary\ntuser.dat{f1819a30-39fb-11df-ab0a-0016e65a2068}.TMContainer00000000000000000001.regtrans-ms
[2010/06/12 22:01:35 | 000,065,536 | -HS- | M] () – C:\Users\Gary\ntuser.dat{f1819a30-39fb-11df-ab0a-0016e65a2068}.TM.blf
[2010/06/12 22:01:33 | 002,801,612 | -H– | M] () – C:\Users\Gary\AppData\Local\IconCache.db
[2010/06/12 19:29:53 | 000,212,480 | —- | M] () – C:\Users\Gary\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/12 19:12:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3942733629-2771798251-4067787467-1001Core.job
[2010/06/12 03:22:00 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3942733629-2771798251-4067787467-1002Core.job
[2010/06/11 18:14:52 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Gary\Desktop\HiJackThis.exe
[2010/06/11 18:12:50 | 000,359,929 | —- | M] () – C:\Users\Gary\Desktop\dds.scr
[2010/06/11 14:38:17 | 000,001,905 | —- | M] () – C:\Windows\diagwrn.xml
[2010/06/11 14:38:17 | 000,001,905 | —- | M] () – C:\Windows\diagerr.xml
[2010/06/11 03:44:56 | 000,002,188 | —- | M] () – C:\Users\Gary\AppData\Local\d3d9caps64.dat
[2010/06/11 03:43:31 | 000,001,356 | —- | M] () – C:\Users\Gary\AppData\Local\d3d9caps.dat
[2010/06/09 21:51:26 | 000,630,742 | —- | M] () – C:\Users\Gary\Desktop\oap-landsea-oceans-100608-02.jpg
[2010/06/09 00:11:10 | 000,080,229 | —- | M] () – C:\Users\Gary\Desktop\12275396.pdf
[2010/06/08 23:39:41 | 000,053,069 | —- | M] () – C:\Users\Gary\Desktop\DL_SubUnsub_BRR.pdf
[2010/06/08 23:16:36 | 000,207,618 | —- | M] () – C:\Users\Gary\Desktop\attachments_2010_06_08.zip
[2010/06/08 21:57:21 | 000,094,390 | —- | M] () – C:\Users\Gary\Desktop\0ec82692adff72fc0c7d82f84d243781.jpg
[2010/06/08 19:05:22 | 000,318,944 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/06/08 18:57:01 | 000,000,240 | —- | M] () – C:\Windows\win.ini
[2010/06/07 22:02:04 | 000,025,913 | —- | M] () – C:\Users\Gary\Desktop\tumblr_l3meggd9Fm1qay8mao1_400.jpg
[2010/06/07 21:15:42 | 000,058,476 | —- | M] () – C:\Users\Gary\Desktop\TDLPn.jpg
[2010/06/07 17:29:17 | 478,531,721 | —- | M] () – C:\Users\Gary\Desktop\Brocket.wmv
[2010/06/07 17:28:09 | 174,953,531 | —- | M] () – C:\Users\Gary\Desktop\MassiveStd Johnny and Tim.flv
[2010/06/07 15:09:06 | 000,082,432 | —- | M] () – C:\Users\Gary\Desktop\securedownload (1).jpg
[2010/06/07 15:08:58 | 000,070,957 | —- | M] () – C:\Users\Gary\Desktop\securedownload.jpg
[2010/06/05 19:25:48 | 000,385,315 | —- | M] () – C:\Users\Gary\Desktop\Book On The Taboo Against Knowing Who You Are.pdf
[2010/06/05 15:48:28 | 001,392,526 | —- | M] () – C:\Users\Gary\Desktop\philosophy of humanism.pdf
[2010/06/04 13:24:29 | 000,121,789 | —- | M] () – C:\Users\Gary\Desktop\FWSAPP1011.pdf
[2010/06/03 09:42:57 | 000,000,848 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/02 00:15:45 | 000,164,689 | —- | M] () – C:\Users\Gary\Desktop\Class-Search-4-09.pdf
[2010/06/02 00:13:57 | 000,351,754 | —- | M] () – C:\Users\Gary\Desktop\Registration-Process-4-09.pdf
[2010/06/01 13:22:27 | 000,002,369 | —- | M] () – C:\Users\Gary\Desktop\WinWay Resume Deluxe.lnk
[2010/05/30 23:29:52 | 000,000,942 | —- | M] () – C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010/05/30 18:57:48 | 000,046,415 | —- | M] () – C:\Users\Gary\Desktop\tWkCL.jpg
[2010/05/30 18:36:44 | 000,023,997 | —- | M] () – C:\Users\Gary\Desktop\q4XvN.jpg
[2010/05/29 13:35:07 | 000,001,724 | —- | M] () – C:\Users\Gary\Desktop\CCleaner.lnk
[2010/05/29 10:22:37 | 000,008,687 | —- | M] () – C:\Users\Gary\Desktop\fall-2010.pdf
[2010/05/29 10:22:15 | 000,038,766 | —- | M] () – C:\Users\Gary\Desktop\summer 2010 rev 07-24-09.pdf
[2010/05/29 01:11:31 | 000,000,752 | —- | M] () – C:\Users\Gary\Desktop\Ventrilo.lnk
[2010/05/29 01:11:31 | 000,000,210 | —- | M] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2010/05/27 19:34:38 | 000,023,063 | —- | M] () – C:\Users\Gary\Desktop\esar[1].pdf
[2010/05/23 18:06:40 | 000,000,388 | —- | M] () – C:\Users\Gary\Desktop\desktop for c - Shortcut.lnk
[2010/05/18 09:44:37 | 000,079,600 | —- | M] () – C:\Users\Gary\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/05/17 20:35:21 | 000,002,030 | —- | M] () – C:\Users\Public\Desktop\Microsoft Mouse.lnk
[2010/05/17 20:02:41 | 000,000,270 | —- | M] () – C:\Users\Gary\Desktop\Mouse - Shortcut.lnk
[2010/05/16 15:19:48 | 000,018,960 | —- | M] (Logitech, Inc.) – C:\Windows\SysNative\drivers\LNonPnP.sys
[2010/05/14 16:32:54 | 000,000,219 | —- | M] () – C:\Users\Gary\Desktop\Portal.url
[2010/05/11 22:05:50 | 000,000,382 | —- | M] () – C:\Users\Gary\Desktop\adult toons - Shortcut.lnk
[2010/05/07 00:42:12 | 000,002,024 | —- | M] () – C:\Users\Gary\Desktop\Tuner2 - your ears will know.lnk
[2010/05/07 00:42:12 | 000,001,018 | —- | M] () – C:\Users\Gary\Desktop\AAC-aacPlus Plugin Read Me.lnk
[2010/05/04 10:57:37 | 000,001,878 | —- | M] () – C:\Users\Gary\Desktop\Mahjong.lnk
[2010/05/04 10:57:28 | 000,001,910 | —- | M] () – C:\Users\Gary\Desktop\Solitaire.lnk
[2010/05/04 01:08:07 | 000,000,972 | —- | M] () – C:\Users\Public\Desktop\Switch Sound File Converter.lnk
[2010/05/02 23:47:08 | 000,000,944 | —- | M] () – C:\Users\Public\Desktop\GOM Player.lnk
[2010/05/02 18:51:02 | 012,447,954 | —- | M] () – C:\Users\Gary\Desktop\Tempest_in_Tristram.mp3
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/04/29 15:39:28 | 000,024,664 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/04/22 15:42:34 | 000,032,256 | —- | M] () – C:\Users\Gary\Desktop\Gary Till.doc
[2010/04/22 04:35:58 | 000,000,828 | —- | M] () – C:\Users\Public\Desktop\Steam.lnk
[2010/04/15 12:58:13 | 000,002,120 | —- | M] () – C:\Users\Public\Desktop\Acronis One-Click Backup.lnk
[2010/04/15 12:58:13 | 000,001,046 | —- | M] () – C:\Users\Public\Desktop\Acronis True Image Home 2010.lnk
[2010/04/15 12:55:21 | 000,001,917 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/04/14 23:10:33 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2010/04/03 22:55:32 | 000,064,616 | —- | M] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2010/04/03 22:55:32 | 000,056,424 | —- | M] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2010/04/03 22:55:32 | 000,009,832 | —- | M] () – C:\Windows\SysNative\nvinfo.pb
[2010/04/03 18:41:38 | 000,276,196 | —- | M] () – C:\Windows\SysNative\NvApps.xml
[2010/04/03 18:41:38 | 000,066,714 | —- | M] () – C:\Windows\SysNative\NvwsApps.xml
[2010/04/03 10:07:31 | 000,001,756 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/04/02 17:17:34 | 000,179,091 | —- | M] () – C:\Windows\SysWow64\xlive.dll.cat
[2010/03/31 01:29:15 | 000,003,519 | —- | M] () – C:\Windows\InstText.ini
[2010/03/28 01:29:08 | 000,524,288 | -HS- | M] () – C:\Users\Gary\ntuser.dat{f1819a30-39fb-11df-ab0a-0016e65a2068}.TMContainer00000000000000000002.regtrans-ms
[2010/03/27 07:51:13 | 000,524,288 | -HS- | M] () – C:\Users\Gary\ntuser.dat{9af99f4c-359c-11df-91a6-0016e65a2068}.TMContainer00000000000000000001.regtrans-ms
[2010/03/27 07:51:13 | 000,065,536 | -HS- | M] () – C:\Users\Gary\ntuser.dat{9af99f4c-359c-11df-91a6-0016e65a2068}.TM.blf
[2010/03/23 06:36:15 | 000,000,258 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2010/03/22 10:13:07 | 000,524,288 | -HS- | M] () – C:\Users\Gary\ntuser.dat{9af99f4c-359c-11df-91a6-0016e65a2068}.TMContainer00000000000000000002.regtrans-ms
[2010/03/21 22:59:17 | 000,524,288 | -HS- | M] () – C:\Users\Gary\ntuser.dat{da4e1f6f-2bcb-11df-8b47-0016e65a2068}.TMContainer00000000000000000001.regtrans-ms
[2010/03/21 22:59:17 | 000,065,536 | -HS- | M] () – C:\Users\Gary\ntuser.dat{da4e1f6f-2bcb-11df-8b47-0016e65a2068}.TM.blf
[8 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Users\Gary\*.tmp files -> C:\Users\Gary\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/12 19:03:06 | 000,359,929 | —- | C] () – C:\Users\Gary\Desktop\dds.scr
[2010/06/11 14:34:18 | 000,001,905 | —- | C] () – C:\Windows\diagwrn.xml
[2010/06/11 14:34:18 | 000,001,905 | —- | C] () – C:\Windows\diagerr.xml
[2010/06/09 21:51:25 | 000,630,742 | —- | C] () – C:\Users\Gary\Desktop\oap-landsea-oceans-100608-02.jpg
[2010/06/09 00:11:10 | 000,080,229 | —- | C] () – C:\Users\Gary\Desktop\12275396.pdf
[2010/06/08 23:39:41 | 000,053,069 | —- | C] () – C:\Users\Gary\Desktop\DL_SubUnsub_BRR.pdf
[2010/06/08 23:16:34 | 000,207,618 | —- | C] () – C:\Users\Gary\Desktop\attachments_2010_06_08.zip
[2010/06/08 21:57:20 | 000,094,390 | —- | C] () – C:\Users\Gary\Desktop\0ec82692adff72fc0c7d82f84d243781.jpg
[2010/06/07 22:02:03 | 000,025,913 | —- | C] () – C:\Users\Gary\Desktop\tumblr_l3meggd9Fm1qay8mao1_400.jpg
[2010/06/07 21:15:42 | 000,058,476 | —- | C] () – C:\Users\Gary\Desktop\TDLPn.jpg
[2010/06/07 16:14:17 | 174,953,531 | —- | C] () – C:\Users\Gary\Desktop\MassiveStd Johnny and Tim.flv
[2010/06/07 15:28:06 | 478,531,721 | —- | C] () – C:\Users\Gary\Desktop\Brocket.wmv
[2010/06/07 15:09:06 | 000,082,432 | —- | C] () – C:\Users\Gary\Desktop\securedownload (1).jpg
[2010/06/07 15:08:58 | 000,070,957 | —- | C] () – C:\Users\Gary\Desktop\securedownload.jpg
[2010/06/05 19:25:48 | 000,385,315 | —- | C] () – C:\Users\Gary\Desktop\Book On The Taboo Against Knowing Who You Are.pdf
[2010/06/05 15:48:28 | 001,392,526 | —- | C] () – C:\Users\Gary\Desktop\philosophy of humanism.pdf
[2010/06/04 13:24:28 | 000,121,789 | —- | C] () – C:\Users\Gary\Desktop\FWSAPP1011.pdf
[2010/06/03 09:42:57 | 000,000,848 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/02 00:15:45 | 000,164,689 | —- | C] () – C:\Users\Gary\Desktop\Class-Search-4-09.pdf
[2010/06/02 00:13:57 | 000,351,754 | —- | C] () – C:\Users\Gary\Desktop\Registration-Process-4-09.pdf
[2010/05/30 23:29:52 | 000,000,942 | —- | C] () – C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010/05/30 18:57:47 | 000,046,415 | —- | C] () – C:\Users\Gary\Desktop\tWkCL.jpg
[2010/05/30 18:36:42 | 000,023,997 | —- | C] () – C:\Users\Gary\Desktop\q4XvN.jpg
[2010/05/29 10:22:37 | 000,008,687 | —- | C] () – C:\Users\Gary\Desktop\fall-2010.pdf
[2010/05/29 10:22:15 | 000,038,766 | —- | C] () – C:\Users\Gary\Desktop\summer 2010 rev 07-24-09.pdf
[2010/05/29 05:57:52 | 000,001,356 | —- | C] () – C:\Users\Gary\AppData\Local\d3d9caps.dat
[2010/05/29 01:11:30 | 000,000,752 | —- | C] () – C:\Users\Gary\Desktop\Ventrilo.lnk
[2010/05/29 01:11:26 | 000,000,210 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2010/05/27 19:34:38 | 000,023,063 | —- | C] () – C:\Users\Gary\Desktop\esar[1].pdf
[2010/05/23 18:06:40 | 000,000,388 | —- | C] () – C:\Users\Gary\Desktop\desktop for c - Shortcut.lnk
[2010/05/17 20:35:21 | 000,002,030 | —- | C] () – C:\Users\Public\Desktop\Microsoft Mouse.lnk
[2010/05/17 20:02:41 | 000,000,270 | —- | C] () – C:\Users\Gary\Desktop\Mouse - Shortcut.lnk
[2010/05/14 16:32:54 | 000,000,219 | —- | C] () – C:\Users\Gary\Desktop\Portal.url
[2010/05/11 22:05:50 | 000,000,382 | —- | C] () – C:\Users\Gary\Desktop\adult toons - Shortcut.lnk
[2010/05/04 10:57:37 | 000,001,878 | —- | C] () – C:\Users\Gary\Desktop\Mahjong.lnk
[2010/05/04 10:57:28 | 000,001,910 | —- | C] () – C:\Users\Gary\Desktop\Solitaire.lnk
[2010/05/04 01:08:07 | 000,000,972 | —- | C] () – C:\Users\Public\Desktop\Switch Sound File Converter.lnk
[2010/05/02 18:47:07 | 012,447,954 | —- | C] () – C:\Users\Gary\Desktop\Tempest_in_Tristram.mp3
[2010/04/22 15:42:34 | 000,032,256 | —- | C] () – C:\Users\Gary\Desktop\Gary Till.doc
[2010/04/21 10:26:22 | 000,000,828 | —- | C] () – C:\Users\Public\Desktop\Steam.lnk
[2010/04/15 12:58:13 | 000,002,120 | —- | C] () – C:\Users\Public\Desktop\Acronis One-Click Backup.lnk
[2010/04/15 12:58:13 | 000,001,046 | —- | C] () – C:\Users\Public\Desktop\Acronis True Image Home 2010.lnk
[2010/04/03 22:55:32 | 000,009,832 | —- | C] () – C:\Windows\SysNative\nvinfo.pb
[2010/04/03 18:41:38 | 000,276,196 | —- | C] () – C:\Windows\SysNative\NvApps.xml
[2010/04/03 18:41:38 | 000,066,714 | —- | C] () – C:\Windows\SysNative\NvwsApps.xml
[2010/04/03 10:07:31 | 000,001,756 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/04/02 17:17:34 | 000,179,091 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2010/03/27 23:07:56 | 000,524,288 | -HS- | C] () – C:\Users\Gary\ntuser.dat{f1819a30-39fb-11df-ab0a-0016e65a2068}.TMContainer00000000000000000002.regtrans-ms
[2010/03/27 23:07:56 | 000,524,288 | -HS- | C] () – C:\Users\Gary\ntuser.dat{f1819a30-39fb-11df-ab0a-0016e65a2068}.TMContainer00000000000000000001.regtrans-ms
[2010/03/27 23:07:56 | 000,065,536 | -HS- | C] () – C:\Users\Gary\ntuser.dat{f1819a30-39fb-11df-ab0a-0016e65a2068}.TM.blf
[2010/03/22 06:22:55 | 000,524,288 | -HS- | C] () – C:\Users\Gary\ntuser.dat{9af99f4c-359c-11df-91a6-0016e65a2068}.TMContainer00000000000000000002.regtrans-ms
[2010/03/22 06:22:55 | 000,524,288 | -HS- | C] () – C:\Users\Gary\ntuser.dat{9af99f4c-359c-11df-91a6-0016e65a2068}.TMContainer00000000000000000001.regtrans-ms
[2010/03/22 06:22:55 | 000,065,536 | -HS- | C] () – C:\Users\Gary\ntuser.dat{9af99f4c-359c-11df-91a6-0016e65a2068}.TM.blf
[2010/03/12 01:10:16 | 000,708,868 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/02/12 08:02:00 | 000,003,519 | —- | C] () – C:\Windows\InstText.ini
[2010/02/11 17:32:24 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2009/12/21 22:20:16 | 000,000,496 | —- | C] () – C:\Windows\SysWow64\wlan.ini
[2009/12/21 20:05:48 | 000,094,208 | —- | C] () – C:\Windows\SysWow64\GTW32N50.dll
[2009/06/09 00:22:36 | 000,144,896 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2009/06/09 00:22:36 | 000,071,168 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2009/06/02 10:22:56 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/06/02 10:21:32 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2008/11/01 16:30:18 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/10/08 00:08:38 | 000,020,936 | —- | C] () – C:\Windows\SysWow64\instwdm.ini
[2008/10/07 23:41:40 | 000,002,560 | —- | C] () – C:\Windows\SysWow64\CtxfiRes.dll
[2008/10/07 10:13:22 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelFrench.dll
[2008/08/19 18:39:18 | 000,000,321 | —- | C] () – C:\Windows\SysWow64\kill.ini
[2008/07/11 16:22:30 | 000,000,054 | —- | C] () – C:\Windows\SysWow64\ctzapxx.ini
[2008/06/05 08:58:26 | 000,197,912 | —- | C] () – C:\Windows\SysWow64\physxcudart_20.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\Windows\SysWow64\OUTLPERF.INI

========== LOP Check ==========

[2010/04/16 09:34:29 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Acronis
[2009/11/13 16:05:46 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Amazon
[2009/07/13 02:26:15 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Braid
[2009/10/16 11:49:51 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2008/12/19 04:21:10 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Ideazon
[2009/08/29 23:18:40 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Leadertech
[2010/05/04 01:07:56 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\NCH Swift Sound
[2009/05/13 12:46:12 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\The Creative Assembly
[2009/08/16 02:55:14 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Thunderbird
[2010/05/07 13:03:04 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\Windows SideBar
[2010/01/01 13:54:05 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\WinWay
[2010/02/21 02:12:39 | 000,000,000 | —D | M] – C:\Users\Gary\AppData\Roaming\yess
[2010/06/12 22:01:39 | 000,032,574 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/06/13 11:27:59 | 000,000,436 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{4F921297-886A-42B4-B743-9E6D5990E6A3}.job
[2010/06/13 09:53:15 | 000,000,432 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{9C87E4B8-515C-4766-9808-5C3389C31BB5}.job
[2010/06/13 11:29:59 | 000,000,432 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{D705618D-2A18-4B1D-B733-4F084BB0159C}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/01/19 04:09:09 | 000,064,568 | —- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008/01/19 04:09:09 | 000,064,568 | —- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys

< MD5 for: ATAPI.SYS >
[2008/09/17 04:09:57 | 000,022,584 | —- | M] (Microsoft Corporation) MD5=05001E1FACCE49DB895B8526B05C7302 – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_37cb142cf6008bc1\atapi.sys
[2008/01/19 04:07:46 | 000,022,584 | —- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2008/09/17 04:09:57 | 000,022,584 | —- | M] (Microsoft Corporation) MD5=BB55C79E0595D8CFBE4A80A3C9EB77EA – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_375215c7dcd73562\atapi.sys
[2009/04/11 03:15:00 | 000,020,952 | —- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys

< MD5 for: CNGAUDIT.DLL >
[2006/11/02 07:16:48 | 000,014,848 | —- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006/11/02 05:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 05:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 05:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

< MD5 for: IASTORV.SYS >
[2008/01/19 04:11:31 | 000,290,872 | —- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys

< MD5 for: NETLOGON.DLL >
[2008/01/19 04:03:01 | 000,716,800 | —- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2006/11/02 05:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_61f43b1d27cd0ab4\netlogon.dll
[2009/04/11 02:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SysWOW64\netlogon.dll
[2009/04/11 02:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SysWOW64\netlogon.dll
[2009/04/11 02:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009/04/11 03:11:16 | 000,717,312 | —- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008/01/19 03:35:36 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll
[2006/11/02 07:18:47 | 000,684,032 | —- | M] (Microsoft Corporation) MD5=BFAB28B54DF41208CF3490FF26E53FD9 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_579f90caf36c48b9\netlogon.dll

< MD5 for: NVSTOR.SYS >
[2008/01/19 04:08:50 | 000,054,328 | —- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys

< MD5 for: SCECLI.DLL >
[2008/01/19 03:36:19 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2006/11/02 07:19:09 | 000,239,616 | —- | M] (Microsoft Corporation) MD5=32EF13F20B28966D29DE5EABE036431D – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_91f5bbe3948dcf74\scecli.dll
[2008/01/19 04:03:55 | 000,235,520 | —- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2006/11/02 05:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_9c4a6635c8ee916f\scecli.dll
[2009/04/11 02:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SysWOW64\scecli.dll
[2009/04/11 02:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SysWOW64\scecli.dll
[2009/04/11 02:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009/04/11 03:11:23 | 000,235,520 | —- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >

< %systemroot%\system32\drivers\*.sys /90 >
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWOW64\drivers\mbamswissarmy.sys
< End of Report >





Extras folder:

OTL Extras logfile created on: 6/13/2010 11:27:37 AM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Users\Gary\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
8.00 Gb Paging File | 6.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 186.30 Gb Total Space | 76.58 Gb Free Space | 41.11% Space Free | Partition Type: NTFS
Drive D: | 232.89 Gb Total Space | 104.70 Gb Free Space | 44.96% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 465.76 Gb Total Space | 71.65 Gb Free Space | 15.38% Space Free | Partition Type: NTFS
Drive G: | 1.86 Gb Total Space | 1.69 Gb Free Space | 90.55% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: GARY-PC
Current User Name: Gary
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Browse with FastStone] – "C:\Program Files (x86)\FastStone Image Viewer\FSViewer.exe" "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [MediaMonkey.1Play] – "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" "%1" (Ventis Media Inc.)
Directory [MediaMonkey.2PlayNext] – "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /NEXT "%1" (Ventis Media Inc.)
Directory [MediaMonkey.3Enqueue] – "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /ADD "%1" (Ventis Media Inc.)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Browse with FastStone] – "C:\Program Files (x86)\FastStone Image Viewer\FSViewer.exe" "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [MediaMonkey.1Play] – "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" "%1" (Ventis Media Inc.)
Directory [MediaMonkey.2PlayNext] – "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /NEXT "%1" (Ventis Media Inc.)
Directory [MediaMonkey.3Enqueue] – "C:\Program Files (x86)\MediaMonkey\MediaMonkey.exe" /ADD "%1" (Ventis Media Inc.)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 86 63 CB B5 79 3C C9 01 [binary data]
"VistaSp2" = 29 89 C8 08 91 E3 C9 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0AF0F4E2-A8EC-4683-BD7C-F27A7AB817B0}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0C30746F-169D-4B67-AAC1-D67DEF315C49}" = rport=10243 | protocol=6 | dir=out | app=system |
"{19D77A63-51E5-4F47-A40E-7365E6249FCC}" = lport=2869 | protocol=6 | dir=in | app=system |
"{1B1D802F-7E56-4DB4-886F-42F77B3830DC}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2162921C-81FF-49FF-9D5E-5639C5F4CE81}" = lport=137 | protocol=17 | dir=in | app=system |
"{27179819-2137-43D7-90C9-13322E78F48F}" = lport=10243 | protocol=6 | dir=in | app=system |
"{27593AB3-F3C1-45E8-A52F-E48073D6B5F6}" = lport=139 | protocol=6 | dir=in | app=system |
"{39FAA7C2-3783-48E4-BBB6-4BAFDFE4229E}" = rport=137 | protocol=17 | dir=out | app=system |
"{3FBE4DC1-0A44-4563-A0D0-8E8E10454D9D}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 |
"{44B5A9B6-93F5-4A26-BFFD-7C28F1E20274}" = rport=445 | protocol=6 | dir=out | app=system |
"{4C465E55-FD53-47BE-9CFB-7B28B84FD572}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{6CC010D6-7D66-48D8-830A-D2EB31331B1B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7142FA0D-7249-4EC1-B365-7A38E845ED05}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7262555C-5D75-4129-82B1-27CCB0904502}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A40EC0D9-C77D-40F3-9422-458D7F53603D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{B70D60D9-9CDC-445F-9EE0-6FFF2793ECBB}" = lport=445 | protocol=6 | dir=in | app=system |
"{D7AE2A3E-3E84-4412-9665-5483F66FEEE6}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{E7D114D5-6A48-41C7-A804-3074D4902F0C}" = rport=138 | protocol=17 | dir=out | app=system |
"{EDEE8D63-80E6-4B7E-A631-769476616B5B}" = rport=139 | protocol=6 | dir=out | app=system |
"{EEACD182-196D-4A86-AEB6-2A8150ADDC78}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F2336454-9EE9-4E71-AFAB-18CBEF17932D}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F71E97FF-F58E-408E-8333-3959350AD9BF}" = lport=138 | protocol=17 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{010059A8-1BBC-4481-9BF0-097906AE8535}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{05CB3FB8-26A6-4FBD-A186-B7CE7E39D5FC}" = protocol=17 | dir=in | app=c:\program files\softscript\ssivoxplayer\ssivoxplayer.exe |
"{0CB40D16-4698-4910-BC56-9E48A552646D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{11DA3D27-46A8-4B2B-884D-239AA1600AE1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{14E388F4-B25C-448C-8535-DD7A7E005A00}" = protocol=6 | dir=in | app=c:\windows\system32\supdsvc.exe |
"{152B843E-7AEC-4853-8C91-0096A7DD8062}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{15EE0C52-48C1-40EF-8807-FB773E1E1DA9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{1C479EFB-DABC-4C8C-896B-2A2BF8B5F862}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\empire total war demo\empire.exe |
"{1FCAFAB1-7945-42B9-A8C4-2114DD17F65D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{1FF5462D-3901-4975-91F0-CF631602EA8D}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{2824FCFF-4321-4FFE-B092-66A482EF1E60}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe |
"{2E061F15-FC71-48C9-B062-04B60FC2B40F}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{304BFF29-786C-4BA3-8ECB-DE6B1FA5C4DB}" = protocol=17 | dir=in | app=c:\windows\system32\supdsvc.exe |
"{372C394B-4164-4BD8-9090-FD944CC70AF5}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe |
"{376938EF-93DD-4485-95C2-D973712BA545}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{3814265C-BBFF-49A9-943E-A9B6A214AB9D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3FAE04D3-57C0-416B-A468-AE9DF2EFE07C}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{401C830C-E908-4339-95AA-F308BA03D370}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{41B50745-FC21-4EC7-97AF-F6C69C701076}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{42DEF683-54F0-419C-8309-13DC7A18A24C}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.2.9901-to-3.1.3.9947-enus-downloader.exe |
"{45DC0035-BBA2-4502-9252-6E727D7D6D69}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe |
"{4A65A611-879E-467D-B71A-C1989F0779B5}" = protocol=17 | dir=in | app=c:\program files (x86)\softscript\sftrclient\sftrclient.exe |
"{56B3C475-D3C3-48BB-BCB2-DDF21D6633BB}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{571B517F-0943-4D42-B81B-E6BE3F8248D3}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{5B3CE2AD-85F3-45FC-9C61-DBE8BA1565B6}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{6FE48371-4108-4899-B2D9-E81902BA2481}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{708F0CF8-0DF6-485C-B93F-D2D03557779D}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{7719E841-0F04-482B-8699-51ECDA5DBCCB}" = protocol=6 | dir=in | app=c:\program files\softscript\ssivoxplayer\ssivoxplayer.exe |
"{7FF7A18F-306B-40BD-B867-F7BA6FB719AC}" = protocol=6 | dir=out | app=system |
"{85FF9D46-55CF-4BB1-9051-D8C9CAECBC59}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\empire total war demo\empire.exe |
"{88830778-662D-48C8-9FEB-9287AAA16665}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe |
"{8DCF1E75-7EE9-44F7-AE75-5C9F36351E2D}" = protocol=6 | dir=in | app=c:\program files (x86)\softscript\sftrclient\sftrclient.exe |
"{90A826C5-1A26-4037-A361-F4B86472FEB1}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |
"{92F2CE6F-F87F-4416-841D-01E3BAC22799}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{95589064-0229-421D-AD41-4B3B7CC8CAFF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\empire total war\empire.exe |
"{975BF5AF-4655-4891-AB25-F455D6714DFE}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{99F04F04-DE5C-4A50-90AE-0076E28A44EE}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{9A62D37A-D2E7-4D81-BEA6-830CEFBEBE9A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A3588213-55D3-4B79-9E5D-609C492BAA4F}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-enus-downloader.exe |
"{A7EC658A-8B0B-4C54-B09A-B73813F2FC76}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spectraball\spectraball.exe |
"{B6C0F68D-85DA-4289-A75F-12BE45F85F93}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{B7D52360-345C-460E-A857-D7C3381477C3}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{BD5B17FD-4810-490C-B22A-92D376E68824}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C6836A8B-E587-4CE9-BE13-E711A9707096}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{CB217C87-DF01-40BA-A345-9E6E8871F410}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{CD89012F-F8AE-45C3-B685-4D8B61519740}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe |
"{D83904DB-BEEF-4938-86DA-DA2916E7C9C9}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{DEC81621-5A6B-4C40-A56B-A4EEC98603A6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\empire total war\empire.exe |
"{E9285948-FF70-4B34-94FA-9D88B8606525}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe |
"{F43933BB-9A0E-4CA2-8A5F-B26203FE81B7}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.2.9901-to-3.1.3.9947-enus-downloader.exe |
"{F5C17BFB-A96A-404F-9927-C5EE136740D5}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-enus-downloader.exe |
"{F726EB6C-F8B2-43D7-9EB2-3E505F9916E8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{FA7A6F81-A806-473B-A8E0-DD501EA4CEE0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spectraball\spectraball.exe |
"TCP Query User{130C32A7-368B-4D64-8FF2-914768682D83}C:\program files (x86)\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files (x86)\real\realplayer\realplay.exe |
"TCP Query User{1662442B-B39D-4AC6-9396-8F89229C1BC5}C:\users\gaming\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe" = protocol=6 | dir=in | app=c:\users\gaming\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe |
"TCP Query User{24F1B28C-BD60-47C7-8050-0F63B581F90C}C:\users\gary\appdata\local\temp\blizzard launcher temporary - 1b714658\launcher.exe" = protocol=6 | dir=in | app=c:\users\gary\appdata\local\temp\blizzard launcher temporary - 1b714658\launcher.exe |
"TCP Query User{33459EF0-ADE0-4671-8F2B-7FF3617F4C4C}C:\users\gary\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe" = protocol=6 | dir=in | app=c:\users\gary\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe |
"TCP Query User{3B8113D9-0CB5-4DD5-A693-0F234421B283}D:\world of warcraft\repair.exe" = protocol=6 | dir=in | app=d:\world of warcraft\repair.exe |
"TCP Query User{6B2AA169-9F55-4045-988F-4F32FC125779}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"TCP Query User{77251446-8963-4155-81CC-0A943703ED23}C:\program files (x86)\quicktime\quicktimeplayer.exe" = protocol=6 | dir=in | app=c:\program files (x86)\quicktime\quicktimeplayer.exe |
"TCP Query User{7D1ADD4A-A746-4A9F-B552-E47DCFFE064A}D:\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=d:\world of warcraft\launcher.exe |
"TCP Query User{7F954C0A-DB8E-493A-9B51-86705AF3179A}C:\users\gary\appdata\local\temp\blizzard launcher temporary - 856b5d70\launcher.exe" = protocol=6 | dir=in | app=c:\users\gary\appdata\local\temp\blizzard launcher temporary - 856b5d70\launcher.exe |
"TCP Query User{8C1E2163-A889-432A-8E30-58E28E5B300E}C:\program files (x86)\gretech\gomplayer\gom.exe" = protocol=6 | dir=in | app=c:\program files (x86)\gretech\gomplayer\gom.exe |
"TCP Query User{992675CF-CF4D-44F0-90FA-402FF32A433A}C:\program files (x86)\gigabyte\@bios\gwflash.exe" = protocol=6 | dir=in | app=c:\program files (x86)\gigabyte\@bios\gwflash.exe |
"TCP Query User{9B0094FD-A87C-44F4-AEA2-82303B6AFC60}C:\users\gary\appdata\local\octoshape\octoshape streaming services\octoshapeclient.exe" = protocol=6 | dir=in | app=c:\users\gary\appdata\local\octoshape\octoshape streaming services\octoshapeclient.exe |
"TCP Query User{AD42D239-151A-4D3B-BBF6-0AD7699CBA23}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"TCP Query User{EA9BC793-128C-4451-BBA9-E0269A4C2ED3}D:\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=d:\world of warcraft\backgrounddownloader.exe |
"UDP Query User{3680E554-CF1C-4B5A-896C-EE71B30A2CD1}C:\program files (x86)\gigabyte\@bios\gwflash.exe" = protocol=17 | dir=in | app=c:\program files (x86)\gigabyte\@bios\gwflash.exe |
"UDP Query User{3684E0B0-D55C-4855-BD7C-C8F11D49DC8E}C:\users\gary\appdata\local\octoshape\octoshape streaming services\octoshapeclient.exe" = protocol=17 | dir=in | app=c:\users\gary\appdata\local\octoshape\octoshape streaming services\octoshapeclient.exe |
"UDP Query User{4B58CBD4-56B8-4FFE-953F-CAB67D060A59}C:\program files (x86)\quicktime\quicktimeplayer.exe" = protocol=17 | dir=in | app=c:\program files (x86)\quicktime\quicktimeplayer.exe |
"UDP Query User{58888D5F-6086-4277-8500-C4E67707FB9A}D:\world of warcraft\repair.exe" = protocol=17 | dir=in | app=d:\world of warcraft\repair.exe |
"UDP Query User{674592F5-DF3F-46B0-91E0-FCA1DE7FE4D2}D:\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=d:\world of warcraft\launcher.exe |
"UDP Query User{6BBB18A3-4153-40A1-B7B1-D7BB7DF354CC}C:\users\gary\appdata\local\temp\blizzard launcher temporary - 856b5d70\launcher.exe" = protocol=17 | dir=in | app=c:\users\gary\appdata\local\temp\blizzard launcher temporary - 856b5d70\launcher.exe |
"UDP Query User{7E1F2FB1-81D3-4BA6-87F7-E9CCA773A8D1}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"UDP Query User{8364F391-8CFF-44A2-993F-CFF103142A57}C:\users\gary\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe" = protocol=17 | dir=in | app=c:\users\gary\appdata\roaming\macromedia\flash player\www.macromedia.com\bin\octoshape\octoshape.exe |
"UDP Query User{8C270C61-7774-4FB1-9BA8-0B143CCDB9BE}C:\users\gary\appdata\local\temp\blizzard launcher temporary - 1b714658\launcher.exe" = protocol=17 | dir=in | app=c:\users\gary\appdata\local\temp\blizzard launcher temporary - 1b714658\launcher.exe |
"UDP Query User{A8569EB8-3C63-476F-B6AD-2FF5A4D19816}D:\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=d:\world of warcraft\backgrounddownloader.exe |
"UDP Query User{B1A79019-C0BC-4FB6-BFAB-414D6F91522F}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"UDP Query User{B9C5AF96-BB88-40CA-AFC5-0B531EC3C1CF}C:\program files (x86)\gretech\gomplayer\gom.exe" = protocol=17 | dir=in | app=c:\program files (x86)\gretech\gomplayer\gom.exe |
"UDP Query User{DB56F0C1-35B3-4634-BF0A-0A24ABCB7E3B}C:\program files (x86)\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files (x86)\real\realplayer\realplay.exe |
"UDP Query User{DB58C517-8113-4E2A-8434-F966CEE7775B}C:\users\gaming\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe" = protocol=17 | dir=in | app=c:\users\gaming\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{5EBE0F1F-45DF-4298-AC6B-E8E54EAEC834}" = Microsoft IntelliPoint 7.1
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95C9C76F-ECF3-40FA-94F8-5DDFB6BAF40D}" = Microsoft Security Essentials
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E590FD1C-E8C6-4D2E-8CA9-77B403F7EE01}" = Microsoft Antimalware
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64
"{F7513E19-6224-485E-988D-9BF45BE64B53}" = Windows Live Family Safety
"Defraggler" = Defraggler
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Essentials" = Microsoft Security Essentials
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{67ED38A3-4882-448B-B44D-3428AB00D7D5}" = Acronis True Image Home
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8FB1B528-E260-451E-9B55-E9152F94B80B}" = Microsoft Games for Windows - LIVE Redistributable
"{91CA0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Small Business Edition 2003
"{95120000-003F-0409-0000-0000000FF1CE}" = Microsoft Office Excel Viewer
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}" = @BIOS Ver.2.03
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{DB0A8A2A-4EA7-4FE3-802E-8A6DEE32696C}_is1" = Orban/Coding Technologies AAC/aacPlus Player Plugin™ 1.0
"{DFACE88E-BFD1-4E1F-AF5C-100C979A12B0}" = WinWay Resume Deluxe
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F97E3841-CA9D-4964-9D64-26066241D26F}" = Microsoft Games for Windows - LIVE
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"ALchemy" = Creative ALchemy
"AudioCS" = Creative Audio Control Panel
"CCleaner" = CCleaner
"Console Launcher" = Creative Console Launcher
"Cool Timer_is1" = Cool Timer 3.6
"Creative Sound Blaster Properties x64 Edition" = Creative Sound Blaster Properties x64 Edition
"Creative Volume Panel" = Volume Panel
"FastStone Image Viewer" = FastStone Image Viewer 3.9
"GOM Player" = GOM Player
"Instant Text V Pro" = Instant Text V Pro
"Karen's Alarm Clock" = Karen's Alarm Clock
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaMonkey_is1" = MediaMonkey 3.2
"OpenAL" = OpenAL
"Picasa 3" = Picasa 3
"ProcessScanner_is1" = Uniblue ProcessScanner
"RealPlayer 6.0" = RealPlayer
"Samsung ML-1710 Series" = Samsung ML-1710 Series
"Samsung Universal Print Driver" = Samsung Universal Print Driver
"Steam App 12900" = Audiosurf
"Steam App 18300" = Spectraball
"Steam App 400" = Portal
"Stedmans Spell Checker Setup_is1" = Stedmans Spell Checker Setup
"Switch" = Switch Sound File Converter
"SystemRequirementsLab" = System Requirements Lab
"VLC media player" = VLC media player 1.0.5
"Winamp" = Winamp
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Wisdom-soft ScreenHunter 5.0 Free" = Wisdom-soft ScreenHunter 5.0 Free
"XiphQT" = Xiph QuickTime Components

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f031ef6ac137efc5" = Dell Driver Download Manager
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
"Octoshape Streaming Services" = Octoshape Streaming Services
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/10/2010 2:19:23 PM | Computer Name = Gary-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 6/10/2010 2:36:25 PM | Computer Name = Gary-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 6/10/2010 5:47:25 PM | Computer Name = Gary-PC | Source = EventSystem | ID = 4609
Description =

Error - 6/10/2010 5:48:28 PM | Computer Name = Gary-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 6/10/2010 5:48:28 PM | Computer Name = Gary-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 6/11/2010 3:49:03 AM | Computer Name = Gary-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 6/11/2010 3:49:03 AM | Computer Name = Gary-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 6/12/2010 6:16:11 PM | Computer Name = Gary-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 6/13/2010 9:51:53 AM | Computer Name = Gary-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

Error - 6/13/2010 9:51:53 AM | Computer Name = Gary-PC | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.

[ System Events ]
Error - 6/10/2010 6:03:33 PM | Computer Name = Gary-PC | Source = DCOM | ID = 10005
Description =

Error - 6/11/2010 2:19:51 AM | Computer Name = Gary-PC | Source = DCOM | ID = 10005
Description =

Error - 6/11/2010 3:46:27 AM | Computer Name = Gary-PC | Source = DCOM | ID = 10010
Description =

Error - 6/11/2010 3:47:54 AM | Computer Name = Gary-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.100 for the Network Card with network
address 0016E65A2068 has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).

Error - 6/11/2010 3:49:23 AM | Computer Name = Gary-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 6/11/2010 3:52:37 AM | Computer Name = Gary-PC | Source = Print | ID = 19
Description = The print spooler failed to share printer Samsung ML-1710 Series with
shared resource name Samsung ML-1710 Series. Error 2114. The printer cannot be
used by others on the network.

Error - 6/11/2010 3:53:54 AM | Computer Name = Gary-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 6/12/2010 3:08:02 PM | Computer Name = Gary-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 6/13/2010 9:51:05 AM | Computer Name = Gary-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.100 for the Network Card with network
address 0016E65A2068 has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).

Error - 6/13/2010 9:52:28 AM | Computer Name = Gary-PC | Source = Service Control Manager | ID = 7000
Description =


< End of report >
From the log, it looks as though you have deleted what was on your machine,

just a couple of entries to look after

please do the following:

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:62747
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log


NEXT


Please do the following:


**Vista users - right click on the IE icon and run as administrator

Go here to run an online scanner from ESET.

  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
For some reason, IE is still not working. :popcorn: Therefore, I am unable to run Eset's scanner. However, I managed to run OTL and this is the resulting log: All processes killed Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! Error: Unable to interpret in the current context! ========== COMMANDS ========== File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot. HOSTS file reset successfully [EMPTYFLASH] User: All Users User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: Gaming ->Flash cache emptied: 0 bytes User: Gary ->Flash cache emptied: 0 bytes User: Public User: Work ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0.00 mb [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Gaming ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Gary ->Temp folder emptied: 31832 bytes ->Temporary Internet Files folder emptied: 93478 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public User: Work ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 1512084 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 525078 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 32768 bytes %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 2.00 mb OTL by OldTimer - Version 3.2.6.0 log created on 06132010_134556 Files\Folders moved on Reboot… File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot. File move failed. C:\Windows\SysNative\SET1582.tmp scheduled to be moved on reboot. File move failed. C:\Windows\SysNative\SET1611.tmp scheduled to be moved on reboot. File move failed. C:\Windows\SysNative\SET2E52.tmp scheduled to be moved on reboot. File move failed. C:\Windows\SysNative\SET2EC3.tmp scheduled to be moved on reboot. File move failed. C:\Windows\SysNative\SETA0CC.tmp scheduled to be moved on reboot. File move failed. C:\Windows\SysNative\SETA2C3.tmp scheduled to be moved on reboot. File move failed. C:\Windows\SysNative\SETBFFF.tmp scheduled to be moved on reboot. File move failed. C:\Windows\SysNative\SETC0EC.tmp scheduled to be moved on reboot. File\Folder C:\Windows\temp\TMP0000000E17D2C4BAD1FC8AD2 not found! Registry entries deleted on Reboot…
Hi,

can you please run that fix again, but make sure you don't copy the word "code"

start with the colon in front of :OTL

Try resetting IE back to default:

go here and use the fix-it button

http://support.microsoft.com/kb/923737
I performed the fix and the scan and everything worked well. IE is working well. I have a couple of questions though….

  • Is it safe to reinstall FireFox and Chrome?
  • How could I prevent this from happening again? I'm on a tight budget ATM, so I have to rely on freebies.
Thanks once again for all your help :notworthy:

Here are my scan results:

All processes killed
========== OTL ==========
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
========== COMMANDS ==========
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
HOSTS file reset successfully

[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Gaming
->Flash cache emptied: 0 bytes

User: Gary
->Flash cache emptied: 0 bytes

User: Public

User: Work
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Gaming
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Gary
->Temp folder emptied: 32436 bytes
->Temporary Internet Files folder emptied: 120616 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: Work
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 1512084 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 525866 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 2.00 mb


OTL by OldTimer - Version 3.2.6.0 log created on 06132010_143414

Files\Folders moved on Reboot…
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\SET1582.tmp scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\SET1611.tmp scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\SET2E52.tmp scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\SET2EC3.tmp scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\SETA0CC.tmp scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\SETA2C3.tmp scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\SETBFFF.tmp scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\SETC0EC.tmp scheduled to be moved on reboot.
File\Folder C:\Windows\temp\TMP00000014D41F83C03894F556 not found!

Registry entries deleted on Reboot…



———————————————————————————————————————-

ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0338)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-06-13 10:19:16
# local_time=2010-06-13 06:19:16 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=768 16777215 100 0 0 0 0 0
# compatibility_mode=5891 16776573 100 83 0 15970075 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=129656
# found=0
# cleaned=0
# scan_time=9784
# nod_component=V3 Build:0x30000000
esets_scanner_update returned -1 esets_gle=53251
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0338)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-06-14 01:12:22
# local_time=2010-06-13 09:12:22 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=768 16777215 100 0 0 0 0 0
# compatibility_mode=5891 16776573 100 83 0 15983090 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=242813
# found=0
# cleaned=0
# scan_time=7155
# nod_component=V3 Build:0x30000000
Hi

Yes, go ahead and reinstall those programs

Install the latest Java from here
http://www.java.com/en/download/manual.jsp

Please advise if you have any outstanding issues

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI