This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

computer acting weird

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:28:00, on 31-10-2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16671)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
C:\Program Files (x86)\AutoHotkey\AutoHotkey.exe
C:\Program Files (x86)\ShaPlus Bandwidth Meter\ShaPlus Bandwidth Meter.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\Program Files (x86)\HideIPEasy\HideIPEasy.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\AIM\aim.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.danskebank.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 72.254.128.201:80
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [ShaPlus Bandwidth Meter] "C:\Program Files (x86)\ShaPlus Bandwidth Meter\ShaPlus Bandwidth Meter" /s
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [Hide IP Easy] C:\Program Files (x86)\HideIPEasy\HideIPEasy.exe
O4 - HKCU\..\Run: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-US
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Itunes_script.ahk
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device… - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.danskebank.dk/html/activex/…B/e-Safekey.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Bonjour tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files (x86)\WinPcap\rpcapd.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Sandboxie Service (SbieSvc) - SANDBOXIE L.T.D - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: @C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VSNService - Sony Corporation - C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

–
End of file - 12158 bytes
Hello deloux :welcome:

Before we begin, I would like to make a few things clear so that we can fix your problem as efficiently as possible:
  • Be sure to follow all my instructions carefully! If there is anything you don''t understand, don't hesitate to ask.
  • Please do not do anything or perform other steps unless I have asked you to do so.
  • Please make sure you post all logs I ask you to, and make sure that the entire log gets posted.


Step 1

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan bot paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Step 2

Download the GMER Rootkit Scanner.

  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe.
    [external image: Posted Image]
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan…click on NO, then use the following settings for a more complete scan..
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
      [external image: Posted Image]
      Click the image to enlarge it
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
  • Save the log where you can easily find it, such as your desktop.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Please copy and paste the report into your Post.


Things I would like to see in your reply:
  • OTL.txt and Extras.txt
  • GMER Log ark.txt
OTL logfile created on: 31/10/2010 16:10:42 - Run 1
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Users\Mads\Documents\Downloads\Programs
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: Denmark | Language: DAN | Date Format: dd-MM-yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 284.05 Gb Total Space | 119.62 Gb Free Space | 42.11% Space Free | Partition Type: NTFS

Computer Name: MADS-VAIO | User Name: Mads | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/10/31 16:03:47 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Mads\My Documents\Downloads\Programs\OTL.exe
PRC - [2010/10/13 00:11:42 | 004,258,136 | —- | M] (AOL Inc.) – C:\Program Files (x86)\AIM\aim.exe
PRC - [2010/09/27 09:40:10 | 003,804,912 | —- | M] (easy-hideip.com) – C:\Program Files (x86)\HideIPEasy\HideIPEasy.exe
PRC - [2010/07/06 16:03:00 | 000,173,352 | —- | M] (TeamViewer GmbH) – C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe
PRC - [2010/06/10 20:03:08 | 000,144,176 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/03/06 03:04:24 | 000,310,224 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
PRC - [2010/01/25 21:12:36 | 003,179,952 | —- | M] (Tonec Inc.) – C:\Program Files (x86)\Internet Download Manager\IDMan.exe
PRC - [2010/01/04 16:08:46 | 000,151,552 | —- | M] (ShaPlus Software) – C:\Program Files (x86)\ShaPlus Bandwidth Meter\ShaPlus Bandwidth Meter.exe
PRC - [2009/12/23 22:34:20 | 000,370,688 | —- | M] (StarWind Software) – C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
PRC - [2009/12/14 21:06:24 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2009/12/14 21:06:08 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/11/21 00:25:24 | 000,013,336 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2009/11/21 00:25:22 | 000,284,696 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [2009/11/09 04:17:50 | 000,180,224 | —- | M] (PowerISO Computing, Inc.) – C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
PRC - [2009/10/15 10:51:51 | 000,263,600 | —- | M] (Tonec Inc.) – C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
PRC - [2009/09/25 19:57:38 | 000,245,248 | —- | M] () – C:\Program Files (x86)\AutoHotkey\AutoHotkey.exe
PRC - [2005/07/15 22:48:33 | 000,479,232 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe


========== Modules (SafeList) ==========

MOD - [2010/10/31 16:03:47 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Mads\My Documents\Downloads\Programs\OTL.exe
MOD - [2010/08/21 06:21:32 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - File not found [On_Demand | Stopped] – C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe – (VcmXmlIfHelper)
SRV:64bit: - [2010/09/30 16:51:32 | 000,036,160 | —- | M] (TuneUp Software) [Auto | Running] – C:\Windows\SysNative\uxtuneup.dll – (UxTuneUp)
SRV:64bit: - [2010/08/08 16:57:08 | 000,099,048 | —- | M] (SANDBOXIE L.T.D) [Auto | Running] – C:\Program Files\Sandboxie\SbieSvc.exe – (SbieSvc)
SRV:64bit: - [2010/03/25 22:48:42 | 000,017,424 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe – (MsMpSvc)
SRV:64bit: - [2009/11/30 20:51:18 | 000,571,248 | —- | M] (Sony Corporation) [On_Demand | Running] – C:\Program Files\Sony\VAIO Power Management\SPMService.exe – (VAIO Power Management)
SRV:64bit: - [2009/11/25 20:06:06 | 000,821,760 | —- | M] (Sony Corporation) [Auto | Running] – C:\Program Files\Sony\VAIO Smart Network\VSNService.exe – (VSNService)
SRV:64bit: - [2009/09/04 22:35:12 | 000,873,248 | —- | M] (Broadcom Corporation.) [Auto | Running] – C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe – (btwdins)
SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2010/10/18 10:34:06 | 000,607,040 | —- | M] (TuneUp Software) [On_Demand | Stopped] – C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe – (TuneUp.Defrag)
SRV - [2010/09/30 16:56:12 | 001,403,200 | —- | M] (TuneUp Software) [Auto | Running] – C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe – (TuneUp.UtilitiesSvc)
SRV - [2010/09/30 16:51:26 | 000,030,016 | —- | M] (TuneUp Software) [Auto | Running] – C:\Windows\SysWOW64\uxtuneup.dll – (UxTuneUp)
SRV - [2010/09/29 19:02:11 | 002,950,744 | —- | M] () [Auto | Running] – C:/Program Files (x86)/Common Files/Akamai/netsession_win_062a651.dll – (Akamai)
SRV - [2010/07/06 16:03:00 | 000,173,352 | —- | M] (TeamViewer GmbH) [Auto | Running] – C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe – (TeamViewer5)
SRV - [2010/06/10 20:03:08 | 000,144,176 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2010/06/02 14:07:52 | 000,655,624 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2010/03/18 10:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe – (ACDaemon)
SRV - [2010/02/19 12:37:14 | 000,517,096 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe – (SwitchBoard)
SRV - [2009/12/23 22:34:20 | 000,370,688 | —- | M] (StarWind Software) [Auto | Running] – C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe – (StarWindServiceAE)
SRV - [2009/12/14 21:06:24 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS) Intel®
SRV - [2009/12/14 21:06:08 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS) Intel®
SRV - [2009/11/21 00:25:24 | 000,013,336 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc) Intel®
SRV - [2009/10/20 19:19:48 | 000,117,264 | —- | M] (CACE Technologies, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\WinPcap\rpcapd.exe – (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2009/06/17 10:18:42 | 006,582,912 | —- | M] () [On_Demand | Stopped] – c:\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe – (wampmysqld)
SRV - [2009/06/10 22:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2008/12/10 00:10:14 | 000,024,636 | —- | M] (Apache Software Foundation) [On_Demand | Stopped] – c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe – (wampapache)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/08/08 17:03:24 | 000,143,464 | —- | M] (SANDBOXIE L.T.D) [Kernel | On_Demand | Running] – C:\Program Files\Sandboxie\SbieDrv.sys – (SbieDrv)
DRV:64bit: - [2010/06/23 03:47:58 | 000,037,888 | —- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\taphss.sys – (taphss)
DRV:64bit: - [2010/04/19 19:47:42 | 000,050,688 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2010/04/08 13:35:34 | 000,021,184 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\CPen.sys – (CPen)
DRV:64bit: - [2010/03/15 00:22:32 | 000,834,544 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\sptd.sys – (sptd)
DRV:64bit: - [2009/12/24 21:06:08 | 006,106,624 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\atikmdag.sys – (atikmdag)
DRV:64bit: - [2009/12/16 21:03:59 | 000,244,736 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud) Intel®
DRV:64bit: - [2009/12/16 21:03:04 | 007,778,176 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2009/12/14 21:06:07 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:64bit: - [2009/11/21 00:09:48 | 000,537,112 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/11/18 05:30:44 | 000,021,160 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\btwrchid.sys – (btwrchid)
DRV:64bit: - [2009/11/18 05:30:32 | 000,132,648 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\btwavdt.sys – (btwavdt)
DRV:64bit: - [2009/11/18 05:30:32 | 000,098,344 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\btwaudio.sys – (btwaudio)
DRV:64bit: - [2009/11/18 05:30:21 | 000,052,264 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\btusbflt.sys – (btusbflt)
DRV:64bit: - [2009/11/18 05:23:46 | 000,035,104 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\btwl2cap.sys – (btwl2cap)
DRV:64bit: - [2009/11/13 21:08:21 | 000,151,936 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:64bit: - [2009/11/12 21:16:19 | 000,395,264 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\yk62x64.sys – (yukonw7)
DRV:64bit: - [2009/11/12 21:06:44 | 001,542,656 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\athrx.sys – (athr)
DRV:64bit: - [2009/11/06 21:27:30 | 000,093,696 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\rimssne64.sys – (rimspci)
DRV:64bit: - [2009/11/04 10:59:59 | 000,253,488 | —- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Apfiltr.sys – (ApfiltrService)
DRV:64bit: - [2009/10/20 19:19:54 | 000,047,632 | —- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\npf.sys – (NPF)
DRV:64bit: - [2009/09/15 21:09:08 | 000,075,776 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\risdsne64.sys – (risdsnpe)
DRV:64bit: - [2009/08/19 21:09:21 | 000,011,392 | —- | M] (Sony Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SFEP.sys – (SFEP)
DRV:64bit: - [2009/07/14 02:52:21 | 000,106,576 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2009/07/14 02:52:21 | 000,028,752 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/14 00:31:10 | 000,109,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\sdbus.sys – (sdbus)
DRV:64bit: - [2009/06/10 21:38:56 | 000,000,308 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\wbem\ntfs.mof – (Ntfs)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/18 12:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2008/03/13 08:46:00 | 000,027,136 | —- | M] (ManyCam LLC.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ManyCam_x64.sys – (ManyCam)
DRV - [2010/02/24 13:41:50 | 000,011,856 | —- | M] (TuneUp Software) [Kernel | On_Demand | Running] – C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys – (TuneUpUtilitiesDrv)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…C&bmod;=EU01
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.danskebank.dk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:6.9.1
FF - prefs.js..extensions.enabledItems: [removed]:1.6.1
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/09/29 14:51:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/10/31 00:45:08 | 000,000,000 | —D | M]

[2010/03/12 19:09:46 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\Mozilla\Extensions
[2010/10/31 11:13:42 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\Mozilla\Firefox\Profiles\rg6lgvnn.default\extensions
[2010/09/18 21:42:47 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Mads\AppData\Roaming\Mozilla\Firefox\Profiles\rg6lgvnn.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/08/14 13:08:23 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\Mozilla\Firefox\Profiles\rg6lgvnn.default\extensions\[removed]
[2010/09/16 17:30:37 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\Mozilla\Firefox\Profiles\rg6lgvnn.default\extensions\[removed]
[2010/10/31 11:13:42 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\Mozilla\Firefox\Profiles\rg6lgvnn.default\extensions\[removed]
[2010/06/08 10:28:50 | 000,000,929 | —- | M] () – C:\Users\Mads\AppData\Roaming\Mozilla\Firefox\Profiles\rg6lgvnn.default\searchplugins\conduit.xml
[2010/03/14 23:23:19 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/03/14 23:23:19 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/09/29 14:51:30 | 000,001,525 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\amazon-co-uk.xml
[2010/09/29 14:51:30 | 000,001,178 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\wikipedia-da.xml
[2010/09/29 14:51:30 | 000,001,102 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo-dk.xml

O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Tonec Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe (Google Inc.)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [ShaPlus Bandwidth Meter] File not found
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [Aim] C:\Program Files (x86)\AIM\aim.exe (AOL Inc.)
O4 - HKCU..\Run: [Hide IP Easy] C:\Program Files (x86)\HideIPEasy\HideIPEasy.exe (easy-hideip.com)
O4 - HKCU..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
O4 - Startup: C:\Users\Mads\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Itunes_script.ahk ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8:64bit: - Extra context menu item: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm ()
O8:64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth; Device… - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} https://netbank.danskebank.dk/html/activex/…B/e-Safekey.cab (e-Safekey)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\Windows\SysWow64\VESWinlogon.dll (Sony Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{19515331-c367-11df-bd57-0024bebab327}\Shell - "" = AutoRun
O33 - MountPoints2\{19515331-c367-11df-bd57-0024bebab327}\Shell\AutoRun\command - "" = J:\Startme.exe – File not found
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\autoplay.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: UxTuneUp - C:\Windows\SysNative\uxtuneup.dll (TuneUp Software)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.vorbis - C:\Windows\SysWow64\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/10/31 11:22:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/10/31 00:45:33 | 000,000,000 | —D | C] – C:\Users\Mads\AppData\Roaming\acccore
[2010/10/31 00:45:31 | 000,000,000 | —D | C] – C:\Users\Mads\AppData\Local\AOL
[2010/10/31 00:45:31 | 000,000,000 | —D | C] – C:\Users\Mads\AppData\Local\AIM
[2010/10/31 00:45:26 | 000,000,000 | —D | C] – C:\ProgramData\AIM
[2010/10/31 00:45:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Software Update Utility
[2010/10/31 00:45:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\AIM
[2010/10/31 00:45:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AOL
[2010/10/29 10:15:30 | 000,000,000 | —D | C] – C:\Users\Mads\Desktop\faktura assasins creed_files
[2010/10/27 21:43:53 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2010/10/27 15:43:53 | 000,000,000 | —D | C] – C:\Users\Mads\Desktop\Adobe Flash Professional CS5
[2010/10/26 22:19:08 | 000,000,000 | —D | C] – C:\Users\Mads\AppData\Local\Unity
[2010/10/26 22:16:33 | 000,000,000 | —D | C] – C:\Users\Mads\AppData\Roaming\Electronic Arts
[2010/10/26 18:19:30 | 000,000,000 | —D | C] – C:\Users\Mads\AppData\Local\ElevatedDiagnostics
[2010/10/24 18:38:50 | 000,000,000 | —D | C] – C:\Users\Mads\Desktop\film
[2010/10/24 17:18:00 | 000,000,000 | —D | C] – C:\Users\Mads\AppData\Roaming\HideIPEasy
[2010/10/24 17:18:00 | 000,000,000 | —D | C] – C:\ProgramData\HideIPEasy
[2010/10/24 17:17:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\HideIPEasy
[2010/10/24 16:28:28 | 000,061,440 | —- | C] (MagTek,Inc.) – C:\Windows\SysWow64\MTUSBHIDSwipe.ocx
[2010/10/24 16:28:27 | 000,000,000 | —D | C] – C:\Windows\SigPlus
[2010/10/20 02:08:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
[2010/10/20 02:05:27 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2010/10/18 10:34:19 | 000,034,624 | —- | C] (TuneUp Software) – C:\Windows\SysNative\TURegOpt.exe
[2010/10/18 10:34:12 | 000,036,160 | —- | C] (TuneUp Software) – C:\Windows\SysNative\uxtuneup.dll
[2010/10/18 10:34:12 | 000,030,016 | —- | C] (TuneUp Software) – C:\Windows\SysWow64\uxtuneup.dll
[2010/10/18 10:34:12 | 000,025,920 | —- | C] (TuneUp Software) – C:\Windows\SysNative\authuitu.dll
[2010/10/18 10:34:12 | 000,021,312 | —- | C] (TuneUp Software) – C:\Windows\SysWow64\authuitu.dll
[2010/10/18 10:33:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\TuneUp Utilities 2010
[2010/10/18 10:13:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Antimalware
[2010/10/18 10:13:14 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Essentials
[2010/10/16 13:48:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Fusion
[2010/10/16 00:09:57 | 000,000,000 | —D | C] – C:\Users\Mads\Desktop\PlayStation 3
[2010/10/16 00:09:29 | 000,000,000 | —D | C] – C:\Users\Mads\AppData\Roaming\Nero
[2010/10/16 00:09:25 | 000,000,000 | —D | C] – C:\Users\Mads\AppData\Local\Nero
[2010/10/16 00:04:23 | 000,000,000 | —D | C] – C:\ProgramData\Nero
[2010/10/16 00:04:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Nero
[2010/10/16 00:02:07 | 000,000,000 | —D | C] – C:\Users\Mads\Desktop\Nero MediaHome 4 Essentials
[2010/10/15 23:51:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\ShaPlus Bandwidth Meter
[2010/10/15 23:50:56 | 000,000,000 | —D | C] – C:\Users\Mads\Desktop\11w
[2010/10/12 10:12:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ordbog
[2010/10/03 13:16:33 | 000,000,000 | —D | C] – C:\Users\Mads\.oces
[3 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/10/31 15:48:14 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/10/31 11:43:54 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/10/31 11:43:54 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/10/31 11:22:44 | 000,002,971 | —- | M] () – C:\Users\Mads\Desktop\HiJackThis.lnk
[2010/10/31 00:45:31 | 000,000,362 | -H– | M] () – C:\IPH.PH
[2010/10/31 00:45:26 | 000,001,941 | —- | M] () – C:\Users\Mads\Application Data\Microsoft\Internet Explorer\Quick Launch\AIM.lnk
[2010/10/31 00:45:25 | 000,001,917 | —- | M] () – C:\Users\Public\Desktop\AIM.lnk
[2010/10/30 20:59:30 | 2955,485,184 | -HS- | M] () – C:\hiberfil.sys
[2010/10/29 10:38:09 | 000,727,362 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/10/29 10:38:09 | 000,615,958 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/10/29 10:38:09 | 000,107,594 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/10/29 10:30:58 | 000,011,811 | —- | M] () – C:\Users\Mads\Desktop\Kildelæsning.docx
[2010/10/29 10:30:58 | 000,000,162 | -H– | M] () – C:\Users\Mads\Desktop\~$ldelæsning.docx
[2010/10/29 10:15:31 | 000,041,849 | —- | M] () – C:\Users\Mads\Desktop\faktura assasins creed.htm
[2010/10/24 17:17:56 | 000,001,035 | —- | M] () – C:\Users\Public\Desktop\Hide IP Easy.lnk
[2010/10/24 16:29:19 | 000,000,981 | —- | M] () – C:\Users\Mads\Desktop\SigCard1Client.lnk
[2010/10/18 10:34:05 | 000,002,181 | —- | M] () – C:\Users\Public\Desktop\TuneUp 1-Click Maintenance.lnk
[2010/10/18 10:34:05 | 000,002,163 | —- | M] () – C:\Users\Public\Desktop\TuneUp Utilities.lnk
[2010/10/18 10:13:15 | 000,001,023 | —- | M] () – C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010/10/16 13:48:25 | 000,001,150 | —- | M] () – C:\Users\Mads\Desktop\FUSION WOL.lnk
[2010/10/13 02:19:43 | 003,118,320 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/10/07 11:40:13 | 000,000,000 | —- | M] () – C:\Users\Mads\temp.dat
[3 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/10/31 11:22:44 | 000,002,971 | —- | C] () – C:\Users\Mads\Desktop\HiJackThis.lnk
[2010/10/31 00:45:26 | 000,001,941 | —- | C] () – C:\Users\Mads\Application Data\Microsoft\Internet Explorer\Quick Launch\AIM.lnk
[2010/10/31 00:45:25 | 000,001,917 | —- | C] () – C:\Users\Public\Desktop\AIM.lnk
[2010/10/31 00:44:50 | 000,000,362 | -H– | C] () – C:\IPH.PH
[2010/10/29 10:30:58 | 000,011,811 | —- | C] () – C:\Users\Mads\Desktop\Kildelæsning.docx
[2010/10/29 10:30:58 | 000,000,162 | -H– | C] () – C:\Users\Mads\Desktop\~$ldelæsning.docx
[2010/10/29 10:15:30 | 000,041,849 | —- | C] () – C:\Users\Mads\Desktop\faktura assasins creed.htm
[2010/10/27 19:54:40 | 000,173,535 | —- | C] () – C:\Users\Mads\Desktop\Super.High.Me.2007.DVDRip.XviD-NODLABS.srt
[2010/10/27 19:52:01 | 733,888,512 | —- | C] () – C:\Users\Mads\Desktop\Super.High.Me.2007.DVDRip.XviD-NODLABS.avi
[2010/10/24 17:17:56 | 000,001,035 | —- | C] () – C:\Users\Public\Desktop\Hide IP Easy.lnk
[2010/10/24 16:29:19 | 000,000,981 | —- | C] () – C:\Users\Mads\Desktop\SigCard1Client.lnk
[2010/10/18 10:34:05 | 000,002,181 | —- | C] () – C:\Users\Public\Desktop\TuneUp 1-Click Maintenance.lnk
[2010/10/18 10:34:05 | 000,002,163 | —- | C] () – C:\Users\Public\Desktop\TuneUp Utilities.lnk
[2010/10/18 10:13:15 | 000,001,023 | —- | C] () – C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010/10/16 13:48:25 | 000,001,150 | —- | C] () – C:\Users\Mads\Desktop\FUSION WOL.lnk
[2010/10/03 13:16:34 | 000,000,000 | —- | C] () – C:\Users\Mads\temp.dat
[2010/10/02 15:33:31 | 482,878,739 | —- | C] () – C:\Users\Mads\Desktop\Half.Baked.1998.m720p.ManO.mkv
[2010/09/29 13:35:40 | 000,230,752 | —- | C] () – C:\Windows\patchw32.dll
[2010/09/29 13:35:40 | 000,118,176 | —- | C] () – C:\Windows\patchw.dll
[2010/09/19 00:36:49 | 000,000,090 | —- | C] () – C:\Windows\WININIT.INI
[2010/09/18 21:23:43 | 000,001,282 | —- | C] () – C:\Windows\Sandboxie.ini
[2010/09/01 10:26:29 | 000,000,132 | —- | C] () – C:\Users\Mads\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/07/27 23:25:02 | 000,000,092 | —- | C] () – C:\Users\Mads\AppData\Local\fusioncache.dat
[2010/03/17 08:04:31 | 000,735,290 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/03/16 13:19:54 | 000,000,207 | —- | C] () – C:\Windows\Ic32.ini
[2010/03/15 00:45:21 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/03/14 16:50:09 | 000,000,000 | —- | C] () – C:\Users\Mads\AppData\Roaming\chrtmp
[2009/12/26 01:43:03 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2009/12/26 01:43:03 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2009/11/06 10:58:04 | 000,178,975 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2009/10/20 19:19:30 | 000,053,299 | —- | C] () – C:\Windows\SysWow64\pthreadVC.dll
[2009/07/14 00:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 22:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2007/04/27 09:43:58 | 000,120,200 | —- | C] () – C:\Windows\SysWow64\DLLDEV32i.dll

========== LOP Check ==========

[2010/10/31 00:47:39 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\acccore
[2010/09/03 11:43:19 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\C Technologies
[2010/10/30 21:00:22 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\DMCache
[2010/10/26 22:16:33 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\Electronic Arts
[2010/10/24 17:18:00 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\HideIPEasy
[2010/09/29 13:37:22 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\IDM
[2010/07/21 02:02:56 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\Leadertech
[2010/09/01 09:09:52 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\MAGIX
[2010/05/08 18:35:29 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\ManyCam
[2010/04/15 09:02:55 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\OpenCandy
[2010/09/19 00:34:22 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\phpDesigner
[2010/04/13 07:42:47 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\Red Kawa
[2010/08/14 20:20:46 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\TeamViewer
[2010/04/04 21:48:21 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\The Creative Assembly
[2010/09/18 21:31:13 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\TuneUp Software
[2010/09/19 13:07:42 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\uTorrent
[2010/03/15 12:34:25 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\VitySoft
[2010/08/23 14:19:59 | 000,032,656 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/04/09 14:44:29 | 000,608,256 | —- | M] () – C:\blackra1n.exe
[2010/04/09 14:57:36 | 000,000,000 | —- | M] () – C:\blackra1n.log
[2010/10/30 20:59:30 | 2955,485,184 | -HS- | M] () – C:\hiberfil.sys
[2010/10/31 00:45:31 | 000,000,362 | -H– | M] () – C:\IPH.PH
[2000/10/30 12:04:06 | 000,045,936 | —- | M] (LEAD Technologies, Inc.) – C:\ltvdd10w.drv
[2010/01/23 06:03:59 | 000,305,864 | —- | M] () – C:\lv.log
[2010/10/30 20:59:35 | 3940,651,008 | -HS- | M] () – C:\pagefile.sys
[2000/10/30 12:04:08 | 000,029,184 | —- | M] (Blue Sky Software) – C:\Popup.ocx
[2010/01/23 06:00:19 | 000,002,269 | —- | M] () – C:\RHDSetup.log
[2010/01/23 06:03:54 | 000,000,073 | -H– | M] () – C:\splash.idx
[2009/12/15 12:53:48 | 000,003,872 | -H– | M] () – C:\version

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >







OTL Extras logfile created on: 31/10/2010 16:10:42 - Run 1
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Users\Mads\Documents\Downloads\Programs
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: Denmark | Language: DAN | Date Format: dd-MM-yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 284.05 Gb Total Space | 119.62 Gb Free Space | 42.11% Space Free | Partition Type: NTFS

Computer Name: MADS-VAIO | User Name: Mads | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\System32\ieframe.DLL (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.url [@ = InternetShortcut] – C:\Windows\System32\ieframe.DLL (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{26A24AE4-039D-4CA4-87B4-2F86416016FF}" = Java™ 6 Update 16 (64-bit)
"{328CC232-CFDC-468B-A214-2E21300E4CB5}" = Apple Mobile Device Support
"{6522F10D-3EB1-4FF4-8758-ABFB227CD8B5}" = Microsoft Antimalware Service DA-DK Language Pack
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{8F790958-2107-48F2-88E0-B352A0C225AB}" = iTunes
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95C9C76F-ECF3-40FA-94F8-5DDFB6BAF40D}" = Microsoft Security Essentials
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = WIDCOMM Bluetooth Software
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Alps Pointing-device for VAIO
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{B91110FB-33B4-468B-90C2-4D5E8AE3FAE1}" = Bonjour
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"3BA80AB4C7E9F8497C115C844953A3D4BEB84D21" = Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800)
"930E4792BDAEAFB62A9514EE7578775658A5D07C" = Windows Driver Package - Broadcom Bluetooth (09/09/2009 6.2.0.9405)
"CD890B33C151F0A9940A3982594354969B729745" = Windows Driver Package - C Technologies AB (CPen) Input Pen (02/22/2010 3.0.0.2)
"Defraggler" = Defraggler
"Microsoft Security Essentials" = Microsoft Security Essentials
"Sandboxie" = Sandboxie 3.47.04 (64-bit)
"WinRAR archiver" = WinRAR archiver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}" = Microsoft Games for Windows - LIVE Redistributable
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" = Google Gmail Notifier
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{06F80017-8F98-4C94-B868-52358569FC32}" = Command & Conquer Generals
"{0899D75A-C2FC-42EA-A702-5B9A5F24EAD5}" = VAIO Smart Network
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{121C477C-5B7B-44E3-B621-BDDB542AE8FD}" = TuneUp Utilities Language Pack (en-GB)
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16C315AA-1027-4530-92E1-C47CA832E330}" = Xara Designer Pro 6 Content Pack
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1D13459A-B743-46D8-B1D7-BECAC7ED4C17}" = Fists of Fu
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 17
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}" = Microsoft Games for Windows - LIVE
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{34DC654E-6E43-4BFA-9E00-6C16CFA7B9F0}" = VAIO Data Restore Tool
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{411F3ABA-2AB5-4799-AA19-6ADF0A8F7424}" = Adobe Setup
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{44E240EC-2224-4078-A88B-2CEE0D3016EF}" = Adobe After Effects CS4 Presets
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{45EC816C-0771-4C14-AE6D-72D1B578F4C8}" = Adobe After Effects CS4
"{4BE09A97-FEA8-4ACA-8684-C0F8CF418034}" = Fists of Fu
"{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}" = VAIO Data Restore Tool
"{5E22DF13-BF77-4E88-9BC1-8367FE35DE6F}" = C-Pen Core
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6E9EF98E-259E-416D-B5F8-0ABDB99942CE}" = Adobe Flash Player 10 ActiveX
"{70991E0A-1108-437E-BA7D-085702C670C0}" =
"{72042FA6-5609-489F-A8EA-3C2DD650F667}" = VAIO Control Center
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{803E4FA5-A940-4420-B89D-A8BC2E160247}" = VAIO Power Management
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{931FE23C-BB40-4C7A-A594-DB35908D8E83}" = VAIO Quick Web Access
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{96D0B6C6-5A72-4B47-8583-A87E55F5FE81}" =
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DA53D22-D922-494C-B1D7-51CD9BCB9E4A}" = VAIO Hardware Diagnostics
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A63E7492-A0BC-4BB9-89A7-352965222380}" = VAIO Original Function Settings
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A7C30414-2382-4086-B0D6-01A88ABA21C3}" = VAIO Gate
"{A7DA438C-2E43-4C20-BFDA-C1F4A6208558}" = Setting Utility Series
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.4
"{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4
"{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B7546697-2A80-4256-A24B-1C33163F535B}" = VAIO Gate Default
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BC41C09D-FAA9-4346-9FE6-1E0017BC551A}" = Adobe Flash Player 10 Plugin
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{C066286F-E002-46C0-9DFD-2DCB9A2B7A99}_is1" = iLiberty+ 1.3.0 Build 113
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C7163400-6A4A-467E-A31B-3841C33F6F5D}" = Xara Designer Pro 6
"{C79312BD-3E76-4474-A10C-1435D1856A4B}" = Adobe Dreamweaver CS5
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CFC9F871-7C40-40B6-BE4A-B98A5B309716}" = Adobe Flash Professional CS5
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.3.22 Game
"{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}" = TuneUp Utilities
"{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}" = Intel® Turbo Boost Technology Driver
"{D7BF3B76-EEF9-4868-9B2B-42ABF60B279A}" = Microsoft_VC80_CRT_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DACFD753-491E-4BC4-95A0-A49D05475FF6}" = TI Interactive!
"{DE8AAC73-6D8D-483E-96EA-CAEDDADB9079}" = ArcSoft WebCam Companion 3
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{EE18E5E3-9929-4A7C-AA08-E0AEC2FEA75C}" = Air Mouse Server
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1432614-6183-49E6-98E8-674485463CFE}" = VAIO Original Function Settings
"{F3E9C243-122E-4D6B-ACC1-E1FEC02F6CA1}" = Command and ConquerTM Generals Zero Hour
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FB77DB0C-6951-47B6-9D80-A0FDBEE0334C}" =
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_3dcb365ab9e01871fb8c6f27b0ea079" = Adobe After Effects CS4
"AIM_7" = AIM 7
"Akamai" = Akamai NetSession Interface
"AutoHotkey" = AutoHotkey 1.0.48.05
"CCleaner" = CCleaner
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FUSION WOL_is1" = FUSION WOL v1.0
"Garena" = Garena 2010
"HideIPEasy" = Hide IP Easy
"InstallShield_{06F80017-8F98-4C94-B868-52358569FC32}" = Command & Conquer Generals
"InstallShield_{F3E9C243-122E-4D6B-ACC1-E1FEC02F6CA1}" = Command and ConquerTM Generals Zero Hour
"Internet Download Manager" = Internet Download Manager
"MAGIX_MSI_XtremePro6" = Xara Designer Pro 6
"Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10)
"OpenAL" = OpenAL
"PowerISO" = PowerISO
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"splashtop" = VAIO Quick Web Access
"TeamViewer 5" = TeamViewer 5
"Tekken 3" = Tekken 3
"Topaz SigCard1 MSR ActiveX" = Topaz SigCard1 MSR ActiveX
"TuneUp Utilities" = TuneUp Utilities
"uTorrent" = µTorrent
"VAIO Help and Support" =
"VAIO Premium Partners" = VAIO Premium Partners
"Videora iPod Converter" = Videora iPod Converter 5.04
"VLC Connection Utility_is1" = VLC Connection Utility 2.60
"VLC media player" = VLC media player 1.0.5
"WampServer 2_is1" = WampServer 2.0
"Warcraft III" = Warcraft III
"WinPcapInst" = WinPcap 4.1.1

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"EA SPORTS Game Face Browser Plugin" = EA SPORTS Game Face Browser Plugin 1.0.0.18
"UnityWebPlayer" = Unity Web Player
"Warcraft III" = Warcraft III: All Products

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 16/10/2010 12:56:39 | Computer Name = Mads-VAIO | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 5054

Error - 16/10/2010 12:56:40 | Computer Name = Mads-VAIO | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 16/10/2010 12:56:40 | Computer Name = Mads-VAIO | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 6068

Error - 16/10/2010 12:56:40 | Computer Name = Mads-VAIO | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 6068

Error - 17/10/2010 17:13:51 | Computer Name = Mads-VAIO | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 17/10/2010 17:13:51 | Computer Name = Mads-VAIO | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1076

Error - 17/10/2010 17:13:51 | Computer Name = Mads-VAIO | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1076

Error - 18/10/2010 04:11:41 | Computer Name = Mads-VAIO | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 18/10/2010 04:11:41 | Computer Name = Mads-VAIO | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 39470780

Error - 18/10/2010 04:11:41 | Computer Name = Mads-VAIO | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 39470780

[ System Events ]
Error - 18/10/2010 04:55:46 | Computer Name = Mads-VAIO | Source = EventLog | ID = 6008
Description = The previous system shutdown at 10:54:29 on ?18-?10-?2010 was unexpected.

Error - 18/10/2010 04:55:59 | Computer Name = Mads-VAIO | Source = Service Control Manager | ID = 7000
Description = The MySQL service failed to start due to the following error: %%2

Error - 18/10/2010 05:11:13 | Computer Name = Mads-VAIO | Source = Service Control Manager | ID = 7000
Description = The MySQL service failed to start due to the following error: %%2

Error - 18/10/2010 05:34:18 | Computer Name = Mads-VAIO | Source = Service Control Manager | ID = 7000
Description = The TuneUp Theme Extension service failed to start due to the following
error: %%1083

Error - 18/10/2010 05:58:14 | Computer Name = Mads-VAIO | Source = volsnap | ID = 393230
Description = The shadow copies of volume C: were aborted because of an IO failure
on volume C:.

Error - 18/10/2010 09:28:16 | Computer Name = Mads-VAIO | Source = EventLog | ID = 6008
Description = The previous system shutdown at 15:26:56 on ?18-?10-?2010 was unexpected.

Error - 18/10/2010 09:28:25 | Computer Name = Mads-VAIO | Source = Service Control Manager | ID = 7000
Description = The MySQL service failed to start due to the following error: %%2

Error - 18/10/2010 09:48:41 | Computer Name = Mads-VAIO | Source = EventLog | ID = 6008
Description = The previous system shutdown at 15:47:05 on ?18-?10-?2010 was unexpected.

Error - 18/10/2010 09:48:41 | Computer Name = Mads-VAIO | Source = Service Control Manager | ID = 7000
Description = The MySQL service failed to start due to the following error: %%2

Error - 18/10/2010 10:25:17 | Computer Name = Mads-VAIO | Source = EventLog | ID = 6008
Description = The previous system shutdown at 16:01:28 on ?18-?10-?2010 was unexpected.

[ TuneUp Events ]
Error - 18/10/2010 14:33:40 | Computer Name = Mads-VAIO | Source = TuneUp.UtilitiesSvc | ID = 300
Description =

Error - 18/10/2010 15:39:26 | Computer Name = Mads-VAIO | Source = TuneUp.UtilitiesSvc | ID = 300
Description =

Error - 29/10/2010 07:09:21 | Computer Name = Mads-VAIO | Source = TuneUp.UtilitiesSvc | ID = 300
Description =


< End of report >






GMER 1.0.15.15477 - http://www.gmer.net
Rootkit scan 2010-10-31 16:57:20
Windows 6.1.7600
Running: gmer.exe


—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0c6076a27b49
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files (x86)\Alcohol Soft\Alcohol 52\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC7 0x8F 0xE7 0x53 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x25 0x7E 0x0D 0x57 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xB2 0x4E 0x41 0x35 …
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0c6076a27b49 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files (x86)\Alcohol Soft\Alcohol 52\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC7 0x8F 0xE7 0x53 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x25 0x7E 0x0D 0x57 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xB2 0x4E 0x41 0x35 …

—- EOF - GMER 1.0.15 —-
hi

Step 1

[external image: Posted Image] Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.


Step 3

Please download JavaRa to your desktop and unzip it to it's own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

Next

Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply


Things i would like to see in your reply:
  • Malwarebytes Results.
  • Kaspersky WebScanner Report
  • Update on how your computer is running

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI