This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

unable to remove searchqu malware

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there

I'm very grateful to have come across this site. We have inadvertantly installed 'searchqu' when updating bandoo emoticons for MSN messenger. My internet provider helped me stop this program opening up as a new tab in my browser, however I am getting warning messages pop up that an attempt has been made to change my browser homepage (or something quick to that effect) and I can see the program is still buried when I run your diagnostic tools. I'm not sure exactly what this thing is doing but do know I don't want it on my computer! Any help would be greatly appreciated. I've run the OTL tools and the results are as follows:

OTL logfile created on: 15/12/2010 10:56:33 PM - Run 4
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Office PC\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 58.00% Memory free
7.00 Gb Paging File | 5.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455.78 Gb Total Space | 29.93 Gb Free Space | 6.57% Space Free | Partition Type: NTFS
Drive D: | 9.98 Gb Total Space | 1.36 Gb Free Space | 13.62% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 465.64 Gb Free Space | 99.97% Space Free | Partition Type: NTFS

Computer Name: OFFICEPC-PC | User Name: Office PC | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Office PC\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe (Nokia)
PRC - C:\Program Files\Common Files\Nokia\NoA\nokiaaserver.exe ()
PRC - C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe (Nokia)
PRC - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe (Nokia)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Windows\System32\schtasks.exe (Microsoft Corporation)
PRC - C:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
PRC - C:\Windows\System32\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro)
PRC - C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe (TerraTec Electronic GmbH)


========== Modules (SafeList) ==========

MOD - C:\Users\Office PC\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe ()
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (SymIMMP) – C:\Windows\System32\DRIVERS\SymIM.sys File not found
DRV - (SymIM) – C:\Windows\System32\DRIVERS\SymIM.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\Windows\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\Windows\System32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (nmwcd) – C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (fssfltr) – C:\Windows\System32\drivers\fssfltr.sys (Microsoft Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (netr73) – C:\Windows\System32\drivers\netr73.sys (Ralink Technology, Corp.)
DRV - (mod7700) – C:\Windows\System32\drivers\mod7700.sys (DiBcom SA)
DRV - (MODRC) – C:\Windows\System32\drivers\modrc.sys (DiBcom S.A.)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (iaStor) – C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (61883) – C:\Windows\System32\drivers\61883.sys (Microsoft Corporation)
DRV - (Avc) – C:\Windows\System32\drivers\avc.sys (Microsoft Corporation)
DRV - (MSDV) – C:\Windows\System32\drivers\msdv.sys (Microsoft Corporation)
DRV - (pgfilter) – C:\Program Files\PeerGuardian2\pgfilter.sys ()
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (Ps2) – C:\Windows\System32\drivers\PS2.sys (Hewlett-Packard Company)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://myplace.westnet.com.au/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.searchqu.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.startup.homepage: "http://www.westnet.com.au/customers/|http://www.searchqu.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1167
FF - prefs.js..extensions.enabledItems: avg@igeared:6.010.023.001
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.3.42
FF - prefs.js..extensions.enabledItems: {1FD91A9C-410C-4090-BBCC-55D3450EF433}:2.0
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&systemid=101&q="
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/11/24 09:29:01 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared [2010/12/12 13:50:33 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2010/11/30 20:03:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\mozilla firefox\components [2010/12/13 21:46:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\mozilla firefox\plugins [2010/12/13 21:46:41 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2010/11/30 20:03:43 | 000,000,000 | —D | M]

[2010/12/06 22:22:04 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\Mozilla\Extensions
[2010/12/15 21:14:05 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\Mozilla\Firefox\Profiles\4omgl5i3.default\extensions
[2010/08/12 22:12:24 | 000,005,529 | —- | M] () – C:\Users\Office PC\AppData\Roaming\Mozilla\Firefox\Profiles\4omgl5i3.default\searchplugins\SearchquWebSearch.xml
[2010/12/06 22:22:04 | 000,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2010/07/18 22:16:19 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\mozilla firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/05/17 08:42:25 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/09/06 17:26:43 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/22 16:57:27 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/02/21 09:24:52 | 000,660,872 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\npOGAPlugin.dll
[2010/06/25 17:49:14 | 000,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2010/06/25 17:49:14 | 000,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2010/06/25 17:49:14 | 000,000,769 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2010/08/12 22:12:24 | 000,005,529 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\SearchquWebSearch.xml
[2010/06/25 17:49:14 | 000,001,135 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2006/09/19 08:41:30 | 000,000,736 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Searchqu Toolbar) - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\Program Files\Windows Searchqu Toolbar\ToolBar\SearchquDx.dll ()
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\Program Files\Windows Searchqu Toolbar\ToolBar\SearchquDx.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O4 - HKLM..\Run: [HP Health Check Scheduler] File not found
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [OsdMaestro] C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateReg] C:\Windows\System32\jureg.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TerraTec Remote Control] C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe (TerraTec Electronic GmbH)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [NokiaOviSuite2] C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe (Nokia)
O4 - HKCU..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe (Phoenix Labs)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -Mozilla\4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident\4.0; File not found
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: ([]msn in Computer)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\progra~1\wi9130~1\datamngr\datamngr.dll) - c:\Program Files\Windows Searchqu Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
O20 - AppInit_DLLs: (nvdesk32.dll) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/15 16:01:45 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{491ec0dd-fe0d-11dd-b720-001e8c05bbec}\Shell - "" = AutoRun
O33 - MountPoints2\{491ec0dd-fe0d-11dd-b720-001e8c05bbec}\Shell\AutoRun\command - "" = L:\LaunchU3.exe – File not found
O33 - MountPoints2\{707978a1-9180-11df-8b36-001e8c05bbec}\Shell - "" = AutoRun
O33 - MountPoints2\{707978a1-9180-11df-8b36-001e8c05bbec}\Shell\AutoRun\command - "" = M:\LaunchU3.exe – File not found
O33 - MountPoints2\L\Shell - "" = AutoRun
O33 - MountPoints2\L\Shell\AutoRun\command - "" = L:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.ac3filter - C:\Windows\System32\ac3filter.acm ()
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2010/12/06 22:22:02 | 000,000,000 | —D | C] – C:\Program Files\Windows Searchqu Toolbar
[2010/12/05 22:14:16 | 000,000,000 | —D | C] – C:\ProgramData\WinZip
[2010/12/03 16:07:54 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\System32\GEARAspi.dll
[2010/12/03 16:07:14 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/12/03 16:07:12 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/12/01 18:07:55 | 000,038,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WdfLdr.sys
[2010/12/01 18:07:08 | 000,000,000 | —D | C] – C:\Users\Office PC\AppData\Roaming\Nokia
[2010/12/01 18:07:03 | 000,000,000 | —D | C] – C:\Users\Office PC\AppData\Local\NokiaAccount
[2010/11/30 20:05:26 | 000,000,000 | —D | C] – C:\Users\Office PC\AppData\Local\Nokia
[2010/11/30 20:05:23 | 000,000,000 | —D | C] – C:\ProgramData\PC Suite
[2010/11/30 20:05:22 | 000,000,000 | —D | C] – C:\Users\Office PC\AppData\Roaming\PC Suite
[2010/11/30 20:04:16 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Nokia
[2010/11/30 20:03:31 | 000,000,000 | —D | C] – C:\Program Files\DIFX
[2010/11/30 20:03:30 | 000,018,816 | —- | C] (Nokia) – C:\Windows\System32\drivers\pccsmcfd.sys
[2010/11/30 20:02:27 | 000,000,000 | —D | C] – C:\Program Files\PC Connectivity Solution
[2010/11/30 19:59:03 | 000,092,672 | —- | C] (Nokia) – C:\Windows\System32\nmwcdcls.dll
[2010/11/30 19:58:33 | 000,000,000 | —D | C] – C:\ProgramData\NokiaInstallerCache
[2010/11/30 19:58:33 | 000,000,000 | —D | C] – C:\Program Files\Nokia
[2010/11/28 23:26:55 | 000,000,000 | —D | C] – C:\Users\Office PC\Calibre Library
[2010/11/28 23:26:52 | 000,000,000 | —D | C] – C:\Users\Office PC\AppData\Roaming\calibre
[2010/11/28 23:25:45 | 000,000,000 | —D | C] – C:\Program Files\Calibre2
[2010/11/27 00:00:47 | 000,000,000 | —D | C] – C:\Users\Office PC\Documents\Spectres
[2 C:\Users\Office PC\AppData\Local\*.tmp files -> C:\Users\Office PC\AppData\Local\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/12/15 22:56:05 | 006,291,456 | -HS- | M] () – C:\Users\Office PC\NTUSER.DAT
[2010/12/15 22:53:52 | 000,703,388 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/12/15 22:53:52 | 000,608,760 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/12/15 22:53:52 | 000,108,268 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/12/15 22:50:47 | 000,032,251 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/12/15 22:50:46 | 000,032,251 | —- | M] () – C:\ProgramData\nvModes.001
[2010/12/15 22:47:35 | 000,003,696 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/12/15 22:47:35 | 000,003,696 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/12/15 22:47:35 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/12/15 22:47:33 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/12/15 22:47:08 | 3488,899,072 | -HS- | M] () – C:\hiberfil.sys
[2010/12/15 22:45:55 | 000,524,288 | -HS- | M] () – C:\Users\Office PC\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/12/15 22:45:55 | 000,065,536 | -HS- | M] () – C:\Users\Office PC\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/12/15 22:45:40 | 004,088,674 | -H– | M] () – C:\Users\Office PC\AppData\Local\IconCache.db
[2010/12/15 22:39:21 | 000,243,712 | —- | M] () – C:\Users\Office PC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/15 22:37:25 | 000,002,609 | —- | M] () – C:\Users\Office PC\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2007.lnk
[2010/12/15 13:04:04 | 101,826,508 | —- | M] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2010/12/12 11:02:06 | 000,002,651 | —- | M] () – C:\Users\Office PC\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2007.lnk
[2010/12/08 20:39:11 | 000,034,304 | —- | M] () – C:\Users\Office PC\Documents\2011 forward order summary_draft.xls
[2010/12/01 18:08:13 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2010/12/01 18:08:13 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
[2010/11/30 20:05:16 | 000,001,934 | —- | M] () – C:\Users\Public\Desktop\Nokia Ovi Suite.lnk
[2010/11/26 13:52:51 | 000,000,060 | —- | M] () – C:\Windows\wpd99.drv
[2010/11/16 16:27:55 | 000,014,336 | —- | M] () – C:\Users\Office PC\Documents\DEB2010.TAX
[2 C:\Users\Office PC\AppData\Local\*.tmp files -> C:\Users\Office PC\AppData\Local\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/12/08 20:39:10 | 000,034,304 | —- | C] () – C:\Users\Office PC\Documents\2011 forward order summary_draft.xls
[2010/12/01 18:08:13 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2010/12/01 18:08:13 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
[2010/12/01 18:07:56 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Inbox_Critical.Wdf
[2010/11/30 20:05:16 | 000,001,934 | —- | C] () – C:\Users\Public\Desktop\Nokia Ovi Suite.lnk
[2010/09/23 09:03:54 | 000,197,120 | —- | C] () – C:\Windows\patchw32.dll
[2010/03/11 17:43:45 | 000,000,000 | —- | C] () – C:\Users\Office PC\AppData\Local\prvlcl.dat
[2010/01/31 11:29:20 | 000,032,251 | —- | C] () – C:\ProgramData\nvModes.001
[2010/01/31 11:29:16 | 000,032,251 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/11/21 16:20:48 | 000,000,198 | —- | C] () – C:\Windows\Typing.ini
[2009/11/21 13:40:58 | 000,010,240 | —- | C] () – C:\Windows\System32\vidx16.dll
[2009/09/11 11:17:00 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/09/11 11:16:42 | 000,368,640 | —- | C] () – C:\Windows\System32\msjetoledb40.dll
[2009/08/16 08:31:34 | 000,000,271 | —- | C] () – C:\Windows\ka.ini
[2009/07/10 10:48:44 | 000,000,024 | —- | C] () – C:\Windows\Woabc123.ini
[2009/07/04 18:36:47 | 000,000,770 | —- | C] () – C:\Windows\hegames.ini
[2009/05/08 20:10:32 | 000,000,060 | —- | C] () – C:\Windows\wpd99.drv
[2009/05/08 20:10:31 | 000,051,716 | —- | C] () – C:\Windows\System32\pdf995mon.dll
[2009/03/08 15:32:24 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/02/21 14:49:12 | 000,060,124 | —- | C] () – C:\Windows\System32\tcpmon.ini
[2009/02/20 11:31:27 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2009/02/19 13:06:39 | 000,243,712 | —- | C] () – C:\Users\Office PC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/10 22:06:33 | 000,000,680 | —- | C] () – C:\Users\Office PC\AppData\Local\d3d9caps.dat
[2008/12/10 21:56:46 | 004,088,674 | -H– | C] () – C:\Users\Office PC\AppData\Local\IconCache.db
[2008/12/10 21:14:39 | 000,109,208 | —- | C] () – C:\Users\Office PC\AppData\Local\GDIPFONTCACHEV1.DAT
[2008/02/15 15:56:04 | 000,002,429 | —- | C] () – C:\ProgramData\hpzinstall.log
[2008/02/15 15:39:28 | 000,327,680 | —- | C] () – C:\Windows\System32\pythoncom25.dll
[2008/02/15 15:39:28 | 000,102,400 | —- | C] () – C:\Windows\System32\pywintypes25.dll
[2006/11/02 23:50:50 | 000,000,174 | -HS- | C] () – C:\Program Files\desktop.ini
[2006/11/02 23:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 21:33:01 | 000,703,388 | —- | C] () – C:\Windows\System32\PerfStringBackup.INI
[2006/11/02 21:24:31 | 000,001,405 | —- | C] () – C:\Windows\msdfmap.ini
[2006/11/02 21:23:31 | 000,000,235 | —- | C] () – C:\Windows\system.ini
[2006/11/02 21:23:31 | 000,000,219 | —- | C] () – C:\Windows\win.ini
[2006/11/02 18:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 18:09:45 | 000,027,097 | —- | C] () – C:\Windows\System32\country.sys
[2006/11/02 18:09:44 | 000,042,809 | —- | C] () – C:\Windows\System32\KEY01.SYS
[2006/11/02 18:09:44 | 000,042,537 | —- | C] () – C:\Windows\System32\KEYBOARD.SYS
[2006/11/02 18:09:42 | 000,009,029 | —- | C] () – C:\Windows\System32\ANSI.SYS
[2006/11/02 18:09:41 | 000,004,768 | —- | C] () – C:\Windows\System32\HIMEM.SYS
[2006/11/02 18:09:40 | 000,029,274 | —- | C] () – C:\Windows\System32\NTDOS412.SYS
[2006/11/02 18:09:38 | 000,029,370 | —- | C] () – C:\Windows\System32\NTDOS411.SYS
[2006/11/02 18:09:35 | 000,029,146 | —- | C] () – C:\Windows\System32\NTDOS404.SYS
[2006/11/02 18:09:31 | 000,029,146 | —- | C] () – C:\Windows\System32\NTDOS804.SYS
[2006/11/02 18:09:29 | 000,027,866 | —- | C] () – C:\Windows\System32\NTDOS.SYS
[2006/11/02 18:09:26 | 000,035,536 | —- | C] () – C:\Windows\System32\NTIO412.SYS
[2006/11/02 18:09:24 | 000,035,776 | —- | C] () – C:\Windows\System32\NTIO411.SYS
[2006/11/02 18:09:23 | 000,034,672 | —- | C] () – C:\Windows\System32\NTIO404.SYS
[2006/11/02 18:09:22 | 000,034,672 | —- | C] () – C:\Windows\System32\NTIO804.SYS
[2006/11/02 18:09:20 | 000,033,952 | —- | C] () – C:\Windows\System32\NTIO.SYS
[2006/11/02 17:25:08 | 000,013,312 | —- | C] () – C:\Windows\System32\win87em.dll
[2003/11/04 20:05:47 | 000,001,125 | —- | C] () – C:\Windows\Winamp.ini

========== LOP Check ==========

[2010/09/23 09:08:15 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\Atari
[2010/11/18 21:58:16 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\Audacity
[2010/11/07 12:55:58 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\AVG10
[2009/07/19 14:30:42 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\Azureus
[2010/11/28 23:30:30 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\calibre
[2010/04/18 00:00:51 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\Facebook
[2009/04/13 17:36:26 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\ImgBurn
[2009/11/21 16:23:18 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\InterTrust
[2010/09/23 09:04:01 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\Leadertech
[2009/06/01 21:14:05 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\muvee Technologies
[2010/12/01 18:07:08 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\Nokia
[2010/11/30 20:05:23 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\PC Suite
[2009/05/08 20:12:06 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\pdf995
[2009/02/22 17:43:29 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\Pinnacle Systems
[2009/04/29 18:42:10 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\TerraTec
[2010/12/15 21:53:44 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\uTorrent
[2008/12/11 23:28:45 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\WinBatch
[2010/12/15 22:46:10 | 000,032,560 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2004/10/22 23:00:35 | 000,008,612 | —- | M] () – C:\ANZ.CSV
[2004/09/27 23:06:02 | 000,120,320 | —- | M] () – C:\rear 2 data.xls
[2008/02/15 16:01:45 | 000,000,074 | —- | M] () – C:\autoexec.bat
[2005/01/09 18:26:18 | 005,204,034 | RHS- | M] () – C:\AVG6DB_F (1).DAT
[2005/01/09 18:27:11 | 000,007,150 | RHS- | M] () – C:\AVG6DB_F.DAT
[2004/11/11 23:32:18 | 010,156,943 | —- | M] () – C:\avg70free_289a392.exe
[2009/04/11 17:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/02/15 15:13:48 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/19 08:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2004/10/23 00:59:56 | 000,119,808 | —- | M] () – C:\credit card June to Sept.xls
[1999/04/20 16:08:40 | 000,000,183 | —- | M] () – C:\ds.cnt
[2000/03/02 12:03:02 | 000,400,384 | —- | M] () – C:\ds.exe
[2007/06/02 16:15:29 | 000,010,823 | -H– | M] () – C:\ds.GID
[2000/01/04 16:38:52 | 000,130,838 | —- | M] () – C:\Ds.hlp
[2007/06/02 16:37:17 | 000,000,000 | —- | M] () – C:\dslist.dat
[2009/10/28 22:31:41 | 000,000,125 | —- | M] () – C:\FINIS_IT.TXT
[2009/02/02 19:17:32 | 004,830,208 | —- | M] () – C:\First day collage.ppt
[2005/06/28 21:31:34 | 000,700,120 | —- | M] () – C:\flashplayer7installer.exe
[2008/08/18 20:29:12 | 000,001,600 | —- | M] () – C:\help.zip_zip_Data Recovery.hhp.cached
[2010/12/15 22:47:08 | 3488,899,072 | -HS- | M] () – C:\hiberfil.sys
[2005/03/29 22:52:37 | 000,022,016 | —- | M] () – C:\House Problems.doc
[2005/03/29 22:51:12 | 000,022,016 | —- | M] () – C:\House Warranty List.doc
[2008/11/12 16:37:39 | 000,013,584 | —- | M] () – C:\I admire speech.docx
[2009/11/21 13:23:35 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/05/27 23:47:58 | 000,037,428 | —- | M] () – C:\MP4debug.log
[2009/11/21 13:23:35 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2005/08/23 14:24:20 | 000,000,312 | —- | M] () – C:\My Documents.lnk
[2006/06/18 18:14:50 | 000,315,703 | —- | M] () – C:\nas1000-Manual.pdf
[2006/11/02 19:58:22 | 000,051,310 | —- | M] () – C:\nathan snorkling.jpg
[2010/12/15 22:47:05 | 3802,546,176 | -HS- | M] () – C:\pagefile.sys
[2005/06/02 10:11:21 | 000,236,760 | —- | M] () – C:\PopUpScanner.exe
[2009/03/01 14:24:43 | 000,000,574 | —- | M] () – C:\RHDSetup.log
[2005/05/22 22:17:43 | 000,000,202 | —- | M] () – C:\Shortcut (2) to public on '192.168.1.3' (Z).lnk
[2006/09/02 20:08:42 | 000,000,368 | —- | M] () – C:\Shortcut to Mia.lnk
[2005/05/15 11:29:01 | 000,000,202 | —- | M] () – C:\Shortcut to public on '192.168.1.3' (Z).lnk
[2006/12/27 14:43:05 | 020,155,344 | —- | M] (Skype Technologies S.A. ) – C:\SkypeSetup.exe
[2008/01/31 19:05:14 | 000,012,288 | -HS- | M] () – C:\Thumbs.db
[2006/06/18 17:48:02 | 000,002,592 | —- | M] () – C:\Uninst.isu
[2009/03/01 15:26:52 | 000,000,594 | —- | M] () – C:\updatedatfix.log
[2008/11/30 10:44:17 | 000,056,469 | —- | M] () – C:\Washington Network Nov08 updated.JPG
[2005/02/05 20:08:19 | 000,051,851 | —- | M] () – C:\Washington Network.jpg
[2004/09/14 23:18:27 | 000,015,360 | —- | M] () – C:\Windows.xls
[2007/11/24 21:18:25 | 000,024,576 | —- | M] () – C:\wines.doc
[2005/03/29 22:51:12 | 000,000,162 | -H– | M] () – C:\~$use Warranty List.doc

< %systemroot%\Fonts\*.com >
[2006/11/02 23:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 23:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 23:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/09/12 15:50:44 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/19 08:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/09/14 14:18:30 | 000,076,288 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpzpp4qv.dll
[2007/01/29 14:21:10 | 000,273,920 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpzpp4v2.dll
[2006/11/02 23:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/07/10 12:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/03/05 03:23:08 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/02 21:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 21:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 21:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 21:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 21:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/06/10 04:09:21 | 000,000,286 | -HS- | M] () – C:\Users\Office PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-24 16:00:30

< End of report >


and from Extras:

OTL Extras logfile created on: 15/12/2010 10:56:33 PM - Run 4
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Office PC\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 58.00% Memory free
7.00 Gb Paging File | 5.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455.78 Gb Total Space | 29.93 Gb Free Space | 6.57% Space Free | Partition Type: NTFS
Drive D: | 9.98 Gb Total Space | 1.36 Gb Free Space | 13.62% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 465.64 Gb Free Space | 99.97% Space Free | Partition Type: NTFS

Computer Name: OFFICEPC-PC | User Name: Office PC | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\mozilla firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1678808A-5307-4FDB-A6AB-AEB57751D7D4}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=c:\windows\system32\svchost.exe |
"{222B6E6B-7BE9-4C05-B7B2-46C604D79C18}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{2AEB1A8E-CE15-4D35-AEDF-4FB3E440618B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{2F8B97F2-FDFD-40A9-8717-8D8C41DD3415}" = lport=30015 | protocol=6 | dir=in | name=vuse |
"{45AADE3B-2E80-49E5-A64F-E3B318739FCB}" = lport=2869 | protocol=6 | dir=in | app=system |
"{54F324C4-838E-4D9F-92DE-375AEAF7CF1B}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{5E34E808-097F-4D98-85AF-D817FE5FD0D4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{A4C87983-9BB2-4482-9A43-6A2B779B130C}" = lport=30015 | protocol=17 | dir=in | name=vuse 2 |
"{AE42677B-ED43-4AD0-917F-3A019E362306}" = lport=3702 | protocol=17 | dir=in | app=c:\windows\system32\p2phost.exe |
"{B6ABC475-E96B-48C9-A145-3106FD21ABDC}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=c:\windows\system32\svchost.exe |
"{CFF5CCCA-92D3-49FE-8D01-82C8C0B9BD51}" = rport=3702 | protocol=17 | dir=out | app=c:\windows\system32\p2phost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01D61B0F-F834-40F8-8C5B-536E384C316C}" = protocol=6 | dir=out | app=c:\windows\system32\p2phost.exe |
"{030FC33A-1E87-4FFA-8BFF-C3D8CFB264D3}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{07F52DFE-B27B-4BFA-A71C-E42F965352E2}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{0B507A48-D375-47CB-8FF1-0BC99BB53FFC}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{14B013AF-9C93-4509-9103-B414DFB501D7}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{29A746D0-35C5-459F-AD60-45C5ED06365D}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{56C0CD1E-143C-43CE-AD69-2CCE25CC20DA}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{57D0109C-6811-46E0-9F7B-7FD08922A095}" = protocol=6 | dir=in | app=c:\windows\system32\p2phost.exe |
"{5D93C28A-581A-48E0-A26E-FE75A83E6335}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe |
"{688EFC27-6B50-4B8B-9C60-26D708344CBF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6BE33E8B-5F95-4E62-9212-4907434FBD78}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{714605C9-739C-465C-9EFD-CE72984A687F}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{7CDDED20-46B1-4886-BC2C-E7FF5AD016C5}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{7FAD2D49-B9B8-4541-A6E6-705AC84897C1}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{7FE6E74C-37E4-473A-9649-A4341FAE8A49}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{82E65908-D0AE-48C2-AC17-62BFD7C6E21C}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{8E2FDAFE-9925-4263-AC65-4F3B0F74862B}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{9344278C-2D5E-4269-96AA-3B35A1235C67}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{B26352B3-609C-4254-B564-05A73A24854A}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{C9F117B4-9F50-4DC3-8C9B-AF40EFA8F29F}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{CA5DDC49-78A7-43AA-992A-2A837168F14C}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{D1666FE1-5B53-4D74-A7FD-42E65B9F32BC}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{D187D807-F4BE-4FAE-BC63-EB14E57A9E21}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{DAFFF7CC-5A23-4CBB-804D-DED85A3461F8}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{DEFEEBA5-D23A-4DB8-A159-6CEF5B2FFA30}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{ECF957E0-D535-4511-8B20-635B153CE5A9}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{FAFE4487-105E-4159-A8A7-8C5C4F8EB26D}" = dir=in | app=c:\program files\itunes\itunes.exe |
"TCP Query User{34E86C25-1759-4A9B-97F1-3831B197229E}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{35715022-1353-4735-8B5D-754531D4A785}C:\program files\hasbro interactive\rollercoaster tycoon\rct.exe" = protocol=6 | dir=in | app=c:\program files\hasbro interactive\rollercoaster tycoon\rct.exe |
"TCP Query User{6BDC1372-AEA4-473C-8949-1A723B7F545C}C:\program files\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"TCP Query User{71C5F247-C93A-4139-B565-3D16DA7855BA}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"TCP Query User{7F8B346C-17AF-4747-9E2F-8B506BE2E706}C:\program files\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"UDP Query User{38BC4BAE-9092-4DC7-9739-305AF871D163}C:\program files\hasbro interactive\rollercoaster tycoon\rct.exe" = protocol=17 | dir=in | app=c:\program files\hasbro interactive\rollercoaster tycoon\rct.exe |
"UDP Query User{38ECA769-39E5-4B8D-B2E5-DE048B6A7248}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"UDP Query User{A273B48D-0926-44EF-975D-E6CF4E406227}C:\program files\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"UDP Query User{BBB96063-4D54-4A8D-9491-7F810C097B89}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{D9AC2982-429E-401E-A7CF-46B27F83D090}C:\program files\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0A2C5854-557E-48C8-835A-3B9F074BDCAA}" = Python 2.5
"{0A8C7880-F199-4807-ABD4-6E695B71A3D7}" = e-tax 2009
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{139E303E-1050-497F-98B1-9AE87B15C463}" = Windows Live Family Safety
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1BCE2581-B7CA-4BB4-BDFB-D113506AA38B}" = HP Easy Setup - Frontend
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java™ 6 Update 22
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34DAFDEC-A4B4-488A-A5CD-C91975A6F083}" = MediaRing Talk
"{360022A4-9339-426B-8F36-1465CBAEABC0}" = D7300
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45DF6D99-666D-41FA-8D62-0E183B6240F3}" = PC Connectivity Solution
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{5115C036-C0D5-4E1B-81C9-542CA967478A}" = muvee autoProducer 6.1
"{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In
"{5A39E27B-BFFB-48B5-886F-D3038AD176BF}" = calibre
"{5AD96CF5-2627-4F29-9D2D-72FCD85F6355}" = AVG 2011
"{6009F2FC-EC56-4e28-B91C-0BA5104D6419}" = SF_CDA_Software
"{63B9BAB5-F36A-4A3B-9E5C-68A7F212BFB9}" = TerraTec Home Cinema
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{714B6179-84C4-4FBE-B934-B6CF75ED37A5}" = D6100_D7100_D7300_Help
"{73A43E42-3658-4DD9-8551-FACDA3632538}" = HP Advisor
"{749A1EDD-16C2-4C63-B013-D38F0F953973}" = OviMPlatform
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7F10292C-A190-4176-A665-A1ED3478DF86}" = LightScribe System Software
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{8112C6B3-91E1-4560-8AB9-876DADFA37C5}" = Ovi Desktop Sync Engine
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8CC42289-E228-4A35-B8A9-015242283BB2}" = SPORE™ Creature Creator
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{907B4640-266B-4A21-92FB-CD1A86CD0F63}" = RollerCoaster Tycoon® 3
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{9718521B-A345-4ad9-A52B-74D1435FB708}" = SF_CDA_ProductContext
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{981DE354-9301-440f-AAFC-025AA2354A93}" = HP Deskjet & Photosmart Printer Driver Software 8.0.A
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{A23061AF-5361-433C-B7F0-CE5F79A22C49}" = AVG 2011
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A6D23784-2091-11D4-9BEB-00104B198B0D}" = Oz - TMA
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.5
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B148AB4B-C8FA-474B-B981-F2943C5B5BCD}" = OGA Notifier 1.7.0105.35.0
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B8B4446F-87E1-4423-A47A-16832C24A199}" = Nokia Ovi Suite
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C8D47273-7A1A-4614-A3D8-263632D8A5ED}" = HP Customer Experience Enhancements
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BE}" = WinZip 15.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D2023740-9AAC-11D4-B54D-006008571948}" = Pac-Man Adventures in Time
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{EE5B5B24-EEFC-4C8B-BF8B-256D705BAD89}" = Nokia Ovi Suite Software Updater
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1FDAA01-988C-423F-AC12-0D8F333943FD}" = Nokia Connectivity Cable Driver
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FAE36873-1941-4076-A9A5-48812B5EA0B7}" = iTunes
"{FBE569CA-BFEB-4E57-A674-F94D938E1AEF}" = e-tax 2010
"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"6273b5a2c962d830ec3ac19663871c2c187731047" = Become a History Explorer
"ABC's & 123's" = ABC's & 123's
"AC3Filter" = AC3Filter (remove only)
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.12 (Unicode)
"AVG" = AVG 2011
"Blue's Treasure Hunt" = Blue's Treasure Hunt
"CCleaner" = CCleaner
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"ENTERPRISE" = Microsoft Office Enterprise 2007
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"I Love Spelling!" = I Love Spelling!
"ImgBurn" = ImgBurn
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"JumpStart Artist" = JumpStart Artist
"JumpStart Explorers" = JumpStart Explorers
"Marketmaker CFD-FX Asia Pacific" = Marketmaker CFD-FX Asia Pacific
"McAfee Security Scan" = McAfee Security Scan Plus
"MFMA2 - Adding and Subtracting" = MFMA2 - Adding and Subtracting
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MTK3" = Imagine Pet Vet Australia
"Nokia Ovi Suite" = Nokia Ovi Suite
"NVIDIA Drivers" = NVIDIA Drivers
"OsdMaestro" = HP On-Screen Cap/Num/Scroll Lock Indicator
"PC-Doctor 5 for Windows" = Hardware Diagnostic Tools
"Pdf995" = Pdf995
"PeerGuardian_is1" = PeerGuardian 2.0
"RollerCoaster Tycoon Setup" = Roll
"Scholastic's I SPY Spooky Mansion" = Scholastic's I SPY Spooky Mansion
"Searchqu MediaBar" = Windows Searchqu Toolbar
"Typing Tutor" = Typing Tutor
"Vuze" = Vuze
"whirlN&E.exe" = Whirled Math N&E
"WildTangent hp Master Uninstall" = My HP Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WinXMedia iPod/3GP/PSP/MP4 Converter" = WinXMedia iPod/3GP/PSP/MP4 Converter 1.12
"XBALLOON" = XBALLOON

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
Posted Image

Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")



Please do not delete anything unless instructed to.


1. launch Notepad (Start>All Programs>Accessories), and copy/paste all the Quoted REGEDIT below to it. Don't forget to include REGEDIT4.
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""

2. Save this text as fixme.reg. Make sure the "Save as type:" is "All Files (*.*)" and save it to your desktop.
3. Double-click on fixme.reg. When it asks you to merge the information to the registry click Yes.



Next:
Note: Close all browsers before running ATF Cleaner: IE, FireFox, etc.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.


  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

Also please describe how your computer behaves at the moment.

Please don't attach the scans / logs, use "copy/paste".
Thanks for such a fast reply. I've followed instructions and the result of the anti-malware scan is copied below. As to how my computer is behaving, I tried to open a new internet banking window after running this program and it still had a pop-up message that a program was trying to change my home page. It comes up and goes so quickly I can't read everything it says. I didn't get a notice that some items could not be removed so have not rebooted the computer at this stage… Malwarebytes' Anti-Malware 1.50 www.malwarebytes.org Database version: 5347 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18999 19/12/2010 12:27:13 AM mbam-log-2010-12-19 (00-27-13).txt Scan type: Quick scan Objects scanned: 179356 Time elapsed: 3 minute(s), 15 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 9 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
OTL Fix
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\Program Files\Windows Searchqu Toolbar\ToolBar\SearchquDx.dll ()
    O4 - HKCU..\Run: [] File not found
    O20 - AppInit_DLLs: (c:\progra~1\wi9130~1\datamngr\datamngr.dll) - c:\Program Files\Windows Searchqu Toolbar\Datamngr\datamngr.dll (Discordia, LTD)
    O20 - AppInit_DLLs: (nvdesk32.dll) - File not found
    
    :Files
    C:\Program Files\Windows Searchqu Toolbar
    
    :Commands
    [EmptyFlash]
    [EmptyTemp]
    [RESETHOSTS] 
    [purity]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
thanks, the result is below. I just retried internet banking and no pop up warning this time User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Config.Msi User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Office PC ->Temp folder emptied: 248543 bytes ->Temporary Internet Files folder emptied: 14337773 bytes ->Java cache emptied: 54022154 bytes ->FireFox cache emptied: 67109359 bytes ->Flash cache emptied: 0 bytes User: Public User: remoteservice %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 258048 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 130.00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.2.17.3 log created on 12192010_004742 Files\Folders moved on Reboot… C:\Users\Office PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{7E528BAD-1E37-4A86-B0A4-772C0EF6EEF1}.tmp moved successfully. C:\Users\Office PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{15F701BE-2CCF-48F4-8D2F-7A0E5FB4BEF0}.tmp moved successfully. C:\Users\Office PC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{F7C3BF7E-6944-43F0-B79D-66837B78ED19}.tmp moved successfully. Registry entries deleted on Reboot…
ok have done. It did not find any problems, but I re-ran the OTL scan and it still seems to be there (also posted below). Well past 1am here and I'm not well so off to bed now but will be interested in your comments in the morning :)

Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org

Database version: 5348

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18999

19/12/2010 1:21:34 AM
mbam-log-2010-12-19 (01-21-34).txt

Scan type: Quick scan
Objects scanned: 178870
Time elapsed: 2 minute(s), 58 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

OTL logfile created on: 19/12/2010 1:13:29 AM - Run 5
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Office PC\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18999)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
7.00 Gb Paging File | 5.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455.78 Gb Total Space | 11.92 Gb Free Space | 2.61% Space Free | Partition Type: NTFS
Drive D: | 9.98 Gb Total Space | 1.36 Gb Free Space | 13.62% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 465.64 Gb Free Space | 99.97% Space Free | Partition Type: NTFS

Computer Name: OFFICEPC-PC | User Name: Office PC | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Office PC\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe (Nokia)
PRC - C:\Program Files\Common Files\Nokia\NoA\nokiaaserver.exe ()
PRC - C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe (Nokia)
PRC - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe (Nokia)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Windows\System32\schtasks.exe (Microsoft Corporation)
PRC - C:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro)
PRC - C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe (TerraTec Electronic GmbH)


========== Modules (SafeList) ==========

MOD - C:\Users\Office PC\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe ()
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (SymIMMP) – C:\Windows\System32\DRIVERS\SymIM.sys File not found
DRV - (SymIM) – C:\Windows\System32\DRIVERS\SymIM.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (MBAMSwissArmy) – C:\Windows\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\Windows\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\Windows\System32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (nmwcd) – C:\Windows\System32\drivers\ccdcmb.sys (Nokia)
DRV - (fssfltr) – C:\Windows\System32\drivers\fssfltr.sys (Microsoft Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (netr73) – C:\Windows\System32\drivers\netr73.sys (Ralink Technology, Corp.)
DRV - (mod7700) – C:\Windows\System32\drivers\mod7700.sys (DiBcom SA)
DRV - (MODRC) – C:\Windows\System32\drivers\modrc.sys (DiBcom S.A.)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (iaStor) – C:\Windows\system32\drivers\iastor.sys (Intel Corporation)
DRV - (pccsmcfd) – C:\Windows\System32\drivers\pccsmcfd.sys (Nokia)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (61883) – C:\Windows\System32\drivers\61883.sys (Microsoft Corporation)
DRV - (Avc) – C:\Windows\System32\drivers\avc.sys (Microsoft Corporation)
DRV - (MSDV) – C:\Windows\System32\drivers\msdv.sys (Microsoft Corporation)
DRV - (pgfilter) – C:\Program Files\PeerGuardian2\pgfilter.sys ()
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (Ps2) – C:\Windows\System32\drivers\PS2.sys (Hewlett-Packard Company)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://myplace.westnet.com.au/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.westnet.com.au/customers/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.startup.homepage: "http://www.westnet.com.au/customers/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1167
FF - prefs.js..extensions.enabledItems: avg@igeared:6.010.023.001
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.3.42
FF - prefs.js..keyword.URL: "http://search.avg.com/route/?d=4b73bd36&v=6.010.023.001&i=23&tp=ab&iy=&ychte=au&lng=en-GB&q="
FF - prefs.js..network.proxy.no_proxies_on: "localhost,127.0.0.1"

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/11/24 09:29:01 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared [2010/12/12 13:50:33 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\ [2010/11/30 20:03:42 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\mozilla firefox\components [2010/12/18 14:17:39 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\mozilla firefox\plugins [2010/12/18 14:17:39 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\{CCB7D94B-CA92-4E3F-B79D-ADE0F07ADC74}: C:\Program Files\Nokia\Nokia Ovi Suite\Connectors\Thunderbird Connector\ThunderbirdExtension\ [2010/11/30 20:03:43 | 000,000,000 | —D | M]

[2010/12/06 22:22:04 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\Mozilla\Extensions
[2010/12/15 21:14:05 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\Mozilla\Firefox\Profiles\4omgl5i3.default\extensions
[2010/08/12 22:12:24 | 000,005,529 | —- | M] () – C:\Users\Office PC\AppData\Roaming\Mozilla\Firefox\Profiles\4omgl5i3.default\searchplugins\SearchquWebSearch.xml
[2010/12/06 22:22:04 | 000,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2010/07/18 22:16:19 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\mozilla firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/05/17 08:42:25 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/09/06 17:26:43 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/22 16:57:27 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/02/21 09:24:52 | 000,660,872 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\npOGAPlugin.dll
[2010/06/25 17:49:14 | 000,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2010/06/25 17:49:14 | 000,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2010/06/25 17:49:14 | 000,000,769 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2010/08/12 22:12:24 | 000,005,529 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\SearchquWebSearch.xml
[2010/06/25 17:49:14 | 000,001,135 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/12/19 00:48:31 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (no name) - {7FF99715-3016-4381-84CE-E4E4C9673020} - No CLSID value found.
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DATAMNGR] C:\PROGRA~1\WI9130~1\Datamngr\DATAMN~1.EXE File not found
O4 - HKLM..\Run: [HP Health Check Scheduler] File not found
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe (Nokia)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [OsdMaestro] C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateReg] C:\Windows\System32\jureg.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TerraTec Remote Control] C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe (TerraTec Electronic GmbH)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [NokiaOviSuite2] C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe (Nokia)
O4 - HKCU..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe (Phoenix Labs)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -Mozilla\4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident\4.0; File not found
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: ([]msn in Computer)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/15 16:01:45 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{491ec0dd-fe0d-11dd-b720-001e8c05bbec}\Shell - "" = AutoRun
O33 - MountPoints2\{491ec0dd-fe0d-11dd-b720-001e8c05bbec}\Shell\AutoRun\command - "" = L:\LaunchU3.exe – File not found
O33 - MountPoints2\{707978a1-9180-11df-8b36-001e8c05bbec}\Shell - "" = AutoRun
O33 - MountPoints2\{707978a1-9180-11df-8b36-001e8c05bbec}\Shell\AutoRun\command - "" = M:\LaunchU3.exe – File not found
O33 - MountPoints2\L\Shell - "" = AutoRun
O33 - MountPoints2\L\Shell\AutoRun\command - "" = L:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/12/19 00:47:42 | 000,000,000 | —D | C] – C:\_OTL
[2010/12/19 00:22:03 | 000,000,000 | —D | C] – C:\Users\Office PC\AppData\Roaming\Malwarebytes
[2010/12/19 00:21:53 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/12/19 00:21:53 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/12/19 00:21:50 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/12/19 00:21:50 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/12/18 14:28:18 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/12/18 14:28:17 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/12/18 14:17:26 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/12/18 13:46:01 | 000,000,000 | —D | C] – C:\Windows\LastGood.Tmp
[2010/12/15 18:11:00 | 002,038,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/12/15 18:10:59 | 000,352,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskschd.dll
[2010/12/15 18:10:59 | 000,345,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2010/12/15 18:10:59 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2010/12/15 18:10:57 | 000,292,352 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2010/12/15 18:10:57 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2010/12/15 18:10:57 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2010/12/15 18:10:56 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2010/12/15 18:10:54 | 000,611,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/12/15 18:10:53 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/12/15 18:10:53 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/12/15 18:10:52 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/12/15 18:10:52 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/12/15 18:10:52 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2010/12/15 18:10:52 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/12/15 18:10:52 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/12/15 18:10:52 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/12/15 18:10:52 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/12/15 18:10:52 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/12/15 18:10:52 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/12/15 18:10:52 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/12/15 18:10:52 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2010/12/15 18:10:52 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/12/15 18:10:52 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/12/15 18:10:51 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/12/15 18:10:49 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/12/05 22:14:16 | 000,000,000 | —D | C] – C:\ProgramData\WinZip
[2010/12/03 16:07:54 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\System32\GEARAspi.dll
[2010/12/01 18:07:55 | 000,038,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WdfLdr.sys
[2010/12/01 18:07:08 | 000,000,000 | —D | C] – C:\Users\Office PC\AppData\Roaming\Nokia
[2010/12/01 18:07:03 | 000,000,000 | —D | C] – C:\Users\Office PC\AppData\Local\NokiaAccount
[2010/11/30 20:05:26 | 000,000,000 | —D | C] – C:\Users\Office PC\AppData\Local\Nokia
[2010/11/30 20:05:23 | 000,000,000 | —D | C] – C:\ProgramData\PC Suite
[2010/11/30 20:05:22 | 000,000,000 | —D | C] – C:\Users\Office PC\AppData\Roaming\PC Suite
[2010/11/30 20:04:16 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Nokia
[2010/11/30 20:03:31 | 000,000,000 | —D | C] – C:\Program Files\DIFX
[2010/11/30 20:03:30 | 000,018,816 | —- | C] (Nokia) – C:\Windows\System32\drivers\pccsmcfd.sys
[2010/11/30 20:02:27 | 000,000,000 | —D | C] – C:\Program Files\PC Connectivity Solution
[2010/11/30 19:59:03 | 000,092,672 | —- | C] (Nokia) – C:\Windows\System32\nmwcdcls.dll
[2010/11/30 19:58:33 | 000,000,000 | —D | C] – C:\ProgramData\NokiaInstallerCache
[2010/11/30 19:58:33 | 000,000,000 | —D | C] – C:\Program Files\Nokia
[2010/11/29 17:38:30 | 000,094,208 | —- | C] (Apple Inc.) – C:\Windows\System32\QuickTimeVR.qtx
[2010/11/29 17:38:30 | 000,069,632 | —- | C] (Apple Inc.) – C:\Windows\System32\QuickTime.qts
[2010/11/28 23:26:55 | 000,000,000 | —D | C] – C:\Users\Office PC\Calibre Library
[2010/11/28 23:26:52 | 000,000,000 | —D | C] – C:\Users\Office PC\AppData\Roaming\calibre
[2010/11/28 23:25:45 | 000,000,000 | —D | C] – C:\Program Files\Calibre2
[2010/11/27 00:00:47 | 000,000,000 | —D | C] – C:\Users\Office PC\Documents\Spectres
[2 C:\Users\Office PC\AppData\Local\*.tmp files -> C:\Users\Office PC\AppData\Local\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/12/19 01:13:23 | 006,291,456 | -HS- | M] () – C:\Users\Office PC\NTUSER.DAT
[2010/12/19 01:03:14 | 000,032,251 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/12/19 01:03:13 | 000,032,251 | —- | M] () – C:\ProgramData\nvModes.001
[2010/12/19 01:03:04 | 000,003,696 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/12/19 01:03:04 | 000,003,696 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/12/19 01:03:03 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/12/19 01:03:01 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/12/19 01:02:37 | 3488,899,072 | -HS- | M] () – C:\hiberfil.sys
[2010/12/19 01:01:33 | 000,524,288 | -HS- | M] () – C:\Users\Office PC\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/12/19 01:01:33 | 000,065,536 | -HS- | M] () – C:\Users\Office PC\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/12/19 00:48:31 | 000,000,098 | —- | M] () – C:\Windows\System32\drivers\etc\Hosts
[2010/12/19 00:21:53 | 000,000,912 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/19 00:12:15 | 000,000,106 | —- | M] () – C:\Users\Office PC\Desktop\fixme.reg
[2010/12/19 00:09:26 | 000,009,319 | —- | M] () – C:\Users\Office PC\Desktop\weeks.xlsx
[2010/12/19 00:08:10 | 000,142,298 | —- | M] () – C:\Users\Office PC\Desktop\Stay with this topic until I give you the all clean post.docx
[2010/12/19 00:08:10 | 000,000,162 | -H– | M] () – C:\Users\Office PC\Desktop\~$ay with this topic until I give you the all clean post.docx
[2010/12/19 00:07:50 | 000,002,651 | —- | M] () – C:\Users\Office PC\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2007.lnk
[2010/12/18 14:28:39 | 000,001,670 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/12/18 14:17:34 | 000,001,732 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/12/18 13:51:22 | 102,026,208 | —- | M] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2010/12/17 20:39:57 | 000,245,760 | —- | M] () – C:\Users\Office PC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/17 18:46:49 | 000,703,388 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/12/17 18:46:49 | 000,608,760 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/12/17 18:46:49 | 000,108,268 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/12/17 16:47:52 | 000,002,609 | —- | M] () – C:\Users\Office PC\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2007.lnk
[2010/12/16 03:26:59 | 000,396,240 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/12/16 03:24:28 | 005,202,426 | -H– | M] () – C:\Users\Office PC\AppData\Local\IconCache.db
[2010/12/08 20:39:11 | 000,034,304 | —- | M] () – C:\Users\Office PC\Documents\2011 forward order summary_draft.xls
[2010/12/01 18:08:13 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2010/12/01 18:08:13 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
[2010/11/30 20:05:16 | 000,001,934 | —- | M] () – C:\Users\Public\Desktop\Nokia Ovi Suite.lnk
[2010/11/29 17:42:18 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/11/29 17:42:06 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/11/29 17:38:30 | 000,094,208 | —- | M] (Apple Inc.) – C:\Windows\System32\QuickTimeVR.qtx
[2010/11/29 17:38:30 | 000,069,632 | —- | M] (Apple Inc.) – C:\Windows\System32\QuickTime.qts
[2010/11/26 13:52:51 | 000,000,060 | —- | M] () – C:\Windows\wpd99.drv
[2 C:\Users\Office PC\AppData\Local\*.tmp files -> C:\Users\Office PC\AppData\Local\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/12/19 00:21:53 | 000,000,912 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/19 00:12:15 | 000,000,106 | —- | C] () – C:\Users\Office PC\Desktop\fixme.reg
[2010/12/19 00:09:25 | 000,009,319 | —- | C] () – C:\Users\Office PC\Desktop\weeks.xlsx
[2010/12/19 00:08:10 | 000,142,298 | —- | C] () – C:\Users\Office PC\Desktop\Stay with this topic until I give you the all clean post.docx
[2010/12/19 00:08:10 | 000,000,162 | -H– | C] () – C:\Users\Office PC\Desktop\~$ay with this topic until I give you the all clean post.docx
[2010/12/18 14:28:39 | 000,001,670 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/12/18 14:17:34 | 000,001,732 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/12/08 20:39:10 | 000,034,304 | —- | C] () – C:\Users\Office PC\Documents\2011 forward order summary_draft.xls
[2010/12/01 18:08:13 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
[2010/12/01 18:08:13 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
[2010/12/01 18:07:56 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01009_Inbox_Critical.Wdf
[2010/11/30 20:05:16 | 000,001,934 | —- | C] () – C:\Users\Public\Desktop\Nokia Ovi Suite.lnk
[2010/09/23 09:03:54 | 000,197,120 | —- | C] () – C:\Windows\patchw32.dll
[2010/03/11 17:43:45 | 000,000,000 | —- | C] () – C:\Users\Office PC\AppData\Local\prvlcl.dat
[2010/01/31 11:29:20 | 000,032,251 | —- | C] () – C:\ProgramData\nvModes.001
[2010/01/31 11:29:16 | 000,032,251 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/11/21 16:20:48 | 000,000,198 | —- | C] () – C:\Windows\Typing.ini
[2009/11/21 13:40:58 | 000,010,240 | —- | C] () – C:\Windows\System32\vidx16.dll
[2009/09/11 11:17:00 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/09/11 11:16:42 | 000,368,640 | —- | C] () – C:\Windows\System32\msjetoledb40.dll
[2009/08/16 08:31:34 | 000,000,271 | —- | C] () – C:\Windows\ka.ini
[2009/07/10 10:48:44 | 000,000,024 | —- | C] () – C:\Windows\Woabc123.ini
[2009/07/04 18:36:47 | 000,000,770 | —- | C] () – C:\Windows\hegames.ini
[2009/05/08 20:10:32 | 000,000,060 | —- | C] () – C:\Windows\wpd99.drv
[2009/05/08 20:10:31 | 000,051,716 | —- | C] () – C:\Windows\System32\pdf995mon.dll
[2009/03/08 15:32:24 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/02/21 14:49:12 | 000,060,124 | —- | C] () – C:\Windows\System32\tcpmon.ini
[2009/02/20 11:31:27 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2009/02/19 13:06:39 | 000,245,760 | —- | C] () – C:\Users\Office PC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/10 22:06:33 | 000,000,680 | —- | C] () – C:\Users\Office PC\AppData\Local\d3d9caps.dat
[2008/12/10 21:56:46 | 005,202,426 | -H– | C] () – C:\Users\Office PC\AppData\Local\IconCache.db
[2008/12/10 21:14:39 | 000,109,208 | —- | C] () – C:\Users\Office PC\AppData\Local\GDIPFONTCACHEV1.DAT
[2008/02/15 15:56:04 | 000,002,429 | —- | C] () – C:\ProgramData\hpzinstall.log
[2008/02/15 15:39:28 | 000,327,680 | —- | C] () – C:\Windows\System32\pythoncom25.dll
[2008/02/15 15:39:28 | 000,102,400 | —- | C] () – C:\Windows\System32\pywintypes25.dll
[2006/11/02 23:50:50 | 000,000,174 | -HS- | C] () – C:\Program Files\desktop.ini
[2006/11/02 23:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 21:33:01 | 000,703,388 | —- | C] () – C:\Windows\System32\PerfStringBackup.INI
[2006/11/02 21:24:31 | 000,001,405 | —- | C] () – C:\Windows\msdfmap.ini
[2006/11/02 21:23:31 | 000,000,235 | —- | C] () – C:\Windows\system.ini
[2006/11/02 21:23:31 | 000,000,219 | —- | C] () – C:\Windows\win.ini
[2006/11/02 18:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 18:09:45 | 000,027,097 | —- | C] () – C:\Windows\System32\country.sys
[2006/11/02 18:09:44 | 000,042,809 | —- | C] () – C:\Windows\System32\KEY01.SYS
[2006/11/02 18:09:44 | 000,042,537 | —- | C] () – C:\Windows\System32\KEYBOARD.SYS
[2006/11/02 18:09:42 | 000,009,029 | —- | C] () – C:\Windows\System32\ANSI.SYS
[2006/11/02 18:09:41 | 000,004,768 | —- | C] () – C:\Windows\System32\HIMEM.SYS
[2006/11/02 18:09:40 | 000,029,274 | —- | C] () – C:\Windows\System32\NTDOS412.SYS
[2006/11/02 18:09:38 | 000,029,370 | —- | C] () – C:\Windows\System32\NTDOS411.SYS
[2006/11/02 18:09:35 | 000,029,146 | —- | C] () – C:\Windows\System32\NTDOS404.SYS
[2006/11/02 18:09:31 | 000,029,146 | —- | C] () – C:\Windows\System32\NTDOS804.SYS
[2006/11/02 18:09:29 | 000,027,866 | —- | C] () – C:\Windows\System32\NTDOS.SYS
[2006/11/02 18:09:26 | 000,035,536 | —- | C] () – C:\Windows\System32\NTIO412.SYS
[2006/11/02 18:09:24 | 000,035,776 | —- | C] () – C:\Windows\System32\NTIO411.SYS
[2006/11/02 18:09:23 | 000,034,672 | —- | C] () – C:\Windows\System32\NTIO404.SYS
[2006/11/02 18:09:22 | 000,034,672 | —- | C] () – C:\Windows\System32\NTIO804.SYS
[2006/11/02 18:09:20 | 000,033,952 | —- | C] () – C:\Windows\System32\NTIO.SYS
[2006/11/02 17:25:08 | 000,013,312 | —- | C] () – C:\Windows\System32\win87em.dll
[2003/11/04 20:05:47 | 000,001,125 | —- | C] () – C:\Windows\Winamp.ini

========== LOP Check ==========

[2010/09/23 09:08:15 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\Atari
[2010/11/18 21:58:16 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\Audacity
[2010/11/07 12:55:58 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\AVG10
[2009/07/19 14:30:42 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\Azureus
[2010/11/28 23:30:30 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\calibre
[2010/04/18 00:00:51 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\Facebook
[2009/04/13 17:36:26 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\ImgBurn
[2009/11/21 16:23:18 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\InterTrust
[2010/09/23 09:04:01 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\Leadertech
[2009/06/01 21:14:05 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\muvee Technologies
[2010/12/01 18:07:08 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\Nokia
[2010/11/30 20:05:23 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\PC Suite
[2009/05/08 20:12:06 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\pdf995
[2009/02/22 17:43:29 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\Pinnacle Systems
[2009/04/29 18:42:10 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\TerraTec
[2010/12/19 00:44:56 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\uTorrent
[2008/12/11 23:28:45 | 000,000,000 | —D | M] – C:\Users\Office PC\AppData\Roaming\WinBatch
[2010/12/19 01:01:39 | 000,032,560 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >
actually was only in the extras file…

OTL Extras logfile created on: 19/12/2010 1:13:29 AM - Run 5
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Users\Office PC\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18999)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
7.00 Gb Paging File | 5.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455.78 Gb Total Space | 11.92 Gb Free Space | 2.61% Space Free | Partition Type: NTFS
Drive D: | 9.98 Gb Total Space | 1.36 Gb Free Space | 13.62% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 465.64 Gb Free Space | 99.97% Space Free | Partition Type: NTFS

Computer Name: OFFICEPC-PC | User Name: Office PC | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\mozilla firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1678808A-5307-4FDB-A6AB-AEB57751D7D4}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=c:\windows\system32\svchost.exe |
"{222B6E6B-7BE9-4C05-B7B2-46C604D79C18}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{2AEB1A8E-CE15-4D35-AEDF-4FB3E440618B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{2F8B97F2-FDFD-40A9-8717-8D8C41DD3415}" = lport=30015 | protocol=6 | dir=in | name=vuse |
"{45AADE3B-2E80-49E5-A64F-E3B318739FCB}" = lport=2869 | protocol=6 | dir=in | app=system |
"{54F324C4-838E-4D9F-92DE-375AEAF7CF1B}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{5E34E808-097F-4D98-85AF-D817FE5FD0D4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{A4C87983-9BB2-4482-9A43-6A2B779B130C}" = lport=30015 | protocol=17 | dir=in | name=vuse 2 |
"{AE42677B-ED43-4AD0-917F-3A019E362306}" = lport=3702 | protocol=17 | dir=in | app=c:\windows\system32\p2phost.exe |
"{B6ABC475-E96B-48C9-A145-3106FD21ABDC}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=c:\windows\system32\svchost.exe |
"{CFF5CCCA-92D3-49FE-8D01-82C8C0B9BD51}" = rport=3702 | protocol=17 | dir=out | app=c:\windows\system32\p2phost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01D61B0F-F834-40F8-8C5B-536E384C316C}" = protocol=6 | dir=out | app=c:\windows\system32\p2phost.exe |
"{030FC33A-1E87-4FFA-8BFF-C3D8CFB264D3}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{07CA70DA-CB6B-4074-976E-9796B43A2354}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{07F52DFE-B27B-4BFA-A71C-E42F965352E2}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{0B507A48-D375-47CB-8FF1-0BC99BB53FFC}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{14B013AF-9C93-4509-9103-B414DFB501D7}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{29A746D0-35C5-459F-AD60-45C5ED06365D}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{56C0CD1E-143C-43CE-AD69-2CCE25CC20DA}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{57D0109C-6811-46E0-9F7B-7FD08922A095}" = protocol=6 | dir=in | app=c:\windows\system32\p2phost.exe |
"{5D93C28A-581A-48E0-A26E-FE75A83E6335}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe |
"{688EFC27-6B50-4B8B-9C60-26D708344CBF}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6BE33E8B-5F95-4E62-9212-4907434FBD78}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{714605C9-739C-465C-9EFD-CE72984A687F}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{7CDDED20-46B1-4886-BC2C-E7FF5AD016C5}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{7FAD2D49-B9B8-4541-A6E6-705AC84897C1}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{7FE6E74C-37E4-473A-9649-A4341FAE8A49}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{82E65908-D0AE-48C2-AC17-62BFD7C6E21C}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{8E2FDAFE-9925-4263-AC65-4F3B0F74862B}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{9344278C-2D5E-4269-96AA-3B35A1235C67}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{B26352B3-609C-4254-B564-05A73A24854A}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{C9F117B4-9F50-4DC3-8C9B-AF40EFA8F29F}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{CA5DDC49-78A7-43AA-992A-2A837168F14C}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{D1666FE1-5B53-4D74-A7FD-42E65B9F32BC}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{D187D807-F4BE-4FAE-BC63-EB14E57A9E21}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{DAFFF7CC-5A23-4CBB-804D-DED85A3461F8}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{DEFEEBA5-D23A-4DB8-A159-6CEF5B2FFA30}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{ECF957E0-D535-4511-8B20-635B153CE5A9}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"TCP Query User{34E86C25-1759-4A9B-97F1-3831B197229E}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{35715022-1353-4735-8B5D-754531D4A785}C:\program files\hasbro interactive\rollercoaster tycoon\rct.exe" = protocol=6 | dir=in | app=c:\program files\hasbro interactive\rollercoaster tycoon\rct.exe |
"TCP Query User{6BDC1372-AEA4-473C-8949-1A723B7F545C}C:\program files\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"TCP Query User{71C5F247-C93A-4139-B565-3D16DA7855BA}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"TCP Query User{7F8B346C-17AF-4747-9E2F-8B506BE2E706}C:\program files\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"UDP Query User{38BC4BAE-9092-4DC7-9739-305AF871D163}C:\program files\hasbro interactive\rollercoaster tycoon\rct.exe" = protocol=17 | dir=in | app=c:\program files\hasbro interactive\rollercoaster tycoon\rct.exe |
"UDP Query User{38ECA769-39E5-4B8D-B2E5-DE048B6A7248}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"UDP Query User{A273B48D-0926-44EF-975D-E6CF4E406227}C:\program files\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"UDP Query User{BBB96063-4D54-4A8D-9491-7F810C097B89}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{D9AC2982-429E-401E-A7CF-46B27F83D090}C:\program files\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{06E6E30D-B498-442F-A943-07DE41D7F785}" = Microsoft Search Enhancement Pack
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0A2C5854-557E-48C8-835A-3B9F074BDCAA}" = Python 2.5
"{0A8C7880-F199-4807-ABD4-6E695B71A3D7}" = e-tax 2009
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{139E303E-1050-497F-98B1-9AE87B15C463}" = Windows Live Family Safety
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1BCE2581-B7CA-4BB4-BDFB-D113506AA38B}" = HP Easy Setup - Frontend
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java™ 6 Update 22
"{308B6AEA-DE50-4666-996D-0FA461719D6B}" = Apple Mobile Device Support
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34DAFDEC-A4B4-488A-A5CD-C91975A6F083}" = MediaRing Talk
"{360022A4-9339-426B-8F36-1465CBAEABC0}" = D7300
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45DF6D99-666D-41FA-8D62-0E183B6240F3}" = PC Connectivity Solution
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{5115C036-C0D5-4E1B-81C9-542CA967478A}" = muvee autoProducer 6.1
"{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5A39E27B-BFFB-48B5-886F-D3038AD176BF}" = calibre
"{5AD96CF5-2627-4F29-9D2D-72FCD85F6355}" = AVG 2011
"{6009F2FC-EC56-4e28-B91C-0BA5104D6419}" = SF_CDA_Software
"{63B9BAB5-F36A-4A3B-9E5C-68A7F212BFB9}" = TerraTec Home Cinema
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{714B6179-84C4-4FBE-B934-B6CF75ED37A5}" = D6100_D7100_D7300_Help
"{73A43E42-3658-4DD9-8551-FACDA3632538}" = HP Advisor
"{749A1EDD-16C2-4C63-B013-D38F0F953973}" = OviMPlatform
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7F10292C-A190-4176-A665-A1ED3478DF86}" = LightScribe System Software
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{8112C6B3-91E1-4560-8AB9-876DADFA37C5}" = Ovi Desktop Sync Engine
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{881F5DE8-9367-4B81-A325-E91BBC6472F9}" = iTunes
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8CC42289-E228-4A35-B8A9-015242283BB2}" = SPORE™ Creature Creator
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{907B4640-266B-4A21-92FB-CD1A86CD0F63}" = RollerCoaster Tycoon® 3
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{9718521B-A345-4ad9-A52B-74D1435FB708}" = SF_CDA_ProductContext
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{981DE354-9301-440f-AAFC-025AA2354A93}" = HP Deskjet & Photosmart Printer Driver Software 8.0.A
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{A23061AF-5361-433C-B7F0-CE5F79A22C49}" = AVG 2011
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A6D23784-2091-11D4-9BEB-00104B198B0D}" = Oz - TMA
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.5
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B148AB4B-C8FA-474B-B981-F2943C5B5BCD}" = OGA Notifier 1.7.0105.35.0
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B8B4446F-87E1-4423-A47A-16832C24A199}" = Nokia Ovi Suite
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C8D47273-7A1A-4614-A3D8-263632D8A5ED}" = HP Customer Experience Enhancements
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BE}" = WinZip 15.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D2023740-9AAC-11D4-B54D-006008571948}" = Pac-Man Adventures in Time
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{EE5B5B24-EEFC-4C8B-BF8B-256D705BAD89}" = Nokia Ovi Suite Software Updater
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1FDAA01-988C-423F-AC12-0D8F333943FD}" = Nokia Connectivity Cable Driver
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FBE569CA-BFEB-4E57-A674-F94D938E1AEF}" = e-tax 2010
"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"6273b5a2c962d830ec3ac19663871c2c187731047" = Become a History Explorer
"ABC's & 123's" = ABC's & 123's
"AC3Filter" = AC3Filter (remove only)
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.12 (Unicode)
"AVG" = AVG 2011
"Blue's Treasure Hunt" = Blue's Treasure Hunt
"CCleaner" = CCleaner
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"ENTERPRISE" = Microsoft Office Enterprise 2007
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"I Love Spelling!" = I Love Spelling!
"ImgBurn" = ImgBurn
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"JumpStart Artist" = JumpStart Artist
"JumpStart Explorers" = JumpStart Explorers
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Marketmaker CFD-FX Asia Pacific" = Marketmaker CFD-FX Asia Pacific
"McAfee Security Scan" = McAfee Security Scan Plus
"MFMA2 - Adding and Subtracting" = MFMA2 - Adding and Subtracting
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MTK3" = Imagine Pet Vet Australia
"Nokia Ovi Suite" = Nokia Ovi Suite
"NVIDIA Drivers" = NVIDIA Drivers
"OsdMaestro" = HP On-Screen Cap/Num/Scroll Lock Indicator
"PC-Doctor 5 for Windows" = Hardware Diagnostic Tools
"Pdf995" = Pdf995
"PeerGuardian_is1" = PeerGuardian 2.0
"RollerCoaster Tycoon Setup" = Roll
"Scholastic's I SPY Spooky Mansion" = Scholastic's I SPY Spooky Mansion
"Searchqu MediaBar" = Windows Searchqu Toolbar
"Typing Tutor" = Typing Tutor
"Vuze" = Vuze
"whirlN&E.exe" = Whirled Math N&E
"WildTangent hp Master Uninstall" = My HP Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WinXMedia iPod/3GP/PSP/MP4 Converter" = WinXMedia iPod/3GP/PSP/MP4 Converter 1.12
"XBALLOON" = XBALLOON

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Facebook Plug-In" = Facebook Plug-In
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI