Auntie Vira's inf.ected
Topic Starter
Hi and thank you very much in advance for your assistance. My laptop is just over a year old but it acts like it's on it's last leg. First of all, Windows defender runs scans daily but fails to alert me of any detrimental findings. I only found this out by accessing the error logs in the event viewer of the Administrative Tools, things like Trojans that have downloaded, etc… it gives me no alert whatsoever when anything critical happens, it simply makes a log of the event and files it away. Avast however, does alert me instantly and SAYS it has either aborted the connection or it has quarantined the file, however, whether it does either of the two is unknown, but what I DO know, is that it is either allowing it to also download and install simultaneously, or the file finds it's way through and installs anyway.
In the past 2-3 weeks I have had 3 different instances of the fake AV8 malware install simply by going to a website. The latest occurrence I simply clicked on a link in the search results of a google query and got it. I got it previously just from visiting a friends facebook profile, and I am not sure how I came into contact with it the first time. I also have what seems to be 30 or so instances of svchost.exe/+k (or something like that) running in my processes at all times. It seems to be making my computer run slow or eating up my resources because my CPU is always up high and my processor always seems to be kicked into high gear like it's being overworked. Especially when I open a program that utilizes graphics, you can hear that puppy just kick in and rev up, and whatever program i'm attempting to run just runs so sluggish it's almost pathetic to watch. This is only reinforced by the fact that there are more of these warning logs than I can count in the event viewer: The speed of processor 1 is being limited by system firmware. The processor has been in this reduced performance state for 71 seconds since the last report. the number of seconds since the last report is often in the quintuple digits which signals the processor is almost constantly in this state. I have attached all 3 program scan logs as requested. Please let me know what else you need. I appreciate your help greatly. Happy New Year
OLT Scans:
OTL logfile created on: 12/31/2010 5:03:56 AM - Run 1
OTL by OldTimer - Version 3.2.18.2 Folder = C:\Users\Daniel\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287.17 Gb Total Space | 134.51 Gb Free Space | 46.84% Space Free | Partition Type: NTFS
Drive D: | 10.92 Gb Total Space | 1.81 Gb Free Space | 16.57% Space Free | Partition Type: NTFS
Drive E: | 2.50 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: DANIELS-LAPTOP | User Name: Daniel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Daniel\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Safari\Safari.exe (Apple Inc.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\SMINST\BLService.exe ()
PRC - C:\Windows\System32\iashost.exe (Microsoft Corporation)
PRC - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION)
PRC - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
========== Modules (SafeList) ==========
MOD - C:\Users\Daniel\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (Norton Internet Security) – C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe File not found
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\netsession_win_aeec0f0.dll ()
SRV - (HssTrayService) – C:\Program Files\Hotspot Shield\bin\HssTrayService.exe ()
SRV - (HotspotShieldService) – C:\Program Files\Hotspot Shield\bin\openvpnas.exe ()
SRV - (HssWd) – C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
SRV - (HssSrv) – C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Recovery Service for Windows) – C:\Program Files\SMINST\BLService.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (EPSON_EB_RPCV4_01) EPSON V5 Service4(01) – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION)
SRV - (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
========== Driver Services (SafeList) ==========
DRV - (SRTSPX) – C:\Windows\System32\drivers\NIS\1000000.07D\SRTSPX.SYS File not found
DRV - (SRTSP) – C:\Windows\System32\drivers\NIS\1000000.07D\SRTSP.SYS File not found
DRV - (SCREAMINGBDRIVER) – C:\Windows\System32\drivers\ScreamingBAudio.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVEX15.SYS File not found
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVENG.SYS File not found
DRV - (ManyCam) – C:\Windows\System32\DRIVERS\ManyCam.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (clwvd) – C:\Windows\System32\DRIVERS\clwvd.sys File not found
DRV - (NVNET) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (HssDrv) – C:\Windows\System32\drivers\hssdrv.sys (AnchorFree Inc.)
DRV - (SASKUTIL) – C:\Users\Daniel\AppData\Local\Temp\SAS_SelfExtract\saskutil.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (SASDIFSV) – C:\Users\Daniel\AppData\Local\Temp\SAS_SelfExtract\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (taphss) – C:\Windows\System32\drivers\taphss.sys (AnchorFree Inc)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (RTSTOR) – C:\Windows\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (motccgpfl) – C:\Windows\System32\drivers\motccgpfl.sys (Motorola)
DRV - (motccgp) – C:\Windows\System32\drivers\motccgp.sys (Motorola)
DRV - (NVHDA) – C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (NETw3v32) Intel® – C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (motport) – C:\Windows\System32\drivers\motport.sys (Motorola)
DRV - (motmodem) – C:\Windows\System32\drivers\motmodem.sys (Motorola)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (yukonwlh) – C:\Windows\System32\drivers\yk60x86.sys (Marvell)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.netzero.net/search?action=mi…urce=minisearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.facebook.com/?ref=hp [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: {3e0e7d2a-070f-4a47-b019-91fe5385ba79}:3.1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {582195F5-92E7-40a0-A127-DB71295901D7}:0.6
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: [removed]:0.9948
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: {1b8cc170-8c85-11db-b606-0800200c9a66}:3.4.2
FF - prefs.js..extensions.enabledItems: {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:11.0.1
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.1
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&q;="
FF - prefs.js..network.proxy.type: 0
FF - user.js..network.proxy.type: 0
FF - user.js..network.proxy.http: ""
FF - user.js..network.proxy.http_port:
FF - user.js..network.proxy.no_proxies_on: ""
FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2009/09/10 12:49:37 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{577e3214-a6d3-4bd9-b689-381f57e69bcf}: C:\Program Files\Windows Live\Writer\BlogThis\Mozilla Firefox\ [2010/03/05 00:06:48 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/12 14:00:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/12 14:00:22 | 000,000,000 | —D | M]
[2009/09/30 04:48:22 | 000,000,000 | —D | M] (No name found) – C:\Users\Daniel\AppData\Roaming\Mozilla\Extensions
[2009/09/30 04:48:22 | 000,000,000 | —D | M] (No name found) – C:\Users\Daniel\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/12/31 03:04:35 | 000,000,000 | —D | M] (No name found) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions
[2010/10/03 11:31:14 | 000,000,000 | —D | M] (Screengrab) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2010/10/03 11:31:14 | 000,000,000 | —D | M] (ShareThis) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{1b8cc170-8c85-11db-b606-0800200c9a66}
[2010/10/03 11:31:14 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/10/03 11:31:14 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/10/03 11:31:14 | 000,000,000 | —D | M] (Tournament Games for Firefox) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{398FE6B9-01FB-4860-920B-BE9F2E04DF3D}
[2010/10/11 15:43:08 | 000,000,000 | —D | M] (AddThis) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
[2010/01/28 15:28:42 | 000,000,000 | —D | M] (AddThis) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}(1194)
[2010/10/03 11:31:14 | 000,000,000 | —D | M] (Gmail Manager) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{582195F5-92E7-40a0-A127-DB71295901D7}
[2010/10/03 11:31:14 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/01/31 06:44:08 | 000,000,000 | —D | M] (iMacros for Firefox) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}(1206)
[2010/10/16 14:51:52 | 000,000,000 | —D | M] (Tamper Data) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
[2010/10/16 16:43:28 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/03/08 00:41:04 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(100)
[2010/10/03 11:31:14 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/10/03 11:31:13 | 000,000,000 | —D | M] (ChaCha Guide App Toolbar) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\[removed]
[2010/10/03 11:31:13 | 000,000,000 | —D | M] (No name found) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\[removed]
[2010/10/03 11:31:13 | 000,000,000 | —D | M] (Read it Later) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\[removed]
[2010/10/03 11:31:13 | 000,000,000 | —D | M] (Flash AX Control) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\[removed]
[2010/10/03 11:31:13 | 000,000,000 | —D | M] (Veoh Video Compass) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\[removed]
[2010/10/16 16:43:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2009/09/21 06:53:28 | 000,000,000 | —D | M] (HideMyIP) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2010/04/12 12:45:54 | 000,000,000 | —D | M] (Hide My IP) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2010/05/26 18:15:33 | 000,000,000 | —D | M] (Easy-Hide-IP Firefox Plugin) – C:\PROGRAM FILES\EASY-HIDE-IP\FF-EXTENSION
[2009/11/14 19:00:43 | 000,036,864 | —- | M] (Homestead Technologies, Inc.) – C:\Program Files\Mozilla Firefox\plugins\nphssb.dll
[2009/05/30 17:39:34 | 000,221,184 | —- | M] (CNN) – C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll
[2010/07/12 09:33:56 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
O1 HOSTS File: ([2010/04/10 12:18:47 | 000,385,927 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 13313 more lines…
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Pop-up Blocker) - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll (NetZero, Inc.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll (AnchorFree Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (NetZero Toolbar Helper) - {FE3098B0-04A3-41fd-8CA9-BEA39CB14C87} - C:\Program Files\NetZero\UCReg.dll (NetZero, Inc.)
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (ZeroBar) - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll (NetZero, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [PRISMSVR.EXE] C:\Windows\System32\PRISMSVR.EXE File not found
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\VirtuaGirl.lnk = C:\Program Files\Vg\Vg.exe ()
O8 - Extra context menu item: Download with Xilisoft Download YouTube Video - C:\Program Files\Xilisoft\Download YouTube Video\upod_link.HTM ()
O8 - Extra context menu item: Download with Xilisoft YouTube Video Converter - C:\Program Files\Xilisoft\YouTube Video Converter\upod_link.HTM ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: netzero.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: netzero.net ([]* in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCMaticVer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Daniel\Desktop\misc\101.jpg
O24 - Desktop BackupWallPaper: C:\Users\Daniel\Desktop\misc\101.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{75b4d4f2-0d07-11e0-b5b2-001f16d17702}\Shell\AutoRun\command - "" = F:\urDrive.exe – File not found
O33 - MountPoints2\{fc7962cc-4198-11df-b0af-001f16d17702}\Shell\AutoRun\command - "" = F:\setupSNK.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.g723 - g723.acm File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.I263 - C:\Windows\System32\i263_32.drv (Intel Corporation)
Drivers32: vidc.i420 - C:\Windows\System32\i263_32.drv (Intel Corporation)
Drivers32: VIDC.IV41 - C:\Windows\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2010/12/31 05:01:19 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Users\Daniel\Desktop\OTL.exe
[2010/12/22 03:42:40 | 000,000,000 | —D | C] – C:\Users\Daniel\Desktop\Junk Trunk
[2010/12/22 03:41:53 | 000,000,000 | R–D | C] – C:\Users\Daniel\Desktop\Junk in My Trunk
[2010/12/21 11:19:05 | 000,000,000 | —D | C] – C:\Program Files\Vg
[2010/12/21 04:06:40 | 000,000,000 | —D | C] – C:\Program Files\2Wire
[2010/12/21 03:44:31 | 000,393,216 | —- | C] (Atheros) – C:\Windows\System32\athihvs.dll
[2010/12/21 03:44:31 | 000,376,832 | —- | C] (Atheros) – C:\Windows\System32\S64CPA.exe
[2010/12/21 03:44:31 | 000,053,248 | —- | C] (Atheros) – C:\Windows\System32\athihvui.dll
[2010/12/21 03:44:31 | 000,000,000 | —D | C] – C:\Windows\System32\nn-NO
[2010/12/21 03:43:35 | 000,000,000 | —D | C] – C:\Program Files\Cisco
[2010/12/11 19:58:54 | 000,758,784 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\cohelper.dll
[2010/12/11 19:40:00 | 000,000,000 | —D | C] – C:\Windows\en
[2010/12/11 19:37:23 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_3.dll
[2010/12/11 19:37:22 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_5.dll
[2010/12/11 19:37:22 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_42.dll
[2010/12/11 19:10:19 | 000,000,000 | —D | C] – C:\Users\Daniel\AppData\Local\Windows Live
[2010/12/11 19:09:41 | 000,754,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webservices.dll
[2010/12/09 01:13:57 | 000,000,000 | —D | C] – C:\Users\Daniel\AppData\Roaming\SUPERAntiSpyware.com
[2010/12/09 01:13:57 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2009/10/14 08:42:45 | 000,398,416 | —- | C] (Microsoft Corporation) – C:\Program Files\VBRUN300.DLL
[2009/10/14 08:42:45 | 000,060,992 | —- | C] (Willow Pond Corporation) – C:\Program Files\WPCTRL.DLL
[2009/10/14 08:42:45 | 000,026,768 | —- | C] (Microsoft Corporation) – C:\Program Files\CTL3D.DLL
[2009/10/14 08:42:45 | 000,014,176 | —- | C] (Willow Pond Corporation) – C:\Program Files\DOC.EXE
[7 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/12/31 05:06:04 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2302350703-3623477863-1373200073-1000UA.job
[2010/12/31 05:05:00 | 000,000,424 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{2C65306E-A463-4FA4-818A-3E01482134B4}.job
[2010/12/31 05:01:24 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Users\Daniel\Desktop\OTL.exe
[2010/12/31 04:48:00 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/31 04:14:32 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/12/31 04:14:32 | 000,104,170 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/12/31 04:11:22 | 000,031,966 | —- | M] () – C:\ProgramData\nvModes.001
[2010/12/31 04:10:52 | 000,031,966 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/12/31 04:10:48 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/31 04:09:06 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/12/31 04:09:06 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/12/31 04:08:22 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/12/31 04:08:15 | 2951,106,560 | -HS- | M] () – C:\hiberfil.sys
[2010/12/31 04:06:30 | 000,000,244 | —- | M] () – C:\Users\Daniel\Documents\zonemapdomains.reg
[2010/12/30 13:24:06 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2302350703-3623477863-1373200073-1000Core.job
[2010/12/22 19:39:09 | 000,033,428 | —- | M] () – C:\Users\Daniel\.recently-used.xbel
[2010/12/21 11:19:40 | 000,020,358 | —- | M] () – C:\Windows\vgirl.prf
[2010/12/21 11:19:08 | 000,000,746 | —- | M] () – C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\VirtuaGirl.lnk
[2010/12/21 04:31:22 | 000,000,258 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2010/12/20 18:09:00 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/12/11 20:11:00 | 000,000,326 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForDaniel.job
[2010/12/11 20:10:43 | 000,330,480 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/12/10 01:56:15 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/10 01:50:55 | 107,653,792 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/12/09 01:57:36 | 000,001,356 | —- | M] () – C:\Users\Daniel\AppData\Local\d3d9caps.dat
[2010/12/09 01:37:26 | 000,091,648 | —- | M] () – C:\Users\Daniel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[7 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/12/31 04:08:15 | 2951,106,560 | -HS- | C] () – C:\hiberfil.sys
[2010/12/31 04:06:29 | 000,000,244 | —- | C] () – C:\Users\Daniel\Documents\zonemapdomains.reg
[2010/12/22 19:39:09 | 000,033,428 | —- | C] () – C:\Users\Daniel\.recently-used.xbel
[2010/12/21 11:19:40 | 000,020,358 | —- | C] () – C:\Windows\vgirl.prf
[2010/12/21 11:19:08 | 000,000,746 | —- | C] () – C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\VirtuaGirl.lnk
[2010/12/10 01:56:15 | 000,000,906 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/10 01:50:55 | 107,653,792 | —- | C] () – C:\Windows\MEMORY.DMP
[2010/10/16 17:51:43 | 000,000,067 | —- | C] () – C:\Windows\swf2avi.INI
[2010/10/16 17:51:38 | 000,758,018 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/10/16 17:51:38 | 000,180,224 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/08/29 05:33:19 | 000,000,002 | —- | C] () – C:\Windows\PhotoSuite.ini
[2010/07/03 15:40:47 | 000,458,752 | —- | C] () – C:\Windows\System32\Fpl.dll
[2010/07/03 15:40:47 | 000,122,880 | —- | C] () – C:\Windows\System32\JPEGLIB.DLL
[2010/07/03 15:40:47 | 000,019,968 | —- | C] () – C:\Windows\System32\CPUINF32.DLL
[2010/07/03 15:40:46 | 000,332,800 | —- | C] () – C:\Windows\System32\FPXLIB.DLL
[2010/06/24 05:46:19 | 000,000,220 | -HS- | C] () – C:\Windows\dwin.sys
[2010/06/06 07:08:30 | 000,000,024 | —- | C] () – C:\Users\Daniel\AppData\Local\37562-11537-09847-00QV1-78241
[2010/04/12 12:45:40 | 000,196,608 | —- | C] () – C:\Windows\System32\HMIPCore.dll
[2010/03/25 19:50:37 | 000,000,050 | —- | C] () – C:\Windows\MegaManager.INI
[2010/03/03 08:16:50 | 000,010,752 | —- | C] () – C:\Windows\System32\BASSMOD.dll
[2010/02/06 17:26:45 | 000,000,048 | —- | C] () – C:\Users\Daniel\AppData\Local\47599-22037-39462-09QV6-33854
[2010/01/04 05:39:47 | 000,335,872 | —- | C] () – C:\Windows\System32\m4atag.dll
[2009/12/22 04:33:11 | 000,000,148 | —- | C] () – C:\Windows\System32\acmeinc.ini
[2009/12/22 04:33:11 | 000,000,116 | —- | C] () – C:\Windows\System32\vxdtgm.ini
[2009/11/26 18:38:05 | 000,001,356 | —- | C] () – C:\Users\Daniel\AppData\Local\d3d9caps.dat
[2009/10/26 06:59:55 | 000,073,728 | —- | C] () – C:\Windows\System32\VistaInfo8.dll
[2009/10/15 07:21:22 | 000,000,000 | —- | C] () – C:\Users\Daniel\AppData\Local\FnF4.txt
[2009/10/14 08:59:51 | 000,000,031 | —- | C] () – C:\Windows\custvoic.ini
[2009/10/14 08:42:45 | 000,097,259 | —- | C] () – C:\Program Files\Talker.exe
[2009/10/14 08:42:45 | 000,001,660 | —- | C] () – C:\Program Files\README.TXT
[2009/10/14 08:42:45 | 000,000,591 | —- | C] () – C:\Program Files\prog.ini
[2009/10/13 16:35:51 | 000,116,224 | —- | C] () – C:\Windows\System32\pdfcmnnt.dll
[2009/10/12 21:07:56 | 000,000,518 | —- | C] () – C:\Users\Daniel\AppData\Roaming\wklnhst.dat
[2009/09/26 02:45:52 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2009/09/26 01:50:50 | 000,029,696 | —- | C] () – C:\Program Files\Veoh3260B5D63432474ABED033A073A35E39.videos
[2009/09/22 23:59:15 | 000,000,097 | —- | C] () – C:\Windows\System32\PICSDK.ini
[2009/09/22 23:56:15 | 000,000,044 | —- | C] () – C:\Windows\EPSNX300.ini
[2009/09/13 08:28:49 | 000,002,238 | —- | C] () – C:\Users\Daniel\AppData\Roaming\Jackpot City Flash Casino.ico
[2009/09/11 07:36:06 | 000,073,728 | —- | C] () – C:\Windows\System32\VistaInfo32.dll
[2009/08/30 04:08:51 | 000,056,832 | —- | C] () – C:\Windows\System32\Iyvu9_32.dll
[2009/08/24 18:48:37 | 000,001,304 | —- | C] () – C:\ProgramData\hpzinstall.log
[2009/08/20 12:04:22 | 000,057,710 | —- | C] () – C:\Program Files\VeohVideoCompass-1.5.1.1034.xpi
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 00:21:54 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll
[2009/06/01 16:32:53 | 000,031,966 | —- | C] () – C:\ProgramData\nvModes.001
[2009/06/01 16:31:17 | 000,031,966 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/05/31 16:20:49 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/05/30 13:36:45 | 000,091,648 | —- | C] () – C:\Users\Daniel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/29 14:33:37 | 000,000,000 | —- | C] () – C:\Users\Daniel\AppData\Local\QSwitch.txt
[2009/05/29 14:33:37 | 000,000,000 | —- | C] () – C:\Users\Daniel\AppData\Local\DSwitch.txt
[2009/05/29 14:33:37 | 000,000,000 | —- | C] () – C:\Users\Daniel\AppData\Local\AtStart.txt
[2009/05/16 05:07:20 | 000,000,105 | —- | C] () – C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
[2009/05/16 05:07:10 | 000,000,032 | —- | C] () – C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2009/05/16 05:06:44 | 000,000,032 | —- | C] () – C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
[2009/05/16 05:06:08 | 000,000,032 | —- | C] () – C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
[2009/05/16 05:04:09 | 000,000,032 | —- | C] () – C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
[2009/05/16 05:03:33 | 000,000,246 | —- | C] () – C:\ProgramData\hpqp.ini
[2009/04/20 14:34:59 | 000,000,109 | —- | C] () – C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2009/04/20 14:28:56 | 000,000,110 | —- | C] () – C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
[2009/04/20 14:26:52 | 000,000,105 | —- | C] () – C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2009/04/20 14:25:26 | 000,000,107 | —- | C] () – C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/03/09 02:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2000/04/14 16:50:02 | 000,343,040 | —- | C] () – C:\Windows\System32\Lffpx7.dll
[1998/06/11 13:08:06 | 000,095,232 | —- | C] () – C:\Windows\System32\Lfkodak.dll
========== LOP Check ==========
[2009/09/11 08:02:46 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\50States
[2010/11/15 15:59:38 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\BitTorrent
[2010/01/31 00:54:45 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Blackdiamond
[2009/09/11 08:03:05 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\CasinoStates
[2009/10/06 07:17:39 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/06/05 02:40:34 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\com.prakaz.project.photogettr.FBAB9E68ED32BC183252F597C39DBF71CF315A79.1
[2010/02/16 04:05:59 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\EPSON
[2010/01/03 21:31:17 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\FileZilla
[2009/08/14 05:47:11 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\funkitron
[2010/12/22 19:39:09 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\gtk-2.0
[2010/10/03 11:31:08 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Hide IP NG
[2009/11/23 09:58:46 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\iLike
[2010/02/13 08:30:05 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Keynote Systems
[2010/10/03 11:31:08 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Keyword Strategy Studio Pro
[2009/09/23 00:46:24 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Leadertech
[2009/10/02 06:16:20 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\LimeWire
[2009/11/29 00:28:48 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\ManyCam
[2010/03/24 09:23:49 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Megaupload
[2009/06/01 18:13:31 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\monkey money
[2010/03/23 22:57:00 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Moyea
[2010/10/02 21:06:45 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\muvee Technologies
[2009/09/30 07:47:08 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\NCH Swift Sound
[2010/05/27 18:21:24 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Nvu
[2009/05/29 20:17:00 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\OpenOffice.org
[2009/06/01 18:09:30 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\PlayFirst
[2010/03/03 09:32:16 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Screaming Bee
[2009/12/24 23:24:05 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Smith Micro
[2010/10/03 11:31:17 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\SystemRequirementsLab
[2009/10/12 21:07:59 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Template
[2009/11/11 07:45:01 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2010/10/02 02:56:13 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Ulead Systems
[2009/11/29 00:16:51 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\WeatherBug
[2009/05/29 18:10:26 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\WildTangent
[2009/08/02 23:23:08 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\WildTangentv1002
[2010/05/28 01:05:55 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Windows Live Writer
[2009/11/23 09:47:42 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Xilisoft
[2010/12/30 05:03:24 | 000,032,556 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/12/31 05:05:00 | 000,000,424 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{2C65306E-A463-4FA4-818A-3E01482134B4}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 14:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/10 23:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2010/07/18 20:28:39 | 003,396,176 | —- | M] (Piriform Ltd) – C:\ccsetup233.exe
[2006/09/18 14:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/12/31 04:08:15 | 2951,106,560 | -HS- | M] () – C:\hiberfil.sys
[2009/08/30 04:08:08 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/12/02 17:21:27 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2009/08/30 04:08:08 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2009/11/14 19:00:43 | 000,036,864 | —- | M] (Homestead Technologies, Inc.) – C:\nphssb.dll
[2009/11/14 19:00:43 | 000,000,247 | —- | M] () – C:\nphssb.xpt
[2010/12/31 04:08:11 | 3264,942,080 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/11/02 05:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 05:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 05:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/05/31 16:26:45 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 14:37:34 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/12/16 18:17:56 | 000,315,392 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpfpp6en.dll
[2008/01/20 19:23:14 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/09/23 00:32:56 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[1998/05/11 20:01:00 | 000,026,768 | —- | M] (Microsoft Corporation) – C:\Program Files\CTL3D.DLL
[2008/01/20 19:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
[1995/12/04 11:47:10 | 000,014,176 | —- | M] (Willow Pond Corporation) – C:\Program Files\DOC.EXE
[2009/10/14 08:43:27 | 000,000,591 | —- | M] () – C:\Program Files\prog.ini
[1999/07/19 08:48:32 | 000,001,660 | —- | M] () – C:\Program Files\README.TXT
[1999/07/19 08:27:28 | 000,097,259 | —- | M] () – C:\Program Files\Talker.exe
[1993/05/12 00:00:00 | 000,398,416 | —- | M] (Microsoft Corporation) – C:\Program Files\VBRUN300.DLL
[2009/09/26 01:51:23 | 000,029,696 | —- | M] () – C:\Program Files\Veoh3260B5D63432474ABED033A073A35E39.videos
[2009/08/20 12:04:22 | 000,057,710 | —- | M] () – C:\Program Files\VeohVideoCompass-1.5.1.1034.xpi
[1996/01/25 14:12:34 | 000,060,992 | —- | M] (Willow Pond Corporation) – C:\Program Files\WPCTRL.DLL
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/01/20 20:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 20:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 20:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 03:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 03:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/05/31 16:03:04 | 000,000,286 | -HS- | M] () – C:\Users\Daniel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2010/12/31 05:01:24 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Users\Daniel\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-12 02:59:03
========== Alternate Data Streams ==========
@Alternate Data Stream - 81 bytes -> C:\Program Files\Intertops Poker:MID
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:05BF1B63
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:33DB8278
@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:E91ADC66
@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:A8ADE5D8
@Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:A688EF17
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:A692C296
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:43860CE8
@Alternate Data Stream - 107 bytes -> C:\ProgramData\Temp:A3E34FEB
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:FC2E567F
@Alternate Data Stream - 102 bytes -> C:\ProgramData\Temp:4D2028FC
@Alternate Data Stream - 100 bytes -> C:\ProgramData\Temp:A1D3FEF0
< End of report >
OTL Extras logfile created on: 12/31/2010 5:03:56 AM - Run 1
OTL by OldTimer - Version 3.2.18.2 Folder = C:\Users\Daniel\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287.17 Gb Total Space | 134.51 Gb Free Space | 46.84% Space Free | Partition Type: NTFS
Drive D: | 10.92 Gb Total Space | 1.81 Gb Free Space | 16.57% Space Free | Partition Type: NTFS
Drive E: | 2.50 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: DANIELS-LAPTOP | User Name: Daniel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.chm [@ = chm.file] – Reg Error: Key error. File not found
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-2302350703-3623477863-1373200073-1000]
"EnableNotifications" = 1
"EnableNotificationsRef" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0183F9D0-A230-45A9-8032-B46876F1736C}" = lport=49163 | protocol=6 | dir=in | name=akamai netsession interface |
"{02DFA78D-9D71-4690-982F-8EDFD1B35F62}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{037C2478-F6FB-4CF7-8962-1FAA0C22EE72}" = rport=445 | protocol=6 | dir=out | app=system |
"{268EE24F-0A1E-4468-B72A-736404A3B204}" = lport=49184 | protocol=6 | dir=in | name=akamai netsession interface |
"{35729933-CD40-4090-A0FF-A8563F9ED239}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{35CBC390-EAED-44EC-B864-94A133CEA80C}" = rport=139 | protocol=6 | dir=out | app=system |
"{3C67C091-D15A-457D-9FAA-3E18E6EF69C0}" = rport=138 | protocol=17 | dir=out | app=system |
"{4B33E63F-6FCC-445D-B6AB-E64086011344}" = lport=8081 | protocol=6 | dir=in | name=proxy |
"{65ED8BD0-8F43-436C-A049-8EB4AFEC5751}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{68B99A25-C128-4870-B196-96546B60F3F0}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6A1CC862-AA4C-47A2-8690-0F76B756E9DB}" = lport=137 | protocol=17 | dir=in | app=system |
"{7699BF94-F936-4147-8ACC-23BCE91EB5D2}" = lport=138 | protocol=17 | dir=in | app=system |
"{7B643425-B8DA-4102-B668-95ADBEAC9970}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{7BAB008B-1E9A-4AA7-9007-35CDD5AB6117}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{854F399B-FFE0-48FE-8EC9-02750EEB9344}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{86DCA94B-3992-4087-9C17-6E4C9BBC4228}" = lport=49159 | protocol=6 | dir=in | name=akamai netsession interface |
"{8C504B58-AD88-43FF-844B-33CB473BD72E}" = lport=445 | protocol=6 | dir=in | app=system |
"{93B8C938-9503-4867-9C55-E77503FEC951}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{94CEBCC7-58F1-4674-8497-E2472AC7C1F2}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A0B8F954-8168-4662-9D6D-2547754DF7A6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B14B88B0-0317-42ED-A20D-3D104D39A8A0}" = lport=49471 | protocol=6 | dir=in | name=akamai netsession interface |
"{B37E627D-8CF6-4831-8C91-2531F6BED43E}" = lport=139 | protocol=6 | dir=in | app=system |
"{C057A5D4-4C70-4DFB-A5F2-BA2D861ED4CE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CDF7C7C8-BC66-4A3B-A8E3-00E13D05A65F}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{DDF3092A-BF2C-4F39-95D8-51AA2059DAC2}" = rport=137 | protocol=17 | dir=out | app=system |
"{F2054FBC-8AD2-447E-AA52-B78261D2E1A3}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{FADEC0A0-7F94-4D20-814C-2BE193C20FF3}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04207B04-77D8-42DF-9C5C-9F2E1BA51B15}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{0DC8714D-7449-4F2E-89FE-6C87C6BEED6A}" = protocol=17 | dir=in | app=c:\program files\easy-hide-ip\easyhideip.exe |
"{0EDEBF13-B54E-484B-8DA2-02D9147A0971}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{1254062C-3FEA-4B24-AB20-B58919106353}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{1754A5EE-1C76-45ED-B73C-BFD627848A2F}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{2DC3385A-9405-4C38-AB27-F51A83DCD6EA}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |
"{34FAD3B9-9A62-4BD1-9544-64A74E339C20}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3669D566-067B-4D76-A877-6E37C5A16B69}" = protocol=17 | dir=in | app=c:\program files\pinnacle\videospin\programs\rm.exe |
"{3B9A531E-B15E-4360-9DD7-5DB4E36752DA}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{4844259A-1650-49C3-817D-36F54E4AC6E3}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{494A25FE-D933-4741-952F-55B32E419E4D}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{4BA405C1-A5B2-4CC2-A6E5-9A1650A5AC06}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{51C18E13-0881-4B19-99F6-059E2BD68267}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{5BAA344A-8428-452C-A152-58A3B589D4B8}" = protocol=6 | dir=in | app=c:\program files\pinnacle\videospin\programs\umi.exe |
"{6DC80416-ABD5-4176-8A6A-DC941E8B650A}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{8009AA8B-B7F6-49AE-AD51-0D556BD1DC7A}" = protocol=6 | dir=in | app=c:\program files\easy-hide-ip\easyhideip.exe |
"{82F1FA22-DB70-4EB0-B1E3-C16EA0D32FEA}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{8A04A4C5-2A65-4C56-B5C5-1E4C2B0547FE}" = protocol=17 | dir=in | app=c:\program files\pinnacle\videospin\programs\umi.exe |
"{95507AAD-F39A-4295-A233-8A8FF3773CA5}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{96C3EEAB-23DA-4F96-991C-F07B4B12DA39}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{B957667B-F962-4681-AED6-9A45E5EA23CE}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{BEFE73FD-6447-48EF-A027-E7AFF76160F0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C6BE8966-86D2-409E-9967-ED33DA19E09C}" = protocol=6 | dir=in | app=c:\program files\pinnacle\videospin\programs\rm.exe |
"{CAB3C9EA-C2E1-4F15-AA27-CB930DE79346}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{CC6CB051-68DE-46AC-9430-8BDFC020E6B6}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{D3066696-DAE4-4D29-9668-4E0867FA1B53}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{EB614195-430B-4466-9259-0DFAEEABB7D1}" = protocol=6 | dir=in | app=c:\program files\pinnacle\videospin\programs\videospin.exe |
"{ECB2E3FA-5B9C-47E1-9E12-492A79621192}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{FA11C6DF-FB36-4C9B-B90D-74E0BEB4A9A2}" = protocol=17 | dir=in | app=c:\program files\pinnacle\videospin\programs\videospin.exe |
"{FA24B9AD-997F-45DF-90D8-6B40A15BD463}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{150F653B-5E48-4C90-9249-7EA0EC662A75}C:\program files\veoh networks\veohwebplayer\veohwebplayer.exe" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"TCP Query User{3396A736-9561-44F6-B567-9CEA3D90E266}C:\windows\system32\spool\drivers\w32x86\3\e_dupa30.exe" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\e_dupa30.exe |
"TCP Query User{44F4EDA4-DEE9-4E07-A10E-A5E08564E156}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{4593A125-279D-44CB-8DDC-1ACD49A5EC72}C:\program files\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files\videolan\vlc\vlc.exe |
"TCP Query User{54D1DC77-2116-45F5-B004-3E17EC7DBF1A}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{861946D9-89C5-4C5C-A448-8BEEFAFD8185}C:\microgaming\casino\grandmondial\casinogame.exe" = protocol=6 | dir=in | app=c:\microgaming\casino\grandmondial\casinogame.exe |
"TCP Query User{90F3B7A8-BA9A-4267-BE2C-79ABA1DC35EB}C:\program files\ip hider\ip hider.exe" = protocol=6 | dir=in | app=c:\program files\ip hider\ip hider.exe |
"TCP Query User{99910B38-8D63-4129-AB8A-FBB136E767FA}C:\program files\easy-hide-ip\easy-hide-ip.exe" = protocol=6 | dir=in | app=c:\program files\easy-hide-ip\easy-hide-ip.exe |
"TCP Query User{9A61417F-6AD3-412A-93DB-E244CDE452FF}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"TCP Query User{A4B83540-A00C-4FD4-8DF7-A32E04BED141}C:\users\daniel\appdata\local\temp\stu3cc2.tmp\viewerpc.exe" = protocol=6 | dir=in | app=c:\users\daniel\appdata\local\temp\stu3cc2.tmp\viewerpc.exe |
"TCP Query User{C5C215EF-5D14-4C46-9135-F7B84E95D176}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{DEC20702-08D2-40F9-AB89-6AAB137932E3}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{0772EF7B-5732-4345-B79C-A7E3A2D98422}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"UDP Query User{18865007-0AA2-49A2-9A7D-8745D22DED42}C:\microgaming\casino\grandmondial\casinogame.exe" = protocol=17 | dir=in | app=c:\microgaming\casino\grandmondial\casinogame.exe |
"UDP Query User{224806CC-9DE7-423A-8AF1-3DCAE2C87083}C:\program files\ip hider\ip hider.exe" = protocol=17 | dir=in | app=c:\program files\ip hider\ip hider.exe |
"UDP Query User{2408BC81-5D1E-49F8-B4AA-35A903F37DEE}C:\program files\easy-hide-ip\easy-hide-ip.exe" = protocol=17 | dir=in | app=c:\program files\easy-hide-ip\easy-hide-ip.exe |
"UDP Query User{2AE7E71B-5B22-453D-86C9-1CAB85378C04}C:\users\daniel\appdata\local\temp\stu3cc2.tmp\viewerpc.exe" = protocol=17 | dir=in | app=c:\users\daniel\appdata\local\temp\stu3cc2.tmp\viewerpc.exe |
"UDP Query User{3DBB8732-6F89-4506-90A0-40F17D4D210D}C:\program files\veoh networks\veohwebplayer\veohwebplayer.exe" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"UDP Query User{4317BF2D-93D6-4BF0-8A1B-9681C65A26DE}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{58C802FF-97F2-486B-B2C6-C316A575C217}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{AB378B09-6C6C-49C7-8B9E-62E0E05D1B86}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{B2C3708E-515C-49CA-B790-54F748F27E77}C:\program files\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files\videolan\vlc\vlc.exe |
"UDP Query User{CF82C431-9F9C-43CD-9FFE-9C95F85EE011}C:\windows\system32\spool\drivers\w32x86\3\e_dupa30.exe" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\e_dupa30.exe |
"UDP Query User{E75398E6-482B-49A7-AB1C-B5363167E6F4}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{003D3756-10DE-4CAA-9A59-705E041000BA}" = video-processor
"{0054A0F6-00C9-4498-B821-B5C9578F433E}" = HP Help and Support
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}" = LightScribe System Software 1.14.17.1
"{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{14291118-0C19-45EA-A4FA-5C1C0F5FDE09}" = Primo
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}" = HP Total Care Advisor
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{203E564A-51E6-44E5-9DF9-8D0AD66E401D}" = DJ_SF_05_D2600_Software_Min
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 18
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{27F00C63-449B-2FAB-CBE8-24AB80E17449}" = Acrobat.com
"{2AD738DC-FC24-4342-A2DA-BB6DCCF6B048}" = Jing
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{32A3A4F4-B792-11D6-A78A-00B0D0160140}" = Java™ SE Development Kit 6 Update 14
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 H2
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{38058455-8C21-4C2F-B2F6-14ED166039CB}" = HP Total Care Setup
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Vista
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{39E705C7-669D-42EC-90F0-38F376D24774}" = Windows Live Writer Blog This for Mozilla Firefox
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C79DC59-6099-323B-B27B-90B45542B270}" = Google Talk Plugin
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.7
"{46473794-57D2-4512-9AAC-EB7E7F5D1E52}" = Gmail Account Creator
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{57A5AEC1-97FC-474D-92C4-908FCC2253D4}" = HP Customer Experience Enhancements
"{593A99E0-AB4E-49E0-AE23-3499E1C43FBA}" = Quivic 6
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{665CBCA4-5AB0-414B-A288-3F8F99FEFC45}" = HP User Guides 0118
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6c651250-2eb2-11d5-8e33-0050dad72ac2}" = NetZero Internet
"{6CE460E5-54F5-46EB-83DB-B514215D66B7}" = Hide The IP 2009
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{775290AD-C54E-418C-9564-A10836F42C1C}" = D2600
"{7B15D70E-9449-4CFB-B9BC-798465B2BD5C}" = Norton Internet Security
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{80D3CFFD-4CB5-47A1-8779-11A720A9ADB2}" = HP Deskjet D2600 Printer Driver Software 13.0 Rel .5
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{878A2B1F-0BDA-4739-B8D7-490315B9BE93}_is1" = X2X Free Video Trim 1.0
"{88D68A69-D247-466B-90DD-575F6BE16230}_is1" = CardRecovery 5.20
"{893931C2-0CD4-45DD-AFE3-3B7772FE65E1}" = Word count plugin for Live Writer
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{926C96FB-9D0A-4504-8000-C6D3A4A3118E}" = Java DB 10.4.2.1
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9ADABDDE-9644-461B-9E73-83FA3EFCAB50}" = HP Wireless Assistant
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9DF0BE48-16F0-4E36-814D-9B4FDFFAF25F}" = PayPal Plug-In
"{9F3C8BE0-A54A-2D46-36FB-0029D412B0AC}" = TweetDeck
"{A19B094A-42EB-4D3F-A57E-0CDE052A1D80}" = IS-DV
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3BC5D37-30F9-4CF7-BD5C-0DFF063E4B6D}" = 2Wire Wireless Client
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA047707-196A-77B3-E971-2885E0CB157A}" = Bulkr
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}" = Adobe Shockwave Player
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{AFAC914D-9E83-4A89-8ABE-427521C82CCF}" = Safari
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BC4664AC-AA57-4DD2-93BE-54CDF57D63CE}" = Cricket Wireless PC Media Center 1.1
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B8}" = WinZip 12.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{DABF43D9-1104-4764-927B-5BED1274A3B0}" = Runtime
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DD35C328-F115-BEDA-6EEE-E00C5AACCCBC}" = muvee Reveal
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DEDB47A3-C988-4A43-A645-E2CEA571E680}" = Epson Easy Photo Print 2
"{E031338C-839D-4EDD-9537-99B653C39D81}" = Autodesk MapGuide® Viewer ActiveX Control Release 6.5
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{E9ED0801-253D-4FE9-AB20-F63DEFE72547}" = SAMSUNG Mobile USB DRIVER(4.40.7.0) v1.6
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE4270D7-A642-49C1-9A40-854DA3F13FB2}_is1" = Moyea FLV Player version: 2.0.2.96
"{fe986ae8-5283-4177-9178-52ba8d21bb10}" = Jackpot Capital
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"123VideoMagic" = 123VideoMagic
"2Wire SetupWiz" = AT&T; Yahoo! High Speed Internet Home Networking Installer
"4Bec Article Rewriter_is1" = 4Bec Article Rewriter v2.0
"4Bec Equi_is1" = 4Bec Equi v2.0
"4Bec Forum_is1" = 4Bec Forum v2.0
"7-Zip" = 7-Zip 4.65
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Akamai" = Akamai NetSession Interface
"AnalogX AutoTune" = AnalogX AutoTune
"Article Buzz_is1" = Article Buzz v2.0
"Audacity_is1" = Audacity 1.2.6
"avast5" = avast! Free Antivirus
"B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind
"Bejeweled 2 Deluxe 1.1.3.2523" = Bejeweled 2 Deluxe 1.1.3.2523
"BFGC" = Big Fish Games Client
"BFG-Call of Atlantis" = Call of Atlantis
"BFG-Megaplex Madness - Now Playing" = Megaplex Madness: Now Playing ™
"BFG-Midnight Mysteries - The Edgar Allan Poe Conspiracy" = Midnight Mysteries: The Edgar Allan Poe Conspiracy
"BFG-Slingo Supreme" = Slingo Supreme
"BFG-Zuma Deluxe" = Zuma Deluxe
"Bookworm Adventures Vol. 2" = Bookworm Adventures Vol. 2
"Bookworm Deluxe 1.13" = Bookworm Deluxe 1.13
"Bruce's Unusual Typing Wizard_is1" = Bruce's Unusual Typing Wizard, Version 1.5.0
"CCleaner" = CCleaner
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"CocoaCasino" = Cocoa Casino
"CodInstl" = Intel A/V Codecs V2.0
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"com.prakaz.project.photogettr.FBAB9E68ED32BC183252F597C39DBF71CF315A79.1" = Bulkr
"DenderaCasino" = Dendera Casino
"Digital Laugh Track" = Digital Laugh Track
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX Setup
"Easy-Hide-IP_is1" = Easy-Hide-IP 3.5
"EPSON NX300 Series" = EPSON NX300 Series Printer Uninstall
"EPSON Scanner" = EPSON Scan
"EZ Keez by Gina Geez_is1" = EZ Keez by Gina Geez v2.01
"EZKeez by GinaGeez_is1" = EZKeez by GinaGeez v2.01
"Face Smoother_is1" = Face Smoother 2.54
"FaceDub" = FaceDub
"FileZilla Client" = FileZilla Client 3.3.1
"Flash Movie Player" = Flash Movie Player 1.5
"Grammar Slammer Deluxe with Spelling and Grammar Checkers" = Grammar Slammer Deluxe with Spelling and Grammar Checkers
"grandmonaco" = Grand Mondial Casino
"Hixus Keyword Inventor_is1" = Hixus Keyword Inventor 1.1
"HotspotShield" = Hotspot Shield 1.44
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"InstallShield_{E9ED0801-253D-4FE9-AB20-F63DEFE72547}" = SAMSUNG Mobile USB DRIVER(4.40.7.0) v1.6
"Intertops Poker" = Intertops Poker
"Intuit SiteBuilder" = Intuit SiteBuilder
"iWisoft Flash SWF to Video Converter_is1" = iWisoft Flash SWF to Video Converter 3.4
"jackpotcity" = Jackpot City Online Casino
"Keyword Buzz_is1" = Keyword Buzz v2.01
"Keyword Strategy Studio Pro_is1" = Keyword Strategy Studio Pro v2010.030210
"Keyword Swarm_is1" = Keyword Swarm
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"Magic Photo Editor_is1" = Magic Photo Editor 5.8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MSCSR" = Microsoft Speech Recognition Engine 4.0 (English)
"MVP Backgammon Professional_is1" = MVP Backgammon Professional 2.0.1 Trial
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"redflush" = Red Flush
"Replay Media Catcher 3.01" = Replay Media Catcher 3.01
"SlotOCash" = Sloto Cash
"Streamster" = Marketiva
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"SystemRequirementsLab" = System Requirements Lab
"tournamentgames_3.exe" = Tournament Games (remove only)
"TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1" = TweetDeck
"VegasRegalCasino" = Vegas Regal Casino
"Veoh Web Player Beta" = Veoh Web Player
"VirtuaGirl" = VirtuaGirl
"VLC media player" = VideoLAN VLC media player 0.8.6i
"WildTangent hp Master Uninstall" = HP Games
"Winamp" = Winamp
"WinGimp-2.0_is1" = GIMP 2.4.0
"WinLiveSuite" = Windows Live Essentials
"WT076365" = Family Mystery - The Story of Amy
"Xilisoft Download YouTube Video" = Xilisoft Download YouTube Video
"Xilisoft YouTube Video Converter" = Xilisoft YouTube Video Converter
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update
"Zuma Deluxe 1.0" = Zuma Deluxe 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent
"Winamp Detect" = Winamp Detector Plug-in
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >
Hijack this scan:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:19:19 AM, on 12/31/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18975)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Safari\Safari.exe
C:\Users\Daniel\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.netzero.net/search?action=mi…urce=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.netzero.net/search?action=mi…urce=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.netzero.net/search?action=mi…urce=minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-up Blocker - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O2 - BHO: NetZero Toolbar Helper - {FE3098B0-04A3-41fd-8CA9-BEA39CB14C87} - C:\Program Files\NetZero\ucreg.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\Windows\system32\PRISMSVR.EXE" /APPLY
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: VirtuaGirl.lnk = C:\Program Files\Vg\Vg.exe
O8 - Extra context menu item: Download with Xilisoft Download YouTube Video - C:\Program Files\Xilisoft\Download YouTube Video\upod_link.HTM
O8 - Extra context menu item: Download with Xilisoft YouTube Video Converter - C:\Program Files\Xilisoft\YouTube Video Converter\upod_link.HTM
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O8 - Extra context menu item: Send Image to Photo Library - file://C:\ProgramData\MGI\PhotoSuite4\Temp\MGI00000.html
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Grand Mondial Casino - 1D9BD393-E01E-4C70-B602-0CACF6C5FAA9 - C:\Microgaming\Casino\GrandMondial\Casinogame.exe (HKCU)
O9 - Extra button: Jackpot City Online Casino - CE0C94F3-E30E-45BD-B900-D519E0DD6956 - C:\Microgaming\Casino\JackpotCity\Casinogame.exe (HKCU)
O9 - Extra button: Red Flush - {1864FB6F-969B-4DB1-AA99-13B5F05C6833} - C:\Casino\RedFlush\casinogame.exe (HKCU)
O15 - Trusted Zone: *.netzero.com
O15 - Trusted Zone: *.netzero.net
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} (PCMaticVer Class) - http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: EPSON V5 Service4(01) (EPSON_EB_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
–
End of file - 10365 bytes
DDS scan:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 5:25:13.94 on Fri 12/31/2010
Internet Explorer: 8.0.6001.18975 BrowserJavaVersion: 1.6.0_18
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2814.1533 [GMT -7:00]
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k Akamai
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\SMINST\BLService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\System32\svchost.exe -k NetSvcs
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\iashost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Safari\Safari.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Daniel\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=en_us&c;=91&bd;=Pavilion&pf;=cnnb
uSearch Bar = hxxp://search.netzero.net/search?action=minisearch&source;=minisearch
uSearch Page = hxxp://search.netzero.net/search?action=minisearch&source;=minisearch
mDefault_Page_URL = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://search.netzero.net/search?action=minisearch&source;=minisearch
uURLSearchHooks: H - No File
BHO: &Yahoo;! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Pop-up Blocker: {52706ef7-d7a2-49ad-a615-e903858cf284} - c:\program files\netzero\qsacc\X1IEBHO.dll
BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
BHO: NetZero Toolbar Helper: {fe3098b0-04a3-41fd-8ca9-bea39cb14c87} - c:\program files\netzero\ucreg.dll
TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll
TB: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
TB: ZeroBar: {f0f8ecbe-d460-4b34-b007-56a92e8f84a7} - c:\program files\netzero\Toolbar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [PRISMSVR.EXE] "c:\windows\system32\PRISMSVR.EXE" /APPLY
StartupFolder: c:\users\daniel\appdata\roaming\micros~1\windows\startm~1\programs\startup\virtua~1.lnk - c:\program files\vg\Vg.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Download with Xilisoft Download YouTube Video - c:\program files\xilisoft\download youtube video\upod_link.HTM
IE: Download with Xilisoft YouTube Video Converter - c:\program files\xilisoft\youtube video converter\upod_link.HTM
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: Send Image to Photo Library - file://c:\programdata\mgi\photosuite4\temp\MGI00000.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: netzero.com
Trusted Zone: netzero.net
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\daniel\appdata\roaming\mozilla\firefox\profiles\jbe8185r.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&q;=
FF - prefs.js: network.proxy.type - 0
FF - component: c:\users\daniel\appdata\roaming\mozilla\firefox\profiles\jbe8185r.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nphssb.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\daniel\appdata\local\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\users\daniel\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\users\daniel\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
FF - user.js: network.proxy.type - 0
FF - user.js: network.proxy.http -
user_pref(network.proxy.http_port,);
FF - user.js: network.proxy.no_proxies_on -
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4f16a", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4fra", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2009-5-29 164048]
R1 SASDIFSV;SASDIFSV;c:\users\daniel\appdata\local\temp\sas_selfextract\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\users\daniel\appdata\local\temp\sas_selfextract\saskutil.sys [2010-5-10 67656]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2008-1-20 21504]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-5-29 19024]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-5-29 51792]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\sminst\BLService.exe [2009-4-20 365952]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-10-24 1153368]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2010-9-21 1710464]
R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-4-20 193840]
R3 HssDrv;Hotspot Shield Helper Miniport;c:\windows\system32\drivers\hssdrv.sys [2010-5-13 37376]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-5-9 43040]
R3 NVNET;NVIDIA nForce Ethernet Driver;c:\windows\system32\drivers\nvmfdx32.sys [2010-8-12 292712]
R3 taphss;Anchorfree HSS Adapter;c:\windows\system32\drivers\taphss.sys [2009-9-15 32768]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 Norton Internet Security;Norton Internet Security;"c:\program files\norton internet security\engine\16.0.0.125\ccsvchst.exe" /s "norton internet security" /m "c:\program files\norton internet security\engine\16.0.0.125\dimaster.dll" /prefetch:1 –> c:\program files\norton internet security\engine\16.0.0.125\ccSvcHst.exe [?]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2008-8-21 18688]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2008-8-21 8320]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [2007-6-18 23680]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-8-31 136176]
S4 HssSrv;Hotspot Shield Routing Service;c:\program files\hotspot shield\hsswpr\hsssrv.exe [2010-5-13 348208]
S4 HssTrayService;Hotspot Shield Tray Service;c:\program files\hotspot shield\bin\HssTrayService.exe [2010-5-13 57640]
S4 HssWd;Hotspot Shield Monitoring Service;c:\program files\hotspot shield\bin\hsswd.exe -product hss –> c:\program files\hotspot shield\bin\hsswd.exe -product HSS [?]
S4 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
=============== Created Last 30 ================
2010-12-21 11:19 20,358 a——- c:\windows\vgirl.prf
2010-12-21 11:19 –d—– c:\program files\Vg
2010-12-21 04:06 –d—– c:\program files\2Wire
2010-12-21 03:44 393,216 a——- c:\windows\system32\athihvs.dll
2010-12-21 03:44 376,832 a——- c:\windows\system32\S64CPA.exe
2010-12-21 03:44 53,248 a——- c:\windows\system32\athihvui.dll
2010-12-21 03:44 –d—– c:\windows\system32\nn-NO
2010-12-21 03:43 –d—– c:\program files\Cisco
2010-12-11 19:58 758,784 a——- c:\windows\system32\cohelper.dll
2010-12-11 19:40 –d—– c:\windows\en
2010-12-11 19:37 69,464 a——- c:\windows\system32\XAPOFX1_3.dll
2010-12-11 19:37 515,416 a——- c:\windows\system32\XAudio2_5.dll
2010-12-11 19:37 453,456 a——- c:\windows\system32\d3dx10_42.dll
2010-12-11 19:09 754,688 a——- c:\windows\system32\webservices.dll
2010-12-10 01:50 107,653,792 a——- c:\windows\MEMORY.DMP
2010-12-09 01:13 –d—– c:\users\daniel\appdata\roaming\SUPERAntiSpyware.com
2010-12-09 01:13 –d—– c:\programdata\SUPERAntiSpyware.com
2010-12-09 01:13 –d—– c:\progra~2\SUPERAntiSpyware.com
==================== Find3M ====================
2010-12-31 04:10 31,966 a——- c:\programdata\nvModes.dat
2010-12-31 04:10 31,966 a——- c:\progra~2\nvModes.dat
2010-12-21 03:53 143,360 a——- c:\windows\inf\infstrng.dat
2010-12-21 03:53 51,200 a——- c:\windows\inf\infpub.dat
2010-12-21 03:44 86,016 a——- c:\windows\inf\infstor.dat
2010-12-20 18:09 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 18:08 20,952 a——- c:\windows\system32\drivers\mbam.sys
2010-11-09 10:44 1,798,146 a——- c:\users\daniel\smoother.exe
2010-11-04 03:10 323,584 a——- c:\windows\system32\AUDIOGENIE2.DLL
2010-10-19 10:41 222,080 ——– c:\windows\system32\MpSigStub.exe
2010-10-10 09:34 32,000 a——- c:\users\daniel\usbaapl.sys
2010-07-22 19:45 11,285,608 a——- c:\users\daniel\winamp5581_full_emusic-7plus_en-us.exe
2010-06-21 12:50 418,304 a——- c:\users\daniel\msgr10us.exe
2010-03-22 20:11 518 a——- c:\users\daniel\appdata\roaming\wklnhst.dat
2009-11-02 10:11 665,600 a——- c:\windows\inf\drvindex.dat
2009-10-29 08:32 167 a——- c:\users\daniel\udownload.dat
2009-10-14 08:43 591 a——- c:\program files\prog.ini
2009-09-26 01:51 29,696 a——- c:\program files\Veoh3260B5D63432474ABED033A073A35E39.videos
2009-08-20 12:04 57,710 a——- c:\program files\VeohVideoCompass-1.5.1.1034.xpi
2008-01-20 19:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
1999-07-19 08:48 1,660 a——- c:\program files\README.TXT
1999-07-19 08:27 97,259 a——- c:\program files\Talker.exe
1998-05-11 20:01 26,768 a——- c:\program files\CTL3D.DLL
1996-01-25 14:12 60,992 a——- c:\program files\WPCTRL.DLL
1995-12-04 11:47 14,176 a——- c:\program files\DOC.EXE
1993-05-12 00:00 398,416 a——- c:\program files\VBRUN300.DLL
2010-06-24 05:46 220 —sh— c:\windows\dwin.sys
2010-08-15 13:52 262,144 a–sh— c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2010-09-09 01:16 16,384 a–sh— c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2010-09-09 01:16 32,768 a–sh— c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2010-09-09 01:16 16,384 a–sh— c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat
2010-08-15 14:09 262,144 a–sh— c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
============= FINISH: 5:25:53.14 ===============
In the past 2-3 weeks I have had 3 different instances of the fake AV8 malware install simply by going to a website. The latest occurrence I simply clicked on a link in the search results of a google query and got it. I got it previously just from visiting a friends facebook profile, and I am not sure how I came into contact with it the first time. I also have what seems to be 30 or so instances of svchost.exe/+k (or something like that) running in my processes at all times. It seems to be making my computer run slow or eating up my resources because my CPU is always up high and my processor always seems to be kicked into high gear like it's being overworked. Especially when I open a program that utilizes graphics, you can hear that puppy just kick in and rev up, and whatever program i'm attempting to run just runs so sluggish it's almost pathetic to watch. This is only reinforced by the fact that there are more of these warning logs than I can count in the event viewer: The speed of processor 1 is being limited by system firmware. The processor has been in this reduced performance state for 71 seconds since the last report. the number of seconds since the last report is often in the quintuple digits which signals the processor is almost constantly in this state. I have attached all 3 program scan logs as requested. Please let me know what else you need. I appreciate your help greatly. Happy New Year
OLT Scans:
OTL logfile created on: 12/31/2010 5:03:56 AM - Run 1
OTL by OldTimer - Version 3.2.18.2 Folder = C:\Users\Daniel\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287.17 Gb Total Space | 134.51 Gb Free Space | 46.84% Space Free | Partition Type: NTFS
Drive D: | 10.92 Gb Total Space | 1.81 Gb Free Space | 16.57% Space Free | Partition Type: NTFS
Drive E: | 2.50 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: DANIELS-LAPTOP | User Name: Daniel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Daniel\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Safari\Safari.exe (Apple Inc.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\SMINST\BLService.exe ()
PRC - C:\Windows\System32\iashost.exe (Microsoft Corporation)
PRC - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION)
PRC - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
========== Modules (SafeList) ==========
MOD - C:\Users\Daniel\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (Norton Internet Security) – C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe File not found
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\netsession_win_aeec0f0.dll ()
SRV - (HssTrayService) – C:\Program Files\Hotspot Shield\bin\HssTrayService.exe ()
SRV - (HotspotShieldService) – C:\Program Files\Hotspot Shield\bin\openvpnas.exe ()
SRV - (HssWd) – C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
SRV - (HssSrv) – C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (WPFFontCache_v0400) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (Recovery Service for Windows) – C:\Program Files\SMINST\BLService.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (EPSON_EB_RPCV4_01) EPSON V5 Service4(01) – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE (SEIKO EPSON CORPORATION)
SRV - (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE (SEIKO EPSON CORPORATION)
========== Driver Services (SafeList) ==========
DRV - (SRTSPX) – C:\Windows\System32\drivers\NIS\1000000.07D\SRTSPX.SYS File not found
DRV - (SRTSP) – C:\Windows\System32\drivers\NIS\1000000.07D\SRTSP.SYS File not found
DRV - (SCREAMINGBDRIVER) – C:\Windows\System32\drivers\ScreamingBAudio.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVEX15.SYS File not found
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVENG.SYS File not found
DRV - (ManyCam) – C:\Windows\System32\DRIVERS\ManyCam.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (clwvd) – C:\Windows\System32\DRIVERS\clwvd.sys File not found
DRV - (NVNET) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (HssDrv) – C:\Windows\System32\drivers\hssdrv.sys (AnchorFree Inc.)
DRV - (SASKUTIL) – C:\Users\Daniel\AppData\Local\Temp\SAS_SelfExtract\saskutil.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (SASDIFSV) – C:\Users\Daniel\AppData\Local\Temp\SAS_SelfExtract\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (taphss) – C:\Windows\System32\drivers\taphss.sys (AnchorFree Inc)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (RTSTOR) – C:\Windows\System32\drivers\RTSTOR.sys (Realtek Semiconductor Corp.)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (motccgpfl) – C:\Windows\System32\drivers\motccgpfl.sys (Motorola)
DRV - (motccgp) – C:\Windows\System32\drivers\motccgp.sys (Motorola)
DRV - (NVHDA) – C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (MegaSR) – C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Corporation)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (NETw3v32) Intel® – C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL) – C:\Windows\System32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (motport) – C:\Windows\System32\drivers\motport.sys (Motorola)
DRV - (motmodem) – C:\Windows\System32\drivers\motmodem.sys (Motorola)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (yukonwlh) – C:\Windows\System32\drivers\yk60x86.sys (Marvell)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.netzero.net/search?action=mi…urce=minisearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.facebook.com/?ref=hp [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: {3e0e7d2a-070f-4a47-b019-91fe5385ba79}:3.1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {582195F5-92E7-40a0-A127-DB71295901D7}:0.6
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20100408.6
FF - prefs.js..extensions.enabledItems: [removed]:0.9948
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: {1b8cc170-8c85-11db-b606-0800200c9a66}:3.4.2
FF - prefs.js..extensions.enabledItems: {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:11.0.1
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.1
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&q;="
FF - prefs.js..network.proxy.type: 0
FF - user.js..network.proxy.type: 0
FF - user.js..network.proxy.http: ""
FF - user.js..network.proxy.http_port:
FF - user.js..network.proxy.no_proxies_on: ""
FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\ProgramData\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c} [2009/09/10 12:49:37 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{577e3214-a6d3-4bd9-b689-381f57e69bcf}: C:\Program Files\Windows Live\Writer\BlogThis\Mozilla Firefox\ [2010/03/05 00:06:48 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/12 14:00:22 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/12 14:00:22 | 000,000,000 | —D | M]
[2009/09/30 04:48:22 | 000,000,000 | —D | M] (No name found) – C:\Users\Daniel\AppData\Roaming\Mozilla\Extensions
[2009/09/30 04:48:22 | 000,000,000 | —D | M] (No name found) – C:\Users\Daniel\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/12/31 03:04:35 | 000,000,000 | —D | M] (No name found) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions
[2010/10/03 11:31:14 | 000,000,000 | —D | M] (Screengrab) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2010/10/03 11:31:14 | 000,000,000 | —D | M] (ShareThis) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{1b8cc170-8c85-11db-b606-0800200c9a66}
[2010/10/03 11:31:14 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/10/03 11:31:14 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/10/03 11:31:14 | 000,000,000 | —D | M] (Tournament Games for Firefox) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{398FE6B9-01FB-4860-920B-BE9F2E04DF3D}
[2010/10/11 15:43:08 | 000,000,000 | —D | M] (AddThis) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
[2010/01/28 15:28:42 | 000,000,000 | —D | M] (AddThis) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}(1194)
[2010/10/03 11:31:14 | 000,000,000 | —D | M] (Gmail Manager) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{582195F5-92E7-40a0-A127-DB71295901D7}
[2010/10/03 11:31:14 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/01/31 06:44:08 | 000,000,000 | —D | M] (iMacros for Firefox) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}(1206)
[2010/10/16 14:51:52 | 000,000,000 | —D | M] (Tamper Data) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
[2010/10/16 16:43:28 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/03/08 00:41:04 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(100)
[2010/10/03 11:31:14 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/10/03 11:31:13 | 000,000,000 | —D | M] (ChaCha Guide App Toolbar) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\[removed]
[2010/10/03 11:31:13 | 000,000,000 | —D | M] (No name found) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\[removed]
[2010/10/03 11:31:13 | 000,000,000 | —D | M] (Read it Later) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\[removed]
[2010/10/03 11:31:13 | 000,000,000 | —D | M] (Flash AX Control) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\[removed]
[2010/10/03 11:31:13 | 000,000,000 | —D | M] (Veoh Video Compass) – C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\jbe8185r.default\extensions\[removed]
[2010/10/16 16:43:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2009/09/21 06:53:28 | 000,000,000 | —D | M] (HideMyIP) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2010/04/12 12:45:54 | 000,000,000 | —D | M] (Hide My IP) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2010/05/26 18:15:33 | 000,000,000 | —D | M] (Easy-Hide-IP Firefox Plugin) – C:\PROGRAM FILES\EASY-HIDE-IP\FF-EXTENSION
[2009/11/14 19:00:43 | 000,036,864 | —- | M] (Homestead Technologies, Inc.) – C:\Program Files\Mozilla Firefox\plugins\nphssb.dll
[2009/05/30 17:39:34 | 000,221,184 | —- | M] (CNN) – C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll
[2010/07/12 09:33:56 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
O1 HOSTS File: ([2010/04/10 12:18:47 | 000,385,927 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 13313 more lines…
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Pop-up Blocker) - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll (NetZero, Inc.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll (AnchorFree Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (NetZero Toolbar Helper) - {FE3098B0-04A3-41fd-8CA9-BEA39CB14C87} - C:\Program Files\NetZero\UCReg.dll (NetZero, Inc.)
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (ZeroBar) - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll (NetZero, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [PRISMSVR.EXE] C:\Windows\System32\PRISMSVR.EXE File not found
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\VirtuaGirl.lnk = C:\Program Files\Vg\Vg.exe ()
O8 - Extra context menu item: Download with Xilisoft Download YouTube Video - C:\Program Files\Xilisoft\Download YouTube Video\upod_link.HTM ()
O8 - Extra context menu item: Download with Xilisoft YouTube Video Converter - C:\Program Files\Xilisoft\YouTube Video Converter\upod_link.HTM ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: netzero.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: netzero.net ([]* in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCMaticVer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Daniel\Desktop\misc\101.jpg
O24 - Desktop BackupWallPaper: C:\Users\Daniel\Desktop\misc\101.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{75b4d4f2-0d07-11e0-b5b2-001f16d17702}\Shell\AutoRun\command - "" = F:\urDrive.exe – File not found
O33 - MountPoints2\{fc7962cc-4198-11df-b0af-001f16d17702}\Shell\AutoRun\command - "" = F:\setupSNK.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.g723 - g723.acm File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.I263 - C:\Windows\System32\i263_32.drv (Intel Corporation)
Drivers32: vidc.i420 - C:\Windows\System32\i263_32.drv (Intel Corporation)
Drivers32: VIDC.IV41 - C:\Windows\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2010/12/31 05:01:19 | 000,602,624 | —- | C] (OldTimer Tools) – C:\Users\Daniel\Desktop\OTL.exe
[2010/12/22 03:42:40 | 000,000,000 | —D | C] – C:\Users\Daniel\Desktop\Junk Trunk
[2010/12/22 03:41:53 | 000,000,000 | R–D | C] – C:\Users\Daniel\Desktop\Junk in My Trunk
[2010/12/21 11:19:05 | 000,000,000 | —D | C] – C:\Program Files\Vg
[2010/12/21 04:06:40 | 000,000,000 | —D | C] – C:\Program Files\2Wire
[2010/12/21 03:44:31 | 000,393,216 | —- | C] (Atheros) – C:\Windows\System32\athihvs.dll
[2010/12/21 03:44:31 | 000,376,832 | —- | C] (Atheros) – C:\Windows\System32\S64CPA.exe
[2010/12/21 03:44:31 | 000,053,248 | —- | C] (Atheros) – C:\Windows\System32\athihvui.dll
[2010/12/21 03:44:31 | 000,000,000 | —D | C] – C:\Windows\System32\nn-NO
[2010/12/21 03:43:35 | 000,000,000 | —D | C] – C:\Program Files\Cisco
[2010/12/11 19:58:54 | 000,758,784 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\cohelper.dll
[2010/12/11 19:40:00 | 000,000,000 | —D | C] – C:\Windows\en
[2010/12/11 19:37:23 | 000,069,464 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_3.dll
[2010/12/11 19:37:22 | 000,515,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_5.dll
[2010/12/11 19:37:22 | 000,453,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_42.dll
[2010/12/11 19:10:19 | 000,000,000 | —D | C] – C:\Users\Daniel\AppData\Local\Windows Live
[2010/12/11 19:09:41 | 000,754,688 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webservices.dll
[2010/12/09 01:13:57 | 000,000,000 | —D | C] – C:\Users\Daniel\AppData\Roaming\SUPERAntiSpyware.com
[2010/12/09 01:13:57 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2009/10/14 08:42:45 | 000,398,416 | —- | C] (Microsoft Corporation) – C:\Program Files\VBRUN300.DLL
[2009/10/14 08:42:45 | 000,060,992 | —- | C] (Willow Pond Corporation) – C:\Program Files\WPCTRL.DLL
[2009/10/14 08:42:45 | 000,026,768 | —- | C] (Microsoft Corporation) – C:\Program Files\CTL3D.DLL
[2009/10/14 08:42:45 | 000,014,176 | —- | C] (Willow Pond Corporation) – C:\Program Files\DOC.EXE
[7 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/12/31 05:06:04 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2302350703-3623477863-1373200073-1000UA.job
[2010/12/31 05:05:00 | 000,000,424 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{2C65306E-A463-4FA4-818A-3E01482134B4}.job
[2010/12/31 05:01:24 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Users\Daniel\Desktop\OTL.exe
[2010/12/31 04:48:00 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/31 04:14:32 | 000,604,502 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/12/31 04:14:32 | 000,104,170 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/12/31 04:11:22 | 000,031,966 | —- | M] () – C:\ProgramData\nvModes.001
[2010/12/31 04:10:52 | 000,031,966 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/12/31 04:10:48 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/31 04:09:06 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/12/31 04:09:06 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/12/31 04:08:22 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/12/31 04:08:15 | 2951,106,560 | -HS- | M] () – C:\hiberfil.sys
[2010/12/31 04:06:30 | 000,000,244 | —- | M] () – C:\Users\Daniel\Documents\zonemapdomains.reg
[2010/12/30 13:24:06 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2302350703-3623477863-1373200073-1000Core.job
[2010/12/22 19:39:09 | 000,033,428 | —- | M] () – C:\Users\Daniel\.recently-used.xbel
[2010/12/21 11:19:40 | 000,020,358 | —- | M] () – C:\Windows\vgirl.prf
[2010/12/21 11:19:08 | 000,000,746 | —- | M] () – C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\VirtuaGirl.lnk
[2010/12/21 04:31:22 | 000,000,258 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2010/12/20 18:09:00 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/12/11 20:11:00 | 000,000,326 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForDaniel.job
[2010/12/11 20:10:43 | 000,330,480 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/12/10 01:56:15 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/10 01:50:55 | 107,653,792 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/12/09 01:57:36 | 000,001,356 | —- | M] () – C:\Users\Daniel\AppData\Local\d3d9caps.dat
[2010/12/09 01:37:26 | 000,091,648 | —- | M] () – C:\Users\Daniel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[7 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/12/31 04:08:15 | 2951,106,560 | -HS- | C] () – C:\hiberfil.sys
[2010/12/31 04:06:29 | 000,000,244 | —- | C] () – C:\Users\Daniel\Documents\zonemapdomains.reg
[2010/12/22 19:39:09 | 000,033,428 | —- | C] () – C:\Users\Daniel\.recently-used.xbel
[2010/12/21 11:19:40 | 000,020,358 | —- | C] () – C:\Windows\vgirl.prf
[2010/12/21 11:19:08 | 000,000,746 | —- | C] () – C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\VirtuaGirl.lnk
[2010/12/10 01:56:15 | 000,000,906 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/10 01:50:55 | 107,653,792 | —- | C] () – C:\Windows\MEMORY.DMP
[2010/10/16 17:51:43 | 000,000,067 | —- | C] () – C:\Windows\swf2avi.INI
[2010/10/16 17:51:38 | 000,758,018 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/10/16 17:51:38 | 000,180,224 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/08/29 05:33:19 | 000,000,002 | —- | C] () – C:\Windows\PhotoSuite.ini
[2010/07/03 15:40:47 | 000,458,752 | —- | C] () – C:\Windows\System32\Fpl.dll
[2010/07/03 15:40:47 | 000,122,880 | —- | C] () – C:\Windows\System32\JPEGLIB.DLL
[2010/07/03 15:40:47 | 000,019,968 | —- | C] () – C:\Windows\System32\CPUINF32.DLL
[2010/07/03 15:40:46 | 000,332,800 | —- | C] () – C:\Windows\System32\FPXLIB.DLL
[2010/06/24 05:46:19 | 000,000,220 | -HS- | C] () – C:\Windows\dwin.sys
[2010/06/06 07:08:30 | 000,000,024 | —- | C] () – C:\Users\Daniel\AppData\Local\37562-11537-09847-00QV1-78241
[2010/04/12 12:45:40 | 000,196,608 | —- | C] () – C:\Windows\System32\HMIPCore.dll
[2010/03/25 19:50:37 | 000,000,050 | —- | C] () – C:\Windows\MegaManager.INI
[2010/03/03 08:16:50 | 000,010,752 | —- | C] () – C:\Windows\System32\BASSMOD.dll
[2010/02/06 17:26:45 | 000,000,048 | —- | C] () – C:\Users\Daniel\AppData\Local\47599-22037-39462-09QV6-33854
[2010/01/04 05:39:47 | 000,335,872 | —- | C] () – C:\Windows\System32\m4atag.dll
[2009/12/22 04:33:11 | 000,000,148 | —- | C] () – C:\Windows\System32\acmeinc.ini
[2009/12/22 04:33:11 | 000,000,116 | —- | C] () – C:\Windows\System32\vxdtgm.ini
[2009/11/26 18:38:05 | 000,001,356 | —- | C] () – C:\Users\Daniel\AppData\Local\d3d9caps.dat
[2009/10/26 06:59:55 | 000,073,728 | —- | C] () – C:\Windows\System32\VistaInfo8.dll
[2009/10/15 07:21:22 | 000,000,000 | —- | C] () – C:\Users\Daniel\AppData\Local\FnF4.txt
[2009/10/14 08:59:51 | 000,000,031 | —- | C] () – C:\Windows\custvoic.ini
[2009/10/14 08:42:45 | 000,097,259 | —- | C] () – C:\Program Files\Talker.exe
[2009/10/14 08:42:45 | 000,001,660 | —- | C] () – C:\Program Files\README.TXT
[2009/10/14 08:42:45 | 000,000,591 | —- | C] () – C:\Program Files\prog.ini
[2009/10/13 16:35:51 | 000,116,224 | —- | C] () – C:\Windows\System32\pdfcmnnt.dll
[2009/10/12 21:07:56 | 000,000,518 | —- | C] () – C:\Users\Daniel\AppData\Roaming\wklnhst.dat
[2009/09/26 02:45:52 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2009/09/26 01:50:50 | 000,029,696 | —- | C] () – C:\Program Files\Veoh3260B5D63432474ABED033A073A35E39.videos
[2009/09/22 23:59:15 | 000,000,097 | —- | C] () – C:\Windows\System32\PICSDK.ini
[2009/09/22 23:56:15 | 000,000,044 | —- | C] () – C:\Windows\EPSNX300.ini
[2009/09/13 08:28:49 | 000,002,238 | —- | C] () – C:\Users\Daniel\AppData\Roaming\Jackpot City Flash Casino.ico
[2009/09/11 07:36:06 | 000,073,728 | —- | C] () – C:\Windows\System32\VistaInfo32.dll
[2009/08/30 04:08:51 | 000,056,832 | —- | C] () – C:\Windows\System32\Iyvu9_32.dll
[2009/08/24 18:48:37 | 000,001,304 | —- | C] () – C:\ProgramData\hpzinstall.log
[2009/08/20 12:04:22 | 000,057,710 | —- | C] () – C:\Program Files\VeohVideoCompass-1.5.1.1034.xpi
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 00:21:54 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2009/08/03 00:21:54 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2009/08/03 00:21:52 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll
[2009/06/01 16:32:53 | 000,031,966 | —- | C] () – C:\ProgramData\nvModes.001
[2009/06/01 16:31:17 | 000,031,966 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/05/31 16:20:49 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/05/30 13:36:45 | 000,091,648 | —- | C] () – C:\Users\Daniel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/05/29 14:33:37 | 000,000,000 | —- | C] () – C:\Users\Daniel\AppData\Local\QSwitch.txt
[2009/05/29 14:33:37 | 000,000,000 | —- | C] () – C:\Users\Daniel\AppData\Local\DSwitch.txt
[2009/05/29 14:33:37 | 000,000,000 | —- | C] () – C:\Users\Daniel\AppData\Local\AtStart.txt
[2009/05/16 05:07:20 | 000,000,105 | —- | C] () – C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
[2009/05/16 05:07:10 | 000,000,032 | —- | C] () – C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
[2009/05/16 05:06:44 | 000,000,032 | —- | C] () – C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
[2009/05/16 05:06:08 | 000,000,032 | —- | C] () – C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
[2009/05/16 05:04:09 | 000,000,032 | —- | C] () – C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
[2009/05/16 05:03:33 | 000,000,246 | —- | C] () – C:\ProgramData\hpqp.ini
[2009/04/20 14:34:59 | 000,000,109 | —- | C] () – C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
[2009/04/20 14:28:56 | 000,000,110 | —- | C] () – C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
[2009/04/20 14:26:52 | 000,000,105 | —- | C] () – C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
[2009/04/20 14:25:26 | 000,000,107 | —- | C] () – C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/03/09 02:58:00 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2000/04/14 16:50:02 | 000,343,040 | —- | C] () – C:\Windows\System32\Lffpx7.dll
[1998/06/11 13:08:06 | 000,095,232 | —- | C] () – C:\Windows\System32\Lfkodak.dll
========== LOP Check ==========
[2009/09/11 08:02:46 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\50States
[2010/11/15 15:59:38 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\BitTorrent
[2010/01/31 00:54:45 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Blackdiamond
[2009/09/11 08:03:05 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\CasinoStates
[2009/10/06 07:17:39 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/06/05 02:40:34 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\com.prakaz.project.photogettr.FBAB9E68ED32BC183252F597C39DBF71CF315A79.1
[2010/02/16 04:05:59 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\EPSON
[2010/01/03 21:31:17 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\FileZilla
[2009/08/14 05:47:11 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\funkitron
[2010/12/22 19:39:09 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\gtk-2.0
[2010/10/03 11:31:08 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Hide IP NG
[2009/11/23 09:58:46 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\iLike
[2010/02/13 08:30:05 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Keynote Systems
[2010/10/03 11:31:08 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Keyword Strategy Studio Pro
[2009/09/23 00:46:24 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Leadertech
[2009/10/02 06:16:20 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\LimeWire
[2009/11/29 00:28:48 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\ManyCam
[2010/03/24 09:23:49 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Megaupload
[2009/06/01 18:13:31 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\monkey money
[2010/03/23 22:57:00 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Moyea
[2010/10/02 21:06:45 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\muvee Technologies
[2009/09/30 07:47:08 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\NCH Swift Sound
[2010/05/27 18:21:24 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Nvu
[2009/05/29 20:17:00 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\OpenOffice.org
[2009/06/01 18:09:30 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\PlayFirst
[2010/03/03 09:32:16 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Screaming Bee
[2009/12/24 23:24:05 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Smith Micro
[2010/10/03 11:31:17 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\SystemRequirementsLab
[2009/10/12 21:07:59 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Template
[2009/11/11 07:45:01 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2010/10/02 02:56:13 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Ulead Systems
[2009/11/29 00:16:51 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\WeatherBug
[2009/05/29 18:10:26 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\WildTangent
[2009/08/02 23:23:08 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\WildTangentv1002
[2010/05/28 01:05:55 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Windows Live Writer
[2009/11/23 09:47:42 | 000,000,000 | —D | M] – C:\Users\Daniel\AppData\Roaming\Xilisoft
[2010/12/30 05:03:24 | 000,032,556 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/12/31 05:05:00 | 000,000,424 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{2C65306E-A463-4FA4-818A-3E01482134B4}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 14:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/10 23:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2010/07/18 20:28:39 | 003,396,176 | —- | M] (Piriform Ltd) – C:\ccsetup233.exe
[2006/09/18 14:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/12/31 04:08:15 | 2951,106,560 | -HS- | M] () – C:\hiberfil.sys
[2009/08/30 04:08:08 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/12/02 17:21:27 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2009/08/30 04:08:08 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2009/11/14 19:00:43 | 000,036,864 | —- | M] (Homestead Technologies, Inc.) – C:\nphssb.dll
[2009/11/14 19:00:43 | 000,000,247 | —- | M] () – C:\nphssb.xpt
[2010/12/31 04:08:11 | 3264,942,080 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/11/02 05:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 05:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 05:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/05/31 16:26:45 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 14:37:34 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/12/16 18:17:56 | 000,315,392 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\hpfpp6en.dll
[2008/01/20 19:23:14 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/09/23 00:32:56 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[1998/05/11 20:01:00 | 000,026,768 | —- | M] (Microsoft Corporation) – C:\Program Files\CTL3D.DLL
[2008/01/20 19:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
[1995/12/04 11:47:10 | 000,014,176 | —- | M] (Willow Pond Corporation) – C:\Program Files\DOC.EXE
[2009/10/14 08:43:27 | 000,000,591 | —- | M] () – C:\Program Files\prog.ini
[1999/07/19 08:48:32 | 000,001,660 | —- | M] () – C:\Program Files\README.TXT
[1999/07/19 08:27:28 | 000,097,259 | —- | M] () – C:\Program Files\Talker.exe
[1993/05/12 00:00:00 | 000,398,416 | —- | M] (Microsoft Corporation) – C:\Program Files\VBRUN300.DLL
[2009/09/26 01:51:23 | 000,029,696 | —- | M] () – C:\Program Files\Veoh3260B5D63432474ABED033A073A35E39.videos
[2009/08/20 12:04:22 | 000,057,710 | —- | M] () – C:\Program Files\VeohVideoCompass-1.5.1.1034.xpi
[1996/01/25 14:12:34 | 000,060,992 | —- | M] (Willow Pond Corporation) – C:\Program Files\WPCTRL.DLL
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/01/20 20:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 20:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 20:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 03:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 03:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/05/31 16:03:04 | 000,000,286 | -HS- | M] () – C:\Users\Daniel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2010/12/31 05:01:24 | 000,602,624 | —- | M] (OldTimer Tools) – C:\Users\Daniel\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-12 02:59:03
========== Alternate Data Streams ==========
@Alternate Data Stream - 81 bytes -> C:\Program Files\Intertops Poker:MID
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:05BF1B63
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:33DB8278
@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:E91ADC66
@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:A8ADE5D8
@Alternate Data Stream - 113 bytes -> C:\ProgramData\Temp:A688EF17
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:A692C296
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:43860CE8
@Alternate Data Stream - 107 bytes -> C:\ProgramData\Temp:A3E34FEB
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:FC2E567F
@Alternate Data Stream - 102 bytes -> C:\ProgramData\Temp:4D2028FC
@Alternate Data Stream - 100 bytes -> C:\ProgramData\Temp:A1D3FEF0
< End of report >
OTL Extras logfile created on: 12/31/2010 5:03:56 AM - Run 1
OTL by OldTimer - Version 3.2.18.2 Folder = C:\Users\Daniel\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18975)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287.17 Gb Total Space | 134.51 Gb Free Space | 46.84% Space Free | Partition Type: NTFS
Drive D: | 10.92 Gb Total Space | 1.81 Gb Free Space | 16.57% Space Free | Partition Type: NTFS
Drive E: | 2.50 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: DANIELS-LAPTOP | User Name: Daniel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.chm [@ = chm.file] – Reg Error: Key error. File not found
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-2302350703-3623477863-1373200073-1000]
"EnableNotifications" = 1
"EnableNotificationsRef" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0183F9D0-A230-45A9-8032-B46876F1736C}" = lport=49163 | protocol=6 | dir=in | name=akamai netsession interface |
"{02DFA78D-9D71-4690-982F-8EDFD1B35F62}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{037C2478-F6FB-4CF7-8962-1FAA0C22EE72}" = rport=445 | protocol=6 | dir=out | app=system |
"{268EE24F-0A1E-4468-B72A-736404A3B204}" = lport=49184 | protocol=6 | dir=in | name=akamai netsession interface |
"{35729933-CD40-4090-A0FF-A8563F9ED239}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{35CBC390-EAED-44EC-B864-94A133CEA80C}" = rport=139 | protocol=6 | dir=out | app=system |
"{3C67C091-D15A-457D-9FAA-3E18E6EF69C0}" = rport=138 | protocol=17 | dir=out | app=system |
"{4B33E63F-6FCC-445D-B6AB-E64086011344}" = lport=8081 | protocol=6 | dir=in | name=proxy |
"{65ED8BD0-8F43-436C-A049-8EB4AFEC5751}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{68B99A25-C128-4870-B196-96546B60F3F0}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6A1CC862-AA4C-47A2-8690-0F76B756E9DB}" = lport=137 | protocol=17 | dir=in | app=system |
"{7699BF94-F936-4147-8ACC-23BCE91EB5D2}" = lport=138 | protocol=17 | dir=in | app=system |
"{7B643425-B8DA-4102-B668-95ADBEAC9970}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{7BAB008B-1E9A-4AA7-9007-35CDD5AB6117}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{854F399B-FFE0-48FE-8EC9-02750EEB9344}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{86DCA94B-3992-4087-9C17-6E4C9BBC4228}" = lport=49159 | protocol=6 | dir=in | name=akamai netsession interface |
"{8C504B58-AD88-43FF-844B-33CB473BD72E}" = lport=445 | protocol=6 | dir=in | app=system |
"{93B8C938-9503-4867-9C55-E77503FEC951}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{94CEBCC7-58F1-4674-8497-E2472AC7C1F2}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A0B8F954-8168-4662-9D6D-2547754DF7A6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B14B88B0-0317-42ED-A20D-3D104D39A8A0}" = lport=49471 | protocol=6 | dir=in | name=akamai netsession interface |
"{B37E627D-8CF6-4831-8C91-2531F6BED43E}" = lport=139 | protocol=6 | dir=in | app=system |
"{C057A5D4-4C70-4DFB-A5F2-BA2D861ED4CE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CDF7C7C8-BC66-4A3B-A8E3-00E13D05A65F}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{DDF3092A-BF2C-4F39-95D8-51AA2059DAC2}" = rport=137 | protocol=17 | dir=out | app=system |
"{F2054FBC-8AD2-447E-AA52-B78261D2E1A3}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{FADEC0A0-7F94-4D20-814C-2BE193C20FF3}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04207B04-77D8-42DF-9C5C-9F2E1BA51B15}" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{0DC8714D-7449-4F2E-89FE-6C87C6BEED6A}" = protocol=17 | dir=in | app=c:\program files\easy-hide-ip\easyhideip.exe |
"{0EDEBF13-B54E-484B-8DA2-02D9147A0971}" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"{1254062C-3FEA-4B24-AB20-B58919106353}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{1754A5EE-1C76-45ED-B73C-BFD627848A2F}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{2DC3385A-9405-4C38-AB27-F51A83DCD6EA}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |
"{34FAD3B9-9A62-4BD1-9544-64A74E339C20}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3669D566-067B-4D76-A877-6E37C5A16B69}" = protocol=17 | dir=in | app=c:\program files\pinnacle\videospin\programs\rm.exe |
"{3B9A531E-B15E-4360-9DD7-5DB4E36752DA}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{4844259A-1650-49C3-817D-36F54E4AC6E3}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{494A25FE-D933-4741-952F-55B32E419E4D}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{4BA405C1-A5B2-4CC2-A6E5-9A1650A5AC06}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{51C18E13-0881-4B19-99F6-059E2BD68267}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{5BAA344A-8428-452C-A152-58A3B589D4B8}" = protocol=6 | dir=in | app=c:\program files\pinnacle\videospin\programs\umi.exe |
"{6DC80416-ABD5-4176-8A6A-DC941E8B650A}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{8009AA8B-B7F6-49AE-AD51-0D556BD1DC7A}" = protocol=6 | dir=in | app=c:\program files\easy-hide-ip\easyhideip.exe |
"{82F1FA22-DB70-4EB0-B1E3-C16EA0D32FEA}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{8A04A4C5-2A65-4C56-B5C5-1E4C2B0547FE}" = protocol=17 | dir=in | app=c:\program files\pinnacle\videospin\programs\umi.exe |
"{95507AAD-F39A-4295-A233-8A8FF3773CA5}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{96C3EEAB-23DA-4F96-991C-F07B4B12DA39}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{B957667B-F962-4681-AED6-9A45E5EA23CE}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{BEFE73FD-6447-48EF-A027-E7AFF76160F0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C6BE8966-86D2-409E-9967-ED33DA19E09C}" = protocol=6 | dir=in | app=c:\program files\pinnacle\videospin\programs\rm.exe |
"{CAB3C9EA-C2E1-4F15-AA27-CB930DE79346}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{CC6CB051-68DE-46AC-9430-8BDFC020E6B6}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{D3066696-DAE4-4D29-9668-4E0867FA1B53}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{EB614195-430B-4466-9259-0DFAEEABB7D1}" = protocol=6 | dir=in | app=c:\program files\pinnacle\videospin\programs\videospin.exe |
"{ECB2E3FA-5B9C-47E1-9E12-492A79621192}" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"{FA11C6DF-FB36-4C9B-B90D-74E0BEB4A9A2}" = protocol=17 | dir=in | app=c:\program files\pinnacle\videospin\programs\videospin.exe |
"{FA24B9AD-997F-45DF-90D8-6B40A15BD463}" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{150F653B-5E48-4C90-9249-7EA0EC662A75}C:\program files\veoh networks\veohwebplayer\veohwebplayer.exe" = protocol=6 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"TCP Query User{3396A736-9561-44F6-B567-9CEA3D90E266}C:\windows\system32\spool\drivers\w32x86\3\e_dupa30.exe" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\e_dupa30.exe |
"TCP Query User{44F4EDA4-DEE9-4E07-A10E-A5E08564E156}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{4593A125-279D-44CB-8DDC-1ACD49A5EC72}C:\program files\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files\videolan\vlc\vlc.exe |
"TCP Query User{54D1DC77-2116-45F5-B004-3E17EC7DBF1A}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"TCP Query User{861946D9-89C5-4C5C-A448-8BEEFAFD8185}C:\microgaming\casino\grandmondial\casinogame.exe" = protocol=6 | dir=in | app=c:\microgaming\casino\grandmondial\casinogame.exe |
"TCP Query User{90F3B7A8-BA9A-4267-BE2C-79ABA1DC35EB}C:\program files\ip hider\ip hider.exe" = protocol=6 | dir=in | app=c:\program files\ip hider\ip hider.exe |
"TCP Query User{99910B38-8D63-4129-AB8A-FBB136E767FA}C:\program files\easy-hide-ip\easy-hide-ip.exe" = protocol=6 | dir=in | app=c:\program files\easy-hide-ip\easy-hide-ip.exe |
"TCP Query User{9A61417F-6AD3-412A-93DB-E244CDE452FF}C:\program files\bittorrent\bittorrent.exe" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"TCP Query User{A4B83540-A00C-4FD4-8DF7-A32E04BED141}C:\users\daniel\appdata\local\temp\stu3cc2.tmp\viewerpc.exe" = protocol=6 | dir=in | app=c:\users\daniel\appdata\local\temp\stu3cc2.tmp\viewerpc.exe |
"TCP Query User{C5C215EF-5D14-4C46-9135-F7B84E95D176}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{DEC20702-08D2-40F9-AB89-6AAB137932E3}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{0772EF7B-5732-4345-B79C-A7E3A2D98422}C:\program files\bittorrent\bittorrent.exe" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"UDP Query User{18865007-0AA2-49A2-9A7D-8745D22DED42}C:\microgaming\casino\grandmondial\casinogame.exe" = protocol=17 | dir=in | app=c:\microgaming\casino\grandmondial\casinogame.exe |
"UDP Query User{224806CC-9DE7-423A-8AF1-3DCAE2C87083}C:\program files\ip hider\ip hider.exe" = protocol=17 | dir=in | app=c:\program files\ip hider\ip hider.exe |
"UDP Query User{2408BC81-5D1E-49F8-B4AA-35A903F37DEE}C:\program files\easy-hide-ip\easy-hide-ip.exe" = protocol=17 | dir=in | app=c:\program files\easy-hide-ip\easy-hide-ip.exe |
"UDP Query User{2AE7E71B-5B22-453D-86C9-1CAB85378C04}C:\users\daniel\appdata\local\temp\stu3cc2.tmp\viewerpc.exe" = protocol=17 | dir=in | app=c:\users\daniel\appdata\local\temp\stu3cc2.tmp\viewerpc.exe |
"UDP Query User{3DBB8732-6F89-4506-90A0-40F17D4D210D}C:\program files\veoh networks\veohwebplayer\veohwebplayer.exe" = protocol=17 | dir=in | app=c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe |
"UDP Query User{4317BF2D-93D6-4BF0-8A1B-9681C65A26DE}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{58C802FF-97F2-486B-B2C6-C316A575C217}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{AB378B09-6C6C-49C7-8B9E-62E0E05D1B86}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{B2C3708E-515C-49CA-B790-54F748F27E77}C:\program files\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files\videolan\vlc\vlc.exe |
"UDP Query User{CF82C431-9F9C-43CD-9FFE-9C95F85EE011}C:\windows\system32\spool\drivers\w32x86\3\e_dupa30.exe" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\e_dupa30.exe |
"UDP Query User{E75398E6-482B-49A7-AB1C-B5363167E6F4}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{003D3756-10DE-4CAA-9A59-705E041000BA}" = video-processor
"{0054A0F6-00C9-4498-B821-B5C9578F433E}" = HP Help and Support
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}" = LightScribe System Software 1.14.17.1
"{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{14291118-0C19-45EA-A4FA-5C1C0F5FDE09}" = Primo
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}" = HP Total Care Advisor
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{203E564A-51E6-44E5-9DF9-8D0AD66E401D}" = DJ_SF_05_D2600_Software_Min
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216014FF}" = Java™ 6 Update 18
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{27F00C63-449B-2FAB-CBE8-24AB80E17449}" = Acrobat.com
"{2AD738DC-FC24-4342-A2DA-BB6DCCF6B048}" = Jing
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{32A3A4F4-B792-11D6-A78A-00B0D0160140}" = Java™ SE Development Kit 6 Update 14
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 H2
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{38058455-8C21-4C2F-B2F6-14ED166039CB}" = HP Total Care Setup
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Vista
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{39E705C7-669D-42EC-90F0-38F376D24774}" = Windows Live Writer Blog This for Mozilla Firefox
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3C79DC59-6099-323B-B27B-90B45542B270}" = Google Talk Plugin
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{415B2719-AD3A-4944-B404-C472DB6085B3}" = Cisco EAP-FAST Module
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP DVD Play 3.7
"{46473794-57D2-4512-9AAC-EB7E7F5D1E52}" = Gmail Account Creator
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{57A5AEC1-97FC-474D-92C4-908FCC2253D4}" = HP Customer Experience Enhancements
"{593A99E0-AB4E-49E0-AE23-3499E1C43FBA}" = Quivic 6
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{665CBCA4-5AB0-414B-A288-3F8F99FEFC45}" = HP User Guides 0118
"{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6c651250-2eb2-11d5-8e33-0050dad72ac2}" = NetZero Internet
"{6CE460E5-54F5-46EB-83DB-B514215D66B7}" = Hide The IP 2009
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{775290AD-C54E-418C-9564-A10836F42C1C}" = D2600
"{7B15D70E-9449-4CFB-B9BC-798465B2BD5C}" = Norton Internet Security
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{80D3CFFD-4CB5-47A1-8779-11A720A9ADB2}" = HP Deskjet D2600 Printer Driver Software 13.0 Rel .5
"{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{878A2B1F-0BDA-4739-B8D7-490315B9BE93}_is1" = X2X Free Video Trim 1.0
"{88D68A69-D247-466B-90DD-575F6BE16230}_is1" = CardRecovery 5.20
"{893931C2-0CD4-45DD-AFE3-3B7772FE65E1}" = Word count plugin for Live Writer
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{926C96FB-9D0A-4504-8000-C6D3A4A3118E}" = Java DB 10.4.2.1
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9ADABDDE-9644-461B-9E73-83FA3EFCAB50}" = HP Wireless Assistant
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9DF0BE48-16F0-4E36-814D-9B4FDFFAF25F}" = PayPal Plug-In
"{9F3C8BE0-A54A-2D46-36FB-0029D412B0AC}" = TweetDeck
"{A19B094A-42EB-4D3F-A57E-0CDE052A1D80}" = IS-DV
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3BC5D37-30F9-4CF7-BD5C-0DFF063E4B6D}" = 2Wire Wireless Client
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA047707-196A-77B3-E971-2885E0CB157A}" = Bulkr
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}" = Adobe Shockwave Player
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{AFAC914D-9E83-4A89-8ABE-427521C82CCF}" = Safari
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BC4664AC-AA57-4DD2-93BE-54CDF57D63CE}" = Cricket Wireless PC Media Center 1.1
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B8}" = WinZip 12.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7E3BE0-2DD3-4416-A690-F9E4A99A8CFF}" = HP Active Support Library
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{DABF43D9-1104-4764-927B-5BED1274A3B0}" = Runtime
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{DD35C328-F115-BEDA-6EEE-E00C5AACCCBC}" = muvee Reveal
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DEDB47A3-C988-4A43-A645-E2CEA571E680}" = Epson Easy Photo Print 2
"{E031338C-839D-4EDD-9537-99B653C39D81}" = Autodesk MapGuide® Viewer ActiveX Control Release 6.5
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{E9ED0801-253D-4FE9-AB20-F63DEFE72547}" = SAMSUNG Mobile USB DRIVER(4.40.7.0) v1.6
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE4270D7-A642-49C1-9A40-854DA3F13FB2}_is1" = Moyea FLV Player version: 2.0.2.96
"{fe986ae8-5283-4177-9178-52ba8d21bb10}" = Jackpot Capital
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"123VideoMagic" = 123VideoMagic
"2Wire SetupWiz" = AT&T; Yahoo! High Speed Internet Home Networking Installer
"4Bec Article Rewriter_is1" = 4Bec Article Rewriter v2.0
"4Bec Equi_is1" = 4Bec Equi v2.0
"4Bec Forum_is1" = 4Bec Forum v2.0
"7-Zip" = 7-Zip 4.65
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Akamai" = Akamai NetSession Interface
"AnalogX AutoTune" = AnalogX AutoTune
"Article Buzz_is1" = Article Buzz v2.0
"Audacity_is1" = Audacity 1.2.6
"avast5" = avast! Free Antivirus
"B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind
"Bejeweled 2 Deluxe 1.1.3.2523" = Bejeweled 2 Deluxe 1.1.3.2523
"BFGC" = Big Fish Games Client
"BFG-Call of Atlantis" = Call of Atlantis
"BFG-Megaplex Madness - Now Playing" = Megaplex Madness: Now Playing ™
"BFG-Midnight Mysteries - The Edgar Allan Poe Conspiracy" = Midnight Mysteries: The Edgar Allan Poe Conspiracy
"BFG-Slingo Supreme" = Slingo Supreme
"BFG-Zuma Deluxe" = Zuma Deluxe
"Bookworm Adventures Vol. 2" = Bookworm Adventures Vol. 2
"Bookworm Deluxe 1.13" = Bookworm Deluxe 1.13
"Bruce's Unusual Typing Wizard_is1" = Bruce's Unusual Typing Wizard, Version 1.5.0
"CCleaner" = CCleaner
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"CocoaCasino" = Cocoa Casino
"CodInstl" = Intel A/V Codecs V2.0
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"com.prakaz.project.photogettr.FBAB9E68ED32BC183252F597C39DBF71CF315A79.1" = Bulkr
"DenderaCasino" = Dendera Casino
"Digital Laugh Track" = Digital Laugh Track
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX Setup
"Easy-Hide-IP_is1" = Easy-Hide-IP 3.5
"EPSON NX300 Series" = EPSON NX300 Series Printer Uninstall
"EPSON Scanner" = EPSON Scan
"EZ Keez by Gina Geez_is1" = EZ Keez by Gina Geez v2.01
"EZKeez by GinaGeez_is1" = EZKeez by GinaGeez v2.01
"Face Smoother_is1" = Face Smoother 2.54
"FaceDub" = FaceDub
"FileZilla Client" = FileZilla Client 3.3.1
"Flash Movie Player" = Flash Movie Player 1.5
"Grammar Slammer Deluxe with Spelling and Grammar Checkers" = Grammar Slammer Deluxe with Spelling and Grammar Checkers
"grandmonaco" = Grand Mondial Casino
"Hixus Keyword Inventor_is1" = Hixus Keyword Inventor 1.1
"HotspotShield" = Hotspot Shield 1.44
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"InstallShield_{E9ED0801-253D-4FE9-AB20-F63DEFE72547}" = SAMSUNG Mobile USB DRIVER(4.40.7.0) v1.6
"Intertops Poker" = Intertops Poker
"Intuit SiteBuilder" = Intuit SiteBuilder
"iWisoft Flash SWF to Video Converter_is1" = iWisoft Flash SWF to Video Converter 3.4
"jackpotcity" = Jackpot City Online Casino
"Keyword Buzz_is1" = Keyword Buzz v2.01
"Keyword Strategy Studio Pro_is1" = Keyword Strategy Studio Pro v2010.030210
"Keyword Swarm_is1" = Keyword Swarm
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"Magic Photo Editor_is1" = Magic Photo Editor 5.8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MSCSR" = Microsoft Speech Recognition Engine 4.0 (English)
"MVP Backgammon Professional_is1" = MVP Backgammon Professional 2.0.1 Trial
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"redflush" = Red Flush
"Replay Media Catcher 3.01" = Replay Media Catcher 3.01
"SlotOCash" = Sloto Cash
"Streamster" = Marketiva
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"SystemRequirementsLab" = System Requirements Lab
"tournamentgames_3.exe" = Tournament Games (remove only)
"TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1" = TweetDeck
"VegasRegalCasino" = Vegas Regal Casino
"Veoh Web Player Beta" = Veoh Web Player
"VirtuaGirl" = VirtuaGirl
"VLC media player" = VideoLAN VLC media player 0.8.6i
"WildTangent hp Master Uninstall" = HP Games
"Winamp" = Winamp
"WinGimp-2.0_is1" = GIMP 2.4.0
"WinLiveSuite" = Windows Live Essentials
"WT076365" = Family Mystery - The Story of Amy
"Xilisoft Download YouTube Video" = Xilisoft Download YouTube Video
"Xilisoft YouTube Video Converter" = Xilisoft YouTube Video Converter
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update
"Zuma Deluxe 1.0" = Zuma Deluxe 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent
"Winamp Detect" = Winamp Detector Plug-in
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >
Hijack this scan:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:19:19 AM, on 12/31/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18975)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Safari\Safari.exe
C:\Users\Daniel\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.netzero.net/search?action=mi…urce=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.netzero.net/search?action=mi…urce=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.netzero.net/search?action=mi…urce=minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-up Blocker - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O2 - BHO: NetZero Toolbar Helper - {FE3098B0-04A3-41fd-8CA9-BEA39CB14C87} - C:\Program Files\NetZero\ucreg.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\Windows\system32\PRISMSVR.EXE" /APPLY
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: VirtuaGirl.lnk = C:\Program Files\Vg\Vg.exe
O8 - Extra context menu item: Download with Xilisoft Download YouTube Video - C:\Program Files\Xilisoft\Download YouTube Video\upod_link.HTM
O8 - Extra context menu item: Download with Xilisoft YouTube Video Converter - C:\Program Files\Xilisoft\YouTube Video Converter\upod_link.HTM
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O8 - Extra context menu item: Send Image to Photo Library - file://C:\ProgramData\MGI\PhotoSuite4\Temp\MGI00000.html
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Grand Mondial Casino - 1D9BD393-E01E-4C70-B602-0CACF6C5FAA9 - C:\Microgaming\Casino\GrandMondial\Casinogame.exe (HKCU)
O9 - Extra button: Jackpot City Online Casino - CE0C94F3-E30E-45BD-B900-D519E0DD6956 - C:\Microgaming\Casino\JackpotCity\Casinogame.exe (HKCU)
O9 - Extra button: Red Flush - {1864FB6F-969B-4DB1-AA99-13B5F05C6833} - C:\Casino\RedFlush\casinogame.exe (HKCU)
O15 - Trusted Zone: *.netzero.com
O15 - Trusted Zone: *.netzero.net
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} (PCMaticVer Class) - http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: EPSON V5 Service4(01) (EPSON_EB_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
–
End of file - 10365 bytes
DDS scan:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 5:25:13.94 on Fri 12/31/2010
Internet Explorer: 8.0.6001.18975 BrowserJavaVersion: 1.6.0_18
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2814.1533 [GMT -7:00]
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k Akamai
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXE
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\SMINST\BLService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\System32\svchost.exe -k NetSvcs
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\iashost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Safari\Safari.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Daniel\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=en_us&c;=91&bd;=Pavilion&pf;=cnnb
uSearch Bar = hxxp://search.netzero.net/search?action=minisearch&source;=minisearch
uSearch Page = hxxp://search.netzero.net/search?action=minisearch&source;=minisearch
mDefault_Page_URL = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://search.netzero.net/search?action=minisearch&source;=minisearch
uURLSearchHooks: H - No File
BHO: &Yahoo;! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Pop-up Blocker: {52706ef7-d7a2-49ad-a615-e903858cf284} - c:\program files\netzero\qsacc\X1IEBHO.dll
BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
BHO: NetZero Toolbar Helper: {fe3098b0-04a3-41fd-8ca9-bea39cb14c87} - c:\program files\netzero\ucreg.dll
TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll
TB: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
TB: ZeroBar: {f0f8ecbe-d460-4b34-b007-56a92e8f84a7} - c:\program files\netzero\Toolbar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [PRISMSVR.EXE] "c:\windows\system32\PRISMSVR.EXE" /APPLY
StartupFolder: c:\users\daniel\appdata\roaming\micros~1\windows\startm~1\programs\startup\virtua~1.lnk - c:\program files\vg\Vg.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Download with Xilisoft Download YouTube Video - c:\program files\xilisoft\download youtube video\upod_link.HTM
IE: Download with Xilisoft YouTube Video Converter - c:\program files\xilisoft\youtube video converter\upod_link.HTM
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: Send Image to Photo Library - file://c:\programdata\mgi\photosuite4\temp\MGI00000.html
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: netzero.com
Trusted Zone: netzero.net
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\daniel\appdata\roaming\mozilla\firefox\profiles\jbe8185r.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&q;=
FF - prefs.js: network.proxy.type - 0
FF - component: c:\users\daniel\appdata\roaming\mozilla\firefox\profiles\jbe8185r.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nphssb.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\daniel\appdata\local\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\users\daniel\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\users\daniel\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
FF - user.js: network.proxy.type - 0
FF - user.js: network.proxy.http -
user_pref(network.proxy.http_port,);
FF - user.js: network.proxy.no_proxies_on -
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4f16a", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4fra", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2009-5-29 164048]
R1 SASDIFSV;SASDIFSV;c:\users\daniel\appdata\local\temp\sas_selfextract\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\users\daniel\appdata\local\temp\sas_selfextract\saskutil.sys [2010-5-10 67656]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2008-1-20 21504]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-5-29 19024]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-5-29 51792]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\sminst\BLService.exe [2009-4-20 365952]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-10-24 1153368]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2010-9-21 1710464]
R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-4-20 193840]
R3 HssDrv;Hotspot Shield Helper Miniport;c:\windows\system32\drivers\hssdrv.sys [2010-5-13 37376]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-5-9 43040]
R3 NVNET;NVIDIA nForce Ethernet Driver;c:\windows\system32\drivers\nvmfdx32.sys [2010-8-12 292712]
R3 taphss;Anchorfree HSS Adapter;c:\windows\system32\drivers\taphss.sys [2009-9-15 32768]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 Norton Internet Security;Norton Internet Security;"c:\program files\norton internet security\engine\16.0.0.125\ccsvchst.exe" /s "norton internet security" /m "c:\program files\norton internet security\engine\16.0.0.125\dimaster.dll" /prefetch:1 –> c:\program files\norton internet security\engine\16.0.0.125\ccSvcHst.exe [?]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2008-8-21 18688]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2008-8-21 8320]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [2007-6-18 23680]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-8-31 136176]
S4 HssSrv;Hotspot Shield Routing Service;c:\program files\hotspot shield\hsswpr\hsssrv.exe [2010-5-13 348208]
S4 HssTrayService;Hotspot Shield Tray Service;c:\program files\hotspot shield\bin\HssTrayService.exe [2010-5-13 57640]
S4 HssWd;Hotspot Shield Monitoring Service;c:\program files\hotspot shield\bin\hsswd.exe -product hss –> c:\program files\hotspot shield\bin\hsswd.exe -product HSS [?]
S4 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
=============== Created Last 30 ================
2010-12-21 11:19 20,358 a——- c:\windows\vgirl.prf
2010-12-21 11:19 –d—– c:\program files\Vg
2010-12-21 04:06 –d—– c:\program files\2Wire
2010-12-21 03:44 393,216 a——- c:\windows\system32\athihvs.dll
2010-12-21 03:44 376,832 a——- c:\windows\system32\S64CPA.exe
2010-12-21 03:44 53,248 a——- c:\windows\system32\athihvui.dll
2010-12-21 03:44 –d—– c:\windows\system32\nn-NO
2010-12-21 03:43 –d—– c:\program files\Cisco
2010-12-11 19:58 758,784 a——- c:\windows\system32\cohelper.dll
2010-12-11 19:40 –d—– c:\windows\en
2010-12-11 19:37 69,464 a——- c:\windows\system32\XAPOFX1_3.dll
2010-12-11 19:37 515,416 a——- c:\windows\system32\XAudio2_5.dll
2010-12-11 19:37 453,456 a——- c:\windows\system32\d3dx10_42.dll
2010-12-11 19:09 754,688 a——- c:\windows\system32\webservices.dll
2010-12-10 01:50 107,653,792 a——- c:\windows\MEMORY.DMP
2010-12-09 01:13 –d—– c:\users\daniel\appdata\roaming\SUPERAntiSpyware.com
2010-12-09 01:13 –d—– c:\programdata\SUPERAntiSpyware.com
2010-12-09 01:13 –d—– c:\progra~2\SUPERAntiSpyware.com
==================== Find3M ====================
2010-12-31 04:10 31,966 a——- c:\programdata\nvModes.dat
2010-12-31 04:10 31,966 a——- c:\progra~2\nvModes.dat
2010-12-21 03:53 143,360 a——- c:\windows\inf\infstrng.dat
2010-12-21 03:53 51,200 a——- c:\windows\inf\infpub.dat
2010-12-21 03:44 86,016 a——- c:\windows\inf\infstor.dat
2010-12-20 18:09 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 18:08 20,952 a——- c:\windows\system32\drivers\mbam.sys
2010-11-09 10:44 1,798,146 a——- c:\users\daniel\smoother.exe
2010-11-04 03:10 323,584 a——- c:\windows\system32\AUDIOGENIE2.DLL
2010-10-19 10:41 222,080 ——– c:\windows\system32\MpSigStub.exe
2010-10-10 09:34 32,000 a——- c:\users\daniel\usbaapl.sys
2010-07-22 19:45 11,285,608 a——- c:\users\daniel\winamp5581_full_emusic-7plus_en-us.exe
2010-06-21 12:50 418,304 a——- c:\users\daniel\msgr10us.exe
2010-03-22 20:11 518 a——- c:\users\daniel\appdata\roaming\wklnhst.dat
2009-11-02 10:11 665,600 a——- c:\windows\inf\drvindex.dat
2009-10-29 08:32 167 a——- c:\users\daniel\udownload.dat
2009-10-14 08:43 591 a——- c:\program files\prog.ini
2009-09-26 01:51 29,696 a——- c:\program files\Veoh3260B5D63432474ABED033A073A35E39.videos
2009-08-20 12:04 57,710 a——- c:\program files\VeohVideoCompass-1.5.1.1034.xpi
2008-01-20 19:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
1999-07-19 08:48 1,660 a——- c:\program files\README.TXT
1999-07-19 08:27 97,259 a——- c:\program files\Talker.exe
1998-05-11 20:01 26,768 a——- c:\program files\CTL3D.DLL
1996-01-25 14:12 60,992 a——- c:\program files\WPCTRL.DLL
1995-12-04 11:47 14,176 a——- c:\program files\DOC.EXE
1993-05-12 00:00 398,416 a——- c:\program files\VBRUN300.DLL
2010-06-24 05:46 220 —sh— c:\windows\dwin.sys
2010-08-15 13:52 262,144 a–sh— c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2010-09-09 01:16 16,384 a–sh— c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2010-09-09 01:16 32,768 a–sh— c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2010-09-09 01:16 16,384 a–sh— c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat
2010-08-15 14:09 262,144 a–sh— c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
============= FINISH: 5:25:53.14 ===============