This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

I cant open any applications.

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When i open or click an application for example Google chrome, there is a window coming out.

Which States: Open With
Choose the program you want to open with…………..

Which is totally irritating!
I know that there has been a virus because there are so many stuffs happening in my computer that there was a virus found, and i think it was 29 or something and i dont know what to do.

After a few days, the virus is still there and The "OPEN WITH" stuff started. Please Help me.

I downloaded Otl, and this is the result.

otl. txt :

TL logfile created on: 6/20/2011 3:04:44 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Home\Downloads
An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000464 | Country: Pilipinas | Language: FPO | Date Format: M/d/yyyy

1.75 Gb Total Physical Memory | 1.13 Gb Available Physical Memory | 64.57% Memory free
3.50 Gb Paging File | 2.53 Gb Available in Paging File | 72.29% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 99.26 Gb Total Space | 57.39 Gb Free Space | 57.81% Space Free | Partition Type: NTFS
Drive D: | 99.36 Gb Total Space | 99.27 Gb Free Space | 99.91% Space Free | Partition Type: NTFS
Drive E: | 99.36 Gb Total Space | 99.26 Gb Free Space | 99.89% Space Free | Partition Type: NTFS

Computer Name: HOME-PC | User Name: Home | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Home\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Google\Update\Install\{A06E9B84-4CA9-4932-B780-01A07ED5D178}\GoogleEarth-Win-Bundle-6.0.3.2197.exe ()
PRC - C:\Program Files\MyWebSearch\bar\6.bin\MWSSVC.EXE (MyWebSearch.com)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
PRC - C:\Program Files\Globe Telecom\Click Fix\bin\sprtsvc.exe (SupportSoft, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\Home\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (MyWebSearchService) – C:\Program Files\MyWebSearch\bar\6.bin\MWSSVC.EXE (MyWebSearch.com)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (WinHttpAutoProxySvc) – winhttp.dll (Microsoft Corporation)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (sprtsvc_globe) SupportSoft Sprocket Service (globe) – C:\Program Files\Globe Telecom\Click Fix\bin\sprtsvc.exe (SupportSoft, Inc.)


========== Driver Services (SafeList) ==========

DRV - (avgntflt) – C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvm62x32.sys (NVIDIA Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (ssmdrv) – C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (avipbb) – C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files\BrotherSoft_Extreme\tbBrot.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfir.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.iminent.com/?appId=2A4066A6-…38-E950732B22EE
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ph.msn.com/iat/us_ph.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fil
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0C BD F4 23 77 07 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\6.bin\MWSSRCAS.DLL (MyWebSearch.com)
IE - HKCU\..\URLSearchHook: {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files\BrotherSoft_Extreme\tbBrot.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfir.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - C:\Program Files\Iminent\SearchTheWeb\Iminent.BHO.NavigationError.dll (Iminent)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "SearchTheWeb"
FF - prefs.js..browser.search.defaultthis.engineName: "ToggleEN Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2077543&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "ToggleEN Customized Web Search"
FF - prefs.js..browser.startup.homepage: "http://search.iminent.com/?appId=2a4066a6-ccee-4934-b638-e950732b22ee&ref;=homepage"
FF - prefs.js..keyword.URL: "http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZCfox000&ptb;=A26UMNpHkW.HdOieQnwp9A&ind;=2010071102&ptnrS;=ZCfox000&si;=&n;=77cf403e&psa;=&st;=kwd&searchfor;="

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MyWebSearch\bar\6.bin [2011/03/22 06:09:31 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/10 17:44:31 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/17 14:02:20 | 000,000,000 | —D | M]

[2010/06/09 10:03:32 | 000,000,000 | —D | M] (No name found) – C:\Users\Home\AppData\Roaming\mozilla\Extensions
[2010/06/09 10:03:32 | 000,000,000 | —D | M] (No name found) – C:\Users\Home\AppData\Roaming\mozilla\Extensions\[removed]
[2011/06/03 18:11:37 | 000,000,000 | —D | M] (No name found) – C:\Users\Home\AppData\Roaming\mozilla\Firefox\Profiles\no8de4kp.default\extensions
[2010/11/02 18:22:57 | 000,000,000 | —D | M] (ToggleEN Toolbar) – C:\Users\Home\AppData\Roaming\mozilla\Firefox\Profiles\no8de4kp.default\extensions\{038cb5c7-48ea-4af9-94e0-a1646542e62b}
[2010/12/22 21:38:32 | 000,000,000 | —D | M] (BrotherSoft Extreme Community Toolbar) – C:\Users\Home\AppData\Roaming\mozilla\Firefox\Profiles\no8de4kp.default\extensions\{51a86bb3-6602-4c85-92a5-130ee4864f13}
[2010/07/24 11:30:59 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Users\Home\AppData\Roaming\mozilla\Firefox\Profiles\no8de4kp.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2010/09/28 18:40:30 | 000,000,000 | —D | M] (TorrentMan Toolbar) – C:\Users\Home\AppData\Roaming\mozilla\Firefox\Profiles\no8de4kp.default\extensions\{7c5c0f58-e061-457d-9033-77307f5ed00c}
[2010/08/19 18:44:50 | 000,000,000 | —D | M] (IMinent Toolbar) – C:\Users\Home\AppData\Roaming\mozilla\Firefox\Profiles\no8de4kp.default\extensions\{C9B68337-E93A-44EA-94DC-CB300EC06444}
[2010/08/28 13:46:09 | 000,000,000 | —D | M] (Facicons) – C:\Users\Home\AppData\Roaming\mozilla\Firefox\Profiles\no8de4kp.default\extensions\{DDABDBA1-2377-4A30-A027-25697B99E254}
[2010/08/03 19:19:28 | 000,000,000 | —D | M] (RadioBar Toolbar) – C:\Users\Home\AppData\Roaming\mozilla\Firefox\Profiles\no8de4kp.default\extensions\radiobar@toolbar
[2011/06/03 18:16:09 | 000,000,921 | —- | M] () – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\no8de4kp.default\searchplugins\conduit.xml
[2011/05/28 12:59:07 | 000,000,000 | —- | M] () – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\no8de4kp.default\searchplugins\mywebsearch.xml
[2011/06/08 07:09:46 | 000,002,230 | —- | M] () – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\no8de4kp.default\searchplugins\SearchTheWeb.xml
[2011/04/26 19:19:20 | 000,001,589 | —- | M] () – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\no8de4kp.default\searchplugins\web-search.xml
[2011/03/26 19:57:14 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/09 09:41:56 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/06/09 10:01:20 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/11/14 09:21:59 | 000,000,000 | —D | M] (Iminent WebBooster) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/03/22 06:09:31 | 000,000,000 | —D | M] (My Web Search) – C:\PROGRAM FILES\MYWEBSEARCH\BAR\6.BIN
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/07/02 11:19:28 | 000,102,400 | —- | M] (Zylom) – C:\Program Files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
[2010/07/09 16:21:02 | 000,002,157 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\SearchTheWeb.xml

O1 HOSTS File: ([2009/06/11 05:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (MyWebSearch Search Assistant BHO) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\6.bin\MWSSRCAS.DLL (MyWebSearch.com)
O2 - BHO: (ToggleEN Toolbar) - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
O2 - BHO: (mwsBar BHO) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\6.bin\MWSBAR.DLL (MyWebSearch.com)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (BrotherSoft Extreme Toolbar) - {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files\BrotherSoft_Extreme\tbBrot.dll (Conduit Ltd.)
O2 - BHO: (TBSB01620 Class) - {58124A0B-DC32-4180-9BFF-E0E21AE34026} - C:\Program Files\IMinent Toolbar\tbcore3.dll ()
O2 - BHO: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfir.dll (Conduit Ltd.)
O2 - BHO: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O2 - BHO: (TorrentMan Toolbar) - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll (Conduit Ltd.)
O2 - BHO: (Iminent.BHO.NavigationError) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - C:\Program Files\Iminent\SearchTheWeb\Iminent.BHO.NavigationError.dll (Iminent)
O2 - BHO: (IMinent WebBooster (BHO)) - {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} - C:\Program Files\Iminent\IMBooster4Web\Iminent.WebBooster.dll (Iminent)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (LimeWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - File not found
O3 - HKLM\..\Toolbar: (ToggleEN Toolbar) - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\6.bin\MWSBAR.DLL (MyWebSearch.com)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (BrotherSoft Extreme Toolbar) - {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files\BrotherSoft_Extreme\tbBrot.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\tbXfir.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (TorrentMan Toolbar) - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (IMinent Toolbar) - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - C:\Program Files\IMinent Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (LimeWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (ToggleEN Toolbar) - {038CB5C7-48EA-4AF9-94E0-A1646542E62B} - C:\Program Files\ToggleEN\tbTogg.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (My Web Search) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\6.bin\MWSBAR.DLL (MyWebSearch.com)
O3 - HKCU\..\Toolbar\WebBrowser: (BrotherSoft Extreme Toolbar) - {51A86BB3-6602-4C85-92A5-130EE4864F13} - C:\Program Files\BrotherSoft_Extreme\tbBrot.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (XfireXO Toolbar) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - C:\Program Files\XfireXO\tbXfir.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Zynga Toolbar) - {7B13EC3E-999A-4B70-B9CB-2617B8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (TorrentMan Toolbar) - {7C5C0F58-E061-457D-9033-77307F5ED00C} - C:\Program Files\TorrentMan\tbTorr.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (IMinent Toolbar) - {977AE9CC-AF83-45E8-9E03-E2798216E2D5} - C:\Program Files\IMinent Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (LimeWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [globe] C:\Program Files\Globe Telecom\Click Fix\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [IMBooster] C:\Program Files\Iminent\IMBooster\imbooster.exe (Iminent)
O4 - HKLM..\Run: [Iminent.Notifier] C:\Program Files\Iminent\SearchTheWeb\Iminent.Notifier.exe (Iminent)
O4 - HKLM..\Run: [My Web Search Bar Search Scope Monitor] C:\Program Files\MyWebSearch\bar\6.bin\M3SRCHMN.EXE (MyWebSearch.com)
O4 - HKLM..\Run: [MyWebSearch Email Plugin] C:\Program Files\MyWebSearch\bar\6.bin\MWSOEMON.EXE (MyWebSearch.com)
O4 - HKLM..\Run: [USB Antivirus] C:\Program Files\USB Disk Security\USBGuard.exe (Zbshareware Lab)
O4 - HKCU..\Run: [06ae3454d92ff3a31aaa23136e885da5] File not found
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [MyWebSearch Email Plugin] C:\Program Files\MyWebSearch\bar\6.bin\MWSOEMON.EXE (MyWebSearch.com)
O4 - HKCU..\RunOnce: [Application Restart #0] C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - Startup: C:\Users\Home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MP3 Rocket (Minimized).lnk = C:\Program Files\MP3 Rocket\MP3Rocket.exe ()
O4 - Startup: C:\Users\Home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk = C:\Program Files\Xfire\Xfire.exe (Xfire Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll (Google Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 05:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "C:\Users\Home\AppData\Local\lxv.exe" -a "%1" %*
O35 - HKCU\..exefile [open] – "C:\Users\Home\AppData\Local\lxv.exe" -a "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "C:\Users\Home\AppData\Local\lxv.exe" -a "%1" %*
O37 - HKCU\…exe [@ = exefile] – "C:\Users\Home\AppData\Local\lxv.exe" -a "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: aux - wdmaud.drv (Microsoft Corporation)
Drivers32: midi - wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - midimap.dll (Microsoft Corporation)
Drivers32: mixer - wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation)
Drivers32: vidc.cvid - iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.iyuv - iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - msvidc32.dll (Microsoft Corporation)
Drivers32: vidc.uyvy - msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.XFR1 - xfcodec.dll ()
Drivers32: vidc.yuy2 - msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvu9 - tsbyuv.dll (Microsoft Corporation)
Drivers32: vidc.yvyu - msyuv.dll (Microsoft Corporation)
Drivers32: wave - wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - msacm32.drv (Microsoft Corporation)


========== Files/Folders - Created Within 30 Days ==========

File not found –
[2011/06/18 11:39:20 | 000,000,000 | —D | C] – C:\Users\Home\AppData\Local\Unity
[2011/06/16 07:01:42 | 000,606,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2011/06/16 07:01:42 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/06/16 07:01:42 | 000,381,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/06/16 07:01:42 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/06/16 07:01:42 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/06/16 07:01:41 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/06/16 07:01:41 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/06/16 07:01:41 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/06/16 07:01:41 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/06/16 07:01:41 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/06/16 07:01:41 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/06/06 12:16:25 | 000,000,000 | —D | C] – C:\output
[2011/03/21 14:54:12 | 003,002,471 | —- | C] (MyWebSearch.com) – C:\Users\Home\AppData\Local\mwsautSp.exe

========== Files - Modified Within 30 Days ==========

[2011/06/20 14:23:00 | 000,001,060 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/20 10:56:49 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/20 07:50:33 | 000,014,448 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/20 07:50:33 | 000,014,448 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/20 07:43:33 | 000,001,056 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/20 07:43:17 | 1408,098,304 | -HS- | M] () – C:\hiberfil.sys
[2011/06/18 22:13:13 | 000,023,152 | —- | M] () – C:\Users\Home\.recently-used.xbel
[2011/06/18 11:37:38 | 000,666,361 | —- | M] () – C:\Users\Home\Documents\fathers-day-card.pdf
[2011/06/09 08:02:18 | 000,010,284 | -HS- | M] () – C:\Users\Home\AppData\Local\8dhnv12wf2f0lr7s25kn7jp7
[2011/06/09 07:27:33 | 000,010,268 | -HS- | M] () – C:\ProgramData\8dhnv12wf2f0lr7s25kn7jp7
[2011/06/08 20:03:08 | 000,003,072 | -H– | M] () – C:\Users\Home\Desktop\photothumb.db
[2011/06/08 20:01:15 | 000,051,200 | -H– | M] () – C:\Users\Home\Documents\photothumb.db
[2011/06/05 19:35:08 | 000,497,520 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/05/28 11:00:02 | 001,638,912 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/05/27 07:00:50 | 000,001,415 | —- | M] () – C:\Users\Home\Desktop\GameHouse Games Collection - Shortcut.lnk
[2011/05/24 13:21:28 | 000,074,752 | —- | M] () – C:\Users\Home\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== Files Created - No Company Name ==========

[2011/06/18 22:13:13 | 000,023,152 | —- | C] () – C:\Users\Home\.recently-used.xbel
[2011/06/18 11:37:34 | 000,666,361 | —- | C] () – C:\Users\Home\Documents\fathers-day-card.pdf
[2011/06/08 08:11:11 | 000,010,284 | -HS- | C] () – C:\Users\Home\AppData\Local\8dhnv12wf2f0lr7s25kn7jp7
[2011/06/08 08:11:11 | 000,010,268 | -HS- | C] () – C:\ProgramData\8dhnv12wf2f0lr7s25kn7jp7
[2011/05/27 07:00:50 | 000,001,415 | —- | C] () – C:\Users\Home\Desktop\GameHouse Games Collection - Shortcut.lnk
[2010/11/08 19:41:43 | 000,033,134 | —- | C] () – C:\Users\Home\AppData\Roaming\UserTile.png
[2010/07/10 15:53:16 | 001,970,176 | —- | C] () – C:\Windows\System32\d3dx9.dll
[2010/06/19 15:38:58 | 000,074,752 | —- | C] () – C:\Users\Home\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/10 14:55:00 | 000,000,025 | —- | C] () – C:\Windows\CDET10.ini
[2010/06/09 09:35:55 | 000,098,254 | —- | C] () – C:\Windows\certs.exe
[2010/03/27 03:04:54 | 000,041,872 | —- | C] () – C:\Windows\System32\xfcodec.dll
[2009/07/14 12:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 12:33:53 | 000,497,520 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 10:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 10:05:48 | 000,104,214 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 10:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 10:05:48 | 000,000,000 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 10:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 10:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/14 08:19:49 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2009/07/14 07:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 07:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 07:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/11 05:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat

========== LOP Check ==========

[2010/06/09 20:10:47 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\EA
[2010/06/20 12:55:17 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\EPSON
[2010/08/30 12:36:16 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\FashionCrazeChech
[2010/06/17 15:47:35 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\funkitron
[2010/07/05 16:24:25 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\GameBlend
[2010/10/27 18:44:28 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\GameHousev1005
[2010/12/22 21:41:13 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\GetRightToGo
[2011/06/18 22:13:13 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\gtk-2.0
[2010/06/10 10:12:33 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Incredible Ink
[2011/03/26 13:14:51 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\MP3Rocket
[2011/03/28 12:09:26 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\PhotoScape
[2010/06/11 08:42:06 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\pixelStorm
[2010/10/19 13:37:01 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\PlayFirst
[2010/10/19 14:45:33 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\SpinTop
[2010/10/29 11:08:21 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\SpinTop Games
[2011/03/28 19:42:28 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Wildfire
[2011/03/20 13:48:54 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\YoudaGames
[2011/06/06 06:08:36 | 000,032,590 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/11 05:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/06/11 05:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2011/06/20 07:43:17 | 1408,098,304 | -HS- | M] () – C:\hiberfil.sys
[2010/11/24 18:33:24 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/11/24 18:33:24 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/06/20 07:43:17 | 1877,467,136 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 12:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 12:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 12:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 12:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/11 05:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/14 09:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2009/07/14 09:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2005/08/03 13:48:54 | 000,389,120 | —- | M] (GameHouse) – C:\Windows\Adventure Inlay.scr
[2004/09/20 16:00:28 | 000,802,816 | —- | M] (Sprout Games, LLC) – C:\Windows\FeedingFrenzy.scr
[1999/02/16 22:02:24 | 000,049,664 | —- | M] (Magic Modules) – C:\Windows\SSMaui Wowee.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 12:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/06/09 09:57:35 | 000,000,221 | -HS- | M] () – C:\Users\Home\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-06-17 23:21:08

========== Alternate Data Streams ==========

@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:B2077F63
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:CF75D88F
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:CA408490
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:83E716F0
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:1DEE6B65
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:114BD271
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:D507B5A8

< End of report >

Extras.txt :

OTL Extras logfile created on: 6/20/2011 3:04:44 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Home\Downloads
An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000464 | Country: Pilipinas | Language: FPO | Date Format: M/d/yyyy

1.75 Gb Total Physical Memory | 1.13 Gb Available Physical Memory | 64.57% Memory free
3.50 Gb Paging File | 2.53 Gb Available in Paging File | 72.29% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 99.26 Gb Total Space | 57.39 Gb Free Space | 57.81% Space Free | Partition Type: NTFS
Drive D: | 99.36 Gb Total Space | 99.27 Gb Free Space | 99.91% Space Free | Partition Type: NTFS
Drive E: | 99.36 Gb Total Space | 99.26 Gb Free Space | 99.89% Space Free | Partition Type: NTFS

Computer Name: HOME-PC | User Name: Home | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.exe [@ = exefile] – "C:\Users\Home\AppData\Local\lxv.exe" -a "%1" %*
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – "C:\Users\Home\AppData\Local\lxv.exe" -a "%1" %*
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "C:\Users\Home\AppData\Local\lxv.exe" -a "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 2.5.4
"{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant
"{46CBBDF8-55B5-40DB-B459-7B848394309C}" = EPSON File Manager
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8A8F8391-4C2C-4BE1-A984-CD4A5A546467}" = EPSON Easy Photo Print
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9387BD93-D281-457A-B694-77155F74E0A2}" = Iminent
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A76AA284-E52D-47E6-9E4F-B85DBF8E35C3}" = IMinent Toolbar
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AF36CE1D-FD2C-4BA0-93FA-1196785DD610}" = Adobe Flash Player 10 Plugin
"{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6
"{C768790F-04FB-11E0-9B2C-001AA037B01E}" = Google Earth
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{d55c59eb-9aa3-47a4-bd12-933c17d9f2f6}" = MP3 Remix Player Standalone
"{F58E86C0-75E2-4D40-A5F7-14D7B2772DC7}" = SearchTheWeb
"Academy of Magic" = GameHouse Games Collection: Academy of Magic
"Acoustica Effects Pack" = Acoustica Effects Pack
"Acoustica Mixcraft 5" = Acoustica Mixcraft 5
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adventure Inlay" = GameHouse Games Collection: Adventure Inlay
"Adventure Inlay - Safari Edition" = GameHouse Games Collection: Adventure Inlay - Safari Edition
"Air Force Missions_is1" = Air Force Missions
"Alarm_is1" = Alarm 2.0.4
"Alien Sky" = GameHouse Games Collection: Alien Sky
"Aloha Solitaire" = GameHouse Games Collection: Aloha Solitaire
"Aloha TriPeaks" = GameHouse Games Collection: Aloha TriPeaks
"am-amazingadventuresaroundtheworldtm" = Amazing Adventures Around the World™
"Amazing Adventures Around the World" = Amazing Adventures Around the World
"am-plantsvszombiestm" = Plants vs. Zombies™
"Ancient Tri-Jong" = GameHouse Games Collection: Ancient Tri-Jong
"Ancient Tripeaks" = GameHouse Games Collection: Ancient Tripeaks
"Astrobatics" = GameHouse Games Collection: Astrobatics
"Atlantis" = GameHouse Games Collection: Atlantis
"Atomaders" = GameHouse Games Collection: Atomaders
"autoclicker_is1" = auto-clicker 2.3.0
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"Bejeweled 2" = GameHouse Games Collection: Bejeweled 2
"Bewitched" = GameHouse Games Collection: Bewitched
"BFGC" = Big Fish Games: Game Manager
"BFG-Dream Chronicles" = Dream Chronicles
"Big Kahuna Reef" = GameHouse Games Collection: Big Kahuna Reef
"BitLord" = BitLord 1.1
"Boggle Supreme" = GameHouse Games Collection: Boggle Supreme
"Bookworm Adventures Deluxe" = Bookworm Adventures Deluxe
"Bounce Out Blitz" = GameHouse Games Collection: Bounce Out Blitz
"BrotherSoft_Extreme Toolbar" = BrotherSoft Extreme Toolbar
"Casino Island To Go" = GameHouse Games Collection: Casino Island To Go
"Chainz" = GameHouse Games Collection: Chainz
"Chainz 2: Relinked" = GameHouse Games Collection: Chainz 2 - Relinked
"Charm Solitaire" = GameHouse Games Collection: Charm Solitaire
"Charm Tale" = GameHouse Games Collection: Charm Tale
"Cheat Engine 5.6.1_is1" = Cheat Engine 5.6.1
"Chicktionary" = GameHouse Games Collection: Chicktionary
"Chuzzle Deluxe" = GameHouse Games Collection: Chuzzle Deluxe
"Collapse! Crunch" = GameHouse Games Collection: Collapse! Crunch
"Combo Chaos!" = GameHouse Games Collection: Combo Chaos!
"conduitEngine" = Conduit Engine
"Cool Timer_is1" = Cool Timer 3.7
"Cradle Of Persia_is1" = Cradle Of Persia
"Cross Fire_is1" = Cross Fire En
"Crystal Path" = GameHouse Games Collection: Crystal Path
"Cubis Gold 2" = GameHouse Games Collection: Cubis Gold 2
"Digby's Donuts" = GameHouse Games Collection: Digby's Donuts
"Diner Dash" = GameHouse Games Collection: Diner Dash
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Farm Frenzy 2_is1" = Farm Frenzy 2
"Fashion Craze_is1" = Fashion Craze
"Feeding Frenzy" = GameHouse Games Collection: Feeding Frenzy
"Fiber Twig" = GameHouse Games Collection: Fiber Twig
"Five Card Deluxe" = GameHouse Games Collection: Five Card Deluxe
"Flip Words" = GameHouse Games Collection: Flip Words
"Flying Leo" = GameHouse Games Collection: Flying Leo
"Fortune Tiles Gold" = GameHouse Games Collection: Fortune Tiles Gold
"Fresco Wizard" = GameHouse Games Collection: Fresco Wizard
"GameHouse Sudoku" = GameHouse Games Collection: GameHouse Sudoku
"Gearz" = GameHouse Games Collection: Gearz
"Globe Broadband Click Fix_is1" = Globe Broadband Click Fix
"Google Chrome" = Google Chrome
"Granny in Paradise" = GameHouse Games Collection: Granny in Paradise
"Great Secrets - Da Vinci_is1" = Great Secrets - Da Vinci
"Gutterball" = GameHouse Games Collection: Gutterball
"Gutterball 2" = GameHouse Games Collection: Gutterball 2
"Hamsterball" = GameHouse Games Collection: Hamsterball
"Hello!" = GameHouse Games Collection: Hello!
"Holiday Express" = GameHouse Games Collection: Holiday Express
"Iggle Pop!" = GameHouse Games Collection: Iggle Pop!
"IMBoosterARP" = Iminent
"Incadia" = GameHouse Games Collection: Incadia
"Incredible Ink" = GameHouse Games Collection: Incredible Ink
"Insaniquarium Deluxe" = GameHouse Games Collection: Insaniquarium Deluxe
"Inspector Parker" = GameHouse Games Collection: Inspector Parker
"InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"Invadazoid" = GameHouse Games Collection: Invadazoid
"Jewel Quest" = GameHouse Games Collection: Jewel Quest
"Lemonade Tycoon" = GameHouse Games Collection: Lemonade Tycoon
"Lost Treasures of El Dorado_is1" = Lost Treasures of El Dorado
"Luxor" = GameHouse Games Collection: Luxor
"Mad Caps" = GameHouse Games Collection: Mad Caps
"Magic Ball Deluxe" = GameHouse Games Collection: Magic Ball
"Magic Inlay" = GameHouse Games Collection: Magic Inlay
"Magic Music Editor_is1" = Magic Music Editor v8.11.1.2219
"Magic Vines" = GameHouse Games Collection: Magic Vines
"Mah Jong Adventures" = GameHouse Games Collection: Mah Jong Adventures
"Mah Jong Medley" = GameHouse Games Collection: Mah Jong Medley
"Mah Jong Quest" = GameHouse Games Collection: Mah Jong Quest
"Mahjong Garden To Go" = GameHouse Games Collection: Mahjong Garden To Go
"Mahjong Towers Eternity" = GameHouse Games Collection: Mahjong Towers Eternity
"Maui Wowee" = GameHouse Games Collection: Maui Wowee
"Mozilla Firefox (3.0.19)" = Mozilla Firefox (3.0.19)
"MP3 Rocket" = MP3 Rocket
"MyWebSearch bar Uninstall" = My Web Search
"Nanny Mania_is1" = Nanny Mania
"Phlinx To Go" = GameHouse Games Collection: Phlinx To Go
"PhotoScape" = PhotoScape
"Pin High Country Club Golf" = GameHouse Games Collection: Pin High Country Club Golf
"Pizza Frenzy" = GameHouse Games Collection: Pizza Frenzy
"Plants vs. Zombies" = Plants vs. Zombies
"Platypus" = GameHouse Games Collection: Platypus
"Poker Superstars" = GameHouse Games Collection: Poker Superstars
"Puzzle Express" = GameHouse Games Collection: Puzzle Express
"Puzzle Inlay" = GameHouse Games Collection: Puzzle Inlay
"Puzzle Solitaire" = GameHouse Games Collection: Puzzle Solitaire
"QBz" = GameHouse Games Collection: QBz
"Reader's Digest Super Word Power" = GameHouse Games Collection: Reader's Digest Super Word Power
"Ricochet" = GameHouse Games Collection: Ricochet
"Ricochet Lost Worlds" = GameHouse Games Collection: Ricochet Lost Worlds
"Ricochet Lost Worlds: Recharged" = GameHouse Games Collection: Ricochet Lost Worlds - Recharged
"Road Attack_is1" = Road Attack
"Roller Rush" = GameHouse Games Collection: Roller Rush
"Saints & Sinners Bingo" = GameHouse Games Collection: Saints & Sinners Bingo
"Sandlot Games Client Services_is1" = Sandlot Games Client Services
"SCRABBLE" = GameHouse Games Collection: SCRABBLE
"SearchTheWebARP" = SearchTheWeb
"Shape Shifter" = GameHouse Games Collection: Shape Shifter
"Slingo Deluxe" = GameHouse Games Collection: Slingo Deluxe
"Spelvin" = GameHouse Games Collection: Spelvin
"Splash" = GameHouse Games Collection: Splash
"Spring Sprang Sprung" = GameHouse Games Collection: Spring Sprang Sprung
"Super 5-Line Slots" = GameHouse Games Collection: Super 5-Line Slots
"Super Blackjack!" = GameHouse Games Collection: Super Blackjack!
"Super Bounce Out!" = GameHouse Games Collection: Super Bounce Out!
"Super Candy Cruncher" = GameHouse Games Collection: Super Candy Cruncher
"Super Collapse!" = GameHouse Games Collection: Super Collapse!
"Super Collapse! II" = GameHouse Games Collection: Super Collapse! II
"Super Collapse! II Platinum" = GameHouse Games Collection: Super Collapse! II Platinum
"Super Fruit Frolic" = GameHouse Games Collection: Super Fruit Frolic
"Super GameHouse Solitaire Vol. 1" = GameHouse Games Collection: Super GameHouse Solitaire Vol. 1
"Super GameHouse Solitaire Vol. 2" = GameHouse Games Collection: Super GameHouse Solitaire Vol. 2
"Super GameHouse Solitaire Vol. 3" = GameHouse Games Collection: Super GameHouse Solitaire Vol. 3
"Super Gem Drop" = GameHouse Games Collection: Super Gem Drop
"Super Glinx!" = GameHouse Games Collection: Super Glinx!
"Super Letter Linker" = GameHouse Games Collection: Super Letter Linker
"Super Mah Jong Solitaire" = GameHouse Games Collection: Super Mah Jong Solitaire
"Super Nisqually" = GameHouse Games Collection: Super Nisqually
"Super PileUp!" = GameHouse Games Collection: Super PileUp!
"Super Pool" = GameHouse Games Collection: Super Pool
"Super Pop & Drop!" = GameHouse Games Collection: Super Pop & Drop!
"Super Rumble Cube" = GameHouse Games Collection: Super Rumble Cube
"Super SpongeBob Collapse!" = GameHouse Games Collection: Super SpongeBob Collapse!
"Super TextTwist" = GameHouse Games Collection: Super TextTwist
"Super WHATword" = GameHouse Games Collection: Super WHATword
"Super Wild Wild Words" = GameHouse Games Collection: Super Wild Wild Words
"Tap a Jam" = GameHouse Games Collection: Tap a Jam
"Ten Pin Championship Bowling Pro" = GameHouse Games Collection: Ten Pin Championship Bowling Pro
"Tennis Titans" = GameHouse Games Collection: Tennis Titans
"ToggleEN Toolbar" = ToggleEN Toolbar
"TorrentMan Toolbar" = TorrentMan Toolbar
"Total Video Converter 3.20_is1" = Total Video Converter 3.20 090104
"Tradewinds 2" = GameHouse Games Collection: Tradewinds 2
"Treasures of the Ancient Cavern_is1" = Treasures of the Ancient Cavern
"Trivia Machine" = GameHouse Games Collection: Trivia Machine
"Tropical Swaps" = GameHouse Games Collection: Tropical Swaps
"Tumblebugs" = GameHouse Games Collection: Tumblebugs
"Turtle Bay" = GameHouse Games Collection: Turtle Bay
"Twistingo" = GameHouse Games Collection: Twistingo
"Ultimate Dominoes" = GameHouse Games Collection: Ultimate Dominoes
"USB Disk Security_is1" = USB Disk Security [removed]
"Varmintz Deluxe" = GameHouse Games Collection: Varmintz Deluxe
"Walls of Jericho, The" = GameHouse Games Collection: Walls of Jericho, The
"Web Games Player Plugin" = Web Games Player Plugin
"Wheel of Fortune" = Wheel of Fortune (remove only)
"WidgetServ" = WidgetServ 1.0
"WinGimp-2.0_is1" = GIMP 2.6.11
"WinRAR archiver" = WinRAR archiver
"Word Jolt" = GameHouse Games Collection: Word Jolt
"Word Slinger" = GameHouse Games Collection: Word Slinger
"WordJong To Go" = GameHouse Games Collection: WordJong To Go
"Xfire" = Xfire (remove only)
"XfireXO Toolbar" = XfireXO Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Zuma Deluxe" = GameHouse Games Collection: Zuma Deluxe
"Zynga Toolbar" = Zynga Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Kids Pix Demo" = Kids Pix Demo
"UnityWebPlayer" = Unity Web Player

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post













Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Hello , thank you for replying to my post. :) I would just want to clarify the note saying : - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools I have difficulties and i also click the link to help me, but i could just not get it. I have clicked the system tray but i cant find the red thing with an opened umbrella. Please Help :)
I dont get it. Uhmmmm… I have already clicked disable but ther are still windows showing still have an antivir . Is the system tray Icon the one with two arrows >> ? If it is the STI i cant find the logo with the umbrellas :[[
Thanks Guys, the problem has been solved. :) BTW here is the combofix.txt :) ComboFix 11-06-20.01 - Home 06/21/2011 17:41:27.1.2 - x86 Microsoft Windows 7 Professional 6.1.7600.0.1252.63.1033.18.1790.905 [GMT 8:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7} SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\CFLog c:\cflog\CrashLog_20101019.txt c:\progra~1\MYWEBS~1\bar\6.bin\mwsoemon.exe c:\program files\FunWebProducts c:\program files\MyWebSearch c:\program files\MyWebSearch\bar\1.bin\chrome\M3FFXTBR.JAR c:\program files\MyWebSearch\bar\2.bin\chrome\M3FFXTBR.JAR c:\program files\MyWebSearch\bar\3.bin\chrome\M3FFXTBR.JAR c:\program files\MyWebSearch\bar\4.bin\chrome\M3FFXTBR.JAR c:\program files\MyWebSearch\bar\5.bin\chrome\M3FFXTBR.JAR c:\program files\MyWebSearch\bar\5.bin\M3FFTBPR.DLL c:\program files\MyWebSearch\bar\5.bin\M3PATCH.DLL c:\program files\MyWebSearch\bar\6.bin\CHROME.MANIFEST c:\program files\MyWebSearch\bar\6.bin\chrome\M3FFXTBR.JAR c:\program files\MyWebSearch\bar\6.bin\F3BKGERR.JPG c:\program files\MyWebSearch\bar\6.bin\F3CJPEG.DLL c:\program files\MyWebSearch\bar\6.bin\F3DTACTL.DLL c:\program files\MyWebSearch\bar\6.bin\F3HISTSW.DLL c:\program files\MyWebSearch\bar\6.bin\F3HKSTUB.DLL c:\program files\MyWebSearch\bar\6.bin\F3HTmlmu.dll c:\program files\MyWebSearch\bar\6.bin\F3HTtpct.dll c:\program files\MyWebSearch\bar\6.bin\F3IMSTUB.DLL c:\program files\MyWebSearch\bar\6.bin\F3POPSWT.DLL c:\program files\MyWebSearch\bar\6.bin\F3PSSAVR.SCR c:\program files\MyWebSearch\bar\6.bin\F3REGHK.DLL c:\program files\MyWebSearch\bar\6.bin\F3REPROX.DLL c:\program files\MyWebSearch\bar\6.bin\F3RESTUB.DLL c:\program files\MyWebSearch\bar\6.bin\F3SCHMON.EXE c:\program files\MyWebSearch\bar\6.bin\F3SCRCTR.DLL c:\program files\MyWebSearch\bar\6.bin\F3SPACER.WMV c:\program files\MyWebSearch\bar\6.bin\F3WALLPP.DAT c:\program files\MyWebSearch\bar\6.bin\F3WPHOOK.DLL c:\program files\MyWebSearch\bar\6.bin\FWPBUDDY.PNG c:\program files\MyWebSearch\bar\6.bin\INSTALL.RDF c:\program files\MyWebSearch\bar\6.bin\M3AUXSTB.DLL c:\program files\MyWebSearch\bar\6.bin\M3DLGHK.DLL c:\program files\MyWebSearch\bar\6.bin\M3HIGHIN.EXE c:\program files\MyWebSearch\bar\6.bin\M3HTML.DLL c:\program files\MyWebSearch\bar\6.bin\M3IDLE.DLL c:\program files\MyWebSearch\bar\6.bin\M3IMPIPE.EXE c:\program files\MyWebSearch\bar\6.bin\M3MEDINT.EXE c:\program files\MyWebSearch\bar\6.bin\M3MSg.dll c:\program files\MyWebSearch\bar\6.bin\M3OUtlcn.dll c:\program files\MyWebSearch\bar\6.bin\M3PLUGIN.DLL c:\program files\MyWebSearch\bar\6.bin\M3SKIN.DLL c:\program files\MyWebSearch\bar\6.bin\M3SKPLAY.EXE c:\program files\MyWebSearch\bar\6.bin\M3SLSRCH.EXE c:\program files\MyWebSearch\bar\6.bin\M3SRCHMN.EXE c:\program files\MyWebSearch\bar\6.bin\M3TPINST.DLL c:\program files\MyWebSearch\bar\6.bin\MWSBAR.DLL c:\program files\MyWebSearch\bar\6.bin\MWSMLBTN.DLL c:\program files\MyWebSearch\bar\6.bin\MWSOEMON.EXE c:\program files\MyWebSearch\bar\6.bin\MWSOEPLG.DLL c:\program files\MyWebSearch\bar\6.bin\MWSOESTB.DLL c:\program files\MyWebSearch\bar\6.bin\MWSSRCAS.DLL c:\program files\MyWebSearch\bar\6.bin\MWSSVC.EXE c:\program files\MyWebSearch\bar\6.bin\MWSUABTN.DLL c:\program files\MyWebSearch\bar\6.bin\NPMYWEBS.DLL c:\program files\MyWebSearch\bar\Avatar\COMMON.F3S c:\program files\MyWebSearch\bar\Game\CHECKERS.F3S c:\program files\MyWebSearch\bar\Game\CHESS.F3S c:\program files\MyWebSearch\bar\Game\REVERSI.F3S c:\program files\MyWebSearch\bar\icons\CM.ICO c:\program files\MyWebSearch\bar\icons\MFC.ICO c:\program files\MyWebSearch\bar\icons\PSS.ICO c:\program files\MyWebSearch\bar\icons\SMILEY.ICO c:\program files\MyWebSearch\bar\icons\WB.ICO c:\program files\MyWebSearch\bar\icons\ZWINKY.ICO c:\program files\MyWebSearch\bar\Message\COMMON.F3S c:\program files\MyWebSearch\bar\Notifier\COMMON.F3S c:\program files\MyWebSearch\bar\Notifier\DOG.F3S c:\program files\MyWebSearch\bar\Notifier\FISH.F3S c:\program files\MyWebSearch\bar\Notifier\KUNGFU.F3S c:\program files\MyWebSearch\bar\Notifier\LIFEGARD.F3S c:\program files\MyWebSearch\bar\Notifier\MAID.F3S c:\program files\MyWebSearch\bar\Notifier\MAILBOX.F3S c:\program files\MyWebSearch\bar\Notifier\OPERA.F3S c:\program files\MyWebSearch\bar\Notifier\ROBOT.F3S c:\program files\MyWebSearch\bar\Notifier\SEDUCT.F3S c:\program files\MyWebSearch\bar\Notifier\SURFER.F3S c:\program files\MyWebSearch\bar\Overlay\COMMON.F3S c:\program files\MyWebSearch\bar\Settings\s_pid.dat c:\programdata\Microsoft\Network\Downloader\qmgr0.dat c:\programdata\Microsoft\Network\Downloader\qmgr1.dat c:\windows\system32\ccrpTmr6.dll c:\windows\system32\f3PSSavr.scr . —– BITS: Possible infected sites —– . hxxp://globebroadbandclickfix.com.ph . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_MyWebSearchService . . ((((((((((((((((((((((((( Files Created from 2011-05-21 to 2011-06-21 ))))))))))))))))))))))))))))))) . . 2011-06-21 09:53 . 2011-06-21 09:53 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-06-18 03:39 . 2011-06-18 04:07 ——– d—–w- c:\users\Home\AppData\Local\Unity 2011-06-16 21:46 . 2011-04-27 02:33 78336 —-a-w- c:\windows\system32\drivers\dfsc.sys 2011-06-16 21:46 . 2011-05-03 04:50 740864 —-a-w- c:\windows\system32\inetcomm.dll 2011-06-15 23:02 . 2011-04-29 02:57 311296 —-a-w- c:\windows\system32\drivers\srv.sys 2011-06-15 23:02 . 2011-04-29 02:57 309760 —-a-w- c:\windows\system32\drivers\srv2.sys 2011-06-15 23:02 . 2011-04-29 02:57 114176 —-a-w- c:\windows\system32\drivers\srvnet.sys 2011-06-15 22:54 . 2011-05-04 02:43 222720 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-06-15 22:54 . 2011-05-04 02:43 96256 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-06-15 22:54 . 2011-05-04 02:43 123392 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-06-07 22:55 . 2011-05-09 20:46 6962000 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B0E366A7-812D-4D87-B514-B31FF507D92B}\mpengine.dll 2011-06-06 04:16 . 2011-06-08 10:17 ——– d—–w- C:\output . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-05-18 06:04 . 2010-07-14 06:42 48648 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll 2011-04-23 07:09 . 2010-07-07 05:51 48648 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll 2011-04-09 06:13 . 2011-05-11 19:28 3957632 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-04-09 06:13 . 2011-05-11 19:28 3901824 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-04-09 05:56 . 2011-05-12 04:04 123904 —-a-w- c:\windows\system32\poqexec.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-01 1487240] "{7c5c0f58-e061-457d-9033-77307f5ed00c}"= "c:\program files\TorrentMan\tbTorr.dll" [2008-05-20 1526296] "{5e5ab302-7f65-44cd-8211-c1d4caaccea3}"= "c:\program files\XfireXO\tbXfir.dll" [2010-10-10 3906656] "{038cb5c7-48ea-4af9-94e0-a1646542e62b}"= "c:\program files\ToggleEN\tbTogg.dll" [2010-09-12 3863136] "{84FF7BD6-B47F-46F8-9130-01B2696B36CB}"= "c:\program files\Iminent\SearchTheWeb\Iminent.BHO.NavigationError.dll" [2010-07-09 111608] "{7b13ec3e-999a-4b70-b9cb-2617b8323822}"= "c:\program files\Zynga\tbZyng.dll" [2010-12-01 2735200] "{51a86bb3-6602-4c85-92a5-130ee4864f13}"= "c:\program files\BrotherSoft_Extreme\tbBrot.dll" [2010-09-12 3863136] . [HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}] . [HKEY_CLASSES_ROOT\clsid\{7c5c0f58-e061-457d-9033-77307f5ed00c}] . [HKEY_CLASSES_ROOT\clsid\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}] . [HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}] . [HKEY_CLASSES_ROOT\clsid\{84ff7bd6-b47f-46f8-9130-01b2696b36cb}] [HKEY_CLASSES_ROOT\IminentBHONavigationError.CHelperBHO.1] [HKEY_CLASSES_ROOT\TypeLib\{59E6E159-57CC-4DA5-8700-2AD17DC31DD1}] [HKEY_CLASSES_ROOT\IminentBHONavigationError.CHelperBHO] . [HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}] . [HKEY_CLASSES_ROOT\clsid\{51a86bb3-6602-4c85-92a5-130ee4864f13}] . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{038cb5c7-48ea-4af9-94e0-a1646542e62b}] 2010-09-12 07:02 3863136 —-a-w- c:\program files\ToggleEN\tbTogg.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}] 2010-10-10 07:51 3906656 —-a-w- c:\program files\ConduitEngine\ConduitEngine.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51a86bb3-6602-4c85-92a5-130ee4864f13}] 2010-09-12 07:02 3863136 —-a-w- c:\program files\BrotherSoft_Extreme\tbBrot.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{58124A0B-DC32-4180-9BFF-E0E21AE34026}] 2010-07-02 01:54 2607872 —-a-w- c:\program files\IMinent Toolbar\tbcore3.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}] 2010-10-10 07:51 3906656 —-a-w- c:\program files\XfireXO\tbXfir.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7b13ec3e-999a-4b70-b9cb-2617b8323822}] 2010-12-01 03:27 2735200 —-a-w- c:\program files\Zynga\tbZyng.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7c5c0f58-e061-457d-9033-77307f5ed00c}] 2008-05-20 16:43 1526296 —-a-w- c:\program files\TorrentMan\tbTorr.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}] 2010-07-09 08:21 111608 —-a-w- c:\program files\Iminent\SearchTheWeb\Iminent.BHO.NavigationError.dll . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2011-02-01 11:17 1487240 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{977AE9CC-AF83-45E8-9E03-E2798216E2D5}"= "c:\program files\IMinent Toolbar\tbcore3.dll" [2010-07-02 2607872] "{7c5c0f58-e061-457d-9033-77307f5ed00c}"= "c:\program files\TorrentMan\tbTorr.dll" [2008-05-20 1526296] "{5e5ab302-7f65-44cd-8211-c1d4caaccea3}"= "c:\program files\XfireXO\tbXfir.dll" [2010-10-10 3906656] "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngine.dll" [2010-10-10 3906656] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-01 1487240] "{038cb5c7-48ea-4af9-94e0-a1646542e62b}"= "c:\program files\ToggleEN\tbTogg.dll" [2010-09-12 3863136] "{7b13ec3e-999a-4b70-b9cb-2617b8323822}"= "c:\program files\Zynga\tbZyng.dll" [2010-12-01 2735200] "{51a86bb3-6602-4c85-92a5-130ee4864f13}"= "c:\program files\BrotherSoft_Extreme\tbBrot.dll" [2010-09-12 3863136] . [HKEY_CLASSES_ROOT\clsid\{977ae9cc-af83-45e8-9e03-e2798216e2d5}] [HKEY_CLASSES_ROOT\TBSB01620.TBSB01620.3] [HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}] [HKEY_CLASSES_ROOT\TBSB01620.TBSB01620] . [HKEY_CLASSES_ROOT\clsid\{7c5c0f58-e061-457d-9033-77307f5ed00c}] . [HKEY_CLASSES_ROOT\clsid\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}] . [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}] . [HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}] . [HKEY_CLASSES_ROOT\clsid\{51a86bb3-6602-4c85-92a5-130ee4864f13}] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-01 1487240] "{977AE9CC-AF83-45E8-9E03-E2798216E2D5}"= "c:\program files\IMinent Toolbar\tbcore3.dll" [2010-07-02 2607872] "{7C5C0F58-E061-457D-9033-77307F5ED00C}"= "c:\program files\TorrentMan\tbTorr.dll" [2008-05-20 1526296] "{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3}"= "c:\program files\XfireXO\tbXfir.dll" [2010-10-10 3906656] "{038CB5C7-48EA-4AF9-94E0-A1646542E62B}"= "c:\program files\ToggleEN\tbTogg.dll" [2010-09-12 3863136] "{7B13EC3E-999A-4B70-B9CB-2617B8323822}"= "c:\program files\Zynga\tbZyng.dll" [2010-12-01 2735200] "{51A86BB3-6602-4C85-92A5-130EE4864F13}"= "c:\program files\BrotherSoft_Extreme\tbBrot.dll" [2010-09-12 3863136] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CLASSES_ROOT\clsid\{977ae9cc-af83-45e8-9e03-e2798216e2d5}] [HKEY_CLASSES_ROOT\TBSB01620.TBSB01620.3] [HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}] [HKEY_CLASSES_ROOT\TBSB01620.TBSB01620] . [HKEY_CLASSES_ROOT\clsid\{7c5c0f58-e061-457d-9033-77307f5ed00c}] . [HKEY_CLASSES_ROOT\clsid\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}] . [HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}] . [HKEY_CLASSES_ROOT\clsid\{7b13ec3e-999a-4b70-b9cb-2617b8323822}] . [HKEY_CLASSES_ROOT\clsid\{51a86bb3-6602-4c85-92a5-130ee4864f13}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-02-20 4363504] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-07-16 25604904] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-07-06 39408] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] "USB Antivirus"="c:\program files\USB Disk Security\USBGuard.exe" [2008-09-23 798720] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "globe"="c:\program files\Globe Telecom\Click Fix\bin\sprtcmd.exe" [2008-08-21 200384] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "IMBooster"="c:\program files\Iminent\IMBooster\imbooster.exe" [2010-11-08 1322488] "Iminent.Notifier"="c:\program files\Iminent\SearchTheWeb\Iminent.Notifier.exe" [2010-07-09 536056] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2009-07-14 8704] . c:\users\Home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ MP3 Rocket (Minimized).lnk - c:\program files\MP3 Rocket\MP3Rocket.exe [2010-7-26 174080] OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696] Xfire.lnk - c:\program files\Xfire\Xfire.exe [2010-3-27 3250576] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . R2 gupdate;Serbisyo ng Update ng Google (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-07-12 135664] R3 gupdatem;Serbisyong Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-07-12 135664] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-08-06 1343400] R3 XDva370;XDva370;c:\windows\system32\XDva370.sys [x] R3 XDva372;XDva372;c:\windows\system32\XDva372.sys [x] R3 XDva377;XDva377;c:\windows\system32\XDva377.sys [x] R3 XDva382;XDva382;c:\windows\system32\XDva382.sys [x] S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289] S2 sprtsvc_globe;SupportSoft Sprocket Service (globe);c:\program files\Globe Telecom\Click Fix\bin\sprtsvc.exe [2008-08-21 200384] . . Contents of the 'Scheduled Tasks' folder . 2011-06-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-07-12 12:16] . 2011-06-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-07-12 12:16] . . ——- Supplementary Scan ——- . uStart Page = hxxp://search.iminent.com/?appId=2A4066A6-CCEE-4934-B638-E950732B22EE IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\no8de4kp.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2077543&SearchSource;=3&q;={searchTerms} FF - prefs.js: browser.search.selectedEngine - ToggleEN Customized Web Search FF - prefs.js: browser.startup.homepage - hxxp://search.iminent.com/?appId=2a4066a6-ccee-4934-b638-e950732b22ee&ref;=homepage FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZCfox000&ptb;=A26UMNpHkW.HdOieQnwp9A&ind;=2010071102&ptnrS;=ZCfox000&si;=&n;=77cf403e&psa;=&st;=kwd&searchfor;= . . ——- File Associations ——- . exefile="c:\users\Home\AppData\Local\lxv.exe" -a "%1" %* . - - - - ORPHANS REMOVED - - - - . HKCU-Run-06ae3454d92ff3a31aaa23136e885da5 - c:\users\Home\DOWNLO~1\DFBHDS~1.EXE AddRemove-Academy of Magic - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Adventure Inlay - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Adventure Inlay - Safari Edition - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Alien Sky - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Aloha Solitaire - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Aloha TriPeaks - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Ancient Tri-Jong - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Ancient Tripeaks - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Astrobatics - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Atlantis - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Atomaders - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Bejeweled 2 - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Bewitched - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-BFG-Dream Chronicles - c:\program files\Dream Chronicles\Uninstall.exe AddRemove-Big Kahuna Reef - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Boggle Supreme - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Bounce Out Blitz - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Casino Island To Go - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Chainz - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Chainz 2: Relinked - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Charm Solitaire - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Charm Tale - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Chicktionary - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Chuzzle Deluxe - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Collapse! Crunch - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Combo Chaos! - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Crystal Path - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Cubis Gold 2 - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Digby's Donuts - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Diner Dash - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Feeding Frenzy - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Fiber Twig - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Five Card Deluxe - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Flip Words - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Flying Leo - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Fortune Tiles Gold - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Fresco Wizard - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-GameHouse Sudoku - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Gearz - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Granny in Paradise - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Gutterball - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Gutterball 2 - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Hamsterball - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Hello! - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Holiday Express - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Iggle Pop! - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Incadia - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Incredible Ink - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Insaniquarium Deluxe - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Inspector Parker - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Invadazoid - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Jewel Quest - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Lemonade Tycoon - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Luxor - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Mad Caps - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Magic Ball Deluxe - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Magic Inlay - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Magic Vines - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Mah Jong Adventures - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Mah Jong Medley - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Mah Jong Quest - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Mahjong Garden To Go - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Mahjong Towers Eternity - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Maui Wowee - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Phlinx To Go - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Pin High Country Club Golf - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Pizza Frenzy - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Platypus - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Poker Superstars - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Puzzle Express - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Puzzle Inlay - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Puzzle Solitaire - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-QBz - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Reader's Digest Super Word Power - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Ricochet - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Ricochet Lost Worlds - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Ricochet Lost Worlds: Recharged - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Roller Rush - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Saints & Sinners Bingo - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-SCRABBLE - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Shape Shifter - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Slingo Deluxe - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Spelvin - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Splash - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Spring Sprang Sprung - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super 5-Line Slots - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super Blackjack! - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super Bounce Out! - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super Candy Cruncher - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super Collapse! - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super Collapse! II - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super Collapse! II Platinum - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super Fruit Frolic - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super GameHouse Solitaire Vol. 1 - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super GameHouse Solitaire Vol. 2 - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super GameHouse Solitaire Vol. 3 - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super Gem Drop - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super Glinx! - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super Letter Linker - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super Mah Jong Solitaire - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super Nisqually - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super PileUp! - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super Pool - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super Pop & Drop! - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super Rumble Cube - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super SpongeBob Collapse! - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super TextTwist - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super WHATword - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Super Wild Wild Words - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Tap a Jam - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Ten Pin Championship Bowling Pro - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Tennis Titans - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Tradewinds 2 - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Trivia Machine - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Tropical Swaps - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Tumblebugs - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Turtle Bay - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Twistingo - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Ultimate Dominoes - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Varmintz Deluxe - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Walls of Jericho, The - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-WidgetServ - c:\program files\Softomate\common\uninst.exe AddRemove-Word Jolt - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Word Slinger - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-WordJong To Go - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-Zuma Deluxe - c:\progra~1\GAMEHO~1\unwise.exe AddRemove-UnityWebPlayer - c:\users\Home\AppData\Local\Unity\WebPlayer\Uninstall.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files\Avira\AntiVir Desktop\avguard.exe c:\windows\system32\WUDFHost.exe c:\windows\system32\sppsvc.exe c:\windows\system32\taskhost.exe c:\windows\system32\conhost.exe c:\\?\c:\windows\system32\wbem\WMIADAP.EXE c:\program files\Google\Chrome\Application\chrome.exe c:\program files\Google\Chrome\Application\chrome.exe . ************************************************************************** . Completion time: 2011-06-21 18:01:33 - machine was rebooted ComboFix-quarantined-files.txt 2011-06-21 10:01 . Pre-Run: 66,503,770,112 bytes free Post-Run: 69,196,447,744 bytes free . - - End Of File - - B7BD933FB618C6A5F4FECCBFF0D92C15
Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please












Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI