This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

blocks ALL antivirus or file scanning programs, Google Redirect

331 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

sigh. alright. i have tryed ALOT of antivirus programs, but it blocks them all and then stops them from opening again, some programs like hijackthis run till a certen point then close and is not accessible or removable anymore.
windows installer will not run and when i tryed to restart that like i have seen on a few sites. im blocked from doing that aswell.
system restore will not work anymore, it only works for the time the computer is on. once i restart or turn it off thos restore points no longer work.
safe mode will not work anymore, it loads to a point then the system just freezes up. i used to have to use safe mode to remove some antiviruses becuase it would just end up blocking the computer from loading XP at all.
and then i have the pesky google redirect so i have to press enter on the address to stop it from redirecting.

i have tryed everything i can think of other then just reformatting the drive. witch i cant do because the cd drive wont read anything ><

OTL did manage to complete its scan so heres what it got.
PLZ any help would be great :(
first file

OTL logfile created on: 12/22/2011 4:18:52 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\matt\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1015.30 Mb Total Physical Memory | 489.04 Mb Available Physical Memory | 48.17% Memory free
14.65 Gb Paging File | 14.29 Gb Available in Paging File | 97.59% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.12 Gb Total Space | 50.98 Gb Free Space | 22.75% Space Free | Partition Type: NTFS
Drive D: | 8.74 Gb Total Space | 4.76 Gb Free Space | 54.41% Space Free | Partition Type: FAT32
Drive G: | 585.95 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: MATTHEW-B672D25 | User Name: matt | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\385991325:1648230120.exe File not found
PRC - C:\Documents and Settings\matt\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\ThreatFire\TFService.exe (PC Tools)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\SoundMan.exe (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\system32\NMSSvc.Exe (Intel Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()


========== Win32 Services (SafeList) ==========

SRV - (PCToolsSSDMonitorSvc) – C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (SbieSvc) – C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (FlvTube Toolbar Helper Service) – C:\Program Files\FlvTube Toolbar\FLVTubeSvc.exe ()
SRV - (UxTuneUp) – C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
SRV - (FirebirdGuardianDefaultInstance) – C:\Program Files\Firebird\Firebird_2_5\bin\fbguard.exe (Firebird Project)
SRV - (FirebirdServerDefaultInstance) – C:\Program Files\Firebird\Firebird_2_5\bin\fbserver.exe (Firebird Project)
SRV - (cFosSpeedS) – C:\Program Files\cFosSpeed\spd.exe (cFos Software GmbH)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (RalinkRegistryWriter) – C:\Program Files\Ralink\Common\RaRegistry.exe (Ralink Technology, Corp.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (ThreatFire) – C:\Program Files\ThreatFire\TFService.exe (PC Tools)
SRV - (Icecast-trunk) – C:\Program Files\Icecast2 Win32\icecastService.exe ()
SRV - (MSIServer) – C:\WINDOWS\System32\msiexec.exe ()
SRV - (NMSSvc) Intel® – C:\WINDOWS\system32\NMSSvc.Exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (39128875) – C:\WINDOWS\system32\drivers\80223438.sys (Kaspersky Lab, GERT)
DRV - (51518490) – C:\WINDOWS\system32\drivers\76704618.sys (Kaspersky Lab, GERT)
DRV - (38982636) – C:\WINDOWS\system32\drivers\61068841.sys (Kaspersky Lab, GERT)
DRV - (rkhdrv40) – C:\WINDOWS\System32\drivers\rkhdrv40.sys ()
DRV - (Partizan) – C:\WINDOWS\system32\drivers\Partizan.sys (Greatis Software)
DRV - (BANTExt) – C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (SbieDrv) – C:\Program Files\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV - (speedfan) – C:\WINDOWS\system32\speedfan.sys (Almico Software)
DRV - (mvxxmm) – C:\WINDOWS\System32\drivers\mvxxmm.sys (Marvell Semiconductor Inc.)
DRV - (mv64xxmm) – C:\WINDOWS\System32\drivers\mv64xxmm.sys (Marvell Semiconductor Inc.)
DRV - (mv61xxmm) – C:\WINDOWS\System32\drivers\mv61xxmm.sys (Marvell Semiconductor Inc.)
DRV - (cFosSpeed) – C:\WINDOWS\system32\drivers\cfosspeed.sys (cFos Software GmbH)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (SCDEmu) – C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (ISODrive) – C:\Program Files\UltraISO\drivers\ISODrive.sys (EZB Systems, Inc.)
DRV - (RT73) – C:\WINDOWS\system32\drivers\rt73.sys (Ralink Technology, Corp.)
DRV - (Scutum50) – C:\WINDOWS\system32\drivers\Scutum50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (VCSVADHWSer) Avnex Virtual Audio Device (WDM) – C:\WINDOWS\system32\drivers\vcsvad.sys (Avnex)
DRV - (TfSysMon) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfNetMon) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (TfFsMon) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (NMSCFG) – C:\WINDOWS\system32\drivers\NMSCFG.SYS (Intel Corporation)
DRV - (es1371) Creative AudioPCI (ES1371,ES1373) (WDM) – C:\WINDOWS\system32\drivers\es1371mp.sys (Creative Technology Ltd.)
DRV - (giveio) – C:\WINDOWS\system32\giveio.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?l=dis&o;=16794S
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B2 19 A5 54 5A F4 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..extensions.enabledItems: [removed]:3.3.5.1
FF - prefs.js..extensions.enabledItems: [removed]:1.7.3
FF - prefs.js..extensions.enabledItems: [removed]:5.90
FF - prefs.js..extensions.enabledItems: {3DB5ABE1-407D-458F-AD5D-8D89BD625CCC}:1.2.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.3.5.20110120033202
FF - prefs.js..extensions.enabledItems: {9c51bd27-6ed8-4000-a2bf-36cb95c0c947}:11.0.1
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.4
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.8
FF - prefs.js..extensions.enabledItems: {e6103d7b-6052-4575-a010-59037765e87a}:[removed]
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:5.0.0
FF - prefs.js..extensions.enabledItems: [removed]:2.5.3
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:0.2.7
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.7
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.66
FF - prefs.js..extensions.enabledItems: [removed]:1.1.1
FF - prefs.js..extensions.enabledItems: {e968fc70-8f95-4ab9-9e79-304de2a71ee1}:0.7.3
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.9
FF - prefs.js..extensions.enabledItems: {bb6bc1bb-f824-4702-90cd-35e2fb24f25d}:1.5.1
FF - prefs.js..keyword.URL: "http://flvtubesearch.co/?prt=flvtubetb02ff&Keywords;="
FF - prefs.js..network.proxy.ftp_port: 80
FF - prefs.js..network.proxy.gopher_port: 80
FF - prefs.js..network.proxy.http: "[removed]"
FF - prefs.js..network.proxy.http_port: 80
FF - prefs.js..network.proxy.socks_port: 80
FF - prefs.js..network.proxy.ssl_port: 80

FF - user.js..keyword.URL: "http://flvtubesearch.co/?prt=flvtubetb02ff&Keywords;="
FF - user.js..keyword.enabled: 1

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.46: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.46: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.46: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.10: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\npDisplayEngine: C:\Program Files\LivingPlay\nplplaypop.dll ( )
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/04/06 23:28:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/04/06 23:28:12 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2011/04/29 20:29:03 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn\ [2011/08/23 03:12:13 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/21 14:22:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/08/31 08:50:08 | 000,000,000 | —D | M]

[2011/05/24 20:41:26 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\matt\Application Data\Mozilla\Extensions
[2011/05/24 20:41:26 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\matt\Application Data\Mozilla\Extensions\[removed]
[2011/10/16 16:39:22 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions
[2011/06/21 13:04:38 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/07/18 12:07:56 | 000,000,000 | —D | M] (Flashblock) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2011/05/08 15:55:17 | 000,000,000 | —D | M] (Veehd Plugin) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{3DB5ABE1-407D-458F-AD5D-8D89BD625CCC}
[2011/08/17 22:53:08 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/05/08 16:04:25 | 000,000,000 | —D | M] (Tamper Data) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
[2011/08/16 17:46:21 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(2)
[2011/07/07 16:12:35 | 000,000,000 | —D | M] (Cookies Manager+) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25d}
[2011/07/07 06:29:22 | 000,000,000 | —D | M] (Web Developer) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2011/08/16 17:46:25 | 000,000,000 | —D | M] ("BetterPrivacy") – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}(2)
[2011/08/16 17:46:22 | 000,000,000 | —D | M] (Greasemonkey) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}(2)
[2011/08/16 17:46:23 | 000,000,000 | —D | M] (quixley_v2 Community Toolbar) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{e6103d7b-6052-4575-a010-59037765e87a}(2)
[2011/07/07 05:42:59 | 000,000,000 | —D | M] (User Agent Switcher) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2011/04/23 03:18:30 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\[removed]
[2011/06/21 13:04:58 | 000,000,000 | —D | M] (Firebug) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\[removed]
[2011/10/16 16:39:19 | 000,000,000 | —D | M] (Ghostery) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\[removed]
[2011/05/04 22:17:12 | 000,000,000 | —D | M] (FLV Blaster) – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\extensions\[removed]
[2011/06/10 21:28:27 | 000,002,568 | —- | M] () – C:\Documents and Settings\matt\Application Data\Mozilla\Firefox\Profiles\p6e9b870.default\searchplugins\askcom.xml
[2011/09/05 23:31:06 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/04/12 17:21:21 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/04/12 18:07:02 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/05/07 02:35:34 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/09/05 23:31:07 | 000,000,000 | —D | M] (FLVTube Toolbar) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/07/07 06:18:49 | 000,000,000 | —D | M] (LivingPlay TextLinks) – C:\DOCUMENTS AND SETTINGS\MATT\APPLICATION DATA\MOZILLA\EXTENSIONS\{EC8030F7-C20A-464F-9B0E-13A3A9E97384}\[removed]
() (No name found) – C:\DOCUMENTS AND SETTINGS\MATT\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\P6E9B870.DEFAULT\EXTENSIONS\{888D99E7-E8B5-46A3-851E-1EC45DA1E644}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\MATT\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\P6E9B870.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\MATT\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\P6E9B870.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
() (No name found) – C:\DOCUMENTS AND SETTINGS\MATT\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\P6E9B870.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\DOCUMENTS AND SETTINGS\MATT\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\P6E9B870.DEFAULT\EXTENSIONS\[removed]
[2011/04/12 17:21:01 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/12/21 14:22:54 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/04/14 04:08:00 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/05/13 17:58:48 | 002,418,176 | —- | M] (1 mal 1 Software GmbH) – C:\Program Files\mozilla firefox\plugins\NpFp530.dll
[2011/12/21 14:22:50 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/22 03:37:43 | 000,001,235 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\flvtube.xml

O1 HOSTS File: ([2011/04/19 21:54:50 | 000,001,274 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 adobe.activate.com
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\18.1.0.37\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (LivingPlay) - {D9291F9E-7010-4D7A-8DF6-455DEEF8EF51} - C:\Program Files\LivingPlay\lplaytl.dll ()
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (FlvTube Toolbar) - {851552F5-B878-4b03-904F-2AD6A4CC8994} - C:\Program Files\FlvTube Toolbar\flvtubetb.dll (FlvTube 2.6.0.0)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AlcWzrd] C:\WINDOWS\alcwzrd.exe (RealTek Semicoductor Corp.)
O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SoundMan.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized File not found
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O8 - Extra context menu item: Download with FLV Blaster - C:\Documents and Settings\matt\Application Data\FLV Blaster\Internet Explorer\script.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.15.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EBBAC1D3-9A89-4AC7-B78F-AF89E2DEA75A}: DhcpNameServer = 192.168.15.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/04/05 21:28:46 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk /r \??\C:)
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (Partizan)
O34 - HKLM BootExecute: (rentVersion\Explorer\MountPoints2\E\Shell\AutoRun\comma)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: UxTuneUp - C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.vorbis - C:\WINDOWS\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.X264 - C:\WINDOWS\System32\x264vfw.dll ()
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2011/12/22 04:16:00 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\matt\Desktop\OTL.exe
[2011/12/22 03:59:38 | 000,000,000 | —D | C] – C:\New Folder (2)
[2011/12/22 03:00:42 | 000,010,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\gameenum.sys
[2011/12/22 03:00:42 | 000,010,624 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\gameenum.sys
[2011/12/22 02:57:04 | 000,040,704 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\drivers\es1371mp.sys
[2011/12/22 02:57:04 | 000,040,704 | —- | C] (Creative Technology Ltd.) – C:\WINDOWS\System32\dllcache\es1371mp.sys
[2011/12/18 18:37:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Virtual Magnifying Glass
[2011/12/18 18:37:29 | 000,000,000 | —D | C] – C:\Program Files\Virtual Magnifying Glass
[2011/12/18 14:34:36 | 000,081,920 | —- | C] (Realtek Semiconductor Corp.) – C:\WINDOWS\ALCFDRTM.EXE
[2011/12/18 14:07:31 | 000,000,000 | —D | C] – C:\Program Files\Realtek AC97
[2011/12/18 06:10:48 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Real
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\matt\*.tmp files -> C:\Documents and Settings\matt\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/22 04:16:00 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\matt\Desktop\OTL.exe
[2011/12/22 03:42:30 | 000,504,722 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/12/22 03:42:30 | 000,088,848 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/12/22 03:37:27 | 000,000,000 | —- | M] () – C:\WINDOWS\385991325
[2011/12/22 03:37:26 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/22 03:03:59 | 000,000,724 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/12/22 02:06:36 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/21 12:00:01 | 000,000,438 | —- | M] () – C:\WINDOWS\tasks\FixCleaner Scan.job
[2011/12/20 23:08:07 | 000,081,920 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\ALCFDRTM.VER
[2011/12/20 18:13:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/12/18 18:37:32 | 000,000,799 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Virtual Magnifying Glass.lnk
[2011/12/18 14:34:36 | 000,081,920 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\ALCFDRTM.EXE
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\matt\*.tmp files -> C:\Documents and Settings\matt\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/18 18:37:32 | 000,000,799 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Virtual Magnifying Glass.lnk
[2011/12/18 14:27:55 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2011/09/01 16:46:13 | 000,272,909 | —- | C] () – C:\WINDOWS\PC Image Editor Uninstaller.exe
[2011/08/31 08:21:02 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2011/08/23 08:43:26 | 000,024,320 | —- | C] () – C:\WINDOWS\System32\drivers\rkhdrv40.sys
[2011/08/23 05:04:51 | 000,001,638 | —- | C] () – C:\WINDOWS\Sandboxie.ini
[2011/07/20 14:12:37 | 000,645,632 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2011/07/20 14:12:37 | 000,240,640 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2011/07/14 14:49:19 | 000,000,819 | —- | C] () – C:\WINDOWS\CoDUO.INI
[2011/07/14 14:24:21 | 000,037,336 | —- | C] () – C:\WINDOWS\System32\CleanMFT32.exe
[2011/07/14 13:52:16 | 000,000,036 | —- | C] () – C:\Documents and Settings\matt\Local Settings\Application Data\housecall.guid.cache
[2011/07/14 11:09:21 | 000,000,745 | —- | C] () – C:\WINDOWS\CoD.INI
[2011/07/08 22:43:00 | 000,000,203 | —- | C] () – C:\WINDOWS\GSdx9.INI
[2011/07/08 12:01:19 | 000,000,203 | —- | C] () – C:\WINDOWS\GSdx9 sse2.INI
[2011/06/14 01:58:20 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2011/06/13 13:38:55 | 000,182,275 | —- | C] () – C:\WINDOWS\System32\d3d10core.dll
[2011/06/13 13:38:55 | 000,124,931 | —- | C] () – C:\WINDOWS\System32\dxgi.dll
[2011/06/13 13:38:52 | 000,376,832 | —- | C] () – C:\WINDOWS\System32\M2000Twn.dll
[2011/06/13 13:38:49 | 000,728,858 | —- | C] () – C:\Program Files\Common Files\unins000.exe
[2011/06/13 13:38:49 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\CompressATI2.dll
[2011/06/13 13:38:49 | 000,003,005 | —- | C] () – C:\Program Files\Common Files\unins000.dat
[2011/05/31 11:30:07 | 000,000,171 | —- | C] () – C:\WINDOWS\icecast2.ini
[2011/05/31 09:52:25 | 000,715,038 | —- | C] () – C:\WINDOWS\unins000.exe
[2011/05/31 09:52:05 | 000,004,213 | —- | C] () – C:\WINDOWS\unins000.dat
[2011/05/30 21:19:36 | 000,000,016 | —- | C] () – C:\WINDOWS\popcinfo.dat
[2011/05/06 14:54:23 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/04/29 19:55:50 | 000,008,704 | —- | C] () – C:\Documents and Settings\matt\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/23 04:56:54 | 000,000,980 | —- | C] () – C:\WINDOWS\eReg.dat
[2011/04/21 20:03:42 | 000,230,752 | —- | C] () – C:\WINDOWS\patchw32.dll
[2011/04/21 20:03:41 | 000,118,176 | —- | C] () – C:\WINDOWS\patchw.dll
[2011/04/18 17:38:30 | 000,004,212 | -H– | C] () – C:\WINDOWS\System32\zllictbl.dat
[2011/04/13 15:44:06 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2011/04/08 21:04:58 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2011/04/07 15:20:49 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2011/04/06 07:49:03 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/04/06 07:23:13 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\DiagFunc.dll
[2011/04/06 07:23:13 | 000,001,191 | —- | C] () – C:\WINDOWS\System32\W32N55.INI
[2011/04/06 07:23:13 | 000,000,480 | —- | C] () – C:\WINDOWS\System32\DiagFunc.ini
[2011/04/06 07:22:11 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4764.dll
[2011/04/05 21:31:10 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/04/05 21:25:31 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/04/05 16:18:07 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/04/05 16:16:47 | 002,019,440 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/25 11:03:12 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2010/05/01 01:46:04 | 000,407,476 | —- | C] () – C:\WINDOWS\BOX_cFosTASK.exe
[2010/02/28 09:17:48 | 003,284,480 | —- | C] () – C:\WINDOWS\System32\x264vfw.dll
[2008/04/14 05:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/04/14 05:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 05:00:00 | 000,504,722 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/04/14 05:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 05:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 05:00:00 | 000,095,744 | —- | C] () – C:\WINDOWS\System32\msiexec.exe
[2008/04/14 05:00:00 | 000,088,848 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/04/14 05:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 05:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 05:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 05:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/04/14 05:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2008/04/14 05:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2002/03/26 07:36:48 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\PROInst.dll
[2002/02/06 08:04:14 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\NMSInst.dll
[1996/04/03 13:33:26 | 000,005,248 | —- | C] () – C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2011/06/15 12:23:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ableton
[2011/06/03 21:14:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM
[2011/10/16 22:20:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/08/23 04:28:55 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/08/12 07:41:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\firebird
[2011/08/13 23:40:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallMate
[2011/08/23 04:28:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/04/12 11:16:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nexon
[2011/05/13 07:29:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonUS
[2011/07/13 21:29:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PassMark
[2011/04/06 09:24:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCSettings
[2011/04/21 19:46:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2011/08/16 17:53:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Premium
[2011/04/06 07:23:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ralink Driver
[2011/12/22 03:37:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2011/06/13 14:07:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2011/06/13 13:55:24 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
[2011/05/24 20:01:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/08/23 02:36:23 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\.minecraft
[2011/06/15 12:23:05 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Ableton
[2011/06/03 21:16:19 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\acccore
[2011/05/27 12:47:01 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Avnex
[2011/08/27 09:24:00 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\BitLord
[2011/08/16 18:17:59 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Blender Foundation
[2011/04/06 07:04:49 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Blitware
[2011/04/06 23:29:45 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\DDMSettings
[2011/08/12 06:55:31 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\ElevatedDiagnostics
[2011/05/04 22:17:11 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\FLV Blaster
[2011/06/13 14:29:53 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\FrostWire
[2011/08/22 19:06:05 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\MWSE
[2011/05/13 07:30:04 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Paltalk
[2011/07/20 10:42:41 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Python-Eggs
[2011/07/14 14:34:50 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Registry Mechanic
[2011/05/24 21:38:40 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\rockbox.org
[2011/06/26 10:35:49 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\SecondLife
[2011/08/24 08:19:40 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\SystemRequirementsLab
[2011/06/13 12:51:52 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\TeamViewer
[2011/06/02 00:21:51 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\Titanium
[2011/08/19 20:30:32 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\tixati
[2011/08/16 17:49:42 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\tixati(3)
[2011/06/13 13:56:09 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\TuneUp Software
[2011/12/22 03:39:25 | 000,000,000 | —D | M] – C:\Documents and Settings\matt\Application Data\uTorrent
[2011/09/05 07:14:00 | 000,000,474 | —- | M] () – C:\WINDOWS\Tasks\Automatic Maintenance.job
[2011/12/21 12:00:01 | 000,000,438 | —- | M] () – C:\WINDOWS\Tasks\FixCleaner Scan.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/04/05 21:28:46 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/08/23 07:41:45 | 000,000,220 | -HS- | M] () – C:\boot.ini
[2011/04/05 21:28:46 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/07/13 16:25:43 | 000,001,209 | —- | M] () – C:\DV.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 07:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 07:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 07:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2011/08/21 01:57:53 | 000,000,460 | —- | M] () – C:\HelioS-Hook-v4.3.log
[2007/11/07 07:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 07:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 07:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 07:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 07:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 07:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 07:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 07:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 07:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 07:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 07:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2011/04/05 21:28:46 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/06/03 21:15:02 | 000,000,466 | -H– | M] () – C:\IPH.PH
[2011/04/05 21:28:46 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 05:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/12/22 03:37:15 | 1895,825,406 | -HS- | M] () – C:\pagefile.sys
[2011/07/08 05:00:10 | 000,008,412 | —- | M] () – C:\Pokemon Emerald.clt
[2011/09/05 23:13:16 | 000,005,595 | —- | M] () – C:\Setup Log.txt
[2011/08/31 08:52:11 | 000,001,946 | —- | M] () – C:\TDSSKiller.2.5.17.0_31.08.2011_09.52.09_log.txt
[2011/08/31 08:54:08 | 000,001,946 | —- | M] () – C:\TDSSKiller.2.5.17.0_31.08.2011_09.54.07_log.txt
[2011/08/31 08:54:46 | 000,001,946 | —- | M] () – C:\TDSSKiller.2.5.17.0_31.08.2011_09.54.45_log.txt
[2007/11/07 07:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 07:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 07:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2011/04/05 21:28:14 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >
[2008/02/12 18:57:48 | 000,000,047 | —- | M] () – C:\Documents and Settings\All Users\Favorites\DirectX10.url

< %APPDATA%\Microsoft\*.* >
[2011/04/05 21:42:09 | 000,001,754 | -H– | M] () – C:\Documents and Settings\matt\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2011/04/05 16:11:52 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2011/04/05 16:11:52 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2011/04/05 16:11:52 | 000,905,216 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/04/05 21:28:53 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/05 21:36:37 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\matt\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2011/04/05 21:36:37 | 000,000,079 | —- | M] () – C:\Documents and Settings\matt\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2007/07/10 16:35:54 | 000,142,336 | R— | M] () – C:\Documents and Settings\matt\Desktop\apt.exe
[2011/12/22 04:16:00 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\matt\Desktop\OTL.exe
[2011/08/17 10:35:02 | 004,768,032 | —- | M] () – C:\Documents and Settings\matt\Desktop\procexp.exe

< %PROGRAMFILES%\Common Files\*.* >
[2011/06/13 13:38:56 | 000,003,005 | —- | M] () – C:\Program Files\Common Files\unins000.dat
[2011/06/13 13:38:25 | 000,728,858 | —- | M] () – C:\Program Files\Common Files\unins000.exe

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >
[2003/06/13 16:23:00 | 000,004,304 | —- | M] () – C:\WINDOWS\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-05-29 08:00:53

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB25386$] -> Error: Cannot create file handle -> Unknown point type

========== Alternate Data Streams ==========

@Alternate Data Stream - 816 bytes -> C:\WINDOWS\385991325:1648230120.exe
@Alternate Data Stream - 177 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:76650B61

< End of report >

second file


OTL Extras logfile created on: 12/22/2011 4:18:52 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\matt\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1015.30 Mb Total Physical Memory | 489.04 Mb Available Physical Memory | 48.17% Memory free
14.65 Gb Paging File | 14.29 Gb Available in Paging File | 97.59% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 224.12 Gb Total Space | 50.98 Gb Free Space | 22.75% Space Free | Partition Type: NTFS
Drive D: | 8.74 Gb Total Space | 4.76 Gb Free Space | 54.41% Space Free | Partition Type: FAT32
Drive G: | 585.95 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: MATTHEW-B672D25 | User Name: matt | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
"DisableConfig" = 0
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"58221:TCP" = 58221:TCP:*:Enabled:Pando Media Booster
"58221:UDP" = 58221:UDP:*:Enabled:Pando Media Booster

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5353:TCP" = 5353:TCP:*:Enabled:Adobe CSI CS4
"58221:TCP" = 58221:TCP:*:Enabled:Pando Media Booster
"58221:UDP" = 58221:UDP:*:Enabled:Pando Media Booster

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"C:\Nexon\Combat Arms\Engine.exe" = C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\NGM\NGM.exe" = C:\NGM\NGM.exe:*:Enabled:Nexon Game Manager – (Nexon)
"C:\Nexon\Combat Arms\Engine.exe" = C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" = C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4 – (Adobe Systems Incorporated)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster – ()
"C:\Documents and Settings\matt\Local Settings\Temp\~osAD.tmp\opnsqr.exe" = C:\Documents and Settings\matt\Local Settings\Temp\~osAD.tmp\opnsqr.exe:*:Enabled:opnsqr.exe
"C:\Program Files\Phoenix Viewer\SLVoice.exe" = C:\Program Files\Phoenix Viewer\SLVoice.exe:*:Enabled:SLVoice – ()
"C:\Program Files\Phoenix Viewer\SLPlugin.exe" = C:\Program Files\Phoenix Viewer\SLPlugin.exe:*:Enabled:SLPlugin – ()
"C:\Program Files\SpacialAudio\SAMBC\SAMBC.exe" = C:\Program Files\SpacialAudio\SAMBC\SAMBC.exe:*:Enabled:SAMBC – ()
"C:\Program Files\Icecast2 Win32\Icecast2win.exe" = C:\Program Files\Icecast2 Win32\Icecast2win.exe:*:Enabled:Icecast2win – ()
"C:\Program Files\VirtualDJ\virtualdj_pro.exe" = C:\Program Files\VirtualDJ\virtualdj_pro.exe:*:Enabled:VirtualDJ – (Atomix Productions)
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AIM – (AOL Inc.)
"C:\Program Files\SHOUTcast\sc_serv.exe" = C:\Program Files\SHOUTcast\sc_serv.exe:*:Enabled:sc_serv – ()
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\TeamViewer\Version6\TeamViewer.exe" = C:\Program Files\TeamViewer\Version6\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application – (TeamViewer GmbH)
"C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe" = C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service – (TeamViewer GmbH)
"C:\Program Files\2K Games\Firaxis Games\Sid Meier's Civilization 4 Complete\Civilization4.exe" = C:\Program Files\2K Games\Firaxis Games\Sid Meier's Civilization 4 Complete\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4 Complete – (Firaxis Games)
"C:\Program Files\2K Games\Firaxis Games\Sid Meier's Civilization 4 Complete\Warlords\Civ4Warlords.exe" = C:\Program Files\2K Games\Firaxis Games\Sid Meier's Civilization 4 Complete\Warlords\Civ4Warlords.exe:*:Enabled:Sid Meier's Civilization 4: Warlords – (Firaxis Games)
"C:\Program Files\2K Games\Firaxis Games\Sid Meier's Civilization IV Colonization\Colonization.exe" = C:\Program Files\2K Games\Firaxis Games\Sid Meier's Civilization IV Colonization\Colonization.exe:*:Enabled:Sid Meier's Civilization IV Colonization – (Firaxis Games)
"C:\Documents and Settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe" = C:\Documents and Settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe:*:Enabled:Yahoo Auto Updater – (Yahoo! Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Xvid\autoupdate-windows.exe" = C:\Program Files\Xvid\autoupdate-windows.exe:*:Enabled:autoupdate-windows – (Xvid Team)
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Program Files\cFosSpeed\cfosspeed.exe" = C:\Program Files\cFosSpeed\cfosspeed.exe:*:Enabled:cFosSpeed Window – (cFos Software GmbH)
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Windows Explorer – (Microsoft Corporation)
"C:\Program Files\Call of Duty\CoDUOMP.exe" = C:\Program Files\Call of Duty\CoDUOMP.exe:*:Enabled:CoDUOMP – ()
"C:\Documents and Settings\matt\My Documents\Downloads\Codec-C.exe" = C:\Documents and Settings\matt\My Documents\Downloads\Codec-C.exe:*:Enabled:Installer – (Premium)
"C:\Program Files\tixati\tixati.exe" = C:\Program Files\tixati\tixati.exe:*:Enabled:tixati – ()
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\Documents and Settings\matt\Application Data\Real\Update\UpgradeHelper\RealPlayer\8.01\rnupgagent.exe" = C:\Documents and Settings\matt\Application Data\Real\Update\UpgradeHelper\RealPlayer\8.01\rnupgagent.exe:*:Enabled:RealNetworks Installer
"C:\Program Files\DivX\DivX Plus Web Player\DDMService.exe" = C:\Program Files\DivX\DivX Plus Web Player\DDMService.exe:*:Enabled:DivX Download Manager Service – (DivX, LLC)
"C:\Program Files\Phoenix Viewer\PhoenixViewer.exe" = C:\Program Files\Phoenix Viewer\PhoenixViewer.exe:*:Enabled:Phoenix Viewer – (Phoenix Viewer)
"C:\Documents and Settings\matt\My Documents\BitLord\Rulers.Of.Nations.Geopolitical.Simulator.2.PC.Game(djDEVASTATE™)\Rulers.Of.Nations.Geopolitical.Simulator.2.PC.Game(djDEVASTATE™)\_start.exe" = C:\Documents and Settings\matt\My Documents\BitLord\Rulers.Of.Nations.Geopolitical.Simulator.2.PC.Game(djDEVASTATE™)\Rulers.Of.Nations.Geopolitical.Simulator.2.PC.Game(djDEVASTATE™)\_start.exe:*:Enabled:_start – ()
"C:\Documents and Settings\matt\My Documents\Downloads\MicrosoftFixit.AudioPlayback.Run.exe" = C:\Documents and Settings\matt\My Documents\Downloads\MicrosoftFixit.AudioPlayback.Run.exe:*:Enabled:Microsoft Fix it – (Microsoft Corporation)
"C:\Documents and Settings\matt\Local Settings\Temp\~nsu.tmp\Au_.exe" = C:\Documents and Settings\matt\Local Settings\Temp\~nsu.tmp\Au_.exe:*:Enabled:Yahoo! Toolbar Uninstall Setup
"C:\Program Files\BitLord 1.2\Bitlord files\bitlord.exe" = C:\Program Files\BitLord 1.2\Bitlord files\bitlord.exe:*:Enabled:BitLord – ()
"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\WINDOWS\system32\dxdiag.exe" = C:\WINDOWS\system32\dxdiag.exe:*:Enabled:Microsoft DirectX Diagnostic Tool – (Microsoft Corporation)
"C:\Documents and Settings\matt\Desktop\downloads\Unreal Tournament\UnrealTournament\System\UnrealTournament.exe" = C:\Documents and Settings\matt\Desktop\downloads\Unreal Tournament\UnrealTournament\System\UnrealTournament.exe:*:Enabled:UnrealTournament – ()
"C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe" = C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe:*:Enabled:Adobe Updater – (Adobe Systems Incorporated)
"C:\Program Files\Driver-Soft\DriverGenius\DriverGenius.exe" = C:\Program Files\Driver-Soft\DriverGenius\DriverGenius.exe:*:Enabled:Driver Genius Professional Edition – (Driver-Soft Inc.)
"C:\Program Files\UnHackMe\GWebUpdate.exe" = C:\Program Files\UnHackMe\GWebUpdate.exe:*:Enabled:Web Update component – (Greais Software)
"C:\Program Files\UnHackMe\reanimator.exe" = C:\Program Files\UnHackMe\reanimator.exe:*:Enabled:RegRun Start Control – ()
"C:\Program Files\TuneUp Utilities 2011\UpdateWizard.exe" = C:\Program Files\TuneUp Utilities 2011\UpdateWizard.exe:*:Enabled:TuneUp Update Wizard – (TuneUp Software)
"C:\Program Files\Belarc\Advisor\BelarcAdvisor.exe" = C:\Program Files\Belarc\Advisor\BelarcAdvisor.exe:*:Enabled:Belarc Advisor Computer Inventory – (Belarc, Inc.)
"C:\Program Files\CPUID\HWMonitorPro\HWMonitorPro.exe" = C:\Program Files\CPUID\HWMonitorPro\HWMonitorPro.exe:*:Enabled:Hardware Monitor Pro
"C:\Documents and Settings\matt\My Documents\Downloads\SoftonicDownloader_for_process-killer.exe" = C:\Documents and Settings\matt\My Documents\Downloads\SoftonicDownloader_for_process-killer.exe:*:Enabled:SoftonicDownloader_for_process-killer – ()
"C:\Documents and Settings\matt\Local Settings\Temp\Rar$EX50.968\NPE.exe" = C:\Documents and Settings\matt\Local Settings\Temp\Rar$EX50.968\NPE.exe:*:Enabled:Norton Power Eraser
"C:\Documents and Settings\matt\My Documents\Downloads\NPE.exe" = C:\Documents and Settings\matt\My Documents\Downloads\NPE.exe:*:Enabled:Norton Power Eraser – ()
"C:\Documents and Settings\matt\Local Settings\Temp\Rar$EX06.376\NPE.exe" = C:\Documents and Settings\matt\Local Settings\Temp\Rar$EX06.376\NPE.exe:*:Enabled:Norton Power Eraser
"C:\Documents and Settings\matt\Local Settings\Temp\Rar$EX53.376\NPE.exe" = C:\Documents and Settings\matt\Local Settings\Temp\Rar$EX53.376\NPE.exe:*:Enabled:Norton Power Eraser
"C:\Documents and Settings\matt\Local Settings\Temp\7zS1.tmp\avgmfapx.exe" = C:\Documents and Settings\matt\Local Settings\Temp\7zS1.tmp\avgmfapx.exe:*:Enabled:AVG Installer Application
"C:\Documents and Settings\All Users\Application Data\MFAData\SelfUpd\avgmfapx.exe" = C:\Documents and Settings\All Users\Application Data\MFAData\SelfUpd\avgmfapx.exe:*:Enabled:AVG Installer Application – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\ThreatFire\TFTray.exe" = C:\Program Files\ThreatFire\TFTray.exe:*:Enabled:PC Tools ThreatFire Tray App – (PC Tools)
"C:\Program Files\Apple Software Update\SoftwareUpdate.exe" = C:\Program Files\Apple Software Update\SoftwareUpdate.exe:*:Enabled:Apple Software Update – (Apple Inc.)
"C:\Program Files\Defcon\defcon.exe" = C:\Program Files\Defcon\defcon.exe:*:Enabled:Defcon – (Introversion Software)
"C:\Documents and Settings\matt\Local Settings\Temp\Rar$EX39.120\aida32.bin" = C:\Documents and Settings\matt\Local Settings\Temp\Rar$EX39.120\aida32.bin:*:Enabled:AIDA32 - Worldwide SysInfo Tool
"C:\Documents and Settings\matt\My Documents\Downloads\utorrent.exe" = C:\Documents and Settings\matt\My Documents\Downloads\utorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Norton AntiVirus\Engine\18.1.0.37\hsplayer.exe" = C:\Program Files\Norton AntiVirus\Engine\18.1.0.37\hsplayer.exe:*:Enabled:Norton Premium Services & One Click Support Player – (Symantec Corporation)
"E:\SETUP.EXE" = E:\SETUP.EXE:*:Enabled:SETUP
"C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" = C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe:*:Enabled:Malwarebytes' Anti-Malware – ()
"C:\Documents and Settings\matt\Desktop\tdsskiller.exe" = C:\Documents and Settings\matt\Desktop\tdsskiller.exe:*:Enabled:TDSS rootkit removing tool
"C:\Documents and Settings\matt\Desktop\1234.com" = C:\Documents and Settings\matt\Desktop\1234.com:*:Enabled:TDSS rootkit removing tool
"C:\Documents and Settings\matt\My Documents\Downloads\SkypeSetup.exe" = C:\Documents and Settings\matt\My Documents\Downloads\SkypeSetup.exe:*:Enabled:Skype – (Skype Technologies S.A.)
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" = C:\Program Files\AVAST Software\Avast\AvastUI.exe:*:Enabled:avast! Antivirus
"C:\Program Files\AVAST Software\Avast\Setup\avast.setup" = C:\Program Files\AVAST Software\Avast\Setup\avast.setup:*:Enabled:avast! antivirus Update
"C:\Program Files\FixCleaner\FixCleaner.exe" = C:\Program Files\FixCleaner\FixCleaner.exe:*:Enabled:FixCleaner – ()
"C:\Program Files\DivX\DivX Update\DivXUpdate.exe" = C:\Program Files\DivX\DivX Update\DivXUpdate.exe:*:Enabled:DivX Update – ()
"C:\Program Files\Adobe Media Player\Adobe Media Player.exe" = C:\Program Files\Adobe Media Player\Adobe Media Player.exe:*:Enabled:Adobe Media Player – ()
"C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe" = C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe:*:Enabled:Adobe AIR Installer – ()
"C:\Documents and Settings\admin\My Documents\Downloads\utorrent.exe" = C:\Documents and Settings\admin\My Documents\Downloads\utorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Documents and Settings\admin\Local Settings\Temp\nskC.tmp\ymsgr_suite_setup.exe" = C:\Documents and Settings\admin\Local Settings\Temp\nskC.tmp\ymsgr_suite_setup.exe:*:Enabled:Yahoo! Messenger Setup
"C:\Documents and Settings\admin\Local Settings\Temp\GLB11.tmp" = C:\Documents and Settings\admin\Local Settings\Temp\GLB11.tmp:*:Enabled:Yahoo! Messenger
"C:\Documents and Settings\admin\Local Settings\Temp\nsk23.tmp\ytb_setup.exe" = C:\Documents and Settings\admin\Local Settings\Temp\nsk23.tmp\ytb_setup.exe:*:Enabled:Yahoo! Toolbar Setup
"C:\Documents and Settings\admin\My Documents\Downloads\msgr11us.exe" = C:\Documents and Settings\admin\My Documents\Downloads\msgr11us.exe:*:Enabled:Yahoo! Messenger Suite Install Bootstrapper Setup – (Yahoo! Inc.)
"C:\Documents and Settings\admin\Local Settings\Temp\_ir_sf_temp_0\apl-freecorder-dtx.exe" = C:\Documents and Settings\admin\Local Settings\Temp\_ir_sf_temp_0\apl-freecorder-dtx.exe:*:Enabled:Freecorder Toolbar – ()
"C:\Documents and Settings\admin\Local Settings\Temp\_ir_sf_temp_0\irsetup.exe" = C:\Documents and Settings\admin\Local Settings\Temp\_ir_sf_temp_0\irsetup.exe:*:Enabled:Setup Application
"C:\Program Files\Freecorder\FLVPlayer.exe" = C:\Program Files\Freecorder\FLVPlayer.exe:*:Enabled:FLVPlayer – ()
"C:\Documents and Settings\admin\My Documents\Downloads\FLVDirect.exe" = C:\Documents and Settings\admin\My Documents\Downloads\FLVDirect.exe:*:Enabled:FLV Pro Player Installer – (Design and Marketing D.M. S.A.)
"C:\Program Files\DownloadToolz\Xnxx Video Downloader\xnxx_d.exe" = C:\Program Files\DownloadToolz\Xnxx Video Downloader\xnxx_d.exe:*:Enabled:xnxx_d – (DownloadToolz, Inc.)
"C:\Program Files\DivX\DivX Plus Player\DivX Plus Player.exe" = C:\Program Files\DivX\DivX Plus Player\DivX Plus Player.exe:*:Enabled:DivX Plus Player – ()
"C:\Documents and Settings\admin\Application Data\Real\Update\UpgradeHelper\RealPlayer\8.01\rnupgagent.exe" = C:\Documents and Settings\admin\Application Data\Real\Update\UpgradeHelper\RealPlayer\8.01\rnupgagent.exe:*:Enabled:RealNetworks Installer
"C:\Program Files\Mozilla Firefox\abcd.exe" = C:\Program Files\Mozilla Firefox\abcd.exe:*:Enabled:Firefox
"C:\Program Files\Mozilla Firefox\abcd.exe.exe" = C:\Program Files\Mozilla Firefox\abcd.exe.exe:*:Enabled:Firefox – (Mozilla Corporation)
"C:\Documents and Settings\matt\Application Data\Real\Update\UpgradeHelper\RealPlayer\9.00\rnupgagent.exe" = C:\Documents and Settings\matt\Application Data\Real\Update\UpgradeHelper\RealPlayer\9.00\rnupgagent.exe:*:Enabled:RealNetworks Installer – (RealNetworks, Inc.)
"C:\Documents and Settings\admin\Application Data\Real\Update\UpgradeHelper\RealPlayer\9.00\rnupgagent.exe" = C:\Documents and Settings\admin\Application Data\Real\Update\UpgradeHelper\RealPlayer\9.00\rnupgagent.exe:*:Enabled:RealNetworks Installer – ()
"C:\Documents and Settings\matt\Local Settings\Temp\is-7879P.tmp\ApnStub.exe" = C:\Documents and Settings\matt\Local Settings\Temp\is-7879P.tmp\ApnStub.exe:*:Disabled:AskStub Application – (Ask.com)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{01A4AEDE-F219-49A2-B855-16A016EAF9A4}" = Intel® PROSet II
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F2DF2C6-08F7-40BD-8E85-D16CB436E7F0}" = Free NaturalReader
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{23BE4DF2-293D-4077-82F4-1FD8C269277C}" = TuneUp Utilities Language Pack (en-US)
"{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}" = TuneUp Utilities 2011
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 25
"{26DB09BC-6EB5-4CE0-A05D-D4DECE60E189}_is1" = Phoenix Viewer 1.5.2.1185
"{2A9A40C7-6670-4D5F-8F41-D12E2E08B48B}" = Star Wars®: Knights of the Old Republic ™
"{2E295B5B-1AD4-4d36-97C2-A316084722CF}" = Python 2.7.2
"{30D1F3D2-54CF-481D-A005-F94B0E98FEEC}" = Sid Meier's Civilization 4 Complete
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{32E4F0D2-C135-475E-A841-1D59A0D22989}" = Sid Meier's Civilization 4 - Beyond the Sword
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{394BE3D9-7F57-4638-A8D1-1D88671913B7}" = Microsoft AppLocale
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F5CE00D-82D7-4BDB-868E-F5FA2D2740E5}" = Intel Processor Diagnostic Tool
"{502499DC-2EDB-45A2-8F7C-83E6E5DE067E}" = ILLUSION ジンコウガクエン きゃらめいく
"{5290930D-C6D8-4EDB-98ED-7E025E65CAFF}" = Vampire Realism II
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{66F0AC35-4805-44BC-A3D4-347D4196F9B3}" = Microsoft Xbox 360 Accessories 1.1
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7A65E382-1843-4B46-861B-1BECB8354911}" = Falcon 4.0: Allied Force
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87EAFB9D-12C2-40E1-80F7-576470011DAD}" = FLV Blaster 5.90
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A662E280-64A8-4CF5-8407-13D0808602B3}" = Call of Duty - United Offensive
"{A8D93648-9F7F-407D-915C-62044644C3DA}" = MSI to redistribute MS VS2005 CRT libraries
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.0)
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C109AF5B-69D0-4C93-B360-F28D9FAB6084}" = ILLUSION ジンコウガクエン
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C325F588-D6B1-4A7F-B6A2-914C75DDA348}" = Morrowind
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DB3C800B-081B-4146-B4E3-EFB5B77AA913}" = TES Construction Set
"{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb" = Microsoft Windows Application Compatibility Database
"{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E91E8912-769D-42F0-8408-0E329443BABC}" = Ralink RT7x Wireless LAN Card
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EF36A836-BF89-4A4F-B079-057B0C68C1E0}" = Sid Meier's Civilization IV Colonization
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4F7F393-A8E8-42CC-8C2E-7A999B48B2AE}_is1" = DirectX10 LV (Last Version)
"{F59A9E08-A6A4-4ACF-91F2-D0344956C30B}" = iTunes
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"3554AA4B-9B0B-451a-A269-2B5F53982209_is1" = ThreatFire 4.0
"AC3File_is1" = AC3File 0.7b
"AC3Filter_is1" = AC3Filter 1.63b
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4
"AIM_7" = AIM 7
"ASIO4ALL" = ASIO4ALL
"Avidemux 2.5" = Avidemux 2.5 (32-bit)
"Bejeweled 2 Deluxe" = Bejeweled 2 Deluxe
"Belarc Advisor" = Belarc Advisor 8.2
"BitLord" = BitLord 1.2
"Cain & Abel v4.9.40" = Cain & Abel v4.9.40
"Call of Duty" = Call of Duty
"cFosSpeed" = cFosSpeed v6.00
"CPUID HWMonitorPro_is1" = CPUID HWMonitor Pro 1.12
"Defcon_is1" = Defcon
"DivX Setup.divx.com" = DivX Setup
"Driver Genius Professional Edition_is1" = Driver Genius Professional Edition
"F3B506E1FDAEA4DC6669B53B2D3F0B68FBA20C2D" = Windows Driver Package - AMD System (04/06/2006 1.0.1.0)
"FBDBServer_2_5_is1" = Firebird 2.5.0.26074 (Win32)
"FixCleaner_is1" = FixCleaner 2.0.4251
"FL Studio 9" = FL Studio 9
"FlashWAmp_is1" = FlashWAmp 1.1
"Flatcast Producer 5.3_is1" = Flatcast Producer Plugin 5.3.0.752
"FLV Pro Player" = FLV Pro Player
"FlvTube Toolbar" = FlvTube Toolbar
"Focus Magic_is1" = Focus Magic 3.02
"Freecorder5.04" = Freecorder 5
"Freemake Video Converter_is1" = Freemake Video Converter version 2.2.0
"HDMI" = Intel® Graphics Media Accelerator Driver
"Homepage Protection Service" = Homepage Protection Service
"Icecast2 Win32_is1" = Icecast 2.3.2
"IL Download Manager" = IL Download Manager
"InstallShield_{A662E280-64A8-4CF5-8407-13D0808602B3}" = Call of Duty - United Offensive
"JAIELangPack" = Japanese Language Support
"Live 8.1.1" = Live 8.1.1
"LivingPlay" = LivingPlay
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"MegaTrainer eXperience_is1" = MegaTrainer eXperience V1.0.4.4
"MegaTrainer XL_is1" = MegaTrainer XL V1.5.5.5-Beta
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Firefox 7.0.1 (x86 en-US)" = Mozilla Firefox 7.0.1 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NAV" = Norton AntiVirus
"NirSoft VideoCacheView" = NirSoft VideoCacheView
"PC Image Editor" = PC Image Editor
"Pcsx2_is1" = Pcsx2 0.9.1 Watermoose
"pcsx2-r3878" = PCSX2 - Playstation 2 Emulator
"Perfect Uninstaller_is1" = Perfect Uninstaller v6.3.3.9
"PerformanceTest 7_is1" = PerformanceTest v7.0
"PoiZone" = PoiZone
"PowerISO" = PowerISO
"Process Killer_is1" = Process Killer 2.0.1
"PROSet" = Intel® Network Connections Drivers
"RealPlayer 6.0" = RealPlayer
"Registry Mechanic_is1" = Registry Mechanic 10.0
"RKU" = Rootkit Unhooker Uninstall
"romcenter_is1" = RomCenter 3.58
"SAM3" = SAM Broadcaster (remove only)
"Sandboxie" = Sandboxie 3.56 (32-bit)
"SCDNAS" = SHOUTcast DNAS (remove only)
"SHOUTcast" = SHOUTcast DNAS Server v2
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SpeedFan" = SpeedFan (remove only)
"TeamViewer 6" = TeamViewer 6
"tixati" = Tixati
"TuneUp Utilities 2011" = TuneUp Utilities 2011
"UltraISO_is1" = UltraISO Premium V9.36
"UnHackMe_is1" = UnHackMe 5.99 release
"uTorrent" = µTorrent
"Virtual Magnifying Glass_is1" = Virtual Magnifying Glass v3.5
"VLC media player" = VLC media player 1.1.10
"Wdf01001" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.1
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinGimp-2.0_is1" = GIMP 2.6.11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinPcapInst" = WinPcap 3.0
"WinRAR archiver" = WinRAR 4.00 (32-bit)
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XBCD" = XBCD 1.07
"Xnxx Video Downloader_is1" = Xnxx Video Downloader 3.11
"Xvid Video Codec 1.3.2" = Xvid Video Codec
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/19/2011 4:20:56 PM | Computer Name = MATTHEW-B672D25 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 12/19/2011 4:20:56 PM | Computer Name = MATTHEW-B672D25 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 12/19/2011 4:20:57 PM | Computer Name = MATTHEW-B672D25 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 12/19/2011 4:20:57 PM | Computer Name = MATTHEW-B672D25 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 12/19/2011 4:20:57 PM | Computer Name = MATTHEW-B672D25 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 12/19/2011 4:20:57 PM | Computer Name = MATTHEW-B672D25 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 12/19/2011 4:20:57 PM | Computer Name = MATTHEW-B672D25 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: 12175 (0x2f8f)

Error - 12/19/2011 4:20:57 PM | Computer Name = MATTHEW-B672D25 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The specified server cannot perform the requested operation.

Error - 12/20/2011 3:12:19 PM | Computer Name = MATTHEW-B672D25 | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 80080005 from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

Error - 12/22/2011 4:20:05 AM | Computer Name = MATTHEW-B672D25 | Source = EventSystem | ID = 4609
Description = The COM+ Event System detected a bad return code during its internal
processing. HRESULT was 80080005 from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp.
Please contact Microsoft Product Support Services to report this erro

[ System Events ]
Error - 12/20/2011 10:05:45 AM | Computer Name = MATTHEW-B672D25 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/20/2011 10:26:25 AM | Computer Name = MATTHEW-B672D25 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/20/2011 10:26:29 AM | Computer Name = MATTHEW-B672D25 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/20/2011 10:47:37 AM | Computer Name = MATTHEW-B672D25 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/20/2011 10:48:50 AM | Computer Name = MATTHEW-B672D25 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/20/2011 11:07:56 AM | Computer Name = MATTHEW-B672D25 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/20/2011 11:08:10 AM | Computer Name = MATTHEW-B672D25 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/20/2011 11:28:18 AM | Computer Name = MATTHEW-B672D25 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/20/2011 11:28:22 AM | Computer Name = MATTHEW-B672D25 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

Error - 12/20/2011 11:48:46 AM | Computer Name = MATTHEW-B672D25 | Source = Service Control Manager | ID = 7023
Description = The Network Location Awareness (NLA) service terminated with the following
error: %%127

[ Windows PowerShel Events ]
Error - 12/19/2011 4:20:56 PM | Computer Name = MATTHEW-B672D25 | Source = crypt32 | ID = 131080
Description =

Error - 12/19/2011 4:20:56 PM | Computer Name = MATTHEW-B672D25 | Source = crypt32 | ID = 131080
Description =

Error - 12/19/2011 4:20:57 PM | Computer Name = MATTHEW-B672D25 | Source = crypt32 | ID = 131080
Description =

Error - 12/19/2011 4:20:57 PM | Computer Name = MATTHEW-B672D25 | Source = crypt32 | ID = 131080
Description =

Error - 12/19/2011 4:20:57 PM | Computer Name = MATTHEW-B672D25 | Source = crypt32 | ID = 131080
Description =

Error - 12/19/2011 4:20:57 PM | Computer Name = MATTHEW-B672D25 | Source = crypt32 | ID = 131080
Description =

Error - 12/19/2011 4:20:57 PM | Computer Name = MATTHEW-B672D25 | Source = crypt32 | ID = 131080
Description =

Error - 12/19/2011 4:20:57 PM | Computer Name = MATTHEW-B672D25 | Source = crypt32 | ID = 131080
Description =

Error - 12/20/2011 3:12:19 PM | Computer Name = MATTHEW-B672D25 | Source = EventSystem | ID = 4609
Description =

Error - 12/22/2011 4:20:05 AM | Computer Name = MATTHEW-B672D25 | Source = EventSystem | ID = 4609
Description =


< End of report >
Hi there you have the zero access rootkit

This is cleanable but it can do a lot of damage in some cases : Allow combofix to install the recovery console when it asks

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.

  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    [external image: Posted Image]

    [external image: Posted Image]
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
well it went all the way to the output folder area (Output folder: C\32788R22FWJFW) Wellll i was going to take a screen shot but paint wont open ><. but it pretty much looks like the pic in your first post and its not doing anything. its still open right now
OK using task manager stop Combofix.

Run this small OTL fix and then retry combofix please

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    @Alternate Data Stream - 816 bytes -> C:\WINDOWS\385991325:1648230120.exe

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
OK methinks you may have a new variant - as they normally go quietly

Download AVPTool from Here to your desktop

Run the programme you have just downloaded to your desktop (it will be randomly named )

First we will run a virus scan

Click the cog in the upper right
[external image: Posted Image]


Select down to and including your main drive, once done select the Automatic scan tab and press Start Scan
[external image: Posted Image]

Allow AVP to delete all infections found
Once it has finished select report tab (last tab)
Select Detected threats report from the left and press Save button
Save it to your desktop and attach to your next post


Now the Analysis

Rerun AVP and select the Manual Disinfection tab and press Start Gathering System Information

[external image: Posted Image]

On completion click the link to locate the zip file to upload and attach to your next post

[external image: Posted Image]
Megaupload
another no go. (Please try to reboot your computer. Error message is Failed to exrtact the product into C:\DOCUME~1\matt\LOCALS~1\Temp\3728346, error is 193
Can you burn a CD ?

Please download the following programmes to your desktop:

Dr Web Live CD

ImgBurn

Install IMGBurn
  • Double click Dr Web
  • IMGBurn will open
  • Burn the ISO to a cd
  • Reboot the infected computer with the CD in the drive
  • Ensure that the first boot device is CD - If you are not sure about that then see this page for instructions
  • As loading starts, a dialogue window will prompt you to choose between the standard and safe modes.

    [external image: Posted Image]
  • Use arrow keys to select DrWeb-LiveCD (Default)
  • When the system is loaded, check the disks or folders you want to scan, and click on “Start”.

    [external image: Posted Image]
  • The programme will now scan for and cure/delete any malware that it finds. Allow it to do so
  • Once completed reboot to normal windows
  • No log is produced so once in normal windows run a fresh OTL scan and let me know if the problems persist
No i cant. i have a windows XP cd that i could have used along time ago to just reformat the drive. but the cd drive will not read anything in it. and it dosent even show that their is anything in it. :(
Hmm this is really limiting our options

One last chance - as without access to USB or CD I am very limited

Download Dr.Web CureIt to the desktop.
  • Doubleclick the drweb-cureit.exe file, then on Start and allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, chose the Complete Scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow [external image: Posted Image] at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look and see if you can click the following icon next to the files found:
    [external image: Posted Image]
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    [external image: Posted Image]
  • This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer to allow files that were in use to be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply along with a new OTL log.
NOTE: During the scan, a pop-up window will open asking for full version purchase. Simply close the window by clicking on X in upper right corner.
ok well i had to use Internet Explorer since i get an error trying to download anything with firefox now. my guess is that when i tryed that other program the virus made the temp folder inaccessible >< (C:\DOCUME~1\matt\LOCALS~1\Temp\1YZ8XNCY.exe.part could not be saved, becuase you cannot changethe contents of that folder Change the folder properties and try again, or try saveing in a different location) i will try the Dr.Web CureIt once its done downloading

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI