This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan.BHO

35 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi James,

Let's have another look but with a different tool. :)

  • Download OTL to your desktop.
  • Right-click and Run as Administrator on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
HI Jeff:


OTL.TXT output file:

OTL logfile created on: 11/4/2011 9:27:36 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Admin\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.99 Gb Total Physical Memory | 3.74 Gb Available Physical Memory | 62.43% Memory free
12.09 Gb Paging File | 9.68 Gb Available in Paging File | 80.06% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 688.87 Gb Total Space | 38.59 Gb Free Space | 5.60% Space Free | Partition Type: NTFS
Drive I: | 245.73 Mb Total Space | 238.26 Mb Free Space | 96.96% Space Free | Partition Type: FAT

Computer Name: ADMIN-PC | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Admin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
PRC - C:\Windows\SysWOW64\cfgmig32.exe ()
PRC - C:\Windows\SysWOW64\svcprs32.exe ()
PRC - C:\Windows\SysWOW64\mdmcls32.exe ()
PRC - C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrvProxy.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrvProxy.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Windows\mHotkey.exe ()
PRC - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Windows\CNYHKey.exe (Creative)
PRC - C:\Windows\ChiFuncExt.exe (Chicony)
PRC - C:\Windows\ModLEDKey.exe (Chicony)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Windows\SysWOW64\winsflt.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL ()
MOD - C:\Windows\mHotkey.exe ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (CAAMSvc) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\CAAMSvc.exe (CA)
SRV:64bit: - (CaCCProvSP) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
SRV:64bit: - (ccSchedulerSVC) – C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe (Computer Associates International, Inc.)
SRV:64bit: - (CAISafe) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe (Computer Associates International, Inc.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (UmxEngine) – C:\Program Files\CA\SharedComponents\TMEngine\UmxEngine.exe (CA)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (AgereModemAudio) – C:\Windows\SysNative\agr64svc.exe (Agere Systems)
SRV:64bit: - (ETService) – C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (NAUpdate) – C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
SRV - (WinSvchostManagerSrv) – C:\Windows\SysWOW64\cfgmig32.exe ()
SRV - (WinSvchostManager) – C:\Windows\SysWOW64\svcprs32.exe ()
SRV - (WinExtManager) – C:\Windows\SysWOW64\mdmcls32.exe ()
SRV - (SpeedDiskService) – C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe (Symantec Corporation)
SRV - (DiskDoctorService) – C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe (Symantec Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (GoToAssist) – C:\Program Files (x86)\Citrix\GoToAssist\615\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SupportSoft RemoteAssist) – C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe (SupportSoft, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (CTAudSvcService) – C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (Symantec RemoteAssist) – C:\Program Files (x86)\Common Files\Symantec Shared\Support Controls\ssrc.exe (Symantec, Inc.)
SRV - (Symantec Core LC) – C:\Program Files (x86)\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (EPSON_EB_RPCV4_01) EPSON V5 Service4(01) – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE (SEIKO EPSON CORPORATION)
SRV - (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (SEIKO EPSON CORPORATION)


========== Driver Services (SafeList) ==========

DRV:64bit: - (atikmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\DRIVERS\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (KmxCF) – C:\Windows\SysNative\DRIVERS\KmxCF.sys (CA)
DRV:64bit: - (KmxCfg) – C:\Windows\SysNative\DRIVERS\kmxcfg.sys (CA)
DRV:64bit: - (KmxAMRT) – C:\Windows\SysNative\DRIVERS\KmxAMRT.sys (CA)
DRV:64bit: - (KmxAgent) – C:\Windows\SysNative\DRIVERS\kmxagent.sys (CA)
DRV:64bit: - (KmxFile) – C:\Windows\SysNative\DRIVERS\KmxFile.sys (CA)
DRV:64bit: - (KmxSbx) – C:\Windows\SysNative\DRIVERS\KmxSbx.sys (CA)
DRV:64bit: - (KmxFw) – C:\Windows\SysNative\DRIVERS\kmxfw.sys (CA)
DRV:64bit: - (KmxFilter) – C:\Windows\SysNative\DRIVERS\KmxFilter.sys (CA)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\Drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (SymDSMon) – C:\Windows\SysNative\drivers\SymDSMon.sys (Symantec Corporation)
DRV:64bit: - (SYMSpeedDisk) – C:\Windows\SysNative\drivers\SymSpeedDisk.sys (Symantec Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\DRIVERS\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (AgereSoftModem) – C:\Windows\SysNative\DRIVERS\agrsm64.sys (LSI Corporation)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (HPEWSFXBULK) – C:\Windows\SysNative\drivers\hpfx64bulk.sys (Hewlett Packard)
DRV:64bit: - (RTL8187Se) – C:\Windows\SysNative\DRIVERS\RTL8187Se.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (RTHDMIAzAudService) – C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\DRIVERS\iaStor.sys (Intel Corporation)
DRV:64bit: - (e1yexpress) Intel® – C:\Windows\SysNative\DRIVERS\e1y60x64.sys (Intel Corporation)
DRV:64bit: - (gwfilt64) – C:\Windows\SysNative\drivers\gwfilt64.sys (Creative Technology Ltd.)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (SYMSpeedDisk) – C:\Windows\SysWOW64\drivers\SymSpeedDisk.sys (Symantec Corporation)
DRV - (int15) – C:\Windows\SysWOW64\drivers\int15_64.sys (Acer, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 1C F7 7A 0E 74 0D 1D 44 A6 FD E9 39 B6 6D 90 5D [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files (x86)\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Admin\AppData\Local\Google\Update\1.3.21.53\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Admin\AppData\Local\Google\Update\1.3.21.53\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\Toolbar\Firefox [2011/09/16 12:12:51 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{5576EE23-03F7-4284-AA8B-760A71D594D2}: C:\Users\Admin\AppData\Local\{5576EE23-03F7-4284-AA8B-760A71D594D2} [2011/05/08 10:01:02 | 000,000,000 | —D | M]

[2011/06/30 14:30:14 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll

O1 HOSTS File: ([2011/11/02 19:53:05 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (CA Anti-Phishing Toolbar Helper) - {45011CF5-E4A9-4F13-9093-F30A784EB9B2} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O2 - BHO: (CA Anti-Phishing Toolbar Helper) - {45011CF5-E4A9-4F13-9093-F30A784EB9B2} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\Toolbar\caIEToolbar.dll (CA, Inc.)
O2 - BHO: (WinZip Courier BHO) - {A8FB70FA-0FDF-4601-9DC4-BFA1B357204F} - C:\Program Files (x86)\WinZip Courier\wzwmcie.dll (WinZip Computing, S.L.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKLM\..\Toolbar: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\casc.exe (CA, Inc.)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RunDLLEntry] C:\Windows\SysNative\AmbRunE.DLL (Creative Technology Ltd.)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [LchDrvKey] C:\Windows\LchDrvKey.exe ()
O4 - HKLM..\Run: [LedKey] C:\Windows\CNYHKey.exe (Creative)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\VetRedir64.dll (Computer Associates International, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Windows\SysNative\VetRedir64.dll (Computer Associates International, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000023 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000024 - C:\Windows\SysNative\VetRedir64.dll (Computer Associates International, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.5.7.cab (DLM Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A417D75D-F4FC-4C7A-BA84-8CE7394E032E}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (C:\Windows\System32\UmxSbxExA64.dll) - C:\Windows\SysNative\UmxSbxExA64.dll (CA)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\615\G2AWinLogon_x64.dll) - C:\Program Files (x86)\Citrix\GoToAssist\615\g2awinlogon_x64.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20:64bit: - Winlogon\Notify\PFW: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20 - Winlogon\Notify\PFW: DllName - (UmxWnp.Dll) - C:\Windows\SysWow64\UmxWNP.dll (CA)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/04 08:59:19 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Admin\Desktop\OTL.exe
[2011/11/02 23:26:40 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/11/02 23:26:40 | 000,000,000 | -HSD | C] – \$RECYCLE.BIN
[2011/11/02 22:48:28 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/11/02 22:48:28 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Local\temp
[2011/11/02 22:16:48 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/11/01 19:41:57 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/11/01 19:41:57 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/11/01 19:40:20 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/11/01 19:37:57 | 000,000,000 | —D | C] – C:\Qoobox
[2011/11/01 19:37:57 | 000,000,000 | —D | C] – \Qoobox
[2011/10/31 23:11:24 | 001,916,416 | —- | C] (AVAST Software) – C:\Users\Admin\Desktop\aswMBR.exe
[2011/10/31 23:11:24 | 000,607,260 | R— | C] (Swearware) – C:\Users\Admin\Desktop\dds.com
[2011/10/30 00:20:55 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Roaming\Malwarebytes
[2011/10/30 00:20:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/10/30 00:20:39 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/10/30 00:20:34 | 000,025,416 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/10/30 00:20:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/10/29 23:59:05 | 000,000,000 | —D | C] – C:\Config.Msi
[2011/10/29 23:59:05 | 000,000,000 | —D | C] – \Config.Msi
[2011/10/29 14:34:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/10/29 14:34:32 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/10/29 13:37:20 | 000,446,464 | —- | C] (OldTimer Tools) – C:\Users\Admin\Desktop\TFC.exe
[2011/10/29 13:37:17 | 009,852,544 | —- | C] (Malwarebytes Corporation ) – C:\Users\Admin\Desktop\mbam-setup-1.51.2.1300.exe
[2011/10/27 18:16:00 | 004,266,378 | —- | C] (Swearware) – C:\Users\Admin\Desktop\Combo-Fix.exe
[2011/10/27 18:15:05 | 004,280,796 | R— | C] (Swearware) – C:\Users\Admin\Desktop\ComboFix.exe
[2011/10/13 03:01:08 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/10/13 03:01:08 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/10/13 03:01:07 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/10/13 03:01:07 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/10/13 03:01:06 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/10/13 03:01:06 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/10/13 03:01:06 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/10/13 03:01:05 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/10/13 03:01:05 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/10/12 20:09:31 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/10/12 20:09:31 | 000,735,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAutomationCore.dll
[2011/10/12 20:09:31 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAutomationCore.dll
[2011/10/12 20:09:31 | 000,332,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2011/10/12 20:09:31 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\oleaccrc.dll
[2011/10/12 20:09:31 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaccrc.dll
[2011/10/12 20:08:59 | 000,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/10/12 20:08:59 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/10/12 20:08:59 | 000,289,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2011/10/12 20:08:59 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2011/10/12 20:08:59 | 000,100,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Mpeg2Data.ax
[2011/10/12 20:08:59 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSDvbNP.ax
[2011/10/12 20:08:59 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Mpeg2Data.ax
[2011/10/12 20:08:59 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSDvbNP.ax
[2011/10/11 20:03:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/10/11 20:03:05 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/10/11 20:02:31 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/10/11 20:02:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/10/11 19:54:35 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/10/11 19:54:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour

========== Files - Modified Within 30 Days ==========

[2011/11/04 09:29:01 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/04 09:17:19 | 000,000,126 | —- | M] () – C:\pclog_3440.dat
[2011/11/04 08:55:26 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/04 08:55:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4027082081-1360438707-2940866900-1000UA.job
[2011/11/04 08:54:17 | 000,000,000 | —- | M] () – C:\Windows\SysNative\LogConfigTemp.xml
[2011/11/04 08:54:04 | 000,006,080 | —- | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/04 08:54:04 | 000,006,080 | —- | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/04 08:54:00 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/04 01:39:23 | 003,657,573 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k0
[2011/11/04 01:39:23 | 000,371,180 | —- | M] () – C:\Windows\SysNative\drivers\KmxAgent.asc
[2011/11/04 01:39:23 | 000,000,337 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k0
[2011/11/04 01:39:23 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k7
[2011/11/04 01:39:23 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k6
[2011/11/04 01:39:23 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k5
[2011/11/04 01:39:23 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k4
[2011/11/04 01:39:23 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k3
[2011/11/04 01:39:23 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k2
[2011/11/04 01:39:23 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k1
[2011/11/04 01:39:23 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k7
[2011/11/04 01:39:23 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k6
[2011/11/04 01:39:23 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k5
[2011/11/04 01:39:23 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k4
[2011/11/04 01:39:23 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k3
[2011/11/04 01:39:23 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k2
[2011/11/04 01:39:23 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k1
[2011/11/04 01:37:39 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4027082081-1360438707-2940866900-1000Core.job
[2011/11/03 23:58:22 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Admin\Desktop\OTL.exe
[2011/11/03 21:22:45 | 000,725,182 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/03 21:22:45 | 000,620,130 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/11/03 21:22:45 | 000,109,204 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/11/02 19:53:05 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/11/02 18:50:28 | 004,280,796 | R— | M] (Swearware) – C:\Users\Admin\Desktop\ComboFix.exe
[2011/11/01 03:51:40 | 000,000,378 | —- | M] () – C:\pclog_3636.dat
[2011/10/31 23:08:05 | 000,000,680 | —- | M] () – C:\Users\Admin\AppData\Local\d3d9caps.dat
[2011/10/31 22:51:08 | 001,916,416 | —- | M] (AVAST Software) – C:\Users\Admin\Desktop\aswMBR.exe
[2011/10/31 22:48:58 | 000,607,260 | R— | M] (Swearware) – C:\Users\Admin\Desktop\dds.com
[2011/10/31 13:55:02 | 000,002,519 | —- | M] () – C:\Users\Admin\Desktop\HiJackThis.lnk
[2011/10/31 08:44:05 | 000,000,126 | —- | M] () – C:\pclog_3460.dat
[2011/10/31 01:50:58 | 000,000,126 | —- | M] () – C:\pclog_3496.dat
[2011/10/30 00:20:40 | 000,000,910 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/29 13:01:15 | 009,852,544 | —- | M] (Malwarebytes Corporation ) – C:\Users\Admin\Desktop\mbam-setup-1.51.2.1300.exe
[2011/10/29 12:58:04 | 000,446,464 | —- | M] (OldTimer Tools) – C:\Users\Admin\Desktop\TFC.exe
[2011/10/28 08:57:04 | 000,000,245 | —- | M] () – C:\Win32-FakeAV.NQ trojan infection - Tech Support Guy Forums.url
[2011/10/27 18:16:00 | 004,266,378 | —- | M] (Swearware) – C:\Users\Admin\Desktop\Combo-Fix.exe
[2011/10/27 16:17:03 | 000,000,930 | —- | M] () – C:\Users\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2011/10/26 08:19:04 | 000,000,063 | —- | M] () – C:\pclog_3652.dat
[2011/10/21 12:10:15 | 000,000,063 | —- | M] () – C:\pclog_4268.dat
[2011/10/16 05:41:04 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/10/15 20:19:42 | 000,134,382 | —- | M] () – C:\Users\Admin\Documents\Pams_Itinerary101211.pdf
[2011/10/13 03:50:48 | 000,389,272 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/10/13 00:57:04 | 000,000,063 | —- | M] () – C:\pclog_3620.dat
[2011/10/12 22:02:32 | 928,890,990 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/10/12 19:44:36 | 000,000,063 | —- | M] () – C:\pclog_3648.dat
[2011/10/11 20:03:53 | 000,001,656 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/10/10 01:17:12 | 000,000,069 | —- | M] () – C:\Windows\NeroDigital.ini
[2011/10/08 15:14:18 | 000,000,063 | —- | M] () – C:\pclog_3716.dat

========== Files Created - No Company Name ==========

[2011/11/04 09:14:49 | 000,000,126 | —- | C] () – C:\pclog_3440.dat
[2011/11/04 09:14:49 | 000,000,126 | —- | C] () – \pclog_3440.dat
[2011/11/01 19:41:57 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/11/01 19:41:57 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/11/01 19:41:57 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/11/01 19:41:57 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/11/01 19:41:57 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/10/31 23:10:54 | 010,288,649 | —- | C] () – C:\Submission_Contract.pdf
[2011/10/31 23:10:54 | 010,288,649 | —- | C] () – \Submission_Contract.pdf
[2011/10/31 23:10:54 | 002,913,028 | —- | C] () – C:\ICISurvivalGuide.pdf
[2011/10/31 23:10:54 | 002,913,028 | —- | C] () – \ICISurvivalGuide.pdf
[2011/10/31 23:10:54 | 000,851,948 | —- | C] () – C:\GAO_Report_Foreclosures.pdf
[2011/10/31 23:10:54 | 000,851,948 | —- | C] () – \GAO_Report_Foreclosures.pdf
[2011/10/31 23:10:54 | 000,122,770 | —- | C] () – C:\winningargument.pdf
[2011/10/31 23:10:54 | 000,122,770 | —- | C] () – \winningargument.pdf
[2011/10/31 23:10:54 | 000,056,589 | —- | C] () – C:\sf_rcd_execsum.pdf
[2011/10/31 23:10:54 | 000,056,589 | —- | C] () – \sf_rcd_execsum.pdf
[2011/10/31 23:10:52 | 081,020,975 | —- | C] () – C:\2011-05-11 19.04 The Perfect Storm for Paper Buyers.wmv
[2011/10/31 23:10:52 | 081,020,975 | —- | C] () – \2011-05-11 19.04 The Perfect Storm for Paper Buyers.wmv
[2011/10/31 23:10:52 | 000,002,002 | —- | C] () – C:\National Estimator.lnk
[2011/10/31 23:10:52 | 000,002,002 | —- | C] () – \National Estimator.lnk
[2011/10/31 23:10:52 | 000,001,703 | —- | C] () – C:\1846 Douglas Ave Dunedin - Shortcut.lnk
[2011/10/31 23:10:52 | 000,001,703 | —- | C] () – \1846 Douglas Ave Dunedin - Shortcut.lnk
[2011/10/31 23:10:52 | 000,000,699 | —- | C] () – C:\Winamp.lnk
[2011/10/31 23:10:52 | 000,000,699 | —- | C] () – \Winamp.lnk
[2011/10/31 23:10:52 | 000,000,245 | —- | C] () – C:\Win32-FakeAV.NQ trojan infection - Tech Support Guy Forums.url
[2011/10/31 23:10:52 | 000,000,245 | —- | C] () – \Win32-FakeAV.NQ trojan infection - Tech Support Guy Forums.url
[2011/10/31 23:10:52 | 000,000,215 | —- | C] () – C:\Intelligent Real Estate Investment Decisions - eRealInvestor.url
[2011/10/31 23:10:52 | 000,000,215 | —- | C] () – \Intelligent Real Estate Investment Decisions - eRealInvestor.url
[2011/10/31 23:10:52 | 000,000,211 | —- | C] () – C:\Progressive Rock - Definition, Genres & Articles.url
[2011/10/31 23:10:52 | 000,000,211 | —- | C] () – \Progressive Rock - Definition, Genres & Articles.url
[2011/10/31 23:10:52 | 000,000,208 | —- | C] () – C:\Demystifying Fraud.url
[2011/10/31 23:10:52 | 000,000,208 | —- | C] () – \Demystifying Fraud.url
[2011/10/31 23:10:52 | 000,000,203 | —- | C] () – C:\FHA Loan Limits for CALIFORNIA.url
[2011/10/31 23:10:52 | 000,000,203 | —- | C] () – \FHA Loan Limits for CALIFORNIA.url
[2011/10/31 23:10:52 | 000,000,200 | —- | C] () – C:\PortalProgressive rock - Wikipedia, the free encyclopedia.url
[2011/10/31 23:10:52 | 000,000,200 | —- | C] () – \PortalProgressive rock - Wikipedia, the free encyclopedia.url
[2011/10/31 23:10:52 | 000,000,147 | —- | C] () – C:\Demystifying Fraud part 2.url
[2011/10/31 23:10:52 | 000,000,147 | —- | C] () – \Demystifying Fraud part 2.url
[2011/10/31 23:10:52 | 000,000,137 | —- | C] () – C:\D-Addicts View topic - [Tutorial] How to Burn w- Subtitles.url
[2011/10/31 23:10:52 | 000,000,137 | —- | C] () – \D-Addicts View topic - [Tutorial] How to Burn w- Subtitles.url
[2011/10/31 23:10:52 | 000,000,124 | —- | C] () – C:\Making Your Next Business Trip Tax Deductible.htm
[2011/10/31 23:10:52 | 000,000,124 | —- | C] () – \Making Your Next Business Trip Tax Deductible.htm
[2011/10/31 23:10:52 | 000,000,124 | —- | C] () – C:\Driving For Dollars.url
[2011/10/31 23:10:52 | 000,000,124 | —- | C] () – \Driving For Dollars.url
[2011/10/31 23:10:52 | 000,000,108 | —- | C] () – C:\Tutorial for National Estimator.url
[2011/10/31 23:10:52 | 000,000,108 | —- | C] () – \Tutorial for National Estimator.url
[2011/10/31 08:22:15 | 000,000,126 | —- | C] () – C:\pclog_3460.dat
[2011/10/31 08:22:15 | 000,000,126 | —- | C] () – \pclog_3460.dat
[2011/10/30 16:35:55 | 000,000,126 | —- | C] () – C:\pclog_3496.dat
[2011/10/30 16:35:55 | 000,000,126 | —- | C] () – \pclog_3496.dat
[2011/10/30 00:20:40 | 000,000,910 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/29 14:34:32 | 000,002,519 | —- | C] () – C:\Users\Admin\Desktop\HiJackThis.lnk
[2011/10/28 09:39:54 | 000,000,680 | —- | C] () – C:\Users\Admin\AppData\Local\d3d9caps.dat
[2011/10/27 17:30:17 | 000,000,378 | —- | C] () – C:\pclog_3636.dat
[2011/10/27 17:30:17 | 000,000,378 | —- | C] () – \pclog_3636.dat
[2011/10/26 08:19:04 | 000,000,063 | —- | C] () – C:\pclog_3652.dat
[2011/10/26 08:19:04 | 000,000,063 | —- | C] () – \pclog_3652.dat
[2011/10/21 12:10:15 | 000,000,063 | —- | C] () – C:\pclog_4268.dat
[2011/10/21 12:10:15 | 000,000,063 | —- | C] () – \pclog_4268.dat
[2011/10/15 20:19:42 | 000,134,382 | —- | C] () – C:\Users\Admin\Documents\Pams_Itinerary101211.pdf
[2011/10/13 00:57:04 | 000,000,063 | —- | C] () – C:\pclog_3620.dat
[2011/10/13 00:57:04 | 000,000,063 | —- | C] () – \pclog_3620.dat
[2011/10/12 19:44:36 | 000,000,063 | —- | C] () – C:\pclog_3648.dat
[2011/10/12 19:44:36 | 000,000,063 | —- | C] () – \pclog_3648.dat
[2011/10/11 20:03:53 | 000,001,656 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/10/08 15:14:18 | 000,000,063 | —- | C] () – C:\pclog_3716.dat
[2011/10/08 15:14:18 | 000,000,063 | —- | C] () – \pclog_3716.dat
[2011/10/04 20:10:07 | 000,000,189 | —- | C] () – \pclog_3500.dat
[2011/09/29 00:25:54 | 000,000,063 | —- | C] () – \pclog_3656.dat
[2011/09/14 11:47:40 | 000,053,760 | —- | C] () – C:\Windows\SysWow64\OVDecode.dll
[2011/08/24 20:19:10 | 000,056,320 | —- | C] () – C:\Windows\SysWow64\OpenVideo.dll
[2011/06/29 13:47:56 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2011/06/13 08:47:01 | 1073,741,824 | —- | C] () – \pgbleach.27
[2011/05/08 10:01:03 | 000,000,120 | —- | C] () – C:\Users\Admin\AppData\Local\Snapadutodi.dat
[2011/05/08 10:01:03 | 000,000,000 | —- | C] () – C:\Users\Admin\AppData\Local\Ivekalega.bin
[2011/04/26 15:58:54 | 000,000,066 | —- | C] () – C:\Windows\bi_group.ini
[2011/03/22 23:41:29 | 1073,741,824 | —- | C] () – \pgbleach.45
[2011/03/17 13:51:44 | 000,003,929 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/03/15 01:48:25 | 000,000,000 | —- | C] () – C:\Windows\HPMProp.INI
[2011/01/08 01:37:39 | 000,000,000 | —- | C] () – C:\Users\Admin\AppData\Roaming\bibstats
[2010/12/25 20:53:38 | 000,000,007 | —- | C] () – C:\Windows\SysWow64\mkghj.dll
[2010/12/25 20:43:17 | 001,422,672 | —- | C] () – C:\Windows\SysWow64\cfgmig32.dll
[2010/12/25 20:43:17 | 000,263,504 | —- | C] () – C:\Windows\SysWow64\cfgmig32.exe
[2010/12/25 20:43:01 | 004,108,304 | —- | C] () – C:\Windows\SysWow64\win32cpr.dll
[2010/12/25 20:43:01 | 002,760,720 | —- | C] () – C:\Windows\SysWow64\svcprs32.exe
[2010/12/25 20:43:01 | 001,744,912 | —- | C] () – C:\Windows\SysWow64\winsflt.dll
[2010/12/25 20:43:01 | 000,098,320 | —- | C] () – C:\Windows\SysWow64\winsfinst.exe
[2010/12/25 20:43:00 | 003,207,184 | —- | C] () – C:\Windows\SysWow64\mdmcls32.exe
[2010/06/04 21:07:04 | 000,036,864 | —- | C] () – \nphssb.dll
[2010/06/04 21:07:04 | 000,000,247 | —- | C] () – \nphssb.xpt
[2010/06/04 21:04:21 | 000,098,136 | —- | C] () – C:\Windows\gzip.exe
[2010/05/31 16:27:08 | 000,000,000 | —- | C] () – C:\Windows\DVEdit.INI
[2010/05/11 22:30:25 | 000,000,062 | —- | C] () – C:\Windows\wininit.ini
[2010/04/07 11:25:11 | 000,037,027 | —- | C] () – C:\Windows\atmoUn.exe
[2010/02/16 00:17:13 | 000,004,096 | —- | C] () – C:\Users\Admin\AppData\Local\keyfile3.drm
[2010/02/01 22:38:22 | 000,016,384 | —- | C] () – C:\Windows\SysWow64\FileOps.exe
[2010/01/31 18:43:33 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2009/12/25 18:44:18 | 000,000,000 | —- | C] () – C:\Users\Admin\AppData\Roaming\downloads.m3u
[2009/12/08 22:52:35 | 000,073,220 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2009/12/08 22:52:35 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2009/12/08 22:52:35 | 000,029,114 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2009/12/08 22:52:35 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2009/12/08 22:52:35 | 000,021,021 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2009/12/08 22:52:35 | 000,015,670 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2009/12/08 22:52:35 | 000,013,280 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2009/12/08 22:52:35 | 000,010,673 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2009/12/08 22:52:35 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2009/12/08 22:52:35 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2009/12/08 22:52:35 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2009/12/08 22:52:35 | 000,001,137 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2009/12/08 22:52:35 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2009/12/08 22:52:35 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2009/12/08 22:52:35 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2009/12/08 22:52:35 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2009/12/08 22:50:16 | 000,000,044 | —- | C] () – C:\Windows\EPSNX400.ini
[2009/12/02 09:24:03 | 000,726,594 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2009/11/23 20:32:22 | 000,000,000 | —- | C] () – C:\Users\Admin\AppData\Roaming\wklnhst.dat
[2009/11/20 10:25:01 | 000,000,197 | —- | C] () – C:\Users\Admin\AppData\Roaming\default.rss
[2009/11/20 09:49:52 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2009/11/20 00:48:45 | 000,004,767 | —- | C] () – C:\Windows\Irremote.ini
[2009/11/19 00:19:06 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/11/19 00:18:37 | 000,107,612 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchema.bin
[2009/11/19 00:18:09 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/11/19 00:17:54 | 000,018,904 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2009/11/17 17:42:22 | 000,019,313 | —- | C] () – C:\Users\Admin\AppData\Roaming\UserTile.png
[2009/11/17 16:49:45 | 000,001,460 | —- | C] () – C:\Users\Admin\AppData\Local\d3d9caps64.dat
[2009/11/17 16:41:31 | 003,107,788 | —- | C] () – C:\Windows\SysWow64\atiumdva.dat
[2009/11/17 14:30:39 | 000,145,920 | —- | C] () – C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/17 13:53:36 | 000,581,120 | —- | C] () – C:\Windows\mHotkey.exe
[2009/11/17 13:53:36 | 000,294,912 | —- | C] () – C:\Windows\PIC.dll
[2009/11/17 13:53:36 | 000,036,864 | —- | C] () – C:\Windows\LchDrvKey.exe
[2009/11/17 13:53:36 | 000,000,870 | —- | C] () – C:\Windows\mhotkey_reg.ini
[2009/09/10 17:31:13 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2008/01/20 22:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/01/09 20:29:25 | 000,001,324 | —- | C] () – C:\Windows\FF08_not_Spk_Hp.ini
[2008/01/09 20:29:25 | 000,001,269 | —- | C] () – C:\Windows\FF08_Render_Spk_Hp.ini
[2008/01/09 20:28:57 | 000,145,408 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2008/01/09 20:28:57 | 000,071,680 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2008/01/09 19:37:33 | 000,008,192 | R-S- | C] () – \BOOTSECT.BAK
[2008/01/09 19:37:32 | 000,333,257 | RHS- | C] () – \bootmgr
[2006/11/02 11:37:05 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:37:14 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2006/11/02 08:24:17 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 08:18:17 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2006/11/02 05:47:54 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/05/20 14:44:46 | 000,051,392 | —- | C] () – C:\Windows\SysWow64\drivers\atnt40k.sys
[2002/03/14 13:00:26 | 000,038,567 | —- | C] () – C:\Windows\SysWow64\pcpbios.exe
[1998/08/16 06:00:00 | 000,004,096 | —- | C] () – C:\Windows\SysWow64\sysres.dll

========== LOP Check ==========

[2010/09/27 19:11:30 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Amazon
[2011/10/01 04:00:48 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Azureus
[2010/11/21 14:05:33 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\DelTel, Inc
[2009/12/09 22:54:06 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\EPSON
[2009/11/17 18:57:58 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Forte
[2009/12/02 09:19:57 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\GetRightToGo
[2009/12/08 23:02:23 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Leadertech
[2011/07/07 22:24:19 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\OpenCandy
[2011/01/20 15:16:58 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\SupportSoft
[2011/05/05 00:04:05 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Usuqz
[2010/03/19 12:08:06 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\webex
[2011/11/04 01:37:56 | 000,032,608 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Files - Unicode (All) ==========
[2011/10/31 23:10:52 | 000,000,198 | —- | C] ()(C:\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics).url) – C:\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics).url
[2011/10/31 23:10:52 | 000,000,198 | —- | C] ()(\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics).url) – \Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics).url
[2011/10/31 23:10:52 | 000,000,195 | —- | C] ()(C:\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics) NEW.url) – C:\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics) NEW.url
[2011/10/31 23:10:52 | 000,000,195 | —- | C] ()(\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics) NEW.url) – \Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics) NEW.url
[2011/07/06 15:58:13 | 000,000,195 | —- | M] ()(C:\Users\Admin\Desktop\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics) NEW.url) – C:\Users\Admin\Desktop\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics) NEW.url
[2011/07/06 15:58:13 | 000,000,195 | —- | M] ()(C:\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics) NEW.url) – C:\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics) NEW.url
[2011/07/06 15:58:13 | 000,000,195 | —- | C] ()(C:\Users\Admin\Desktop\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics) NEW.url) – C:\Users\Admin\Desktop\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics) NEW.url
[2011/07/06 15:57:54 | 000,000,198 | —- | M] ()(C:\Users\Admin\Desktop\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics).url) – C:\Users\Admin\Desktop\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics).url
[2011/07/06 15:57:54 | 000,000,198 | —- | M] ()(C:\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics).url) – C:\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics).url
[2011/07/06 15:57:54 | 000,000,198 | —- | C] ()(C:\Users\Admin\Desktop\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics).url) – C:\Users\Admin\Desktop\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics).url

========== Alternate Data Streams ==========

@Alternate Data Stream - 166 bytes -> C:\ProgramData\TEMP:D3A96964
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:D287FACF

< End of report >


The EXTRAS.TXT will be in next post.

~James
Jeff:


The EXTRAS.TXT file generated from OTL:

OTL Extras logfile created on: 11/4/2011 9:27:36 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Admin\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.99 Gb Total Physical Memory | 3.74 Gb Available Physical Memory | 62.43% Memory free
12.09 Gb Paging File | 9.68 Gb Available in Paging File | 80.06% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 688.87 Gb Total Space | 38.59 Gb Free Space | 5.60% Space Free | Partition Type: NTFS
Drive I: | 245.73 Mb Total Space | 238.26 Mb Free Space | 96.96% Space Free | Partition Type: FAT

Computer Name: ADMIN-PC | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [RapidShareManagerEmail] – C:\Program Files (x86)\RapidShareManager\RapidShareManager.exe -mailto "%1" (RapidShare AG)
Directory [RapidShareManagerUpload] – C:\Program Files (x86)\RapidShareManager\RapidShareManager.exe -sendto "%1" (RapidShare AG)
Directory [Winamp.Bookmark] – "C:\Users\Admin\Downloads\WinAmp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Users\Admin\Downloads\WinAmp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Users\Admin\Downloads\WinAmp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [RapidShareManagerEmail] – C:\Program Files (x86)\RapidShareManager\RapidShareManager.exe -mailto "%1" (RapidShare AG)
Directory [RapidShareManagerUpload] – C:\Program Files (x86)\RapidShareManager\RapidShareManager.exe -sendto "%1" (RapidShare AG)
Directory [Winamp.Bookmark] – "C:\Users\Admin\Downloads\WinAmp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Users\Admin\Downloads\WinAmp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Users\Admin\Downloads\WinAmp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\CA Personal Firewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiMalware]
"DisableMonitoring" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiSpywareOverride" = 1
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = 2A 70 BA 37 B5 6A CA 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05FF6896-64AD-4785-BD7D-D5DF8DDCBEB8}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{0CB6EEF6-13F5-42DA-8F7A-1463B50DD636}" = rport=445 | protocol=6 | dir=out | app=system |
"{4A450B1A-33D8-4988-9157-5A1B15ACFD44}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{77822E87-7214-48B0-B886-734053B8EB33}" = lport=445 | protocol=6 | dir=in | app=system |
"{7A957438-EE28-4F4F-B3E9-9FE9C8F1BBF7}" = lport=139 | protocol=6 | dir=in | app=system |
"{87B1C663-3661-4B20-BF61-7AAC2391AE00}" = lport=138 | protocol=17 | dir=in | app=system |
"{9CBABCE0-529E-4F2D-B7AE-576555828452}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{A34D1F43-F2CE-40E4-8D44-FA7CA7B09BAC}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{A7A44FFE-6E64-4795-8555-039A561B6977}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{AFA9F52C-85C4-4ED1-9528-7E931CA46922}" = rport=139 | protocol=6 | dir=out | app=system |
"{C4DE9476-199D-4F77-94E1-47D07A99E05B}" = rport=137 | protocol=17 | dir=out | app=system |
"{D4A36D45-72B1-4714-BE4A-C88902C67F8B}" = rport=138 | protocol=17 | dir=out | app=system |
"{E4C79001-CEDC-4E63-B3CE-1EFD89C1D78A}" = lport=137 | protocol=17 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{054EB5AC-B557-4FEB-909C-AF868B8B4D41}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{1A8EC97B-0C23-4B83-AF09-88AA9D6E42D4}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{35D649D0-992A-4513-9B46-28AC9AF29EAC}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{44935B36-ADAA-45BE-A685-080B1B9501CC}" = protocol=17 | dir=in | app=c:\program files (x86)\addthis toolbar\toolbarupdate.exe |
"{606A4D8D-647C-41AA-A129-22EED03AFFAF}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{7559B20C-400F-4EF4-B889-12B7A8E5E2F5}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{7F1A6AB1-9637-444F-8C2D-62FD5F5FA980}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\pure networks shared\platform\nmsrvc.exe |
"{8A631004-FF7D-4D41-AED7-DBF84BAD98C8}" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{9C6CB52F-6C8D-49D4-A269-26DD3D265DDE}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{A16E5880-D733-4EB6-BCC3-9BF44E23839B}" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"{A5C8B1AD-C37B-43D4-8D0B-89B67721B77D}" = protocol=17 | dir=in | app=c:\program files (x86)\addthis toolbar\troubleshooter.exe |
"{B859731D-81B7-4290-BE77-A3594AE01F29}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{C287BEBF-4EB0-4CB6-8672-F70F8E76706F}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{CB7BAFE7-DBF1-4600-961F-49BB32C2B014}" = protocol=6 | dir=in | app=c:\program files (x86)\addthis toolbar\toolbarupdate.exe |
"{E16CAEBA-E255-4F0E-A279-DA4A58AFADC3}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{E3374147-8BEA-453D-8738-CF1E74A6BE17}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{E95C94C4-C2DE-4D00-A512-06A2B87D8577}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{EA125E49-C9E4-4BCD-AD20-22B2E89180DF}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{ED9E1735-55EC-41E9-9715-F3E602694CB8}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{F0788B81-7474-4432-9BB4-CDBD1FC07A6F}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{F0A62734-F38F-4788-9E98-07609BE962D4}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\pure networks shared\platform\nmsrvc.exe |
"{F5ABDA49-02CA-4E4C-8D98-3E2D8BF51DEF}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{FBBE064A-56BE-482F-9ED6-FC1D273BE6BE}" = protocol=6 | dir=in | app=c:\program files (x86)\addthis toolbar\troubleshooter.exe |
"TCP Query User{06FEBE8E-30A6-4B4C-AAA3-822EEDCB0D42}C:\windows\splwow64.exe" = protocol=6 | dir=in | app=c:\windows\splwow64.exe |
"TCP Query User{3E26696A-FFC4-406B-8432-3B3D598767AD}C:\program files (x86)\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"TCP Query User{601ED5E8-31FD-4B4B-8084-6ED7F27CA3FA}C:\users\admin\appdata\roaming\usuqz\gyria.exe" = protocol=6 | dir=in | app=c:\users\admin\appdata\roaming\usuqz\gyria.exe |
"TCP Query User{71D6F577-2D55-459A-B9F4-97CB6B1405F5}C:\program files (x86)\downloadhq\downloadhq.exe" = protocol=6 | dir=in | app=c:\program files (x86)\downloadhq\downloadhq.exe |
"TCP Query User{BF8A2599-B5A9-41BD-BEDC-1F39A9539BDA}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe |
"TCP Query User{E2A65E72-9F31-479D-9209-B3DA3BFB8737}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe |
"UDP Query User{081C17F3-386B-4482-9DBB-4610DD9BFB5A}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe |
"UDP Query User{08C3B991-C9C1-4DB5-843A-7BD64D37A0F8}C:\windows\splwow64.exe" = protocol=17 | dir=in | app=c:\windows\splwow64.exe |
"UDP Query User{3396C331-43B2-432D-B010-0028A1E9707C}C:\users\admin\appdata\roaming\usuqz\gyria.exe" = protocol=17 | dir=in | app=c:\users\admin\appdata\roaming\usuqz\gyria.exe |
"UDP Query User{ADA0B466-411D-4E8D-AAFB-8E464D76D421}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe |
"UDP Query User{AE3FAF3A-6B4F-4FED-95D3-7DB2935C060F}C:\program files (x86)\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"UDP Query User{FDEF015C-453E-4C7B-9DD5-DC44B5028178}C:\program files (x86)\downloadhq\downloadhq.exe" = protocol=17 | dir=in | app=c:\program files (x86)\downloadhq\downloadhq.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{119CFC4D-EB75-D47F-1209-032721858C32}" = ccc-utility64
"{1AAF3A3B-7B32-4DDF-8ABB-438DAEB46EEC}" = Windows Live Family Safety
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{38151262-FAF8-4778-9AAB-33E90B60D8E9}" = CA Anti-Virus Plus
"{44E3AB6B-453B-8DAE-9777-1C48F5AB8965}" = AMD Catalyst Install Manager
"{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}" = Windows Live Family Safety
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5737101A-27C4-408A-8A57-D1DC78DF84B4}" = 64 Bit HP CIO Components Installer
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{79BF7CB8-1E09-489F-9547-DB3EE8EA3F16}" = Microsoft SQL Server Native Client
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{8887AEF8-2603-4A9A-9580-631616E49ED7}" = MyFax® Print-to-Fax Assistant
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9C98CA38-4C1A-4AC8-B55C-169497C8826B}" = Apple Mobile Device Support
"{9CD0F7D3-B67F-4BF8-8784-D73AD229FF1E}" = iTunes
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Agere Systems Soft Modem" = Agere Systems PCI-SV92EX Soft Modem
"CAAPH2" = APH placeholder
"EPSON Stylus NX400 Series" = EPSON Stylus NX400 Series Printer Uninstall
"eTrust Suite Personal" = CA Internet Security Suite
"LSI Soft Modem" = LSI PCI-SV92EX Soft Modem
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"PROSet" = Intel® Network Connections Drivers
"WinRAR archiver" = WinRAR archiver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{08C8666B-C502-4AB3-B4CB-D74AC42D14FE}" = Nero BackItUp 10 Help (CHM)
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0CAE2FF0-AFC9-733D-EC3C-04BCB6B3C06F}" = Application Profiles
"{1367D815-EC9F-4e2f-9FB9-E40A075AD19B}" = DNAMigrator
"{13AE7598-928A-83E7-548B-44FA68242798}" = CCC Help English
"{13FAB014-DFC1-49AB-ACB4-220F6685CCDA}" = 2011 National Repair and Remodeling Estimator License
"{16987E99-C95C-4513-9239-7B44A0A71DB5}" = Nero SoundTrax 10 Help (CHM)
"{19A492A0-888F-44A0-9B21-D91700763F62}" = Catalyst Control Center - Branding
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1D243F00-1389-4C63-A7E9-B17E967D1901}" = WebEx Record and Playback
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1F7FB68F-52F6-46A3-B42F-38CE46295AE5}" = Nero MediaHub 10
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20C53FA2-4307-4671-A93F-9463B29DFCF1}" = Symantec Technical Support Web Controls
"{211D9A2A-0ECA-7AC7-ABAA-03ED3242F33E}" = Catalyst Control Center
"{237CCB62-8454-43E3-B158-3ACD0134852E}" = High-Definition Video Playback
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{248E4799-DB04-4B1A-902C-194669F995CE}" = Nero Move it
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 22
"{277C1559-4CF7-44FF-8D07-98AA9C13AABD}" = Nero Multimedia Suite 10
"{279c6cf3-9186-453a-b24a-8601f8b0e104}" = Nero 9
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{329411A0-19F3-4740-874F-17400B126F27}" = Nero Vision 10 Help (CHM)
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33643918-7957-4839-92C7-EA96CB621A98}" = Nero Express 10 Help (CHM)
"{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed
"{34490F4E-48D0-492E-8249-B48BECF0537C}" = Nero DiscSpeed 10
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{359cfc0a-beb1-440d-95ba-cf63a86da34f}" = Nero Recode
"{368ba326-73ad-4351-84ed-3c0a7a52cc53}" = Nero Rescue Agent
"{3AD2A908-3255-4F2C-873C-1BAFC9F6821B}" = 2008 National Repair and Remodeling Estimator Download
"{43e39830-1826-415d-8bae-86845787b54b}" = Nero Vision
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5066FFF7-0029-BBA3-DD41-D71599987F1B}" = Catalyst Control Center InstallProxy
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{523B2B1B-D8DB-4B41-90FF-C4D799E2758A}" = Nero ControlCenter 10 Help (CHM)
"{5424F5EF-BB5B-4416-AB99-C623B869D115}_is1" = Lane Guide Online Launcher version 1.0
"{555868C6-49FB-484F-BB43-8980651A1B00}" = Nero BurnRights 10 Help (CHM)
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
"{5A05B328-35EB-4CED-B16F-62FA5A2642E6}" =
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{62ac81f6-bdd3-4110-9d36-3e9eaab40999}" = Nero CoverDesigner
"{63AA3EAB-23BB-48B2-9AD0-44F878075604}" = Nero 10 Menu TemplatePack Basic
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{66049135-9659-4AAD-9169-9CCA269EBB3E}" = Nero InfoTool 10 Help (CHM)
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68A10D83-4FE9-4A43-AEBA-043A25B05722}" = 2011 National Repair and Remodeling Estimator
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{68AB6930-5BFF-4FF6-923B-516A91984FE6}" = Nero BackItUp 10
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{70550193-1C22-445C-8FA4-564E155DB1A7}" = Nero Express 10
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{78D8E9C8-50C0-4089-A913-29B53CE47978}" = The National Estimator
"{7a08f6c6-d529-4047-a195-2c1e05c58807}" = Nero Move it Trial
"{7A295D8F-484B-4FFB-89AB-C1FD497591FE}" = Nero WaveEditor 10 Help (CHM)
"{7A5D731D-B4B3-490E-B339-75685712BAAB}" = Nero Burning ROM 10
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Gateway Recovery Management
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{85BEC8F6-9AA3-43FF-B56B-8276277137B3}" = Nero 10 Video TransitionPack 1
"{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8ECEC853-5C3D-4B10-B5C7-FF11FF724807}" = Nero Recode 10
"{8F93C410-D762-482B-B2D9-934C475F71FA}" = Nero 10 Creative CollectionPack 1
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_PROPLUS_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_PROPLUS_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_PROPLUS_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91A4AD99-69CE-4745-97B7-0E0DFBECFDE5}" = Adobe Illustrator CS
"{92E25238-61A3-4ACD-A407-3C480EEF47A7}" = Nero RescueAgent 10 Help (CHM)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{943CFD7D-5336-47AF-9418-E02473A5A517}" = Nero BurnRights 10
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}" = Nero Vision 10
"{9B6B24BE-80E7-46C4-9FA5-B167D5E0F345}" = Nero BurningROM 10 Help (CHM)
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9e82b934-9a25-445b-b8df-8012808074ac}" = Nero PhotoSnap
"{9e9fdde6-2c26-492a-85a0-05646b3f2795}" = NeroLiveGadget
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{a209525b-3377-43f4-b886-32f6b6e7356f}" = Nero WaveEditor
"{A2E5F2AA-2996-41EA-BCCD-9FD0476A5326}" = TWC Customer Controls
"{A70B0C7B-3527-4D53-A694-E9492ECE9EE1}" = Nero 10 Movie ThemePack 4
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{A9F6CFB0-806D-11E0-8EA1-B8AC6F97B88E}" = Google Earth Plug-in
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-1033-F400-7760-000000000004}_912" = Adobe Acrobat 9.1.2 - CPSID_49166
"{AC76BA86-1033-F400-7760-000000000004}{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{B1ADF008-E898-4FE2-8A1F-690D9A06ACAF}" = DolbyFiles
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{b78120a0-cf84-4366-a393-4d0a59bc546c}" = Menu Templates - Starter Kit
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{C18A0418-442A-4186-AF98-D08F5054A2FC}" = Nero DiscSpeed 10 Help (CHM)
"{C3273C55-E1E4-41FF-8D69-0158090DB8D8}" = Nero CoverDesigner 10 Help (CHM)
"{C3580AC4-C827-4332-B935-9A282ED5BB97}" = Nero Dolby Files 10
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{c5a7cb6c-e76d-408f-ba0e-85605420fe9d}" = SoundTrax
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C7E99FEB-A620-40B0-9B37-4410738B351E}" = Sound Blaster X-Fi MB
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CB84F0F2-927B-458D-9DC5-87832E3DC653}" = GearDrvs
"{CD95F661-A5C4-11AF-B2CC-ABCD21A325B3}" = WinZip Courier
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C2}" = WinZip 15.5
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CF0EDB56-BBF6-3C9F-9C50-2E3B3D444641}" = Google Talk Plugin
"{d025a639-b9c9-417d-8531-208859000af8}" = NeroBurningROM
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D52ECEBC-9B20-41A5-81C4-A62DE2367419}" = Adobe Creative Suite
"{d9dcf92e-72eb-412d-ac71-3b01276e5f8b}" = Nero ShowTime
"{DB7C1D4A-08BA-4C7E-A8AA-B7F9BB372DCF}" = Nero Recode 10 Help (CHM)
"{DD238642-14C7-4D54-8BD7-FAD6DEA9999B}" = Nero 10 Movie ThemePack 3
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DEFA5390-8533-47B5-81F7-3816916BDC6F}" = Nero Move it Help
"{df6a95f5-adc1-406a-bdc6-2aa7cc0182aa}" = Nero Live
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1EE5339-5D32-458F-BAAB-B19F6301BCE2}" = Nero SoundTrax 10
"{E337E787-CF61-4B7B-B84F-509202A54023}" = Nero RescueAgent 10
"{e498385e-1c51-459a-b45f-1721e37aa1a0}" = Movie Templates - Starter Kit
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{ED5DCA6F-5FEA-47CB-83DB-210A468C298B}" = KB0817 Keyboard Driver
"{EDCDFAD5-DF80-4600-A493-E9DAD6810230}" = Nero WaveEditor 10
"{EF3A4DAE-F16F-4AC1-87BB-FE00A784084F}" = Nero 10 PiP EffectPack 1
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f1861f30-3419-44db-b2a1-c274825698b3}" = Nero Disc Copy Gadget
"{F4041DCE-3FE1-4E18-8A9E-9DE65231EE36}" = Nero ControlCenter
"{F412B4AF-388C-4FF5-9B2F-33DB1C536953}" = Nero InfoTool 10
"{F467862A-D9CA-47ED-8D81-B4B3C9399272}" = Nero MediaHub 10 Help (CHM)
"{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}" = Nero 10 Movie ThemePack Basic
"{F6117F9C-ADB5-4590-9BE4-12C7BEC28702}" = Nero StartSmart 10 Help (CHM)
"{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}" = Nero StartSmart 10
"{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool
"{FCF00A6E-FB58-477A-ABE9-232907105521}" = Nero CoverDesigner 10
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FECCC297-24D6-F2B0-2BEC-446AC0205EEB}" = Catalyst Control Center Graphics Previews Common
"6103-4188-8184-5707" = RapidShare Manager 2
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe SVG Viewer" = Adobe SVG Viewer 6.0
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.10
"AVerMedia M791 PCIe Combo NTSC/ATSC" = AVerMedia M791 PCIe Combo NTSC/ATSC 6.104.64.5
"conduitEngine" = Conduit Engine
"EPSON Scanner" = EPSON Scan
"Forte Agent" = Forté Agent
"GoToAssist" = GoToAssist Corporate
"Intuit SiteBuilder" = Intuit SiteBuilder
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable Package
"Monkey's Audio_is1" = Monkey's Audio
"Norton Utilities 15_is1" = Norton Utilities 15
"Picasa 3" = Picasa 3
"PROPLUS" = Microsoft Office Professional Plus 2007
"VLC media player" = VLC media player 1.1.11
"VuePrint" = VuePrint
"VueScan" = VueScan
"Vuze_Remote Toolbar" = Vuze Remote Toolbar
"Winamp" = Winamp
"WinLiveSuite" = Windows Live Essentials
"WinZip Self-Extractor" = WinZip Self-Extractor

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"GoToMeeting" = GoToMeeting 4.8.0.723
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/3/2011 8:16:48 PM | Computer Name = Admin-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\Adobe\Acrobat
9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.

Error - 11/3/2011 8:23:41 PM | Computer Name = Admin-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\Adobe\Acrobat
9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.

Error - 11/3/2011 8:23:41 PM | Computer Name = Admin-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\Adobe\Acrobat
9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.

Error - 11/4/2011 8:55:41 AM | Computer Name = Admin-PC | Source = WinMgmt | ID = 10
Description =

Error - 11/4/2011 8:55:48 AM | Computer Name = Admin-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\Adobe\Acrobat
9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.

Error - 11/4/2011 8:55:48 AM | Computer Name = Admin-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\Adobe\Acrobat
9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.

Error - 11/4/2011 8:56:11 AM | Computer Name = Admin-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\Adobe\Acrobat
9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.

Error - 11/4/2011 8:56:35 AM | Computer Name = Admin-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\Nero\Nero
9\Nero PhotoSnap\PhotoSnapViewer.exe.Manifest".Error in manifest or policy file
"" on line . A component version required by the application conflicts with another
component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.

Error - 11/4/2011 9:13:21 AM | Computer Name = Admin-PC | Source = Application Error | ID = 1000
Description = Faulting application mdmcls32.exe, version 2011.0.3215.0, time stamp
0x4e0b0a59, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception
code 0xc0000005, fault offset 0x6f9fb005, process id 0xcc8, application start time
0x01cc9af0dd4b7a4b.

Error - 11/4/2011 9:17:11 AM | Computer Name = Admin-PC | Source = Application Error | ID = 1000
Description = Faulting application mdmcls32.exe, version 2011.0.3215.0, time stamp
0x4e0b0a59, faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception
code 0xc0000005, fault offset 0xc483ffef, process id 0xfa4, application start time
0x01cc9af3bb719dcb.

[ OSession Events ]
Error - 10/2/2010 12:23:54 PM | Computer Name = Admin-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6539.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 191
seconds with 180 seconds of active time. This session ended with a crash.

Error - 12/26/2010 5:04:43 PM | Computer Name = Admin-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6548.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 81
seconds with 60 seconds of active time. This session ended with a crash.

Error - 1/20/2011 8:01:52 AM | Computer Name = Admin-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 98
seconds with 0 seconds of active time. This session ended with a crash.

Error - 1/20/2011 8:03:33 AM | Computer Name = Admin-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 92
seconds with 0 seconds of active time. This session ended with a crash.

Error - 1/20/2011 8:24:11 AM | Computer Name = Admin-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 92
seconds with 0 seconds of active time. This session ended with a crash.

Error - 1/20/2011 2:13:15 PM | Computer Name = Admin-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 20865
seconds with 720 seconds of active time. This session ended with a crash.

Error - 1/20/2011 2:30:16 PM | Computer Name = Admin-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 450
seconds with 300 seconds of active time. This session ended with a crash.

Error - 2/18/2011 12:25:25 AM | Computer Name = Admin-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 17
seconds with 0 seconds of active time. This session ended with a crash.

Error - 3/15/2011 3:02:11 PM | Computer Name = Admin-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 493
seconds with 480 seconds of active time. This session ended with a crash.

Error - 7/10/2011 8:09:14 PM | Computer Name = Admin-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 237
seconds with 60 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 11/3/2011 8:33:13 PM | Computer Name = Admin-PC | Source = Tcpip | ID = 4199
Description = The system detected an address conflict for IP address 192.168.0.1
with the system having network hardware address 00-26-5A-FB-A7-CA. Network operations
on this system may be disrupted as a result.

Error - 11/3/2011 9:18:31 PM | Computer Name = Admin-PC | Source = DCOM | ID = 10016
Description =

Error - 11/3/2011 9:18:31 PM | Computer Name = Admin-PC | Source = DCOM | ID = 10016
Description =

Error - 11/3/2011 9:18:31 PM | Computer Name = Admin-PC | Source = DCOM | ID = 10016
Description =

Error - 11/3/2011 9:18:31 PM | Computer Name = Admin-PC | Source = DCOM | ID = 10016
Description =

Error - 11/3/2011 9:18:31 PM | Computer Name = Admin-PC | Source = DCOM | ID = 10016
Description =

Error - 11/4/2011 8:55:41 AM | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 11/4/2011 9:14:50 AM | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7034
Description =

Error - 11/4/2011 9:17:19 AM | Computer Name = Admin-PC | Source = Service Control Manager | ID = 7034
Description =

Error - 11/4/2011 9:17:49 AM | Computer Name = Admin-PC | Source = DCOM | ID = 10010
Description =


< End of report >



Thanks very much


~James
Hi James,

What antivirus are you actively using? I see both CA and Symantec on your system. Having more than one antivirus can cause system conflicts. Let me know which one your are using and I can get you the removal tool for the other.

I am still reviewing your OTL log, which came out just fine, and I still see some entries here that need to be taken care of. :) I will be back shortly with what we need to do next.

By the way…are you familiar with the Korean Drama Group being on your system?
Hi Jeff: Thanks again for the quick response. I only use CA Technology for protection and I use Symantec's Norton Utilities (not their antivirus software) so there typically should not be a conflict between the two programs. I have limited capability to use of the Internet. e.g. I try to do a search on Google and it goes nowhere when I click on the results even though there are no connectivity issues. I was afraid you might ask about Korean Drama Group. They were links that I saved on my desktop to see the instructions they publish on their blog demonsrating how to hardcode english subititles on foreign movies (movies are my hobby). If I have contracted some worm or trojan from them, then lets take care of it right away. Furthermore, I no longer download anything using P2P/file sharing methods as I know the risks for contamination from downloading from these sources are very high. I used to use Vuze, but I no longer have the software on my computer. (I see there are entries in the log files for Vuze Remote which I do not use or want.) Finally, my adobe acrobat Pro ver 9 has been affected somehow because it scrambles the text in documents that I convert to PDF regrardless if it is prinitng from documents online or through MS Office Suite. I want to thank you for all you assistance during this process. ~James
Hi James,

I only use CA Technology for protection and I use Symantec's Norton Utilities (not their antivirus software) so there typically should not be a conflict between the two programs.

I would highly recommend that you remove one of these. What are you using as far as Symantec?

—————–

Please download ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
———-

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 1C F7 7A 0E 74 0D 1D 44 A6 FD E9 39 B6 6D 90 5D [binary data]
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - wwinsflt.dll File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - wwinsflt.dll File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - wwinsflt.dll File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - wwinsflt.dll File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - wwinsflt.dll File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - wwinsflt.dll File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - wwinsflt.dll File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - wwinsflt.dll File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - wwinsflt.dll File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - wwinsflt.dll File not found
    O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000023 - wwinsflt.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
    O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
    O18:64bit: - Protocol\Handler\livecall - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
    O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
    O18:64bit: - Protocol\Handler\msnim - No CLSID value found
    O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
    O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
    [2011/06/13 08:47:01 | 1073,741,824 | —- | C] () – \pgbleach.27
    [2011/03/22 23:41:29 | 1073,741,824 | —- | C] () – \pgbleach.45
    [2009/11/17 14:30:39 | 000,145,920 | —- | C] () – C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    
    :Commands
    [purity]
    [clearallrestorepoints]
    [resethosts]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )


Hi Jeff:

I use Norton Utilities to clean the discs and defragment the hard drive as well as defrag the registry

The output file from the RUN FIX command with OTL.EXE using the script

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\XMLHTTP_UUID_Default| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000001\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000002\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000003\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000004\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000005\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000006\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000007\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000008\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000009\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000010\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000023\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000021\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully.
File Protocol\Handler\livecall - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\ deleted successfully.
File Protocol\Handler\msdaipp - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\0x00000001\ not found.
File Protocol\Handler\msdaipp\0x00000001 - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\oledb\ not found.
File Protocol\Handler\msdaipp\oledb - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
File Protocol\Handler\ms-help - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully.
File Protocol\Handler\msnim - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully.
File Protocol\Handler\wlmailhtml - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully.
File Protocol\Handler\wlpg - No CLSID value found not found.
File move failed. \pgbleach.27 scheduled to be moved on reboot.
File move failed. \pgbleach.45 scheduled to be moved on reboot.
C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
HOSTS file reset successfully

[EMPTYTEMP]

User: Admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 53619558 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 456 bytes

User: All Users

User: AppData
->Temp folder emptied: 0 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 12167648 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 63.00 mb

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\: LSP stack updated.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\: LSP stack updated.

OTL by OldTimer - Version 3.2.31.0 log created on 11042011_211041

Files\Folders moved on Reboot…
File move failed. \pgbleach.27 scheduled to be moved on reboot.
File move failed. \pgbleach.45 scheduled to be moved on reboot.
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
File\Folder C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{0678C35C-B0F2-41A7-BB61-D2CCEA8FE17F}.tmp not found!
File\Folder C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{1D0FEA62-DEEC-41D2-BCF6-14AC2EC09151}.tmp not found!
File\Folder C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{39A535C4-1B55-4A93-AA64-FB8CBA1D3520}.tmp not found!
File\Folder C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{55452A89-BEA2-4BCA-BC51-A47FA30FAC42}.tmp not found!
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{5E6A1696-FCA3-4B1C-B5C6-018943C73E64}.tmp moved successfully.
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{5F689549-5670-4DF6-AB41-36DD82B791F5}.tmp moved successfully.
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{987E23DB-D6A1-475F-AD28-9994844A4B6E}.tmp moved successfully.
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{CE11C526-3B82-4202-88B1-A24281696EE6}.tmp moved successfully.
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3Z36NVPR\news[1].xml moved successfully.
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3Z36NVPR\rss[1].xml moved successfully.

Registry entries deleted on Reboot…


Next is the output file from running a scan using OTL.EXE:

OTL logfile created on: 11/4/2011 9:31:56 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Admin\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.99 Gb Total Physical Memory | 3.96 Gb Available Physical Memory | 66.06% Memory free
12.09 Gb Paging File | 9.93 Gb Available in Paging File | 82.13% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 688.87 Gb Total Space | 35.59 Gb Free Space | 5.17% Space Free | Partition Type: NTFS
Drive I: | 245.73 Mb Total Space | 229.70 Mb Free Space | 93.48% Space Free | Partition Type: FAT

Computer Name: ADMIN-PC | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Admin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
PRC - C:\Windows\SysWOW64\cfgmig32.exe ()
PRC - C:\Windows\SysWOW64\svcprs32.exe ()
PRC - C:\Windows\SysWOW64\mdmcls32.exe ()
PRC - C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrvProxy.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrvProxy.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Windows\mHotkey.exe ()
PRC - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Windows\CNYHKey.exe (Creative)
PRC - C:\Windows\ChiFuncExt.exe (Chicony)
PRC - C:\Windows\ModLEDKey.exe (Chicony)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Windows\SysWOW64\winsflt.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL ()
MOD - C:\Windows\mHotkey.exe ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (CAAMSvc) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\CAAMSvc.exe (CA)
SRV:64bit: - (CaCCProvSP) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
SRV:64bit: - (ccSchedulerSVC) – C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe (Computer Associates International, Inc.)
SRV:64bit: - (CAISafe) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe (Computer Associates International, Inc.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (UmxEngine) – C:\Program Files\CA\SharedComponents\TMEngine\UmxEngine.exe (CA)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (AgereModemAudio) – C:\Windows\SysNative\agr64svc.exe (Agere Systems)
SRV:64bit: - (ETService) – C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (NAUpdate) – C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
SRV - (WinSvchostManagerSrv) – C:\Windows\SysWOW64\cfgmig32.exe ()
SRV - (WinSvchostManager) – C:\Windows\SysWOW64\svcprs32.exe ()
SRV - (WinExtManager) – C:\Windows\SysWOW64\mdmcls32.exe ()
SRV - (SpeedDiskService) – C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe (Symantec Corporation)
SRV - (DiskDoctorService) – C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe (Symantec Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (GoToAssist) – C:\Program Files (x86)\Citrix\GoToAssist\615\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SupportSoft RemoteAssist) – C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe (SupportSoft, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (CTAudSvcService) – C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (Symantec RemoteAssist) – C:\Program Files (x86)\Common Files\Symantec Shared\Support Controls\ssrc.exe (Symantec, Inc.)
SRV - (Symantec Core LC) – C:\Program Files (x86)\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (EPSON_EB_RPCV4_01) EPSON V5 Service4(01) – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE (SEIKO EPSON CORPORATION)
SRV - (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (SEIKO EPSON CORPORATION)


========== Driver Services (SafeList) ==========

DRV:64bit: - (atikmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\DRIVERS\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (KmxCF) – C:\Windows\SysNative\DRIVERS\KmxCF.sys (CA)
DRV:64bit: - (KmxCfg) – C:\Windows\SysNative\DRIVERS\kmxcfg.sys (CA)
DRV:64bit: - (KmxAMRT) – C:\Windows\SysNative\DRIVERS\KmxAMRT.sys (CA)
DRV:64bit: - (KmxAgent) – C:\Windows\SysNative\DRIVERS\kmxagent.sys (CA)
DRV:64bit: - (KmxFile) – C:\Windows\SysNative\DRIVERS\KmxFile.sys (CA)
DRV:64bit: - (KmxSbx) – C:\Windows\SysNative\DRIVERS\KmxSbx.sys (CA)
DRV:64bit: - (KmxFw) – C:\Windows\SysNative\DRIVERS\kmxfw.sys (CA)
DRV:64bit: - (KmxFilter) – C:\Windows\SysNative\DRIVERS\KmxFilter.sys (CA)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\Drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (SymDSMon) – C:\Windows\SysNative\drivers\SymDSMon.sys (Symantec Corporation)
DRV:64bit: - (SYMSpeedDisk) – C:\Windows\SysNative\drivers\SymSpeedDisk.sys (Symantec Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\DRIVERS\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (AgereSoftModem) – C:\Windows\SysNative\DRIVERS\agrsm64.sys (LSI Corporation)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (HPEWSFXBULK) – C:\Windows\SysNative\drivers\hpfx64bulk.sys (Hewlett Packard)
DRV:64bit: - (RTL8187Se) – C:\Windows\SysNative\DRIVERS\RTL8187Se.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (RTHDMIAzAudService) – C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\DRIVERS\iaStor.sys (Intel Corporation)
DRV:64bit: - (e1yexpress) Intel® – C:\Windows\SysNative\DRIVERS\e1y60x64.sys (Intel Corporation)
DRV:64bit: - (gwfilt64) – C:\Windows\SysNative\drivers\gwfilt64.sys (Creative Technology Ltd.)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (SYMSpeedDisk) – C:\Windows\SysWOW64\drivers\SymSpeedDisk.sys (Symantec Corporation)
DRV - (int15) – C:\Windows\SysWOW64\drivers\int15_64.sys (Acer, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files (x86)\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Admin\AppData\Local\Google\Update\1.3.21.53\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Admin\AppData\Local\Google\Update\1.3.21.53\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\Toolbar\Firefox [2011/09/16 12:12:51 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{5576EE23-03F7-4284-AA8B-760A71D594D2}: C:\Users\Admin\AppData\Local\{5576EE23-03F7-4284-AA8B-760A71D594D2} [2011/05/08 10:01:02 | 000,000,000 | —D | M]

[2011/06/30 14:30:14 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll

O1 HOSTS File: ([2011/11/04 21:11:21 | 000,000,098 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (CA Anti-Phishing Toolbar Helper) - {45011CF5-E4A9-4F13-9093-F30A784EB9B2} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O2 - BHO: (CA Anti-Phishing Toolbar Helper) - {45011CF5-E4A9-4F13-9093-F30A784EB9B2} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\Toolbar\caIEToolbar.dll (CA, Inc.)
O2 - BHO: (WinZip Courier BHO) - {A8FB70FA-0FDF-4601-9DC4-BFA1B357204F} - C:\Program Files (x86)\WinZip Courier\wzwmcie.dll (WinZip Computing, S.L.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKLM\..\Toolbar: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\casc.exe (CA, Inc.)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RunDLLEntry] C:\Windows\SysNative\AmbRunE.DLL (Creative Technology Ltd.)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [LchDrvKey] C:\Windows\LchDrvKey.exe ()
O4 - HKLM..\Run: [LedKey] C:\Windows\CNYHKey.exe (Creative)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\VetRedir64.dll (Computer Associates International, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\VetRedir64.dll (Computer Associates International, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000020 - C:\Windows\SysNative\VetRedir64.dll (Computer Associates International, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000021 - wwinsflt.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.5.7.cab (DLM Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A417D75D-F4FC-4C7A-BA84-8CE7394E032E}: DhcpNameServer = 192.168.0.1
O20:64bit: - AppInit_DLLs: (C:\Windows\System32\UmxSbxExA64.dll) - C:\Windows\SysNative\UmxSbxExA64.dll (CA)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\615\G2AWinLogon_x64.dll) - C:\Program Files (x86)\Citrix\GoToAssist\615\g2awinlogon_x64.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20:64bit: - Winlogon\Notify\PFW: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20 - Winlogon\Notify\PFW: DllName - (UmxWnp.Dll) - C:\Windows\SysWow64\UmxWNP.dll (CA)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/04 21:10:41 | 000,000,000 | —D | C] – C:\_OTL
[2011/11/04 21:10:41 | 000,000,000 | —D | C] – \_OTL
[2011/11/04 20:57:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2011/11/04 20:57:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\ERUNT
[2011/11/04 15:12:34 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Users\Admin\Desktop\erunt-setup.exe
[2011/11/04 08:59:19 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Admin\Desktop\OTL.exe
[2011/11/02 23:26:40 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/11/02 23:26:40 | 000,000,000 | -HSD | C] – \$RECYCLE.BIN
[2011/11/02 22:48:28 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/11/02 22:48:28 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Local\temp
[2011/11/02 22:16:48 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/11/01 19:41:57 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/11/01 19:41:57 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/11/01 19:40:20 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/11/01 19:37:57 | 000,000,000 | —D | C] – C:\Qoobox
[2011/11/01 19:37:57 | 000,000,000 | —D | C] – \Qoobox
[2011/10/31 23:11:24 | 001,916,416 | —- | C] (AVAST Software) – C:\Users\Admin\Desktop\aswMBR.exe
[2011/10/31 23:11:24 | 000,607,260 | R— | C] (Swearware) – C:\Users\Admin\Desktop\dds.com
[2011/10/30 00:20:55 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Roaming\Malwarebytes
[2011/10/30 00:20:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/10/30 00:20:39 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/10/30 00:20:34 | 000,025,416 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/10/30 00:20:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/10/29 23:59:05 | 000,000,000 | —D | C] – C:\Config.Msi
[2011/10/29 23:59:05 | 000,000,000 | —D | C] – \Config.Msi
[2011/10/29 14:34:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/10/29 14:34:32 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/10/29 13:37:20 | 000,446,464 | —- | C] (OldTimer Tools) – C:\Users\Admin\Desktop\TFC.exe
[2011/10/29 13:37:17 | 009,852,544 | —- | C] (Malwarebytes Corporation ) – C:\Users\Admin\Desktop\mbam-setup-1.51.2.1300.exe
[2011/10/27 18:16:00 | 004,266,378 | —- | C] (Swearware) – C:\Users\Admin\Desktop\Combo-Fix.exe
[2011/10/27 18:15:05 | 004,280,796 | R— | C] (Swearware) – C:\Users\Admin\Desktop\ComboFix.exe
[2011/10/13 03:01:08 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/10/13 03:01:08 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/10/13 03:01:07 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/10/13 03:01:07 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/10/13 03:01:06 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/10/13 03:01:06 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/10/13 03:01:06 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/10/13 03:01:05 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/10/13 03:01:05 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/10/12 20:09:31 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/10/12 20:09:31 | 000,735,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAutomationCore.dll
[2011/10/12 20:09:31 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAutomationCore.dll
[2011/10/12 20:09:31 | 000,332,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2011/10/12 20:09:31 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\oleaccrc.dll
[2011/10/12 20:09:31 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaccrc.dll
[2011/10/12 20:08:59 | 000,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/10/12 20:08:59 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/10/12 20:08:59 | 000,289,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2011/10/12 20:08:59 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2011/10/12 20:08:59 | 000,100,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Mpeg2Data.ax
[2011/10/12 20:08:59 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSDvbNP.ax
[2011/10/12 20:08:59 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Mpeg2Data.ax
[2011/10/12 20:08:59 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSDvbNP.ax
[2011/10/11 20:03:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/10/11 20:03:05 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/10/11 20:02:31 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/10/11 20:02:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/10/11 19:54:35 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/10/11 19:54:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour

========== Files - Modified Within 30 Days ==========

[2011/11/04 21:29:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/04 21:26:18 | 000,000,000 | —- | M] () – C:\Windows\SysNative\LogConfigTemp.xml
[2011/11/04 21:25:59 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/04 21:25:51 | 000,006,080 | —- | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/04 21:25:51 | 000,006,080 | —- | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/04 21:25:38 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/04 21:20:01 | 003,659,265 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k0
[2011/11/04 21:20:01 | 000,000,337 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k0
[2011/11/04 21:20:01 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k7
[2011/11/04 21:20:01 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k6
[2011/11/04 21:20:01 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k5
[2011/11/04 21:20:01 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k4
[2011/11/04 21:20:01 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k3
[2011/11/04 21:20:01 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k2
[2011/11/04 21:20:01 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k1
[2011/11/04 21:20:01 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k7
[2011/11/04 21:20:01 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k6
[2011/11/04 21:20:01 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k5
[2011/11/04 21:20:01 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k4
[2011/11/04 21:20:01 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k3
[2011/11/04 21:20:01 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k2
[2011/11/04 21:20:01 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k1
[2011/11/04 21:20:00 | 000,372,244 | —- | M] () – C:\Windows\SysNative\drivers\KmxAgent.asc
[2011/11/04 21:11:21 | 000,000,098 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/11/04 21:10:46 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4027082081-1360438707-2940866900-1000Core.job
[2011/11/04 20:57:44 | 000,725,182 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/04 20:57:44 | 000,620,130 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/11/04 20:57:44 | 000,109,204 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/11/04 20:57:22 | 000,000,725 | —- | M] () – C:\Users\Admin\Desktop\NTREGOPT.lnk
[2011/11/04 20:57:22 | 000,000,706 | —- | M] () – C:\Users\Admin\Desktop\ERUNT.lnk
[2011/11/04 20:55:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4027082081-1360438707-2940866900-1000UA.job
[2011/11/04 15:12:34 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Users\Admin\Desktop\erunt-setup.exe
[2011/11/04 09:17:19 | 000,000,126 | —- | M] () – C:\pclog_3440.dat
[2011/11/03 23:58:22 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Admin\Desktop\OTL.exe
[2011/11/02 18:50:28 | 004,280,796 | R— | M] (Swearware) – C:\Users\Admin\Desktop\ComboFix.exe
[2011/11/01 03:51:40 | 000,000,378 | —- | M] () – C:\pclog_3636.dat
[2011/10/31 23:08:05 | 000,000,680 | —- | M] () – C:\Users\Admin\AppData\Local\d3d9caps.dat
[2011/10/31 22:51:08 | 001,916,416 | —- | M] (AVAST Software) – C:\Users\Admin\Desktop\aswMBR.exe
[2011/10/31 22:48:58 | 000,607,260 | R— | M] (Swearware) – C:\Users\Admin\Desktop\dds.com
[2011/10/31 13:55:02 | 000,002,519 | —- | M] () – C:\Users\Admin\Desktop\HiJackThis.lnk
[2011/10/31 08:44:05 | 000,000,126 | —- | M] () – C:\pclog_3460.dat
[2011/10/31 01:50:58 | 000,000,126 | —- | M] () – C:\pclog_3496.dat
[2011/10/30 00:20:40 | 000,000,910 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/29 13:01:15 | 009,852,544 | —- | M] (Malwarebytes Corporation ) – C:\Users\Admin\Desktop\mbam-setup-1.51.2.1300.exe
[2011/10/29 12:58:04 | 000,446,464 | —- | M] (OldTimer Tools) – C:\Users\Admin\Desktop\TFC.exe
[2011/10/28 08:57:04 | 000,000,245 | —- | M] () – C:\Win32-FakeAV.NQ trojan infection - Tech Support Guy Forums.url
[2011/10/27 18:16:00 | 004,266,378 | —- | M] (Swearware) – C:\Users\Admin\Desktop\Combo-Fix.exe
[2011/10/27 16:17:03 | 000,000,930 | —- | M] () – C:\Users\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2011/10/26 08:19:04 | 000,000,063 | —- | M] () – C:\pclog_3652.dat
[2011/10/21 12:10:15 | 000,000,063 | —- | M] () – C:\pclog_4268.dat
[2011/10/16 05:41:04 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/10/15 20:19:42 | 000,134,382 | —- | M] () – C:\Users\Admin\Documents\Pams_Itinerary101211.pdf
[2011/10/13 03:50:48 | 000,389,272 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/10/13 00:57:04 | 000,000,063 | —- | M] () – C:\pclog_3620.dat
[2011/10/12 22:02:32 | 928,890,990 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/10/12 19:44:36 | 000,000,063 | —- | M] () – C:\pclog_3648.dat
[2011/10/11 20:03:53 | 000,001,656 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/10/10 01:17:12 | 000,000,069 | —- | M] () – C:\Windows\NeroDigital.ini
[2011/10/08 15:14:18 | 000,000,063 | —- | M] () – C:\pclog_3716.dat

========== Files Created - No Company Name ==========

[2011/11/04 20:57:22 | 000,000,725 | —- | C] () – C:\Users\Admin\Desktop\NTREGOPT.lnk
[2011/11/04 20:57:22 | 000,000,706 | —- | C] () – C:\Users\Admin\Desktop\ERUNT.lnk
[2011/11/04 09:14:49 | 000,000,126 | —- | C] () – C:\pclog_3440.dat
[2011/11/04 09:14:49 | 000,000,126 | —- | C] () – \pclog_3440.dat
[2011/11/01 19:41:57 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/11/01 19:41:57 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/11/01 19:41:57 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/11/01 19:41:57 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/11/01 19:41:57 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/10/31 23:10:54 | 010,288,649 | —- | C] () – C:\Submission_Contract.pdf
[2011/10/31 23:10:54 | 010,288,649 | —- | C] () – \Submission_Contract.pdf
[2011/10/31 23:10:54 | 002,913,028 | —- | C] () – C:\ICISurvivalGuide.pdf
[2011/10/31 23:10:54 | 002,913,028 | —- | C] () – \ICISurvivalGuide.pdf
[2011/10/31 23:10:54 | 000,851,948 | —- | C] () – C:\GAO_Report_Foreclosures.pdf
[2011/10/31 23:10:54 | 000,851,948 | —- | C] () – \GAO_Report_Foreclosures.pdf
[2011/10/31 23:10:54 | 000,122,770 | —- | C] () – C:\winningargument.pdf
[2011/10/31 23:10:54 | 000,122,770 | —- | C] () – \winningargument.pdf
[2011/10/31 23:10:54 | 000,056,589 | —- | C] () – C:\sf_rcd_execsum.pdf
[2011/10/31 23:10:54 | 000,056,589 | —- | C] () – \sf_rcd_execsum.pdf
[2011/10/31 23:10:52 | 081,020,975 | —- | C] () – C:\2011-05-11 19.04 The Perfect Storm for Paper Buyers.wmv
[2011/10/31 23:10:52 | 081,020,975 | —- | C] () – \2011-05-11 19.04 The Perfect Storm for Paper Buyers.wmv
[2011/10/31 23:10:52 | 000,002,002 | —- | C] () – C:\National Estimator.lnk
[2011/10/31 23:10:52 | 000,002,002 | —- | C] () – \National Estimator.lnk
[2011/10/31 23:10:52 | 000,001,703 | —- | C] () – C:\1846 Douglas Ave Dunedin - Shortcut.lnk
[2011/10/31 23:10:52 | 000,001,703 | —- | C] () – \1846 Douglas Ave Dunedin - Shortcut.lnk
[2011/10/31 23:10:52 | 000,000,699 | —- | C] () – C:\Winamp.lnk
[2011/10/31 23:10:52 | 000,000,699 | —- | C] () – \Winamp.lnk
[2011/10/31 23:10:52 | 000,000,245 | —- | C] () – C:\Win32-FakeAV.NQ trojan infection - Tech Support Guy Forums.url
[2011/10/31 23:10:52 | 000,000,245 | —- | C] () – \Win32-FakeAV.NQ trojan infection - Tech Support Guy Forums.url
[2011/10/31 23:10:52 | 000,000,215 | —- | C] () – C:\Intelligent Real Estate Investment Decisions - eRealInvestor.url
[2011/10/31 23:10:52 | 000,000,215 | —- | C] () – \Intelligent Real Estate Investment Decisions - eRealInvestor.url
[2011/10/31 23:10:52 | 000,000,211 | —- | C] () – C:\Progressive Rock - Definition, Genres & Articles.url
[2011/10/31 23:10:52 | 000,000,211 | —- | C] () – \Progressive Rock - Definition, Genres & Articles.url
[2011/10/31 23:10:52 | 000,000,208 | —- | C] () – C:\Demystifying Fraud.url
[2011/10/31 23:10:52 | 000,000,208 | —- | C] () – \Demystifying Fraud.url
[2011/10/31 23:10:52 | 000,000,203 | —- | C] () – C:\FHA Loan Limits for CALIFORNIA.url
[2011/10/31 23:10:52 | 000,000,203 | —- | C] () – \FHA Loan Limits for CALIFORNIA.url
[2011/10/31 23:10:52 | 000,000,200 | —- | C] () – C:\PortalProgressive rock - Wikipedia, the free encyclopedia.url
[2011/10/31 23:10:52 | 000,000,200 | —- | C] () – \PortalProgressive rock - Wikipedia, the free encyclopedia.url
[2011/10/31 23:10:52 | 000,000,147 | —- | C] () – C:\Demystifying Fraud part 2.url
[2011/10/31 23:10:52 | 000,000,147 | —- | C] () – \Demystifying Fraud part 2.url
[2011/10/31 23:10:52 | 000,000,137 | —- | C] () – C:\D-Addicts View topic - [Tutorial] How to Burn w- Subtitles.url
[2011/10/31 23:10:52 | 000,000,137 | —- | C] () – \D-Addicts View topic - [Tutorial] How to Burn w- Subtitles.url
[2011/10/31 23:10:52 | 000,000,124 | —- | C] () – C:\Making Your Next Business Trip Tax Deductible.htm
[2011/10/31 23:10:52 | 000,000,124 | —- | C] () – \Making Your Next Business Trip Tax Deductible.htm
[2011/10/31 23:10:52 | 000,000,124 | —- | C] () – C:\Driving For Dollars.url
[2011/10/31 23:10:52 | 000,000,124 | —- | C] () – \Driving For Dollars.url
[2011/10/31 23:10:52 | 000,000,108 | —- | C] () – C:\Tutorial for National Estimator.url
[2011/10/31 23:10:52 | 000,000,108 | —- | C] () – \Tutorial for National Estimator.url
[2011/10/31 08:22:15 | 000,000,126 | —- | C] () – C:\pclog_3460.dat
[2011/10/31 08:22:15 | 000,000,126 | —- | C] () – \pclog_3460.dat
[2011/10/30 16:35:55 | 000,000,126 | —- | C] () – C:\pclog_3496.dat
[2011/10/30 16:35:55 | 000,000,126 | —- | C] () – \pclog_3496.dat
[2011/10/30 00:20:40 | 000,000,910 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/29 14:34:32 | 000,002,519 | —- | C] () – C:\Users\Admin\Desktop\HiJackThis.lnk
[2011/10/28 09:39:54 | 000,000,680 | —- | C] () – C:\Users\Admin\AppData\Local\d3d9caps.dat
[2011/10/27 17:30:17 | 000,000,378 | —- | C] () – C:\pclog_3636.dat
[2011/10/27 17:30:17 | 000,000,378 | —- | C] () – \pclog_3636.dat
[2011/10/26 08:19:04 | 000,000,063 | —- | C] () – C:\pclog_3652.dat
[2011/10/26 08:19:04 | 000,000,063 | —- | C] () – \pclog_3652.dat
[2011/10/21 12:10:15 | 000,000,063 | —- | C] () – C:\pclog_4268.dat
[2011/10/21 12:10:15 | 000,000,063 | —- | C] () – \pclog_4268.dat
[2011/10/15 20:19:42 | 000,134,382 | —- | C] () – C:\Users\Admin\Documents\Pams_Itinerary101211.pdf
[2011/10/13 00:57:04 | 000,000,063 | —- | C] () – C:\pclog_3620.dat
[2011/10/13 00:57:04 | 000,000,063 | —- | C] () – \pclog_3620.dat
[2011/10/12 19:44:36 | 000,000,063 | —- | C] () – C:\pclog_3648.dat
[2011/10/12 19:44:36 | 000,000,063 | —- | C] () – \pclog_3648.dat
[2011/10/11 20:03:53 | 000,001,656 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/10/08 15:14:18 | 000,000,063 | —- | C] () – C:\pclog_3716.dat
[2011/10/08 15:14:18 | 000,000,063 | —- | C] () – \pclog_3716.dat
[2011/10/04 20:10:07 | 000,000,189 | —- | C] () – \pclog_3500.dat
[2011/09/29 00:25:54 | 000,000,063 | —- | C] () – \pclog_3656.dat
[2011/09/14 11:47:40 | 000,053,760 | —- | C] () – C:\Windows\SysWow64\OVDecode.dll
[2011/08/24 20:19:10 | 000,056,320 | —- | C] () – C:\Windows\SysWow64\OpenVideo.dll
[2011/06/29 13:47:56 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2011/06/13 08:47:01 | 1073,741,824 | —- | C] () – \pgbleach.27
[2011/05/08 10:01:03 | 000,000,120 | —- | C] () – C:\Users\Admin\AppData\Local\Snapadutodi.dat
[2011/05/08 10:01:03 | 000,000,000 | —- | C] () – C:\Users\Admin\AppData\Local\Ivekalega.bin
[2011/04/26 15:58:54 | 000,000,066 | —- | C] () – C:\Windows\bi_group.ini
[2011/03/22 23:41:29 | 1073,741,824 | —- | C] () – \pgbleach.45
[2011/03/17 13:51:44 | 000,003,929 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/03/15 01:48:25 | 000,000,000 | —- | C] () – C:\Windows\HPMProp.INI
[2011/01/08 01:37:39 | 000,000,000 | —- | C] () – C:\Users\Admin\AppData\Roaming\bibstats
[2010/12/25 20:53:38 | 000,000,007 | —- | C] () – C:\Windows\SysWow64\mkghj.dll
[2010/12/25 20:43:17 | 001,422,672 | —- | C] () – C:\Windows\SysWow64\cfgmig32.dll
[2010/12/25 20:43:17 | 000,263,504 | —- | C] () – C:\Windows\SysWow64\cfgmig32.exe
[2010/12/25 20:43:01 | 004,108,304 | —- | C] () – C:\Windows\SysWow64\win32cpr.dll
[2010/12/25 20:43:01 | 002,760,720 | —- | C] () – C:\Windows\SysWow64\svcprs32.exe
[2010/12/25 20:43:01 | 001,744,912 | —- | C] () – C:\Windows\SysWow64\winsflt.dll
[2010/12/25 20:43:01 | 000,098,320 | —- | C] () – C:\Windows\SysWow64\winsfinst.exe
[2010/12/25 20:43:00 | 003,207,184 | —- | C] () – C:\Windows\SysWow64\mdmcls32.exe
[2010/06/04 21:07:04 | 000,036,864 | —- | C] () – \nphssb.dll
[2010/06/04 21:07:04 | 000,000,247 | —- | C] () – \nphssb.xpt
[2010/06/04 21:04:21 | 000,098,136 | —- | C] () – C:\Windows\gzip.exe
[2010/05/31 16:27:08 | 000,000,000 | —- | C] () – C:\Windows\DVEdit.INI
[2010/05/11 22:30:25 | 000,000,062 | —- | C] () – C:\Windows\wininit.ini
[2010/04/07 11:25:11 | 000,037,027 | —- | C] () – C:\Windows\atmoUn.exe
[2010/02/16 00:17:13 | 000,004,096 | —- | C] () – C:\Users\Admin\AppData\Local\keyfile3.drm
[2010/02/01 22:38:22 | 000,016,384 | —- | C] () – C:\Windows\SysWow64\FileOps.exe
[2010/01/31 18:43:33 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2009/12/25 18:44:18 | 000,000,000 | —- | C] () – C:\Users\Admin\AppData\Roaming\downloads.m3u
[2009/12/08 22:52:35 | 000,073,220 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2009/12/08 22:52:35 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2009/12/08 22:52:35 | 000,029,114 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2009/12/08 22:52:35 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2009/12/08 22:52:35 | 000,021,021 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2009/12/08 22:52:35 | 000,015,670 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2009/12/08 22:52:35 | 000,013,280 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2009/12/08 22:52:35 | 000,010,673 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2009/12/08 22:52:35 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2009/12/08 22:52:35 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2009/12/08 22:52:35 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2009/12/08 22:52:35 | 000,001,137 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2009/12/08 22:52:35 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2009/12/08 22:52:35 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2009/12/08 22:52:35 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2009/12/08 22:52:35 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2009/12/08 22:50:16 | 000,000,044 | —- | C] () – C:\Windows\EPSNX400.ini
[2009/12/02 09:24:03 | 000,726,594 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2009/11/23 20:32:22 | 000,000,000 | —- | C] () – C:\Users\Admin\AppData\Roaming\wklnhst.dat
[2009/11/20 10:25:01 | 000,000,197 | —- | C] () – C:\Users\Admin\AppData\Roaming\default.rss
[2009/11/20 09:49:52 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2009/11/20 00:48:45 | 000,004,767 | —- | C] () – C:\Windows\Irremote.ini
[2009/11/19 00:19:06 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/11/19 00:18:37 | 000,107,612 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchema.bin
[2009/11/19 00:18:09 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/11/19 00:17:54 | 000,018,904 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2009/11/17 17:42:22 | 000,019,313 | —- | C] () – C:\Users\Admin\AppData\Roaming\UserTile.png
[2009/11/17 16:49:45 | 000,001,460 | —- | C] () – C:\Users\Admin\AppData\Local\d3d9caps64.dat
[2009/11/17 16:41:31 | 003,107,788 | —- | C] () – C:\Windows\SysWow64\atiumdva.dat
[2009/11/17 13:53:36 | 000,581,120 | —- | C] () – C:\Windows\mHotkey.exe
[2009/11/17 13:53:36 | 000,294,912 | —- | C] () – C:\Windows\PIC.dll
[2009/11/17 13:53:36 | 000,036,864 | —- | C] () – C:\Windows\LchDrvKey.exe
[2009/11/17 13:53:36 | 000,000,870 | —- | C] () – C:\Windows\mhotkey_reg.ini
[2009/09/10 17:31:13 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2008/01/20 22:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/01/09 20:29:25 | 000,001,324 | —- | C] () – C:\Windows\FF08_not_Spk_Hp.ini
[2008/01/09 20:29:25 | 000,001,269 | —- | C] () – C:\Windows\FF08_Render_Spk_Hp.ini
[2008/01/09 20:28:57 | 000,145,408 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2008/01/09 20:28:57 | 000,071,680 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2008/01/09 19:37:33 | 000,008,192 | R-S- | C] () – \BOOTSECT.BAK
[2008/01/09 19:37:32 | 000,333,257 | RHS- | C] () – \bootmgr
[2006/11/02 11:37:05 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:37:14 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2006/11/02 08:24:17 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 08:18:17 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2006/11/02 05:47:54 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/05/20 14:44:46 | 000,051,392 | —- | C] () – C:\Windows\SysWow64\drivers\atnt40k.sys
[2002/03/14 13:00:26 | 000,038,567 | —- | C] () – C:\Windows\SysWow64\pcpbios.exe
[1998/08/16 06:00:00 | 000,004,096 | —- | C] () – C:\Windows\SysWow64\sysres.dll

========== Files - Unicode (All) ==========
[2011/10/31 23:10:52 | 000,000,198 | —- | C] ()(C:\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics).url) – C:\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics).url
[2011/10/31 23:10:52 | 000,000,198 | —- | C] ()(\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics).url) – \Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics).url
[2011/10/31 23:10:52 | 000,000,195 | —- | C] ()(C:\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics) NEW.url) – C:\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics) NEW.url
[2011/10/31 23:10:52 | 000,000,195 | —- | C] ()(\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics) NEW.url) – \Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics) NEW.url
[2011/07/06 15:58:13 | 000,000,195 | —- | M] ()(C:\Users\Admin\Desktop\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics) NEW.url) – C:\Users\Admin\Desktop\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics) NEW.url
[2011/07/06 15:58:13 | 000,000,195 | —- | M] ()(C:\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics) NEW.url) – C:\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics) NEW.url
[2011/07/06 15:58:13 | 000,000,195 | —- | C] ()(C:\Users\Admin\Desktop\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics) NEW.url) – C:\Users\Admin\Desktop\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics) NEW.url
[2011/07/06 15:57:54 | 000,000,198 | —- | M] ()(C:\Users\Admin\Desktop\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics).url) – C:\Users\Admin\Desktop\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics).url
[2011/07/06 15:57:54 | 000,000,198 | —- | M] ()(C:\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics).url) – C:\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics).url
[2011/07/06 15:57:54 | 000,000,198 | —- | C] ()(C:\Users\Admin\Desktop\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics).url) – C:\Users\Admin\Desktop\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics).url

========== Alternate Data Streams ==========

@Alternate Data Stream - 166 bytes -> C:\ProgramData\TEMP:D3A96964
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:D287FACF

< End of report >

~James

Hi James, How is your system running now? Please run a new scan with OTL, but this time do not check Purity or LOP and then post the new log into your next reply. :)
Hey Jeff:

Sorry you aked me to provide this in your last post.
Here is the OTL Run Scan output file – OTL.TXT


OTL logfile created on: 11/5/2011 12:06:26 PM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Admin\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.99 Gb Total Physical Memory | 3.80 Gb Available Physical Memory | 63.39% Memory free
12.09 Gb Paging File | 9.68 Gb Available in Paging File | 80.03% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 688.87 Gb Total Space | 32.29 Gb Free Space | 4.69% Space Free | Partition Type: NTFS

Computer Name: ADMIN-PC | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Admin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
PRC - C:\Windows\SysWOW64\cfgmig32.exe ()
PRC - C:\Windows\SysWOW64\svcprs32.exe ()
PRC - C:\Windows\SysWOW64\mdmcls32.exe ()
PRC - C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrvProxy.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrvProxy.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Windows\mHotkey.exe ()
PRC - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Windows\CNYHKey.exe (Creative)
PRC - C:\Windows\ChiFuncExt.exe (Chicony)
PRC - C:\Windows\ModLEDKey.exe (Chicony)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Windows\SysWOW64\winsflt.dll ()
MOD - C:\Windows\mHotkey.exe ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (CAAMSvc) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\CAAMSvc.exe (CA)
SRV:64bit: - (CaCCProvSP) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
SRV:64bit: - (ccSchedulerSVC) – C:\Program Files\CA\CA Internet Security Suite\ccschedulersvc.exe (Computer Associates International, Inc.)
SRV:64bit: - (CAISafe) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus Plus\isafe.exe (Computer Associates International, Inc.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (UmxEngine) – C:\Program Files\CA\SharedComponents\TMEngine\UmxEngine.exe (CA)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (AgereModemAudio) – C:\Windows\SysNative\agr64svc.exe (Agere Systems)
SRV:64bit: - (ETService) – C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (NAUpdate) – C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
SRV - (WinSvchostManagerSrv) – C:\Windows\SysWOW64\cfgmig32.exe ()
SRV - (WinSvchostManager) – C:\Windows\SysWOW64\svcprs32.exe ()
SRV - (WinExtManager) – C:\Windows\SysWOW64\mdmcls32.exe ()
SRV - (SpeedDiskService) – C:\Program Files (x86)\Norton Utilities 15\Tools\SpeedDisk\SpeedDiskSrv.exe (Symantec Corporation)
SRV - (DiskDoctorService) – C:\Program Files (x86)\Norton Utilities 15\Tools\Disk Doctor\DiskDoctorSrv.exe (Symantec Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (GoToAssist) – C:\Program Files (x86)\Citrix\GoToAssist\615\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SupportSoft RemoteAssist) – C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe (SupportSoft, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (CTAudSvcService) – C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (Symantec RemoteAssist) – C:\Program Files (x86)\Common Files\Symantec Shared\Support Controls\ssrc.exe (Symantec, Inc.)
SRV - (Symantec Core LC) – C:\Program Files (x86)\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (EPSON_EB_RPCV4_01) EPSON V5 Service4(01) – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE (SEIKO EPSON CORPORATION)
SRV - (EPSON_PM_RPCV4_01) EPSON V3 Service4(01) – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (SEIKO EPSON CORPORATION)


========== Driver Services (SafeList) ==========

DRV:64bit: - (atikmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\DRIVERS\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (KmxCF) – C:\Windows\SysNative\DRIVERS\KmxCF.sys (CA)
DRV:64bit: - (KmxCfg) – C:\Windows\SysNative\DRIVERS\kmxcfg.sys (CA)
DRV:64bit: - (KmxAMRT) – C:\Windows\SysNative\DRIVERS\KmxAMRT.sys (CA)
DRV:64bit: - (KmxAgent) – C:\Windows\SysNative\DRIVERS\kmxagent.sys (CA)
DRV:64bit: - (KmxFile) – C:\Windows\SysNative\DRIVERS\KmxFile.sys (CA)
DRV:64bit: - (KmxSbx) – C:\Windows\SysNative\DRIVERS\KmxSbx.sys (CA)
DRV:64bit: - (KmxFw) – C:\Windows\SysNative\DRIVERS\kmxfw.sys (CA)
DRV:64bit: - (KmxFilter) – C:\Windows\SysNative\DRIVERS\KmxFilter.sys (CA)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\Drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (SymDSMon) – C:\Windows\SysNative\drivers\SymDSMon.sys (Symantec Corporation)
DRV:64bit: - (SYMSpeedDisk) – C:\Windows\SysNative\drivers\SymSpeedDisk.sys (Symantec Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\DRIVERS\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (AgereSoftModem) – C:\Windows\SysNative\DRIVERS\agrsm64.sys (LSI Corporation)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (HPEWSFXBULK) – C:\Windows\SysNative\drivers\hpfx64bulk.sys (Hewlett Packard)
DRV:64bit: - (RTL8187Se) – C:\Windows\SysNative\DRIVERS\RTL8187Se.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (RTHDMIAzAudService) – C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\DRIVERS\iaStor.sys (Intel Corporation)
DRV:64bit: - (e1yexpress) Intel® – C:\Windows\SysNative\DRIVERS\e1y60x64.sys (Intel Corporation)
DRV:64bit: - (gwfilt64) – C:\Windows\SysNative\drivers\gwfilt64.sys (Creative Technology Ltd.)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (SYMSpeedDisk) – C:\Windows\SysWOW64\drivers\SymSpeedDisk.sys (Symantec Corporation)
DRV - (int15) – C:\Windows\SysWOW64\drivers\int15_64.sys (Acer, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files (x86)\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Admin\AppData\Local\Google\Update\1.3.21.53\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Admin\AppData\Local\Google\Update\1.3.21.53\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\Toolbar\Firefox [2011/09/16 12:12:51 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{5576EE23-03F7-4284-AA8B-760A71D594D2}: C:\Users\Admin\AppData\Local\{5576EE23-03F7-4284-AA8B-760A71D594D2} [2011/05/08 10:01:02 | 000,000,000 | —D | M]

[2011/06/30 14:30:14 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll

O1 HOSTS File: ([2011/11/04 21:11:21 | 000,000,098 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (CA Anti-Phishing Toolbar Helper) - {45011CF5-E4A9-4F13-9093-F30A784EB9B2} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O2 - BHO: (CA Anti-Phishing Toolbar Helper) - {45011CF5-E4A9-4F13-9093-F30A784EB9B2} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\Toolbar\caIEToolbar.dll (CA, Inc.)
O2 - BHO: (WinZip Courier BHO) - {A8FB70FA-0FDF-4601-9DC4-BFA1B357204F} - C:\Program Files (x86)\WinZip Courier\wzwmcie.dll (WinZip Computing, S.L.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKLM\..\Toolbar: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (CA Anti-Phishing Toolbar) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\Toolbar\caIEToolbar.dll (CA, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\casc.exe (CA, Inc.)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RunDLLEntry] C:\Windows\SysNative\AmbRunE.DLL (Creative Technology Ltd.)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [LchDrvKey] C:\Windows\LchDrvKey.exe ()
O4 - HKLM..\Run: [LedKey] C:\Windows\CNYHKey.exe (Creative)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - wwinsflt.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\VetRedir64.dll (Computer Associates International, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\VetRedir64.dll (Computer Associates International, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000020 - C:\Windows\SysNative\VetRedir64.dll (Computer Associates International, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000021 - wwinsflt.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.5.7.cab (DLM Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A417D75D-F4FC-4C7A-BA84-8CE7394E032E}: DhcpNameServer = 192.168.0.1
O20:64bit: - AppInit_DLLs: (C:\Windows\System32\UmxSbxExA64.dll) - C:\Windows\SysNative\UmxSbxExA64.dll (CA)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\615\G2AWinLogon_x64.dll) - C:\Program Files (x86)\Citrix\GoToAssist\615\g2awinlogon_x64.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20:64bit: - Winlogon\Notify\PFW: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20 - Winlogon\Notify\PFW: DllName - (UmxWnp.Dll) - C:\Windows\SysWow64\UmxWNP.dll (CA)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/04 21:10:41 | 000,000,000 | —D | C] – C:\_OTL
[2011/11/04 21:10:41 | 000,000,000 | —D | C] – \_OTL
[2011/11/04 20:57:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2011/11/04 20:57:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\ERUNT
[2011/11/04 15:12:34 | 000,791,393 | —- | C] (Lars Hederer ) – C:\Users\Admin\Desktop\erunt-setup.exe
[2011/11/04 08:59:19 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Admin\Desktop\OTL.exe
[2011/11/02 23:26:40 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/11/02 23:26:40 | 000,000,000 | -HSD | C] – \$RECYCLE.BIN
[2011/11/02 22:48:28 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/11/02 22:48:28 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Local\temp
[2011/11/02 22:16:48 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/11/01 19:41:57 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/11/01 19:41:57 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/11/01 19:40:20 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/11/01 19:37:57 | 000,000,000 | —D | C] – C:\Qoobox
[2011/11/01 19:37:57 | 000,000,000 | —D | C] – \Qoobox
[2011/10/31 23:11:24 | 001,916,416 | —- | C] (AVAST Software) – C:\Users\Admin\Desktop\aswMBR.exe
[2011/10/31 23:11:24 | 000,607,260 | R— | C] (Swearware) – C:\Users\Admin\Desktop\dds.com
[2011/10/30 00:20:55 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Roaming\Malwarebytes
[2011/10/30 00:20:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/10/30 00:20:39 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/10/30 00:20:34 | 000,025,416 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/10/30 00:20:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/10/29 23:59:05 | 000,000,000 | —D | C] – C:\Config.Msi
[2011/10/29 23:59:05 | 000,000,000 | —D | C] – \Config.Msi
[2011/10/29 14:34:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/10/29 14:34:32 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/10/29 13:37:20 | 000,446,464 | —- | C] (OldTimer Tools) – C:\Users\Admin\Desktop\TFC.exe
[2011/10/29 13:37:17 | 009,852,544 | —- | C] (Malwarebytes Corporation ) – C:\Users\Admin\Desktop\mbam-setup-1.51.2.1300.exe
[2011/10/27 18:16:00 | 004,266,378 | —- | C] (Swearware) – C:\Users\Admin\Desktop\Combo-Fix.exe
[2011/10/27 18:15:05 | 004,280,796 | R— | C] (Swearware) – C:\Users\Admin\Desktop\ComboFix.exe
[2011/10/13 03:01:08 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/10/13 03:01:08 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/10/13 03:01:07 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/10/13 03:01:07 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/10/13 03:01:06 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/10/13 03:01:06 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/10/13 03:01:06 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/10/13 03:01:05 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/10/13 03:01:05 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/10/12 20:09:31 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/10/12 20:09:31 | 000,735,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAutomationCore.dll
[2011/10/12 20:09:31 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAutomationCore.dll
[2011/10/12 20:09:31 | 000,332,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2011/10/12 20:09:31 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\oleaccrc.dll
[2011/10/12 20:09:31 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaccrc.dll
[2011/10/12 20:08:59 | 000,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/10/12 20:08:59 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/10/12 20:08:59 | 000,289,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2011/10/12 20:08:59 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2011/10/12 20:08:59 | 000,100,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Mpeg2Data.ax
[2011/10/12 20:08:59 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSDvbNP.ax
[2011/10/12 20:08:59 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Mpeg2Data.ax
[2011/10/12 20:08:59 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSDvbNP.ax
[2011/10/11 20:03:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/10/11 20:03:05 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/10/11 20:02:31 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/10/11 20:02:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/10/11 19:54:35 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/10/11 19:54:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour

========== Files - Modified Within 30 Days ==========

[2011/11/05 11:55:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4027082081-1360438707-2940866900-1000UA.job
[2011/11/05 11:29:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/05 11:03:48 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/05 11:03:32 | 000,000,000 | —- | M] () – C:\Windows\SysNative\LogConfigTemp.xml
[2011/11/05 11:03:25 | 000,006,080 | —- | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/05 11:03:25 | 000,006,080 | —- | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/05 11:03:17 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/05 03:46:03 | 003,659,453 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k0
[2011/11/05 03:46:03 | 000,000,337 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k0
[2011/11/05 03:46:03 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k7
[2011/11/05 03:46:03 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k6
[2011/11/05 03:46:03 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k5
[2011/11/05 03:46:03 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k4
[2011/11/05 03:46:03 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k3
[2011/11/05 03:46:03 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k2
[2011/11/05 03:46:03 | 000,000,085 | —- | M] () – C:\Windows\SysNative\drivers\kmxcfg.u2k1
[2011/11/05 03:46:03 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k7
[2011/11/05 03:46:03 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k6
[2011/11/05 03:46:03 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k5
[2011/11/05 03:46:03 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k4
[2011/11/05 03:46:03 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k3
[2011/11/05 03:46:03 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k2
[2011/11/05 03:46:03 | 000,000,049 | —- | M] () – C:\Windows\SysNative\drivers\kmxzone.u2k1
[2011/11/05 03:46:02 | 000,372,244 | —- | M] () – C:\Windows\SysNative\drivers\KmxAgent.asc
[2011/11/04 21:11:21 | 000,000,098 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/11/04 21:10:46 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4027082081-1360438707-2940866900-1000Core.job
[2011/11/04 20:57:44 | 000,725,182 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/04 20:57:44 | 000,620,130 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/11/04 20:57:44 | 000,109,204 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/11/04 20:57:22 | 000,000,725 | —- | M] () – C:\Users\Admin\Desktop\NTREGOPT.lnk
[2011/11/04 20:57:22 | 000,000,706 | —- | M] () – C:\Users\Admin\Desktop\ERUNT.lnk
[2011/11/04 15:12:34 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Users\Admin\Desktop\erunt-setup.exe
[2011/11/04 09:17:19 | 000,000,126 | —- | M] () – C:\pclog_3440.dat
[2011/11/03 23:58:22 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Admin\Desktop\OTL.exe
[2011/11/02 18:50:28 | 004,280,796 | R— | M] (Swearware) – C:\Users\Admin\Desktop\ComboFix.exe
[2011/11/01 03:51:40 | 000,000,378 | —- | M] () – C:\pclog_3636.dat
[2011/10/31 23:08:05 | 000,000,680 | —- | M] () – C:\Users\Admin\AppData\Local\d3d9caps.dat
[2011/10/31 22:51:08 | 001,916,416 | —- | M] (AVAST Software) – C:\Users\Admin\Desktop\aswMBR.exe
[2011/10/31 22:48:58 | 000,607,260 | R— | M] (Swearware) – C:\Users\Admin\Desktop\dds.com
[2011/10/31 13:55:02 | 000,002,519 | —- | M] () – C:\Users\Admin\Desktop\HiJackThis.lnk
[2011/10/31 08:44:05 | 000,000,126 | —- | M] () – C:\pclog_3460.dat
[2011/10/31 01:50:58 | 000,000,126 | —- | M] () – C:\pclog_3496.dat
[2011/10/30 00:20:40 | 000,000,910 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/29 13:01:15 | 009,852,544 | —- | M] (Malwarebytes Corporation ) – C:\Users\Admin\Desktop\mbam-setup-1.51.2.1300.exe
[2011/10/29 12:58:04 | 000,446,464 | —- | M] (OldTimer Tools) – C:\Users\Admin\Desktop\TFC.exe
[2011/10/28 08:57:04 | 000,000,245 | —- | M] () – C:\Win32-FakeAV.NQ trojan infection - Tech Support Guy Forums.url
[2011/10/27 18:16:00 | 004,266,378 | —- | M] (Swearware) – C:\Users\Admin\Desktop\Combo-Fix.exe
[2011/10/27 16:17:03 | 000,000,930 | —- | M] () – C:\Users\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2011/10/26 08:19:04 | 000,000,063 | —- | M] () – C:\pclog_3652.dat
[2011/10/21 12:10:15 | 000,000,063 | —- | M] () – C:\pclog_4268.dat
[2011/10/16 05:41:04 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/10/15 20:19:42 | 000,134,382 | —- | M] () – C:\Users\Admin\Documents\Pams_Itinerary101211.pdf
[2011/10/13 03:50:48 | 000,389,272 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/10/13 00:57:04 | 000,000,063 | —- | M] () – C:\pclog_3620.dat
[2011/10/12 22:02:32 | 928,890,990 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/10/12 19:44:36 | 000,000,063 | —- | M] () – C:\pclog_3648.dat
[2011/10/11 20:03:53 | 000,001,656 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/10/10 01:17:12 | 000,000,069 | —- | M] () – C:\Windows\NeroDigital.ini
[2011/10/08 15:14:18 | 000,000,063 | —- | M] () – C:\pclog_3716.dat

========== Files Created - No Company Name ==========

[2011/11/04 20:57:22 | 000,000,725 | —- | C] () – C:\Users\Admin\Desktop\NTREGOPT.lnk
[2011/11/04 20:57:22 | 000,000,706 | —- | C] () – C:\Users\Admin\Desktop\ERUNT.lnk
[2011/11/04 09:14:49 | 000,000,126 | —- | C] () – C:\pclog_3440.dat
[2011/11/04 09:14:49 | 000,000,126 | —- | C] () – \pclog_3440.dat
[2011/11/01 19:41:57 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2011/11/01 19:41:57 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/11/01 19:41:57 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/11/01 19:41:57 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/11/01 19:41:57 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/10/31 23:10:54 | 010,288,649 | —- | C] () – C:\Submission_Contract.pdf
[2011/10/31 23:10:54 | 010,288,649 | —- | C] () – \Submission_Contract.pdf
[2011/10/31 23:10:54 | 002,913,028 | —- | C] () – C:\ICISurvivalGuide.pdf
[2011/10/31 23:10:54 | 002,913,028 | —- | C] () – \ICISurvivalGuide.pdf
[2011/10/31 23:10:54 | 000,851,948 | —- | C] () – C:\GAO_Report_Foreclosures.pdf
[2011/10/31 23:10:54 | 000,851,948 | —- | C] () – \GAO_Report_Foreclosures.pdf
[2011/10/31 23:10:54 | 000,122,770 | —- | C] () – C:\winningargument.pdf
[2011/10/31 23:10:54 | 000,122,770 | —- | C] () – \winningargument.pdf
[2011/10/31 23:10:54 | 000,056,589 | —- | C] () – C:\sf_rcd_execsum.pdf
[2011/10/31 23:10:54 | 000,056,589 | —- | C] () – \sf_rcd_execsum.pdf
[2011/10/31 23:10:52 | 081,020,975 | —- | C] () – C:\2011-05-11 19.04 The Perfect Storm for Paper Buyers.wmv
[2011/10/31 23:10:52 | 081,020,975 | —- | C] () – \2011-05-11 19.04 The Perfect Storm for Paper Buyers.wmv
[2011/10/31 23:10:52 | 000,002,002 | —- | C] () – C:\National Estimator.lnk
[2011/10/31 23:10:52 | 000,002,002 | —- | C] () – \National Estimator.lnk
[2011/10/31 23:10:52 | 000,001,703 | —- | C] () – C:\1846 Douglas Ave Dunedin - Shortcut.lnk
[2011/10/31 23:10:52 | 000,001,703 | —- | C] () – \1846 Douglas Ave Dunedin - Shortcut.lnk
[2011/10/31 23:10:52 | 000,000,699 | —- | C] () – C:\Winamp.lnk
[2011/10/31 23:10:52 | 000,000,699 | —- | C] () – \Winamp.lnk
[2011/10/31 23:10:52 | 000,000,245 | —- | C] () – C:\Win32-FakeAV.NQ trojan infection - Tech Support Guy Forums.url
[2011/10/31 23:10:52 | 000,000,245 | —- | C] () – \Win32-FakeAV.NQ trojan infection - Tech Support Guy Forums.url
[2011/10/31 23:10:52 | 000,000,215 | —- | C] () – C:\Intelligent Real Estate Investment Decisions - eRealInvestor.url
[2011/10/31 23:10:52 | 000,000,215 | —- | C] () – \Intelligent Real Estate Investment Decisions - eRealInvestor.url
[2011/10/31 23:10:52 | 000,000,211 | —- | C] () – C:\Progressive Rock - Definition, Genres & Articles.url
[2011/10/31 23:10:52 | 000,000,211 | —- | C] () – \Progressive Rock - Definition, Genres & Articles.url
[2011/10/31 23:10:52 | 000,000,208 | —- | C] () – C:\Demystifying Fraud.url
[2011/10/31 23:10:52 | 000,000,208 | —- | C] () – \Demystifying Fraud.url
[2011/10/31 23:10:52 | 000,000,203 | —- | C] () – C:\FHA Loan Limits for CALIFORNIA.url
[2011/10/31 23:10:52 | 000,000,203 | —- | C] () – \FHA Loan Limits for CALIFORNIA.url
[2011/10/31 23:10:52 | 000,000,200 | —- | C] () – C:\PortalProgressive rock - Wikipedia, the free encyclopedia.url
[2011/10/31 23:10:52 | 000,000,200 | —- | C] () – \PortalProgressive rock - Wikipedia, the free encyclopedia.url
[2011/10/31 23:10:52 | 000,000,147 | —- | C] () – C:\Demystifying Fraud part 2.url
[2011/10/31 23:10:52 | 000,000,147 | —- | C] () – \Demystifying Fraud part 2.url
[2011/10/31 23:10:52 | 000,000,137 | —- | C] () – C:\D-Addicts View topic - [Tutorial] How to Burn w- Subtitles.url
[2011/10/31 23:10:52 | 000,000,137 | —- | C] () – \D-Addicts View topic - [Tutorial] How to Burn w- Subtitles.url
[2011/10/31 23:10:52 | 000,000,124 | —- | C] () – C:\Making Your Next Business Trip Tax Deductible.htm
[2011/10/31 23:10:52 | 000,000,124 | —- | C] () – \Making Your Next Business Trip Tax Deductible.htm
[2011/10/31 23:10:52 | 000,000,124 | —- | C] () – C:\Driving For Dollars.url
[2011/10/31 23:10:52 | 000,000,124 | —- | C] () – \Driving For Dollars.url
[2011/10/31 23:10:52 | 000,000,108 | —- | C] () – C:\Tutorial for National Estimator.url
[2011/10/31 23:10:52 | 000,000,108 | —- | C] () – \Tutorial for National Estimator.url
[2011/10/31 08:22:15 | 000,000,126 | —- | C] () – C:\pclog_3460.dat
[2011/10/31 08:22:15 | 000,000,126 | —- | C] () – \pclog_3460.dat
[2011/10/30 16:35:55 | 000,000,126 | —- | C] () – C:\pclog_3496.dat
[2011/10/30 16:35:55 | 000,000,126 | —- | C] () – \pclog_3496.dat
[2011/10/30 00:20:40 | 000,000,910 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/29 14:34:32 | 000,002,519 | —- | C] () – C:\Users\Admin\Desktop\HiJackThis.lnk
[2011/10/28 09:39:54 | 000,000,680 | —- | C] () – C:\Users\Admin\AppData\Local\d3d9caps.dat
[2011/10/27 17:30:17 | 000,000,378 | —- | C] () – C:\pclog_3636.dat
[2011/10/27 17:30:17 | 000,000,378 | —- | C] () – \pclog_3636.dat
[2011/10/26 08:19:04 | 000,000,063 | —- | C] () – C:\pclog_3652.dat
[2011/10/26 08:19:04 | 000,000,063 | —- | C] () – \pclog_3652.dat
[2011/10/21 12:10:15 | 000,000,063 | —- | C] () – C:\pclog_4268.dat
[2011/10/21 12:10:15 | 000,000,063 | —- | C] () – \pclog_4268.dat
[2011/10/15 20:19:42 | 000,134,382 | —- | C] () – C:\Users\Admin\Documents\Pams_Itinerary101211.pdf
[2011/10/13 00:57:04 | 000,000,063 | —- | C] () – C:\pclog_3620.dat
[2011/10/13 00:57:04 | 000,000,063 | —- | C] () – \pclog_3620.dat
[2011/10/12 19:44:36 | 000,000,063 | —- | C] () – C:\pclog_3648.dat
[2011/10/12 19:44:36 | 000,000,063 | —- | C] () – \pclog_3648.dat
[2011/10/11 20:03:53 | 000,001,656 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/10/08 15:14:18 | 000,000,063 | —- | C] () – C:\pclog_3716.dat
[2011/10/08 15:14:18 | 000,000,063 | —- | C] () – \pclog_3716.dat
[2011/10/04 20:10:07 | 000,000,189 | —- | C] () – \pclog_3500.dat
[2011/09/29 00:25:54 | 000,000,063 | —- | C] () – \pclog_3656.dat
[2011/09/14 11:47:40 | 000,053,760 | —- | C] () – C:\Windows\SysWow64\OVDecode.dll
[2011/08/24 20:19:10 | 000,056,320 | —- | C] () – C:\Windows\SysWow64\OpenVideo.dll
[2011/06/29 13:47:56 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2011/06/13 08:47:01 | 1073,741,824 | —- | C] () – \pgbleach.27
[2011/05/08 10:01:03 | 000,000,120 | —- | C] () – C:\Users\Admin\AppData\Local\Snapadutodi.dat
[2011/05/08 10:01:03 | 000,000,000 | —- | C] () – C:\Users\Admin\AppData\Local\Ivekalega.bin
[2011/04/26 15:58:54 | 000,000,066 | —- | C] () – C:\Windows\bi_group.ini
[2011/03/22 23:41:29 | 1073,741,824 | —- | C] () – \pgbleach.45
[2011/03/17 13:51:44 | 000,003,929 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/03/15 01:48:25 | 000,000,000 | —- | C] () – C:\Windows\HPMProp.INI
[2011/01/08 01:37:39 | 000,000,000 | —- | C] () – C:\Users\Admin\AppData\Roaming\bibstats
[2010/12/25 20:53:38 | 000,000,007 | —- | C] () – C:\Windows\SysWow64\mkghj.dll
[2010/12/25 20:43:17 | 001,422,672 | —- | C] () – C:\Windows\SysWow64\cfgmig32.dll
[2010/12/25 20:43:17 | 000,263,504 | —- | C] () – C:\Windows\SysWow64\cfgmig32.exe
[2010/12/25 20:43:01 | 004,108,304 | —- | C] () – C:\Windows\SysWow64\win32cpr.dll
[2010/12/25 20:43:01 | 002,760,720 | —- | C] () – C:\Windows\SysWow64\svcprs32.exe
[2010/12/25 20:43:01 | 001,744,912 | —- | C] () – C:\Windows\SysWow64\winsflt.dll
[2010/12/25 20:43:01 | 000,098,320 | —- | C] () – C:\Windows\SysWow64\winsfinst.exe
[2010/12/25 20:43:00 | 003,207,184 | —- | C] () – C:\Windows\SysWow64\mdmcls32.exe
[2010/06/04 21:07:04 | 000,036,864 | —- | C] () – \nphssb.dll
[2010/06/04 21:07:04 | 000,000,247 | —- | C] () – \nphssb.xpt
[2010/06/04 21:04:21 | 000,098,136 | —- | C] () – C:\Windows\gzip.exe
[2010/05/31 16:27:08 | 000,000,000 | —- | C] () – C:\Windows\DVEdit.INI
[2010/05/11 22:30:25 | 000,000,062 | —- | C] () – C:\Windows\wininit.ini
[2010/04/07 11:25:11 | 000,037,027 | —- | C] () – C:\Windows\atmoUn.exe
[2010/02/16 00:17:13 | 000,004,096 | —- | C] () – C:\Users\Admin\AppData\Local\keyfile3.drm
[2010/02/01 22:38:22 | 000,016,384 | —- | C] () – C:\Windows\SysWow64\FileOps.exe
[2010/01/31 18:43:33 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2009/12/25 18:44:18 | 000,000,000 | —- | C] () – C:\Users\Admin\AppData\Roaming\downloads.m3u
[2009/12/08 22:52:35 | 000,073,220 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2009/12/08 22:52:35 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2009/12/08 22:52:35 | 000,029,114 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2009/12/08 22:52:35 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2009/12/08 22:52:35 | 000,021,021 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2009/12/08 22:52:35 | 000,015,670 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2009/12/08 22:52:35 | 000,013,280 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2009/12/08 22:52:35 | 000,010,673 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2009/12/08 22:52:35 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2009/12/08 22:52:35 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2009/12/08 22:52:35 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2009/12/08 22:52:35 | 000,001,137 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2009/12/08 22:52:35 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2009/12/08 22:52:35 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2009/12/08 22:52:35 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2009/12/08 22:52:35 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2009/12/08 22:50:16 | 000,000,044 | —- | C] () – C:\Windows\EPSNX400.ini
[2009/12/02 09:24:03 | 000,726,594 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2009/11/23 20:32:22 | 000,000,000 | —- | C] () – C:\Users\Admin\AppData\Roaming\wklnhst.dat
[2009/11/20 10:25:01 | 000,000,197 | —- | C] () – C:\Users\Admin\AppData\Roaming\default.rss
[2009/11/20 09:49:52 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2009/11/20 00:48:45 | 000,004,767 | —- | C] () – C:\Windows\Irremote.ini
[2009/11/19 00:19:06 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/11/19 00:18:37 | 000,107,612 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchema.bin
[2009/11/19 00:18:09 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/11/19 00:17:54 | 000,018,904 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2009/11/17 17:42:22 | 000,019,313 | —- | C] () – C:\Users\Admin\AppData\Roaming\UserTile.png
[2009/11/17 16:49:45 | 000,001,460 | —- | C] () – C:\Users\Admin\AppData\Local\d3d9caps64.dat
[2009/11/17 16:41:31 | 003,107,788 | —- | C] () – C:\Windows\SysWow64\atiumdva.dat
[2009/11/17 13:53:36 | 000,581,120 | —- | C] () – C:\Windows\mHotkey.exe
[2009/11/17 13:53:36 | 000,294,912 | —- | C] () – C:\Windows\PIC.dll
[2009/11/17 13:53:36 | 000,036,864 | —- | C] () – C:\Windows\LchDrvKey.exe
[2009/11/17 13:53:36 | 000,000,870 | —- | C] () – C:\Windows\mhotkey_reg.ini
[2009/09/10 17:31:13 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2008/01/20 22:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/01/09 20:29:25 | 000,001,324 | —- | C] () – C:\Windows\FF08_not_Spk_Hp.ini
[2008/01/09 20:29:25 | 000,001,269 | —- | C] () – C:\Windows\FF08_Render_Spk_Hp.ini
[2008/01/09 20:28:57 | 000,145,408 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2008/01/09 20:28:57 | 000,071,680 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2008/01/09 19:37:33 | 000,008,192 | R-S- | C] () – \BOOTSECT.BAK
[2008/01/09 19:37:32 | 000,333,257 | RHS- | C] () – \bootmgr
[2006/11/02 11:37:05 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 08:37:14 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2006/11/02 08:24:17 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 08:18:17 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2006/11/02 05:47:54 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/05/20 14:44:46 | 000,051,392 | —- | C] () – C:\Windows\SysWow64\drivers\atnt40k.sys
[2002/03/14 13:00:26 | 000,038,567 | —- | C] () – C:\Windows\SysWow64\pcpbios.exe
[1998/08/16 06:00:00 | 000,004,096 | —- | C] () – C:\Windows\SysWow64\sysres.dll

========== Files - Unicode (All) ==========
[2011/10/31 23:10:52 | 000,000,198 | —- | C] ()(C:\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics).url) – C:\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics).url
[2011/10/31 23:10:52 | 000,000,198 | —- | C] ()(\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics).url) – \Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics).url
[2011/10/31 23:10:52 | 000,000,195 | —- | C] ()(C:\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics) NEW.url) – C:\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics) NEW.url
[2011/10/31 23:10:52 | 000,000,195 | —- | C] ()(\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics) NEW.url) – \Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics) NEW.url
[2011/07/06 15:58:13 | 000,000,195 | —- | M] ()(C:\Users\Admin\Desktop\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics) NEW.url) – C:\Users\Admin\Desktop\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics) NEW.url
[2011/07/06 15:58:13 | 000,000,195 | —- | M] ()(C:\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics) NEW.url) – C:\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics) NEW.url
[2011/07/06 15:58:13 | 000,000,195 | —- | C] ()(C:\Users\Admin\Desktop\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics) NEW.url) – C:\Users\Admin\Desktop\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics) NEW.url
[2011/07/06 15:57:54 | 000,000,198 | —- | M] ()(C:\Users\Admin\Desktop\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics).url) – C:\Users\Admin\Desktop\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics).url
[2011/07/06 15:57:54 | 000,000,198 | —- | M] ()(C:\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics).url) – C:\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics).url
[2011/07/06 15:57:54 | 000,000,198 | —- | C] ()(C:\Users\Admin\Desktop\Korean Drama Group ?? ? ? - View topic - Adding Permanent Subtitles (with pics).url) – C:\Users\Admin\Desktop\Korean Drama Group 한국 무 리 - View topic - Adding Permanent Subtitles (with pics).url

========== Alternate Data Streams ==========

@Alternate Data Stream - 166 bytes -> C:\ProgramData\TEMP:D3A96964
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:D287FACF

< End of report >

Questions:

Is it possible that some system files could be permanently damaged from the infection(s)?
What is the remedy for repairing or replacing those damaged files?
It seems my Java is not working anymore, what do you suggest download from SunMicrosytems?
Hi James,

Good questions…It is possible for files to be damaged but I am not seeing that yet. If it comes to that we can fix it. :)
———-

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).


Hi Jeff:


The output file GOOREDFIX.TXT

GooredFix by jpshortstuff (03.07.10.1)
Log created at 14:51 on 06/11/2011 (Admin)
Firefox version [Unable to determine]

========== GooredScan ==========


========== GooredLog ==========

C:\Program Files (x86)\Mozilla Firefox\extensions\
(none)

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [18:35 17/11/2009]
"[removed]"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Phishing\x86\Toolbar\Firefox" [00:45 26/12/2010]

———- Old Logs ———-
GooredFix[19.50.42_06-11-2011].txt

-=E.O.F=-



~James


Hi James,

Please download JavaRa to your desktop and unzip it to its own
folder
  • Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista), pick the language of your choice and click Select. Then
    click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista) again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest
    Java Runtime Environment (JRE) version for your computer.
———-

How is your system running? What remaining issues are you having? :)
Hi Jeff: Thanks for the help. I ran JavaRa and removed older versions and reinstalled the latest version of Java SE Runtime. Current issues: I am unable to view video content on the internet such as YouTube, etc including imbedded content on websites I also cannot go to webpages from links on search engines such as google or links within webpages ~James
Hi James,

Do an online scan with BitDefender QuickScan.
Please be patient as scanning may take some time. If you have problem running the scan, you might want to disable any real time protection that you have.
  • Click here to go to BitDefender QuickScan page.
  • For Firefox users:
    • Click on Free Scan Now. You will be prompted to install a plug-in. Please Allow. In case you get stuck, please refresh the page to try again.
    • A Software Installation window will appear. Click Install Now and the plugin will be installed as an Add-on.
    • Restart Firefox when done. Go back to the BitDefender QuickScan page again and click on Free Scan Now and proceed accordingly.
  • For Internet Explorer users:
    • Click on Free Scan Now. You will be prompted to install an ActiveX control. Please install.
    • The page will refresh. Click on Free Scan Now again and proceed accordingly.
  • When scan has completed, click on View report and a Notepad log shall open.
  • If there are any infections found, you will get a warning and the link to the report will be displayed as the number of infections. Click on it.
  • Post back the contents of this report. It can also be found at C:\Documents and Settings\\Application Data\QuickScan, is the Windows log-in name.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI