This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

this is my stuff [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL Extras logfile created on: 12/20/2011 5:00:08 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\consul69\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.87 Gb Total Physical Memory | 1.03 Gb Available Physical Memory | 55.24% Memory free
3.99 Gb Paging File | 2.81 Gb Available in Paging File | 70.45% Paging File free
Paging file location(s): ?:\pagefile.sys

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 137.14 Gb Total Space | 75.28 Gb Free Space | 54.89% Space Free | Partition Type: NTFS
Drive D: | 11.91 Gb Total Space | 1.85 Gb Free Space | 15.50% Space Free | Partition Type: NTFS

Computer Name: CONSUL69-PC | User Name: consul69 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 60 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.pif [@ = piffile] – "%1" %*"
.scr [@ = Reg Error: Key error.] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*"
regfile [merge] – Reg Error: Key error.
scrfile [config] – Reg Error: Key error.
scrfile [install] – Reg Error: Key error.
scrfile [open] – Reg Error: Key error.
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
"DisableSR" = 0
"DisableConfig" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0595250A-FF2F-4F94-96FE-8A7D783FE609}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{0721E790-8F5A-4946-B213-5BAD6AFB59A4}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{0993AAB6-D5A1-4F5F-92B7-16A612E7B1C2}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0A1AB0B2-5F33-4BA6-BF27-E7EDCF6D8C8A}" = lport=10244 | protocol=6 | dir=in | app=system |
"{0B228180-0754-4550-A142-726F21AC1A5B}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{12464FAE-F971-4F8F-87DF-76E42215F5FB}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{17A8F994-D37E-4087-AF15-0B309BFBE095}" = lport=10243 | protocol=6 | dir=in | app=system |
"{186C957E-9A86-4664-B0B3-A158C4DFED55}" = lport=10244 | protocol=6 | dir=in | app=system |
"{1BA19C08-3ACB-441A-B7E4-3CAE8DD33FE2}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{1C84B43B-C193-4FB1-A68B-B129E02DB387}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{274C12E5-87C3-4B15-AF3F-4A30F2BD133D}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{335966A4-53C4-4B9F-B8A5-38A1ECE5138E}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | app=c:\windows\system32\svchost.exe |
"{3576FE52-BD50-4C32-A445-CF37892F22B6}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{3873886F-FB24-4AC5-9740-78C725BC09AB}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{38F83032-B494-4C0A-A631-C46476CBFC03}" = lport=3390 | protocol=6 | dir=in | app=system |
"{39596123-EBEA-471E-9197-51C63A113993}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{41EF097B-7BC7-43EC-81FE-5DC555189CDF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{44D6BC9F-63F4-42E2-ACBF-C4B88BCA3ABA}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{487A09C1-8F67-4836-968D-6F9BE214472D}" = rport=10244 | protocol=6 | dir=out | app=system |
"{55723C68-0840-4349-9078-BB39D81D73EE}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{57DE4FEB-50D8-47F1-A906-B99A6846C529}" = rport=10243 | protocol=6 | dir=out | app=system |
"{5C16D694-C0B1-4B64-84D3-B3F395C021D7}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{5ECC76E4-B4CE-4E23-962E-5B34D1C5EBEE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{627BF55A-4B64-46B2-ADD2-B6B19809CE5C}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{6A24A436-044F-4F38-B727-22CEFB264F39}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{6E91FE71-E723-4A42-965A-DBD6A4475608}" = rport=10244 | protocol=6 | dir=out | app=system |
"{6ECB71AA-C314-4585-BD7D-0644CDABB6F3}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7F7AD4DA-5D66-4D51-8984-C51D91CA6526}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7F9CA516-52D2-413F-97DA-116ED26F5B87}" = lport=2869 | protocol=6 | dir=in | app=system |
"{883CACAC-B0E4-4714-B99D-6DDAE9D1C3B9}" = lport=2869 | protocol=6 | dir=in | app=system |
"{9003B1E8-57F1-41AA-BB81-8915D15C25A0}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9C3DD6B4-0553-4119-BDCE-6B68344636E5}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9FFF6DAA-95A6-48A3-BBEF-688E97F85CDC}" = lport=3390 | protocol=6 | dir=in | app=system |
"{A7D9F3CB-0F23-45C7-AB9D-68CD8CEF73EF}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{B95E15D4-DF17-4B69-88EC-3F1C29B49961}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{C4D5BBE3-9C6C-4D23-B3D2-2008AC6A713C}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D2F101FE-DC59-44B1-9BA0-57B112930162}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{D78017CE-D1E3-427E-8D22-F96DC1BCD9F3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D9684888-18CB-4231-BDA1-C0B1C71C733E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{DD82C411-44A3-4D82-8EC0-BE7C0016255D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E9C95ADA-4C1F-4DAA-94C1-6AAC043B43E1}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EA719BBF-A71F-49EE-8D33-AF1A1B4B25BE}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe |
"{ED5030AF-197D-4085-BDA0-51EFBF38C034}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{EE0EEE80-E1E3-4A3F-8B81-E81A1802C0C4}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F4DC66FB-18E6-4E32-B8A0-BBC91D8731AF}" = lport=rpc | protocol=6 | dir=in | svc=policyagent | app=c:\windows\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1F192124-FC56-4F24-AE07-213E4172E7BE}" = protocol=6 | dir=in | app=c:\program files\dna\btdna.exe |
"{390D0C20-2AFA-4F80-98C1-F6F9C7CA6652}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{3A9D7C65-6D77-46CF-BBA6-2C5AF0670DEC}" = dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{3BEDCD57-4621-4CDA-902B-19F71D3D5863}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{3C703326-F9C5-48CD-83B7-4BA6F1B9DED0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3CF2AF43-1BF2-467D-BD33-EF2A6CAC714F}" = protocol=17 | dir=in | app=c:\program files\itibiti soft phone\itibiti.exe |
"{3E13264B-9B66-4F5B-BCEB-264D69389BD1}" = protocol=6 | dir=in | app=c:\windows\system32\skcbgm.exe |
"{3F2AECCE-EB10-43F4-AD27-38070E5DC3AF}" = dir=in | app=c:\users\consul69\appdata\local\temp\ibtmp9feb103\component_102.decrpt |
"{3FC031C3-8D96-4D98-B849-453A31E033ED}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{446FD695-3C41-48AB-9B9C-E76D12AA2EC3}" = protocol=17 | dir=in | app=c:\windows\ehome\ehshell.exe |
"{45E13F8C-E7BE-4867-AC1D-858605AB93B2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5D4A51AC-06D7-47BA-B521-19F982D312A5}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5DA6E3AC-71D2-42AB-A9DE-74817EF39036}" = protocol=6 | dir=in | app=c:\program files\hp\hpnetworkassistant\hpnetworkassistant.exe |
"{5DAA4DE0-750E-4DE6-9AC3-B420E4D13BB0}" = protocol=6 | dir=in | app=c:\program files\vuze\azureus.exe |
"{64BF744E-4FDC-4FEB-A295-A77B66286FFD}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{6974F62A-A5AF-4CDF-BA9A-41AB76C3A162}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{698861DE-B6F9-493D-BCFB-6D5BFB082E52}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6A137228-5E63-41DA-AC4A-1CF1A65A4E4D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6ADA564B-514A-414E-9DBE-150FED8EB9A1}" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
"{6D1D40C9-A0B8-4581-B52A-B1DE12F24636}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{70A501AD-9E37-4087-8002-7C9ADE666561}" = protocol=17 | dir=in | app=c:\program files\vuze\azureus.exe |
"{7E88DF94-3DA9-4AAC-AFBA-9E41A2968118}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
"{8376FEED-4D3B-4335-AD95-23756CE73A1A}" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
"{84F988A2-284A-42FB-9EC9-3F167C798840}" = dir=out | app=c:\users\consul69\appdata\local\temp\ibtmp9feb103\component_102.decrpt |
"{892FB576-27BE-443A-9930-EFC5FEBC82D8}" = protocol=6 | dir=out | app=system |
"{8EAD19FF-B61C-443A-A7FC-B54CE9914165}" = dir=in | app=c:\users\consul69\appdata\local\temp\ibtmp9feb103\component_126.decrpt |
"{90BE88D7-EC45-43E3-AD52-F4B854683F7D}" = protocol=6 | dir=in | app=c:\program files\itibiti soft phone\itibiti.exe |
"{97B07F12-2B60-4260-A130-3FF38C10D18F}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{98737530-E9F2-4DFA-8AFF-226597C5AD59}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{9BF350EE-58BD-484C-AD6C-0285D644E930}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{9F3EAB6F-D1F9-4912-A2C5-94C3C01AEAA9}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A035FC6B-FA25-445A-AE69-F6B2EFEDF962}" = protocol=17 | dir=in | app=c:\program files\hp\hpnetworkassistant\hpnetworkassistant.exe |
"{A209A652-4647-43CB-9EB8-733B5C5E251E}" = protocol=17 | dir=in | app=c:\windows\system32\skcbgm.exe |
"{AFB0EAA5-8C7A-4E6E-9561-F873152F5EA3}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{BCE346FC-F3A0-42E6-BE08-4361207CA61C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C05A7E7C-27D3-4A16-A9CA-04A498F03C4C}" = protocol=17 | dir=in | app=c:\program files\dna\btdna.exe |
"{C95F4780-0CA2-440F-8E04-BF16F311ADDD}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{CAB6C301-4D90-4864-9A88-2CCE25FE21D0}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{CC2947F1-4644-451E-9DD0-59205926E45B}" = protocol=6 | dir=in | app=c:\windows\ehome\ehshell.exe |
"{DCBDF857-12F0-4292-808F-1F8D669E1817}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{DF87DB4D-8C6F-4721-B4A0-3ECE5851785D}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{E4B88CBA-E5E5-4FD0-900F-37DCC4066FC4}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe |
"{E5FF4D7C-44BC-412B-8BC1-A0626FF7CF28}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe |
"{E932F031-F83B-4F1C-AFC9-52DBAE59EE5C}" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
"{E9CC2414-4FA6-4AD7-871A-5CED98F0A7C7}" = dir=in | app=c:\program files\common files\mcafee\mna\mcnasvc.exe |
"{F0053ECF-EA35-4FCC-997F-3486A9331056}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{F423D438-D2EE-4B44-98B3-3F35A9901344}" = dir=out | app=c:\users\consul69\appdata\local\temp\ibtmp9feb103\component_126.decrpt |
"{F4B31F37-B7A1-43F0-9544-1479DE0D498E}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe |
"{FB28CB05-7BB4-4750-A448-4BAFF5364414}" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
"{FC6D030B-9F19-4FA6-A39A-7FE3F8B50B14}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"TCP Query User{832F8D3B-27AC-46D3-9AF0-D9E91754951D}C:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe" = protocol=6 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |
"TCP Query User{921D48EA-1580-41E8-8D8C-56348DF3B566}C:\filetopia3\filetopia.exe" = protocol=6 | dir=in | app=c:\filetopia3\filetopia.exe |
"TCP Query User{C19886DB-4738-410F-A553-0570AAD3D7A1}C:\program files\myspace\im\myspaceim.exe" = protocol=6 | dir=in | app=c:\program files\myspace\im\myspaceim.exe |
"TCP Query User{D176EF1B-785A-493D-9256-1A2249A0ECC1}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{EDB465C2-6C95-4D30-8480-DEC4875CF4AC}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{FD0DB834-2BA1-4D39-A287-35F3526F4B31}C:\filetopia3\filetopia.exe" = protocol=6 | dir=in | app=c:\filetopia3\filetopia.exe |
"UDP Query User{3F02EE90-B8C3-4ECC-9D2B-92BB8CCB2886}C:\program files\myspace\im\myspaceim.exe" = protocol=17 | dir=in | app=c:\program files\myspace\im\myspaceim.exe |
"UDP Query User{5BF316FC-9A4B-4C13-966C-E41396FE14FF}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"UDP Query User{5C6D17C7-A893-4BA0-9724-15AACE62A503}C:\filetopia3\filetopia.exe" = protocol=17 | dir=in | app=c:\filetopia3\filetopia.exe |
"UDP Query User{5DB0758C-74A2-459D-8D83-76FB8C054DD2}C:\filetopia3\filetopia.exe" = protocol=17 | dir=in | app=c:\filetopia3\filetopia.exe |
"UDP Query User{68EFF3D9-B7C6-437C-8562-4AE5E3BD1436}C:\program files\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"UDP Query User{7FF4BBA4-98FC-40BB-838B-BB0274B77EAC}C:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe" = protocol=17 | dir=in | app=c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}" = Zune Language Pack (FR)
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
"{31216452-5540-4C96-B754-94890A63D5AB}" = HP Help and Support
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{341201D4-4F61-4ADB-987E-9CCE4D83A58D}" = Windows Live Toolbar Extension (Windows Live Toolbar)
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3515DF4C-3529-407E-A1E1-E2C0EDB36FF0}" = KwiClick
"{370BCBBA-67D7-4535-ADCD-58CD1C8DEC99}" = Zune Language Pack (DE)
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{40EC6323-497B-44DA-8A88-74578622D9B3}" = Zune Language Pack (IT)
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1" = Auslogics BoostSpeed
"{730E03E4-350E-48E5-9D3E-4329903D454D}" = Itibiti RTC
"{7745B7A9-F323-4BB9-9811-01BF57A028DA}" = Map Button (Windows Live Toolbar)
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{8347A7A5-4AB8-433F-82AA-496B0D189A9B}" = HP User Guides 0088
"{888FFC82-688D-46AB-A776-B417885432B6}" = Zune
"{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8D15E1B2-D2B7-4A17-B44B-D2DDE5981406}" = iLivid
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-006D-0409-0000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A5C4AD72-25FE-4899-B6DF-6D8DF63C93CF}" = Highlight Viewer (Windows Live Toolbar)
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{AEBEF8E1-11B9-4458-A619-14EEE48A5BB4}" = Pure Networks Platform
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{b02df929-29a7-4fd2-9a70-81a644b635f7}" = HP Total Care Advisor
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E63E34A7-E552-412B-9E40-FD6FC5227ABA}" = Uniblue RegistryBooster 2009
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EE4ACABF-531E-419A-9225-B8E0FA4955AF}" = Zune Language Pack (ES)
"{F084395C-40FB-4DB3-981C-B51E74E1E83D}" = Smart Menus (Windows Live Toolbar)
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
"{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}" = ooVoo
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Ashampoo Internet Accelerator 3_is1" = Ashampoo Internet Accelerator 3.20
"Ashampoo WinOptimizer 8_is1" = Ashampoo WinOptimizer 8 v.8.13
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"'Full Speed' Internet Booster + Performance Tests3.4" = 'Full Speed' Internet Booster + Performance Tests
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"iLivid" = iLivid
"InstallBrain Updater Service" = InstallBrain Updater Service
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"Itibiti_is1" = Knctr
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MSC" = McAfee AntiVirus Plus
"MSNINST" = MSN
"Network MagicUninstall" = Network Magic
"NortonPCCheckup" = Norton PC Checkup
"NVIDIA Drivers" = NVIDIA Drivers
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"ooVoo_Video_Chat Toolbar" = ooVoo Video Chat Toolbar
"oovootoolbar" = ooVoo Toolbar
"SpeedItup Free_is1" = SpeedItup Free 7.70
"Uniblue RegistryBooster 2009" = Uniblue RegistryBooster 2009
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VLC media player 1.0.1
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite" = Windows Live Essentials
"Yahoo! Extras" = Yahoo! Browser Services
"Yahoo! Mail" = Yahoo! Internet Mail
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update
"Zune" = Zune

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >
:welcome:

Just reply to this thread only by using the Add Reply and do not start any New Topics please or else we wont be able to keep track of you.


Tell me what your experiencing, browser redirects, pop up windows , blue screens ??????

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]







Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI