This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

It wastes 400-500k memory. When i have any browser open, it opens windows or tabs stating ive won and the date. also causes random crashes. i searched the forum and have seen multiple fixes for this and have pre installed avast internet security also will have a log from the aswMBR
Hi Skyler227, welcome to the forum.


To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.


Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lรฎk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    consrv.dll
    /md5stop


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
OTL logfile created on: 12/26/2011 9:11:36 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Skyler\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.24 Gb Available Physical Memory | 61.80% Memory free
3.85 Gb Paging File | 3.26 Gb Available in Paging File | 84.57% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 47.63 Gb Free Space | 63.92% Space Free | Partition Type: NTFS

Computer Name: PC | User Name: Skyler | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Skyler\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\AVG\AVG2012\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe ()
PRC - C:\Program Files\Safari\Safari.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe (Apple Inc.)
PRC - C:\Program Files\TeamViewer\Version6\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
PRC - c:\Program Files\GrassSoft\Mouse Recorder\MacroService.exe (Grass Software)
PRC - c:\Program Files\GrassSoft\Mouse Recorder\MacroServiceWnd.exe (Grass Software)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\AVAST Software\Avast\defs\11122601\algo.dll ()
MOD - C:\Program Files\AVAST Software\Avast\defs\11122600\algo.dll ()
MOD - C:\Program Files\AVAST Software\Avast\defs\11122601\aswRep.dll ()
MOD - C:\Program Files\AVAST Software\Avast\defs\11122600\aswRep.dll ()
MOD - C:\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - c:\Program Files\GrassSoft\Mouse Recorder\mk_nt.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()


========== Win32 Services (SafeList) ==========

SRV - (avast! Firewall) โ€“ C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
SRV - (avast! Antivirus) โ€“ C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (Updater Service for StartNow Toolbar) โ€“ C:\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe ()
SRV - (AVGIDSAgent) โ€“ C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (TeamViewer6) โ€“ C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (avgwd) โ€“ C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (SwitchBoard) โ€“ C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (Macro Expert) โ€“ c:\Program Files\GrassSoft\Mouse Recorder\MacroService.exe (Grass Software)


========== Driver Services (SafeList) ==========

DRV - (aswFW) โ€“ C:\WINDOWS\System32\drivers\aswFW.sys (AVAST Software)
DRV - (aswSnx) โ€“ C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) โ€“ C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswNdis2) โ€“ C:\WINDOWS\System32\drivers\aswNdis2.sys (AVAST Software)
DRV - (aswRdr) โ€“ C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) โ€“ C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) โ€“ C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) โ€“ C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) โ€“ C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (aswNdis) โ€“ C:\WINDOWS\system32\DRIVERS\aswNdis.sys (ALWIL Software)
DRV - (AVGIDSShim) โ€“ C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgrkx86) โ€“ C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) โ€“ C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) โ€“ C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSFilter) โ€“ C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSEH) โ€“ C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) โ€“ C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (Tcpip6) โ€“ C:\WINDOWS\system32\drivers\tcpip6.sys (Microsoft Corporation)
DRV - (RTL8023xp) โ€“ C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (dsiarhwprog) โ€“ C:\WINDOWS\system32\drivers\dsiarhwprog.sys (Thesycon GmbH, Germany)
DRV - (RT73) โ€“ C:\WINDOWS\system32\drivers\rt73.sys (Ralink Technology, Corp.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) โ€“ C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (AR5211) โ€“ C:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) โ€“ C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AgereSoftModem) โ€“ C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (SMCIRDA) โ€“ C:\WINDOWS\system32\drivers\smcirda.sys (SMC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.0.198: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.0.198: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.0.198: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.0.198: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.0.198: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{EB132DB0-A4CA-11DF-9732-0E29E0D72085}: C:\Program Files\Object\facetheme [2011/07/06 06:31:25 | 000,000,000 | โ€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011/12/23 09:16:10 | 000,000,000 | โ€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/12/07 00:21:47 | 000,000,000 | โ€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/12/26 02:21:18 | 000,000,000 | โ€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/25 15:02:56 | 000,000,000 | โ€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/07 00:22:51 | 000,000,000 | โ€”D | M]

[2011/12/25 17:03:24 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Documents and Settings\Skyler\Application Data\Mozilla\Extensions
[2011/12/26 01:09:35 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Documents and Settings\Skyler\Application Data\Mozilla\Firefox\Profiles\fydzxqih.default\extensions
[2011/12/26 01:09:39 | 000,000,000 | โ€”D | M] (uTorrentBar Community Toolbar) โ€“ C:\Documents and Settings\Skyler\Application Data\Mozilla\Firefox\Profiles\fydzxqih.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/12/25 15:02:56 | 000,000,000 | โ€”D | M] (No name found) โ€“ C:\Program Files\Mozilla Firefox\extensions
[2011/08/17 04:09:06 | 000,000,000 | โ€”D | M] (ViaSheep Games) โ€“ C:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/12/21 01:24:52 | 000,121,816 | โ€”- | M] (Mozilla Foundation) โ€“ C:\Program Files\mozilla firefox\components\browsercomps.dll
[2008/07/08 15:07:06 | 000,040,960 | โ€”- | M] (BYOND) โ€“ C:\Program Files\mozilla firefox\plugins\npbyond.dll
[2011/05/04 03:52:23 | 000,476,904 | โ€”- | M] (Sun Microsystems, Inc.) โ€“ C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/12/20 22:30:41 | 000,002,252 | โ€”- | M] () โ€“ C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010/01/01 02:00:00 | 000,002,252 | โ€”- | M] () โ€“ C:\Program Files\mozilla firefox\searchplugins\bing.xml.old
[2009/09/24 09:26:03 | 000,003,700 | โ€”- | M] () โ€“ C:\Program Files\mozilla firefox\searchplugins\fast.png
[2009/09/24 09:26:04 | 000,001,963 | โ€”- | M] () โ€“ C:\Program Files\mozilla firefox\searchplugins\fast.xml
[2011/12/20 22:30:41 | 000,002,040 | โ€”- | M] () โ€“ C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Javaโ„ข Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: BYOND stub plugin for Mozilla (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npbyond.dll
CHR - plugin: RealPlayerโ„ข G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayerโ„ข HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: RealNetworksโ„ข Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: uTorrentBar = C:\Documents and Settings\Skyler\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bejbohlohkkgompgecdcbbglkpjfjgdj\2.3.2.4_0\
CHR - Extension: Complitly plugin for chrome = C:\Documents and Settings\Skyler\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\defdhglnppeioeflggkmglipcecffkhk\1.1_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Skyler\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: ViaSheep Games = C:\Documents and Settings\Skyler\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nehfjblpeaoahhpnkkpbnkiepedijlie\1.0_0\

Hosts file not found
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\prxtbFree.dll (Conduit Ltd.)
O2 - BHO: (WhiteSmoke Bar Toolbar) - {167d9323-f7cc-48f5-948a-6f012831a69f} - C:\Program Files\WhiteSmoke_Bar\prxtbWhit.dll (Conduit Ltd.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (StartNow Toolbar Helper) - {6E13D095-45C3-4271-9475-F3B48227DD9F} - C:\Program Files\StartNow Toolbar\Toolbar32.dll ()
O2 - BHO: (Facetheme) - {70C6E9DE-F30E-4A40-8A6F-9572C2328320} - C:\Program Files\Object\bho_project.dll (InternetEngine)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O2 - BHO: (Updater For Simppull Toolbar) - {C4B8BAB4-1667-11DF-A242-BA9455D89593} - C:\Program Files\simppulltoolbar\auxi\simppulltoolbAu.dll File not found
O2 - BHO: (Complitly) - {D27FC31C-6E3D-4305-8D53-ACDAEFA5F862} - C:\Documents and Settings\Kuraikage\Application Data\Complitly\Complitly.dll File not found
O2 - BHO: (no name) - {E4E6BF2A-1667-11DF-A01F-1F9655D89593} - No CLSID value found.
O2 - BHO: (ViaSheep Games) - {E6A9268B-F8C9-4748-B453-E7FA556D94B8} - C:\Program Files\ViaSheep Games\ViaSheepGames.dll (Company Name)
O2 - BHO: (Yontoo Layers) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Runtime\YontooIEClient.dll (Yontoo LLC)
O3 - HKLM\..\Toolbar: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\prxtbFree.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (WhiteSmoke Bar Toolbar) - {167d9323-f7cc-48f5-948a-6f012831a69f} - C:\Program Files\WhiteSmoke_Bar\prxtbWhit.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (StartNow Toolbar) - {5911488E-9D1E-40ec-8CBB-06B231CC153F} - C:\Program Files\StartNow Toolbar\Toolbar32.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [EZSleepAutoStart] C:\Program Files\EasySleep\easysleep.exe (LullSoft.com, Inc.)
O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [hpqSRMon] File not found
O4 - HKLM..\Run: [Macro Manager] C:\Program Files\GrassSoft\Mouse Recorder\MacroManager.exe (GrassSoftware)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" File not found
O4 - HKCU..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupdโ€ฆb?1233619539906 (WUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/instโ€ฆctDetection.cab (GMNRev Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashโ€ฆr/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} http://lads.myspace.com/upload/MySpaceUploader2.cab (MySpace Uploader Control)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-โ€ฆindows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F0C32D74-1D53-4552-83D3-2CB624353B91}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/02/02 17:40:01 | 000,000,000 | โ€”- | M] () - C:\AUTOEXEC.BAT โ€“ [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] โ€“ "%1" %*
O35 - HKLM\..exefile [open] โ€“ "%1" %*
O37 - HKLM\โ€ฆcom [@ = comfile] โ€“ "%1" %*
O37 - HKLM\โ€ฆexe [@ = exefile] โ€“ "%1" %*

NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/26 20:54:39 | 000,584,192 | โ€”- | C] (OldTimer Tools) โ€“ C:\Documents and Settings\Skyler\Desktop\OTL.exe
[2011/12/26 07:16:36 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Application Data\TeamViewer
[2011/12/26 03:21:25 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Start Menu\Programs\Wise PC Doctor
[2011/12/26 03:21:06 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Wise PC Doctor
[2011/12/26 02:40:53 | 000,111,320 | โ€”- | C] (AVAST Software) โ€“ C:\WINDOWS\System32\drivers\aswFW.sys
[2011/12/26 02:40:05 | 000,195,416 | โ€”- | C] (AVAST Software) โ€“ C:\WINDOWS\System32\drivers\aswNdis2.sys
[2011/12/26 02:39:30 | 000,012,112 | โ€”- | C] (ALWIL Software) โ€“ C:\WINDOWS\System32\drivers\aswNdis.sys
[2011/12/26 02:33:31 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Start Menu\Programs\avast! Internet Security
[2011/12/26 02:27:15 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome
[2011/12/26 02:21:47 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Local Settings\Application Data\Google
[2011/12/26 02:21:42 | 000,314,456 | โ€”- | C] (AVAST Software) โ€“ C:\WINDOWS\System32\drivers\aswSP.sys
[2011/12/26 02:21:42 | 000,020,568 | โ€”- | C] (AVAST Software) โ€“ C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/12/26 02:21:39 | 000,034,392 | โ€”- | C] (AVAST Software) โ€“ C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/12/26 02:21:38 | 000,435,032 | โ€”- | C] (AVAST Software) โ€“ C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/12/26 02:21:38 | 000,052,952 | โ€”- | C] (AVAST Software) โ€“ C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/12/26 02:21:36 | 000,111,320 | โ€”- | C] (AVAST Software) โ€“ C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/12/26 02:21:36 | 000,105,176 | โ€”- | C] (AVAST Software) โ€“ C:\WINDOWS\System32\drivers\aswmon.sys
[2011/12/26 02:21:36 | 000,030,808 | โ€”- | C] (AVAST Software) โ€“ C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/12/26 02:21:14 | 000,041,184 | โ€”- | C] (AVAST Software) โ€“ C:\WINDOWS\avastSS.scr
[2011/12/26 02:21:13 | 000,199,816 | โ€”- | C] (AVAST Software) โ€“ C:\WINDOWS\System32\aswBoot.exe
[2011/12/26 02:20:40 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\AVAST Software
[2011/12/26 02:20:40 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/12/26 01:50:39 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Local Settings\Application Data\Apple Computer
[2011/12/26 01:37:38 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\Premium
[2011/12/26 01:37:16 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Application Data\InstallMate
[2011/12/26 01:09:22 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Local Settings\Application Data\uTorrentBar
[2011/12/26 01:09:20 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Local Settings\Application Data\Conduit
[2011/12/26 01:09:19 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Local Settings\Application Data\Temp
[2011/12/26 01:09:17 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\uTorrentBar
[2011/12/26 00:08:49 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\LocalService\Application Data\Macromedia
[2011/12/26 00:08:40 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\LocalService\Application Data\Adobe
[2011/12/25 22:47:54 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Application Data\LolClient
[2011/12/25 22:38:19 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\My Documents\Downloads
[2011/12/25 21:57:06 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Application Data\Ahead
[2011/12/25 17:03:21 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Local Settings\Application Data\Mozilla
[2011/12/25 17:03:21 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Application Data\Mozilla
[2011/12/25 16:54:03 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Application Data\Sun
[2011/12/25 16:49:25 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Application Data\AVG2012
[2011/12/25 16:49:22 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Local Settings\Application Data\Ahead
[2011/12/25 16:49:06 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Application Data\Real
[2011/12/25 16:49:04 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Application Data\Adobe
[2011/12/25 16:49:02 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Application Data\Grasssoft
[2011/12/25 16:49:01 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\My Documents\Freecorder
[2011/12/25 16:49:01 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Application Data\Apple Computer
[2011/12/25 16:48:59 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Local Settings\Application Data\FLVService
[2011/12/25 16:48:09 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Start Menu\Programs\Internet Explorer
[2011/12/25 16:48:06 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Application Data\Identities
[2011/12/25 16:47:42 | 000,000,000 | Rโ€“D | C] โ€“ C:\Documents and Settings\Skyler\My Documents\My Music
[2011/12/25 16:47:41 | 000,000,000 | Rโ€“D | C] โ€“ C:\Documents and Settings\Skyler\My Documents\My Pictures
[2011/12/25 16:46:41 | 000,000,000 | โ€“SD | C] โ€“ C:\Documents and Settings\Skyler\Application Data\Microsoft
[2011/12/25 16:46:41 | 000,000,000 | RH-D | C] โ€“ C:\Documents and Settings\Skyler\SendTo
[2011/12/25 16:46:41 | 000,000,000 | RH-D | C] โ€“ C:\Documents and Settings\Skyler\Recent
[2011/12/25 16:46:41 | 000,000,000 | RH-D | C] โ€“ C:\Documents and Settings\Skyler\Application Data
[2011/12/25 16:46:41 | 000,000,000 | Rโ€“D | C] โ€“ C:\Documents and Settings\Skyler\Start Menu\Programs\Startup
[2011/12/25 16:46:41 | 000,000,000 | Rโ€“D | C] โ€“ C:\Documents and Settings\Skyler\Start Menu
[2011/12/25 16:46:41 | 000,000,000 | Rโ€“D | C] โ€“ C:\Documents and Settings\Skyler\My Documents
[2011/12/25 16:46:41 | 000,000,000 | Rโ€“D | C] โ€“ C:\Documents and Settings\Skyler\Favorites
[2011/12/25 16:46:41 | 000,000,000 | Rโ€“D | C] โ€“ C:\Documents and Settings\Skyler\Start Menu\Programs\Accessories
[2011/12/25 16:46:41 | 000,000,000 | -HSD | C] โ€“ C:\Documents and Settings\Skyler\IETldCache
[2011/12/25 16:46:41 | 000,000,000 | -HSD | C] โ€“ C:\Documents and Settings\Skyler\Cookies
[2011/12/25 16:46:41 | 000,000,000 | -H-D | C] โ€“ C:\Documents and Settings\Skyler\Templates
[2011/12/25 16:46:41 | 000,000,000 | -H-D | C] โ€“ C:\Documents and Settings\Skyler\PrintHood
[2011/12/25 16:46:41 | 000,000,000 | -H-D | C] โ€“ C:\Documents and Settings\Skyler\NetHood
[2011/12/25 16:46:41 | 000,000,000 | -H-D | C] โ€“ C:\Documents and Settings\Skyler\Local Settings
[2011/12/25 16:46:41 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Local Settings\Application Data\Microsoft Help
[2011/12/25 16:46:41 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Local Settings\Application Data\Microsoft
[2011/12/25 16:46:41 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Application Data\Macromedia
[2011/12/25 16:46:41 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Desktop
[2011/12/25 16:46:41 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\Skyler\Local Settings\Application Data\Adobe
[2011/12/24 18:57:15 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\NetworkService\Application Data\RealNetworks
[2011/12/24 18:56:46 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\NetworkService\Application Data\Real
[2011/12/24 07:38:49 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/12/23 22:24:21 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/12/23 22:23:46 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/12/07 00:21:59 | 000,000,000 | โ€”D | C] โ€“ C:\Program Files\Common Files\xing shared
[2011/12/07 00:21:31 | 000,198,832 | โ€”- | C] (RealNetworks, Inc.) โ€“ C:\WINDOWS\System32\rmoc3260.dll
[2011/12/07 00:21:15 | 000,006,656 | โ€”- | C] (RealNetworks, Inc.) โ€“ C:\WINDOWS\System32\pndx5016.dll
[2011/12/07 00:21:15 | 000,005,632 | โ€”- | C] (RealNetworks, Inc.) โ€“ C:\WINDOWS\System32\pndx5032.dll
[2011/12/07 00:21:14 | 000,000,000 | โ€”D | C] โ€“ C:\Documents and Settings\All Users\Start Menu\Programs\Real
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/26 20:55:00 | 000,584,192 | โ€”- | M] (OldTimer Tools) โ€“ C:\Documents and Settings\Skyler\Desktop\OTL.exe
[2011/12/26 18:33:00 | 000,000,886 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/26 18:00:00 | 000,000,446 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\ParetoLogic Registration.job
[2011/12/26 17:25:49 | 055,626,464 | โ€”- | M] () โ€“ C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/12/26 17:25:49 | 000,113,461 | โ€”- | M] () โ€“ C:\WINDOWS\System32\drivers\AVG\iavichjw.avm
[2011/12/26 07:18:05 | 000,000,430 | โ€”- | M] () โ€“ C:\WINDOWS\System32\drivers\etc\hosts.ics
[2011/12/26 07:18:01 | 000,002,206 | โ€”- | M] () โ€“ C:\WINDOWS\System32\wpa.dbl
[2011/12/26 07:15:51 | 000,000,882 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/26 07:15:46 | 000,000,286 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1390067357-507921405-725345543-1007.job
[2011/12/26 07:15:46 | 000,000,282 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1390067357-507921405-725345543-1003.job
[2011/12/26 07:15:36 | 000,002,048 | โ€“S- | M] () โ€“ C:\WINDOWS\bootstat.dat
[2011/12/26 04:46:05 | 000,000,512 | โ€”- | M] () โ€“ C:\Documents and Settings\Skyler\Desktop\MBR.dat
[2011/12/26 04:27:08 | 000,002,187 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2011/12/26 03:21:30 | 000,000,762 | โ€”- | M] () โ€“ C:\Documents and Settings\Skyler\Application Data\Microsoft\Internet Explorer\Quick Launch\Wise PC Doctor.lnk
[2011/12/26 03:21:29 | 000,000,744 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Wise PC Doctor.lnk
[2011/12/26 03:08:55 | 000,001,324 | โ€”- | M] () โ€“ C:\WINDOWS\System32\d3d9caps.dat
[2011/12/26 02:40:04 | 000,002,625 | โ€”- | M] () โ€“ C:\WINDOWS\System32\CONFIG.NT
[2011/12/26 02:33:31 | 000,001,689 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\avast! Internet Security.lnk
[2011/12/26 02:30:18 | 000,001,791 | โ€”- | M] () โ€“ C:\Documents and Settings\Skyler\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/12/26 02:27:16 | 000,001,813 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/12/26 02:00:00 | 000,000,350 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-PC-Kuraikage.job
[2011/12/26 01:50:36 | 000,002,409 | โ€”- | M] () โ€“ C:\Documents and Settings\Skyler\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/12/26 00:33:00 | 000,000,420 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\ParetoLogic Update Version2.job
[2011/12/25 16:48:39 | 000,000,079 | โ€”- | M] () โ€“ C:\Documents and Settings\Skyler\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/12/25 15:03:08 | 000,000,724 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/12/24 06:42:00 | 000,000,290 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1390067357-507921405-725345543-1003.job
[2011/12/23 21:02:42 | 000,001,316 | -HS- | M] () โ€“ C:\Documents and Settings\All Users\Application Data\301311k1t287s744w427h1kxp7h2
[2011/12/22 12:45:00 | 000,000,284 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/12/21 00:20:23 | 000,000,294 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1390067357-507921405-725345543-1007.job
[2011/12/20 12:00:00 | 000,000,398 | โ€”- | M] () โ€“ C:\WINDOWS\tasks\Schedule Task Weekly.job
[2011/12/15 17:10:09 | 000,259,733 | โ€”- | M] () โ€“ C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/12/15 03:59:31 | 000,378,448 | โ€”- | M] () โ€“ C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/15 03:41:14 | 000,001,393 | โ€”- | M] () โ€“ C:\WINDOWS\imsins.BAK
[2011/12/07 00:21:31 | 000,198,832 | โ€”- | M] (RealNetworks, Inc.) โ€“ C:\WINDOWS\System32\rmoc3260.dll
[2011/12/07 00:21:15 | 000,006,656 | โ€”- | M] (RealNetworks, Inc.) โ€“ C:\WINDOWS\System32\pndx5016.dll
[2011/12/07 00:21:15 | 000,005,632 | โ€”- | M] (RealNetworks, Inc.) โ€“ C:\WINDOWS\System32\pndx5032.dll
[2011/12/07 00:21:13 | 000,272,896 | โ€”- | M] (Progressive Networks) โ€“ C:\WINDOWS\System32\pncrt.dll
[2011/12/07 00:17:11 | 000,414,368 | โ€”- | M] (Adobe Systems Incorporated) โ€“ C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/11/30 08:53:13 | 000,000,116 | โ€”- | M] () โ€“ C:\WINDOWS\NeroDigital.ini
[2011/11/29 10:17:43 | 000,000,000 | โ€”- | M] () โ€“ C:\t6c
[2011/11/29 10:17:30 | 000,000,000 | โ€”- | M] () โ€“ C:\t6c.1
[2011/11/29 09:29:02 | 000,000,000 | โ€”- | M] () โ€“ C:\t148
[2011/11/29 09:28:52 | 000,000,000 | โ€”- | M] () โ€“ C:\t148.1
[2011/11/28 12:01:25 | 000,041,184 | โ€”- | M] (AVAST Software) โ€“ C:\WINDOWS\avastSS.scr
[2011/11/28 12:01:23 | 000,199,816 | โ€”- | M] (AVAST Software) โ€“ C:\WINDOWS\System32\aswBoot.exe
[2011/11/28 11:54:38 | 000,111,320 | โ€”- | M] (AVAST Software) โ€“ C:\WINDOWS\System32\drivers\aswFW.sys
[2011/11/28 11:53:53 | 000,435,032 | โ€”- | M] (AVAST Software) โ€“ C:\WINDOWS\System32\drivers\aswSnx.sys
[2011/11/28 11:53:35 | 000,314,456 | โ€”- | M] (AVAST Software) โ€“ C:\WINDOWS\System32\drivers\aswSP.sys
[2011/11/28 11:53:22 | 000,195,416 | โ€”- | M] (AVAST Software) โ€“ C:\WINDOWS\System32\drivers\aswNdis2.sys
[2011/11/28 11:52:19 | 000,034,392 | โ€”- | M] (AVAST Software) โ€“ C:\WINDOWS\System32\drivers\aswRdr.sys
[2011/11/28 11:52:16 | 000,052,952 | โ€”- | M] (AVAST Software) โ€“ C:\WINDOWS\System32\drivers\aswTdi.sys
[2011/11/28 11:52:02 | 000,111,320 | โ€”- | M] (AVAST Software) โ€“ C:\WINDOWS\System32\drivers\aswmon2.sys
[2011/11/28 11:51:59 | 000,105,176 | โ€”- | M] (AVAST Software) โ€“ C:\WINDOWS\System32\drivers\aswmon.sys
[2011/11/28 11:51:50 | 000,020,568 | โ€”- | M] (AVAST Software) โ€“ C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2011/11/28 11:48:49 | 000,030,808 | โ€”- | M] (AVAST Software) โ€“ C:\WINDOWS\System32\drivers\aavmker4.sys
[2011/11/28 11:26:19 | 000,012,112 | โ€”- | M] (ALWIL Software) โ€“ C:\WINDOWS\System32\drivers\aswNdis.sys
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/26 04:46:05 | 000,000,512 | โ€”- | C] () โ€“ C:\Documents and Settings\Skyler\Desktop\MBR.dat
[2011/12/26 03:21:30 | 000,000,762 | โ€”- | C] () โ€“ C:\Documents and Settings\Skyler\Application Data\Microsoft\Internet Explorer\Quick Launch\Wise PC Doctor.lnk
[2011/12/26 03:21:29 | 000,000,744 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\Wise PC Doctor.lnk
[2011/12/26 02:33:31 | 000,001,689 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\avast! Internet Security.lnk
[2011/12/26 02:27:16 | 000,001,791 | โ€”- | C] () โ€“ C:\Documents and Settings\Skyler\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/12/26 02:27:15 | 000,001,813 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/12/26 02:22:03 | 000,000,886 | โ€”- | C] () โ€“ C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/26 02:22:02 | 000,000,882 | โ€”- | C] () โ€“ C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/26 01:50:36 | 000,002,409 | โ€”- | C] () โ€“ C:\Documents and Settings\Skyler\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/12/26 01:50:36 | 000,002,187 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2011/12/25 16:48:39 | 000,000,079 | โ€”- | C] () โ€“ C:\Documents and Settings\Skyler\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2011/12/25 16:48:15 | 000,000,788 | โ€”- | C] () โ€“ C:\Documents and Settings\Skyler\Start Menu\Programs\Windows Media Player.lnk
[2011/12/25 16:48:08 | 000,000,738 | โ€”- | C] () โ€“ C:\Documents and Settings\Skyler\Start Menu\Programs\Outlook Express.lnk
[2011/12/25 16:46:42 | 000,001,599 | โ€”- | C] () โ€“ C:\Documents and Settings\Skyler\Start Menu\Programs\Remote Assistance.lnk
[2011/12/25 15:03:08 | 000,000,730 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2011/12/25 15:03:08 | 000,000,724 | โ€”- | C] () โ€“ C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/12/23 21:02:34 | 000,001,316 | -HS- | C] () โ€“ C:\Documents and Settings\All Users\Application Data\301311k1t287s744w427h1kxp7h2
[2011/11/29 09:46:16 | 000,000,000 | โ€”- | C] () โ€“ C:\t6c.1
[2011/11/29 09:46:02 | 000,000,000 | โ€”- | C] () โ€“ C:\t6c
[2011/11/29 07:51:24 | 000,000,000 | โ€”- | C] () โ€“ C:\t148.1
[2011/11/29 07:51:15 | 000,000,000 | โ€”- | C] () โ€“ C:\t148
[2011/08/07 01:43:01 | 000,002,272 | โ€”- | C] () โ€“ C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/08/01 22:08:03 | 000,000,262 | โ€”- | C] () โ€“ C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2011/07/12 11:24:53 | 000,000,025 | โ€”- | C] () โ€“ C:\WINDOWS\popcinfot.dat
[2011/04/09 17:55:28 | 000,179,261 | โ€”- | C] () โ€“ C:\WINDOWS\System32\xlive.dll.cat
[2010/08/14 19:59:56 | 000,001,324 | โ€”- | C] () โ€“ C:\WINDOWS\System32\d3d9caps.dat
[2010/03/30 19:28:12 | 000,000,256 | โ€”- | C] () โ€“ C:\WINDOWS\System32\pool.bin
[2010/01/06 21:13:02 | 000,166,425 | โ€”- | C] () โ€“ C:\WINDOWS\hpoins30.dat.temp
[2010/01/06 21:13:02 | 000,000,844 | โ€”- | C] () โ€“ C:\WINDOWS\hpomdl30.dat.temp
[2009/12/24 11:12:31 | 000,077,377 | โ€”- | C] () โ€“ C:\WINDOWS\hpqins05.dat
[2009/12/23 00:31:57 | 000,096,308 | -Hโ€“ | C] () โ€“ C:\WINDOWS\System32\mlfcache.dat
[2009/12/12 00:29:46 | 000,129,024 | โ€”- | C] () โ€“ C:\WINDOWS\System32\AVERM.dll
[2009/12/12 00:29:46 | 000,028,672 | โ€”- | C] () โ€“ C:\WINDOWS\System32\AVEQT.dll
[2009/08/24 14:40:58 | 000,000,000 | โ€”- | C] () โ€“ C:\WINDOWS\nsreg.dat
[2009/08/03 15:07:42 | 000,403,816 | โ€”- | C] () โ€“ C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | โ€”- | C] () โ€“ C:\WINDOWS\System32\OGAEXEC.exe
[2009/05/06 14:53:29 | 000,166,226 | โ€”- | C] () โ€“ C:\WINDOWS\hpoins30.dat
[2009/05/06 14:53:29 | 000,000,844 | โ€”- | C] () โ€“ C:\WINDOWS\hpomdl30.dat
[2009/03/15 17:43:20 | 000,000,116 | โ€”- | C] () โ€“ C:\WINDOWS\NeroDigital.ini
[2009/02/14 08:50:17 | 000,002,740 | โ€”- | C] () โ€“ C:\WINDOWS\ACROREAD.INI
[2009/02/03 09:06:29 | 000,000,808 | โ€”- | C] () โ€“ C:\WINDOWS\System32\drivers\alcxinit.dat
[2009/02/03 09:05:33 | 000,128,113 | โ€”- | C] () โ€“ C:\WINDOWS\System32\csellang.ini
[2009/02/03 09:05:33 | 000,009,538 | โ€”- | C] () โ€“ C:\WINDOWS\System32\tosmreg.ini
[2009/02/03 09:05:33 | 000,007,671 | โ€”- | C] () โ€“ C:\WINDOWS\System32\cseltbl.ini
[2009/02/03 09:05:32 | 000,045,056 | โ€”- | C] () โ€“ C:\WINDOWS\System32\csellang.dll
[2009/02/02 17:42:33 | 000,002,048 | โ€“S- | C] () โ€“ C:\WINDOWS\bootstat.dat
[2009/02/02 17:36:35 | 000,021,640 | โ€”- | C] () โ€“ C:\WINDOWS\System32\emptyregdb.dat
[2009/02/02 13:25:32 | 000,004,161 | โ€”- | C] () โ€“ C:\WINDOWS\ODBCINST.INI
[2009/02/02 13:24:05 | 000,378,448 | โ€”- | C] () โ€“ C:\WINDOWS\System32\FNTCACHE.DAT
[2004/08/04 06:00:00 | 013,107,200 | โ€”- | C] () โ€“ C:\WINDOWS\System32\oembios.bin
[2004/08/04 06:00:00 | 000,673,088 | โ€”- | C] () โ€“ C:\WINDOWS\System32\mlang.dat
[2004/08/04 06:00:00 | 000,444,706 | โ€”- | C] () โ€“ C:\WINDOWS\System32\perfh009.dat
[2004/08/04 06:00:00 | 000,272,128 | โ€”- | C] () โ€“ C:\WINDOWS\System32\perfi009.dat
[2004/08/04 06:00:00 | 000,218,003 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dssec.dat
[2004/08/04 06:00:00 | 000,072,542 | โ€”- | C] () โ€“ C:\WINDOWS\System32\perfc009.dat
[2004/08/04 06:00:00 | 000,046,258 | โ€”- | C] () โ€“ C:\WINDOWS\System32\mib.bin
[2004/08/04 06:00:00 | 000,028,626 | โ€”- | C] () โ€“ C:\WINDOWS\System32\perfd009.dat
[2004/08/04 06:00:00 | 000,004,569 | โ€”- | C] () โ€“ C:\WINDOWS\System32\secupd.dat
[2004/08/04 06:00:00 | 000,004,463 | โ€”- | C] () โ€“ C:\WINDOWS\System32\oembios.dat
[2004/08/04 06:00:00 | 000,001,804 | โ€”- | C] () โ€“ C:\WINDOWS\System32\dcache.bin
[2004/08/04 06:00:00 | 000,000,741 | โ€”- | C] () โ€“ C:\WINDOWS\System32\noise.dat
[1997/06/13 19:56:08 | 000,056,832 | โ€”- | C] () โ€“ C:\WINDOWS\System32\iyvu9_32.dll

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/07/30 20:08:41 | 000,000,000 | โ€”- | M] () โ€“ C:\AILog.txt
[2009/09/17 09:03:50 | 000,000,014 | โ€”- | M] () โ€“ C:\alrt_200.data
[2009/02/02 17:40:01 | 000,000,000 | โ€”- | M] () โ€“ C:\AUTOEXEC.BAT
[2009/02/02 17:26:07 | 000,000,211 | -HS- | M] () โ€“ C:\boot.ini
[2009/02/02 17:40:01 | 000,000,000 | โ€”- | M] () โ€“ C:\CONFIG.SYS
[2009/02/02 17:40:01 | 000,000,000 | RHS- | M] () โ€“ C:\IO.SYS
[2009/11/30 15:20:02 | 000,000,480 | โ€”- | M] () โ€“ C:\LOG15D.log
[2009/11/30 16:05:43 | 000,000,480 | โ€”- | M] () โ€“ C:\LOG19A.log
[2009/02/02 17:40:01 | 000,000,000 | RHS- | M] () โ€“ C:\MSDOS.SYS
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () โ€“ C:\NTDETECT.COM
[2009/02/02 17:55:40 | 000,250,048 | RHS- | M] () โ€“ C:\ntldr
[2011/12/26 07:15:32 | 2145,386,496 | -HS- | M] () โ€“ C:\pagefile.sys
[2011/11/29 09:29:02 | 000,000,000 | โ€”- | M] () โ€“ C:\t148
[2011/11/29 09:28:52 | 000,000,000 | โ€”- | M] () โ€“ C:\t148.1
[2011/11/16 23:56:43 | 000,000,000 | โ€”- | M] () โ€“ C:\t2kc
[2011/11/16 23:56:18 | 000,000,000 | โ€”- | M] () โ€“ C:\t2kc.1
[2011/09/09 10:23:57 | 000,000,000 | โ€”- | M] () โ€“ C:\t2p0
[2011/09/09 10:10:15 | 000,000,000 | โ€”- | M] () โ€“ C:\t2p0.1
[2011/09/05 16:45:06 | 000,000,000 | โ€”- | M] () โ€“ C:\t2qo
[2011/09/05 16:43:00 | 000,000,000 | โ€”- | M] () โ€“ C:\t2qo.1
[2011/08/31 04:02:39 | 000,000,000 | โ€”- | M] () โ€“ C:\t54
[2011/08/31 04:00:33 | 000,000,000 | โ€”- | M] () โ€“ C:\t54.1
[2011/08/31 12:54:35 | 000,000,000 | โ€”- | M] () โ€“ C:\t55s
[2011/08/31 12:47:18 | 000,000,000 | โ€”- | M] () โ€“ C:\t55s.1
[2011/08/31 15:03:57 | 000,000,000 | โ€”- | M] () โ€“ C:\t5ps
[2011/08/31 14:18:15 | 000,000,000 | โ€”- | M] () โ€“ C:\t5ps.1
[2011/11/29 10:17:43 | 000,000,000 | โ€”- | M] () โ€“ C:\t6c
[2011/11/29 10:17:30 | 000,000,000 | โ€”- | M] () โ€“ C:\t6c.1
[2011/11/17 23:34:45 | 000,000,000 | โ€”- | M] () โ€“ C:\t924
[2011/11/17 23:34:16 | 000,000,000 | โ€”- | M] () โ€“ C:\t924.1
[2011/11/26 15:05:18 | 000,000,000 | โ€”- | M] () โ€“ C:\t9n8
[2011/11/26 15:03:42 | 000,000,000 | โ€”- | M] () โ€“ C:\t9n8.1
[2011/11/21 02:14:58 | 000,000,000 | โ€”- | M] () โ€“ C:\tr4
[2011/11/21 01:13:28 | 000,000,000 | โ€”- | M] () โ€“ C:\tr4.1
[2009/08/17 02:57:50 | 000,000,922 | โ€”- | M] () โ€“ C:\updatedatfix.log
[2 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | โ€”- | M] () โ€“ C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | โ€”- | M] () โ€“ C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | โ€”- | M] () โ€“ C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | โ€”- | M] () โ€“ C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/02/02 17:39:34 | 000,000,067 | -HS- | M] () โ€“ C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 06:06:10 | 000,089,088 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/06/06 19:49:18 | 000,302,592 | โ€”- | M] (Hewlett-Packard Corporation) โ€“ C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp692.dll
[2006/10/26 19:58:12 | 000,030,512 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 19:56:12 | 000,033,104 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 04:50:03 | 000,597,504 | โ€”- | M] (Microsoft Corporation) โ€“ C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/11/28 12:01:25 | 000,041,184 | โ€”- | M] (AVAST Software) โ€“ C:\WINDOWS\avastSS.scr
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/02/02 13:23:26 | 000,094,208 | โ€”- | M] () โ€“ C:\WINDOWS\System32\config\default.sav
[2009/02/02 13:23:26 | 000,733,184 | โ€”- | M] () โ€“ C:\WINDOWS\System32\config\software.sav
[2009/02/02 13:23:25 | 000,892,928 | โ€”- | M] () โ€“ C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lรฎk /x >
[2009/02/02 18:00:14 | 000,000,272 | -HS- | M] () โ€“ C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2009/12/24 11:13:53 | 000,001,018 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Start Menu\HP Solution Center.lnk
[2009/05/11 09:55:40 | 000,002,449 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Start Menu\New Microsoft Office Document.lnk
[2009/10/12 05:12:09 | 000,002,459 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Start Menu\Open Microsoft Office Document.lnk
[2009/02/02 18:00:14 | 000,001,563 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
[2009/02/02 17:40:08 | 000,000,398 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk
[2009/02/02 18:05:35 | 000,001,507 | โ€”- | M] () โ€“ C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Desktop\*.exe >
[2011/12/26 20:55:00 | 000,584,192 | โ€”- | M] (OldTimer Tools) โ€“ C:\Documents and Settings\Skyler\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-26 09:04:37

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s >


< MD5 for: EXPLORER.EXE >
[2008/04/14 05:42:20 | 001,033,728 | โ€”- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 โ€“ C:\WINDOWS\explorer.exe
[2008/04/14 05:42:20 | 001,033,728 | โ€”- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 โ€“ C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004/08/04 06:00:00 | 001,032,192 | โ€”- | M] () MD5=A0732187050030AE399B241436565E64 โ€“ C:\RECYCLER\S-1-5-21-1105570221-2221730290-1772776687-569489\Df9\explorer.exe

< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2011/12/26 20:55:31 | 000,018,396 | โ€”- | M] () MD5=B00CE93E0201EA875B7C343D08834AE9 โ€“ C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf

< MD5 for: EXPLORER.SCF >
[2004/08/04 06:00:00 | 000,000,080 | โ€”- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 โ€“ C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2009/02/21 00:21:24 | 000,529,818 | โ€”- | M] () MD5=1435F4731719DF5F57D17DC38196245D โ€“ C:\WINDOWS\Help\iexplore.chm
[2004/08/04 06:00:00 | 000,204,810 | โ€”- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE โ€“ C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | โ€”- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 โ€“ C:\WINDOWS\ie8\iexplore.chm

< MD5 for: IEXPLORE.EXE >
[2009/06/29 01:25:31 | 000,634,632 | โ€”- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD โ€“ C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2008/12/18 23:25:25 | 000,634,024 | โ€”- | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 โ€“ C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[2008/10/15 00:34:58 | 000,633,632 | โ€”- | M] () MD5=056C927CF7207857E8B34F7A8FFD9B9E โ€“ C:\RECYCLER\S-1-5-21-1105570221-2221730290-1772776687-569489\Df8\KB958215-IE7\SP2QFE\iexplore.exe
[2009/04/24 23:27:50 | 000,636,088 | โ€”- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 โ€“ C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2008/12/18 23:25:30 | 000,634,024 | โ€”- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 โ€“ C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2009/06/29 02:35:10 | 000,634,632 | โ€”- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD โ€“ C:\WINDOWS\ie8\iexplore.exe
[2008/04/14 05:42:24 | 000,093,184 | โ€”- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 โ€“ C:\WINDOWS\ie7\iexplore.exe
[2008/04/14 05:42:24 | 000,093,184 | โ€”- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 โ€“ C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2008/10/15 01:06:26 | 000,633,632 | โ€”- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB โ€“ C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | -HS- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E โ€“ C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 13:09:26 | 000,638,816 | โ€”- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E โ€“ C:\WINDOWS\system32\dllcache\iexplore.exe
[2009/04/24 23:27:39 | 000,636,088 | โ€”- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C โ€“ C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2007/08/13 18:43:56 | 000,622,080 | โ€”- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 โ€“ C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[2004/08/04 06:00:00 | 000,093,184 | โ€”- | M] () MD5=E7484514C0464642BE7B4DC2689354C8 โ€“ C:\RECYCLER\S-1-5-21-1105570221-2221730290-1772776687-569489\Df9\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 13:21:44 | 000,012,288 | โ€”- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 โ€“ C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 13:21:44 | 000,012,288 | โ€”- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 โ€“ C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 18:43:36 | 000,573,440 | โ€”- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 โ€“ C:\WINDOWS\ie8\iexplore.exe.mui

< MD5 for: IEXPLORE.HLP >
[2004/08/04 06:00:00 | 000,180,335 | โ€”- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 โ€“ C:\WINDOWS\Help\iexplore.hlp

< MD5 for: WINLOGON.EXE >
[2004/08/04 06:00:00 | 000,502,272 | โ€”- | M] () MD5=01C3346C241652F43AED8E2149881BFE โ€“ C:\RECYCLER\S-1-5-21-1105570221-2221730290-1772776687-569489\Df9\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | โ€”- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E โ€“ C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | โ€”- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E โ€“ C:\WINDOWS\system32\winlogon.exe

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB46935$] -> Error: Cannot create file handle -> Unknown point type

< End of report >
OTL Extras logfile created on: 12/26/2011 9:11:36 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Skyler\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.24 Gb Available Physical Memory | 61.80% Memory free
3.85 Gb Paging File | 3.26 Gb Available in Paging File | 84.57% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 47.63 Gb Free Space | 63.92% Space Free | Partition Type: NTFS

Computer Name: PC | User Name: Skyler | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] โ€“ rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = ChromeHTML] โ€“ C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] โ€“ Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] โ€“ "%1" %*
cmdfile [open] โ€“ "%1" %*
comfile [open] โ€“ "%1" %*
cplfile [cplopen] โ€“ rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] โ€“ "%1" %*
http [open] โ€“ "C:\Program Files\Google\Chrome\Application\chrome.exe" โ€“ "%1" (Google Inc.)
https [open] โ€“ "C:\Program Files\Google\Chrome\Application\chrome.exe" โ€“ "%1" (Google Inc.)
piffile [open] โ€“ "%1" %*
regfile [merge] โ€“ Reg Error: Key error.
scrfile [config] โ€“ "%1"
scrfile [install] โ€“ rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] โ€“ "%1" /S
txtfile โ€“ Reg Error: Key error.
Unknown [openas] โ€“ %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDSee 11.0.Browse] โ€“ "C:\Program Files\ACD Systems\ACDSee\11.0\ACDSeeQV11.exe" "%1" (ACD Systems)
Directory [Bridge] โ€“ C:\Program Files\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [find] โ€“ %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] โ€“ %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] โ€“ %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] โ€“ %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"427:UDP" = 427:UDP:*:Enabled:SLP_Port(427)
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"58138:TCP" = 58138:TCP:*:Enabled:Pando Media Booster
"58138:UDP" = 58138:UDP:*:Enabled:Pando Media Booster
"56802:TCP" = 56802:TCP:*:Enabled:Pando Media Booster
"56802:UDP" = 56802:UDP:*:Enabled:Pando Media Booster
"58146:TCP" = 58146:TCP:*:Enabled:Pando Media Booster
"58146:UDP" = 58146:UDP:*:Enabled:Pando Media Booster

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"427:UDP" = 427:UDP:*:Enabled:SLP_Port(427)
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"6112:TCP" = 6112:TCP:*:Enabled:battle.net1
"6112:UDP" = 6112:UDP:*:Enabled:battle.net2
"58138:TCP" = 58138:TCP:*:Enabled:Pando Media Booster
"58138:UDP" = 58138:UDP:*:Enabled:Pando Media Booster
"56802:TCP" = 56802:TCP:*:Enabled:Pando Media Booster
"56802:UDP" = 56802:UDP:*:Enabled:Pando Media Booster
"58146:TCP" = 58146:TCP:*:Enabled:Pando Media Booster
"58146:UDP" = 58146:UDP:*:Enabled:Pando Media Booster

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"D:\setup\HPZnui01.exe" = D:\setup\HPZnui01.exe:*:Enabled:hpznui01.exe
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe โ€“ (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe โ€“ (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe โ€“ (Hewlett-Packard)
"C:\Program Files\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe โ€“ (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe:*:Enabled:hpqpsapp.exe โ€“ (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe:*:Enabled:hpqpse.exe โ€“ (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe:*:Enabled:hpqsudi.exe โ€“ (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe โ€“ (Hewlett-Packard Co.)
"C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"C:\Nexon\Combat Arms\Engine.exe" = C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster โ€“ ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox โ€“ (Mozilla Corporation)
"C:\Program Files\Microsoft Games\Halo Trial\halo.exe" = C:\Program Files\Microsoft Games\Halo Trial\halo.exe:*:Enabled:Halo
"C:\Program Files\GameSpy Arcade\Aphex.exe" = C:\Program Files\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade
"D:\setup\HPZnui01.exe" = D:\setup\HPZnui01.exe:*:Enabled:hpznui01.exe
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe โ€“ (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe โ€“ (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe โ€“ (Hewlett-Packard)
"C:\Program Files\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe" = C:\Program Files\Common Files\HP\Digital Imaging\bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe โ€“ (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe:*:Enabled:hpqpsapp.exe โ€“ (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe:*:Enabled:hpqpse.exe โ€“ (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe:*:Enabled:hpqsudi.exe โ€“ (Hewlett-Packard Development Co. L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe โ€“ (Hewlett-Packard Co.)
"C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe" = C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager โ€“ (Nexon)
"C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"C:\Nexon\Combat Arms\NMService.exe" = C:\Nexon\Combat Arms\NMService.exe:*:Enabled:Nexon Messenger Core
"E:\Warcraft III\Warcraft III.exe" = E:\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III
"F:\Warcraft III\Warcraft III.exe" = F:\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III
"C:\Documents and Settings\Richard\My Documents\Downloads\Empire Earth\Empire Earth.exe" = C:\Documents and Settings\Richard\My Documents\Downloads\Empire Earth\Empire Earth.exe:*:Enabled:Empire Earth
"C:\Program Files\Microsoft Games\Age of Empires II\EMPIRES2.ICD" = C:\Program Files\Microsoft Games\Age of Empires II\EMPIRES2.ICD:*:Enabled:Age of Empires II
"C:\Documents and Settings\Richard\Desktop\Warcraft III\Warcraft III.exe" = C:\Documents and Settings\Richard\Desktop\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III
"C:\Program Files\Ventrilo\Ventrilo.exe" = C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe โ€“ (Flagship Industries, Inc.)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer
"C:\Program Files\BYOND\bin\byond.exe" = C:\Program Files\BYOND\bin\byond.exe:*:Enabled:byond โ€“ ()
"C:\Documents and Settings\Richard\My Documents\Downloads\489.1099_byond\byond\bin\byond.exe" = C:\Documents and Settings\Richard\My Documents\Downloads\489.1099_byond\byond\bin\byond.exe:*:Enabled:byond
"C:\Program Files\TeamViewer\Version6\TeamViewer.exe" = C:\Program Files\TeamViewer\Version6\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application โ€“ (TeamViewer GmbH)
"C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe" = C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe:*:Enabled:Teamviewer Remote Control Service โ€“ (TeamViewer GmbH)
"C:\Program Files\Steam\Steam.exe" = C:\Program Files\Steam\Steam.exe:*:Enabled:Steam
"C:\Program Files\FrostWire\FrostWire.exe" = C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:FrostWire
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit โ€“ (Apple Inc.)
"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer โ€“ (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Adobe\Adobe Flash CS5.5\Flash.exe" = C:\Program Files\Adobe\Adobe Flash CS5.5\Flash.exe:*:Enabled:Adobe Flash CS5.5 โ€“ (Adobe Systems Incorporated.)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster โ€“ ()
"C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield โ€“ (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 โ€“ (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgemcx.exe" = C:\Program Files\AVG\AVG2012\avgemcx.exe:*:Enabled:Personal E-mail Scanner โ€“ (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00718491-55BF-46C6-83EF-4B3B95AC807A}" = SplitCam
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{09633A5E-3089-41A8-9FF1-382171423C5D}" = PSSWCORE
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{15B8AFD9-92E9-4E86-96D9-83FAC510B82E}" = HPPhotoSmartPhotobookWebPack1
"{1D5355BA-562B-4C29-83C0-1D0ED41B2D87}" = TinyZIP
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22F761D1-8063-4170-ADF7-2D2F47834CA9}" = VideoToolkit01
"{23E445D5-FD83-4C50-A211-EB26A2975317}" = Adobe Flash Professional CS5.5
"{2614F54E-A828-49FA-93BA-45A3F756BFAA}" = 32 Bit HP CIO Components Installer
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Javaโ„ข 6 Update 26
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{29ED20C9-5E15-4969-9279-25BF3727A3DA}" = iTunes
"{2AFEAA03-2DFE-4519-A629-EDAB6541ABE9}" = HPSSupply
"{300578F9-9EFF-4B93-9AB1-C0E5707EF463}" = ACDSee Photo Manager 2009
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{3700194C-C5DD-439A-BE06-A66960CA4C70}" = MSVCSetup
"{3C9D008D-3716-4C3F-90CD-38ED57568FAB}_is1" = Video Download Capture V2.6.6
"{43C0C354-A185-4D2D-A057-67C9160460E1}" = PS_AIO_04_C4580_Software_Min
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A3D0CF8-60FF-4CEF-91A4-A1F001424602}" = DocProc
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4E74D41C-5864-4561-9F6B-069372513A0B}" = AVG 2012
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{4FFBB818-B13C-11E0-931D-B2664824019B}_is1" = Complitly
"{5E453519-60F6-4A4D-A0BF-16663F9B3536}" = Safari
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67DD11CB-7C27-4072-B970-B57755294B28}" = Windows Macro Recorder
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{70E1E357-E57C-4284-B04E-58196DC27BC1}" = PanoStandAlone
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{75A0EB9D-2D1E-4FB7-BF61-498E33C73EB4}" = Motorola Driver Installation
"{7641710F-A4AD-4EAE-889C-4958BE3F169C}" = C4580
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{787D1A33-A97B-4245-87C0-7174609A540C}" = HP Update
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{8398852A-7B61-4808-8F58-D0A40D1B2CB6}" = AVG 2012
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers Runtime 1.10.01
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9119A44D-E936-4BD3-B973-26152118876F}_is1" = AutoClickExtreme 5.99
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9CA21A22-5816-4789-A225-6BF126EA0FB7}" = BlackBerry Device Software v4.5.0 for the BlackBerry 8800 smartphone
"{9F4EE72A-C5C9-42ad-ABEF-427690843577}" = MarketResearch
"{A00B9A50-3090-4CFF-9CDA-82DA0BEDAA21}" = Apple Mobile Device Support
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A436B59A-756E-426F-A348-2BE1BE99B86F}" = AVG 2012
"{A6A195F5-BCAB-4F38-8459-DF693303CD8D}" = PS_AIO_04_C4580_ProductContext
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA2E8A46-B45E-4aea-8A23-88AB57D04523}" = WebReg
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{B001064C-D061-4BAE-9031-416A838D5536}" = Adobe Flash Player 10 ActiveX
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{BED1705F-7558-40f7-9F52-6C6FBD58EA2E}" = HP Photosmart C4500 All-In-One Driver Software 11.0 Rel .4
"{BF08AB1C-3357-4f20-A200-8EBB8EF27C59}" = BufferChm
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C89B5E3A-690F-4CEE-909A-BF869E198B0A}" = Scan
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D16B4BE6-8B10-422f-8034-96D1CA9483B5}" = GPBaseService
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D23E2520-0EAA-4AC3-A47E-A551C70D4FED}" = C4580_Help
"{D4278897-1541-493E-9D39-59CC6AB0FC09}" = PS_AIO_04_C4580_Software
"{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}" = HP Photosmart Essential 2.5
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DCFD26A8-60A5-4C69-A52D-264D0386FDB3}" = Microsoft Xbox 360 Accessories 1.2
"{DD1E51DF-C3C0-400C-A0D7-C67DB49C9D9C}" = RingtoneJunkiez Desktop
"{DF817F49-F4DE-4564-9D0A-68F742A573F9}_is1" = Wise PC Doctor version 3.8.8
"{E1845F1C-068C-F8F4-D31D-D3540D47C453}" = Adobe Download Assistant
"{E535C94A-B87F-4182-BEA8-1E9322078D3E}" = Cards_Calendar_OrderGift_DoMorePlugout
"{E96B0085-6659-486b-A221-5042A042728D}" = Toolbox
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{EF9E56EE-0243-4BAD-88F4-5E7508AA7D96}" = Destination Component
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{F95F178B-56AD-4fab-87F8-FA81E66C7D68}" = Network
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FFB10368-5623-49AA-BD51-B321DB9625CE}" = Force Feedback Driver for XInput
"7-Zip" = 7-Zip 9.20
"Action Replay DSi Code Manager_is1" = Action Replay DSi Code Manager
"Adobe Acrobat Reader 3.01" = Adobe Acrobat Reader 3.01
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"American Greetings ArtMore Store 2.0" = American Greetingsยฎ Art & More Store
"Any Video Converter_is1" = Any Video Converter 3.1.2
"avast" = avast! Internet Security
"AVG" = AVG 2012
"Build Your Own Net Dream" = Build Your Own Net Dream (remove only)
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"conduitEngine" = Conduit Engine
"DigitalVid" = DigitalVid
"EasySleep_is1" = EasySleep 3.0
"ENTERPRISE" = Microsoft Office Enterprise 2007
"facetheme" = Facetheme
"Freecorder Toolbar" = Freecorder Toolbar
"Freecorder5.02" = Freecorder 5
"Freecorder5.05" = Freecorder 5
"Google Chrome" = Google Chrome
"HP Imaging Device Functions" = HP Imaging Device Functions 11.0
"HP Photosmart Essential" = HP Photosmart Essential 3.0
"HPExtendedCapabilities" = HP Customer Participation Program 11.0
"HPOCR" = OCR Software by I.R.I.S. 11.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Macro" = Advanced Key and Mouse Recorder
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 9.0.1 (x86 en-US)" = Mozilla Firefox 9.0.1 (x86 en-US)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"Photo Organizer 1.8" = Photo Organizer
"RealPlayer 15.0" = RealPlayer
"Shop for HP Supplies" = Shop for HP Supplies
"StartNow Toolbar" = StartNow Toolbar
"TeamViewer 6" = TeamViewer 6
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"uTorrentBar Toolbar" = uTorrentBar Toolbar
"ViaSheepGames_1" = ViaSheep Games
"Warcraft III" = Warcraft III
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WebPost" = Microsoft Web Publishing Wizard 1.52
"WhiteSmoke_Bar Toolbar" = WhiteSmoke Bar Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/22/2011 8:20:52 PM | Computer Name = PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 12/22/2011 8:20:52 PM | Computer Name = PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4156

Error - 12/22/2011 8:20:52 PM | Computer Name = PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4156

Error - 12/22/2011 8:20:54 PM | Computer Name = PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 12/22/2011 8:20:54 PM | Computer Name = PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 6109

Error - 12/22/2011 8:20:54 PM | Computer Name = PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 6109

Error - 12/26/2011 3:41:49 AM | Computer Name = PC | Source = Application Hang | ID = 1002
Description = Hanging application DownloadSetup (65).exe, version 2011.12.25.2024,
hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/26/2011 8:34:20 PM | Computer Name = PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 12/26/2011 8:34:20 PM | Computer Name = PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1984

Error - 12/26/2011 8:34:20 PM | Computer Name = PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1984

[ System Events ]
Error - 12/26/2011 7:50:50 PM | Computer Name = PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 12/26/2011 7:50:53 PM | Computer Name = PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 12/26/2011 7:50:56 PM | Computer Name = PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 12/26/2011 7:50:59 PM | Computer Name = PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 12/26/2011 7:51:02 PM | Computer Name = PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 12/26/2011 7:51:05 PM | Computer Name = PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 12/26/2011 7:51:08 PM | Computer Name = PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 12/26/2011 7:51:11 PM | Computer Name = PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 12/26/2011 10:54:08 PM | Computer Name = PC | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address [removed] on
the Network Card with network address 0090968A0613.

Error - 12/26/2011 10:54:18 PM | Computer Name = PC | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0090968A0613. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.


< End of report >
Hi Skyler227,

You currently have 2 antivirus programs installed. This will not give you more protection, rather it will probably be less as the 2 programs will conflict. Please uninstall either AVG or Avast.


Next


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log.

How's the computer?
ComboFix 11-12-26.03 - Skyler 12/27/2011 2:19.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1555 [GMT -6:00]
Running from: c:\docume~1\Skyler\LOCALS~1\Temp\ol4r95tf.tmp\ComboFix.exe
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\301311k1t287s744w427h1kxp7h2
c:\documents and settings\All Users\Application Data\Tarma Installer
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico
c:\documents and settings\All Users\Application Data\Tarma Installer\{DA00D550-BB91-4A26-AAE5-9172D626CAAE}\_Setup.dll
c:\documents and settings\All Users\Application Data\Tarma Installer\{DA00D550-BB91-4A26-AAE5-9172D626CAAE}\_Setupx.dll
c:\documents and settings\All Users\Application Data\Tarma Installer\{DA00D550-BB91-4A26-AAE5-9172D626CAAE}\Setup.dat
c:\documents and settings\All Users\Application Data\Tarma Installer\{DA00D550-BB91-4A26-AAE5-9172D626CAAE}\Setup.exe
c:\documents and settings\All Users\Application Data\Tarma Installer\{DA00D550-BB91-4A26-AAE5-9172D626CAAE}\Setup.ico
C:\LOG15D.tmp
C:\LOG19A.tmp
c:\program files\Object
c:\program files\Object\bho_project.dll
c:\program files\Object\ChromeAddon.pem
c:\program files\Object\chromeaddon\._included.js
c:\program files\Object\chromeaddon\background.html
c:\program files\Object\chromeaddon\included.js
c:\program files\Object\chromeaddon\manifest.json
c:\program files\Object\config.ini
c:\program files\Object\facetheme\build.sh
c:\program files\Object\facetheme\chrome.manifest
c:\program files\Object\facetheme\config_build.sh
c:\program files\Object\facetheme\content\.DS_Store
c:\program files\Object\facetheme\content\firefoxOverlay.xul
c:\program files\Object\facetheme\content\installid.js
c:\program files\Object\facetheme\content\overlay.js
c:\program files\Object\facetheme\content\sudoku.js
c:\program files\Object\facetheme\defaults\.DS_Store
c:\program files\Object\facetheme\defaults\preferences\._sudoku.js
c:\program files\Object\facetheme\defaults\preferences\.DS_Store
c:\program files\Object\facetheme\defaults\preferences\sudoku.js
c:\program files\Object\facetheme\files
c:\program files\Object\facetheme\install.rdf
c:\program files\Object\facetheme\locale\.DS_Store
c:\program files\Object\facetheme\locale\en-US\.DS_Store
c:\program files\Object\facetheme\locale\en-US\sudoku.dtd
c:\program files\Object\facetheme\locale\en-US\sudoku.properties
c:\program files\Object\facetheme\readme.txt
c:\program files\Object\facetheme\skin\overlay.css
c:\program files\Object\facetheme_uninstall.exe
c:\program files\Object\status.txt
c:\program files\Object\status2.txt
c:\program files\StartNow Toolbar
c:\program files\StartNow Toolbar\ReactivateFF.exe
c:\program files\StartNow Toolbar\ReactivateIE.exe
c:\program files\StartNow Toolbar\Resources\images\btn-msn.png
c:\program files\StartNow Toolbar\Resources\images\chevronButton.png
c:\program files\StartNow Toolbar\Resources\images\engine_images.png
c:\program files\StartNow Toolbar\Resources\images\engine_maps.png
c:\program files\StartNow Toolbar\Resources\images\engine_news.png
c:\program files\StartNow Toolbar\Resources\images\engine_videos.png
c:\program files\StartNow Toolbar\Resources\images\engine_web.png
c:\program files\StartNow Toolbar\Resources\images\icon_amazon.png
c:\program files\StartNow Toolbar\Resources\images\icon_ebay.png
c:\program files\StartNow Toolbar\Resources\images\icon_facebook.png
c:\program files\StartNow Toolbar\Resources\images\icon_games.png
c:\program files\StartNow Toolbar\Resources\images\icon_msn.png
c:\program files\StartNow Toolbar\Resources\images\icon_shopping.png
c:\program files\StartNow Toolbar\Resources\images\icon_travel.png
c:\program files\StartNow Toolbar\Resources\images\icon_twitter.png
c:\program files\StartNow Toolbar\Resources\images\separator.png
c:\program files\StartNow Toolbar\Resources\images\splitter.png
c:\program files\StartNow Toolbar\Resources\images\startnow_logo.png
c:\program files\StartNow Toolbar\Resources\installer.xml
c:\program files\StartNow Toolbar\Resources\skin\chevron_button.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_button_hover.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_button_normal.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_dropdown_button_normal.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_input_background.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_input_left.png
c:\program files\StartNow Toolbar\Resources\skin\searchbox_input_middle.png
c:\program files\StartNow Toolbar\Resources\skin\separator.png
c:\program files\StartNow Toolbar\Resources\skin\splitter.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ff_hover_c.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_hover_c.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_hover_l.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_hover_r.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_normal_c.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_normal_l.png
c:\program files\StartNow Toolbar\Resources\skin\toolbarbutton_ie_normal_r.png
c:\program files\StartNow Toolbar\Resources\toolbar.xml
c:\program files\StartNow Toolbar\Resources\update.xml
c:\program files\StartNow Toolbar\StartNowToolbarUninstall.exe
c:\program files\StartNow Toolbar\Toolbar32.dll
c:\program files\StartNow Toolbar\ToolbarBroker.exe
c:\program files\StartNow Toolbar\ToolbarUpdaterService.exe
c:\program files\StartNow Toolbar\uninstall.dat
c:\windows\$NtUninstallKB46935$
c:\windows\$NtUninstallKB46935$\151371346\@
c:\windows\$NtUninstallKB46935$\151371346\bckfg.tmp
c:\windows\$NtUninstallKB46935$\151371346\cfg.ini
c:\windows\$NtUninstallKB46935$\151371346\Desktop.ini
c:\windows\$NtUninstallKB46935$\151371346\keywords
c:\windows\$NtUninstallKB46935$\151371346\kwrd.dll
c:\windows\$NtUninstallKB46935$\151371346\L\jzypedjh
c:\windows\$NtUninstallKB46935$\151371346\lsflt7.ver
c:\windows\$NtUninstallKB46935$\151371346\U\00000001.@
c:\windows\$NtUninstallKB46935$\151371346\U\00000002.@
c:\windows\$NtUninstallKB46935$\151371346\U\00000004.@
c:\windows\$NtUninstallKB46935$\151371346\U\80000000.@
c:\windows\$NtUninstallKB46935$\151371346\U\80000004.@
c:\windows\$NtUninstallKB46935$\151371346\U\80000032.@
c:\windows\$NtUninstallKB46935$\4124496448
c:\windows\alcrmv.exe
c:\windows\system32\SET4C1.tmp
c:\windows\system32\SET4C3.tmp
c:\windows\system32\SET4D1.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
โ€”โ€”-\Legacy_Updater_Service_for_StartNow_Toolbar
โ€”โ€”-\Legacy_Updater_Service_for_StartNow_Toolbar
โ€”โ€”-\Service_Updater Service for StartNow Toolbar
โ€”โ€”-\Service_Updater Service for StartNow Toolbar
.
.
((((((((((((((((((((((((( Files Created from 2011-11-27 to 2011-12-27 )))))))))))))))))))))))))))))))
.
.
2011-12-26 09:21 . 2011-12-26 09:21 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Wise PC Doctor
2011-12-26 08:20 . 2011-12-27 05:59 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\All Users\Application Data\AVAST Software
2011-12-26 08:20 . 2011-12-26 08:20 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\AVAST Software
2011-12-26 07:37 . 2011-12-26 07:37 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\All Users\Application Data\Premium
2011-12-26 07:37 . 2011-12-26 07:37 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\All Users\Application Data\InstallMate
2011-12-26 07:09 . 2011-12-26 07:09 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\uTorrentBar
2011-12-26 06:09 . 2011-12-26 06:09 โ€”โ€”โ€“ d-shโ€“w- c:\documents and settings\LocalService\IETldCache
2011-12-25 22:46 . 2011-12-27 07:34 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\Skyler
2011-12-24 04:11 . 2011-12-24 04:11 โ€”โ€”โ€“ dโ€”โ€“w- c:\windows\system32\wbem\Repository
2011-12-07 06:22 . 2011-12-07 06:22 11776 โ€”-a-w- c:\program files\Mozilla Firefox\plugins\nprjplug.dll
2011-12-07 06:21 . 2011-12-07 06:21 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Common Files\xing shared
2011-12-07 06:21 . 2011-12-07 06:21 150696 โ€”-a-w- c:\program files\Mozilla Firefox\plugins\nppl3260.dll
2011-12-07 06:21 . 2011-12-07 06:21 108544 โ€”-a-w- c:\program files\Mozilla Firefox\plugins\nprpjplug.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-07 06:21 . 2009-05-22 02:21 499712 โ€”-a-w- c:\windows\system32\msvcp71.dll
2011-12-07 06:21 . 2008-03-26 07:25 348160 โ€”-a-w- c:\windows\system32\msvcr71.dll
2011-12-07 06:17 . 2011-09-20 16:15 414368 โ€”-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-23 13:25 . 2007-01-14 05:16 1859584 โ€”-a-w- c:\windows\system32\win32k.sys
2011-11-04 19:20 . 2007-01-14 05:20 916992 โ€”-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2004-08-04 12:00 43520 โ€”-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2004-08-04 12:00 1469440 โ€”โ€”w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2004-08-04 12:00 385024 โ€”-a-w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2007-01-14 05:17 1288704 โ€”-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2004-08-04 12:00 33280 โ€”-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37 . 2007-01-14 05:15 2148864 โ€”-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2005-03-02 03:36 2027008 โ€”-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2004-08-04 12:00 186880 โ€”-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22 . 2009-02-02 23:37 692736 โ€”-a-w- c:\windows\system32\inetcomm.dll
2011-12-21 07:24 . 2011-12-25 21:02 121816 โ€”-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\prxtbuTor.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1392b8d2-5c05-419f-a8f6-b9f15a596612}]
2011-01-17 21:54 175912 โ€”-a-w- c:\program files\Freecorder\prxtbFree.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 21:54 175912 โ€”-a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2011-05-09 08:49 176936 โ€”-a-w- c:\program files\uTorrentBar\prxtbuTor.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E6A9268B-F8C9-4748-B453-E7FA556D94B8}]
2011-08-12 19:04 163840 โ€”-a-w- c:\program files\ViaSheep Games\ViaSheepGames.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-08-19 16:45 790304 โ€”-a-w- c:\program files\Yontoo Layers Runtime\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{1392b8d2-5c05-419f-a8f6-b9f15a596612}"= "c:\program files\Freecorder\prxtbFree.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\prxtbuTor.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{1392b8d2-5c05-419f-a8f6-b9f15a596612}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-06-25 4800512]
"nwiz"="nwiz.exe" [2003-06-25 323584]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 718688]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"EZSleepAutoStart"="c:\progra~1\EASYSL~1\easysleep.exe" [2003-05-29 39936]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"Freecorder FLV Service"="c:\program files\Freecorder\FLVSrvc.exe" [2011-03-24 167936]
"Macro Manager"="c:\program files\GrassSoft\Mouse Recorder\MacroManager.exe" [2009-06-19 2471936]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
"AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-12-07 296056]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\BYOND\\bin\\byond.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Adobe\\Adobe Flash CS5.5\\Flash.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"427:UDP"= 427:UDP:SLP_Port(427)
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"6112:TCP"= 6112:TCP:battle.net1
"6112:UDP"= 6112:UDP:battle.net2
"58138:TCP"= 58138:TCP:Pando Media Booster
"58138:UDP"= 58138:UDP:Pando Media Booster
"56802:TCP"= 56802:TCP:Pando Media Booster
"56802:UDP"= 56802:UDP:Pando Media Booster
"58146:TCP"= 58146:TCP:Pando Media Booster
"58146:UDP"= 58146:UDP:Pando Media Booster
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundRouterRequest"= 1 (0x1)
.
R2 Macro Expert;Macro Expert;c:\program files\GrassSoft\Mouse Recorder\MacroService.exe [9/27/2009 7:40 AM 206848]
R2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [8/12/2011 4:50 AM 2358656]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/26/2011 2:21 AM 136176]
S3 cpuz134;cpuz134;\??\c:\docume~1\Richard\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys โ€“> c:\docume~1\Richard\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys [?]
S3 dsiarhwprog;dsiarhwprog;c:\windows\system32\drivers\dsiarhwprog.sys [7/24/2011 1:11 AM 29184]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [12/26/2011 2:21 AM 136176]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 1:37 PM 517096]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-26 c:\windows\Tasks\AdobeAAMUpdater-1.0-PC-Kuraikage.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-11-17 23:42]
.
2011-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-12-26 08:21]
.
2011-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-12-26 08:21]
.
2011-12-27 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2009-01-21 05:36]
.
2011-12-27 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2009-01-21 05:36]
.
2011-12-27 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1390067357-507921405-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-08 22:14]
.
2011-12-27 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1390067357-507921405-725345543-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-08 22:14]
.
2011-12-24 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1390067357-507921405-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-08 22:14]
.
2011-12-21 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1390067357-507921405-725345543-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-08 22:14]
.
.
โ€”โ€”- Supplementary Scan โ€”โ€”-
.
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\documents and settings\Skyler\Application Data\Mozilla\Firefox\Profiles\fydzxqih.default\
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{C4B8BAB4-1667-11DF-A242-BA9455D89593} - c:\program files\simppulltoolbar\auxi\simppulltoolbAu.dll
BHO-{E4E6BF2A-1667-11DF-A01F-1F9655D89593} - (no file)
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
HKCU-Run-uTorrent - c:\program files\uTorrent\uTorrent.exe
HKLM-Run-hpqSRMon - (no file)
AddRemove-Action Replay DSi Code Manager_is1 - c:\documents and settings\Richard\Desktop\Action Replay DSi Code Manager\unins000.exe
AddRemove-Any Video Converter_is1 - e:\any video converter\unins000.exe
AddRemove-DigitalVid - e:\digitalvid\uninstall.exe
AddRemove-facetheme - c:\program files\Object\facetheme_uninstall.exe
AddRemove-RealPlayer 15.0 - c:\program files\real\realplayer\Update\r1puninst.exe
AddRemove-StartNow Toolbar - c:\program files\StartNow Toolbar\StartNowToolbarUninstall.exe
AddRemove-{889DF117-14D1-44EE-9F31-C5FB5D47F68B} - c:\docume~1\ALLUSE~1\APPLIC~1\TARMAI~1\{889DF~1\Setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-27 02:32
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes โ€ฆ
.
scanning hidden autostart entries โ€ฆ
.
scanning hidden files โ€ฆ
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
โ€”โ€”โ€”โ€”โ€”โ€”โ€” DLLs Loaded Under Running Processes โ€”โ€”โ€”โ€”โ€”โ€”โ€”
.
- - - - - - - > 'explorer.exe'(4044)
c:\windows\system32\WININET.dll
c:\documents and settings\Skyler\Local Settings\Application Data\FLVService\lib\FLVSrvLib.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€” Other Running Processes โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\program files\grasssoft\mouse recorder\MacroServiceWnd.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2011-12-27 02:36:35 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-27 08:36
.
Pre-Run: 50,933,469,184 bytes free
Post-Run: 53,390,917,632 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 1E6838635DAD440EBE32EBFB1EB93E6C
Hi Skyerl337,

Looks pretty good so far.

Which antivirus program did you keep?

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


One more to check for stragglers.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.

Please post back with
  • MBAM log
  • ESET log
Still ok?
Actually, i removed both bc the installers for avg disappeared and the one i downloaded told me had to remove my other one to begin my uninstallation though something is alerting me and taking me away from potentially harmfull websites which is useful though id like some suggestions on good free ones, im willing to pay for one just prefer not to :D. ill start the anti malware now. also, my web borwsers are still slow, suggestions?
Hi Skyler227,

The MBAM log show detections were present but no action taken. You should have "Make sure that everything is checked, and click Remove Selected."

How is the ESET scan going?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI