This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware, system hijack, CUP Runs hard, freezes [Closed]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Issues: Computer programs and websites both freeze, website redirects search engine :(

My user name: xxxxxxxx
email: xxxxxxxxx

Blessing to you all this new year.

Hi,

I was lead to your wonderful site. But could not upload my computers information after I followed how to get it. I am sure it is an user error LOL me:(… I have taken no actions.

I my income and was searching for something to do on-line. My system is slow as well as my internet redirects my search engine and Facebook want come up most times and when it does it has a corner of porn. I am 57 years lady; I don't need that. I need Christ and an income.

These are the things I have used. Charter Business Desktop Security (main), I have run CCleaner, Registry Editor HijackThis and piriform CCleaner, google click and clean.



It said that I have about 20 HKCR\CLSID IE hijacker.

Here is the information that was ran. I know this is not how it is to be done. Can you tell me Sir, where to post and how to post it. My user name is creamjj,

From: OTL.txt

OTL logfile created on: 12/30/2011 8:16:41 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Darlita\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.23 Mb Total Physical Memory | 186.39 Mb Available Physical Memory | 19.45% Memory free
2.25 Gb Paging File | 1.33 Gb Available in Paging File | 58.95% Paging File free
Paging file location(s): C:\pagefile.sys 2 1437E:\pagefile.sys 2 1437 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 37.02 Gb Free Space | 24.84% Space Free | Partition Type: NTFS
Drive E: | 298.09 Gb Total Space | 256.00 Gb Free Space | 85.88% Space Free | Partition Type: NTFS

Computer Name: LITAS-ELOHIM709 | User Name: Darlita | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Darlita\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
PRC - C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Documents and Settings\Darlita\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\7.8.2.0_0\plugin\ClickClean.exe ()
PRC - C:\Program Files\Charter Business Desktop Security\Anti-Virus\fsav32.exe (F-Secure Corporation)
PRC - C:\Program Files\Charter Business Desktop Security\Anti-Virus\fssm32.exe (F-Secure Corporation)
PRC - C:\Program Files\Charter Business Desktop Security\Anti-Virus\fsgk32.exe (F-Secure Corporation)
PRC - C:\Program Files\Charter Business Desktop Security\ORSP Client\fsorsp.exe (F-Secure Corporation)
PRC - C:\Program Files\Gladinet\Gladinet Cloud Desktop\GladFileMonSvc.exe (Gladinet, INC)
PRC - C:\Program Files\Charter Business Desktop Security\Common\FSM32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Charter Business Desktop Security\Common\FSMA32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Charter Business Desktop Security\Common\FSHDLL32.EXE (F-Secure Corporation)
PRC - C:\Program Files\Charter Business Desktop Security\FWES\program\fsdfwd.exe (F-Secure Corporation)
PRC - C:\Program Files\Charter Business Desktop Security\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\HijackThis\HijackThis.exe (Soeperman Enterprises Ltd.)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe (HP)
PRC - C:\Program Files\MouseWare\system\EM_EXEC.EXE (Logitech Inc.)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\8061a0f5c1c2ee0549e19224352f67fa\System.Runtime.Serialization.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\095bb4f033374647b6d66c51f16bb886\System.IdentityModel.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\8043a108e3bb2d3dcc84b547b8085e99\SMDiagnostics.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7bffd7ff2009f421fe5d229927588496\mscorlib.ni.dll ()
MOD - C:\Program Files\Google\Chrome\Application\16.0.912.63\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files\Google\Chrome\Application\16.0.912.63\pdf.dll ()
MOD - C:\Program Files\Google\Chrome\Application\16.0.912.63\avutil-51.dll ()
MOD - C:\Program Files\Google\Chrome\Application\16.0.912.63\avformat-53.dll ()
MOD - C:\Program Files\Google\Chrome\Application\16.0.912.63\avcodec-53.dll ()
MOD - C:\Documents and Settings\Darlita\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\7.8.2.0_0\plugin\ClickClean.exe ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Charter Business Desktop Security\Anti-Virus\minifilter\hashlib_x86.dll ()
MOD - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\WINDOWS\system32\sbe.dll ()
MOD - C:\Program Files\Charter Business Desktop Security\Anti-Virus\fm4av.dll ()
MOD - C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\4200f716e9a41cb91d17516ba864e586\System.Web.Mobile.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\41f436dae3c8146752d06130f7331527\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - \\?\C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\webengine.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\16ff33f07efdb9da2a18e27585c604be\Microsoft.JScript.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8b000cc703c9d95593b516bf2c2ec316\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\d0ae809162b55e2fa958739177476af8\System.Web.RegularExpressions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Transactions\26d5bf1f7e700c2c19aa9b1da5519b24\System.Transactions.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\ab688d0f9f333ba117832726bfb589c1\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\a6dbe24cbfe3ab6b318ed3095cc572d8\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\f04ef00e652a8655a717639e8aeb7b63\System.Data.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\08ffa4d388d5f007869aa7651c458e7c\System.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMDiagnostics.dll ()
MOD - C:\Program Files\Gladinet\Gladinet Cloud Desktop\sqlite3.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\Program Files\Charter Business Desktop Security\Spam Control\fsas.dll ()
MOD - C:\Program Files\Charter Business Desktop Security\Common\OnDemandInstallWatcher.dll ()
MOD - \\?\c:\program files\charter business desktop security\hips\fsumi.dll ()
MOD - C:\Program Files\Charter Business Desktop Security\FSGUI\strres.eng ()
MOD - C:\Program Files\Charter Business Desktop Security\FSGUI\fsavures.eng ()
MOD - C:\Program Files\Charter Business Desktop Security\FSGUI\about.dll ()
MOD - C:\Program Files\Charter Business Desktop Security\FSGUI\aboutres.dll ()
MOD - C:\Program Files\Charter Business Desktop Security\Anti-Virus\fsavhres.eng ()
MOD - C:\Program Files\Fast Folder Access\FAShellExt.dll ()
MOD - \\?\C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (Microsoft SharePoint Workspace Audit Service) – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (FSORSPClient) – C:\Program Files\Charter Business Desktop Security\ORSP Client\fsorsp.exe (F-Secure Corporation)
SRV - (PrismXL) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
SRV - (GladFileMonSvc) – C:\Program Files\Gladinet\Gladinet Cloud Desktop\GladFileMonSvc.exe (Gladinet, INC)
SRV - (RegMumService) – C:\Program Files\Active PC Optimizer\ActivePCOptimizerService.exe (Weskysoft Inc.)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (FSMA) – C:\Program Files\Charter Business Desktop Security\Common\FSMA32.EXE (F-Secure Corporation)
SRV - (FSDFWD) – C:\Program Files\Charter Business Desktop Security\FWES\Program\fsdfwd.exe (F-Secure Corporation)
SRV - (F-Secure Gatekeeper Handler Starter) – C:\Program Files\Charter Business Desktop Security\Anti-Virus\fsgk32st.exe (F-Secure Corporation)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (SBAMSvc) – C:\Program Files\Common Files\AntiVirus\SBAMSvc.exe (Sunbelt Software)
SRV - (SystemSuite Task Manager) – C:\Program Files\Avanquest\SystemSuite\MXTask.exe (Avanquest North America, Inc.)
SRV - (W3SVC) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (SMTPSVC) Simple Mail Transfer Protocol (SMTP) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (MSFtpsvc) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (IISADMIN) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (ICDSPTSV) – C:\WINDOWS\system32\IcdSptSv.exe (Sony Corporation)


========== Driver Services (SafeList) ==========

DRV - (F-Secure Gatekeeper) – C:\Program Files\Charter Business Desktop Security\Anti-Virus\minifilter\fsgk.sys ()
DRV - (ssadmdm) – C:\WINDOWS\system32\drivers\ssadmdm.sys (MCCI Corporation)
DRV - (ssadbus) SAMSUNG Android USB Composite Device driver (WDM) – C:\WINDOWS\system32\drivers\ssadbus.sys (MCCI Corporation)
DRV - (ssadmdfl) SAMSUNG Android USB Modem (Filter) – C:\WINDOWS\system32\drivers\ssadmdfl.sys (MCCI Corporation)
DRV - (fsbts) – C:\WINDOWS\system32\Drivers\fsbts.sys ()
DRV - (DrvAgent32) – C:\WINDOWS\system32\drivers\DrvAgent32.sys (Phoenix Technologies)
DRV - (KFilter) – C:\Program Files\Avanquest\SystemSuite\KFilter.sys (Avanquest North America, Inc.)
DRV - (TFilter) – C:\Program Files\Avanquest\SystemSuite\TFilter.sys (Avanquest North America, Inc.)
DRV - (tifm21) – C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (F-Secure HIPS) – C:\Program Files\Charter Business Desktop Security\HIPS\drivers\fshs.sys (F-Secure Corporation)
DRV - (FSFW) – C:\WINDOWS\System32\drivers\fsdfw.sys (F-Secure Corporation)
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (SBRE) – C:\WINDOWS\system32\drivers\SBREDrv.sys (Sunbelt Software)
DRV - (sbtis) – C:\WINDOWS\system32\drivers\sbtis.sys (Sunbelt Software)
DRV - (yukonwxp) – C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (sbapifs) – C:\WINDOWS\system32\drivers\sbapifs.sys (Sunbelt Software)
DRV - (sbaphd) – C:\WINDOWS\system32\drivers\sbaphd.sys (Sunbelt Software)
DRV - (Changer) – C:\WINDOWS\System32\drivers\changer.sys (Microsoft Corporation)
DRV - (lbrtfdc) – C:\WINDOWS\System32\drivers\lbrtfdc.sys (Toshiba Corp.)
DRV - (BANTExt) – C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (amdide) – C:\WINDOWS\system32\DRIVERS\amdide.sys (Advanced Micro Devices)
DRV - (AmdPPM) – C:\WINDOWS\system32\drivers\AmdPPM.sys (Advanced Micro Devices)
DRV - (AVG Anti-Rootkit) – C:\WINDOWS\System32\DRIVERS\avgarkt.sys (GRISOFT, s.r.o.)
DRV - (AvgArCln) – C:\WINDOWS\system32\drivers\AvgArCln.sys (GRISOFT, s.r.o.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (CAMCHALA) – C:\WINDOWS\system32\drivers\camc6hal.sys (Conexant Systems Inc.)
DRV - (CAMCAUD) – C:\WINDOWS\system32\drivers\camc6aud.sys (Conexant Systems Inc.)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWATI) – C:\WINDOWS\system32\drivers\HSFHWATI.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (LMouFlt2) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (LHidUsb) – C:\WINDOWS\system32\drivers\LHidUsb.sys (Logitech, Inc.)
DRV - (LHidFlt2) – C:\WINDOWS\system32\drivers\LHidFlt2.Sys (Logitech, Inc.)
DRV - (el575nd5) – C:\WINDOWS\system32\drivers\el575ND5.sys (3Com Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://login.live.com/login.srf?wa=wsignin…=mai&snsc;=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.startup.homepage: "http://www.bing.com/?pc=ZUGO&form;=ZGAPHP"
FF - prefs.js..extensions.enabledItems: [removed]:1.10
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.5
FF - prefs.js..extensions.enabledItems: {b51f491d-d355-412b-a4d6-f31d258e4c56}:3.1.1
FF - prefs.js..extensions.enabledItems: {398e77b8-2304-11dc-8314-0800200c9a66}:0.3.13
FF - prefs.js..extensions.enabledItems: {347ed93c-d850-11da-8af6-55f5aaf316dd}:0.5.4
FF - prefs.js..extensions.enabledItems: {94cf5eff-1def-405e-b82a-30598a4d602c}:0.1.5
FF - prefs.js..extensions.enabledItems: {4D1E692F-D179-413b-A987-EEEAAD85DDB3}:5.51.20.6608
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [removed]:1.10.01
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://www.bing.com/search?pc=ZUGO&form;=ZGAADF&q;="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.81\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.81\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\ZEON/PDF,version=2.0: C:\Program Files\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Charter Business Desktop Security\NRS\[removed] [2011/11/04 08:10:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\2YourFace\ffextension [2011/12/14 22:34:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/12/26 21:22:03 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/27 00:55:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/27 00:55:11 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\2YourFace\ffextension [2011/12/14 22:34:00 | 000,000,000 | —D | M]

[2010/06/24 19:58:27 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Darlita\Application Data\Mozilla\Extensions
[2011/12/28 20:52:38 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Darlita\Application Data\Mozilla\Firefox\Profiles\iyug72fr.default\extensions
[2010/08/08 23:22:36 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Darlita\Application Data\Mozilla\Firefox\Profiles\iyug72fr.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/12/14 22:34:15 | 000,000,000 | —D | M] (Complitly - Speed up your search with your personal search suggestions tool) – C:\Documents and Settings\Darlita\Application Data\Mozilla\Firefox\Profiles\iyug72fr.default\extensions\{33e0daa6-3af3-d8b5-6752-10e949c61516}
[2011/02/17 14:52:45 | 000,000,000 | —D | M] (All Your Maps Are Belong To Us) – C:\Documents and Settings\Darlita\Application Data\Mozilla\Firefox\Profiles\iyug72fr.default\extensions\{347ed93c-d850-11da-8af6-55f5aaf316dd}
[2010/08/08 23:19:14 | 000,000,000 | —D | M] (Minimap Addon) – C:\Documents and Settings\Darlita\Application Data\Mozilla\Firefox\Profiles\iyug72fr.default\extensions\{398e77b8-2304-11dc-8314-0800200c9a66}
[2011/02/17 14:52:44 | 000,000,000 | —D | M] (MapQuest Toolbar) – C:\Documents and Settings\Darlita\Application Data\Mozilla\Firefox\Profiles\iyug72fr.default\extensions\{4D1E692F-D179-413b-A987-EEEAAD85DDB3}
[2011/12/14 22:33:38 | 000,000,000 | —D | M] (PriceGong) – C:\Documents and Settings\Darlita\Application Data\Mozilla\Firefox\Profiles\iyug72fr.default\extensions\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}
[2010/08/08 23:19:06 | 000,000,000 | —D | M] (OsmJumper) – C:\Documents and Settings\Darlita\Application Data\Mozilla\Firefox\Profiles\iyug72fr.default\extensions\{94cf5eff-1def-405e-b82a-30598a4d602c}
[2010/08/08 23:19:17 | 000,000,000 | —D | M] (Full Map) – C:\Documents and Settings\Darlita\Application Data\Mozilla\Firefox\Profiles\iyug72fr.default\extensions\{b51f491d-d355-412b-a4d6-f31d258e4c56}
[2011/03/16 14:28:17 | 000,000,000 | —D | M] (Yontoo Layers) – C:\Documents and Settings\Darlita\Application Data\Mozilla\Firefox\Profiles\iyug72fr.default\extensions\[removed]
[2011/09/06 15:54:59 | 000,000,000 | —D | M] (MyPlayCity Toolbar) – C:\Documents and Settings\Darlita\Application Data\Mozilla\Firefox\Profiles\iyug72fr.default\extensions\[removed]
[2011/12/12 15:56:13 | 000,000,000 | —D | M] (We-Care Reminder) – C:\Documents and Settings\Darlita\Application Data\Mozilla\Firefox\Profiles\iyug72fr.default\extensions\wecarereminder@bryan
[2010/08/15 07:59:29 | 000,002,350 | —- | M] () – C:\Documents and Settings\Darlita\Application Data\Mozilla\Firefox\Profiles\iyug72fr.default\searchplugins\aol-search.xml
[2010/12/25 00:12:07 | 000,001,919 | —- | M] () – C:\Documents and Settings\Darlita\Application Data\Mozilla\Firefox\Profiles\iyug72fr.default\searchplugins\bing-zugo.xml
[2011/12/28 23:09:09 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/06/03 09:17:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/11/18 01:16:54 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/12/14 22:43:17 | 000,000,000 | —D | M] (GetDislike) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/12/26 21:22:03 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
File not found (No name found) – C:\DOCUMENTS AND SETTINGS\DARLITA\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\IYUG72FR.DEFAULT\EXTENSIONS\[removed]
[2011/11/04 08:10:19 | 000,000,000 | —D | M] ("Browsing Protection") – C:\PROGRAM FILES\CHARTER BUSINESS DESKTOP SECURITY\NRS\[removed]
[2011/06/03 09:17:11 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
File not found (No name found) – C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2009/11/19 17:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2011/10/03 05:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/19 17:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2009/05/07 16:27:36 | 000,283,952 | —- | M] (Musicnotes, Inc.) – C:\Program Files\mozilla firefox\plugins\npmusicn.dll

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chr
o
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.250.6 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U25 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealNetworks™ RealPlayer Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = E:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: Musicnotes (Enabled) = C:\Program Files\Google\Chrome\Application\plugins\npmusicn.dll
CHR - plugin: ScorchPlugin (Enabled) = C:\Program Files\Google\Chrome\Application\plugins\NPSibelius.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Zeon Plus (Enabled) = C:\Program Files\Nuance\PDF Reader\bin\nppdf.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: PriceGong = C:\Documents and Settings\Darlita\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok\5.5.4_0\
CHR - Extension: Google Search = C:\Documents and Settings\Darlita\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Complitly plugin for chrome = C:\Documents and Settings\Darlita\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dlfienamagdnkekbbbocojppncdambda\1.1_0\
CHR - Extension: GetDislike = C:\Documents and Settings\Darlita\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gecfaonpigeiandhnmepfclkmldegepl\3.2_0\
CHR - Extension: Click&Clean; = C:\Documents and Settings\Darlita\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\7.8.2.0_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\Darlita\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: We-Care Reminder Lite = C:\Documents and Settings\Darlita\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lkpmjnommfoljgjbckjmjhkmnhfmcmon\1.2.0.2_0\
CHR - Extension: We-Care Reminder Lite = C:\Documents and Settings\Darlita\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lkpmjnommfoljgjbckjmjhkmnhfmcmon\1.2.0.2_0\.bak
CHR - Extension: 2YourFace = C:\Documents and Settings\Darlita\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lmblfngognklgemafekefcdjcnkdhmdm\1.0_0\
CHR - Extension: Poppit = C:\Documents and Settings\Darlita\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
CHR - Extension: FastestChrome - Browse Faster = C:\Documents and Settings\Darlita\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mmffncokckfccddfenhkhnllmlobdahm\5.9.5_0\
CHR - Extension: iReader = C:\Documents and Settings\Darlita\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ppelffpjgkifjfgnbaaldcehkpajlmbc\1.3.0.2_0\

O1 HOSTS File: ([2011/12/28 15:00:54 | 001,248,071 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 # ads and track users across
O1 - Hosts: 127.0.0.1 # and potentially other sites.
O1 - Hosts: 127.0.0.1 # and some distribute adware and spyware
O1 - Hosts: 127.0.0.1 # log all such errors.
O1 - Hosts: 127.0.0.1 # message board spam and are unlikely to be real sites
O1 - Hosts: 127.0.0.1 # mistyped URLs to search engines. They
O1 - Hosts: 127.0.0.1 # problems with NPR.org
O1 - Hosts: 127.0.0.1 # the com.com family of sites
O1 - Hosts: 127.0.0.1 # up CSS on livejournal
O1 - Hosts: 127.0.0.1 # URLs to their site.
O1 - Hosts: 127.0.0.1 .
O1 - Hosts: 127.0.0.1 ::1localhost
O1 - Hosts: 127.0.0.1 0 old macs
O1 - Hosts: 127.0.0.1 0 text file
O1 - Hosts: 127.0.0.1 0.0.0.0
O1 - Hosts: 127.0.0.1 0.0.0.0 006.free-counter.co.uk
O1 - Hosts: 127.0.0.1 0.0.0.0 006.freecounters.co.uk
O1 - Hosts: 127.0.0.1 0.0.0.0 06272002-dbase.hitcountz.net # Web bugs in spam
O1 - Hosts: 127.0.0.1 0.0.0.0 09killspyware.com
O1 - Hosts: 127.0.0.1 0.0.0.0 0pn.ru
O1 - Hosts: 127.0.0.1 0.0.0.0 0stats.com
O1 - Hosts: 127.0.0.1 0.0.0.0 1.adbrite.com
O1 - Hosts: 127.0.0.1 0.0.0.0 1.httpads.com
O1 - Hosts: 127.0.0.1 0.0.0.0 1.primaryads.com
O1 - Hosts: 127.0.0.1 0.0.0.0 102.112.2o7.net
O1 - Hosts: 40575 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll File not found
O2 - BHO: (no name) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - No CLSID value found.
O2 - BHO: (no name) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - No CLSID value found.
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - No CLSID value found.
O2 - BHO: (no name) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - No CLSID value found.
O2 - BHO: (no name) - {8373ADC0-6330-11DD-9D77-22C856D89593} - No CLSID value found.
O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - No CLSID value found.
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - No CLSID value found.
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No CLSID value found.
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (no name) - {bd3fd433-147a-482e-a192-614f26e2310c} - No CLSID value found.
O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O2 - BHO: (no name) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - No CLSID value found.
O2 - BHO: (no name) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - No CLSID value found.
O2 - BHO: (no name) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Browsing Protection Toolbar) - {265EEE8E-3228-44D3-AEA5-F7FDF5860049} - C:\Program Files\Charter Business Desktop Security\NRS\iescript\baselitmus.dll (F-Secure Corporation)
O3 - HKLM\..\Toolbar: (MapQuest Toolbar) - {9302e698-7e00-43ab-b867-c6e759bc2ada} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (MapQuest Toolbar) - {9302E698-7E00-43AB-B867-C6E759BC2ADA} - Reg Error: Value error. File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [F-Secure Manager] C:\Program Files\Charter Business Desktop Security\Common\FSM32.EXE (F-Secure Corporation)
O4 - HKLM..\Run: [F-Secure TNB] C:\Program Files\Charter Business Desktop Security\FSGUI\TNBUtil.exe (F-Secure Corporation)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe (HP)
O4 - HKLM..\Run: [Logitech Utility] C:\WINDOWS\LOGI_MWX.EXE (Logitech Inc.)
O4 - HKLM..\Run: [SpybotSnD] C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe (Safer Networking Limited)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [chromium] C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - Reg Error: Key error. File not found
O9 - Extra Button: Go to PlaySushi web site - {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - Reg Error: Value error. File not found
O15 - HKCU\..Trusted Domains: live.com ([mail] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Treasures%20Of%20Montezuma/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: Garmin Communicator Plug-In https://my.garmin.com/static/m/cab/2.7.1/GarminAxControl.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6622BFED-AF73-47BB-B494-05378CEA4EC6}: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/11/23 04:00:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{01170d51-7221-11de-8c86-0014a542aea0}\Shell - "" = AutoRun
O33 - MountPoints2\{01170d51-7221-11de-8c86-0014a542aea0}\Shell\AutoRun - "" = Auto&Play;
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3acm - C:\WINDOWS\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - C:\WINDOWS\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.scg726 - C:\WINDOWS\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - C:\WINDOWS\System32\vct3216.acm (Voxware, Inc.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\divx.dll (DivXNetworks, Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\mcdvd_32.dll (MainConcept)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2024/07/09 00:07:18 | 000,000,000 | —D | C] – C:\Program Files\iWin.com
[2024/07/09 00:03:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\iWin Games
[2011/12/30 10:36:40 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Darlita\Recent
[2011/12/29 16:29:42 | 000,000,000 | —D | C] – C:\Program Files\Chrome Extensions
[2011/12/29 16:28:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Darlita\My Documents\Chrome Extensions Support
[2011/12/29 16:28:09 | 000,000,000 | —D | C] – C:\Documents and Settings\Darlita\My Documents\New Folder (2)
[2011/12/29 15:26:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Darlita\Local Settings\Application Data\Promosoft Corporation
[2011/12/29 15:25:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Promosoft Corporation
[2011/12/29 15:25:43 | 000,000,000 | —D | C] – C:\Program Files\Promosoft Corporation
[2011/12/28 21:17:47 | 000,034,688 | —- | C] (Toshiba Corp.) – C:\WINDOWS\System32\drivers\lbrtfdc.sys
[2011/12/28 21:17:47 | 000,034,688 | —- | C] (Toshiba Corp.) – C:\WINDOWS\System32\dllcache\lbrtfdc.sys
[2011/12/28 21:17:47 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\changer.sys
[2011/12/28 21:17:47 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\changer.sys
[2011/12/28 20:44:30 | 000,000,000 | —D | C] – C:\Program Files\AA Antimalware
[2011/12/28 15:30:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
[2011/12/27 12:58:13 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2011/12/27 01:36:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/12/27 01:33:20 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/12/27 01:04:20 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Apple Computer
[2011/12/27 00:54:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2011/12/27 00:53:01 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2011/12/26 21:23:34 | 000,000,000 | —D | C] – C:\Program Files\Common Files\xing shared
[2011/12/26 21:19:24 | 000,198,832 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/12/26 21:12:13 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/12/26 21:12:12 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/12/26 21:12:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Real
[2011/12/26 21:11:59 | 000,272,896 | —- | C] (Progressive Networks) – C:\WINDOWS\System32\pncrt.dll
[2011/12/25 01:07:12 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SpeedyPC Software
[2011/12/25 01:06:27 | 000,000,000 | —D | C] – C:\Program Files\SpeedyPC Software
[2011/12/25 01:06:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SpeedyPC Software
[2011/12/22 10:20:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Darlita\Local Settings\Application Data\doubleTwist Corporation
[2011/12/22 10:19:08 | 000,000,000 | —D | C] – C:\Program Files\ffdshow
[2011/12/22 10:12:31 | 000,000,000 | —D | C] – C:\Program Files\doubleTwist 2.0
[2011/12/22 10:11:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Darlita\Application Data\OpenCandy
[2011/12/15 18:07:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2011/12/15 14:38:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Darlita\Application Data\FreeFileViewer
[2011/12/14 22:43:13 | 000,000,000 | —D | C] – C:\Program Files\getdislike
[2011/12/14 22:37:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Darlita\Application Data\KC Softwares
[2011/12/14 22:34:11 | 000,000,000 | —D | C] – C:\Program Files\Complitly
[2011/12/14 22:34:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Darlita\Application Data\Complitly
[2011/12/14 22:34:00 | 000,000,000 | —D | C] – C:\Program Files\2YourFace
[2011/12/14 22:33:52 | 000,000,000 | —D | C] – C:\Program Files\Surf Canyon
[2011/12/14 22:33:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\PriceGong
[2011/12/14 22:33:36 | 000,000,000 | —D | C] – C:\Program Files\PriceGong
[2011/12/14 22:32:39 | 000,000,000 | —D | C] – C:\Program Files\KC Softwares
[2011/12/12 16:02:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\FreeFileViewer
[2011/12/12 16:01:45 | 000,000,000 | —D | C] – C:\Program Files\FreeFileViewer
[2011/12/12 16:01:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Darlita\Application Data\Fighters
[2011/12/12 16:00:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Fighters
[2011/12/12 15:59:50 | 000,000,000 | —D | C] – C:\Program Files\Fighters
[2011/12/12 15:59:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Fighters
[2011/12/12 15:56:06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\WeCareReminder
[2011/12/08 14:46:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Darlita\Application Data\QuickScan
[2010/10/21 11:18:00 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Program Files\spybotsd162.exe
[80 C:\Documents and Settings\Darlita\My Documents\*.tmp files -> C:\Documents and Settings\Darlita\My Documents\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/30 20:18:00 | 000,000,746 | —- | M] () – C:\WINDOWS\tasks\OpenCandyHelper.job
[2011/12/30 20:01:00 | 000,000,238 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/12/30 19:51:10 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/30 17:34:30 | 000,625,664 | —- | M] () – C:\Documents and Settings\Darlita\Desktop\dds.scr
[2011/12/30 17:01:03 | 000,000,000 | —- | M] () – C:\3590F75ABA9E485486C100C1A9D4FF06SPBTZSKAWLYEVVOH
[2011/12/30 16:02:00 | 000,000,382 | —- | M] () – C:\WINDOWS\tasks\FreeFileViewerUpdateChecker.job
[2011/12/30 16:01:00 | 000,000,388 | —- | M] () – C:\WINDOWS\tasks\SLOW-PCfighter-Darlita-Notification.job
[2011/12/30 15:29:01 | 000,000,372 | —- | M] () – C:\WINDOWS\tasks\FinalTorrent Update Checker.job
[2011/12/30 14:56:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cc9b22c9c4d498.job
[2011/12/30 12:00:00 | 000,000,674 | —- | M] () – C:\WINDOWS\tasks\Free Registry Fix.job
[2011/12/30 04:00:00 | 000,000,320 | —- | M] () – C:\WINDOWS\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2011/12/29 19:44:00 | 000,000,300 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-49310632-759934470-755470493-1009.job
[2011/12/29 15:25:46 | 000,001,129 | —- | M] () – C:\Documents and Settings\Darlita\Application Data\Microsoft\Internet Explorer\Quick Launch\Free Registry Fix.lnk
[2011/12/29 15:25:46 | 000,001,111 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Free Registry Fix.lnk
[2011/12/28 22:54:56 | 000,000,746 | —- | M] () – C:\WINDOWS\tasks\OpenCandyHelperRun.job
[2011/12/28 22:54:56 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-49310632-759934470-755470493-1009.job
[2011/12/28 22:54:56 | 000,000,282 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-49310632-759934470-755470493-1006.job
[2011/12/28 22:54:55 | 000,000,360 | —- | M] () – C:\WINDOWS\tasks\SLOW-PCfighter-Darlita-Startup.job
[2011/12/28 22:54:28 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/28 22:54:25 | 1004,851,200 | -HS- | M] () – C:\hiberfil.sys
[2011/12/28 22:50:21 | 000,002,392 | —- | M] () – C:\Documents and Settings\Darlita\My Documents\delete files and go to site.rtf
[2011/12/28 21:59:02 | 000,184,479 | —- | M] () – C:\Documents and Settings\Darlita\My Documents\Remove from computer.rtf
[2011/12/28 20:04:51 | 000,000,290 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-49310632-759934470-755470493-1006.job
[2011/12/27 01:36:23 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/12/27 00:39:15 | 000,001,854 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2011/12/27 00:39:15 | 000,001,854 | —- | M] () – C:\Documents and Settings\Darlita\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/12/26 21:38:13 | 000,000,747 | —- | M] () – C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
[2011/12/26 21:19:24 | 000,198,832 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/12/26 21:12:13 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/12/26 21:12:12 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/12/26 21:11:59 | 000,272,896 | —- | M] (Progressive Networks) – C:\WINDOWS\System32\pncrt.dll
[2011/12/26 12:24:25 | 000,000,238 | RHS- | M] () – C:\boot.ini
[2011/12/26 11:20:31 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/12/25 04:43:00 | 000,000,340 | —- | M] () – C:\WINDOWS\tasks\Driver Robot.job
[2011/12/25 01:20:49 | 000,000,424 | —- | M] () – C:\WINDOWS\tasks\SpeedyPC Registration3.job
[2011/12/25 01:07:35 | 000,000,444 | —- | M] () – C:\WINDOWS\tasks\SpeedyPC Update Version3.job
[2011/12/25 01:07:34 | 000,000,400 | —- | M] () – C:\WINDOWS\tasks\SpeedyPC Pro.job
[2011/12/17 09:45:21 | 000,355,360 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/12/15 19:15:32 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/12/14 22:47:21 | 000,000,000 | —- | M] () – C:\Documents and Settings\All Users\Application Data\d02025c1d9b1ff64326d9fec08d9ccd1_c
[2011/12/12 16:02:18 | 000,000,772 | —- | M] () – C:\Documents and Settings\Darlita\Application Data\Microsoft\Internet Explorer\Quick Launch\FreeFileViewer.lnk
[2011/12/10 08:23:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/30 23:41:23 | 024,939,525 | —- | M] () – C:\Documents and Settings\Darlita\My Documents\My Baby Lit Rick.rtf
[80 C:\Documents and Settings\Darlita\My Documents\*.tmp files -> C:\Documents and Settings\Darlita\My Documents\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/30 17:34:28 | 000,625,664 | —- | C] () – C:\Documents and Settings\Darlita\Desktop\dds.scr
[2011/12/30 17:01:03 | 000,000,000 | —- | C] () – C:\3590F75ABA9E485486C100C1A9D4FF06SPBTZSKAWLYEVVOH
[2011/12/29 15:26:07 | 000,000,674 | —- | C] () – C:\WINDOWS\tasks\Free Registry Fix.job
[2011/12/29 15:25:46 | 000,001,129 | —- | C] () – C:\Documents and Settings\Darlita\Application Data\Microsoft\Internet Explorer\Quick Launch\Free Registry Fix.lnk
[2011/12/29 15:25:46 | 000,001,117 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Free Registry Fix.lnk
[2011/12/29 15:25:46 | 000,001,111 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Free Registry Fix.lnk
[2011/12/28 22:50:21 | 000,002,392 | —- | C] () – C:\Documents and Settings\Darlita\My Documents\delete files and go to site.rtf
[2011/12/28 21:16:22 | 000,184,479 | —- | C] () – C:\Documents and Settings\Darlita\My Documents\Remove from computer.rtf
[2011/12/27 01:36:23 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/12/27 00:39:15 | 000,001,854 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2011/12/26 21:38:12 | 000,000,747 | —- | C] () – C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
[2011/12/25 01:20:49 | 000,000,424 | —- | C] () – C:\WINDOWS\tasks\SpeedyPC Registration3.job
[2011/12/25 01:07:35 | 000,000,444 | —- | C] () – C:\WINDOWS\tasks\SpeedyPC Update Version3.job
[2011/12/25 01:07:32 | 000,000,400 | —- | C] () – C:\WINDOWS\tasks\SpeedyPC Pro.job
[2011/12/22 13:03:45 | 000,000,746 | —- | C] () – C:\WINDOWS\tasks\OpenCandyHelperRun.job
[2011/12/22 13:03:43 | 000,000,746 | —- | C] () – C:\WINDOWS\tasks\OpenCandyHelper.job
[2011/12/15 18:07:16 | 000,000,682 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/12/14 22:47:21 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\d02025c1d9b1ff64326d9fec08d9ccd1_c
[2011/12/12 16:02:35 | 000,000,382 | —- | C] () – C:\WINDOWS\tasks\FreeFileViewerUpdateChecker.job
[2011/12/12 16:02:18 | 000,000,772 | —- | C] () – C:\Documents and Settings\Darlita\Application Data\Microsoft\Internet Explorer\Quick Launch\FreeFileViewer.lnk
[2011/12/12 16:01:26 | 000,000,388 | —- | C] () – C:\WINDOWS\tasks\SLOW-PCfighter-Darlita-Notification.job
[2011/12/12 16:01:24 | 000,000,360 | —- | C] () – C:\WINDOWS\tasks\SLOW-PCfighter-Darlita-Startup.job
[2011/07/26 19:26:02 | 000,000,000 | —- | C] () – C:\WINDOWS\loader2.exe_ok
[2011/07/12 14:38:50 | 000,032,397 | —- | C] () – C:\WINDOWS\SGTBox.INI
[2011/06/19 23:41:58 | 000,000,074 | —- | C] () – C:\WINDOWS\DosHlpLnk.ini
[2011/06/19 23:38:12 | 000,002,752 | —- | C] () – C:\WINDOWS\LottoBuster.ini
[2011/05/22 23:00:00 | 000,000,130 | -H– | C] () – C:\Documents and Settings\Darlita\Local Settings\Application Data\spbconfigvla.cfg
[2011/04/05 21:12:07 | 000,194,200 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/02/07 19:42:47 | 000,345,518 | —- | C] () – C:\WINDOWS\uninstall asl_scre.exe
[2011/01/11 16:50:14 | 000,000,054 | —- | C] () – C:\WINDOWS\INSTALL.INI
[2010/11/21 21:38:54 | 000,018,944 | —- | C] () – C:\WINDOWS\System32\xrxscnui.dll
[2010/10/23 22:00:11 | 000,000,136 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/10/21 12:24:02 | 000,000,370 | —- | C] () – C:\WINDOWS\wininit.ini
[2010/10/20 12:28:46 | 000,042,664 | —- | C] () – C:\WINDOWS\System32\drivers\fsbts.sys
[2010/09/27 10:25:24 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\nwrrcinfo.dll
[2010/09/10 09:27:21 | 000,104,096 | —- | C] () – C:\WINDOWS\hpoins04.dat.temp
[2010/09/10 09:27:20 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat.temp
[2010/09/04 10:13:11 | 000,000,106 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2010/08/07 23:04:16 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/07/14 13:28:04 | 000,000,099 | —- | C] () – C:\WINDOWS\System32\mhncache.dat
[2010/07/07 23:35:02 | 000,074,703 | —- | C] () – C:\WINDOWS\System32\mfc45.dll
[2010/07/04 18:19:41 | 000,021,791 | —- | C] () – C:\WINDOWS\System32\smtpctrs.ini
[2010/07/04 18:19:40 | 000,001,037 | —- | C] () – C:\WINDOWS\System32\ntfsdrct.ini
[2010/07/04 18:17:54 | 000,007,909 | —- | C] () – C:\WINDOWS\System32\ftpctrs.ini
[2010/07/04 18:17:42 | 000,038,576 | —- | C] () – C:\WINDOWS\System32\w3ctrs.ini
[2010/07/04 18:17:41 | 000,010,225 | —- | C] () – C:\WINDOWS\System32\axperf.ini
[2010/07/04 18:17:37 | 000,011,435 | —- | C] () – C:\WINDOWS\System32\infoctrs.ini
[2010/06/24 01:01:54 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/06/16 13:30:04 | 000,001,748 | —- | C] () – C:\Program Files\Belarc Advisor.lnk
[2010/06/16 13:29:59 | 000,003,840 | —- | C] () – C:\WINDOWS\System32\drivers\BANTExt.sys
[2010/06/16 13:28:50 | 002,277,896 | —- | C] () – C:\Program Files\advisor.exe
[2010/06/12 11:11:58 | 000,067,988 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/06/12 10:13:47 | 000,008,704 | —- | C] () – C:\Documents and Settings\Darlita\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/22 20:56:44 | 000,000,064 | —- | C] () – C:\WINDOWS\GPlrLanc.dat
[2010/03/10 20:18:11 | 000,004,096 | —- | C] () – C:\WINDOWS\d3dx.dat
[2009/10/20 13:19:30 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2009/07/28 11:27:30 | 000,000,065 | —- | C] () – C:\Documents and Settings\Darlita\Application Data\AVSMediaPlayer.m3u
[2009/07/23 13:09:00 | 000,000,202 | —- | C] () – C:\WINDOWS\PowerReg.dat
[2009/07/23 11:01:13 | 000,000,069 | —- | C] () – C:\WINDOWS\encore_launcher.ini
[2009/07/15 14:55:39 | 000,000,000 | —- | C] () – C:\WINDOWS\Dvm.INI
[2009/07/15 13:52:08 | 000,000,000 | —- | C] () – C:\WINDOWS\DVEdit.INI
[2009/07/15 13:37:52 | 000,122,880 | —- | C] () – C:\WINDOWS\System32\trc.dll
[2009/07/15 13:37:52 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\dsp_trc.dll
[2009/07/15 13:37:52 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\IcdSptSvps.dll
[2009/07/15 13:33:17 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/07/15 13:33:17 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\vidccleaner.exe
[2009/07/14 23:15:27 | 000,000,130 | —- | C] () – C:\Documents and Settings\Darlita\Local Settings\Application Data\fusioncache.dat
[2009/07/14 16:10:15 | 000,104,096 | —- | C] () – C:\WINDOWS\hpoins04.dat
[2009/07/14 16:10:15 | 000,017,176 | —- | C] () – C:\WINDOWS\hpomdl04.dat
[2009/07/10 11:23:26 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2009/07/10 10:50:44 | 000,000,060 | —- | C] () – C:\WINDOWS\System32\SYSDRV.DAT
[2009/07/10 09:52:43 | 000,087,540 | R— | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2009/07/10 09:01:40 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\BJAXSecurityManager.dll
[2009/07/10 09:01:38 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\BJInstaller.dll
[2009/07/10 01:38:49 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2009/07/10 01:38:07 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2009/07/10 01:38:07 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2009/07/10 01:37:56 | 000,005,151 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2009/07/10 01:37:43 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2009/07/10 01:37:21 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2009/07/10 01:36:03 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2009/07/10 01:36:01 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2009/07/10 01:32:45 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2009/07/10 01:31:28 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2008/09/22 18:26:02 | 000,029,600 | —- | C] () – C:\WINDOWS\System32\mxntdfg.exe
[2005/11/23 06:14:52 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/11/23 05:52:11 | 000,352,256 | —- | C] () – C:\WINDOWS\System32\HotlineClient.exe
[2005/11/23 04:03:30 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005/11/23 03:56:12 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005/11/23 02:13:49 | 000,000,461 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2005/11/23 02:13:49 | 000,000,378 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/11/23 02:12:42 | 000,565,060 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005/11/23 02:12:42 | 000,120,104 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005/11/22 19:49:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005/11/22 19:48:41 | 000,355,360 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/10/14 04:56:50 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/10/14 04:56:50 | 000,921,600 | —- | C] () – C:\WINDOWS\System32\VorbisEnc.dll
[2005/10/14 04:56:50 | 000,778,240 | —- | C] () – C:\WINDOWS\System32\DivXsm.exe
[2005/10/14 04:56:50 | 000,761,856 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2005/10/14 04:56:50 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\xvid.dll
[2005/10/14 04:56:50 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2005/10/14 04:56:50 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2005/10/14 04:56:50 | 000,155,136 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2005/10/14 04:56:50 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2005/10/14 04:56:48 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\MMSwitch.dll
[2005/10/14 04:56:48 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\MMAVILNG.exe
[2005/08/06 00:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll

========== LOP Check ==========

[2011/04/23 13:58:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alawar Stargaze
[2010/09/26 19:42:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avanquest
[2009/11/04 11:24:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Broderbund
[2010/07/16 12:06:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2009/07/31 00:14:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cakewalk
[2010/07/29 05:42:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\d1ac72d
[2010/03/10 20:18:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Digital Praise
[2010/09/17 18:16:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2010/09/18 20:20:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Driver Boost
[2010/10/27 04:50:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\f-secure
[2011/12/12 15:59:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fighters
[2010/11/04 10:32:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Free Ride Games
[2010/06/24 00:00:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Friends Games
[2010/10/27 04:48:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\fssg
[2010/07/12 12:29:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intenium
[2020/07/08 01:05:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2024/07/09 00:03:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iWin Games
[2010/08/11 20:22:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MapQuest Toolbar
[2010/04/27 19:07:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2010/10/18 20:54:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nuance
[2011/10/18 16:01:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/07/14 14:55:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/06/12 08:53:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2010/04/30 15:36:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2010/11/07 22:23:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Playrix Entertainment
[2010/11/12 10:14:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Rumbic Studio
[2010/09/21 20:52:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2010/09/17 18:17:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/07/26 15:13:15 | 000,000,000 | -HSD | M] – C:\Documents and Settings\All Users\Application Data\SMFXCDRAV
[2011/12/25 01:07:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpeedyPC Software
[2011/12/14 22:19:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2011/12/29 15:29:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/26 21:01:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VisualShape
[2010/05/15 17:36:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\W3i
[2011/12/12 15:56:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WeCareReminder
[2010/05/08 14:06:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/01/10 19:35:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011/12/28 15:30:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
[2011/07/04 18:43:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\.expertlotto
[2010/07/01 16:21:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\AdBin
[2010/12/10 21:17:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Amazon
[2010/09/25 15:08:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Avanquest
[2011/01/01 02:06:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Awem
[2011/12/15 14:47:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\BeadTool
[2011/09/19 20:31:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Cache
[2009/07/31 23:31:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Cakewalk
[2011/12/14 22:34:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Complitly
[2010/12/26 11:25:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Data Solutions
[2010/06/23 20:46:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\DeviceDoctorSoftware
[2011/10/18 15:28:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\DriverCure
[2011/08/12 11:44:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Dropbox
[2009/07/22 22:53:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\eGames
[2010/09/06 10:52:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\ElevatedDiagnostics
[2010/05/02 18:57:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Exent Technologies
[2010/10/28 11:54:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\F-Secure
[2010/12/27 19:37:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\FedEx
[2010/12/19 14:07:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\FedExDesktop.026F9BDCA0F141E500950436A5D33181EE6B8EF5.1
[2011/12/12 16:01:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Fighters
[2011/03/17 10:21:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\FinalTorrent
[2011/12/15 14:39:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\FreeFileViewer
[2011/03/24 18:54:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Friday's games
[2010/06/01 11:07:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Gaijin Ent
[2009/07/21 15:30:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\GARMIN
[2009/07/22 22:19:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Hulabee
[2010/07/07 23:26:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\iolo
[2011/12/14 22:37:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\KC Softwares
[2011/01/17 13:49:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Microsys
[2010/10/18 20:54:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Nuance
[2011/12/26 11:53:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\OpenCandy
[2011/10/18 15:28:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\ParetoLogic
[2010/04/30 15:36:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\PlayFirst
[2011/12/08 14:47:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\QuickScan
[2010/06/24 15:30:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Readonweb
[2011/10/01 12:41:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Reviversoft
[2010/12/20 17:43:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Sahmon Games
[2010/11/24 15:43:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Software Informer
[2010/06/30 21:27:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\SpinTop
[2011/12/28 20:03:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Spotify
[2011/06/21 21:42:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Sprintbit Software
[2010/12/05 09:35:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Titanium Gears
[2011/12/28 15:29:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Uniblue
[2010/10/02 12:36:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Video Surgeon
[2010/10/26 21:01:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\VisualShape
[2010/09/29 10:18:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Windows Search
[2010/11/21 21:39:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Xerox
[2010/09/17 18:17:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Darlita\Application Data\Zeon
[2011/12/25 04:43:00 | 000,000,340 | —- | M] () – C:\WINDOWS\Tasks\Driver Robot.job
[2011/12/30 15:29:01 | 000,000,372 | —- | M] () – C:\WINDOWS\Tasks\FinalTorrent Update Checker.job
[2011/12/30 12:00:00 | 000,000,674 | —- | M] () – C:\WINDOWS\Tasks\Free Registry Fix.job
[2011/12/30 16:02:00 | 000,000,382 | —- | M] () – C:\WINDOWS\Tasks\FreeFileViewerUpdateChecker.job
[2011/12/30 20:18:00 | 000,000,746 | —- | M] () – C:\WINDOWS\Tasks\OpenCandyHelper.job
[2011/12/28 22:54:56 | 000,000,746 | —- | M] () – C:\WINDOWS\Tasks\OpenCandyHelperRun.job
[2011/12/30 20:01:00 | 000,000,238 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
[2011/12/30 16:01:00 | 000,000,388 | —- | M] () – C:\WINDOWS\Tasks\SLOW-PCfighter-Darlita-Notification.job
[2011/12/28 22:54:55 | 000,000,360 | —- | M] () – C:\WINDOWS\Tasks\SLOW-PCfighter-Darlita-Startup.job
[2011/12/25 01:07:34 | 000,000,400 | —- | M] () – C:\WINDOWS\Tasks\SpeedyPC Pro.job
[2011/12/25 01:20:49 | 000,000,424 | —- | M] () – C:\WINDOWS\Tasks\SpeedyPC Registration3.job
[2011/12/25 01:07:35 | 000,000,444 | —- | M] () – C:\WINDOWS\Tasks\SpeedyPC Update Version3.job
[2011/01/21 13:42:25 | 000,000,426 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{079F5238-CBE3-47AE-895B-101D5F2477BA}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/12/30 17:01:03 | 000,000,000 | —- | M] () – C:\3590F75ABA9E485486C100C1A9D4FF06SPBTZSKAWLYEVVOH
[2005/11/23 04:00:29 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/07/28 11:31:46 | 000,000,809 | —- | M] () – C:\AVS Media Player.lnk
[2009/07/10 09:01:44 | 007,902,990 | —- | M] () – C:\BellSouthIW.re~
[2011/12/26 12:24:25 | 000,000,238 | RHS- | M] () – C:\boot.ini
[2009/07/16 10:25:58 | 074,681,904 | —- | M] (F-Secure Corporation) – C:\Charter_version_8.exe
[2005/11/23 04:00:29 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/07/04 21:18:37 | 000,000,214 | —- | M] () – C:\Controls.ini
[2011/06/09 23:24:25 | 000,000,184 | —- | M] () – C:\error.fstmp
[2011/12/28 22:54:25 | 1004,851,200 | -HS- | M] () – C:\hiberfil.sys
[2011/06/09 23:00:00 | 000,000,000 | —- | M] () – C:\infect.fstmp
[2005/11/23 04:00:29 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2005/11/23 04:00:29 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/10 14:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/06/17 12:24:33 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/06/16 14:27:07 | 000,000,038 | —- | M] () – C:\ntosboot.bat
[2011/12/28 22:54:21 | 1507,172,352 | -HS- | M] () – C:\pagefile.sys
[2009/07/10 11:57:54 | 000,000,002 | —- | M] () – C:\REQUEST_OEMRESET_ENDUSER
[2009/07/10 11:57:54 | 000,000,002 | RHS- | M] () – C:\USER

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2004/08/10 14:00:00 | 000,000,067 | —- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2009/12/04 09:53:54 | 000,281,600 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpcpp094.dll
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/02/07 21:23:10 | 006,266,276 | —- | M] () – C:\WINDOWS\asl_scre.scr
[2010/04/16 23:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2009/10/30 10:47:05 | 000,001,666 | -H– | M] () – C:\Documents and Settings\Darlita\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >
[2010/06/16 13:29:43 | 002,277,896 | —- | M] () – C:\Program Files\advisor.exe
[2010/06/16 13:30:04 | 000,001,748 | —- | M] () – C:\Program Files\Belarc Advisor.lnk
[2010/06/16 12:58:06 | 000,045,426 | —- | M] () – C:\Program Files\DxDiag 061610.txt
[2010/10/21 11:18:03 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Program Files\spybotsd162.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010/07/08 17:09:06 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2010/07/08 17:09:06 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2010/07/08 17:09:06 | 000,892,928 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/06/17 12:40:56 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/07/10 12:37:11 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Darlita\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/11/23 04:05:23 | 000,000,079 | —- | M] () – C:\Documents and Settings\Darlita\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-12-30 08:03:00

========== Alternate Data Streams ==========

@Alternate Data Stream - 94 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F79F64B8
@Alternate Data Stream - 48 bytes -> C:\Documents and Settings\All Users\DRM:مايكروسوفت
@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EF84937D
@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D8F51B27
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B63300D1
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:815D61C4
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:8D072ABD

< End of report >

From Extras
OTL Extras logfile created on: 12/30/2011 8:16:41 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Darlita\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

958.23 Mb Total Physical Memory | 186.39 Mb Available Physical Memory | 19.45% Memory free
2.25 Gb Paging File | 1.33 Gb Available in Paging File | 58.95% Paging File free
Paging file location(s): C:\pagefile.sys 2 1437E:\pagefile.sys 2 1437 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 37.02 Gb Free Space | 24.84% Space Free | Partition Type: NTFS
Drive E: | 298.09 Gb Total Space | 256.00 Gb Free Space | 85.88% Space Free | Partition Type: NTFS

Computer Name: LITAS-ELOHIM709 | User Name: Darlita | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – "C:\Program Files\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [File Finder…] – C:\Program Files\Avanquest\PowerDesk\pdfind.exe /PATH:%1 (Avanquest North America, Inc.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [mass zip] – Reg Error: Value error.
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"DisableThumbnailCache" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Dogpile Toolbar\TroubleShooter.exe" = C:\Program Files\Dogpile Toolbar\TroubleShooter.exe:*:Disabled:Dogpile Toolbar (Helper)
"C:\Program Files\Dogpile Toolbar\ToolbarUpdate.exe" = C:\Program Files\Dogpile Toolbar\ToolbarUpdate.exe:*:Disabled:Dogpile Toolbar (Update)
"C:\Program Files\Microsoft Office\Office14\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote – (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)
"C:\Documents and Settings\Darlita\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Darlita\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox – (Dropbox, Inc.)
"C:\Program Files\FinalTorrent\FinalTorrent.EXE" = C:\Program Files\FinalTorrent\FinalTorrent.EXE:*:Enabled:FinalTorrent – (Bitberry Software)
"C:\Program Files\FinalTorrent\FTCheckForUpdates.exe" = C:\Program Files\FinalTorrent\FTCheckForUpdates.exe:*:Enabled:FinalTorrent Update Checker – (Bitberry Software)
"C:\Program Files\Audio Bible Ambassador\ABA3.exe" = C:\Program Files\Audio Bible Ambassador\ABA3.exe:*:Enabled:Audio Bible Ambassador – ()
"C:\Program Files\Audio Bible Ambassador\webupdater.exe" = C:\Program Files\Audio Bible Ambassador\webupdater.exe:*:Enabled:Audio Bible Ambassador Updater – ()
"C:\Documents and Settings\Darlita\Application Data\Spotify\spotify.exe" = C:\Documents and Settings\Darlita\Application Data\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify Ltd)
"C:\Program Files\FreeFileViewer\FFVCheckForUpdates.exe" = C:\Program Files\FreeFileViewer\FFVCheckForUpdates.exe:*:Enabled:FreeFileViewerUpdateChecker – (Bitberry Software)
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
"C:\Documents and Settings\Darlita\My Documents\Downloads\cnet2_frf_demo2_exe.exe" = C:\Documents and Settings\Darlita\My Documents\Downloads\cnet2_frf_demo2_exe.exe:*:Enabled:CNET Download.com Installer – (CNET Download.com)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{03853A8E-10F5-463D-8799-4D69C7C5CC1A}_is1" = Video Surgeon [removed]
"{08F32589-5E39-42B8-8BC5-6A8126ED2A70}" = Microsoft Visual C++ 2008 Redistributable Package
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{16F06070-DC5D-4F52-A162-C9E99C09E6CB}" = AutorunCleanUpTool
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{21E75254-410E-49C4-8981-2E1A2A2221F2}" = HP Diagnostic Assistant
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{238F787F-4FE9-4644-8362-30800F50E190}" = MediaSPace
"{2405665A-16C9-4D3A-B70E-F006220E1472}" = Overland
"{267868CE-6DFF-40F7-9C58-C01119B7B117}" = Fax
"{26A24AE4-039D-4CA4-87B4-2F83216025FF}" = Java™ 6 Update 29
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2BBC9458-07CA-4843-848B-5C8146E5EFA8}" = CreativeProjects
"{30E10267-3B27-42CC-B727-681DEBD30C4D}" = Clean Water Action TriMini Reminder by We-Care.com v5.0.2.2
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{34A59AC3-6C5C-4A09-A7F5-369A37176C8A}" = AiOSoftware
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3AE681E0-4E8D-453F-950A-48534D3C0724}" = Copy
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics
"{41254D7B-EADF-4078-AE4A-BD73B300EE86}" = Unload
"{416D1B47-451B-435A-8441-12A9F33AE860}" = Lotto Buster 2010
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{457791C5-D702-4143-A7B2-2744BE9573F2}" = HP Software Update
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E10664E-64AD-4F9D-B1D4-5FD8B6CC4427}_is1" = Spybot-S&D; Boot CD creator
"{4FFBB818-B13C-11E0-931D-B2664824019B}_is1" = Complitly
"{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{55A75679-02D1-4C8C-85CA-B4E4DF4D775F}" = MSM32Installer
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = MouseWare 9.76
"{597D73A8-5FDB-4bc1-9893-40B54459F1BC}" = ProductContext
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5DAB41E5-2979-42B2-91C5-57E68627EE58}" = Visual Lottery Analyser
"{607398CF-354B-4E21-B1BC-549424BFD04C}" = TIPCI
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A615007-721D-4063-B226-EA41EB6604B9}" = SystemSuite 9 Professional
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{779DECD7-E072-4B56-9B6B-BEB5973EEEB5}" = MobileMe Control Panel
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79ED0EE7-098C-465F-A853-B17F6FC6CDD8}" = GPS TrackMaker
"{7B478ACE-8512-4A46-ACB2-69D83DF2F6C7}" = Digital Voice Recorder
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{868291A4-229E-4795-B0B0-E60E87AF53CD}" = Sibelius Scorch (ActiveX Only)
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers Client 1.10.01
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00D1-0409-0000-0000000FF1CE}" = Microsoft Office Access database engine 2007 (English)
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUSR_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{94824ADD-8F26-43D2-84DB-22E11F377E5E}" = Microsoft English TTS Engine
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{96172E04-BB14-45F6-A77B-8EE7A421B903}" = SAPI Wrapper
"{97D0C0A1-7E64-4B05-A2EE-61D2CE23F154}" = TTS Wrapper
"{981FB376-8418-4EA8-BBED-9DE5AA63E7D5}" = SkinsHP1
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack
"{9CB2512B-3EC4-43DF-8002-46BDAB5EDD1B}" = QuickProjects
"{9EEBF8D5-8712-4D1D-88F4-4CDC2D270BC3}" = PrintScreen
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.2
"{A1DCC235-DACC-4E1F-8D11-D630634B4AEF}" = PhotoGallery
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2500497-FD32-493e-B8E5-28D6728DBEF5}" = Readme
"{A2A73632-BBAA-43EB-A337-ADF43F905A1C}" = Gateway Download Assistant
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{A7BE7658-4DB4-42D0-A128-C525C4A32703}" = InstallIQ Updater
"{A844AF89-2DB6-DAAA-6881-884F8E6DB96A}" = FedEx Desktop
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B1102A25-3AA3-446B-AA0F-A699B07A02FD}" = Garmin USB Drivers
"{B32C75F2-7495-4D01-9431-C11E97D66F8C}" = DocProc
"{B3D5D4E0-E965-41C4-ABFD-A7B1AD0663C2}" = Director
"{B3F1E526-180B-4480-9FEC-3E2DCB8EA9CE}" = F-Secure PSC Prerequisites
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B45D9FEE-1AF4-46F3-9A83-2545F81547F5}" = CreativeProjectsTemplates
"{B480904D-F73F-4673-B034-8A5F492C9184}" = Nuance PDF Reader
"{B56D5B09-C4FB-4EA0-8EAD-7BC3E2715A2D}" = DocumentViewer
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B73A3AD0-DEE1-4DB0-925F-1A9D9AC7ECED}" = Gladinet Cloud Desktop
"{B7DBF6E8-0D17-4BE4-853B-ACD6EFBD4A1F}" = iTunes
"{B93251B5-9209-4DAB-867C-AA98D91584CD}" = PowerDesk 7
"{BCC992E5-5C81-4066-9B55-03DC10B24D21}" = InstantShare
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BF018D2F-C788-4AB1-AB95-1280EAB8F13E}" = TrayApp
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2F8CA82-2BD9-4513-B2D1-08A47914C1DA}_is1" = Uniblue DriverScanner
"{C54CF9B1-B0A9-4FB6-9E9E-0F151754D823}_is1" = Active PC Optimizer 1.0
"{C67AD4DA-AF35-4341-B134-EFB131EA3C03}" = DesktopBFL
"{c6c214df-2922-4809-94aa-f4d67d4451ec}" = Music Oasis
"{C82185E8-C27B-4EF4-2010-3333BC2C2B6D}" = Microsoft AutoRoute 2010
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D575FBAA-D6D6-4221-A2C4-67541DB7AB5E}_is1" = Device Doctor 1.0.0.1
"{D92FF8EB-BD77-40AE-B68B-A6BFC6F8661D}" = Windows Live Family Safety
"{DE956B3E-4D2B-494C-8E5D-EF06BFA97AFA}" = Personal Financial Statement
"{E0783143-EAE2-4047-A8D6-E155523C594C}" = Garmin WebUpdater
"{E55B3271-7CA8-4D0C-AE06-69A24856E996}_is1" = Uniblue SpeedUpMyPC
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E94C6F6B-B53A-407A-A4E5-1F48719C11CA}" = AdBin
"{EC8673DA-F96B-497E-B2DB-BC7B029FD680}" = BufferChm
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F2AF3E5D-9697-485C-A5AC-E2B9468C446A}" = Safari
"{F4F47155-5B4D-42AA-97F8-490BC52EA7F3}" = Destinations
"{F65787F3-B356-45EC-8DD0-0E6758EDBCEE}" = WebReg
"{F6FCC591-A21B-47C7-BCB3-F535FBA210E2}" = SLOW-PCfighter
"{FF26F7EA-BCEE-478C-9A1B-6B4F88717D73}" = CueTour
"2YourFace" = 2YourFace 1.0
"45A7283175C62FAC673F913C1F532C5361F97841" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Age of Emerald_is1" = Age of Emerald
"All ATI Software" = ATI - Software Uninstall Utility
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.10
"am-wordmojogold" = Word Mojo Gold
"asl-screensaver" = asl-screensaver
"ATI Display Driver" = ATI Display Driver
"Atlantis Quest_is1" = Atlantis Quest
"Audio Bible Ambassador_is1" = Audio Bible Ambassador 1.0
"AVGantiRootkit" = AVG Anti-Rootkit Free
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVSCoverEditor_AVS4YOU_is1" = AVS Cover Editor [removed] (AVS4YOU)
"BeadTool 4_is1" = BeadTool 4.4.26
"Belarc Advisor" = Belarc Advisor 8.1
"Canon ScanGear Toolbox CS" = Canon ScanGear Toolbox CS 2.2
"CCleaner" = CCleaner
"Cheatbook 09.2010" = Cheatbook 09.2010
"Cheatbook Database 2010" = Cheatbook Database 2010
"Christmas Puzzle_is1" = Christmas Puzzle
"CleanMem" = CleanMem
"CNXT_AUDIO" = Conexant AC-Link Audio
"CNXT_MODEM_PCI_VEN_1002&DEV;_4378&SUBSYS;_0300107B" = Soft Data Fax Modem with SmartCP
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Cradle of Rome_is1" = Cradle of Rome
"DECCHECK" = Microsoft Windows XP Video Decoder Checkup Utility
"DriverAgent.exe" = DriverAgent by eSupport.com
"EasyGPS_is1" = EasyGPS 4.13
"EasyMapping" = EasyMapping
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"FA6937FABB6A495BB649F1BA09F8CBF2_is1" = A1 Website Analyzer
"Fast Folder Access" = Fast Folder Access
"FedExDesktop.026F9BDCA0F141E500950436A5D33181EE6B8EF5.1" = FedEx Desktop
"FinalTorrent_is1" = FinalTorrent 2011
"Free Registry Fix" = Free Registry Fix 5.6
"FreeFileViewer_is1" = Free File Viewer 2011
"F-Secure Product 440" = Charter Business® Desktop Security
"Gateway Drivers and Applications Recovery" = Gateway Drivers and Applications Recovery
"GetDislike" = GetDislike
"Google Chrome" = Google Chrome
"GoZone iSync" = GoZone iSync
"HijackThis" = HijackThis 1.99.1
"HP Photo & Imaging" = HP Image Zone 4.2
"Inca Ball_is1" = Inca Ball
"InstallShield_{607398CF-354B-4E21-B1BC-549424BFD04C}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"KC Softwares IDPhotoStudio_is1" = KC Softwares IDPhotoStudio
"Lotto Pro" = Lotto Pro
"LyricsSeeker plugins" = LyricsSeeker plugins 2.3
"Mah Jong Quest_is1" = Mah Jong Quest
"MapQuest Toolbar" = MapQuest Toolbar
"Marvell Miniport Driver" = Marvell Miniport Driver
"McAfee Security Scan" = McAfee Security Scan Plus
"MetroLyricsSeeker" = MetroLyrics Seeker
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mixxx" = NSIS Mixxx
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Musicnotes Combined Installer_is1" = Musicnotes Software Suite 1.0
"nbi-expertlotto-1.0.0.0.0" = Expert Lotto 5
"nutsie_uploader" = NSIS nutsie_uploader
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"Play Mahjong Forever_is1" = Play Mahjong Forever
"PowerPlayer For Pick 3 Pick 4 2010 Demo_is1" = PowerPlayer For Pick 3 Pick 4 7.7
"PriceGong" = PriceGong 2.5.4
"RealPlayer 15.0" = RealPlayer
"SignGenius ASL Pro DEMO" = SignGenius ASL Pro DEMO 3.1.3.780
"SLOW-PCfighter" = SLOW-PCfighter
"Software Informer_is1" = Software Informer 1.0 BETA
"Surf Canyon" = Fast Search
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"The Bible Lesson Record Book" = The Bible Lesson Record Book
"The Rise Of Atlantis_is1" = The Rise Of Atlantis
"The Treasures Of Montezuma_is1" = The Treasures Of Montezuma
"Trusted Software Assistant_is1" = File Type Assistant
"Tweak UI 2.10" = Tweak UI
"VLC media player" = VideoLAN VLC media player 0.8.6f
"What The Bible Says" = What The Bible Says
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.1.1
"Wizard Land_is1" = Wizard Land
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WMRemoteRegistryCleaner_is1" = RemoteRegistryCleaner v1.5 Build:500
"Word Hunt_is1" = Word Hunt [removed]
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"2004 Mahjongg" = 2004 Mahjongg
"Dropbox" = Dropbox
"Mahjongg Jr." = Mahjongg Jr.
"Mahjongg Master 5" = Mahjongg Master 5
"Mahjongg Master Egyptian Edition" = Mahjongg Master Egyptian Edition
"Mahjongg Patience" = Mahjongg Patience
"Mahjongg Tiles of Time Lite" = Mahjongg Tiles of Time Lite
"Spotify" = Spotify

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 12/28/2011 4:58:50 PM | Computer Name = LITAS-ELOHIM709 | Source = F-Secure Anti-Virus | ID = 103
Description = 9 2011-12-28 15:58:50-04:00 litas-elohim709 LITAS-ELOHIM709\Darlita
F-Secure Anti-Virus Malicious code found in file C:\Documents and Settings\Darlita\My
Documents\Downloads\A2.tmp. Infection: Gen:Variant.Graftor.6830 Action: The file
was quarantined.

Error - 12/28/2011 4:58:57 PM | Computer Name = LITAS-ELOHIM709 | Source = F-Secure Anti-Virus | ID = 103
Description = 10 2011-12-28 15:58:57-04:00 litas-elohim709 LITAS-ELOHIM709\Darlita
F-Secure Anti-Virus Malicious code found in file C:\Documents and Settings\Darlita\Local
Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_00009a. Infection:
Gen:Variant.Adware.Gamevance.11 Action: The file was deleted.

Error - 12/28/2011 4:58:59 PM | Computer Name = LITAS-ELOHIM709 | Source = F-Secure Anti-Virus | ID = 103
Description = 11 2011-12-28 15:58:58-04:00 litas-elohim709 LITAS-ELOHIM709\Darlita
F-Secure Anti-Virus Malicious code found in file C:\Documents and Settings\Darlita\My
Documents\Downloads\A2.tmp. Infection: Gen:Variant.Graftor.6830 Action: The file
was quarantined.

Error - 12/28/2011 4:59:00 PM | Computer Name = LITAS-ELOHIM709 | Source = F-Secure Anti-Virus | ID = 103
Description = 12 2011-12-28 15:58:59-04:00 litas-elohim709 LITAS-ELOHIM709\Darlita
F-Secure Anti-Virus Malicious code found in file C:\Documents and Settings\Darlita\My
Documents\Downloads\EpicPlaySetup.exe.crdownload. Infection: Gen:Variant.Graftor.6830
Action: The file was quarantined.

Error - 12/28/2011 4:59:01 PM | Computer Name = LITAS-ELOHIM709 | Source = F-Secure Anti-Virus | ID = 103
Description = 13 2011-12-28 15:59:00-04:00 litas-elohim709 LITAS-ELOHIM709\Darlita
F-Secure Anti-Virus Malicious code found in file C:\Documents and Settings\Darlita\My
Documents\Downloads\EpicPlaySetup.exe.crdownload. Infection: Gen:Variant.Adware.Gamevance.11
Action: The file was quarantined.

Error - 12/28/2011 4:59:04 PM | Computer Name = LITAS-ELOHIM709 | Source = F-Secure Anti-Virus | ID = 103
Description = 14 2011-12-28 15:59:01-04:00 litas-elohim709 LITAS-ELOHIM709\Darlita
F-Secure Anti-Virus Malicious code found in file C:\Documents and Settings\Darlita\My
Documents\Downloads\EpicPlaySetup.exe.crdownload. Infection: Gen:Variant.Adware.Gamevance.11
Action: The file was quarantined.

Error - 12/28/2011 4:59:09 PM | Computer Name = LITAS-ELOHIM709 | Source = F-Secure Anti-Virus | ID = 103
Description = 15 2011-12-28 15:59:09-04:00 litas-elohim709 LITAS-ELOHIM709\Darlita
F-Secure Anti-Virus Malicious code found in file C:\Documents and Settings\Darlita\My
Documents\Downloads\A9.tmp. Infection: Gen:Variant.Graftor.6830 Action: The file
was quarantined.

Error - 12/28/2011 4:59:16 PM | Computer Name = LITAS-ELOHIM709 | Source = F-Secure Anti-Virus | ID = 103
Description = 16 2011-12-28 15:59:16-04:00 litas-elohim709 LITAS-ELOHIM709\Darlita
F-Secure Anti-Virus Malicious code found in file C:\Documents and Settings\Darlita\Local
Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_00009d. Infection:
Gen:Variant.Adware.Gamevance.11 Action: The file was deleted.

Error - 12/28/2011 4:59:31 PM | Computer Name = LITAS-ELOHIM709 | Source = F-Secure Anti-Virus | ID = 103
Description = 17 2011-12-28 15:59:31-04:00 litas-elohim709 LITAS-ELOHIM709\Darlita
F-Secure Anti-Virus Malicious code found in file C:\Documents and Settings\Darlita\My
Documents\Downloads\B5.tmp. Infection: Gen:Variant.Adware.Gamevance.11 Action:
The file was quarantined.

Error - 12/30/2011 3:30:17 PM | Computer Name = LITAS-ELOHIM709 | Source = F-Secure Management Agent | ID = 103
Description = 1 2011-12-30 14:29:16-04:00 litas-elohim709 SYSTEM F-Secure Management
Agent The module F-Secure Anti-Virus Handler monitored by F-Secure Management Agent
has stopped responding or was terminated. Restarting it was not possible and it
will not be functional until the computer is restarted. If this message appears
after restarting the computer, contact the system administrator or reinstall F-Secure
products.

[ OSession Events ]
Error - 11/16/2010 12:36:35 PM | Computer Name = LITAS-ELOHIM709 | Source = Microsoft Office 12 Sessions | ID = 7001
Description =

[ System Events ]
Error - 12/28/2011 11:56:21 PM | Computer Name = LITAS-ELOHIM709 | Source = Service Control Manager | ID = 7000
Description = The SystemSuite Task Manager service failed to start due to the following
error: %%1053

Error - 12/28/2011 11:57:45 PM | Computer Name = LITAS-ELOHIM709 | Source = Service Control Manager | ID = 7022
Description = The SystemSuite service hung on starting.

Error - 12/29/2011 12:00:51 AM | Computer Name = LITAS-ELOHIM709 | Source = DCOM | ID = 10010
Description = The server {D61A27C6-8F53-11D0-BFA0-00A024151983} did not register
with DCOM within the required timeout.

Error - 12/29/2011 12:01:22 AM | Computer Name = LITAS-ELOHIM709 | Source = DCOM | ID = 10010
Description = The server {D61A27C6-8F53-11D0-BFA0-00A024151983} did not register
with DCOM within the required timeout.

Error - 12/29/2011 12:01:53 AM | Computer Name = LITAS-ELOHIM709 | Source = DCOM | ID = 10010
Description = The server {D61A27C6-8F53-11D0-BFA0-00A024151983} did not register
with DCOM within the required timeout.

Error - 12/29/2011 12:02:24 AM | Computer Name = LITAS-ELOHIM709 | Source = DCOM | ID = 10010
Description = The server {D61A27C6-8F53-11D0-BFA0-00A024151983} did not register
with DCOM within the required timeout.

Error - 12/29/2011 12:03:24 AM | Computer Name = LITAS-ELOHIM709 | Source = DCOM | ID = 10010
Description = The server {D61A27C6-8F53-11D0-BFA0-00A024151983} did not register
with DCOM within the required timeout.

Error - 12/29/2011 12:03:55 AM | Computer Name = LITAS-ELOHIM709 | Source = DCOM | ID = 10010
Description = The server {D61A27C6-8F53-11D0-BFA0-00A024151983} did not register
with DCOM within the required timeout.

Error - 12/29/2011 12:04:26 AM | Computer Name = LITAS-ELOHIM709 | Source = DCOM | ID = 10010
Description = The server {D61A27C6-8F53-11D0-BFA0-00A024151983} did not register
with DCOM within the required timeout.

Error - 12/29/2011 12:04:35 AM | Computer Name = LITAS-ELOHIM709 | Source = Service Control Manager | ID = 7034
Description = The SystemSuite service terminated unexpectedly. It has done this
1 time(s).


< End of report >
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

GMER

Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
———-

I removed your personal email address from your post.

In your next reply please post the log that is created by GMER. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI