This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Laptop Sluggish Lately [Solved]

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Really sluggish laptop lately, Especially with certain games I play. I'm not too sure if it's a video card related issue or malware etc. Would be more than greatful if I could have someone look over it for me. I feel selfish asking for help when there are others in need more then I am, so I've decided to join the classroom here at WTT so I can be an extra hand in the fight against malware. :D

OTL logfile created on: 7/02/2012 4:43:42 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Locky & Ricki-Lee\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 1.83 Gb Available Physical Memory | 61.23% Memory free
6.19 Gb Paging File | 4.63 Gb Available in Paging File | 74.82% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 361.45 Gb Total Space | 206.45 Gb Free Space | 57.12% Space Free | Partition Type: NTFS
Drive D: | 11.16 Gb Total Space | 1.85 Gb Free Space | 16.54% Space Free | Partition Type: NTFS

Computer Name: LOCKYSPC | User Name: Locky & Ricki-Lee | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Locky & Ricki-Lee\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_408c4e5a\stacsv.exe (IDT, Inc.)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Program Files\SMINST\BLService.exe ()
PRC - C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
PRC - C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
PRC - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe ()
PRC - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe ()
PRC - C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Hewlett-Packard)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_408c4e5a\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\BillP Studios\WinPatrol\sqlite3.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\10fc12b6bf6510f0b967d20a2b04c476\Microsoft.VisualBasic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\31729b33207d1093721f9e943302b900\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\a4fd3b000abfd4712b02ec223df3e9dd\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\9a01d9b5c7b5509bbc964881ce2be5a1\System.Transactions.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\7895f580432cd243f19aa40db58d38bc\System.EnterpriseServices.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\7895f580432cd243f19aa40db58d38bc\System.EnterpriseServices.Wrapper.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\45d73bf5a07b8fd8a12fcf7d68e9b318\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\024d3dc8d8df47a0420a382959c64fdf\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\4f15f4468f90ae42f43a74b94b064fae\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6d75eb3ca10a514754f5e87cc2134f07\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\19d027c3381110e60c003f2c8bd307ee\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\38b9d09539b67b08ee996db6c71f8a9b\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\982c005f97eacba888acdda322c49362\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\8a84d9c1f313d52f24bf191df15eead2\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\880639d34ff339510176a4c8b4251954\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\57ac9ba5419d6bf4b79f2979b0755428\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\c068708e16abf0be77a21b9f29817d83\mscorlib.ni.dll ()
MOD - C:\Program Files\Hewlett-Packard\HP Advisor\Content.XmlSerializers.dll ()
MOD - C:\Program Files\Hewlett-Packard\HP Advisor\RemotingClient.dll ()
MOD - C:\Program Files\Hewlett-Packard\HP Advisor\Pillars\PCAlerts\PCAlertsPillar.dll ()
MOD - C:\Program Files\Hewlett-Packard\HP Advisor\ECLibrary.dll ()
MOD - C:\Program Files\Hewlett-Packard\HP Advisor\MessagingClients.dll ()
MOD - C:\Program Files\Hewlett-Packard\HP Advisor\MessagingServer.dll ()
MOD - C:\Program Files\Hewlett-Packard\HP Advisor\MessagingMessages.dll ()
MOD - C:\Program Files\Hewlett-Packard\HP Advisor\MessagingInterface.dll ()
MOD - C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll ()
MOD - C:\Program Files\Hewlett-Packard\Media\TV\Kernel\Common\MCEMediaStatus.dll ()
MOD - C:\Windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\Program Files\CyberLink\Shared files\richvideops.dll ()
MOD - C:\Windows\System32\msjetoledb40.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll ()


========== Win32 Services (SafeList) ==========

SRV - (Pml Driver HPZ12) – File not found
SRV - (Norton Internet Security) – File not found
SRV - (Net Driver HPZ12) – File not found
SRV - (hpqddsvc) – File not found
SRV - (hpqcxs08) – File not found
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (nmservice) – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Cisco Systems, Inc.)
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_408c4e5a\stacsv.exe (IDT, Inc.)
SRV - (Recovery Service for Windows) – C:\Program Files\SMINST\BLService.exe ()
SRV - (TVCapSvc) TV Background Capture Service (TVBCS) – C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe ()
SRV - (TVSched) TV Task Scheduler (TVTS) – C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe ()
SRV - (AESTFilters) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_408c4e5a\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (BcmSqlStartupSvc) – C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (nTuneService) – C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)


========== Driver Services (SafeList) ==========

DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NVHDA) – C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (hwdatacard) – C:\Windows\System32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (hwusbdev) – C:\Windows\System32\drivers\ewusbdev.sys (Huawei Technologies Co., Ltd.)
DRV - (ewusbnet) – C:\Windows\System32\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV - (Netaapl) – C:\Windows\System32\drivers\netaapl.sys (Apple Inc.)
DRV - (AvgLdx86) – C:\Windows\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\Windows\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX) – C:\Windows\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (purendis) – C:\Windows\System32\drivers\purendis.sys (Cisco Systems, Inc.)
DRV - (pnarp) – C:\Windows\System32\drivers\pnarp.sys (Cisco Systems, Inc.)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - ({55662437-DA8C-40c0-AADA-2C816A897A49}) – C:\Program Files\Hewlett-Packard\Media\DVD\000.fcl (Cyberlink Corp.)
DRV - (enecir) – C:\Windows\System32\drivers\enecir.sys (ENE TECHNOLOGY INC.)
DRV - (NETw5v32) Intel® – C:\Windows\System32\drivers\NETw5v32.sys (Intel Corporation)
DRV - (JMCR) – C:\Windows\System32\drivers\jmcr.sys (JMicron Technology Corporation)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (hpdskflt) – C:\Windows\system32\DRIVERS\hpdskflt.sys (Hewlett-Packard Corporation)
DRV - (Accelerometer) – C:\Windows\System32\drivers\Accelerometer.sys (Hewlett-Packard Corporation)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (irsir) – C:\Windows\System32\drivers\irsir.sys (Microsoft Corporation)
DRV - (NETw3v32) Intel® – C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (NVR0Dev) – C:\Windows\nvoclock.sys (NVidia Corp.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "DAEMON Search"
FF - prefs.js..browser.startup.homepage: "http://en-US.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.2
FF - prefs.js..extensions.enabledItems: {E9A1DEE0-C623-4439-8932-001E7D17607D}:2.1.0.2
FF - prefs.js..extensions.enabledItems: [removed]:1.1.2.0185
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.6.5

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.51204.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Locky & Ricki-Lee\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Locky & Ricki-Lee\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/03/07 17:31:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/03/07 17:31:49 | 000,000,000 | —D | M]

[2009/04/21 18:12:31 | 000,000,000 | —D | M] (No name found) – C:\Users\Locky & Ricki-Lee\AppData\Roaming\mozilla\Extensions
[2012/02/06 09:27:57 | 000,000,000 | —D | M] (No name found) – C:\Users\Locky & Ricki-Lee\AppData\Roaming\mozilla\Firefox\Profiles\xgjjagft.default\extensions
[2009/09/03 08:24:20 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Locky & Ricki-Lee\AppData\Roaming\mozilla\Firefox\Profiles\xgjjagft.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/12/21 19:43:48 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Locky & Ricki-Lee\AppData\Roaming\mozilla\Firefox\Profiles\xgjjagft.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/04/21 18:17:53 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Locky & Ricki-Lee\AppData\Roaming\mozilla\Firefox\Profiles\xgjjagft.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/05/21 23:23:26 | 000,000,000 | —D | M] ("Ask Toolbar for Firefox") – C:\Users\Locky & Ricki-Lee\AppData\Roaming\mozilla\Firefox\Profiles\xgjjagft.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2010/07/13 03:09:44 | 000,000,000 | —D | M] ("DAEMON Tools Toolbar") – C:\Users\Locky & Ricki-Lee\AppData\Roaming\mozilla\Firefox\Profiles\xgjjagft.default\extensions\[removed]
[2010/07/13 03:09:30 | 000,002,059 | —- | M] () – C:\Users\Locky & Ricki-Lee\AppData\Roaming\Mozilla\Firefox\Profiles\xgjjagft.default\searchplugins\daemon-search.xml
[2010/09/14 23:00:49 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chr
o
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Locky & Ricki-Lee\AppData\Local\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Locky & Ricki-Lee\AppData\Local\Google\Chrome\Application\16.0.912.77\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Locky & Ricki-Lee\AppData\Local\Google\Chrome\Application\16.0.912.77\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.160.1 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java™ Platform SE 6 U16 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.51204.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2006/09/19 08:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (AOL Toolbar BHO) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O3 - HKLM\..\Toolbar: (Yahoo!7 Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [CLMLServer for HP TouchSmart] C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [DVDAgent] C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Hewlett-Packard)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [TSMAgent] C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [TVAgent] C:\Program Files\Hewlett-Packard\Media\TV\TVAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent File not found
O4 - HKCU..\Run: [NVIDIA nTune] C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe (NVIDIA)
O8 - Extra context menu item: &AOL; Toolbar Search - C:\ProgramData\AOL\ieToolbar\resources\en-AU\local\search.html ()
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html File not found
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.143.147.147 10.143.147.148
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1F1A81C4-6D66-4F0E-89CE-E24E9D156CD2}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{88500EEA-BB90-4570-8FD8-D192B5888E23}: DhcpNameServer = 10.143.147.147 10.143.147.148
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E091E988-57D2-4814-826F-4F57449C03A2}: DhcpNameServer = 10.1.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O20 - AppInit_DLLs: (avgrsstx.dll) -C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\Reflection.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\Reflection.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/19 08:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{04d5a100-140a-11e0-86c3-001e101fbcad}\Shell - "" = AutoRun
O33 - MountPoints2\{04d5a100-140a-11e0-86c3-001e101fbcad}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{1be4798d-8dd0-11df-885b-00238b68d757}\Shell - "" = AutoRun
O33 - MountPoints2\{1be4798d-8dd0-11df-885b-00238b68d757}\Shell\AutoRun\command - "" = F:\autoplay.exe
O33 - MountPoints2\{1be4798e-8dd0-11df-885b-00238b68d757}\Shell - "" = AutoRun
O33 - MountPoints2\{1be4798e-8dd0-11df-885b-00238b68d757}\Shell\AutoRun\command - "" = G:\autoplay.exe
O33 - MountPoints2\{39c4146c-5414-11de-97dc-00238b68d757}\Shell\AutoRun\command - "" = F:\0u.cmd
O33 - MountPoints2\{39c4146c-5414-11de-97dc-00238b68d757}\Shell\explore\Command - "" = F:\0u.cmd
O33 - MountPoints2\{39c4146c-5414-11de-97dc-00238b68d757}\Shell\open\Command - "" = F:\0u.cmd
O33 - MountPoints2\{551f2d43-bed2-11df-9410-00238b68d757}\Shell - "" = AutoRun
O33 - MountPoints2\{551f2d43-bed2-11df-9410-00238b68d757}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{551f2d62-bed2-11df-9410-00238b68d757}\Shell - "" = AutoRun
O33 - MountPoints2\{551f2d62-bed2-11df-9410-00238b68d757}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{62bc9a81-0058-11e0-9ad1-00238b68d757}\Shell - "" = AutoRun
O33 - MountPoints2\{62bc9a81-0058-11e0-9ad1-00238b68d757}\Shell\AutoRun\command - "" = F:\NokiaPCIA_Autorun.exe
O33 - MountPoints2\{7e1969da-2119-11e0-ac60-00238b68d757}\Shell - "" = AutoRun
O33 - MountPoints2\{7e1969da-2119-11e0-ac60-00238b68d757}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{7e1969dc-2119-11e0-ac60-00238b68d757}\Shell - "" = AutoRun
O33 - MountPoints2\{7e1969dc-2119-11e0-ac60-00238b68d757}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{7e1969de-2119-11e0-ac60-00238b68d757}\Shell - "" = AutoRun
O33 - MountPoints2\{7e1969de-2119-11e0-ac60-00238b68d757}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{9db4c47c-ffab-11df-bfa7-00238b68d757}\Shell - "" = AutoRun
O33 - MountPoints2\{9db4c47c-ffab-11df-bfa7-00238b68d757}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{d4739c44-c165-11df-bbf5-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{d4739c44-c165-11df-bbf5-806e6f6e6963}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\Windows\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.vorbis - C:\Windows\System32\vorbis.acm (HMS http://hp.vector.co.jp/authors/VA012897/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/02/07 05:35:48 | 000,000,000 | —D | C] – C:\Users\Locky & Ricki-Lee\riotsGamesLogs
[2012/02/06 16:32:00 | 000,000,000 | —D | C] – C:\Users\Locky & Ricki-Lee\AppData\Roaming\WinPatrol
[2012/02/06 16:31:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPatrol
[2012/02/06 16:31:43 | 000,000,000 | —D | C] – C:\ProgramData\InstallMate
[2012/02/06 16:31:43 | 000,000,000 | —D | C] – C:\Program Files\BillP Studios
[2012/02/06 11:50:30 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Locky & Ricki-Lee\Desktop\HiJackThis.exe
[2012/02/06 11:47:55 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Locky & Ricki-Lee\Desktop\OTL.exe
[2012/02/06 09:32:30 | 000,404,640 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2010/01/15 22:04:18 | 000,047,360 | —- | C] (VSO Software) – C:\Users\Locky & Ricki-Lee\AppData\Roaming\pcouffin.sys
[2009/04/10 13:06:04 | 000,396,288 | —- | C] (Trend Micro Inc.) – C:\Program Files\HijackThis.exe
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/02/07 16:44:04 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/07 16:43:16 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/02/07 16:43:16 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/02/07 16:00:00 | 000,000,956 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2609881489-2696938298-1515882581-1003UA.job
[2012/02/07 09:00:00 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2609881489-2696938298-1515882581-1003Core.job
[2012/02/07 08:44:00 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/06 20:18:01 | 000,000,032 | —- | M] () – C:\Users\Locky & Ricki-Lee\jagex_cl_runescape_LIVE.dat
[2012/02/06 16:50:52 | 000,649,990 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/02/06 16:50:52 | 000,124,218 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/02/06 16:43:22 | 000,065,536 | —- | M] () – C:\Windows\System32\Ikeext.etl
[2012/02/06 16:43:00 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/02/06 13:42:45 | 000,038,400 | —- | M] () – C:\Users\Locky & Ricki-Lee\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/06 13:31:48 | 000,000,117 | —- | M] () – C:\Users\Locky & Ricki-Lee\jagex_runescape_preferences2.dat
[2012/02/06 13:27:49 | 000,000,046 | —- | M] () – C:\Users\Locky & Ricki-Lee\jagex_runescape_preferences.dat
[2012/02/06 11:50:37 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Locky & Ricki-Lee\Desktop\HiJackThis.exe
[2012/02/06 11:48:13 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Locky & Ricki-Lee\Desktop\OTL.exe
[2012/02/06 09:32:30 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/02/06 09:05:49 | 000,002,102 | —- | M] () – C:\Users\Locky & Ricki-Lee\Desktop\Google Chrome.lnk
[2012/02/06 09:05:49 | 000,002,064 | —- | M] () – C:\Users\Locky & Ricki-Lee\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/02/06 08:47:41 | 089,634,404 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/02/06 13:27:45 | 000,000,032 | —- | C] () – C:\Users\Locky & Ricki-Lee\jagex_cl_runescape_LIVE.dat
[2010/04/18 11:08:38 | 000,007,592 | —- | C] () – C:\Users\Locky & Ricki-Lee\AppData\Local\d3d9caps.dat
[2010/03/25 22:11:48 | 000,110,060 | —- | C] () – C:\Windows\hpoins11.dat
[2010/03/25 22:11:48 | 000,006,947 | —- | C] () – C:\Windows\hpomdl11.dat
[2010/02/21 19:57:40 | 000,017,089 | —- | C] () – C:\Users\Locky & Ricki-Lee\AppData\Roaming\UserTile.png
[2010/02/21 13:05:25 | 000,021,840 | —- | C] () – C:\Windows\System32\SIntfNT.dll
[2010/02/21 13:05:25 | 000,017,212 | —- | C] () – C:\Windows\System32\SIntf32.dll
[2010/02/21 13:05:25 | 000,012,067 | —- | C] () – C:\Windows\System32\SIntf16.dll
[2010/02/21 13:03:53 | 000,013,779 | —- | C] () – C:\Windows\DIIUnin.dat
[2010/01/15 22:04:18 | 000,087,608 | —- | C] () – C:\Users\Locky & Ricki-Lee\AppData\Roaming\inst.exe
[2010/01/15 22:04:18 | 000,007,887 | —- | C] () – C:\Users\Locky & Ricki-Lee\AppData\Roaming\pcouffin.cat
[2010/01/15 22:04:18 | 000,001,144 | —- | C] () – C:\Users\Locky & Ricki-Lee\AppData\Roaming\pcouffin.inf
[2009/08/10 22:43:01 | 000,819,200 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2009/08/10 22:43:01 | 000,180,224 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2009/05/05 18:28:28 | 000,038,400 | —- | C] () – C:\Users\Locky & Ricki-Lee\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/08 23:46:14 | 008,673,792 | —- | C] () – C:\ProgramData\atscie.msi
[2009/03/09 20:18:06 | 000,000,262 | —- | C] () – C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2008/12/31 17:04:42 | 000,691,560 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2008/12/31 17:04:42 | 000,528,744 | —- | C] () – C:\Windows\System32\OGAVerify.exe
[2008/12/16 22:29:31 | 000,295,289 | —- | C] () – C:\ProgramData\nvModes.001
[2008/12/16 22:17:32 | 000,295,289 | —- | C] () – C:\ProgramData\nvModes.dat
[2008/11/16 02:53:56 | 000,106,605 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2008/11/16 02:53:56 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2007/03/12 13:01:30 | 000,217,088 | —- | C] () – C:\Windows\NVGfxOgl.dll
[2006/11/02 23:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 23:47:37 | 000,381,144 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 23:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 21:33:01 | 000,649,990 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 21:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 21:33:01 | 000,124,218 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 21:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 21:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 19:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 19:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 18:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 18:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat

========== LOP Check ==========

[2010/07/13 03:19:26 | 000,000,000 | —D | M] – C:\Users\Locky & Ricki-Lee\AppData\Roaming\DAEMON Tools Lite
[2010/03/20 14:22:52 | 000,000,000 | —D | M] – C:\Users\Locky & Ricki-Lee\AppData\Roaming\FrostWire
[2010/02/13 10:16:47 | 000,000,000 | —D | M] – C:\Users\Locky & Ricki-Lee\AppData\Roaming\funkitron
[2009/12/29 17:42:05 | 000,000,000 | —D | M] – C:\Users\Locky & Ricki-Lee\AppData\Roaming\Gamelab
[2009/03/15 05:31:18 | 000,000,000 | —D | M] – C:\Users\Locky & Ricki-Lee\AppData\Roaming\iWin
[2010/12/05 22:13:47 | 000,000,000 | —D | M] – C:\Users\Locky & Ricki-Lee\AppData\Roaming\LolClient
[2010/02/21 19:57:39 | 000,000,000 | —D | M] – C:\Users\Locky & Ricki-Lee\AppData\Roaming\PeerNetworking
[2010/02/13 12:26:30 | 000,000,000 | —D | M] – C:\Users\Locky & Ricki-Lee\AppData\Roaming\PlayFirst
[2009/03/13 22:43:20 | 000,000,000 | —D | M] – C:\Users\Locky & Ricki-Lee\AppData\Roaming\Red Alert 3
[2009/08/29 20:40:26 | 000,000,000 | —D | M] – C:\Users\Locky & Ricki-Lee\AppData\Roaming\Sierra
[2012/02/06 08:45:15 | 000,000,000 | —D | M] – C:\Users\Locky & Ricki-Lee\AppData\Roaming\uTorrent
[2010/12/10 21:49:36 | 000,000,000 | —D | M] – C:\Users\Locky & Ricki-Lee\AppData\Roaming\Vso
[2009/03/06 07:33:01 | 000,000,000 | —D | M] – C:\Users\Locky & Ricki-Lee\AppData\Roaming\WildTangent
[2012/02/06 16:32:00 | 000,000,000 | —D | M] – C:\Users\Locky & Ricki-Lee\AppData\Roaming\WinPatrol
[2012/02/06 16:41:40 | 000,032,628 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/19 08:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2008/01/21 13:24:42 | 000,333,203 | RHS- | M] () – C:\bootmgr
[2006/09/19 08:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2012/02/06 16:42:56 | 3531,870,208 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/11/02 23:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 23:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 23:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 23:37:12 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/19 08:37:34 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/01/21 13:23:14 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/11/02 23:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/21 13:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
[2009/04/10 13:06:04 | 000,396,288 | —- | M] (Trend Micro Inc.) – C:\Program Files\HijackThis.exe
[2009/04/10 13:06:17 | 000,011,299 | —- | M] () – C:\Program Files\hijackthis.log

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/21 14:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 14:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 14:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 21:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 21:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/03/07 09:45:13 | 000,000,286 | -HS- | M] () – C:\Users\Locky & Ricki-Lee\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/02/06 11:50:37 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Locky & Ricki-Lee\Desktop\HiJackThis.exe
[2012/02/06 11:48:13 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Locky & Ricki-Lee\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-02-06 16:17:33

< End of report >


OTL Extras logfile created on: 7/02/2012 4:43:42 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Locky & Ricki-Lee\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.00 Gb Total Physical Memory | 1.83 Gb Available Physical Memory | 61.23% Memory free
6.19 Gb Paging File | 4.63 Gb Available in Paging File | 74.82% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 361.45 Gb Total Space | 206.45 Gb Free Space | 57.12% Space Free | Partition Type: NTFS
Drive D: | 11.16 Gb Total Space | 1.85 Gb Free Space | 16.54% Space Free | Partition Type: NTFS

Computer Name: LOCKYSPC | User Name: Locky & Ricki-Lee | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0E21EC9B-7EEC-4882-8979-1EC8A8350672}" = rport=137 | protocol=17 | dir=out | app=system |
"{1C1E8FD7-26A5-405B-B419-3E40F908E8B8}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{2316523D-9422-4FFD-B415-D5593C21449E}" = lport=8381 | protocol=6 | dir=in | name=league of legends launcher |
"{2501170F-0D8B-439F-B100-4C90B0D4FA9C}" = lport=137 | protocol=17 | dir=in | app=system |
"{2FAD5CDB-E9C7-46CC-9A06-2CE453977F6E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{4318AA3A-43F8-473D-A5E8-7928986E81AE}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{4AAADFB6-9C39-4AFC-9D3F-5B326513BD62}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{4AE8CD02-EFA8-413A-80C7-504A2BBD0AB3}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{4CCD9C5D-6986-4430-832F-8E815A2C0A38}" = lport=8390 | protocol=6 | dir=in | name=league of legends game client |
"{545F1D2B-DFE8-4E7B-9E7E-1630A64DB807}" = rport=138 | protocol=17 | dir=out | app=system |
"{56B8F18B-5C34-4FC1-B9D4-4D76AF52459F}" = rport=139 | protocol=6 | dir=out | app=system |
"{5C722C5F-9274-499D-9EBA-19F80F4961E2}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{60FFDFF6-B01E-4699-99B0-1709FE58428C}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 |
"{68F2BA47-620B-455A-AB17-10D5DF8EA60D}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{69A2BA8D-C2DD-46A0-B4CA-24FC86F5CFB0}" = lport=67 | protocol=17 | dir=in | name=dhcp discovery service |
"{705EF914-3F6D-42F8-A959-57B8C42DD39D}" = lport=6925 | protocol=6 | dir=in | name=league of legends launcher |
"{734FAC25-8EF4-46E1-8073-83B8CC55C21E}" = lport=8393 | protocol=6 | dir=in | name=league of legends lobby |
"{7C891FE0-A1B4-4923-A634-685AC1E66089}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{836BAC19-0DB1-4ECF-A728-094BC8CC4518}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{85C71D02-2AF8-4484-9D44-340AD572B17D}" = lport=445 | protocol=6 | dir=in | app=system |
"{8B728BF4-B396-458F-A79C-6EAF1EBD9769}" = lport=2869 | protocol=6 | dir=in | app=system |
"{9082C818-0839-4516-91C0-6E6AC788CE07}" = lport=139 | protocol=6 | dir=in | app=system |
"{9530E178-833F-40BC-AC3D-387417E332A5}" = lport=6925 | protocol=17 | dir=in | name=league of legends launcher |
"{9C03A2F3-A928-406C-8137-D4F8E1CB7C43}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A1B568B9-748C-4FCC-A1C5-622606908775}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A5870547-B56A-4AD9-8C84-97682C38C9F9}" = rport=445 | protocol=6 | dir=out | app=system |
"{AC2D58C6-3AB5-4377-8FA6-BC9518B54A95}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B13576F0-AE50-40C4-BFAE-84B326B60699}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B7C101FE-5AB2-4878-8054-7549ED9039FC}" = lport=8390 | protocol=17 | dir=in | name=league of legends game client |
"{C6446EDC-FBC5-4EEC-8C7F-BB730980F1E1}" = rport=2869 | protocol=6 | dir=out | app=system |
"{CBBECF35-4A15-417B-BACE-67B1FCB8399E}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{CFB79245-14C6-4DDD-BD01-167042466347}" = lport=138 | protocol=17 | dir=in | app=system |
"{DCC8ABFC-E916-4D79-9CE5-2B98B0A5C44C}" = lport=8381 | protocol=17 | dir=in | name=league of legends launcher |
"{E1ACF09A-D338-49B8-BEBD-3B849365221E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E7960B4E-E775-4AA5-B8A4-6EAB49143C1F}" = lport=8393 | protocol=17 | dir=in | name=league of legends lobby |
"{E8964A85-C02D-4277-A67C-4F075641545E}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{EFC06CE1-D60C-4817-B6CE-134CC23F4FBD}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{F4579779-7BF6-46DC-8EF3-3EABAA91B1C4}" = lport=67 | protocol=17 | dir=in | name=dhcp discovery service |
"{FA9C9D80-B30B-47D6-9542-8ACD8244395B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{FE852673-2274-4D4B-B4D7-A6768ED00998}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04CC0F35-5E8A-4719-B839-01AC86FD3FB5}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{06290FA1-E861-4C4B-8F10-109E81E28569}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{0A56724D-89C2-4EC8-933A-263703CB1EC4}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"{0E621D4C-4BF2-4149-96D8-A360C1D98FF8}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe |
"{103315F0-3461-4756-B7A0-8933EF7302BA}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{18A5295D-EC64-4422-B3D2-0A941433B28C}" = protocol=17 | dir=in | app=c:\program files\common files\pure networks shared\platform\nmsrvc.exe |
"{20252F2F-FCDC-45ED-9112-3C57572D793C}" = dir=in | app=c:\program files\avg\avg8\avgnsx.exe |
"{2683E49C-5E68-4E32-B9A3-41100CF0A881}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{2B744D65-BA75-4E05-BF20-7E1479FCFE4D}" = dir=in | app=c:\program files\hewlett-packard\media\dvd\hptouchsmartphoto.exe |
"{3033EC78-B7C8-44F2-8C01-EA3677C8C120}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{319E6C84-0EE3-4D5C-B1BB-717A0C4D3E9E}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{43F4F87E-A3A7-4721-B525-24F3D89A2CB7}" = protocol=6 | dir=in | app=c:\program files\ea games\battlefield 2\bf2.exe |
"{495F5AC7-2641-45CB-A9D3-5CE0F0A917C0}" = dir=in | app=c:\program files\hewlett-packard\touchsmart\media\kernel\clml\clmlsvc.exe |
"{4C042C46-A5B3-4DF8-88D4-62D0E75A1A46}" = protocol=6 | dir=in | app=c:\riot games\league of legends\game\league of legends.exe |
"{4E2CDCED-29AD-451C-A9E8-26126DEFDE30}" = dir=in | app=c:\program files\hewlett-packard\touchsmart\media\tsmagent.exe |
"{4EE92E8C-60B1-4FF5-B7CE-D8A1BF573207}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{5222D350-5D81-4932-B49B-07FDBA78D5DA}" = protocol=17 | dir=in | app=c:\program files\ea games\battlefield 2\bf2.exe |
"{542018C6-DCAB-496A-95CD-51DCC35A3391}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{54523637-D219-4F58-9BA3-C6F793F38B65}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{55B2EDE5-322C-4DB5-9838-9DEDCB33BECF}" = dir=in | app=c:\program files\hewlett-packard\touchsmart\media\hptouchsmartmusic.exe |
"{5AAD4C36-C5F4-4297-ADA4-41AF21CAD5CE}" = dir=in | app=c:\program files\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{5B742626-59BD-4E05-ABE2-48C5160A3653}" = dir=in | app=c:\program files\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe |
"{60ADD7D3-4D01-46B3-A210-2B4B541D5F21}" = dir=in | app=c:\program files\hewlett-packard\touchsmart\media\hptouchsmartvideo.exe |
"{61A87EAF-671D-4D79-BDA0-1FCFC6F479A3}" = dir=in | app=c:\program files\hewlett-packard\media\dvd\kernel\clml\clmlsvc.exe |
"{695EB498-3B0E-4319-BF6A-B285C61BF4BA}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{6BBDB897-1C12-4B70-9FBF-1086B56E19DD}" = protocol=6 | dir=in | app=c:\program files\common files\pure networks shared\platform\nmsrvc.exe |
"{6E618E52-2097-483D-B161-A96866B5C68B}" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe |
"{70093443-4FE6-46D6-B110-F1E2AE610CF2}" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe |
"{72502678-1E1C-4FDD-8986-73FB8B8BE4AB}" = dir=in | app=c:\program files\hewlett-packard\media\dvd\tsmagent.exe |
"{73D658D9-46C4-42CF-8B0E-CCB040A555ED}" = protocol=17 | dir=in | app=c:\riot games\league of legends\game\league of legends.exe |
"{754FC0A3-3882-44EC-ACAE-6693E18487F8}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{7DB0CF90-E319-4319-BC4F-8BB4C70CC7AF}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe |
"{83F339AA-1881-4CF7-B960-3860942FB703}" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe |
"{894C5751-4918-4F9C-8F84-B3C75091BB30}" = protocol=17 | dir=in | app=c:\program files\frostwire\frostwire.exe |
"{A1B0685D-3B07-46DF-B4CC-6DAD31A87B46}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{A4BC3040-D91F-4AF6-B76A-14BF95F1EFBE}" = dir=in | app=c:\program files\hewlett-packard\media\tv\qpservice.exe |
"{A7DEE92C-EB2A-47E6-9C34-8076979064F5}" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe |
"{ABCE7A3F-8536-41C9-884B-6B394671E7D4}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{ACB35C5F-67C1-49A9-B916-E5EB86033E23}" = dir=in | app=c:\program files\hewlett-packard\media\dvd\hptouchsmartvideo.exe |
"{AF9C17CD-0B81-4176-9C08-5AD744E8B5CD}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{B69233B3-DA90-4EDA-AB5C-B17F74E75900}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{C3E65918-9C99-4377-9F5E-B705F6E4FBDA}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{C5FDB978-7063-4921-BAEB-EBF27BE9FC29}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{D637308F-9627-485A-A50D-29DC69B2C74D}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{DE48628F-7CCD-49D3-B654-00429CB6105E}" = protocol=6 | dir=in | app=c:\riot games\league of legends\air\lolclient.exe |
"{DF3A4A36-76EF-4EFF-BB97-DBBD38FC8346}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe |
"{E0922226-DDC6-42ED-81F3-BF9CB1BBD0F0}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{E211A628-06B1-4C7B-9063-1A396536B8DA}" = dir=in | app=c:\program files\hewlett-packard\media\tv\qp.exe |
"{E343C05C-7EDE-4F04-AC51-2B7CA1A8439D}" = protocol=6 | dir=in | app=c:\program files\frostwire\frostwire.exe |
"{E630B534-455E-4650-B61F-C95CB45ED6E3}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{E7F4CBE9-903E-4F9D-886E-634A54E7B916}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{E93DE040-BB0F-44E7-9DE7-EC769B2938C3}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{EAC95946-B018-4C68-A011-AAF20F9C8E49}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{EC757E3F-1C63-4E50-B416-BBA51176100F}" = dir=in | app=c:\program files\hewlett-packard\media\dvd\hptouchsmartmusic.exe |
"{EF1643F4-21F4-4A28-A83D-955787E011A6}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{EF5AB5CA-C3DE-48B6-A40E-6949B49BB8CD}" = protocol=17 | dir=in | app=c:\riot games\league of legends\air\lolclient.exe |
"{F4AC9555-06D4-4F8D-9831-FEE34F4B8D87}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{F8385D66-F2B1-421C-B334-E037C14BBA8A}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"TCP Query User{0D00DE7A-9F2A-48E7-83C4-7B5ED684C1E4}C:\riot games\league of legends\lol.launcher.exe" = protocol=6 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
"TCP Query User{47F06550-C9B8-46E3-8322-300B58DD72A5}C:\program files\warcraft iii\war3.exe" = protocol=6 | dir=in | app=c:\program files\warcraft iii\war3.exe |
"TCP Query User{4C7367C1-4AB5-48E9-86E8-E6E3B2B2B530}C:\program files\ea games\battlefield 2\bf2.exe" = protocol=6 | dir=in | app=c:\program files\ea games\battlefield 2\bf2.exe |
"TCP Query User{5288203C-20C0-4178-85B9-F8DFA23ADC86}C:\program files\electronic arts\red alert 3\data\ra3_1.8.game" = protocol=6 | dir=in | app=c:\program files\electronic arts\red alert 3\data\ra3_1.8.game |
"TCP Query User{5D8341C5-612C-4F6C-A868-28D3607CA00A}C:\program files\sierra\empire earth ii\ee2.exe" = protocol=6 | dir=in | app=c:\program files\sierra\empire earth ii\ee2.exe |
"TCP Query User{6095A70F-20D7-470A-9691-E89F3A56ED5A}C:\program files\steam\steamapps\lockyzz\counter-strike source\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\lockyzz\counter-strike source\hl2.exe |
"TCP Query User{651C8B20-44B5-4056-BC2A-110E75D4D17F}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"TCP Query User{68624123-14AA-40BB-A099-289CBE499175}C:\program files\tale of tales\the endless forest 3\forestviewer.exe" = protocol=6 | dir=in | app=c:\program files\tale of tales\the endless forest 3\forestviewer.exe |
"TCP Query User{73168CD9-2C27-4182-9FF4-64F11EE7CE94}C:\users\public\games\world of warcraft\wow-3.2.2.10505-to-3.3.0.10958-enus-downloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.2.2.10505-to-3.3.0.10958-enus-downloader.exe |
"TCP Query User{78596F6C-029B-446A-B638-D75708265FDE}C:\program files\hp games\polar pool\polarpool.exe" = protocol=6 | dir=in | app=c:\program files\hp games\polar pool\polarpool.exe |
"TCP Query User{9762AE3E-C5D3-422E-A5D1-967CA04CEF78}C:\users\public\games\world of warcraft\wow-3.3.5.12213-to-3.3.5.12340-enus-downloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.3.5.12213-to-3.3.5.12340-enus-downloader.exe |
"TCP Query User{A4AA76DE-8822-4AD7-BF96-501956BE799F}C:\users\public\games\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"TCP Query User{A5312D6A-8317-4935-8B4B-2214C4D74EB2}C:\users\public\games\world of warcraft\wow-3.3.0.10958-to-3.3.0.11159-enus-downloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.3.0.10958-to-3.3.0.11159-enus-downloader.exe |
"TCP Query User{AD71EA54-AFD2-4B93-9BC4-C8DBAC923C23}C:\program files\world of warcraft\wow-2.4.0-enus-downloader.exe" = protocol=6 | dir=in | app=c:\program files\world of warcraft\wow-2.4.0-enus-downloader.exe |
"TCP Query User{B6F01433-B8AC-4279-B94A-9EC7E6B9F234}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"TCP Query User{C3011C60-F45D-4F3D-AE4E-F4ACD6D02CC8}C:\users\public\games\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\backgrounddownloader.exe |
"TCP Query User{CA97B2ED-0D75-4179-8CA5-74AB1222CD47}C:\riot games\league of legends\lol.launcher.exe" = protocol=6 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
"TCP Query User{DAE5BF0A-3EE6-4BEC-8A03-DB8FFB543198}C:\users\public\games\world of warcraft\wow-3.3.3.11723-to-3.3.5.12213-enus-downloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.3.3.11723-to-3.3.5.12213-enus-downloader.exe |
"TCP Query User{E565BC3D-DD08-4DBE-8DBF-3931ACC170D2}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"TCP Query User{E60F916E-7DEF-4ADA-89D4-7063C5A079D0}C:\program files\frostwire\frostwire.exe" = protocol=6 | dir=in | app=c:\program files\frostwire\frostwire.exe |
"TCP Query User{EEBC6ECC-8F3E-4DD9-BA8F-7EF44647F057}C:\users\public\games\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\backgrounddownloader.exe |
"TCP Query User{F1685D35-0EFF-4D79-9370-5ABD3FF1CF9C}C:\program files\world of warcraft\world of warcraft\world of warcraft\repair.exe" = protocol=6 | dir=in | app=c:\program files\world of warcraft\world of warcraft\world of warcraft\repair.exe |
"TCP Query User{F6E343EE-B0F0-44A9-A858-EEA28A0B8366}C:\users\public\games\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"TCP Query User{FA6DF1CB-8A8B-4EB6-8EFD-907033113D20}C:\program files\warcraft iii\war3.exe" = protocol=6 | dir=in | app=c:\program files\warcraft iii\war3.exe |
"UDP Query User{09C5DF32-C249-4020-8498-23732DC650DD}C:\program files\warcraft iii\war3.exe" = protocol=17 | dir=in | app=c:\program files\warcraft iii\war3.exe |
"UDP Query User{20931CA7-9F26-492C-B615-19EC134670F8}C:\program files\world of warcraft\world of warcraft\world of warcraft\repair.exe" = protocol=17 | dir=in | app=c:\program files\world of warcraft\world of warcraft\world of warcraft\repair.exe |
"UDP Query User{28EE084E-1E13-4267-9690-BCB1F1268ADF}C:\users\public\games\world of warcraft\wow-3.2.2.10505-to-3.3.0.10958-enus-downloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.2.2.10505-to-3.3.0.10958-enus-downloader.exe |
"UDP Query User{3321CE99-339E-4873-95AF-D24ACEA439B9}C:\users\public\games\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\backgrounddownloader.exe |
"UDP Query User{36C522FD-D85E-4B6A-823A-7E7AC886D417}C:\riot games\league of legends\lol.launcher.exe" = protocol=17 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
"UDP Query User{4498F591-546E-41AD-B6CA-8869B7542458}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"UDP Query User{45BB8100-FF9C-4B1A-B6C7-3A9A72C72CFD}C:\users\public\games\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\backgrounddownloader.exe |
"UDP Query User{645B54F9-25DD-413C-8DEB-70C5B7D93FC6}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"UDP Query User{74C0C73A-9D25-44BC-B3DA-7F49E42F79AE}C:\riot games\league of legends\lol.launcher.exe" = protocol=17 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
"UDP Query User{7795336E-2CCD-4C47-9588-E7583FB4D1A6}C:\program files\sierra\empire earth ii\ee2.exe" = protocol=17 | dir=in | app=c:\program files\sierra\empire earth ii\ee2.exe |
"UDP Query User{79EA9091-377E-4AD6-8403-991C20A0F633}C:\program files\warcraft iii\war3.exe" = protocol=17 | dir=in | app=c:\program files\warcraft iii\war3.exe |
"UDP Query User{83EC61AD-F7E6-46C3-BADF-7BFFEB2843EC}C:\program files\world of warcraft\wow-2.4.0-enus-downloader.exe" = protocol=17 | dir=in | app=c:\program files\world of warcraft\wow-2.4.0-enus-downloader.exe |
"UDP Query User{8743119B-C61D-42D0-85E9-FA5E5F894F15}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"UDP Query User{971CB2EB-73EC-428C-890C-0934971924B0}C:\program files\electronic arts\red alert 3\data\ra3_1.8.game" = protocol=17 | dir=in | app=c:\program files\electronic arts\red alert 3\data\ra3_1.8.game |
"UDP Query User{9B762682-AD41-428C-BBE9-50A1E47F8A2A}C:\users\public\games\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"UDP Query User{9ED733EF-7964-4E9A-9C1E-FAAE0D4374F1}C:\program files\frostwire\frostwire.exe" = protocol=17 | dir=in | app=c:\program files\frostwire\frostwire.exe |
"UDP Query User{9F5E9838-4583-4DD9-9353-8052C9B462D6}C:\users\public\games\world of warcraft\wow-3.3.0.10958-to-3.3.0.11159-enus-downloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.3.0.10958-to-3.3.0.11159-enus-downloader.exe |
"UDP Query User{A4F5227C-ED66-4494-9B20-8B0602687ADD}C:\program files\hp games\polar pool\polarpool.exe" = protocol=17 | dir=in | app=c:\program files\hp games\polar pool\polarpool.exe |
"UDP Query User{B0E9642F-73ED-47E1-A8BD-22456E7263E3}C:\users\public\games\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"UDP Query User{B121DB49-1D4D-4AF4-B7BC-EA589A605C51}C:\users\public\games\world of warcraft\wow-3.3.3.11723-to-3.3.5.12213-enus-downloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.3.3.11723-to-3.3.5.12213-enus-downloader.exe |
"UDP Query User{B29D4AB6-69F0-4B86-AAAD-290D258A313B}C:\program files\tale of tales\the endless forest 3\forestviewer.exe" = protocol=17 | dir=in | app=c:\program files\tale of tales\the endless forest 3\forestviewer.exe |
"UDP Query User{B9059F58-D0E5-49D5-A82A-605666339C62}C:\users\public\games\world of warcraft\wow-3.3.5.12213-to-3.3.5.12340-enus-downloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\wow-3.3.5.12213-to-3.3.5.12340-enus-downloader.exe |
"UDP Query User{BF27A418-5214-4F23-AC47-8E4C09E7D764}C:\program files\ea games\battlefield 2\bf2.exe" = protocol=17 | dir=in | app=c:\program files\ea games\battlefield 2\bf2.exe |
"UDP Query User{DA080C8C-D3CF-405C-93C7-27F3FE8177A8}C:\program files\steam\steamapps\lockyzz\counter-strike source\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\lockyzz\counter-strike source\hl2.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0054A0F6-00C9-4498-B821-B5C9578F433E}" = HP Help and Support
"{007811BF-E310-4285-BFC6-55DB29B3EDDE}" = WinPatrol
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04858915-9F49-4B2A-AED4-DC49A7DE6A7B}" = Battlefield 2™
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{08C7A49D-2B12-46F6-8B41-26D3B0D1C01F}" = Visual Studio C++ 9.0 Runtime
"{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}" = LightScribe System Software 1.14.17.1
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{154A4184-1A3D-4BF9-A5AE-4FA1660445F3}" = HP Total Care Advisor
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron JMB38X Flash Media Controller
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 16
"{296D8550-CB06-48E4-9A8B-E5034FB64715}" = Command & Conquer™ Red Alert™ 3
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 H2
"{38058455-8C21-4C2F-B2F6-14ED166039CB}" = HP Total Care Setup
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Vista
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3E0E6066-A687-448D-BFC4-D58BE3399C3B}" = SoftStylus
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45A136EC-88BF-4B95-99F5-C45D3930E1CC}" = HP MULTIPLE MODEM INSTALLER for VISTA
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{57A5AEC1-97FC-474D-92C4-908FCC2253D4}" = HP Customer Experience Enhancements
"{5DAA9C36-8F8B-462F-8CCA-E205BC3751F5}" = HP Active Support Library
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart TV
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7197F874-B0E0-4A73-A880-7E712F4D0EB7}}_is1" = Uninstall KnightOnline
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7B15D70E-9449-4CFB-B9BC-798465B2BD5C}" = Norton Internet Security
"{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROHYBRIDR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROHYBRIDR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROHYBRIDR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROHYBRIDR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROHYBRIDR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9ADABDDE-9644-461B-9E73-83FA3EFCAB50}" = HP Wireless Assistant
"{9E2BD6FF-CE8D-47B5-AD9C-0A5C2D54EB3C}" = League of Legends
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AAD72731-807A-4B79-AE05-9190B7002B7B}" = ProtectSmart Hard Drive Protection
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}" = Adobe Shockwave Player
"{ADE91A13-434D-4229-00BC-182BAD607303}" = Need for Speed™ Most Wanted
"{B148AB4B-C8FA-474B-B981-F2943C5B5BCD}" = OGA Notifier 1.7.0105.35.0
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 260.99
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 260.99
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 260.99
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver [removed]
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B32C4059-6E7A-41EF-AD20-56DF1872B923}" = Business Contact Manager for Outlook 2007 SP2
"{B8F941EA-FC3E-4915-B5EB-E91A47BF3394}" = Marc Ecko's Getting Up - Contents Under Pressure
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{BA3FD02D-7BD0-4CD0-BFB4-B407D43D6A17}" = Cisco Network Magic
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{BE78F458-88D3-4894-87E9-54B96D1FFAB6}" = HP User Guides 0126
"{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}" = WebEx Support Manager for Internet Explorer
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C7DEE429-4C9B-4126-894F-50B4F54FF196}" = inSSIDer
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D5A9DA4B-E4F9-FB49-017D-769FC540F1F0}" = EA Download Manager UI
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DD35C328-F115-BEDA-6EEE-E00C5AACCCBC}" = muvee Reveal
"{DF315348-721C-40B8-BAE2-58C6C7D935A2}" = Empire Earth II
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{ECEE0279-785F-4CB3-9F28-E69813234BF8}" = SPORE Creature Creator Trial Edition
"{EFC5939F-470F-454E-B3DA-F51FDD83F6CE}" = HP MediaSmart SmartMenu
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FBDBC490-089D-4476-BF72-1F7A6368200A}" = Pure Networks Platform
"7DE39862CC26DCE2446838AAF7CD5C163F835A57" = Windows Driver Package - ENE (enecir) HIDClass (09/04/2008 2.6.0.0)
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"AOL Toolbar" = AOL Toolbar 5.0
"ASIO4ALL" = ASIO4ALL
"Ask Toolbar_is1" = Ask Toolbar
"AVG8Uninstall" = AVG 8.5
"Business Contact Manager" = Business Contact Manager for Outlook 2007 SP2
"CCleaner" = CCleaner
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"com.ea.Vault.919CACB699904AC5D41B606703500DD39747C02D.1" = EA Download Manager UI
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"Diablo II" = Diablo II
"Drug Lord 2" = Drug Lord 2
"EA Download Manager" = EA Download Manager
"ERUNT_is1" = ERUNT 1.1j
"FL Studio 9" = FL Studio 9
"FrostWire" = FrostWire 4.18.0
"Halo Trial" = Microsoft Halo Trial
"HijackThis" = HijackThis 2.0.2
"Icy Tower v1.3.1_is1" = Icy Tower v1.3.1
"IL Download Manager" = IL Download Manager
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart TV
"InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Mozilla Firefox (3.5.8)" = Mozilla Firefox (3.5.8)
"MyTomTom" = MyTomTom [removed]
"Network MagicUninstall" = Network Magic
"Optus Wireless Broadband" = Optus Wireless Broadband
"PartyPoker" = PartyPoker
"pocketwifi" = pocketwifi
"PoiZone" = PoiZone
"PROHYBRIDR" = 2007 Microsoft Office system
"Sakura" = Sakura
"Sawer" = Sawer
"ST6UNST #1" = Hazard Perception Test Demo
"Steam App 240" = Counter-Strike: Source
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"SystemRequirementsLab" = System Requirements Lab
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"The Endless Forest_is1" = The Endless Forest
"Toxic Biohazard" = Toxic Biohazard
"VLC media player" = VLC media player 1.0.1
"Warcraft III" = Warcraft III
"WildTangent hp Master Uninstall" = My HP Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"World of Warcraft" = World of Warcraft
"Xvid_is1" = Xvid 1.2.2 final uninstall
"Yahoo! Companion" = Yahoo!7 Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"2speced 10.6 client" = 2speced 10.6 client
"Diablo II" = Diablo II
"Google Chrome" = Google Chrome
"SwiftKit" = SwiftKit
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, Lochy

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.

—————————————————————————————————

Do you still need help?

—————————————————————————————————
Please run this :)

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Probably. ;)

Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • If it needs to, DeFogger may ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.

===================================================

Please read through these instructions to familarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide


Download ComboFix from one of these locations:

Link 1
Link 2



* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs


====================================================


Double click on combofix.exe & follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.

===================================================

On your next reply please post :
Combofix log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Here's the ComboFix log: ComboFix 12-02-13.01 - Locky & Ricki-Lee 14/02/2012 10:14:05.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.61.1033.18.3068.1163 [GMT 11:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: AVG Anti-Virus Free *Disabled/Updated* {0C939084-9E57-CBDB-EA61-0B0C7F62AF82} SP: AVG Anti-Virus Free *Disabled/Updated* {B7F27160-B86D-C455-D0D1-307E04E5E53F} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe c:\program files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\setup.lnk c:\windows\msxml4-KB973688-enu.LOG c:\windows\ST6UNST.000 c:\windows\system32\SET1DD3.tmp . . ((((((((((((((((((((((((( Files Created from 2012-01-13 to 2012-02-13 ))))))))))))))))))))))))))))))) . . 2012-02-13 23:37 . 2012-02-13 23:37 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-02-09 03:36 . 2012-02-09 03:36 ——– d—–w- c:\programdata\InstallShield 2012-02-09 03:36 . 2008-01-23 06:08 99456 —-a-w- c:\windows\system32\drivers\bsusbser.sys 2012-02-09 03:35 . 2012-02-09 03:35 ——– d—–w- c:\program files\Crazy John's 2012-02-09 03:35 . 2004-08-08 19:04 73728 —-a-w- c:\windows\system32\ISUSPM.cpl 2012-02-09 03:35 . 2004-08-08 19:03 221184 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe 2012-02-09 03:35 . 2004-08-08 19:03 385024 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\_ispmres.dll 2012-02-09 03:35 . 2004-08-08 19:03 81920 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe 2012-02-09 03:35 . 2004-08-08 19:03 368640 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\_isusres.dll 2012-02-09 03:35 . 2004-08-08 19:03 512000 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\agent.exe 2012-02-09 03:35 . 2004-08-08 19:02 217088 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\ISDM.exe 2012-02-09 01:24 . 2012-02-09 01:24 ——– d—–w- C:\dce96077da98193421b983e1f8 2012-02-08 06:25 . 2012-02-08 06:25 ——– d—–w- c:\users\Locky & Ricki-Lee\AppData\Roaming\SystemRequirementsLab 2012-02-06 18:35 . 2012-02-13 09:22 ——– d—–w- c:\users\Locky & Ricki-Lee\riotsGamesLogs 2012-02-06 05:32 . 2012-02-09 00:39 ——– d—–w- c:\users\Locky & Ricki-Lee\AppData\Roaming\WinPatrol 2012-02-06 05:31 . 2012-02-06 05:31 ——– d—–w- c:\programdata\InstallMate 2012-02-06 05:31 . 2012-02-06 05:31 ——– d—–w- c:\program files\BillP Studios 2012-02-05 22:32 . 2012-02-05 22:32 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-04-10 02:06 . 2009-04-10 02:06 396288 —-a-w- c:\program files\HijackThis.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}] 2008-09-08 12:08 279944 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-08 279944] . [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-08 279944] . [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392] "HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2008-10-01 972080] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-24 1348904] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-10-26 450659] "DVDAgent"="c:\program files\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2008-09-26 1148200] "TSMAgent"="c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [2008-09-26 1152296] "CLMLServer for HP TouchSmart"="c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [2008-09-26 189736] "TVAgent"="c:\program files\Hewlett-Packard\Media\TV\TVAgent.exe" [2008-09-25 206120] "SmartMenu"="c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [2008-09-23 912688] "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-02 202032] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-02 149280] "HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008] "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-09 54840] "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792] "WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2012-01-30 400480] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\avgrsstx.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_408c4e5a\aestsrv.exe [2008-06-27 77824] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2008-06-09 18:14 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe . Contents of the 'Scheduled Tasks' folder . 2012-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-28 09:38] . 2012-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-28 09:38] . 2012-02-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2609881489-2696938298-1515882581-1003Core.job - c:\users\Locky & Ricki-Lee\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-13 08:49] . 2012-02-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2609881489-2696938298-1515882581-1003UA.job - c:\users\Locky & Ricki-Lee\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-13 08:49] . . ——- Supplementary Scan ——- . uStart Page = about:blank mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=en_au&c;=91&bd;=Pavilion&pf;=cnnb uInternet Settings,ProxyOverride = *.local IE: &AOL; Toolbar Search - c:\programdata\AOL\ieToolbar\resources\en-AU\local\search.html IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html TCP: DhcpNameServer = 10.143.147.147 10.143.147.148 FF - ProfilePath - c:\users\Locky & Ricki-Lee\AppData\Roaming\Mozilla\Firefox\Profiles\xgjjagft.default\ FF - prefs.js: browser.search.selectedEngine - DAEMON Search FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} FF - Ext: Ask Toolbar for Firefox: {E9A1DEE0-C623-4439-8932-001E7D17607D} - %profile%\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} FF - Ext: DAEMON Tools Toolbar: [removed] - %profile%\extensions\[removed] FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension . - - - - ORPHANS REMOVED - - - - . HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe HKLM-Run-UCam_Menu - c:\program files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe HKLM-Run-UpdateLBPShortCut - c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe HKLM-Run-UpdatePSTShortCut - c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe HKLM-Run-UpdateP2GoShortCut - c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe HKLM-Run-UpdatePDIRShortCut - c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe . . . ************************************************************************** scanning hidden processes … . scanning hidden autostart entries … . scanning hidden files … . scan completed successfully hidden files: . ************************************************************************** . [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Norton Internet Security] "ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.0.0.125\diMaster.dll\" /prefetch:1" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}] "ImagePath"="\??\c:\program files\Hewlett-Packard\Media\DVD\000.fcl" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-2609881489-2696938298-1515882581-1003\Software\SecuROM\License information*] "datasecu"=hex:3a,0b,e3,f3,b7,ee,50,9e,0b,a5,2d,e6,3c,a7,13,ec,5b,03,20,4d,88, 4e,ea,83,3f,70,ea,2b,7e,66,1e,92,db,71,42,4a,04,bd,8d,48,52,8a,0a,19,99,ed,\ "rkeysecu"=hex:8f,04,52,d4,bd,a4,3a,0d,86,35,0a,55,c3,76,93,09 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Completion time: 2012-02-14 10:43:47 ComboFix-quarantined-files.txt 2012-02-13 23:43 . Pre-Run: 216,560,263,168 bytes free Post-Run: 216,752,517,120 bytes free . - - End Of File - - 2C04548B0A64CCFDB596B27B109BCB4C
Looks good at my end, but we need to make sure. :)

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
===================================================

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as MyEsetScan. Alternatively, look for report in C:\Program Files\ESET\ESET Online Scanner\log.txt. Include the contents of this report in your next reply.
  • Push the Back button.
  • Select Uninstall application on close check box and push [external image: Posted Image]
===================================================

Re-run Malwarebytes' Anti-Malware
  • Double-click MalwareBytes' (Note to Vista users, please right-click and select Run as Administrator.)
    • Go to Update tab to update Malwarebytes' Anti-Malware
  • Then click Check for Updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Quick Scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

On your next reply please post :
ESET log
MBAM log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hi Conspire, All is good, I'm pretty sure. Computer is 100% better. didn't give you eset log, if you think I need it, let me know. but heres Malwarebytes' log: Malwarebytes' Anti-Malware 1.41 Database version: 2775 Windows 6.0.6001 Service Pack 1 15/02/2012 3:20:14 PM mbam-log-2012-02-15 (15-20-12).txt Scan type: Quick Scan Objects scanned: 24415 Time elapsed: 4 minute(s), 50 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Very well. You're good to go.

Follow these steps to uninstall Combofix
  • Click START then RUN
  • Now copy/paste the code into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.
Combofix /Uninstall
[external image: Posted Image]

===================================================

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
===================================================

MICROSOFT UPDATES
It is very important that you get all of the critical updates for your Operating System and Internet Explorer. Keeping your OS and browser up to date will help make you less susceptible to attacks by Trojans and viruses. Please go to Microsoft and download all the critical updates to help prevent possible re-infection.


Passwords
It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
Strong passwords: How to create and use them and consider a password keeper, to keep all your passwords safe.


SPYWARE PREVENTION
This is a good time to set up protection against further attacks. In light of your recent problem, I'm sure you'd like to avoid any future infections. Please read these well written articles:
  • How Did I Get Infected In The First Place? by TonyKlein
  • How to Prevent Malware by miekiemoes
  • PC Safety and Security–What Do I Need?

To help protect your computer in the future I recommend that you get the following free programs if you do not already have them:
  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
  • Green to go
  • Yellow for caution
  • Red to stop

WOT has an add-on available for both Firefox and IE.

  • SpywareBlaster prevents the installation of ActiveX-based malware, blocks cookies, and restricts the actions of "bad" sites. See tutorial here
  • MVPS HOSTS FILE replaces your current HOSTS file with one that will restrict known ad sites from serving you unsolicited advertisements. It basically prevents your computer from connecting to those sites by redirecting the attempted connections to 127.0.0.1, which is the IP of your local computer. See guide here and for Windows Vista here
  • Download Host.zip and Save it to your Desktop.
  • Right-click hosts.zip and select 'Extract all files' or 'Extract files…'.
  • Follow the prompts and click 'Finish'.
  • This will open the newly created hosts folder on your Desktop.
  • Double-click on the included mvps.bat file, this will rename the existing HOSTS file to HOSTS.MVP, then it will copy the included updated HOSTS file to the correct location on your machine.
  • Once updated you should see another prompt that the task was completed.
Follow this list and keep your antivirus program and antispyware programs updated and scan with them on a regular basis. By doing so, your potential for being infected again will reduce dramatically.

Hopefully this should take care of your problems! Good luck.

Do you have any questions or problems to ask? Please do not hesitate to do so.

**Please respond this one more time to ensure it is resolved and close this topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI