This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Babylon IE Browser Hijack [Closed]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, my browser seems to have been hijacked by something called "Babylon." It adds an unwanted toolbar and replaces Google with it's own search engine. Can you help me to solve this problem ? windows 7, IE 8 Thanks.
Hello himo 77 and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Download and run OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply
Logs to include with next post:

OTL.txt
Extras.txt
aswMBR log


Thanks

Satchfan
Hi Satchfan ,

Thanks for your help.
Kindly find below the logs you have requested.

BR,

OTL.Txt

PRC - File not found
PRC - D:\userdata\ifaradna\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Connectify\Connectify.exe (Connectify)
PRC - C:\Program Files (x86)\Connectify\Connectifyd.exe (Connectify)
PRC - C:\Program Files (x86)\Connectify\ConnectifyService.exe ()
PRC - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files (x86)\MCollect\MPCMon.exe (SIS GO DS PSU6)
PRC - C:\ProgramData\Qtel Mobile Broadband\OnlineUpdate\ouc.exe ()
PRC - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
PRC - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
PRC - C:\Program Files (x86)\WebEx\Connect\connect.exe (Cisco WebEx)
PRC - C:\Program Files (x86)\WebEx\Connect\apUpdate.exe (WebEx Communications Inc.)
PRC - C:\Windows\SysWOW64\SvcLncher.exe (SIS GO ICS PSU SMSEC T2)
PRC - C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe (Citrix Systems, Inc.)
PRC - C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files (x86)\Pointsec\Pointsec for PC\P95tray.exe (Check Point Software Tech Ltd)
PRC - C:\Windows\SysWOW64\Prot_srv.exe (Check Point Software Tech Ltd)
PRC - C:\Windows\SysWOW64\pstartSr.exe (Check Point Software Tech Ltd)
PRC - C:\Program Files (x86)\Common Files\Check Point\UIFramework\cptray.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Windows\SysWOW64\CCM\CcmExec.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Trend Micro\OfficeScan Client\CNTAoSMgr.exe (Trend Micro Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\d362f68d3bf954ba55a4494a659492af\System.WorkflowServices.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\507b4ca18da9d2fde2e51a1f04593443\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\262285b3d0afafc5059f3fe9be69bff5\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\8177623eac8f15cf95b587625439eac7\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\0113a0162fe157bb4f0130a60bbcad1a\System.ServiceModel.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\f01c5c76d0a19516a37b7bd191a02cda\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\09cea564f5888335ef97bd104d7e4ea6\Microsoft.JScript.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\cb5bd98ffa4c82327b0e4db02bb58d2d\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\d939fca96c3645bb8806ea8ae43cc0ca\System.IdentityModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\bc96c5c6e644452270ff7c3d066ff713\System.Runtime.Serialization.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\281b67b96a2dd473dad4d222da0ca514\SMDiagnostics.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\b74950292d5681795d9d2c1a72a79952\System.ServiceModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\a1c4a635721f85bef0ea4194b888b871\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\dc4a4350f8c0c0919b5fb78f0c44291b\System.Security.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\9866d1f6178e1cde25642f1ac293ff8d\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e620323cacb5b6bfd93fd28d263440e4\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\faf4e8730ecbd07570111bb7c3b20565\System.ni.dll ()
MOD - C:\Program Files (x86)\Connectify\Vendors.dll ()
MOD - C:\Program Files (x86)\Connectify\NativeLibrary.dll ()
MOD - C:\Program Files (x86)\Connectify\Scannify.dll ()
MOD - C:\Program Files (x86)\Connectify\Network.dll ()
MOD - C:\Program Files (x86)\Connectify\DriverLib.dll ()
MOD - C:\Program Files (x86)\Connectify\BuildProps.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\skinengine.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\threadipc.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\libetpan.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\libexpatw.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\at_dll.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\personalmgr.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\WapiClient.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\XmppMgr.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\conComUI.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\apComRes.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\conCommClient.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\WidgetProxy.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\apCsSe.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\conhelp.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\apSSLGse.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\apReportDll.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\ipc.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\TriAVView.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\P2PAudioVideo.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\PandoraWidget.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\SearchOverlay.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\TriCapture.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\SharedMenu.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\ConvWindow.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\MeetingTab.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\ContactPage.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\MeetingMgr.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\AudioConfMgr.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\ConnectConfigInfo.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\CEB.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\InstantMeeting.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\NotiMgr.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\Expat.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\NetworkMonitor.dll ()
MOD - C:\Program Files (x86)\WebEx\Connect\AudioConfBridge.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (STacSV) – C:\Program Files\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (AESTFilters) – C:\Program Files\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (O2FLASH) – C:\Windows\SysNative\drivers\o2flash.exe (O2Micro International)
SRV:64bit: - (UCMS) – C:\Program Files\Siemens\UCMS\Core\UCMS.exe (Siemens AG)
SRV:64bit: - (dcpsysmgrsvc) – C:\Program Files\Dell\Dell System Manager\DCPSysMgrSvc.exe (Dell Inc.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Connectify) – C:\Program Files (x86)\Connectify\ConnectifyService.exe ()
SRV - (tmlisten) – C:\Program Files (x86)\Trend Micro\OfficeScan Client\TmListen.exe (Trend Micro Inc.)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (ntrtscan) – C:\Program Files (x86)\Trend Micro\OfficeScan Client\NTRTScan.exe (Trend Micro Inc.)
SRV - (Qtel Mobile Broadband. RunOuc) – C:\Program Files (x86)\Qtel Mobile Broadband\UpdateDog\ouc.exe ()
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (vpnagent) – C:\Program Files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.)
SRV - (Cisco WebEx Connect Upgrade Service) – C:\Program Files (x86)\WebEx\Connect\apUpdate.exe (WebEx Communications Inc.)
SRV - (Service Launcher) – C:\Windows\SysWOW64\SvcLncher.exe (SIS GO ICS PSU SMSEC T2)
SRV - (TmPfw) – C:\Program Files (x86)\Trend Micro\OfficeScan Client\TmPfw.exe (Trend Micro Inc.)
SRV - (TmProxy) – C:\Program Files (x86)\Trend Micro\OfficeScan Client\TmProxy.exe (Trend Micro Inc.)
SRV - (HWDeviceService64.exe) – C:\ProgramData\DatacardService\HWDeviceService64.exe ()
SRV - (Pointsec) – C:\Windows\SysWOW64\Prot_srv.exe (Check Point Software Tech Ltd)
SRV - (Pointsec_start) – C:\Windows\SysWOW64\pstartSr.exe (Check Point Software Tech Ltd)
SRV - (CVPND) – C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (CcmExec) – C:\Windows\SysWOW64\CCM\CcmExec.exe (Microsoft Corporation)
SRV - (smstsmgr) – C:\Windows\SysWOW64\CCM\TSManager.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files (x86)\WinPcap\rpcapd.exe (CACE Technologies)


========== Driver Services (SafeList) ==========

DRV:64bit: - (cnnctfy2) – C:\Windows\SysNative\drivers\cnnctfy2.sys (Connectify)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (ew_usbenumfilter) – C:\Windows\SysNative\drivers\ew_usbenumfilter.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (ewusbnet) – C:\Windows\SysNative\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (hwdatacard) – C:\Windows\SysNative\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (ew_hwusbdev) – C:\Windows\SysNative\drivers\ew_hwusbdev.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (huawei_enumerator) – C:\Windows\SysNative\drivers\ew_jubusenum.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (prot_2k) – C:\Windows\SysNative\drivers\prot_2k.sys (Check Point Software Tech Ltd)
DRV:64bit: - (nwdelserial) – C:\Windows\SysNative\drivers\nwdelserial.sys (Novatel Wireless Inc.)
DRV:64bit: - (nwdelgobi3kfilter) – C:\Windows\SysNative\drivers\nwdelgobi3kfilter.sys (Novatel Wireless Inc)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (d554gps) – C:\Windows\SysNative\drivers\d554gps64.sys (Ericsson AB)
DRV:64bit: - (ecnssndisfltr) – C:\Windows\SysNative\drivers\wwussf64.sys (Ericsson AB)
DRV:64bit: - (ecnssndis) – C:\Windows\SysNative\drivers\wwuss64.sys (Ericsson AB)
DRV:64bit: - (Mbm3DevMt) Dell Wireless HSPA Mini-Card Device Management Driver (WDM) – C:\Windows\SysNative\drivers\Mbm3DevMt.sys (MCCI Corporation)
DRV:64bit: - (Mbm3CBus) Dell Wireless 5530 HSPA Mini-Card Device (WDM) – C:\Windows\SysNative\drivers\Mbm3CBus.sys (MCCI Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (Acceler) – C:\Windows\SysNative\drivers\Accelern.sys (ST Microelectronics)
DRV:64bit: - (O2MDRRDR) – C:\Windows\SysNative\drivers\O2MDRw7x64.sys (O2Micro )
DRV:64bit: - (O2MDFRDR) – C:\Windows\SysNative\drivers\o2mdfw7x64.sys (O2Micro )
DRV:64bit: - (O2SDJRDR) – C:\Windows\SysNative\drivers\o2sdjw7x64.sys (O2Micro )
DRV:64bit: - (NETwNs64) ___ Intel® – C:\Windows\SysNative\drivers\NETwNs64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) Intel® – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (MEIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (ApfiltrService) – C:\Windows\SysNative\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (vpnva) – C:\Windows\SysNative\drivers\vpnva64.sys (Cisco Systems, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (dmvsc) – C:\Windows\SysNative\drivers\dmvsc.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (tmwfp) – C:\Windows\SysNative\drivers\tmwfp.sys (Trend Micro Inc.)
DRV:64bit: - (tmlwf) – C:\Windows\SysNative\drivers\tmlwf.sys (Trend Micro Inc.)
DRV:64bit: - (tmtdi) – C:\Windows\SysNative\drivers\tmtdi.sys (Trend Micro Inc.)
DRV:64bit: - (stdcfltn) – C:\Windows\SysNative\drivers\stdcfltn.sys (ST Microelectronics)
DRV:64bit: - (U2SP) USB to Serial Converter Driver(Philips) – C:\Windows\SysNative\drivers\u2s2kxp64.sys (Magic Control Technology Corp.)
DRV:64bit: - (CVPNDRVA) – C:\Windows\SysNative\drivers\CVPNDRVA.sys ()
DRV:64bit: - (CVirtA) – C:\Windows\SysNative\drivers\CVirtA64.sys (Cisco Systems, Inc.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (DNE) – C:\Windows\SysNative\drivers\dne64x.sys (Deterministic Networks, Inc.)
DRV:64bit: - (NPF) – C:\Windows\SysNative\drivers\npf.sys (CACE Technologies)
DRV - (TmFilter) – C:\Program Files (x86)\Trend Micro\OfficeScan Client\tmxpflt.sys (Trend Micro Inc.)
DRV - (TmPreFilter) – C:\Program Files (x86)\Trend Micro\OfficeScan Client\tmpreflt.sys (Trend Micro Inc.)
DRV - (VSApiNt) – C:\Program Files (x86)\Trend Micro\OfficeScan Client\VsapiNT.sys (Trend Micro Inc.)
DRV - (prot_2k) – C:\Windows\SysWow64\drivers\prot_2k.sys (Check Point Software Tech Ltd)
DRV - (prepdrvr) – C:\Windows\SysWOW64\CCM\PrepDrv.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = https://inside.nokiasiemensnetworks.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://inside.nokiasiemensnetworks.com/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}…00060d819fda2a5
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = http://proxyconf.glb.nsn-net.net/proxy.pac


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.2.72: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.2.72: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.2.72: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.2.72: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.2.72: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/02/24 23:47:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2012/02/26 12:09:29 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/02/20 18:37:12 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/01/11 23:32:33 | 000,000,000 | —D | M] (GPO For Firefox) – C:\Program Files (x86)\Mozilla Firefox\extensions\[removed]
[2012/01/11 23:32:33 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions\[removed]\chrome
[2012/01/11 23:32:33 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions\[removed]\defaults
[2012/02/25 19:45:09 | 000,002,310 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2011/11/10 17:07:42 | 000,002,114 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\een.xml
[2011/11/10 17:07:42 | 000,007,831 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\NSN.xml

O1 HOSTS File: ([2009/06/11 00:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (WebEx Productivity Tools) - {90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7} - C:\Program Files (x86)\WebEx\Productivity Tools\ptonecli64.dll (Cisco WebEx LLC)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (WebEx Productivity Tools) - {90E2BA2E-DD1B-4cde-9134-7A8B86D33CA7} - C:\Program Files (x86)\WebEx\Productivity Tools\ptonecli64.dll (Cisco WebEx LLC)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MCDesk] %ProgramFiles%\Siemens\Customer\tools\MCDesk\MCDesk64.exe %ProgramFiles%\Siemens\Customer\tools\MCDesk\NSN.ini File not found
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Check Point Endpoint Tray Application] C:\Program Files (x86)\Common Files\Check Point\UIFramework\cptray.exe (Check Point Software Technologies LTD)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [OfficeScanNT Monitor] C:\Program Files (x86)\Trend Micro\OfficeScan Client\pccntmon.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [Pointsec Tray] C:\Program Files (x86)\Pointsec\Pointsec for PC\P95tray.exe (Check Point Software Tech Ltd)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [Cisco WebEx Connect] C:\Program Files (x86)\WebEx\Connect\connect.exe (Cisco WebEx)
O4 - HKCU..\Run: [Connectify] C:\Program Files (x86)\Connectify\Connectify.exe (Connectify)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\CaretBrowsing present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Download present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Security present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\SQM present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoPublishingWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWebServices = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoOnlinePrintsWizard = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: enablelinkedconnections = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: nointernetopenwith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStartupSound = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: MaxGPOScriptWait = 1800
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideShutdownScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\SQM present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowCpl = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisablePersonalDirChange = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuMyGames = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 1 = HomeGroup
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 2 = Share with a homegroup
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 3 = Get Windows Live Essentials
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 4 = Go online to get Windows Live Essentials
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 5 = Create a system repair disc
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: I&M; Chat - C:\Program Files (x86)\Nokia Siemens Networks\Communication Suite\scripts\call_imscript.htm ()
O8:64bit: - Extra context menu item: V&oice; Call - C:\Program Files (x86)\Nokia Siemens Networks\Communication Suite\scripts\call_voicescript.htm ()
O8:64bit: - Extra context menu item: Vi&deo; Call - C:\Program Files (x86)\Nokia Siemens Networks\Communication Suite\scripts\call_videoscript.htm ()
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: I&M; Chat - C:\Program Files (x86)\Nokia Siemens Networks\Communication Suite\scripts\call_imscript.htm ()
O8 - Extra context menu item: V&oice; Call - C:\Program Files (x86)\Nokia Siemens Networks\Communication Suite\scripts\call_voicescript.htm ()
O8 - Extra context menu item: Vi&deo; Call - C:\Program Files (x86)\Nokia Siemens Networks\Communication Suite\scripts\call_videoscript.htm ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: 55963676-2F5E-4BAF-AC28-CF26AA587566 vpnweb.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.159.192.10 10.159.208.5 10.159.0.140
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = nsn-intra.net
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2FF8DDDB-6CE3-4D78-A0AE-AAAFF169E506}: NameServer = 212.77.192.59 212.77.192.60
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A17589F4-F346-4B2F-A6B1-0CD3853045EC}: DhcpNameServer = 10.159.192.10 10.159.208.5 10.159.0.140
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C62878B3-F84B-440F-85B6-4E76070D8BF5}: NameServer = 212.77.192.59 212.77.192.60
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E004D312-DB1E-4AE0-ABC3-70EA3DFD4FF8}: NameServer = 212.77.192.59 212.77.192.60
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\application/x-ica - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=euc-jp - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=ISO-8859-1 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS936 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS949 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=MS950 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=UTF8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica; charset=UTF-8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=euc-jp - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=ISO-8859-1 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS936 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS949 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=MS950 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=UTF8 - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-ica;charset=UTF-8 - No CLSID value found
O18:64bit: - Protocol\Filter\ica - No CLSID value found
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\System32\Userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: GinaDLL - (pssogina.dll) - C:\Windows\SysNative\pssogina.dll (Check Point Software Tech Ltd)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 0
O33 - MountPoints2\{56d8d6be-5004-11e1-8b2b-60d819fda2a5}\Shell - "" = AutoRun
O33 - MountPoints2\{56d8d6be-5004-11e1-8b2b-60d819fda2a5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{69b748fa-4014-11e1-a11b-00059a3c7a00}\Shell - "" = AutoRun
O33 - MountPoints2\{69b748fa-4014-11e1-a11b-00059a3c7a00}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{85a54871-3f4b-11e1-b8d1-60d819fda2a5}\Shell - "" = AutoRun
O33 - MountPoints2\{85a54871-3f4b-11e1-b8d1-60d819fda2a5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

CREATERESTOREPOINT
Unable to start System Restore Service. Error code 5

========== Files/Folders - Created Within 30 Days ==========

[2012/04/24 09:14:52 | 000,594,944 | —- | C] (OldTimer Tools) – D:\userdata\ifaradna\Desktop\OTL.exe
[2012/04/24 05:24:36 | 000,000,000 | —D | C] – C:\Users\ifaradna\AppData\Local\Adobe
[2012/04/20 12:35:48 | 000,000,000 | —D | C] – D:\userdata\ifaradna\Desktop\corporate credit card
[2012/04/18 09:42:11 | 000,000,000 | —D | C] – D:\userdata\ifaradna\Application Data\Wireshark
[2012/04/18 09:40:55 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap
[2012/04/18 09:40:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\WinPcap
[2012/04/18 09:40:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wireshark
[2012/04/18 09:39:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Wireshark
[2012/04/18 05:00:22 | 005,559,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/04/18 05:00:22 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/04/18 05:00:22 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/04/17 18:12:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Connectify
[2012/04/17 18:12:33 | 000,031,344 | —- | C] (Connectify) – C:\Windows\SysNative\drivers\cnnctfy2.sys
[2012/04/17 18:12:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Connectify
[2012/04/17 18:12:18 | 000,000,000 | —D | C] – C:\ProgramData\Connectify
[2012/04/17 15:47:39 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imagehlp.dll
[2012/04/17 15:47:39 | 000,023,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fs_rec.sys
[2012/04/17 15:47:38 | 000,220,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2012/04/17 15:47:01 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/04/17 15:47:00 | 000,702,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/04/17 15:47:00 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/04/17 15:46:59 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/04/17 15:46:59 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/04/17 15:46:57 | 000,134,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/04/17 15:46:57 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/04/17 09:04:21 | 000,000,000 | —D | C] – D:\userdata\ifaradna\Application Data\Malwarebytes
[2012/04/17 09:04:12 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/04/17 09:04:12 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/04/17 09:04:10 | 000,024,904 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/04/17 09:04:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/04/17 08:57:25 | 000,050,688 | —- | C] (Atribune.org) – D:\userdata\ifaradna\Desktop\ATF-Cleaner.exe
[2012/04/16 05:52:23 | 000,000,000 | —D | C] – D:\userdata\ifaradna\Desktop\GOMS RU30 AL
[12 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/04/24 11:12:44 | 000,594,944 | —- | M] (OldTimer Tools) – D:\userdata\ifaradna\Desktop\OTL.exe
[2012/04/24 10:06:02 | 000,002,573 | —- | M] () – C:\Users\Public\Desktop\Connect network drives.lnk
[2012/04/24 10:05:54 | 000,200,713 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2012/04/24 09:43:06 | 000,019,120 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/24 09:43:06 | 000,019,120 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/24 04:46:52 | 000,001,962 | —- | M] () – D:\userdata\ifaradna\Desktop\2WX05S1 ifaradna.lnk
[2012/04/24 04:46:29 | 000,008,192 | —- | M] () – C:\Windows\SysWow64\srbt.dll
[2012/04/24 04:46:16 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/04/23 15:02:27 | 000,921,362 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/04/23 15:02:27 | 000,765,396 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/04/23 15:02:27 | 000,156,206 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/04/23 14:54:51 | 000,000,463 | —- | M] () – C:\Windows\SMSCFG.INI
[2012/04/23 14:51:34 | 3140,136,960 | -HS- | M] () – C:\hiberfil.sys
[2012/04/23 13:48:20 | 000,009,300 | —- | M] () – C:\Windows\cfgall.ini
[2012/04/18 09:40:40 | 000,001,740 | —- | M] () – C:\Users\Public\Desktop\Wireshark.lnk
[2012/04/17 18:14:17 | 000,323,360 | —- | M] () – D:\userdata\ifaradna\Desktop\address.png
[2012/04/17 18:12:40 | 000,001,005 | —- | M] () – C:\Users\Public\Desktop\Connectify.lnk
[2012/04/17 18:12:33 | 000,031,344 | —- | M] (Connectify) – C:\Windows\SysNative\drivers\cnnctfy2.sys
[2012/04/17 09:04:13 | 000,001,083 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/17 08:57:25 | 000,050,688 | —- | M] (Atribune.org) – D:\userdata\ifaradna\Desktop\ATF-Cleaner.exe
[2012/04/16 12:32:30 | 000,301,597 | —- | M] () – D:\userdata\ifaradna\Desktop\hangzhou_40857.jpg
[2012/04/12 15:43:15 | 000,001,998 | -H– | M] () – d:\userdata\ifaradna\My Documents\Default.rdp
[2012/04/09 03:50:58 | 000,000,600 | —- | M] () – C:\Users\ifaradna\PUTTY.RND
[2012/04/04 15:56:40 | 000,024,904 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/04/03 16:46:51 | 000,779,049 | —- | M] () – D:\userdata\ifaradna\Desktop\corporate credit card.zip
[2012/04/01 00:07:40 | 000,001,811 | —- | M] () – D:\userdata\ifaradna\Desktop\Application Launcher Client 2.lnk
[12 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/04/23 14:52:00 | 000,008,192 | —- | C] () – C:\Windows\SysWow64\srbt.dll
[2012/04/20 12:35:13 | 000,779,049 | —- | C] () – D:\userdata\ifaradna\Desktop\corporate credit card.zip
[2012/04/19 15:43:04 | 000,001,962 | —- | C] () – D:\userdata\ifaradna\Desktop\2WX05S1 ifaradna.lnk
[2012/04/18 09:40:40 | 000,001,740 | —- | C] () – C:\Users\Public\Desktop\Wireshark.lnk
[2012/04/17 18:14:17 | 000,323,360 | —- | C] () – D:\userdata\ifaradna\Desktop\address.png
[2012/04/17 18:12:40 | 000,001,005 | —- | C] () – C:\Users\Public\Desktop\Connectify.lnk
[2012/04/17 09:04:13 | 000,001,083 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/16 12:32:49 | 000,301,597 | —- | C] () – D:\userdata\ifaradna\Desktop\hangzhou_40857.jpg
[2012/04/09 03:50:58 | 000,000,600 | —- | C] () – C:\Users\ifaradna\PUTTY.RND
[2012/02/11 02:15:23 | 000,000,600 | —- | C] () – C:\Users\ifaradna\AppData\Local\PUTTY.RND
[2012/01/03 13:29:45 | 000,200,713 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2012/01/03 13:20:38 | 000,009,300 | —- | C] () – C:\Windows\cfgall.ini
[2012/01/03 13:08:34 | 000,004,764 | —- | C] () – C:\Windows\SysWow64\CcmFramework.ini
[2011/11/23 12:30:27 | 000,960,940 | —- | C] () – C:\Windows\SysWow64\igkrng600.bin
[2011/11/23 12:30:20 | 000,207,376 | —- | C] () – C:\Windows\SysWow64\igfcg600m.bin
[2011/11/23 12:30:10 | 000,145,804 | —- | C] () – C:\Windows\SysWow64\igcompkrng600.bin
[2011/10/14 10:56:38 | 000,853,194 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/10/14 10:55:15 | 000,000,463 | —- | C] () – C:\Windows\SMSCFG.INI
[2011/05/13 12:07:24 | 000,139,264 | —- | C] () – C:\Windows\SysWow64\nsldap32v50.dll
[2011/05/13 12:07:24 | 000,040,960 | —- | C] () – C:\Windows\SysWow64\nsldapssl32v50.dll
[2011/05/13 12:07:24 | 000,024,576 | —- | C] () – C:\Windows\SysWow64\nsldappr32v50.dll
[2010/08/05 09:39:12 | 000,135,168 | —- | C] () – C:\Windows\SysWow64\LogonAgentAPI.dll

========== LOP Check ==========

[2009/07/14 08:08:49 | 000,011,462 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2010/11/21 06:23:51 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2011/10/14 10:49:21 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2012/01/03 13:22:23 | 000,000,512 | —- | M] () – C:\BOOT_SAV.BOT
[2012/04/23 14:51:34 | 3140,136,960 | -HS- | M] () – C:\hiberfil.sys
[2012/04/23 14:51:38 | 4186,849,280 | -HS- | M] () – C:\pagefile.sys
[2012/01/03 13:22:41 | 002,097,152 | RHS- | M] () – C:\PROT_INS.SYS
[2012/02/25 19:45:34 | 000,000,237 | —- | M] () – C:\user.js
[2012/01/03 13:22:18 | 000,000,006 | —- | M] () – C:\VOL_CHAR.DAT

< %systemroot%\Fonts\*.com >
[2009/07/14 08:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 08:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 08:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 08:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 23:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 07:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
"UseWUServer" = 1
"NoAutoUpdate" = 1

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2010/11/21 09:13:55 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\PolicyDefinitions\en-US\Explorer.adml
[2010/11/21 09:13:55 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 23:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\PolicyDefinitions\Explorer.admx
[2009/06/10 23:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 08:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 09:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 09:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 09:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/21 06:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 08:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 08:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/21 06:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2010/11/21 09:13:43 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2010/11/21 09:13:43 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2010/11/21 09:13:44 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2010/11/21 09:13:44 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: EXPLORER.EXE.WINDOWS EXPLORER.MICROSOFT CORPORATION.6.1.7601.17567.ICO >
[2012/04/01 02:10:43 | 000,187,373 | —- | M] () MD5=59EF532FA50E1EC27DC50D43DA386BFB – C:\Users\ifaradna\AppData\Local\TechSmith\Snagit\DataStore\AppIcons\explorer.exe.Windows Explorer.Microsoft Corporation.6.1.7601.17567.ico

< MD5 for: EXPLORER.ZIP >
[2006/03/06 23:48:08 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.EXE >
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2010/11/21 06:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Program Files\Internet Explorer\iexplore.exe
[2010/11/21 06:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2010/11/21 06:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2010/11/21 06:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe

< MD5 for: IEXPLORE.EXE.INTERNET EXPLORER.MICROSOFT CORPORATION.8.0.7601.17514.ICO >
[2012/04/04 17:26:07 | 000,097,527 | —- | M] () MD5=66BA3CA5EFAEC697C374EBCCE61061CF – C:\Users\ifaradna\AppData\Local\TechSmith\Snagit\DataStore\AppIcons\iexplore.exe.Internet Explorer.Microsoft Corporation.8.0.7601.17514.ico

< MD5 for: IEXPLORE.EXE.MUI >
[2009/07/14 05:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/07/14 05:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/14 05:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2009/07/14 05:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-F6A52C86.PF >
[2012/04/24 10:45:42 | 000,258,352 | —- | M] () MD5=CFEDD75BED8ACDA6E07D097C8E1333E2 – C:\Windows\Prefetch\IEXPLORE.EXE-F6A52C86.pf

< MD5 for: WINLOGON.ADML >
[2010/11/21 09:13:55 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\PolicyDefinitions\en-US\WinLogon.adml
[2010/11/21 09:13:55 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/11 00:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\PolicyDefinitions\WinLogon.admx
[2009/06/11 00:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2010/11/21 06:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/21 06:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/21 09:13:40 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/21 09:13:40 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui

< MD5 for: WINLOGON.LOG >
[2012/04/24 08:21:29 | 000,221,952 | —- | M] () MD5=7811B237C63CCE6DDDC07787D7278536 – C:\Windows\security\logs\winlogon.log

< MD5 for: WINLOGON.MFL >
[2010/11/21 09:13:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2010/11/21 09:13:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 23:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 23:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< MD5 for: WINLOGON.OLD >
[2012/04/19 08:28:17 | 001,058,258 | —- | M] () MD5=9C545635998C096E48F648E8E9D00692 – C:\Windows\security\logs\winlogon.old

========== Files - Unicode (All) ==========
(C:\ProgramData\Microsoft\Windows\Start Menu\Programs\???? ???? ControlPoint) – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\مدير نظام ControlPoint

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\Managed\Logs] -> -> Unknown point type

< End of report >


Extras.Txt

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
"DisableConfig" = 1
"DisableSR" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
"DisableConfig" = 1
"DisableSR" = 1

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
"PolicyVersion" = 522

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
"EnableFirewall" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\PrivateProfile]
"EnableFirewall" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\PublicProfile]
"EnableFirewall" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
"PolicyVersion" = 522

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\PrivateProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\PublicProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\WebEx\Connect\wbxcOIEx.exe" = C:\Program Files (x86)\WebEx\Connect\wbxcOIEx.exe:*:Enabled:wbxcOIEx – (WebEx)
"C:\Program Files (x86)\WebEx\Connect\widget.exe" = C:\Program Files (x86)\WebEx\Connect\widget.exe:*:Enabled:widget – ()
"C:\Program Files (x86)\WebEx\Connect\connect.exe" = C:\Program Files (x86)\WebEx\Connect\connect.exe:*:Enabled:WebEx Connect – (Cisco WebEx)
"C:\Program Files (x86)\WebEx\Connect\wbxcOIEx.exe" = C:\Program Files (x86)\WebEx\Connect\wbxcOIEx.exe:*:Enabled:wbxcOIEx – (WebEx)
"C:\Program Files (x86)\WebEx\Connect\widget.exe" = C:\Program Files (x86)\WebEx\Connect\widget.exe:*:Enabled:widget – ()
"C:\Program Files (x86)\WebEx\Connect\connect.exe" = C:\Program Files (x86)\WebEx\Connect\connect.exe:*:Enabled:WebEx Connect – (Cisco WebEx)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\WebEx\Connect\wbxcOIEx.exe" = C:\Program Files (x86)\WebEx\Connect\wbxcOIEx.exe:*:Enabled:wbxcOIEx – (WebEx)
"C:\Program Files (x86)\WebEx\Connect\widget.exe" = C:\Program Files (x86)\WebEx\Connect\widget.exe:*:Enabled:widget – ()
"C:\Program Files (x86)\WebEx\Connect\connect.exe" = C:\Program Files (x86)\WebEx\Connect\connect.exe:*:Enabled:WebEx Connect – (Cisco WebEx)
"C:\Program Files (x86)\WebEx\Connect\wbxcOIEx.exe" = C:\Program Files (x86)\WebEx\Connect\wbxcOIEx.exe:*:Enabled:wbxcOIEx – (WebEx)
"C:\Program Files (x86)\WebEx\Connect\widget.exe" = C:\Program Files (x86)\WebEx\Connect\widget.exe:*:Enabled:widget – ()
"C:\Program Files (x86)\WebEx\Connect\connect.exe" = C:\Program Files (x86)\WebEx\Connect\connect.exe:*:Enabled:WebEx Connect – (Cisco WebEx)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{446D8E56-5E4F-4B20-A199-25087C63E420}" = NSN Office Templates 1.0 English
"{467D5E81-8349-4892-9E81-C3674ED8E451}" = Cisco Systems VPN Client 5.0.07.0290
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90120000-0028-0404-1000-0000000FF1CE}" = Microsoft Office IME (Chinese (Traditional)) 2007
"{90120000-0028-0411-1000-0000000FF1CE}" = Microsoft Office IME (Japanese) 2007
"{90120000-0028-0412-1000-0000000FF1CE}" = Microsoft Office IME (Korean) 2007
"{90120000-0028-0804-1000-0000000FF1CE}" = Microsoft Office IME (Chinese (Simplified)) 2007
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9243F09B-3319-4A55-8181-9BCEC7391079}" = Adobe Flash Player 11 Plugin (x64)
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FB2CBB77-53EB-4CEA-A916-701D62C400F4}" = PDFCreator 1.2 English
"{FDF509ED-9624-4FDE-9BAA-9566C186AB96}" = Dell System Manager
"Connectify" = Connectify
"CutePDF Writer Installation" = CutePDF Writer 2.8
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{04EB7EC7-BA84-11D6-A753-0006298968D6}" = NED 6.0
"{0B448DFD-1170-4E4B-9AEB-3F0157560A02}" = BMC Remedy User 7.5 Multilingual
"{0BC52583-70CA-46E7-BD43-E8FA7486F689}" = Cisco WebEx Connect
"{199C20D6-10D3-4210-B361-4760209F56AE}" = Citrix online plug-in (Web)
"{23EEC842-57ED-4055-A056-9D4185DFB1AA}" = Dell Mobile Broadband Manager
"{24C4AC5A-67A4-4E1D-B30C-8C7A01712607}" = RSA SecurID Software Token for Microsoft Windows
"{2609EDF1-34C4-4B03-B634-55F3B3BC4931}" = Configuration Manager Client
"{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java™ 6 Update 26
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{31B33270-24D7-4307-84F2-A3288636B83A}" = Check Point Endpoint Security - Full Disk Encryption
"{31F2F7A5-98C0-4442-8565-D774DA446792}" = UltraEdit 16.30
"{3937B908-E836-4034-A59F-7746AF5B168A}" = FileZilla 3.5 Multilingual
"{3E5CBADD-2E51-47C1-BBE2-B802DB6DA56A}" = FX Solutions UK - MetaTrader 4.00
"{44AA4928-29F6-49E0-AB96-A26F93039525}" = XenApp Plugin for Hosted Apps
"{50319255-8B40-41F6-BD3E-3C230F3EABAD}" = Cisco WebEx Connect
"{5098AE98-FB04-4D03-8B74-0B8292CEF06B}" = Nokia Siemens Networks Communication Suite 4.2.2.8922
"{5AFAA589-F446-4D9E-AAD6-B8C9B43BEB08}" = ServiceLauncher
"{5BCC634A-58AD-42F9-B3C6-2EA52F81CF85}" = Snagit 10
"{5C50C262-6088-4E16-83D9-2414BF8E3F17}" = TreeSize Professional 5.4 English
"{6969899D-0D56-45D5-9C41-7489F2153F8C}" = USB to Serial Port Adapter(PA088) V3.0.0
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{793AF38E-71F8-4384-8A32-747B2DCAAEF6}" = LocalAdminWMIProvider
"{795096D9-8C08-4D47-97C5-571AA10C7B50}" = WebEx Productivity Tools
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8EB9050D-14C8-41B1-BB7A-EF5D365D6D86}" = Notepad++ 5.9 English
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0401-0000-0000000FF1CE}" = Microsoft Office Proof (Arabic) 2007
"{90120000-001F-0401-0000-0000000FF1CE}_PROOFKIT_{5A2F65A4-808F-4A1E-973E-92E17824982D}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0402-0000-0000000FF1CE}" = Microsoft Office Proof (Bulgarian) 2007
"{90120000-001F-0402-0000-0000000FF1CE}_PROOFKIT_{3F15EA4D-E8E2-4FAE-9EAF-E0AAD6D67F77}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0403-0000-0000000FF1CE}" = Microsoft Office Proof (Catalan) 2007
"{90120000-001F-0403-0000-0000000FF1CE}_PROOFKIT_{A5B6B786-2D6F-4B75-940F-42B32D01D146}" = Microsoft Office SharePoint Designer Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0404-0000-0000000FF1CE}" = Microsoft Office Proof (Chinese (Traditional)) 2007
"{90120000-001F-0404-0000-0000000FF1CE}_PROOFKIT_{6197A9A1-87C4-4899-80A7-C555C31F95E4}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}_PROOFKIT_{3C3813E1-C370-4F32-9639-8B43C7C780CD}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0406-0000-0000000FF1CE}" = Microsoft Office Proof (Danish) 2007
"{90120000-001F-0406-0000-0000000FF1CE}_PROOFKIT_{AAA2F315-90E9-40B3-8F83-4E52A5B461B2}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_PROOFKIT_{2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0408-0000-0000000FF1CE}" = Microsoft Office Proof (Greek) 2007
"{90120000-001F-0408-0000-0000000FF1CE}_PROOFKIT_{0C4FD7D7-C166-42BD-8970-4C5D53CA29B3}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROOFKIT_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040B-0000-0000000FF1CE}" = Microsoft Office Proof (Finnish) 2007
"{90120000-001F-040B-0000-0000000FF1CE}_PROOFKIT_{F14C929B-E0E6-4EB5-8BFD-FC71AAC7D39C}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROOFKIT_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040D-0000-0000000FF1CE}" = Microsoft Office Proof (Hebrew) 2007
"{90120000-001F-040D-0000-0000000FF1CE}_PROOFKIT_{5159E1AC-E76D-4654-9C02-F1D519420853}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-040E-0000-0000000FF1CE}" = Microsoft Office Proof (Hungarian) 2007
"{90120000-001F-040E-0000-0000000FF1CE}_PROOFKIT_{685D17E5-D868-4A77-B58E-255DEBA78262}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_PROOFKIT_{58FC5E37-DD28-4D4A-A549-125744C6763C}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0411-0000-0000000FF1CE}" = Microsoft Office Proof (Japanese) 2007
"{90120000-001F-0411-0000-0000000FF1CE}_PROOFKIT_{EA692029-ACE6-48E9-9FDE-A190C874EBE1}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0412-0000-0000000FF1CE}" = Microsoft Office Proof (Korean) 2007
"{90120000-001F-0412-0000-0000000FF1CE}_PROOFKIT_{C7466D9B-B03F-4FEE-B7B4-BE8C8DCF5792}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0413-0000-0000000FF1CE}" = Microsoft Office Proof (Dutch) 2007
"{90120000-001F-0413-0000-0000000FF1CE}_PROOFKIT_{B3F4DC34-7F60-4B7C-A79F-1C13012D99D4}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0414-0000-0000000FF1CE}" = Microsoft Office Proof (Norwegian (Bokmål)) 2007
"{90120000-001F-0414-0000-0000000FF1CE}_PROOFKIT_{3FE135E8-2B21-44ED-99CA-87C782C4F5F7}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0415-0000-0000000FF1CE}" = Microsoft Office Proof (Polish) 2007
"{90120000-001F-0415-0000-0000000FF1CE}_PROOFKIT_{2D1F88C2-ADAE-47C4-8648-6EA8F7E6EB2D}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0416-0000-0000000FF1CE}" = Microsoft Office Proof (Portuguese (Brazil)) 2007
"{90120000-001F-0416-0000-0000000FF1CE}_PROOFKIT_{669EB263-0AFE-4FCB-A068-DB082CA6273C}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0418-0000-0000000FF1CE}" = Microsoft Office Proof (Romanian) 2007
"{90120000-001F-0418-0000-0000000FF1CE}_PROOFKIT_{C7B5CA5D-ADBD-4768-964A-32E46B239DFE}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0419-0000-0000000FF1CE}" = Microsoft Office Proof (Russian) 2007
"{90120000-001F-0419-0000-0000000FF1CE}_PROOFKIT_{D7CE14BC-96D9-41C5-822D-F5B1C2C35AA2}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-041A-0000-0000000FF1CE}" = Microsoft Office Proof (Croatian) 2007
"{90120000-001F-041A-0000-0000000FF1CE}_PROOFKIT_{F0144F1E-9775-492B-8B8C-ACB7B76B47DC}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-001F-041B-0000-0000000FF1CE}_PROOFKIT_{F67648A4-713E-4298-BBAD-A83D8283B0F3}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-041D-0000-0000000FF1CE}" = Microsoft Office Proof (Swedish) 2007
"{90120000-001F-041D-0000-0000000FF1CE}_PROOFKIT_{A8626CEF-CB0A-4BC2-8F51-210A43B6158D}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-041E-0000-0000000FF1CE}" = Microsoft Office Proof (Thai) 2007
"{90120000-001F-041E-0000-0000000FF1CE}_PROOFKIT_{4CD10956-4F76-46E0-9A0A-CB58A084E1B2}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-041F-0000-0000000FF1CE}" = Microsoft Office Proof (Turkish) 2007
"{90120000-001F-041F-0000-0000000FF1CE}_PROOFKIT_{E0E4AC2D-2A1F-438E-A523-682A6E2252A8}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0420-0000-0000000FF1CE}" = Microsoft Office Proof (Urdu) 2007
"{90120000-001F-0422-0000-0000000FF1CE}" = Microsoft Office Proof (Ukrainian) 2007
"{90120000-001F-0422-0000-0000000FF1CE}_PROOFKIT_{DC154E48-5278-423A-80A1-B93247E38A1A}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0424-0000-0000000FF1CE}" = Microsoft Office Proof (Slovenian) 2007
"{90120000-001F-0424-0000-0000000FF1CE}_PROOFKIT_{C1EEDFD4-743A-49F9-A2C9-189E3B7079A4}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0425-0000-0000000FF1CE}" = Microsoft Office Proof (Estonian) 2007
"{90120000-001F-0425-0000-0000000FF1CE}_PROOFKIT_{1D67F1FA-4C56-481F-B0E1-EC38033CFCCF}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0426-0000-0000000FF1CE}" = Microsoft Office Proof (Latvian) 2007
"{90120000-001F-0426-0000-0000000FF1CE}_PROOFKIT_{68CC1EB8-6E99-4B6D-AC71-16EF6C591880}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0427-0000-0000000FF1CE}" = Microsoft Office Proof (Lithuanian) 2007
"{90120000-001F-0427-0000-0000000FF1CE}_PROOFKIT_{1F6D2E5E-ED04-4E6D-94BA-2AEE21A5CA94}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-042D-0000-0000000FF1CE}" = Microsoft Office Proof (Basque) 2007
"{90120000-001F-0439-0000-0000000FF1CE}" = Microsoft Office Proof (Hindi) 2007
"{90120000-001F-0439-0000-0000000FF1CE}_PROOFKIT_{B7B8BE87-7A76-45CC-B2E8-A60D01846EB5}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0446-0000-0000000FF1CE}" = Microsoft Office Proof (Punjabi) 2007
"{90120000-001F-0447-0000-0000000FF1CE}" = Microsoft Office Proof (Gujarati) 2007
"{90120000-001F-0449-0000-0000000FF1CE}" = Microsoft Office Proof (Tamil) 2007
"{90120000-001F-044A-0000-0000000FF1CE}" = Microsoft Office Proof (Telugu) 2007
"{90120000-001F-044B-0000-0000000FF1CE}" = Microsoft Office Proof (Kannada) 2007
"{90120000-001F-044E-0000-0000000FF1CE}" = Microsoft Office Proof (Marathi) 2007
"{90120000-001F-0456-0000-0000000FF1CE}" = Microsoft Office Proof (Galician) 2007
"{90120000-001F-0804-0000-0000000FF1CE}" = Microsoft Office Proof (Chinese (Simplified)) 2007
"{90120000-001F-0804-0000-0000000FF1CE}_PROOFKIT_{C0214747-76E6-4C82-ACE7-4F6FB84CE5A9}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0814-0000-0000000FF1CE}" = Microsoft Office Proof (Norwegian (Nynorsk)) 2007
"{90120000-001F-0814-0000-0000000FF1CE}_PROOFKIT_{63BBC1EA-E390-403D-BFDE-B53E1D23FF46}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0816-0000-0000000FF1CE}" = Microsoft Office Proof (Portuguese (Portugal)) 2007
"{90120000-001F-0816-0000-0000000FF1CE}_PROOFKIT_{C450104C-4F9F-4924-8B97-92FB09DE9A92}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-081A-0000-0000000FF1CE}" = Microsoft Office Proof (Serbian (Latin)) 2007
"{90120000-001F-081A-0000-0000000FF1CE}_PROOFKIT_{4F771D58-556B-4D70-AD58-24FFEE4B9836}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROOFKIT_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0028-0404-0000-0000000FF1CE}" = Microsoft Office IME (Chinese (Traditional)) 2007
"{90120000-0028-0404-0000-0000000FF1CE}_PROOFKIT_{5CE74E24-2E09-4547-A1E0-354688209BBA}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-0028-0404-1000-0000000FF1CE}_PROOFKIT_{FD24402C-5DCE-4381-8477-0151B3771BD2}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-0028-0411-0000-0000000FF1CE}" = Microsoft Office IME (Japanese) 2007
"{90120000-0028-0411-0000-0000000FF1CE}_PROOFKIT_{00027B64-55FE-4FAF-9E2B-BB6EF3DB7B8F}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-0028-0411-1000-0000000FF1CE}_PROOFKIT_{0B1678E8-57B8-4679-A0E0-FFF7D03A51B8}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-0028-0412-0000-0000000FF1CE}" = Microsoft Office IME (Korean) 2007
"{90120000-0028-0412-0000-0000000FF1CE}_PROOFKIT_{32F6FF38-FD94-4667-AC0D-DB3F599DCD84}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-0028-0412-1000-0000000FF1CE}_PROOFKIT_{8E63514A-4C6B-4FD9-B98D-42C5BB8F4946}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-0028-0804-0000-0000000FF1CE}" = Microsoft Office IME (Chinese (Simplified)) 2007
"{90120000-0028-0804-0000-0000000FF1CE}_PROOFKIT_{5E9B9C9D-964B-4E00-BD68-A22AC484E835}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-0028-0804-1000-0000000FF1CE}_PROOFKIT_{ECB64CBB-31D9-4975-918A-CDEDC23DBE81}" = Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
"{90120000-002A-0000-1000-0000000FF1CE}_PROPLUS_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_PROPLUS_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0048-0409-0000-0000000FF1CE}" = Microsoft Office ProofMUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_PROPLUS_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-0103-0000-0000-0000000FF1CE}" = Microsoft Office Proofing Kit 2007
"{95120000-0052-0409-0000-0000000FF1CE}" = Microsoft Office Visio Viewer 2007
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9EC613A0-2F05-4242-AC34-6E48ABD13EC1}" = Settings for Microsoft Office Proofing Tools Kit 2007
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{AB6112E2-FF31-4FD9-9ECC-D571E6664265}" = HIT 2.10.3
"{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-1033-F400-7760-000000000004}_950" = Adobe Acrobat 9.5.0 - CPSID_83708
"{AC76BA86-1033-F400-7760-000000000004}{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X (10.0.1)
"{AC76BA86-7AD7-2447-0000-A00000000003}" = Chinese Simplified Fonts Support For Adobe Reader X
"{AC76BA86-7AD7-5760-0000-A00000000003}" = Japanese Fonts Support For Adobe Reader X
"{AFBD3104-3F35-4FB0-80FB-B09AA20E7D76}" = Cisco AnyConnect VPN Client
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BF88473C-7635-4F1A-84B8-DF3DAF3F7074}" = Putty 0.62 English
"{C2A02857-D138-446B-B181-442DEE20C8E6}" = Password Safe 3.23 for Windows
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BE}" = WinZip 15.0
"{CF7DB4E1-73D5-455B-AC44-128F933110EC}" = WinSCP 4.1 English
"{D34598D1-07B8-4EB6-AD9A-DBDF58FFC19F}" = Adobe Shockwave Player 11.6
"{D9A12818-E1E2-4433-A09A-EB65D2639D93}" = WinZip Command Line 3.2 English
"{DA7113AA-E3D0-48C6-BE31-E1F11BB9D18E}" = U232 P9/P25 10.2.98
"{DB716861-D95F-458D-BD32-C75AC4E0E50D}" = Emil
"{E0CE343A-DCE3-49EC-8D21-D13185B1C24A}" = Mindjet MindManager Viewer 7
"{ECEA7878-2100-4525-915D-B09174E36971}" = Trend Micro OfficeScan Client
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.8
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F758D5E5-03AA-45BF-82D3-28D5B2778874}" = DisplayInfoWMIProvider
"Application Launcher Client 2" = Application Launcher Client 2
"AVS DVD Copy_is1" = AVS DVD Copy 4.1.2.283
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"BTS Site Manager" = BTS Site Manager
"CitrixOnlinePluginPackWeb" = Citrix online plug-in - web
"FileZilla Client" = FileZilla Client 3.5.3
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"MetaTrader 4" = MetaTrader 4
"PROOFKIT" = Microsoft Office Proofing Tools Kit 2007
"PROPLUS" = Microsoft Office Professional Plus 2007
"Qtel Mobile Broadband" = Qtel Mobile Broadband
"RealPlayer 15.0" = RealPlayer
"WinPcapInst" = WinPcap 4.0.2
"Wireshark" = Wireshark 8.1.0-Corr3
"WZCLINE" = WinZip Command Line Support Add-On 3.2

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 4/9/2012 7:20:28 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = SceCli | ID = 1001
Description = Security policy cannot be propagated. Cannot access the template. Error
code = 3. \\nsn-intra.net\sysvol\nsn-intra.net\Policies\{D620C396-B35D-4E35-95AC-C8B036F1D815}\Machine\Microsoft\Windows
NT\SecEdit\GptTmpl.inf.

Error - 4/9/2012 7:20:31 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = Group Policy Services | ID = 100737026
Description = The client-side extension could not apply computer policy settings
for 'G_Win7_C_System_V05 {0BB006A0-B0DB-4040-8FB3-89046C8A0B12}' because it failed
with error code '0x80070035 The network path was not found.'%100790275

Error - 4/9/2012 7:20:31 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = Group Policy Registry | ID = 100737026
Description = The client-side extension could not apply computer policy settings
for 'G_Workstations_C_MS_IE_V04 {DE0D7BA2-A096-4E5C-A7E0-92E8E4839A55}' because
it failed with error code '0x80070035 The network path was not found.'%100790275

Error - 4/9/2012 7:20:31 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = Group Policy Shortcuts | ID = 100737026
Description = The client-side extension could not apply computer policy settings
for 'G_Win7_C_System_V05 {0BB006A0-B0DB-4040-8FB3-89046C8A0B12}' because it failed
with error code '0x80070035 The network path was not found.'%100790275

Error - 4/9/2012 10:05:43 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Adobe\Acrobat
9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 4/12/2012 1:06:23 AM | Computer Name = 2WX05S1.nsn-intra.net | Source = WinMgmt | ID = 10
Description =

Error - 4/14/2012 2:41:21 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.7601.17514 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 1390 Start
Time: 01cd12dc72fe8e1e Termination Time: 96 Application Path: C:\Program Files (x86)\Internet
Explorer\iexplore.exe Report Id: 6b68e326-8661-11e1-a3bc-60d819fda2a5

Error - 4/14/2012 2:44:23 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = UCMS | ID = 0
Description = Error running function SetSource()Illegal operation attempted on a
registry key that has been marked for deletion.

Error - 4/14/2012 2:47:24 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = WinMgmt | ID = 10
Description =

Error - 4/15/2012 4:07:35 AM | Computer Name = 2WX05S1.nsn-intra.net | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\Adobe\Acrobat
9.0\Designer 8.2\FormDesigner.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

[ Cisco AnyConnect VPN Client Events ]
Error - 4/23/2012 9:48:44 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = vpnagent | ID = 67108866
Description = Function: CTlsTransport::OnTransportInitiateComplete File: .\IP\TlsTransport.cpp
Line:
344 Invoked Function: ISocketTransportCB::OnTransportInitiateComplete Return Code:
-31522780 (0xFE1F0024) Description: SOCKETTRANSPORT_ERROR_CONNECT_TIMEOUT

Error - 4/23/2012 9:48:44 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = vpnagent | ID = 67108866
Description = Function: CHttpSessionAsync::OnTransportInitiateComplete File: .\IP\HttpSessionAsync.cpp
Line:
1002 Invoked Function: ISocketTransportCB::OnTransportInitiateComplete Return Code:
-31522780 (0xFE1F0024) Description: SOCKETTRANSPORT_ERROR_CONNECT_TIMEOUT

Error - 4/23/2012 9:48:44 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = vpnagent | ID = 67108866
Description = Function: CHttpProbeAsync::OnOpenRequestComplete File: .\IP\HttpProbeAsync.cpp
Line:
254 Invoked Function: CHttpSessionAsync::OnOpenRequestComplete Return Code: -31522780
(0xFE1F0024) Description: SOCKETTRANSPORT_ERROR_CONNECT_TIMEOUT

Error - 4/23/2012 9:48:44 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = vpnagent | ID = 67108866
Description = Function: CSocketTransport::OnTimerExpired File: .\IPC\SocketTransport.cpp
Line:
1175 Invoked Function: CSocketTransport::postConnectProcessing Return Code: -31522780
(0xFE1F0024) Description: SOCKETTRANSPORT_ERROR_CONNECT_TIMEOUT

Error - 4/23/2012 9:48:52 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = vpnagent | ID = 67108866
Description = Function: CHttpSessionAsync::OnTransportInitiateComplete File: .\IP\HttpSessionAsync.cpp
Line:
1002 Invoked Function: ISocketTransportCB::OnTransportInitiateComplete Return Code:
-31522780 (0xFE1F0024) Description: SOCKETTRANSPORT_ERROR_CONNECT_TIMEOUT

Error - 4/23/2012 9:48:52 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = vpnagent | ID = 67108866
Description = Function: CHttpProbeAsync::OnOpenRequestComplete File: .\IP\HttpProbeAsync.cpp
Line:
254 Invoked Function: CHttpSessionAsync::OnOpenRequestComplete Return Code: -31522780
(0xFE1F0024) Description: SOCKETTRANSPORT_ERROR_CONNECT_TIMEOUT

Error - 4/23/2012 9:48:52 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = vpnagent | ID = 67108866
Description = Function: CSocketTransport::OnTimerExpired File: .\IPC\SocketTransport.cpp
Line:
1175 Invoked Function: CSocketTransport::postConnectProcessing Return Code: -31522780
(0xFE1F0024) Description: SOCKETTRANSPORT_ERROR_CONNECT_TIMEOUT

Error - 4/23/2012 9:48:52 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = vpnagent | ID = 67108866
Description = Function: CNetEnvironment::TestAccessToSG File: .\NetEnvironment.cpp
Line:
1020 Invoked Function: CNetEnvironment::analyzeHttpResponse Return Code: -28901363
(0xFE47000D) Description: NETENVIRONMENT_ERROR_PROBE_INCOMPLETE:Network Probe could
not contact target

Error - 4/23/2012 9:48:52 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = vpnagent | ID = 67108866
Description = Function: CNetEnvironment::testNetwork File: .\NetEnvironment.cpp Line:
856 Invoked Function: CNetEnvironment::IsSGAccessible Return Code: -28901363 (0xFE47000D)
Description:
NETENVIRONMENT_ERROR_PROBE_INCOMPLETE:Network Probe could not contact target

Error - 4/23/2012 9:48:52 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = vpnagent | ID = 67108866
Description = Function: CNetEnvironment::TestNetEnv File: .\NetEnvironment.cpp Line:
190 Invoked Function: CNetEnvironment::testNetwork Return Code: -28901363 (0xFE47000D)
Description:
NETENVIRONMENT_ERROR_PROBE_INCOMPLETE:Network Probe could not contact target

[ Pointsec Events ]
Error - 1/11/2012 3:33:10 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = prot_srv | ID = 462753
Description = The recovery file could not be created: process failed.

Error - 1/11/2012 3:33:31 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = prot_srv | ID = 462753
Description = The recovery file could not be created: process failed.

Error - 1/11/2012 3:33:32 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = prot_srv | ID = 462753
Description = The recovery file could not be created: process failed.

Error - 1/11/2012 3:33:33 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = prot_srv | ID = 462753
Description = The recovery file could not be created: process failed.

Error - 1/11/2012 3:33:34 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = prot_srv | ID = 462753
Description = The recovery file could not be created: process failed.

Error - 1/11/2012 3:36:48 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = prot_srv | ID = 462753
Description = The recovery file could not be created: process failed.

Error - 1/11/2012 3:37:14 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = prot_srv | ID = 462753
Description = The recovery file could not be created: process failed.

Error - 1/11/2012 3:37:25 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = prot_srv | ID = 462753
Description = The recovery file could not be created: process failed.

Error - 1/11/2012 3:46:09 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = prot_srv | ID = 462753
Description = The recovery file could not be created: process failed.

Error - 1/11/2012 4:11:32 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = prot_srv | ID = 462753
Description = The recovery file could not be created: process failed.

[ System Events ]
Error - 4/21/2012 10:29:14 AM | Computer Name = 2WX05S1.nsn-intra.net | Source = Microsoft-Windows-GroupPolicy | ID = 1096
Description = The processing of Group Policy failed. Windows could not apply the
registry-based policy settings for the Group Policy object LDAP://CN=Machine,CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=nsn-intra,DC=net.
Group Policy settings will not be resolved until this event is resolved. View the
event details for more information on the file name and path that caused the failure.

Error - 4/21/2012 10:32:55 AM | Computer Name = 2WX05S1.nsn-intra.net | Source = Microsoft-Windows-GroupPolicy | ID = 1096
Description = The processing of Group Policy failed. Windows could not apply the
registry-based policy settings for the Group Policy object LDAP://CN=Machine,cn={083D09AA-A545-4826-8D55-EDF0BE06115A},cn=policies,cn=system,DC=nsn-intra,DC=net.
Group Policy settings will not be resolved until this event is resolved. View the
event details for more information on the file name and path that caused the failure.

Error - 4/21/2012 11:55:54 AM | Computer Name = 2WX05S1.nsn-intra.net | Source = Microsoft-Windows-GroupPolicy | ID = 1055
Description = The processing of Group Policy failed. Windows could not resolve the
computer name. This could be caused by one of more of the following: a) Name Resolution
failure on the current domain controller. B) Active Directory Replication Latency
(an account created on another domain controller has not replicated to the current
domain controller).

Error - 4/21/2012 1:52:56 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = Microsoft-Windows-GroupPolicy | ID = 1055
Description = The processing of Group Policy failed. Windows could not resolve the
computer name. This could be caused by one of more of the following: a) Name Resolution
failure on the current domain controller. B) Active Directory Replication Latency
(an account created on another domain controller has not replicated to the current
domain controller).

Error - 4/21/2012 2:29:56 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = NETLOGON | ID = 5719
Description = This computer was not able to set up a secure session with a domain
controller
in domain NSN-INTRA due to the following: %%1311 This may lead to authentication
problems. Make sure that this computer is connected to the network. If the problem
persists, please contact your domain administrator. ADDITIONAL INFO If this computer
is a domain controller for the specified domain, it sets up the secure session to
the primary domain controller emulator in the specified domain. Otherwise, this
computer sets up the secure session to any domain controller in the specified domain.

Error - 4/21/2012 8:52:04 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = NETLOGON | ID = 5719
Description = This computer was not able to set up a secure session with a domain
controller
in domain NSN-INTRA due to the following: %%1311 This may lead to authentication
problems. Make sure that this computer is connected to the network. If the problem
persists, please contact your domain administrator. ADDITIONAL INFO If this computer
is a domain controller for the specified domain, it sets up the secure session to
the primary domain controller emulator in the specified domain. Otherwise, this
computer sets up the secure session to any domain controller in the specified domain.

Error - 4/21/2012 8:52:04 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = Microsoft-Windows-GroupPolicy | ID = 1055
Description = The processing of Group Policy failed. Windows could not resolve the
computer name. This could be caused by one of more of the following: a) Name Resolution
failure on the current domain controller. B) Active Directory Replication Latency
(an account created on another domain controller has not replicated to the current
domain controller).

Error - 4/21/2012 8:52:04 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = Microsoft-Windows-GroupPolicy | ID = 1129
Description = The processing of Group Policy failed because of lack of network connectivity
to a domain controller. This may be a transient condition. A success message would
be generated once the machine gets connected to the domain controller and Group
Policy has succesfully processed. If you do not see a success message for several
hours, then contact your administrator.

Error - 4/21/2012 10:42:13 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = Microsoft-Windows-GroupPolicy | ID = 1055
Description = The processing of Group Policy failed. Windows could not resolve the
computer name. This could be caused by one of more of the following: a) Name Resolution
failure on the current domain controller. B) Active Directory Replication Latency
(an account created on another domain controller has not replicated to the current
domain controller).

Error - 4/21/2012 10:44:50 PM | Computer Name = 2WX05S1.nsn-intra.net | Source = Microsoft-Windows-GroupPolicy | ID = 1129
Description = The processing of Group Policy failed because of lack of network connectivity
to a domain controller. This may be a transient condition. A success message would
be generated once the machine gets connected to the domain controller and Group
Policy has succesfully processed. If you do not see a success message for several
hours, then contact your administrator.


< End of report >
Hi again,

below you find the aswMBR logs:

aswMBR.txt

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-04-24 11:43:27
—————————–
11:43:27.080 OS Version: Windows x64 6.1.7601 Service Pack 1
11:43:27.080 Number of processors: 4 586 0x2A07
11:43:27.081 ComputerName: 2WX05S1 UserName:
11:43:28.677 Initialize success
11:47:51.587 AVAST engine defs: 12042400
11:49:05.764 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
11:49:05.769 Disk 0 Vendor: TOSHIBA_ GS00 Size: 238475MB BusType: 3
11:49:05.797 Disk 0 MBR read successfully
11:49:05.802 Disk 0 MBR scan
11:49:05.813 Disk 0 Windows 7 default MBR code
11:49:05.820 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 118784 MB offset 2048
11:49:05.855 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 119689 MB offset 243271680
11:49:05.891 Disk 0 scanning C:\Windows\system32\drivers
11:49:05.899 Service scanning
11:49:40.335 Service TmFilter C:\Program Files (x86)\Trend Micro\OfficeScan Client\TmXPFlt.sys **LOCKED** 32
11:49:40.805 Service TmPreFilter C:\Program Files (x86)\Trend Micro\OfficeScan Client\TmPreFlt.sys **LOCKED** 32
11:49:44.521 Service VSApiNt C:\Program Files (x86)\Trend Micro\OfficeScan Client\VSApiNt.sys **LOCKED** 32
11:49:48.365 Modules scanning
11:49:48.370 Disk 0 trace - called modules:
11:49:48.424 ntoskrnl.exe CLASSPNP.SYS disk.sys stdcfltn.sys iaStor.sys hal.dll
11:49:48.427 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006305060]
11:49:48.428 3 CLASSPNP.SYS[fffff8800168c43f] -> nt!IofCallDriver -> [0xfffffa80061ad8d0]
11:49:48.429 5 stdcfltn.sys[fffff88001ac5c52] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004450050]
11:49:49.080 AVAST engine scan C:\Windows
11:49:49.132 AVAST engine scan C:\Windows\system32
11:49:49.137 AVAST engine scan C:\Windows\system32\drivers
11:49:49.141 AVAST engine scan C:\Users\ifaradna
11:49:49.143 AVAST engine scan C:\ProgramData
11:49:49.144 Scan finished successfully
11:59:57.435 Disk 0 MBR has been saved successfully to "D:\userdata\ifaradna\Desktop\OTL\MBR.dat"
11:59:57.444 The log file has been saved successfully to "D:\userdata\ifaradna\Desktop\OTL\aswMBR.txt"
Hi

There are a lot of restrictions on this computer: these and other entries are usually present on business computers.

If you work for a company and it is their computer, it is up to your company IT department to resolve this as we generally only help with home computers.

Working on a corporate computer can sometimes change settings and potentially harm your system which your company might not be too pleased about and could leave us liable for a lawsuit.

================================================

Babylon is not malware and you can easily uninstall this via add & remove programs.

Uninstall Babylon Toolbar:1. Click Start, Control Panel, Programs, and then Uninstall a Program.
2. Click on Babylon Toolbar, and then Uninstall.
If you are prompted for an administrator password or confirmation, type the password or provide confirmation.

When you,ve done that, delete this file:

C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml

If this is not a business computer and you still need help, please let me know.

Regards

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI