This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Redirected to my modem info page [Closed]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

πŸ“Žhighjackthislog.txtI was redirected to my ip modem page for anysite so I did a system restore a week back and it mostly works now but get errors on sending info to sites(could not make a bet on the Kentucky Derby). Here is my Highjackthis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:59:47 AM, on 5/6/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe
C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
C:\Program Files (x86)\hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Users\shalafi\AppData\Local\Autobahn\nexdef.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\SysWOW64\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…buy&pf=cndt
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…buy&pf=cndt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…buy&pf=cndt
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…buy&pf=cndt
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.4.12.6.dll
O2 - BHO: Javaβ„’ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: HelloWorldBHO - {ABD3B5E1-B268-407B-A150-2641DAB8D898} - C:\Program Files (x86)\Common Files\Homepage Protection\HomepageProtection.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
O2 - BHO: Javaβ„’ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
O4 - HKLM\..\Run: [HP Remote Solution] %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - Startup: DesktopVideoPlayer.lnk = shalafi\AppData\Local\vghd\bin\vghd.exe
O4 - Startup: NexDef Plug-in.lnk = shalafi\AppData\Local\Autobahn\nexdef.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O4 - Global Startup: PictureMover.lnk = C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files (x86)\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files (x86)\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.4.12.6.dll/206 (file missing)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agr64svc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Realtime Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: BitComet Disk Boost Service (BITCOMET_HELPER_SERVICE) - www.BitComet.com - C:\Program Files (x86)\BitComet\tools\BitCometService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files (x86)\Common Files\Motive\McciCMService.exe
O23 - Service: McciCMService64 - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 11284 bytes
Hello and welcome to What the Tech.

My name is Michael and I will be helping you with your computer problems.

Be aware that I am currently in training, which means that my replies must first be approved by one of my teachers. This may cause a slight delay in my responses, but keep in mind that this process is only to ensure you are receiving advice of the utmost accuracy.

Please keep the following points in mind:
  • Malware research is often a time consuming process and sometimes multiple tools/methods will have to be employed before an infection is completely dealt with. Please be patient during the process of removal.
  • Read my instructions carefully before carrying them out. Also, consider printing out any instructions in case you lose your Internet connection.
  • If you have any questions, please ask before carrying out a fix. Clearing up any confusion beforehand will save time in the long run. That said, I will try to post instructions as clearly and concisely as possible.
  • Please reply to this thread. Do not start a new topic, and do not request help on other forums during the course of the cleaning process.
  • If you do not reply after three (3) days, your thread will be closed.
IMPORTANT NOTE: Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

I will be back as soon as possible with a response.
  • OTL

    Download OTL to your desktop.

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs

[*]aswMBR


Please download aswMBR and save it to your desktop.

  • Double click aswMBR.exe to start the tool.
  • When prompted to download virus definitions, please do so.
  • Click Scan. Note: Do NOT attempt any Fix yet.
  • When the scan completes, click Save log, save it to your desktop and post it in your next reply.
  • There should also be another file that is created on your desktop named MBR.dat. Please right-click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
Here are my 3 logs and the zip file.

OTL logfile created on: 5/7/2012 4:17:26 PM - Run 1
OTL by OldTimer - Version 3.2.42.3 Folder = C:\Users\shalafi\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.99 Gb Total Physical Memory | 1.84 Gb Available Physical Memory | 46.03% Memory free
7.98 Gb Paging File | 5.87 Gb Available in Paging File | 73.59% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 584.24 Gb Total Space | 112.14 Gb Free Space | 19.19% Space Free | Partition Type: NTFS
Drive D: | 11.83 Gb Total Space | 2.16 Gb Free Space | 18.27% Space Free | Partition Type: NTFS
Drive G: | 931.48 Gb Total Space | 316.25 Gb Free Space | 33.95% Space Free | Partition Type: NTFS

Computer Name: SHALAFI-PC | User Name: shalafi | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/05/07 16:10:24 | 000,595,456 | β€”- | M] (OldTimer Tools) – C:\Users\shalafi\Desktop\OTL.exe
PRC - [2012/05/05 04:00:22 | 000,351,904 | β€”- | M] (Adobe Systems Incorporated) – C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe
PRC - [2012/04/04 01:53:50 | 000,063,928 | β€”- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/12/10 02:08:07 | 000,296,056 | β€”- | M] (RealNetworks, Inc.) – C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
PRC - [2011/10/19 17:56:36 | 000,086,224 | β€”- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2011/10/19 17:56:24 | 000,258,512 | β€”- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011/10/19 17:56:24 | 000,110,032 | β€”- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/08/11 11:27:42 | 015,490,560 | β€”- | M] () – C:\Users\shalafi\AppData\Local\Autobahn\nexdef.exe
PRC - [2011/01/27 04:33:00 | 012,336,432 | β€”- | M] (www.BitComet.com) – C:\Program Files (x86)\BitComet\BitComet.exe
PRC - [2010/12/28 04:00:34 | 001,296,728 | β€”- | M] (www.BitComet.com) – C:\Program Files (x86)\BitComet\tools\BitCometService.exe
PRC - [2010/03/18 14:16:28 | 000,130,384 | β€”- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
PRC - [2009/08/05 17:45:22 | 000,206,120 | β€”- | M] (CyberLink) – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
PRC - [2009/07/24 00:45:52 | 000,128,296 | β€”- | M] (CyberLink Corp.) – c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
PRC - [2009/06/03 16:35:16 | 000,430,080 | β€”- | M] (Hewlett-Packard Company) – C:\Program Files (x86)\PictureMover\Bin\PictureMover.exe
PRC - [2009/05/26 04:36:13 | 000,656,896 | β€”- | M] () – C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
PRC - [2008/11/20 14:47:28 | 000,062,768 | β€”- | M] (Hewlett-Packard) – C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe


========== Modules (No Company Name) ==========

MOD - [2011/09/27 08:23:00 | 000,087,912 | β€”- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 08:22:40 | 001,242,472 | β€”- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/08/11 11:27:44 | 000,159,744 | β€”- | M] () – C:\Users\shalafi\AppData\Local\Autobahn\rt\jetrt\baseline720.dll
MOD - [2011/08/11 11:27:44 | 000,069,632 | β€”- | M] () – C:\Users\shalafi\AppData\Local\Autobahn\rt\bin\java.dll
MOD - [2011/08/11 11:27:42 | 015,490,560 | β€”- | M] () – C:\Users\shalafi\AppData\Local\Autobahn\nexdef.exe
MOD - [2011/08/11 11:27:40 | 000,126,976 | β€”- | M] () – C:\Users\shalafi\AppData\Local\Autobahn\rt\bin\zip.dll
MOD - [2011/08/11 11:27:40 | 000,020,480 | β€”- | M] () – C:\Users\shalafi\AppData\Local\Autobahn\rt\bin\jetvm\jvm.dll
MOD - [2009/08/05 17:45:22 | 000,931,112 | β€”- | M] () – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll
MOD - [2009/07/13 21:15:45 | 000,364,544 | β€”- | M] () – C:\Windows\SysWOW64\msjetoledb40.dll
MOD - [2009/06/03 16:43:14 | 001,703,936 | β€”- | M] () – C:\Users\shalafi\AppData\Roaming\PictureMover\EN-US\Presentation.dll
MOD - [2009/06/03 16:34:18 | 003,764,224 | β€”- | M] () – C:\Users\shalafi\AppData\Roaming\PictureMover\Bin\Core.dll
MOD - [2009/05/26 04:36:13 | 000,656,896 | β€”- | M] () – C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | β€”- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/03/27 14:10:16 | 000,016,896 | β€”- | M] (LSI Corporation) [Auto | Running] – C:\Program Files\LSI SoftModem\agr64svc.exe – (AgereModemAudio)
SRV - [2012/05/05 05:00:48 | 000,257,696 | β€”- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/04/04 01:53:50 | 000,063,928 | β€”- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011/10/19 17:56:36 | 000,086,224 | β€”- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe – (AntiVirSchedulerService)
SRV - [2011/10/19 17:56:24 | 000,110,032 | β€”- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe – (AntiVirService)
SRV - [2010/12/28 04:00:34 | 001,296,728 | β€”- | M] (www.BitComet.com) [On_Demand | Running] – C:\Program Files (x86)\BitComet\tools\BitCometService.exe – (BITCOMET_HELPER_SERVICE)
SRV - [2010/03/18 14:16:28 | 000,130,384 | β€”- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/01/15 08:49:20 | 000,227,232 | β€”- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe – (McComponentHostService)
SRV - [2009/06/10 17:23:09 | 000,066,384 | β€”- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/05/22 14:02:20 | 000,250,616 | β€”- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe – (GameConsoleService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | β€”- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2012/02/15 23:06:48 | 000,132,320 | β€”- | M] (Avira GmbH) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avipbb.sys – (avipbb)
DRV:64bit: - [2011/10/19 17:56:50 | 000,027,760 | β€”- | M] (Avira GmbH) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avkmgr.sys – (avkmgr)
DRV:64bit: - [2011/10/19 17:56:49 | 000,097,312 | β€”- | M] (Avira GmbH) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\avgntflt.sys – (avgntflt)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | β€”- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | β€”- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | β€”- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | β€”- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | β€”- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | β€”- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | β€”- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 10:31:42 | 000,233,472 | β€”- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2009/07/09 06:38:42 | 001,208,320 | β€”- | M] (LSI Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\agrsm64.sys – (AgereSoftModem)
DRV:64bit: - [2009/06/16 07:32:14 | 006,112,672 | β€”- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | β€”- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | β€”- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | β€”- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | β€”- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/18 14:17:08 | 000,034,152 | β€”- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2009/05/09 02:14:20 | 000,015,752 | β€”- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\nuidfltr.sys – (NuidFltr)
DRV:64bit: - [2008/05/06 17:06:00 | 000,014,464 | β€”- | M] (Western Digital Technologies) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\wdcsam64.sys – (WDC_SAM)
DRV - [2010/05/04 11:51:46 | 000,020,096 | β€”- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Motive\MRESP50.sys – (MRESP50)
DRV - [2010/05/04 11:50:54 | 000,021,248 | β€”- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Motive\MREMP50.sys – (MREMP50)
DRV - [2009/07/13 21:19:10 | 000,019,008 | β€”- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…buy&pf;=cndt
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…buy&pf;=cndt
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {372DA26F-EE6C-4FA1-98CB-3F1B6DF1E831}
IE:64bit: - HKLM\..\SearchScopes\{372DA26F-EE6C-4FA1-98CB-3F1B6DF1E831}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{DECD5976-D500-4D4B-A856-034E26769E84}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpd
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…buy&pf;=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…buy&pf;=cndt
IE - HKLM\..\SearchScopes,DefaultScope = {372DA26F-EE6C-4FA1-98CB-3F1B6DF1E831}
IE - HKLM\..\SearchScopes\{372DA26F-EE6C-4FA1-98CB-3F1B6DF1E831}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{DECD5976-D500-4D4B-A856-034E26769E84}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpd


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-165932115-1053801288-1729283660-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…buy&pf;=cndt
IE - HKU\S-1-5-21-165932115-1053801288-1729283660-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…buy&pf;=cndt
IE - HKU\S-1-5-21-165932115-1053801288-1729283660-1000\..\SearchScopes,DefaultScope = {372DA26F-EE6C-4FA1-98CB-3F1B6DF1E831}
IE - HKU\S-1-5-21-165932115-1053801288-1729283660-1000\..\SearchScopes\{372DA26F-EE6C-4FA1-98CB-3F1B6DF1E831}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKU\S-1-5-21-165932115-1053801288-1729283660-1000\..\SearchScopes\{DECD5976-D500-4D4B-A856-034E26769E84}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpd
IE - HKU\S-1-5-21-165932115-1053801288-1729283660-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-165932115-1053801288-1729283660-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_2_202_235.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\2.0.31005.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files (x86)\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.0.198: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.0.198: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.0.198: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.0.198: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.0.198: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/05/05 02:55:56 | 000,000,000 | β€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/01/11 18:01:35 | 000,000,000 | β€”D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/17 17:14:33 | 000,000,000 | β€”D | M]

[2011/12/04 23:11:36 | 000,000,000 | β€”D | M] (No name found) – C:\Users\shalafi\AppData\Roaming\Mozilla\Extensions
[2012/04/24 16:59:14 | 000,000,000 | β€”D | M] (No name found) – C:\Users\shalafi\AppData\Roaming\Mozilla\Firefox\Profiles\lj16lspc.default\extensions
[2011/12/22 21:55:07 | 000,000,000 | β€”D | M] (BitComet Video Downloader) – C:\Users\shalafi\AppData\Roaming\Mozilla\Firefox\Profiles\lj16lspc.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2012/04/06 01:25:20 | 000,000,000 | β€”D | M] (DownloadHelper) – C:\Users\shalafi\AppData\Roaming\Mozilla\Firefox\Profiles\lj16lspc.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012/01/24 17:25:42 | 000,000,000 | β€”D | M] (Super Start) – C:\Users\shalafi\AppData\Roaming\Mozilla\Firefox\Profiles\lj16lspc.default\extensions\[removed]
[2012/03/20 22:57:18 | 000,002,571 | β€”- | M] () – C:\Users\shalafi\AppData\Roaming\Mozilla\Firefox\Profiles\lj16lspc.default\searchplugins\amazon-search-suggestions.xml
[2012/01/30 20:13:02 | 000,002,140 | β€”- | M] () – C:\Users\shalafi\AppData\Roaming\Mozilla\Firefox\Profiles\lj16lspc.default\searchplugins\lycos.xml
[2012/03/01 17:14:38 | 000,000,000 | β€”D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/03/01 17:14:39 | 000,000,000 | β€”D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
[2012/05/05 02:55:56 | 000,000,000 | β€”D | M] (RealPlayer Browser Record Plugin) – C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2012/04/06 01:25:07 | 000,084,405 | β€”- | M] () (No name found) – C:\USERS\SHALAFI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LJ16LSPC.DEFAULT\EXTENSIONS\{0545B830-F0AA-4D7E-8820-50A4629A56FE}.XPI
[2012/04/24 16:59:14 | 000,336,242 | β€”- | M] () (No name found) – C:\USERS\SHALAFI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LJ16LSPC.DEFAULT\EXTENSIONS\{19503E42-CA3C-4C27-B1E2-9CDB2170EE34}.XPI
[2011/12/05 00:32:19 | 000,088,908 | β€”- | M] () (No name found) – C:\USERS\SHALAFI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LJ16LSPC.DEFAULT\EXTENSIONS\{D47A9F51-8281-43FA-F450-F28EF8735E9A}.XPI
[2012/02/15 19:53:01 | 000,709,293 | β€”- | M] () (No name found) – C:\USERS\SHALAFI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LJ16LSPC.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
[2012/01/11 18:01:34 | 000,121,816 | β€”- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010/08/24 05:31:30 | 000,773,120 | β€”- | M] (BitComet) – C:\Program Files (x86)\mozilla firefox\plugins\npBitCometAgent.dll
[2012/03/01 17:14:23 | 000,476,904 | β€”- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012/01/11 18:01:31 | 000,002,252 | β€”- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/01/11 18:01:31 | 000,002,040 | β€”- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\18.0.1025.162\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\18.0.1025.162\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\18.0.1025.162\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\shalafi\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_233.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: BitCometAgent (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npBitCometAgent.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Javaβ„’ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Motive Plugin (Enabled) = C:\Program Files (x86)\Common Files\Motive\npMotive.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: RealPlayerβ„’ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: RealPlayerβ„’ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealNetworksβ„’ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\2.0.31005.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\shalafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\shalafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\shalafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Gmail = C:\Users\shalafi\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | β€”- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.4.12.6.dll (BitComet)
O2 - BHO: (Javaβ„’ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (hpBHO Class) - {ABD3B5E1-B268-407B-A150-2641DAB8D898} - C:\Program Files (x86)\Common Files\Homepage Protection\HomepageProtection.dll (AOL Products)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0560.0\msneshellx.dll (Microsoft Corp.)
O3 - HKU\S-1-5-21-165932115-1053801288-1729283660-1000\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [HP Remote Solution] C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe ()
O4 - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\shalafi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DesktopVideoPlayer.lnk = C:\Users\shalafi\AppData\Local\vghd\bin\vghd.exe (Totem Entertainment)
O4 - Startup: C:\Users\shalafi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\NexDef Plug-in.lnk = C:\Users\shalafi\AppData\Local\Autobahn\nexdef.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: &D;&ownload; &with; BitComet - C:\Program Files (x86)\BitComet\BitComet.exe (www.BitComet.com)
O8:64bit: - Extra context menu item: &D;&ownload; all with BitComet - C:\Program Files (x86)\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D;&ownload; &with; BitComet - C:\Program Files (x86)\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D;&ownload; all with BitComet - C:\Program Files (x86)\BitComet\BitComet.exe (www.BitComet.com)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.4.12.6.dll (BitComet)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{478427F3-E4A6-4105-A5B2-AD736A740BB3}: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/05/07 16:13:22 | 004,731,392 | β€”- | C] (AVAST Software) – C:\Users\shalafi\Desktop\aswMBR.exe
[2012/05/07 16:10:20 | 000,595,456 | β€”- | C] (OldTimer Tools) – C:\Users\shalafi\Desktop\OTL.exe
[2012/05/06 18:00:57 | 000,000,000 | β€”D | C] – C:\Users\shalafi\Desktop\iecv
[2012/05/06 17:57:47 | 000,000,000 | β€”D | C] – C:\Users\shalafi\AppData\Roaming\CapSystems
[2012/05/06 17:54:24 | 000,000,000 | β€”D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CapSystems
[2012/05/06 17:54:24 | 000,000,000 | β€”D | C] – C:\Program Files (x86)\CapSystems
[2012/05/06 17:52:35 | 000,463,080 | β€”- | C] (CNET Download.com) – C:\Users\shalafi\Desktop\cnet2_mzcv_zip.exe
[2012/05/06 17:51:13 | 000,463,080 | β€”- | C] (CNET Download.com) – C:\Users\shalafi\Desktop\cnet2_CookieCrumbler_1_6_setup_exe.exe
[2012/05/06 17:23:03 | 000,000,000 | β€”D | C] – C:\Users\shalafi\Desktop\goodcookies
[2012/05/06 17:17:23 | 000,000,000 | β€”D | C] – C:\Users\shalafi\AppData\Local\ConsumerSoft
[2012/05/06 17:16:12 | 000,463,080 | β€”- | C] (CNET Download.com) – C:\Users\shalafi\Desktop\cnet2_dfsetup_exe.exe
[2012/05/06 17:12:14 | 001,717,640 | β€”- | C] (ConsumerSoft) – C:\Users\shalafi\Desktop\FlashCookieCleaner.exe
[2012/05/06 06:28:33 | 000,000,000 | β€”D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\2BrightSparks
[2012/05/06 06:28:31 | 000,000,000 | β€”D | C] – C:\Program Files (x86)\2BrightSparks
[2012/05/05 22:00:36 | 000,000,000 | -H-D | C] – C:\Users\shalafi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2012/05/05 22:00:35 | 000,000,000 | β€”D | C] – C:\Program Files (x86)\Trend Micro
[2012/05/05 20:13:52 | 000,000,000 | β€”D | C] – C:\Users\shalafi\AppData\Roaming\Malwarebytes
[2012/05/05 20:13:39 | 000,000,000 | β€”D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/05/05 20:13:38 | 000,024,904 | β€”- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/05/05 20:13:38 | 000,000,000 | β€”D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/05/05 20:13:38 | 000,000,000 | β€”D | C] – C:\ProgramData\Malwarebytes
[2012/05/05 18:42:27 | 003,313,664 | β€”- | C] (Avira GmbH) – C:\Users\shalafi\Desktop\bootwizard.exe
[2012/05/05 18:35:34 | 000,000,000 | β€”D | C] – C:\Users\shalafi\AppData\Roaming\CyberLink
[2012/05/05 18:18:28 | 000,000,000 | β€”D | C] – C:\Program Files (x86)\ESET

========== Files - Modified Within 30 Days ==========

[2012/05/07 16:13:38 | 004,731,392 | β€”- | M] (AVAST Software) – C:\Users\shalafi\Desktop\aswMBR.exe
[2012/05/07 16:10:24 | 000,595,456 | β€”- | M] (OldTimer Tools) – C:\Users\shalafi\Desktop\OTL.exe
[2012/05/07 16:02:02 | 000,000,342 | β€”- | M] () – C:\Windows\tasks\HPCeeScheduleForshalafi.job
[2012/05/07 16:00:00 | 000,000,830 | β€”- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/05/07 15:27:00 | 000,000,900 | β€”- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/05/07 03:27:00 | 000,000,896 | β€”- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/05/06 22:42:56 | 000,000,035 | β€”- | M] () – C:\Users\shalafi\Desktop\p-5dyPa639IrgIw.gif
[2012/05/06 18:22:21 | 000,002,021 | β€”- | M] () – C:\Users\shalafi\Desktop\modem.rtf
[2012/05/06 17:52:38 | 000,463,080 | β€”- | M] (CNET Download.com) – C:\Users\shalafi\Desktop\cnet2_mzcv_zip.exe
[2012/05/06 17:51:17 | 000,463,080 | β€”- | M] (CNET Download.com) – C:\Users\shalafi\Desktop\cnet2_CookieCrumbler_1_6_setup_exe.exe
[2012/05/06 17:48:02 | 000,096,394 | β€”- | M] () – C:\Users\shalafi\Desktop\iecv.zip
[2012/05/06 17:16:17 | 000,463,080 | β€”- | M] (CNET Download.com) – C:\Users\shalafi\Desktop\cnet2_dfsetup_exe.exe
[2012/05/06 17:12:16 | 001,717,640 | β€”- | M] (ConsumerSoft) – C:\Users\shalafi\Desktop\FlashCookieCleaner.exe
[2012/05/06 17:07:16 | 000,306,938 | β€”- | M] () – C:\Users\shalafi\Desktop\JS1.jpg
[2012/05/06 17:03:17 | 000,342,960 | β€”- | M] () – C:\Users\shalafi\Desktop\MICHELLE-5364702-1050-1400.jpg
[2012/05/06 07:38:19 | 000,778,834 | β€”- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/05/06 07:38:19 | 000,660,068 | β€”- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/05/06 07:38:19 | 000,120,996 | β€”- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/05/06 06:28:35 | 000,001,175 | β€”- | M] () – C:\Users\shalafi\Desktop\SyncBack.lnk
[2012/05/06 06:10:47 | 000,015,760 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/06 06:10:46 | 000,015,760 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/06 05:59:25 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/05/06 05:59:24 | 000,355,792 | β€”- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/05/06 05:58:55 | 3212,713,984 | -HS- | M] () – C:\hiberfil.sys
[2012/05/05 22:00:36 | 000,002,985 | β€”- | M] () – C:\Users\shalafi\Desktop\HiJackThis.lnk
[2012/05/05 20:13:39 | 000,001,111 | β€”- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/05 18:45:58 | 000,232,608 | β€”- | M] () – C:\Users\shalafi\Desktop\avira_antivir_antirootkit_en.exe
[2012/05/05 18:45:40 | 000,238,608 | β€”- | M] () – C:\Users\shalafi\Desktop\avira_registry_cleaner_en.exe
[2012/05/05 18:43:55 | 003,313,664 | β€”- | M] (Avira GmbH) – C:\Users\shalafi\Desktop\bootwizard.exe
[2012/05/05 08:28:48 | 000,002,342 | β€”- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/05/02 11:53:31 | 000,017,637 | β€”- | M] () – C:\Users\shalafi\Desktop\aubrey.jpg
[2012/05/01 12:27:55 | 000,017,268 | β€”- | M] () – C:\Users\shalafi\Desktop\1-VS_SmrEnt_Sat-Thurs.jpg
[2012/04/30 17:11:59 | 000,003,368 | β€”- | M] () – C:\bootsqm.dat
[2012/04/30 17:00:21 | 000,000,552 | β€”- | M] () – C:\Windows\tasks\PCDRScheduledMaintenance.job
[2012/04/16 17:33:01 | 000,033,950 | β€”- | M] () – C:\Users\shalafi\Desktop\05.jpg
[2012/04/16 17:30:15 | 000,044,972 | β€”- | M] () – C:\Users\shalafi\Desktop\2011_3_23_staci_noblett_4_347x509.jpg
[2012/04/16 17:29:48 | 000,036,461 | β€”- | M] () – C:\Users\shalafi\Desktop\2010_11_17_staci_noblett_3_347x509.jpg
[2012/04/16 17:28:24 | 000,019,449 | β€”- | M] () – C:\Users\shalafi\Desktop\2008_4_08_vikki_blows_3_250x380.jpg
[2012/04/16 17:25:52 | 000,020,848 | β€”- | M] () – C:\Users\shalafi\Desktop\lucy_06.jpg
[2012/04/16 17:25:18 | 000,047,754 | β€”- | M] () – C:\Users\shalafi\Desktop\02.jpg
[2012/04/16 17:17:28 | 000,069,030 | β€”- | M] () – C:\Users\shalafi\Desktop\article-2128587-128F8295000005DC-198_306x706.jpg
[2012/04/16 14:12:37 | 000,020,090 | β€”- | M] () – C:\Users\shalafi\Desktop\336x100_tv.jpg

========== Files Created - No Company Name ==========

[2012/05/06 22:42:57 | 000,020,090 | β€”- | C] () – C:\Users\shalafi\Desktop\336x100_tv.jpg
[2012/05/06 22:42:57 | 000,017,637 | β€”- | C] () – C:\Users\shalafi\Desktop\aubrey.jpg
[2012/05/06 22:42:57 | 000,017,268 | β€”- | C] () – C:\Users\shalafi\Desktop\1-VS_SmrEnt_Sat-Thurs.jpg
[2012/05/06 22:42:57 | 000,000,035 | β€”- | C] () – C:\Users\shalafi\Desktop\p-5dyPa639IrgIw.gif
[2012/05/06 18:22:21 | 000,002,021 | β€”- | C] () – C:\Users\shalafi\Desktop\modem.rtf
[2012/05/06 17:48:01 | 000,096,394 | β€”- | C] () – C:\Users\shalafi\Desktop\iecv.zip
[2012/05/06 17:07:07 | 000,306,938 | β€”- | C] () – C:\Users\shalafi\Desktop\JS1.jpg
[2012/05/06 17:03:12 | 000,342,960 | β€”- | C] () – C:\Users\shalafi\Desktop\MICHELE-5364702-1050-1400.jpg
[2012/05/06 06:28:35 | 000,001,175 | β€”- | C] () – C:\Users\shalafi\Desktop\SyncBack.lnk
[2012/05/05 22:00:36 | 000,002,985 | β€”- | C] () – C:\Users\shalafi\Desktop\HiJackThis.lnk
[2012/05/05 20:13:39 | 000,001,111 | β€”- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/05 18:45:57 | 000,232,608 | β€”- | C] () – C:\Users\shalafi\Desktop\avira_antivir_antirootkit_en.exe
[2012/05/05 18:45:34 | 000,238,608 | β€”- | C] () – C:\Users\shalafi\Desktop\avira_registry_cleaner_en.exe
[2012/04/30 17:11:59 | 000,003,368 | β€”- | C] () – C:\bootsqm.dat
[2012/04/16 17:32:58 | 000,033,950 | β€”- | C] () – C:\Users\shalafi\Desktop\05.jpg
[2012/04/16 17:30:12 | 000,044,972 | β€”- | C] () – C:\Users\shalafi\Desktop\2011_3_23_staci_noblett_4_347x509.jpg
[2012/04/16 17:29:47 | 000,036,461 | β€”- | C] () – C:\Users\shalafi\Desktop\2010_11_17_staci_noblett_3_347x509.jpg
[2012/04/16 17:28:22 | 000,019,449 | β€”- | C] () – C:\Users\shalafi\Desktop\2008_4_08_vikki_blows_3_250x380.jpg
[2012/04/16 17:25:50 | 000,020,848 | β€”- | C] () – C:\Users\shalafi\Desktop\lucy_06.jpg
[2012/04/16 17:25:14 | 000,047,754 | β€”- | C] () – C:\Users\shalafi\Desktop\02.jpg
[2012/04/16 17:17:26 | 000,069,030 | β€”- | C] () – C:\Users\shalafi\Desktop\article-2128587-128F8295000005DC-198_306x706.jpg
[2012/04/10 16:25:53 | 000,000,830 | β€”- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/01/27 22:38:59 | 000,000,096 | -HS- | C] () – C:\Windows\WSYS049.SYS
[2012/01/27 22:37:42 | 000,203,822 | β€”- | C] () – C:\Windows\Photo Pos Pro Uninstaller.exe
[2011/12/24 02:25:08 | 000,772,558 | β€”- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI

========== LOP Check ==========

[2012/05/07 16:23:45 | 000,000,000 | β€”D | M] – C:\Users\shalafi\AppData\Roaming\BitComet
[2012/05/06 17:57:47 | 000,000,000 | β€”D | M] – C:\Users\shalafi\AppData\Roaming\CapSystems
[2012/02/16 20:42:32 | 000,000,000 | β€”D | M] – C:\Users\shalafi\AppData\Roaming\OpenOffice.org
[2011/12/23 22:29:26 | 000,000,000 | β€”D | M] – C:\Users\shalafi\AppData\Roaming\Origin
[2012/01/27 22:36:22 | 000,000,000 | β€”D | M] – C:\Users\shalafi\AppData\Roaming\PhotoScape
[2011/12/04 22:06:42 | 000,000,000 | β€”D | M] – C:\Users\shalafi\AppData\Roaming\PictureMover
[2012/04/30 17:00:21 | 000,000,552 | β€”- | M] () – C:\Windows\Tasks\PCDRScheduledMaintenance.job
[2009/07/14 01:08:49 | 000,012,876 | β€”- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >
[2008/04/19 15:09:30 | 005,438,448 | β€”- | M] () – C:\bitcomet_setup42008.exe
[2011/09/11 01:57:02 | 015,582,616 | β€”- | M] (Totem Entertainment ) – C:\setup-dbabes-us[0].exe

< MD5 for: EXPLORER.EXE >
[2011/02/26 02:23:14 | 002,870,272 | β€”- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 01:19:21 | 002,616,320 | β€”- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | β€”- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 01:51:13 | 002,614,784 | β€”- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | β€”- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 01:33:07 | 002,614,784 | β€”- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | β€”- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | β€”- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 02:14:34 | 002,871,808 | β€”- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | β€”- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/03 02:19:07 | 002,868,224 | β€”- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | β€”- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | β€”- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 02:34:59 | 002,870,272 | β€”- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 01:49:47 | 002,613,248 | β€”- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 09:24:45 | 002,872,320 | β€”- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 02:38:38 | 002,870,272 | β€”- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 01:35:50 | 002,613,248 | β€”- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 21:39:10 | 002,868,224 | β€”- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 02:00:51 | 002,614,272 | β€”- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 02:26:45 | 002,870,784 | β€”- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/03 02:17:37 | 002,868,224 | β€”- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: SVCHOST.EXE >
[2012/04/04 15:56:38 | 000,199,240 | β€”- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | β€”- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | β€”- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 21:39:46 | 000,027,136 | β€”- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 21:39:46 | 000,027,136 | β€”- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 08:17:48 | 000,026,624 | β€”- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 08:17:48 | 000,026,624 | β€”- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 21:14:43 | 000,026,112 | β€”- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 21:39:48 | 000,030,208 | β€”- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 09:25:24 | 000,030,720 | β€”- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 09:25:24 | 000,030,720 | β€”- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2012/04/04 15:56:38 | 000,199,240 | β€”- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2010/11/20 09:25:30 | 000,390,656 | β€”- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 09:25:30 | 000,390,656 | β€”- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 21:39:52 | 000,389,120 | β€”- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/28 03:01:57 | 000,389,632 | β€”- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 02:24:40 | 000,389,632 | β€”- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
β€”β€”β€”β€”β€”

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: WDC WD6400AAKS-65A7B2 ATA Device
Partitions: 3
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 -
Interface type: USB
Media Type:
Model: Multi Flash Reader USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 - External hard disk media
Interface type: USB
Media Type: External hard disk media
Model: WD My Book 1130 USB Device
Partitions: 1
Status: OK
Status Info: 0

Partitions
β€”β€”β€”β€”β€”

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 0.00GB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 584.00GB
Starting Offset: 105938432
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 12.00GB
Starting Offset: 627430129664
Hidden sectors: 0


DeviceID: Disk #2, Partition #0
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 931.00GB
Starting Offset: 1048576
Hidden sectors: 0


< End of report >

OTL Extras logfile created on: 5/7/2012 4:17:26 PM - Run 1
OTL by OldTimer - Version 3.2.42.3 Folder = C:\Users\shalafi\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.99 Gb Total Physical Memory | 1.84 Gb Available Physical Memory | 46.03% Memory free
7.98 Gb Paging File | 5.87 Gb Available in Paging File | 73.59% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 584.24 Gb Total Space | 112.14 Gb Free Space | 19.19% Space Free | Partition Type: NTFS
Drive D: | 11.83 Gb Total Space | 2.16 Gb Free Space | 18.27% Space Free | Partition Type: NTFS
Drive G: | 931.48 Gb Total Space | 316.25 Gb Free Space | 33.95% Space Free | Partition Type: NTFS

Computer Name: SHALAFI-PC | User Name: shalafi | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-165932115-1053801288-1729283660-1000\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{08771F26-CD40-4624-A64F-758C714B1167}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{31A7CC9E-4CAB-42CE-AF7C-984004581AF9}" = lport=10243 | protocol=6 | dir=in | app=system |
"{3A7899A0-3695-4151-8C44-1190F052B5AE}" = lport=139 | protocol=6 | dir=in | app=system |
"{3B2057E6-66B3-499E-820B-E5442B69D99F}" = lport=138 | protocol=17 | dir=in | app=system |
"{4033084E-83A6-4EAF-A6DC-3A4AA63BC26E}" = rport=10243 | protocol=6 | dir=out | app=system |
"{4366916D-DE4A-4117-8338-40757044E6AE}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{50B687C0-E920-423B-9D5F-84E6BD06356C}" = lport=445 | protocol=6 | dir=in | app=system |
"{5E7B0AC0-341F-4E94-8742-422E200C0CD8}" = rport=445 | protocol=6 | dir=out | app=system |
"{69073B86-E1F6-4B46-ADAE-E335A60C5D39}" = rport=139 | protocol=6 | dir=out | app=system |
"{709B0271-EF8F-4089-834A-F62B559043F1}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{81CB7988-6434-4FC6-B930-B5EECD66A803}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{93159674-F573-4629-88FD-1AAEB4C3E924}" = lport=137 | protocol=17 | dir=in | app=system |
"{A3ADA35D-66F8-4464-A695-4F0D4364C936}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A77B4EB3-F82C-4E38-A6E0-EB69509FD333}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C355F713-F09E-4A8A-8C90-63F5889A9B91}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{C86A3B29-0F9A-4233-A64C-36E697AA5A2F}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{CA3ECD29-E1B0-4EB8-99AC-1FB9D837A71C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CD0D7237-04EA-444F-AFB1-51DE0B410F4B}" = rport=137 | protocol=17 | dir=out | app=system |
"{D86D6551-36BA-4CC6-95F9-A7FEC4F7E8F1}" = lport=2869 | protocol=6 | dir=in | app=system |
"{F3CB0669-78E0-4BCD-B5FE-D9EB53368CE9}" = rport=138 | protocol=17 | dir=out | app=system |
"{FFA9B6B8-AC07-433B-9251-191EA9CCDCEF}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{07FA4C70-AF99-43D9-824D-6A6D02D3E8C2}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartvideo.exe |
"{195A1255-93E0-45EF-A5F3-3D0D92BC08C8}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{2FC5BFC5-B199-4B39-9433-6A8936C387D0}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{365EE6EC-A07A-42D6-A9FC-2F0034C42BB6}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{37F9F03F-A43C-468D-B6E0-160C1861B04E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{406C3407-132A-4F37-A5F9-7DF7992EB220}" = protocol=17 | dir=in | app=c:\program files (x86)\att-hsi\mccibrowser.exe |
"{40F0BDB1-50F4-42BC-9DD4-467D22B9A7FB}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{42B435A5-E94E-4705-AD32-03596A6F337E}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe |
"{5064B57F-CB69-4942-A1DC-51033D35C3D3}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{52C3378C-86C5-4CC8-AC22-B2C170726552}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{5C1B52CC-7CA2-476F-951F-D580E135467B}" = protocol=6 | dir=out | app=system |
"{6FCB6D07-A2B2-4D10-928F-12F62E0E3EC1}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\tsmagent.exe |
"{75F65EAE-11D6-4452-9901-7FD1FEEB8A94}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7620BC39-DCA6-4689-879F-8E5918C71975}" = protocol=17 | dir=in | app=c:\program files (x86)\att-hsi\mccibrowser.exe |
"{7BB069BE-3DAE-4FA1-ABC4-683941E4E524}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{851F7DE3-C26A-42F0-A8BC-8DB596E7CD19}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{8791075A-AA70-4916-8BF6-F9F29FEDE156}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{8D3C7335-EE91-4858-A38A-04C57F976C12}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartmusic.exe |
"{90B69DE5-7B10-4FDB-9617-8DA5776758AD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{924D3B57-F0DE-44B1-8EF7-CE40E8EC7FEB}" = protocol=17 | dir=in | app=c:\program files (x86)\bitcomet\bitcomet.exe |
"{951430C0-AE78-410F-98DF-0977556C82C5}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{9687874F-E5E9-4D09-B7A8-7F3FD5A52852}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{9A698B24-5C87-4C09-9670-DEBB67921B48}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{9DD2899A-F6FF-473A-A0A2-2EDE84069DE3}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{9DDD958C-D91C-4A37-A872-CFF630D8AF02}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{AB3E7F33-B656-4306-848F-83E450FC0D59}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{B1160DEA-1F70-42B5-A0FC-B558E8E95CA7}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{B1EC8E1A-7F24-42AE-ADE5-2832C71F0722}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartvideo.exe |
"{B3E9BA24-CF8D-4502-8F49-F91246FEFCBC}" = protocol=6 | dir=in | app=c:\program files (x86)\att-hsi\mccibrowser.exe |
"{B6CB10E6-D922-4A86-B548-7BD131E263EB}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\kernel\clml\clmlsvc.exe |
"{B7D0F9B1-D038-4566-894F-F6D141A0ED1B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{BDB4CE9B-FC1E-4797-9919-F93560A1C587}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BFDA9BC8-DA41-45ED-9AA4-9C0989C2B210}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C3072C61-7E40-4FBB-AF0C-1F7919C5729E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{C65C9444-0B9F-491B-AED3-5DCAB8E164A7}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\tsmagent.exe |
"{C963B0EB-8440-4A8C-A532-D8BD2EBA1CED}" = protocol=6 | dir=in | app=c:\program files (x86)\att-hsi\mccibrowser.exe |
"{D0B59947-7727-464C-A8A1-AD5E48C8E95D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D95A27BB-D50A-4DC5-AE3B-46B03887DFB2}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\clml\clmlsvc.exe |
"{D98DE3FE-7EEA-4404-B3F4-EA6BA4208295}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartphoto.exe |
"{E4ABC4EF-DD1E-4F17-856C-F74D7D1BA845}" = protocol=6 | dir=in | app=c:\program files (x86)\bitcomet\bitcomet.exe |
"{F7AD9B0C-39F7-4265-BBA3-A31A0A1F27E8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F95FBB81-1F32-4E42-963D-E9AFEADBA047}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartmusic.exe |
"{FE0A9F62-DF28-4070-BB86-D4DAF36301BB}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"TCP Query User{5C2D4AB2-E453-46E1-97B6-D93BD16195D5}C:\users\shalafi\appdata\local\vghd\bin\virtuagirl_downloader.exe" = protocol=6 | dir=in | app=c:\users\shalafi\appdata\local\vghd\bin\virtuagirl_downloader.exe |
"TCP Query User{D8A9F181-F6DE-4526-8980-475174F5E02F}C:\users\shalafi\appdata\local\vghd\bin\virtuagirl_downloader.exe" = protocol=6 | dir=in | app=c:\users\shalafi\appdata\local\vghd\bin\virtuagirl_downloader.exe |
"UDP Query User{8C9AFF09-098D-4613-B8F1-3B60A8BA96CD}C:\users\shalafi\appdata\local\vghd\bin\virtuagirl_downloader.exe" = protocol=17 | dir=in | app=c:\users\shalafi\appdata\local\vghd\bin\virtuagirl_downloader.exe |
"UDP Query User{D584FE26-F800-415C-8C43-51A00360F561}C:\users\shalafi\appdata\local\vghd\bin\virtuagirl_downloader.exe" = protocol=17 | dir=in | app=c:\users\shalafi\appdata\local\vghd\bin\virtuagirl_downloader.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{26280024-DFB7-4967-90DB-7F9C6660D01E}" = HP MediaSmart SmartMenu
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{6CFB1B20-ECAE-488F-9FFB-6AD420882E71}" = iTunes
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"LSI Soft Modem" = LSI PCI-SV92EX Soft Modem
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"OfficeTrial" = Microsoft Office Home and Student 60 day trial
"PC-Doctor for Windows" = Hardware Diagnostic Tools

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1896E712-2B3D-45eb-BCE9-542742A51032}" = PictureMover
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Javaβ„’ 6 Update 31
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = HP MediaSmart Movie Themes
"{37D59F62-2FC7-412D-AA55-3D0E6A9BD9C7}" = Microsoft Live Search Toolbar
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = PowerRecover
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4F46FDB9-B906-47BF-B3D5-C62E01B3C5EE}" = HP Support Assistant
"{5B295588-59C1-4386-9F85-BB4BEDCB0D22}" = HP Customer Experience Enhancements
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{83BEEFB4-8C28-4F4F-8A9D-E0D1ADCE335B}" = The Sims Medieval
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DEF9686-CCB2-47B7-BF83-B49EA21FA016}" = HP MediaSmart Demo
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B53E61D7-7C80-40DF-82D2-CF5390D6D20A}" = HP Advisor
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information
"{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}" = Activate Norton Online Backup
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C611CF88-969D-43E6-A877-D6D6439DD081}" = HP Remote Solution
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{D46D081B-F60E-467E-A7C4-117B70D76731}" = HP Update
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DD6C316A-FE75-4FBB-9D22-4C1920232B72}" = LightScribe System Software
"{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F3B912F5-EB57-45AA-B3D1-EB532BCF6EF8}" = HP Setup
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"Adobe AIR" = Adobe AIR
"Avira AntiVir Desktop" = Avira Free Antivirus
"BitComet" = BitComet 1.26
"CookieCrumbler_is1" = CookieCrumbler
"ESET Online Scanner" = ESET Online Scanner v3
"Google Chrome" = Google Chrome
"Homepage Protection" = Homepage Protection
"HP Remote Solution" = HP Remote Solution
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = HP MediaSmart Movie Themes
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"McAfee Security Scan" = McAfee Security Scan Plus
"Mozilla Firefox 9.0.1 (x86 en-US)" = Mozilla Firefox 9.0.1 (x86 en-US)
"Origin" = Origin
"Photo Pos Pro" = Photo Pos Pro
"PhotoScape" = PhotoScape
"RealPlayer 15.0" = RealPlayer
"SyncBack_is1" = SyncBack
"WildTangent hp Master Uninstall" = HP Games

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-165932115-1053801288-1729283660-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"VirtuaGirl_is1" = VirtuaGirl version 1.0.6.99

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/4/2012 12:40:06 AM | Computer Name = shalafi-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 6100

Error - 1/7/2012 3:56:51 AM | Computer Name = shalafi-PC | Source = Application Hang | ID = 1002
Description = The program iTunes.exe version 10.5.1.42 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 7ac Start
Time: 01cccd0b9a1c725d Termination Time: 87 Application Path: C:\Program Files (x86)\iTunes\iTunes.exe

Report
Id:

Error - 1/16/2012 4:46:57 PM | Computer Name = shalafi-PC | Source = Application Hang | ID = 1002
Description = The program vghd.exe version 1.0.6.99 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: bfc Start Time:
01ccd29e9ebc7207 Termination Time: 11 Application Path: C:\Users\shalafi\AppData\Local\vghd\bin\vghd.exe

Report
Id: 338864a1-4083-11e1-91eb-4061860fe3b4

Error - 1/27/2012 9:24:19 PM | Computer Name = shalafi-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "G:\New reinst\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifest.

Error - 1/27/2012 11:57:13 PM | Computer Name = shalafi-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "G:\allprograms\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifest.

Error - 1/29/2012 6:59:34 AM | Computer Name = shalafi-PC | Source = Application Hang | ID = 1002
Description = The program iTunes.exe version 10.5.1.42 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 20f8 Start
Time: 01ccde74489c883c Termination Time: 177 Application Path: C:\Program Files (x86)\iTunes\iTunes.exe

Report
Id:

Error - 2/3/2012 7:57:49 PM | Computer Name = shalafi-PC | Source = Application Hang | ID = 1002
Description = The program vghd.exe version 1.0.6.99 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 19a4 Start Time:
01cce2316dda339e Termination Time: 8 Application Path: C:\Users\shalafi\AppData\Local\vghd\bin\vghd.exe

Report
Id: d861b824-4ec2-11e1-9931-4061860fe3b4

Error - 3/1/2012 5:05:24 PM | Computer Name = shalafi-PC | Source = ESENT | ID = 215
Description = WinMail (2992) WindowsMail0: The backup has been stopped because it
was halted by the client or the connection with the client failed.

Error - 3/19/2012 1:17:27 AM | Computer Name = shalafi-PC | Source = Application Error | ID = 1000
Description = Faulting application name: vghd.exe, version: 1.0.6.99, time stamp:
0x4ec5204f Faulting module name: MSVCR100.dll, version: 10.0.40219.1, time stamp:
0x4d5f0c22 Exception code: 0x40000015 Fault offset: 0x0008d6fd Faulting process id:
0xa3f4 Faulting application start time: 0x01cd055267060fe6 Faulting application path:
C:\Users\shalafi\AppData\Local\vghd\bin\vghd.exe Faulting module path: C:\Users\shalafi\AppData\Local\vghd\bin\MSVCR100.dll
Report
Id: d1157817-7182-11e1-979a-4061860fe3b4

Error - 3/23/2012 11:29:45 PM | Computer Name = shalafi-PC | Source = Application Hang | ID = 1002
Description = The program vghd.exe version 1.0.6.99 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: e078 Start Time:
01cd096e47dd7c04 Termination Time: 6 Application Path: C:\Users\shalafi\AppData\Local\vghd\bin\vghd.exe

Report
Id: 9347228e-7561-11e1-979a-4061860fe3b4

[ Hewlett-Packard Events ]
Error - 2/13/2012 6:00:17 PM | Computer Name = shalafi-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Object reference not set to an instance of an object. HPSF at
HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender, RoutedEventArgs
e) at System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object target, RoutedEventArgs
routedEventArgs) at System.Windows.EventRoute.InvokeHandlersImpl(Object source,
RoutedEventArgs args, Boolean reRaised) at System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) at System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) at System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) at System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) at MS.Internal.LoadedOrUnloadedOperation.DoWork() at System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()

at System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() at System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) at System.Windows.Media.MediaContext.RenderMessageHandler(Object
resizedCompositionTarget) at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)


Error - 2/27/2012 5:16:00 PM | Computer Name = shalafi-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Object reference not set to an instance of an object. HPSF at
HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender, RoutedEventArgs
e) at System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object target, RoutedEventArgs
routedEventArgs) at System.Windows.EventRoute.InvokeHandlersImpl(Object source,
RoutedEventArgs args, Boolean reRaised) at System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) at System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) at System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) at System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) at MS.Internal.LoadedOrUnloadedOperation.DoWork() at System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()

at System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() at System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) at System.Windows.Media.MediaContext.AnimatedRenderMessageHandler(Object
resizedCompositionTarget) at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)


Error - 3/5/2012 6:06:28 PM | Computer Name = shalafi-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Object reference not set to an instance of an object. HPSF at
HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender, RoutedEventArgs
e) at System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object target, RoutedEventArgs
routedEventArgs) at System.Windows.EventRoute.InvokeHandlersImpl(Object source,
RoutedEventArgs args, Boolean reRaised) at System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) at System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) at System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) at System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) at MS.Internal.LoadedOrUnloadedOperation.DoWork() at System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()

at System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() at System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) at System.Windows.Media.MediaContext.RenderMessageHandler(Object
resizedCompositionTarget) at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)


Error - 3/5/2012 6:06:40 PM | Computer Name = shalafi-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Exception has been thrown by the target of an invocation. mscorlib

at System.RuntimeMethodHandle._InvokeMethodFast(Object target, Object[] arguments,
SignatureStruct& sig, MethodAttributes methodAttributes, RuntimeTypeHandle typeOwner)

at System.RuntimeMethodHandle.InvokeMethodFast(Object target, Object[] arguments,
Signature sig, MethodAttributes methodAttributes, RuntimeTypeHandle typeOwner)
at System.Reflection.RuntimeMethodInfo.Invoke(Object obj, BindingFlags invokeAttr,
Binder binder, Object[] parameters, CultureInfo culture, Boolean skipVisibilityChecks)

at System.Delegate.DynamicInvokeImpl(Object[] args) at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)
Object
reference not set to an instance of an object.

Error - 3/26/2012 5:01:31 PM | Computer Name = shalafi-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Object reference not set to an instance of an object. HPSF at
HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender, RoutedEventArgs
e) at System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object target, RoutedEventArgs
routedEventArgs) at System.Windows.EventRoute.InvokeHandlersImpl(Object source,
RoutedEventArgs args, Boolean reRaised) at System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) at System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) at System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) at System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) at MS.Internal.LoadedOrUnloadedOperation.DoWork() at System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()

at System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() at System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) at System.Windows.Media.MediaContext.RenderMessageHandler(Object
resizedCompositionTarget) at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)


Error - 4/4/2012 9:34:05 PM | Computer Name = shalafi-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Object reference not set to an instance of an object. HPSF at
HPAssistant.Pages.MaintainAnalyzing.MaintainAnalyzing_Unloaded(Object sender, RoutedEventArgs
e) at System.Windows.RoutedEventHandlerInfo.InvokeHandler(Object target, RoutedEventArgs
routedEventArgs) at System.Windows.EventRoute.InvokeHandlersImpl(Object source,
RoutedEventArgs args, Boolean reRaised) at System.Windows.UIElement.RaiseEventImpl(DependencyObject
sender, RoutedEventArgs args) at System.Windows.UIElement.RaiseEvent(RoutedEventArgs
e) at System.Windows.BroadcastEventHelper.BroadcastEvent(DependencyObject root,
RoutedEvent routedEvent) at System.Windows.BroadcastEventHelper.BroadcastUnloadedEvent(Object
root) at MS.Internal.LoadedOrUnloadedOperation.DoWork() at System.Windows.Media.MediaContext.FireLoadedPendingCallbacks()

at System.Windows.Media.MediaContext.FireInvokeOnRenderCallbacks() at System.Windows.Media.MediaContext.RenderMessageHandlerCore(Object
resizedCompositionTarget) at System.Windows.Media.MediaContext.AnimatedRenderMessageHandler(Object
resizedCompositionTarget) at System.Windows.Threading.ExceptionWrapper.InternalRealCall(Delegate
callback, Object args, Boolean isSingleParameter) at System.Windows.Threading.ExceptionWrapper.TryCatchWhen(Object
source, Delegate callback, Object args, Boolean isSingleParameter, Delegate catchHandler)


[ Media Center Events ]
Error - 1/30/2012 4:51:23 PM | Computer Name = shalafi-PC | Source = MCUpdate | ID = 0
Description = 3:51:22 PM - Failed to retrieve SportsSchedule (Error: Unable to connect
to the remote server)

Error - 1/30/2012 5:52:11 PM | Computer Name = shalafi-PC | Source = MCUpdate | ID = 0
Description = 4:52:09 PM - Failed to retrieve SportsSchedule (Error: Unable to connect
to the remote server)

Error - 2/1/2012 2:29:51 AM | Computer Name = shalafi-PC | Source = MCUpdate | ID = 0
Description = 1:29:51 AM - Error connecting to the internet. 1:29:51 AM - Unable
to contact server..

Error - 2/1/2012 2:30:22 AM | Computer Name = shalafi-PC | Source = MCUpdate | ID = 0
Description = 1:30:20 AM - Error connecting to the internet. 1:30:20 AM - Unable
to contact server..

Error - 5/5/2012 2:04:54 AM | Computer Name = shalafi-PC | Source = MCUpdate | ID = 0
Description = 2:04:54 AM - Failed to retrieve Directory (Error: The underlying connection
was closed: Could not establish trust relationship for the SSL/TLS secure channel.)


Error - 5/5/2012 2:04:55 AM | Computer Name = shalafi-PC | Source = MCUpdate | ID = 0
Description = 2:04:55 AM - Failed to retrieve NetTV (Error: The underlying connection
was closed: Could not establish trust relationship for the SSL/TLS secure channel.)


Error - 5/5/2012 2:04:55 AM | Computer Name = shalafi-PC | Source = MCUpdate | ID = 0
Description = 2:04:55 AM - Failed to retrieve MCEClientUX (Error: The underlying
connection was closed: Could not establish trust relationship for the SSL/TLS secure
channel.)

Error - 5/5/2012 2:04:55 AM | Computer Name = shalafi-PC | Source = MCUpdate | ID = 0
Description = 2:04:55 AM - Failed to retrieve SportsSchedule (Error: The underlying
connection was closed: Could not establish trust relationship for the SSL/TLS secure
channel.)

Error - 5/5/2012 2:04:56 AM | Computer Name = shalafi-PC | Source = MCUpdate | ID = 0
Description = 2:04:55 AM - Failed to retrieve SportsV2 (Error: The underlying connection
was closed: Could not establish trust relationship for the SSL/TLS secure channel.)


Error - 5/5/2012 2:05:03 AM | Computer Name = shalafi-PC | Source = MCUpdate | ID = 0
Description = 2:04:56 AM - Failed to retrieve Broadband (Error: The underlying connection
was closed: Could not establish trust relationship for the SSL/TLS secure channel.)


[ System Events ]
Error - 4/24/2012 4:59:52 PM | Computer Name = shalafi-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume HP.

Error - 4/24/2012 5:00:32 PM | Computer Name = shalafi-PC | Source = Service Control Manager | ID = 7022
Description = The Windows Search service hung on starting.

Error - 4/24/2012 5:03:04 PM | Computer Name = shalafi-PC | Source = Service Control Manager | ID = 7022
Description = The Windows Update service hung on starting.

Error - 4/25/2012 6:19:45 AM | Computer Name = shalafi-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume HP.

Error - 4/26/2012 6:20:30 AM | Computer Name = shalafi-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume HP.

Error - 4/27/2012 6:21:27 AM | Computer Name = shalafi-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume HP.

Error - 4/28/2012 6:25:32 AM | Computer Name = shalafi-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume HP.

Error - 4/30/2012 5:04:01 PM | Computer Name = shalafi-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume HP.

Error - 5/5/2012 2:57:03 AM | Computer Name = shalafi-PC | Source = Service Control Manager | ID = 7024
Description = The Avira Realtime Protection service terminated with service-specific
error %%306.

Error - 5/5/2012 3:06:06 AM | Computer Name = shalafi-PC | Source = Service Control Manager | ID = 7024
Description = The Avira Realtime Protection service terminated with service-specific
error %%306.


< End of report >

aswMBR version 0.9.9.1665 CopyrightΒ© 2011 AVAST Software
Run date: 2012-05-07 16:36:17
—————————–
16:36:17.763 OS Version: Windows x64 6.1.7601 Service Pack 1
16:36:17.763 Number of processors: 2 586 0x170A
16:36:17.763 ComputerName: SHALAFI-PC UserName: shalafi
16:36:19.760 Initialize success
16:36:47.685 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
16:36:47.685 Disk 0 Vendor: WDC_WD6400AAKS-65A7B2 01.03B01 Size: 610480MB BusType: 3
16:36:47.716 Disk 0 MBR read successfully
16:36:47.716 Disk 0 MBR scan
16:36:47.716 Disk 0 unknown MBR code
16:36:47.731 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
16:36:47.731 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 598262 MB offset 206911
16:36:47.778 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 12115 MB offset 1225449472
16:36:47.809 Disk 0 scanning C:\Windows\system32\drivers
16:36:52.926 Service scanning
16:37:04.579 Modules scanning
16:37:04.579 Disk 0 trace - called modules:
16:37:04.595 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS intelide.sys PCIIDEX.SYS hal.dll atapi.sys
16:37:04.611 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80048c24f0]
16:37:04.611 3 CLASSPNP.SYS[fffff8800194c43f] -> nt!IofCallDriver -> [0xfffffa8004498520]
16:37:04.611 5 ACPI.sys[fffff88000f897a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004491060]
16:37:04.626 Scan finished successfully
16:37:45.030 Disk 0 MBR has been saved successfully to "C:\Users\shalafi\Desktop\MBR.dat"
16:37:45.030 The log file has been saved successfully to "C:\Users\shalafi\Desktop\aswMBR.txt"


aswMBR version 0.9.9.1665 CopyrightΒ© 2011 AVAST Software
Run date: 2012-05-07 16:41:36
—————————–
16:41:36.548 OS Version: Windows x64 6.1.7601 Service Pack 1
16:41:36.548 Number of processors: 2 586 0x170A
16:41:36.548 ComputerName: SHALAFI-PC UserName: shalafi
16:41:38.694 Initialize success
16:43:35.374 AVAST engine defs: 12050701
16:44:51.045 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
16:44:51.049 Disk 0 Vendor: WDC_WD6400AAKS-65A7B2 01.03B01 Size: 610480MB BusType: 3
16:44:51.073 Disk 0 MBR read successfully
16:44:51.077 Disk 0 MBR scan
16:44:51.086 Disk 0 unknown MBR code
16:44:51.099 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
16:44:51.114 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 598262 MB offset 206911
16:44:51.145 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 12115 MB offset 1225449472
16:44:51.180 Disk 0 scanning C:\Windows\system32\drivers
16:44:59.917 Service scanning
16:45:18.864 Modules scanning
16:45:18.878 Disk 0 trace - called modules:
16:45:18.886
16:45:20.679 AVAST engine scan C:\Windows
16:45:23.933 AVAST engine scan C:\Windows\system32
16:47:34.454 AVAST engine scan C:\Windows\system32\drivers
16:47:47.372 AVAST engine scan C:\Users\shalafi
16:51:57.425 Disk 0 MBR has been saved successfully to "C:\Users\shalafi\Desktop\MBR.dat"
16:51:57.432 The log file has been saved successfully to "C:\Users\shalafi\Desktop\aswMBR.txt"

Attachments:

Hi cjk,

I notice you have two anti-viruses - Avira AntiVir and McAfee Security Scan Plus - installed on your PC. Using more than one anti-virus overall weakens the security of your PC because the programs conflict and can cause all manner of problems. Please remove one of them before continuing.

I also see that you have BitComet installed, which is considered peer-to-peer file sharing software. We do not pass judgment on file sharing, but we must warn you of the potential dangers of using this kind of software. Even if you are using a P2P program that is deemed safe, it is only the program that is safe. Any files that you receive using a "safe" P2P program may be infected with malware. The malware writers use P2P file-sharing as a major conduit to spread infected files. You can read more about the dangers of P2P programs here. Please do not use BitComet until it is determined that your PC is free of infection.

Please familiarize yourself with the following instructions before running this next program so that you know what to expect:

  • ComboFix

    Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouse click ComboFix's window whilst it's running. That may cause it to stall.


    β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI