Thank you so much for your time and help! My son has been driving me crazy over this.
I ran Tdsskiller and it found nothing and I couldn't find a log afterwards.
Here is the OTL.txt
OTL logfile created on: 5/9/2012 12:43:47 AM - Run 1
OTL by OldTimer - Version 3.2.42.3 Folder = C:\Users\FunFun\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.26 Gb Available Physical Memory | 75.47% Memory free
7.40 Gb Paging File | 6.29 Gb Available in Paging File | 84.96% Paging File free
Paging file location(s): c:\pagefile.sys 4605 4605 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 283.02 Gb Total Space | 59.06 Gb Free Space | 20.87% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 7.08 Gb Free Space | 47.23% Space Free | Partition Type: NTFS
Computer Name: FUNFUN-PC | User Name: FunFun | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\FunFun\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Ad-Aware Antivirus\Engine\SBAMSvc.exe (Sunbelt Software)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (RPCER) Remote Procedure Call (HNM) – C:\Program Files\Common Files\ODBC\comp.exe File not found
SRV:
64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV:
64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV:
64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe ()
SRV:
64bit: - (AERTFilters) – C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)
SRV:
64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Ad-Aware Service) – C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe (Lavasoft Limited)
SRV - (Giraffic) – C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe (Giraffic)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (SBAMSvc) – C:\Program Files (x86)\Ad-Aware Antivirus\Engine\SBAMSvc.exe (Sunbelt Software)
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files (x86)\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (DAUpdaterSvc) – C:\Program Files (x86)\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (WindowBlinds) – C:\Program Files (x86)\Stardock\Object Desktop\WindowBlinds\VistaSrv.exe (Stardock Corporation)
SRV - (hnmsvc) – c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe (Dell Inc.)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files (x86)\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys ()
DRV:
64bit: - (NisDrv) – C:\Windows\SysNative\DRIVERS\NisDrvWFP.sys ()
DRV:
64bit: - (sptd) – C:\Windows\SysNative\Drivers\sptd.sys ()
DRV:
64bit: - (atksgt) – C:\Windows\SysNative\DRIVERS\atksgt.sys ()
DRV:
64bit: - (lirsgt) – C:\Windows\SysNative\DRIVERS\lirsgt.sys ()
DRV:
64bit: - (R300) – C:\Windows\SysNative\DRIVERS\atikmdag.sys ()
DRV:
64bit: - (atikmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys ()
DRV:
64bit: - (amdkmdag) – C:\Windows\SysNative\DRIVERS\atikmdag.sys ()
DRV:
64bit: - (amdkmdap) – C:\Windows\SysNative\DRIVERS\atikmpag.sys ()
DRV:
64bit: - (sbapifs) – C:\Windows\SysNative\DRIVERS\sbapifs.sys ()
DRV:
64bit: - (SBRE) – C:\Windows\SysNative\drivers\SBREdrv.sys ()
DRV:
64bit: - (SbFw) – C:\Windows\SysNative\drivers\SbFw.sys ()
DRV:
64bit: - (SbTis) – C:\Windows\SysNative\drivers\sbtis.sys ()
DRV:
64bit: - (sbhips) – C:\Windows\SysNative\drivers\sbhips.sys ()
DRV:
64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdLH6.sys ()
DRV:
64bit: - (SBFWIMCLMP) – C:\Windows\SysNative\DRIVERS\SBFWIM.sys ()
DRV:
64bit: - (SBFWIMCL) – C:\Windows\SysNative\DRIVERS\sbfwim.sys ()
DRV:
64bit: - (trackcam) – C:\Windows\SysNative\DRIVERS\trackcam.sys ()
DRV:
64bit: - (vaxscsi) – C:\Windows\SysNative\Drivers\vaxscsi.sys ()
DRV:
64bit: - (GEARAspiWDM) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys ()
DRV:
64bit: - (xusb21) – C:\Windows\SysNative\DRIVERS\xusb21.sys ()
DRV:
64bit: - (RTL8169) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys ()
DRV:
64bit: - (mcdbus) – C:\Windows\SysNative\DRIVERS\mcdbus.sys ()
DRV:
64bit: - (NPF) – C:\Windows\SysNative\drivers\npf.sys ()
DRV:
64bit: - (Packet) – C:\Windows\SysNative\DRIVERS\packet.sys ()
DRV:
64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys ()
DRV:
64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys ()
DRV:
64bit: - (xnacc) – C:\Windows\SysNative\DRIVERS\xnacc.sys ()
DRV:
64bit: - (e1express) Intel® – C:\Windows\SysNative\DRIVERS\e1e6032e.sys ()
DRV:
64bit: - (PxHlpa64) – C:\Windows\SysNative\Drivers\PxHlpa64.sys ()
DRV - (SBRE) – C:\Windows\SysWOW64\drivers\SBREDrv.sys (Sunbelt Software)
DRV - (SecDrv) – C:\Windows\SysWOW64\drivers\SECDRV.SYS (Macrovision Europe Ltd)
DRV - (mcdbus) – C:\Windows\SysWOW64\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (NPF) – C:\Windows\SysWOW64\drivers\npf.sys (CACE Technologies)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0B4A10D1-FBD6-451d-BFDA-F03252B05984}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{0B4A10D1-FBD6-451d-BFDA-F03252B05984}: "URL" =
http://slirsredirect.search.aol.com/redire…mrud=11-05-2010
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT1060933
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{0B4A10D1-FBD6-451d-BFDA-F03252B05984}: "URL" =
http://slirsredirect.search.aol.com/redire…mrud=11-05-2010
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT1060933
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "
https://www.google.com"
FF - user.js..browser.startup.homepage: "
https://www.google.com"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@idsoftware.com/QuakeLive: C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+®,version=1.6.2.100: C:\Program Files (x86)\NOS\bin\np_gp.dll (NOS Microsystems Ltd.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.669: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.669: c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.669: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.669: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.669: c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Users\FunFun\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll (Octoshape ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/11/15 06:07:03 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/05/06 23:45:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/08 15:57:47 | 000,000,000 | —D | M]
[2011/07/13 12:41:29 | 000,000,000 | —D | M] (No name found) – C:\Users\FunFun\AppData\Roaming\Mozilla\Extensions
[2009/09/02 17:07:33 | 000,000,000 | —D | M] (No name found) – C:\Users\FunFun\AppData\Roaming\Mozilla\Extensions\[removed]
[2012/05/09 00:36:03 | 000,000,000 | —D | M] (No name found) – C:\Users\FunFun\AppData\Roaming\Mozilla\Firefox\Profiles\9ddjy4fl.default\extensions
[2011/12/06 07:59:09 | 000,000,000 | —D | M] (No name found) – C:\Users\FunFun\AppData\Roaming\Mozilla\Firefox\Profiles\dje8u448.default\extensions
[2010/05/30 08:28:03 | 000,000,000 | —D | M] (No name found) – C:\Users\FunFun\AppData\Roaming\Mozilla\Firefox\Profiles\dje8u448.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/12/06 07:59:09 | 000,000,000 | —D | M] (CouponAlert) – C:\Users\FunFun\AppData\Roaming\Mozilla\Firefox\Profiles\dje8u448.default\extensions\2pffxtbr@CouponAlert_2p.com
[2010/05/30 08:28:03 | 000,000,000 | —D | M] (No name found) – C:\Users\FunFun\AppData\Roaming\Mozilla\Firefox\Profiles\dje8u448.default\extensions\staged-xpis
[2012/05/06 23:45:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/05/07 00:02:01 | 000,523,514 | —- | M] () (No name found) – C:\USERS\FUNFUN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\9DDJY4FL.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
[2012/04/20 20:19:34 | 000,097,208 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/03/18 13:32:12 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npCouponPrinter.dll
[2011/11/10 06:54:13 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/03/18 13:32:14 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npMozCouponPrinter.dll
[2012/04/20 20:18:25 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/04/20 20:18:25 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\FunFun\AppData\Local\Google\Chrome\Application\17.0.963.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\FunFun\AppData\Local\Google\Chrome\Application\17.0.963.79\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\FunFun\AppData\Local\Google\Chrome\Application\17.0.963.79\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\FunFun\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\plugins/avgnpss.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U30 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: downloadUpdater (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
CHR - plugin: downloadUpdater2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: getPlusPlus for Adobe 162100 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np_gp.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\FunFun\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\FunFun\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1101262-0-npoctoshape.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: QUAKE LIVE (Enabled) = C:\ProgramData\id Software\QuakeLive\npquakezero.dll
CHR - plugin: Google Update (Enabled) = C:\Users\FunFun\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\FunFun\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: Google Search = C:\Users\FunFun\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\FunFun\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: AVG Safe Search = C:\Users\FunFun\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1901_0\
CHR - Extension: Gmail = C:\Users\FunFun\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\
O1 HOSTS File: ([2012/04/06 19:55:19 | 000,000,822 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (SMTTB2009 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files (x86)\HyperCam Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (BigSeekPro Toolbar) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files (x86)\BigSeekPro Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (HyperCam Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files (x86)\HyperCam Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (BigSeekPro Toolbar) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files (x86)\BigSeekPro Toolbar\tbcore3.dll ()
O4:
64bit: - HKLM..\Run: [] File not found
O4:
64bit: - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
O4:
64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Ad-Aware Antivirus] C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher.exe (Lavasoft Limited)
O4 - HKLM..\Run: [Ad-Aware Browsing Protection] C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Lavasoft)
O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [VeohPlugin] C:\Program Files (x86)\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks)
O4 - Startup: C:\Users\FunFun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O4 - Startup: C:\Users\FunFun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\wpclsp.dll ()
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\wpclsp.dll ()
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\wpclsp.dll ()
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\wpclsp.dll ()
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\wpclsp.dll ()
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\wpclsp.dll ()
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\wpclsp.dll ()
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\wpclsp.dll ()
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000019 - C:\Windows\SysNative\wpclsp.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {0EED7206-1661-11D7-84A3-00606744831D}
http://doodlekit.com/plugins/xstandard/XStandard.cab (XStandard)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77}
http://i.dell.com/images/global/js/scanner/SysProExe.cab (Scanner.SysScanner)
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} http://das.microsoft.com/activate/cab/x86/…tail/DASAct.cab (DASWebDownload Class)
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} http://chat.yahoo.com/cab/yuplapp.cab (Yahoo! Webcam Upload Wrapper)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D}
http://content.systemrequirementslab.com.s…yri_4.5.1.0.cab (SysInfo Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2328FAD7-8EE1-4EAD-895D-EBB4776AE94C}: DhcpNameServer = 192.168.1.254
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\WB: DllName - (C:\PROGRA~2\Stardock\OBJECT~1\WINDOW~1\fast64.dll) - File not found
O24 - Desktop WallPaper: C:\Users\FunFun\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\FunFun\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{9efab46c-529e-11df-8d3b-002564006453}\Shell - "" = AutoRun
O33 - MountPoints2\{9efab46c-529e-11df-8d3b-002564006453}\Shell\AutoRun\command - "" = N:\VVD.exe
O33 - MountPoints2\{c11e7af6-37b3-11e0-9c59-002564006453}\Shell - "" = AutoRun
O33 - MountPoints2\{c11e7af6-37b3-11e0-9c59-002564006453}\Shell\AutoRun\command - "" = N:\LaunchU3.exe -a
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\autorun.exe
O33 - MountPoints2\H\Shell\phone\command - "" = H:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1084
========== Files/Folders - Created Within 30 Days ==========
[2012/05/09 00:38:58 | 000,595,456 | —- | C] (OldTimer Tools) – C:\Users\FunFun\Desktop\OTL.exe
[2012/05/08 16:08:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Security Client
[2012/05/07 19:55:10 | 000,000,000 | —D | C] – C:\HJT
[2012/05/07 12:19:37 | 000,000,000 | —D | C] – C:\Users\FunFun\AppData\Local\adaware
[2012/05/07 12:19:33 | 000,000,000 | —D | C] – C:\ProgramData\Ad-Aware Browsing Protection
[2012/05/07 12:18:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad-Aware Antivirus
[2012/05/07 12:15:18 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2012/05/07 12:15:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ad-Aware Antivirus
[2012/05/07 12:12:47 | 000,000,000 | —D | C] – C:\Users\FunFun\AppData\Roaming\Ad-Aware Antivirus
[2012/05/07 11:38:43 | 000,000,000 | —D | C] – C:\Users\FunFun\AppData\Roaming\Ylko
[2012/05/07 11:38:43 | 000,000,000 | —D | C] – C:\Users\FunFun\AppData\Roaming\Quyna
[2012/05/06 23:45:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Maintenance Service
[2012/05/04 18:16:00 | 000,000,000 | —D | C] – C:\Users\FunFun\Desktop\New Folder (12)
[2012/05/01 10:15:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mass Effect 2
[2012/04/29 18:06:49 | 000,000,000 | —D | C] – C:\Users\FunFun\Desktop\New Folder
[2012/04/26 12:59:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft XNA
[2012/04/26 08:53:30 | 000,000,000 | —D | C] – C:\Users\FunFun\Documents\My Cheat Tables
[2012/04/26 08:53:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.1
[2012/04/26 08:52:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Cheat Engine 6.1
[2012/04/26 08:12:18 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla
[2012/04/25 21:42:34 | 000,418,464 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/04/19 00:11:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\MediaFire
[6 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[6 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/05/09 00:39:02 | 000,595,456 | —- | M] (OldTimer Tools) – C:\Users\FunFun\Desktop\OTL.exe
[2012/05/09 00:35:09 | 000,721,030 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/05/09 00:35:09 | 000,614,824 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/05/09 00:35:09 | 000,108,948 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/05/09 00:30:39 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/05/09 00:05:04 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/05/08 23:50:47 | 000,001,741 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
[2012/05/08 23:48:40 | 000,003,744 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/08 23:48:39 | 000,003,744 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/08 16:38:54 | 000,292,528 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/05/08 16:11:21 | 000,737,952 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/05/08 16:09:19 | 000,001,945 | —- | M] () – C:\Windows\epplauncher.mif
[2012/05/08 16:03:46 | 000,002,976 | —- | M] () – C:\Users\FunFun\Documents\cc_20120508_160343.reg
[2012/05/08 16:02:38 | 000,063,202 | —- | M] () – C:\Users\FunFun\Documents\cc_20120508_160153.reg
[2012/05/08 15:43:06 | 000,000,632 | RHS- | M] () – C:\Users\FunFun\ntuser.pol
[2012/05/08 14:38:25 | 000,000,164 | —- | M] () – C:\Windows\install.dat
[2012/05/08 03:42:43 | 000,001,460 | —- | M] () – C:\Users\FunFun\AppData\Local\d3d9caps64.dat
[2012/05/08 02:58:19 | 000,001,356 | —- | M] () – C:\Users\FunFun\AppData\Local\d3d9caps.dat
[2012/05/07 19:26:22 | 000,000,946 | —- | M] () – C:\Windows\tasks\Ad-Aware Antivirus Scheduled Scan.job
[2012/05/07 12:13:44 | 000,000,910 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/07 00:33:00 | 000,000,442 | —- | M] () – C:\Windows\tasks\ParetoLogic Update Version2.job
[2012/05/06 23:45:50 | 000,000,874 | —- | M] () – C:\Users\FunFun\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/05/06 23:45:50 | 000,000,850 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/05/06 18:00:01 | 000,000,468 | —- | M] () – C:\Windows\tasks\ParetoLogic Registration.job
[2012/05/01 10:32:56 | 000,000,985 | —- | M] () – C:\Users\FunFun\Desktop\MassEffect2 - Shortcut.lnk
[2012/04/26 11:46:05 | 000,000,222 | —- | M] () – C:\Users\FunFun\Desktop\Bastion.url
[2012/04/26 08:53:11 | 000,000,886 | —- | M] () – C:\Users\FunFun\Desktop\Cheat Engine.lnk
[2012/04/25 21:42:34 | 000,418,464 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/04/25 21:42:34 | 000,070,304 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/04/25 04:02:06 | 000,001,087 | —- | M] () – C:\Users\FunFun\Desktop\MassEffect3 - Shortcut.lnk
[2012/04/20 13:20:15 | 000,082,944 | —- | M] () – C:\Users\FunFun\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[6 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[6 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/05/08 16:03:44 | 000,002,976 | —- | C] () – C:\Users\FunFun\Documents\cc_20120508_160343.reg
[2012/05/08 16:01:57 | 000,063,202 | —- | C] () – C:\Users\FunFun\Documents\cc_20120508_160153.reg
[2012/05/08 14:38:24 | 000,000,164 | —- | C] () – C:\Windows\install.dat
[2012/05/07 12:23:06 | 000,000,946 | —- | C] () – C:\Windows\tasks\Ad-Aware Antivirus Scheduled Scan.job
[2012/05/07 12:18:59 | 000,055,384 | —- | C] () – C:\Windows\SysNative\drivers\SBREDrv.sys
[2012/05/07 12:18:59 | 000,045,904 | —- | C] () – C:\Windows\SysNative\sbbd.exe
[2012/05/07 12:18:47 | 000,001,741 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware Antivirus.lnk
[2012/05/07 12:18:26 | 000,060,504 | —- | C] () – C:\Windows\SysNative\drivers\sbhips.sys
[2012/05/07 12:18:16 | 000,094,296 | —- | C] () – C:\Windows\SysNative\drivers\sbtis.sys
[2012/05/07 12:15:26 | 000,084,568 | —- | C] () – C:\Windows\SysNative\drivers\SbFwIm.sys
[2012/05/07 12:15:23 | 000,253,528 | —- | C] () – C:\Windows\SysNative\drivers\SbFw.sys
[2012/05/06 23:45:50 | 000,000,874 | —- | C] () – C:\Users\FunFun\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/05/06 23:45:50 | 000,000,862 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/05/06 23:45:50 | 000,000,850 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/05/01 10:32:56 | 000,000,985 | —- | C] () – C:\Users\FunFun\Desktop\MassEffect2 - Shortcut.lnk
[2012/04/26 11:46:05 | 000,000,222 | —- | C] () – C:\Users\FunFun\Desktop\Bastion.url
[2012/04/26 08:53:11 | 000,000,886 | —- | C] () – C:\Users\FunFun\Desktop\Cheat Engine.lnk
[2012/04/25 21:42:36 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/04/25 04:02:06 | 000,001,087 | —- | C] () – C:\Users\FunFun\Desktop\MassEffect3 - Shortcut.lnk
[2012/03/26 06:44:49 | 000,000,018 | —- | C] () – C:\Windows\cmm.dat
[2012/01/03 01:08:23 | 000,158,720 | —- | C] () – C:\Windows\SysWow64\WS_VideoConverterContextMenu.dll
[2012/01/02 23:12:56 | 000,615,936 | —- | C] () – C:\Windows\SysWow64\avformat-52.dll
[2012/01/02 23:12:56 | 000,160,768 | —- | C] () – C:\Windows\SysWow64\swscale-0.dll
[2012/01/02 23:12:56 | 000,057,856 | —- | C] () – C:\Windows\SysWow64\avutil-49.dll
[2012/01/02 23:12:56 | 000,022,528 | —- | C] () – C:\Windows\SysWow64\myutil.dll
[2012/01/02 23:12:56 | 000,012,800 | —- | C] () – C:\Windows\SysWow64\avfilter-0.dll
[2012/01/02 23:12:56 | 000,010,752 | —- | C] () – C:\Windows\SysWow64\avdevice-52.dll
[2012/01/02 23:12:55 | 007,999,488 | —- | C] () – C:\Windows\SysWow64\avcodec-51.dll
[2011/10/25 05:46:29 | 000,057,904 | —- | C] () – C:\Windows\SysWow64\wbload.dll
[2011/05/26 13:44:15 | 000,000,194 | —- | C] () – C:\Users\FunFun\AppData\Roaming\dmsettings.xml
[2011/04/17 08:37:32 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2011/04/09 18:55:28 | 000,179,261 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/04/05 22:31:50 | 000,737,952 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/03/17 12:51:44 | 000,003,929 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/03/04 03:49:21 | 001,970,176 | —- | C] () – C:\Windows\SysWow64\d3dx9.dll
[2011/02/17 22:09:43 | 000,000,000 | —- | C] () – C:\Windows\PowerReg.dat
[2011/01/10 18:23:42 | 000,000,195 | —- | C] () – C:\Windows\SysWow64\CleanMem.ini
[2010/08/15 11:06:07 | 000,000,120 | —- | C] () – C:\Users\FunFun\AppData\Local\Ckugulivihan.dat
[2010/08/15 11:06:07 | 000,000,000 | —- | C] () – C:\Users\FunFun\AppData\Local\Llicunifusizebaz.bin
[2010/06/18 02:59:13 | 000,001,460 | —- | C] () – C:\Users\FunFun\AppData\Local\d3d9caps64.dat
========== LOP Check ==========
[2010/02/01 09:55:56 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Acapela Group
[2010/11/29 23:23:42 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\acccore
[2009/09/11 01:52:45 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Acreon
[2012/05/07 22:46:02 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Ad-Aware Antivirus
[2012/03/24 18:28:23 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Audacity
[2011/11/15 06:16:24 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\AVG2012
[2010/03/05 11:09:59 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\AVG9
[2012/02/01 06:12:04 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\avidemux
[2011/07/21 03:52:10 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Bioshock2
[2011/08/08 00:24:18 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Blender Foundation
[2012/05/07 23:36:17 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\DAEMON Tools Lite
[2011/12/11 01:35:45 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Day 1 Studios
[2011/04/05 23:54:38 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Dragon Age Toolset
[2009/09/10 16:10:56 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\DriverCure
[2009/06/03 02:00:25 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Eltima Software
[2010/12/25 12:17:54 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\EuroTalk
[2010/05/16 20:17:56 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\fltk.org
[2011/12/17 16:07:46 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\foobar2000
[2012/03/06 22:18:31 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\GetRightToGo
[2011/04/10 02:43:11 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\gtk-2.0
[2010/06/01 14:00:02 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\ImgBurn
[2012/02/04 10:36:57 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Iomatic
[2009/07/13 23:32:34 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Jasc
[2011/07/29 13:39:05 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\L4D2AOI
[2009/08/13 05:36:01 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Leadertech
[2009/09/10 16:48:42 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\licenses
[2011/07/17 14:35:05 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Lionhead Studios
[2011/10/13 04:43:30 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\LockHunter
[2011/07/09 08:54:46 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\mjusbsp
[2011/10/10 17:29:25 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Mobipocket
[2011/12/17 16:20:22 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Music Recognition
[2010/08/30 05:43:52 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Octoshape
[2009/09/10 16:48:39 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\PCMM2009
[2011/09/16 09:18:51 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Philipp Winterberg
[2012/02/04 06:40:10 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Publish Providers
[2011/11/23 10:21:48 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\PunkBuster
[2012/05/07 12:19:01 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Quyna
[2012/01/03 00:00:11 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Red Kawa
[2012/03/08 01:56:13 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\RenPy
[2009/12/23 23:33:29 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\runic games
[2010/11/02 16:06:20 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\SmartDraw
[2012/02/04 06:39:50 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Sony
[2011/10/25 05:35:46 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Stardock
[2011/07/26 09:41:36 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Sudeki
[2011/07/22 22:39:39 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\SystemRequirementsLab
[2010/03/05 20:29:35 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Template
[2012/05/08 16:50:48 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\uTorrent
[2010/02/01 09:56:11 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Xtranormal
[2012/05/07 19:25:29 | 000,000,000 | —D | M] – C:\Users\FunFun\AppData\Roaming\Ylko
[2012/05/07 19:26:22 | 000,000,946 | —- | M] () – C:\Windows\Tasks\Ad-Aware Antivirus Scheduled Scan.job
[2012/05/06 18:00:01 | 000,000,468 | —- | M] () – C:\Windows\Tasks\ParetoLogic Registration.job
[2012/05/07 00:33:00 | 000,000,442 | —- | M] () – C:\Windows\Tasks\ParetoLogic Update Version2.job
[2012/05/07 23:45:49 | 000,032,552 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2007/11/07 09:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
< MD5 for: EXPLORER.EXE >
[2009/05/20 14:45:24 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_b5f700fe698beb14\explorer.exe
[2009/05/20 14:45:23 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\SysWOW64\explorer.exe
[2009/05/20 14:45:23 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_b7eb106e66a7ac19\explorer.exe
[2009/05/20 14:45:24 | 003,087,360 | —- | M] (Microsoft Corporation) MD5=50514057C28A74BAC2BD04B7B990D615 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_aba256ac352b2919\explorer.exe
[2009/05/20 14:45:23 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_b8583e9d7fda0512\explorer.exe
[2009/04/11 02:10:17 | 003,079,168 | —- | M] (Microsoft Corporation) MD5=6B08E54A451B3F95E4109DBA7E594270 – C:\Windows\SoftwareDistribution\Download\61da130e21aad3387c2fa3ca1d469de3\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_afbebba22f3bab41\explorer.exe
[2009/05/20 14:45:23 | 003,086,848 | —- | M] (Microsoft Corporation) MD5=72B9990E45C25AA3C75C4FB50A9D6CE0 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_ac5266dd4e2b0a41\explorer.exe
[2009/05/20 14:45:23 | 003,080,704 | —- | M] (Microsoft Corporation) MD5=BBD8E74F23D7605CB0CDB57A1B25D826 – C:\Windows\explorer.exe
[2009/05/20 14:45:23 | 003,080,704 | —- | M] (Microsoft Corporation) MD5=BBD8E74F23D7605CB0CDB57A1B25D826 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_ad96661c3246ea1e\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\SoftwareDistribution\Download\61da130e21aad3387c2fa3ca1d469de3\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_ba1365f4639c6d3c\explorer.exe
[2009/05/20 14:45:23 | 003,081,216 | —- | M] (Microsoft Corporation) MD5=E404A65EF890140410E9F3D405841C95 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_ae03944b4b794317\explorer.exe
[2009/05/20 14:45:24 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_b6a7112f828bcc3c\explorer.exe
[2008/01/20 21:48:44 | 003,080,704 | —- | M] (Microsoft Corporation) MD5=F6D765FB6B457542D954682F50C26E4F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_add342963219dff5\explorer.exe
[2008/01/20 21:49:23 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_b827ece8667aa1f0\explorer.exe
< MD5 for: SVCHOST.EXE >
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2008/01/20 21:48:05 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\SysWOW64\svchost.exe
[2008/01/20 21:48:05 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
[2008/01/20 21:50:24 | 000,027,648 | —- | M] () MD5=CDA9F1373805AF88F6FA4F2064BBA24D – C:\Windows\SysNative\svchost.exe
[2008/01/20 21:50:24 | 000,027,648 | —- | M] (Microsoft Corporation) MD5=CDA9F1373805AF88F6FA4F2064BBA24D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_11d9f524bdab2f1b\svchost.exe
< MD5 for: USERINIT.EXE >
[2008/01/20 21:50:36 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\SysWOW64\userinit.exe
[2008/01/20 21:50:36 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2008/01/20 21:49:46 | 000,028,160 | —- | M] () MD5=A0AB2BB9A92293D9CE66E252719AB5FE – C:\Windows\SysNative\userinit.exe
[2008/01/20 21:49:46 | 000,028,160 | —- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_384755998a0d6941\userinit.exe
< MD5 for: WINLOGON.EXE >
[2012/04/04 15:56:38 | 000,199,240 | —- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/04/11 02:11:08 | 000,405,504 | —- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A – C:\Windows\SoftwareDistribution\Download\61da130e21aad3387c2fa3ca1d469de3\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_cdcd15a68a70b877\winlogon.exe
[2008/01/20 21:49:47 | 000,406,016 | —- | M] () MD5=856491FCED98093D824B9EB2892F564A – C:\Windows\SysNative\winlogon.exe
[2008/01/20 21:49:47 | 000,406,016 | —- | M] (Microsoft Corporation) MD5=856491FCED98093D824B9EB2892F564A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_cbe19c9a8d4eed2b\winlogon.exe
[2009/04/11 01:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\SoftwareDistribution\Download\61da130e21aad3387c2fa3ca1d469de3\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/20 21:50:38 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\SysWOW64\winlogon.exe
[2008/01/20 21:50:38 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< C:\Windows\assembly\tmp\U\*.* /s >
========== Alternate Data Streams ==========
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:5D432CE3
< End of report >
Here is the Extras.txt
OTL Extras logfile created on: 5/9/2012 12:43:47 AM - Run 1
OTL by OldTimer - Version 3.2.42.3 Folder = C:\Users\FunFun\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.26 Gb Available Physical Memory | 75.47% Memory free
7.40 Gb Paging File | 6.29 Gb Available in Paging File | 84.96% Paging File free
Paging file location(s): c:\pagefile.sys 4605 4605 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 283.02 Gb Total Space | 59.06 Gb Free Space | 20.87% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 7.08 Gb Free Space | 47.23% Space Free | Partition Type: NTFS
Computer Name: FUNFUN-PC | User Name: FunFun | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe ()
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.ini [@ = inifile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" ()
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l ()
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" ()
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{68983E2F-EF26-497B-9D09-5526BD55625A}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{D440F46C-5847-4BF7-BB68-B3C64D72D77B}" = lport=2869 | protocol=6 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04576DBA-762A-4145-845C-8BA5B3CE0612}" = protocol=17 | dir=in | app=c:\program files (x86)\dragon age\bin_ship\daorigins.exe |
"{095963D1-A95F-4491-A297-B7E988AA838F}" = protocol=6 | dir=in | app=c:\program files (x86)\veoh networks\veohwebplayer\veohwebplayer.exe |
"{1C08E323-1E67-41E3-AA46-5035A57734F8}" = protocol=6 | dir=in | app=c:\program files (x86)\dragon age\daoriginslauncher.exe |
"{28CBB92F-91EC-40BD-9F00-132737BE67B1}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\dell\advanced networking service\hnm_svc.exe |
"{2F50E9F0-5C9A-4FCC-9502-376ABD9DF1E6}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{32A5A045-E95C-4196-BED8-9F44F568FE90}" = protocol=17 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"{3411EF52-9F05-4273-8D43-7516A1C69191}" = protocol=17 | dir=in | app=c:\program files (x86)\giraffic\veoh_giraffic.exe |
"{391BAFFD-E6F7-4331-B606-120B12FF9899}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{46A6262C-B629-4FAF-A584-F15C1A37287E}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{4D89055A-A9D7-4D4B-9A17-A68D82012EF3}" = protocol=17 | dir=in | app=c:\program files (x86)\veoh networks\veohwebplayer\veohwebplayer.exe |
"{50B99F94-8838-42D0-8403-C40D51CD8022}" = protocol=6 | dir=in | app=c:\program files (x86)\dragon age\bin_ship\daupdatersvc.service.exe |
"{53945235-3ED4-4FB3-AAC5-E22C460B1FC9}" = protocol=17 | dir=in | app=c:\program files (x86)\dragon age 2\dragonage2launcher.exe |
"{5D2AB310-B11E-4B3B-838F-D8A9AA8F85BA}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{6249C922-8FA3-4AB3-9B4A-03C1CB8EB3C0}" = protocol=17 | dir=in | app=c:\program files (x86)\dragon age\bin_ship\daupdatersvc.service.exe |
"{659D6999-5BD0-4751-9908-E1B45A51D894}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{6E522832-51DD-4EC7-AD0F-CED7D226E8FC}" = protocol=6 | dir=in | app=c:\program files (x86)\dell remote access\ezi_ra.exe |
"{73BA9A6D-0995-4899-968B-17ECCC8EAD26}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{781FFF11-E56A-4545-A953-6A1C958B1AC4}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{787899D6-C256-43F4-B576-F9E3735F53E8}" = protocol=17 | dir=in | app=c:\program files (x86)\giraffic\veoh_girafficwatchdog.exe |
"{79FE4C8C-A644-407B-890E-D93B13AE6D72}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{7BDC3C9C-D333-4044-8F81-1B6F898EA426}" = protocol=6 | dir=in | app=c:\program files (x86)\dragon age\bin_ship\daorigins.exe |
"{7C56DF26-F8A5-48A9-B6B9-B1F80177A8C1}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{7D68E8DC-91F2-402A-9907-ECECC903666E}" = protocol=6 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"{857ED6A1-980F-4D56-8B44-05ED014C8806}" = protocol=17 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"{871D2703-9CC3-41C9-8746-0E065AE8DC30}" = protocol=17 | dir=in | app=c:\program files (x86)\dragon age\daoriginslauncher.exe |
"{89FE528A-4810-4A76-94EE-AF7A3D9D8041}" = protocol=17 | dir=in | app=c:\program files (x86)\dragon age 2\bin_ship\dragonage2.exe |
"{91A3AD7E-63C9-40DB-9CD5-F46BEF89B8D3}" = protocol=6 | dir=in | app=c:\program files (x86)\veoh networks\veohwebplayer\veohwebplayer.exe |
"{91F0BD28-A245-4C39-9114-3F4FAB608099}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{93D10D78-8E96-4CFB-96C0-2282FFB3BA89}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\dell\vlc\vlc.exe |
"{9415A125-093B-471C-A481-794312F67A37}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{9D40B3F3-3585-41C3-B053-4575E311805C}" = protocol=6 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"{A47D48E2-FD5A-40B5-914E-F6F649C02D9A}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\dell\advanced networking service\hnm_svc.exe |
"{A7C84971-2BE4-4772-9776-B45CFE4A4375}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{ADACCA4C-1D33-49E2-A4C1-15A68EABA390}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{B4A43D64-C797-4F2E-860F-E28F04B8A68F}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{B5F6AC0A-CE76-4538-A03B-1A0ECF694B81}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{BA9C1417-E927-4FDC-A547-31FD15EEBB2D}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\dell\vlc\vlc.exe |
"{BC9E829D-DCD6-4640-A5F0-75362CF06F2A}" = protocol=6 | dir=in | app=c:\program files (x86)\giraffic\veoh_giraffic.exe |
"{C20341E8-CED9-4A5F-BB08-CE65AECDC976}" = protocol=6 | dir=in | app=c:\program files (x86)\dragon age 2\bin_ship\dragonage2.exe |
"{C2DE62B5-75EF-4630-A212-6DB758837EE6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{C80CE9C6-D5EB-448F-8F3A-4A01B154461C}" = protocol=6 | dir=in | app=c:\program files (x86)\giraffic\veoh_girafficwatchdog.exe |
"{CC537CF3-57C4-459C-890C-6E2D610D7411}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{D194A660-8485-4F02-B94D-FCC1CEF981EC}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{D8DA7CD2-85D8-400F-B65F-5995ACBFF17B}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{E1721D99-6334-43AF-B90C-9C65B43CE71B}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{E9DC6764-42B6-42BA-A0B7-B39073FF2941}" = protocol=6 | dir=in | app=c:\program files (x86)\dragon age 2\dragonage2launcher.exe |
"{E9F19ACA-7028-4641-BB3B-9DED6DAD121D}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{EAE87CB0-7D77-492A-8777-D65244A7D6AB}" = protocol=17 | dir=in | app=c:\program files (x86)\veoh networks\veohwebplayer\veohwebplayer.exe |
"{EC168265-F227-4BE9-BCA3-0EA532F15FFB}" = protocol=17 | dir=in | app=c:\program files (x86)\dell remote access\ezi_ra.exe |
"{F937CDF6-07DA-4703-932F-40A8B698BEB8}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\powerdvd.exe |
"{FF928FAA-56ED-4018-AD00-662C7555E406}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"TCP Query User{004ECCA3-CC5E-43C9-8354-D83D8078B613}C:\users\funfun\appdata\roaming\mjusbsp\magicjack.exe" = protocol=6 | dir=in | app=c:\users\funfun\appdata\roaming\mjusbsp\magicjack.exe |
"TCP Query User{431C9003-012E-476D-8A96-F6ADBB91D331}C:\program files (x86)\xbc\nexbc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\xbc\nexbc.exe |
"TCP Query User{76032B04-88E0-4640-8CDD-2659978E39AB}C:\users\funfun\appdata\roaming\mjusbsp\magicjack.exe" = protocol=6 | dir=in | app=c:\users\funfun\appdata\roaming\mjusbsp\magicjack.exe |
"TCP Query User{814264D5-95A0-416E-B6AC-1B19F9079651}C:\program files (x86)\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"TCP Query User{9CCDFCE4-3F25-463D-B4F9-53A7074A3EFC}C:\windows\syswow64\regsvr32.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\regsvr32.exe |
"TCP Query User{A3742F03-2803-4A99-B454-AA578CD1226E}C:\users\funfun\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe" = protocol=6 | dir=in | app=c:\users\funfun\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe |
"TCP Query User{F2D9A676-39E8-4A16-BE12-0E8EAF00902B}C:\users\funfun\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe" = protocol=6 | dir=in | app=c:\users\funfun\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe |
"UDP Query User{015DAD2C-6AE2-4C85-936A-BD19F362AA8D}C:\users\funfun\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe" = protocol=17 | dir=in | app=c:\users\funfun\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe |
"UDP Query User{1835CD02-1056-4E48-869B-99CA857F27DB}C:\users\funfun\appdata\roaming\mjusbsp\magicjack.exe" = protocol=17 | dir=in | app=c:\users\funfun\appdata\roaming\mjusbsp\magicjack.exe |
"UDP Query User{26E8EBDB-E218-4B4B-86B2-AA9172EB2CD9}C:\users\funfun\appdata\roaming\mjusbsp\magicjack.exe" = protocol=17 | dir=in | app=c:\users\funfun\appdata\roaming\mjusbsp\magicjack.exe |
"UDP Query User{3AF4A98A-D348-432D-8BB2-F7016CB08D81}C:\windows\syswow64\regsvr32.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\regsvr32.exe |
"UDP Query User{7DCF0C64-7F7F-4009-A646-E0817139E19A}C:\program files (x86)\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"UDP Query User{8CF1684E-249E-4BA5-A7B0-22760B6E8A8B}C:\users\funfun\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe" = protocol=17 | dir=in | app=c:\users\funfun\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe |
"UDP Query User{C6A041DB-FF54-4DD1-B6DC-B0148853B2BD}C:\program files (x86)\xbc\nexbc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\xbc\nexbc.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{104FB32A-7CE3-4C4B-B2AA-70C613FF9DFA}" = iTunes
"{22441735-5983-AD2A-5CC5-FA2CCD7EF732}" = ATI Stream SDK v2 Developer
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{2E295B5B-1AD4-4d36-97C2-A316084722C0}" = Python 2.7.2 (64-bit)
"{33EB1061-ABF1-4470-A540-32E97A610536}" = Apple Mobile Device Support
"{41BF0DE4-5BAE-4B88-AFD3-86A30B222186}" = Bonjour
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{9CF4A37B-A8C4-44D7-8C53-13B9D9594BB3}" = Paint.NET v3.5.8
"{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}" = Microsoft Security Client
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2C5B378-546F-75A7-7757-C1EAAFAF9E33}" = ccc-utility64
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFF9D801-1EC4-B8F5-2CAB-4A1790C95A18}" = ATI Catalyst Install Manager
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{E4C229B2-51E3-49E7-3A42-A3B695B4E56E}" = ccc-utility64
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F6CB42B9-F033-4152-8813-FF11DA8E6A78}" = Dell Dock
"ATRAC3" = Sony ATRAC3 Audio Codec (remove only)
"CCleaner" = CCleaner
"HyperCam 2 (64 bit)" = HyperCam 2 (64 bit)
"LockHunter_is1" = LockHunter version 1.0 beta 3, 64 bit edition
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Recuva" = Recuva
"SmartDraw PDF Export_is1" = SmartDraw PDF Export (novaPDF 6.4 printer)
"WinRAR archiver" = WinRAR 4.01 (64-bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04D5E56E-F323-27F2-C075-EF1AE9A3CF2B}" = Catalyst Control Center Graphics Light
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{07288267-318E-9B78-B04E-984F9149EE24}" = Catalyst Control Center Graphics Previews Common
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{0B23ACC5-88A6-FEE4-0131-8777A1BA0B68}" = Catalyst Control Center Graphics Previews Vista
"{0CD81D7E-94E2-D230-E37E-C9B16E90D01C}" = CCC Help Italian
"{11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}" = ATI Catalyst Registration
"{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}" = Dell DataSafe Online
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1696C54E-599A-4BA2-9941-BB70C4727887}" = Xtranormal State - Voicepack-English-UK-Daniel
"{16A7FAD8-EE4F-C413-8359-833A3B2D39FB}" = CCC Help Portuguese
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18364179-C5E5-F826-E2FC-D99D575AF997}" = Catalyst Control Center Localization All
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 30
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{342126E1-173C-4585-BFBE-3EBDD20E3E9E}" = Mobipocket Reader 6.2
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3CD5832D-13D9-4751-8B22-3A7D3F4ACA42}" = Quake Live Mozilla Plugin
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{47C72DA6-E7AC-984C-5475-15A65F9B41BE}" = Catalyst Control Center Graphics Full New
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A194623-3878-4CAA-B5F7-FC21B1AE3CAD}" = Left 4 Dead 2 Add-On Installer
"{4A918155-6399-4673-0D08-85A0DBEC1389}" = CCC Help Chinese Traditional
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4F94119D-1B71-400e-9F04-B4E5CEAE71F8}_is1" = Sothink Movie DVD Maker
"{537791BE-B032-D116-0C59-13541E17BFEA}" = CCC Help English
"{5FD89EA1-99C2-40EE-BBF5-20F8991ED756}" = Catalyst Control Center - Branding
"{625386A4-B6B6-4911-A6E8-23189C3F2D15}" = Microsoft .NET Compact Framework 2.0 SP1
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{664D6E1D-2A6C-D54D-31A5-B6BC30CEB0C6}" = CCC Help English
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{66DAE8D7-D5F7-462F-5815-102EE4B191C4}" = CCC Help Korean
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB}" = Mass Effect 2
"{763B809A-6874-5979-CD69-39491392262C}" = Catalyst Control Center InstallProxy
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{7FE440D8-8F16-24CA-81B6-7DEB4D6BF92D}" = CCC Help Hungarian
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{838A22DF-81CA-4452-9BDD-A1745224D960}" = Xtranormal State - Voicepack-English-UK-Serena
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{88D3B829-DBA4-D839-33BF-9A5794CC21EB}" = CCC Help Chinese Standard
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8A809006-C25A-4A3A-9DAB-94659BCDB107}" = NVIDIA PhysX
"{8ACC73AA-6511-7C55-B1A9-8E5D1DEAFAA3}" = The Lord of the Rings FREE Trial
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{9044B9A5-B7D7-3EA2-B20B-49A47853D62F}" = CCC Help Spanish
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{912536C4-273C-416F-B42C-BBC5B72114D7}" = Xtranormal State - Voicepack-English-US-Samantha
"{943A8D28-80D6-41DC-AE94-81FEB42041BF}" = System Requirements Lab CYRI
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A0BA5AAC-CA61-4C71-9A29-FDF521296225}" = Xtranormal State - SoundPack-Starter Kit
"{A69D7B32-2BE9-42BF-B576-69B5E0FF7394}" = Catalyst Control Center - Branding
"{A7F37935-A880-8657-79CE-F98BF3A358E1}" = CCC Help Turkish
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AA945C94-285E-DE48-A30F-70105C6580DE}" = Catalyst Control Center Graphics Previews Common
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
"{AEC81925-9C76-4707-84A9-40696C613ED3}" = Dragon Age: Origins
"{AFF8C8F4-E4BB-891F-8636-5E71F946C5B6}" = Catalyst Control Center InstallProxy
"{B297076F-905F-7E13-57EF-7D254EBB7589}" = CCC Help Japanese
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader
"{B935C985-A17F-484B-8470-09E4FC27DC26}" = Dell-eBay
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{cc937cbc-4be2-4227-9660-ff2f2a1d9467}" = Ad-Aware Antivirus
"{CF91A5A9-F10D-433D-A677-9505B84EAF1B}" = Stardock Impulse
"{D1B8C6AC-C4F8-E8AF-E157-AF3E16B97903}" = CCC Help French
"{D28CB048-A0AB-4F98-909F-69F3F25AA87D}" = Xtranormal State - Showpak-Playgoz-Preview
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7 Anniversary Edition
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DC702FC1-4746-CD99-0578-02839474C2F8}" = Skins
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E371C150-A9F1-49CE-ACC1-51AEFD01C1D4}_is1" = TurboTax Audit Support Center 3.0
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E59145A6-2D21-9E5C-6551-ACA2539CDE50}" = ccc-core-static
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{E89371A0-2FCD-F518-EECB-09AB27724CEE}" = CCC Help German
"{ED06F22F-DADB-E713-2E49-EEB154950285}" = Catalyst Control Center Graphics Full Existing
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{F26615EF-AF0A-486C-99C9-B65C8C401EBC}" = EuroTalk Talk Now!
"{F2E23139-3404-4E3C-9855-7724415D62A5}" = Dragon Age II
"{F66A31D9-7831-4FBA-BA02-C411C0047CC5}" = Dell Remote Access
"{F6706DF9-B0B6-8496-F302-BF511197A32F}" = Catalyst Control Center Core Implementation
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FF70923C-8A51-47F4-A7E9-893C6D54EB68}" = TES Construction Set
"Ad-Aware Browsing Protection" = Ad-Aware Browsing Protection
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AIM_7" = AIM 7
"All To PSP Converter_is1" = All To PSP Converter [removed]
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.13 (Unicode)
"Avidemux 2.5 (64-bit)" = Avidemux 2.5
"AviSynth" = AviSynth 2.5
"BootSkin Vista (Free)" = BootSkin Vista (Free)
"CDisplay_is1" = CDisplay 1.8
"Cheat Engine 5.6.1_is1" = Cheat Engine 5.6.1
"Cheat Engine 6.1_is1" = Cheat Engine 6.1
"CleanMem" = CleanMem
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CoreAAC Audio Decoder" = CoreAAC Audio Decoder (remove only)
"Coupon Printer for Windows5.0.0.1" = Coupon Printer for Windows
"DAEMON Tools Lite" = DAEMON Tools Lite
"Digital Editions" = Adobe Digital Editions
"DVD Flick_is1" = DVD Flick 1.3.0.7
"EAX™ Unified (SHELL)" = EAX™ Unified (SHELL)
"FastStone Capture" = FastStone Capture 5.3
"ffdshow_is1" = ffdshow [rev 2583] [2009-01-05]
"GFWL_{45410935-3E72-472B-8C35-AB1000008200}" = Bulletstorm
"Giraffic" = Veoh Giraffic Video Accelerator
"GOM Player" = GOM Player
"HaaliMkx" = Haali Media Splitter
"HyperCam Toolbar" = HyperCam Toolbar
"ImgBurn" = ImgBurn
"LastFM_is1" = Last.fm 1.5.4.27091
"Magic ISO Maker v5.4 (build 0239)" = Magic ISO Maker v5.4 (build 0239)
"Magic ISO Maker v5.5 (build 0276)" = Magic ISO Maker v5.5 (build 0276)
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox 12.0 (x86 en-US)" = Mozilla Firefox 12.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MS Access 97 SP2" = MS Access 97 SP2
"PunkBusterSvc" = PunkBuster Services
"RealPlayer 12.0" = RealPlayer
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Stardock Impulse" = Stardock Impulse
"Steam App 107100" = Bastion
"SWF & FLV Player_is1" = SWF & FLV Player 3.0 (build 3.0.33.5106)
"TSBm 2000" = TSBm 2000
"UltraISO_is1" = UltraISO Premium V9.36
"uTorrent" = µTorrent
"Veoh Web Player Beta" = Veoh Web Player
"VLC media player" = VLC media player 1.0.0
"VobSub" = VobSub v2.23 (Remove Only)
"WIDI Recognition System Pro 4.11" = WIDI Recognition System Pro 4.11 (remove only)
"WindowBlinds" = WindowBlinds
"WinGimp-2.0_is1" = GIMP 2.6.11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.1 beta5
"WinRAR archiver" = WinRAR archiver
"Wondershare Video Converter Platinum_is1" = Wondershare Video Converter Platinum(Build 5.1.2.0)
"XBC 5.1" = XBC 5.1
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Amazon Kindle" = Amazon Kindle
"Dragon Age Awakening Redesigned" = Dragon Age Awakening Redesigned
"Dragon Age Redesigned©" = Dragon Age Redesigned©
"magicJack" = magicJack
"Octoshape Streaming Services" = Octoshape Streaming Services
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >