This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected with Trojan Horse Hider.MPR Please Help! [Closed]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Tonight i got threat detected warnings from both AVG and windows defender security i completed both scans to try and remove the threats to no avail.They just came back saying unable to access files.i wrote down the path files and proceeded to enter safe mode then Googled for a solution and could not find any simple solutions Please i need help!!!! i must say also my system has been using a lot of memory recently and while using Firefox tonight before the threats were detected i could not use the net it wouldn't load the pages i wanted other than that and up until tonight i have been able to use other programs and AV so hopefully i have caught it early. Thankyou
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • If you happen to have a flash drive/thumb drive please have that ready in the event that we need to use it.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Having said that….Let's get going!! :thumbup:
———-

  • Download OTL to your desktop.
  • Right-click and Run as Administrator on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
———-

Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

Please post the logs made by OTL and aswMBR. :)
Thankyou for your response here is the OTL.text file others to follow



OTL logfile created on: 6/30/2012 12:21:39 AM - Run 1
OTL by OldTimer - Version 3.2.53.0 Folder = C:\Users\radiorentals\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.87 Gb Total Physical Memory | 2.93 Gb Available Physical Memory | 75.74% Memory free
7.73 Gb Paging File | 6.87 Gb Available in Paging File | 88.84% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.99 Gb Total Space | 197.56 Gb Free Space | 69.08% Space Free | Partition Type: NTFS

Computer Name: ALISON | User Name: radiorentals | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\radiorentals\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_262.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (.Net Main) – C:\Windows\SysNative\idle-Threads.exe ()
SRV:64bit: - (.Net Security) – C:\Windows\SysNative\latch-Threads.exe ()
SRV:64bit: - (.Net Crypt) – C:\Windows\SysNative\mutex-Threads.exe ()
SRV:64bit: - (.Net Semaphore) – C:\Windows\SysNative\semaphore-Threads.exe ()
SRV:64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (ePowerSvc) – C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (Updater Service) – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer Group)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (vToolbarUpdater11.1.0) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe ()
SRV - (BBUpdate) – C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (GamesAppService) – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (PassThru Service) – C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe ()
SRV - (DsiWMIService) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (IJPLMSVC) – C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe ()
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (GREGService) – C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (IAStorDataMgrSvc) Intel® – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (usbvox) – C:\Windows\SysNative\Drivers\usbvox64.sys ()
DRV:64bit: - (scssifilter) – C:\Windows\SysNative\drivers\scssifilter64.sys (Microsoft Corporation)
DRV:64bit: - (usbmp3) – C:\Windows\SysNative\Drivers\usbmp364.sys ()
DRV:64bit: - (usbwav) – C:\Windows\SysNative\Drivers\usbwav64.sys ()
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Netaapl) – C:\Windows\SysNative\drivers\netaapl64.sys (Apple Inc.)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSEH) – C:\Windows\SysNative\drivers\AVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (htcnprot) – C:\Windows\SysNative\drivers\htcnprot.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (k57nd60a) Broadcom NetLink ™ – C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atipmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (RTHDMIAzAudService) – C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (HTCAND64) – C:\Windows\SysNative\drivers\ANDROIDUSB.sys (HTC, Corporation)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV:64bit: - (hwdatacard) – C:\Windows\SysNative\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…d4z125a4562d204
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…d4z125a4562d204
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACGW
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2438727

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchPage =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.imesh.net
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {F08555B0-9CC3-11D2-AA8E-000000000567} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?FORM=VIATDF&…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}…0000017c4f4f1d2
IE - HKCU\..\SearchScopes\{4B8C28A7-A9BC-45F8-990D-21499EED643C}: "URL" = http://www.questscan.com/?prt=QstscanPB&am;…s={searchTerms}
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…1I7ACGW_enAU382
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…1I7ACGW_enAU382
IE - HKCU\..\SearchScopes\{78FF7C5E-67BA-4E4A-B09E-84BFE0DF08D6}: "URL" = http://websearch.ask.com/redirect?client=i…9B-8713DF73C198
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={544C5B4…mp;d=2012-06-14 21:30:50&v;=10.0.0.7&sap;=dsp&q;={searchTerms}
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKCU\..\SearchScopes\{A531D99C-5A22-449b-83DA-872725C6D0ED}: "URL" = http://search.alot.com/web?q={searchTerms}…n=1.1.3001.0(B)
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2438727
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://search.imesh.net"
FF - prefs.js..extensions.enabledItems: [removed]:0.1
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid;=1157&systemid;=1&sr;=0&q;="


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.1.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\5\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\radiorentals\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\radiorentals\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\radiorentals\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\radiorentals\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\radiorentals\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4C0766D3-67A7-45a3-85A2-752F77312F32}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.1.0.19\coFFPlgn\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\ProgramData\CodecCheck\firefox [2011/07/12 17:16:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/02/20 17:51:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012/06/14 23:15:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\11.1.0.7\ [2012/06/16 09:36:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/17 11:45:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/23 20:01:54 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/17 11:45:01 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/23 20:01:54 | 000,000,000 | —D | M]

[2012/05/17 17:03:15 | 000,000,000 | —D | M] (No name found) – C:\Users\radiorentals\AppData\Roaming\mozilla\Extensions
[2010/08/16 10:12:12 | 000,000,000 | —D | M] (No name found) – C:\Users\radiorentals\AppData\Roaming\mozilla\Extensions\[removed]
[2010/09/20 05:42:40 | 000,000,000 | —D | M] (No name found) – C:\Users\radiorentals\AppData\Roaming\mozilla\Extensions\[removed]
[2012/05/17 17:03:15 | 000,000,000 | —D | M] (No name found) – C:\Users\radiorentals\AppData\Roaming\mozilla\Firefox\Profiles\1nxsss19.default\extensions
[2012/05/17 17:03:07 | 000,000,000 | —D | M] (Wincore Mediabar) – C:\Users\radiorentals\AppData\Roaming\mozilla\Firefox\Profiles\1nxsss19.default\extensions\{28387537-e3f9-4ed7-860c-11e69af4a8a0}
[2012/04/29 00:14:54 | 000,000,000 | —D | M] (wxDfast) – C:\Users\radiorentals\AppData\Roaming\mozilla\Firefox\Profiles\1nxsss19.default\extensions\[removed]
[2012/03/20 13:52:38 | 000,002,205 | —- | M] () – C:\Users\radiorentals\AppData\Roaming\Mozilla\Firefox\Profiles\1nxsss19.default\searchplugins\alot-search.xml
[2011/06/08 13:47:03 | 000,002,574 | —- | M] () – C:\Users\radiorentals\AppData\Roaming\Mozilla\Firefox\Profiles\1nxsss19.default\searchplugins\askcom.xml
[2011/03/20 16:30:43 | 000,001,834 | —- | M] () – C:\Users\radiorentals\AppData\Roaming\Mozilla\Firefox\Profiles\1nxsss19.default\searchplugins\bing.xml
[2012/05/17 17:03:00 | 000,002,517 | —- | M] () – C:\Users\radiorentals\AppData\Roaming\Mozilla\Firefox\Profiles\1nxsss19.default\searchplugins\Search_Results.xml
[2012/05/17 17:03:15 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/02/20 17:51:33 | 000,000,000 | —D | M] (DivX Plus Web Player HTML5 ) – C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
[2011/07/12 17:16:19 | 000,000,000 | —D | M] ("Premiumplay Codec-C") – C:\PROGRAMDATA\CODECCHECK\FIREFOX
[2012/06/17 11:45:00 | 000,085,472 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/06/16 09:35:57 | 000,003,766 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/03/15 18:10:12 | 000,002,310 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
[2012/06/17 11:44:56 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/05/17 17:03:00 | 000,002,517 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml
[2012/06/17 11:44:56 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Search the web (Babylon) (Enabled)
CHR - default_search_provider: search_url = http://search.babylon.com/?q={searchTerms}…0000017c4f4f1d2
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\radiorentals\AppData\Local\Google\Chrome\Application\19.0.1084.56\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Users\radiorentals\AppData\Local\Google\Chrome\Application\19.0.1084.56\gears.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\radiorentals\AppData\Local\Google\Chrome\Application\19.0.1084.56\gcswf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U22 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\radiorentals\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\radiorentals\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.50917.0\npctrl.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2009/06/11 07:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (DataMngr) - {BE7A24F5-69CB-4708-B77B-B1EDA6043B95} - C:\Program Files (x86)\iMesh Applications\MediaBar\Datamngr\x64\BrowserConnection.dll (iMesh, Inc)
O2 - BHO: (Wincore Mediabar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\Program Files (x86)\iMesh Applications\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll ()
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll ()
O2 - BHO: (DataMngr) - {BE7A24F5-69CB-4708-B77B-B1EDA6043B95} - C:\Program Files (x86)\iMesh Applications\MediaBar\Datamngr\BrowserConnection.dll (iMesh, Inc)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll (Yontoo LLC)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Wincore Mediabar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\Program Files (x86)\iMesh Applications\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll ()
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [apvxdwin] File not found
O4:64bit: - HKLM..\Run: [avgnt] File not found
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [Defender Pro Antiphishing Helper] File not found
O4:64bit: - HKLM..\Run: [DPAgent] File not found
O4:64bit: - HKLM..\Run: [G Data AntiVirus Tray Application] File not found
O4:64bit: - HKLM..\Run: [GDFirewallTray] File not found
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [scaninicio] File not found
O4:64bit: - HKLM..\Run: [UfSeAgnt.exe] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files (x86)\Video Web Camera\traybar.exe (Chicony)
O4 - HKLM..\Run: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\iMesh Applications\MediaBar\Datamngr\datamngrUI.exe (iMesh, Inc)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [sound-card-recorder] "C:\Program Files (x86)\Phone Call Recorder\phonerec.exe" /tray File not found
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKCU..\Run: [Facebook Update] C:\Users\radiorentals\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [QcrJdlni] C:\Users\radiorentals\AppData\Local\ivawsleu\qcrjdlni.exe ()
O4 - HKCU..\Run: [Speech Recognition] C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation)
O4 - Startup: C:\Users\radiorentals\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qcrjdlni.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 157
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/trialo…osoft/wrc32.ocx (WRC Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{113A12D7-D158-4CB4-ACCA-102DC7CDCA41}: DhcpNameServer = 10.143.147.147 10.143.147.148
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A37BEAB5-1E21-4CC3-B88C-EBF540245F4D}: DhcpNameServer = 10.0.0.138
O18:64bit: - Protocol\Handler\belarc - No CLSID value found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.1.0\ViProtocol.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Users\radiorentals\AppData\Local\ivawsleu\qcrjdlni.exe) - C:\Users\radiorentals\AppData\Local\ivawsleu\qcrjdlni.exe ()
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{0b482776-a241-11df-b753-0017c4f4f1d2}\Shell - "" = AutoRun
O33 - MountPoints2\{0b482776-a241-11df-b753-0017c4f4f1d2}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{0b48277a-a241-11df-b753-0017c4f4f1d2}\Shell - "" = AutoRun
O33 - MountPoints2\{0b48277a-a241-11df-b753-0017c4f4f1d2}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{0b4827d7-a241-11df-b753-705ab6e51266}\Shell - "" = AutoRun
O33 - MountPoints2\{0b4827d7-a241-11df-b753-705ab6e51266}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{0b4827d9-a241-11df-b753-705ab6e51266}\Shell - "" = AutoRun
O33 - MountPoints2\{0b4827d9-a241-11df-b753-705ab6e51266}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{36c224bf-1017-11e0-b63b-705ab6e51266}\Shell - "" = AutoRun
O33 - MountPoints2\{36c224bf-1017-11e0-b63b-705ab6e51266}\Shell\AutoRun\command - "" = E:\LGAutoRun.exe
O33 - MountPoints2\{6488bc11-b187-11df-9ea5-705ab6e51266}\Shell - "" = AutoRun
O33 - MountPoints2\{6488bc11-b187-11df-9ea5-705ab6e51266}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{6488bc13-b187-11df-9ea5-705ab6e51266}\Shell - "" = AutoRun
O33 - MountPoints2\{6488bc13-b187-11df-9ea5-705ab6e51266}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Program Files (x86)\Combined Community Codec Pack\Filters\FFDShow\ff_vfw.dll ()
Drivers32: vidc.i420 - C:\Windows\SysWow64\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1084

========== Files/Folders - Created Within 30 Days ==========

[2012/06/29 21:55:38 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{1D12CC76-E393-4208-8086-8FA9461315AE}
[2012/06/29 21:55:26 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{7090F71F-F744-41D4-B6EA-8D2FA7A51546}
[2012/06/29 19:30:25 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\ivawsleu
[2012/06/29 09:54:53 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{7242A710-C0FF-4F05-9A9E-10A23C4C3D86}
[2012/06/29 09:54:41 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{97FE2437-8690-4D6A-9601-1E57E73DEB21}
[2012/06/28 21:54:21 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{D3C6DA99-E853-40BE-B699-6712ED42788C}
[2012/06/28 21:54:08 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{72C850ED-3BB0-437B-A45C-8B31CEF33650}
[2012/06/28 20:42:32 | 000,000,000 | —D | C] – C:\Windows\en
[2012/06/28 20:38:24 | 000,048,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fssfltr.sys
[2012/06/28 20:34:34 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{B267C275-B16E-4491-8AC9-203953524CE6}
[2012/06/28 20:34:23 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{5556EF6B-3D6E-47FE-9868-46AEC5A91B12}
[2012/06/28 20:27:50 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{7071BD75-769C-48DB-9200-80FE6E61C2FF}
[2012/06/28 20:27:39 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{161234F5-C5DE-40D2-B4CC-6A706A3574DD}
[2012/06/28 20:27:29 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{5C9FE7BE-3460-46C2-8CAE-0D90C229CEF9}
[2012/06/28 20:27:19 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{0772D968-63BA-4EBD-BECE-2D23FF3754B4}
[2012/06/28 20:27:09 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{493293F5-1504-4A06-9967-69714447F5DE}
[2012/06/28 20:26:58 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{B780D0E3-2C87-409B-8B58-A2A906867B08}
[2012/06/28 20:26:48 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{3FA523EB-7AC6-4972-8576-A37EAF9A11F0}
[2012/06/28 20:26:37 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{AD373357-F4B6-4B45-B686-611ED5D217B4}
[2012/06/28 20:26:25 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{B126786E-4984-4264-A42D-740E2AE768D9}
[2012/06/28 20:26:13 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{D4E95DD4-F513-42EF-BF5D-D4BC143645CD}
[2012/06/28 20:26:03 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{59A0B056-AE70-4990-A32A-E89F3040441F}
[2012/06/28 20:25:51 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{A13B57FD-38E6-4F62-B7F1-F3ACE013257F}
[2012/06/26 11:26:17 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/06/26 11:26:17 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/06/26 11:26:16 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/06/26 11:25:52 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/06/26 11:25:52 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/06/26 11:25:51 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/06/23 23:47:05 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{4E726720-C554-4283-A849-CA5475D242AC}
[2012/06/23 23:46:54 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{E50A0124-AAC8-457C-A735-8C85ACF8EA31}
[2012/06/22 10:01:32 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/06/22 10:01:32 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2012/06/20 08:54:04 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{6AB197A2-28B2-4E69-847F-F694D48E45E3}
[2012/06/20 08:53:47 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{5135D699-CCC9-4549-B845-055C0111023A}
[2012/06/19 08:50:21 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{AE331330-AA36-48C6-B2C5-7680BA192E6E}
[2012/06/19 08:50:05 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\AVG Secure Search
[2012/06/19 08:02:39 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/06/19 08:02:38 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/06/19 08:02:36 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/06/19 08:02:36 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/06/19 08:02:32 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/06/19 08:02:31 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/06/19 08:02:30 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/06/19 08:02:30 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/06/19 08:02:24 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/06/19 08:02:24 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/06/19 08:02:23 | 002,311,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/06/19 08:02:22 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/06/19 08:02:21 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/06/17 13:18:28 | 000,000,000 | —D | C] – C:\Users\radiorentals\FrostWire
[2012/06/17 13:18:23 | 000,000,000 | —D | C] – C:\Users\radiorentals\.frostwire5
[2012/06/17 11:53:23 | 000,426,184 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/06/17 11:53:23 | 000,070,344 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/06/14 23:19:36 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{2D7818AA-162A-4C13-903C-357CFB4D96DD}
[2012/06/14 23:19:24 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{8E8555C9-14B3-4187-8553-143820D4C0D1}
[2012/06/14 21:39:58 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{C9A65FDD-955A-414C-96C5-E9CE877B5B5C}
[2012/06/14 21:39:45 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{0BCFC424-08A6-4AF6-9338-4E4BAAC527D3}
[2012/06/14 21:36:11 | 000,000,000 | -H-D | C] – C:\$AVG
[2012/06/14 21:32:21 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Roaming\AVG2012
[2012/06/14 21:30:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2012
[2012/06/14 21:30:50 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2012/06/14 21:30:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVG Secure Search
[2012/06/14 21:30:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG Secure Search
[2012/06/14 21:30:43 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2012/06/14 21:30:31 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\AVG
[2012/06/14 21:29:50 | 000,000,000 | —D | C] – C:\ProgramData\AVG2012
[2012/06/14 21:29:50 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\AVG
[2012/06/14 21:11:24 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2012/06/14 20:35:17 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorekmts.dll
[2012/06/14 20:35:16 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpwsx.dll
[2012/06/14 20:35:16 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdrmemptylst.exe
[2012/06/14 20:35:06 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/06/14 20:35:05 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/06/14 20:35:04 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/06/14 20:35:00 | 003,216,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msi.dll
[2012/06/14 20:34:49 | 001,462,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012/06/14 20:34:48 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012/06/14 19:59:46 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\Macromedia
[2012/06/14 19:58:12 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{BFF4B682-D5CE-4A3F-B861-A0F09B9A2427}
[2012/06/14 19:58:01 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{457098C9-2E0E-4295-B50B-C06E7EF928B4}
[2012/06/13 15:49:05 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{EE8E9369-85C1-47BC-AE01-FF139683E442}
[2012/06/13 15:48:50 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{C1488EDD-755C-4470-99EE-88E72C3E290E}
[2012/06/12 17:06:21 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{E824A145-8763-447D-9F45-46C9CAA71E5E}
[2012/06/12 17:06:06 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{EB3E53B3-2DE9-4611-89E6-6EA0256CA12B}
[2012/06/11 10:28:23 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{EA46E58B-C36F-4410-938F-F0EAEAC2B5FC}
[2012/06/11 10:28:13 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{E310FE54-DBE4-490A-9BDD-6FF42249317F}
[2012/06/11 10:17:28 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{FFE96526-1B05-4EBF-83C0-427C4DA84BBE}
[2012/06/11 10:17:17 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{E1916FBA-BE68-4362-B3E9-D38350995F42}
[2012/06/07 19:55:28 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{B7ED88FA-ED40-4768-978F-5F3D4F0DB258}
[2012/06/07 19:55:15 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{FEB88999-E9E6-4303-8926-21A102576BAA}
[2012/06/05 17:04:02 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{ABBFA0E3-3214-476F-8EE9-B68AD36D745B}
[2012/06/05 17:03:52 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{0961A955-3CC9-4D58-86FC-FA8F9C6DD163}
[2012/06/04 17:21:12 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{DEF1D142-FAD5-4582-AC55-7D8E0C32750E}
[2012/06/04 17:20:57 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{769BAC13-7A28-4954-8B10-032CBE6F122C}
[2012/06/04 17:11:18 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{51146BCB-FE36-48D0-9D33-55AC0FF3F254}
[2012/06/04 17:11:08 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{FFA318A0-8120-49F4-B441-9B225EF2257B}
[2012/06/03 12:30:25 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{0BF89684-C314-42D9-840E-13AC5421795A}
[2012/06/03 12:30:13 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{C6483662-159B-4E94-92F7-418D9AEDED59}
[2012/06/02 15:58:35 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{01ABE5D9-8805-4DB0-853A-D28D32247E66}
[2012/06/02 15:58:25 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{EF120D16-F395-4A2B-9E97-FFDB8C3302F6}
[2012/06/01 09:32:00 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{0DC69B49-6DF3-4368-B23F-14B2C70C5413}
[2012/06/01 09:31:48 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{82B8ADA1-EAF3-480F-9C6F-8BFCAEEF3103}
[2012/04/19 23:59:20 | 007,760,687 | —- | C] (Boraxsoft) – C:\Users\radiorentals\AppData\Roaming\SetupGFD.exe
[2012/04/19 23:55:55 | 005,514,668 | —- | C] (LIGHTNING UK!) – C:\Users\radiorentals\AppData\Roaming\Imgburn.exe
[2012/04/19 23:55:04 | 005,082,084 | —- | C] (The Public) – C:\Users\radiorentals\AppData\Roaming\Avisynth.exe

========== Files - Modified Within 30 Days ==========

[2012/06/29 22:55:29 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/06/29 22:55:19 | 3113,254,912 | -HS- | M] () – C:\hiberfil.sys
[2012/06/29 22:54:31 | 000,104,047 | RHS- | M] () – C:\Windows\SysNative\masteraclini.enu
[2012/06/29 22:50:25 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/29 22:50:25 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/29 22:47:00 | 000,000,936 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-110146109-1976382319-2385151686-1000UA.job
[2012/06/29 22:43:05 | 000,000,147 | RH– | M] () – C:\Windows\SysNative\masteraclbini.enu
[2012/06/29 22:42:17 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/29 22:41:08 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/29 21:24:02 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/29 21:02:16 | 000,000,512 | -H– | M] () – C:\Windows\tasks\Norton Security Scan for radiorentals.job
[2012/06/29 19:30:24 | 000,092,172 | –S- | M] () – C:\Users\radiorentals\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qcrjdlni.exe
[2012/06/29 19:30:24 | 000,092,172 | —- | M] () – C:\Users\radiorentals\0.37516256241763035.exe
[2012/06/29 19:06:02 | 000,000,956 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-110146109-1976382319-2385151686-1000UA.job
[2012/06/29 08:47:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-110146109-1976382319-2385151686-1000Core.job
[2012/06/29 07:11:36 | 100,783,635 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/06/29 07:10:20 | 000,137,616 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/06/28 22:06:00 | 000,000,934 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-110146109-1976382319-2385151686-1000Core.job
[2012/06/23 22:42:29 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/06/23 22:42:28 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/06/19 08:46:48 | 000,441,168 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/19 08:24:57 | 000,749,420 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/19 08:24:57 | 000,627,138 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/19 08:24:57 | 000,111,676 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/15 07:33:24 | 000,002,438 | —- | M] () – C:\Users\radiorentals\Desktop\Google Chrome.lnk
[2012/06/14 21:30:58 | 000,000,932 | —- | M] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/06/14 21:30:31 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2012/06/14 21:30:31 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2012/06/03 08:19:46 | 000,038,424 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/06/03 08:19:42 | 000,057,880 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/06/03 08:19:42 | 000,044,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/06/03 08:19:23 | 000,701,976 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/06/03 08:15:31 | 002,622,464 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/06/03 08:15:08 | 000,099,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/06/02 15:19:42 | 000,186,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/06/02 15:15:12 | 000,036,864 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe

========== Files Created - No Company Name ==========

[2012/06/29 19:30:25 | 000,092,172 | –S- | C] () – C:\Users\radiorentals\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qcrjdlni.exe
[2012/06/29 19:30:22 | 000,092,172 | —- | C] () – C:\Users\radiorentals\0.37516256241763035.exe
[2012/06/29 07:11:36 | 100,783,635 | —- | C] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/06/29 07:10:20 | 000,137,616 | —- | C] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/06/17 11:53:24 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/14 21:30:58 | 000,000,932 | —- | C] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/06/14 21:30:31 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2012/06/14 21:30:31 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2012/04/20 00:01:42 | 000,034,936 | —- | C] () – C:\Windows\SysWow64\uninstHelixYUV.exe
[2012/04/19 23:57:58 | 005,243,208 | —- | C] ( ) – C:\Users\radiorentals\AppData\Roaming\AvsP.exe
[2012/04/19 23:57:22 | 001,357,348 | —- | C] () – C:\Users\radiorentals\AppData\Roaming\MatroskaSplitter.exe
[2012/04/19 23:57:18 | 000,117,723 | —- | C] () – C:\Users\radiorentals\AppData\Roaming\yuvcodecs-1.3.exe
[2011/12/04 12:16:59 | 000,000,064 | —- | C] () – C:\Windows\GPlrLanc.dat
[2011/12/03 12:55:25 | 000,026,018 | —- | C] () – C:\Users\radiorentals\AppData\Roaming\UserTile.png
[2011/08/07 17:54:08 | 000,012,712 | -HS- | C] () – C:\ProgramData\vydm2tkqc846qk5r2761qlb8ah15252rc05a0p
[2011/08/07 17:54:08 | 000,012,586 | -HS- | C] () – C:\Users\radiorentals\AppData\Local\vydm2tkqc846qk5r2761qlb8ah15252rc05a0p
[2010/12/04 17:52:04 | 000,000,100 | —- | C] () – C:\Users\radiorentals\AppData\Local\fusioncache.dat
[2010/12/04 17:47:31 | 000,749,200 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/12/01 18:24:37 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/09/30 10:07:56 | 008,007,680 | —- | C] ( ) – C:\Windows\SysWow64\Microsoft.mshtml.dll
[2010/09/30 10:07:55 | 000,126,976 | —- | C] ( ) – C:\Windows\SysWow64\Interop.SHDocVw.dll
[2010/06/09 11:57:47 | 000,000,946 | —- | C] () – C:\Users\radiorentals\AppData\Roaming\wklnhst.dat
[2010/06/06 12:15:54 | 000,000,032 | R— | C] () – C:\ProgramData\hash.dat

========== LOP Check ==========

[2011/12/06 07:24:47 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Alawar
[2012/06/14 23:14:53 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\AVG2012
[2012/03/15 18:10:07 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Babylon
[2010/12/10 16:58:04 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\BBB
[2012/04/17 20:07:50 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Canon
[2010/06/06 07:55:13 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Faerie Solitaire
[2012/04/18 15:14:14 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\FUJIFILM
[2010/06/26 15:51:41 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Gaijin Ent
[2010/11/12 20:09:49 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Gamelab
[2011/06/24 17:49:45 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\GetRightToGo
[2012/04/07 00:28:53 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\HTC
[2011/05/15 18:43:39 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Leadertech
[2011/12/08 22:21:25 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\monkey money
[2012/05/17 17:02:44 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\MusicNet
[2010/09/28 11:28:20 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\OpenOffice.org
[2010/06/05 11:15:02 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Packard Bell
[2011/12/08 19:54:32 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\PlayFirst
[2011/11/05 11:37:14 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Shareaza
[2010/06/05 09:31:41 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\SNS
[2010/06/09 11:57:48 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Template
[2010/09/28 11:28:20 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\TomTom
[2012/03/24 18:40:50 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Uniblue
[2011/12/11 12:03:57 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Virtual City
[2012/05/21 20:42:53 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\WildTangent
[2010/09/28 11:28:20 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\WildTangentv1002
[2012/01/03 11:15:44 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Windows Live Writer
[2012/06/28 22:06:00 | 000,000,934 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-110146109-1976382319-2385151686-1000Core.job
[2012/06/29 19:06:02 | 000,000,956 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-110146109-1976382319-2385151686-1000UA.job
[2012/03/10 01:10:17 | 000,032,588 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2010/04/01 15:06:26 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2007/11/08 01:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/08 01:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/08 01:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/08 01:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/08 01:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/08 01:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/08 01:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/08 01:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/08 01:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/08 01:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/06/29 22:55:19 | 3113,254,912 | -HS- | M] () – C:\hiberfil.sys
[2007/11/08 01:44:20 | 000,855,040 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/08 01:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/08 01:44:20 | 000,075,280 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/08 01:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/08 01:44:20 | 000,090,128 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/08 01:44:20 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/08 01:44:20 | 000,094,224 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/08 01:44:20 | 000,080,400 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/08 01:44:20 | 000,078,864 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/08 01:44:20 | 000,074,768 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/08 01:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2012/06/29 22:55:19 | 4151,009,280 | -HS- | M] () – C:\pagefile.sys
[2010/04/01 15:06:26 | 000,003,274 | —- | M] () – C:\RHDSetup.log
[2011/04/02 07:41:01 | 000,000,404 | —- | M] () – C:\rkill.log
[2010/04/01 15:06:26 | 000,005,902 | —- | M] () – C:\scramble.log
[2012/03/16 01:12:44 | 000,000,510 | —- | M] () – C:\settings.ini
[1999/12/31 23:00:08 | 000,000,895 | —- | M] () – C:\tmp1
[1999/12/31 23:00:10 | 000,000,128 | —- | M] () – C:\tmp2
[2012/03/15 18:10:19 | 000,000,237 | —- | M] () – C:\user.js
[2007/11/08 01:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/08 01:50:40 | 001,927,956 | —- | M] () – C:\VC_RED.cab
[2007/11/08 01:53:12 | 000,242,176 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2009/07/14 15:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 15:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 15:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 15:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/11 06:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/03/08 18:37:20 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 14:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/09/02 13:09:53 | 000,000,314 | -HS- | M] () – C:\Users\radiorentals\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/04/02 07:45:56 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Users\radiorentals\Desktop\mbam-setup-1.50.1.1100.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 180 bytes -> C:\ProgramData\Temp:CB0AACC9
@Alternate Data Stream - 16 bytes -> C:\Users\radiorentals\Downloads:Shareaza.GUID
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:1DA424AA
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:D1B5B4F1

< End of report >
Extras.Txt file

OTL Extras logfile created on: 6/30/2012 12:21:39 AM - Run 1
OTL by OldTimer - Version 3.2.53.0 Folder = C:\Users\radiorentals\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.87 Gb Total Physical Memory | 2.93 Gb Available Physical Memory | 75.74% Memory free
7.73 Gb Paging File | 6.87 Gb Available in Paging File | 88.84% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.99 Gb Total Space | 197.56 Gb Free Space | 69.08% Space Free | Partition Type: NTFS

Computer Name: ALISON | User Name: radiorentals | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [FinePix] – "C:\Program Files (x86)\FinePixViewer\FinePixViewer.exe" "%1" (FUJIFILM Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [FinePix] – "C:\Program Files (x86)\FinePixViewer\FinePixViewer.exe" "%1" (FUJIFILM Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00238B40-8E93-4626-846B-382BDD3212F7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{00866821-3E89-4CE5-A939-3BFAE3AEE8C7}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{05847DD0-5C52-47F0-A9B4-0309AE347CCE}" = rport=137 | protocol=17 | dir=out | app=system |
"{1B3EF682-9281-4FC1-9521-BA4E666AD326}" = rport=445 | protocol=6 | dir=out | app=system |
"{276CA5CC-F3AE-48EF-809E-C77AE74FBD5E}" = rport=138 | protocol=17 | dir=out | app=system |
"{2B83AAB2-CC9C-4345-B845-6F62B31EF04D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{31CF4831-DB25-4F0B-B622-9E68E16F17E1}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3F0A4361-4DAE-47B5-8E08-5C71CC4F4FBB}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4439A6D4-6E17-4B9A-BA7C-52706C135C26}" = lport=445 | protocol=6 | dir=in | app=system |
"{455EA44D-E53E-42AD-BA47-F12C82F7EAF5}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{492C1160-4B2F-4E7C-B423-CC34070DC6C6}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{57EE6FFD-5D6B-41ED-8A0E-93F9097271A8}" = lport=2869 | protocol=6 | dir=in | app=system |
"{58BAD898-DE57-4C26-95A2-F34B8337C9C7}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{58C227BE-22ED-4428-9971-DFE21EF898EE}" = lport=138 | protocol=17 | dir=in | app=system |
"{5982EA31-1C3B-4EE3-95E0-70B78C819F9F}" = lport=137 | protocol=17 | dir=in | app=system |
"{6F143093-36B6-4F93-A6BF-807A6C09BA63}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{83334C47-4E18-499B-9E97-48587166D22E}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{838E4629-8776-4A0A-AD71-B87D8CC69AC5}" = rport=139 | protocol=6 | dir=out | app=system |
"{9022E9E3-8D8C-408A-9754-15ECC060B6EC}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{99937210-60D4-4D54-A0BD-BDE64F6BE1D5}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{AB0D8AE8-49CF-429B-9354-0FDFFF6A6F9A}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{AB56885F-26F2-4029-9FD7-FA3EA4B05E09}" = lport=139 | protocol=6 | dir=in | app=system |
"{B1B629AB-0EA1-4C53-AF41-582A1306933C}" = rport=10243 | protocol=6 | dir=out | app=system |
"{C4B90F0C-470D-46D5-8CC7-33FB6DCE887C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CDB3F560-6B09-4CF9-BDCB-9272AF176EFB}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D953CB4C-63BC-4EC9-8430-E9BB7C2BAAFC}" = lport=10243 | protocol=6 | dir=in | app=system |
"{E241D634-1349-4640-81B7-C8D75EAE4574}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{EC86FF98-6129-40D8-B93E-428EC25177AF}" = lport=2869 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00549EA6-87BB-4D40-939D-F0D55BA696EB}" = protocol=17 | dir=in | app=c:\users\radiorentals\appdata\local\temp\7zs1f81.tmp\symnrt.exe |
"{03DD1157-EC97-4236-8144-F9EE36486773}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{071F1BAC-FD6E-498B-ABD3-D2D11CD6FC34}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{07C63556-D59B-45CA-9F86-E2DB89A28E3F}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{0C638C3E-36C2-48B6-9305-1483E7E72E98}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{0D228912-3DE1-49E9-B8AE-266E60B5FC35}" = protocol=6 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"{0D90772D-CA26-44C1-83F4-EA9A4E5AF02A}" = protocol=17 | dir=in | app=c:\program files (x86)\imesh applications\imesh\imesh.exe |
"{19AC118F-E5B7-47A8-882B-CCBA9EF6FBEF}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{1D1BBD11-67E7-438F-910A-E99356988A03}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{22729F89-79D7-4353-8D34-30D7F4671B01}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{2A3BEEEA-D1B4-4D3C-BD0F-623AAF6F4B77}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{2CCC269D-BB41-408C-80D4-856F9BFF1D38}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{2E34B47F-B0F4-4304-B71E-54643F4B50FB}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{319EE9D3-DB5B-4D25-8F90-0903D86583FD}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{326A744C-BCE6-42CF-8EA4-141566D5E122}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{32CAB875-4B5F-4A5F-B441-0FECBD98AA34}" = protocol=6 | dir=in | app=c:\program files (x86)\imesh applications\mediabar\datamngr\toolbar\dtuser.exe |
"{35F72E42-3AC2-4676-8F84-DAEB1B2C2AC0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3685798A-F010-44AC-A897-2F9DEE6ECE86}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{39F39992-D210-4E41-816C-06FF556F4E2B}" = protocol=17 | dir=in | app=c:\program files (x86)\frostwire 5\frostwire.exe |
"{3D6CD9EF-A858-4076-B119-D4FF4B569C89}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{404A7294-CCD4-4ABD-A416-C2A7418AF6A2}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{42863596-4788-4511-BC68-B95EDC0B75C7}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{4C77EE5A-7A12-47B5-9621-6C0F6E521FCE}" = protocol=17 | dir=in | app=c:\program files (x86)\imesh applications\mediabar\datamngr\toolbar\dtuser.exe |
"{4D748DCA-075C-4C56-BC70-99B0A149CDCB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{50F04392-4999-4A1A-829D-FAF7970C601E}" = protocol=6 | dir=in | app=c:\program files (x86)\imesh applications\imesh\imesh.exe |
"{56FC7096-D862-4C50-B2A9-75133B8C2783}" = dir=in | app=c:\users\radiorentals\appdata\local\facebook\video\skype\facebookvideocalling.exe |
"{5A787944-5A47-4843-A6D7-32D65999BAEF}" = protocol=6 | dir=in | app=c:\program files (x86)\frostwire 5\frostwire.exe |
"{5C275BF5-7FBE-448E-B65E-A3BAEC4FA7F6}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{5E2E8FE7-230D-4EC9-829E-0CA4186DF1A6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5E2EBEE5-EB01-4338-A9DB-03E18F1CFA60}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{5FF87406-7D5A-4858-8037-43DCEDA92681}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{60A11B90-791D-4DAF-A62D-58090BA78C4D}" = protocol=17 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"{635C3A5C-1742-48F2-99E4-CFBC20DB7360}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{66E089CF-4DF8-43D1-A9C6-2BCBAD426852}" = protocol=17 | dir=in | app=c:\program files (x86)\imesh applications\imesh\imesh.exe |
"{6AE28459-6D57-4FC9-9F6E-3D6932AA91A6}" = protocol=6 | dir=out | app=system |
"{6BC76BB3-E416-4F83-92E5-2F832058FC04}" = protocol=6 | dir=in | app=c:\program files (x86)\imesh applications\imesh\imesh.exe |
"{76ADF1B0-420F-41E9-A22F-48671198AA6F}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd9\powerdvd9.exe |
"{7DFCFBE5-603B-4EE8-8069-B700FA1D2DB5}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{7ED787DC-BE12-4631-8D93-B5005F037888}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{8239BB80-A637-4F3C-A726-A637D68861D0}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{93CA4BA1-48E9-44E2-9447-CC5E9AF45694}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{95E2946C-B936-40EF-8154-C23A40BBC4BA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{973D0719-AFE7-4BC1-ABB7-291B883F4E7B}" = protocol=6 | dir=in | app=c:\users\radiorentals\appdata\local\temp\7zs1f81.tmp\symnrt.exe |
"{9B502C8A-8BD1-431D-A2AC-18B36482BA12}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{9FF9C940-FE5D-422B-9C84-6BC478BA5FBD}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{A071C336-5408-428D-8788-9B9452A6FA98}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{A592B22F-C8D3-47E3-A06F-A3BD1C032B80}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{AD66581E-60FB-43FE-92ED-8363031329BF}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{B1134CF4-029B-49B9-A46D-DC4DE5181A0C}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{BA5FF784-6854-47A0-99C1-CAE10A54A641}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{BABAE043-A111-4E88-A143-15737A9DB52A}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{C7E19212-159A-4E89-8B1D-6C5B0B9A2C19}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{C8BAF450-C82C-4B56-B1D4-5FBE8FEE178D}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{C8C7E8EC-CF85-49C2-9A5D-69AF9FE3989E}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{CA1538EB-FD57-4C62-A944-6833C3C6987A}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{CCF535DE-BC15-43AD-9016-944054FD1074}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{D83AAD80-0D88-4767-B818-1D9D26BC5227}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{DA04EC08-5910-419A-8968-AE454D45EEA0}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{E3542546-E922-483C-8C37-257F1928ABBB}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{E5C6393D-7BF6-41B6-98E7-A0227B7DE4DD}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{E674639A-94CA-4D7A-90FB-ED68D5FD4D29}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"TCP Query User{1A7D3E59-8DA3-47F9-A359-0D85AD295C41}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"TCP Query User{26B83EE7-477F-4D2B-BDEF-F3B30F59E90E}C:\program files (x86)\phone call recorder\phonerec.exe" = protocol=6 | dir=in | app=c:\program files (x86)\phone call recorder\phonerec.exe |
"TCP Query User{29B2DFCC-D203-4602-8018-1964FDBBF3AE}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe |
"TCP Query User{9CEAFC6B-64D2-484E-8D90-B2039DDD0E0B}C:\program files (x86)\phone call recorder\phonerec.exe" = protocol=6 | dir=in | app=c:\program files (x86)\phone call recorder\phonerec.exe |
"TCP Query User{A4C0BDC4-8FA4-4374-849B-90AA232F3487}C:\windows\syswow64\svchost.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\svchost.exe |
"TCP Query User{C7ADEA90-330E-436E-9B39-5DAFA1DCCADD}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe |
"TCP Query User{E16EE487-CEB1-4311-81ED-D34BFA3152DF}C:\windows\syswow64\svchost.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\svchost.exe |
"UDP Query User{03F8B8B9-94A5-4BDB-B9A0-CEE94483D3C1}C:\windows\syswow64\svchost.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\svchost.exe |
"UDP Query User{146B3058-CC35-4777-90A6-B9B100062FE8}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe |
"UDP Query User{2EB5D0EF-7FE1-4E0E-883C-0CAF47D65905}C:\program files (x86)\phone call recorder\phonerec.exe" = protocol=17 | dir=in | app=c:\program files (x86)\phone call recorder\phonerec.exe |
"UDP Query User{4398A696-8A68-4549-A4DC-22994D68781B}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"UDP Query User{5E6CF37C-62B1-49A8-A8B3-E31E28D65673}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe |
"UDP Query User{6E3A7033-D109-4864-862A-DF3562FB2C37}C:\program files (x86)\phone call recorder\phonerec.exe" = protocol=17 | dir=in | app=c:\program files (x86)\phone call recorder\phonerec.exe |
"UDP Query User{A7CF5BFD-D7FA-4D41-B831-4362D908EC16}C:\windows\syswow64\svchost.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\svchost.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{02A5BD31-16AC-45DF-BE9F-A3167BC4AFB2}" = Windows Live Family Safety
"{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG6100_series" = Canon MG6100 series MP Drivers
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{3C8159DD-1890-4625-A5B2-E3D8D78D4486}" = AVG 2012
"{5E11C972-1E76-45FE-8F92-14E0D1140B1B}" = iTunes
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo 1.10.02
"{8B79B3A9-6E49-5FFB-2017-A822BBDC4992}" = ATI Catalyst Install Manager
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}" = Microsoft Security Client
"{A84DB02B-9C2B-4272-9D2D-A80E00A56513}" = Broadcom Gigabit NetLink Controller
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B0B97CF2-5032-A645-7FFC-BD1E39FC4E3F}" = ccc-utility64
"{D050583D-5CEC-47B1-88AA-8B328CAA8621}" = AVG 2012
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"2CA3B8348CD526E9B8928840AC68738C5B5A4F8F" = Windows Driver Package - Thomson (USB_RNDIS) Net (02/15/2007 2.0.0.0)
"5AF8BE22A56B38B1816F36BAC6A71F1277E45440" = Windows Driver Package - NETGEAR Inc. (RTL8187) Net (12/01/2006 6.1258.1201.2006)
"AVG" = AVG 2012
"B090418E214D6BD6EE18A512A8EE609225AC9279" = Windows Driver Package - Atheros Communications Inc. (arusb_lhx) Net (09/25/2008 3.1.0.101)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinRAR archiver" = WinRAR archiver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02A414EA-0E5F-CD08-61EF-E155F31DFF76}" = Catalyst Control Center Graphics Previews Vista
"{08938019-97FA-1C7A-19E0-0C8D56ED7CB2}" = CCC Help Hungarian
"{0A4D717B-E6E8-11FA-E7D2-385EBB1A4A85}" = CCC Help Japanese
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{12A1B519-5934-4508-ADBD-335347B0DC87}" = Video Web Camera
"{13BA5548-1065-4DBE-B115-681AFB77263B}" = CCC Help Swedish
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{16890D7F-1C77-733B-D8E4-F5D4315A5F93}" = Catalyst Control Center Localization All
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1CBDB473-E303-EFAE-88D1-6F741ACD5B31}" = CCC Help Czech
"{1D8912B0-343C-EB1F-28EE-B672D444C192}" = Catalyst Control Center InstallProxy
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20400DBD-E6DB-45B8-9B6B-1DD7033818EC}" = Nero InfoTool Help
"{2348B586-C9AE-46CE-936C-A68E9426E214}" = Nero StartSmart Help
"{24ED4D80-8294-11D5-96CD-0040266301AD}" = FinePixViewer Ver.5.3
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 22
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2C59BF0E-66A5-681E-60FE-8D18CE6319A1}" = CCC Help German
"{2C9D4FCA-3E7F-9368-6955-EA6D65F7DC78}" = CCC Help English
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33CF58F5-48D8-4575-83D6-96F574E4D83A}" = Nero DriveSpeed
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3788B9B7-C15F-4C64-D52B-3DD1BA494B7A}" = CCC Help Korean
"{3D200EB9-44FC-432F-1E35-C20AB5FDCD77}" = CCC Help Thai
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Gateway Power Management
"{3DEDEE1A-E391-49B8-B3AA-2ABD5ACE0013}" = Brother HL-2140
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{433A39B0-380C-4634-93FE-12A812954F5B}" = BigPond Broadband ADSL
"{44D52071-5077-2839-1AE6-863563AEA269}" = CCC Help Russian
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4BCBC4D0-1D88-462D-809E-506F34EA11C0}" = Catalyst Control Center - Branding
"{4D43D635-6FDA-4FA5-AA9B-23CF73D058EA}" = Nero StartSmart OEM
"{4F4C5E11-0612-48D2-8055-987992AAC432}" = wxDfast
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{619298EB-D2D1-49C1-8096-88A75CC92E5F}" = SBP
"{64EF903E-D00A-414C-94A4-FBA368FFCDC9}" = Gateway Social Networks
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6ADD0603-16EF-400D-9F9E-486432835002}" = OpenOffice.org 3.2
"{6B0A8356-2312-497F-B11D-0839D0BDB7CE}" = HTC Sync
"{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-gateway" = WildTangent Games App (Gateway Games)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic
"{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling [removed]
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Gateway Recovery Management
"{83202942-84B3-4C50-8622-B8C0AA2D2885}" = Nero Express Help
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{869200DB-287A-4DC0-B02B-2B6787FBCD4C}" = Nero DiscSpeed
"{87976D85-DBF6-F263-39B6-500ACB658CE0}" = Catalyst Control Center Graphics Full Existing
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C20787A-7402-4FA7-BF25-6E5750930FDC}" = PowerDVD
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8FB495A1-4A3F-4C1D-BD27-3F3AB2E66763}" = iMesh
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{975C3A93-2491-3D44-A071-F6CBF153E46D}" = Google Talk Plugin
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9BBB29A1-C71D-DD1D-66B1-352AAAB13FC6}" = CCC Help Danish
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9F4D1D9E-5542-B572-81A7-9DCB0AEED1BE}" = CCC Help French
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A3EF3FAD-6ABA-1551-AD3B-D09361C5EEC9}" = CCC Help Polish
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A73FBC00-44F8-0ECF-76FB-14CF62120B55}" = ccc-core-static
"{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AACEAAE9-9CC3-5715-4539-EB13CA3C67BA}" = CCC Help Spanish
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB756389-9A03-44f3-ABAF-3699C01B4868}-Navman-7.30" = NavDesk 7.30
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.5.1 MUI
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B2463AD3-1334-A30E-A523-D38E8E7B09A2}" = CCC Help Dutch
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{BA2AD7F2-55AE-87B5-00DD-9B0C6F087FD0}" = Catalyst Control Center Graphics Light
"{BC940CD7-FC71-83C5-2001-CF6FD07BA3D1}" = CCC Help Chinese Traditional
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{BF847A60-119D-6888-B2DA-EC62F1B66BBB}" = CCC Help Chinese Standard
"{C078C299-C2C2-4110-A6EF-8D5E66C228DA}" = e-tax 2011
"{c25cac75-0ca2-4a35-9734-0cac6c70e003}" = Nero 9 Essentials
"{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}" = Norton Online Backup
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C81A2FE0-3574-00A9-CED4-BDAA334CBE8E}" = Nero Online Upgrade
"{C97396A9-44BC-C856-0B92-93A6A417D6A8}" = Catalyst Control Center Graphics Full New
"{CA10114E-3941-E8ED-70A3-17CAA2226AFC}" = CCC Help Turkish
"{CAB89605-7C12-8082-32DF-B419C696BD12}" = Catalyst Control Center Core Implementation
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC019E3F-59D2-4486-8D4B-878105B62A71}" = Nero DiscSpeed Help
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D6C3C9E7-D334-4918-BD57-5B1EF14C207D}" = Bing Bar
"{D98C2191-0AE0-4087-9153-018A4810DF45}" = CCC Help Norwegian
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DF7D3C5E-87FC-6AE6-D986-35E0F05FEFD9}" = CCC Help Italian
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E5C7D048-F9B4-4219-B323-8BDB01A2563D}" = Nero DriveSpeed Help
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{EBA8538C-F0B1-A089-D555-44DBF3A47C9F}" = CCC Help Finnish
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Gateway Updater
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F22E305E-BD02-5CC1-92D0-BD7170CDFE45}" = CCC Help Portuguese
"{F4041DCE-3FE1-4E18-8A9E-9DE65231EE36}" = Nero ControlCenter
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FBCDFD61-7DCF-4E71-9226-873BA0053139}" = Nero InfoTool
"{FBE569CA-BFEB-4E57-A674-F94D938E1AEF}" = e-tax 2010
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FD4B3108-0915-31E1-5A7C-AC5B3C33846C}" = CCC Help Greek
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"AviSynth" = AviSynth 2.6
"AvsP_is1" = AvsP
"BE37E547-62DF-43C8-AE6A-D03E82BC67A2_is1" = DVD slideshow GUI 0.9.5.1
"Belarc Advisor" = Belarc Advisor 8.1
"Canon Easy-PhotoPrint Pro - Pro9000 series Extention Data" = Canon Easy-PhotoPrint Pro - Pro9000 series Extention Data
"Canon Easy-PhotoPrint Pro - Pro9500 series Extention Data" = Canon Easy-PhotoPrint Pro - Pro9500 series Extention Data
"CANONIJPLM100" = Canon Inkjet Printer/Scanner/Fax Extended Survey Program
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenuEX" = Canon Solution Menu EX
"Cheat Engine 6.1_is1" = Cheat Engine 6.1
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2011-06-26
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"Easy-PhotoPrint Pro" = Canon Easy-PhotoPrint Pro
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"Gateway InfoCentre" = Gateway InfoCentre
"Gateway Registration" = Gateway Registration
"Gateway Screensaver" = Gateway ScreenSaver
"Gateway Welcome Center" = Welcome Center
"GUI for dvdauthor" = GUI for dvdauthor 1.07
"HaaliMkx" = Haali Media Splitter
"HelixYUVCodecs" = Helix YUV Codecs (remove only)
"Identity Card" = Identity Card
"iMesh" = iMesh
"ImgBurn" = ImgBurn
"InstallShield_{64EF903E-D00A-414C-94A4-FBA368FFCDC9}" = Gateway Social Networks
"InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Gateway MyBackup
"InstallShield_{8C20787A-7402-4FA7-BF25-6E5750930FDC}" = PowerDVD
"InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9
"Jewel Quest Solitaire III 1.00" = Jewel Quest Solitaire III 1.00
"LManager" = Launch Manager
"MediaNavigation.CDLabelPrint" = CD-LabelPrint
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox 13.0.1 (x86 en-US)" = Mozilla Firefox 13.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 4.0" = Canon MP Navigator EX 4.0
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"OpenAL" = OpenAL
"Picasa 3" = Picasa 3
"VIRGIN BROADBAND" = VIRGIN BROADBAND
"WildTangent gateway Master Uninstall" = Gateway Games
"Wincore MediaBar" = Wincore MediaBar
"WinLiveSuite" = Windows Live Essentials
"WT078871" = Bejeweled 2 Deluxe
"WT078886" = Insaniquarium Deluxe
"WT078903" = Zuma Deluxe
"WT078959" = Blasterball 3
"WT078963" = Bob the Builder Can-Do-Zoo
"WT079019" = Faerie Solitaire
"WT079063" = Jewel Quest
"WT079067" = Jewel Quest Solitaire 3
"WT079107" = Penguins!
"WT079115" = Polar Bowler
"WT079119" = Polar Golfer
"WT079123" = Polar Pool
"WT079176" = Virtual Villagers - A New Home
"WT079182" = Yahtzee
"WT079239" = Build-a-lot 2
"WT079245" = Chicken Invaders 3 - Revenge of the Yolk
"WT079258" = Escape Rosecliff Island
"WT079263" = Mahjongg Artifacts
"WT079419" = Virtual Families
"WT084387" = Virtual City
"WT089150" = Great Secrets - Da Vinci
"WTA-2cc9896d-2942-4cbc-a176-89bf5f452143" = Virtual Farm
"WTA-5d51cc55-fa87-49c2-9849-4e8249f19499" = Lost Lagoon - The Trail of Destiny
"WTA-859c839d-2147-4185-b0ea-5bdf1574824f" = The Lost Kingdom Prophecy
"WTA-8930701e-a575-4952-90e7-203bd704f49f" = Bistro Boulevard
"WTA-b56c747a-3ce7-44a4-9f2c-d956920c2fa1" = World Cup Cricket 20-20
"WTA-d59b7a3f-3d3c-4413-b62e-7d2782789a4d" = Cruise Clues: Caribbean Adventure
"wxDownload Fast_is1" = wxDownload Fast 0.6.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Amazon Kindle" = Amazon Kindle
"Google Chrome" = Google Chrome

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 10/25/2011 10:17:11 AM | Computer Name = Alison | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 10/25/2011 7:00:12 PM | Computer Name = Alison | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 10/26/2011 3:31:16 AM | Computer Name = Alison | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 10/27/2011 2:15:16 AM | Computer Name = Alison | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 10/27/2011 6:10:23 PM | Computer Name = Alison | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 10/27/2011 6:36:53 PM | Computer Name = Alison | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 10/28/2011 4:43:14 PM | Computer Name = Alison | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 10/29/2011 7:49:00 PM | Computer Name = Alison | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 11/1/2011 5:44:42 PM | Computer Name = Alison | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 11/1/2011 6:08:13 PM | Computer Name = Alison | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

[ Media Center Events ]
Error - 8/7/2010 12:37:37 PM | Computer Name = Alison | Source = MCUpdate | ID = 0
Description = 9:37:37 AM - Error connecting to the internet. 9:37:37 AM - Unable
to contact server..

Error - 8/7/2010 12:37:45 PM | Computer Name = Alison | Source = MCUpdate | ID = 0
Description = 9:37:42 AM - Error connecting to the internet. 9:37:42 AM - Unable
to contact server..

Error - 8/7/2010 1:37:50 PM | Computer Name = Alison | Source = MCUpdate | ID = 0
Description = 10:37:50 AM - Error connecting to the internet. 10:37:50 AM - Unable
to contact server..

Error - 8/7/2010 1:37:56 PM | Computer Name = Alison | Source = MCUpdate | ID = 0
Description = 10:37:55 AM - Error connecting to the internet. 10:37:55 AM - Unable
to contact server..

Error - 8/7/2010 2:38:01 PM | Computer Name = Alison | Source = MCUpdate | ID = 0
Description = 11:38:01 AM - Error connecting to the internet. 11:38:01 AM - Unable
to contact server..

Error - 8/7/2010 2:38:07 PM | Computer Name = Alison | Source = MCUpdate | ID = 0
Description = 11:38:06 AM - Error connecting to the internet. 11:38:06 AM - Unable
to contact server..

Error - 5/19/2012 6:10:52 PM | Computer Name = Alison | Source = MCUpdate | ID = 0
Description = 8:10:52 AM - Error connecting to the internet. 8:10:52 AM - Unable
to contact server..

Error - 5/19/2012 6:11:01 PM | Computer Name = Alison | Source = MCUpdate | ID = 0
Description = 8:10:57 AM - Error connecting to the internet. 8:10:57 AM - Unable
to contact server..

Error - 5/19/2012 7:11:06 PM | Computer Name = Alison | Source = MCUpdate | ID = 0
Description = 9:11:06 AM - Error connecting to the internet. 9:11:06 AM - Unable
to contact server..

Error - 5/19/2012 7:11:12 PM | Computer Name = Alison | Source = MCUpdate | ID = 0
Description = 9:11:11 AM - Error connecting to the internet. 9:11:11 AM - Unable
to contact server..

[ System Events ]
Error - 6/29/2012 10:21:39 AM | Computer Name = Alison | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 6/29/2012 10:23:45 AM | Computer Name = Alison | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 6/29/2012 10:23:45 AM | Computer Name = Alison | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 6/29/2012 10:23:45 AM | Computer Name = Alison | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 6/29/2012 10:28:45 AM | Computer Name = Alison | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 6/29/2012 10:28:45 AM | Computer Name = Alison | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 6/29/2012 10:28:45 AM | Computer Name = Alison | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 6/29/2012 10:30:53 AM | Computer Name = Alison | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 6/29/2012 10:30:53 AM | Computer Name = Alison | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068

Error - 6/29/2012 10:30:53 AM | Computer Name = Alison | Source = Service Control Manager | ID = 7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068


< End of report >
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-06-30 00:45:15 —————————– 00:45:15.505 OS Version: Windows x64 6.1.7601 Service Pack 1 00:45:15.505 Number of processors: 4 586 0x2502 00:45:15.505 ComputerName: ALISON UserName: 00:45:16.525 Initialize success 00:45:53.063 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 00:45:53.063 Disk 0 Vendor: TOSHIBA_ GJ00 Size: 305245MB BusType: 3 00:45:53.073 Disk 0 MBR read successfully 00:45:53.073 Disk 0 MBR scan 00:45:53.073 Disk 0 Windows 7 default MBR code 00:45:53.073 Disk 0 Partition 1 00 27 Hidden NTFS WinRE 12291 MB offset 63 00:45:53.083 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 101 MB offset 25173855 00:45:53.093 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 292850 MB offset 25382700 00:45:53.103 Disk 0 Partition 4 00 DE Dell Utility 146 MB offset 250 00:45:53.123 Disk 0 scanning C:\Windows\system32\drivers 00:46:01.203 Service scanning 00:46:28.633 Modules scanning 00:46:28.633 Disk 0 trace - called modules: 00:46:28.673 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 00:46:28.683 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80060c5060] 00:46:28.683 3 CLASSPNP.SYS[fffff88001b9543f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80050ef050] 00:46:28.683 Scan finished successfully 00:47:36.108 Disk 0 MBR has been saved successfully to "C:\Users\radiorentals\Desktop\MBR.dat" 00:47:36.108 The log file has been saved successfully to "C:\Users\radiorentals\Desktop\aswMBR.txt"
Hi,

Please download ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
———-

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
    IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2438727
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.imesh.net
    IE - HKCU\..\URLSearchHook: {F08555B0-9CC3-11D2-AA8E-000000000567} - No CLSID value found
    IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?FORM=VIATDF&…rc=IE-SearchBox
    IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}…0000017c4f4f1d2
    IE - HKCU\..\SearchScopes\{4B8C28A7-A9BC-45F8-990D-21499EED643C}: "URL" = http://www.questscan.com/?prt=QstscanPB&am…s={searchTerms}
    IE - HKCU\..\SearchScopes\{78FF7C5E-67BA-4E4A-B09E-84BFE0DF08D6}: "URL" = http://websearch.ask.com/redirect?client=i…9B-8713DF73C198
    IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&a…q={searchTerms}
    IE - HKCU\..\SearchScopes\{A531D99C-5A22-449b-83DA-872725C6D0ED}: "URL" = http://search.alot.com/web?q={searchTerms}…n=1.1.3001.0(
    IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2438727
    FF - prefs.js..browser.search.order.1: "Search Results"
    FF - prefs.js..browser.startup.homepage: "http://search.imesh.net"
    FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
    FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
    [2012/04/29 00:14:54 | 000,000,000 | —D | M] (wxDfast) – C:\Users\radiorentals\AppData\Roaming\mozilla\Firefox\Profiles\1nxsss19.default\extensions\[removed]
    [2012/03/20 13:52:38 | 000,002,205 | —- | M] () – C:\Users\radiorentals\AppData\Roaming\Mozilla\Firefox\Profiles\1nxsss19.default\searchplugins\alot-search.xml
    [2011/06/08 13:47:03 | 000,002,574 | —- | M] () – C:\Users\radiorentals\AppData\Roaming\Mozilla\Firefox\Profiles\1nxsss19.default\searchplugins\askcom.xml
    [2011/03/20 16:30:43 | 000,001,834 | —- | M] () – C:\Users\radiorentals\AppData\Roaming\Mozilla\Firefox\Profiles\1nxsss19.default\searchplugins\bing.xml
    [2012/05/17 17:03:00 | 000,002,517 | —- | M] () – C:\Users\radiorentals\AppData\Roaming\Mozilla\Firefox\Profiles\1nxsss19.default\searchplugins\Search_Results.xml
    [2012/05/17 17:03:07 | 000,000,000 | —D | M] (Wincore Mediabar) – C:\Users\radiorentals\AppData\Roaming\mozilla\Firefox\Profiles\1nxsss19.default\extensions\{28387537-e3f9-4ed7-860c-11e69af4a8a0}
    [2012/03/15 18:10:12 | 000,002,310 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml
    [2012/06/17 11:44:56 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
    [2012/05/17 17:03:00 | 000,002,517 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml
    O2:64bit: - BHO: (DataMngr) - {BE7A24F5-69CB-4708-B77B-B1EDA6043B95} - C:\Program Files (x86)\iMesh Applications\MediaBar\Datamngr\x64\BrowserConnection.dll (iMesh, Inc)
    O2 - BHO: (Wincore Mediabar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\Program Files (x86)\iMesh Applications\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll ()
    O2 - BHO: (DataMngr) - {BE7A24F5-69CB-4708-B77B-B1EDA6043B95} - C:\Program Files (x86)\iMesh Applications\MediaBar\Datamngr\BrowserConnection.dll (iMesh, Inc)
    O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (Wincore Mediabar) - {28387537-e3f9-4ed7-860c-11e69af4a8a0} - C:\Program Files (x86)\iMesh Applications\MediaBar\Datamngr\ToolBar\wincoreimdtx.dll ()
    O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
    O4:64bit: - HKLM..\Run: [apvxdwin] File not found
    O4:64bit: - HKLM..\Run: [avgnt] File not found
    O4:64bit: - HKLM..\Run: [Defender Pro Antiphishing Helper] File not found
    O4:64bit: - HKLM..\Run: [DPAgent] File not found
    O4:64bit: - HKLM..\Run: [G Data AntiVirus Tray Application] File not found
    O4:64bit: - HKLM..\Run: [GDFirewallTray] File not found
    O4:64bit: - HKLM..\Run: [scaninicio] File not found
    O4:64bit: - HKLM..\Run: [UfSeAgnt.exe] File not found
    O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\iMesh Applications\MediaBar\Datamngr\datamngrUI.exe (iMesh, Inc)
    O4 - HKCU..\Run: [QcrJdlni] C:\Users\radiorentals\AppData\Local\ivawsleu\qcrjdlni.exe ()
    O4 - Startup: C:\Users\radiorentals\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qcrjdlni.exe ()
    O20 - HKLM Winlogon: UserInit - (C:\Users\radiorentals\AppData\Local\ivawsleu\qcrjdlni.exe) - C:\Users\radiorentals\AppData\Local\ivawsleu\qcrjdlni.exe ()
    O33 - MountPoints2\{0b482776-a241-11df-b753-0017c4f4f1d2}\Shell - "" = AutoRun
    O33 - MountPoints2\{0b482776-a241-11df-b753-0017c4f4f1d2}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{0b48277a-a241-11df-b753-0017c4f4f1d2}\Shell - "" = AutoRun
    O33 - MountPoints2\{0b48277a-a241-11df-b753-0017c4f4f1d2}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{0b4827d7-a241-11df-b753-705ab6e51266}\Shell - "" = AutoRun
    O33 - MountPoints2\{0b4827d7-a241-11df-b753-705ab6e51266}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{0b4827d9-a241-11df-b753-705ab6e51266}\Shell - "" = AutoRun
    O33 - MountPoints2\{0b4827d9-a241-11df-b753-705ab6e51266}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{36c224bf-1017-11e0-b63b-705ab6e51266}\Shell - "" = AutoRun
    O33 - MountPoints2\{36c224bf-1017-11e0-b63b-705ab6e51266}\Shell\AutoRun\command - "" = E:\LGAutoRun.exe
    O33 - MountPoints2\{6488bc11-b187-11df-9ea5-705ab6e51266}\Shell - "" = AutoRun
    O33 - MountPoints2\{6488bc11-b187-11df-9ea5-705ab6e51266}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    O33 - MountPoints2\{6488bc13-b187-11df-9ea5-705ab6e51266}\Shell - "" = AutoRun
    O33 - MountPoints2\{6488bc13-b187-11df-9ea5-705ab6e51266}\Shell\AutoRun\command - "" = E:\AutoRun.exe
    [2012/06/29 19:30:24 | 000,092,172 | –S- | M] () – C:\Users\radiorentals\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qcrjdlni.exe
    [2012/03/15 18:10:07 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\Babylon
    [2011/06/24 17:49:45 | 000,000,000 | —D | M] – C:\Users\radiorentals\AppData\Roaming\GetRightToGo
    @Alternate Data Stream - 16 bytes -> C:\Users\radiorentals\Downloads:Shareaza.GUID
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [emptytemp]
    [resethosts]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
ive run the otl scan then rebooted but before i do the final scan should i be running in safe mode still or in normal mode thanks
OTL logfile created on: 6/30/2012 1:47:49 AM - Run 2
OTL by OldTimer - Version 3.2.53.0 Folder = C:\Users\radiorentals\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

3.87 Gb Total Physical Memory | 1.94 Gb Available Physical Memory | 50.27% Memory free
7.73 Gb Paging File | 5.40 Gb Available in Paging File | 69.92% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.99 Gb Total Space | 200.29 Gb Free Space | 70.04% Space Free | Partition Type: NTFS

Computer Name: ALISON | User Name: radiorentals | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\radiorentals\Downloads\OTL(2).exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_262.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe ()
PRC - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
PRC - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.EXE (Microsoft Corporation.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
PRC - C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe ()
PRC - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LMworker.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.)
PRC - C:\Program Files (x86)\Video Web Camera\traybar.exe (Chicony)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Windows\PLFSetI.exe ()
PRC - C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer Group)
PRC - C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\FinePixViewer\QuickDCF2.exe (FUJIFILM Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.1.0\SiteSafety.dll ()
MOD - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\Maps\R66Api.dll ()
MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\sqlite3.dll ()
MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDetect.dll ()
MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDisk.dll ()
MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcDetectLegend.dll ()
MOD - C:\Program Files (x86)\HTC\HTC Sync 3.0\fdHttpd.dll ()
MOD - C:\Windows\PLFSetI.exe ()
MOD - C:\Program Files (x86)\Launch Manager\CdDirIo.dll ()
MOD - C:\Program Files (x86)\FinePixViewer\wia_register_event.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (.Net Main) – C:\Windows\SysNative\idle-Threads.exe ()
SRV:64bit: - (.Net Security) – C:\Windows\SysNative\latch-Threads.exe ()
SRV:64bit: - (.Net Crypt) – C:\Windows\SysNative\mutex-Threads.exe ()
SRV:64bit: - (.Net Semaphore) – C:\Windows\SysNative\semaphore-Threads.exe ()
SRV:64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (ePowerSvc) – C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (Updater Service) – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer Group)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (vToolbarUpdater11.1.0) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe ()
SRV - (BBUpdate) – C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (GamesAppService) – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (PassThru Service) – C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe ()
SRV - (DsiWMIService) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (IJPLMSVC) – C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe ()
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (GREGService) – C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (IAStorDataMgrSvc) Intel® – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (usbvox) – C:\Windows\SysNative\Drivers\usbvox64.sys ()
DRV:64bit: - (scssifilter) – C:\Windows\SysNative\drivers\scssifilter64.sys (Microsoft Corporation)
DRV:64bit: - (usbmp3) – C:\Windows\SysNative\Drivers\usbmp364.sys ()
DRV:64bit: - (usbwav) – C:\Windows\SysNative\Drivers\usbwav64.sys ()
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Netaapl) – C:\Windows\SysNative\drivers\netaapl64.sys (Apple Inc.)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSEH) – C:\Windows\SysNative\drivers\AVGIDSEH.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (htcnprot) – C:\Windows\SysNative\drivers\htcnprot.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (k57nd60a) Broadcom NetLink ™ – C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atipmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (RTHDMIAzAudService) – C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (HTCAND64) – C:\Windows\SysNative\drivers\ANDROIDUSB.sys (HTC, Corporation)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV:64bit: - (hwdatacard) – C:\Windows\SysNative\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…d4z125a4562d204
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…d4z125a4562d204
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACGW
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchPage =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…1I7ACGW_enAU382
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…1I7ACGW_enAU382
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={544C5B4…mp;d=2012-06-14 21:30:50&v;=10.0.0.7&sap;=dsp&q;={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: [removed]:0.1
FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid;=1157&systemid;=1&sr;=0&q;="


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.1.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\5\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\radiorentals\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\radiorentals\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\radiorentals\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\radiorentals\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\radiorentals\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4C0766D3-67A7-45a3-85A2-752F77312F32}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.1.0.19\coFFPlgn\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\ProgramData\CodecCheck\firefox [2011/07/12 17:16:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/02/20 17:51:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012/06/14 23:15:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\11.1.0.7\ [2012/06/16 09:36:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/17 11:45:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/23 20:01:54 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/17 11:45:01 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/04/23 20:01:54 | 000,000,000 | —D | M]

[2012/05/17 17:03:15 | 000,000,000 | —D | M] (No name found) – C:\Users\radiorentals\AppData\Roaming\mozilla\Extensions
[2010/08/16 10:12:12 | 000,000,000 | —D | M] (No name found) – C:\Users\radiorentals\AppData\Roaming\mozilla\Extensions\[removed]
[2010/09/20 05:42:40 | 000,000,000 | —D | M] (No name found) – C:\Users\radiorentals\AppData\Roaming\mozilla\Extensions\[removed]
[2012/05/17 17:03:15 | 000,000,000 | —D | M] (No name found) – C:\Users\radiorentals\AppData\Roaming\mozilla\Firefox\Profiles\1nxsss19.default\extensions
[2012/05/17 17:03:15 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/02/20 17:51:33 | 000,000,000 | —D | M] (DivX Plus Web Player HTML5 ) – C:\PROGRAM FILES (X86)\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
[2011/07/12 17:16:19 | 000,000,000 | —D | M] ("Premiumplay Codec-C") – C:\PROGRAMDATA\CODECCHECK\FIREFOX
[2012/06/17 11:45:00 | 000,085,472 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/06/16 09:35:57 | 000,003,766 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/06/17 11:44:56 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Search the web (Babylon) (Enabled)
CHR - default_search_provider: search_url = http://search.babylon.com/?q={searchTerms}…0000017c4f4f1d2
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\radiorentals\AppData\Local\Google\Chrome\Application\19.0.1084.56\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Users\radiorentals\AppData\Local\Google\Chrome\Application\19.0.1084.56\gears.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\radiorentals\AppData\Local\Google\Chrome\Application\19.0.1084.56\gcswf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U22 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\radiorentals\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\radiorentals\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.50917.0\npctrl.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2012/06/30 01:29:08 | 000,000,098 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll (Yontoo LLC)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll ()
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files (x86)\Video Web Camera\traybar.exe (Chicony)
O4 - HKLM..\Run: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [sound-card-recorder] "C:\Program Files (x86)\Phone Call Recorder\phonerec.exe" /tray File not found
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKCU..\Run: [Facebook Update] C:\Users\radiorentals\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [Speech Recognition] C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation)
O4 - Startup: C:\Users\radiorentals\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files (x86)\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 157
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/trialo…osoft/wrc32.ocx (WRC Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{113A12D7-D158-4CB4-ACCA-102DC7CDCA41}: DhcpNameServer = 10.143.147.147 10.143.147.148
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A37BEAB5-1E21-4CC3-B88C-EBF540245F4D}: DhcpNameServer = 10.0.0.138
O18:64bit: - Protocol\Handler\belarc - No CLSID value found
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.1.0\ViProtocol.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/06/30 01:23:03 | 000,000,000 | —D | C] – C:\_OTL
[2012/06/30 01:20:43 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012/06/30 01:18:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2012/06/30 01:18:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\ERUNT
[2012/06/29 21:55:38 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{1D12CC76-E393-4208-8086-8FA9461315AE}
[2012/06/29 21:55:26 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{7090F71F-F744-41D4-B6EA-8D2FA7A51546}
[2012/06/29 19:30:25 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\ivawsleu
[2012/06/29 09:54:53 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{7242A710-C0FF-4F05-9A9E-10A23C4C3D86}
[2012/06/29 09:54:41 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{97FE2437-8690-4D6A-9601-1E57E73DEB21}
[2012/06/28 21:54:21 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{D3C6DA99-E853-40BE-B699-6712ED42788C}
[2012/06/28 21:54:08 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{72C850ED-3BB0-437B-A45C-8B31CEF33650}
[2012/06/28 20:42:32 | 000,000,000 | —D | C] – C:\Windows\en
[2012/06/28 20:38:24 | 000,048,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\fssfltr.sys
[2012/06/28 20:34:34 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{B267C275-B16E-4491-8AC9-203953524CE6}
[2012/06/28 20:34:23 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{5556EF6B-3D6E-47FE-9868-46AEC5A91B12}
[2012/06/28 20:27:50 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{7071BD75-769C-48DB-9200-80FE6E61C2FF}
[2012/06/28 20:27:39 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{161234F5-C5DE-40D2-B4CC-6A706A3574DD}
[2012/06/28 20:27:29 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{5C9FE7BE-3460-46C2-8CAE-0D90C229CEF9}
[2012/06/28 20:27:19 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{0772D968-63BA-4EBD-BECE-2D23FF3754B4}
[2012/06/28 20:27:09 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{493293F5-1504-4A06-9967-69714447F5DE}
[2012/06/28 20:26:58 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{B780D0E3-2C87-409B-8B58-A2A906867B08}
[2012/06/28 20:26:48 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{3FA523EB-7AC6-4972-8576-A37EAF9A11F0}
[2012/06/28 20:26:37 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{AD373357-F4B6-4B45-B686-611ED5D217B4}
[2012/06/28 20:26:25 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{B126786E-4984-4264-A42D-740E2AE768D9}
[2012/06/28 20:26:13 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{D4E95DD4-F513-42EF-BF5D-D4BC143645CD}
[2012/06/28 20:26:03 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{59A0B056-AE70-4990-A32A-E89F3040441F}
[2012/06/28 20:25:51 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{A13B57FD-38E6-4F62-B7F1-F3ACE013257F}
[2012/06/26 11:26:17 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/06/26 11:26:17 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/06/26 11:26:16 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/06/26 11:25:52 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/06/26 11:25:52 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/06/26 11:25:51 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/06/23 23:47:05 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{4E726720-C554-4283-A849-CA5475D242AC}
[2012/06/23 23:46:54 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{E50A0124-AAC8-457C-A735-8C85ACF8EA31}
[2012/06/22 10:01:32 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/06/22 10:01:32 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2012/06/20 08:54:04 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{6AB197A2-28B2-4E69-847F-F694D48E45E3}
[2012/06/20 08:53:47 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{5135D699-CCC9-4549-B845-055C0111023A}
[2012/06/19 08:50:21 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{AE331330-AA36-48C6-B2C5-7680BA192E6E}
[2012/06/19 08:50:05 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\AVG Secure Search
[2012/06/19 08:02:39 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/06/19 08:02:38 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/06/19 08:02:36 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/06/19 08:02:36 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/06/19 08:02:32 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/06/19 08:02:31 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/06/19 08:02:30 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/06/19 08:02:30 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/06/19 08:02:24 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/06/19 08:02:24 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/06/19 08:02:23 | 002,311,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/06/19 08:02:22 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/06/19 08:02:21 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/06/17 13:18:28 | 000,000,000 | —D | C] – C:\Users\radiorentals\FrostWire
[2012/06/17 13:18:23 | 000,000,000 | —D | C] – C:\Users\radiorentals\.frostwire5
[2012/06/17 11:53:23 | 000,426,184 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/06/17 11:53:23 | 000,070,344 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/06/14 23:19:36 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{2D7818AA-162A-4C13-903C-357CFB4D96DD}
[2012/06/14 23:19:24 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{8E8555C9-14B3-4187-8553-143820D4C0D1}
[2012/06/14 21:39:58 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{C9A65FDD-955A-414C-96C5-E9CE877B5B5C}
[2012/06/14 21:39:45 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{0BCFC424-08A6-4AF6-9338-4E4BAAC527D3}
[2012/06/14 21:36:11 | 000,000,000 | -H-D | C] – C:\$AVG
[2012/06/14 21:32:21 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Roaming\AVG2012
[2012/06/14 21:30:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2012
[2012/06/14 21:30:50 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2012/06/14 21:30:47 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVG Secure Search
[2012/06/14 21:30:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG Secure Search
[2012/06/14 21:30:43 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2012/06/14 21:30:31 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\AVG
[2012/06/14 21:29:50 | 000,000,000 | —D | C] – C:\ProgramData\AVG2012
[2012/06/14 21:29:50 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\AVG
[2012/06/14 21:11:24 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2012/06/14 20:35:17 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorekmts.dll
[2012/06/14 20:35:16 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpwsx.dll
[2012/06/14 20:35:16 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdrmemptylst.exe
[2012/06/14 20:35:06 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/06/14 20:35:05 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/06/14 20:35:04 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/06/14 20:35:00 | 003,216,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msi.dll
[2012/06/14 20:34:49 | 001,462,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012/06/14 20:34:48 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012/06/14 19:59:46 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\Macromedia
[2012/06/14 19:58:12 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{BFF4B682-D5CE-4A3F-B861-A0F09B9A2427}
[2012/06/14 19:58:01 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{457098C9-2E0E-4295-B50B-C06E7EF928B4}
[2012/06/13 15:49:05 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{EE8E9369-85C1-47BC-AE01-FF139683E442}
[2012/06/13 15:48:50 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{C1488EDD-755C-4470-99EE-88E72C3E290E}
[2012/06/12 17:06:21 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{E824A145-8763-447D-9F45-46C9CAA71E5E}
[2012/06/12 17:06:06 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{EB3E53B3-2DE9-4611-89E6-6EA0256CA12B}
[2012/06/11 10:28:23 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{EA46E58B-C36F-4410-938F-F0EAEAC2B5FC}
[2012/06/11 10:28:13 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{E310FE54-DBE4-490A-9BDD-6FF42249317F}
[2012/06/11 10:17:28 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{FFE96526-1B05-4EBF-83C0-427C4DA84BBE}
[2012/06/11 10:17:17 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{E1916FBA-BE68-4362-B3E9-D38350995F42}
[2012/06/07 19:55:28 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{B7ED88FA-ED40-4768-978F-5F3D4F0DB258}
[2012/06/07 19:55:15 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{FEB88999-E9E6-4303-8926-21A102576BAA}
[2012/06/05 17:04:02 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{ABBFA0E3-3214-476F-8EE9-B68AD36D745B}
[2012/06/05 17:03:52 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{0961A955-3CC9-4D58-86FC-FA8F9C6DD163}
[2012/06/04 17:21:12 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{DEF1D142-FAD5-4582-AC55-7D8E0C32750E}
[2012/06/04 17:20:57 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{769BAC13-7A28-4954-8B10-032CBE6F122C}
[2012/06/04 17:11:18 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{51146BCB-FE36-48D0-9D33-55AC0FF3F254}
[2012/06/04 17:11:08 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{FFA318A0-8120-49F4-B441-9B225EF2257B}
[2012/06/03 12:30:25 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{0BF89684-C314-42D9-840E-13AC5421795A}
[2012/06/03 12:30:13 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{C6483662-159B-4E94-92F7-418D9AEDED59}
[2012/06/02 15:58:35 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{01ABE5D9-8805-4DB0-853A-D28D32247E66}
[2012/06/02 15:58:25 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{EF120D16-F395-4A2B-9E97-FFDB8C3302F6}
[2012/06/01 09:32:00 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{0DC69B49-6DF3-4368-B23F-14B2C70C5413}
[2012/06/01 09:31:48 | 000,000,000 | —D | C] – C:\Users\radiorentals\AppData\Local\{82B8ADA1-EAF3-480F-9C6F-8BFCAEEF3103}
[2012/04/19 23:59:20 | 007,760,687 | —- | C] (Boraxsoft) – C:\Users\radiorentals\AppData\Roaming\SetupGFD.exe
[2012/04/19 23:55:55 | 005,514,668 | —- | C] (LIGHTNING UK!) – C:\Users\radiorentals\AppData\Roaming\Imgburn.exe
[2012/04/19 23:55:04 | 005,082,084 | —- | C] (The Public) – C:\Users\radiorentals\AppData\Roaming\Avisynth.exe

========== Files - Modified Within 30 Days ==========

[2012/06/30 01:50:41 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/30 01:50:41 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/30 01:47:25 | 000,000,936 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-110146109-1976382319-2385151686-1000UA.job
[2012/06/30 01:47:14 | 100,801,629 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/06/30 01:44:49 | 000,104,046 | RHS- | M] () – C:\Windows\SysNative\masteraclini.enu
[2012/06/30 01:44:49 | 000,000,147 | RH– | M] () – C:\Windows\SysNative\masteraclbini.enu
[2012/06/30 01:42:48 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/30 01:41:48 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/06/30 01:41:46 | 3113,254,912 | -HS- | M] () – C:\hiberfil.sys
[2012/06/30 01:29:08 | 000,000,098 | —- | M] () – C:\Windows\SysNative\drivers\etc\Hosts
[2012/06/30 01:19:07 | 000,001,071 | —- | M] () – C:\Users\radiorentals\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/06/30 01:18:22 | 000,000,891 | —- | M] () – C:\Users\radiorentals\Desktop\NTREGOPT.lnk
[2012/06/30 01:18:22 | 000,000,872 | —- | M] () – C:\Users\radiorentals\Desktop\ERUNT.lnk
[2012/06/30 00:47:36 | 000,000,512 | —- | M] () – C:\Users\radiorentals\Desktop\MBR.dat
[2012/06/29 22:42:17 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/29 21:24:02 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/29 21:02:16 | 000,000,512 | -H– | M] () – C:\Windows\tasks\Norton Security Scan for radiorentals.job
[2012/06/29 19:30:24 | 000,092,172 | —- | M] () – C:\Users\radiorentals\0.37516256241763035.exe
[2012/06/29 19:06:02 | 000,000,956 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-110146109-1976382319-2385151686-1000UA.job
[2012/06/29 08:47:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-110146109-1976382319-2385151686-1000Core.job
[2012/06/29 07:10:20 | 000,137,616 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/06/28 22:06:00 | 000,000,934 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-110146109-1976382319-2385151686-1000Core.job
[2012/06/23 22:42:29 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/06/23 22:42:28 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/06/19 08:46:48 | 000,441,168 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/19 08:24:57 | 000,749,420 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/19 08:24:57 | 000,627,138 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/19 08:24:57 | 000,111,676 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/15 07:33:24 | 000,002,438 | —- | M] () – C:\Users\radiorentals\Desktop\Google Chrome.lnk
[2012/06/14 21:30:58 | 000,000,932 | —- | M] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/06/14 21:30:31 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2012/06/14 21:30:31 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2012/06/03 08:19:46 | 000,038,424 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/06/03 08:19:42 | 000,057,880 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/06/03 08:19:42 | 000,044,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/06/03 08:19:23 | 000,701,976 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/06/03 08:15:31 | 002,622,464 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/06/03 08:15:08 | 000,099,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/06/02 15:19:42 | 000,186,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/06/02 15:15:12 | 000,036,864 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe

========== Files Created - No Company Name ==========

[2012/06/30 01:47:14 | 100,801,629 | —- | C] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/06/30 01:19:07 | 000,001,071 | —- | C] () – C:\Users\radiorentals\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/06/30 01:18:22 | 000,000,891 | —- | C] () – C:\Users\radiorentals\Desktop\NTREGOPT.lnk
[2012/06/30 01:18:22 | 000,000,872 | —- | C] () – C:\Users\radiorentals\Desktop\ERUNT.lnk
[2012/06/30 00:47:36 | 000,000,512 | —- | C] () – C:\Users\radiorentals\Desktop\MBR.dat
[2012/06/29 19:30:22 | 000,092,172 | —- | C] () – C:\Users\radiorentals\0.37516256241763035.exe
[2012/06/29 07:10:20 | 000,137,616 | —- | C] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/06/17 11:53:24 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/14 21:30:58 | 000,000,932 | —- | C] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2012/06/14 21:30:31 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2012/06/14 21:30:31 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2012/04/20 00:01:42 | 000,034,936 | —- | C] () – C:\Windows\SysWow64\uninstHelixYUV.exe
[2012/04/19 23:57:58 | 005,243,208 | —- | C] ( ) – C:\Users\radiorentals\AppData\Roaming\AvsP.exe
[2012/04/19 23:57:22 | 001,357,348 | —- | C] () – C:\Users\radiorentals\AppData\Roaming\MatroskaSplitter.exe
[2012/04/19 23:57:18 | 000,117,723 | —- | C] () – C:\Users\radiorentals\AppData\Roaming\yuvcodecs-1.3.exe
[2011/12/04 12:16:59 | 000,000,064 | —- | C] () – C:\Windows\GPlrLanc.dat
[2011/12/03 12:55:25 | 000,026,018 | —- | C] () – C:\Users\radiorentals\AppData\Roaming\UserTile.png
[2011/08/07 17:54:08 | 000,012,712 | -HS- | C] () – C:\ProgramData\vydm2tkqc846qk5r2761qlb8ah15252rc05a0p
[2011/08/07 17:54:08 | 000,012,586 | -HS- | C] () – C:\Users\radiorentals\AppData\Local\vydm2tkqc846qk5r2761qlb8ah15252rc05a0p
[2010/12/04 17:52:04 | 000,000,100 | —- | C] () – C:\Users\radiorentals\AppData\Local\fusioncache.dat
[2010/12/04 17:47:31 | 000,749,200 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/12/01 18:24:37 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/09/30 10:07:56 | 008,007,680 | —- | C] ( ) – C:\Windows\SysWow64\Microsoft.mshtml.dll
[2010/09/30 10:07:55 | 000,126,976 | —- | C] ( ) – C:\Windows\SysWow64\Interop.SHDocVw.dll
[2010/06/09 11:57:47 | 000,000,946 | —- | C] () – C:\Users\radiorentals\AppData\Roaming\wklnhst.dat
[2010/06/06 12:15:54 | 000,000,032 | R— | C] () – C:\ProgramData\hash.dat

========== Alternate Data Streams ==========

@Alternate Data Stream - 180 bytes -> C:\ProgramData\Temp:CB0AACC9
@Alternate Data Stream - 16 bytes -> C:\Users\radiorentals\Downloads:Shareaza.GUID
@Alternate Data Stream - 123 bytes -> C:\ProgramData\Temp:1DA424AA
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:D1B5B4F1

< End of report >
Hi,

Please open Google Chrome >> press the Wrench in the upper right-hand corner >> select Settings >> Settings >> set your Default Browser to Google so we can remove Babylon.
————–

Please download Malwarebytes' Anti-Malware to your desktop.

  • Right-click and Run as Administrator mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.


The log can also be found here:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
———-

Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats is NOT selected and the option Scan unwanted applications is selected.
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic
———-

In your next reply please post the logs made by Malwarebytes and ESET. :)
first of all i can not do the first task as when i opened chrome my whole computer froze the only thing i could do was restart should i just uninstall chrome, and when i did restart the computer it took longer than usual to start up. i will now continue to do all the other downloads and logs.So what should i do about chrome and once again thankyou so much for all your help
Hi, For now just use Internet Explorer or Firefox. There seems to be some problems with Chrome lately. I am trying to look into that. Besides…you should run ESET online scanner from Internet Explorer anyway. :)
Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Database version: v2012.06.29.08 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 radiorentals :: ALISON [administrator] 30/06/2012 2:54:37 AM mbam-log-2012-06-30 (02-54-37).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 213925 Time elapsed: 6 minute(s), 19 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4F4C5E11-0612-48D2-8055-987992AAC432} (PUP.wxDfast) -> Quarantined and deleted successfully. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 1 C:\ProgramData\wxDfast (PUP.wxDfast) -> Quarantined and deleted successfully. Files Detected: 7 C:\Users\radiorentals\Downloads\FastDownload.exe (Affiliate.Downloader) -> Quarantined and deleted successfully. C:\Users\radiorentals\0.37516256241763035.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully. C:\ProgramData\wxDfast\background.html (PUP.wxDfast) -> Quarantined and deleted successfully. C:\ProgramData\wxDfast\content.js (PUP.wxDfast) -> Quarantined and deleted successfully. C:\ProgramData\wxDfast\ekdjfcdinekpfcedakhpngcnaamhiihn.crx (PUP.wxDfast) -> Quarantined and deleted successfully. C:\ProgramData\wxDfast\settings.ini (PUP.wxDfast) -> Quarantined and deleted successfully. C:\ProgramData\wxDfast\uninstall.exe (PUP.wxDfast) -> Quarantined and deleted successfully. (end)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI