This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer slow down [Closed]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Couple weeks ago my computer has been infected with Windows defender and I successfully removed it. This wasn't the first time and I sure knew what to do at that point. The last couple of days i am trying to recover my system and getting rid of several malware etc.. However my pc is clearly not at the state of properly working right now. Last night i ran in several other problems. My pc is slowing down at times throughout the day, I am getting windows errors about updates windows couldn't install and need to reboot my pc quiet often. Or telling me my windows is in trial. I am a professional graphic designer, I work with my pc 24/7 and being connected to the internet 24/7, all those problems make it very difficult to work with and I really would hate reinstalling my windows, due the fact that of course I have no backups on my pc :wacko: So maybe I missed couple of things here. I would appreciate if someone could look into this and help me out. thanks in advanced.

side note: I read the "Are you infected topic" before hand and ran all programs I am supposed to run, however I can not run OTL. Error: Access violation at address CCCC0460. (just as heads up)

Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:07:16 PM, on 10/1/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16450)
Boot mode: Normal

Running processes:
C:\Windows\FixCamera.exe
E:\Skype\Phone\Skype.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_278.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_278.exe
E:\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files

(x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files

(x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program

Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files

(x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program

Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe

\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [WinampAgent] E:\!Winamp\Winamp\winampa.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader

\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [FixCamera] C:\Windows\FixCamera.exe
O4 - HKUS\S-1-5-18\..\Run: [Samsung.PCSync] "E:\Samsung\Samsung PC Studio 7\PcSync2.exe"

/NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Samsung.PCSync] "E:\Samsung\Samsung PC Studio 7\PcSync2.exe"

/NoDialog (User 'Default user')
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\JAZZ\AppData\Roaming

\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program

Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:

\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows

live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows

live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files

(x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems

Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows

\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows

\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows

\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common

Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common

Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files

(x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files

(x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file

missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program

Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file

missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows

\system32\lsass.exe (file missing)
O23 - Service: Nalpeiron X64 Service (nlscc) - Unknown owner - C:\Windows

\system32\nlsInterface.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows

\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows

\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:

\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows

\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows

\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files (x86)\PC Connectivity Solution

\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype

\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows

\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows

\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows

\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:

\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: TabletServicePen - Unknown owner - C:\Windows\system32\Pen_Tablet.exe (file

missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:

\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows

\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows

\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows

\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:

\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows

\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:

\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown

owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: WTouch Service (WTouchService) - Wacom Technology, Corp. - C:\Program Files

\WTouch\WTouchService.exe

–
End of file - 8349 bytes
Hello Soulhunter,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort. This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Important Note for Vista and Windows 7 users:

These tools MUST be run from the executable.(.exe) every time you run them with Admin Rights (Right click, choose "Run as Administrator")

Please stay with this topic until I let you know that your system appears to be "All Clear"
Hi Soulhunter,

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.com
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Right click DDS icon select "Run as Administrator" to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Please download aswMBR to your desktop.
  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the log file to your desktop.
[external image: Posted Image]
Click the image to enlarge it
In your next post please provide the following:
  • DDS.txt
  • Attach.txt
  • aswMBR log
Thank you OCD for helping me with my pc, which is clearly a pain in the butt lol. Here are the logs you requested. . DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 12:42:14.62 on Tue 10/02/2012 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.7.2 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2048.697 [GMT -7:00] . SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\WTouch\WTouchService.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\nlsInterface.exe C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\Pen_Tablet.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\SYSTEM32\WISPTIS.EXE C:\Windows\system32\taskhost.exe C:\Windows\system32\WTablet\Pen_TabletUser.exe C:\Windows\SYSTEM32\WISPTIS.EXE C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe C:\Windows\system32\Dwm.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe C:\Program Files\WTouch\WTouchUser.exe C:\Windows\Explorer.EXE C:\Windows\system32\Pen_Tablet.exe C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Windows\FixCamera.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe E:\Skype\Phone\Skype.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\DllHost.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe C:\Windows\system32\wuauclt.exe C:\Program Files (x86)\Internet Explorer\IELowutil.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_278.exe C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_278.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe E:\dds.scr C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uSearch Page = uStart Page = about:blank uSearch Bar = uInternet Settings,ProxyOverride = uURLSearchHooks: H - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll mRun: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin mRun: [WinampAgent] E:\!Winamp\Winamp\winampa.exe mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [FixCamera] C:\Windows\FixCamera.exe dRun: [Samsung.PCSync] "E:\Samsung\Samsung PC Studio 7\PcSync2.exe" /NoDialog mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Free YouTube to MP3 Converter - C:\Users\JAZZ\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll mRun-x64: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon mRun-x64: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe /logon mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll FF - component: C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\components\RadioWMPCore.dll FF - component: C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\components\RadioWMPCoreGecko19.dll FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll FF - plugin: C:\Program Files (x86)\TabletPlugins\npwacom.dll FF - plugin: C:\Users\JAZZ\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll FF - plugin: C:\Users\JAZZ\AppData\Roaming\raidcall\plugins\nprcplugin.dll FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll FF - plugin: C:\Windows\SysWOW64\npmproxy.dll . —- FIREFOX POLICIES —- FF - user.js: yahoo.ytff.general.dontshowhpoffer - true FF - user.js: extensions.funmoods.hmpg - false FF - user.js: extensions.funmoods.hmpgUrl - hxxp://start.funmoods.com/?f=1&a=axl&chnl=axl&cd=2XzutAtN2Y1L1QzutDtDyDtDzz0DzytAzztA0FtB0DyCyBzztN0D0TzutBtDtCtBtDyCtCtD&cr=1575741541 FF - user.js: extensions.funmoods.dfltSrch - false FF - user.js: extensions.funmoods.srchPrvdr - Search FF - user.js: extensions.funmoods.dnsErr - true FF - user.js: extensions.funmoods_i.newTab - false FF - user.js: extensions.funmoods.newTabUrl - hxxp://start.funmoods.com/?f=2&a=axl&chnl=axl&cd=2XzutAtN2Y1L1QzutDtDyDtDzz0DzytAzztA0FtB0DyCyBzztN0D0TzutBtDtCtBtDyCtCtD&cr=1575741541 FF - user.js: extensions.funmoods.tlbrSrchUrl - FF - user.js: extensions.funmoods.id - bcb4d67800000000000000508d9383f1 FF - user.js: extensions.funmoods.instlDay - 15501 FF - user.js: extensions.funmoods.vrsn - 1.5.23.22 FF - user.js: extensions.funmoods.vrsni - 1.5.23.22 FF - user.js: extensions.funmoods_i.vrsnTs - 1.5.23.2211:55:58 FF - user.js: extensions.funmoods.prtnrId - funmoods FF - user.js: extensions.funmoods.prdct - funmoods FF - user.js: extensions.funmoods.aflt - axl FF - user.js: extensions.funmoods_i.smplGrp - none FF - user.js: extensions.funmoods.tlbrId - base FF - user.js: extensions.funmoods.instlRef - axl FF - user.js: extensions.funmoods.dfltLng - FF - user.js: extensions.funmoods.excTlbr - false FF - user.js: extensions.funmoods.autoRvrt - false FF - user.js: extensions.funmoods.envrmnt - production FF - user.js: extensions.funmoods.isdcmntcmplt - true FF - user.js: extensions.funmoods.mntrvrsn - 1.3.0 . ============= SERVICES / DRIVERS =============== . R2 nlscc;Nalpeiron X64 Service;C:\Windows\System32\nlsInterface.EXE [2010-7-10 72192] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-6-7 240232] R2 TabletServicePen;TabletServicePen;C:\Windows\System32\Pen_Tablet.exe [2010-7-13 5556520] R2 WTouchService;WTouch Service;C:\Program Files\WTouch\WTouchService.exe [2010-7-13 127784] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-11-14 136176] S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-6-7 160944] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-6-13 250288] S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-7-10 1038088] S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-11-14 136176] S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-9-10 114144] S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service –> C:\Windows\system32\GameMon.des -service [?] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-3-13 20992] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-7-1 59392] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-7-7 1255736] . =============== Created Last 30 ================ . 2012-10-02 11:41:50 9308616 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{237FE4F7-F164-4F2B-A488-459CDC183DB0}\mpengine.dll 2012-10-01 20:20:51 ——– d—–w- C:\Users\JAZZ\AppData\Roaming\KudosChatSearch 2012-09-22 10:01:59 548864 —-a-w- C:\Program Files\Internet Explorer\ieproxy.dll 2012-09-12 09:43:49 1913200 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2012-09-12 09:43:48 376688 —-a-w- C:\Windows\System32\drivers\netio.sys 2012-09-12 09:43:48 288624 —-a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS 2012-09-11 11:28:44 31232 —-a-w- C:\Windows\SysWow64\prevhost.exe 2012-09-11 11:28:44 31232 —-a-w- C:\Windows\System32\prevhost.exe 2012-09-11 02:08:03 ——– d—–w- C:\Windows\System32\SPReview 2012-09-10 07:38:47 ——– d—–w- C:\Users\JAZZ\AppData\Local\Aeria Games 2012-09-10 07:31:33 ——– d-sh–w- C:\Windows\SysWow64\AI_RecycleBin 2012-09-10 02:33:16 95208 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll 2012-09-09 23:52:04 ——– d—–w- C:\PROGRA~3\Spybot - Search & Destroy 2012-09-07 11:55:50 ——– d—–w- C:\AeriaGames . ==================== Find3M ==================== . 2012-09-21 08:35:18 73136 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-09-21 08:35:18 696240 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-09-11 02:18:16 152576 —-a-w- C:\Windows\SysWow64\msclmd.dll 2012-09-11 02:18:15 175616 —-a-w- C:\Windows\System32\msclmd.dll 2012-09-10 02:33:05 821736 —-a-w- C:\Windows\SysWow64\npdeployJava1.dll 2012-09-10 02:33:05 746984 —-a-w- C:\Windows\SysWow64\deployJava1.dll 2012-09-08 00:04:46 25928 —-a-w- C:\Windows\System32\drivers\mbam.sys 2012-08-24 10:31:32 2312704 —-a-w- C:\Windows\System32\jscript9.dll 2012-08-24 10:21:18 1392128 —-a-w- C:\Windows\System32\wininet.dll 2012-08-24 10:20:11 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl 2012-08-24 10:14:45 173056 —-a-w- C:\Windows\System32\ieUnatt.exe 2012-08-24 10:13:29 599040 —-a-w- C:\Windows\System32\vbscript.dll 2012-08-24 10:09:42 2382848 —-a-w- C:\Windows\System32\mshtml.tlb 2012-08-24 06:59:17 1800704 —-a-w- C:\Windows\SysWow64\jscript9.dll 2012-08-24 06:51:27 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll 2012-08-24 06:51:02 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl 2012-08-24 06:47:26 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe 2012-08-24 06:47:12 420864 —-a-w- C:\Windows\SysWow64\vbscript.dll 2012-08-24 06:43:58 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2012-07-18 18:15:06 3148800 —-a-w- C:\Windows\System32\win32k.sys 2012-07-04 22:13:27 59392 —-a-w- C:\Windows\System32\browcli.dll 2012-07-04 22:13:27 136704 —-a-w- C:\Windows\System32\browser.dll 2012-07-04 21:14:34 41984 —-a-w- C:\Windows\SysWow64\browcli.dll . ============= FINISH: 12:42:51.18 =============== aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-10-02 12:44:03 —————————– 12:44:03.970 OS Version: Windows x64 6.1.7601 Service Pack 1 12:44:03.970 Number of processors: 2 586 0x4303 12:44:03.970 ComputerName: JAZZ-PC UserName: JAZZ 12:44:04.439 Initialize success 12:44:15.173 AVAST engine defs: 12100101 12:44:16.548 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000058 12:44:16.564 Disk 0 Vendor: WDC_WD74 33.0 Size: 70911MB BusType: 3 12:44:16.564 Disk 0 MBR read successfully 12:44:16.580 Disk 0 MBR scan 12:44:16.595 Disk 0 Windows 7 default MBR code 12:44:16.595 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 61443 MB offset 63 12:44:16.626 Disk 0 Partition 2 00 83 Linux 9460 MB offset 125837145 12:44:16.658 Disk 0 scanning C:\Windows\system32\drivers 12:44:25.111 Service scanning 12:44:43.439 Modules scanning 12:44:43.455 Disk 0 trace - called modules: 12:44:43.470 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll nvstor.sys 12:44:43.486 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80027124b0] 12:44:44.001 3 CLASSPNP.SYS[fffff8800190743f] -> nt!IofCallDriver -> [0xfffffa8002284d30] 12:44:44.017 5 ACPI.sys[fffff88000ef87a1] -> nt!IofCallDriver -> \Device\00000058[0xfffffa800226b9c0] 12:44:44.408 AVAST engine scan C:\Windows 12:44:46.095 AVAST engine scan C:\Windows\system32 12:47:07.673 AVAST engine scan C:\Windows\system32\drivers 12:47:17.111 AVAST engine scan C:\Users\JAZZ 12:50:30.751 Disk 0 MBR has been saved successfully to "E:\Recovery\2\MBR.dat" 12:50:30.767 The log file has been saved successfully to "E:\Recovery\2\aswMBR.txt"

Attachments:

Hi Soulhunter,

I have a few questions:
  • Your log does not show a Firewall. Are you currently using one?
  • Also, I see no sign of an Anti-Virus program installed and running.
  • Windows Defender is not an Anti-Virus. It is used to prevent, remove spyware.
As a rule of thumb one should run one firewall, one antivirus program in memory, and one antispyware utility in memory. It's fine to have other security tools available on an as-needed or on-demand basis, but when multiple tools simultaneously perform the same function, you're asking for trouble.

Next

P2P - I see you have/had P2P software BitTorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections and possibly Identity Theft. It likely contributed to your current situation. This page will give you further information.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Programs and Features.

Click 'Start > Control Panel > Programs and Features. Locate and select the following that are present on the list and click the Remove button:
  • BitTorrent
Next
  • Please download AdwCleaner from here and save it to your desktop.
  • Right click on AdwCleaner.exe and click "Run as Administrator" to run the tool.
  • Click on Search.
A logfile will automatically open after the scan has finished.

Please post the content of that logfile in your reply.

You can find the logfile at C:\AdwCleaner[Rn].txt as well - (n is the scan number.)

In your next post please provide the following:
  • AdwCleaner log
  • Answers my questions
Hey OCD, Yes I do use a firewall and anitvirus normally, I am using Norton but as mentioned in my first post I got this Windows Recovery virus couple weeks ago, sorry for saying it was defender was a bit sleepy as I made the post. Ever since my pc has stopped/removed files and added new stuff to it. I never used BitTorrent and won't use it in future. My programs are all legally purchased which as I said is funny since my windows now claims to be a trial version and most programs are unable to even be located or started in my system -sigh- I prolly shoudl take a look at other anit viruses and firewalls but I haven't even noticed that it's not running since my desktop shows clearly it's running if that makes any sense. maybe you can recommend something not sure if you guys do that. sorry if that question is something i should not ask. Here's the log you request: # AdwCleaner v2.003 - Logfile created 10/03/2012 at 12:58:29 # Updated 23/09/2012 by Xplode # Operating system : Windows 7 Ultimate Service Pack 1 (64 bits) # User : JAZZ - JAZZ-PC # Boot Mode : Normal # Running from : C:\Users\JAZZ\Desktop\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** File Found : C:\Windows\SysWOW64\conduitEngine.tmp Folder Found : C:\ProgramData\boost_interprocess Folder Found : C:\ProgramData\InstallMate Folder Found : C:\ProgramData\Premium Folder Found : C:\ProgramData\WeCareReminder Folder Found : C:\Users\JAZZ\AppData\Local\Conduit Folder Found : C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhfdcmehmjcclgopdodkjdicohagipid Folder Found : C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhfdcmehmjcclgopdodkjdicohagipid Folder Found : C:\Users\JAZZ\AppData\Local\TempDir Folder Found : C:\Users\JAZZ\AppData\LocalLow\Conduit Folder Found : C:\Users\JAZZ\AppData\LocalLow\Toolbar4 Folder Found : C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\ConduitCommon Folder Found : C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\CT2790392 Folder Found : C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527} Folder Found : C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\[removed] Folder Found : C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\staged ***** [Registry] ***** Key Found : HKCU\Software\AppDataLow\Software\Crossrider Key Found : HKCU\Software\Conduit Key Found : HKCU\Software\Cr_Installer Key Found : HKCU\Software\Google\Chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki Key Found : HKCU\Software\Softonic Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Key Found : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E} Key Found : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Found : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291} Key Found : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Found : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C} Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine Key Found : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils Key Found : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils.1 Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager.1 Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager.1 Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbRequest Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbRequest.1 Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbTask Key Found : HKLM\SOFTWARE\Classes\TbHelper.TbTask.1 Key Found : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper Key Found : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper.1 Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2790392 Key Found : HKLM\SOFTWARE\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C} Key Found : HKLM\Software\Conduit Key Found : HKLM\Software\Freeze.com Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1C950DE5-D31E-42FB-AFB9-91B0161633D8} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AE338F6D-5A7C-4D1D-86E3-C618532079B5} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{C339D489-FABC-41DD-B39D-276101667C70} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D89031C2-10DA-4C90-9A62-FCED012BC46B} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{23C70BCA-6E23-4A65-AD2E-1389062074F1} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{295CACB4-51F5-46FD-914E-C72BAAE1B672} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{34C1FDF7-02C1-4F23-B393-F48B16E071D1} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{54291324-7A3D-4F11-B707-3FB6A2C97BD9} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C0585B2F-74D7-4734-88DE-6C150C5D4036} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EF0588D6-1621-4A75-B8BE-F4BC34794136} Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mhfdcmehmjcclgopdodkjdicohagipid Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mhfdcmehmjcclgopdodkjdicohagipid Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Found : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921} Key Found : HKLM\SOFTWARE\Classes\Interface\{0D80F1C5-D17B-4177-AC68-955F3EF9F191} Key Found : HKLM\SOFTWARE\Classes\Interface\{23C70BCA-6E23-4A65-AD2E-1389062074F1} Key Found : HKLM\SOFTWARE\Classes\Interface\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1} Key Found : HKLM\SOFTWARE\Classes\Interface\{295CACB4-51F5-46FD-914E-C72BAAE1B672} Key Found : HKLM\SOFTWARE\Classes\Interface\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762} Key Found : HKLM\SOFTWARE\Classes\Interface\{34C1FDF7-02C1-4F23-B393-F48B16E071D1} Key Found : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F} Key Found : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979} Key Found : HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B} Key Found : HKLM\SOFTWARE\Classes\Interface\{54291324-7A3D-4F11-B707-3FB6A2C97BD9} Key Found : HKLM\SOFTWARE\Classes\Interface\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8} Key Found : HKLM\SOFTWARE\Classes\Interface\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED} Key Found : HKLM\SOFTWARE\Classes\Interface\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D} Key Found : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29} Key Found : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659} Key Found : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47} Key Found : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C} Key Found : HKLM\SOFTWARE\Classes\Interface\{C0585B2F-74D7-4734-88DE-6C150C5D4036} Key Found : HKLM\SOFTWARE\Classes\Interface\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347} Key Found : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6} Key Found : HKLM\SOFTWARE\Classes\Interface\{EF0588D6-1621-4A75-B8BE-F4BC34794136} Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki Key Found : HKU\S-1-5-21-2375342815-4246018699-2964025557-1001\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Value Found : HKCU\Software\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com] Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com] ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v15.0.1 (en-US) Profile name : default File : C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\prefs.js Found : user_pref("CT2790392..clientLogIsEnabled", true); Found : user_pref("CT2790392..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[…] Found : user_pref("CT2790392..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[…] Found : user_pref("CT2790392.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx"); Found : user_pref("CT2790392.AppTrackingLastCheckTime", "Sat Dec 10 2011 04:21:32 GMT-0800 (Pacific Standard[…] Found : user_pref("CT2790392.BrowserCompStateIsOpen_129633547190125290", true); Found : user_pref("CT2790392.CTID", "CT2790392"); Found : user_pref("CT2790392.CommunitiesChangesLastCheckTime", "0"); Found : user_pref("CT2790392.CurrentServerDate", "10-12-2011"); Found : user_pref("CT2790392.DialogsAlignMode", "LTR"); Found : user_pref("CT2790392.DialogsGetterLastCheckTime", "Wed Dec 07 2011 14:14:34 GMT-0800 (Pacific Standa[…] Found : user_pref("CT2790392.DownloadReferralCookieData", ""); Found : user_pref("CT2790392.EMailNotifierPollDate", "Sat Dec 10 2011 04:36:21 GMT-0800 (Pacific Standard Ti[…] Found : user_pref("CT2790392.FeedLastCount129313977501788460", 501); Found : user_pref("CT2790392.FeedPollDate129313974171006416", "Sat Dec 10 2011 04:21:21 GMT-0800 (Pacific St[…] Found : user_pref("CT2790392.FeedPollDate129313975698350231", "Sat Dec 10 2011 04:21:21 GMT-0800 (Pacific St[…] Found : user_pref("CT2790392.FeedPollDate129313976370850190", "Sat Dec 10 2011 04:21:21 GMT-0800 (Pacific St[…] Found : user_pref("CT2790392.FeedPollDate129313976648818968", "Sat Dec 10 2011 04:21:21 GMT-0800 (Pacific St[…] Found : user_pref("CT2790392.FeedPollDate129313977444757117", "Sat Dec 10 2011 04:21:21 GMT-0800 (Pacific St[…] Found : user_pref("CT2790392.FeedPollDate129313980389131455", "Sat Dec 10 2011 04:21:21 GMT-0800 (Pacific St[…] Found : user_pref("CT2790392.FeedPollDate129313980655381977", "Sat Dec 10 2011 04:21:21 GMT-0800 (Pacific St[…] Found : user_pref("CT2790392.FeedPollDate129313980886163259", "Sat Dec 10 2011 04:21:21 GMT-0800 (Pacific St[…] Found : user_pref("CT2790392.FeedPollDate129313981234756535", "Sat Dec 10 2011 04:21:22 GMT-0800 (Pacific St[…] Found : user_pref("CT2790392.FeedPollDate129313983226631720", "Sat Dec 10 2011 04:21:22 GMT-0800 (Pacific St[…] Found : user_pref("CT2790392.FeedPollDate129313983607725691", "Sat Dec 10 2011 04:21:22 GMT-0800 (Pacific St[…] Found : user_pref("CT2790392.FeedTTL129313974171006416", 10); Found : user_pref("CT2790392.FeedTTL129313977444757117", 15); Found : user_pref("CT2790392.FeedTTL129313980655381977", 5); Found : user_pref("CT2790392.FeedTTL129313981234756535", 5); Found : user_pref("CT2790392.FirstServerDate", "6-7-2011"); Found : user_pref("CT2790392.FirstTime", true); Found : user_pref("CT2790392.FirstTimeFF3", true); Found : user_pref("CT2790392.FixPageNotFoundErrors", false); Found : user_pref("CT2790392.GroupingInvalidateCache", false); Found : user_pref("CT2790392.GroupingLastCheckTime", "0"); Found : user_pref("CT2790392.GroupingLastServerUpdateTime", "0"); Found : user_pref("CT2790392.GroupingServerCheckInterval", 1440); Found : user_pref("CT2790392.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/"); Found : user_pref("CT2790392.HasUserGlobalKeys", true); Found : user_pref("CT2790392.HomePageProtectorEnabled", false); Found : user_pref("CT2790392.Initialize", true); Found : user_pref("CT2790392.InitializeCommonPrefs", true); Found : user_pref("CT2790392.InstallationAndCookieDataSentCount", 3); Found : user_pref("CT2790392.InstallationType", "UnknownIntegration"); Found : user_pref("CT2790392.InstalledDate", "Wed Jul 06 2011 07:39:55 GMT-0700 (Pacific Daylight Time)"); Found : user_pref("CT2790392.InvalidateCache", false); Found : user_pref("CT2790392.IsAlertDBUpdated", true); Found : user_pref("CT2790392.IsGrouping", false); Found : user_pref("CT2790392.IsInitSetupIni", true); Found : user_pref("CT2790392.IsMulticommunity", false); Found : user_pref("CT2790392.IsOpenThankYouPage", true); Found : user_pref("CT2790392.IsOpenUninstallPage", false); Found : user_pref("CT2790392.LanguagePackLastCheckTime", "Fri Dec 09 2011 19:51:47 GMT-0800 (Pacific Standar[…] Found : user_pref("CT2790392.LanguagePackReloadIntervalMM", 1440); Found : user_pref("CT2790392.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[…] Found : user_pref("CT2790392.LastLogin_3.5.0.12", "Sat Dec 10 2011 04:21:21 GMT-0800 (Pacific Standard Time)[…] Found : user_pref("CT2790392.LatestVersion", "3.8.1.0"); Found : user_pref("CT2790392.Locale", "en"); Found : user_pref("CT2790392.MCDetectTooltipHeight", "83"); Found : user_pref("CT2790392.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1"); Found : user_pref("CT2790392.MCDetectTooltipWidth", "295"); Found : user_pref("CT2790392.MyStuffEnabledAtInstallation", true); Found : user_pref("CT2790392.OriginalFirstVersion", "3.5.0.12"); Found : user_pref("CT2790392.RadioLastCheckTime", "0"); Found : user_pref("CT2790392.RadioLastUpdateIPServer", "0"); Found : user_pref("CT2790392.RadioLastUpdateServer", "0"); Found : user_pref("CT2790392.SHRINK_TOOLBAR", 1); Found : user_pref("CT2790392.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties"); Found : user_pref("CT2790392.SearchFromAddressBarIsInit", true); Found : user_pref("CT2790392.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT279[…] Found : user_pref("CT2790392.SearchInNewTabEnabled", true); Found : user_pref("CT2790392.SearchInNewTabIntervalMM", 1440); Found : user_pref("CT2790392.SearchInNewTabLastCheckTime", "Fri Dec 09 2011 19:51:46 GMT-0800 (Pacific Stand[…] Found : user_pref("CT2790392.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[…] Found : user_pref("CT2790392.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[…] Found : user_pref("CT2790392.SearchInNewTabUserEnabled", false); Found : user_pref("CT2790392.SearchProtectorEnabled", false); Found : user_pref("CT2790392.SearchProtectorToolbarDisabled", false); Found : user_pref("CT2790392.ServiceMapLastCheckTime", "Fri Dec 09 2011 19:51:47 GMT-0800 (Pacific Standard […] Found : user_pref("CT2790392.SettingsLastCheckTime", "Fri Dec 09 2011 12:21:20 GMT-0800 (Pacific Standard Ti[…] Found : user_pref("CT2790392.SettingsLastUpdate", "1321973040"); Found : user_pref("CT2790392.ThirdPartyComponentsInterval", 504); Found : user_pref("CT2790392.ThirdPartyComponentsLastCheck", "Thu Dec 01 2011 14:14:32 GMT-0800 (Pacific Sta[…] Found : user_pref("CT2790392.ThirdPartyComponentsLastUpdate", "1312887586"); Found : user_pref("CT2790392.ToolbarShrinkedFromSetup", false); Found : user_pref("CT2790392.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2790392"); Found : user_pref("CT2790392.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[…] Found : user_pref("CT2790392.UserID", "UN49523552041056196"); Found : user_pref("CT2790392.ValidationData_Toolbar", 2); Found : user_pref("CT2790392.WeatherNetwork", ""); Found : user_pref("CT2790392.WeatherPollDate", "Sat Dec 10 2011 04:21:26 GMT-0800 (Pacific Standard Time)"); Found : user_pref("CT2790392.WeatherUnit", "F"); Found : user_pref("CT2790392.alertChannelId", "1182482"); Found : user_pref("CT2790392.appApproved.129309578575850709", true); Found : user_pref("CT2790392.backendstorage.cb_firstuse0100", "31"); Found : user_pref("CT2790392.backendstorage.cbfirsttime", "5475652053657020323720323031312031393A33313A32342[…] Found : user_pref("CT2790392.backendstorage.scriptsource", "687474703A2F2F3132372E302E302E313A31303030302F67[…] Found : user_pref("CT2790392.backendstorage.url_history", "687474703A2F2F7777772E676F6F676C652E636F6D2F75726[…] Found : user_pref("CT2790392.backendstorage.url_history_time", "31333233343832393035373734"); Found : user_pref("CT2790392.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[…] Found : user_pref("CT2790392.globalFirstTimeInfoLastCheckTime", "Sat Dec 10 2011 04:21:21 GMT-0800 (Pacific […] Found : user_pref("CT2790392.homepageProtectorEnableByLogin", true); Found : user_pref("CT2790392.initDone", true); Found : user_pref("CT2790392.isAppTrackingManagerOn", true); Found : user_pref("CT2790392.myStuffEnabled", true); Found : user_pref("CT2790392.myStuffPublihserMinWidth", 400); Found : user_pref("CT2790392.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[…] Found : user_pref("CT2790392.myStuffServiceIntervalMM", 1440); Found : user_pref("CT2790392.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[…] Found : user_pref("CT2790392.oldAppsList", "129298377186075601,129298377186388102,111,1000234,12929837718654[…] Found : user_pref("CT2790392.searchProtectorDialogDelayInSec", 10); Found : user_pref("CT2790392.searchProtectorEnableByLogin", true); Found : user_pref("CT2790392.testingCtid", ""); Found : user_pref("CT2790392.toolbarAppMetaDataLastCheckTime", "Fri Dec 09 2011 19:51:47 GMT-0800 (Pacific S[…] Found : user_pref("CT2790392.toolbarContextMenuLastCheckTime", "Fri Dec 09 2011 12:21:20 GMT-0800 (Pacific S[…] Found : user_pref("CT2790392.usagesFlag", 2); Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2790392/CT2790392[…] Found : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1182482/1178159/US", "\"0\"[…] Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2790392", […] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[…] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[…] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[…] Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[…] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[…] Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.5.[…] Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2790392",[…] Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2790392&octid=[…] Found : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2790392/CT2790392[…] Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=EB_LOCALE",[…] Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"1d8[…] Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\JAZZ\\AppData\\Roaming\\Mozilla\\Fi[…] Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.5.0.12"); Found : user_pref("CommunityToolbar.MiniIPageGadgetPosition.hxxp://youtube.conduitapps.com/v115/gadget.php?a[…] Found : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", ""); Found : user_pref("CommunityToolbar.ToolbarsList", "CT2790392"); Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2790392"); Found : user_pref("CommunityToolbar.ToolbarsList4", "CT2790392"); Found : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Fri Dec 09 2011 19:51:47 GMT-0800 (Pac[…] Found : user_pref("CommunityToolbar.globalUserId", "f3ccd69c-3273-4c46-8c21-6a68baf0b075"); Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true); Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true); Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Sat Dec 03 2011 15:35:1[…] Found : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440); Found : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Fri Dec 09 2011 19:51:55 GMT-080[…] Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com"); Found : user_pref("CommunityToolbar.notifications.locale", "en"); Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440); Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Fri Dec 09 2011 19:51:47 GMT-0800 (P[…] Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611"); Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20); Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com"); Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false); Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300); Found : user_pref("CommunityToolbar.notifications.userId", "227799c1-a21c-4ee0-924a-b3f1e7ea0360"); Found : user_pref("extensions.crossriderapp435.435.InstallationThankYouPage", true); Found : user_pref("extensions.crossriderapp435.435.InstallationTime", 1339366826); Found : user_pref("extensions.crossriderapp435.435.InstallationUserSettings.searchUserConifrma tion", false); Found : user_pref("extensions.crossriderapp435.435.InstallationUserSettings.setHomepage", false); Found : user_pref("extensions.crossriderapp435.435.InstallationUserSettings.setNewTab", false); Found : user_pref("extensions.crossriderapp435.435.InstallationUserSettings.setSearch", false); Found : user_pref("extensions.crossriderapp435.435.active", true); Found : user_pref("extensions.crossriderapp435.435.addressbar", ""); Found : user_pref("extensions.crossriderapp435.435.affid", "0"); Found : user_pref("extensions.crossriderapp435.435.backgroundjs", "\n\nfunction buttonClick() { \n \[…] Found : user_pref("extensions.crossriderapp435.435.backgroundver", 8); Found : user_pref("extensions.crossriderapp435.435.can_run_bg_code", true); Found : user_pref("extensions.crossriderapp435.435.certdomaininstaller", ""); Found : user_pref("extensions.crossriderapp435.435.changeprevious", false); Found : user_pref("extensions.crossriderapp435.435.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:[…] Found : user_pref("extensions.crossriderapp435.435.cookie.InstallationTime.value", "1339366826"); Found : user_pref("extensions.crossriderapp435.435.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00:0[…] Found : user_pref("extensions.crossriderapp435.435.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 GM[…] Found : user_pref("extensions.crossriderapp435.435.cookie._GPL_aoi.value", "%221339366913%22"); Found : user_pref("extensions.crossriderapp435.435.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030 0[…] Found : user_pref("extensions.crossriderapp435.435.cookie._GPL_parent_zoneid.value", "%2214974%22"); Found : user_pref("extensions.crossriderapp435.435.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:00:00[…] Found : user_pref("extensions.crossriderapp435.435.cookie._GPL_zoneid.value", "%2244191%22"); Found : user_pref("extensions.crossriderapp435.435.cookie.__GPL_ID.expiration", "Fri Feb 01 2030 00:00:00 GM[…] Found : user_pref("extensions.crossriderapp435.435.cookie.__GPL_ID.value", "435"); Found : user_pref("extensions.crossriderapp435.435.cookie.__GPL_custom_zoneid.expiration", "Fri Feb 01 2030 […] Found : user_pref("extensions.crossriderapp435.435.cookie.__GPL_custom_zoneid.value", "14969"); Found : user_pref("extensions.crossriderapp435.435.cookie.__GPL_pubid.expiration", "Fri Feb 01 2030 00:00:00[…] Found : user_pref("extensions.crossriderapp435.435.cookie.__GPL_pubid.value", "%222993%22"); Found : user_pref("extensions.crossriderapp435.435.description", "Premiumplay Codec check"); Found : user_pref("extensions.crossriderapp435.435.domain", ""); Found : user_pref("extensions.crossriderapp435.435.emailsig", ""); Found : user_pref("extensions.crossriderapp435.435.enablesearch", false); Found : user_pref("extensions.crossriderapp435.435.exposesites", ""); Found : user_pref("extensions.crossriderapp435.435.fbremoteurl", ""); Found : user_pref("extensions.crossriderapp435.435.group", 0); Found : user_pref("extensions.crossriderapp435.435.homepage", ""); Found : user_pref("extensions.crossriderapp435.435.iframe", false); Found : user_pref("extensions.crossriderapp435.435.internaldb.InstallerIdentifiers.expiration", "Fri Feb 01 […] Found : user_pref("extensions.crossriderapp435.435.internaldb.InstallerIdentifiers.value", "%7B%22installer_[…] Found : user_pref("extensions.crossriderapp435.435.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030[…] Found : user_pref("extensions.crossriderapp435.435.internaldb.Resources_appVer.value", "61"); Found : user_pref("extensions.crossriderapp435.435.internaldb.Resources_lastVersion.expiration", "Fri Feb 01[…] Found : user_pref("extensions.crossriderapp435.435.internaldb.Resources_lastVersion.value", "0"); Found : user_pref("extensions.crossriderapp435.435.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 0[…] Found : user_pref("extensions.crossriderapp435.435.internaldb.Resources_meta.value", "%7B%7D"); Found : user_pref("extensions.crossriderapp435.435.internaldb.Resources_nextCheck.expiration", "Tue Oct 02 2[…] Found : user_pref("extensions.crossriderapp435.435.internaldb.Resources_nextCheck.value", "true"); Found : user_pref("extensions.crossriderapp435.435.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 […] Found : user_pref("extensions.crossriderapp435.435.internaldb.Resources_queue.value", "%7B%7D"); Found : user_pref("extensions.crossriderapp435.435.js", "\n\n$jquery(document).ready(function() {\n \n $[…] Found : user_pref("extensions.crossriderapp435.435.manifesturl", ""); Found : user_pref("extensions.crossriderapp435.435.name", "Codec-V"); Found : user_pref("extensions.crossriderapp435.435.newtab", ""); Found : user_pref("extensions.crossriderapp435.435.opensearch", ""); Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_10.code", "if(!appAPI.matchPages(\"search.[…] Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_10.name", "app_435_specific"); Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_10.ver", 4); Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_13.code", "(function(a){a.selectedText=fun[…] Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_13.name", "CrossriderAppUtils"); Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_13.ver", 2); Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_14.code", "if(typeof(appAPI)===\"undefined[…] Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_14.name", "CrossriderUtils"); Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_14.ver", 2); Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_15.code", "(function(f){var u={};var e=Mat[…] Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_15.name", "FacebookFFIE"); Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_15.ver", 1); Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_16.code", "(function(b,a){function h(){var[…] Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_16.name", "FFAppAPIWrapper"); Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_16.ver", 3); Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_17.code", "/*!\n * jQuery JavaScript Libra[…] Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_17.name", "jQuery"); Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_17.ver", 1); Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_47.code", "(function(){appAPI.ready=functi[…] Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_47.name", "resources_background"); Found : user_pref("extensions.crossriderapp435.435.plugins.plugin_47.ver", 1); Found : user_pref("extensions.crossriderapp435.435.plugins_lists.plugins_0", "17,14,16,47"); Found : user_pref("extensions.crossriderapp435.435.plugins_lists.plugins_1", "17,14,13,16,15,10"); Found : user_pref("extensions.crossriderapp435.435.pluginsurl", "hxxp://app-static.crossrider.com/plugin/app[…] Found : user_pref("extensions.crossriderapp435.435.pluginsversion", 10); Found : user_pref("extensions.crossriderapp435.435.premium", true); Found : user_pref("extensions.crossriderapp435.435.publisher", "Premiumplay"); Found : user_pref("extensions.crossriderapp435.435.searchstatus", 0); Found : user_pref("extensions.crossriderapp435.435.setnewtab", false); Found : user_pref("extensions.crossriderapp435.435.settingsurl", ""); Found : user_pref("extensions.crossriderapp435.435.thankyou", ""); Found : user_pref("extensions.crossriderapp435.435.updateinterval", 360); Found : user_pref("extensions.crossriderapp435.435.ver", 61); Found : user_pref("extensions.crossriderapp435.adsOldValue", -1); Found : user_pref("extensions.crossriderapp435.apps", "435"); Found : user_pref("extensions.crossriderapp435.bic", "137d87d0e85c1d2a39b0862c52e72fad"); Found : user_pref("extensions.crossriderapp435.cid", 435); Found : user_pref("extensions.crossriderapp435.firstrun", false); Found : user_pref("extensions.crossriderapp435.hadappinstalled", true); Found : user_pref("extensions.crossriderapp435.installationdate", 1339366903); Found : user_pref("extensions.crossriderapp435.lastcheck", 22486771); Found : user_pref("extensions.crossriderapp435.lastcheckitem", 22486771); Found : user_pref("extensions.crossriderapp435.misc.lastBgWorkerTimer", "1341835010742"); Found : user_pref("extensions.crossriderapp435.misc.lastDomWorkerTimer", "1341835010737"); Found : user_pref("extensions.crossriderapp435.modetype", "production"); Found : user_pref("extensions.enabledAddons", "[removed]:2.0.2.039,adblockpopups@jessehakanen.n[…] Found : user_pref("extensions.funmoods.aflt", "axl"); Found : user_pref("extensions.funmoods.autoRvrt", false); Found : user_pref("extensions.funmoods.brwsrsrc", "ietlbr"); Found : user_pref("extensions.funmoods.cntry", "US"); Found : user_pref("extensions.funmoods.dfltLng", ""); Found : user_pref("extensions.funmoods.dfltSrch", false); Found : user_pref("extensions.funmoods.dfltlng", "en"); Found : user_pref("extensions.funmoods.dfltsrch", "false"); Found : user_pref("extensions.funmoods.dnsErr", true); Found : user_pref("extensions.funmoods.envrmnt", "production"); Found : user_pref("extensions.funmoods.excTlbr", false); Found : user_pref("extensions.funmoods.hdrMd5", "7E3BDAB3052A5E16213945077B9382A8"); Found : user_pref("extensions.funmoods.hmpg", false); Found : user_pref("extensions.funmoods.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=axl&chnl=axl&cd=2XzutAtN2[…] Found : user_pref("extensions.funmoods.hrdid", "bcb4d67800000000000000508d9383f1"); Found : user_pref("extensions.funmoods.id", "bcb4d67800000000000000508d9383f1"); Found : user_pref("extensions.funmoods.instlDay", "15501"); Found : user_pref("extensions.funmoods.instlRef", "axl"); Found : user_pref("extensions.funmoods.instlday", "15501"); Found : user_pref("extensions.funmoods.instlref", "axl"); Found : user_pref("extensions.funmoods.isdcmntcmplt", true); Found : user_pref("extensions.funmoods.keywordurl", ""); Found : user_pref("extensions.funmoods.lastVrsnTs", "1.5.23.2211:55:58"); Found : user_pref("extensions.funmoods.mntrvrsn", "1.3.0"); Found : user_pref("extensions.funmoods.newTab", false); Found : user_pref("extensions.funmoods.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=axl&chnl=axl&cd=2XzutAt[…] Found : user_pref("extensions.funmoods.newtab", "false"); Found : user_pref("extensions.funmoods.newtaburl", "hxxp://start.funmoods.com/?f=2&a=axl&chnl=axl&cd=2XzutAt[…] Found : user_pref("extensions.funmoods.prdct", "funmoods"); Found : user_pref("extensions.funmoods.prtnrId", "funmoods"); Found : user_pref("extensions.funmoods.prtnrid", "funmoods"); Found : user_pref("extensions.funmoods.savedVrsnTs", "1"); Found : user_pref("extensions.funmoods.sg", "none"); Found : user_pref("extensions.funmoods.smplGrp", "none"); Found : user_pref("extensions.funmoods.smplgrp", "none"); Found : user_pref("extensions.funmoods.srch", ""); Found : user_pref("extensions.funmoods.srchPrvdr", "Search"); Found : user_pref("extensions.funmoods.srchprvdr", "Search"); Found : user_pref("extensions.funmoods.tlbrId", "base"); Found : user_pref("extensions.funmoods.tlbrSrchUrl", ""); Found : user_pref("extensions.funmoods.tlbrid", "base"); Found : user_pref("extensions.funmoods.tlbrsrchurl", ""); Found : user_pref("extensions.funmoods.vrsn", "1.5.23.22"); Found : user_pref("extensions.funmoods.vrsnTs", "1.5.23.2211:55:58"); Found : user_pref("extensions.funmoods.vrsni", "1.5.23.22"); Found : user_pref("extensions.funmoods.vrsnts", "1.5.23.2211:55:58"); Found : user_pref("extensions.funmoods_i.newTab", false); Found : user_pref("extensions.funmoods_i.smplGrp", "none"); Found : user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2211:55:58"); -\\ Google Chrome v22.0.1229.79 File : C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[R1].txt - [35188 octets] - [03/10/2012 12:58:29] ########## EOF - C:\AdwCleaner[R1].txt - [35249 octets] ##########
Hi Soulhunter,

  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
Next
  • Download OTL to your desktop.
  • Right click and select "Run as Administrator". Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    %systemdrive%\$Recycle.Bin|@;true;true;true
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
In your next post please provide the following:
  • AdwCleaner log
  • OTL.Txt
  • Extras.Txt
# AdwCleaner v2.003 - Logfile created 10/04/2012 at 12:54:55
# Updated 23/09/2012 by Xplode
# Operating system : Windows 7 Ultimate Service Pack 1 (64 bits)
# User : JAZZ - JAZZ-PC
# Boot Mode : Normal
# Running from : C:\Users\JAZZ\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Deleted on reboot : C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhfdcmehmjcclgopdodkjdicohagipid
File Deleted : C:\Windows\SysWOW64\conduitEngine.tmp
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\ProgramData\InstallMate
Folder Deleted : C:\ProgramData\Premium
Folder Deleted : C:\ProgramData\WeCareReminder
Folder Deleted : C:\Users\JAZZ\AppData\Local\Conduit
Folder Deleted : C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhfdcmehmjcclgopdodkjdicohagipid
Folder Deleted : C:\Users\JAZZ\AppData\Local\TempDir
Folder Deleted : C:\Users\JAZZ\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\JAZZ\AppData\LocalLow\Toolbar4
Folder Deleted : C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\ConduitCommon
Folder Deleted : C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\CT2790392
Folder Deleted : C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
Folder Deleted : C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\[removed]

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Cr_Installer
Key Deleted : HKCU\Software\Google\Chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4CE516A7-F7AC-4628-B411-8F886DC5733E}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbCommonUtils.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\TbHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils
Key Deleted : HKLM\SOFTWARE\Classes\TbCommonUtils.CommonUtils.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbDownloadManager.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbPropertyManager.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbRequest
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbRequest.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbTask
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.TbTask.1
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper
Key Deleted : HKLM\SOFTWARE\Classes\TbHelper.ToolbarHelper.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2790392
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B87F8B63-7274-43FD-87FA-09D3B7496148}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C4BAE205-5E02-4E32-876E-F34B4E2D000C}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\Freeze.com
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{1C950DE5-D31E-42FB-AFB9-91B0161633D8}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3BDF4CE9-E81D-432B-A55E-9F0570CE811F}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A9A56B8E-2DEB-4ED3-BC92-1FA450BCE1A5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AE338F6D-5A7C-4D1D-86E3-C618532079B5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{C339D489-FABC-41DD-B39D-276101667C70}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D89031C2-10DA-4C90-9A62-FCED012BC46B}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{23C70BCA-6E23-4A65-AD2E-1389062074F1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{295CACB4-51F5-46FD-914E-C72BAAE1B672}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C0585B2F-74D7-4734-88DE-6C150C5D4036}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EF0588D6-1621-4A75-B8BE-F4BC34794136}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mhfdcmehmjcclgopdodkjdicohagipid
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{01221FCC-4BFB-461C-B08C-F6D2DF309921}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0D80F1C5-D17B-4177-AC68-955F3EF9F191}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23C70BCA-6E23-4A65-AD2E-1389062074F1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{295CACB4-51F5-46FD-914E-C72BAAE1B672}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{452AE416-9A97-44CA-93DA-D0F15C36254F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{45CDA4F7-594C-49A0-AAD1-8224517FE979}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{81E852CC-1FD5-4004-8761-79A48B975E29}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B2CA345D-ADB8-4F5D-AC64-4AB34322F659}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B9F43021-60D4-42A6-A065-9BA37F38AC47}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BF921DD3-732A-4A11-933B-A5EA49F2FD2C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C0585B2F-74D7-4734-88DE-6C150C5D4036}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D83B296A-2FA6-425B-8AE8-A1F33D99FBD6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EF0588D6-1621-4A75-B8BE-F4BC34794136}
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

Restored : [HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]

-\\ Mozilla Firefox v15.0.1 (en-US)

Profile name : default
File : C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\prefs.js

C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\user.js … Deleted !

Deleted : user_pref("CT2790392..clientLogIsEnabled", true);
Deleted : user_pref("CT2790392..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[…]
Deleted : user_pref("CT2790392..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[…]
Deleted : user_pref("CT2790392.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2790392.AppTrackingLastCheckTime", "Sat Dec 10 2011 04:21:32 GMT-0800 (Pacific Standard[…]
Deleted : user_pref("CT2790392.BrowserCompStateIsOpen_129633547190125290", true);
Deleted : user_pref("CT2790392.CTID", "CT2790392");
Deleted : user_pref("CT2790392.CommunitiesChangesLastCheckTime", "0");
Deleted : user_pref("CT2790392.CurrentServerDate", "10-12-2011");
Deleted : user_pref("CT2790392.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2790392.DialogsGetterLastCheckTime", "Wed Dec 07 2011 14:14:34 GMT-0800 (Pacific Standa[…]
Deleted : user_pref("CT2790392.DownloadReferralCookieData", "");
Deleted : user_pref("CT2790392.EMailNotifierPollDate", "Sat Dec 10 2011 04:36:21 GMT-0800 (Pacific Standard Ti[…]
Deleted : user_pref("CT2790392.FeedLastCount129313977501788460", 501);
Deleted : user_pref("CT2790392.FeedPollDate129313974171006416", "Sat Dec 10 2011 04:21:21 GMT-0800 (Pacific St[…]
Deleted : user_pref("CT2790392.FeedPollDate129313975698350231", "Sat Dec 10 2011 04:21:21 GMT-0800 (Pacific St[…]
Deleted : user_pref("CT2790392.FeedPollDate129313976370850190", "Sat Dec 10 2011 04:21:21 GMT-0800 (Pacific St[…]
Deleted : user_pref("CT2790392.FeedPollDate129313976648818968", "Sat Dec 10 2011 04:21:21 GMT-0800 (Pacific St[…]
Deleted : user_pref("CT2790392.FeedPollDate129313977444757117", "Sat Dec 10 2011 04:21:21 GMT-0800 (Pacific St[…]
Deleted : user_pref("CT2790392.FeedPollDate129313980389131455", "Sat Dec 10 2011 04:21:21 GMT-0800 (Pacific St[…]
Deleted : user_pref("CT2790392.FeedPollDate129313980655381977", "Sat Dec 10 2011 04:21:21 GMT-0800 (Pacific St[…]
Deleted : user_pref("CT2790392.FeedPollDate129313980886163259", "Sat Dec 10 2011 04:21:21 GMT-0800 (Pacific St[…]
Deleted : user_pref("CT2790392.FeedPollDate129313981234756535", "Sat Dec 10 2011 04:21:22 GMT-0800 (Pacific St[…]
Deleted : user_pref("CT2790392.FeedPollDate129313983226631720", "Sat Dec 10 2011 04:21:22 GMT-0800 (Pacific St[…]
Deleted : user_pref("CT2790392.FeedPollDate129313983607725691", "Sat Dec 10 2011 04:21:22 GMT-0800 (Pacific St[…]
Deleted : user_pref("CT2790392.FeedTTL129313974171006416", 10);
Deleted : user_pref("CT2790392.FeedTTL129313977444757117", 15);
Deleted : user_pref("CT2790392.FeedTTL129313980655381977", 5);
Deleted : user_pref("CT2790392.FeedTTL129313981234756535", 5);
Deleted : user_pref("CT2790392.FirstServerDate", "6-7-2011");
Deleted : user_pref("CT2790392.FirstTime", true);
Deleted : user_pref("CT2790392.FirstTimeFF3", true);
Deleted : user_pref("CT2790392.FixPageNotFoundErrors", false);
Deleted : user_pref("CT2790392.GroupingInvalidateCache", false);
Deleted : user_pref("CT2790392.GroupingLastCheckTime", "0");
Deleted : user_pref("CT2790392.GroupingLastServerUpdateTime", "0");
Deleted : user_pref("CT2790392.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2790392.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2790392.HasUserGlobalKeys", true);
Deleted : user_pref("CT2790392.HomePageProtectorEnabled", false);
Deleted : user_pref("CT2790392.Initialize", true);
Deleted : user_pref("CT2790392.InitializeCommonPrefs", true);
Deleted : user_pref("CT2790392.InstallationAndCookieDataSentCount", 3);
Deleted : user_pref("CT2790392.InstallationType", "UnknownIntegration");
Deleted : user_pref("CT2790392.InstalledDate", "Wed Jul 06 2011 07:39:55 GMT-0700 (Pacific Daylight Time)");
Deleted : user_pref("CT2790392.InvalidateCache", false);
Deleted : user_pref("CT2790392.IsAlertDBUpdated", true);
Deleted : user_pref("CT2790392.IsGrouping", false);
Deleted : user_pref("CT2790392.IsInitSetupIni", true);
Deleted : user_pref("CT2790392.IsMulticommunity", false);
Deleted : user_pref("CT2790392.IsOpenThankYouPage", true);
Deleted : user_pref("CT2790392.IsOpenUninstallPage", false);
Deleted : user_pref("CT2790392.LanguagePackLastCheckTime", "Fri Dec 09 2011 19:51:47 GMT-0800 (Pacific Standar[…]
Deleted : user_pref("CT2790392.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2790392.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[…]
Deleted : user_pref("CT2790392.LastLogin_3.5.0.12", "Sat Dec 10 2011 04:21:21 GMT-0800 (Pacific Standard Time)[…]
Deleted : user_pref("CT2790392.LatestVersion", "3.8.1.0");
Deleted : user_pref("CT2790392.Locale", "en");
Deleted : user_pref("CT2790392.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2790392.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2790392.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2790392.MyStuffEnabledAtInstallation", true);
Deleted : user_pref("CT2790392.OriginalFirstVersion", "3.5.0.12");
Deleted : user_pref("CT2790392.RadioLastCheckTime", "0");
Deleted : user_pref("CT2790392.RadioLastUpdateIPServer", "0");
Deleted : user_pref("CT2790392.RadioLastUpdateServer", "0");
Deleted : user_pref("CT2790392.SHRINK_TOOLBAR", 1);
Deleted : user_pref("CT2790392.SearchEngineBeforeUnload", "chrome://browser-region/locale/region.properties");
Deleted : user_pref("CT2790392.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2790392.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT279[…]
Deleted : user_pref("CT2790392.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2790392.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2790392.SearchInNewTabLastCheckTime", "Fri Dec 09 2011 19:51:46 GMT-0800 (Pacific Stand[…]
Deleted : user_pref("CT2790392.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[…]
Deleted : user_pref("CT2790392.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[…]
Deleted : user_pref("CT2790392.SearchInNewTabUserEnabled", false);
Deleted : user_pref("CT2790392.SearchProtectorEnabled", false);
Deleted : user_pref("CT2790392.SearchProtectorToolbarDisabled", false);
Deleted : user_pref("CT2790392.ServiceMapLastCheckTime", "Fri Dec 09 2011 19:51:47 GMT-0800 (Pacific Standard […]
Deleted : user_pref("CT2790392.SettingsLastCheckTime", "Fri Dec 09 2011 12:21:20 GMT-0800 (Pacific Standard Ti[…]
Deleted : user_pref("CT2790392.SettingsLastUpdate", "1321973040");
Deleted : user_pref("CT2790392.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2790392.ThirdPartyComponentsLastCheck", "Thu Dec 01 2011 14:14:32 GMT-0800 (Pacific Sta[…]
Deleted : user_pref("CT2790392.ThirdPartyComponentsLastUpdate", "1312887586");
Deleted : user_pref("CT2790392.ToolbarShrinkedFromSetup", false);
Deleted : user_pref("CT2790392.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2790392");
Deleted : user_pref("CT2790392.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[…]
Deleted : user_pref("CT2790392.UserID", "UN49523552041056196");
Deleted : user_pref("CT2790392.ValidationData_Toolbar", 2);
Deleted : user_pref("CT2790392.WeatherNetwork", "");
Deleted : user_pref("CT2790392.WeatherPollDate", "Sat Dec 10 2011 04:21:26 GMT-0800 (Pacific Standard Time)");
Deleted : user_pref("CT2790392.WeatherUnit", "F");
Deleted : user_pref("CT2790392.alertChannelId", "1182482");
Deleted : user_pref("CT2790392.appApproved.129309578575850709", true);
Deleted : user_pref("CT2790392.backendstorage.cb_firstuse0100", "31");
Deleted : user_pref("CT2790392.backendstorage.cbfirsttime", "5475652053657020323720323031312031393A33313A32342[…]
Deleted : user_pref("CT2790392.backendstorage.scriptsource", "687474703A2F2F3132372E302E302E313A31303030302F67[…]
Deleted : user_pref("CT2790392.backendstorage.url_history", "687474703A2F2F7777772E676F6F676C652E636F6D2F75726[…]
Deleted : user_pref("CT2790392.backendstorage.url_history_time", "31333233343832393035373734");
Deleted : user_pref("CT2790392.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[…]
Deleted : user_pref("CT2790392.globalFirstTimeInfoLastCheckTime", "Sat Dec 10 2011 04:21:21 GMT-0800 (Pacific […]
Deleted : user_pref("CT2790392.homepageProtectorEnableByLogin", true);
Deleted : user_pref("CT2790392.initDone", true);
Deleted : user_pref("CT2790392.isAppTrackingManagerOn", true);
Deleted : user_pref("CT2790392.myStuffEnabled", true);
Deleted : user_pref("CT2790392.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2790392.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr;[…]
Deleted : user_pref("CT2790392.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2790392.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[…]
Deleted : user_pref("CT2790392.oldAppsList", "129298377186075601,129298377186388102,111,1000234,12929837718654[…]
Deleted : user_pref("CT2790392.searchProtectorDialogDelayInSec", 10);
Deleted : user_pref("CT2790392.searchProtectorEnableByLogin", true);
Deleted : user_pref("CT2790392.testingCtid", "");
Deleted : user_pref("CT2790392.toolbarAppMetaDataLastCheckTime", "Fri Dec 09 2011 19:51:47 GMT-0800 (Pacific S[…]
Deleted : user_pref("CT2790392.toolbarContextMenuLastCheckTime", "Fri Dec 09 2011 12:21:20 GMT-0800 (Pacific S[…]
Deleted : user_pref("CT2790392.usagesFlag", 2);
Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2790392/CT2790392[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1182482/1178159/US", "\"0\"[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2790392", […]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo;[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc;[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo;[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local;[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.5.[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2790392",[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2790392&octid;=[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2790392/CT2790392[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=EB_LOCALE",[…]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"1d8[…]
Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\JAZZ\\AppData\\Roaming\\Mozilla\\Fi[…]
Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.5.0.12");
Deleted : user_pref("CommunityToolbar.MiniIPageGadgetPosition.hxxp://youtube.conduitapps.com/v115/gadget.php?a[…]
Deleted : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "");
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2790392");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2790392");
Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT2790392");
Deleted : user_pref("CommunityToolbar.facebook.settingsLastCheckTime", "Fri Dec 09 2011 19:51:47 GMT-0800 (Pac[…]
Deleted : user_pref("CommunityToolbar.globalUserId", "f3ccd69c-3273-4c46-8c21-6a68baf0b075");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Sat Dec 03 2011 15:35:1[…]
Deleted : user_pref("CommunityToolbar.notifications.alertInfoInterval", 1440);
Deleted : user_pref("CommunityToolbar.notifications.alertInfoLastCheckTime", "Fri Dec 09 2011 19:51:55 GMT-080[…]
Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.locale", "en");
Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Fri Dec 09 2011 19:51:47 GMT-0800 (P[…]
Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.notifications.userId", "227799c1-a21c-4ee0-924a-b3f1e7ea0360");
Deleted : user_pref("extensions.crossriderapp435.435.InstallationThankYouPage", true);
Deleted : user_pref("extensions.crossriderapp435.435.InstallationTime", 1339366826);
Deleted : user_pref("extensions.crossriderapp435.435.InstallationUserSettings.searchUserConifrma
tion", false);
Deleted : user_pref("extensions.crossriderapp435.435.InstallationUserSettings.setHomepage", false);
Deleted : user_pref("extensions.crossriderapp435.435.InstallationUserSettings.setNewTab", false);
Deleted : user_pref("extensions.crossriderapp435.435.InstallationUserSettings.setSearch", false);
Deleted : user_pref("extensions.crossriderapp435.435.active", true);
Deleted : user_pref("extensions.crossriderapp435.435.addressbar", "");
Deleted : user_pref("extensions.crossriderapp435.435.affid", "0");
Deleted : user_pref("extensions.crossriderapp435.435.backgroundjs", "\n\nfunction buttonClick() { \n \[…]
Deleted : user_pref("extensions.crossriderapp435.435.backgroundver", 8);
Deleted : user_pref("extensions.crossriderapp435.435.can_run_bg_code", true);
Deleted : user_pref("extensions.crossriderapp435.435.certdomaininstaller", "");
Deleted : user_pref("extensions.crossriderapp435.435.changeprevious", false);
Deleted : user_pref("extensions.crossriderapp435.435.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:[…]
Deleted : user_pref("extensions.crossriderapp435.435.cookie.InstallationTime.value", "1339366826");
Deleted : user_pref("extensions.crossriderapp435.435.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00:0[…]
Deleted : user_pref("extensions.crossriderapp435.435.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 GM[…]
Deleted : user_pref("extensions.crossriderapp435.435.cookie._GPL_aoi.value", "%221339366913%22");
Deleted : user_pref("extensions.crossriderapp435.435.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030 0[…]
Deleted : user_pref("extensions.crossriderapp435.435.cookie._GPL_parent_zoneid.value", "%2214974%22");
Deleted : user_pref("extensions.crossriderapp435.435.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:00:00[…]
Deleted : user_pref("extensions.crossriderapp435.435.cookie._GPL_zoneid.value", "%2244191%22");
Deleted : user_pref("extensions.crossriderapp435.435.cookie.__GPL_ID.expiration", "Fri Feb 01 2030 00:00:00 GM[…]
Deleted : user_pref("extensions.crossriderapp435.435.cookie.__GPL_ID.value", "435");
Deleted : user_pref("extensions.crossriderapp435.435.cookie.__GPL_custom_zoneid.expiration", "Fri Feb 01 2030 […]
Deleted : user_pref("extensions.crossriderapp435.435.cookie.__GPL_custom_zoneid.value", "14969");
Deleted : user_pref("extensions.crossriderapp435.435.cookie.__GPL_pubid.expiration", "Fri Feb 01 2030 00:00:00[…]
Deleted : user_pref("extensions.crossriderapp435.435.cookie.__GPL_pubid.value", "%222993%22");
Deleted : user_pref("extensions.crossriderapp435.435.description", "Premiumplay Codec check");
Deleted : user_pref("extensions.crossriderapp435.435.domain", "");
Deleted : user_pref("extensions.crossriderapp435.435.emailsig", "");
Deleted : user_pref("extensions.crossriderapp435.435.enablesearch", false);
Deleted : user_pref("extensions.crossriderapp435.435.exposesites", "");
Deleted : user_pref("extensions.crossriderapp435.435.fbremoteurl", "");
Deleted : user_pref("extensions.crossriderapp435.435.group", 0);
Deleted : user_pref("extensions.crossriderapp435.435.homepage", "");
Deleted : user_pref("extensions.crossriderapp435.435.iframe", false);
Deleted : user_pref("extensions.crossriderapp435.435.internaldb.InstallerIdentifiers.expiration", "Fri Feb 01 […]
Deleted : user_pref("extensions.crossriderapp435.435.internaldb.InstallerIdentifiers.value", "%7B%22installer_[…]
Deleted : user_pref("extensions.crossriderapp435.435.internaldb.Resources_appVer.expiration", "Fri Feb 01 2030[…]
Deleted : user_pref("extensions.crossriderapp435.435.internaldb.Resources_appVer.value", "61");
Deleted : user_pref("extensions.crossriderapp435.435.internaldb.Resources_lastVersion.expiration", "Fri Feb 01[…]
Deleted : user_pref("extensions.crossriderapp435.435.internaldb.Resources_lastVersion.value", "0");
Deleted : user_pref("extensions.crossriderapp435.435.internaldb.Resources_meta.expiration", "Fri Feb 01 2030 0[…]
Deleted : user_pref("extensions.crossriderapp435.435.internaldb.Resources_meta.value", "%7B%7D");
Deleted : user_pref("extensions.crossriderapp435.435.internaldb.Resources_nextCheck.expiration", "Thu Oct 04 2[…]
Deleted : user_pref("extensions.crossriderapp435.435.internaldb.Resources_nextCheck.value", "true");
Deleted : user_pref("extensions.crossriderapp435.435.internaldb.Resources_queue.expiration", "Fri Feb 01 2030 […]
Deleted : user_pref("extensions.crossriderapp435.435.internaldb.Resources_queue.value", "%7B%7D");
Deleted : user_pref("extensions.crossriderapp435.435.js", "\n\n$jquery(document).ready(function() {\n \n $[…]
Deleted : user_pref("extensions.crossriderapp435.435.manifesturl", "");
Deleted : user_pref("extensions.crossriderapp435.435.name", "Codec-V");
Deleted : user_pref("extensions.crossriderapp435.435.newtab", "");
Deleted : user_pref("extensions.crossriderapp435.435.opensearch", "");
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_10.code", "if(!appAPI.matchPages(\"search.[…]
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_10.name", "app_435_specific");
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_10.ver", 4);
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_13.code", "(function(a){a.selectedText=fun[…]
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_13.name", "CrossriderAppUtils");
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_13.ver", 2);
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_14.code", "if(typeof(appAPI)===\"undefined[…]
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_14.name", "CrossriderUtils");
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_14.ver", 2);
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_15.code", "(function(f){var u={};var e=Mat[…]
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_15.name", "FacebookFFIE");
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_15.ver", 1);
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_16.code", "(function(b,a){function h(){var[…]
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_16.name", "FFAppAPIWrapper");
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_16.ver", 3);
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_17.code", "/*!\n * jQuery JavaScript Libra[…]
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_17.name", "jQuery");
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_17.ver", 1);
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_47.code", "(function(){appAPI.ready=functi[…]
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_47.name", "resources_background");
Deleted : user_pref("extensions.crossriderapp435.435.plugins.plugin_47.ver", 1);
Deleted : user_pref("extensions.crossriderapp435.435.plugins_lists.plugins_0", "17,14,16,47");
Deleted : user_pref("extensions.crossriderapp435.435.plugins_lists.plugins_1", "17,14,13,16,15,10");
Deleted : user_pref("extensions.crossriderapp435.435.pluginsurl", "hxxp://app-static.crossrider.com/plugin/app[…]
Deleted : user_pref("extensions.crossriderapp435.435.pluginsversion", 10);
Deleted : user_pref("extensions.crossriderapp435.435.premium", true);
Deleted : user_pref("extensions.crossriderapp435.435.publisher", "Premiumplay");
Deleted : user_pref("extensions.crossriderapp435.435.searchstatus", 0);
Deleted : user_pref("extensions.crossriderapp435.435.setnewtab", false);
Deleted : user_pref("extensions.crossriderapp435.435.settingsurl", "");
Deleted : user_pref("extensions.crossriderapp435.435.thankyou", "");
Deleted : user_pref("extensions.crossriderapp435.435.updateinterval", 360);
Deleted : user_pref("extensions.crossriderapp435.435.ver", 61);
Deleted : user_pref("extensions.crossriderapp435.adsOldValue", -1);
Deleted : user_pref("extensions.crossriderapp435.apps", "435");
Deleted : user_pref("extensions.crossriderapp435.bic", "137d87d0e85c1d2a39b0862c52e72fad");
Deleted : user_pref("extensions.crossriderapp435.cid", 435);
Deleted : user_pref("extensions.crossriderapp435.firstrun", false);
Deleted : user_pref("extensions.crossriderapp435.hadappinstalled", true);
Deleted : user_pref("extensions.crossriderapp435.installationdate", 1339366903);
Deleted : user_pref("extensions.crossriderapp435.lastcheck", 22489671);
Deleted : user_pref("extensions.crossriderapp435.lastcheckitem", 22489671);
Deleted : user_pref("extensions.crossriderapp435.misc.lastBgWorkerTimer", "1341835010742");
Deleted : user_pref("extensions.crossriderapp435.misc.lastDomWorkerTimer", "1341835010737");
Deleted : user_pref("extensions.crossriderapp435.modetype", "production");
Deleted : user_pref("extensions.enabledAddons", "[removed]:2.0.2.039,adblockpopups@jessehakanen.n[…]
Deleted : user_pref("extensions.funmoods.aflt", "axl");
Deleted : user_pref("extensions.funmoods.autoRvrt", false);
Deleted : user_pref("extensions.funmoods.brwsrsrc", "ietlbr");
Deleted : user_pref("extensions.funmoods.cntry", "US");
Deleted : user_pref("extensions.funmoods.dfltLng", "");
Deleted : user_pref("extensions.funmoods.dfltSrch", false);
Deleted : user_pref("extensions.funmoods.dfltlng", "en");
Deleted : user_pref("extensions.funmoods.dfltsrch", "false");
Deleted : user_pref("extensions.funmoods.dnsErr", true);
Deleted : user_pref("extensions.funmoods.envrmnt", "production");
Deleted : user_pref("extensions.funmoods.excTlbr", false);
Deleted : user_pref("extensions.funmoods.hdrMd5", "7E3BDAB3052A5E16213945077B9382A8");
Deleted : user_pref("extensions.funmoods.hmpg", false);
Deleted : user_pref("extensions.funmoods.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a;=axl&chnl;=axl&cd;=2XzutAtN2[…]
Deleted : user_pref("extensions.funmoods.hrdid", "bcb4d67800000000000000508d9383f1");
Deleted : user_pref("extensions.funmoods.id", "bcb4d67800000000000000508d9383f1");
Deleted : user_pref("extensions.funmoods.instlDay", "15501");
Deleted : user_pref("extensions.funmoods.instlRef", "axl");
Deleted : user_pref("extensions.funmoods.instlday", "15501");
Deleted : user_pref("extensions.funmoods.instlref", "axl");
Deleted : user_pref("extensions.funmoods.isdcmntcmplt", true);
Deleted : user_pref("extensions.funmoods.keywordurl", "");
Deleted : user_pref("extensions.funmoods.lastVrsnTs", "1.5.23.2211:55:58");
Deleted : user_pref("extensions.funmoods.mntrvrsn", "1.3.0");
Deleted : user_pref("extensions.funmoods.newTab", false);
Deleted : user_pref("extensions.funmoods.newTabUrl", "hxxp://start.funmoods.com/?f=2&a;=axl&chnl;=axl&cd;=2XzutAt[…]
Deleted : user_pref("extensions.funmoods.newtab", "false");
Deleted : user_pref("extensions.funmoods.newtaburl", "hxxp://start.funmoods.com/?f=2&a;=axl&chnl;=axl&cd;=2XzutAt[…]
Deleted : user_pref("extensions.funmoods.prdct", "funmoods");
Deleted : user_pref("extensions.funmoods.prtnrId", "funmoods");
Deleted : user_pref("extensions.funmoods.prtnrid", "funmoods");
Deleted : user_pref("extensions.funmoods.savedVrsnTs", "1");
Deleted : user_pref("extensions.funmoods.sg", "none");
Deleted : user_pref("extensions.funmoods.smplGrp", "none");
Deleted : user_pref("extensions.funmoods.smplgrp", "none");
Deleted : user_pref("extensions.funmoods.srch", "");
Deleted : user_pref("extensions.funmoods.srchPrvdr", "Search");
Deleted : user_pref("extensions.funmoods.srchprvdr", "Search");
Deleted : user_pref("extensions.funmoods.tlbrId", "base");
Deleted : user_pref("extensions.funmoods.tlbrSrchUrl", "");
Deleted : user_pref("extensions.funmoods.tlbrid", "base");
Deleted : user_pref("extensions.funmoods.tlbrsrchurl", "");
Deleted : user_pref("extensions.funmoods.vrsn", "1.5.23.22");
Deleted : user_pref("extensions.funmoods.vrsnTs", "1.5.23.2211:55:58");
Deleted : user_pref("extensions.funmoods.vrsni", "1.5.23.22");
Deleted : user_pref("extensions.funmoods.vrsnts", "1.5.23.2211:55:58");
Deleted : user_pref("extensions.funmoods_i.newTab", false);
Deleted : user_pref("extensions.funmoods_i.smplGrp", "none");
Deleted : user_pref("extensions.funmoods_i.vrsnTs", "1.5.23.2211:55:58");

-\\ Google Chrome v22.0.1229.79

File : C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [35271 octets] - [03/10/2012 12:58:29]
AdwCleaner[R2].txt - [35226 octets] - [04/10/2012 12:54:41]
AdwCleaner[S1].txt - [36131 octets] - [04/10/2012 12:54:55]

########## EOF - C:\AdwCleaner[S1].txt - [36192 octets] ##########


OTL logfile created on: 10/4/2012 12:59:25 PM - Run 1
OTL by OldTimer - Version 3.2.70.2 Folder = C:\Users\JAZZ\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 0.94 Gb Available Physical Memory | 47.26% Memory free
4.00 Gb Paging File | 2.87 Gb Available in Paging File | 71.76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 60.00 Gb Total Space | 5.72 Gb Free Space | 9.54% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 134.74 Gb Free Space | 28.93% Space Free | Partition Type: NTFS
Drive F: | 465.65 Gb Total Space | 4.96 Gb Free Space | 1.06% Space Free | Partition Type: FAT32

Computer Name: JAZZ-PC | User Name: JAZZ | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\JAZZ\Desktop\OTL(1).exe (OldTimer Tools)
PRC - C:\Users\JAZZ\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_278.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - E:\!Winamp\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Windows\FixCamera.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\FixCamera.exe ()


========== Services (SafeList) ==========

SRV:64bit: - (FLEXnet Licensing Service 64) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Acresso Software Inc.)
SRV:64bit: - (nlscc) – C:\Windows\SysNative\nlsInterface.EXE (Nalpeiron Ltd.)
SRV:64bit: - (WTouchService) – C:\Program Files\WTouch\WTouchService.exe (Wacom Technology, Corp.)
SRV:64bit: - (TabletServicePen) – C:\Windows\SysNative\Pen_Tablet.exe (Wacom Technology, Corp.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (npggsvc) – C:\Windows\SysWOW64\GameMon.des (INCA Internet Co., Ltd.)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ServiceLayer) – C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (wacomvhid) – C:\Windows\SysNative\drivers\wacomvhid.sys (Wacom Technology)
DRV:64bit: - (pccsmcfd) – C:\Windows\SysNative\drivers\pccsmcfdx64.sys (Nokia)
DRV:64bit: - (adfs) – C:\Windows\SysNative\drivers\adfs.sys (Adobe Systems, Inc.)
DRV:64bit: - (wacommousefilter) – C:\Windows\SysNative\drivers\wacommousefilter.sys (Wacom Technology)
DRV - (CdaC15BA) – C:\Windows\SysWOW64\drivers\CDAC15BA.SYS ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (adfs) – C:\Windows\SysWow64\drivers\adfs.sys (Adobe Systems, Inc.)
DRV - (NPPTNT2) – C:\Windows\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 07 F6 33 BF E4 8E CD 01 [binary data]
IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {88c7f2aa-f93f-432c-8f0e-b7d85967a527}:[removed]
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8442
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_278.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@raidcall.en/RCplugin: C:\Users\JAZZ\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.3: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\JAZZ\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\JAZZ\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/10 19:11:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2010/07/07 00:04:52 | 000,000,000 | -H-D | M] (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Extensions
[2012/10/04 12:55:01 | 000,000,000 | -H-D | M] (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions
[2012/09/17 15:13:01 | 000,000,000 | —D | M] (FT DeepDark) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66}
[2012/02/06 19:02:08 | 000,000,000 | -H-D | M] ("Free YouTube Download (Free Studio) Menu") – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012/10/04 12:50:54 | 000,000,000 | —D | M] ("Codec-V") – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\[removed]
[2012/09/10 20:14:59 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\[removed]
[2012/10/04 12:50:54 | 000,000,000 | —D | M] (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\[removed]\chrome\content\extensionCode
[2012/09/10 19:52:22 | 000,109,964 | —- | M] () (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\[removed]
[2012/05/18 13:24:35 | 000,550,833 | -H– | M] () (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\[removed]
[2012/09/10 19:55:44 | 000,123,385 | —- | M] () (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\[removed]
[2012/06/10 11:56:30 | 000,179,234 | -H– | M] () (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\[removed]
[2012/09/10 19:54:08 | 000,056,403 | —- | M] () (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\[removed]
[2012/09/10 19:56:42 | 000,097,169 | —- | M] () (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}.xpi
[2012/09/26 12:09:20 | 000,061,406 | —- | M] () (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi
[2012/09/10 19:48:11 | 000,199,396 | —- | M] () (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
[2012/09/10 19:45:44 | 000,741,958 | —- | M] () (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/09/10 19:11:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/09/05 18:27:05 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/09/05 18:26:22 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/09/05 18:26:22 | 000,002,253 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\JAZZ\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\JAZZ\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\JAZZ\AppData\Local\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: PopCap Games Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nppopcaploader.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Wacom Dynamic Link Library (Enabled) = C:\Program Files (x86)\TabletPlugins\npwacom.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - Extension: YouTube = C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Codec-V = C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpnbdefcbnoefmmcpelplabbkfmfhlho\1.17.48_0\
CHR - Extension: Codec-V = C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpnbdefcbnoefmmcpelplabbkfmfhlho\1.20.61_0\crossrider
CHR - Extension: Codec-V = C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpnbdefcbnoefmmcpelplabbkfmfhlho\1.20.61_0\
CHR - Extension: Skype Click to Call = C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\
CHR - Extension: Gmail = C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2010/07/10 13:15:10 | 000,000,879 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [FixCamera] C:\Windows\FixCamera.exe ()
O4 - HKLM..\Run: [WinampAgent] E:\!Winamp\Winamp\winampa.exe (Nullsoft, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\JAZZ\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\JAZZ\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.7.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A3512F62-7263-484B-99A6-3FA560CAEE7D}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/04/05 08:44:20 | 000,000,000 | -H-D | M] - F:\autorun – [ FAT32 ]
O33 - MountPoints2\{832882ee-8992-11df-a617-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{832882ee-8992-11df-a617-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/10/04 12:58:23 | 000,601,088 | —- | C] (OldTimer Tools) – C:\Users\JAZZ\Desktop\OTL(1).exe
[2012/10/04 06:18:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2012/10/03 23:09:04 | 000,000,000 | —D | C] – C:\Users\JAZZ\AppData\Local\Electronic_Arts_Inc
[2012/10/01 15:27:57 | 000,000,000 | —D | C] – C:\Users\JAZZ\Desktop\RK_Quarantine
[2012/10/01 15:17:56 | 000,600,576 | —- | C] (OldTimer Tools) – C:\Users\JAZZ\Desktop\OTL.exe
[2012/10/01 13:20:51 | 000,000,000 | —D | C] – C:\Users\JAZZ\AppData\Roaming\KudosChatSearch
[2012/09/22 03:02:08 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/09/22 03:02:07 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/09/22 03:02:05 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/09/22 03:02:04 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/09/22 03:02:04 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/09/22 03:02:04 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/09/22 03:02:03 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/09/22 03:02:03 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/09/22 03:02:02 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/09/22 03:02:02 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/09/22 03:02:01 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/09/22 03:02:00 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/09/22 03:01:56 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/09/22 03:01:56 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/09/22 03:01:56 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/09/12 02:43:48 | 000,376,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\netio.sys
[2012/09/12 02:43:48 | 000,288,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2012/09/11 04:28:44 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\prevhost.exe
[2012/09/11 04:28:44 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\prevhost.exe
[2012/09/11 04:03:31 | 000,000,000 | R–D | C] – C:\Users\JAZZ\Downloads
[2012/09/11 02:04:55 | 000,000,000 | R–D | C] – C:\Users\JAZZ\Pictures
[2012/09/10 19:11:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Maintenance Service
[2012/09/10 19:11:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012/09/10 19:08:03 | 000,000,000 | —D | C] – C:\Windows\SysNative\SPReview
[2012/09/10 00:38:47 | 000,000,000 | —D | C] – C:\Users\JAZZ\AppData\Local\Aeria Games
[2012/09/10 00:33:43 | 000,000,000 | —D | C] – C:\Users\JAZZ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AeriaGames
[2012/09/10 00:31:33 | 000,000,000 | -HSD | C] – C:\Windows\SysWow64\AI_RecycleBin
[2012/09/09 19:33:34 | 000,246,760 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2012/09/09 19:33:16 | 000,095,208 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2012/09/09 19:32:16 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2012/09/09 16:52:04 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2012/09/09 16:38:40 | 000,000,000 | -H-D | C] – C:\Users\JAZZ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\File Recovery
[2012/09/09 15:44:11 | 000,000,000 | -H-D | C] – C:\Users\JAZZ\Desktop\we
[2012/09/07 04:55:50 | 000,000,000 | —D | C] – C:\AeriaGames

========== Files - Modified Within 30 Days ==========

[2012/10/04 13:00:40 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/10/04 13:00:40 | 000,623,940 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/10/04 13:00:40 | 000,106,316 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/10/04 12:58:26 | 000,601,088 | —- | M] (OldTimer Tools) – C:\Users\JAZZ\Desktop\OTL(1).exe
[2012/10/04 12:56:24 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/04 12:56:23 | 000,000,412 | —- | M] () – C:\Windows\tasks\PC Optimizer Pro64 startups.job
[2012/10/04 12:56:12 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/10/04 12:56:02 | 1610,260,480 | -HS- | M] () – C:\hiberfil.sys
[2012/10/04 12:41:00 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2375342815-4246018699-2964025557-1001UA.job
[2012/10/04 12:37:03 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/04 12:35:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/10/04 06:22:23 | 000,005,872 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/04 06:22:23 | 000,005,872 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/03 23:22:18 | 000,000,061 | —- | M] () – C:\Users\JAZZ\Desktop\Need for Speed World - Home.URL
[2012/10/03 23:08:27 | 000,000,788 | —- | M] () – C:\Users\Public\Desktop\Need For Speed World.lnk
[2012/10/03 23:02:20 | 000,363,502 | —- | M] () – C:\Users\JAZZ\nfsw004.jpg
[2012/10/03 23:02:20 | 000,351,248 | —- | M] () – C:\Users\JAZZ\nfsw003.jpg
[2012/10/03 23:02:20 | 000,333,015 | —- | M] () – C:\Users\JAZZ\nfsw002.jpg
[2012/10/03 23:02:19 | 000,365,164 | —- | M] () – C:\Users\JAZZ\nfsw006.jpg
[2012/10/03 23:02:18 | 000,377,127 | —- | M] () – C:\Users\JAZZ\nfsw005.jpg
[2012/10/03 23:02:18 | 000,348,281 | —- | M] () – C:\Users\JAZZ\nfsw001.jpg
[2012/10/03 23:02:16 | 000,319,333 | —- | M] () – C:\Users\JAZZ\nfsw000.jpg
[2012/10/03 12:58:10 | 000,513,501 | —- | M] () – C:\Users\JAZZ\Desktop\adwcleaner.exe
[2012/10/03 10:41:00 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2375342815-4246018699-2964025557-1001Core.job
[2012/10/02 04:00:45 | 005,863,736 | —- | M] () – C:\Users\JAZZ\2012-10-02 06-55-42.bmp
[2012/10/02 04:00:43 | 005,863,736 | —- | M] () – C:\Users\JAZZ\2012-10-02 06-55-36.bmp
[2012/10/01 16:17:12 | 000,001,456 | —- | M] () – C:\Users\JAZZ\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012/10/01 15:23:05 | 000,000,082 | —- | M] () – C:\Users\JAZZ\Desktop\Annoying Virus on my computer!.URL
[2012/10/01 15:16:19 | 000,600,576 | —- | M] (OldTimer Tools) – C:\Users\JAZZ\Desktop\OTL.exe
[2012/10/01 13:44:02 | 000,007,597 | —- | M] () – C:\Users\JAZZ\AppData\Local\Resmon.ResmonCfg
[2012/09/30 23:31:01 | 000,000,093 | —- | M] () – C:\Users\JAZZ\Desktop\DollarTimes.com Add Hours, Minutes and Seconds.URL
[2012/09/30 13:19:36 | 000,001,147 | —- | M] () – C:\Users\JAZZ\Desktop\game - Shortcut.lnk
[2012/09/29 20:09:55 | 005,863,736 | —- | M] () – C:\Users\JAZZ\2012-09-29 23-07-11.bmp
[2012/09/29 20:09:54 | 005,863,736 | —- | M] () – C:\Users\JAZZ\2012-09-29 23-07-13.bmp
[2012/09/24 18:26:36 | 000,000,124 | —- | M] () – C:\Users\JAZZ\Desktop\1275980671_3390139_43dcbe2cdc346e7ef924eCt8xLlKAAnO.gif (GIF Image, 654 × 2628 pixels).URL
[2012/09/24 03:13:48 | 000,000,072 | —- | M] () – C:\Users\JAZZ\Desktop\Pink Pearl Song - NEW SCHOOL Strawberry Shortcake BLOG CREW.URL
[2012/09/23 16:23:12 | 000,002,385 | —- | M] () – C:\Users\JAZZ\Desktop\CLERIC.ini
[2012/09/21 15:31:49 | 000,000,109 | —- | M] () – C:\Users\JAZZ\Desktop\Forsaken World Game rules (ban & mute info).URL
[2012/09/21 15:14:48 | 000,000,084 | —- | M] () – C:\Users\JAZZ\Desktop\Bruno Mars - It Will Rain [Official Music Video] - YouTube.URL
[2012/09/21 15:14:43 | 000,000,068 | —- | M] () – C:\Users\JAZZ\Desktop\NOBODYKEITH SWEAT - YouTube.URL
[2012/09/21 15:14:34 | 000,000,091 | —- | M] () – C:\Users\JAZZ\Desktop\De'Mario and Odane - One For You - YouTube.URL
[2012/09/21 15:14:21 | 000,000,084 | —- | M] () – C:\Users\JAZZ\Desktop\Chris Brown - With You - YouTube.URL
[2012/09/21 01:35:18 | 000,696,240 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/09/21 01:35:18 | 000,073,136 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/09/20 23:13:14 | 000,000,625 | —- | M] () – C:\Users\JAZZ\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/09/20 22:56:34 | 000,000,114 | —- | M] () – C:\Users\JAZZ\Desktop\IR5 - The Official Windows 7 Rearm Solution.URL
[2012/09/19 15:16:08 | 000,000,077 | —- | M] () – C:\Users\JAZZ\Desktop\msn-nicks-generator.de - Zeichen und Special Symbole - ASCII Symbols.URL
[2012/09/12 11:34:43 | 002,946,464 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/09/12 05:12:01 | 000,001,057 | —- | M] () – C:\Users\JAZZ\Desktop\patcher - Shortcut (2).lnk
[2012/09/12 00:47:12 | 000,001,540 | —- | M] () – C:\Users\JAZZ\Desktop\patcher - Shortcut.lnk
[2012/09/12 00:23:22 | 000,000,068 | —- | M] () – C:\Users\JAZZ\Desktop\Jon Young - Like A Pro - YouTube.URL
[2012/09/11 01:51:47 | 000,001,132 | —- | M] () – C:\Users\JAZZ\Desktop\PhotoshopCS5Portable - Shortcut.lnk
[2012/09/10 19:25:49 | 000,001,567 | —- | M] () – C:\Users\JAZZ\Desktop\pk3tgw10.default - Shortcut.lnk
[2012/09/10 19:18:16 | 000,152,576 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msclmd.dll
[2012/09/10 19:18:15 | 000,175,616 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msclmd.dll
[2012/09/10 19:11:19 | 000,001,094 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/09/09 19:44:59 | 000,000,136 | -H– | M] () – C:\Users\JAZZ\Desktop\Vendetta Gaming Network Forums.URL
[2012/09/09 19:33:06 | 000,095,208 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2012/09/09 19:33:05 | 000,821,736 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npdeployJava1.dll
[2012/09/09 19:33:05 | 000,746,984 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2012/09/09 19:33:05 | 000,246,760 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2012/09/09 19:33:05 | 000,174,056 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2012/09/09 19:33:05 | 000,174,056 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2012/09/09 19:30:43 | 000,001,974 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2012/09/09 16:38:42 | 000,000,160 | —- | M] () – C:\ProgramData\-HjoC93XNZNIYior
[2012/09/09 16:38:42 | 000,000,144 | —- | M] () – C:\ProgramData\-HjoC93XNZNIYio
[2012/09/09 16:38:40 | 000,000,368 | —- | M] () – C:\ProgramData\HjoC93XNZNIYio
[2012/09/08 23:01:32 | 000,000,368 | —- | M] () – C:\ProgramData\NNvRF9IMLfKX6o
[2012/09/08 22:57:44 | 000,000,679 | -H– | M] () – C:\Users\JAZZ\Application Data\Microsoft\Internet Explorer\Quick Launch\File_Recovery.lnk
[2012/09/07 17:04:46 | 000,025,928 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys

========== Files Created - No Company Name ==========


[2012/10/03 12:57:57 | 000,513,501 | —- | C] () – C:\Users\JAZZ\Desktop\adwcleaner.exe
[2012/10/02 03:57:32 | 005,863,736 | —- | C] () – C:\Users\JAZZ\2012-10-02 06-55-42.bmp
[2012/10/02 03:57:32 | 005,863,736 | —- | C] () – C:\Users\JAZZ\2012-10-02 06-55-36.bmp
[2012/10/01 15:23:05 | 000,000,082 | —- | C] () – C:\Users\JAZZ\Desktop\Annoying Virus on my computer!.URL
[2012/10/01 13:44:02 | 000,007,597 | —- | C] () – C:\Users\JAZZ\AppData\Local\Resmon.ResmonCfg
[2012/09/30 13:19:36 | 000,001,147 | —- | C] () – C:\Users\JAZZ\Desktop\game - Shortcut.lnk
[2012/09/29 20:09:02 | 005,863,736 | —- | C] () – C:\Users\JAZZ\2012-09-29 23-07-13.bmp
[2012/09/29 20:09:02 | 005,863,736 | —- | C] () – C:\Users\JAZZ\2012-09-29 23-07-11.bmp
[2012/09/29 18:30:42 | 000,000,093 | —- | C] () – C:\Users\JAZZ\Desktop\DollarTimes.com Add Hours, Minutes and Seconds.URL
[2012/09/24 18:26:36 | 000,000,124 | —- | C] () – C:\Users\JAZZ\Desktop\1275980671_3390139_43dcbe2cdc346e7ef924eCt8xLlKAAnO.gif (GIF Image, 654 × 2628 pixels).URL
[2012/09/24 03:13:48 | 000,000,072 | —- | C] () – C:\Users\JAZZ\Desktop\Pink Pearl Song - NEW SCHOOL Strawberry Shortcake BLOG CREW.URL
[2012/09/23 16:14:49 | 000,002,385 | —- | C] () – C:\Users\JAZZ\Desktop\CLERIC.ini
[2012/09/21 15:14:48 | 000,000,084 | —- | C] () – C:\Users\JAZZ\Desktop\Bruno Mars - It Will Rain [Official Music Video] - YouTube.URL
[2012/09/21 15:14:43 | 000,000,068 | —- | C] () – C:\Users\JAZZ\Desktop\NOBODYKEITH SWEAT - YouTube.URL
[2012/09/21 15:14:34 | 000,000,091 | —- | C] () – C:\Users\JAZZ\Desktop\De'Mario and Odane - One For You - YouTube.URL
[2012/09/21 15:14:21 | 000,000,084 | —- | C] () – C:\Users\JAZZ\Desktop\Chris Brown - With You - YouTube.URL
[2012/09/20 22:56:34 | 000,000,114 | —- | C] () – C:\Users\JAZZ\Desktop\IR5 - The Official Windows 7 Rearm Solution.URL
[2012/09/19 15:16:08 | 000,000,077 | —- | C] () – C:\Users\JAZZ\Desktop\msn-nicks-generator.de - Zeichen und Special Symbole - ASCII Symbols.URL
[2012/09/12 05:12:01 | 000,001,057 | —- | C] () – C:\Users\JAZZ\Desktop\patcher - Shortcut (2).lnk
[2012/09/12 00:47:12 | 000,001,540 | —- | C] () – C:\Users\JAZZ\Desktop\patcher - Shortcut.lnk
[2012/09/12 00:23:22 | 000,000,068 | —- | C] () – C:\Users\JAZZ\Desktop\Jon Young - Like A Pro - YouTube.URL
[2012/09/11 06:06:36 | 000,001,456 | —- | C] () – C:\Users\JAZZ\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012/09/11 01:51:47 | 000,001,132 | —- | C] () – C:\Users\JAZZ\Desktop\PhotoshopCS5Portable - Shortcut.lnk
[2012/09/10 19:25:49 | 000,001,567 | —- | C] () – C:\Users\JAZZ\Desktop\pk3tgw10.default - Shortcut.lnk
[2012/09/10 19:11:19 | 000,001,106 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/09/10 19:11:19 | 000,001,094 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/09/09 19:30:43 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2012/09/09 19:30:43 | 000,001,974 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2012/09/09 16:38:42 | 000,000,160 | —- | C] () – C:\ProgramData\-HjoC93XNZNIYior
[2012/09/09 16:38:41 | 000,000,144 | —- | C] () – C:\ProgramData\-HjoC93XNZNIYio
[2012/09/09 16:38:37 | 000,000,368 | —- | C] () – C:\ProgramData\HjoC93XNZNIYio
[2012/09/08 22:57:44 | 000,000,679 | -H– | C] () – C:\Users\JAZZ\Application Data\Microsoft\Internet Explorer\Quick Launch\File_Recovery.lnk
[2012/09/08 22:57:41 | 000,000,368 | —- | C] () – C:\ProgramData\NNvRF9IMLfKX6o
[2012/07/30 18:06:27 | 000,020,480 | —- | C] () – C:\Windows\FixCamera.exe
[2012/07/30 17:04:13 | 000,057,856 | —- | C] () – C:\Windows\Fce32.dll
[2012/07/30 17:04:11 | 000,092,672 | —- | C] () – C:\Windows\SysWow64\See32.dll
[2012/07/30 17:04:11 | 000,057,856 | —- | C] () – C:\Windows\SysWow64\Fce32.dll
[2012/07/30 05:37:42 | 000,008,864 | —- | C] () – C:\Windows\SysWow64\drivers\CDAC15BA.SYS
[2012/03/10 21:50:03 | 000,000,239 | —- | C] () – C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2011/03/26 17:15:16 | 003,133,496 | -H– | C] () – C:\Users\JAZZ\2011-02-19 14-03-25.bmp
[2011/03/26 17:15:16 | 003,133,496 | -H– | C] () – C:\Users\JAZZ\2011-02-19 14-00-26.bmp
[2011/03/12 19:16:03 | 000,000,309 | —- | C] () – C:\ProgramData\nvUnsupRes.dat
[2010/12/27 16:46:30 | 000,000,056 | —- | C] () – C:\ProgramData\ezsidmv.dat
[2010/11/20 03:58:12 | 000,120,200 | —- | C] () – C:\Windows\SysWow64\DLLDEV32i.dll
[2010/11/20 03:57:54 | 000,006,211 | —- | C] () – C:\Windows\mgxoschk.ini
[2010/07/09 15:04:30 | 000,000,132 | -H– | C] () – C:\Users\JAZZ\AppData\Roaming\Adobe Targa Format CS5 Prefs
[2008/08/25 15:40:54 | 001,768,497 | -H– | C] () – C:\Users\JAZZ\AiPictureExplorer_v850.exe
[2008/08/23 23:27:22 | 000,000,185 | -H– | C] () – C:\Users\JAZZ\FILE_ID.DIZ
[2007/01/01 05:26:55 | 000,000,160 | —- | C] () – C:\ProgramData\-HcFi9Of3olNeLkr
[2007/01/01 05:26:55 | 000,000,144 | —- | C] () – C:\ProgramData\-HcFi9Of3olNeLk
[2007/01/01 02:56:04 | 000,000,368 | —- | C] () – C:\ProgramData\HcFi9Of3olNeLk
[2007/01/01 00:08:36 | 000,000,368 | —- | C] () – C:\ProgramData\xJphLKeMhUxzZN

========== ZeroAccess Check ==========

[2009/07/13 21:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 22:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 21:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 18:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 05:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 18:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2010/08/07 15:15:39 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\AppData\Roaming\Blender Foundation
[2010/08/19 19:31:40 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\AppData\Roaming\Canon
[2010/07/29 16:51:48 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\AppData\Roaming\com.adobe.ExMan
[2012/04/04 19:49:36 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\AppData\Roaming\DVDVideoSoft
[2012/02/06 19:02:08 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\AppData\Roaming\DVDVideoSoftIEHelpers
[2011/05/19 18:30:59 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\AppData\Roaming\GetRightToGo
[2012/10/01 13:20:51 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\KudosChatSearch
[2012/03/11 14:06:06 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\AppData\Roaming\Macro Recorder
[2010/11/20 03:58:35 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\AppData\Roaming\MAGIX
[2010/07/10 15:55:58 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\AppData\Roaming\onOne Software
[2010/08/11 16:43:27 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\AppData\Roaming\OpenOffice.org
[2011/04/19 13:00:39 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\AppData\Roaming\PC Suite
[2010/11/20 00:55:03 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\AppData\Roaming\Photodex
[2012/08/27 23:27:34 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\AppData\Roaming\raidcall
[2011/04/19 13:00:50 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\AppData\Roaming\Samsung
[2011/04/25 17:43:25 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\AppData\Roaming\SecondLife
[2012/03/08 17:53:18 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\AppData\Roaming\SysLipe
[2011/12/12 18:49:08 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\AppData\Roaming\TS3Client
[2011/12/12 16:50:16 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\AppData\Roaming\ts3overlay
[2010/07/13 01:01:00 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\AppData\Roaming\WTouch

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/25 23:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/25 22:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 18:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/25 22:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/30 22:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/25 22:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/24 23:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/25 23:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 05:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\SysWOW64\explorer.exe
[2010/11/20 05:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/02 23:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/24 22:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/30 23:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/02 22:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 06:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\explorer.exe
[2010/11/20 06:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/30 23:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/02 22:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 18:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/30 23:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/25 23:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/02 23:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/13 18:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 18:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 18:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 18:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2012/07/03 13:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/13 18:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 18:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 05:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 05:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 18:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 18:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 06:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 06:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 06:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 06:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 18:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012/07/03 13:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/28 00:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/27 23:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< %systemroot%\*. /rp /s >

< %systemdrive%\$Recycle.Bin|@;true;true;true >

< %USERPROFILE%\..|smtmp;true;true;true /FP >
[2012/09/08 23:00:33 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\..\JAZZ\AppData\Local\Temp\smtmp
[2012/09/10 18:59:00 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\..\JAZZ\AppData\Local\Temp\smtmp\1
[2012/09/10 18:58:58 | 000,000,000 | -H-D | M] – C:\Users\JAZZ\..\JAZZ\AppData\Local\Temp\smtmp\4

< %temp%\smtmp\*.* /s > >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: SCSI
Media Type: Fixed hard disk media
Model: WDC WD74 0GD-00FLC0 SCSI Disk Device
Partitions: 2
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 - External hard disk media
Interface type: USB
Media Type: External hard disk media
Model: Hitachi HDS721050CLA362 USB Device
Partitions: 1
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 - External hard disk media
Interface type: USB
Media Type: External hard disk media
Model: WD 5000AAJ External USB Device
Partitions: 1
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 60.00GB
Starting Offset: 32256
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 9.00GB
Starting Offset: 64428618240
Hidden sectors: 0


DeviceID: Disk #1, Partition #0
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 466.00GB
Starting Offset: 32256
Hidden sectors: 0


DeviceID: Disk #2, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 466.00GB
Starting Offset: 32256
Hidden sectors: 0


< End of report >


OTL Extras logfile created on: 10/4/2012 12:59:25 PM - Run 1
OTL by OldTimer - Version 3.2.70.2 Folder = C:\Users\JAZZ\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 0.94 Gb Available Physical Memory | 47.26% Memory free
4.00 Gb Paging File | 2.87 Gb Available in Paging File | 71.76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 60.00 Gb Total Space | 5.72 Gb Free Space | 9.54% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 134.74 Gb Free Space | 28.93% Space Free | Partition Type: NTFS
Drive F: | 465.65 Gb Total Space | 4.96 Gb Free Space | 1.06% Space Free | Partition Type: FAT32

Computer Name: JAZZ-PC | User Name: JAZZ | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Unable to open value key
htmlfile – Reg Error: Unable to open value key
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Unable to open value key
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Unable to open value key
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "E:\!Winamp\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "E:\!Winamp\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "E:\!Winamp\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Unable to open value key
htmlfile – Reg Error: Unable to open value key
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Unable to open value key
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Unable to open value key
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "E:\!Winamp\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "E:\!Winamp\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "E:\!Winamp\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"E:\!Perfect World Genesis - chinese\w2i_client_v539.exe" = E:\!Perfect World Genesis - chinese\w2i_client_v539.exe:*:Enabled:@xpsp2res.dll,-22008
"E:\!Perfect World Genesis - chinese\w2i_client_v539.exe" = E:\!Perfect World Genesis - chinese\w2i_client_v539.exe:*:Enabled:@xpsp2res.dll,-22008


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0D382DD2-8A5C-4585-9CB4-C3478CD92251}" = lport=138 | protocol=17 | dir=in | app=system |
"{1053BAEB-D192-4232-9B0B-22B7D243A9CA}" = lport=10243 | protocol=6 | dir=in | app=system |
"{1670E961-FF5C-4B83-A63D-483F8A9B94F4}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{21C2D022-606B-4071-BAB6-1BE90832465E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{3420F61A-A56C-4FCA-A7FE-3563590B66F0}" = rport=137 | protocol=17 | dir=out | app=system |
"{42375846-EB01-461A-AD32-430DB712A455}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{4323585F-12CA-4410-A079-C02D780281B1}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{7766E0AE-7217-4551-9EB6-34705E44571C}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{84A02DD0-06D0-44F1-858B-986A8655C3BE}" = lport=139 | protocol=6 | dir=in | app=system |
"{8E6F3C09-53A8-42D6-A23C-6E33D66EDC48}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 |
"{8EE776B7-E2B5-44D2-AD27-DFB2AB1E9570}" = rport=139 | protocol=6 | dir=out | app=system |
"{8F97CF48-D5EB-4AD0-839B-8517533221BD}" = rport=138 | protocol=17 | dir=out | app=system |
"{9B23F98A-9461-49A8-9039-7C63B4383E7B}" = lport=137 | protocol=17 | dir=in | app=system |
"{9EAB397A-E4F8-4BE1-AD65-9552EC3D722D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{AD72A78F-E2CF-4C32-B46E-959E1B389476}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B0B283F1-6A84-408B-A3F2-EA82DE605820}" = lport=2869 | protocol=6 | dir=in | app=system |
"{BDD4C423-ED43-4E45-9B51-C02F8AFC5F66}" = rport=10243 | protocol=6 | dir=out | app=system |
"{BF9DF4F5-049C-444C-8192-2022C7C6AF02}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C3D3D170-66EB-47D2-BF55-B5335E28B152}" = rport=445 | protocol=6 | dir=out | app=system |
"{CA39B551-B16A-4A52-8D42-6A7B7D78471B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CC45FE48-8648-4ABF-8B99-BFC49C4FBC99}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{CC6E814F-B454-4776-B5F8-4D33820E3094}" = lport=445 | protocol=6 | dir=in | app=system |
"{D06BC37A-E7BC-4077-93B0-3FA278216056}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D4BBB908-85A5-47D7-9246-01E975DFB8EA}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D78E7DD1-72BC-45BA-A440-A6EC73E21748}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{FFF7FAEF-E4E4-4A0E-8FD7-9A6964EF0702}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0EA96F21-8495-4052-A7BB-E2281B6696AA}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{22E585FC-C1C7-48A6-B661-474DDB5696AE}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{2B43C60A-03DD-4E9E-A034-88E834EF0B17}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{30C97BFC-5022-4A3B-9448-6BC8EF896EE3}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{35475BBB-F5C1-4DE3-BE6F-4D774F4AAFA9}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{39606217-1803-430D-AA8C-F3D1736AA277}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{3ACEF1BF-08DE-427F-9D06-A54C3FE5C247}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3CF80405-6C6D-4FB1-91FE-174F06F5CB5B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{43E22B2F-64C0-4E2B-ADF2-47B5BACD6A9F}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{4B32EFCE-AFBB-42BE-9335-0F5DCA76A528}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{4B82A806-7D1B-4836-91CA-C9FB735B2769}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{53D90A52-4411-4F66-A841-F2E5EB4E061D}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{6020615C-2FF1-4EB8-B365-9DC291B04587}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{63E2DC37-06FE-43FE-9480-347FC13BD0CB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{69323FFE-35F6-43FC-8CDA-978DEF1084A9}" = protocol=17 | dir=in | app=e:\torrent\bittorrent.exe |
"{6DB800BD-C172-4014-9A83-A4A7AC5B2CC5}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{6E015CB2-284A-4B4E-838E-0CE9D20A8A5F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{6E7448CE-26BD-4DFF-9511-A8436E92A21C}" = protocol=6 | dir=in | app=e:\ventrilo.exe |
"{761B6930-DB30-42FA-AE55-D422332B893A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{77E68A13-9FE0-4CF7-9ED1-9BA937C9F977}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{914AAD3F-A34A-497B-899B-6F7F00A7BD12}" = dir=in | app=e:\!!!!!!!aolons\allods online\bin\launcher.exe |
"{97395342-F2E2-4213-8316-D431728028A6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{A252CFA9-3C47-47AD-B035-FCD1A26B3B02}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{AF386874-BED2-4083-A903-3C788EC7D5AA}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{B4E2BC6D-7F41-42D8-A21E-624B695DA62A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C0D855A6-4F97-4ECF-92CC-DED2B6C5359A}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C6790904-9C05-4647-A17B-9CE4DEAB1528}" = protocol=6 | dir=in | app=e:\torrent\bittorrent.exe |
"{C97E5C91-55B8-428E-BADC-89CB816A2FA7}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{CC0EDB37-48A4-4701-ABB3-135C8BAC49F3}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{D1986E98-BA69-4EE5-A150-FC003ED03769}" = protocol=6 | dir=out | app=system |
"{D4ACAAC7-7103-4FD3-A266-BFE722B57EDB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DC329736-61CA-4D1D-B8D9-860FE1B12499}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{E6803D94-4C33-470F-837E-CA414D65D62A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{EC0BA7BC-4839-4522-B4D5-678762BA8D1F}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{EF4FBC92-F97C-4F0D-ADEB-41563E0C8266}" = protocol=17 | dir=in | app=e:\ventrilo.exe |
"{FDB0D4CF-02DD-4E0F-A4DF-97DD8A5A85BF}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"TCP Query User{0B2B09CD-317F-458D-93B8-28E0DB735048}E:\!rohan\rohanclient.exe" = protocol=6 | dir=in | app=e:\!rohan\rohanclient.exe |
"TCP Query User{14562AB5-FB4E-4ED9-8C3B-D2C104418C22}E:\vinn\vindictus\en-us\vindictus.exe" = protocol=6 | dir=in | app=e:\vinn\vindictus\en-us\vindictus.exe |
"TCP Query User{33C2BC91-E2B6-43D2-AB3F-FCC28DDAB5BC}C:\program files (x86)\entropia universe\bin32\eigc\eigcc_main.exe" = protocol=6 | dir=in | app=c:\program files (x86)\entropia universe\bin32\eigc\eigcc_main.exe |
"TCP Query User{3FAC251F-F988-4B74-954A-5CACEE45105E}E:\!!!cam\easy web cam\easywebcam.exe" = protocol=6 | dir=in | app=e:\!!!cam\easy web cam\easywebcam.exe |
"TCP Query User{69C12A2B-A640-49B5-9EA8-1CF93B1A422A}C:\users\jazz\desktop\w2i_client_v539.exe" = protocol=6 | dir=in | app=c:\users\jazz\desktop\w2i_client_v539.exe |
"TCP Query User{6FED9792-E319-400A-9A2D-244E76919E51}C:\program files (x86)\kudoschatsearchagent\kudoschatsearchagent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\kudoschatsearchagent\kudoschatsearchagent.exe |
"TCP Query User{713C3B5F-015F-49BC-9B64-51D1D85028D9}E:\hko_download_manager.exe" = protocol=6 | dir=in | app=e:\hko_download_manager.exe |
"TCP Query User{77743CB9-30BC-4A7A-B125-7A8975D6CFCF}C:\users\jazz\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\jazz\appdata\local\akamai\netsession_win.exe |
"TCP Query User{8EDF400D-529D-403C-BC94-0AB96D10980A}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe |
"TCP Query User{9B0F5FE4-003D-45AB-A4DE-DC5D32794DDB}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe |
"TCP Query User{9C1760B8-FC5C-46BC-A1F1-6F08E323ACE1}E:\vinn\vindictus\en-us\nmservice.exe" = protocol=6 | dir=in | app=e:\vinn\vindictus\en-us\nmservice.exe |
"TCP Query User{A6B30CCA-0136-48D1-9F0A-42F8C8F02A6B}E:\skype\phone\skype.exe" = protocol=6 | dir=in | app=e:\skype\phone\skype.exe |
"TCP Query User{C8B463AA-F4ED-49D0-AF03-5D3B4E844ACF}E:\!winamp\winamp\winamp.exe" = protocol=6 | dir=in | app=e:\!winamp\winamp\winamp.exe |
"TCP Query User{CC84585D-3F8C-4C81-B96D-6E9F5F68B2F4}E:\!perfect world genesis - chinese\w2i_client_v539.exe" = protocol=6 | dir=in | app=e:\!perfect world genesis - chinese\w2i_client_v539.exe |
"TCP Query User{FE472D9F-A4DF-4A58-9B44-F9A07680332B}C:\program files (x86)\entropia universe\bin32\entropia.exe" = protocol=6 | dir=in | app=c:\program files (x86)\entropia universe\bin32\entropia.exe |
"UDP Query User{0007D4B0-BA18-4912-AEEA-D93392206A4A}E:\!rohan\rohanclient.exe" = protocol=17 | dir=in | app=e:\!rohan\rohanclient.exe |
"UDP Query User{06A371F7-9F6E-4880-A952-1299B36917D6}E:\vinn\vindictus\en-us\nmservice.exe" = protocol=17 | dir=in | app=e:\vinn\vindictus\en-us\nmservice.exe |
"UDP Query User{084653B4-1589-4001-9DD6-AF63C0347FAD}E:\skype\phone\skype.exe" = protocol=17 | dir=in | app=e:\skype\phone\skype.exe |
"UDP Query User{14150089-B18D-4850-9ADB-A1AFC7D86EC3}C:\program files (x86)\entropia universe\bin32\entropia.exe" = protocol=17 | dir=in | app=c:\program files (x86)\entropia universe\bin32\entropia.exe |
"UDP Query User{2D0C65A6-3652-46B9-85F1-1BE7D2BC180D}E:\hko_download_manager.exe" = protocol=17 | dir=in | app=e:\hko_download_manager.exe |
"UDP Query User{2F64D1E6-82FD-4848-8C62-AD5E2415AA4B}C:\users\jazz\desktop\w2i_client_v539.exe" = protocol=17 | dir=in | app=c:\users\jazz\desktop\w2i_client_v539.exe |
"UDP Query User{5F1A8DA4-6A11-4876-854A-AFE3EB0C62F8}E:\!perfect world genesis - chinese\w2i_client_v539.exe" = protocol=17 | dir=in | app=e:\!perfect world genesis - chinese\w2i_client_v539.exe |
"UDP Query User{5F38B7A5-5808-4BC9-836A-572884102A87}C:\users\jazz\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\jazz\appdata\local\akamai\netsession_win.exe |
"UDP Query User{65C6BFDD-93F9-4E70-BDCF-2CC9E4321975}E:\!!!cam\easy web cam\easywebcam.exe" = protocol=17 | dir=in | app=e:\!!!cam\easy web cam\easywebcam.exe |
"UDP Query User{6F0860D1-FD69-4EB2-97AB-CFF3CFB4DE5A}C:\program files (x86)\entropia universe\bin32\eigc\eigcc_main.exe" = protocol=17 | dir=in | app=c:\program files (x86)\entropia universe\bin32\eigc\eigcc_main.exe |
"UDP Query User{9C14CD80-2511-44B2-84CA-E52C3D5DB5DC}E:\vinn\vindictus\en-us\vindictus.exe" = protocol=17 | dir=in | app=e:\vinn\vindictus\en-us\vindictus.exe |
"UDP Query User{C25F23C0-37D9-4D44-9C60-BA75B5EB1722}C:\program files (x86)\kudoschatsearchagent\kudoschatsearchagent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\kudoschatsearchagent\kudoschatsearchagent.exe |
"UDP Query User{C4E79A91-D958-495C-A6DF-2CD9B913AACD}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe |
"UDP Query User{C6CF94E9-6975-4277-B135-E06660A36FA7}E:\!winamp\winamp\winamp.exe" = protocol=17 | dir=in | app=e:\!winamp\winamp\winamp.exe |
"UDP Query User{F2F3EEA1-507F-4EEC-848B-F8443BCDCEC1}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP490_series" = Canon MP490 series MP Drivers
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
"{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1" = Media Player Classic - Home Cinema v. 1.3.1249.0
"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
"{68660049-8D48-427C-9FF7-139D8340CDC0}" = MSVC80_x64
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"FCEC33AD40CEA5E0FC4CEE6E42041A0DA189652D" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{2540BCAF-A9CC-4A22-9905-9964129227A0}}_is1" = Xtreme Jade
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java™ 6 Update 33
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 7
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{34610DE0-3C13-42CA-8E32-01FFA38AB6E8}" = PC Connectivity Solution
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1" = Need For Speed™ World
"{7E84FAC8-C518-40F9-9807-7455301D6D25}" = SamsungConnectivityCableDriver
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D318C86-AF4C-409F-A6AC-7183FF4CF424}" = Internet TV for Windows Media Center
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AB6F6C80-1C35-4672-BDEF-F26FF214C409}" = Samsung PC Studio 7
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.2
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B4F3A360-E1E2-479D-ADE7-9BE3B07F4539}" = NVIDIA PhysX
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E2D09AC2-4153-4817-AAEB-24F92A8BCE88}" = Windows Media Center Add-in for Flash
"{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FCADA4FF-142C-42A8-B73C-0A54A7F83345}" = Genuine Fractals 6.0.6 Professional Edition
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"7-Zip" = 7-Zip 9.20
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4
"BandiMPEG1" = Bandisoft MPEG-1 Decoder
"Bejeweled 3" = Bejeweled 3
"BitTorrent" = BitTorrent
"Canon MP490 series User Registration" = Canon MP490 series User Registration
"CanonMyPrinter" = Canon Utilities My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.11.17.319
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.0.1400
"Mozilla Firefox 15.0.1 (x86 en-US)" = Mozilla Firefox 15.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 3.0" = Canon MP Navigator EX 3.0
"MplayerforWindows" = MplayerforWindows v2011-03-27
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Pen Tablet Driver" = Pen Tablet
"RaidCall" = RaidCall
"Samsung PC Studio 7" = Samsung PC Studio 7
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"Text To PDF Converter v1.5_is1" = Text To PDF Converter v1.5
"VLC media player" = VLC media player 2.0.0
"Wacom WebTabletPlugin for IE" = WebTablet IE Plugin
"Wacom WebTabletPlugin for Netscape" = WebTablet Netscape Plugin
"Winamp" = Winamp
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.11 (32-bit)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Winamp Detect" = Winamp Detector Plug-in

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 9/14/2012 3:06:19 AM | Computer Name = JAZZ-PC | Source = Application Hang | ID = 1002
Description = The program game.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 1900 Start Time:
01cd924073ad2787 Termination Time: 136 Application Path: E:\!!Forsaken World Vendetta
Beta\!!Forsaken World Vendetta (Released)\Forsaken World Vendetta\update\game.exe

Report
Id: 97039654-fe3a-11e1-803e-00508d9383f2

Error - 9/19/2012 11:13:29 PM | Computer Name = JAZZ-PC | Source = Desktop Window Manager | ID = 9020
Description = The Desktop Window Manager has encountered a fatal error (0x88980406)

Error - 9/26/2012 3:01:49 AM | Computer Name = JAZZ-PC | Source = Desktop Window Manager | ID = 9020
Description = The Desktop Window Manager has encountered a fatal error (0x88980406)

Error - 9/29/2012 8:37:16 PM | Computer Name = JAZZ-PC | Source = Application Hang | ID = 1002
Description = The program game.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: ec0 Start Time:
01cd9e9c7992ec55 Termination Time: 3431 Application Path: E:\!!Forsaken World Vendetta
Beta\!!Forsaken World Vendetta (Released)\Forsaken World Vendetta\update\game.exe

Report
Id: d9181dfe-0a96-11e2-9527-00508d9383f2

Error - 9/29/2012 8:37:23 PM | Computer Name = JAZZ-PC | Source = Application Hang | ID = 1002
Description = The program game.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 838 Start Time:
01cd9e7a746a1ad3 Termination Time: 11311 Application Path: E:\!!Forsaken World Vendetta
Beta\!!Forsaken World Vendetta (Released)\Forsaken World Vendetta\update\game.exe

Report
Id: d917f6ee-0a96-11e2-9527-00508d9383f2

Error - 9/30/2012 6:25:43 AM | Computer Name = JAZZ-PC | Source = Application Hang | ID = 1002
Description = The program NOTEPAD.EXE version 6.1.7600.16385 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: e78 Start
Time: 01cd9ef5b555353c Termination Time: 5 Application Path: C:\Windows\system32\NOTEPAD.EXE

Report
Id: 218bd424-0ae9-11e2-9527-00508d9383f2

Error - 10/1/2012 1:53:57 AM | Computer Name = JAZZ-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Photoshop.exe, version: 12.0.0.0, time
stamp: 0x4bbc56b6 Faulting module name: BIB.dll, version: 1.2.2.7602, time stamp:
0x4b97fce8 Exception code: 0xc0000005 Fault offset: 0x00002725 Faulting process id:
0x14bc Faulting application start time: 0x01cd9f98f346b4c6 Faulting application path:
C:\PhotoshopPortable\App\PhotoshopCS5\Photoshop.exe Faulting module path: C:\PhotoshopPortable\App\PhotoshopCS5\BIB.dll
Report
Id: 630ddfbc-0b8c-11e2-ba4d-00508d9383f2

Error - 10/1/2012 4:10:00 PM | Computer Name = JAZZ-PC | Source = Application Hang | ID = 1002
Description = The program Kudos Chat Search v3.0_beta.tmp version 51.52.0.0 stopped
interacting with Windows and was closed. To see if more information about the problem
is available, check the problem history in the Action Center control panel. Process
ID: 1120 Start Time: 01cda01068600b9b Termination Time: 33 Application Path: C:\Users\JAZZ\AppData\Local\Temp\is-M6VUD.tmp\Kudos
Chat Search v3.0_beta.tmp Report Id:

Error - 10/4/2012 3:48:23 AM | Computer Name = JAZZ-PC | Source = Application Hang | ID = 1002
Description = The program game.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: f1c Start Time:
01cda1b1fee63904 Termination Time: 2369 Application Path: E:\!!Forsaken World Vendetta
Beta\!!Forsaken World Vendetta (Released)\Forsaken World Vendetta\update\game.exe

Report
Id: ca2f0033-0df7-11e2-a316-00508d9383f2

Error - 10/4/2012 7:03:11 AM | Computer Name = JAZZ-PC | Source = Application Hang | ID = 1002
Description = The program game.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Action Center control panel. Process ID: 1b58 Start Time:
01cda204f215475d Termination Time: 4081 Application Path: E:\!!Forsaken World Vendetta
Beta\!!Forsaken World Vendetta (Released)\Forsaken World Vendetta\update\game.exe

Report
Id: 0b2403a2-0e13-11e2-a316-00508d9383f2

[ System Events ]
Error - 10/4/2012 3:36:02 PM | Computer Name = JAZZ-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80071a90: Update for Windows 7 for x64-based Systems (KB2541014).

Error - 10/4/2012 3:36:02 PM | Computer Name = JAZZ-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80071a90: Update for Windows 7 for x64-based Systems (KB2709630).

Error - 10/4/2012 3:36:02 PM | Computer Name = JAZZ-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80071a90: Update for Windows 7 for x64-based Systems (KB2732059).

Error - 10/4/2012 3:36:02 PM | Computer Name = JAZZ-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80071a90: Update for Windows 7 for x64-based Systems (KB2488113).

Error - 10/4/2012 3:36:02 PM | Computer Name = JAZZ-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80071a90: Update for Windows 7 for x64-based Systems (KB2679255).

Error - 10/4/2012 3:36:02 PM | Computer Name = JAZZ-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80071a90: Update for Windows 7 for x64-based Systems (KB2699779).

Error - 10/4/2012 3:36:02 PM | Computer Name = JAZZ-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80071a90: Update for Windows 7 for x64-based Systems (KB2529073).

Error - 10/4/2012 3:36:02 PM | Computer Name = JAZZ-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80071a90: Update for Windows 7 for x64-based Systems (KB982018).

Error - 10/4/2012 3:56:14 PM | Computer Name = JAZZ-PC | Source = Application Popup | ID = 1060
Description = \??\C:\Windows\SysWow64\drivers\CDAC15BA.SYS has been blocked from
loading due to incompatibility with this system. Please contact your software vendor
for a compatible version of the driver.

Error - 10/4/2012 3:56:14 PM | Computer Name = JAZZ-PC | Source = Service Control Manager | ID = 7000
Description = The CdaC15BA service failed to start due to the following error: %%1275


< End of report >
Hi Soulhunter,

Sorry for the delay.

In the logs you posted there are a number of files which are questionable. Could you tell me if you put them on you computer and what they are for?

Show Hidden Files & Folders in Windows 7
  • To show hidden files, just click on the Organize button in any folder, and then select “Folder and Search Options” from the menu.
  • Click the View tab, and then you should select “Show hidden files and folders” in the list.
  • Then click OK.
Next

  • C:\Users\JAZZ\Desktop\Annoying Virus on my computer!.URL
  • C:\Users\JAZZ\Desktop\DollarTimes.com Add Hours, Minutes and Seconds.URL
  • C:\Users\JAZZ\Desktop\1275980671_3390139_43dcbe2cdc346e7ef924eCt8xLlKAAnO.gif (GIF Image, 654 × 2628 pixels).URL
  • C:\Users\JAZZ\Desktop\Pink Pearl Song - NEW SCHOOL Strawberry Shortcake BLOG CREW.URL
  • C:\Users\JAZZ\Desktop\Forsaken World Game rules (ban & mute info).URL
  • C:\Users\JAZZ\Desktop\Bruno Mars - It Will Rain [Official Music Video] - YouTube.URL
  • C:\Users\JAZZ\Desktop\NOBODYKEITH SWEAT - YouTube.URL
  • C:\Users\JAZZ\Desktop\De'Mario and Odane - One For You - YouTube.URL
  • C:\Users\JAZZ\Desktop\Chris Brown - With You - YouTube.URL
  • C:\Users\JAZZ\Desktop\msn-nicks-generator.de - Zeichen und Special Symbole - ASCII Symbols.URL
  • C:\Users\JAZZ\Desktop\Jon Young - Like A Pro - YouTube.URL
  • C:\Users\JAZZ\2012-10-02 06-55-42.bmp
  • C:\Users\JAZZ\2012-10-02 06-55-36.bmp
  • C:\Users\JAZZ\2012-09-29 23-07-13.bmp
  • C:\Users\JAZZ\2012-09-29 23-07-11.bmp
  • C:\Users\JAZZ\Desktop\IR5 - The Official Windows 7 Rearm Solution.URL
  • C:\Users\JAZZ\2011-02-19 14-03-25.bmp
  • C:\Users\JAZZ\2011-02-19 14-00-26.bmp
Next

  • Download Unhide
  • Right click and select "Run as Administrator" to run Unhide
  • The program will open a black box and start making the files on your fixed disks visible again.
  • Once it has finished, the program will display a Windows alert stating that your files have been restored.
  • When Unhide is complete, it will create a logfile on the Windows Desktop called Unhide.txt.
In your next post please provide the following:
  • Information about the files
  • Unhide.txt
no i did not put em there and in fact they weren't even visible lol. i will take care of those links since they are useless to me. thanks for pointing it out so ;p

Unhide by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2012 BleepingComputer.com
More Information about Unhide.exe can be found at this link:
http://www.bleepingcomputer.com/forums/topic405109.html

Program started at: 10/06/2012 04:08:31 AM
Windows Version: Windows 7

Please be patient while your files are made visible again.

Processing the A:\ drive
Finished processing the A:\ drive. 0 files processed.

Processing the C:\ drive
Finished processing the C:\ drive. 341049 files processed.

Processing the E:\ drive
Finished processing the E:\ drive. 83915 files processed.

Processing the F:\ drive
Finished processing the F:\ drive. 173638 files processed.

Restoring the Start Menu.
* 14 Shortcuts and Desktop items were restored.


Searching for Windows Registry changes made by FakeHDD rogues.
- Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
* NoActiveDesktopChanges policy was found and deleted!
- Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
* Start_ShowControlPanel was set to 0! It was set back to 1!
* Start_ShowHelp was set to 0! It was set back to 1!
* Start_ShowMyDocs was set to 0! It was set back to 1!
* Start_ShowMyMusic was set to 0! It was set back to 1!
* Start_ShowMyPics was set to 0! It was set back to 1!
* Start_ShowPrinters was set to 0! It was set back to 1!
* Start_ShowRun was set to 0! It was set back to 1!
* Start_ShowSetProgramAccessAndDefaults was set to 0! It was set back to 1!
* Start_ShowRecentDocs was set to 0! It was set back to 2!
* Start_ShowNetConn was set to 0! It was set back to 1!
* Start_ShowNetPlaces was set to 0! It was set back to 1!
* Start_TrackDocs was set to 0! It was set back to 1!
* Start_TrackProgs was set to 0! It was set back to 1!
* Start_ShowUser was set to 0! It was set back to 1!
* Start_ShowMyGames was set to 0! It was set back to 1!

Restarting Explorer.exe in order to apply changes.

Program finished at: 10/06/2012 04:32:01 AM
Execution time: 0 hours(s), 23 minute(s), and 30 seconds(s)
Hi Soulhunter,

Please delete the copy of OTL you have on your desktop and download a fresh copy.

  • Download OTL to your desktop.
  • Right click and select "Run as Administrator". Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    %systemdrive%\$Recycle.Bin|@;true;true;true
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open in notepad. OTL.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
In your next post please provide the following:
  • OTL.txt (no extras.txt will be generated)
  • Tell me how your computer is running at the moment
it's better not 100% so but defiantly an improvement :D


OTL logfile created on: 10/7/2012 12:53:58 AM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\JAZZ\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.41 Gb Available Physical Memory | 70.61% Memory free
4.00 Gb Paging File | 2.51 Gb Available in Paging File | 62.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 60.00 Gb Total Space | 4.53 Gb Free Space | 7.54% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 134.65 Gb Free Space | 28.91% Space Free | Partition Type: NTFS
Drive F: | 465.65 Gb Total Space | 4.96 Gb Free Space | 1.06% Space Free | Partition Type: FAT32

Computer Name: JAZZ-PC | User Name: JAZZ | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\JAZZ\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Windows\FixCamera.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Windows\FixCamera.exe ()


========== Services (SafeList) ==========

SRV:64bit: - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
SRV:64bit: - (FLEXnet Licensing Service 64) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Acresso Software Inc.)
SRV:64bit: - (nlscc) – C:\Windows\SysNative\nlsInterface.EXE (Nalpeiron Ltd.)
SRV:64bit: - (WTouchService) – C:\Program Files\WTouch\WTouchService.exe (Wacom Technology, Corp.)
SRV:64bit: - (TabletServicePen) – C:\Windows\SysNative\Pen_Tablet.exe (Wacom Technology, Corp.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (vsmon) – C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (npggsvc) – C:\Windows\SysWOW64\GameMon.des (INCA Internet Co., Ltd.)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ServiceLayer) – C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe (Nokia.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (KLIF) – C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab)
DRV:64bit: - (KL1) – C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV:64bit: - (kl2) – C:\Windows\SysNative\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV:64bit: - (Vsdatant) – C:\Windows\SysNative\drivers\vsdatant.sys (Check Point Software Technologies LTD)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (NVENETFD) – C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (wacomvhid) – C:\Windows\SysNative\drivers\wacomvhid.sys (Wacom Technology)
DRV:64bit: - (pccsmcfd) – C:\Windows\SysNative\drivers\pccsmcfdx64.sys (Nokia)
DRV:64bit: - (adfs) – C:\Windows\SysNative\drivers\adfs.sys (Adobe Systems, Inc.)
DRV:64bit: - (wacommousefilter) – C:\Windows\SysNative\drivers\wacommousefilter.sys (Wacom Technology)
DRV - (CdaC15BA) – C:\Windows\SysWOW64\drivers\CDAC15BA.SYS ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (adfs) – C:\Windows\SysWow64\drivers\adfs.sys (Adobe Systems, Inc.)
DRV - (NPPTNT2) – C:\Windows\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 07 F6 33 BF E4 8E CD 01 [binary data]
IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledAddons: [removed]:2.0.2.039
FF - prefs.js..extensions.enabledAddons: [removed]:0.4
FF - prefs.js..extensions.enabledAddons: [removed]:2.1.0.2
FF - prefs.js..extensions.enabledAddons: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:[removed]
FF - prefs.js..extensions.enabledAddons: [removed]:6.0
FF - prefs.js..extensions.enabledAddons: {9AA46F4F-4DC7-4c06-97AF-5035170634FE}:4.19
FF - prefs.js..extensions.enabledAddons: [removed]:0.85.61
FF - prefs.js..extensions.enabledAddons: {77d2ed30-4cd2-11e0-b8af-0800200c9a66}:4.8.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {88c7f2aa-f93f-432c-8f0e-b7d85967a527}:[removed]
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8442
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_278.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@raidcall.en/RCplugin: C:\Users\JAZZ\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.0: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.3: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\JAZZ\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\JAZZ\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\TRUSTCHECKER [2012/10/06 16:36:13 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker [2012/10/06 16:36:15 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/10 19:11:10 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2010/07/07 00:04:52 | 000,000,000 | —D | M] (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Extensions
[2012/10/06 12:16:33 | 000,000,000 | —D | M] (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions
[2012/10/06 12:16:33 | 000,000,000 | —D | M] (FT DeepDark) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66}
[2012/02/06 19:02:08 | 000,000,000 | —D | M] ("Free YouTube Download (Free Studio) Menu") – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2012/10/04 12:50:54 | 000,000,000 | —D | M] ("Codec-V") – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\[removed]
[2012/09/10 20:14:59 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\[removed]
[2012/10/04 12:50:54 | 000,000,000 | —D | M] (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\[removed]\chrome\content\extensionCode
[2012/09/10 19:52:22 | 000,109,964 | —- | M] () (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\[removed]
[2012/05/18 13:24:35 | 000,550,833 | —- | M] () (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\[removed]
[2012/09/10 19:55:44 | 000,123,385 | —- | M] () (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\[removed]
[2012/06/10 11:56:30 | 000,179,234 | —- | M] () (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\[removed]
[2012/09/10 19:54:08 | 000,056,403 | —- | M] () (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\[removed]
[2012/09/10 19:56:42 | 000,097,169 | —- | M] () (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}.xpi
[2012/09/26 12:09:20 | 000,061,406 | —- | M] () (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi
[2012/09/10 19:48:11 | 000,199,396 | —- | M] () (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
[2012/09/10 19:45:44 | 000,741,958 | —- | M] () (No name found) – C:\Users\JAZZ\AppData\Roaming\Mozilla\Firefox\Profiles\pk3tgw10.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/09/10 19:11:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/09/05 18:27:05 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/09/05 18:26:22 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/09/05 18:26:22 | 000,002,253 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\JAZZ\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\JAZZ\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\JAZZ\AppData\Local\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: PopCap Games Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nppopcaploader.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Wacom Dynamic Link Library (Enabled) = C:\Program Files (x86)\TabletPlugins\npwacom.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - Extension: YouTube = C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Codec-V = C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpnbdefcbnoefmmcpelplabbkfmfhlho\1.17.48_0\
CHR - Extension: Codec-V = C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpnbdefcbnoefmmcpelplabbkfmfhlho\1.20.61_0\crossrider
CHR - Extension: Codec-V = C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpnbdefcbnoefmmcpelplabbkfmfhlho\1.20.61_0\
CHR - Extension: Skype Click to Call = C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\
CHR - Extension: Gmail = C:\Users\JAZZ\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2010/07/10 13:15:10 | 000,000,879 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O2:64bit: - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [FixCamera] C:\Windows\FixCamera.exe ()
O4 - HKLM..\Run: [WinampAgent] E:\!Winamp\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\JAZZ\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\JAZZ\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 10.7.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A3512F62-7263-484B-99A6-3FA560CAEE7D}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/04/05 08:44:20 | 000,000,000 | —D | M] - F:\autorun – [ FAT32 ]
O33 - MountPoints2\{832882ee-8992-11df-a617-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{832882ee-8992-11df-a617-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/10/07 00:51:59 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\JAZZ\Desktop\OTL.exe
[2012/10/06 16:37:57 | 000,011,864 | —- | C] (Kaspersky Lab ZAO) – C:\Windows\SysNative\drivers\kl2.sys
[2012/10/06 16:37:56 | 000,460,888 | —- | C] (Kaspersky Lab ZAO) – C:\Windows\SysNative\drivers\kl1.sys
[2012/10/06 16:37:51 | 000,485,680 | —- | C] (Kaspersky Lab) – C:\Windows\SysNative\drivers\klif.sys
[2012/10/06 16:37:12 | 000,000,000 | —D | C] – C:\Users\JAZZ\Documents\ForceField Shared Files
[2012/10/06 16:36:46 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Check Point
[2012/10/06 16:36:20 | 000,000,000 | —D | C] – C:\Users\JAZZ\AppData\Roaming\CheckPoint
[2012/10/06 16:35:56 | 000,000,000 | —D | C] – C:\Program Files\CheckPoint
[2012/10/06 16:33:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\CheckPoint
[2012/10/06 16:33:05 | 000,000,000 | —D | C] – C:\ProgramData\CheckPoint
[2012/10/06 04:31:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Optimizer Pro
[2012/10/06 04:31:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\gPotato.com
[2012/10/06 04:31:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2012/10/06 04:31:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA GAMES
[2012/10/06 03:00:45 | 000,399,264 | —- | C] (Bleeping Computer, LLC) – C:\Users\JAZZ\Desktop\unhide.exe
[2012/10/04 06:18:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2012/10/03 23:09:04 | 000,000,000 | —D | C] – C:\Users\JAZZ\AppData\Local\Electronic_Arts_Inc
[2012/10/01 13:20:51 | 000,000,000 | —D | C] – C:\Users\JAZZ\AppData\Roaming\KudosChatSearch
[2012/09/22 03:02:08 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/09/22 03:02:07 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/09/22 03:02:05 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/09/22 03:02:04 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/09/22 03:02:04 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/09/22 03:02:04 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/09/22 03:02:03 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/09/22 03:02:03 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/09/22 03:02:02 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/09/22 03:02:02 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/09/22 03:02:01 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/09/22 03:02:00 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/09/22 03:01:56 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/09/22 03:01:56 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/09/22 03:01:56 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/09/12 02:43:48 | 000,376,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\netio.sys
[2012/09/12 02:43:48 | 000,288,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2012/09/11 04:28:44 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\prevhost.exe
[2012/09/11 04:28:44 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\prevhost.exe
[2012/09/11 04:03:31 | 000,000,000 | R–D | C] – C:\Users\JAZZ\Downloads
[2012/09/11 02:04:55 | 000,000,000 | R–D | C] – C:\Users\JAZZ\Pictures
[2012/09/10 19:11:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Maintenance Service
[2012/09/10 19:11:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012/09/10 19:08:03 | 000,000,000 | —D | C] – C:\Windows\SysNative\SPReview
[2012/09/10 00:38:47 | 000,000,000 | —D | C] – C:\Users\JAZZ\AppData\Local\Aeria Games
[2012/09/10 00:33:43 | 000,000,000 | —D | C] – C:\Users\JAZZ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AeriaGames
[2012/09/10 00:31:33 | 000,000,000 | -HSD | C] – C:\Windows\SysWow64\AI_RecycleBin
[2012/09/09 19:33:34 | 000,246,760 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2012/09/09 19:33:16 | 000,095,208 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2012/09/09 19:32:16 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2012/09/09 16:52:04 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2012/09/09 16:38:40 | 000,000,000 | —D | C] – C:\Users\JAZZ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\File Recovery
[2012/09/07 04:55:50 | 000,000,000 | —D | C] – C:\AeriaGames

========== Files - Modified Within 30 Days ==========

[2012/10/07 01:37:05 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/07 01:35:09 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/10/07 00:52:09 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\JAZZ\Desktop\OTL.exe
[2012/10/07 00:41:06 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2375342815-4246018699-2964025557-1001UA.job
[2012/10/06 19:37:32 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/06 16:43:40 | 000,415,877 | —- | M] () – C:\Windows\SysNative\drivers\vsconfig.xml
[2012/10/06 16:36:49 | 000,000,762 | —- | M] () – C:\Users\Public\Desktop\ZoneAlarm Security.lnk
[2012/10/06 12:16:10 | 000,000,412 | —- | M] () – C:\Windows\tasks\PC Optimizer Pro64 startups.job
[2012/10/06 12:07:52 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/10/06 12:07:52 | 000,623,940 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/10/06 12:07:52 | 000,106,316 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/10/06 12:03:03 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/10/06 12:02:55 | 1610,260,480 | -HS- | M] () – C:\hiberfil.sys
[2012/10/06 04:50:20 | 000,005,872 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/06 04:50:20 | 000,005,872 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/03 12:58:10 | 000,513,501 | —- | M] () – C:\Users\JAZZ\Desktop\adwcleaner.exe
[2012/10/03 10:41:00 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2375342815-4246018699-2964025557-1001Core.job
[2012/10/02 04:00:45 | 005,863,736 | —- | M] () – C:\Users\JAZZ\2012-10-02 06-55-42.bmp
[2012/10/02 04:00:43 | 005,863,736 | —- | M] () – C:\Users\JAZZ\2012-10-02 06-55-36.bmp
[2012/10/01 16:17:12 | 000,001,456 | —- | M] () – C:\Users\JAZZ\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012/10/01 13:44:02 | 000,007,597 | —- | M] () – C:\Users\JAZZ\AppData\Local\Resmon.ResmonCfg
[2012/09/21 01:35:18 | 000,696,240 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/09/21 01:35:18 | 000,073,136 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/09/20 23:13:14 | 000,000,625 | —- | M] () – C:\Users\JAZZ\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/09/12 11:34:43 | 002,946,464 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/09/12 05:12:01 | 000,001,057 | —- | M] () – C:\Users\JAZZ\Desktop\patcher - Shortcut (2).lnk
[2012/09/12 00:47:12 | 000,001,540 | —- | M] () – C:\Users\JAZZ\Desktop\patcher - Shortcut.lnk
[2012/09/11 01:51:47 | 000,001,132 | —- | M] () – C:\Users\JAZZ\Desktop\PhotoshopCS5Portable - Shortcut.lnk
[2012/09/10 19:18:16 | 000,152,576 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msclmd.dll
[2012/09/10 19:18:15 | 000,175,616 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msclmd.dll
[2012/09/10 19:11:19 | 000,001,094 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/09/09 19:44:59 | 000,000,136 | —- | M] () – C:\Users\JAZZ\Desktop\Vendetta Gaming Network Forums.URL
[2012/09/09 19:33:06 | 000,095,208 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2012/09/09 19:33:05 | 000,821,736 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npdeployJava1.dll
[2012/09/09 19:33:05 | 000,746,984 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2012/09/09 19:33:05 | 000,246,760 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2012/09/09 19:33:05 | 000,174,056 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2012/09/09 19:33:05 | 000,174,056 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2012/09/09 19:30:43 | 000,001,974 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2012/09/09 16:38:42 | 000,000,160 | —- | M] () – C:\ProgramData\-HjoC93XNZNIYior
[2012/09/09 16:38:42 | 000,000,144 | —- | M] () – C:\ProgramData\-HjoC93XNZNIYio
[2012/09/09 16:38:40 | 000,000,368 | —- | M] () – C:\ProgramData\HjoC93XNZNIYio
[2012/09/08 23:01:32 | 000,000,368 | —- | M] () – C:\ProgramData\NNvRF9IMLfKX6o
[2012/09/08 22:57:44 | 000,000,679 | —- | M] () – C:\Users\JAZZ\Application Data\Microsoft\Internet Explorer\Quick Launch\File_Recovery.lnk
[2012/09/07 17:04:46 | 000,025,928 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys

========== Files Created - No Company Name ==========

[2012/10/06 16:38:03 | 000,415,877 | —- | C] () – C:\Windows\SysNative\drivers\vsconfig.xml
[2012/10/06 16:36:49 | 000,000,762 | —- | C] () – C:\Users\Public\Desktop\ZoneAlarm Security.lnk
[2012/10/03 12:57:57 | 000,513,501 | —- | C] () – C:\Users\JAZZ\Desktop\adwcleaner.exe
[2012/10/02 03:57:32 | 005,863,736 | —- | C] () – C:\Users\JAZZ\2012-10-02 06-55-42.bmp
[2012/10/02 03:57:32 | 005,863,736 | —- | C] () – C:\Users\JAZZ\2012-10-02 06-55-36.bmp
[2012/10/01 13:44:02 | 000,007,597 | —- | C] () – C:\Users\JAZZ\AppData\Local\Resmon.ResmonCfg
[2012/09/30 13:19:36 | 000,001,147 | —- | C] () – C:\Users\JAZZ\Desktop\game - Shortcut.lnk
[2012/09/29 20:09:02 | 005,863,736 | —- | C] () – C:\Users\JAZZ\2012-09-29 23-07-13.bmp
[2012/09/29 20:09:02 | 005,863,736 | —- | C] () – C:\Users\JAZZ\2012-09-29 23-07-11.bmp
[2012/09/12 05:12:01 | 000,001,057 | —- | C] () – C:\Users\JAZZ\Desktop\patcher - Shortcut (2).lnk
[2012/09/12 00:47:12 | 000,001,540 | —- | C] () – C:\Users\JAZZ\Desktop\patcher - Shortcut.lnk
[2012/09/11 06:06:36 | 000,001,456 | —- | C] () – C:\Users\JAZZ\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012/09/11 01:51:47 | 000,001,132 | —- | C] () – C:\Users\JAZZ\Desktop\PhotoshopCS5Portable - Shortcut.lnk
[2012/09/10 19:11:19 | 000,001,106 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/09/10 19:11:19 | 000,001,094 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/09/09 19:30:43 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2012/09/09 19:30:43 | 000,001,974 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2012/09/09 16:38:42 | 000,000,160 | —- | C] () – C:\ProgramData\-HjoC93XNZNIYior
[2012/09/09 16:38:41 | 000,000,144 | —- | C] () – C:\ProgramData\-HjoC93XNZNIYio
[2012/09/09 16:38:37 | 000,000,368 | —- | C] () – C:\ProgramData\HjoC93XNZNIYio
[2012/09/08 22:57:44 | 000,000,679 | —- | C] () – C:\Users\JAZZ\Application Data\Microsoft\Internet Explorer\Quick Launch\File_Recovery.lnk
[2012/09/08 22:57:41 | 000,000,368 | —- | C] () – C:\ProgramData\NNvRF9IMLfKX6o
[2012/07/30 18:06:27 | 000,020,480 | —- | C] () – C:\Windows\FixCamera.exe
[2012/07/30 17:04:13 | 000,057,856 | —- | C] () – C:\Windows\Fce32.dll
[2012/07/30 17:04:11 | 000,092,672 | —- | C] () – C:\Windows\SysWow64\See32.dll
[2012/07/30 17:04:11 | 000,057,856 | —- | C] () – C:\Windows\SysWow64\Fce32.dll
[2012/07/30 05:37:42 | 000,008,864 | —- | C] () – C:\Windows\SysWow64\drivers\CDAC15BA.SYS
[2012/03/10 21:50:03 | 000,000,239 | —- | C] () – C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2011/03/26 17:15:16 | 003,133,496 | —- | C] () – C:\Users\JAZZ\2011-02-19 14-03-25.bmp
[2011/03/26 17:15:16 | 003,133,496 | —- | C] () – C:\Users\JAZZ\2011-02-19 14-00-26.bmp
[2011/03/12 19:16:03 | 000,000,309 | —- | C] () – C:\ProgramData\nvUnsupRes.dat
[2010/12/27 16:46:30 | 000,000,056 | —- | C] () – C:\ProgramData\ezsidmv.dat
[2010/11/20 03:58:12 | 000,120,200 | —- | C] () – C:\Windows\SysWow64\DLLDEV32i.dll
[2010/11/20 03:57:54 | 000,006,211 | —- | C] () – C:\Windows\mgxoschk.ini
[2010/07/09 15:04:30 | 000,000,132 | —- | C] () – C:\Users\JAZZ\AppData\Roaming\Adobe Targa Format CS5 Prefs
[2008/08/25 15:40:54 | 001,768,497 | —- | C] () – C:\Users\JAZZ\AiPictureExplorer_v850.exe
[2008/08/23 23:27:22 | 000,000,185 | —- | C] () – C:\Users\JAZZ\FILE_ID.DIZ
[2007/01/01 05:26:55 | 000,000,160 | —- | C] () – C:\ProgramData\-HcFi9Of3olNeLkr
[2007/01/01 05:26:55 | 000,000,144 | —- | C] () – C:\ProgramData\-HcFi9Of3olNeLk
[2007/01/01 02:56:04 | 000,000,368 | —- | C] () – C:\ProgramData\HcFi9Of3olNeLk
[2007/01/01 00:08:36 | 000,000,368 | —- | C] () – C:\ProgramData\xJphLKeMhUxzZN

========== ZeroAccess Check ==========

[2009/07/13 21:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 22:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 21:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 18:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 05:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 18:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2010/08/07 15:15:39 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\Blender Foundation
[2010/08/19 19:31:40 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\Canon
[2012/10/06 16:36:20 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\CheckPoint
[2010/07/29 16:51:48 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\com.adobe.ExMan
[2012/04/04 19:49:36 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\DVDVideoSoft
[2012/02/06 19:02:08 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\DVDVideoSoftIEHelpers
[2011/05/19 18:30:59 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\GetRightToGo
[2012/10/01 13:20:51 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\KudosChatSearch
[2012/03/11 14:06:06 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\Macro Recorder
[2010/11/20 03:58:35 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\MAGIX
[2010/07/10 15:55:58 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\onOne Software
[2010/08/11 16:43:27 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\OpenOffice.org
[2011/04/19 13:00:39 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\PC Suite
[2010/11/20 00:55:03 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\Photodex
[2012/08/27 23:27:34 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\raidcall
[2011/04/19 13:00:50 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\Samsung
[2011/04/25 17:43:25 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\SecondLife
[2012/03/08 17:53:18 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\SysLipe
[2011/12/12 18:49:08 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\TS3Client
[2011/12/12 16:50:16 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\ts3overlay
[2010/07/13 01:01:00 | 000,000,000 | —D | M] – C:\Users\JAZZ\AppData\Roaming\WTouch

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/25 23:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/25 22:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 18:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/25 22:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/30 22:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/25 22:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/24 23:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/25 23:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 05:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\SysWOW64\explorer.exe
[2010/11/20 05:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/02 23:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/24 22:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/30 23:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/02 22:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 06:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\explorer.exe
[2010/11/20 06:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/30 23:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/02 22:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 18:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/30 23:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/25 23:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/02 23:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
[2008/04/29 08:42:08 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/13 18:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 18:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 18:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 18:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2012/07/03 13:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/13 18:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 18:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe
[2008/07/01 06:17:12 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 05:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 05:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 18:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 18:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 06:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 06:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 06:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 06:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 18:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012/07/03 13:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/28 00:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/27 23:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
[2008/07/01 06:17:12 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\winlogon.exe

< %systemroot%\*. /rp /s >

< %systemdrive%\$Recycle.Bin|@;true;true;true >

< %USERPROFILE%\..|smtmp;true;true;true /FP >
[2012/09/08 23:00:33 | 000,000,000 | —D | M] – C:\Users\JAZZ\..\JAZZ\AppData\Local\Temp\smtmp
[2012/09/10 18:59:00 | 000,000,000 | —D | M] – C:\Users\JAZZ\..\JAZZ\AppData\Local\Temp\smtmp\1
[2012/09/10 18:58:58 | 000,000,000 | —D | M] – C:\Users\JAZZ\..\JAZZ\AppData\Local\Temp\smtmp\4

< %temp%\smtmp\*.* /s > >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: SCSI
Media Type: Fixed hard disk media
Model: WDC WD74 0GD-00FLC0 SCSI Disk Device
Partitions: 2
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 - External hard disk media
Interface type: USB
Media Type: External hard disk media
Model: Hitachi HDS721050CLA362 USB Device
Partitions: 1
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 - External hard disk media
Interface type: USB
Media Type: External hard disk media
Model: WD 5000AAJ External USB Device
Partitions: 1
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 60.00GB
Starting Offset: 32256
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 9.00GB
Starting Offset: 64428618240
Hidden sectors: 0


DeviceID: Disk #1, Partition #0
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 466.00GB
Starting Offset: 32256
Hidden sectors: 0


DeviceID: Disk #2, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 466.00GB
Starting Offset: 32256
Hidden sectors: 0


< End of report >
Hi Soulhunter,

Run OTL.exe Right click on the icon and select "Run as Administrator" to run it.
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    [2012/09/09 16:38:42 | 000,000,160 | —- | M] () – C:\ProgramData\-HjoC93XNZNIYior
    [2012/09/09 16:38:42 | 000,000,144 | —- | M] () – C:\ProgramData\-HjoC93XNZNIYio
    [2012/09/09 16:38:40 | 000,000,368 | —- | M] () – C:\ProgramData\HjoC93XNZNIYio
    [2012/09/08 23:01:32 | 000,000,368 | —- | M] () – C:\ProgramData\NNvRF9IMLfKX6o
    [2007/01/01 05:26:55 | 000,000,160 | —- | C] () – C:\ProgramData\-HcFi9Of3olNeLkr
    [2007/01/01 05:26:55 | 000,000,144 | —- | C] () – C:\ProgramData\-HcFi9Of3olNeLk
    [2007/01/01 02:56:04 | 000,000,368 | —- | C] () – C:\ProgramData\HcFi9Of3olNeLk
    [2007/01/01 00:08:36 | 000,000,368 | —- | C] () – C:\ProgramData\xJphLKeMhUxzZN
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
Next


Locate Malwarebytes' Anti-Malware (it should be on your desktop).

  • Right click and select "Run as Administrator" mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]

  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Next

Please run Eset Online Scanner

Administrator rights are required to run ESET Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.

In your next post please provide the following:
  • OTL.txt (no Extras.txt will be generated)
  • MBAM log
  • ESET log
  • Tell me how your computer is running at the moment
I wasn't sure if you wanted a whole new OTL scan after the instructions above or the log of this one. Anyways, my pc does run much better even so there's still freezes from time to time but by now i believe it's just my pc itself that defiantly needs a update lol. thanks for your help guys. ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=2bda107a5d1b6346883ef48cfc300194 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-10-09 06:49:33 # local_time=2012-10-09 11:49:33 (-0800, Pacific Daylight Time) # country="United States" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 0 101335724 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # compatibility_mode=9217 16776573 100 13 139226 3425554 0 0 # scanned=534883 # found=3 # cleaned=0 # scan_time=16320 C:\Users\JAZZ\Desktop\PWV BackUp\Archived\bla\HC2Setup.exe Win32/Somoto application (unable to clean) 00000000000000000000000000000000 I C:\Windows\FixCamera.exe a variant of Win32/KillProc.A application (unable to clean) 00000000000000000000000000000000 I ${Memory} a variant of Win32/KillProc.A application 00000000000000000000000000000000 I All processes killed ========== OTL ========== C:\ProgramData\-HjoC93XNZNIYior moved successfully. C:\ProgramData\-HjoC93XNZNIYio moved successfully. C:\ProgramData\HjoC93XNZNIYio moved successfully. C:\ProgramData\NNvRF9IMLfKX6o moved successfully. C:\ProgramData\-HcFi9Of3olNeLkr moved successfully. C:\ProgramData\-HcFi9Of3olNeLk moved successfully. C:\ProgramData\HcFi9Of3olNeLk moved successfully. C:\ProgramData\xJphLKeMhUxzZN moved successfully. ========== COMMANDS ========== Restore point Set: OTL Restore Point [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56504 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: JAZZ ->Temp folder emptied: 2146532529 bytes ->Temporary Internet Files folder emptied: 282846308 bytes ->Java cache emptied: 281733 bytes ->FireFox cache emptied: 473065770 bytes ->Google Chrome cache emptied: 239227468 bytes ->Flash cache emptied: 229536 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 380395612 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 36030846 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 3,394.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 10092012_064727 Files\Folders moved on Reboot… C:\Users\JAZZ\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\JAZZ\AppData\Local\Temp\~DF7FC2446F3912F55C.TMP moved successfully. C:\Users\JAZZ\AppData\Local\Mozilla\Firefox\Profiles\pk3tgw10.default\startupCache\startupCache.4.little moved successfully. C:\Users\JAZZ\AppData\Local\Mozilla\Firefox\Profiles\pk3tgw10.default\Cache\_CACHE_001_ moved successfully. C:\Users\JAZZ\AppData\Local\Mozilla\Firefox\Profiles\pk3tgw10.default\Cache\_CACHE_002_ moved successfully. C:\Users\JAZZ\AppData\Local\Mozilla\Firefox\Profiles\pk3tgw10.default\Cache\_CACHE_003_ moved successfully. C:\Users\JAZZ\AppData\Local\Mozilla\Firefox\Profiles\pk3tgw10.default\Cache\_CACHE_MAP_ moved successfully. C:\Users\JAZZ\AppData\Local\Mozilla\Firefox\Profiles\pk3tgw10.default\urlclassifier3.sqlite moved successfully. C:\Windows\temp\ZLT0008f.TMP moved successfully. PendingFileRenameOperations files… Registry entries deleted on Reboot… Malwarebytes Anti-Malware 1.65.0.1400 www.malwarebytes.org Database version: v2012.10.09.07 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 JAZZ :: JAZZ-PC [administrator] 10/9/2012 7:02:23 AM mbam-log-2012-10-09 (07-02-23).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 199421 Time elapsed: 5 minute(s), 21 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Hi Soulhunter,

Anyways, my pc does run much better even so there's still freezes from time to time but by now i believe it's just my pc itself that defiantly needs a update lol. thanks for your help guys.

There is still some work to be done. Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.

Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following files: (one at a time)
    • C:\Users\JAZZ\Desktop\PWV BackUp\Archived\bla\HC2Setup.exe
    • C:\Windows\FixCamera.exe
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Please post the results in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI