Spyware / Malware / Virus Removal
Searchiu.com [Solved]
21 min read
Chamby
Topic Starter
I use Chrome as a search engine and it has recently started to redirect me to searchiu.com whenever i try to search for something. If I type the URL of a website, it will go to the website. I ran Norton virus scan and MalwareBytes and neither detected anything. Please help!
Satchfan
Hello Chamby and welcome to the WTT forum.
My name is Satchfan and I would be glad to help you with your computer problem.
Please read the following guidelines which will help to make cleaning your machine easier:
Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested
===================================================
Download and run OTL
Run aswMBR
OTL.txt
Extras.txt
aswMBR log
Thanks
Satchfan
My name is Satchfan and I would be glad to help you with your computer problem.
Please read the following guidelines which will help to make cleaning your machine easier:
- please follow all instructions in the order posted
- please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
- all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
- if you don't understand something, please don't hesitate to ask for clarification before proceeding
- the fixes are specific to your problem and should only be used for this issue on this machine.
- please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested
===================================================
Download and run OTL
- download OTL to your desktop.
- double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
- click Scan all users.
- under Custom Scan paste this in
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
consrv.dll
/md5stop
%systemroot%\*. /rp /s
DRIVES
CREATERESTOREPOINT - click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
- when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
- please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
- you may need two posts to fit them both in.
Run aswMBR
- download aswMBR.exe to your desktop.
- double click the aswMBR.exe to run it
- if asked, accept the AVAST virus definition download
- click the "Scan" button to start scan
- on completion of the scan click Save log, save it to your desktop and post in your next reply
OTL.txt
Extras.txt
aswMBR log
Thanks
Satchfan
Chamby
Thank you Satchfan for the help. I am a student so i do not have a lot of free time until Friday morning, would you be able to help me more then?
Satchfan
I don't know your location.
I am in the UK but whatever the difference, sometime Friday would be OK. As long as I know you are still in need of help and you you keep me updated, I'll keep the topic open.
If Searchiu.com is the only problem, we should be able to deal with it quite easily but will need some scans to be sure it hasn't brought anything else with it.
Satchfan
Chamby
Thank you, I am on the eastern coast of the USA, so I am about 5 hours behind you. Once again thanks for the help.
Satchfan
Chamby
Here is the OTL.Txt
OTL logfile created on: 3/29/2013 8:48:58 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\admin\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19401)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.96 Gb Total Physical Memory | 1.82 Gb Available Physical Memory | 45.87% Memory free
8.09 Gb Paging File | 5.57 Gb Available in Paging File | 68.84% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451.07 Gb Total Space | 307.35 Gb Free Space | 68.14% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 0.00 Gb Free Space | 0.01% Space Free | Partition Type: NTFS
Computer Name: JEREMYCOMPUTER | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/03/29 08:46:39 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\admin\Downloads\OTL.exe
PRC - [2012/12/25 17:35:10 | 004,474,832 | —- | M] (IObit) – C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe
PRC - [2012/12/14 16:49:28 | 000,682,344 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/12/14 16:49:28 | 000,512,360 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/12/14 16:49:28 | 000,398,184 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/07/14 21:19:18 | 000,138,096 | —- | M] (Facebook Inc.) – C:\Users\admin\AppData\Local\Facebook\Update\FacebookUpdate.exe
PRC - [2012/06/21 06:01:58 | 000,092,632 | —- | M] (TomTom) – C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2012/06/21 06:01:56 | 000,247,768 | —- | M] (TomTom) – C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2012/06/15 22:24:19 | 000,138,272 | R— | M] (Symantec Corporation) – C:\Program Files (x86)\Norton 360\Engine\6.4.1.14\ccsvchst.exe
PRC - [2012/06/11 17:22:16 | 000,240,208 | —- | M] (Microsoft Corporation.) – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE
PRC - [2012/01/09 20:17:44 | 000,821,592 | —- | M] (IObit) – C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
PRC - [2011/01/17 19:37:40 | 011,322,880 | —- | M] (OpenOffice.org) – C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
PRC - [2011/01/17 19:37:40 | 011,314,688 | —- | M] (OpenOffice.org) – C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
PRC - [2009/07/07 10:23:00 | 001,779,952 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
PRC - [2009/04/13 10:50:14 | 000,497,496 | —- | M] (Dell Inc.) – C:\Program Files (x86)\Dell Remote Access\ezi_ra.exe
PRC - [2009/04/13 10:48:12 | 000,828,656 | —- | M] (Dell Inc.) – c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
PRC - [2009/02/04 22:26:38 | 000,128,232 | —- | M] (CyberLink Corp.) – C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
PRC - [2008/12/18 15:05:28 | 000,155,648 | —- | M] (Stardock Corporation) – C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2008/12/18 00:27:22 | 004,823,928 | —- | M] (Dell Inc. and SightSpeed Inc.) – C:\Program Files (x86)\Dell Video Chat\DellVideoChat.exe
PRC - [2008/03/20 00:49:42 | 000,025,840 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtmsdmon.exe
PRC - [2008/03/20 00:49:10 | 000,668,912 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtmon.exe
PRC - [2007/03/29 16:41:26 | 000,222,128 | —- | M] (Macrovision Corporation) – C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe
========== Modules (No Company Name) ==========
MOD - [2013/02/14 12:12:48 | 001,840,640 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\d186bf251ae14af93b3a943d472ee9f5\System.Web.Services.ni.dll
MOD - [2013/02/14 12:03:05 | 012,433,920 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\e64304962098e90f0d3f4c33c1b080a6\System.Windows.Forms.ni.dll
MOD - [2013/01/10 18:22:10 | 000,998,400 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\f042f66c2ad8fd5b8c34fa22cd22079e\System.Management.ni.dll
MOD - [2013/01/10 17:15:21 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\0525305cfa7fc1437348559b7af5003a\System.Configuration.ni.dll
MOD - [2013/01/10 17:02:56 | 005,450,752 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\b757806657fa5db2b1ed1a89b026b463\System.Xml.ni.dll
MOD - [2013/01/10 17:02:06 | 001,593,856 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\78157a494dc9a7e52be8840decfcd9cc\System.Drawing.ni.dll
MOD - [2013/01/10 17:00:10 | 007,977,984 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\cc149d08e75f8c53cd28ac926b38c370\System.ni.dll
MOD - [2013/01/10 16:52:41 | 011,492,352 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\2227d1559f87943255069398608d5c56\mscorlib.ni.dll
MOD - [2011/01/31 16:13:51 | 000,985,088 | —- | M] () – C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
MOD - [2009/07/07 10:24:00 | 000,268,528 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Online\SdbShared.dll
MOD - [2009/07/07 10:24:00 | 000,140,528 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Online\SdbShared.XmlSerializers.dll
MOD - [2009/07/07 10:24:00 | 000,095,472 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Online\SdbUI.dll
MOD - [2009/07/07 10:23:00 | 001,779,952 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
MOD - [2009/07/07 10:23:00 | 000,017,648 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Online\CppUtils.dll
MOD - [2009/04/09 17:29:00 | 000,058,608 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Online\BalloonWindow.dll
MOD - [2008/12/18 00:24:14 | 006,510,416 | —- | M] () – C:\Program Files (x86)\Dell Video Chat\QtGui4.dll
MOD - [2008/12/18 00:24:14 | 001,657,168 | —- | M] () – C:\Program Files (x86)\Dell Video Chat\QtCore4.dll
MOD - [2008/12/18 00:24:14 | 000,396,112 | —- | M] () – C:\Program Files (x86)\Dell Video Chat\QtOpenGL4.dll
MOD - [2008/12/18 00:24:14 | 000,366,928 | —- | M] () – C:\Program Files (x86)\Dell Video Chat\QtNetwork4.dll
MOD - [2008/12/18 00:24:14 | 000,027,472 | —- | M] () – C:\Program Files (x86)\Dell Video Chat\SDL.dll
MOD - [2008/03/20 00:49:42 | 000,025,840 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtmsdmon.exe
MOD - [2008/03/20 00:49:10 | 000,668,912 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtmon.exe
MOD - [2008/03/18 18:05:06 | 000,782,336 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtdrs.dll
MOD - [2008/03/18 18:04:20 | 000,380,928 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtscw.dll
MOD - [2008/02/19 18:25:56 | 000,081,920 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtcaps.dll
MOD - [2008/02/19 18:18:58 | 000,151,552 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtmonr.dll
MOD - [2008/02/19 09:05:38 | 000,036,864 | —- | M] () – C:\Program Files (x86)\Dell V305\app4r.monitor.core.dll
MOD - [2008/02/19 09:05:38 | 000,028,672 | —- | M] () – C:\Program Files (x86)\Dell V305\app4r.monitor.common.dll
MOD - [2008/02/19 09:04:38 | 000,061,440 | —- | M] () – C:\Program Files (x86)\Dell V305\app4r.devmons.mcmdevmon.dll
MOD - [2008/01/21 22:05:12 | 000,077,906 | —- | M] () – C:\Program Files (x86)\Dell V305\DLDTcfg.dll
MOD - [2007/11/22 04:55:48 | 000,011,776 | —- | M] () – C:\Program Files (x86)\Dell V305\app4r.devmons.mcmdevmon.autoplayutil.dll
MOD - [2007/11/13 15:13:10 | 000,069,632 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtcnv4.dll
MOD - [2007/05/29 03:39:08 | 000,589,824 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtdatr.dll
MOD - [2007/03/26 03:39:36 | 000,073,728 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtcats.dll
========== Services (SafeList) ==========
SRV:64bit: - [2009/07/09 19:48:28 | 000,033,448 | —- | M] () [Auto | Running] – C:\Windows\SysNative\spool\DRIVERS\x64\3\\dldtserv.exe – (dldtCATSCustConnectService)
SRV:64bit: - [2009/03/19 12:26:10 | 000,268,288 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_15f4e438\STacSV64.exe – (STacSV)
SRV:64bit: - [2009/03/19 12:25:42 | 000,089,600 | —- | M] (Andrea Electronics Corporation) [Auto | Running] – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe – (AESTFilters)
SRV:64bit: - [2008/12/18 15:05:28 | 000,155,648 | —- | M] (Stardock Corporation) [Auto | Running] – C:\Program Files\Dell\DellDock\DockLogin.exe – (DockLoginService)
SRV:64bit: - [2008/02/25 12:38:24 | 001,045,232 | —- | M] ( ) [Auto | Running] – C:\Windows\SysNative\dldtcoms.exe – (dldt_device)
SRV:64bit: - [2008/01/20 22:47:32 | 000,383,544 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2012/12/14 16:49:28 | 000,682,344 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/12/14 16:49:28 | 000,398,184 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012/07/13 14:28:36 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012/06/21 06:01:58 | 000,092,632 | —- | M] (TomTom) [Auto | Running] – C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe – (TomTomHOMEService)
SRV - [2012/06/15 22:24:19 | 000,138,272 | R— | M] (Symantec Corporation) [Auto | Running] – C:\Program Files (x86)\Norton 360\Engine\6.4.1.14\ccSvcHst.exe – (N360)
SRV - [2012/06/11 17:22:16 | 000,240,208 | —- | M] (Microsoft Corporation.) [On_Demand | Running] – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE – (BBUpdate)
SRV - [2012/06/11 17:22:16 | 000,193,616 | —- | M] (Microsoft Corporation.) [Auto | Stopped] – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.EXE – (BBSvc)
SRV - [2012/01/09 20:17:44 | 000,821,592 | —- | M] (IObit) [Auto | Running] – C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe – (IMFservice)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/08/06 22:17:05 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe – (GoToAssist)
SRV - [2009/07/09 19:48:28 | 000,033,448 | —- | M] () [Auto | Running] – C:\Windows\system32\spool\DRIVERS\x64\3\\dldtserv.exe – (dldtCATSCustConnectService)
SRV - [2009/04/13 10:48:12 | 000,828,656 | —- | M] (Dell Inc.) [Auto | Running] – c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe – (hnmsvc)
SRV - [2009/03/30 00:42:14 | 000,066,368 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2008/02/25 12:38:12 | 000,595,184 | —- | M] ( ) [Auto | Running] – C:\Windows\SysWOW64\dldtcoms.exe – (dldt_device)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012/12/14 16:49:28 | 000,024,176 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2012/08/09 18:06:14 | 000,175,736 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\SYMEVENT64x86.SYS – (SymEvent)
DRV:64bit: - [2012/07/05 22:17:58 | 000,037,536 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\N360x64\0604010.00E\SRTSPX64.SYS – (SRTSPX)
DRV:64bit: - [2012/07/05 22:17:57 | 000,737,952 | —- | M] (Symantec Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\Drivers\N360x64\0604010.00E\SRTSP64.SYS – (SRTSP)
DRV:64bit: - [2012/06/07 00:43:38 | 000,167,072 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\N360x64\0604010.00E\ccSetx64.sys – (ccSet_N360)
DRV:64bit: - [2012/05/21 21:37:12 | 001,129,120 | —- | M] (Symantec Corporation) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\N360x64\0604010.00E\SYMEFA64.SYS – (SymEFA)
DRV:64bit: - [2012/03/29 02:28:38 | 000,445,560 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\N360x64\0604010.00E\SYMTDIV.SYS – (SYMTDIv)
DRV:64bit: - [2012/03/29 02:28:25 | 000,451,192 | R— | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\N360x64\0604010.00E\SYMDS64.SYS – (SymDS)
DRV:64bit: - [2012/03/29 02:06:25 | 000,190,072 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\N360x64\0604010.00E\Ironx64.SYS – (SymIRON)
DRV:64bit: - [2012/02/29 09:52:46 | 000,016,384 | —- | M] (Microsoft Corporation) [Recognizer | System | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/02/11 19:16:38 | 010,628,640 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/07/21 04:40:20 | 000,010,112 | —- | M] (support.com, Inc) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\ssmirrdr.sys – (ssmirrdr)
DRV:64bit: - [2009/09/16 10:22:40 | 000,049,480 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mfesmfk.sys – (mfesmfk)
DRV:64bit: - [2009/09/16 10:15:38 | 000,040,904 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mferkdk.sys – (mferkdk)
DRV:64bit: - [2009/05/06 17:03:00 | 000,313,696 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\OA008Vid.sys – (OA008Vid)
DRV:64bit: - [2009/05/03 23:32:16 | 000,035,840 | R— | M] (Avanquest Software) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\BVRPMPR5a64.SYS – (BVRPMPR5a64)
DRV:64bit: - [2009/04/11 01:03:32 | 000,111,104 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\sdbus.sys – (sdbus)
DRV:64bit: - [2009/03/19 16:34:18 | 000,029,544 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2009/03/19 12:26:24 | 000,477,696 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\stwrt64.sys – (STHDA)
DRV:64bit: - [2009/03/12 12:47:46 | 000,172,160 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\CtClsFlt.sys – (CtClsFlt)
DRV:64bit: - [2009/03/06 07:33:58 | 000,159,840 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\OA008Ufd.sys – (OA008Ufd)
DRV:64bit: - [2008/12/21 13:26:28 | 004,735,488 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\NETw5v64.sys – (NETw5v64)
DRV:64bit: - [2008/12/19 22:24:48 | 000,041,032 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mfebopk.sys – (mfebopk)
DRV:64bit: - [2008/11/25 11:08:48 | 000,126,464 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcHdmi.sys – (IntcHdmiAddService)
DRV:64bit: - [2008/11/25 10:56:58 | 000,261,680 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\SynTP.sys – (SynTP)
DRV:64bit: - [2008/10/07 13:49:52 | 000,252,928 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\k57nd60a.sys – (k57nd60a)
DRV:64bit: - [2008/09/15 13:11:04 | 000,057,856 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\SysNative\DRIVERS\rixdpx64.sys – (rismxdp)
DRV:64bit: - [2008/09/15 13:11:00 | 000,062,976 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\SysNative\DRIVERS\rimmpx64.sys – (rimmptsk)
DRV:64bit: - [2008/09/15 13:10:58 | 000,055,296 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\SysNative\DRIVERS\rimspx64.sys – (rimsptsk)
DRV:64bit: - [2008/06/18 18:48:54 | 000,029,184 | —- | M] (SingleClick Systems) [Kernel | Auto | Running] – C:\Windows\SysNative\DRIVERS\packet.sys – (Packet)
DRV:64bit: - [2008/01/20 22:46:55 | 000,317,952 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\e1e6032e.sys – (e1express)
DRV:64bit: - [2007/11/14 04:00:00 | 000,053,488 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2006/11/02 03:48:50 | 002,488,320 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\atikmdag.sys – (R300)
DRV - [2013/03/21 21:52:21 | 001,387,608 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\BASHDefs\20130322.001\BHDrvx64.sys – (BHDrvx64)
DRV - [2013/01/19 16:51:51 | 002,087,664 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\VirusDefs\20130328.025\ex64.sys – (NAVEX15)
DRV - [2013/01/19 16:51:51 | 000,126,192 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\VirusDefs\20130328.025\eng64.sys – (NAVENG)
DRV - [2013/01/05 20:48:20 | 000,484,512 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys – (eeCtrl)
DRV - [2012/08/31 20:27:23 | 000,513,184 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\IPSDefs\20130328.001\IDSviA64.sys – (IDSVia64)
DRV - [2012/08/09 21:40:25 | 000,138,912 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2012/07/05 13:53:42 | 000,021,904 | —- | M] (IObit.com) [Kernel | On_Demand | Running] – C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\wlh_amd64\UrlFilter.sys – (UrlFilter)
DRV - [2012/07/05 13:53:40 | 000,033,224 | —- | M] (IObit.com) [Kernel | On_Demand | Running] – C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\wlh_amd64\RegFilter.sys – (RegFilter)
DRV - [2012/01/05 18:07:24 | 000,021,384 | —- | M] (IObit) [File_System | On_Demand | Running] – C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\wlh_amd64\FileMonitor.sys – (FileMonitor)
DRV - [2008/06/17 13:01:06 | 000,022,016 | —- | M] (SingleClick Systems) [Kernel | Auto | Running] – C:\Windows\SysWOW64\drivers\packet.sys – (Packet)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://searchou.com/?affil=7&uid=37aef…3a-002219fcc2e0
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{A05A25E8-7D80-44AA-A94A-A54493F11DAD}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8893
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8893
IE - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://searchou.com/?affil=7&uid=37aef…3a-002219fcc2e0
IE - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://searchou.com/?affil=7&uid=37aef…q={searchTerms}
IE - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\..\SearchScopes\{A05A25E8-7D80-44AA-A94A-A54493F11DAD}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?q={SEARCHTERMS}&…b&qsrc=2869
IE - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledAddons: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8442
FF - prefs.js..extensions.enabledAddons: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:11.1.1.5 - 3
FF - prefs.js..browser.startup.homepage: "http://searchou.com/?affil=7&uid=37aef630-f51f-11e1-9b3a-002219fcc2e0"
FF - prefs.js..browser.search.defaultenginename: "Privitize VPN"
FF - prefs.js..browser.search.defaultengine: "Privitize VPN"
FF - prefs.js..browser.search.order.1: "Privitize VPN"
FF - prefs.js..browser.search.selectedEngine: "Privitize VPN"
FF - prefs.js..keyword.URL: "http://searchou.com/?affil=7&uid=37aef630-f51f-11e1-9b3a-002219fcc2e0&q="
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_171.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\admin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\IPSFFPlgn\ [2012/08/09 18:07:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\coFFPlgn\ [2013/03/29 08:17:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/05/04 12:53:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/04 12:53:50 | 000,000,000 | —D | M]
[2012/08/05 17:31:27 | 000,000,000 | —D | M] (No name found) – C:\Users\admin\AppData\Roaming\Mozilla\Extensions
[2012/08/05 17:31:27 | 000,000,000 | —D | M] (No name found) – C:\Users\admin\AppData\Roaming\Mozilla\Extensions\[removed]
[2013/03/17 20:11:50 | 000,002,090 | —- | M] () – C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjqu125v.default\searchplugins\Searchou.xml
[2012/01/12 18:02:22 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/01/12 18:02:25 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/01/31 16:11:19 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/17 16:39:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/04/15 16:19:49 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2012/08/09 18:07:19 | 000,000,000 | —D | M] (Norton Vulnerability Protection) – C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\IPSFFPLGN
[2009/08/04 22:22:22 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/03/18 13:53:24 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/04/14 14:01:38 | 000,024,376 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
========== Chrome ==========
CHR - default_search_provider: Privitize VPN (Enabled)
CHR - default_search_provider: search_url = http://searchou.com/?affil=7&uid=37aef…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.43\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.43\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.43\pdf.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Adobe Acrobat (Enabled) = c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\admin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Google Docs = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Skype Click to Call = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\
CHR - Extension: Norton Identity Protection = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.11.8_0\
CHR - Extension: Gmail = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2011/01/17 15:45:37 | 000,428,637 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14760 more lines…
O2:64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL File not found
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll File not found
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\6.4.1.14\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\6.4.1.14\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\6.4.1.14\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\6.4.1.14\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [dldtamon] C:\Program Files (x86)\Dell V305\dldtamon.exe ()
O4:64bit: - HKLM..\Run: [dldtmon.exe] C:\Program Files (x86)\Dell V305\dldtmon.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [IObit Malware Fighter] C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (IObit)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000..\Run: [Facebook Update] C:\Users\admin\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000..\Run: [ISUSPM] C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe (Macrovision Corporation)
O4 - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000..\Run: [SightSpeed] C:\Program Files (x86)\Dell Video Chat\DellVideoChat.exe (Dell Inc. and SightSpeed Inc.)
O4 - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000..\Run: [TomTomHOME.exe] C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2010/08/25 12:42:15 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O4 - Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8F1D1C59-370F-4EBA-8687-D35FC1FD513D}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A5A852AC-3CA6-436B-B74A-B6170ED61A59}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\belarc - No CLSID value found
O18:64bit: - Protocol\Handler\gopher - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\admin\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\admin\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28:64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/03/27 12:17:53 | 000,000,000 | —D | C] – C:\JEREMYCOMPUTER
[2013/03/27 12:17:39 | 000,000,000 | —D | C] – C:\Tools
[2013/03/27 12:17:39 | 000,000,000 | —D | C] – C:\sources
[2013/03/27 12:11:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/03/25 19:52:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
[2013/03/25 19:51:55 | 000,000,000 | —D | C] – C:\ProgramData\IObit
[2013/03/25 19:51:54 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\IObit
[2013/03/25 19:51:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit
[2013/03/25 12:18:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/03/21 14:01:58 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usb8023.sys
[2013/03/14 10:54:42 | 000,174,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2013/03/14 10:54:42 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/03/14 10:54:42 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/03/14 10:54:42 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/03/14 10:54:42 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/03/14 10:54:41 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/03/14 10:54:41 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/03/14 10:54:41 | 000,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/03/14 10:54:41 | 000,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/03/14 10:54:41 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/03/14 10:54:41 | 000,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/03/14 10:54:41 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/03/14 10:54:41 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/03/14 10:54:41 | 000,056,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/03/14 10:54:40 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/03/14 10:54:39 | 001,538,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/03/14 10:54:39 | 000,479,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/03/14 10:54:33 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/03/14 10:54:33 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/03/14 10:54:33 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/03/14 10:54:33 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/03/14 10:54:33 | 000,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/03/14 10:54:31 | 000,219,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/03/14 10:54:30 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/03/14 10:54:30 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/03/14 10:54:29 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/03/14 10:54:29 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/03/14 10:54:29 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/03/14 10:54:29 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2009/08/04 22:39:36 | 008,270,752 | —- | C] (Dell, Inc. ) – C:\Users\admin\AppData\Roaming\DataSafeDotNet.exe
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/03/29 08:46:51 | 000,000,828 | —- | M] () – C:\Users\admin\Desktop\OTL - Shortcut.lnk
[2013/03/29 08:39:31 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/03/29 08:24:00 | 000,000,928 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3805510809-3204643337-4127071045-1000UA.job
[2013/03/29 08:18:57 | 000,721,710 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/03/29 08:18:57 | 000,617,952 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/03/29 08:18:57 | 000,109,022 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/03/29 08:14:26 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/03/29 08:14:26 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/03/29 08:14:17 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/03/29 08:14:15 | 4251,828,224 | -HS- | M] () – C:\hiberfil.sys
[2013/03/28 20:24:02 | 000,000,906 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3805510809-3204643337-4127071045-1000Core.job
[2013/03/28 20:05:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/03/27 20:08:21 | 000,002,051 | —- | M] () – C:\Users\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/03/27 12:11:13 | 000,002,027 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/03/27 12:05:12 | 000,000,975 | —- | M] () – C:\Users\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/03/25 19:52:03 | 000,001,010 | —- | M] () – C:\Users\Public\Desktop\IObit Malware Fighter.lnk
[2013/03/25 12:18:28 | 000,000,950 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/03/19 14:46:42 | 000,035,328 | —- | M] () – C:\Users\admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/03/10 16:41:52 | 723,540,906 | —- | M] () – C:\Windows\MEMORY.DMP
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/03/29 08:46:50 | 000,000,828 | —- | C] () – C:\Users\admin\Desktop\OTL - Shortcut.lnk
[2013/03/27 12:18:57 | 000,000,528 | R— | C] () – C:\MediaID.bin
[2013/03/27 12:11:13 | 000,002,051 | —- | C] () – C:\Users\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/03/27 12:11:13 | 000,002,027 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/03/25 19:52:03 | 000,001,010 | —- | C] () – C:\Users\Public\Desktop\IObit Malware Fighter.lnk
[2013/03/25 12:18:28 | 000,000,950 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/03/10 16:41:52 | 723,540,906 | —- | C] () – C:\Windows\MEMORY.DMP
[2012/12/28 17:40:43 | 000,000,065 | —- | C] () – C:\Windows\minitab.ini
[2011/08/04 22:21:57 | 000,000,552 | —- | C] () – C:\Users\admin\AppData\Local\d3d8caps.dat
[2011/02/07 16:58:44 | 000,000,129 | —- | C] () – C:\Users\admin\AppData\Roaming\Statdisk.prefs
[2010/11/10 22:27:56 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2010/08/25 11:18:34 | 000,000,732 | —- | C] () – C:\Users\admin\AppData\Local\d3d9caps64.dat
[2009/08/13 08:43:24 | 000,006,080 | —- | C] () – C:\Users\admin\AppData\Local\d3d9caps.dat
[2009/08/05 18:56:23 | 000,035,328 | —- | C] () – C:\Users\admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2006/11/02 11:30:40 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 13:59:03 | 012,899,840 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 13:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/04/11 03:11:14 | 000,891,392 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 02:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2008/01/20 22:50:58 | 000,513,024 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: EXPLORER.EXE >
[2009/04/24 23:53:49 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_b5f700fe698beb14\explorer.exe
[2009/04/24 23:53:48 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_b7eb106e66a7ac19\explorer.exe
[2009/04/24 23:53:48 | 003,087,360 | —- | M] (Microsoft Corporation) MD5=50514057C28A74BAC2BD04B7B990D615 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_aba256ac352b2919\explorer.exe
[2009/04/24 23:53:47 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_b8583e9d7fda0512\explorer.exe
[2009/04/11 03:10:17 | 003,079,168 | —- | M] (Microsoft Corporation) MD5=6B08E54A451B3F95E4109DBA7E594270 – C:\Windows\explorer.exe
[2009/04/11 03:10:17 | 003,079,168 | —- | M] (Microsoft Corporation) MD5=6B08E54A451B3F95E4109DBA7E594270 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_afbebba22f3bab41\explorer.exe
[2009/04/24 23:53:48 | 003,086,848 | —- | M] (Microsoft Corporation) MD5=72B9990E45C25AA3C75C4FB50A9D6CE0 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_ac5266dd4e2b0a41\explorer.exe
[2009/04/24 23:53:47 | 003,080,704 | —- | M] (Microsoft Corporation) MD5=BBD8E74F23D7605CB0CDB57A1B25D826 – C:\Windows\ERDNT\cache86\explorer.exe
[2009/04/24 23:53:47 | 003,080,704 | —- | M] (Microsoft Corporation) MD5=BBD8E74F23D7605CB0CDB57A1B25D826 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_ad96661c3246ea1e\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\SysWOW64\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_ba1365f4639c6d3c\explorer.exe
[2009/04/24 23:53:47 | 003,081,216 | —- | M] (Microsoft Corporation) MD5=E404A65EF890140410E9F3D405841C95 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_ae03944b4b794317\explorer.exe
[2009/04/24 23:53:48 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_b6a7112f828bcc3c\explorer.exe
[2008/01/20 22:48:44 | 003,080,704 | —- | M] (Microsoft Corporation) MD5=F6D765FB6B457542D954682F50C26E4F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_add342963219dff5\explorer.exe
[2008/01/20 22:49:23 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_b827ece8667aa1f0\explorer.exe
< MD5 for: SVCHOST.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2008/01/20 22:48:05 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\ERDNT\cache86\svchost.exe
[2008/01/20 22:48:05 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\SysWOW64\svchost.exe
[2008/01/20 22:48:05 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
[2008/01/20 22:50:24 | 000,027,648 | —- | M] (Microsoft Corporation) MD5=CDA9F1373805AF88F6FA4F2064BBA24D – C:\Windows\ERDNT\cache64\svchost.exe
[2008/01/20 22:50:24 | 000,027,648 | —- | M] (Microsoft Corporation) MD5=CDA9F1373805AF88F6FA4F2064BBA24D – C:\Windows\SysNative\svchost.exe
[2008/01/20 22:50:24 | 000,027,648 | —- | M] (Microsoft Corporation) MD5=CDA9F1373805AF88F6FA4F2064BBA24D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_11d9f524bdab2f1b\svchost.exe
< MD5 for: USERINIT.EXE >
[2008/01/20 22:50:36 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\ERDNT\cache86\userinit.exe
[2008/01/20 22:50:36 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\SysWOW64\userinit.exe
[2008/01/20 22:50:36 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2008/01/20 22:49:46 | 000,028,160 | —- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE – C:\Windows\ERDNT\cache64\userinit.exe
[2008/01/20 22:49:46 | 000,028,160 | —- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE – C:\Windows\SysNative\userinit.exe
[2008/01/20 22:49:46 | 000,028,160 | —- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_384755998a0d6941\userinit.exe
< MD5 for: WINLOGON.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/04/11 03:11:08 | 000,405,504 | —- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A – C:\Windows\SysNative\winlogon.exe
[2009/04/11 03:11:08 | 000,405,504 | —- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_cdcd15a68a70b877\winlogon.exe
[2008/01/20 22:49:47 | 000,406,016 | —- | M] (Microsoft Corporation) MD5=856491FCED98093D824B9EB2892F564A – C:\Windows\ERDNT\cache64\winlogon.exe
[2008/01/20 22:49:47 | 000,406,016 | —- | M] (Microsoft Corporation) MD5=856491FCED98093D824B9EB2892F564A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_cbe19c9a8d4eed2b\winlogon.exe
[2009/04/11 02:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\SysWOW64\winlogon.exe
[2009/04/11 02:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/20 22:50:38 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< %systemroot%\*. /rp /s >
========== Drive Information ==========
Physical Drives
—————
Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: WDC WD5000BEVT-75ZAT0 ATA Device
Partitions: 3
Status: OK
Status Info: 0
Partitions
—————
DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 39.00MB
Starting Offset: 32256
Hidden sectors: 0
DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 15.00GB
Starting Offset: 41126400
Hidden sectors: 0
DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 451.00GB
Starting Offset: 15769766400
Hidden sectors: 0
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\System32\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\System32\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\System32\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
========== Alternate Data Streams ==========
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:5D432CE3
< End of report >
OTL logfile created on: 3/29/2013 8:48:58 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\admin\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19401)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.96 Gb Total Physical Memory | 1.82 Gb Available Physical Memory | 45.87% Memory free
8.09 Gb Paging File | 5.57 Gb Available in Paging File | 68.84% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451.07 Gb Total Space | 307.35 Gb Free Space | 68.14% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 0.00 Gb Free Space | 0.01% Space Free | Partition Type: NTFS
Computer Name: JEREMYCOMPUTER | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/03/29 08:46:39 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\admin\Downloads\OTL.exe
PRC - [2012/12/25 17:35:10 | 004,474,832 | —- | M] (IObit) – C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe
PRC - [2012/12/14 16:49:28 | 000,682,344 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/12/14 16:49:28 | 000,512,360 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/12/14 16:49:28 | 000,398,184 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/07/14 21:19:18 | 000,138,096 | —- | M] (Facebook Inc.) – C:\Users\admin\AppData\Local\Facebook\Update\FacebookUpdate.exe
PRC - [2012/06/21 06:01:58 | 000,092,632 | —- | M] (TomTom) – C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2012/06/21 06:01:56 | 000,247,768 | —- | M] (TomTom) – C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2012/06/15 22:24:19 | 000,138,272 | R— | M] (Symantec Corporation) – C:\Program Files (x86)\Norton 360\Engine\6.4.1.14\ccsvchst.exe
PRC - [2012/06/11 17:22:16 | 000,240,208 | —- | M] (Microsoft Corporation.) – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE
PRC - [2012/01/09 20:17:44 | 000,821,592 | —- | M] (IObit) – C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
PRC - [2011/01/17 19:37:40 | 011,322,880 | —- | M] (OpenOffice.org) – C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
PRC - [2011/01/17 19:37:40 | 011,314,688 | —- | M] (OpenOffice.org) – C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
PRC - [2009/07/07 10:23:00 | 001,779,952 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
PRC - [2009/04/13 10:50:14 | 000,497,496 | —- | M] (Dell Inc.) – C:\Program Files (x86)\Dell Remote Access\ezi_ra.exe
PRC - [2009/04/13 10:48:12 | 000,828,656 | —- | M] (Dell Inc.) – c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
PRC - [2009/02/04 22:26:38 | 000,128,232 | —- | M] (CyberLink Corp.) – C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
PRC - [2008/12/18 15:05:28 | 000,155,648 | —- | M] (Stardock Corporation) – C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2008/12/18 00:27:22 | 004,823,928 | —- | M] (Dell Inc. and SightSpeed Inc.) – C:\Program Files (x86)\Dell Video Chat\DellVideoChat.exe
PRC - [2008/03/20 00:49:42 | 000,025,840 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtmsdmon.exe
PRC - [2008/03/20 00:49:10 | 000,668,912 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtmon.exe
PRC - [2007/03/29 16:41:26 | 000,222,128 | —- | M] (Macrovision Corporation) – C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe
========== Modules (No Company Name) ==========
MOD - [2013/02/14 12:12:48 | 001,840,640 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\d186bf251ae14af93b3a943d472ee9f5\System.Web.Services.ni.dll
MOD - [2013/02/14 12:03:05 | 012,433,920 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\e64304962098e90f0d3f4c33c1b080a6\System.Windows.Forms.ni.dll
MOD - [2013/01/10 18:22:10 | 000,998,400 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\f042f66c2ad8fd5b8c34fa22cd22079e\System.Management.ni.dll
MOD - [2013/01/10 17:15:21 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\0525305cfa7fc1437348559b7af5003a\System.Configuration.ni.dll
MOD - [2013/01/10 17:02:56 | 005,450,752 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\b757806657fa5db2b1ed1a89b026b463\System.Xml.ni.dll
MOD - [2013/01/10 17:02:06 | 001,593,856 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\78157a494dc9a7e52be8840decfcd9cc\System.Drawing.ni.dll
MOD - [2013/01/10 17:00:10 | 007,977,984 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\cc149d08e75f8c53cd28ac926b38c370\System.ni.dll
MOD - [2013/01/10 16:52:41 | 011,492,352 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\2227d1559f87943255069398608d5c56\mscorlib.ni.dll
MOD - [2011/01/31 16:13:51 | 000,985,088 | —- | M] () – C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
MOD - [2009/07/07 10:24:00 | 000,268,528 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Online\SdbShared.dll
MOD - [2009/07/07 10:24:00 | 000,140,528 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Online\SdbShared.XmlSerializers.dll
MOD - [2009/07/07 10:24:00 | 000,095,472 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Online\SdbUI.dll
MOD - [2009/07/07 10:23:00 | 001,779,952 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
MOD - [2009/07/07 10:23:00 | 000,017,648 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Online\CppUtils.dll
MOD - [2009/04/09 17:29:00 | 000,058,608 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Online\BalloonWindow.dll
MOD - [2008/12/18 00:24:14 | 006,510,416 | —- | M] () – C:\Program Files (x86)\Dell Video Chat\QtGui4.dll
MOD - [2008/12/18 00:24:14 | 001,657,168 | —- | M] () – C:\Program Files (x86)\Dell Video Chat\QtCore4.dll
MOD - [2008/12/18 00:24:14 | 000,396,112 | —- | M] () – C:\Program Files (x86)\Dell Video Chat\QtOpenGL4.dll
MOD - [2008/12/18 00:24:14 | 000,366,928 | —- | M] () – C:\Program Files (x86)\Dell Video Chat\QtNetwork4.dll
MOD - [2008/12/18 00:24:14 | 000,027,472 | —- | M] () – C:\Program Files (x86)\Dell Video Chat\SDL.dll
MOD - [2008/03/20 00:49:42 | 000,025,840 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtmsdmon.exe
MOD - [2008/03/20 00:49:10 | 000,668,912 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtmon.exe
MOD - [2008/03/18 18:05:06 | 000,782,336 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtdrs.dll
MOD - [2008/03/18 18:04:20 | 000,380,928 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtscw.dll
MOD - [2008/02/19 18:25:56 | 000,081,920 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtcaps.dll
MOD - [2008/02/19 18:18:58 | 000,151,552 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtmonr.dll
MOD - [2008/02/19 09:05:38 | 000,036,864 | —- | M] () – C:\Program Files (x86)\Dell V305\app4r.monitor.core.dll
MOD - [2008/02/19 09:05:38 | 000,028,672 | —- | M] () – C:\Program Files (x86)\Dell V305\app4r.monitor.common.dll
MOD - [2008/02/19 09:04:38 | 000,061,440 | —- | M] () – C:\Program Files (x86)\Dell V305\app4r.devmons.mcmdevmon.dll
MOD - [2008/01/21 22:05:12 | 000,077,906 | —- | M] () – C:\Program Files (x86)\Dell V305\DLDTcfg.dll
MOD - [2007/11/22 04:55:48 | 000,011,776 | —- | M] () – C:\Program Files (x86)\Dell V305\app4r.devmons.mcmdevmon.autoplayutil.dll
MOD - [2007/11/13 15:13:10 | 000,069,632 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtcnv4.dll
MOD - [2007/05/29 03:39:08 | 000,589,824 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtdatr.dll
MOD - [2007/03/26 03:39:36 | 000,073,728 | —- | M] () – C:\Program Files (x86)\Dell V305\dldtcats.dll
========== Services (SafeList) ==========
SRV:64bit: - [2009/07/09 19:48:28 | 000,033,448 | —- | M] () [Auto | Running] – C:\Windows\SysNative\spool\DRIVERS\x64\3\\dldtserv.exe – (dldtCATSCustConnectService)
SRV:64bit: - [2009/03/19 12:26:10 | 000,268,288 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_15f4e438\STacSV64.exe – (STacSV)
SRV:64bit: - [2009/03/19 12:25:42 | 000,089,600 | —- | M] (Andrea Electronics Corporation) [Auto | Running] – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_15f4e438\AESTSr64.exe – (AESTFilters)
SRV:64bit: - [2008/12/18 15:05:28 | 000,155,648 | —- | M] (Stardock Corporation) [Auto | Running] – C:\Program Files\Dell\DellDock\DockLogin.exe – (DockLoginService)
SRV:64bit: - [2008/02/25 12:38:24 | 001,045,232 | —- | M] ( ) [Auto | Running] – C:\Windows\SysNative\dldtcoms.exe – (dldt_device)
SRV:64bit: - [2008/01/20 22:47:32 | 000,383,544 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2012/12/14 16:49:28 | 000,682,344 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/12/14 16:49:28 | 000,398,184 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012/07/13 14:28:36 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012/06/21 06:01:58 | 000,092,632 | —- | M] (TomTom) [Auto | Running] – C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe – (TomTomHOMEService)
SRV - [2012/06/15 22:24:19 | 000,138,272 | R— | M] (Symantec Corporation) [Auto | Running] – C:\Program Files (x86)\Norton 360\Engine\6.4.1.14\ccSvcHst.exe – (N360)
SRV - [2012/06/11 17:22:16 | 000,240,208 | —- | M] (Microsoft Corporation.) [On_Demand | Running] – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE – (BBUpdate)
SRV - [2012/06/11 17:22:16 | 000,193,616 | —- | M] (Microsoft Corporation.) [Auto | Stopped] – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.EXE – (BBSvc)
SRV - [2012/01/09 20:17:44 | 000,821,592 | —- | M] (IObit) [Auto | Running] – C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe – (IMFservice)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/08/06 22:17:05 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe – (GoToAssist)
SRV - [2009/07/09 19:48:28 | 000,033,448 | —- | M] () [Auto | Running] – C:\Windows\system32\spool\DRIVERS\x64\3\\dldtserv.exe – (dldtCATSCustConnectService)
SRV - [2009/04/13 10:48:12 | 000,828,656 | —- | M] (Dell Inc.) [Auto | Running] – c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe – (hnmsvc)
SRV - [2009/03/30 00:42:14 | 000,066,368 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2008/02/25 12:38:12 | 000,595,184 | —- | M] ( ) [Auto | Running] – C:\Windows\SysWOW64\dldtcoms.exe – (dldt_device)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012/12/14 16:49:28 | 000,024,176 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2012/08/09 18:06:14 | 000,175,736 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\SYMEVENT64x86.SYS – (SymEvent)
DRV:64bit: - [2012/07/05 22:17:58 | 000,037,536 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\N360x64\0604010.00E\SRTSPX64.SYS – (SRTSPX)
DRV:64bit: - [2012/07/05 22:17:57 | 000,737,952 | —- | M] (Symantec Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\Drivers\N360x64\0604010.00E\SRTSP64.SYS – (SRTSP)
DRV:64bit: - [2012/06/07 00:43:38 | 000,167,072 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\N360x64\0604010.00E\ccSetx64.sys – (ccSet_N360)
DRV:64bit: - [2012/05/21 21:37:12 | 001,129,120 | —- | M] (Symantec Corporation) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\N360x64\0604010.00E\SYMEFA64.SYS – (SymEFA)
DRV:64bit: - [2012/03/29 02:28:38 | 000,445,560 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\Drivers\N360x64\0604010.00E\SYMTDIV.SYS – (SYMTDIv)
DRV:64bit: - [2012/03/29 02:28:25 | 000,451,192 | R— | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\N360x64\0604010.00E\SYMDS64.SYS – (SymDS)
DRV:64bit: - [2012/03/29 02:06:25 | 000,190,072 | R— | M] (Symantec Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\N360x64\0604010.00E\Ironx64.SYS – (SymIRON)
DRV:64bit: - [2012/02/29 09:52:46 | 000,016,384 | —- | M] (Microsoft Corporation) [Recognizer | System | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/02/11 19:16:38 | 010,628,640 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\igdkmd64.sys – (igfx)
DRV:64bit: - [2010/07/21 04:40:20 | 000,010,112 | —- | M] (support.com, Inc) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\ssmirrdr.sys – (ssmirrdr)
DRV:64bit: - [2009/09/16 10:22:40 | 000,049,480 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mfesmfk.sys – (mfesmfk)
DRV:64bit: - [2009/09/16 10:15:38 | 000,040,904 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mferkdk.sys – (mferkdk)
DRV:64bit: - [2009/05/06 17:03:00 | 000,313,696 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\OA008Vid.sys – (OA008Vid)
DRV:64bit: - [2009/05/03 23:32:16 | 000,035,840 | R— | M] (Avanquest Software) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\BVRPMPR5a64.SYS – (BVRPMPR5a64)
DRV:64bit: - [2009/04/11 01:03:32 | 000,111,104 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\sdbus.sys – (sdbus)
DRV:64bit: - [2009/03/19 16:34:18 | 000,029,544 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2009/03/19 12:26:24 | 000,477,696 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\stwrt64.sys – (STHDA)
DRV:64bit: - [2009/03/12 12:47:46 | 000,172,160 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\CtClsFlt.sys – (CtClsFlt)
DRV:64bit: - [2009/03/06 07:33:58 | 000,159,840 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\OA008Ufd.sys – (OA008Ufd)
DRV:64bit: - [2008/12/21 13:26:28 | 004,735,488 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\NETw5v64.sys – (NETw5v64)
DRV:64bit: - [2008/12/19 22:24:48 | 000,041,032 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mfebopk.sys – (mfebopk)
DRV:64bit: - [2008/11/25 11:08:48 | 000,126,464 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcHdmi.sys – (IntcHdmiAddService)
DRV:64bit: - [2008/11/25 10:56:58 | 000,261,680 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\SynTP.sys – (SynTP)
DRV:64bit: - [2008/10/07 13:49:52 | 000,252,928 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\k57nd60a.sys – (k57nd60a)
DRV:64bit: - [2008/09/15 13:11:04 | 000,057,856 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\SysNative\DRIVERS\rixdpx64.sys – (rismxdp)
DRV:64bit: - [2008/09/15 13:11:00 | 000,062,976 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\SysNative\DRIVERS\rimmpx64.sys – (rimmptsk)
DRV:64bit: - [2008/09/15 13:10:58 | 000,055,296 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\SysNative\DRIVERS\rimspx64.sys – (rimsptsk)
DRV:64bit: - [2008/06/18 18:48:54 | 000,029,184 | —- | M] (SingleClick Systems) [Kernel | Auto | Running] – C:\Windows\SysNative\DRIVERS\packet.sys – (Packet)
DRV:64bit: - [2008/01/20 22:46:55 | 000,317,952 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\e1e6032e.sys – (e1express)
DRV:64bit: - [2007/11/14 04:00:00 | 000,053,488 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2006/11/02 03:48:50 | 002,488,320 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\atikmdag.sys – (R300)
DRV - [2013/03/21 21:52:21 | 001,387,608 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\BASHDefs\20130322.001\BHDrvx64.sys – (BHDrvx64)
DRV - [2013/01/19 16:51:51 | 002,087,664 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\VirusDefs\20130328.025\ex64.sys – (NAVEX15)
DRV - [2013/01/19 16:51:51 | 000,126,192 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\VirusDefs\20130328.025\eng64.sys – (NAVENG)
DRV - [2013/01/05 20:48:20 | 000,484,512 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys – (eeCtrl)
DRV - [2012/08/31 20:27:23 | 000,513,184 | —- | M] (Symantec Corporation) [Kernel | System | Running] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\Definitions\IPSDefs\20130328.001\IDSviA64.sys – (IDSVia64)
DRV - [2012/08/09 21:40:25 | 000,138,912 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Running] – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2012/07/05 13:53:42 | 000,021,904 | —- | M] (IObit.com) [Kernel | On_Demand | Running] – C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\wlh_amd64\UrlFilter.sys – (UrlFilter)
DRV - [2012/07/05 13:53:40 | 000,033,224 | —- | M] (IObit.com) [Kernel | On_Demand | Running] – C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\wlh_amd64\RegFilter.sys – (RegFilter)
DRV - [2012/01/05 18:07:24 | 000,021,384 | —- | M] (IObit) [File_System | On_Demand | Running] – C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\wlh_amd64\FileMonitor.sys – (FileMonitor)
DRV - [2008/06/17 13:01:06 | 000,022,016 | —- | M] (SingleClick Systems) [Kernel | Auto | Running] – C:\Windows\SysWOW64\drivers\packet.sys – (Packet)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://searchou.com/?affil=7&uid=37aef…3a-002219fcc2e0
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{A05A25E8-7D80-44AA-A94A-A54493F11DAD}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8893
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8893
IE - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://searchou.com/?affil=7&uid=37aef…3a-002219fcc2e0
IE - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://searchou.com/?affil=7&uid=37aef…q={searchTerms}
IE - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\..\SearchScopes\{A05A25E8-7D80-44AA-A94A-A54493F11DAD}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?q={SEARCHTERMS}&…b&qsrc=2869
IE - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledAddons: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8442
FF - prefs.js..extensions.enabledAddons: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:11.1.1.5 - 3
FF - prefs.js..browser.startup.homepage: "http://searchou.com/?affil=7&uid=37aef630-f51f-11e1-9b3a-002219fcc2e0"
FF - prefs.js..browser.search.defaultenginename: "Privitize VPN"
FF - prefs.js..browser.search.defaultengine: "Privitize VPN"
FF - prefs.js..browser.search.order.1: "Privitize VPN"
FF - prefs.js..browser.search.selectedEngine: "Privitize VPN"
FF - prefs.js..keyword.URL: "http://searchou.com/?affil=7&uid=37aef630-f51f-11e1-9b3a-002219fcc2e0&q="
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_171.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\admin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\IPSFFPlgn\ [2012/08/09 18:07:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\coFFPlgn\ [2013/03/29 08:17:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/05/04 12:53:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/04 12:53:50 | 000,000,000 | —D | M]
[2012/08/05 17:31:27 | 000,000,000 | —D | M] (No name found) – C:\Users\admin\AppData\Roaming\Mozilla\Extensions
[2012/08/05 17:31:27 | 000,000,000 | —D | M] (No name found) – C:\Users\admin\AppData\Roaming\Mozilla\Extensions\[removed]
[2013/03/17 20:11:50 | 000,002,090 | —- | M] () – C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjqu125v.default\searchplugins\Searchou.xml
[2012/01/12 18:02:22 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/01/12 18:02:25 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/01/31 16:11:19 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/17 16:39:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/04/15 16:19:49 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2012/08/09 18:07:19 | 000,000,000 | —D | M] (Norton Vulnerability Protection) – C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.1.5\IPSFFPLGN
[2009/08/04 22:22:22 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/03/18 13:53:24 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/04/14 14:01:38 | 000,024,376 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
========== Chrome ==========
CHR - default_search_provider: Privitize VPN (Enabled)
CHR - default_search_provider: search_url = http://searchou.com/?affil=7&uid=37aef…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.43\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.43\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.43\pdf.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Adobe Acrobat (Enabled) = c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\admin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Google Docs = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Skype Click to Call = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\
CHR - Extension: Norton Identity Protection = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.11.8_0\
CHR - Extension: Gmail = C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2011/01/17 15:45:37 | 000,428,637 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14760 more lines…
O2:64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL File not found
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll File not found
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\6.4.1.14\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\6.4.1.14\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\6.4.1.14\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\6.4.1.14\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [dldtamon] C:\Program Files (x86)\Dell V305\dldtamon.exe ()
O4:64bit: - HKLM..\Run: [dldtmon.exe] C:\Program Files (x86)\Dell V305\dldtmon.exe ()
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [IObit Malware Fighter] C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (IObit)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000..\Run: [Facebook Update] C:\Users\admin\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000..\Run: [ISUSPM] C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe (Macrovision Corporation)
O4 - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000..\Run: [SightSpeed] C:\Program Files (x86)\Dell Video Chat\DellVideoChat.exe (Dell Inc. and SightSpeed Inc.)
O4 - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000..\Run: [TomTomHOME.exe] C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled [2010/08/25 12:42:15 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O4 - Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3805510809-3204643337-4127071045-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8F1D1C59-370F-4EBA-8687-D35FC1FD513D}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A5A852AC-3CA6-436B-B74A-B6170ED61A59}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\belarc - No CLSID value found
O18:64bit: - Protocol\Handler\gopher - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\admin\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\admin\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28:64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/03/27 12:17:53 | 000,000,000 | —D | C] – C:\JEREMYCOMPUTER
[2013/03/27 12:17:39 | 000,000,000 | —D | C] – C:\Tools
[2013/03/27 12:17:39 | 000,000,000 | —D | C] – C:\sources
[2013/03/27 12:11:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/03/25 19:52:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
[2013/03/25 19:51:55 | 000,000,000 | —D | C] – C:\ProgramData\IObit
[2013/03/25 19:51:54 | 000,000,000 | —D | C] – C:\Users\admin\AppData\Roaming\IObit
[2013/03/25 19:51:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit
[2013/03/25 12:18:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/03/21 14:01:58 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usb8023.sys
[2013/03/14 10:54:42 | 000,174,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2013/03/14 10:54:42 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/03/14 10:54:42 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/03/14 10:54:42 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/03/14 10:54:42 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/03/14 10:54:41 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/03/14 10:54:41 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/03/14 10:54:41 | 000,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/03/14 10:54:41 | 000,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/03/14 10:54:41 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/03/14 10:54:41 | 000,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/03/14 10:54:41 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/03/14 10:54:41 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/03/14 10:54:41 | 000,056,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/03/14 10:54:40 | 000,743,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/03/14 10:54:39 | 001,538,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/03/14 10:54:39 | 000,479,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/03/14 10:54:33 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/03/14 10:54:33 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/03/14 10:54:33 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/03/14 10:54:33 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/03/14 10:54:33 | 000,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/03/14 10:54:31 | 000,219,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/03/14 10:54:30 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/03/14 10:54:30 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/03/14 10:54:29 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/03/14 10:54:29 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/03/14 10:54:29 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/03/14 10:54:29 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2009/08/04 22:39:36 | 008,270,752 | —- | C] (Dell, Inc. ) – C:\Users\admin\AppData\Roaming\DataSafeDotNet.exe
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/03/29 08:46:51 | 000,000,828 | —- | M] () – C:\Users\admin\Desktop\OTL - Shortcut.lnk
[2013/03/29 08:39:31 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/03/29 08:24:00 | 000,000,928 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3805510809-3204643337-4127071045-1000UA.job
[2013/03/29 08:18:57 | 000,721,710 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/03/29 08:18:57 | 000,617,952 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/03/29 08:18:57 | 000,109,022 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/03/29 08:14:26 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/03/29 08:14:26 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/03/29 08:14:17 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/03/29 08:14:15 | 4251,828,224 | -HS- | M] () – C:\hiberfil.sys
[2013/03/28 20:24:02 | 000,000,906 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3805510809-3204643337-4127071045-1000Core.job
[2013/03/28 20:05:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/03/27 20:08:21 | 000,002,051 | —- | M] () – C:\Users\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/03/27 12:11:13 | 000,002,027 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/03/27 12:05:12 | 000,000,975 | —- | M] () – C:\Users\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/03/25 19:52:03 | 000,001,010 | —- | M] () – C:\Users\Public\Desktop\IObit Malware Fighter.lnk
[2013/03/25 12:18:28 | 000,000,950 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/03/19 14:46:42 | 000,035,328 | —- | M] () – C:\Users\admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/03/10 16:41:52 | 723,540,906 | —- | M] () – C:\Windows\MEMORY.DMP
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/03/29 08:46:50 | 000,000,828 | —- | C] () – C:\Users\admin\Desktop\OTL - Shortcut.lnk
[2013/03/27 12:18:57 | 000,000,528 | R— | C] () – C:\MediaID.bin
[2013/03/27 12:11:13 | 000,002,051 | —- | C] () – C:\Users\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/03/27 12:11:13 | 000,002,027 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/03/25 19:52:03 | 000,001,010 | —- | C] () – C:\Users\Public\Desktop\IObit Malware Fighter.lnk
[2013/03/25 12:18:28 | 000,000,950 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/03/10 16:41:52 | 723,540,906 | —- | C] () – C:\Windows\MEMORY.DMP
[2012/12/28 17:40:43 | 000,000,065 | —- | C] () – C:\Windows\minitab.ini
[2011/08/04 22:21:57 | 000,000,552 | —- | C] () – C:\Users\admin\AppData\Local\d3d8caps.dat
[2011/02/07 16:58:44 | 000,000,129 | —- | C] () – C:\Users\admin\AppData\Roaming\Statdisk.prefs
[2010/11/10 22:27:56 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2010/08/25 11:18:34 | 000,000,732 | —- | C] () – C:\Users\admin\AppData\Local\d3d9caps64.dat
[2009/08/13 08:43:24 | 000,006,080 | —- | C] () – C:\Users\admin\AppData\Local\d3d9caps.dat
[2009/08/05 18:56:23 | 000,035,328 | —- | C] () – C:\Users\admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2006/11/02 11:30:40 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 13:59:03 | 012,899,840 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 13:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/04/11 03:11:14 | 000,891,392 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 02:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2008/01/20 22:50:58 | 000,513,024 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: EXPLORER.EXE >
[2009/04/24 23:53:49 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_b5f700fe698beb14\explorer.exe
[2009/04/24 23:53:48 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_b7eb106e66a7ac19\explorer.exe
[2009/04/24 23:53:48 | 003,087,360 | —- | M] (Microsoft Corporation) MD5=50514057C28A74BAC2BD04B7B990D615 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_aba256ac352b2919\explorer.exe
[2009/04/24 23:53:47 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_b8583e9d7fda0512\explorer.exe
[2009/04/11 03:10:17 | 003,079,168 | —- | M] (Microsoft Corporation) MD5=6B08E54A451B3F95E4109DBA7E594270 – C:\Windows\explorer.exe
[2009/04/11 03:10:17 | 003,079,168 | —- | M] (Microsoft Corporation) MD5=6B08E54A451B3F95E4109DBA7E594270 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_afbebba22f3bab41\explorer.exe
[2009/04/24 23:53:48 | 003,086,848 | —- | M] (Microsoft Corporation) MD5=72B9990E45C25AA3C75C4FB50A9D6CE0 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_ac5266dd4e2b0a41\explorer.exe
[2009/04/24 23:53:47 | 003,080,704 | —- | M] (Microsoft Corporation) MD5=BBD8E74F23D7605CB0CDB57A1B25D826 – C:\Windows\ERDNT\cache86\explorer.exe
[2009/04/24 23:53:47 | 003,080,704 | —- | M] (Microsoft Corporation) MD5=BBD8E74F23D7605CB0CDB57A1B25D826 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_ad96661c3246ea1e\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\SysWOW64\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_ba1365f4639c6d3c\explorer.exe
[2009/04/24 23:53:47 | 003,081,216 | —- | M] (Microsoft Corporation) MD5=E404A65EF890140410E9F3D405841C95 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_ae03944b4b794317\explorer.exe
[2009/04/24 23:53:48 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_b6a7112f828bcc3c\explorer.exe
[2008/01/20 22:48:44 | 003,080,704 | —- | M] (Microsoft Corporation) MD5=F6D765FB6B457542D954682F50C26E4F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_add342963219dff5\explorer.exe
[2008/01/20 22:49:23 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_b827ece8667aa1f0\explorer.exe
< MD5 for: SVCHOST.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2008/01/20 22:48:05 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\ERDNT\cache86\svchost.exe
[2008/01/20 22:48:05 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\SysWOW64\svchost.exe
[2008/01/20 22:48:05 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
[2008/01/20 22:50:24 | 000,027,648 | —- | M] (Microsoft Corporation) MD5=CDA9F1373805AF88F6FA4F2064BBA24D – C:\Windows\ERDNT\cache64\svchost.exe
[2008/01/20 22:50:24 | 000,027,648 | —- | M] (Microsoft Corporation) MD5=CDA9F1373805AF88F6FA4F2064BBA24D – C:\Windows\SysNative\svchost.exe
[2008/01/20 22:50:24 | 000,027,648 | —- | M] (Microsoft Corporation) MD5=CDA9F1373805AF88F6FA4F2064BBA24D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_11d9f524bdab2f1b\svchost.exe
< MD5 for: USERINIT.EXE >
[2008/01/20 22:50:36 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\ERDNT\cache86\userinit.exe
[2008/01/20 22:50:36 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\SysWOW64\userinit.exe
[2008/01/20 22:50:36 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2008/01/20 22:49:46 | 000,028,160 | —- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE – C:\Windows\ERDNT\cache64\userinit.exe
[2008/01/20 22:49:46 | 000,028,160 | —- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE – C:\Windows\SysNative\userinit.exe
[2008/01/20 22:49:46 | 000,028,160 | —- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_384755998a0d6941\userinit.exe
< MD5 for: WINLOGON.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/04/11 03:11:08 | 000,405,504 | —- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A – C:\Windows\SysNative\winlogon.exe
[2009/04/11 03:11:08 | 000,405,504 | —- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_cdcd15a68a70b877\winlogon.exe
[2008/01/20 22:49:47 | 000,406,016 | —- | M] (Microsoft Corporation) MD5=856491FCED98093D824B9EB2892F564A – C:\Windows\ERDNT\cache64\winlogon.exe
[2008/01/20 22:49:47 | 000,406,016 | —- | M] (Microsoft Corporation) MD5=856491FCED98093D824B9EB2892F564A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_cbe19c9a8d4eed2b\winlogon.exe
[2009/04/11 02:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\SysWOW64\winlogon.exe
[2009/04/11 02:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/20 22:50:38 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< %systemroot%\*. /rp /s >
========== Drive Information ==========
Physical Drives
—————
Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: WDC WD5000BEVT-75ZAT0 ATA Device
Partitions: 3
Status: OK
Status Info: 0
Partitions
—————
DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 39.00MB
Starting Offset: 32256
Hidden sectors: 0
DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 15.00GB
Starting Offset: 41126400
Hidden sectors: 0
DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 451.00GB
Starting Offset: 15769766400
Hidden sectors: 0
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\System32\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\System32\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\System32\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
========== Alternate Data Streams ==========
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:5D432CE3
< End of report >
Chamby
Here is the Extras.Txt
OTL Extras logfile created on: 3/29/2013 8:48:58 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\admin\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19401)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.96 Gb Total Physical Memory | 1.82 Gb Available Physical Memory | 45.87% Memory free
8.09 Gb Paging File | 5.57 Gb Available in Paging File | 68.84% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451.07 Gb Total Space | 307.35 Gb Free Space | 68.14% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 0.00 Gb Free Space | 0.01% Space Free | Partition Type: NTFS
Computer Name: JEREMYCOMPUTER | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_USERS\S-1-5-21-3805510809-3204643337-4127071045-1000\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = 5A B5 47 12 96 B6 CB 01 [binary data]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{26471E12-D007-40FB-BCA8-5D7E33EA58F9}" = lport=37674 | protocol=17 | dir=in | name=oovoo udp port 37674 |
"{299186B6-FA78-458A-BEA2-09E0B7E8918A}" = rport=445 | protocol=6 | dir=out | app=system |
"{38F39F6F-A739-4FF3-9735-B4A608DE8B4C}" = rport=139 | protocol=6 | dir=out | app=system |
"{3C821A84-CB77-4B99-BFAB-49FBE7A1D82A}" = rport=137 | protocol=17 | dir=out | app=system |
"{41CCCF58-7E8D-49D2-AB72-55CAA91D739A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{568FF856-6327-4A31-BBC5-4BF83A0E0652}" = lport=37674 | protocol=6 | dir=in | name=oovoo tcp port 37674 |
"{5B543684-7FB4-40B3-AA10-BB4A7754FFA6}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{5BCE40CE-F93A-4127-82F5-73019A8455A5}" = lport=443 | protocol=17 | dir=in | name=oovoo udp port 443 |
"{5EE5D3B3-6F2C-4DF7-845A-B0379A7B4DE6}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{67F03A4D-E0E9-460D-A433-61F996CC25B8}" = lport=443 | protocol=6 | dir=in | name=oovoo tcp port 443 |
"{6A183C0B-B58C-43E8-B0DF-A32C5987A0CB}" = lport=137 | protocol=17 | dir=in | app=system |
"{6B588953-22D3-4DE2-ACA1-69E07FF4175D}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=c:\windows\system32\svchost.exe |
"{6C73C84D-BF4A-4AED-96AB-81303671A032}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{74FAC798-5761-4051-B1C6-2EA5357933F0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{7931CBD5-1D8A-4098-9E5B-4F8607458965}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=c:\windows\system32\svchost.exe |
"{7A6C0863-6036-4C8C-B994-D6C2B21AB61A}" = lport=37675 | protocol=17 | dir=in | name=oovoo udp port 37675 |
"{905E937A-8CDB-4240-9E52-05C9383D9305}" = lport=138 | protocol=17 | dir=in | app=system |
"{90BBEEF9-94F3-480B-A07B-722DDAE338C7}" = lport=445 | protocol=6 | dir=in | app=system |
"{934C4AD2-3406-4C8D-A560-C245A6BE5C4C}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=c:\windows\system32\svchost.exe |
"{A7B9DDEE-90E3-4BBA-A04F-CE0458F6D519}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{BAD9473F-0107-4A01-8EC2-DC7353F4E811}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{D97EF175-5D4A-4722-96E2-CE9909FAFE38}" = lport=139 | protocol=6 | dir=in | app=system |
"{D9D2CE13-602D-4E0F-B467-7D8AE78152AE}" = lport=2869 | protocol=6 | dir=in | app=system |
"{DD4B4A99-758C-4251-B9EC-D349D40A5C8C}" = rport=138 | protocol=17 | dir=out | app=system |
"{DFBD745F-1846-4F14-8EF0-5CE6BF017252}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=c:\windows\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0025C536-DD32-49DE-869D-A6F5BDCD293D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{00271B36-2583-4EB5-87AB-C55B6461FE15}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{01B9384E-F6CB-4917-8B58-AE44AAD609AF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{01E14BDD-0B46-4469-8654-FEB15C24DD54}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{08FF2C01-6045-44EC-BF91-4A7D163BAF69}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0A5F9C56-7930-43EB-8EA1-764DB72407E1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0DA16BFC-202D-49AE-B77A-6A04F2629566}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0F292295-28A6-46EB-B5F7-DF59F8EAAEB6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0FACC609-34C8-4BA2-B15C-E4ABB80128B5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{107FDB13-4262-4373-85EE-EC515BAF7D44}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1194553A-A747-4912-A98C-C7DF704B5FCF}" = protocol=17 | dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe |
"{11AE9032-219A-40FC-B7B1-D3FC2CFD83C5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{12AB6BCA-CC9D-4B58-855F-A6C2BF8F8A96}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{12DCBE51-687E-4AA8-9713-8AEAEC1F6452}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{12E78EA7-7444-449F-A10B-7591E7B4247D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{16C6968C-9820-40E5-BF2F-E77E04B8D3A1}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldtwbgw.exe |
"{178E94A7-4243-435B-B19F-45FE7C53346E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{184BC4D8-10D2-43A0-82CF-3ECB1CEF962F}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{188872C3-9632-4C68-9825-A86305BBC658}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{19B34B8A-9475-42B7-AAD2-7EC4EDFF0CB6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{19F8176A-41CD-4EA6-B83E-D21029D33833}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\dell\vlc\vlc.exe |
"{1A14F9D1-68DB-4428-8E74-699A3B976D16}" = protocol=17 | dir=in | app=c:\program files (x86)\dell v305\dldtmon.exe |
"{1A409B69-3A28-42EE-BB46-6C02270C90F9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1B546B07-7207-4F8D-8366-CD579E76F0BC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1BF2EF81-7968-4B29-9F12-E2C3D22F9683}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1C147B4B-A593-46AB-8E2F-F79CF6875110}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{1C8BA8DB-FFE7-479D-AE2A-0169DC85C5B2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1E79B0FC-678B-46C5-99EA-553C4F0A5743}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1E92F058-E4E7-4012-80D1-BA3187F99D29}" = protocol=6 | dir=in | app=c:\program files (x86)\dell v305\dldtamon.exe |
"{20EE9A19-1160-49D9-BF45-7D001BC8B12E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{2147CA76-D203-4376-8253-565D925BB9D4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{2243B7FF-23CE-4506-B253-FD4B706E9421}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{22B421C4-C3F5-400F-84DD-B78859781E5B}" = dir=in | app=c:\users\admin\appdata\local\facebook\video\skype\facebookvideocalling.exe |
"{24A26865-FEBC-4E4E-88AF-694D10D0A9C1}" = protocol=6 | dir=in | app=c:\program files (x86)\dell v305\dldttime.exe |
"{254C6FDA-D42D-403D-9265-A0604F540CB9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{259C096B-8246-47CF-8F48-55274DE7F231}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{25B154D6-0FE0-4E63-852A-BBE97CBAE55E}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{2747437B-89EB-4619-A81C-DD49BC55117E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{288129E5-8A32-437D-9079-1DD7558AFAAB}" = protocol=17 | dir=in | app=c:\windows\system32\dldtcfg.exe |
"{28B5F8C9-1DF4-4687-90E9-DE01817596D2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{293EE96F-2415-4A86-8CBD-AC53626B4954}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{2A7887BF-32CA-4BFF-A86F-5CABC7C74FAA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{2C44FE44-13FA-4516-874C-851075CDF1C2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{2EE65BB4-ECFD-43C8-89C7-2D93E4BFA685}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{2F278080-CED5-40C3-8862-69CB87AC2DC3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{311669CA-8D30-45FA-B04F-12FBA0430D4A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{31F3626B-C357-4896-A487-4AFF47AF8654}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{33574964-E15D-40CE-B337-6DD646FDBAC3}" = protocol=17 | dir=in | app=f:\stronghold2.exe |
"{338FAB12-A91B-4D52-83FC-9EDBBD2735DA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{339D9100-89ED-4CD0-B6C8-DB501DFDA91E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{33AA16C6-4862-4B0F-99E5-1B61F350DD7A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{34EFF262-B224-4DEF-A4FD-CF44FC7EC528}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3559B53A-C696-4DA7-98B6-6EEC2CFD86A9}" = protocol=6 | dir=in | app=f:\stronghold\stronghold2.exe |
"{355C1828-E920-4822-8B31-499C19136970}" = dir=in | app=c:\program files (x86)\common files\mcafee\mna\mcnasvc.exe |
"{36DE7666-1B71-4EEF-A23A-7C87954E99C6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3720756A-F2E9-41EE-A1BE-12869E85434C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{37375919-702C-4B5B-9FC7-41A2039F3863}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{37DC74F4-9159-4F50-9F10-80AA4DCF31C8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{38C64B91-8FCB-449D-937F-A0FD2D5C7229}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{394FFAE8-A7E5-4717-88B4-81AC932D1CA7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{39DDF35B-BEEA-4875-B449-63A282752E1C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3AF1E6E1-B7E3-4380-AAD2-F0413FDA63E0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3B79EE4C-A7AC-4856-8EB9-079948522771}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3BDD2D34-5575-4597-826F-81DDCC593B8C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3CDB9EA5-6E50-4867-9217-9F800611D7F1}" = protocol=17 | dir=in | app=c:\program files (x86)\dell v305\dldtlscn.exe |
"{3CF76885-CCB7-44BF-9DEC-8CBC8EB7372E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3E049224-8A9A-4560-98D9-B32F993C3F75}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3E20251F-8EA8-4258-A71B-B4CBE9D65AFA}" = protocol=6 | dir=in | app=c:\windows\syswow64\dldtcoms.exe |
"{40CCCB74-0157-4CD7-988C-BA64A95405A5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{417DB9A6-0A70-4F32-8E34-E97E2768375F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{41FB909E-873A-477B-B0F1-4DA421828944}" = protocol=6 | dir=in | app=c:\users\admin\appdata\local\temp\dldt\wireless\english\dldtwpss.exe |
"{4217FA51-0824-4C4A-82A9-2AD0731465E8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{426322C4-33A6-416E-B7E9-A532EF7A198B}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{446EAB1E-B3F8-4EDC-9DAA-9D9627200FE6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{44E075D6-F993-438A-B8D8-811CF639E62E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{46950B40-9BCB-453B-AE8E-0F98E3699A22}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{473B2391-6F77-42C4-8E5E-CCE6CE3A58B7}" = protocol=17 | dir=in | app=c:\program files (x86)\abbyy finereader 6.0 sprint\scan\scanman6.exe |
"{47646D9D-0854-43F1-9A67-46FB46158BE8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{47CCE082-04C5-4284-8F4B-759168BD0A24}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{485DE425-B160-4E4D-911F-D9F922DEB477}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{48E2654B-753B-4B5A-8C1C-8048E2EE4FF2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{49422A02-820C-45CA-8F9C-D16FBB394DDD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{49BF4433-2B5A-410E-B81E-9687579D2881}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{49DB6756-5A74-41CF-ADDD-5BBBE0716F26}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4AA59432-E525-463A-9F1F-4E4FA9620BF0}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{4B0AC1A6-0606-4BAC-889B-18113F465D40}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4BC6A701-02F0-4AD6-8079-7D7F0B018D5B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4BE451F6-1AF4-4386-A076-85A7D325C801}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4CC027D5-C561-4FE3-826C-3659FD91403C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4D44FCEC-AB0D-41CB-8D6F-DAF8FD3B99A3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4D62CD53-4A54-497D-AD3F-8092CAB42EAF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4DC06BE9-CFCB-46A7-AEE4-5F0B1CEA0305}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4DD0CD3B-E753-4B93-A5B1-C34E0B0A7787}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4E4B755F-70ED-40E1-A2D4-074EE5352834}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4EBE7B3D-2952-4FE7-AF01-1FC2C63EDB17}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{50ED2E56-5347-41CD-B2F8-A54E94F18319}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{53586142-B3D4-4E66-BBDC-469349F9242A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{5455590E-72BC-4EAC-9A96-6FBEC45F49D7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{55E0C8B3-02C6-4DCC-B3F5-70EC9AF725F8}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\dell\advanced networking service\hnm_svc.exe |
"{56F575F4-46CA-43C1-BC5E-AA730D7DD4D1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{57F86A22-A069-4D2C-8474-D75C0B047959}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{585A0F11-ED6F-4987-8134-C91EE71F7629}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{587FAEAB-9D8B-43C6-A83D-642161DCBAF1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{58D7A8F4-59F8-4DEB-A1E2-B3E6A398573C}" = protocol=17 | dir=in | app=c:\users\admin\appdata\local\temp\dldt\wireless\english\dldtwpss.exe |
"{5B39A13F-E85F-45F7-B9E0-7E4D315BB92B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{5DC550DA-C429-44D0-8FAF-EDFAE9E62853}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{5E9644F1-D9A8-48FD-A59E-86607AD41DF9}" = protocol=17 | dir=in | app=c:\windows\syswow64\dldtcoms.exe |
"{5F2FAD5F-74EB-446C-844D-4142863D651B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{620165D3-22FE-41B8-B436-5850D6344D64}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{62B23113-F26B-4DCA-906C-A38DC79C2182}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{64FF6A33-48BC-4EF2-83D0-4D445FDD8090}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{65004FBA-ECF7-44A2-A578-463082499BFE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{662FA537-B39C-42F8-90E6-A065BE1B78FB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{66734C66-F192-49D9-93EF-E45C8C1F2865}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{6A3692AD-5A4F-4316-A615-74CE491F3AEC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{6C3FABC8-9A4A-479A-B4EF-D410ABEFC178}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{6E7B3EDA-9D2E-4BEE-8510-611EB7A2110E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{6EEA77DE-2DE8-4C90-AC2C-E7F343E6A9B6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7018F996-C95D-410A-B815-0312BEACAC82}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{72885C92-5ECE-4EE7-B76E-42B345AFBB36}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{72FA63B9-6A69-47C4-AF5C-1B6C34B2002C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{734464E9-3FC4-428F-A83C-A8D1BC34D399}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{73CAC177-DDCD-4E16-B292-6FDED6AF63C6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{75F145AB-9E12-48F2-9D7D-7700F95A8C6D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{77C02DFA-64D4-4695-A1BC-7420FC50B896}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7848238B-2D2E-4E54-B039-7ECC07B32CF8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7888F390-A93D-47B7-A0AA-10DA56A5A4AD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{78A3DAFC-10BD-43CF-B8AA-999FFE7B80EF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{79881859-0D39-423A-8446-2E6F8030FF30}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{799EA43A-F820-4A13-8A05-17E4605929A4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7B7C6B80-76E7-4762-8C5F-D7CB89128B0C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7D4DD538-E302-4912-B03A-C2867F2B10EA}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldtpswx.exe |
"{7DB3A846-9B49-4956-9C7A-DEE118614E6E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7DCDE869-9951-4270-A103-491330E69B31}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7E6F4615-5F26-424B-8232-105110A42A7D}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{7EB4ED45-DD20-48A9-B80B-79CA93BF5AA6}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{7F55CD26-BA09-41A7-A022-2AC67FEB2E6B}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldtjswx.exe |
"{7F79F3FF-57DA-4A24-92EF-1EEDCC4A45F8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7F9473DD-3804-4578-8EC0-A6211504DEB2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7FA3E30F-871A-4C27-A2F8-317F95AEEFEB}" = protocol=6 | dir=in | app=c:\users\admin\appdata\local\google\chrome\application\chrome.exe |
"{809E4063-D3B7-4B55-AB7F-80AC70627160}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{812B3A98-2648-463F-ABF1-0BF33BF34752}" = protocol=6 | dir=in | app=c:\windows\system32\dldtcoms.exe |
"{81966A38-1632-48A9-ACD2-2ACD7178718B}" = protocol=6 | dir=in | app=c:\program files (x86)\dell remote access\ezi_ra.exe |
"{822471D1-C847-48E7-997F-C1045B0C7678}" = protocol=6 | dir=in | app=c:\program files (x86)\dell v305\dldtmon.exe |
"{82DC18CA-EC15-4AA0-BDF8-7C385F2703C7}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldttime.exe |
"{82F2E329-F6D0-4872-A652-B96903A6D876}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{83166ACC-8A9A-4EBE-928A-DCB4F406D669}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{831DDE04-FD20-4766-A09B-6DB02650667C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{836AA9C2-221D-4F70-8B32-AB9654DA572C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{8658CAC6-F52E-4F66-90CD-9571250783CD}" = dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{87A48A2F-EBB6-4025-88F0-99635DAB66C6}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{87D93C73-757C-492F-8250-2798D7C3DFE1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{88D553C2-A96E-4231-A427-BC62C70EF09F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{89840844-BA1B-4EB5-8F5A-831E91B56827}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{8A5821E2-1436-45A7-AD57-72E7AD4BDD49}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{8BF3D330-F67B-4C0D-94A9-06BEEF63E887}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{8C34BE48-DDB5-4D15-ACE5-619E25F6D958}" = protocol=17 | dir=in | app=c:\program files (x86)\dell v305\dldttime.exe |
"{8C737F75-27B1-4990-BCD0-503470E0510D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{8D639A1D-8C34-4EDE-AA62-3C1CEA0AB733}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{8E4CD914-92BD-468D-B09A-7DD82F983818}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{8FA8297F-2DED-4E83-9715-CBBCD07230C8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{912FA7EB-2248-40DB-8F96-01C76861637A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{93D85324-899A-4C65-8037-94BEAC5B0F76}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{947DFE66-9F21-40DA-9B8C-B17238260F37}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{95F58EC1-8854-472D-A6A5-02F1AEE190DD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9612A14E-D88E-44E7-9A07-10A56BBB950D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{96248BF7-B193-449C-B57B-903B865B2673}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{98594328-955E-4DDE-9B2B-7E35C576DFC4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{99C8E4C4-F6E1-444F-834E-6FA1B141B6EF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9A4F066E-12D9-482F-9D6A-B2A6E1106D74}" = protocol=6 | dir=in | app=c:\windows\system32\dldtcoms.exe |
"{9AB9AC53-CFD1-4BF4-92BF-1C138EE6E83C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9B3A333D-5C3D-490D-B6B2-E70ED9CA0F30}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9BF49E13-4309-40A9-98BB-D8855B72C620}" = protocol=17 | dir=in | app=c:\program files (x86)\dell remote access\ezi_ra.exe |
"{9BFAB19B-6636-4502-959A-83070CE96047}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9CD3EB8A-A1B4-4E53-8CA6-EE4EBF6C8CBA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9CEF119E-D0A6-4E4C-B9EC-7ABC2C50727E}" = protocol=17 | dir=in | app=c:\users\admin\appdata\local\google\chrome\application\chrome.exe |
"{9E2DC1C5-086A-438D-9B6A-3AE80D7E7011}" = protocol=17 | dir=in | app=c:\windows\system32\dldtcoms.exe |
"{9E938E5C-B0AF-4A7E-BACE-63F01B1E23A5}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldtpswx.exe |
"{9FD7DB0F-6F07-4BA7-B7D6-2410457FEF4E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9FF5F1A2-FF33-46B2-B173-09ABF407E9FF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A09C0836-BB15-45E9-829A-29EA71C96018}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A0A9E291-3B6F-4025-B3F9-C43171CCB22F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A1079D12-0034-4F6E-9FEB-E26698355D47}" = protocol=17 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{A10F152A-EC08-425B-9720-FC621FE7B488}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A18F6A2A-7129-491E-9D79-36440B4697CD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A2303A14-9438-40BC-8ED0-3143FD6F91C1}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{A257B01D-98FE-4ECD-8D53-63AB15000D0B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A25BC347-2467-4A79-B485-31898AEAF407}" = protocol=6 | dir=in | app=c:\program files (x86)\dell v305\wireless\dldtwpss.exe |
"{A283222C-8429-45DB-A4D4-230B3334432A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A4754990-C713-4F66-BAAE-D15C43BD5DE8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A504F132-378B-478A-B4E8-D3CAF284EF7B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A51EA3B9-03F3-47AA-B5A6-36C9AD587176}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A5349D82-C48F-4D4F-8D6C-6A1231713A48}" = protocol=6 | dir=in | app=c:\program files (x86)\abbyy finereader 6.0 sprint\scan\scanman6.exe |
"{A5D26737-0CA4-49A2-8CE4-8128F5AB3F73}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A61508A4-0740-4BF0-9556-89FF7DA4BF2C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A6971DC3-F122-4C46-9E65-DAE2887CC441}" = protocol=6 | dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe |
"{A6ACADA4-BA3A-45FA-ADB2-B54820926766}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{AAE7D1BC-BEB6-417F-9266-9C6242A58692}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{AAF19AC3-81A0-4206-A545-667C9D87E539}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{AB4DD51C-60AD-4645-9C68-1A86883E6248}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{ABA92BD8-66D8-45FB-A1A5-684C1AC01158}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{AF18F6C1-86BE-45CB-B7B9-50ED8440C410}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{AFFDBF2A-BFF4-4E19-9BFD-874B52E38B6A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B1748864-E6DE-43D2-A21A-8F530083182C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B3384684-4298-4A65-B56D-E42DDE460991}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B3A4CB0C-82D4-4D58-8F3B-3F32B985DDF8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B79AE57B-3839-493E-9BA1-B1A985075FFE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B835F417-FDCF-4CDE-8A65-55ABAA280051}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B850CFA0-DFA8-4EE1-9584-D32B94748EE9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B9097F4A-7097-42FE-BC8E-F9F7C1E87066}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{BA49889D-DACC-4F23-B4F6-6E6649290CA2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{BB6C5DD3-BD62-40DF-ABF6-E556C6420982}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{BB970A42-8B0F-4252-AE23-3D3BB87C9B56}" = protocol=6 | dir=in | app=c:\windows\system32\dldtcfg.exe |
"{BE0120DF-9F52-42F6-9082-4BF565F690CE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{BE733A94-4F01-4AE2-B5B0-B92AF165A0A9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{BE96988B-85BD-42A4-A722-C18B1AB4A549}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C15AFFA4-F803-45EA-A846-5D944949B89E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C1613AE9-3CC7-4FB0-B762-1A5257758FD9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C290E8D1-C572-4954-AAEF-E3FBB8D25002}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldtwbgw.exe |
"{C2E09EF6-3A6C-421D-A81E-B66F852ADA88}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C53A99F2-2580-4E99-A67A-BB5A53E9BD5A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C5A97992-575E-4F98-B1EE-6CECA7205E38}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C5CA9676-35FE-4253-A575-CE7B316BD85E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C7B9FAC7-6FA5-4828-8EA1-089B443C64F9}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{C7E43FC0-8056-47F9-92C7-7EC13B7DB0BE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C8E4C762-F028-4A9F-9EEA-A26B45A45147}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C9CAFB45-7D6B-4838-AA3C-94C264340723}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C9DE4EFD-02B9-474B-A97F-A94737661CF3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{CAFE14E7-3EA2-4788-85C3-BC28B526B85F}" = protocol=6 | dir=in | app=c:\program files (x86)\dell v305\dldtlscn.exe |
"{CBBBEBED-1EAC-4EE0-A609-B0D6A7AEF67F}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\dell\advanced networking service\hnm_svc.exe |
"{CBC9D033-C394-47D2-AA9E-F6DF411ACB63}" = protocol=17 | dir=in | app=f:\stronghold\stronghold2.exe |
"{CD0B38B9-F5C0-4390-A75D-A524C9932A23}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{CDAAB2F8-8E32-4470-9247-C3D9A32A26C7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{CEB45D4A-57AC-496D-9EE6-79AA6BF238A7}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{CEBA0EDF-BC5C-4D28-8176-A48AD7B4CE1E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D0B159B1-F48D-4B3F-A70D-7E85DF5E739E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D0D121AD-931B-4FFF-BC2C-4832F2B28CBD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D0E7E3F2-19AE-44B5-85AA-F7C6B911DA19}" = protocol=6 | dir=in | app=f:\stronghold2.exe |
"{D1401393-25D5-4FFA-8367-FCD2AE1A3827}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D18CF589-1E9D-481C-90D1-2E55553264C7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D1976FC6-1300-4656-BD68-4AD1A244420C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D1EBDC6B-C645-476D-B96B-C3C6202985BA}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\powerdvd.exe |
"{D424FD8F-14C2-46CB-A7CA-E4138F420709}" = protocol=6 | dir=in | app=c:\program files (x86)\dell v305\frun.exe |
"{D57C3116-C0FB-4D91-BFE0-A295425B8107}" = protocol=6 | dir=in | app=c:\program files (x86)\dell video chat\dellvideochat.exe |
"{D600B638-0984-4368-97FA-79A12037E192}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D69334E3-BCDA-4E48-AF64-274B231ED93A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D74D36E7-B311-4572-BFBE-F1DB9408CFC3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D84A0C29-00B2-4701-9721-5C5CDC44A652}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldtjswx.exe |
"{D95D36FD-840C-41F6-A3AA-C0EA926A7C72}" = protocol=17 | dir=in | app=c:\program files (x86)\dell video chat\dellvideochat.exe |
"{D9A5E92E-0986-4A91-A2D4-A9D13C3B3970}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DA616784-8037-46BB-B255-D4D5CA932C12}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DD458E6D-D911-4871-B1AC-98E0883ADDCD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DDA331D8-564C-420F-9B27-F7FF1A56D2B6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DDD513C6-BB74-4BD8-8100-FA819B23A6D0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DDDE1C9E-099C-4A28-B489-C09DB1CB825C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DE5BBC32-B403-461D-A772-ACD9F5D20BED}" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{DEE8459D-28D8-49E0-8A86-FBAEA0B8C2CF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DEF27660-F68B-48DC-9A14-2FE5F785C42C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DF3A86E8-2E69-470C-A82B-1F834F2F7B2C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DF3D8CFB-4B68-404C-9F67-3D75C7256077}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DFEDA999-154C-4A41-B50B-FF4999CA83F0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E01C65BD-3E17-4328-B2BB-673B6760E5DF}" = protocol=17 | dir=in | app=c:\program files (x86)\dell v305\dldtamon.exe |
"{E06C443D-61B8-4762-9670-B8E3A1DD6833}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E0AC8287-3220-479E-A5C9-9BB070DD5AD1}" = protocol=17 | dir=in | app=c:\windows\system32\dldtcoms.exe |
"{E0EA91AF-80D1-4741-B23F-95F055525A26}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E1B38D7D-28CB-4641-95C5-E0F78F570131}" = protocol=17 | dir=in | app=c:\program files (x86)\dell v305\wireless\dldtwpss.exe |
"{E1CC2223-0937-4008-B5A7-1898BB5DAAFB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E338E7B2-9FCB-4222-A127-9CEC4D6AEDA7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E43C46FA-0E0B-45EB-ABC3-AA84DFB95F89}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E4CAE8CC-3134-4DA1-8F19-435864703A21}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E4D15249-0125-41EA-BB34-C6E9322FAEBF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E551C693-96BB-43A0-BF0C-7C67D475B347}" = protocol=17 | dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe |
"{E63C1D2F-219A-4A13-9058-131193BC84C2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E7AE2CAE-2F03-472D-A8FB-C63F061E208E}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\dell\vlc\vlc.exe |
"{E7AFDB30-56B8-48E1-B63C-A781E9CE7A04}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E7C610F3-6EBE-4986-BA29-B8650CC4CB5E}" = protocol=6 | dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe |
"{E9663CAA-1F46-4DF6-BADC-6988C2F7CB96}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E977CC80-FB0D-4A82-8642-1298A2B42628}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E9B815AF-0BC5-4CB1-B64C-0783855A3C1D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{EA95D686-FD31-4024-B1CD-71F7876D88D3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{EAA7085E-846F-44D2-A4BF-D2588E958E4C}" = protocol=17 | dir=in | app=c:\program files (x86)\dell v305\frun.exe |
"{EAE028A4-8034-4477-81EA-75BC4A28B7F2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{EB3F9A53-8939-4A34-A99B-DA4DC6636929}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{EC814A44-C8BC-43B3-86ED-18AF67DCBE21}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{EE8F2C4D-6ECA-485A-B0D5-23060716E950}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{EFC80DEA-A3EA-4793-ADC8-A70BF0DF4AEF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F1BE923D-932F-4FBB-8501-64FC2A5668B1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F64CEB69-AE1B-4CE2-84BC-176D83A4DD14}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldttime.exe |
"{F77E9B45-588C-41C5-9B25-061B32252995}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F7ECC5FD-65C2-4A57-85D9-958579F45F74}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F840803C-0290-4C78-A863-BF23B7CCFC88}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{F8603AA8-021D-4986-B323-01653BEC0203}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F8751723-49A4-4765-B2A9-2F4C72B2B411}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F971307F-D609-4CED-A404-A29B4B2481B2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FA0C4C24-15D2-49D3-B8F4-99DC14FB558C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FA23CB6A-AC45-4CDB-8BCC-384DEE0851C3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FA5819FA-D490-4B65-A814-F0200AB8F64F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FB42C850-EA89-4323-A086-E0D486A3BBF5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FBD4B773-43D2-4051-98B6-D687926162C1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FBDEE49E-8ECB-4C96-901E-99CBA728392D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FC8B7142-266F-43D4-B27A-A88C4840CF39}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FEA1DEEB-5383-4975-A053-69A22599B94F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FFB89EE7-8A33-46E5-9F7C-18C95C644FC5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FFE89F5F-329E-47BC-B9E7-3ECAEC9F4029}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FFF6C081-52E3-47F1-A4F2-4EA3544082BC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"TCP Query User{2DAD67F0-D7D3-4B5E-B516-72FE4F0E677B}C:\program files (x86)\dell video chat\dellvideochat.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dell video chat\dellvideochat.exe |
"TCP Query User{6B5F0246-3159-4BAB-A005-75219A67A6E9}C:\program files (x86)\dell v305\dldtmon.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dell v305\dldtmon.exe |
"TCP Query User{A617269F-7AB3-41EF-A582-20B56E2F28FB}C:\program files (x86)\oovoo\oovoo.exe" = protocol=6 | dir=in | app=c:\program files (x86)\oovoo\oovoo.exe |
"TCP Query User{BEAF82A5-12D0-425F-AA1F-CCC73350810E}C:\windows\system32\spool\drivers\x64\3\dldtpswx.exe" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldtpswx.exe |
"TCP Query User{ED45E139-D83C-4FE4-BCF9-1E775799F894}C:\program files (x86)\oovoo\oovoo.exe" = protocol=6 | dir=in | app=c:\program files (x86)\oovoo\oovoo.exe |
"UDP Query User{68051CA4-3DA7-465F-B862-09F40A790F94}C:\windows\system32\spool\drivers\x64\3\dldtpswx.exe" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldtpswx.exe |
"UDP Query User{6C59B14C-3A37-4972-8FE4-034636B6B599}C:\program files (x86)\dell v305\dldtmon.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dell v305\dldtmon.exe |
"UDP Query User{85F70C55-8A37-4ECE-B36F-78AC290CB9A5}C:\program files (x86)\dell video chat\dellvideochat.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dell video chat\dellvideochat.exe |
"UDP Query User{9B6EAA59-C16F-43F4-B11D-24B69606833A}C:\program files (x86)\oovoo\oovoo.exe" = protocol=17 | dir=in | app=c:\program files (x86)\oovoo\oovoo.exe |
"UDP Query User{BE22473E-4FAE-4662-94E5-FC2A7D8AFFEF}C:\program files (x86)\oovoo\oovoo.exe" = protocol=17 | dir=in | app=c:\program files (x86)\oovoo\oovoo.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{26A24AE4-039D-4CA4-87B4-2F86416013FF}" = Java™ 6 Update 13 (64-bit)
"{3A25872A-0F1C-4989-9435-96C13230F818}" = Apple Mobile Device Support
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6F4B9839-F409-4D38-89D6-145321400FED}" = iTunes
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{87CF757E-C1F1-4D22-865C-00C6950B5258}" = Quickset64
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DAE239CE-EB9D-4EB3-B0D4-528D6BAA48FD}" = Bonjour
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F6CB42B9-F033-4152-8813-FF11DA8E6A78}" = Dell Dock
"Creative OA008" = Integrated Webcam Driver (1.04.01.0601)
"Dell V305" = Dell V305
"HDMI" = Intel® Graphics Media Accelerator Driver
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"SynTPDeinstKey" = Dell Touchpad
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{095B1DCF-5E8B-47EC-9B18-481918A731DB}" = Microsoft Default Manager
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}" = Dell DataSafe Online
"{16D2C649-CBA8-44EE-B730-12584667D487}" = Stronghold 2
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1798D459-6B8B-474B-868D-1229EADA3B95}" = Adobe AIR
"{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}" = Bing Bar
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 24
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java™ 6 Update 22
"{26CE484D-2E8E-40D5-B251-158133114C69}" = TomTom HOME
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}" = Banctec Service Agreement
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AAC5AE8-EDE6-44D4-AA87-E90870178FDE}" = Minitab 15 English
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}" = Windows 7 Upgrade Advisor
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B92C5909-1D37-4C51-8397-A28BB28E5DC3}" = Facebook Video Calling 1.2.0.287
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C8773FDB-D0DB-BE52-D536-F48F9886B57B}" = Adobe Download Assistant
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EF85FEF4-EB92-4075-A6D2-5F519BB30A2C}" = Complete Care Consumer Service Agreement
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F47C37A4-7189-430A-B81D-739FF8A7A554}" = Consumer In-Home Service Agreement
"{F66A31D9-7831-4FBA-BA02-C411C0047CC5}" = Dell Remote Access
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Belarc Advisor" = Belarc Advisor 8.2
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"Dell Video Chat" = Dell Video Chat
"Dell Webcam Central" = Dell Webcam Central
"Google Chrome" = Google Chrome
"GoToAssist" = GoToAssist 8.0.0.514
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IObit Malware Fighter_is1" = IObit Malware Fighter
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Mozilla Firefox 4.0 (x86 en-US)" = Mozilla Firefox 4.0 (x86 en-US)
"N360" = Norton 360
"PopTools_is1" = PopTools
"WinLiveSuite_Wave3" = Windows Live Essentials
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-3805510809-3204643337-4127071045-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f031ef6ac137efc5" = Dell Driver Download Manager
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 3/25/2013 12:20:04 PM | Computer Name = JeremyComputer | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.
Error - 3/25/2013 12:20:28 PM | Computer Name = JeremyComputer | Source = Application Hang | ID = 1002
Description = The program mbam.exe version 1.70.0.9 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 1234 Start Time: 01ce29748f82c83d Termination Time: 17
Error - 3/25/2013 12:41:28 PM | Computer Name = JeremyComputer | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.
Error - 3/26/2013 2:04:50 AM | Computer Name = JeremyComputer | Source = IMFservice | ID = 0
Description =
Error - 3/26/2013 2:04:51 AM | Computer Name = JeremyComputer | Source = IMFservice | ID = 0
Description =
Error - 3/27/2013 11:14:38 AM | Computer Name = JeremyComputer | Source = WinMgmt | ID = 10
Description =
Error - 3/27/2013 12:13:43 PM | Computer Name = JeremyComputer | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.
Error - 3/27/2013 8:03:49 PM | Computer Name = JeremyComputer | Source = WinMgmt | ID = 10
Description =
Error - 3/28/2013 2:15:09 PM | Computer Name = JeremyComputer | Source = WinMgmt | ID = 10
Description =
Error - 3/29/2013 8:15:47 AM | Computer Name = JeremyComputer | Source = WinMgmt | ID = 10
Description =
Error encountered while reading event logs.
< End of report >
OTL Extras logfile created on: 3/29/2013 8:48:58 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\admin\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19401)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.96 Gb Total Physical Memory | 1.82 Gb Available Physical Memory | 45.87% Memory free
8.09 Gb Paging File | 5.57 Gb Available in Paging File | 68.84% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451.07 Gb Total Space | 307.35 Gb Free Space | 68.14% Space Free | Partition Type: NTFS
Drive D: | 14.65 Gb Total Space | 0.00 Gb Free Space | 0.01% Space Free | Partition Type: NTFS
Computer Name: JEREMYCOMPUTER | User Name: admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_USERS\S-1-5-21-3805510809-3204643337-4127071045-1000\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = 5A B5 47 12 96 B6 CB 01 [binary data]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{26471E12-D007-40FB-BCA8-5D7E33EA58F9}" = lport=37674 | protocol=17 | dir=in | name=oovoo udp port 37674 |
"{299186B6-FA78-458A-BEA2-09E0B7E8918A}" = rport=445 | protocol=6 | dir=out | app=system |
"{38F39F6F-A739-4FF3-9735-B4A608DE8B4C}" = rport=139 | protocol=6 | dir=out | app=system |
"{3C821A84-CB77-4B99-BFAB-49FBE7A1D82A}" = rport=137 | protocol=17 | dir=out | app=system |
"{41CCCF58-7E8D-49D2-AB72-55CAA91D739A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{568FF856-6327-4A31-BBC5-4BF83A0E0652}" = lport=37674 | protocol=6 | dir=in | name=oovoo tcp port 37674 |
"{5B543684-7FB4-40B3-AA10-BB4A7754FFA6}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{5BCE40CE-F93A-4127-82F5-73019A8455A5}" = lport=443 | protocol=17 | dir=in | name=oovoo udp port 443 |
"{5EE5D3B3-6F2C-4DF7-845A-B0379A7B4DE6}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{67F03A4D-E0E9-460D-A433-61F996CC25B8}" = lport=443 | protocol=6 | dir=in | name=oovoo tcp port 443 |
"{6A183C0B-B58C-43E8-B0DF-A32C5987A0CB}" = lport=137 | protocol=17 | dir=in | app=system |
"{6B588953-22D3-4DE2-ACA1-69E07FF4175D}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=c:\windows\system32\svchost.exe |
"{6C73C84D-BF4A-4AED-96AB-81303671A032}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{74FAC798-5761-4051-B1C6-2EA5357933F0}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{7931CBD5-1D8A-4098-9E5B-4F8607458965}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=c:\windows\system32\svchost.exe |
"{7A6C0863-6036-4C8C-B994-D6C2B21AB61A}" = lport=37675 | protocol=17 | dir=in | name=oovoo udp port 37675 |
"{905E937A-8CDB-4240-9E52-05C9383D9305}" = lport=138 | protocol=17 | dir=in | app=system |
"{90BBEEF9-94F3-480B-A07B-722DDAE338C7}" = lport=445 | protocol=6 | dir=in | app=system |
"{934C4AD2-3406-4C8D-A560-C245A6BE5C4C}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=c:\windows\system32\svchost.exe |
"{A7B9DDEE-90E3-4BBA-A04F-CE0458F6D519}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{BAD9473F-0107-4A01-8EC2-DC7353F4E811}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=c:\windows\system32\svchost.exe |
"{D97EF175-5D4A-4722-96E2-CE9909FAFE38}" = lport=139 | protocol=6 | dir=in | app=system |
"{D9D2CE13-602D-4E0F-B467-7D8AE78152AE}" = lport=2869 | protocol=6 | dir=in | app=system |
"{DD4B4A99-758C-4251-B9EC-D349D40A5C8C}" = rport=138 | protocol=17 | dir=out | app=system |
"{DFBD745F-1846-4F14-8EF0-5CE6BF017252}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=c:\windows\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0025C536-DD32-49DE-869D-A6F5BDCD293D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{00271B36-2583-4EB5-87AB-C55B6461FE15}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{01B9384E-F6CB-4917-8B58-AE44AAD609AF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{01E14BDD-0B46-4469-8654-FEB15C24DD54}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{08FF2C01-6045-44EC-BF91-4A7D163BAF69}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0A5F9C56-7930-43EB-8EA1-764DB72407E1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0DA16BFC-202D-49AE-B77A-6A04F2629566}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0F292295-28A6-46EB-B5F7-DF59F8EAAEB6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{0FACC609-34C8-4BA2-B15C-E4ABB80128B5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{107FDB13-4262-4373-85EE-EC515BAF7D44}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1194553A-A747-4912-A98C-C7DF704B5FCF}" = protocol=17 | dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe |
"{11AE9032-219A-40FC-B7B1-D3FC2CFD83C5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{12AB6BCA-CC9D-4B58-855F-A6C2BF8F8A96}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{12DCBE51-687E-4AA8-9713-8AEAEC1F6452}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{12E78EA7-7444-449F-A10B-7591E7B4247D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{16C6968C-9820-40E5-BF2F-E77E04B8D3A1}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldtwbgw.exe |
"{178E94A7-4243-435B-B19F-45FE7C53346E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{184BC4D8-10D2-43A0-82CF-3ECB1CEF962F}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{188872C3-9632-4C68-9825-A86305BBC658}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{19B34B8A-9475-42B7-AAD2-7EC4EDFF0CB6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{19F8176A-41CD-4EA6-B83E-D21029D33833}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\dell\vlc\vlc.exe |
"{1A14F9D1-68DB-4428-8E74-699A3B976D16}" = protocol=17 | dir=in | app=c:\program files (x86)\dell v305\dldtmon.exe |
"{1A409B69-3A28-42EE-BB46-6C02270C90F9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1B546B07-7207-4F8D-8366-CD579E76F0BC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1BF2EF81-7968-4B29-9F12-E2C3D22F9683}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1C147B4B-A593-46AB-8E2F-F79CF6875110}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{1C8BA8DB-FFE7-479D-AE2A-0169DC85C5B2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1E79B0FC-678B-46C5-99EA-553C4F0A5743}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{1E92F058-E4E7-4012-80D1-BA3187F99D29}" = protocol=6 | dir=in | app=c:\program files (x86)\dell v305\dldtamon.exe |
"{20EE9A19-1160-49D9-BF45-7D001BC8B12E}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{2147CA76-D203-4376-8253-565D925BB9D4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{2243B7FF-23CE-4506-B253-FD4B706E9421}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{22B421C4-C3F5-400F-84DD-B78859781E5B}" = dir=in | app=c:\users\admin\appdata\local\facebook\video\skype\facebookvideocalling.exe |
"{24A26865-FEBC-4E4E-88AF-694D10D0A9C1}" = protocol=6 | dir=in | app=c:\program files (x86)\dell v305\dldttime.exe |
"{254C6FDA-D42D-403D-9265-A0604F540CB9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{259C096B-8246-47CF-8F48-55274DE7F231}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{25B154D6-0FE0-4E63-852A-BBE97CBAE55E}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{2747437B-89EB-4619-A81C-DD49BC55117E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{288129E5-8A32-437D-9079-1DD7558AFAAB}" = protocol=17 | dir=in | app=c:\windows\system32\dldtcfg.exe |
"{28B5F8C9-1DF4-4687-90E9-DE01817596D2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{293EE96F-2415-4A86-8CBD-AC53626B4954}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{2A7887BF-32CA-4BFF-A86F-5CABC7C74FAA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{2C44FE44-13FA-4516-874C-851075CDF1C2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{2EE65BB4-ECFD-43C8-89C7-2D93E4BFA685}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{2F278080-CED5-40C3-8862-69CB87AC2DC3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{311669CA-8D30-45FA-B04F-12FBA0430D4A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{31F3626B-C357-4896-A487-4AFF47AF8654}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{33574964-E15D-40CE-B337-6DD646FDBAC3}" = protocol=17 | dir=in | app=f:\stronghold2.exe |
"{338FAB12-A91B-4D52-83FC-9EDBBD2735DA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{339D9100-89ED-4CD0-B6C8-DB501DFDA91E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{33AA16C6-4862-4B0F-99E5-1B61F350DD7A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{34EFF262-B224-4DEF-A4FD-CF44FC7EC528}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3559B53A-C696-4DA7-98B6-6EEC2CFD86A9}" = protocol=6 | dir=in | app=f:\stronghold\stronghold2.exe |
"{355C1828-E920-4822-8B31-499C19136970}" = dir=in | app=c:\program files (x86)\common files\mcafee\mna\mcnasvc.exe |
"{36DE7666-1B71-4EEF-A23A-7C87954E99C6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3720756A-F2E9-41EE-A1BE-12869E85434C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{37375919-702C-4B5B-9FC7-41A2039F3863}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{37DC74F4-9159-4F50-9F10-80AA4DCF31C8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{38C64B91-8FCB-449D-937F-A0FD2D5C7229}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{394FFAE8-A7E5-4717-88B4-81AC932D1CA7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{39DDF35B-BEEA-4875-B449-63A282752E1C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3AF1E6E1-B7E3-4380-AAD2-F0413FDA63E0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3B79EE4C-A7AC-4856-8EB9-079948522771}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3BDD2D34-5575-4597-826F-81DDCC593B8C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3CDB9EA5-6E50-4867-9217-9F800611D7F1}" = protocol=17 | dir=in | app=c:\program files (x86)\dell v305\dldtlscn.exe |
"{3CF76885-CCB7-44BF-9DEC-8CBC8EB7372E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3E049224-8A9A-4560-98D9-B32F993C3F75}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{3E20251F-8EA8-4258-A71B-B4CBE9D65AFA}" = protocol=6 | dir=in | app=c:\windows\syswow64\dldtcoms.exe |
"{40CCCB74-0157-4CD7-988C-BA64A95405A5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{417DB9A6-0A70-4F32-8E34-E97E2768375F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{41FB909E-873A-477B-B0F1-4DA421828944}" = protocol=6 | dir=in | app=c:\users\admin\appdata\local\temp\dldt\wireless\english\dldtwpss.exe |
"{4217FA51-0824-4C4A-82A9-2AD0731465E8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{426322C4-33A6-416E-B7E9-A532EF7A198B}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{446EAB1E-B3F8-4EDC-9DAA-9D9627200FE6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{44E075D6-F993-438A-B8D8-811CF639E62E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{46950B40-9BCB-453B-AE8E-0F98E3699A22}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{473B2391-6F77-42C4-8E5E-CCE6CE3A58B7}" = protocol=17 | dir=in | app=c:\program files (x86)\abbyy finereader 6.0 sprint\scan\scanman6.exe |
"{47646D9D-0854-43F1-9A67-46FB46158BE8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{47CCE082-04C5-4284-8F4B-759168BD0A24}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{485DE425-B160-4E4D-911F-D9F922DEB477}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{48E2654B-753B-4B5A-8C1C-8048E2EE4FF2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{49422A02-820C-45CA-8F9C-D16FBB394DDD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{49BF4433-2B5A-410E-B81E-9687579D2881}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{49DB6756-5A74-41CF-ADDD-5BBBE0716F26}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4AA59432-E525-463A-9F1F-4E4FA9620BF0}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{4B0AC1A6-0606-4BAC-889B-18113F465D40}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4BC6A701-02F0-4AD6-8079-7D7F0B018D5B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4BE451F6-1AF4-4386-A076-85A7D325C801}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4CC027D5-C561-4FE3-826C-3659FD91403C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4D44FCEC-AB0D-41CB-8D6F-DAF8FD3B99A3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4D62CD53-4A54-497D-AD3F-8092CAB42EAF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4DC06BE9-CFCB-46A7-AEE4-5F0B1CEA0305}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4DD0CD3B-E753-4B93-A5B1-C34E0B0A7787}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4E4B755F-70ED-40E1-A2D4-074EE5352834}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{4EBE7B3D-2952-4FE7-AF01-1FC2C63EDB17}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{50ED2E56-5347-41CD-B2F8-A54E94F18319}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{53586142-B3D4-4E66-BBDC-469349F9242A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{5455590E-72BC-4EAC-9A96-6FBEC45F49D7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{55E0C8B3-02C6-4DCC-B3F5-70EC9AF725F8}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\dell\advanced networking service\hnm_svc.exe |
"{56F575F4-46CA-43C1-BC5E-AA730D7DD4D1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{57F86A22-A069-4D2C-8474-D75C0B047959}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{585A0F11-ED6F-4987-8134-C91EE71F7629}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{587FAEAB-9D8B-43C6-A83D-642161DCBAF1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{58D7A8F4-59F8-4DEB-A1E2-B3E6A398573C}" = protocol=17 | dir=in | app=c:\users\admin\appdata\local\temp\dldt\wireless\english\dldtwpss.exe |
"{5B39A13F-E85F-45F7-B9E0-7E4D315BB92B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{5DC550DA-C429-44D0-8FAF-EDFAE9E62853}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{5E9644F1-D9A8-48FD-A59E-86607AD41DF9}" = protocol=17 | dir=in | app=c:\windows\syswow64\dldtcoms.exe |
"{5F2FAD5F-74EB-446C-844D-4142863D651B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{620165D3-22FE-41B8-B436-5850D6344D64}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{62B23113-F26B-4DCA-906C-A38DC79C2182}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{64FF6A33-48BC-4EF2-83D0-4D445FDD8090}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{65004FBA-ECF7-44A2-A578-463082499BFE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{662FA537-B39C-42F8-90E6-A065BE1B78FB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{66734C66-F192-49D9-93EF-E45C8C1F2865}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{6A3692AD-5A4F-4316-A615-74CE491F3AEC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{6C3FABC8-9A4A-479A-B4EF-D410ABEFC178}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{6E7B3EDA-9D2E-4BEE-8510-611EB7A2110E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{6EEA77DE-2DE8-4C90-AC2C-E7F343E6A9B6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7018F996-C95D-410A-B815-0312BEACAC82}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{72885C92-5ECE-4EE7-B76E-42B345AFBB36}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{72FA63B9-6A69-47C4-AF5C-1B6C34B2002C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{734464E9-3FC4-428F-A83C-A8D1BC34D399}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{73CAC177-DDCD-4E16-B292-6FDED6AF63C6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{75F145AB-9E12-48F2-9D7D-7700F95A8C6D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{77C02DFA-64D4-4695-A1BC-7420FC50B896}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7848238B-2D2E-4E54-B039-7ECC07B32CF8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7888F390-A93D-47B7-A0AA-10DA56A5A4AD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{78A3DAFC-10BD-43CF-B8AA-999FFE7B80EF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{79881859-0D39-423A-8446-2E6F8030FF30}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{799EA43A-F820-4A13-8A05-17E4605929A4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7B7C6B80-76E7-4762-8C5F-D7CB89128B0C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7D4DD538-E302-4912-B03A-C2867F2B10EA}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldtpswx.exe |
"{7DB3A846-9B49-4956-9C7A-DEE118614E6E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7DCDE869-9951-4270-A103-491330E69B31}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7E6F4615-5F26-424B-8232-105110A42A7D}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{7EB4ED45-DD20-48A9-B80B-79CA93BF5AA6}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{7F55CD26-BA09-41A7-A022-2AC67FEB2E6B}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldtjswx.exe |
"{7F79F3FF-57DA-4A24-92EF-1EEDCC4A45F8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7F9473DD-3804-4578-8EC0-A6211504DEB2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{7FA3E30F-871A-4C27-A2F8-317F95AEEFEB}" = protocol=6 | dir=in | app=c:\users\admin\appdata\local\google\chrome\application\chrome.exe |
"{809E4063-D3B7-4B55-AB7F-80AC70627160}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{812B3A98-2648-463F-ABF1-0BF33BF34752}" = protocol=6 | dir=in | app=c:\windows\system32\dldtcoms.exe |
"{81966A38-1632-48A9-ACD2-2ACD7178718B}" = protocol=6 | dir=in | app=c:\program files (x86)\dell remote access\ezi_ra.exe |
"{822471D1-C847-48E7-997F-C1045B0C7678}" = protocol=6 | dir=in | app=c:\program files (x86)\dell v305\dldtmon.exe |
"{82DC18CA-EC15-4AA0-BDF8-7C385F2703C7}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldttime.exe |
"{82F2E329-F6D0-4872-A652-B96903A6D876}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{83166ACC-8A9A-4EBE-928A-DCB4F406D669}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{831DDE04-FD20-4766-A09B-6DB02650667C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{836AA9C2-221D-4F70-8B32-AB9654DA572C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{8658CAC6-F52E-4F66-90CD-9571250783CD}" = dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{87A48A2F-EBB6-4025-88F0-99635DAB66C6}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{87D93C73-757C-492F-8250-2798D7C3DFE1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{88D553C2-A96E-4231-A427-BC62C70EF09F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{89840844-BA1B-4EB5-8F5A-831E91B56827}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{8A5821E2-1436-45A7-AD57-72E7AD4BDD49}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{8BF3D330-F67B-4C0D-94A9-06BEEF63E887}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{8C34BE48-DDB5-4D15-ACE5-619E25F6D958}" = protocol=17 | dir=in | app=c:\program files (x86)\dell v305\dldttime.exe |
"{8C737F75-27B1-4990-BCD0-503470E0510D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{8D639A1D-8C34-4EDE-AA62-3C1CEA0AB733}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{8E4CD914-92BD-468D-B09A-7DD82F983818}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{8FA8297F-2DED-4E83-9715-CBBCD07230C8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{912FA7EB-2248-40DB-8F96-01C76861637A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{93D85324-899A-4C65-8037-94BEAC5B0F76}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{947DFE66-9F21-40DA-9B8C-B17238260F37}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{95F58EC1-8854-472D-A6A5-02F1AEE190DD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9612A14E-D88E-44E7-9A07-10A56BBB950D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{96248BF7-B193-449C-B57B-903B865B2673}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{98594328-955E-4DDE-9B2B-7E35C576DFC4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{99C8E4C4-F6E1-444F-834E-6FA1B141B6EF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9A4F066E-12D9-482F-9D6A-B2A6E1106D74}" = protocol=6 | dir=in | app=c:\windows\system32\dldtcoms.exe |
"{9AB9AC53-CFD1-4BF4-92BF-1C138EE6E83C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9B3A333D-5C3D-490D-B6B2-E70ED9CA0F30}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9BF49E13-4309-40A9-98BB-D8855B72C620}" = protocol=17 | dir=in | app=c:\program files (x86)\dell remote access\ezi_ra.exe |
"{9BFAB19B-6636-4502-959A-83070CE96047}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9CD3EB8A-A1B4-4E53-8CA6-EE4EBF6C8CBA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9CEF119E-D0A6-4E4C-B9EC-7ABC2C50727E}" = protocol=17 | dir=in | app=c:\users\admin\appdata\local\google\chrome\application\chrome.exe |
"{9E2DC1C5-086A-438D-9B6A-3AE80D7E7011}" = protocol=17 | dir=in | app=c:\windows\system32\dldtcoms.exe |
"{9E938E5C-B0AF-4A7E-BACE-63F01B1E23A5}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldtpswx.exe |
"{9FD7DB0F-6F07-4BA7-B7D6-2410457FEF4E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{9FF5F1A2-FF33-46B2-B173-09ABF407E9FF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A09C0836-BB15-45E9-829A-29EA71C96018}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A0A9E291-3B6F-4025-B3F9-C43171CCB22F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A1079D12-0034-4F6E-9FEB-E26698355D47}" = protocol=17 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{A10F152A-EC08-425B-9720-FC621FE7B488}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A18F6A2A-7129-491E-9D79-36440B4697CD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A2303A14-9438-40BC-8ED0-3143FD6F91C1}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{A257B01D-98FE-4ECD-8D53-63AB15000D0B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A25BC347-2467-4A79-B485-31898AEAF407}" = protocol=6 | dir=in | app=c:\program files (x86)\dell v305\wireless\dldtwpss.exe |
"{A283222C-8429-45DB-A4D4-230B3334432A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A4754990-C713-4F66-BAAE-D15C43BD5DE8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A504F132-378B-478A-B4E8-D3CAF284EF7B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A51EA3B9-03F3-47AA-B5A6-36C9AD587176}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A5349D82-C48F-4D4F-8D6C-6A1231713A48}" = protocol=6 | dir=in | app=c:\program files (x86)\abbyy finereader 6.0 sprint\scan\scanman6.exe |
"{A5D26737-0CA4-49A2-8CE4-8128F5AB3F73}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A61508A4-0740-4BF0-9556-89FF7DA4BF2C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{A6971DC3-F122-4C46-9E65-DAE2887CC441}" = protocol=6 | dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe |
"{A6ACADA4-BA3A-45FA-ADB2-B54820926766}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{AAE7D1BC-BEB6-417F-9266-9C6242A58692}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{AAF19AC3-81A0-4206-A545-667C9D87E539}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{AB4DD51C-60AD-4645-9C68-1A86883E6248}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{ABA92BD8-66D8-45FB-A1A5-684C1AC01158}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{AF18F6C1-86BE-45CB-B7B9-50ED8440C410}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{AFFDBF2A-BFF4-4E19-9BFD-874B52E38B6A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B1748864-E6DE-43D2-A21A-8F530083182C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B3384684-4298-4A65-B56D-E42DDE460991}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B3A4CB0C-82D4-4D58-8F3B-3F32B985DDF8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B79AE57B-3839-493E-9BA1-B1A985075FFE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B835F417-FDCF-4CDE-8A65-55ABAA280051}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B850CFA0-DFA8-4EE1-9584-D32B94748EE9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{B9097F4A-7097-42FE-BC8E-F9F7C1E87066}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{BA49889D-DACC-4F23-B4F6-6E6649290CA2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{BB6C5DD3-BD62-40DF-ABF6-E556C6420982}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{BB970A42-8B0F-4252-AE23-3D3BB87C9B56}" = protocol=6 | dir=in | app=c:\windows\system32\dldtcfg.exe |
"{BE0120DF-9F52-42F6-9082-4BF565F690CE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{BE733A94-4F01-4AE2-B5B0-B92AF165A0A9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{BE96988B-85BD-42A4-A722-C18B1AB4A549}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C15AFFA4-F803-45EA-A846-5D944949B89E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C1613AE9-3CC7-4FB0-B762-1A5257758FD9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C290E8D1-C572-4954-AAEF-E3FBB8D25002}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldtwbgw.exe |
"{C2E09EF6-3A6C-421D-A81E-B66F852ADA88}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C53A99F2-2580-4E99-A67A-BB5A53E9BD5A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C5A97992-575E-4F98-B1EE-6CECA7205E38}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C5CA9676-35FE-4253-A575-CE7B316BD85E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C7B9FAC7-6FA5-4828-8EA1-089B443C64F9}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{C7E43FC0-8056-47F9-92C7-7EC13B7DB0BE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C8E4C762-F028-4A9F-9EEA-A26B45A45147}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C9CAFB45-7D6B-4838-AA3C-94C264340723}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{C9DE4EFD-02B9-474B-A97F-A94737661CF3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{CAFE14E7-3EA2-4788-85C3-BC28B526B85F}" = protocol=6 | dir=in | app=c:\program files (x86)\dell v305\dldtlscn.exe |
"{CBBBEBED-1EAC-4EE0-A609-B0D6A7AEF67F}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\dell\advanced networking service\hnm_svc.exe |
"{CBC9D033-C394-47D2-AA9E-F6DF411ACB63}" = protocol=17 | dir=in | app=f:\stronghold\stronghold2.exe |
"{CD0B38B9-F5C0-4390-A75D-A524C9932A23}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{CDAAB2F8-8E32-4470-9247-C3D9A32A26C7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{CEB45D4A-57AC-496D-9EE6-79AA6BF238A7}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{CEBA0EDF-BC5C-4D28-8176-A48AD7B4CE1E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D0B159B1-F48D-4B3F-A70D-7E85DF5E739E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D0D121AD-931B-4FFF-BC2C-4832F2B28CBD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D0E7E3F2-19AE-44B5-85AA-F7C6B911DA19}" = protocol=6 | dir=in | app=f:\stronghold2.exe |
"{D1401393-25D5-4FFA-8367-FCD2AE1A3827}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D18CF589-1E9D-481C-90D1-2E55553264C7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D1976FC6-1300-4656-BD68-4AD1A244420C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D1EBDC6B-C645-476D-B96B-C3C6202985BA}" = dir=in | app=c:\program files\cyberlink\powerdvd dx\powerdvd.exe |
"{D424FD8F-14C2-46CB-A7CA-E4138F420709}" = protocol=6 | dir=in | app=c:\program files (x86)\dell v305\frun.exe |
"{D57C3116-C0FB-4D91-BFE0-A295425B8107}" = protocol=6 | dir=in | app=c:\program files (x86)\dell video chat\dellvideochat.exe |
"{D600B638-0984-4368-97FA-79A12037E192}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D69334E3-BCDA-4E48-AF64-274B231ED93A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D74D36E7-B311-4572-BFBE-F1DB9408CFC3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{D84A0C29-00B2-4701-9721-5C5CDC44A652}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldtjswx.exe |
"{D95D36FD-840C-41F6-A3AA-C0EA926A7C72}" = protocol=17 | dir=in | app=c:\program files (x86)\dell video chat\dellvideochat.exe |
"{D9A5E92E-0986-4A91-A2D4-A9D13C3B3970}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DA616784-8037-46BB-B255-D4D5CA932C12}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DD458E6D-D911-4871-B1AC-98E0883ADDCD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DDA331D8-564C-420F-9B27-F7FF1A56D2B6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DDD513C6-BB74-4BD8-8100-FA819B23A6D0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DDDE1C9E-099C-4A28-B489-C09DB1CB825C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DE5BBC32-B403-461D-A772-ACD9F5D20BED}" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{DEE8459D-28D8-49E0-8A86-FBAEA0B8C2CF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DEF27660-F68B-48DC-9A14-2FE5F785C42C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DF3A86E8-2E69-470C-A82B-1F834F2F7B2C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DF3D8CFB-4B68-404C-9F67-3D75C7256077}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{DFEDA999-154C-4A41-B50B-FF4999CA83F0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E01C65BD-3E17-4328-B2BB-673B6760E5DF}" = protocol=17 | dir=in | app=c:\program files (x86)\dell v305\dldtamon.exe |
"{E06C443D-61B8-4762-9670-B8E3A1DD6833}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E0AC8287-3220-479E-A5C9-9BB070DD5AD1}" = protocol=17 | dir=in | app=c:\windows\system32\dldtcoms.exe |
"{E0EA91AF-80D1-4741-B23F-95F055525A26}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E1B38D7D-28CB-4641-95C5-E0F78F570131}" = protocol=17 | dir=in | app=c:\program files (x86)\dell v305\wireless\dldtwpss.exe |
"{E1CC2223-0937-4008-B5A7-1898BB5DAAFB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E338E7B2-9FCB-4222-A127-9CEC4D6AEDA7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E43C46FA-0E0B-45EB-ABC3-AA84DFB95F89}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E4CAE8CC-3134-4DA1-8F19-435864703A21}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E4D15249-0125-41EA-BB34-C6E9322FAEBF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E551C693-96BB-43A0-BF0C-7C67D475B347}" = protocol=17 | dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe |
"{E63C1D2F-219A-4A13-9058-131193BC84C2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E7AE2CAE-2F03-472D-A8FB-C63F061E208E}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\dell\vlc\vlc.exe |
"{E7AFDB30-56B8-48E1-B63C-A781E9CE7A04}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E7C610F3-6EBE-4986-BA29-B8650CC4CB5E}" = protocol=6 | dir=in | app=c:\program files (x86)\skype\plugin manager\skypepm.exe |
"{E9663CAA-1F46-4DF6-BADC-6988C2F7CB96}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E977CC80-FB0D-4A82-8642-1298A2B42628}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E9B815AF-0BC5-4CB1-B64C-0783855A3C1D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{EA95D686-FD31-4024-B1CD-71F7876D88D3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{EAA7085E-846F-44D2-A4BF-D2588E958E4C}" = protocol=17 | dir=in | app=c:\program files (x86)\dell v305\frun.exe |
"{EAE028A4-8034-4477-81EA-75BC4A28B7F2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{EB3F9A53-8939-4A34-A99B-DA4DC6636929}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{EC814A44-C8BC-43B3-86ED-18AF67DCBE21}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{EE8F2C4D-6ECA-485A-B0D5-23060716E950}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{EFC80DEA-A3EA-4793-ADC8-A70BF0DF4AEF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F1BE923D-932F-4FBB-8501-64FC2A5668B1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F64CEB69-AE1B-4CE2-84BC-176D83A4DD14}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldttime.exe |
"{F77E9B45-588C-41C5-9B25-061B32252995}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F7ECC5FD-65C2-4A57-85D9-958579F45F74}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F840803C-0290-4C78-A863-BF23B7CCFC88}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{F8603AA8-021D-4986-B323-01653BEC0203}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F8751723-49A4-4765-B2A9-2F4C72B2B411}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{F971307F-D609-4CED-A404-A29B4B2481B2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FA0C4C24-15D2-49D3-B8F4-99DC14FB558C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FA23CB6A-AC45-4CDB-8BCC-384DEE0851C3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FA5819FA-D490-4B65-A814-F0200AB8F64F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FB42C850-EA89-4323-A086-E0D486A3BBF5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FBD4B773-43D2-4051-98B6-D687926162C1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FBDEE49E-8ECB-4C96-901E-99CBA728392D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FC8B7142-266F-43D4-B27A-A88C4840CF39}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FEA1DEEB-5383-4975-A053-69A22599B94F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FFB89EE7-8A33-46E5-9F7C-18C95C644FC5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FFE89F5F-329E-47BC-B9E7-3ECAEC9F4029}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{FFF6C081-52E3-47F1-A4F2-4EA3544082BC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"TCP Query User{2DAD67F0-D7D3-4B5E-B516-72FE4F0E677B}C:\program files (x86)\dell video chat\dellvideochat.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dell video chat\dellvideochat.exe |
"TCP Query User{6B5F0246-3159-4BAB-A005-75219A67A6E9}C:\program files (x86)\dell v305\dldtmon.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dell v305\dldtmon.exe |
"TCP Query User{A617269F-7AB3-41EF-A582-20B56E2F28FB}C:\program files (x86)\oovoo\oovoo.exe" = protocol=6 | dir=in | app=c:\program files (x86)\oovoo\oovoo.exe |
"TCP Query User{BEAF82A5-12D0-425F-AA1F-CCC73350810E}C:\windows\system32\spool\drivers\x64\3\dldtpswx.exe" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldtpswx.exe |
"TCP Query User{ED45E139-D83C-4FE4-BCF9-1E775799F894}C:\program files (x86)\oovoo\oovoo.exe" = protocol=6 | dir=in | app=c:\program files (x86)\oovoo\oovoo.exe |
"UDP Query User{68051CA4-3DA7-465F-B862-09F40A790F94}C:\windows\system32\spool\drivers\x64\3\dldtpswx.exe" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\x64\3\dldtpswx.exe |
"UDP Query User{6C59B14C-3A37-4972-8FE4-034636B6B599}C:\program files (x86)\dell v305\dldtmon.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dell v305\dldtmon.exe |
"UDP Query User{85F70C55-8A37-4ECE-B36F-78AC290CB9A5}C:\program files (x86)\dell video chat\dellvideochat.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dell video chat\dellvideochat.exe |
"UDP Query User{9B6EAA59-C16F-43F4-B11D-24B69606833A}C:\program files (x86)\oovoo\oovoo.exe" = protocol=17 | dir=in | app=c:\program files (x86)\oovoo\oovoo.exe |
"UDP Query User{BE22473E-4FAE-4662-94E5-FC2A7D8AFFEF}C:\program files (x86)\oovoo\oovoo.exe" = protocol=17 | dir=in | app=c:\program files (x86)\oovoo\oovoo.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{26A24AE4-039D-4CA4-87B4-2F86416013FF}" = Java™ 6 Update 13 (64-bit)
"{3A25872A-0F1C-4989-9435-96C13230F818}" = Apple Mobile Device Support
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6F4B9839-F409-4D38-89D6-145321400FED}" = iTunes
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{87CF757E-C1F1-4D22-865C-00C6950B5258}" = Quickset64
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DAE239CE-EB9D-4EB3-B0D4-528D6BAA48FD}" = Bonjour
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F6CB42B9-F033-4152-8813-FF11DA8E6A78}" = Dell Dock
"Creative OA008" = Integrated Webcam Driver (1.04.01.0601)
"Dell V305" = Dell V305
"HDMI" = Intel® Graphics Media Accelerator Driver
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"SynTPDeinstKey" = Dell Touchpad
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{095B1DCF-5E8B-47EC-9B18-481918A731DB}" = Microsoft Default Manager
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}" = Dell DataSafe Online
"{16D2C649-CBA8-44EE-B730-12584667D487}" = Stronghold 2
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1798D459-6B8B-474B-868D-1229EADA3B95}" = Adobe AIR
"{1AE46C09-2AB8-4EE5-88FB-08CD0FF7F2DF}" = Bing Bar
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 24
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java™ 6 Update 22
"{26CE484D-2E8E-40D5-B251-158133114C69}" = TomTom HOME
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}" = Banctec Service Agreement
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AAC5AE8-EDE6-44D4-AA87-E90870178FDE}" = Minitab 15 English
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}" = Windows 7 Upgrade Advisor
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B92C5909-1D37-4C51-8397-A28BB28E5DC3}" = Facebook Video Calling 1.2.0.287
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C8773FDB-D0DB-BE52-D536-F48F9886B57B}" = Adobe Download Assistant
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EF85FEF4-EB92-4075-A6D2-5F519BB30A2C}" = Complete Care Consumer Service Agreement
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F47C37A4-7189-430A-B81D-739FF8A7A554}" = Consumer In-Home Service Agreement
"{F66A31D9-7831-4FBA-BA02-C411C0047CC5}" = Dell Remote Access
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Belarc Advisor" = Belarc Advisor 8.2
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"Dell Video Chat" = Dell Video Chat
"Dell Webcam Central" = Dell Webcam Central
"Google Chrome" = Google Chrome
"GoToAssist" = GoToAssist 8.0.0.514
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IObit Malware Fighter_is1" = IObit Malware Fighter
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Mozilla Firefox 4.0 (x86 en-US)" = Mozilla Firefox 4.0 (x86 en-US)
"N360" = Norton 360
"PopTools_is1" = PopTools
"WinLiveSuite_Wave3" = Windows Live Essentials
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-3805510809-3204643337-4127071045-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f031ef6ac137efc5" = Dell Driver Download Manager
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 3/25/2013 12:20:04 PM | Computer Name = JeremyComputer | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.
Error - 3/25/2013 12:20:28 PM | Computer Name = JeremyComputer | Source = Application Hang | ID = 1002
Description = The program mbam.exe version 1.70.0.9 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 1234 Start Time: 01ce29748f82c83d Termination Time: 17
Error - 3/25/2013 12:41:28 PM | Computer Name = JeremyComputer | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.
Error - 3/26/2013 2:04:50 AM | Computer Name = JeremyComputer | Source = IMFservice | ID = 0
Description =
Error - 3/26/2013 2:04:51 AM | Computer Name = JeremyComputer | Source = IMFservice | ID = 0
Description =
Error - 3/27/2013 11:14:38 AM | Computer Name = JeremyComputer | Source = WinMgmt | ID = 10
Description =
Error - 3/27/2013 12:13:43 PM | Computer Name = JeremyComputer | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.
Error - 3/27/2013 8:03:49 PM | Computer Name = JeremyComputer | Source = WinMgmt | ID = 10
Description =
Error - 3/28/2013 2:15:09 PM | Computer Name = JeremyComputer | Source = WinMgmt | ID = 10
Description =
Error - 3/29/2013 8:15:47 AM | Computer Name = JeremyComputer | Source = WinMgmt | ID = 10
Description =
Error encountered while reading event logs.
< End of report >
Chamby
Here is the aswMBR log
aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-03-29 11:17:33
—————————–
11:17:33.776 OS Version: Windows x64 6.0.6002 Service Pack 2
11:17:33.776 Number of processors: 2 586 0x170A
11:17:33.777 ComputerName: JEREMYCOMPUTER UserName: admin
11:17:38.541 Initialize success
11:23:56.282 AVAST engine defs: 13032900
11:32:30.779 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
11:32:30.786 Disk 0 Vendor: WDC_WD5000BEVT-75ZAT0 01.01A01 Size: 476940MB BusType: 3
11:32:31.090 Disk 0 MBR read successfully
11:32:31.094 Disk 0 MBR scan
11:32:31.102 Disk 0 Windows VISTA default MBR code
11:32:31.107 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
11:32:31.128 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 15000 MB offset 80325
11:32:31.151 Disk 0 Partition 3 80 (A) 07 HPFS/NTFS NTFS 461899 MB offset 30800325
11:32:31.455 Disk 0 scanning C:\Windows\system32\drivers
11:32:48.609 Service scanning
11:33:21.222 Modules scanning
11:33:21.236 Disk 0 trace - called modules:
11:33:21.261 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
11:33:21.627 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8005bec790]
11:33:21.641 3 CLASSPNP.SYS[fffffa6000fd0c33] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004be3060]
11:33:24.790 AVAST engine scan C:\Windows
11:33:33.134 AVAST engine scan C:\Windows\system32
11:39:08.507 AVAST engine scan C:\Windows\system32\drivers
11:39:54.616 AVAST engine scan C:\Users\admin
11:48:28.439 AVAST engine scan C:\ProgramData
11:51:30.360 Scan finished successfully
11:53:02.660 Disk 0 MBR has been saved successfully to "C:\Users\admin\Desktop\MBR.dat"
11:53:02.669 The log file has been saved successfully to "C:\Users\admin\Desktop\aswMBR.txt"
Satchfan
Hi
I recommend that you uninstall IObit. It is has been proved to be untrustworthy in its programming and is pretty ineffective now that it can no longer be propped up by MBAM
See:
http://forums.malwarebytes.org/index.php?showtopic=29681
http://forums.malwarebytes.org/index.php?showtopic=30989
http://forums.malwarebytes.org/index.php?showtopic=33217
===================================================
Run McAfee removal tool
run McAfee Removal Tool
===================================================
Download and run AdwCleaner
Download AdwCleaner from here and save it to your desktop.
Download and run Junkware Removal Tool
[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
===================================================
Run RogueKiller
IMPORTANT: Please remove any usb or external drives from the computer before you run this scan!
Close all running programs.
Download RogueKiller to your desktop.
Please post the contents of the RKreport.txt in your next reply.
AdwCleaner log
JRT.txt
RKreport.txt
Thanks
Satchfan
I recommend that you uninstall IObit. It is has been proved to be untrustworthy in its programming and is pretty ineffective now that it can no longer be propped up by MBAM
See:
http://forums.malwarebytes.org/index.php?showtopic=29681
http://forums.malwarebytes.org/index.php?showtopic=30989
http://forums.malwarebytes.org/index.php?showtopic=33217
===================================================
Run McAfee removal tool
run McAfee Removal Tool
===================================================
Download and run AdwCleaner
Download AdwCleaner from here and save it to your desktop.
- run AdwCleaner and select Delete
- when it has finished it will ask to reboot - allow the reboot
- on reboot a log will be produced; please attach the content of the log to your next reply
Download and run Junkware Removal Tool
[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
- shut down your protection software now to avoid potential conflicts.
- run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
- the tool will open and start scanning your system
- please be patient as this can take a while to complete depending on your system's specifications
- on completion, a log (JRT.txt) is saved to your desktop and will automatically open
- post the contents of JRT.txt into your next message.
===================================================
Run RogueKiller
IMPORTANT: Please remove any usb or external drives from the computer before you run this scan!
Close all running programs.
Download RogueKiller to your desktop.
- close all running programs
- for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
- when the pre-scan is finished, click on Scan
- click on Report and copy/paste the content in your next post
- NOTE: DO NOT attempt to remove anything that the scan detects –everything that is reported is not necessarily bad
Please post the contents of the RKreport.txt in your next reply.
AdwCleaner log
JRT.txt
RKreport.txt
Thanks
Satchfan
Chamby
One question. My mousepad on my laptop is broken so i use a wireless usb mouse, do i have to remove that before i run Rogue Killer?
Satchfan
No.
Chamby
# AdwCleaner v2.115 - Logfile created 03/31/2013 at 09:07:40
# Updated 17/03/2013 by Xplode
# Operating system : Windows ™ Vista Home Premium Service Pack 2 (64 bits)
# User : admin - JEREMYCOMPUTER
# Boot Mode : Normal
# Running from : C:\Users\admin\Downloads\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
Deleted on reboot : C:\Users\admin\AppData\Local\APN
Deleted on reboot : C:\Users\admin\AppData\Local\PackageAware
File Deleted : C:\Program Files (x86)\Mozilla Firefox\.autoreg
***** [Registry] *****
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKCU\Software\StartSearch
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Key Deleted : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
***** [Internet Browsers] *****
-\\ Internet Explorer v8.0.6001.19401
[OK] Registry is clean.
-\\ Mozilla Firefox v4.0 (en-US)
File : C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjqu125v.default\prefs.js
[OK] File is clean.
-\\ Google Chrome v26.0.1410.43
File : C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [1666 octets] - [31/03/2013 09:07:12]
AdwCleaner[S1].txt - [1468 octets] - [31/03/2013 09:07:40]
########## EOF - C:\AdwCleaner[S1].txt - [1528 octets] ##########
Chamby
I just tried to download junkware removal tool and it said it might be malicious? Do I need to turn off my software protection first?
Satchfan
I just tried to download junkware removal tool and it said it might be malicious? Do I need to turn off my software protection first?
Download and run Junkware Removal Tool
[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
- shut down your protection software now to avoid potential conflicts.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI