This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Linksys tech says computer full of malware and viruses & putting a

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am logging on here with my old Win XP computer which is the one our Linksys router and cable internet box are plugged into.  The laptops I use are on wifi through the same router and cable box.

 

This problem started with our internet going down multiple times per day and this has been an ongoing problem for around 6 months but it suddenly escalated to around every 5 minutes.  The Linksys router is around 10 years old.   My son got kicked out of most of his games on Xbox Live so many times,  he called them because he couldn't get back into his account.

 

My son had ports set up in the router so he could play the games on Xbox Live. When he called them,  the tech had him reset the router to factory settings and delete his profile on the website.

 

He could not get back on and Xbox Live told him he was going to have to call Linksys to have them redo the path?? or open the correct ports in order for him to log back into Xbox Live.

 

He called them tonight and the tech at Linksys requested permission to log into my Win XP computer.   My son gave him permission to do so.

 

At that time,  the tech then began going through my desktop and told my son this computer has many issues, including bank statements (true),viruses, trojans, malware and told my son he was going to clean out my computer,  change the settings,  delete things that should not be on here and basically take over the computer.

 

Then he requested my son to go to my laptop and enter a cmd prompt and search for errors on that computer.   Apparently he had already done that with this XP desktop  and was showing my son all kinds of errors and corrupt files and maybe the names of the infections he said were in the computer.

 

My son was becoming more and more alarmed at what this guy was doing and finally refused to let him proceed, further.

 

This tech told my son that this Win XP computer is acting as the server for all devices in the household and because of all the viruses, etc,  that is why we are getting disconnected from the internet.  He said it was not the router, nor the cable box.

 

If that were true, then this problem would have been happening all along, not just now.  And that is not what Xbox Live told my son, either.  The problem is really supposed to be the ports and if my son could just open them, again, he could get back into the games he plays.   However, this would not fix the connection problem which I really feel has nothing to do with the above, anyway.

 

I just ran a new version of Malwarebytes and am including that log. I have Avira on here but it will not work.  Your techs have tried to direct me with various programs that should delete it but it will not delete.  So I am stuck with a non-working antivirus program at this time, on this computer.

 

I am sorry this is so long but I felt it was very important to tell you what kinds of crazy things have been going on, here, with the computer,  the router, cable box,  connection and now this tech who was looking around at everything in my computer.

 

Here is the log.

 

Thank you!

 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 4/2/2015
Scan Time: 9:02:09 PM
Logfile: 
Administrator: Yes
 
Version: 2.00.4.1028
Malware Database: v2015.04.03.01
Rootkit Database: v2015.03.31.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows XP Service Pack 3
CPU: x86
File System: NTFS
User: Sony
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 400874
Time Elapsed: 47 min, 52 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 1
PUP.Optional.ShopToWin.A, HKU\S-1-5-21-1825112312-1052192824-3671610397-1006-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{20FEC4E7-F7B7-438B-8191-33D2EFC5EBEA}, Quarantined, [db52ef794e3ccd69f7d6270d1be89868], 
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 0
(No malicious items detected)
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)

:welcome:

 

Lets run a few scans and see whats going on, lets run these scans on the XP system, are you experiencing any problems on your laptops ?  I guess you know by now that Microsoft discontinued all support for XP, it went the way of Windows 95 and 98, you can still use XP, but without the windows updates that have been discontinued your leaving your system open to infections.

 

 
[external image: 1QYkxTZ.jpg] Please download aswMBR to your desktop.
 
  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
  •  
    I just want to see the report….Please Do Not Fix Anything
     
    ============================================================================
     
     
     
     
    Please download Farbar Recovery Scan Tool and save it to your desktop.
     
    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
     
    How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
    A simple way to check your system: Start –> Computer (right click) –> Properties
     
    [external image: FRST_zps5d956a1a.jpg]
     
     
    • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
    • Please make sure All Users is checked
    • Just keep the defaults as in the picture checkmarked
    • Press Scan button.
    • It will produce a log called FRST.txt in the same directory the tool is run from.
    • Please copy and paste log back here.
    • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
    • Hi,

       

      The laptop I have been using for several months is working fine.  The other one has been put away for the same amount of time. It's an older Vista laptop with some hard drive damage but other wise,  works fine. Both check out ok as far as malware, etc.  are concerned.

       

      I do know XP is no longer supported and did not know what to do as this computer is so old and so full of movies and graphics my son has put on it.  It took ages to run the 1st scan, probably due to so much on here.

       

      Here are the logs.  Thank you!

       

       

      aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
      Run date: 2015-04-05 01:38:20
      —————————–
      01:38:20.234    OS Version: Windows 5.1.2600 Service Pack 3
      01:38:20.234    Number of processors: 2 586 0x401
      01:38:20.234    ComputerName: INNUENDOES  UserName: Sony
      01:38:39.359    Initialize success
      01:38:39.937    VM: initialized successfully
      01:38:39.937    VM: Intel CPU virtualization not supported 
      01:43:28.031    AVAST engine defs: 15040401
      01:46:13.796    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-17
      01:46:13.796    Disk 0 Vendor: ST3200822AS 3.02 Size: 190782MB BusType: 3
      01:46:14.062    Disk 0 MBR read successfully
      01:46:14.062    Disk 0 MBR scan
      01:46:14.140    Disk 0 Windows XP default MBR code
      01:46:14.140    Disk 0 Partition 1 00     12  Compaq diag NTFS         6149 MB offset 63
      01:46:14.171    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS       184629 MB offset 12594960
      01:46:14.171    Disk 0 default boot code
      01:46:14.187    Disk 0 scanning sectors +390716865
      01:46:14.234    Disk 0 malicious Win32:MBRoot code @ sector 390716868 !
      01:46:14.234    Disk 0 PE file @ sector 390716890 !
      01:46:14.359    Disk 0 scanning C:\WINDOWS\system32\drivers
      01:46:46.796    Service scanning
      01:47:37.343    Modules scanning
      01:47:37.343    Disk 0 trace - called modules:
      01:47:37.375    ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys 
      01:47:37.375    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a740ab8]
      01:47:37.375    3 CLASSPNP.SYS[ba108fd7] -> nt!IofCallDriver -> \Device\00000066[0x8a78f180]
      01:47:37.375    5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-17[0x8a742940]
      01:47:40.562    AVAST engine scan C:\WINDOWS
      01:48:22.187    AVAST engine scan C:\WINDOWS\system32
      02:02:10.937    AVAST engine scan C:\WINDOWS\system32\drivers
      02:03:16.203    AVAST engine scan C:\Documents and Settings\Sony
      06:06:26.078    AVAST engine scan C:\Documents and Settings\All Users
      06:28:36.203    Disk 0 statistics 3572345/0/0 @ 0.13 MB/s
      06:28:36.218    Scan finished successfully
      06:45:38.437    Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Sony\Desktop\Anti Spyware\MBR.dat"
      06:45:38.453    The log file has been saved successfully to "C:\Documents and Settings\Sony\Desktop\Anti Spyware\aswMBR.txt"
       
       
      Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
      Ran by [removed] (administrator) on INNUENDOES on 05-04-2015 06:49:21
      Running from C:\Documents and Settings\[removed]\Desktop\Anti Spyware
      [removed]
      Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: English (United States)
      Internet Explorer Version 8 (Default browser: Chrome)
      Boot Mode: Normal
      Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
       
      ==================== Processes (Whitelisted) =================
       
      (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
       
      (AOL LLC) C:\Program Files\Common Files\AOL\1147670399\ee\aolsoftware.exe
      (Agere Systems) C:\WINDOWS\AGRSMMSG.exe
      (Realtek Semiconductor Corp.) C:\WINDOWS\SOUNDMAN.EXE
      (Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
      (Sony Corporation) C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
      (Seagate LLC) C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
      (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
      (America Online, Inc.) C:\Program Files\America Online 9.0a\aoltray.exe
      (AOL LLC) C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
      (Seagate Technology LLC) C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
      (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
      (Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
      (America Online, Inc.) C:\WINDOWS\wanmpsvc.exe
      (Yahoo! Inc.) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
      (Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
      (Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
      (Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
      (Yahoo! Inc.) C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
      (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
       
       
      ==================== Registry (Whitelisted) ==================
       
      (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
       
      HKLM\…\Run: [HostManager] => C:\Program Files\Common Files\AOL\1147670399\ee\AOLSoftware.exe [41824 2007-10-08] (AOL LLC)
      HKLM\…\Run: [AGRSMMSG] => C:\WINDOWS\AGRSMMSG.exe [88363 2004-10-08] (Agere Systems)
      HKLM\…\Run: [SoundMan] => C:\WINDOWS\SOUNDMAN.EXE [77824 2004-10-21] (Realtek Semiconductor Corp.)
      HKLM\…\Run: [AlcWzrd] => C:\WINDOWS\ALCWZRD.EXE [2744832 2004-10-21] (RealTek Semicoductor Corp.)
      HKLM\…\Run: [High Definition Audio Property Page Shortcut] => C:\WINDOWS\system32\HDAudPropShortcut.exe [61952 2004-08-12] (Windows (R) Server 2003 DDK provider)
      HKLM\…\Run: [CreateCD_Reminder] => C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe [53248 2004-07-16] (Sony Electronics, Inc)
      HKLM\…\Run: [ATIPTA] => C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [344064 2004-09-10] (ATI Technologies, Inc.)
      HKLM\…\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [413696 2009-01-05] (Apple Inc.)
      HKLM\…\Run: [VAIO Update 3] => C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe [551032 2007-05-15] (Sony Corporation)
      HKLM\…\Run: [MaxMenuMgr] => C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe [185640 2009-09-26] (Seagate LLC)
      HKLM\…\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
      HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)
      Winlogon\Notify\AtiExtEvent: C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
      Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
      HKU\S-1-5-21-1825112312-1052192824-3671610397-1006\…\Run: [Messenger (Yahoo!)] => C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [4363504 2009-03-18] (Yahoo! Inc.)
      HKU\S-1-5-21-1825112312-1052192824-3671610397-1006\…\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [204288 2006-10-18] (Microsoft Corporation)
      HKU\S-1-5-21-1825112312-1052192824-3671610397-1006\…\Run: [Xvid] => C:\Program Files\Xvid\CheckUpdate.exe [8192 2011-01-17] ()
      Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
      ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
      Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AOL 9.1 Tray Icon.lnk
      ShortcutTarget: AOL 9.1 Tray Icon.lnk -> C:\Program Files\America Online 9.0a\aoltray.exe (America Online, Inc.)
      ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
       
      ==================== Internet (Whitelisted) ====================
       
      (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
       
      HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
      HKU\S-1-5-21-1825112312-1052192824-3671610397-1006\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
      HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
      HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
      HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sony.com/vaiopeople
      HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sony.com/vaiopeople
      HKU\S-1-5-21-1825112312-1052192824-3671610397-1006\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
      SearchScopes: HKLM -> DefaultScope value is missing.
      SearchScopes: HKLM -> {2381E4B7-5C04-459E-9D46-2F9AC1608B66} URL = http://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=ysp
      SearchScopes: HKU\S-1-5-19 -> {2381E4B7-5C04-459E-9D46-2F9AC1608B66} URL = http://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=ysp
      SearchScopes: HKU\S-1-5-20 -> {2381E4B7-5C04-459E-9D46-2F9AC1608B66} URL = http://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=ysp
      SearchScopes: HKU\S-1-5-21-1825112312-1052192824-3671610397-1006 -> DefaultScope {2381E4B7-5C04-459E-9D46-2F9AC1608B66} URL = http://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=ysp
      SearchScopes: HKU\S-1-5-21-1825112312-1052192824-3671610397-1006 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/search
      SearchScopes: HKU\S-1-5-21-1825112312-1052192824-3671610397-1006 -> {080FBDF6-B230-4e4d-A4E7-7C7A56D7BABC} URL = http://searchservice.myspace.com/index.cfm?fuseaction=sitesearch.results&qry;={searchTerms}&type;=Web&orig;=IMC-IE
      SearchScopes: HKU\S-1-5-21-1825112312-1052192824-3671610397-1006 -> {2381E4B7-5C04-459E-9D46-2F9AC1608B66} URL = http://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=ysp
      BHO: Yahooo Search Protection -> {25BC7718-0BFA-40EA-B381-4B2D9732D686} -> C:\Program Files\Yahoo!\Search Protection\ysp.dll [2010-03-31] (Yahoo! Inc.)
      BHO: Yahoo! IE Services Button -> {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -> C:\Program Files\Yahoo!\common\yiesrvc.dll [2006-10-31] (Yahoo! Inc.)
      BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-01-30] (Oracle Corporation)
      BHO: AOL Toolbar Launcher -> {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} -> C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2007-03-23] (AOL LLC)
      BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-30] (Oracle Corporation)
      BHO: SidebarAutoLaunch Class -> {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} -> C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll [2005-02-03] (Yahoo! Inc.)
      BHO: SingleInstance Class -> {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -> C:\Program Files\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll [2010-03-23] (Yahoo! Inc)
      Toolbar: HKLM - AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2007-03-23] (AOL LLC)
      Toolbar: HKU\S-1-5-21-1825112312-1052192824-3671610397-1006 -> AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2007-03-23] (AOL LLC)
      DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab
      DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} http://esupport.sony.com/VaioInfo.CAB
      DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
      DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/betapit/PCPitStop.CAB
      DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
      DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} http://download.ewido.net/ewidoOnlineScan.cab
      DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
      DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
      DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} http://forms.real.com/real/player/download.html?f=windows/mrkt/rhapx/RhapsodyPlayerEngine_Inst_Win.cab
      DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
      DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} http://www.auctiva.com/Aurigma/ImageUploader55.cab
      DPF: {528C14CD-CF9E-489C-A365-5999F17B69B9} http://pictures.sprintpcs.com/activex/LightSurfUploadControl.cab
      DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab
      DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/scan8/oscan8.cab
      DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab
      DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
      DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} http://mediaplayer.walmart.com/installer/install.cab
      DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
      DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
      DPF: {9732FB42-C321-11D1-836F-00A0C993F125} http://www.pcpitstop.com/mhLbl.cab
      DPF: {D1D98C0F-A339-42AB-BD5F-EA0FF5D0E65F} http://www.rockyou.com/RockYouImageUploader.cab
      DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
      DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
      DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
      Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
       
      FireFox:
      ========
      FF ProfilePath: C:\Documents and Settings\Sony\Application Data\Mozilla\Firefox\Profiles\vdvxu7xx.default
      FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-05] ()
      FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-30] (Oracle Corporation)
      FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-30] (Oracle Corporation)
      FF Plugin: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.1 -> C:\Program Files\Yahoo!\Shared\npYState.dll [2009-03-18] (Yahoo! Inc.)
      FF Plugin: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files\Yahoo!\Shared\npYState.dll [2009-03-18] (Yahoo! Inc.)
      FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
      FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
      FF Plugin: @real.com/nppl3260;version=6.0.11.2571 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2007-03-03] (RealNetworks, Inc.)
      FF Plugin: @real.com/nprjplug;version=1.0.2.2629 -> C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll [2007-03-03] (RealNetworks, Inc.)
      FF Plugin: @real.com/nprpjplug;version=6.0.12.1739 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll [2007-03-03] (RealNetworks, Inc.)
      FF Plugin: @real.com/RhapsodyPlayerEngine,version=1.0 -> C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll [2006-03-31] (RealNetworks, Inc.)
      FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-20] (Google Inc.)
      FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-20] (Google Inc.)
      FF Plugin: @viewpoint.com/VMP -> C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll [2003-08-09] ()
      FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
      FF Plugin HKU\S-1-5-21-1825112312-1052192824-3671610397-1006: @unity3d.com/UnityPlayer,version=1.0 -> C:\Documents and Settings\Sony\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll [2014-02-20] (Unity Technologies ApS)
      FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2013-12-18] (Adobe Systems Inc.)
      FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2015-03-24]
      FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
      FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-03-27]
       
      Chrome: 
      =======
      CHR HomePage: Default -> hxxp://www.google.com/
      CHR StartupUrls: Default -> "hxxp://www.google.com/"
      CHR Profile: C:\Documents and Settings\Sony\Local Settings\Application Data\Google\Chrome\User Data\Default
      CHR Extension: (Adblock Plus) - C:\Documents and Settings\Sony\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-02-21]
      CHR Extension: (Chrome Hotword Shared Module) - C:\Documents and Settings\Sony\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-02]
      CHR Extension: (Google Wallet) - C:\Documents and Settings\Sony\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-29]
       
      ========================== Services (Whitelisted) =================
       
      (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
       
      R2 AOL ACS; C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe [46640 2006-10-23] (AOL LLC)
      R2 FreeAgentGoNext Service; C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe [189736 2009-09-26] (Seagate Technology LLC)
      S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
      S3 Image Converter video recording monitor for VAIO Entertainment; C:\Program Files\Sony\Image Converter 2\IcVzMon.exe [32768 2005-02-15] (Sony Corporation) [File not signed]
      S3 MSCSPTISRV; C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe [53337 2005-01-26] (Sony Corporation) [File not signed]
      R2 MSSQL$VAIO_VEDB; C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [7520337 2002-12-17] (Microsoft Corporation) [File not signed]
      S3 MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [66112 2002-12-17] (Microsoft Corporation) [File not signed]
      S3 PACSPTISVR; C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [53337 2005-01-26] (Sony Corporation) [File not signed]
      S3 SPTISRV; C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe [69718 2005-01-26] (Sony Corporation) [File not signed]
      S3 SQLAgent$VAIO_VEDB; C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [311872 2002-12-17] (Microsoft Corporation) [File not signed]
      S3 SSScsiSV; C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe [69632 2005-01-24] (Sony Corporation) [File not signed]
      S3 VAIO Entertainment Aggregation and Control Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe [143360 2005-02-09] (Sony Corporation) [File not signed]
      S3 VAIO Entertainment Task Scheduler; C:\Program Files\Sony\vaio entertainment\VzTaskScheduler.exe [397312 2005-02-10] (Sony Corporation) [File not signed]
      S3 VAIO Entertainment TV Device Arbitration Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe [73728 2005-02-09] (Sony Corporation) [File not signed]
      S3 VAIOMediaPlatform-IntegratedServer-AppServer; C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe [1847296 2006-02-20] (Sony Corporation) [File not signed]
      S3 VAIOMediaPlatform-IntegratedServer-HTTP; C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [57344 2005-01-14] (Sony Corporation) [File not signed]
      S3 VAIOMediaPlatform-IntegratedServer-UPnP; C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [745472 2005-01-14] (Sony Corporation) [File not signed]
      S3 VAIOMediaPlatform-Mobile-Gateway; C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe [188416 2005-01-14] (Sony Corporation) [File not signed]
      R3 Vcsw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [270336 2005-02-09] (Sony Corporation) [File not signed]
      R2 VzCdbSvc; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [167936 2005-02-09] (Sony Corporation) [File not signed]
      R2 VzFw; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe [135168 2005-02-09] (Sony Corporation) [File not signed]
      R2 WANMiniportService; C:\WINDOWS\wanmpsvc.exe [65536 2003-08-27] (America Online, Inc.) [File not signed]
      S2 SpyroService; "C:\Program Files\FS\Spyro Portal\FlashPortal.exe" [X]
       
      ==================== Drivers (Whitelisted) ====================
       
      (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
       
      R2 Aspi32; C:\WINDOWS\System32\drivers\aspi32.sys [16512 2004-07-19] (Adaptec) [File not signed]
      S3 HdAudAddService; C:\WINDOWS\System32\drivers\HdAudio.sys [113664 2004-08-12] (Windows (R) Server 2003 DDK provider)
      S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [114904 2015-04-02] (Malwarebytes Corporation)
      R1 ssmdrv; C:\WINDOWS\System32\DRIVERS\ssmdrv.sys [28520 2009-05-11] (Avira GmbH)
      S3 TVICHW32; C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS [23600 2007-11-10] (EnTech Taiwan) [File not signed]
      R3 wanatw; C:\WINDOWS\System32\DRIVERS\wanatw4.sys [33588 2003-01-10] (America Online, Inc.)
      U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
      U3 TlntSvr; No ImagePath
      S2 tmcomm; \??\C:\WINDOWS\system32\drivers\tmcomm.sys [X]
      U1 WS2IFSL; No ImagePath
      U3 aswMBR; \??\C:\DOCUME~1\Sony\LOCALS~1\Temp\aswMBR.sys [X]
      U3 aswVmm; \??\C:\DOCUME~1\Sony\LOCALS~1\Temp\aswVmm.sys [X]
       
      ==================== NetSvcs (Whitelisted) ===================
       
      (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
       
       
      ==================== One Month Created Files and Folders ========
       
      (If an entry is included in the fixlist, the file\folder will be moved.)
       
      2015-04-05 06:48 - 2015-04-05 06:49 - 00000000 ____D () C:\FRST
      2015-04-02 21:01 - 2015-04-02 21:02 - 00114904 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
      2015-04-02 20:50 - 2015-04-02 20:50 - 00000777 _____ () C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
      2015-04-02 20:50 - 2015-04-02 20:50 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
      2015-04-02 20:50 - 2015-04-02 20:50 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
      2015-04-02 20:50 - 2014-11-21 06:14 - 00054360 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
      2015-04-02 20:41 - 2015-04-02 20:42 - 00001293 _____ () C:\Documents and Settings\Sony\Desktop\linksys tech chat.txt
      2015-03-31 21:08 - 2015-03-31 21:08 - 00002010 _____ () C:\Documents and Settings\All Users\Desktop\PortForward Network Utilities.lnk
      2015-03-31 21:08 - 2015-03-31 21:08 - 00000000 ____D () C:\Program Files\Portforward
      2015-03-31 21:08 - 2015-03-31 21:08 - 00000000 ____D () C:\Documents and Settings\Sony\Application Data\PortForward.com
      2015-03-31 21:08 - 2015-03-31 21:08 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\PortForward.com
      2015-03-31 21:07 - 2015-03-31 21:07 - 03618904 _____ (Portforward, LLC) C:\Documents and Settings\Sony\Desktop\setup-network-utilities.exe
      2015-03-24 17:16 - 2015-03-24 17:18 - 00000000 ____D () C:\Program Files\Mozilla Firefox
      2015-03-13 16:15 - 2015-03-13 16:22 - 00000000 ____D () C:\Documents and Settings\Sony\Desktop\Jilldeaths
       
      ==================== One Month Modified Files and Folders =======
       
      (If an entry is included in the fixlist, the file\folder will be moved.)
       
      2015-04-05 06:50 - 2011-05-09 20:15 - 00000000 ____D () C:\Documents and Settings\Sony\Local Settings\temp
      2015-04-05 06:49 - 2009-05-07 13:11 - 00000000 ___RD () C:\Documents and Settings\Sony\Desktop\Anti Spyware
      2015-04-05 06:46 - 2008-10-19 06:45 - 00000254 _____ () C:\WINDOWS\wiadebug.log
      2015-04-05 06:38 - 2012-07-14 05:24 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
      2015-04-05 06:29 - 2013-02-20 10:43 - 00000886 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
      2015-04-05 05:07 - 2011-05-03 01:27 - 01564696 _____ () C:\WINDOWS\WindowsUpdate.log
      2015-04-05 02:39 - 2013-02-20 10:46 - 00001813 _____ () C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
      2015-04-05 01:31 - 2008-10-19 06:45 - 00000048 _____ () C:\WINDOWS\wiaservc.log
      2015-04-05 01:31 - 2005-03-02 18:45 - 00001158 _____ () C:\WINDOWS\system32\wpa.dbl
      2015-04-05 01:30 - 2014-03-18 15:25 - 00000220 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
      2015-04-05 01:30 - 2014-02-02 23:24 - 00000360 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job
      2015-04-05 01:30 - 2013-02-20 10:43 - 00000882 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
      2015-04-05 01:30 - 2005-03-02 19:59 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
      2015-04-02 23:49 - 2007-01-13 02:16 - 00032454 _____ () C:\WINDOWS\SchedLgU.Txt
      2015-04-02 23:47 - 2005-07-04 17:39 - 00000178 ___SH () C:\Documents and Settings\Sony\ntuser.ini
      2015-04-02 20:50 - 2008-06-25 01:34 - 00000000 ____D () C:\Documents and Settings\Sony\Application Data\Malwarebytes
      2015-04-02 20:50 - 2008-06-25 01:34 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Malwarebytes
      2015-03-31 21:07 - 2009-11-06 10:39 - 00000000 ____D () C:\Documents and Settings\Sony\Local Settings\Application Data\Downloaded Installations
      2015-03-26 14:37 - 2012-04-26 12:11 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
      2015-03-13 16:23 - 2015-02-22 11:46 - 00000000 ____D () C:\Documents and Settings\Sony\Desktop\ResidentEvil&WOT1;
      2015-03-13 15:56 - 2014-10-31 17:16 - 00000000 ____D () C:\Documents and Settings\Sony\Desktop\RobertHalloweenfolder2014
      2015-03-11 20:23 - 2013-08-16 15:54 - 00000000 ____D () C:\WINDOWS\system32\MRT
      2015-03-11 20:09 - 2005-12-31 05:08 - 119837696 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
      2015-03-09 17:45 - 2014-03-18 15:25 - 00000214 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
      2015-03-09 14:03 - 2005-03-02 11:50 - 00548768 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
       
      ==================== Files in the root of some directories =======
       
      2009-08-05 16:22 - 2009-08-05 16:24 - 8050536 _____ (Mozilla) C:\Program Files\Firefox+Setup+3[2].5.2.exe
      2006-02-15 22:55 - 2006-02-15 22:55 - 2817536 _____ (Citrix Systems, Inc.) C:\Program Files\ica32t.exe
      2006-05-24 18:29 - 2006-05-24 18:29 - 37311488 _____ (Apple Computer, Inc.                                      ) C:\Program Files\iTunesSetup.exe
      2006-02-18 02:33 - 2006-02-18 02:33 - 0058368 _____ () C:\Program Files\MFInstall.exe
      2006-02-15 23:01 - 2006-02-15 23:02 - 1951432 _____ (Microsoft Corporation) C:\Program Files\ppviewer.exe
      2006-02-15 22:54 - 2006-02-15 22:54 - 7789851 _____ (Xstream Software Inc.                                       ) C:\Program Files\rpv40plgIEu.exe
      2006-02-19 23:11 - 2006-02-19 23:11 - 1931216 _____ (Sony Corporation                                            ) C:\Program Files\SetupSonyDownloadTaxi.exe
      2006-02-15 23:04 - 2006-02-15 23:05 - 12307656 _____ (Microsoft Corporation) C:\Program Files\wdviewer.exe
      2006-02-15 23:17 - 2006-02-15 23:17 - 10420936 _____ (Microsoft Corporation) C:\Program Files\xlviewer.exe
      2008-03-30 14:30 - 2008-03-30 14:30 - 0102661 _____ () C:\Documents and Settings\Sony\Application Data\PatchUpdate_HP_CounterReport_Update_HPSU.log
      2005-07-28 19:25 - 2005-07-28 19:25 - 0012358 _____ () C:\Documents and Settings\Sony\Application Data\PFP120JCM.{PB
      2005-07-28 19:25 - 2005-07-28 19:25 - 0061678 _____ () C:\Documents and Settings\Sony\Application Data\PFP120JPR.{PB
      2011-03-29 22:33 - 2011-03-29 22:33 - 0000000 _____ () C:\Documents and Settings\Sony\Application Data\protectionwin.ini
      2008-03-30 14:26 - 2008-03-30 14:26 - 0039489 _____ () C:\Documents and Settings\Sony\Application Data\Update_HP_RedboxHprblog_HPSU.log
      2011-04-25 18:36 - 2011-04-25 18:40 - 0013436 ___SH () C:\Documents and Settings\Sony\Local Settings\Application Data\728d8r8641b7v7slg6xd5614lw38o
      2006-01-28 21:30 - 2015-01-30 09:35 - 0064000 _____ () C:\Documents and Settings\Sony\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
       
      Some content of TEMP:
      ====================
      C:\Documents and Settings\Sony\Local Settings\temp\bdfilters.dll
      C:\Documents and Settings\Sony\Local Settings\temp\BDMPEG1SETUP.EXE
      C:\Documents and Settings\Sony\Local Settings\temp\jre-8u31-windows-au.exe
       
       
      ==================== Bamital & volsnap Check =================
       
      (There is no automatic fix for files that do not pass verification.)
       
      C:\WINDOWS\explorer.exe => File is digitally signed
      C:\WINDOWS\system32\winlogon.exe => File is digitally signed
      C:\WINDOWS\system32\svchost.exe => File is digitally signed
      C:\WINDOWS\system32\services.exe => File is digitally signed
      C:\WINDOWS\system32\User32.dll => File is digitally signed
      C:\WINDOWS\system32\userinit.exe => File is digitally signed
      C:\WINDOWS\system32\rpcss.dll => File is digitally signed
      C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
       
      ==================== End Of Log ============================
       
      Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-03-2015
      Ran by [removed] at 2015-04-05 06:51:12
      Running from C:\Documents and Settings\[removed]\Desktop\Anti Spyware
      Boot Mode: Normal
      ==========================================================
       
       
      ==================== Security Center ========================
       
      (If an entry is included in the fixlist, it will be removed.)
       
       
      ==================== Installed Programs ======================
       
      (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
       
      20,000 Recipes (HKLM\…\20,000 Recipes) (Version:  - )
      Adobe Flash Player 16 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated)
      Adobe Flash Player 16 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
      Adobe Photoshop 7.0 (HKLM\…\Adobe Photoshop 7.0) (Version: 7.0 - Adobe Systems, Inc.)
      Adobe Photoshop Album 2.0 Starter Edition (HKLM\…\{11B569C2-4BF6-4ED0-9D17-A4273943CB24}) (Version: 2.00.100 - Adobe Systems, Inc.)
      Adobe Reader XI (11.0.08) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
      Adobe Shockwave Player (HKLM\…\Adobe Shockwave Player) (Version: 10.1.3.18 - Adobe Systems, Inc.)
      Adobe SVG Viewer 3.0 (HKLM\…\Adobe SVG Viewer) (Version:  3.0 - )
      Agere Systems PCI Soft Modem (HKLM\…\Agere Systems Soft Modem) (Version:  - )
      America Online (Choose which version to remove) (HKLM\…\America Online us) (Version:  - )
      AOL Coach Version 1.0(Build:20030807.3) (HKLM\…\AolCoach) (Version:  - )
      AOL Coach Version 2.0(Build:20041026.5 en) (HKLM\…\AolCoach2_en) (Version:  - )
      AOL Setup (HKLM\…\AOL Setup) (Version:  - )
      AOL Toolbar 5.0 (HKLM\…\AOL Toolbar) (Version:  - )
      AOL Uninstaller (Choose which Products to Remove) (HKLM\…\AOL Uninstaller) (Version:  - )
      Apple Software Update (HKLM\…\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}) (Version: 2.1.1.116 - Apple Inc.)
      AT&T; Yahoo! Applications (HKLM\…\Yahoo! Applications) (Version:  - )
      ATI - Software Uninstall Utility (HKLM\…\All ATI Software) (Version: 6.14.10.1010 - )
      ATI Control Panel (HKLM\…\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}) (Version: 6.14.10.5125 - )
      ATI Display Driver (HKLM\…\ATI Display Driver) (Version: 8.06-040909a-018341C-Sony - )
      Bandicam (HKLM\…\Bandicam) (Version: 2.1.2.740 - Bandisoft.com)
      Bandisoft MPEG-1 Decoder (HKLM\…\BandiMPEG1) (Version:  - Bandisoft.com)
      BufferChm (Version: 53.0.13.000 - Hewlett-Packard) Hidden
      CCleaner (remove only) (HKLM\…\CCleaner) (Version:  - Piriform)
      Click to DVD 2.0.03 Menu Data (HKLM\…\{9E407618-D9CD-4F39-9490-9ED45294073D}) (Version: 2.0.03 - Sony Corporation)
      Click to DVD 2.4.12 (HKLM\…\{A4870F16-380A-47D5-B30F-45A99FED3403}) (Version:  - )
      Click to DVD 2.4.12 (HKLM\…\{BC5E5F8F-0BA2-480A-94C4-0E65D4FA8238}) (Version:  - )
      Click to DVD 2.4.12 (HKLM\…\{E809063C-51A3-4269-8984-D1EB742F2151}) (Version: 2.4.12 - Sony Corporation)
      Confidence Online™ for Web Applications (HKU\S-1-5-21-1825112312-1052192824-3671610397-1006\…\Confidence Online EE) (Version:  - )
      Critical Update for Windows Media Player 11 (KB959772) (HKLM\…\KB959772_WM11) (Version:  - Microsoft Corporation)
      CustomerResearchQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
      DeepBurner v1.9.0.228 (HKLM\…\{2ADE2157-7A5E-122C-B51D-EB8A01B15943}) (Version:  - )
      Destinations (Version: 53.0.13.000 - Hewlett-Packard) Hidden
      DeviceFunctionQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
      DeviceManagementQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
      DVgate Plus (HKLM\…\{685BCC47-B8EC-45EC-BBCE-77DF2451502C}) (Version:  - )
      eSupportQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
      FLV Player 1.3.3 (HKLM\…\FLVPlayer) (Version:  - )
      Free CD Ripper 3.1 (HKLM\…\Free CD Ripper_is1) (Version:  - Focussoft.net)
      GemMaster Mystic (HKLM\…\12133444-BF36-4d4e-B7FB-A3424C645DE4) (Version:  - )
      Google Chrome (HKLM\…\Google Chrome) (Version: 41.0.2272.118 - Google Inc.)
      Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
      Google Update Helper (Version: 1.3.26.9 - Google Inc.) Hidden
      High Definition Audio Driver Package - KB835221 (HKLM\…\KB835221WXP) (Version: 20040219.000000 - Microsoft Corporation)
      HiJackThis (HKLM\…\{45A66726-69BC-466B-A7A4-12FCBA4883D7}) (Version: 1.0.0 - Trend Micro)
      HP Deskjet 3900 series (HKLM\…\{3819891A-030B-4a4e-98ED-B28A649E48AB}) (Version: 5.0 - HP)
      HP Extended Capabilities 5.0 (HKLM\…\HPExtendedCapabilities) (Version: 5.0 - HP)
      HP Image Zone Express (HKLM\…\{FE64AE29-0883-4C70-8388-DC026019C900}) (Version: 1.5.1.29 - Hewlett-Packard)
      HP Imaging Device Functions 5.0 (HKLM\…\HP Imaging Device Functions) (Version: 5.0 - HP)
      HP Solution Center & Imaging Support Tools 5.0 (HKLM\…\HP Solution Center & Imaging Support Tools) (Version: 5.0 - HP)
      HP Update (HKLM\…\{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}) (Version: 4.000.010.008 - Hewlett-Packard)
      HPDeskjet3900Series (Version: 1.00.0000 - Hewlett-Packard) Hidden
      HPProductAssistant (Version: 53.0.13.000 - Hewlett-Packard) Hidden
      HPSSupply (Version: 100.0.172.000 - Hewlett-Packard) Hidden
      Image Converter 2 (HKLM\…\{9155A84B-A94B-496E-9661-9978EB0CBC7C}) (Version:  - )
      Intel(R) Graphics Media Accelerator Driver (HKLM\…\{8A708DD8-A5E6-11D4-A706-000629E95E20}) (Version:  - )
      Intel(R) PRO Network Adapters and Drivers (HKLM\…\PROSet) (Version:  - )
      InterVideo WinDVD for VAIO (HKLM\…\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}) (Version: 5.0-B11.727 - InterVideo Inc.)
      InterVideo WinDVDX (HKLM\…\{1A91D1FA-B9B3-4556-9878-5C61059A19B2}) (Version:  - InterVideo Inc.)
      ISScript (Version: 3.00.185 - InstallShield Software Corp.) Hidden
      Java 8 Update 31 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
      Learn2 Player (Uninstall Only) (HKLM\…\StreetPlugin) (Version:  - )
      Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM\…\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
      MarketResearch (Version: 53.0.13.000 - Hewlett-Packard) Hidden
      Memory Stick Formatter (HKLM\…\{27337663-2619-11D4-99DC-0000F49094C7}) (Version:  - )
      MetaFrame Presentation Server Web Client for Win32 (HKLM\…\MetaFrame Presentation Server Web Client for Win32) (Version:  - )
      Microsoft .NET Framework 1.1 (HKLM\…\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
      Microsoft .NET Framework 1.1 Hotfix (KB886904) (HKLM\…\M886904) (Version:  - )
      Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\…\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
      Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\…\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
      Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
      Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\…\MSCompPackV1) (Version: 1 - Microsoft Corporation)
      Microsoft Data Access Components KB870669 (HKLM\…\KB870669) (Version:  - Microsoft Corporation)
      Microsoft Office PowerPoint Viewer 2003 (HKLM\…\{90AF0409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8305.0 - Microsoft Corporation)
      Microsoft Office Word Viewer 2003 (HKLM\…\{90850409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
      Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
      Microsoft SQL Server Desktop Engine (VAIO_VEDB) (HKLM\…\{E09B48B5-E141-427A-AB0C-D3605127224A}) (Version: 8.00.761 - Microsoft Corporation)
      Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\…\Wudf01000) (Version:  - Microsoft Corporation)
      Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
      Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
      Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\…\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM\…\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
      Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
      Microsoft WinUsb 2.0 (HKLM\…\winusb0200) (Version:  - Microsoft Corporation)
      MoodLogic (HKLM\…\MoodLogic) (Version:  - )
      Mozilla Firefox 36.0.4 (x86 en-US) (HKLM\…\Mozilla Firefox 36.0.4 (x86 en-US)) (Version: 36.0.4 - Mozilla)
      Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
      MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
      MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
      Netscape Internet Service Setup (HKLM\…\Netscape Online Setup) (Version:  - )
      OpenMG Limited Patch 4.1-05-13-31-01 (HKLM\…\OpenMG HotFix4.1-05-13-31-01) (Version:  - )
      OpenMG Secure Module 4.1.00 (HKLM\…\InstallShield_{2F151B50-B434-4838-B51D-70442EBA093E}) (Version: 4.1.00.13261 - Sony Corporation)
      OpenMG Secure Module 4.1.00 (Version: 4.1.00.13261 - Sony Corporation) Hidden
      Otto (HKLM\…\B3EE3001-DC24-4cd1-8743-5692C716659F) (Version:  - )
      PC Pitstop Driver Alert 1.0.0.13 (HKLM\…\PC Pitstop Driver Alert_is1) (Version: 1.0.0.13 - PC Pitstop LLC)
      Personal Ancestral File 5 (HKLM\…\{D94A8E22-DF2B-4107-9E51-608A60A7671D}) (Version:  - )
      PictureGear Studio 2.0 (HKLM\…\{88DA0A52-3372-4803-971A-ADFB961707E8}) (Version:  - )
      Port Forward Network Utilities (HKLM\…\{88B1D36C-7B70-4C48-8D2F-AAB956ECF4C3}) (Version: 2.0.9 - Portforward, LLC)
      Pure Networks Port Magic (HKLM\…\Port Magic) (Version: 1.2.1393.0 - Pure Networks)
      Quicken 2005 (HKLM\…\InstallShield_{2DBE41DD-2129-4C65-A3D3-5647236A60F3}) (Version: 14.00.0000 - Intuit)
      Quicken 2005 (Version: 14.00.0000 - Intuit) Hidden
      QuickTime (HKLM\…\{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}) (Version: 7.60.92.0 - Apple Inc.)
      RapidPlayer v4.0 ActiveX Control (HKLM\…\{31C2F32D-C5DD-4583-8181-B48591CA231C}) (Version:  - )
      RealPlayer (HKLM\…\RealPlayer 6.0) (Version:  - RealNetworks)
      Realtek High Definition Audio Driver (HKLM\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version:  - )
      Revo Uninstaller Pro 3.0.8 (HKLM\…\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.0.8 - VS Revo Group, Ltd.)
      Rhapsody Player Engine (HKLM\…\{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}) (Version: 1.0.604 - RealNetworks)
      RUMBA SecureRedirector Client (HKLM\…\SecureRedirClient) (Version:  - )
      Seagate Manager Installer (HKLM\…\InstallShield_{2A30052B-831C-41D3-8044-3C0388066350}) (Version: 2.01.0600 - Seagate)
      Seagate Manager Installer (Version: 2.01.0600 - Seagate) Hidden
      SereneScreen Marine Aquarium 2 + Time (HKLM\…\SereneScreen Marine Aquarium 2 + Time) (Version:  - )
      Shop for HP Supplies (HKLM\…\Shop for HP Supplies) (Version: 10.0 - HP)
      SolutionCenter (Version: 50.0.152.000 - Hewlett-Packard) Hidden
      Sonic RecordNow! (HKLM\…\{9541FED0-327F-4DF0-8B96-EF57EF622F19}) (Version: 7.30 - Sonic Solutions)
      SonicStage 3.0 (HKLM\…\{A0EB195B-5876-48E6-879D-33D4B2102610}) (Version: 3.0 - Sony Corporation)
      SonicStage Mastering Studio Audio Filter Custom Preset (HKLM\…\{013E1BA8-C815-4E27-BCB9-D6B1B2E24094}) (Version:  - )
      Sony Certificate PCH (HKLM\…\{D0448678-1203-4158-A58F-B3D0B616BF9E}) (Version:  - )
      Sony Download Taxi 1.5.0.0 (HKLM\…\{B2B30EC0-FB6A-43BB-9B38-0C3B32D75B40}_is1) (Version:  - Sony Corporation)
      Sony MP4 Shared Library (HKLM\…\{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}) (Version: 1.1 - Sony Corporation)
      Sony Video Shared Library (HKLM\…\{BE56FEF0-1A0F-4719-B3AD-34B5087AFA6D}) (Version: 2.0.01 - Sony Corporation)
      SpyroDriver (HKLM\…\{63104E84-532C-4011-A4F4-AD6EDF8CC214}) (Version: 1.09.0000 - FS)
      SpyroPortalDriver (HKLM\…\{B8C72ECE-87C6-4676-B949-519C1954F9F2}) (Version: 1.0.1 - FS)
      Status (Version: 53.0.13.000 - Hewlett-Packard) Hidden
      TrayApp (Version: 53.0.13.000 - Hewlett-Packard) Hidden
      Unity Web Player (HKU\S-1-5-21-1825112312-1052192824-3671610397-1006\…\UnityWebPlayer) (Version:  - Unity Technologies ApS)
      URGE (HKLM\…\{8BBF6DFD-0AD9-43A7-9FBD-BF065E3866AF}) (Version: 1.1.8115.0 - MTV Networks)
      VAIO Control Center (HKLM\…\{4E993095-28F2-4060-9101-99C1FD1195C0}) (Version:  - )
      VAIO Entertainment Platform (HKLM\…\{D917FD82-6CE5-489A-AAF8-C701AAC85C4D}) (Version: 1.3.00.14090 - Sony Corporation)
      VAIO Launcher (Version:  - ) Hidden
      VAIO Media 4.0 (HKLM\…\{1EB317D8-8945-4FD6-B37F-DF470317C6AB}) (Version:  - )
      VAIO Media AC3 Decoder 1.0 (HKLM\…\{2063C2E8-3812-4BBD-9998-6610F80C1DD4}) (Version:  - )
      VAIO Media Integrated Server 4.1 (HKLM\…\{7A79D11B-FD82-4A5E-834F-20173515DD14}) (Version:  - Sony Corporation)
      VAIO Media Redistribution 4.0 (HKLM\…\{7128C69B-8F7E-4336-8698-3FD3CDD955EC}) (Version:  - )
      VAIO Media Registration Tool 4.0 (HKLM\…\{AF9A04EB-7D8E-41DE-9EDE-4AB9BB2B71B6}) (Version:  - )
      VAIO Original Screen Saver (HKLM\…\{1BEF9285-5530-426B-A5F1-5836B95C7EB1}) (Version:  - )
      VAIO Original Screen Saver VAIO Motion SD Wide Contents (HKLM\…\{51735133-A296-4EB0-BF16-AD93B55BD000}) (Version:  - )
      VAIO Registration (HKLM\…\InstallShield_{315BA29D-2644-4760-B5FD-5AC04A52B8C5}) (Version: 13.0.3 - Sony Electronics)
      VAIO Registration (Version: 13.0.3 - Sony Electronics) Hidden
      VAIO Structure Wallpaper (HKLM\…\{E715FA41-46EB-4D3F-B4D9-A45973E76026}) (Version:  - )
      VAIO Survey Standalone (HKLM\…\InstallShield_{FA11D5B5-7D0A-43E8-88C4-960F97B194DE}) (Version: 3.02 - Sony Electronics)
      VAIO Survey Standalone (Version: 3.02 - Sony Electronics) Hidden
      VAIO Update 2 (HKLM\…\{48820099-ED7D-424B-890C-9A82EF00656D}) (Version:  - )
      VAIO Update 3 (HKLM\…\{9E158BB9-37B9-464B-837E-CC1D5766291B}) (Version: 3.0.02.05090 - Sony Corporation)
      VAIO Zone (HKLM\…\{ED8D39F2-7FFA-45EC-B148-EF2472955BB4}) (Version:  - )
      VAIO Zone Remote Commander (HKLM\…\{E09E82C3-6C4D-45B0-8790-BBBEE39F1A3C}) (Version:  - )
      Viewpoint Media Player (HKLM\…\ViewpointMediaPlayer) (Version:  - )
      WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
      WebReg (Version: 53.0.13.000 - Hewlett-Packard) Hidden
      Winamp (HKLM\…\Winamp) (Version: 5.541  - Nullsoft, Inc)
      Windows Backup Utility (HKLM\…\{76EFFC7C-17A6-479D-9E47-8E658C1695AE}) (Version: 5.1 - Microsoft Corporation)
      Windows Genuine Advantage Notifications (KB905474) (HKLM\…\WgaNotify) (Version: 1.5.0540.0 - Microsoft Corporation)
      Windows Genuine Advantage Validation Tool (KB892130) (HKLM\…\KB892130) (Version:  - Microsoft Corporation)
      Windows Genuine Advantage Validation Tool (KB892130) (HKLM\…\WGA) (Version: 1.7.0069.2 - Microsoft Corporation)
      Windows Internet Explorer 8 (HKLM\…\ie8) (Version: 20090308.140743 - Microsoft Corporation)
      Windows Live OneCare safety scanner (HKLM\…\Windows Live OneCare safety scanner) (Version:  - )
      Windows Media Format 11 runtime (HKLM\…\Windows Media Format Runtime) (Version:  - )
      Windows Media Player 11 (HKLM\…\Windows Media Player) (Version:  - )
      Windows XP Service Pack 3 (HKLM\…\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
      Windows XP Start Something Demo (HKLM\…\{8BE56144-D053-4411-9B48-A481DFF9F5AA}) (Version: 1.00.0000 - vm:creative)
      WordPerfect Office 12 (HKLM\…\{AF19F291-F22F-4798-9662-525305AE9E48}) (Version: 12.0.0.238 - Corel Corporation)
      Xvid Video Codec (HKLM\…\Xvid Video Codec 1.3.3) (Version: 1.3.3 - Xvid Team)
      Yahoo! Search Protection (HKLM\…\Yahoo! Search Defender) (Version:  - ) <==== ATTENTION
      Yahoo! Software Update (HKLM\…\Yahoo! Software Update) (Version:  - )
       
      ==================== Custom CLSID (selected items): ==========================
       
      (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
       
      CustomCLSID: HKU\S-1-5-21-1825112312-1052192824-3671610397-1006_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Documents and Settings\Sony\Local Settings\Application Data\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)
       
      ==================== Restore Points  =========================
       
      04-01-2015 19:41:28 Software Distribution Service 3.0
      05-01-2015 17:21:13 Software Distribution Service 3.0
      06-01-2015 03:14:06 Software Distribution Service 3.0
      06-01-2015 16:52:10 Software Distribution Service 3.0
      07-01-2015 19:38:49 System Checkpoint
      07-01-2015 20:06:15 Software Distribution Service 3.0
      14-01-2015 15:06:00 System Checkpoint
      14-01-2015 21:14:31 Software Distribution Service 3.0
      20-01-2015 12:54:40 Software Distribution Service 3.0
      25-01-2015 13:36:07 Software Distribution Service 3.0
      25-01-2015 14:57:23 Software Distribution Service 3.0
      26-01-2015 15:18:41 System Checkpoint
      26-01-2015 23:30:47 Software Distribution Service 3.0
      30-01-2015 10:42:11 Software Distribution Service 3.0
      05-02-2015 03:45:05 Software Distribution Service 3.0
      20-02-2015 21:36:27 Software Distribution Service 3.0
      21-02-2015 04:36:17 Software Distribution Service 3.0
      21-02-2015 15:54:57 Software Distribution Service 3.0
      22-02-2015 16:29:23 Software Distribution Service 3.0
      24-02-2015 12:27:08 Software Distribution Service 3.0
      26-02-2015 22:24:25 Software Distribution Service 3.0
      01-03-2015 13:40:48 Software Distribution Service 3.0
      03-03-2015 20:33:40 Software Distribution Service 3.0
      03-03-2015 23:24:17 Software Distribution Service 3.0
      04-03-2015 13:50:55 Software Distribution Service 3.0
      04-03-2015 22:28:00 Software Distribution Service 3.0
      05-03-2015 18:59:34 Software Distribution Service 3.0
      06-03-2015 00:10:08 Software Distribution Service 3.0
      06-03-2015 16:12:19 Software Distribution Service 3.0
      09-03-2015 16:03:08 System Checkpoint
      10-03-2015 01:54:15 Software Distribution Service 3.0
      11-03-2015 20:05:38 Software Distribution Service 3.0
      12-03-2015 20:16:50 Software Distribution Service 3.0
      14-03-2015 11:59:41 System Checkpoint
      14-03-2015 23:24:30 Software Distribution Service 3.0
      16-03-2015 21:34:47 Software Distribution Service 3.0
      17-03-2015 13:24:45 Software Distribution Service 3.0
      17-03-2015 23:27:48 Software Distribution Service 3.0
      19-03-2015 04:39:01 Software Distribution Service 3.0
      20-03-2015 18:22:35 System Checkpoint
      20-03-2015 21:36:59 Software Distribution Service 3.0
      23-03-2015 15:32:54 System Checkpoint
      23-03-2015 17:15:23 Software Distribution Service 3.0
      24-03-2015 18:21:38 Software Distribution Service 3.0
      26-03-2015 14:29:03 System Checkpoint
      26-03-2015 18:23:03 Software Distribution Service 3.0
      27-03-2015 20:11:29 Software Distribution Service 3.0
      29-03-2015 13:08:47 System Checkpoint
      29-03-2015 19:02:49 Software Distribution Service 3.0
      30-03-2015 19:14:26 Software Distribution Service 3.0
      31-03-2015 16:26:38 Software Distribution Service 3.0
      31-03-2015 20:28:25 Software Distribution Service 3.0
      31-03-2015 21:08:32 Installed Port Forward Network Utilities.
      31-03-2015 21:38:17 Software Distribution Service 3.0
      01-04-2015 23:16:50 Software Distribution Service 3.0
      02-04-2015 23:47:52 Software Distribution Service 3.0
      05-04-2015 03:03:06 Software Distribution Service 3.0
       
      ==================== Hosts content: ==========================
       
      (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
       
      2009-01-18 08:59 - 2011-05-09 20:09 - 00000027 ____A C:\WINDOWS\system32\Drivers\etc\hosts
      127.0.0.1       localhost
       
      ==================== Scheduled Tasks (whitelisted) =============
       
      (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
       
      Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
      Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
      Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
      Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
      Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe
      Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe
      Task: C:\WINDOWS\Tasks\Registration reminder 1.job => C:\WINDOWS\system32\OOBE\oobebaln.exe
      Task: C:\WINDOWS\Tasks\Registration reminder 2.job => C:\WINDOWS\system32\OOBE\oobebaln.exe
       
      ==================== Loaded Modules (whitelisted) ==============
       
      2013-08-05 01:15 - 2013-08-05 01:15 - 00066104 _____ () C:\WINDOWS\system32\bdmpega.acm
      2005-03-02 18:44 - 2007-04-02 07:49 - 00355112 _____ () C:\WINDOWS\system32\msjetoledb40.dll
      2009-05-07 09:11 - 2009-03-18 18:50 - 00913408 _____ () C:\Program Files\Yahoo!\Messenger\yui.dll
       
      ==================== Alternate Data Streams (whitelisted) =========
       
      (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
       
      AlternateDataStreams: C:\WMIDIAG-V2.0_XP___.CLI.SP2.32_INNUENDOES_2009.01.21_22.46.03.LOG:SummaryInformation
      AlternateDataStreams: C:\WMIDIAG-V2.0_XP___.CLI.SP2.32_INNUENDOES_2009.01.21_22.46.03.LOG:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
      AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
      AlternateDataStreams: C:\Documents and Settings\Sony\My Documents\DisableAOLDSL.exe:SummaryInformation
      AlternateDataStreams: C:\Documents and Settings\Sony\My Documents\DisableAOLDSL.exe:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
      AlternateDataStreams: C:\Documents and Settings\Sony\My Documents\Running scandisk etc.rtf:SummaryInformation
      AlternateDataStreams: C:\Documents and Settings\Sony\My Documents\Running scandisk etc.rtf:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
      AlternateDataStreams: C:\Documents and Settings\Sony\My Documents\terriffic.rtx:SummaryInformation
      AlternateDataStreams: C:\Documents and Settings\Sony\My Documents\terriffic.rtx:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
       
      ==================== Safe Mode (whitelisted) ===================
       
      (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
       
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
      HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
       
      ==================== EXE Association (whitelisted) ===============
       
      (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
       
       
       
      HKU\S-1-5-21-1825112312-1052192824-3671610397-1006\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION!
      HKU\S-1-5-21-1825112312-1052192824-3671610397-1006\Software\Classes\exefile: "%1" %* <===== ATTENTION!
       
      ==================== Other Areas ============================
       
      (Currently there is no automatic fix for this section.)
       
      HKU\S-1-5-21-1825112312-1052192824-3671610397-1006\Control Panel\Desktop\\Wallpaper -> C:\Documents and Settings\Sony\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
      DNS Servers: [removed] - [removed]
       
      ==================== MSCONFIG/TASK MANAGER disabled items ==
       
      (Currently there is no automatic fix for this section.)
       
      MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk => C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
      MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online Tray Icon.lnk => C:\WINDOWS\pss\America Online Tray Icon.lnkCommon Startup
      MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
      MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk => C:\WINDOWS\pss\Service Manager.lnkCommon Startup
      MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SpySubtract.lnk => C:\WINDOWS\pss\SpySubtract.lnkCommon Startup
      MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows XP Start Something Demo Metrics.lnk => C:\WINDOWS\pss\Windows XP Start Something Demo Metrics.lnkCommon Startup
      MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows XP Start Something Demo.lnk => C:\WINDOWS\pss\Windows XP Start Something Demo.lnkCommon Startup
      MSCONFIG\startupreg: AGRSMMSG => AGRSMMSG.exe
      MSCONFIG\startupreg: AlcWzrd => ALCWZRD.EXE
      MSCONFIG\startupreg: ATIPTA => C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      MSCONFIG\startupreg: CreateCD_Reminder => C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe
      MSCONFIG\startupreg: ExecAfterFirstBoot => C:\WINDOWS\SONYSYS\EFlyer\ExecAfterFirstBoot.exe /fC:\WINDOWS\SONYSYS\Docs\Latest Information.pdf /d4
      MSCONFIG\startupreg: High Definition Audio Property Page Shortcut => HDAudPropShortcut.exe
      MSCONFIG\startupreg: HotKeysCmds => C:\WINDOWS\system32\hkcmd.exe
      MSCONFIG\startupreg: IgfxTray => C:\WINDOWS\system32\igfxtray.exe
      MSCONFIG\startupreg: Pure Networks Port Magic => "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
      MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\qttask.exe" -atboottime
      MSCONFIG\startupreg: RealTray => C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
      MSCONFIG\startupreg: SoundMan => SOUNDMAN.EXE
      MSCONFIG\startupreg: VZRemoteCommander => C:\Program Files\Sony\VAIO Zone Remote Commander\AvRmtCtr.exe
      MSCONFIG\startupreg: YBrowser => C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
       
      ==================== Accounts: =============================
       
      Administrator (S-1-5-21-1825112312-1052192824-3671610397-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator.INNUENDOES
      ASPNET (S-1-5-21-1825112312-1052192824-3671610397-1004 - Limited - Enabled)
      Guest (S-1-5-21-1825112312-1052192824-3671610397-501 - Limited - Disabled)
      HelpAssistant (S-1-5-21-1825112312-1052192824-3671610397-1005 - Limited - Disabled)
      Sony (S-1-5-21-1825112312-1052192824-3671610397-1006 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Sony
      SUPPORT_388945a0 (S-1-5-21-1825112312-1052192824-3671610397-1002 - Limited - Disabled)
       
      ==================== Faulty Device Manager Devices =============
       
      Name: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
      Description: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
      Class Guid: {4D36E96B-E325-11CE-BFC1-08002BE10318}
      Manufacturer: (Standard keyboards)
      Service: i8042prt
      Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
      Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
      Devices stay in this state if they have been prepared for removal.
      After you remove the device, this error disappears.Remove the device, and this error should be resolved.
       
      Name: Activision Xbox360 Spyro Portal
      Description: Activision Xbox360 Spyro Portal
      Class Guid: {4A9C2FA7-D63F-44C5-A247-BB3289A3739F}
      Manufacturer: Activision
      Service: WinUSB
      Problem: : This device cannot start. (Code10)
      Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
      On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
       
       
      ==================== Event log errors: =========================
       
      Application errors:
      ==================
      Error: (04/05/2015 03:06:21 AM) (Source: MsiInstaller) (EventID: 1024) (User: NT AUTHORITY)
      Description: Product: Microsoft .NET Framework 1.1 - Update '{411EDCF7-755D-414E-A74B-3DCD6583F589}' could not be installed. Error code 1603. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
       
      Error: (04/02/2015 11:49:14 PM) (Source: MsiInstaller) (EventID: 1024) (User: NT AUTHORITY)
      Description: Product: Microsoft .NET Framework 1.1 - Update '{411EDCF7-755D-414E-A74B-3DCD6583F589}' could not be installed. Error code 1603. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
       
      Error: (04/01/2015 11:18:24 PM) (Source: MsiInstaller) (EventID: 1024) (User: NT AUTHORITY)
      Description: Product: Microsoft .NET Framework 1.1 - Update '{411EDCF7-755D-414E-A74B-3DCD6583F589}' could not be installed. Error code 1603. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
       
      Error: (03/31/2015 09:39:32 PM) (Source: MsiInstaller) (EventID: 1024) (User: NT AUTHORITY)
      Description: Product: Microsoft .NET Framework 1.1 - Update '{411EDCF7-755D-414E-A74B-3DCD6583F589}' could not be installed. Error code 1603. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
       
      Error: (03/31/2015 09:26:44 PM) (Source: Application Error) (EventID: 1001) (User: )
      Description: Fault bucket 223121472.
      The Wep key exchange did not result in a secure connection setup after 802.1x authentication.  The current setting has been marked as failed and the Wireless connection will be disconnected.
       
      Error: (03/31/2015 09:25:11 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.
      Processing media-specific event for [drwtsn32.exe!ws!]
       
      Error: (03/31/2015 09:25:00 PM) (Source: Application Error) (EventID: 1001) (User: )
      Description: Fault bucket -1992352635.
      The Wep key exchange did not result in a secure connection setup after 802.1x authentication.  The current setting has been marked as failed and the Wireless connection will be disconnected.
       
      Error: (03/31/2015 09:24:51 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: Faulting application explorer.exe, version 6.0.2900.5512, faulting module ntdll.dll, version 5.1.2600.6055, fault address 0x00029f07.
      Processing media-specific event for [explorer.exe!ws!]
       
      Error: (03/31/2015 08:29:54 PM) (Source: MsiInstaller) (EventID: 1024) (User: NT AUTHORITY)
      Description: Product: Microsoft .NET Framework 1.1 - Update '{411EDCF7-755D-414E-A74B-3DCD6583F589}' could not be installed. Error code 1603. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
       
      Error: (03/31/2015 04:28:10 PM) (Source: MsiInstaller) (EventID: 1024) (User: NT AUTHORITY)
      Description: Product: Microsoft .NET Framework 1.1 - Update '{411EDCF7-755D-414E-A74B-3DCD6583F589}' could not be installed. Error code 1603. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
       
       
      System errors:
      =============
      Error: (04/05/2015 03:06:35 AM) (Source: Windows Update Agent) (EventID: 20) (User: )
      Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Microsoft .NET Framework 1.1 Service Pack 1.
       
      Error: (04/05/2015 01:31:05 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
      Description: The tmcomm service failed to start due to the following error: 
      %%2
       
      Error: (04/02/2015 11:49:22 PM) (Source: Windows Update Agent) (EventID: 20) (User: )
      Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Microsoft .NET Framework 1.1 Service Pack 1.
       
      Error: (04/02/2015 03:57:13 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
      Description: The tmcomm service failed to start due to the following error: 
      %%2
       
      Error: (04/02/2015 03:56:55 PM) (Source: Dhcp) (EventID: 1002) (User: )
      Description: The IP address lease 192.168.1.102 for the Network Card with network address 001111C62623 has been
      denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
       
      Error: (04/02/2015 03:41:13 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
      Description: The tmcomm service failed to start due to the following error: 
      %%2
       
      Error: (04/01/2015 11:18:33 PM) (Source: Windows Update Agent) (EventID: 20) (User: )
      Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Microsoft .NET Framework 1.1 Service Pack 1.
       
      Error: (04/01/2015 03:17:28 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
      Description: The tmcomm service failed to start due to the following error: 
      %%2
       
      Error: (03/31/2015 09:39:42 PM) (Source: Windows Update Agent) (EventID: 20) (User: )
      Description: Installation Failure: Windows failed to install the following update with error 0x80070643: Microsoft .NET Framework 1.1 Service Pack 1.
       
      Error: (03/31/2015 08:56:19 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
      Description: The tmcomm service failed to start due to the following error: 
      %%2
       
       
      Microsoft Office Sessions:
      =========================
      Error: (04/05/2015 03:06:21 AM) (Source: MsiInstaller) (EventID: 1024) (User: NT AUTHORITY)
      Description: Microsoft .NET Framework 1.1{411EDCF7-755D-414E-A74B-3DCD6583F589}1603(NULL)
       
      Error: (04/02/2015 11:49:14 PM) (Source: MsiInstaller) (EventID: 1024) (User: NT AUTHORITY)
      Description: Microsoft .NET Framework 1.1{411EDCF7-755D-414E-A74B-3DCD6583F589}1603(NULL)
       
      Error: (04/01/2015 11:18:24 PM) (Source: MsiInstaller) (EventID: 1024) (User: NT AUTHORITY)
      Description: Microsoft .NET Framework 1.1{411EDCF7-755D-414E-A74B-3DCD6583F589}1603(NULL)
       
      Error: (03/31/2015 09:39:32 PM) (Source: MsiInstaller) (EventID: 1024) (User: NT AUTHORITY)
      Description: Microsoft .NET Framework 1.1{411EDCF7-755D-414E-A74B-3DCD6583F589}1603(NULL)
       
      Error: (03/31/2015 09:26:44 PM) (Source: Application Error) (EventID: 1001) (User: )
      Description: 223121472
       
      Error: (03/31/2015 09:25:11 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: drwtsn32.exe5.1.2600.0dbghelp.dll5.1.2600.55120001295d
       
      Error: (03/31/2015 09:25:00 PM) (Source: Application Error) (EventID: 1001) (User: )
      Description: -1992352635
       
      Error: (03/31/2015 09:24:51 PM) (Source: Application Error) (EventID: 1000) (User: )
      Description: explorer.exe6.0.2900.5512ntdll.dll5.1.2600.605500029f07
       
      Error: (03/31/2015 08:29:54 PM) (Source: MsiInstaller) (EventID: 1024) (User: NT AUTHORITY)
      Description: Microsoft .NET Framework 1.1{411EDCF7-755D-414E-A74B-3DCD6583F589}1603(NULL)
       
      Error: (03/31/2015 04:28:10 PM) (Source: MsiInstaller) (EventID: 1024) (User: NT AUTHORITY)
      Description: Microsoft .NET Framework 1.1{411EDCF7-755D-414E-A74B-3DCD6583F589}1603(NULL)
       
       
      ==================== Memory info =========================== 
       
      Processor:  Intel(R) Pentium(R) 4 CPU 3.00GHz
      Percentage of memory in use: 30%
      Total physical RAM: 2038.73 MB
      Available physical RAM: 1421.3 MB
      Total Pagefile: 3924.52 MB
      Available Pagefile: 3462.86 MB
      Total Virtual: 2047.88 MB
      Available Virtual: 1936.07 MB
       
      ==================== Drives ================================
       
      Drive c: () (Fixed) (Total:180.3 GB) (Free:27.52 GB) NTFS ==>[Drive with boot components (Windows XP)]
      Drive e: (Kathie-Backup) (CDROM) (Total:0.32 GB) (Free:0 GB) CDFS
       
      ==================== MBR & Partition Table ==================
       
      ========================================================
      Disk: 0 (MBR Code: Windows XP) (Size: 186.3 GB) (Disk ID: 18387C7D)
      Partition 1: (Not Active) - (Size=6 GB) - (Type=12)
      Partition 2: (Active) - (Size=180.3 GB) - (Type=07 NTFS)
       
      ==================== End Of Log ============================

      Good Morning

       

      Nothing really jumping out at me malwarewise, lets do this

       

       
      -AdwCleaner-by Xplode
       
      Click on this link to download : ADWCleaner
      Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
       
      Do not click on any links in the top Advertisment.
       
      • Close all open programs and internet browsers.
      • Double click on AdwCleaner.exe to run the tool.
      • Click on Scan.
      • After the scan is complete click on "Clean"
      • Confirm each time with Ok.
      • Your computer will be rebooted automatically. A text file will open after the restart.
      • Please post the content of that logfile with your next reply.
      • You can find the logfile at C:\AdwCleaner[S1].txt as well.
      • Ask AI

        AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

        Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI