| Live Chat & Podcast at 1:00PM Eastern on Sunday! |
Advertisement
Advertisement
| | |
| |
24-Jul-2012, 03:56 PM
#1 | |||||||
| possible malware? slow system and audio ads Hi, over the last few weeks my computer has been running a lot slower than normal. On start up it freezes for a small amount of time and then unfreezes however it is very slow during use. I am also experiencing ads with no running application, just sound in the background that run for 30 seconds, then stop, then start up again. I have done a full system scan with Norton Anti Virus and it has came back with nothing found however I don't know what else to download to check what it is infected with as using the computer has now became a nightmare. Is there any other programs I can use to sort this? Thanks Lee Here is the required information: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 17:03:45, on 22/07/2012 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v9.00 (9.00.8112.16447) Boot mode: Normal Running processes: C:\Program Files (x86)\TouchSettings\TouchPortalOBR.exe C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe C:\Program Files (x86)\Common Files\AOL\1301732618\ee\aolsoftware.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe C:\Program Files (x86)\AVG Secure Search\vprot.exe C:\Program Files (x86)\PowerISO\PWRISOVM.EXE C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\Downloads\SysInfo.exe C:\Program Files (x86)\Internet Explorer\IELowutil.exe C:\Users\harry\Downloads\HijackThis (1).exe C:\Windows\SysWOW64\DllHost.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://toolbar.inbox.com/search/disp...b_id&%language R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchnu.com/406 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.packardbell.com/rdr....7y175y44l10587 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - (no file) R3 - URLSearchHook: uTorrentControl2 Toolbar - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\coIEPlg.dll O2 - BHO: uTorrentControl2 - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll O2 - BHO: BHO_PROJECT - {68DD98BF-9DE8-418C-89F0-E37AC61CC2D9} - C:\Program Files (x86)\OApps\bho_project.dll O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\IPSBHO.DLL O2 - BHO: AppGraffiti - {6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} - C:\PROGRA~2\APPGRA~1\APPGRA~1.DLL O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll O2 - BHO: Babylon IE plugin - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll O2 - BHO: DataMngr - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\SEARCH~1\Datamngr\BROWSE~1.DLL O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\coIEPlg.dll O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing) O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files (x86)\alot\bin\alot.dll O3 - Toolbar: (no name) - {b278d9f8-0fa9-465e-9938-0c392605d8e3} - (no file) O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll O3 - Toolbar: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - (no file) O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O3 - Toolbar: uTorrentControl2 Toolbar - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\3.0" O4 - HKLM\..\Run: [YouCam Mirror Tray icon] "C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe" /s O4 - HKLM\..\Run: [TVEService] "C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe" O4 - HKLM\..\Run: [HostManager] C:\Program Files (x86)\Common Files\AOL\1301732618\ee\AOLSoftware.exe O4 - HKLM\..\Run: [Babylon Client] C:\Program Files (x86)\Babylon\Babylon-Pro\Babylon.exe -AutoStart O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE -startup O4 - HKLM\..\Run: [HF_G_Jul] "C:\Program Files (x86)\AVG Secure Search\HF_G_Jul.exe" /DoAction O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~1.EXE O4 - HKCU\..\Run: [MusicGadget] "C:\Program Files (x86)\Packard Bell\Packard Bell Touch Suite\TouchMusic.exe" O4 - HKCU\..\Run: [PhotoGadget] "C:\Program Files (x86)\Packard Bell\Packard Bell Touch Suite\TouchPhotoShow.exe" O4 - HKCU\..\Run: [SNSGadget] "C:\Program Files (x86)\Packard Bell\Packard Bell Touch Suite\TouchFriends.exe" O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [Google Update] "C:\Users\harry\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [Speech Recognition] "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup O4 - HKCU\..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe O4 - Startup: TalkTalk Diagnostic Reporting Tool.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105 O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll O9 - Extra 'Tools' menuitem: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - Trusted Zone: www.vizzed.com O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} (WRC Class) - http://trial.trymicrosoftoffice.com/...soft/wrc32.ocx O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\coIEPlg.dll O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - AppInit_DLLs: C:\PROGRA~2\SEARCH~1\Datamngr\datamngr.dll C:\PROGRA~2\SEARCH~1\Datamngr\IEBHO.dll O23 - Service: Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) - Adobe Systems Incorporated - c:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files (x86)\Common Files\AOL\ACS\AOLAcsd.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe O23 - Service: Oberon Media Game Console service (OberonGameConsoleService) - Unknown owner - C:\Program Files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: TVEnhance Background Capture Service (TBCS) (TVECapSvc) - Unknown owner - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe O23 - Service: TVEnhance Task Scheduler (TTS)) (TVESched) - Unknown owner - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: Updater Service - Acer - C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: vToolbarUpdater11.2.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 17448 bytes . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.4.1 Run by harry at 17:04:35 on 2012-07-22 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.4060.2244 [GMT 1:00] . AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\SYSTEM32\WISPTIS.EXE C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\SYSTEM32\WISPTIS.EXE C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe C:\Windows\Explorer.EXE C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork c:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe C:\Program Files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe C:\Program Files (x86)\TouchSettings\TouchPortalOBR.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe C:\Program Files (x86)\Common Files\AOL\1301732618\ee\aolsoftware.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe C:\Windows\system32\conhost.exe C:\Program Files (x86)\AVG Secure Search\vprot.exe C:\Program Files (x86)\PowerISO\PWRISOVM.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Program Files (x86)\Searchqu Toolbar\Datamngr\datamngrUI.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\Dwm.exe C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\harry\Downloads\SysInfo.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\Internet Explorer\IELowutil.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe . ============== Pseudo HJT Report =============== . uSearch Bar = hxxp://toolbar.inbox.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=%tb_id&%language uStart Page = hxxp://www.searchnu.com/406 mDefault_Page_URL = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0809&m=onetwo_m3700&r=273603111000p0437y175y44l10587 uInternet Settings,ProxyOverride = *.local uURLSearchHooks: H - No File uURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll mURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll mWinlogon: Userinit=userinit.exe BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Babylon toolbar helper: {2eecd738-5844-4a99-b4b6-146bf802613b} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\coIEPlg.dll BHO: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll BHO: VideoFileDownload: {68dd98bf-9de8-418c-89f0-e37ac61cc2d9} - C:\Program Files (x86)\OApps\bho_project.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\IPSBHO.DLL BHO: AppGraffiti: {6f6a5334-78e9-4d9b-8182-8b41ea8c39ef} - C:\PROGRA~2\APPGRA~1\APPGRA~1.DLL BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll BHO: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll BHO: Babylon IE plugin: {9cfaccb6-2f3f-4177-94ea-0d2b72d384c1} - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll BHO: DataMngr: {9d717f81-9148-4f12-8568-69135f087db0} - C:\PROGRA~2\SEARCH~1\Datamngr\BROWSE~1.DLL BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\coIEPlg.dll TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" TB: ALOT Toolbar: {5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} - C:\Program Files (x86)\alot\bin\alot.dll TB: {b278d9f8-0fa9-465e-9938-0c392605d8e3} - No File TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll TB: {EEE6C35B-6118-11DC-9C72-001320C79847} - No File TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll TB: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll TB: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File {e7df6bff-55a5-4eb7-a673-4ed3e9456d39} uRun: [PhotoGadgetFirstRun] 0 (0x0) uRun: [MusicGadget] "C:\Program Files (x86)\Packard Bell\Packard Bell Touch Suite\TouchMusic.exe" uRun: [TouchMemo] 0 (0x0) uRun: [PhotoGadget] "C:\Program Files (x86)\Packard Bell\Packard Bell Touch Suite\TouchPhotoShow.exe" uRun: [PhotoGadgetFirstRun_Portal] 0 (0x0) uRun: [SNSGadget] "C:\Program Files (x86)\Packard Bell\Packard Bell Touch Suite\TouchFriends.exe" uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" uRun: [Google Update] "C:\Users\harry\AppData\Local\Google\Update\GoogleUpdate.exe" /c uRun: [msnmsgr] ~"C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background uRun: [Speech Recognition] "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup uRun: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED mRun: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\3.0" mRun: [YouCam Mirror Tray icon] "C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe" /s mRun: [TVEService] "C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe" mRun: [HostManager] C:\Program Files (x86)\Common Files\AOL\1301732618\ee\AOLSoftware.exe mRun: [Babylon Client] C:\Program Files (x86)\Babylon\Babylon-Pro\Babylon.exe -AutoStart mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" mRun: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE -startup mRun: [HF_G_Jul] "C:\Program Files (x86)\AVG Secure Search\HF_G_Jul.exe" /DoAction mRun: [DATAMNGR] C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~1.EXE StartupFolder: C:\Users\harry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TalkTalk Diagnostic Reporting Tool.exe mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105 IE: Translate this web page with Babylon - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm IE: Translate with Babylon - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm IE: {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Trusted Zone: vizzed.com\www DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab TCP: DhcpNameServer = 192.168.0.1 TCP: Interfaces\{8A63913D-417F-4EE8-AEAD-DA34552E29BB} : DhcpNameServer = 192.168.0.1 TCP: Interfaces\{8A63913D-417F-4EE8-AEAD-DA34552E29BB}\142434132333 : DhcpNameServer = 192.168.1.1 192.168.1.1 TCP: Interfaces\{8A63913D-417F-4EE8-AEAD-DA34552E29BB}\14F4C42424D2233454532434 : DhcpNameServer = 192.168.1.1 192.168.1.1 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll AppInit_DLLs: C:\PROGRA~2\SEARCH~1\Datamngr\datamngr.dll C:\PROGRA~2\SEARCH~1\Datamngr\IEBHO.dll BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: Babylon toolbar helper: {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll BHO-X64: Babylon toolbar helper - No File BHO-X64: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\coIEPlg.dll BHO-X64: Symantec NCO BHO - No File BHO-X64: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll BHO-X64: uTorrentControl2 - No File BHO-X64: VideoFileDownload: {68DD98BF-9DE8-418C-89F0-E37AC61CC2D9} - C:\Program Files (x86)\OApps\bho_project.dll BHO-X64: BHO_PROJECT - No File BHO-X64: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\IPSBHO.DLL BHO-X64: Symantec Intrusion Prevention - No File BHO-X64: AppGraffiti: {6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} - C:\PROGRA~2\APPGRA~1\APPGRA~1.DLL BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll BHO-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll BHO-X64: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll BHO-X64: Searchqu Toolbar - No File BHO-X64: Babylon IE plugin: {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll BHO-X64: Babylon IE plugin - No File BHO-X64: DataMngr: {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\SEARCH~1\Datamngr\BROWSE~1.DLL BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\coIEPlg.dll TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" TB-X64: ALOT Toolbar: {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files (x86)\alot\bin\alot.dll TB-X64: {b278d9f8-0fa9-465e-9938-0c392605d8e3} - No File TB-X64: Babylon Toolbar: {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll TB-X64: {EEE6C35B-6118-11DC-9C72-001320C79847} - No File TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll TB-X64: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll TB-X64: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll TB-X64: Searchqu Toolbar: {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll TB-X64: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File mRun-x64: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED mRun-x64: [UCam_Menu] "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\3.0" mRun-x64: [YouCam Mirror Tray icon] "C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe" /s mRun-x64: [TVEService] "C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe" mRun-x64: [HostManager] C:\Program Files (x86)\Common Files\AOL\1301732618\ee\AOLSoftware.exe mRun-x64: [Babylon Client] C:\Program Files (x86)\Babylon\Babylon-Pro\Babylon.exe -AutoStart mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun-x64: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe" mRun-x64: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE -startup mRun-x64: [HF_G_Jul] "C:\Program Files (x86)\AVG Secure Search\HF_G_Jul.exe" /DoAction mRun-x64: [DATAMNGR] C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~1.EXE IE-X64: {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm AppInit_DLLs-X64: C:\PROGRA~2\SEARCH~1\Datamngr\datamngr.dll C:\PROGRA~2\SEARCH~1\Datamngr\IEBHO.dll . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\ FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon) FF - prefs.js: browser.startup.homepage - hxxp://www.searchnu.com/406 FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=390&systemid=406&sr=0&q= FF - prefs.js: network.proxy.type - 0 FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.2.0\npsitesafety.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.95\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npMcAfeeSRPlgn.dll FF - plugin: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll FF - plugin: C:\Program Files (x86)\Virtual Earth 3D\npVE3D.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Users\harry\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll FF - plugin: C:\Users\harry\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll FF - plugin: C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\ex tensions\{687578b9-7132-4a7a-80e4-30ee31099e03}\plugins\np-mswmp.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_265.dll FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll FF - plugin: C:\Windows\SysWOW64\npmproxy.dll . ---- FIREFOX POLICIES ---- FF - user.js: extensions.BabylonToolbar_i.newTab - false FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=110819 FF - user.js: extensions.BabylonToolbar_i.babExt - FF - user.js: extensions.BabylonToolbar_i.srcExt - ss FF - user.js: extensions.BabylonToolbar_i.id - e81350900000000000000017c4ddd1cf FF - user.js: extensions.BabylonToolbar_i.hardId - e81350900000000000000017c4ddd1cf FF - user.js: extensions.BabylonToolbar_i.instlDay - 15486 FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17 FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1716:43:50 FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar FF - user.js: extensions.BabylonToolbar_i.aflt - babsst FF - user.js: extensions.BabylonToolbar_i.smplGrp - none FF - user.js: extensions.BabylonToolbar_i.tlbrId - tb9 FF - user.js: extensions.BabylonToolbar_i.instlRef - sst . user_pref('extensions.autoDisableScopes', 0);user_pref('security.csp.enable', false);user_pref('security.OCSP.enabled', 0); ============= SERVICES / DRIVERS =============== . R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?] R0 SymEFA;Symantec Extended File Attributes;C:\Windows\system32\drivers\NISx64\1008030.006\SYMEFA64.SYS --> C:\Windows\system32\drivers\NISx64\1008030.006\SYMEFA64.SYS [?] R1 BHDrvx64;Symantec Heuristics Driver;C:\Windows\system32\Drivers\NISx64\1008030.006\BHDrvx64.sys --> C:\Windows\system32\Drivers\NISx64\1008030.006\BHDrvx64.sys [?] R1 ccHP;Symantec Hash Provider;C:\Windows\system32\Drivers\NISx64\1008030.006\ccHPx64.sys --> C:\Windows\system32\Drivers\NISx64\1008030.006\ccHPx64.sys [?] R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20120720.001\IDSviA64.sys [2012-7-21 509088] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;C:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-12-8 169312] R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-4-4 63928] R2 Greg_Service;GRegService;C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe [2009-8-28 1150496] R2 Norton Internet Security;Norton Internet Security;C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe [2011-10-11 117648] R2 OberonGameConsoleService;Oberon Media Game Console service;C:\Program Files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe [2009-11-27 44312] R2 TVECapSvc;TVEnhance Background Capture Service (TBCS);C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe [2011-3-31 386400] R2 TVESched;TVEnhance Task Scheduler (TTS));C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe [2011-3-31 202080] R2 Updater Service;Updater Service;C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [2009-11-27 240160] R2 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [2012-7-16 935008] R3 AVerPola;AVerMedia USB Polaris Series Capture Service;C:\Windows\system32\DRIVERS\AVerPola.sys --> C:\Windows\system32\DRIVERS\AVerPola.sys [?] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-6-12 138912] R3 itecir;ITECIR Infrared Receiver;C:\Windows\system32\DRIVERS\itecir.sys --> C:\Windows\system32\DRIVERS\itecir.sys [?] R3 JMCR;JMCR;C:\Windows\system32\DRIVERS\jmcr.sys --> C:\Windows\system32\DRIVERS\jmcr.sys [?] R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\system32\DRIVERS\netr28x.sys --> C:\Windows\system32\DRIVERS\netr28x.sys [?] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?] R3 SYMNDISV;Symantec Network Filter Driver;C:\Windows\system32\Drivers\NISx64\1008030.006\SYMNDISV.SYS --> C:\Windows\system32\Drivers\NISx64\1008030.006\SYMNDISV.SYS [?] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-3-31 135664] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-5-2 250056] S3 AF9035BDA;AF9035 BDA Devices;C:\Windows\system32\Drivers\AF9035BDA.sys --> C:\Windows\system32\Drivers\AF9035BDA.sys [?] S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-2-28 183560] S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?] S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-3-8 1492840] S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-3-31 135664] S3 hwusbfake;Huawei DataCard USB Fake;C:\Windows\system32\DRIVERS\ewusbfake.sys --> C:\Windows\system32\DRIVERS\ewusbfake.sys [?] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== Created Last 30 ================ . 2012-07-19 16:01:14 -------- d-----w- C:\Users\harry\AppData\Local\Ilivid Player 2012-07-19 16:00:42 -------- d-----w- C:\Program Files (x86)\iLivid 2012-07-19 15:58:44 -------- d-----w- C:\ProgramData\boost_interprocess 2012-07-19 15:58:43 -------- d-----w- C:\Program Files (x86)\Searchqu Toolbar 2012-07-16 20:06:07 -------- d-----w- C:\Program Files (x86)\OApps 2012-07-16 20:06:04 -------- d-----w- C:\Program Files (x86)\TorrentSearch 2012-07-16 20:05:41 -------- d-----w- C:\Program Files (x86)\smartdl 2012-07-16 19:51:13 -------- d-----w- C:\Users\harry\AppData\Local\AVG Secure Search 2012-07-16 19:50:56 -------- d-----w- C:\ProgramData\AVG Secure Search 2012-07-16 19:50:54 -------- d-----w- C:\Program Files (x86)\Common Files\AVG Secure Search 2012-07-16 19:50:53 -------- d-----w- C:\Program Files (x86)\AVG Secure Search 2012-07-16 19:49:49 -------- d--h--w- C:\ProgramData\Common Files 2012-07-16 19:49:43 126944 ----a-w- C:\Windows\System32\drivers\scdemu.sys 2012-07-16 19:49:43 -------- d-----w- C:\Program Files (x86)\PowerISO 2012-07-16 18:33:23 -------- d-----w- C:\Program Files (x86)\MSECache 2012-07-16 17:28:52 -------- d-----w- C:\Users\harry\AppData\Local\CRE 2012-07-16 17:28:20 -------- d-----w- C:\Program Files (x86)\uTorrent 2012-07-16 17:27:45 -------- d-----w- C:\Users\harry\AppData\Roaming\uTorrent 2012-07-16 16:47:31 -------- d-----w- C:\Users\harry\AppData\Local\{93521D56-D5BA-45DB-9899-217B984F1B05} 2012-07-16 15:32:10 -------- d-----w- C:\Users\harry\AppData\Local\MicrosoftStore 2012-07-16 11:34:19 -------- d-----w- C:\Users\harry\AppData\Local\{EA2C0C36-F559-4C00-ABEE-8B9BC80FC53F} 2012-07-16 01:03:42 184891 ----a-w- C:\torrent.exe 2012-07-15 10:44:20 -------- d-----w- C:\Users\harry\AppData\Local\{E474B330-5EA8-4835-9507-1F9AEE801165} 2012-07-15 10:44:08 -------- d-----w- C:\Users\harry\AppData\Local\{50BE36D1-782F-4351-A3E4-93BA51BAB5D6} 2012-07-14 14:15:16 -------- d-----w- C:\Users\harry\AppData\Local\{6AFF746D-36B1-4467-A0E2-601D82B81C10} 2012-07-14 14:15:05 -------- d-----w- C:\Users\harry\AppData\Local\{0E1FED34-F893-4966-AB65-D0724E1EB2A0} 2012-07-14 13:50:33 -------- d-----w- C:\Users\harry\AppData\Roaming\Temp 2012-07-14 13:36:31 -------- d-----w- C:\Program Files\CCleaner 2012-07-13 14:34:25 -------- d-----w- C:\Users\harry\AppData\Local\{0388C4E8-CAB5-4D13-80F4-520BD0D8CF68} 2012-07-13 14:34:13 -------- d-----w- C:\Users\harry\AppData\Local\{E87E6765-0AE8-4345-A574-85CA9451B362} 2012-07-13 02:33:47 -------- d-----w- C:\Users\harry\AppData\Local\{9EF70447-BE4E-4BAA-A18D-9D8D3738A371} 2012-07-13 02:33:35 -------- d-----w- C:\Users\harry\AppData\Local\{438AB6C3-BF21-4AFE-9550-A2910F9C6BE5} 2012-07-12 14:33:08 -------- d-----w- C:\Users\harry\AppData\Local\{69FC119A-655F-4D87-B942-E27CACD7E5B3} 2012-07-12 02:31:00 -------- d-----w- C:\Users\harry\AppData\Local\{2D0F57B4-5013-4A0C-AA44-D315CD1EF11E} 2012-07-12 02:30:48 -------- d-----w- C:\Users\harry\AppData\Local\{0DDFB27F-1C74-493C-BC4A-D7335C1E3950} 2012-07-12 02:07:59 3148800 ----a-w- C:\Windows\System32\win32k.sys 2012-07-08 17:56:05 -------- d-----w- C:\Users\harry\AppData\Local\{CB38660F-F955-41F7-9DF0-8EAD307D3731} 2012-07-08 17:55:53 -------- d-----w- C:\Users\harry\AppData\Local\{4C6FC563-98AE-4C5E-BBBA-081E1D4D6B29} 2012-06-26 06:29:30 -------- d-----w- C:\Users\harry\AppData\Local\Macromedia . ==================== Find3M ==================== . 2012-07-12 11:39:35 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-07-12 11:39:35 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-06-06 06:06:16 2004480 ----a-w- C:\Windows\System32\msxml6.dll 2012-06-06 06:06:16 1881600 ----a-w- C:\Windows\System32\msxml3.dll 2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll 2012-06-06 05:05:52 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll 2012-06-06 05:05:52 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll 2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll 2012-06-02 22:15:31 2622464 ----a-w- C:\Windows\System32\wucltux.dll 2012-06-02 22:15:08 99840 ----a-w- C:\Windows\System32\wudriver.dll 2012-06-02 14:19:42 186752 ----a-w- C:\Windows\System32\wuwebv.dll 2012-06-02 14:15:12 36864 ----a-w- C:\Windows\System32\wuapp.exe 2012-06-02 12:12:17 2311680 ----a-w- C:\Windows\System32\jscript9.dll 2012-06-02 12:05:28 1392128 ----a-w- C:\Windows\System32\wininet.dll 2012-06-02 12:04:50 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl 2012-06-02 12:01:40 173056 ----a-w- C:\Windows\System32\ieUnatt.exe 2012-06-02 11:57:08 2382848 ----a-w- C:\Windows\System32\mshtml.tlb 2012-06-02 08:33:25 1800192 ----a-w- C:\Windows\SysWow64\jscript9.dll 2012-06-02 08:25:08 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll 2012-06-02 08:25:03 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl 2012-06-02 08:20:33 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe 2012-06-02 08:16:52 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb 2012-06-02 05:50:10 458704 ----a-w- C:\Windows\System32\drivers\cng.sys 2012-06-02 05:48:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys 2012-06-02 05:48:16 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys 2012-06-02 05:45:31 340992 ----a-w- C:\Windows\System32\schannel.dll 2012-06-02 05:44:21 307200 ----a-w- C:\Windows\System32\ncrypt.dll 2012-06-02 04:40:42 22016 ----a-w- C:\Windows\SysWow64\secur32.dll 2012-06-02 04:40:39 225280 ----a-w- C:\Windows\SysWow64\schannel.dll 2012-06-02 04:39:10 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll 2012-06-02 04:34:09 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll 2012-05-04 11:06:22 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe 2012-05-04 10:03:53 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2012-05-04 10:03:50 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe 2012-05-01 05:40:20 209920 ----a-w- C:\Windows\System32\profsvc.dll 2012-04-28 03:55:21 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys 2012-04-26 05:41:56 77312 ----a-w- C:\Windows\System32\rdpwsx.dll 2012-04-26 05:41:55 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll 2012-04-26 05:34:27 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe 2012-04-24 05:37:37 184320 ----a-w- C:\Windows\System32\cryptsvc.dll 2012-04-24 05:37:37 140288 ----a-w- C:\Windows\System32\cryptnet.dll 2012-04-24 05:37:36 1462272 ----a-w- C:\Windows\System32\crypt32.dll 2012-04-24 04:36:42 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll 2012-04-24 04:36:42 1158656 ----a-w- C:\Windows\SysWow64\crypt32.dll 2012-04-24 04:36:42 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll . ============= FINISH: 17:05:26.46 =============== Last edited by Mrjamieson; 24-Jul-2012 at 04:01 PM.. |
27-Jul-2012, 05:56 AM
#2 | |||||||
| Have i missed any info out? Would really appreciate some help. Many thanks. |
28-Jul-2012, 03:27 PM
#3 | |||||||
| please help? |
30-Jul-2012, 02:00 PM
#4 | |||||||
| bump |
01-Aug-2012, 01:46 PM
#5 | |||||||
| can someone help please? or should i just give up? |
01-Aug-2012, 03:09 PM
#6 | |||||||
| Don`t give up, do the following: Download OTL from any of the following links and save to your desktop. Link 1 Link 2 Link3 Double click the icon to start the tool. (Note: If you are running on Vista or Windows 7 accept UAC alert)
Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of OTL.Txt and the Extras.txt in your next reply. Kevin |
02-Aug-2012, 03:03 PM
#7 | |||||||
| Thank you so much for your reply. Here you go... OTL logfile created on: 02/08/2012 19:41:47 - Run 1 OTL by OldTimer - Version 3.2.55.0 Folder = C:\Users\harry\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 3.96 Gb Total Physical Memory | 1.90 Gb Available Physical Memory | 48.01% Memory free 7.93 Gb Paging File | 5.22 Gb Available in Paging File | 65.81% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 292.04 Gb Total Space | 205.78 Gb Free Space | 70.46% Space Free | Partition Type: NTFS Drive D: | 292.04 Gb Total Space | 291.94 Gb Free Space | 99.97% Space Free | Partition Type: NTFS Computer Name: HARRY-PC | User Name: harry | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012/08/02 19:40:57 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Users\harry\Downloads\OTL.com PRC - [2012/07/16 20:50:55 | 000,935,008 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe PRC - [2012/07/16 20:50:53 | 001,107,552 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe PRC - [2012/07/16 18:28:20 | 000,895,376 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe PRC - [2012/07/08 16:11:04 | 001,825,720 | ---- | M] (Bandoo Media, inc) -- C:\Program Files (x86)\Searchqu Toolbar\Datamngr\datamngrUI.exe PRC - [2012/05/31 05:10:58 | 000,336,992 | ---- | M] (Power Software Ltd) -- C:\Program Files (x86)\PowerISO\PWRISOVM.EXE PRC - [2012/04/04 06:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2012/02/23 12:30:40 | 000,059,240 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe PRC - [2012/01/17 11:07:58 | 000,505,736 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe PRC - [2011/09/22 01:35:57 | 000,117,648 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe PRC - [2011/08/05 15:20:26 | 002,033,152 | ---- | M] () -- C:\Program Files (x86)\iLivid\ilivid.exe PRC - [2011/02/25 10:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE PRC - [2010/03/08 08:27:49 | 000,041,800 | ---- | M] (AOL Inc.) -- C:\Program Files (x86)\Common Files\AOL\1301732618\ee\aolsoftware.exe PRC - [2009/10/23 01:21:14 | 000,151,368 | ---- | M] (Acer Corp.) -- C:\Program Files (x86)\TouchSettings\TouchPortalOBR.exe PRC - [2009/09/14 22:35:06 | 000,167,008 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe PRC - [2009/08/28 10:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe PRC - [2009/07/04 03:47:12 | 000,240,160 | ---- | M] (Acer) -- C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe PRC - [2009/06/24 16:09:56 | 000,386,400 | ---- | M] () -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe PRC - [2009/06/24 16:09:56 | 000,202,080 | ---- | M] () -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe PRC - [2009/06/24 16:09:46 | 000,230,632 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe PRC - [2008/12/08 15:16:56 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) -- c:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe PRC - [2007/06/20 22:04:20 | 000,046,432 | ---- | M] (Microsoft® Corporation) -- c:\Program Files (x86)\Microsoft Works\WkCalRem.exe ========== Modules (No Company Name) ========== MOD - [2012/07/31 06:36:14 | 000,442,392 | ---- | M] () -- C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\ppgoogl enaclpluginchrome.dll MOD - [2012/07/31 06:36:13 | 012,235,288 | ---- | M] () -- C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\PepperF lash\pepflashplayer.dll MOD - [2012/07/31 06:36:12 | 003,997,720 | ---- | M] () -- C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\pdf.dll MOD - [2012/07/31 06:34:57 | 000,526,872 | ---- | M] () -- C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\libgles v2.dll MOD - [2012/07/31 06:34:55 | 000,104,984 | ---- | M] () -- C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\libegl. dll MOD - [2012/07/31 06:34:45 | 000,144,424 | ---- | M] () -- C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\avutil-51.dll MOD - [2012/07/31 06:34:43 | 000,266,792 | ---- | M] () -- C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\avforma t-54.dll MOD - [2012/07/31 06:34:42 | 002,480,680 | ---- | M] () -- C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\avcodec-54.dll MOD - [2012/07/16 20:50:56 | 000,132,704 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.2.0\SiteSafety.dll MOD - [2012/07/16 20:50:53 | 001,107,552 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe MOD - [2012/06/27 16:38:52 | 000,531,968 | ---- | M] () -- C:\Users\harry\AppData\Roaming\BabylonToolbar\CR\BUSolution.dll MOD - [2012/05/26 19:04:13 | 000,134,144 | ---- | M] () -- C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.6_0\BabylonChrom eToolBar.dll MOD - [2012/02/20 21:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2012/02/20 21:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2011/08/05 15:20:26 | 002,033,152 | ---- | M] () -- C:\Program Files (x86)\iLivid\ilivid.exe MOD - [2011/05/16 12:31:36 | 002,555,392 | ---- | M] () -- C:\Program Files (x86)\iLivid\QtCore4.dll MOD - [2011/03/30 10:59:34 | 017,315,328 | ---- | M] () -- C:\Program Files (x86)\iLivid\QtWebKit4.dll MOD - [2011/03/30 08:15:12 | 002,177,024 | ---- | M] () -- C:\Program Files (x86)\iLivid\QtScript4.dll MOD - [2011/03/30 07:59:12 | 000,344,576 | ---- | M] () -- C:\Program Files (x86)\iLivid\phonon4.dll MOD - [2011/03/30 07:30:42 | 009,913,344 | ---- | M] () -- C:\Program Files (x86)\iLivid\QtGui4.dll MOD - [2011/03/30 07:00:00 | 001,209,344 | ---- | M] () -- C:\Program Files (x86)\iLivid\QtNetwork4.dll MOD - [2010/03/29 13:02:48 | 000,520,234 | ---- | M] () -- C:\ProgramData\Babylon\sqlite3.dll MOD - [2009/11/25 20:38:06 | 000,078,848 | ---- | M] () -- C:\Program Files (x86)\iLivid\imageformats\qgif4.dll MOD - [2009/11/25 20:38:02 | 000,193,536 | ---- | M] () -- C:\Program Files (x86)\iLivid\imageformats\qjpeg4.dll MOD - [2009/06/24 16:09:58 | 000,308,584 | ---- | M] () -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLCapEngine.dll MOD - [2009/06/24 16:09:58 | 000,132,448 | ---- | M] () -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLSchMgr.dll MOD - [2009/06/24 16:09:58 | 000,038,120 | ---- | M] () -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLCapSvcps.dll MOD - [2009/06/24 16:09:56 | 000,345,320 | ---- | M] () -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLTinyDB.dll MOD - [2009/06/22 19:42:42 | 000,043,008 | ---- | M] () -- C:\Program Files (x86)\iLivid\libgcc_s_dw2-1.dll MOD - [2009/01/10 11:32:40 | 000,011,362 | ---- | M] () -- C:\Program Files (x86)\iLivid\mingwm10.dll ========== Win32 Services (SafeList) ========== SRV:64bit: - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc) SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:64bit: - [2009/07/04 03:47:12 | 000,240,160 | ---- | M] (Acer) [Auto | Running] -- C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe -- (Updater Service) SRV - [2012/07/26 22:39:30 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012/07/16 20:50:55 | 000,935,008 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe -- (vToolbarUpdater11.2.0) SRV - [2012/04/04 06:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011/09/22 01:35:57 | 000,117,648 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe -- (Norton Internet Security) SRV - [2011/03/31 00:07:11 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2011/02/28 18:44:14 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE -- (BBSvc) SRV - [2011/02/25 10:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE -- (SeaPort) SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009/08/29 02:05:56 | 000,044,312 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe -- (OberonGameConsoleService) SRV - [2009/08/28 10:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe -- (Greg_Service) SRV - [2009/06/24 16:09:56 | 000,386,400 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe -- (TVECapSvc) SRV - [2009/06/24 16:09:56 | 000,202,080 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe -- (TVESched) SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2008/12/08 15:16:56 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- c:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor7.0) SRV - [2006/10/23 13:50:35 | 000,046,640 | R--- | M] (AOL LLC) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\AOL\acs\AOLacsd.exe -- (AOL ACS) ========== Driver Services (SafeList) ========== DRV:64bit: - [2012/05/31 05:10:48 | 000,126,944 | ---- | M] (Power Software Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\scdemu.sys -- (SCDEmu) DRV:64bit: - [2012/03/08 18:40:52 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr) DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2012/02/15 11:01:50 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64) DRV:64bit: - [2011/10/11 02:09:51 | 000,561,800 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\cchpx64.sys -- (ccHP) DRV:64bit: - [2011/09/22 01:35:58 | 000,279,160 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\symtdi.sys -- (SYMTDI) DRV:64bit: - [2011/09/22 01:35:58 | 000,120,952 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\symfw.sys -- (SYMFW) DRV:64bit: - [2011/09/22 01:35:58 | 000,056,952 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\symndisv.sys -- (SYMNDISV) DRV:64bit: - [2011/07/25 14:00:07 | 000,116,864 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard) DRV:64bit: - [2011/07/25 14:00:07 | 000,116,224 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbfake.sys -- (hwusbfake) DRV:64bit: - [2011/03/30 23:37:34 | 000,172,592 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent) DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2010/11/20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010/11/20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010/11/20 10:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus) DRV:64bit: - [2010/08/25 19:36:04 | 010,611,552 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2010/07/13 09:57:08 | 000,069,736 | ---- | M] (ITE Tech. Inc. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\itecir.sys -- (itecir) DRV:64bit: - [2010/01/20 22:18:24 | 000,334,384 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\BHDrvx64.sys -- (BHDrvx64) DRV:64bit: - [2009/11/27 08:29:56 | 000,476,720 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\srtsp64.sys -- (SRTSP) DRV:64bit: - [2009/11/27 08:29:56 | 000,402,992 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\SymEFA64.sys -- (SymEFA) DRV:64bit: - [2009/11/27 08:29:56 | 000,032,304 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\srtspx64.sys -- (SRTSPX) DRV:64bit: - [2009/11/27 08:29:56 | 000,031,280 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SymIMV.sys -- (SymIM) DRV:64bit: - [2009/08/13 04:21:40 | 000,364,800 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVerPola.sys -- (AVerPola) DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009/07/14 01:10:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rootmdm.sys -- (ROOTMODEM) DRV:64bit: - [2009/07/13 07:31:42 | 000,233,472 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2009/07/09 13:45:42 | 000,140,128 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\jmcr.sys -- (JMCR) DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2009/06/10 21:31:36 | 000,220,288 | ---- | M] (AfaTech ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AF9035BDA.sys -- (AF9035BDA) DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV:64bit: - [2009/01/09 15:02:08 | 000,031,744 | ---- | M] (Research in Motion Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimSerial_AMD64.sys -- (RimVSerPort) DRV:64bit: - [2008/06/16 03:00:00 | 000,055,024 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64) DRV:64bit: - [2006/11/29 23:24:49 | 000,024,064 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wanatw64.sys -- (wanatw) DRV:64bit: - [2006/04/07 16:06:59 | 000,702,976 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x) DRV - [2012/06/14 19:39:24 | 000,509,088 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20120801.001\IDSviA64.sys -- (IDSVia64) DRV - [2012/06/12 03:21:30 | 002,068,600 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20120801.037\ex64.sys -- (NAVEX15) DRV - [2012/06/12 03:21:30 | 000,138,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv) DRV - [2012/06/12 03:21:30 | 000,120,440 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20120801.037\eng64.sys -- (NAVENG) DRV - [2012/05/16 05:16:24 | 000,484,512 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl) DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.packardbell.com/rdr....7y175y44l10587 IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={ inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=390&systemid=406&sr=0&q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.packardbell.com/rdr....7y175y44l10587 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\URLSearchHook: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll (Conduit Ltd.) IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer: source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACPW IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={ inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\..\SearchScopes\{74BD08EB-D440-4d57-AAAC-2159274CF9C7}: "URL" = http://slirsredirect.search.aol.com/redirector/sredir?sredir=3530&query={searchTerms}&invocationType=tb50-ie-aolbbTB50CL-chromesbox-en-uk IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=390&systemid=406&sr=0&q={searchTerms} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://toolbar.inbox.com/search/disp...b_id&%language IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ IE - HKCU\..\URLSearchHook: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll (Conduit Ltd.) IE - HKCU\..\URLSearchHook: {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - No CLSID value found IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=110819&babsrc=SP_ss&mntrId=e81350900000000000000017c 4ddd1cf IE - HKCU\..\SearchScopes\{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}: "URL" = http://search.alot.com/web?q={searchTerms} IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer: source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACPW_enGB425 IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={ inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKCU\..\SearchScopes\{74BD08EB-D440-4d57-AAAC-2159274CF9C7}: "URL" = http://slirsredirect.search.aol.com/redirector/sredir?sredir=3530&query={searchTerms}&invocationType=tb50-ie-aolbbTB50CL-chromesbox-en-uk IE - HKCU\..\SearchScopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}: "URL" = http://search.ibryte.com/i/playbryte/search/redirect/?type=default-ie&user_id=2b5874c6-f1a3-49b8-969b-3052e2cfaab3&query={searchTerms} IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={669F9C01-9596-40A7-B6AF-49CA9AAFB861}&mid=bd25346cc18247d0a1c9d14acce4e9e6-b4e8f41bc2ef5df94a3dc5034385d12e1be891b4&lang=en&ds=st011&pr=sa&d=2012-07-16 20:50:57&v=11.1.0.12&sap=dsp&q={searchTerms} IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=390&systemid=406&sr=0&q={searchTerms} IE - HKCU\..\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}: "URL" = http://toolbar.inbox.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=80359&lng=en IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)" FF - prefs.js..browser.search.order.1: "Search Results" FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)" FF - prefs.js..browser.startup.homepage: "http://www.searchnu.com/406" FF - prefs.js..keyword.URL: "http://dts.search-results.com/sr?src=ffb&appid=390&systemid=406&sr=0&q=" FF - prefs.js..network.proxy.type: 0 FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.babylon.com/?AF=100581&babsrc=adbartrp&mntrId=e81350900000000000000017c4ddd1cf&q=" FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_268.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ File not found FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.2.0\\npsitesafety.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\harry\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\harry\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\harry\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\ [2011/10/13 03:29:30 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\11.1.0.12\ [2012/07/16 20:51:07 | 000,000,000 | ---D | M] [2012/07/19 16:58:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\harry\AppData\Roaming\Mozilla\Extensions [2012/07/24 21:43:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\ex tensions [2012/07/24 21:43:01 | 000,000,000 | ---D | M] (uTorrentControl2 Community Toolbar) -- C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\ex tensions\{687578b9-7132-4a7a-80e4-30ee31099e03} [2012/07/19 16:58:49 | 000,000,000 | ---D | M] (Searchqu Toolbar) -- C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\ex tensions\{99079a25-328f-4bd4-be04-00955acaa0a7} [2012/03/31 08:31:21 | 000,000,000 | ---D | M] (AppGraffiti) -- C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\ex tensions\AppGraffiti@AppGraffiti.com [2012/01/03 19:43:22 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\ex tensions\ffxtlbr@babylon.com [2012/07/16 21:06:10 | 000,000,000 | ---D | M] (VideoFileDownload - Download YouTube Videos) -- C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\ex tensions\plugin@videofiledownload.com [2011/07/23 12:03:40 | 000,002,230 | ---- | M] () -- C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\se archplugins\iBryte_playbryte.xml [2012/07/19 16:58:43 | 000,002,519 | ---- | M] () -- C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\se archplugins\Search_Results.xml [2012/01/03 19:44:37 | 000,003,915 | ---- | M] () -- C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\se archplugins\sweetim.xml [2012/07/27 18:24:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions [2011/06/29 21:25:31 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2012/01/03 19:43:40 | 000,000,000 | ---D | M] ("Babylon Spelling and Proofreading") -- C:\Program Files (x86)\Mozilla Firefox\extensions\adapter@babylontc.com [2012/01/03 19:43:38 | 000,000,000 | ---D | M] (Babylon OCR) -- C:\Program Files (x86)\Mozilla Firefox\extensions\ocr@babylon.com [2012/07/19 16:58:54 | 000,000,000 | ---D | M] (DataMngr) -- C:\PROGRAM FILES (X86)\SEARCHQU TOOLBAR\DATAMNGR\FIREFOXEXTENSION [2012/07/16 20:51:07 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\PROGRAMDATA\AVG SECURE SEARCH\11.1.0.12 [2012/07/16 20:50:52 | 000,003,750 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml [2012/05/26 16:43:29 | 000,002,313 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\babylon.xml [2012/07/19 16:58:43 | 000,002,519 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml ========== Chrome ========== CHR - homepage: http://www.searchnu.com/406 CHR - default_search_provider: Search Results (Enabled) CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&appid=390&systemid=406&sr=0&q={searchTerms} CHR - default_search_provider: suggest_url = CHR - homepage: http://www.searchnu.com/406 CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\ppGoogl eNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\pdf.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\gcswf32 .dll CHR - plugin: Shockwave Flash (Disabled) = C:\Users\harry\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll CHR - plugin: Babylon Chrome Plugin (Enabled) = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.4_0\BabylonChrom ePI.dll CHR - plugin: Skype Toolbars (Enabled) = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.3.0.7550_0\npSky peChromePlugin.dll CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll CHR - plugin: Java(TM) Platform SE 7 U4 (Enabled) = C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll CHR - plugin: Java Deployment Toolkit 7.0.40.255 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll CHR - plugin: Vizzed Retro Game Room Plugin (Enabled) = C:\Program Files (x86)\Vizzed\Vizzed Retro Game Room\NpVizzedRgr.dll CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll CHR - plugin: Unity Player (Enabled) = C:\Users\harry\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll CHR - Extension: AppGraffiti - Free Facebook Layouts = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\angobeimajilfhlcpeiccndaifchnppl\1.0.0.9_0\ CHR - Extension: Babylon Toolbar = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.6_0\ CHR - Extension: AT_JennyHolzerV7 = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\fajfiabcfidbbaelfcficghfgheddefo\3_0\ CHR - Extension: Fast save = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffcalihdlalnkhmanhindcdckagnlfce\1.1_0\ CHR - Extension: Planetarium = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\gheikhdfflhlbemfmhcfpeblehemeklp\1.1.1_0\ CHR - Extension: YourNextFilm = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\jadajphjladhhmcjiomkmlihlknbnicc\0.0.0.1_0\ CHR - Extension: VideoFileDownload = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\kincjchfokkeneeofpeefomkikfkiedl\1.0_0\ CHR - Extension: InvisibleHand = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\lghjfnfolmcikomdjmoiemllfnlmmoko\3.8.5_0\ CHR - Extension: Skype Extension = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.3.0.7550_0\ CHR - Extension: uTorrentControl2 = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\ O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files (x86)\Searchqu Toolbar\Datamngr\x64\BrowserConnection.dll (Bandoo Media, inc) O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll (Babylon BHO) O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation) O2 - BHO: (uTorrentControl2 Toolbar) - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll (Conduit Ltd.) O2 - BHO: (VideoFileDownload) - {68DD98BF-9DE8-418C-89F0-E37AC61CC2D9} - C:\Program Files (x86)\OApps\bho_project.dll (VideoFileDownload) O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\IPSBHO.dll (Symantec Corporation) O2 - BHO: (AppGraffiti) - {6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} - C:\Program Files (x86)\AppGraffiti\AppGraffiti.dll (Omega Partners Ltd) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll () O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll () O2 - BHO: (Babylon IE plugin) - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.) O2 - BHO: (DataMngr) - {9D717F81-9148-4f12-8568-69135F087DB0} - C:\Program Files (x86)\Searchqu Toolbar\Datamngr\BrowserConnection.dll (Bandoo Media, inc) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (ALOT Toolbar) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files (x86)\alot\bin\alot.dll (Vertro) O3 - HKLM\..\Toolbar: (uTorrentControl2 Toolbar) - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation) O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.) O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll () O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll (Babylon Ltd.) O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll () O3 - HKLM\..\Toolbar: (no name) - {b278d9f8-0fa9-465e-9938-0c392605d8e3} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentControl2 Toolbar) - {687578B9-7132-4A7A-80E4-30EE31099E03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll (Conduit Ltd.) O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation) O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4:64bit: - HKLM..\Run: [TouchORB] C:\Program Files (x86)\TouchSettings\TouchPortalOBR.exe (Acer Corp.) O4 - HKLM..\Run: [Babylon Client] C:\Program Files (x86)\Babylon\Babylon-Pro\Babylon.exe (Babylon Ltd.) O4 - HKLM..\Run: [DATAMNGR] C:\Program Files (x86)\Searchqu Toolbar\Datamngr\datamngrUI.exe (Bandoo Media, inc) O4 - HKLM..\Run: [HF_G_Jul] C:\Program Files (x86)\AVG Secure Search\HF_G_Jul.exe () O4 - HKLM..\Run: [HostManager] C:\Program Files (x86)\Common Files\AOL\1301732618\ee\aolsoftware.exe (AOL Inc.) O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation) O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (Power Software Ltd) O4 - HKLM..\Run: [TVEService] C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe (CyberLink Corp.) O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe () O4 - HKLM..\Run: [YouCam Mirror Tray icon] C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe (CyberLink Corp.) O4 - HKCU..\Run: [MusicGadget] "C:\Program Files (x86)\Packard Bell\Packard Bell Touch Suite\TouchMusic.exe" File not found O4 - HKCU..\Run: [PhotoGadget] "C:\Program Files (x86)\Packard Bell\Packard Bell Touch Suite\TouchPhotoShow.exe" File not found O4 - HKCU..\Run: [SNSGadget] "C:\Program Files (x86)\Packard Bell\Packard Bell Touch Suite\TouchFriends.exe" File not found O4 - HKCU..\Run: [TouchMemo] Reg Error: Invalid data type. File not found O4 - Startup: C:\Users\harry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TalkTalk Diagnostic Reporting Tool.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found O8:64bit: - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105 File not found O8:64bit: - Extra context menu item: Translate this web page with Babylon - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.) O8:64bit: - Extra context menu item: Translate with Babylon - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.) O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 File not found O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105 File not found O8 - Extra context menu item: Translate this web page with Babylon - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.) O8 - Extra context menu item: Translate with Babylon - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.) O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.) O9 - Extra 'Tools' menuitem : Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (Babylon Ltd.) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5) O15 - HKCU\..Trusted Domains: vizzed.com ([www] * in Trusted sites) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 10.4.1) O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/...soft/wrc32.ocx (WRC Class) O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_30) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 10.4.1) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8A63913D-417F-4EE8-AEAD-DA34552E29BB}: DhcpNameServer = 192.168.0.1 O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found O18:64bit: - Protocol\Handler\msnim - No CLSID value found O18:64bit: - Protocol\Handler\skype4com - No CLSID value found O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found O18:64bit: - Protocol\Handler\symres - No CLSID value found O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation) O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll () O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\SEARCH~1\Datamngr\x64\datamngr.dll) - C:\Program Files (x86)\Searchqu Toolbar\Datamngr\x64\datamngr.dll (Bandoo Media, inc) O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\SEARCH~1\Datamngr\x64\IEBHO.dll) - C:\Program Files (x86)\Searchqu Toolbar\Datamngr\x64\IEBHO.dll (Bandoo Media, inc) O20 - AppInit_DLLs: (C:\PROGRA~2\SEARCH~1\Datamngr\datamngr.dll) - C:\Program Files (x86)\Searchqu Toolbar\Datamngr\datamngr.dll (Bandoo Media, inc) O20 - AppInit_DLLs: (C:\PROGRA~2\SEARCH~1\Datamngr\IEBHO.dll) - C:\Program Files (x86)\Searchqu Toolbar\Datamngr\IEBHO.dll (Bandoo Media, inc) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{5f9ca6a4-b62d-11e0-9e1c-00038a000015}\Shell - "" = AutoRun O33 - MountPoints2\{5f9ca6a4-b62d-11e0-9e1c-00038a000015}\Shell\AutoRun\command - "" = F:\.\Setup.exe AUTORUN=1 O33 - MountPoints2\F\Shell - "" = AutoRun O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\.\Setup.exe AUTORUN=1 O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2012/07/28 20:33:22 | 000,000,000 | ---D | C] -- C:\Users\harry\Desktop\Romantic Lodges - Book UK Lodge Holidays from bookholidaylodge.co.uk's Huge Range of Lodges._files [2012/07/24 21:42:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla [2012/07/22 17:22:35 | 000,000,000 | ---D | C] -- C:\Users\harry\Desktop\tech support [2012/07/19 17:01:14 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\Ilivid Player [2012/07/19 17:00:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iLivid [2012/07/19 16:58:44 | 000,000,000 | ---D | C] -- C:\ProgramData\boost_interprocess [2012/07/19 16:58:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Searchqu Toolbar [2012/07/16 21:06:26 | 000,000,000 | ---D | C] -- C:\Users\harry\Documents\MyTorrents [2012/07/16 21:06:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OApps [2012/07/16 21:06:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TorrentSearch [2012/07/16 21:05:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\smartdl [2012/07/16 20:51:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO [2012/07/16 20:51:13 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\AVG Secure Search [2012/07/16 20:50:56 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Secure Search [2012/07/16 20:50:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVG Secure Search [2012/07/16 20:50:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG Secure Search [2012/07/16 20:49:49 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files [2012/07/16 20:49:43 | 000,126,944 | ---- | C] (Power Software Ltd) -- C:\Windows\SysNative\drivers\scdemu.sys [2012/07/16 20:49:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PowerISO [2012/07/16 19:33:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSECache [2012/07/16 18:28:52 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\CRE [2012/07/16 18:28:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\uTorrent [2012/07/16 18:27:45 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Roaming\uTorrent [2012/07/16 17:47:31 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{93521D56-D5BA-45DB-9899-217B984F1B05} [2012/07/16 16:32:10 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\MicrosoftStore [2012/07/16 16:29:44 | 000,000,000 | ---D | C] -- C:\Users\harry\Documents\OneNote Notebooks [2012/07/16 12:34:19 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{EA2C0C36-F559-4C00-ABEE-8B9BC80FC53F} [2012/07/15 11:44:20 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{E474B330-5EA8-4835-9507-1F9AEE801165} [2012/07/15 11:44:08 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{50BE36D1-782F-4351-A3E4-93BA51BAB5D6} [2012/07/14 15:15:16 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{6AFF746D-36B1-4467-A0E2-601D82B81C10} [2012/07/14 15:15:05 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{0E1FED34-F893-4966-AB65-D0724E1EB2A0} [2012/07/14 14:50:33 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Roaming\Temp [2012/07/14 14:37:43 | 000,000,000 | ---D | C] -- C:\Users\harry\Desktop\C.V's [2012/07/14 14:36:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner [2012/07/14 14:36:31 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner [2012/07/13 15:34:25 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{0388C4E8-CAB5-4D13-80F4-520BD0D8CF68} [2012/07/13 15:34:13 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{E87E6765-0AE8-4345-A574-85CA9451B362} [2012/07/13 03:33:47 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{9EF70447-BE4E-4BAA-A18D-9D8D3738A371} [2012/07/13 03:33:35 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{438AB6C3-BF21-4AFE-9550-A2910F9C6BE5} [2012/07/12 15:33:08 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{69FC119A-655F-4D87-B942-E27CACD7E5B3} [2012/07/12 03:31:00 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{2D0F57B4-5013-4A0C-AA44-D315CD1EF11E} [2012/07/12 03:30:48 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{0DDFB27F-1C74-493C-BC4A-D7335C1E3950} [2012/07/12 03:02:08 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll [2012/07/12 03:02:08 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll [2012/07/12 03:02:07 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll [2012/07/12 03:02:07 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll [2012/07/12 03:02:05 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2012/07/12 03:02:05 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2012/07/12 03:02:04 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe [2012/07/12 03:02:04 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe [2012/07/12 03:02:02 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl [2012/07/12 03:02:02 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl [2012/07/12 03:02:01 | 002,311,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll [2012/07/12 03:02:01 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll [2012/07/12 03:02:01 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll [2012/07/11 13:10:38 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3r.dll [2012/07/11 13:10:38 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml3r.dll [2012/07/11 13:10:30 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll [2012/07/11 13:10:26 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cdosys.dll [2012/07/11 13:10:25 | 001,133,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdosys.dll [2012/07/08 18:56:05 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{CB38660F-F955-41F7-9DF0-8EAD307D3731} [2012/07/08 18:55:53 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{4C6FC563-98AE-4C5E-BBBA-081E1D4D6B29} [2012/07/07 13:12:07 | 000,000,000 | ---D | C] -- C:\Users\harry\Desktop\Ibiza ========== Files - Modified Within 30 Days ========== [2012/08/02 19:39:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012/08/02 19:35:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1615065723-140565034-61851805-1000UA.job [2012/08/02 19:02:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012/08/01 22:35:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1615065723-140565034-61851805-1000Core.job [2012/08/01 21:38:20 | 000,002,457 | ---- | M] () -- C:\Users\harry\Desktop\Google Chrome.lnk [2012/08/01 20:02:01 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012/07/31 04:58:03 | 000,000,572 | ---- | M] () -- C:\Users\harry\AppData\Roaming\wklnhst.dat [2012/07/30 09:50:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012/07/28 20:33:22 | 000,043,569 | ---- | M] () -- C:\Users\harry\Desktop\Romantic Lodges - Book UK Lodge Holidays from bookholidaylodge.co.uk's Huge Range of Lodges..htm [2012/07/26 22:39:29 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe [2012/07/26 22:39:29 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2012/07/26 16:04:13 | 000,007,597 | ---- | M] () -- C:\Users\harry\AppData\Local\Resmon.ResmonCfg [2012/07/25 22:03:08 | 000,013,101 | ---- | M] () -- C:\Users\harry\Desktop\Adjust system volume - Shortcut.lnk [2012/07/24 00:26:39 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012/07/24 00:26:39 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012/07/22 16:28:49 | 3192,987,648 | -HS- | M] () -- C:\hiberfil.sys [2012/07/22 16:25:30 | 000,388,632 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2012/07/19 17:01:00 | 000,001,146 | ---- | M] () -- C:\Users\Public\Desktop\Upgrade Facebook Chat Experience.lnk [2012/07/19 17:01:00 | 000,001,144 | ---- | M] () -- C:\Users\Public\Desktop\Play Games.lnk [2012/07/19 17:01:00 | 000,000,955 | ---- | M] () -- C:\Users\Public\Desktop\iLivid.lnk [2012/07/16 20:51:18 | 000,000,975 | ---- | M] () -- C:\Users\Public\Desktop\PowerISO.lnk [2012/07/16 18:28:20 | 000,000,935 | ---- | M] () -- C:\Users\harry\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk [2012/07/16 18:28:20 | 000,000,911 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk [2012/07/16 02:03:42 | 000,184,891 | ---- | M] () -- C:\torrent.exe [2012/07/14 14:36:37 | 000,000,834 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2012/07/10 10:39:53 | 000,025,088 | ---- | M] () -- C:\Users\harry\Documents\ppi.wps ========== Files Created - No Company Name ========== [2012/07/28 20:33:20 | 000,043,569 | ---- | C] () -- C:\Users\harry\Desktop\Romantic Lodges - Book UK Lodge Holidays from bookholidaylodge.co.uk's Huge Range of Lodges..htm [2012/07/26 16:04:13 | 000,007,597 | ---- | C] () -- C:\Users\harry\AppData\Local\Resmon.ResmonCfg [2012/07/25 22:03:08 | 000,013,101 | ---- | C] () -- C:\Users\harry\Desktop\Adjust system volume - Shortcut.lnk [2012/07/19 17:01:00 | 000,001,146 | ---- | C] () -- C:\Users\Public\Desktop\Upgrade Facebook Chat Experience.lnk [2012/07/19 17:01:00 | 000,001,144 | ---- | C] () -- C:\Users\Public\Desktop\Play Games.lnk [2012/07/19 16:58:23 | 000,000,955 | ---- | C] () -- C:\Users\Public\Desktop\iLivid.lnk [2012/07/17 12:57:28 | 000,002,671 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Word Viewer 2003.lnk [2012/07/16 20:51:18 | 000,000,975 | ---- | C] () -- C:\Users\Public\Desktop\PowerISO.lnk [2012/07/16 18:28:20 | 000,000,935 | ---- | C] () -- C:\Users\harry\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk [2012/07/16 18:28:20 | 000,000,911 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk [2012/07/16 02:03:42 | 000,184,891 | ---- | C] () -- C:\torrent.exe [2012/07/14 14:36:37 | 000,000,834 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk [2012/07/10 10:39:53 | 000,025,088 | ---- | C] () -- C:\Users\harry\Documents\ppi.wps [2011/11/27 18:48:21 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat [2011/11/04 06:00:01 | 000,000,000 | ---- | C] () -- C:\Users\harry\AppData\Local\{62891E8A-8BF0-4290-A839-70717644831D} [2011/10/25 15:59:15 | 000,000,000 | ---- | C] () -- C:\Users\harry\AppData\Local\{2B9BFA8E-E01D-4925-A136-69CEEFCD8A82} [2011/07/06 19:33:09 | 000,017,408 | ---- | C] () -- C:\Users\harry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011/05/19 22:30:54 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2011/04/02 09:16:06 | 000,000,335 | ---- | C] () -- C:\Windows\nsreg.dat [2011/04/01 20:12:31 | 000,000,572 | ---- | C] () -- C:\Users\harry\AppData\Roaming\wklnhst.dat [2010/08/25 19:34:30 | 000,982,240 | ---- | C] () -- C:\Windows\SysWow64\igkrng500.bin [2010/08/25 19:34:30 | 000,439,308 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng500.bin [2010/08/25 19:34:30 | 000,092,356 | ---- | C] () -- C:\Windows\SysWow64\igfcg500m.bin [2010/08/25 18:52:00 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll [2010/08/25 18:52:00 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll [2009/11/27 08:03:20 | 000,131,368 | ---- | C] () -- C:\ProgramData\FullRemove.exe ========== LOP Check ========== [2011/04/01 19:51:53 | 000,000,000 | -HSD | M] -- C:\Users\harry\AppData\Roaming\.# [2012/02/01 04:16:04 | 000,000,000 | ---D | M] -- C:\Users\harry\AppData\Roaming\Babylon [2012/05/26 16:44:16 | 000,000,000 | ---D | M] -- C:\Users\harry\AppData\Roaming\BabylonToolbar [2011/04/01 19:51:43 | 000,000,000 | ---D | M] -- C:\Users\harry\AppData\Roaming\GameConsole [2011/06/06 08:00:20 | 000,000,000 | ---D | M] -- C:\Users\harry\AppData\Roaming\go [2011/04/01 20:17:12 | 000,000,000 | ---D | M] -- C:\Users\harry\AppData\Roaming\Packard Bell [2011/09/25 17:45:49 | 000,000,000 | ---D | M] -- C:\Users\harry\AppData\Roaming\PlayFirst [2011/06/15 22:01:54 | 000,000,000 | ---D | M] -- C:\Users\harry\AppData\Roaming\PowerCinema [2011/08/02 14:31:29 | 000,000,000 | ---D | M] -- C:\Users\harry\AppData\Roaming\SecondLife [2012/07/14 14:52:15 | 000,000,000 | ---D | M] -- C:\Users\harry\AppData\Roaming\Systweak [2011/07/22 19:29:02 | 000,000,000 | ---D | M] -- C:\Users\harry\AppData\Roaming\TalkTalk [2012/07/14 14:50:33 | 000,000,000 | ---D | M] -- C:\Users\harry\AppData\Roaming\Temp [2011/09/24 15:12:33 | 000,000,000 | ---D | M] -- C:\Users\harry\AppData\Roaming\Template [2012/08/02 19:51:45 | 000,000,000 | ---D | M] -- C:\Users\harry\AppData\Roaming\uTorrent [2011/09/25 17:01:14 | 000,000,000 | ---D | M] -- C:\Users\harry\AppData\Roaming\ViquaSoft [2011/11/01 22:46:12 | 000,032,554 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 143 bytes -> C:\ProgramData\Temp:0B9176C0 @Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:798A3728 @Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:CDFF58FE @Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:ABE89FFE @Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:51574724 @Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:4D066AD2 @Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:444C53BA < End of report > OTL Extras logfile created on: 02/08/2012 19:41:47 - Run 1 OTL by OldTimer - Version 3.2.55.0 Folder = C:\Users\harry\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 3.96 Gb Total Physical Memory | 1.90 Gb Available Physical Memory | 48.01% Memory free 7.93 Gb Paging File | 5.22 Gb Available in Paging File | 65.81% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 292.04 Gb Total Space | 205.78 Gb Free Space | 70.46% Space Free | Partition Type: NTFS Drive D: | 292.04 Gb Total Space | 291.94 Gb Free Space | 99.97% Space Free | Partition Type: NTFS Computer Name: HARRY-PC | User Name: harry | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameter s\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameter s\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameter s\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameter s\FirewallPolicy\StandardProfile\AuthorizedApplications\List] ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameter s\FirewallPolicy\FirewallRules] "{024B8FD9-E1C5-4337-8D39-A704BCB85629}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{09698E75-B35D-4C4D-834B-6B1E5E692B2A}" = lport=4482 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer | "{0D088982-7F68-40AA-9354-1B5273490F96}" = lport=4482 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery | "{0F7FEE5E-B8B3-45B8-BF5E-6FE8F9FF77DE}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{11A6E1D9-E78A-4507-BE59-76E90DFF2E96}" = lport=138 | protocol=17 | dir=in | app=system | "{14A47E98-4C2B-45E9-8883-53A11C4E861F}" = lport=139 | protocol=6 | dir=in | app=system | "{17562A89-7E35-4441-A557-3C10C330108E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{1F7D7758-2D65-40C7-B08A-F6323F601901}" = lport=10243 | protocol=6 | dir=in | app=system | "{1F9FCFBD-FD59-4F0A-967C-A43E1E6D9AF6}" = rport=137 | protocol=17 | dir=out | app=system | "{296A800B-8B82-4D3B-84CC-CCE973D5E25B}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{298F8955-719A-4C9D-9F72-B750ABBB7119}" = rport=445 | protocol=6 | dir=out | app=system | "{33BC75AE-AC17-4025-8DDF-3B812CF109D2}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{533EA3E8-71CC-4135-8818-4491F0253E7C}" = lport=2869 | protocol=6 | dir=in | app=system | "{58EFEA2F-AADD-4D4A-91C8-D7FECE781772}" = lport=2869 | protocol=6 | dir=in | app=system | "{5A2317E2-AD61-4772-A2BE-B3537A3457AC}" = lport=4481 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer | "{668A1C73-3847-4FC0-87C9-08E2C2B72EB3}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{66AF9148-643E-4600-A1AB-53C13FA4E5D6}" = rport=10243 | protocol=6 | dir=out | app=system | "{69C1D6F8-D1B5-42A5-8900-6260C68A1324}" = lport=137 | protocol=17 | dir=in | app=system | "{6A931D35-E497-4FA7-82EA-3E827846ABAA}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{7169ACF6-CB73-44CB-B2DE-A91D313A7471}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{850B9F16-1663-4110-9F59-A9928EC9E41F}" = lport=445 | protocol=6 | dir=in | app=system | "{B69E7677-E37A-4E2B-A881-D61E6E9C9481}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{C0FD862F-B0C0-45AE-8F43-6FFFD07CF8F3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{D49B0D2B-2135-46C1-B4CE-44D2F1EEAEFF}" = lport=4481 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery | "{D4ECFF01-BFF0-4F7E-911A-3C6E2CE39471}" = rport=138 | protocol=17 | dir=out | app=system | "{DA4BD205-7CD4-4225-A078-E3F261640971}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{DB4C24D2-47CE-40CF-9C2C-0975BF0A308C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{DB9753AD-7664-4577-AC5C-86B002E280DE}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{EB2301D1-0F50-4FB4-937F-260A20303BDD}" = rport=139 | protocol=6 | dir=out | app=system | "{EDE1DED6-988E-4F1D-BFFC-599F9E50BD63}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{F549EFDB-185A-4686-A4F9-8173173D5C38}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameter s\FirewallPolicy\FirewallRules] "{00072475-1A45-4AD4-9192-92992BE945D8}" = protocol=6 | dir=in | app=c:\program files (x86)\cyberlink\tv enhance\tvenhance.exe | "{032AAEC0-E31F-4037-9AA1-8C9D7860C88D}" = protocol=6 | dir=in | app=c:\users\harry\downloads\sweetimsetup(2).exe | "{05D8A0C9-41E9-4930-AA8B-7E0BAA83671E}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{06B5A145-4563-4276-8EFC-07834EEDED31}" = protocol=17 | dir=in | app=c:\program files (x86)\cyberlink\tv enhance\tvenhance.exe | "{0FBEB474-B289-4CE2-A7E7-1DCBD722F54A}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{1044902C-BCD5-4881-A9CF-CE236A4E262E}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{1425351F-6A5B-41F6-ADC5-6C50E4464E42}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{18C2087C-3646-4D89-B4DB-600F35F11812}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{2BF2D207-3083-425E-B7A1-2C2AC09DAA00}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{31C79A41-3B92-4527-B80B-4DECE520D26B}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\1301732618\ee\aolsoftware.exe | "{398E1825-4686-41AF-BEEB-E490B99F7A2C}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{3E1FD19C-20A1-46DA-B27F-7D35BBEC3EC1}" = dir=in | app=c:\program files (x86)\cyberlink\powercinema\pcmservice.exe | "{4021F177-2F97-4EC6-904A-91BA0EDF7AAD}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe | "{43A68F91-6A53-4C1E-9595-120420540849}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{44ADD980-3D0E-41BB-A766-3EC749588052}" = protocol=17 | dir=in | app=c:\program files (x86)\cyberlink\tv enhance\tveservice.exe | "{46553DAB-C833-426E-84DF-CD6476C8400C}" = protocol=17 | dir=in | app=c:\users\harry\downloads\sweetimsetup(2).exe | "{476C7210-AD49-4279-A0E3-DF38CF6C45A7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{47F8ED8C-FCB9-4B49-AE13-3710AA70A061}" = protocol=17 | dir=in | app=c:\program files (x86)\searchqu toolbar\datamngr\toolbar\dtuser.exe | "{4A5994A5-8C45-4FC8-9266-DA3A596411F3}" = dir=in | app=c:\program files (x86)\cyberlink\powercinema\kernel\dms\clmsservice.exe | "{4A63D6A0-0384-4941-9F13-80C49FA5696B}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{4DAB80F3-D319-4D99-B537-F1498438EE67}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{51A9AE2D-7BC1-492E-B506-5859F0067214}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{5515FC1B-DD99-4D30-B363-C5819067813D}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | "{5DA73CC1-4C45-4825-9FB7-BE0DADD8D885}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{5F6AC7C0-7E9F-4976-8815-B788C2181ED2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{6581D382-1857-4008-9714-EE21AFC534F1}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\topspeed\3.0\aoltpsd3.exe | "{670E6427-C6AB-4530-8858-A98AF4D010F7}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\acs\aoldial.exe | "{673B9F9A-913F-403C-80A1-6CBBFBD3CF5B}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "{74DEA22C-127A-4525-8446-968D97D6B0BA}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{78C9C64D-1B06-405A-A454-7FDC9B3A2160}" = protocol=17 | dir=in | app=c:\program files (x86)\cyberlink\tv enhance\tvenhance.exe | "{7C981FC9-39B7-4C84-8EDD-6FDF333A13EC}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\acs\aolacsd.exe | "{7D888C50-6180-4F2D-A977-DA61D3E8A589}" = dir=in | app=c:\program files (x86)\cyberlink\powercinema\powercinema.exe | "{7DDDD454-04C6-4F67-85B2-D343427669CE}" = protocol=17 | dir=in | app=c:\program files (x86)\cyberlink\tv enhance\tveservice.exe | "{8088C1DB-A913-4E0D-BC7C-125C0CC42CCD}" = protocol=6 | dir=in | app=c:\program files (x86)\cyberlink\tv enhance\tvenhance.exe | "{93E63598-F808-4749-AB07-2CE368D9D69A}" = protocol=6 | dir=in | app=c:\program files (x86)\searchqu toolbar\datamngr\toolbar\dtuser.exe | "{99E97E2B-E5F9-47F4-A606-066D9826B61D}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{9CC7BBBF-5024-4F90-AADF-573176F5F13E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{A13D4FF8-06AF-4F72-B7CA-9D12E43710F5}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{AE38B9B9-B429-4A89-BA63-8B3CF79837E7}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | "{BE331B75-F27E-4D91-9F59-ADB8221CD9C9}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\acs\aolacsd.exe | "{C1C91BEB-AE85-4639-BF27-A3A082639A8F}" = dir=in | app=c:\program files (x86)\cyberlink\powercinema movie\powercinemamovie.exe | "{C48B0D7C-857B-4504-A906-BC2A08E768BE}" = dir=in | app=c:\program files (x86)\cyberlink\powercinema\kernel\dmp\clbrowserengine.exe | "{C58D7FF1-1B1B-46D4-8985-2C8A99FBBDF1}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{C8ED57FF-68BB-404E-830F-00CB4E1D3252}" = protocol=17 | dir=in | app=c:\program files (x86)\research in motion\blackberry desktop\rim.desktop.exe | "{D0042296-D52B-45CD-B5AA-355D30D4C899}" = protocol=6 | dir=in | app=c:\program files (x86)\cyberlink\tv enhance\tveservice.exe | "{D028D6EB-A924-412B-AE24-E4331092BE79}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{D22455A6-A7C2-4768-AA8E-5D4C3710826C}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe | "{D359B29F-0277-4290-8F38-FA460CA2EDED}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\topspeed\3.0\aoltpsd3.exe | "{DA42C984-7802-450B-96CB-001FAE6ABABD}" = protocol=6 | dir=out | app=system | "{DAEA50EE-60CC-431F-9A8D-F7DC33C3C0A8}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{DCA880D8-89B0-4C32-87CB-8481E8ADF651}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{E2344A0B-348B-4D89-86DE-E429EFB07BE6}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe | "{E2445E15-1E55-4C0D-AEC2-F3EF1B629E61}" = protocol=6 | dir=in | app=c:\program files (x86)\cyberlink\tv enhance\tveservice.exe | "{E3C84BEE-0F47-42C2-B61C-630AE8DC5BFA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{EA345036-452F-4592-9CE3-923E4DCBBA44}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{EBCFE805-EF91-4CF6-A6BB-09E2268E6553}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\1301732618\ee\aolsoftware.exe | "{F12227AF-D1BD-45E7-8768-5E6208C1460D}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{F23D4C96-2FEC-4829-81F7-C3CE46286742}" = protocol=6 | dir=in | app=c:\program files (x86)\research in motion\blackberry desktop\rim.desktop.exe | "{FEFE09EB-293B-4C49-A865-108A56208E45}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\acs\aoldial.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector "{02A5BD31-16AC-45DF-BE9F-A3167BC4AFB2}" = Windows Live Family Safety "{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64) "{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety "{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources "{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}" = Apple Mobile Device Support "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources "{8B485965-8EFE-464A-842F-CF8F18C3DFD7}" = iCloud "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 "{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64 "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "CCleaner" = CCleaner "HDMI" = Intel(R) Graphics Media Accelerator Driver "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "{047B9A6A-21E7-45CF-8825-0A061EEF9B23}" = SweetIM Toolbar for Internet Explorer 4.3 "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0D5BBB2B-F044-46C3-877B-6A6BE1E08D19}" = SweetIM for Messenger 3.6 "{0EDBEB2B-7C8D-42E6-8312-0F84394A3223}" = Windows Media Center Add-in for Silverlight "{1111706F-666A-4037-7777-210328764D10}" = JavaFX 2.1.0 "{117E3AE2-10D1-41C1-9FA6-F4C382F767A8}_is1" = Packard Bell GameZone Console "{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = CyberLink PowerCinema "{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron Flash Media Controller Driver "{26A24AE4-039D-4CA4-87B4-2F83216026FF}" = Java(TM) 6 Update 30 "{26A24AE4-039D-4CA4-87B4-2F83217004FF}" = Java(TM) 7 Update 4 "{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections "{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger "{2FDD9D12-46C9-4156-A4A0-55297B9498CA}" = Tiger Woods PGA TOUR 2005 "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}" = Microsoft XNA Framework Redistributable 3.0 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion "{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3 "{5511C07D-A83C-45AD-92B6-42DF99729A3C}" = Adobe Photoshop Elements 7.0 "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack "{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}_is1" = AppGraffiti "{70CC0095-AA68-45BE-AE98-D8170182E9EB}" = PowerCinema Movie "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{75880CD4-9436-4EDD-B7E7-400EBFD60B2C}" = TouchSettings "{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}" = Bing Bar "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core "{7F811A54-5A09-4579-90E1-C93498E230D9}" = Packard Bell Recovery Management "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110209593}" = Chicken Invaders 2 "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110551697}" = Granny In Paradise "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11120457}" = Tumble Bees To Go "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111307457}" = Galapago "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112662477}" = Merriam Websters Spell Jam "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11273477}" = Amazonia "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}" = Alice Greenfingers "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113786380}" = Heroes of Hellas "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113832110}" = Dream Day First Home "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115053100}" = Dairy Dash "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-115208410}" = First Class Flurry "{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11531173}" = Farm Frenzy 2 "{83AA2913-C123-4146-85BD-AD8F93971D39}" = BabylonObjectInstaller "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8FF90DB8-6DED-44A3-B182-244FEC09012F}" = Microsoft Touch Pack for Windows 7 "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system "{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003 "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D318C86-AF4C-409F-A6AC-7183FF4CF424}" = Internet TV for Windows Media Center "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AA027AE9-DD20-4677-AA72-D760A358320B}" = Microsoft VC9 runtime libraries "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3) "{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars "{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}" = Norton Online Backup "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail "{CB6075D9-F912-40AE-BEA6-E590DA24F16B}" = Adobe Photoshop Elements 7.0 "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E0B19DF7-B1C7-4937-82C4-0E4B1E346965}" = eBay Worldwide "{E4C891D6-6844-41B8-86E8-633CACCC644F}" = CyberLink TV Enhance "{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger "{EE171732-BEB4-4576-887D-CB62727F01CA}" = Packard Bell Updater "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin "Adobe Photoshop Elements 7" = Adobe Photoshop Elements 7.0 "alotToolbar" = ALOT Toolbar "AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove) "AVG Secure Search" = AVG Security Toolbar "Babylon" = Babylon "BabylonToolbar" = Babylon toolbar on IE "Identity Card" = Identity Card "iLivid" = iLivid "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam "InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = CyberLink PowerCinema "Metaboli" = Metaboli "NIS" = Norton Internet Security "Packard Bell InfoCentre" = Packard Bell InfoCentre "Packard Bell Registration" = Packard Bell Registration "Packard Bell Screensaver" = Packard Bell ScreenSaver "Packard Bell Software Suite SE" = Packard Bell Software Suite SE "Packard Bell Welcome Center" = Welcome Center "PowerISO" = PowerISO "Searchqu Toolbar" = Searchqu Toolbar "uTorrent" = µTorrent "uTorrentControl2 Toolbar" = uTorrentControl2 Toolbar "vfd-ob" = VideoFileDownload "WinLiveSuite" = Windows Live Essentials ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Google Chrome" = Google Chrome "UnityWebPlayer" = Unity Web Player ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 16/07/2012 07:56:38 | Computer Name = harry-PC | Source = SideBySide | ID = 16842785 Description = Activation context generation failed for "c:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksdb.exe". Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error - 16/07/2012 07:56:39 | Computer Name = harry-PC | Source = SideBySide | ID = 16842785 Description = Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\wksss.exe". Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error - 16/07/2012 07:56:39 | Computer Name = harry-PC | Source = SideBySide | ID = 16842785 Description = Activation context generation failed for "c:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe". Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found. Please use sxstrace.exe for detailed diagnosis. Error - 16/07/2012 11:03:04 | Computer Name = harry-PC | Source = Application Hang | ID = 1002 Description = The program TouchMusic.exe version 1.0.3003.9351 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 670 Start Time: 01cd6363b14df38d Termination Time: 30 Application Path: C:\Program Files (x86)\Packard Bell\Packard Bell Touch Suite\TouchMusic.exe Report Id: 49180112-cf57-11e1-8343-00038a000015 Error - 16/07/2012 11:07:11 | Computer Name = harry-PC | Source = Application Error | ID = 1000 Description = Faulting application name: explorer.exe, version: 6.1.7601.17567, time stamp: 0x4d6727a7 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x69d96c6a Faulting process id: 0x29c Faulting application start time: 0x01cd6364abbab4c3 Faulting application path: C:\Windows\SysWOW64\explorer.exe Faulting module path: unknown Report Id: eaf5c768-cf57-11e1-8343-00038a000015 Error - 16/07/2012 12:46:39 | Computer Name = harry-PC | Source = Application Hang | ID = 1002 Description = The program TouchMusic.exe version 1.0.3003.9351 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 920 Start Time: 01cd63724f11dd06 Termination Time: 46 Application Path: C:\Program Files (x86)\Packard Bell\Packard Bell Touch Suite\TouchMusic.exe Report Id: c05b0bf3-cf65-11e1-8273-00038a000015 Error - 16/07/2012 12:47:21 | Computer Name = harry-PC | Source = Application Hang | ID = 1002 Description = The program TouchPhotoShow.exe version 1.0.3003.9351 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 928 Start Time: 01cd63724f143e67 Termination Time: 46 Application Path: C:\Program Files (x86)\Packard Bell\Packard Bell Touch Suite\TouchPhotoShow.exe Report Id: c01f898d-cf65-11e1-8273-00038a000015 Error - 16/07/2012 13:23:21 | Computer Name = harry-PC | Source = Office Software Protection Platform Service | ID = 1017 Description = Error - 16/07/2012 13:23:29 | Computer Name = harry-PC | Source = Office Software Protection Platform Service | ID = 1017 Description = Error - 16/07/2012 13:23:29 | Computer Name = harry-PC | Source = MsiInstaller | ID = 10005 Description = [ Media Center Events ] Error - 23/11/2011 08:52:11 | Computer Name = harry-PC | Source = MCUpdate | ID = 0 Description = 12:52:03 - Error connecting to the internet. 12:52:03 - Unable to contact server.. Error - 24/11/2011 08:21:06 | Computer Name = harry-PC | Source = MCUpdate | ID = 0 Description = 12:21:05 - Error connecting to the internet. 12:21:06 - Unable to contact server.. Error - 24/11/2011 08:21:43 | Computer Name = harry-PC | Source = MCUpdate | ID = 0 Description = 12:21:35 - Error connecting to the internet. 12:21:35 - Unable to contact server.. Error - 25/11/2011 08:43:28 | Computer Name = harry-PC | Source = MCUpdate | ID = 0 Description = 12:43:19 - Error connecting to the internet. 12:43:19 - Unable to contact server.. Error - 16/02/2012 08:34:12 | Computer Name = harry-PC | Source = MCUpdate | ID = 0 Description = 12:34:12 - Error connecting to the internet. 12:34:12 - Unable to contact server.. Error - 16/02/2012 08:34:37 | Computer Name = harry-PC | Source = MCUpdate | ID = 0 Description = 12:34:17 - Error connecting to the internet. 12:34:17 - Unable to contact server.. Error - 16/02/2012 09:34:42 | Computer Name = harry-PC | Source = MCUpdate | ID = 0 Description = 13:34:42 - Error connecting to the internet. 13:34:42 - Unable to contact server.. Error - 16/02/2012 09:34:56 | Computer Name = harry-PC | Source = MCUpdate | ID = 0 Description = 13:34:47 - Error connecting to the internet. 13:34:47 - Unable to contact server.. Error - 30/05/2012 08:23:07 | Computer Name = harry-PC | Source = MCUpdate | ID = 0 Description = 13:23:07 - Error connecting to the internet. 13:23:07 - Unable to contact server.. Error - 30/05/2012 08:23:35 | Computer Name = harry-PC | Source = MCUpdate | ID = 0 Description = 13:23:12 - Error connecting to the internet. 13:23:12 - Unable to contact server.. [ System Events ] Error - 11/07/2012 22:26:31 | Computer Name = harry-PC | Source = Service Control Manager | ID = 7000 Description = The Oberon Media Game Console service service failed to start due to the following error: %%1053 Error - 13/07/2012 08:31:20 | Computer Name = harry-PC | Source = EventLog | ID = 6008 Description = The previous system shutdown at 09:06:46 on ?13/?07/?2012 was unexpected. Error - 13/07/2012 08:31:59 | Computer Name = harry-PC | Source = Service Control Manager | ID = 7009 Description = A timeout was reached (30000 milliseconds) while waiting for the Oberon Media Game Console service service to connect. Error - 13/07/2012 08:31:59 | Computer Name = harry-PC | Source = Service Control Manager | ID = 7000 Description = The Oberon Media Game Console service service failed to start due to the following error: %%1053 Error - 14/07/2012 09:54:56 | Computer Name = harry-PC | Source = DCOM | ID = 10010 Description = Error - 22/07/2012 11:25:25 | Computer Name = harry-PC | Source = EventLog | ID = 6008 Description = The previous system shutdown at 16:24:08 on ?22/?07/?2012 was unexpected. Error - 22/07/2012 11:26:50 | Computer Name = harry-PC | Source = Service Control Manager | ID = 7022 Description = The WLAN AutoConfig service hung on starting. Error - 22/07/2012 11:28:59 | Computer Name = harry-PC | Source = EventLog | ID = 6008 Description = The previous system shutdown at 16:27:26 on ?22/?07/?2012 was unexpected. Error - 22/07/2012 12:05:31 | Computer Name = harry-PC | Source = Service Control Manager | ID = 7034 Description = The Microsoft Software Shadow Copy Provider service terminated unexpectedly. It has done this 1 time(s). Error - 22/07/2012 12:05:59 | Computer Name = harry-PC | Source = DCOM | ID = 10010 Description = < End of report > |
02-Aug-2012, 04:46 PM
#8 | |||||||
| OK, do the following, see if we can work our way through all the dross that is running on your system: Step 1 Re-Run
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start > All Programs > Accessories > Notepad), click File > Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post. Step 2 Alernative D/L mirror Alternative D/L mirror Double Click mbam-setup.exe to install the application.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Post those two logs, tell me if there has been any improvement, also what issues remain. Kevin |
02-Aug-2012, 05:48 PM
#9 | |||||||
| Ok i have followed instructions and the speed of the computer has increased immensely. However, on start up just before the desktop loads the screen stays black for perhaps 30 seconds then a message comes up reading 'The Publisher Could Not Be Verified ; Are You Sure You Want to Run The Software? ; Name: c:\users\harry\desktop\otl.exe' I click on run and then the desktop loads maybe 10 seconds later. Also once the desktop loads i doubled clicked on chrome and it wouldnt let chrome connect to the net it was saying a message about firewall settings however after about 20 seconds it was fine. here at the logs that came back... All processes killed ========== OTL ========== Process datamngrUI.exe killed successfully! No active process named ilivid.exe was found! HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{687578b9-7132-4a7a-80e4-30ee31099e03} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{687578b9-7132-4a7a-80e4-30ee31099e03}\ deleted successfully. C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll moved successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar| /E : value set successfully! Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{687578b9-7132-4a7a-80e4-30ee31099e03} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{687578b9-7132-4a7a-80e4-30ee31099e03}\ not found. File C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{D3D233D5-9F6D-436C-B6C7-E63F77503B30} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}\ not found. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{91607fa7-3c2f-4f90-93e3-d5337a6b0ac2}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C04B7D22-5AEC-4561-8F49-27F6269208F6}\ not found. Prefs.js: "Search the web (Babylon)" removed from browser.search.defaultenginename Prefs.js: "Search Results" removed from browser.search.order.1 Prefs.js: "Search the web (Babylon)" removed from browser.search.selectedEngine Prefs.js: "http://www.searchnu.com/406" removed from browser.startup.homepage Prefs.js: "http://dts.search-results.com/sr?src=ffb&appid=390&systemid=406&sr=0&q=" removed from keyword.URL Prefs.js: "http://search.babylon.com/?AF=100581&babsrc=adbartrp&mntrId=e81350900000000000000017c4ddd1cf&q=" removed from sweetim.toolbar.previous.keyword.URL 64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully. C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully. Folder C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\ex tensions\{687578b9-7132-4a7a-80e4-30ee31099e03}\ not found. Folder C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\ex tensions\ffxtlbr@babylon.com\ not found. File C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\se archplugins\iBryte_playbryte.xml not found. File C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\se archplugins\Search_Results.xml not found. File C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\se archplugins\sweetim.xml not found. C:\Program Files (x86)\Mozilla Firefox\extensions\adapter@babylontc.com\chrome\skin folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\adapter@babylontc.com\chrome\content folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\adapter@babylontc.com\chrome folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\adapter@babylontc.com folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\ocr@babylon.com\chrome\content folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\ocr@babylon.com\chrome folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\ocr@babylon.com folder moved successfully. C:\PROGRAM FILES (X86)\SEARCHQU TOOLBAR\DATAMNGR\FIREFOXEXTENSION\content folder moved successfully. C:\PROGRAM FILES (X86)\SEARCHQU TOOLBAR\DATAMNGR\FIREFOXEXTENSION\components folder moved successfully. C:\PROGRAM FILES (X86)\SEARCHQU TOOLBAR\DATAMNGR\FIREFOXEXTENSION folder moved successfully. C:\PROGRAMDATA\AVG SECURE SEARCH\11.1.0.12\modules\skin folder moved successfully. C:\PROGRAMDATA\AVG SECURE SEARCH\11.1.0.12\modules folder moved successfully. C:\PROGRAMDATA\AVG SECURE SEARCH\11.1.0.12\locale\en-US folder moved successfully. C:\PROGRAMDATA\AVG SECURE SEARCH\11.1.0.12\locale folder moved successfully. C:\PROGRAMDATA\AVG SECURE SEARCH\11.1.0.12\components folder moved successfully. C:\PROGRAMDATA\AVG SECURE SEARCH\11.1.0.12\chrome folder moved successfully. C:\PROGRAMDATA\AVG SECURE SEARCH\11.1.0.12 folder moved successfully. C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml moved successfully. C:\Program Files (x86)\Mozilla Firefox\searchplugins\Search_Results.xml moved successfully. Use Chrome's Settings page to change the HomePage. Use Chrome's Settings page to remove the default_search_provider items. Use Chrome's Settings page to remove the default_search_provider items. Use Chrome's Settings page to change the HomePage. File C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.4_0\BabylonChrom ePI.dll not found. C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.6_0 folder moved successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{9D717F81-9148-4f12-8568-69135F087DB0}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9D717F81-9148-4f12-8568-69135F087DB0}\ deleted successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\x64\BrowserConnection.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}\ deleted successfully. C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{687578b9-7132-4a7a-80e4-30ee31099e03}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{687578b9-7132-4a7a-80e4-30ee31099e03}\ not found. File C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{68DD98BF-9DE8-418C-89F0-E37AC61CC2D9}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{68DD98BF-9DE8-418C-89F0-E37AC61CC2D9}\ deleted successfully. C:\Program Files (x86)\OApps\bho_project.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ deleted successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}\ deleted successfully. C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{9D717F81-9148-4f12-8568-69135F087DB0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9D717F81-9148-4f12-8568-69135F087DB0}\ deleted successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\BrowserConnection.dll moved successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5AA2BA46-9913-4dc7-9620-69AB0FA17AE7}\ not found. C:\Program Files (x86)\alot\bin\alot.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{687578b9-7132-4a7a-80e4-30ee31099e03} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{687578b9-7132-4a7a-80e4-30ee31099e03}\ not found. File C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8dcb7100-df86-4384-8842-8fa844297b3f}\ deleted successfully. C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{98889811-442D-49dd-99D7-DC866BE87DBC} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}\ deleted successfully. C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{99079a25-328f-4bd4-be04-00955acaa0a7} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}\ not found. File C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{b278d9f8-0fa9-465e-9938-0c392605d8e3} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b278d9f8-0fa9-465e-9938-0c392605d8e3}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{687578B9-7132-4A7A-80E4-30EE31099E03} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{687578B9-7132-4A7A-80E4-30EE31099E03}\ not found. File C:\Program Files (x86)\uTorrentControl2\prxtbuTo0.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Babylon Client deleted successfully. C:\Program Files (x86)\Babylon\Babylon-Pro\Babylon.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DATAMNGR deleted successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\datamngrUI.exe moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\TouchMemo deleted successfully. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\E&xport to Microsoft Excel\ deleted successfully. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Se&nd to OneNote\ deleted successfully. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Translate this web page with Babylon\ deleted successfully. File C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll not found. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Translate with Babylon\ deleted successfully. File C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll not found. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\E&xport to Microsoft Excel\ not found. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Se&nd to OneNote\ not found. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Translate this web page with Babylon\ not found. File C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll not found. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Translate with Babylon\ not found. File C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478}\ not found. File C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478}\ not found. File C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\vizzed.com\www\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully. File Protocol\Handler\livecall - No CLSID value found not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-itss\ deleted successfully. File Protocol\Handler\ms-itss - No CLSID value found not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully. File Protocol\Handler\msnim - No CLSID value found not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype4com\ deleted successfully. File Protocol\Handler\skype4com - No CLSID value found not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype-ie-addon-data\ deleted successfully. File Protocol\Handler\skype-ie-addon-data - No CLSID value found not found. 64bit-Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\symres\ scheduled to be deleted on reboot. File Protocol\Handler\symres - No CLSID value found not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol\ deleted successfully. File Protocol\Handler\viprotocol - No CLSID value found not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully. File Protocol\Handler\wlmailhtml - No CLSID value found not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully. File Protocol\Handler\wlpg - No CLSID value found not found. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\SEARCH~1\Datamngr\x64\d atamngr.dll deleted successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\x64\datamngr.dll moved successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\SEARCH~1\Datamngr\x64\I EBHO.dll deleted successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\x64\IEBHO.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\SEARCH~1\Datamngr\datam ngr.dll deleted successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\datamngr.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\SEARCH~1\Datamngr\IEBHO .dll deleted successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\IEBHO.dll moved successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceOb jectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountP oints2\{5f9ca6a4-b62d-11e0-9e1c-00038a000015}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5f9ca6a4-b62d-11e0-9e1c-00038a000015}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountP oints2\{5f9ca6a4-b62d-11e0-9e1c-00038a000015}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5f9ca6a4-b62d-11e0-9e1c-00038a000015}\ not found. File F:\.\Setup.exe AUTORUN=1 not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountP oints2\F\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountP oints2\F\ not found. File F:\.\Setup.exe AUTORUN=1 not found. ADS C:\ProgramData\Temp:0B9176C0 deleted successfully. ADS C:\ProgramData\Temp:798A3728 deleted successfully. ADS C:\ProgramData\Temp:CDFF58FE deleted successfully. ADS C:\ProgramData\Temp:ABE89FFE deleted successfully. ADS C:\ProgramData\Temp:51574724 deleted successfully. ADS C:\ProgramData\Temp:4D066AD2 deleted successfully. ADS C:\ProgramData\Temp:444C53BA deleted successfully. ========== FILES ========== < ipconfig /flushdns /c > Windows IP Configuration Successfully flushed the DNS Resolver Cache. C:\Users\harry\Desktop\cmd.bat deleted successfully. C:\Users\harry\Desktop\cmd.txt deleted successfully. C:\Program Files (x86)\iLivid\VLC\skins\fonts folder moved successfully. C:\Program Files (x86)\iLivid\VLC\skins folder moved successfully. C:\Program Files (x86)\iLivid\VLC\sdk\lib\pkgconfig folder moved successfully. C:\Program Files (x86)\iLivid\VLC\sdk\lib folder moved successfully. C:\Program Files (x86)\iLivid\VLC\sdk\include\vlc\plugins folder moved successfully. C:\Program Files (x86)\iLivid\VLC\sdk\include\vlc folder moved successfully. C:\Program Files (x86)\iLivid\VLC\sdk\include folder moved successfully. C:\Program Files (x86)\iLivid\VLC\sdk folder moved successfully. C:\Program Files (x86)\iLivid\VLC\plugins folder moved successfully. C:\Program Files (x86)\iLivid\VLC\osdmenu\default\volume folder moved successfully. C:\Program Files (x86)\iLivid\VLC\osdmenu\default\selection folder moved successfully. C:\Program Files (x86)\iLivid\VLC\osdmenu\default\selected folder moved successfully. C:\Program Files (x86)\iLivid\VLC\osdmenu\default folder moved successfully. C:\Program Files (x86)\iLivid\VLC\osdmenu folder moved successfully. C:\Program Files (x86)\iLivid\VLC\NSIS folder moved successfully. C:\Program Files (x86)\iLivid\VLC\mozilla folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\sd folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\playlist folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\modules folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\meta\reader folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\meta\fetcher folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\meta\art folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\meta folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\intf\modules folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\intf folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\http\requests folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\http\js folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\http\images folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\http\dialogs folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\http folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua\extensions folder moved successfully. C:\Program Files (x86)\iLivid\VLC\lua folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\zu\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\zu folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\zh_TW\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\zh_TW folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\zh_CN\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\zh_CN folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\wa\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\wa folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\vi\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\vi folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\uk\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\uk folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\tr\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\tr folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\tl\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\tl folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\th\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\th folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\tet\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\tet folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ta\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ta folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\sv\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\sv folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\sr\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\sr folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\sq\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\sq folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\sl\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\sl folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\sk\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\sk folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\si\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\si folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ru\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ru folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ro\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ro folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\qt4 folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\pt_PT\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\pt_PT folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\pt_BR\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\pt_BR folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ps\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ps folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\pl\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\pl folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\pa\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\pa folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\oc\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\oc folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\nn\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\nn folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\nl\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\nl folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ne\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ne folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\nb\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\nb folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\my\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\my folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ms\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ms folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\mn\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\mn folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ml\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ml folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\mk\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\mk folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\lv\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\lv folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\lt\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\lt folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\lg\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\lg folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ko\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ko folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\km\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\km folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\kk\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\kk folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ka\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ka folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ja\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ja folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\it\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\it folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\is\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\is folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\id\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\id folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\hy\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\hy folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\hu\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\hu folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\hr\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\hr folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\hi\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\hi folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\he\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\he folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\gl\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\gl folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ga\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ga folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\fur\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\fur folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\fr\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\fr folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\fi\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\fi folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ff\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ff folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\fa\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\fa folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\eu\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\eu folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\et\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\et folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\es\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\es folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\en_GB\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\en_GB folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\el\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\el folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\de\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\de folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\da\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\da folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\cs\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\cs folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\co\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\co folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ckb\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ckb folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\cgg\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\cgg folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ca\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ca folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\br\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\br folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\bn\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\bn folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\bg\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\bg folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\be\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\be folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ast\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ast folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ar\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ar folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\am\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\am folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\af\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\af folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ach\LC_MESSAGES folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale\ach folder moved successfully. C:\Program Files (x86)\iLivid\VLC\locale folder moved successfully. C:\Program Files (x86)\iLivid\VLC\languages folder moved successfully. C:\Program Files (x86)\iLivid\VLC\http\requests folder moved successfully. C:\Program Files (x86)\iLivid\VLC\http\js folder moved successfully. C:\Program Files (x86)\iLivid\VLC\http\images folder moved successfully. C:\Program Files (x86)\iLivid\VLC\http\dialogs folder moved successfully. C:\Program Files (x86)\iLivid\VLC\http folder moved successfully. C:\Program Files (x86)\iLivid\VLC\activex folder moved successfully. C:\Program Files (x86)\iLivid\VLC folder moved successfully. C:\Program Files (x86)\iLivid\imageformats folder moved successfully. C:\Program Files (x86)\iLivid\fantastic folder moved successfully. C:\Program Files (x86)\iLivid folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\x64 folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\components folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\searchbar folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\options folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels\images folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\panels folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton\icons folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\weatherbutton folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\uwa folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\images folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio\css folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\radio folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\images folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\scripts folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\images folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default\css folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\default folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels\css folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib\panels folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\lib folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\content\widgets folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\content\modules folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\content\lib folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\content\data\search folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\content\data folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome\content folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar\chrome folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr\ToolBar folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar\Datamngr folder moved successfully. C:\Program Files (x86)\Searchqu Toolbar folder moved successfully. C:\Users\harry\AppData\Roaming\.# folder moved successfully. C:\Users\harry\AppData\Roaming\Babylon\updates folder moved successfully. C:\Users\harry\AppData\Roaming\Babylon\Content\icons folder moved successfully. C:\Users\harry\AppData\Roaming\Babylon\Content folder moved successfully. C:\Users\harry\AppData\Roaming\Babylon folder moved successfully. C:\Users\harry\AppData\Roaming\BabylonToolbar\Shared folder moved successfully. C:\Users\harry\AppData\Roaming\BabylonToolbar\IE folder moved successfully. C:\Users\harry\AppData\Roaming\BabylonToolbar\FF folder moved successfully. C:\Users\harry\AppData\Roaming\BabylonToolbar\CR folder moved successfully. C:\Users\harry\AppData\Roaming\BabylonToolbar folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: harry ->Temp folder emptied: 7667912 bytes ->Temporary Internet Files folder emptied: 46951162 bytes ->Java cache emptied: 275570 bytes ->FireFox cache emptied: 55781043 bytes ->Google Chrome cache emptied: 307990023 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 3142 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 392291 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows \Temporary Internet Files folder emptied: 67697 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 400.00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully Restore point Set: OTL Restore Point OTL by OldTimer - Version 3.2.55.0 log created on 08022012_220524 Files\Folders moved on Reboot... C:\Users\harry\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder C:\Windows\temp\JETEC9F.tmp not found! PendingFileRenameOperations files... File C:\Users\harry\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found! File C:\Windows\temp\JETEC9F.tmp not found! Registry entries deleted on Reboot... 64bit-Registry delete failed. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\symres\ scheduled to be deleted on reboot. Malwarebytes Anti-Malware (Trial) 1.62.0.1300 www.malwarebytes.org Database version: v2012.08.02.09 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 harry :: HARRY-PC [administrator] Protection: Enabled 02/08/2012 22:19:40 mbam-log-2012-08-02 (22-19-40).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 195010 Time elapsed: 3 minute(s), 37 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 3 HKCR\bho_project.bho_object (Trojan.BHO) -> Quarantined and deleted successfully. HKCR\bho_project.bho_object.1 (Trojan.BHO) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\kincjchfokkeneeofpeefomkikfkiedl (PUP.FCTPlugin) -> Quarantined and deleted successfully. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) |
02-Aug-2012, 06:18 PM
#10 | |||||||
| i have removed the shortcut for otl from the desktop and that has resolved the message on startup and also i believe the problem with starting up chrome was that the homepage was not like by malwarebytes so i have set google.com as my homepage and that now works fine. It all seems to be running ok now. Unless you can see anything in the logs? |
02-Aug-2012, 06:19 PM
#11 | |||||||
| Yep there was a lot of dross running on your system, i`m sure we`ve made a big impact and removed most if not all. OK run this please, lets see what remains; Double click on OTL to run it again. Make sure all other windows are closed and to let it run uninterrupted. When the main interface opens change the Standard Registry box to All Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long. When the scan completes, it will open one notepad window. OTL.Txt This is saved in the same location as OTL. Please copy (Edit > Select All, Edit > Copy) the contents of this file and post it with your next reply. Let me see that log, also are you still having problems with Chrome? Kevin... ![]() |
03-Aug-2012, 02:31 AM
#12 | |||||||
| There is definitely a massive massive improvement. Chrome is working fine so is everything else. I'm not 100% its is back to perfect though. It still seems a tiny bit slower than normal when surfing. Or am I being paranoid ? Anyway here you go...OTL logfile created on: 03/08/2012 07:08:43 - Run 2 OTL by OldTimer - Version 3.2.55.0 Folder = C:\Users\harry\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy 3.96 Gb Total Physical Memory | 1.48 Gb Available Physical Memory | 37.37% Memory free 7.93 Gb Paging File | 5.50 Gb Available in Paging File | 69.38% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 292.04 Gb Total Space | 205.01 Gb Free Space | 70.20% Space Free | Partition Type: NTFS Drive D: | 292.04 Gb Total Space | 291.94 Gb Free Space | 99.97% Space Free | Partition Type: NTFS Computer Name: HARRY-PC | User Name: harry | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012/08/03 07:07:57 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Users\harry\Downloads\OTL (4).com PRC - [2012/07/16 20:50:55 | 000,935,008 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe PRC - [2012/07/16 20:50:53 | 001,107,552 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe PRC - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2012/07/03 13:46:44 | 000,462,920 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe PRC - [2012/04/04 06:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2011/09/22 01:35:57 | 000,117,648 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe PRC - [2011/02/25 10:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE PRC - [2010/03/08 08:27:49 | 000,041,800 | ---- | M] (AOL Inc.) -- C:\Program Files (x86)\Common Files\AOL\1301732618\ee\aolsoftware.exe PRC - [2009/10/23 01:21:14 | 000,151,368 | ---- | M] (Acer Corp.) -- C:\Program Files (x86)\TouchSettings\TouchPortalOBR.exe PRC - [2009/09/14 22:35:06 | 000,167,008 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe PRC - [2009/08/28 10:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe PRC - [2009/07/04 03:47:12 | 000,240,160 | ---- | M] (Acer) -- C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe PRC - [2009/06/24 16:09:56 | 000,386,400 | ---- | M] () -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe PRC - [2009/06/24 16:09:56 | 000,202,080 | ---- | M] () -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe PRC - [2009/06/24 16:09:46 | 000,230,632 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe PRC - [2008/12/08 15:16:56 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) -- c:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe ========== Modules (No Company Name) ========== MOD - [2012/07/31 06:36:14 | 000,442,392 | ---- | M] () -- C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\ppgoogl enaclpluginchrome.dll MOD - [2012/07/31 06:36:13 | 012,235,288 | ---- | M] () -- C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\PepperF lash\pepflashplayer.dll MOD - [2012/07/31 06:36:12 | 003,997,720 | ---- | M] () -- C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\pdf.dll MOD - [2012/07/31 06:34:57 | 000,526,872 | ---- | M] () -- C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\libgles v2.dll MOD - [2012/07/31 06:34:55 | 000,104,984 | ---- | M] () -- C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\libegl. dll MOD - [2012/07/31 06:34:45 | 000,144,424 | ---- | M] () -- C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\avutil-51.dll MOD - [2012/07/31 06:34:43 | 000,266,792 | ---- | M] () -- C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\avforma t-54.dll MOD - [2012/07/31 06:34:42 | 002,480,680 | ---- | M] () -- C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\avcodec-54.dll MOD - [2012/07/16 20:50:56 | 000,132,704 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.2.0\SiteSafety.dll MOD - [2012/07/16 20:50:53 | 001,107,552 | ---- | M] () -- C:\Program Files (x86)\AVG Secure Search\vprot.exe MOD - [2009/06/24 16:09:58 | 000,308,584 | ---- | M] () -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLCapEngine.dll MOD - [2009/06/24 16:09:58 | 000,132,448 | ---- | M] () -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLSchMgr.dll MOD - [2009/06/24 16:09:58 | 000,038,120 | ---- | M] () -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLCapSvcps.dll MOD - [2009/06/24 16:09:56 | 000,345,320 | ---- | M] () -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLTinyDB.dll ========== Win32 Services (SafeList) ========== SRV:64bit: - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc) SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV:64bit: - [2009/07/04 03:47:12 | 000,240,160 | ---- | M] (Acer) [Auto | Running] -- C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe -- (Updater Service) SRV - [2012/08/03 06:39:32 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012/07/16 20:50:55 | 000,935,008 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe -- (vToolbarUpdater11.2.0) SRV - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012/04/04 06:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011/09/22 01:35:57 | 000,117,648 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe -- (Norton Internet Security) SRV - [2011/03/31 00:07:11 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2011/02/28 18:44:14 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE -- (BBSvc) SRV - [2011/02/25 10:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE -- (SeaPort) SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009/08/28 10:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe -- (Greg_Service) SRV - [2009/06/24 16:09:56 | 000,386,400 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe -- (TVECapSvc) SRV - [2009/06/24 16:09:56 | 000,202,080 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe -- (TVESched) SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2008/12/08 15:16:56 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- c:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor7.0) SRV - [2006/10/23 13:50:35 | 000,046,640 | R--- | M] (AOL LLC) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\AOL\acs\AOLacsd.exe -- (AOL ACS) ========== Driver Services (SafeList) ========== DRV:64bit: - [2012/07/03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector) DRV:64bit: - [2012/03/08 18:40:52 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr) DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2012/02/15 11:01:50 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64) DRV:64bit: - [2011/10/11 02:09:51 | 000,561,800 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\cchpx64.sys -- (ccHP) DRV:64bit: - [2011/09/22 01:35:58 | 000,279,160 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\symtdi.sys -- (SYMTDI) DRV:64bit: - [2011/09/22 01:35:58 | 000,120,952 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\symfw.sys -- (SYMFW) DRV:64bit: - [2011/09/22 01:35:58 | 000,056,952 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\symndisv.sys -- (SYMNDISV) DRV:64bit: - [2011/07/25 14:00:07 | 000,116,864 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard) DRV:64bit: - [2011/07/25 14:00:07 | 000,116,224 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbfake.sys -- (hwusbfake) DRV:64bit: - [2011/03/30 23:37:34 | 000,172,592 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent) DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2010/11/20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010/11/20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010/11/20 10:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus) DRV:64bit: - [2010/08/25 19:36:04 | 010,611,552 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx) DRV:64bit: - [2010/07/13 09:57:08 | 000,069,736 | ---- | M] (ITE Tech. Inc. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\itecir.sys -- (itecir) DRV:64bit: - [2010/01/20 22:18:24 | 000,334,384 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\BHDrvx64.sys -- (BHDrvx64) DRV:64bit: - [2009/11/27 08:29:56 | 000,476,720 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\srtsp64.sys -- (SRTSP) DRV:64bit: - [2009/11/27 08:29:56 | 000,402,992 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\SymEFA64.sys -- (SymEFA) DRV:64bit: - [2009/11/27 08:29:56 | 000,032,304 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1008030.006\srtspx64.sys -- (SRTSPX) DRV:64bit: - [2009/11/27 08:29:56 | 000,031,280 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SymIMV.sys -- (SymIM) DRV:64bit: - [2009/08/13 04:21:40 | 000,364,800 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVerPola.sys -- (AVerPola) DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009/07/14 01:10:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rootmdm.sys -- (ROOTMODEM) DRV:64bit: - [2009/07/13 07:31:42 | 000,233,472 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2009/07/09 13:45:42 | 000,140,128 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\jmcr.sys -- (JMCR) DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2009/06/10 21:31:36 | 000,220,288 | ---- | M] (AfaTech ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AF9035BDA.sys -- (AF9035BDA) DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV:64bit: - [2009/01/09 15:02:08 | 000,031,744 | ---- | M] (Research in Motion Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimSerial_AMD64.sys -- (RimVSerPort) DRV:64bit: - [2008/06/16 03:00:00 | 000,055,024 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64) DRV:64bit: - [2006/11/29 23:24:49 | 000,024,064 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wanatw64.sys -- (wanatw) DRV:64bit: - [2006/04/07 16:06:59 | 000,702,976 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x) DRV - [2012/06/14 19:39:24 | 000,509,088 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20120802.001\IDSviA64.sys -- (IDSVia64) DRV - [2012/06/12 03:21:30 | 002,068,600 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20120802.008\ex64.sys -- (NAVEX15) DRV - [2012/06/12 03:21:30 | 000,138,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv) DRV - [2012/06/12 03:21:30 | 000,120,440 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20120802.008\eng64.sys -- (NAVENG) DRV - [2012/05/16 05:16:24 | 000,484,512 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl) DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (All) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.packardbell.com/rdr....7y175y44l10587 IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE:64bit: - HKLM\..\SearchScopes,DefaultScope = IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={ inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.packardbell.com/rdr....7y175y44l10587 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer: source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACPW IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={ inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\..\SearchScopes\{74BD08EB-D440-4d57-AAAC-2159274CF9C7}: "URL" = http://slirsredirect.search.aol.com/redirector/sredir?sredir=3530&query={searchTerms}&invocationType=tb50-ie-aolbbTB50CL-chromesbox-en-uk IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ IE - HKCU\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64} IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer: source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACPW_enGB425 IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={ inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKCU\..\SearchScopes\{74BD08EB-D440-4d57-AAAC-2159274CF9C7}: "URL" = http://slirsredirect.search.aol.com/redirector/sredir?sredir=3530&query={searchTerms}&invocationType=tb50-ie-aolbbTB50CL-chromesbox-en-uk IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={669F9C01-9596-40A7-B6AF-49CA9AAFB861}&mid=bd25346cc18247d0a1c9d14acce4e9e6-b4e8f41bc2ef5df94a3dc5034385d12e1be891b4&lang=en&ds=st011&pr=sa&d=2012-07-16 20:50:57&v=11.1.0.12&sap=dsp&q={searchTerms} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "" FF - prefs.js..browser.search.order.1: "" FF - prefs.js..browser.search.selectedEngine: "" FF - prefs.js..browser.startup.homepage: "" FF - prefs.js..network.proxy.type: 0 FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.2.0\\npsitesafety.dll () FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\harry\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\harry\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\harry\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{7BA52691-1876-45ce-9EE6-54BCB3B04BBC}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\ [2011/10/13 03:29:30 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\11.1.0.12\ [2012/07/19 16:58:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\harry\AppData\Roaming\Mozilla\Extensions [2012/07/24 21:43:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\ex tensions [2012/07/24 21:43:01 | 000,000,000 | ---D | M] (uTorrentControl2 Community Toolbar) -- C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\ex tensions\{687578b9-7132-4a7a-80e4-30ee31099e03} [2012/07/19 16:58:49 | 000,000,000 | ---D | M] (Searchqu Toolbar) -- C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\ex tensions\{99079a25-328f-4bd4-be04-00955acaa0a7} [2012/03/31 08:31:21 | 000,000,000 | ---D | M] (AppGraffiti) -- C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\ex tensions\AppGraffiti@AppGraffiti.com [2012/01/03 19:43:22 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\ex tensions\ffxtlbr@babylon.com [2012/07/16 21:06:10 | 000,000,000 | ---D | M] (VideoFileDownload - Download YouTube Videos) -- C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\ex tensions\plugin@videofiledownload.com [2011/07/23 12:03:40 | 000,002,230 | ---- | M] () -- C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\se archplugins\iBryte_playbryte.xml [2012/07/19 16:58:43 | 000,002,519 | ---- | M] () -- C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\se archplugins\Search_Results.xml [2012/01/03 19:44:37 | 000,003,915 | ---- | M] () -- C:\Users\harry\AppData\Roaming\Mozilla\Firefox\Profiles\vrm48h4l.default\se archplugins\sweetim.xml [2012/08/02 22:05:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions [2011/06/29 21:25:31 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} File not found (No name found) -- C:\PROGRAM FILES (X86)\SEARCHQU TOOLBAR\DATAMNGR\FIREFOXEXTENSION File not found (No name found) -- C:\PROGRAMDATA\AVG SECURE SEARCH\11.1.0.12 [2012/07/16 20:50:52 | 000,003,750 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml ========== Chrome ========== CHR - homepage: http://www.searchnu.com/406 CHR - default_search_provider: Search Results (Enabled) CHR - default_search_provider: search_url = http://dts.search-results.com/sr?src=crb&appid=390&systemid=406&sr=0&q={searchTerms} CHR - default_search_provider: suggest_url = CHR - homepage: http://www.searchnu.com/406 CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\ppGoogl eNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\pdf.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Users\harry\AppData\Local\Google\Chrome\Application\21.0.1180.60\gcswf32 .dll CHR - plugin: Shockwave Flash (Disabled) = C:\Users\harry\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll CHR - plugin: Babylon Chrome Plugin (Enabled) = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.4_0\BabylonChrom ePI.dll CHR - plugin: Skype Toolbars (Enabled) = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.3.0.7550_0\npSky peChromePlugin.dll CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll CHR - plugin: Java(TM) Platform SE 7 U4 (Enabled) = C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll CHR - plugin: Java Deployment Toolkit 7.0.40.255 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll CHR - plugin: Vizzed Retro Game Room Plugin (Enabled) = C:\Program Files (x86)\Vizzed\Vizzed Retro Game Room\NpVizzedRgr.dll CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll CHR - plugin: Unity Player (Enabled) = C:\Users\harry\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll CHR - Extension: AppGraffiti - Free Facebook Layouts = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\angobeimajilfhlcpeiccndaifchnppl\1.0.0.9_0\ CHR - Extension: AT_JennyHolzerV7 = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\fajfiabcfidbbaelfcficghfgheddefo\3_0\ CHR - Extension: Fast save = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffcalihdlalnkhmanhindcdckagnlfce\1.1_0\ CHR - Extension: Planetarium = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\gheikhdfflhlbemfmhcfpeblehemeklp\1.1.1_0\ CHR - Extension: YourNextFilm = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\jadajphjladhhmcjiomkmlihlknbnicc\0.0.0.1_0\ CHR - Extension: InvisibleHand = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\lghjfnfolmcikomdjmoiemllfnlmmoko\3.8.5_0\ CHR - Extension: Skype Extension = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.3.0.7550_0\ CHR - Extension: uTorrentControl2 = C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc\2.3.15.10_0\ O1 HOSTS File: ([2012/08/02 22:06:43 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation) O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\IPSBHO.dll (Symantec Corporation) O2 - BHO: (AppGraffiti) - {6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} - C:\Program Files (x86)\AppGraffiti\AppGraffiti.dll (Omega Partners Ltd) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll () O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation) O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll () O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation) O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4:64bit: - HKLM..\Run: [TouchORB] C:\Program Files (x86)\TouchSettings\TouchPortalOBR.exe (Acer Corp.) O4 - HKLM..\Run: [Adobe ARM] C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [HF_G_Jul] C:\Program Files (x86)\AVG Secure Search\HF_G_Jul.exe () O4 - HKLM..\Run: [HostManager] C:\Program Files (x86)\Common Files\AOL\1301732618\ee\aolsoftware.exe (AOL Inc.) O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe (Symantec Corporation) O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.) O4 - HKLM..\Run: [TVEService] C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe (CyberLink Corp.) O4 - HKLM..\Run: [UCam_Menu] C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe () O4 - HKLM..\Run: [YouCam Mirror Tray icon] C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe (CyberLink Corp.) O4 - HKCU..\Run: [MusicGadget] "C:\Program Files (x86)\Packard Bell\Packard Bell Touch Suite\TouchMusic.exe" File not found O4 - HKCU..\Run: [PhotoGadget] "C:\Program Files (x86)\Packard Bell\Packard Bell Touch Suite\TouchPhotoShow.exe" File not found O4 - HKCU..\Run: [SNSGadget] "C:\Program Files (x86)\Packard Bell\Packard Bell Touch Suite\TouchFriends.exe" File not found O4 - Startup: C:\Users\harry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TalkTalk Diagnostic Reporting Tool.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboa rd\ExceptionFormats: CF_TEXT = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboa rd\ExceptionFormats: CF_BITMAP = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboa rd\ExceptionFormats: CF_OEMTEXT = 7 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboa rd\ExceptionFormats: CF_DIB = 8 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboa rd\ExceptionFormats: CF_PALETTE = 9 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboa rd\ExceptionFormats: CF_UNICODETEXT = 13 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboa rd\ExceptionFormats: CF_DIBV5 = 17 O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation) O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation) O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - C:\Windows\SysNative\nlaapi.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Windows\SysNative\wshbth.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\nlaapi.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\NapiNSP.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\SysWOW64\pnrpnsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\wshbth.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 10.4.1) O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicrosoftoffice.com/...soft/wrc32.ocx (WRC Class) O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_30) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 10.4.1) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8A63913D-417F-4EE8-AEAD-DA34552E29BB}: DhcpNameServer = 192.168.0.1 O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\symres - No CLSID value found O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation) O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation) O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation) O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation) O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation) O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation) O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation) O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files (x86)\Norton Internet Security\Engine\16.8.3.6\CoIEPlg.dll (Symantec Corporation) O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation) O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation) O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation) O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation) O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysNative\mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation) O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\SysWow64\mscoree.dll (Microsoft Corporation) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (systempropertiesperformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (systempropertiesperformance.exe) - C:\Windows\SysWow64\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O29:64bit: - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation) O29 - HKLM SecurityProviders - (credssp.dll) - C:\Windows\SysWow64\credssp.dll (Microsoft Corporation) O30:64bit: - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation) O30 - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation) O30:64bit: - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation) O30:64bit: - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation) O30:64bit: - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation) O30:64bit: - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation) O30:64bit: - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\tspkg.dll (Microsoft Corporation) O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation) O30:64bit: - LSA: Security Packages - (livessp) - C:\Windows\SysNative\livessp.dll (Microsoft Corp.) O30 - LSA: Security Packages - (kerberos) - C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation) O30 - LSA: Security Packages - (msv1_0) - C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation) O30 - LSA: Security Packages - (schannel) - C:\Windows\SysWow64\schannel.dll (Microsoft Corporation) O30 - LSA: Security Packages - (wdigest) - C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation) O30 - LSA: Security Packages - (tspkg) - C:\Windows\SysWow64\tspkg.dll (Microsoft Corporation) O30 - LSA: Security Packages - (pku2u) - C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation) O30 - LSA: Security Packages - (livessp) - C:\Windows\SysWow64\livessp.dll (Microsoft Corp.) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2012/08/02 22:18:05 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Roaming\Malwarebytes [2012/08/02 22:17:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2012/08/02 22:17:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2012/08/02 22:17:50 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2012/08/02 22:17:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2012/08/02 22:05:24 | 000,000,000 | ---D | C] -- C:\_OTL [2012/07/24 21:42:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla [2012/07/22 17:22:35 | 000,000,000 | ---D | C] -- C:\Users\harry\Desktop\tech support [2012/07/19 17:01:14 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\Ilivid Player [2012/07/19 16:58:44 | 000,000,000 | ---D | C] -- C:\ProgramData\boost_interprocess [2012/07/16 21:06:26 | 000,000,000 | ---D | C] -- C:\Users\harry\Documents\MyTorrents [2012/07/16 21:06:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OApps [2012/07/16 21:06:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TorrentSearch [2012/07/16 21:05:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\smartdl [2012/07/16 20:51:13 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\AVG Secure Search [2012/07/16 20:50:56 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Secure Search [2012/07/16 20:50:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AVG Secure Search [2012/07/16 20:50:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG Secure Search [2012/07/16 20:49:49 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files [2012/07/16 19:33:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSECache [2012/07/16 18:28:52 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\CRE [2012/07/16 17:47:31 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{93521D56-D5BA-45DB-9899-217B984F1B05} [2012/07/16 16:32:10 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\MicrosoftStore [2012/07/16 16:29:44 | 000,000,000 | ---D | C] -- C:\Users\harry\Documents\OneNote Notebooks [2012/07/16 12:34:19 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{EA2C0C36-F559-4C00-ABEE-8B9BC80FC53F} [2012/07/15 11:44:20 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{E474B330-5EA8-4835-9507-1F9AEE801165} [2012/07/15 11:44:08 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{50BE36D1-782F-4351-A3E4-93BA51BAB5D6} [2012/07/14 15:15:16 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{6AFF746D-36B1-4467-A0E2-601D82B81C10} [2012/07/14 15:15:05 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{0E1FED34-F893-4966-AB65-D0724E1EB2A0} [2012/07/14 14:50:33 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Roaming\Temp [2012/07/14 14:37:43 | 000,000,000 | ---D | C] -- C:\Users\harry\Desktop\C.V's [2012/07/13 15:34:25 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{0388C4E8-CAB5-4D13-80F4-520BD0D8CF68} [2012/07/13 15:34:13 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{E87E6765-0AE8-4345-A574-85CA9451B362} [2012/07/13 03:33:47 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{9EF70447-BE4E-4BAA-A18D-9D8D3738A371} [2012/07/13 03:33:35 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{438AB6C3-BF21-4AFE-9550-A2910F9C6BE5} [2012/07/12 15:33:08 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{69FC119A-655F-4D87-B942-E27CACD7E5B3} [2012/07/12 03:31:00 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{2D0F57B4-5013-4A0C-AA44-D315CD1EF11E} [2012/07/12 03:30:48 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{0DDFB27F-1C74-493C-BC4A-D7335C1E3950} [2012/07/12 03:02:08 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll [2012/07/12 03:02:08 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll [2012/07/12 03:02:07 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll [2012/07/12 03:02:07 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll [2012/07/12 03:02:05 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2012/07/12 03:02:05 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2012/07/12 03:02:04 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe [2012/07/12 03:02:04 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe [2012/07/12 03:02:02 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl [2012/07/12 03:02:02 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl [2012/07/12 03:02:01 | 002,311,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll [2012/07/12 03:02:01 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll [2012/07/12 03:02:01 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll [2012/07/11 13:10:38 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3r.dll [2012/07/11 13:10:38 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml3r.dll [2012/07/11 13:10:30 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll [2012/07/11 13:10:26 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cdosys.dll [2012/07/11 13:10:25 | 001,133,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdosys.dll [2012/07/08 18:56:05 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{CB38660F-F955-41F7-9DF0-8EAD307D3731} [2012/07/08 18:55:53 | 000,000,000 | ---D | C] -- C:\Users\harry\AppData\Local\{4C6FC563-98AE-4C5E-BBBA-081E1D4D6B29} [2012/07/07 13:12:07 | 000,000,000 | ---D | C] -- C:\Users\harry\Desktop\Ibiza ========== Files - Modified Within 30 Days ========== [2012/08/03 07:02:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012/08/03 06:39:33 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012/08/03 06:39:31 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe [2012/08/03 06:39:31 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2012/08/03 06:35:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1615065723-140565034-61851805-1000UA.job [2012/08/02 23:10:50 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012/08/02 23:10:50 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012/08/02 23:03:15 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012/08/02 23:03:07 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012/08/02 23:03:02 | 3192,987,648 | -HS- | M] () -- C:\hiberfil.sys [2012/08/02 22:35:01 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1615065723-140565034-61851805-1000Core.job [2012/08/02 22:17:52 | 000,001,077 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk [2012/08/02 22:14:00 | 000,726,444 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2012/08/02 22:14:00 | 000,628,414 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2012/08/02 22:14:00 | 000,110,598 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2012/08/02 22:06:43 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts [2012/08/01 21:38:20 | 000,002,457 | ---- | M] () -- C:\Users\harry\Desktop\Google Chrome.lnk [2012/07/31 04:58:03 | 000,000,572 | ---- | M] () -- C:\Users\harry\AppData\Roaming\wklnhst.dat [2012/07/26 16:04:13 | 000,007,597 | ---- | M] () -- C:\Users\harry\AppData\Local\Resmon.ResmonCfg [2012/07/22 16:25:30 | 000,388,632 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2012/07/16 02:03:42 | 000,184,891 | ---- | M] () -- C:\torrent.exe [2012/07/10 10:39:53 | 000,025,088 | ---- | M] () -- C:\Users\harry\Documents\ppi.wps ========== Files Created - No Company Name ========== [2012/08/02 22:17:52 | 000,001,077 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk [2012/07/26 16:04:13 | 000,007,597 | ---- | C] () -- C:\Users\harry\AppData\Local\Resmon.ResmonCfg [2012/07/17 12:57:28 | 000,002,671 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Word Viewer 2003.lnk [2012/07/16 02:03:42 | 000,184,891 | ---- | C] () -- C:\torrent.exe [2012/07/10 10:39:53 | 000,025,088 | ---- | C] () -- C:\Users\harry\Documents\ppi.wps [2011/11/27 18:48:21 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat [2011/11/04 06:00:01 | 000,000,000 | ---- | C] () -- C:\Users\harry\AppData\Local\{62891E8A-8BF0-4290-A839-70717644831D} [2011/10/25 15:59:15 | 000,000,000 | ---- | C] () -- C:\Users\harry\AppData\Local\{2B9BFA8E-E01D-4925-A136-69CEEFCD8A82} [2011/07/06 19:33:09 | 000,017,408 | ---- | C] () -- C:\Users\harry\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011/05/19 22:30:54 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat [2011/04/02 09:16:06 | 000,000,335 | ---- | C] () -- C:\Windows\nsreg.dat [2011/04/01 20:12:31 | 000,000,572 | ---- | C] () -- C:\Users\harry\AppData\Roaming\wklnhst.dat [2010/08/25 19:34:30 | 000,982,240 | ---- | C] () -- C:\Windows\SysWow64\igkrng500.bin [2010/08/25 19:34:30 | 000,439,308 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng500.bin [2010/08/25 19:34:30 | 000,092,356 | ---- | C] () -- C:\Windows\SysWow64\igfcg500m.bin [2010/08/25 18:52:00 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll [2010/08/25 18:52:00 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll [2009/11/27 08:03:20 | 000,131,368 | ---- | C] () -- C:\ProgramData\FullRemove.exe < End of report > |
03-Aug-2012, 03:31 AM
#13 | |||||||
| Hiya Lee, There are still a few entries to remove, also be aware when d/l applications for added extras such as anything to do with Babylon or unwanted Toolbars Have a look through you installed programs - Select > start > type uninstall a program into the search box then hit enter. The installed programs window should open and populate. Haave a look through that list, remove any unwanted toolbars, the only one I would keep is Google, the rest can go. Continue as follows: Step 1 Re-Run
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start > All Programs > Accessories > Notepad), click File > Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post. Step 2 We now need to run an online AV scan, this is very thorough so will take several hours but is very well doing: Run ESET Online Scan
Frequently asked questions available Here Please read them before running the scan. Also be aware this scan can take several hours to complete depending on the size of your system. ESET log can be found here "C:\Program Files\ESET\EsetOnlineScanner\log.txt". Post the two logs, give your system a whirl and see how it responds. Let me know of any remaining issues... Thanks, Kevin.... ![]() |
03-Aug-2012, 11:52 AM
#14 | |||||||
| when i right click on OTL it doesnt give me the option to run as administrator? |
Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.
If you're not already familiar with forums, watch our Welcome Guide to get started.
| Tags |
| adware, computer, freezes, malware, slow |

| |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| |


Email 