Solved Might be infected, some help

Status
Not open for further replies.

karol3

Posts: 34   +0
I have randomly gotten a virus notification on my AVG on a full system scan. I have deleted the files which where in the Java folder. I ran spy bot and malwarebyte scans and all are clean, I did download SUPER ANTI SPY WARE and found a virus in

C:\Windows\winsxs\x86_microsoft-windows-msconfig-exe_31bf3856ad364e35_6.0.6001.18000_none_da7a3e839dc01091

folder

the virus is: msconfig.exe

SUPER ANTI SPY WARE detected in and its quarantined.

I want to be 100% safe. Here are the necessary logs as stated in the pinned topic.
Is it safe to permenetly remove msconfg.exe from the quarintined area in SUPER ANTI SPY WARE?

Thanks.

Malwarebyte LOG:


Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5873

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19019

2/27/2011 9:54:59 PM
mbam-log-2011-02-27 (21-54-59).txt

Scan type: Quick scan
Objects scanned: 156043
Time elapsed: 2 minute(s), 40 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

GMER LOG:

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-02-27 22:14:19
Windows 6.0.6002 Service Pack 2 Harddisk2\DR2 -> \Device\Ide\IdeDeviceP5T0L0-5 SAMSUNG_HD753LJ rev.1AA01107
Running: dedn0jns.exe; Driver: C:\Users\User\AppData\Local\Temp\kxldapob.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xA1E9F780]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS ZwTerminateProcess [0x91C8E620]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xA1E9F8D0]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xA1E9F970]

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!KeSetEvent + 3F1 828F2B74 4 Bytes [80, F7, E9, A1]
.text ntkrnlpa.exe!KeSetEvent + 621 828F2DA4 8 Bytes [20, E6, C8, 91, D0, F8, E9, ...]
.text ntkrnlpa.exe!KeSetEvent + 681 828F2E04 4 Bytes [70, F9, E9, A1]
.text C:\Windows\system32\DRIVERS\atksgt.sys section is writeable [0xA1E5A300, 0x3B6D8, 0xE8000020]
.text C:\Windows\system32\DRIVERS\lirsgt.sys section is writeable [0xA1EB1300, 0x1BEE, 0xE8000020]

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Mozilla Firefox\firefox.exe[5200] ntdll.dll!LdrLoadDll 774F93A8 5 Bytes JMP 000313F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [73B47817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [73B9A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [73B4BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [73B3F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [73B475E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [73B3E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [73B78395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [73B4DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [73B3FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [73B3FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [73B371CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [73BCCAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [73B6C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [73B3D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [73B36853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [73B3687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [73B42AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )

---- EOF - GMER 1.0.15 ----


DDS LOG:
DDS:

DDS (Ver_10-12-12.02) - NTFSx86
Run by User at 22:15:45.43 on Sun 02/27/2011
Internet Explorer: 8.0.6001.19019
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3582.1816 [GMT -5:00]

AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\ASUS\AI Suite\EnergySaving\PwSave.exe
C:\Windows\system32\AEADISRV.EXE
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\lxddcoms.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\ASUS\AASP\1.00.91\aaCenter.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Analog Devices\SoundMAX\SoundTray.exe
C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Webshots\webshots.scr
C:\Windows\ehome\ehmsas.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Logitech\SetPointG\SetPointII.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\User\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll
BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
TB: @c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
mRun: [NWEReboot]
mRun: [<NO NAME>]
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [EvtMgr6] c:\program files\logitech\setpointp\SetPoint.exe /launchGaming
mRun: [SoundTray] c:\program files\analog devices\soundmax\SoundTray.exe
mRun: [Ai Nap] "c:\program files\asus\ai suite\ainap\AiNap.exe"
mRun: [QFan Help] "c:\program files\asus\ai suite\qfan3\QFanHelp.exe"
mRun: [CPU Power Monitor] "c:\program files\asus\ai suite\aigear3\CpuPowerMonitor.exe"
mRun: [Cpu Level Up help] "c:\program files\asus\ai suite\CpuLevelUpHelp.exe"
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
StartupFolder: c:\users\user\appdata\roaming\micros~1\windows\startm~1\programs\startup\webshots.lnk - c:\program files\webshots\Launcher.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: Se&nd to OneNote - d:\micros~1\office14\ONBttnIE.dll/105
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\users\user\appdata\roaming\mozilla\firefox\profiles\2wd3uea1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/aol/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us&tb_uuid=100000000000000002&tb_oid=20-05-2010&tb_mrud=20-05-2010
FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4cc235f1&v=6.011.025.001&i=23&tp=ab&iy=&ychte=us&lng=en-US&q=
FF - component: c:\program files\avg\avg10\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\user\appdata\local\yahoo!\browserplus\2.9.2\plugins\npybrowserplus_2.9.2.dll
FF - plugin: c:\users\user\appdata\roaming\mozilla\firefox\profiles\2wd3uea1.default\extensions\devicedetection@logitech.com\plugins\npLogitechDeviceDetection.dll
FF - plugin: c:\users\user\appdata\roaming\mozilla\firefox\profiles\2wd3uea1.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Move Media Player: moveplayer@movenetworks.com - %profile%\extensions\moveplayer@movenetworks.com
FF - Ext: Vista-aero: {07b2a769-ed19-4483-87ce-c643914c81bb} - %profile%\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Media Converter: {6e764c17-863a-450f-bdd0-6772bd5aaa18} - %profile%\extensions\{6e764c17-863a-450f-bdd0-6772bd5aaa18}
FF - Ext: Firefox Showcase: {89506680-e3f4-484c-a2c0-ed711d481eda} - %profile%\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
FF - Ext: SearchPreview: {EF522540-89F5-46b9-B6FE-1829E2B572C6} - %profile%\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - c:\program files\avg\avg10\Firefox
FF - Ext: AVG Security Toolbar em:version=6.011.025.001 em:displayname=AVG Security Toolbar em:iconURL=chrome://tavgp/skin/logo.ico em:creator=AVG Technologies em:description=AVG Security Toolbar em:homepageURL=http://www.avg.com >: avg@igeared - c:\program files\avg\avg10\toolbar\firefox\avg@igeared

---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false
FF - user.js: browser.sessionstore.resume_from_crash - false
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
============= SERVICES / DRIVERS ===============

R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-12-8 251728]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-11-12 299984]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-1-6 6128720]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-10-22 265400]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2011-2-20 22504]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-6-8 21504]
R2 lxdd_device;lxdd_device;c:\windows\system32\lxddcoms.exe -service --> c:\windows\system32\lxddcoms.exe -service [?]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2008-7-8 1153368]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2011-1-7 378984]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 123472]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 30288]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 27216]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2011-2-1 122984]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2010-10-22 517448]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe --> c:\program files\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [?]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2011-2-27 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 lxddCATSCustConnectService;lxddCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxddserv.exe [2007-4-26 99248]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]

=============== Created Last 30 ================

2011-02-28 02:29:33 -------- d-----w- c:\users\user\appdata\roaming\SUPERAntiSpyware.com
2011-02-28 02:29:33 -------- d-----w- c:\progra~2\SUPERAntiSpyware.com
2011-02-28 02:29:29 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-02-28 01:41:57 -------- d-----w- C:\avrescue
2011-02-27 23:22:59 5943120 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{53f92516-038b-4246-a038-28a59990747a}\mpengine.dll
2011-02-27 23:14:43 -------- d-----w- c:\windows\en
2011-02-27 23:09:22 39272 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2011-02-27 23:01:32 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-02-27 22:46:39 -------- d-----w- c:\program files\Microsoft
2011-02-27 22:46:36 -------- d-----w- c:\program files\MSN Toolbar
2011-02-27 22:46:22 -------- d-----w- c:\program files\Bing Bar Installer
2011-02-27 22:46:21 469256 ----a-w- c:\program files\common files\windows live\.cache\261746251cbd6d004\InstallManager_WLE_WLE.exe
2011-02-27 22:43:46 15712 ----a-w- c:\program files\common files\windows live\.cache\cace22251cbd6cf03\MeshBetaRemover.exe
2011-02-27 22:43:37 94040 ----a-w- c:\program files\common files\windows live\.cache\c538d7b51cbd6cf02\DSETUP.dll
2011-02-27 22:43:37 525656 ----a-w- c:\program files\common files\windows live\.cache\c538d7b51cbd6cf02\DXSETUP.exe
2011-02-27 22:43:37 1691480 ----a-w- c:\program files\common files\windows live\.cache\c538d7b51cbd6cf02\dsetup32.dll
2011-02-27 22:43:11 94040 ----a-w- c:\program files\common files\windows live\.cache\b5b87d451cbd6cf01\DSETUP.dll
2011-02-27 22:43:11 525656 ----a-w- c:\program files\common files\windows live\.cache\b5b87d451cbd6cf01\DXSETUP.exe
2011-02-27 22:43:11 1691480 ----a-w- c:\program files\common files\windows live\.cache\b5b87d451cbd6cf01\dsetup32.dll
2011-02-27 22:42:13 -------- d-----w- c:\users\user\appdata\local\Windows Live
2011-02-27 22:42:11 -------- d-----w- c:\program files\common files\Windows Live
2011-02-27 22:41:04 754688 ----a-w- c:\windows\system32\webservices.dll
2011-02-27 17:21:32 -------- d--h--w- c:\windows\PIF
2011-02-25 01:21:20 -------- d-----w- c:\program files\CCleaner
2011-02-20 16:23:42 22504 ----a-w- c:\windows\system32\drivers\cpuz135_x32.sys
2011-02-17 01:22:36 -------- d-----w- c:\program files\common files\Software Update Utility
2011-02-16 01:59:37 12400 ----a-w- c:\windows\system32\drivers\AsIO.sys
2011-02-16 01:59:33 11832 ----a-w- c:\windows\system32\drivers\AsInsHelp64.sys
2011-02-16 01:59:33 10216 ----a-w- c:\windows\system32\drivers\AsInsHelp32.sys
2011-02-16 01:59:16 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2011-02-16 01:59:16 614532 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\IKernel.exe
2011-02-16 01:59:16 32768 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2011-02-16 01:59:16 225280 ----a-w- c:\program files\common files\installshield\iscript\iscript.dll
2011-02-16 01:59:16 176128 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2011-02-10 03:16:05 -------- d-sh--w- c:\windows\system32\%APPDATA%
2011-02-09 22:15:56 33104 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\msonpppr.dll
2011-02-09 22:15:56 32656 ----a-w- c:\windows\system32\msonpmon.dll
2011-02-09 22:14:14 -------- d-----w- c:\windows\PCHEALTH
2011-02-09 22:12:32 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2011-02-08 19:14:59 638232 ----a-w- c:\program files\internet explorer\iexplore.exe
2011-02-06 22:15:10 -------- d-----w- c:\users\user\appdata\local\Microsoft Help
2011-02-06 20:10:12 -------- d-----w- c:\progra~2\VirtualizedApplications
2011-02-06 18:25:57 -------- d-----w- c:\program files\Microsoft XNA
2011-02-06 17:57:50 -------- d-----w- c:\users\user\appdata\local\SoftGrid Client
2011-02-06 17:57:06 -------- d-----w- c:\users\user\appdata\roaming\SoftGrid Client
2011-02-06 17:52:53 -------- d-----w- c:\users\user\appdata\roaming\TP

==================== Find3M ====================

2011-02-11 22:14:10 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-02-02 23:49:11 22328 ----a-w- c:\users\user\appdata\roaming\PnkBstrK.sys
2011-02-02 23:49:00 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-02-02 23:48:54 103736 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-02-02 23:48:53 669184 ----a-w- c:\windows\system32\pbsvc.exe
2011-02-02 22:11:20 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-02-02 19:23:17 270904 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-01-20 16:08:16 478720 ----a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08:06 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08:06 189952 ----a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:08:06 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08:06 1029120 ----a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:07:58 37376 ----a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07:42 258048 ----a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07:16 586240 ----a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf.dll
2011-01-20 16:06:35 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04:54 98816 ----a-w- c:\windows\system32\mfps.dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat.dll
2011-01-20 14:28:38 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27:50 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26:30 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25:25 847360 ----a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24:32 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-01-20 14:24:26 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15:10 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14:39 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14:03 302592 ----a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:14:03 261632 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:12:46 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11:34 486400 ----a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47:51 683008 ----a-w- c:\windows\system32\d2d1.dll
2011-01-20 13:44:05 1068544 ----a-w- c:\windows\system32\DWrite.dll
2011-01-20 13:44:03 797184 ----a-w- c:\windows\system32\FntCache.dll
2011-01-08 08:47:50 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-01-08 06:28:49 292352 ----a-w- c:\windows\system32\atmfd.dll
2011-01-08 03:27:00 941160 ----a-w- c:\windows\system32\nvdispco322090.dll
2011-01-08 03:27:00 837736 ----a-w- c:\windows\system32\nvgenco322040.dll
2011-01-08 03:27:00 57960 ----a-w- c:\windows\system32\OpenCL.dll
2011-01-08 03:27:00 5653096 ----a-w- c:\windows\system32\nvwgf2um.dll
2011-01-08 03:27:00 4941928 ----a-w- c:\windows\system32\nvcuda.dll
2011-01-08 03:27:00 2895976 ----a-w- c:\windows\system32\nvcuvid.dll
2011-01-08 03:27:00 2251368 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-01-08 03:27:00 1965672 ----a-w- c:\windows\system32\nvapi.dll
2011-01-08 03:27:00 15047272 ----a-w- c:\windows\system32\nvoglv32.dll
2011-01-08 03:27:00 13011560 ----a-w- c:\windows\system32\nvcompiler.dll
2011-01-08 03:27:00 10078312 ----a-w- c:\windows\system32\nvd3dum.dll
2011-01-08 02:06:44 580200 ----a-w- c:\windows\system32\easyUpdatusAPIU.dll
2011-01-08 02:06:34 3597416 ----a-w- c:\windows\system32\nvcpl.dll
2011-01-08 02:06:14 2620520 ----a-w- c:\windows\system32\nvsvc.dll
2011-01-08 02:06:02 66664 ----a-w- c:\windows\system32\nvshext.dll
2011-01-08 02:06:02 608872 ----a-w- c:\windows\system32\nvvsvc.exe
2011-01-08 02:06:02 111208 ----a-w- c:\windows\system32\nvmctray.dll
2010-12-31 13:57:01 2039808 ----a-w- c:\windows\system32\win32k.sys
2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32.dll
2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-18 06:22:41 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-12-18 06:22:27 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-12-18 06:22:11 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-12-18 06:22:11 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-12-18 05:25:26 385024 ----a-w- c:\windows\system32\html.iec
2010-12-18 04:48:39 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-12-18 04:47:11 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2010-12-14 14:49:23 1169408 ----a-w- c:\windows\system32\sdclt.exe
2010-12-02 09:12:06 837224 ----a-w- c:\windows\system32\nvgenco32hda.dll

============= FINISH: 22:16:17.31 ===============

ATTACH:


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-12-12.02)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume3
Install Date: 6/4/2008 5:14:27 PM
System Uptime: 2/27/2011 9:35:18 PM (1 hours ago)

Motherboard: ASUSTeK Computer INC. | | P5E
Processor: Intel(R) Core(TM)2 Quad CPU Q9450 @ 2.66GHz | LGA775 | 2664/333mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 699 GiB total, 486.476 GiB free.
D: is FIXED (NTFS) - 112 GiB total, 17.139 GiB free.
E: is CDROM ()
F: is FIXED (NTFS) - 1863 GiB total, 1556.113 GiB free.

==== Disabled Device Manager Items =============

Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft 6to4 Adapter
Device ID: ROOT\*6TO4MP\0001
Manufacturer: Microsoft
Name: Microsoft 6to4 Adapter #2
PNP Device ID: ROOT\*6TO4MP\0001
Service: tunnel

Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft Tun Miniport Adapter
Device ID: ROOT\*TUNMP\0001
Manufacturer: Microsoft
Name: Microsoft Tun Miniport Adapter #2
PNP Device ID: ROOT\*TUNMP\0001
Service: tunmp

==== System Restore Points ===================

RP849: 2/27/2011 5:35:04 PM - 2/27/11
RP850: 2/27/2011 5:40:54 PM - Windows Update
RP851: 2/27/2011 6:22:49 PM - Windows Update

==== Installed Programs ======================

ABBYY FineReader 6.0 Sprint
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader X
Adobe Shockwave Player 11.5
AI Suite
AIM 7
Apple Application Support
Apple Software Update
Assassin's Creed
AutoUpdate
AVG 2011
AVS DVD Player version 2.4
Batman: Arkham Asylum
Bing Bar
Bing Bar Platform
BioShock
BioShock 2
Burnout(TM) Paradise The Ultimate Box
Call of Duty(R) 4 - Modern Warfare(TM)
Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
CCleaner
Company of Heroes
Company of Heroes - FAKEMSI
Content Transfer
CPUID CPU-Z 1.57
Crysis WARHEAD(R)
Crysis WARHEAD(R) Patch
Crysis(R)
D3DX10
DarksidersInstaller
dBpowerAMP Music Converter
Dead Rising 2
DivX Codec
DivX Converter
DivX Player
DivX Web Player
Download Updater (AOL LLC)
DVD Flick 1.3.0.7
EA Download Manager
eReg
Fallout 3
FormatFactory 2.20
Fraps (remove only)
FUJIFILM FinePixViewer S Ver.2.1
Futuremark SystemInfo
Gears of War
GoldWave v5.20
Grand Theft Auto
Grand Theft Auto IV
Grand Theft Auto: Episodes From Liberty City
GRID
GTA2
HandBrake 0.9.5
Host OpenAL (ADI)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Junk Mail filter update
Lexmark 2500 Series
Lexmark Fax Solutions
Logitech SetPoint 6.20
LOST PLANET 2
Malwarebytes' Anti-Malware
Marvell Miniport Driver
Mass Effect
Mesh Runtime
Messenger Companion
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook Connector
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ Run Time Lib Setup
Microsoft XNA Framework Redistributable 3.1
Mirror's Edge™
Mozilla Firefox (3.6.13)
MSVCRT
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NetMeter 1.1.3
NVIDIA 3D Vision Driver 266.58
NVIDIA Control Panel 266.58
NVIDIA Graphics Driver 266.58
NVIDIA HD Audio Driver 1.1.13.1
NVIDIA Install Application
NVIDIA PhysX
NVIDIA PhysX System Software 9.10.0514
NVIDIA Stereoscopic 3D Driver
OpenAL
OpenOffice.org 2.3
Peggle World of Warcraft Edition
Project64 1.6
Prototype(TM)
PunkBuster Services
QuickTime
Rapture3D 2.3.26 Game
Realtek High Definition Audio Driver
Red Faction Guerrilla
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2289158)
Security Update for 2007 Microsoft Office System (KB2344875)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB2345035)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)
Security Update for Microsoft Office Publisher 2007 (KB2284697)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Segoe UI
Skype Toolbars
Skype™ 5.1
Smart Defrag
SoundMAX
SpeedFan (remove only)
Spybot - Search & Destroy
SpywareBlaster 4.4
Steam
SUPERAntiSpyware
SwitchBlade
TBS WMP Plug-in
TeamSpeak 3 Client
The Witcher Enhanced Edition
Twin USB Vibration Gamepad
Ubisoft Game Launcher
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2412171)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (KB2492475)
VC80CRTRedist - 8.0.50727.762
Ventrilo Client
Viewpoint Media Player
VLC media player 1.1.5
Webshots Desktop
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Media Player Firefox Plugin
World in Conflict
Xfire (remove only)
Yahoo! BrowserPlus 2.9.2

==== Event Viewer Messages From Past Week ========

2/27/2011 6:25:11 PM, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Start with the following error: Access is denied.
2/27/2011 6:17:27 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
2/27/2011 6:17:27 PM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/27/2011 6:17:27 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
2/25/2011 11:13:32 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8BC3F05E-D86B-11D0-A075-00C04FB68820} to the user User-PC\User SID (S-1-5-21-2158934232-3957428742-2026527031-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.

==== End Of File ===========================
 
Welcome aboard
yahooo.gif


Please, observe following rules:
  • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
  • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
  • Please refrain from running tools or applying updates other than those I suggest.
  • Never run more than one scan at a time.
  • Keep updating me regarding your computer behavior, good, or bad.
  • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
  • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
  • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

========================================================================

Download MBRCheck to your desktop

Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator).
It will show a black screen with some data on it.
Enter N to exit.
A report called MBRcheckxxxx.txt will be on your desktop
Open this report and post its content in your next reply.

======================================================================

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  1. Please, never rename Combofix unless instructed.
  2. Close any open browsers.
  3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    NOTE1. If Combofix asks you to install Recovery Console, please allow it.
    NOTE 2. If Combofix asks you to update the program, always do so.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
  4. Double click on combofix.exe & follow the prompts.
  5. When finished, it will produce a report for you.
  6. Please post the "C:\ComboFix.txt"
**Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
**Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
Use AppRemover to uninstall it: https://www.techspot.com/downloads/5514-appremover.html
We can reinstall it when we're done with CF.
**Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.



Make sure, you re-enable your security programs, when you're done with Combofix.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

NOTE.
If, for some reason, Combofix refuses to run, try one of the following:

1. Run Combofix from Safe Mode.

2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
Do NOT run it yet.

Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

There are 4 different versions. If one of them won't run then download and try to run the other one.

Vista and Win7 users need to right click Rkill and choose Run as Administrator

You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

Rkill.com
Rkill.scr
Rkill.exe

  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided, please let me know.

Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

If normal mode still doesn't work, run BOTH tools from safe mode.

In case #2, please post BOTH logs, rKill and Combofix.

DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
 
Nice to meet you here is what you asked.

MBR CHECK:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer: ASUSTeK Computer INC.
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: System manufacturer
System Product Name: P5E
Logical Drives Mask: 0x0000003d

Kernel Drivers (total 156):
0x82840000 \SystemRoot\system32\ntkrnlpa.exe
0x8280D000 \SystemRoot\system32\hal.dll
0x8040C000 \SystemRoot\system32\kdcom.dll
0x80413000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x80483000 \SystemRoot\system32\PSHED.dll
0x80494000 \SystemRoot\system32\BOOTVID.dll
0x8049C000 \SystemRoot\system32\CLFS.SYS
0x804DD000 \SystemRoot\system32\CI.dll
0x80600000 \SystemRoot\system32\drivers\Wdf01000.sys
0x8067C000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x80689000 \SystemRoot\system32\drivers\acpi.sys
0x806CF000 \SystemRoot\system32\drivers\WMILIB.SYS
0x806D8000 \SystemRoot\system32\drivers\msisadrv.sys
0x806E0000 \SystemRoot\system32\drivers\pci.sys
0x80707000 \SystemRoot\System32\drivers\partmgr.sys
0x80716000 \SystemRoot\system32\drivers\volmgr.sys
0x80725000 \SystemRoot\System32\drivers\volmgrx.sys
0x8076F000 \SystemRoot\system32\drivers\pciide.sys
0x80776000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x80784000 \SystemRoot\System32\drivers\mountmgr.sys
0x80794000 \SystemRoot\system32\drivers\atapi.sys
0x8079C000 \SystemRoot\system32\drivers\ataport.SYS
0x807BA000 \SystemRoot\system32\drivers\fltmgr.sys
0x807EC000 \SystemRoot\system32\drivers\fileinfo.sys
0x82E07000 \SystemRoot\System32\Drivers\ksecdd.sys
0x82E78000 \SystemRoot\system32\drivers\ndis.sys
0x82F83000 \SystemRoot\system32\drivers\msrpc.sys
0x82FAE000 \SystemRoot\system32\drivers\NETIO.SYS
0x8BC0F000 \SystemRoot\System32\drivers\tcpip.sys
0x8BCF9000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x8BE0D000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8BF1D000 \SystemRoot\system32\drivers\volsnap.sys
0x8BF56000 \SystemRoot\System32\Drivers\spldr.sys
0x8BF5E000 \SystemRoot\system32\speedfan.sys
0x8BF60000 \SystemRoot\System32\Drivers\mup.sys
0x8BF6F000 \SystemRoot\system32\giveio.sys
0x8BF70000 \SystemRoot\System32\drivers\ecache.sys
0x8BF97000 \SystemRoot\system32\drivers\disk.sys
0x8BFA8000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x8BFC9000 \SystemRoot\system32\drivers\crcdisk.sys
0x8BFD2000 \SystemRoot\system32\DRIVERS\avgrkx86.sys
0x8BFD7000 \SystemRoot\system32\DRIVERS\AVGIDSEH.Sys
0x8BE00000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8BD14000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x8BD1D000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8FE00000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x907FA000 \SystemRoot\System32\Drivers\nvBridge.kmd
0x8BD2C000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8BDCC000 \SystemRoot\System32\drivers\watchdog.sys
0x90809000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x90896000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x908A1000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x908DF000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x908EE000 \SystemRoot\system32\DRIVERS\yk60x86.sys
0x9093A000 \SystemRoot\System32\DRIVERS\dvd43llh.sys
0x9093F000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x90957000 \SystemRoot\system32\DRIVERS\ohci1394.sys
0x90967000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
0x90975000 \SystemRoot\system32\DRIVERS\fdc.sys
0x90980000 \SystemRoot\system32\DRIVERS\ASACPI.sys
0x90988000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x9099B000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x909A6000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x805BD000 \SystemRoot\system32\DRIVERS\storport.sys
0x909D5000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x909E0000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8BDD8000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x90C07000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x90C2A000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x90C39000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x90C4D000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x90C62000 \SystemRoot\system32\DRIVERS\termdd.sys
0x90C72000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x90C7D000 \SystemRoot\system32\DRIVERS\swenum.sys
0x90C7F000 \SystemRoot\system32\DRIVERS\ks.sys
0x90CA9000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x90CB3000 \SystemRoot\system32\DRIVERS\umbus.sys
0x90CC0000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x90CF5000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0x90CFF000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x90D10000 \SystemRoot\system32\drivers\nvhda32v.sys
0x90D31000 \SystemRoot\system32\drivers\portcls.sys
0x90D5E000 \SystemRoot\system32\drivers\drmk.sys
0x90D83000 \SystemRoot\system32\drivers\ADIHdAud.sys
0x90DDC000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x90DF3000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x90DF5000 \SystemRoot\system32\DRIVERS\hidusb.sys
0x8BDE3000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x90C00000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x909F7000 \SystemRoot\system32\DRIVERS\LHidFilt.Sys
0x90800000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x8BDF3000 \SystemRoot\system32\DRIVERS\LMouFilt.Sys
0x8BC00000 \SystemRoot\system32\DRIVERS\kbdhid.sys
0x82FE9000 \SystemRoot\system32\DRIVERS\usbscan.sys
0x82FF6000 \SystemRoot\system32\DRIVERS\usbprint.sys
0x80400000 \SystemRoot\system32\DRIVERS\avgmfx86.sys
0x90E07000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x90E10000 \SystemRoot\System32\Drivers\Null.SYS
0x90E17000 \SystemRoot\System32\Drivers\Beep.SYS
0x90E1E000 \SystemRoot\System32\drivers\vga.sys
0x90E2A000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x90E4B000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x90E53000 \SystemRoot\system32\drivers\rdpencdd.sys
0x90E5B000 \SystemRoot\System32\Drivers\Msfs.SYS
0x90E66000 \SystemRoot\System32\Drivers\Npfs.SYS
0x90E74000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x90E7D000 \SystemRoot\system32\DRIVERS\tdx.sys
0x90E93000 \SystemRoot\system32\DRIVERS\avgtdix.sys
0x90EDB000 \SystemRoot\System32\DRIVERS\netbt.sys
0x90F0D000 \SystemRoot\system32\DRIVERS\smb.sys
0x90F21000 \SystemRoot\system32\drivers\afd.sys
0x90F69000 \SystemRoot\system32\DRIVERS\pacer.sys
0x90F7F000 \SystemRoot\system32\DRIVERS\netbios.sys
0x90F8D000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x90FA0000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
0x90FC2000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
0x9160B000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x91647000 \SystemRoot\system32\drivers\nsiproxy.sys
0x91651000 \SystemRoot\System32\Drivers\dfsc.sys
0x91668000 \SystemRoot\system32\DRIVERS\avgldx86.sys
0x916A4000 \SystemRoot\system32\drivers\AsIO.sys
0x916A6000 \SystemRoot\System32\Drivers\crashdmp.sys
0x916B3000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x916BE000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x81670000 \SystemRoot\System32\win32k.sys
0x916C6000 \SystemRoot\System32\drivers\Dxapi.sys
0x916D0000 \SystemRoot\system32\DRIVERS\monitor.sys
0x81890000 \SystemRoot\System32\TSDDD.dll
0x818B0000 \SystemRoot\System32\cdd.dll
0x916DF000 \SystemRoot\system32\drivers\luafv.sys
0x91702000 \SystemRoot\system32\drivers\spsys.sys
0x917B2000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x917C2000 \SystemRoot\system32\DRIVERS\rspndr.sys
0xA1C09000 \SystemRoot\system32\drivers\HTTP.sys
0xA1C76000 \SystemRoot\System32\DRIVERS\srvnet.sys
0xA1C93000 \SystemRoot\system32\DRIVERS\bowser.sys
0xA1CAC000 \SystemRoot\System32\drivers\mpsdrv.sys
0xA1CC1000 \SystemRoot\system32\drivers\mrxdav.sys
0xA1CE2000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xA1D01000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0xA1D3A000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0xA1D52000 \SystemRoot\System32\DRIVERS\srv2.sys
0xA1D7A000 \SystemRoot\System32\DRIVERS\srv.sys
0xA1DC8000 \SystemRoot\system32\DRIVERS\asyncmac.sys
0xAA808000 \SystemRoot\system32\DRIVERS\atksgt.sys
0xAA84B000 \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys
0xAA856000 \??\C:\Windows\system32\drivers\cpuz135_x32.sys
0xAA85F000 \SystemRoot\system32\DRIVERS\lirsgt.sys
0xAA864000 \SystemRoot\system32\drivers\peauth.sys
0xAA942000 \SystemRoot\System32\Drivers\secdrv.SYS
0xAA94C000 \SystemRoot\System32\drivers\tcpipreg.sys
0xAA958000 \SystemRoot\system32\DRIVERS\AVGIDSFilter.Sys
0xAA962000 \SystemRoot\system32\DRIVERS\AVGIDSDriver.Sys
0xAA98A000 \SystemRoot\System32\Drivers\fastfat.SYS
0xAA9B2000 \SystemRoot\system32\DRIVERS\cdfs.sys
0x77900000 \Windows\System32\ntdll.dll

Processes (total 68):
0 System Idle Process
4 System
404 C:\Windows\System32\smss.exe
436 C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
664 csrss.exe
736 C:\Windows\System32\wininit.exe
748 csrss.exe
780 C:\Windows\System32\services.exe
808 C:\Windows\System32\winlogon.exe
860 C:\Windows\System32\lsass.exe
876 C:\Windows\System32\lsm.exe
1032 C:\Windows\System32\svchost.exe
1080 C:\Windows\System32\nvvsvc.exe
1108 C:\Windows\System32\svchost.exe
1236 C:\Windows\System32\svchost.exe
1260 C:\Windows\System32\svchost.exe
1272 C:\Windows\System32\svchost.exe
1404 C:\Windows\System32\audiodg.exe
1432 C:\Windows\System32\svchost.exe
1452 C:\Windows\System32\SLsvc.exe
1500 C:\Windows\System32\svchost.exe
1664 C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
1676 C:\Windows\System32\nvvsvc.exe
1700 C:\Windows\System32\svchost.exe
132 C:\Windows\System32\spoolsv.exe
268 C:\Windows\System32\svchost.exe
1092 C:\Windows\System32\taskeng.exe
1316 C:\Windows\System32\dwm.exe
1892 C:\Windows\explorer.exe
700 C:\Program Files\ASUS\AI Suite\EnergySaving\PwSave.exe
644 C:\Program Files\ASUS\AASP\1.00.91\aaCenter.exe
1640 C:\Windows\System32\taskeng.exe
2184 C:\Windows\System32\AEADISRV.EXE
2292 C:\Program Files\AVG\AVG10\avgwdsvc.exe
2376 C:\Windows\System32\lxddcoms.exe
2520 C:\Windows\System32\PnkBstrA.exe
2536 C:\Windows\System32\svchost.exe
2548 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
2848 C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
2932 C:\Windows\System32\svchost.exe
2988 C:\Program Files\AVG\AVG10\avgtray.exe
3124 C:\Windows\System32\svchost.exe
3176 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
3212 C:\Program Files\Analog Devices\SoundMAX\SoundTray.exe
3304 C:\Windows\System32\SearchIndexer.exe
3344 C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
3380 C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe
3396 C:\Program Files\Analog Devices\Core\smax4pnp.exe
3420 C:\Windows\ehome\ehtray.exe
3440 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
3476 C:\Program Files\Windows Sidebar\sidebar.exe
3512 C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
3824 C:\Windows\ehome\ehmsas.exe
3848 C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
3884 C:\Program Files\Webshots\Webshots.scr
2832 C:\Program Files\AVG\AVG10\avgnsx.exe
620 C:\Program Files\AVG\AVG10\avgemcx.exe
2720 C:\Program Files\Windows Sidebar\sidebar.exe
1212 C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
3600 C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
3732 C:\Program Files\Logitech\SetPointG\SetPointII.exe
4616 C:\Windows\System32\svchost.exe
4920 C:\PROGRA~1\AVG\AVG10\avgrsx.exe
4724 C:\Program Files\AVG\AVG10\avgcsrvx.exe
1508 C:\Program Files\Mozilla Firefox\firefox.exe
5972 C:\Windows\System32\SearchProtocolHost.exe
1708 C:\Windows\System32\SearchFilterHost.exe
5568 C:\Users\User\Desktop\MBRCheck.exe

\\.\C: --> \\.\PhysicalDrive1 at offset 0x00000000`00100000 (NTFS)
\\.\D: --> \\.\PhysicalDrive2 at offset 0x00000000`00100000 (NTFS)
\\.\F: --> \\.\PhysicalDrive0 at offset 0x00000000`00100000 (NTFS)

PhysicalDrive1 Model Number: SAMSUNGHD753LJ, Rev: 1AA01107
PhysicalDrive2 Model Number: WDCWD1200JD-00HBB0, Rev: 08.02D08
PhysicalDrive0 Model Number: WDCWD20EARS-00MVWB0, Rev: 51.0AB51

Size Device Name MBR Status
--------------------------------------------
698 GB \\.\PhysicalDrive1 Windows 2008 MBR code detected
SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979
111 GB \\.\PhysicalDrive2 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
1863 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected
SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979


Done!




COMBO FIX LOG:

ComboFix 11-02-27.03 - User 02/28/2011 12:28:05.1.4 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3582.2504 [GMT -5:00]
Running from: c:\users\User\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\$$DELETME.wtspai32.dll
c:\$$deletme.wtspai32.dll\$$DeleteMe.authui.dll.01c8c67dbedeec23.000d
c:\$$deletme.wtspai32.dll\$$DeleteMe.CbsMsg.dll.01c8c67dbf396063.001e
c:\$$deletme.wtspai32.dll\$$DeleteMe.crypt32.dll.01c8c67dbe6324a3.0003
c:\$$deletme.wtspai32.dll\$$DeleteMe.csrsrv.dll.01c8c67dbfca9443.0029
c:\$$deletme.wtspai32.dll\$$DeleteMe.dhcpcsvc.dll.01c8c67dbee14d83.000e
c:\$$deletme.wtspai32.dll\$$DeleteMe.dhcpcsvc6.dll.01c8c67dbee61043.0010
c:\$$deletme.wtspai32.dll\$$DeleteMe.dnsapi.dll.01c8c67dbe99e443.0009
c:\$$deletme.wtspai32.dll\$$DeleteMe.dnsrslvr.dll.01c8c67dbe99e443.000a
c:\$$deletme.wtspai32.dll\$$DeleteMe.dps.dll.01c8c67dc0890243.0031
c:\$$deletme.wtspai32.dll\$$DeleteMe.dpx.dll.01c8c67dbf2fdae3.0019
c:\$$deletme.wtspai32.dll\$$DeleteMe.FirewallAPI.dll.01c8c67dbf61d7c3.0021
c:\$$deletme.wtspai32.dll\$$DeleteMe.gdi32.dll.01c8c67dbf02a0c3.0016
c:\$$deletme.wtspai32.dll\$$DeleteMe.imagehlp.dll.01c8c67dbe6a48c3.0005
c:\$$deletme.wtspai32.dll\$$DeleteMe.iphlpsvc.dll.01c8c67dbf643923.0024
c:\$$deletme.wtspai32.dll\$$DeleteMe.kmddsp.tsp.01c8c67dc07aba03.002f
c:\$$deletme.wtspai32.dll\$$DeleteMe.loadperf.dll.01c8c67dbf2d7983.0018
c:\$$deletme.wtspai32.dll\$$DeleteMe.localspl.dll.01c8c67dc086a0e3.0030
c:\$$deletme.wtspai32.dll\$$DeleteMe.MpClient.dll.01c8c67dbfa6dfa3.0027
c:\$$deletme.wtspai32.dll\$$DeleteMe.MpRtPlug.dll.01c8c67dbfa21ce3.0025
c:\$$deletme.wtspai32.dll\$$DeleteMe.MPSSVC.dll.01c8c67dbf61d7c3.0023
c:\$$deletme.wtspai32.dll\$$DeleteMe.MpSvc.dll.01c8c67dbfa47e43.0026
c:\$$deletme.wtspai32.dll\$$DeleteMe.msxml3.dll.01c8c67dbf4c6b63.0020
c:\$$deletme.wtspai32.dll\$$DeleteMe.msxml3r.dll.01c8c67dbf4a0a03.001f
c:\$$deletme.wtspai32.dll\$$DeleteMe.msxml6.dll.01c8c67dbeed3463.0013
c:\$$deletme.wtspai32.dll\$$DeleteMe.msxml6r.dll.01c8c67dbeed3463.0012
c:\$$deletme.wtspai32.dll\$$DeleteMe.ndptsp.tsp.01c8c67dc0890243.0032
c:\$$deletme.wtspai32.dll\$$DeleteMe.netcfgx.dll.01c8c67dc0713483.002e
c:\$$deletme.wtspai32.dll\$$DeleteMe.oleaut32.dll.01c8c67dbec71e63.000b
c:\$$deletme.wtspai32.dll\$$DeleteMe.poqexec.exe.01c8c67dbe60c343.0002
c:\$$deletme.wtspai32.dll\$$DeleteMe.qmgr.dll.01c8c67dbe527b03.0000
c:\$$deletme.wtspai32.dll\$$DeleteMe.rpcrt4.dll.01c8c67dbe8dfd63.0008
c:\$$deletme.wtspai32.dll\$$DeleteMe.schannel.dll.01c8c67dbee14d83.000f
c:\$$deletme.wtspai32.dll\$$DeleteMe.schedsvc.dll.01c8c67dbf2fdae3.001a
c:\$$deletme.wtspai32.dll\$$DeleteMe.setupapi.dll.01c8c67dbf323c43.001b
c:\$$deletme.wtspai32.dll\$$DeleteMe.shell32.dll.01c8c67dbee61043.0011
c:\$$deletme.wtspai32.dll\$$DeleteMe.SLC.dll.01c8c67dbefb7ca3.0014
c:\$$deletme.wtspai32.dll\$$DeleteMe.SLsvc.exe.01c8c67dbefb7ca3.0015
c:\$$deletme.wtspai32.dll\$$DeleteMe.srclient.dll.01c8c67dbf323c43.001c
c:\$$deletme.wtspai32.dll\$$DeleteMe.sysmain.dll.01c8c67dbfd8dc83.002c
c:\$$deletme.wtspai32.dll\$$DeleteMe.TrustedInstaller.exe.01c8c67dbf396063.001d
c:\$$deletme.wtspai32.dll\$$DeleteMe.umpnpmgr.dll.01c8c67dbf2b1823.0017
c:\$$deletme.wtspai32.dll\$$DeleteMe.urlmon.dll.01c8c67dbe7d53c3.0006
c:\$$deletme.wtspai32.dll\$$DeleteMe.user32.dll.01c8c67dbe599f23.0001
c:\$$deletme.wtspai32.dll\$$DeleteMe.wbemcomn.dll.01c8c67dbfdd9f43.002d
c:\$$deletme.wtspai32.dll\$$DeleteMe.WebClnt.dll.01c8c67dbfcf5703.002a
c:\$$deletme.wtspai32.dll\$$DeleteMe.wfapigp.dll.01c8c67dbf61d7c3.0022
c:\$$deletme.wtspai32.dll\$$DeleteMe.WindowsCodecs.dll.01c8c67dbedeec23.000c
c:\$$deletme.wtspai32.dll\$$DeleteMe.wininet.dll.01c8c67dbe8477e3.0007
c:\$$deletme.wtspai32.dll\$$DeleteMe.winsrv.dll.01c8c67dbfca9443.0028
c:\$$deletme.wtspai32.dll\$$DeleteMe.wmi.dll.01c8c67dbe6a48c3.0004
c:\$$deletme.wtspai32.dll\$$DeleteMe.wtsapi32.dll.01c8c67dbfd8dc83.002b
C:\install.exe
c:\windows\system32\out.txt

.
((((((((((((((((((((((((( Files Created from 2011-01-28 to 2011-02-28 )))))))))))))))))))))))))))))))
.

2011-02-28 17:32 . 2011-02-28 17:32 -------- d-----w- c:\users\User\AppData\Local\temp
2011-02-28 17:32 . 2011-02-28 17:32 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-02-28 02:29 . 2011-02-28 02:29 -------- d-----w- c:\users\User\AppData\Roaming\SUPERAntiSpyware.com
2011-02-28 02:29 . 2011-02-28 02:29 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-02-28 02:29 . 2011-02-28 02:29 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-02-28 01:41 . 2011-02-28 01:41 -------- d-----w- C:\avrescue
2011-02-27 23:22 . 2011-02-23 14:35 5943120 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{53F92516-038B-4246-A038-28A59990747A}\mpengine.dll
2011-02-27 23:14 . 2011-02-27 23:14 -------- d-----w- c:\windows\en
2011-02-27 23:09 . 2011-02-27 23:09 -------- dc----w- c:\windows\system32\DRVSTORE
2011-02-27 23:09 . 2010-09-23 05:21 39272 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2011-02-27 23:01 . 2011-02-27 23:01 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2011-02-27 22:49 . 2011-02-27 23:15 -------- d-----w- c:\program files\Windows Live
2011-02-27 22:46 . 2011-02-27 22:46 -------- d-----w- c:\program files\Microsoft
2011-02-27 22:46 . 2011-02-27 22:46 -------- d-----w- c:\program files\MSN Toolbar
2011-02-27 22:46 . 2011-02-27 22:46 -------- d-----w- c:\program files\Bing Bar Installer
2011-02-27 22:42 . 2011-02-27 22:42 -------- d-----w- c:\users\User\AppData\Local\Windows Live
2011-02-27 22:42 . 2011-02-27 22:42 -------- d-----w- c:\program files\Common Files\Windows Live
2011-02-27 22:41 . 2009-08-04 08:02 754688 ----a-w- c:\windows\system32\webservices.dll
2011-02-27 17:21 . 2011-02-27 17:21 -------- d--h--w- c:\windows\PIF
2011-02-25 01:21 . 2011-02-25 01:21 -------- d-----w- c:\program files\CCleaner
2011-02-20 16:23 . 2011-01-19 22:47 22504 ----a-w- c:\windows\system32\drivers\cpuz135_x32.sys
2011-02-17 01:22 . 2011-02-17 01:22 -------- d-----w- c:\program files\Common Files\Software Update Utility
2011-02-16 01:59 . 2007-12-17 22:14 12400 ----a-w- c:\windows\system32\drivers\AsIO.sys
2011-02-16 01:59 . 2008-01-04 18:34 11832 ----a-w- c:\windows\system32\drivers\AsInsHelp64.sys
2011-02-16 01:59 . 2008-01-04 18:34 10216 ----a-w- c:\windows\system32\drivers\AsInsHelp32.sys
2011-02-16 01:59 . 2002-07-25 15:07 614532 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe
2011-02-16 01:59 . 2001-09-05 09:18 77824 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
2011-02-16 01:59 . 2001-09-05 09:18 225280 ----a-w- c:\program files\Common Files\InstallShield\IScript\iscript.dll
2011-02-16 01:59 . 2001-09-05 09:14 176128 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
2011-02-16 01:59 . 2001-09-05 09:13 32768 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
2011-02-10 03:16 . 2011-02-10 03:16 -------- d-sh--w- c:\windows\system32\%APPDATA%
2011-02-09 22:15 . 2008-11-10 16:41 32656 ----a-w- c:\windows\system32\msonpmon.dll
2011-02-09 22:15 . 2006-10-27 00:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2011-02-09 22:14 . 2011-02-11 21:41 -------- d-----w- c:\program files\Microsoft Works
2011-02-09 22:14 . 2011-02-09 22:14 -------- d-----w- c:\windows\PCHEALTH
2011-02-09 22:12 . 2011-02-09 22:12 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2011-02-09 18:25 . 2011-02-09 18:25 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2011-02-09 02:46 . 2011-02-09 02:46 -------- d-----r- C:\MSOCache
2011-02-08 19:14 . 2010-12-18 06:28 638232 ----a-w- c:\program files\Internet Explorer\iexplore.exe
2011-02-06 23:46 . 2011-02-16 01:56 -------- d-----w- c:\users\User\AppData\Roaming\Download Manager
2011-02-06 22:15 . 2011-02-13 04:46 -------- d-----w- c:\programdata\Microsoft Help
2011-02-06 22:15 . 2011-02-06 22:15 -------- d-----w- c:\users\User\AppData\Local\Microsoft Help
2011-02-06 20:10 . 2011-02-06 20:10 -------- d-----w- c:\programdata\VirtualizedApplications
2011-02-06 18:25 . 2011-02-06 18:25 -------- d-----w- c:\program files\Microsoft XNA
2011-02-06 17:57 . 2011-02-06 22:59 -------- d-----w- c:\users\User\AppData\Local\SoftGrid Client
2011-02-06 17:57 . 2011-02-07 00:57 -------- d-----w- c:\users\User\AppData\Roaming\SoftGrid Client
2011-02-06 17:52 . 2011-02-06 22:59 -------- d-----w- c:\users\User\AppData\Roaming\TP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-27 22:47 . 2009-08-18 16:24 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-02-11 22:14 . 2008-06-07 18:16 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-02-02 23:49 . 2008-06-07 18:17 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-02-02 23:49 . 2008-06-07 18:17 22328 ----a-w- c:\users\User\AppData\Roaming\PnkBstrK.sys
2011-02-02 23:49 . 2008-06-07 18:16 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-02-02 23:48 . 2008-06-07 18:16 103736 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-02-02 23:48 . 2008-06-07 19:06 669184 ----a-w- c:\windows\system32\pbsvc.exe
2011-02-02 22:11 . 2009-10-03 12:29 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-02-02 19:23 . 2009-04-02 22:34 270904 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-01-08 03:27 . 2011-02-02 02:08 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2011-01-08 02:06 . 2011-01-08 02:06 580200 ----a-w- c:\windows\system32\easyUpdatusAPIU.dll
2011-01-08 02:06 . 2011-01-08 02:06 3597416 ----a-w- c:\windows\system32\nvcpl.dll
2011-01-08 02:06 . 2011-01-08 02:06 2620520 ----a-w- c:\windows\system32\nvsvc.dll
2011-01-08 02:06 . 2011-01-08 02:06 66664 ----a-w- c:\windows\system32\nvshext.dll
2011-01-08 02:06 . 2011-01-08 02:06 608872 ----a-w- c:\windows\system32\nvvsvc.exe
2011-01-08 02:06 . 2011-01-08 02:06 111208 ----a-w- c:\windows\system32\nvmctray.dll
2010-12-28 15:55 . 2011-01-12 14:20 413696 ----a-w- c:\windows\system32\odbc32.dll
2010-12-20 23:09 . 2008-07-30 19:50 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 23:08 . 2008-07-30 19:50 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-14 14:49 . 2011-01-12 14:20 1169408 ----a-w- c:\windows\system32\sdclt.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-10-28 1352272]
"SoundTray"="c:\program files\Analog Devices\SoundMAX\SoundTray.exe" [2007-05-21 49152]
"Ai Nap"="c:\program files\ASUS\AI Suite\AiNap\AiNap.exe" [2009-07-02 1435136]
"QFan Help"="c:\program files\ASUS\AI Suite\QFan3\QFanHelp.exe" [2009-07-02 601088]
"CPU Power Monitor"="c:\program files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe" [2008-01-09 627200]
"Cpu Level Up help"="c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2007-12-01 881152]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-06-06 1261568]

c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2008-6-5 157000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Exif Launcher S.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Exif Launcher S.lnk
backup=c:\windows\pss\Exif Launcher S.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-11-10 17:49 932288 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-11-10 17:49 35736 ----a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ai Nap]
2009-07-02 01:23 1435136 ----a-w- c:\program files\ASUS\AI Suite\AiNap\AiNap.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ContentTransferWMDetector.exe]
2008-07-11 22:51 423200 ----a-w- c:\program files\Sony\Content Transfer\ContentTransferWMDetector.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpu Level Up help]
2007-12-01 01:03 881152 ----a-w- c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPU Power Monitor]
2008-01-09 15:17 627200 ----a-w- c:\program files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
2007-05-04 06:40 312240 ----a-w- c:\program files\Lexmark Fax Solutions\fm3032.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 16:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxddamon]
2007-03-05 07:40 20480 ----a-w- c:\program files\Lexmark 2500 Series\lxddamon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxddmon.exe]
2007-05-04 06:38 291760 ----a-w- c:\program files\Lexmark 2500 Series\lxddmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 22:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2158934232-3957428742-2026527031-1000]
"EnableNotificationsRef"=dword:00000001

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 cpuz130;cpuz130;c:\users\User\AppData\Local\Temp\cpuz130\cpuz_x32.sys [x]
R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [x]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2008-05-06 11520]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R3 XDva195;XDva195;c:\windows\system32\XDva195.sys [x]
R4 lxddCATSCustConnectService;lxddCATSCustConnectService;c:\windows\system32\spool\DRIVERS\W32X86\3\\lxddserv.exe [2007-04-26 99248]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2011-01-19 22504]
S2 lxdd_device;lxdd_device;c:\windows\system32\lxddcoms.exe [2007-04-26 537520]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-08 378984]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2010-11-11 122984]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2011-02-27 c:\windows\Tasks\User_Feed_Synchronization-{333E1AB1-3355-44B5-899A-B6ABBB5D1C32}.job
- c:\windows\system32\msfeedssync.exe [2011-02-08 04:47]
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Se&nd to OneNote - d:\micros~1\Office14\ONBttnIE.dll/105
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/aol/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us&tb_uuid=100000000000000002&tb_oid=20-05-2010&tb_mrud=20-05-2010
FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4cc235f1&v=6.011.025.001&i=23&tp=ab&iy=&ychte=us&lng=en-US&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Move Media Player: moveplayer@movenetworks.com - %profile%\extensions\moveplayer@movenetworks.com
FF - Ext: Vista-aero: {07b2a769-ed19-4483-87ce-c643914c81bb} - %profile%\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Media Converter: {6e764c17-863a-450f-bdd0-6772bd5aaa18} - %profile%\extensions\{6e764c17-863a-450f-bdd0-6772bd5aaa18}
FF - Ext: Firefox Showcase: {89506680-e3f4-484c-a2c0-ed711d481eda} - %profile%\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
FF - Ext: SearchPreview: {EF522540-89F5-46b9-B6FE-1829E2B572C6} - %profile%\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false
FF - user.js: browser.sessionstore.resume_from_crash - false
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
.
- - - - ORPHANS REMOVED - - - -

BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-NWEReboot - (no file)
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Common Files\Java\Java Update\jusched.exe
AddRemove-Grand Theft Auto - d:\gta ii\Uninst.isu
AddRemove-{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB} - c:\program files\Common Files\BioWare\Uninstall Mass Effect 2.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-28 12:32
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2158934232-3957428742-2026527031-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:0c,d4,45,b8,3b,14,07,9f,1e,6e,ad,4f,5a,85,e6,b9,19,53,76,18,04,97,4b,
bc,9d,a9,82,c2,dc,e7,5c,51,2c,a5,0e,18,e0,b7,5c,3e,59,a4,be,21,d0,43,f7,a2,\
"??"=hex:e2,06,90,c3,a9,ab,f7,ca,1c,f7,63,d7,3e,f2,89,5d

[HKEY_USERS\S-1-5-21-2158934232-3957428742-2026527031-1000\Software\SecuROM\License information*]
"datasecu"=hex:83,de,4a,fb,7e,f2,23,63,72,10,a8,17,43,e0,79,db,c2,47,4c,3f,58,
ec,4a,4e,c3,68,6e,97,5e,84,f1,22,40,62,2d,f5,17,1b,bd,27,19,22,d3,a1,e4,4a,\
"rkeysecu"=hex:9e,75,97,ea,ba,23,ca,e1,69,94,3b,81,f2,05,06,08

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-02-28 12:34:08
ComboFix-quarantined-files.txt 2011-02-28 17:34

Pre-Run: 522,515,251,200 bytes free
Post-Run: 522,432,208,896 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,3,5
- - End Of File - - FDCBEA6FCC1BE8BAF1355844415D7CB4
 
Looks good now :)

How is computer doing?

Download OTL to your Desktop.

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click the Scan All Users checkbox.
  • Under the Custom Scan box paste this in:


netsvcs
drivers32
%SYSTEMDRIVE%\*.*
%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\Fonts\*.ini
%systemroot%\Fonts\*.ini2
%systemroot%\Fonts\*.exe
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.jpg
%systemroot%\*.jpg
%systemroot%\*.png
%systemroot%\*.scr
%systemroot%\*._sy
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%APPDATA%\Microsoft\*.*
%PROGRAMFILES%\*.*
%APPDATA%\Update\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\System32\config\*.sav
%PROGRAMFILES%\bak. /s
%systemroot%\system32\bak. /s
%ALLUSERSPROFILE%\Start Menu\*.lnk /x
%systemroot%\system32\config\systemprofile\*.dat /x
%systemroot%\*.config
%systemroot%\system32\*.db
%APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
%USERPROFILE%\Desktop\*.exe
%PROGRAMFILES%\Common Files\*.*
%systemroot%\*.src
%systemroot%\install\*.*
%systemroot%\system32\DLL\*.*
%systemroot%\system32\HelpFiles\*.*
%systemroot%\system32\rundll\*.*
%systemroot%\winn32\*.*
%systemroot%\Java\*.*
%systemroot%\system32\test\*.*
%systemroot%\system32\Rundll32\*.*
%systemroot%\AppPatch\Custom\*.*
%APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
%PROGRAMFILES%\PC-Doctor\Downloads\*.*
%PROGRAMFILES%\Internet Explorer\*.tmp
%PROGRAMFILES%\Internet Explorer\*.dat
%USERPROFILE%\My Documents\*.exe
%USERPROFILE%\*.exe
%systemroot%\ADDINS\*.*
%systemroot%\assembly\*.bak2
%systemroot%\Config\*.*
%systemroot%\REPAIR\*.bak2
%systemroot%\SECURITY\Database\*.sdb /x
%systemroot%\SYSTEM\*.bak2
%systemroot%\Web\*.bak2
%systemroot%\Driver Cache\*.*
%PROGRAMFILES%\Mozilla Firefox\0*.exe
%ProgramFiles%\Microsoft Common\*.*
%ProgramFiles%\TinyProxy.
%USERPROFILE%\Favorites\*.url /x
%systemroot%\system32\*.bk
%systemroot%\*.te
%systemroot%\system32\system32\*.*
%ALLUSERSPROFILE%\*.dat /x
%systemroot%\system32\drivers\*.rmv
dir /b "%systemroot%\system32\*.exe" | find /i " " /c
dir /b "%systemroot%\*.exe" | find /i " " /c
%PROGRAMFILES%\Microsoft\*.*
%systemroot%\System32\Wbem\proquota.exe
%PROGRAMFILES%\Mozilla Firefox\*.dat
%USERPROFILE%\Cookies\*.txt /x
%SystemRoot%\system32\fonts\*.*
%systemroot%\system32\winlog\*.*
%systemroot%\system32\Language\*.*
%systemroot%\system32\Settings\*.*
%systemroot%\system32\*.quo
%SYSTEMROOT%\AppPatch\*.exe
%SYSTEMROOT%\inf\*.exe
%SYSTEMROOT%\Installer\*.exe
%systemroot%\system32\config\*.bak2
%systemroot%\system32\Computers\*.*
%SystemRoot%\system32\Sound\*.*
%SystemRoot%\system32\SpecialImg\*.*
%SystemRoot%\system32\code\*.*
%SystemRoot%\system32\draft\*.*
%SystemRoot%\system32\MSSSys\*.*
%ProgramFiles%\Javascript\*.*
%systemroot%\pchealth\helpctr\System\*.exe /s
%systemroot%\Web\*.exe
%systemroot%\system32\msn\*.*
%systemroot%\system32\*.tro
%AppData%\Microsoft\Installer\msupdates\*.*
%ProgramFiles%\Messenger\*.*
%systemroot%\system32\systhem32\*.*
%systemroot%\system\*.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
/md5start
/md5stop


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
 
Thank for your time, sir. Well my pc is doing well, AVG free for now. So am i safe? I deleted my java 6 program since it was infected and I still have Trojan.Agent/Gen-Nullo in my quarantine section of SUPERAntiSpyware, its MSCONFIG.EXE located in

C:\Windows\winsxs\x86_microsoft-windows-msconfig-exe_31bf3856ad364e35_6.0.6001.18000_none_da7a3e839dc01091

is it safe to permanently delete it?

Logs coming up.
 
OTL:

OTL logfile created on: 2/28/2011 9:51:20 PM - Run 1
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Users\User\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 65.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 698.63 Gb Total Space | 486.40 Gb Free Space | 69.62% Space Free | Partition Type: NTFS
Drive D: | 111.79 Gb Total Space | 17.13 Gb Free Space | 15.32% Space Free | Partition Type: NTFS
Drive F: | 1863.01 Gb Total Space | 1556.11 Gb Free Space | 83.53% Space Free | Partition Type: NTFS

Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/28 21:48:34 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
PRC - [2011/02/24 19:33:04 | 001,242,448 | ---- | M] (Valve Corporation) -- F:\Steam\Steam.exe
PRC - [2011/02/18 14:05:46 | 002,423,752 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
PRC - [2011/01/07 21:06:12 | 000,803,432 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
PRC - [2011/01/07 19:48:56 | 000,378,984 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2010/11/09 15:08:58 | 000,146,000 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
PRC - [2010/10/14 20:09:30 | 000,451,152 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPointG\SetPointII.exe
PRC - [2009/07/01 20:23:52 | 001,435,136 | ---- | M] () -- C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
PRC - [2009/04/11 01:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/03/19 15:41:28 | 000,623,104 | ---- | M] () -- C:\Program Files\ASUS\AASP\1.00.91\aaCenter.exe
PRC - [2009/03/05 15:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2009/01/22 20:43:54 | 001,352,704 | ---- | M] () -- C:\Program Files\ASUS\AI Suite\EnergySaving\PwSave.exe
PRC - [2008/05/13 14:50:56 | 003,310,920 | ---- | M] (Webshots.com) -- C:\Program Files\Webshots\Webshots.scr
PRC - [2008/01/09 10:17:18 | 000,627,200 | ---- | M] () -- C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe
PRC - [2007/06/06 18:41:36 | 000,086,016 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AEADISRV.EXE
PRC - [2007/05/21 14:53:42 | 000,049,152 | ---- | M] (Sonic Focus, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SoundTray.exe
PRC - [2007/04/26 00:21:22 | 000,537,520 | ---- | M] ( ) -- C:\Windows\System32\lxddcoms.exe


========== Modules (SafeList) ==========

MOD - [2011/02/28 21:48:34 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
MOD - [2010/08/31 10:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (DAUpdaterSvc)
SRV - [2011/01/07 19:48:56 | 000,378,984 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2010/11/17 08:23:41 | 000,403,240 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/10/28 05:13:30 | 000,293,456 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2008/01/19 02:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/06/06 18:41:36 | 000,086,016 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AEADISRV.EXE -- (AEADIFilters)
SRV - [2007/04/26 00:21:42 | 000,099,248 | ---- | M] () [Disabled | Stopped] -- C:\Windows\System32\spool\DRIVERS\W32X86\3\\lxddserv.exe -- (lxddCATSCustConnectService)
SRV - [2007/04/26 00:21:22 | 000,537,520 | ---- | M] ( ) [Auto | Running] -- C:\Windows\System32\lxddcoms.exe -- (lxdd_device)


========== Driver Services (SafeList) ==========

DRV - [2011/01/19 17:47:12 | 000,022,504 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\cpuz135_x32.sys -- (cpuz135)
DRV - [2011/01/07 22:27:00 | 010,467,656 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2010/11/11 18:10:50 | 000,122,984 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
DRV - [2010/08/24 12:31:02 | 000,037,328 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2010/08/24 12:30:52 | 000,038,864 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2010/05/10 13:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/02/17 13:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2009/07/28 14:50:42 | 000,281,760 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2009/07/28 14:50:42 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2008/12/18 22:43:06 | 000,020,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV - [2008/05/06 16:06:00 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\wdcsam.sys -- (WDC_SAM)
DRV - [2007/12/17 17:14:06 | 000,012,400 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\AsIO.sys -- (AsIO)
DRV - [2006/10/18 00:44:48 | 000,007,680 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2006/09/24 08:28:46 | 000,005,248 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Boot | Running] -- C:\Windows\system32\speedfan.sys -- (speedfan)
DRV - [2005/08/17 07:47:48 | 000,073,696 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdserd.sys -- (sscdserd) SAMSUNG CDMA Modem Diagnostic Serial Port (WDM)
DRV - [2005/08/17 07:46:26 | 000,093,872 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2005/08/17 07:46:20 | 000,008,272 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2005/08/17 07:45:00 | 000,058,352 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM)
DRV - [1996/04/03 14:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\system32\giveio.sys -- (giveio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 89 A7 EE 71 A0 D7 CB 01 [binary data]
IE - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.defaulturl: "http://aim.search.aol.com/aol/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us&tb_uuid=100000000000000002&tb_oid=20-05-2010&tb_mrud=20-05-2010"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {89506680-e3f4-484c-a2c0-ed711d481eda}:0.9.5.6
FF - prefs.js..extensions.enabledItems: {6e764c17-863a-450f-bdd0-6772bd5aaa18}:1.0.3
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000006
FF - prefs.js..extensions.enabledItems: {EF522540-89F5-46b9-B6FE-1829E2B572C6}:4.9.4
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.6.1
FF - prefs.js..extensions.enabledItems: DeviceDetection@logitech.com:1.20.0.66
FF - prefs.js..extensions.enabledItems: {07b2a769-ed19-4483-87ce-c643914c81bb}:3.0.0.91
FF - prefs.js..keyword.URL: "http://search.avg.com/route/?d=4cc235f1&v=6.011.025.001&i=23&tp=ab&iy=&ychte=us&lng=en-US&q="


FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/01/26 22:28:51 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/02/09 17:14:56 | 000,000,000 | ---D | M]

[2008/06/12 17:55:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Extensions
[2011/02/28 11:05:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\extensions
[2010/05/27 20:09:49 | 000,000,000 | ---D | M] (Vista-aero) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}
[2010/05/11 11:01:14 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/04/07 19:09:52 | 000,000,000 | ---D | M] (Media Converter) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\extensions\{6e764c17-863a-450f-bdd0-6772bd5aaa18}
[2010/10/28 18:35:07 | 000,000,000 | ---D | M] (Firefox Showcase) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
[2010/11/11 17:49:17 | 000,000,000 | ---D | M] (SearchPreview) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
[2010/10/28 18:35:07 | 000,000,000 | ---D | M] (Разпознаване на устройство Logitech) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\extensions\DeviceDetection@logitech.com
[2009/03/18 21:39:35 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\extensions\moveplayer@movenetworks.com
[2010/09/17 17:15:55 | 000,000,000 | ---D | M] (Personas) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\extensions\personas@christopher.beard
[2010/05/27 20:09:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}\chrome\mozapps\extensions
[2009/01/22 17:28:49 | 000,001,739 | ---- | M] () -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\searchplugins\aim-search.xml
[2009/06/07 19:04:32 | 000,002,190 | ---- | M] () -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\searchplugins\hulu.xml
[2010/05/20 20:26:48 | 000,001,705 | ---- | M] () -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\searchplugins\shmoop.xml
[2011/02/27 15:13:06 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/11/23 19:17:26 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/03/09 18:17:25 | 000,221,184 | ---- | M] (CNN) -- C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll
[2007/04/16 12:07:12 | 000,180,293 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll

O1 HOSTS File: ([2011/02/28 12:32:25 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found.
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O3 - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O4 - HKLM..\Run: [Ai Nap] C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe ()
O4 - HKLM..\Run: [Cpu Level Up help] C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe ()
O4 - HKLM..\Run: [CPU Power Monitor] C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe ()
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [QFan Help] C:\Program Files\ASUS\AI Suite\QFan3\QFanHelp.exe ()
O4 - HKLM..\Run: [SoundTray] C:\Program Files\Analog Devices\SoundMAX\SoundTray.exe (Sonic Focus, Inc.)
O4 - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Webshots.lnk = C:\Program Files\Webshots\Launcher.exe (Webshots.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
 
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 157
O7 - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.18.47.61 209.18.47.62
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\User\AppData\Roaming\Webshots\The Webshots Desktop\Webshots Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Users\User\AppData\Roaming\Webshots\The Webshots Desktop\Webshots Wallpaper.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.ac3acm - C:\Windows\System32\AC3ACM.acm (fccHandler)
Drivers32: msacm.alf2cd - C:\Windows\System32\alf2cd.acm (NCT Company)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\Windows\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.scg726 - C:\Windows\System32\Scg726.acm (SHARP Corporation)
Drivers32: msacm.voxacm160 - C:\Windows\System32\vct3216.acm (Voxware, Inc.)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.dvsd - C:\Windows\System32\mcdvd_32.dll (MainConcept)
Drivers32: VIDC.FPS1 - C:\Windows\System32\frapsvid.dll (Beepa P/L)
Drivers32: VIDC.I420 - lvcodec2.dll File not found
Drivers32: vidc.iv31 - C:\Windows\System32\ir32_32.dll (Intel(R) Corporation)
Drivers32: vidc.iv32 - C:\Windows\System32\ir32_32.dll (Intel(R) Corporation)
Drivers32: vidc.iv41 - C:\Windows\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.XFR1 - C:\Windows\System32\xfcodec.dll ()
Drivers32: vidc.xvid - C:\Windows\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/02/28 21:48:30 | 000,581,120 | ---- | C] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
[2011/02/28 18:38:21 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011/02/28 12:34:11 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/02/28 12:34:09 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/02/28 12:34:09 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\temp
[2011/02/28 12:26:17 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/02/28 12:26:17 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/02/28 12:26:17 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/02/28 12:26:13 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/02/28 12:26:04 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/02/28 12:25:49 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2011/02/27 22:19:25 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\New Folder
[2011/02/27 21:29:33 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\SUPERAntiSpyware.com
[2011/02/27 21:29:33 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011/02/27 21:29:30 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011/02/27 21:29:29 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2011/02/27 20:41:57 | 000,000,000 | ---D | C] -- C:\avrescue
[2011/02/27 18:14:43 | 000,000,000 | ---D | C] -- C:\Windows\en
[2011/02/27 18:09:22 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE
[2011/02/27 18:06:16 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
[2011/02/27 18:01:32 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition
[2011/02/27 17:49:04 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
[2011/02/27 17:46:39 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft
[2011/02/27 17:42:13 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Windows Live
[2011/02/27 17:42:11 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
[2011/02/27 12:21:32 | 000,000,000 | -H-D | C] -- C:\Windows\PIF
[2011/02/24 20:21:20 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011/02/24 19:48:52 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\puzzle quest
[2011/02/23 10:49:01 | 000,000,000 | ---D | C] -- C:\Windows\System32\WindowsPowerShell
[2011/02/20 11:23:42 | 000,022,504 | ---- | C] (CPUID) -- C:\Windows\System32\drivers\cpuz135_x32.sys
[2011/02/20 11:23:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
[2011/02/19 11:43:29 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2011/02/19 11:43:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan
[2011/02/16 20:22:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIM
[2011/02/16 20:22:36 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Software Update Utility
[2011/02/15 20:59:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
[2011/02/09 22:16:05 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA%
[2011/02/09 17:16:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011/02/09 17:14:49 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2011/02/09 17:14:34 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio
[2011/02/09 17:14:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2011/02/09 17:14:14 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2011/02/09 17:12:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2005
[2011/02/09 17:12:32 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 8
[2011/02/09 17:11:46 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2011/02/08 21:46:06 | 000,000,000 | R--D | C] -- C:\MSOCache
[2011/02/06 18:46:17 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Download Manager
[2011/02/06 17:15:10 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Microsoft Help
[2011/02/06 17:15:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2011/02/06 15:10:12 | 000,000,000 | ---D | C] -- C:\ProgramData\VirtualizedApplications
[2011/02/06 13:25:57 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft XNA
[2011/02/06 12:57:50 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\SoftGrid Client
[2011/02/06 12:57:06 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\SoftGrid Client
[2011/02/06 12:52:53 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\TP
[2011/02/01 21:28:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2011/02/01 21:08:38 | 000,057,960 | ---- | C] (Khronos Group) -- C:\Windows\System32\OpenCL.dll
[2008/06/05 12:01:21 | 000,413,696 | ---- | C] ( ) -- C:\Windows\System32\lxddinpa.dll
[2008/06/05 12:01:21 | 000,397,312 | ---- | C] ( ) -- C:\Windows\System32\lxddiesc.dll
[2008/06/05 12:01:21 | 000,323,584 | ---- | C] ( ) -- C:\Windows\System32\LXDDhcp.dll
[2008/06/05 12:01:20 | 001,232,896 | ---- | C] ( ) -- C:\Windows\System32\lxddserv.dll
[2008/06/05 12:01:20 | 000,999,424 | ---- | C] ( ) -- C:\Windows\System32\lxddusb1.dll
[2008/06/05 12:01:20 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\lxddpmui.dll
[2008/06/05 12:01:20 | 000,585,728 | ---- | C] ( ) -- C:\Windows\System32\lxddlmpm.dll
[2008/06/05 12:01:20 | 000,163,840 | ---- | C] ( ) -- C:\Windows\System32\lxddprox.dll
[2008/06/05 12:01:20 | 000,094,208 | ---- | C] ( ) -- C:\Windows\System32\lxddpplc.dll
[2008/06/05 12:01:19 | 000,700,416 | ---- | C] ( ) -- C:\Windows\System32\lxddhbn3.dll
[2008/06/05 12:01:19 | 000,385,968 | ---- | C] ( ) -- C:\Windows\System32\lxddih.exe
[2008/06/05 12:01:18 | 000,684,032 | ---- | C] ( ) -- C:\Windows\System32\lxddcomc.dll
[2008/06/05 12:01:18 | 000,537,520 | ---- | C] ( ) -- C:\Windows\System32\lxddcoms.exe
[2008/06/05 12:01:18 | 000,425,984 | ---- | C] ( ) -- C:\Windows\System32\lxddcomm.dll
[2008/06/05 12:01:18 | 000,394,160 | ---- | C] ( ) -- C:\Windows\System32\lxddcfg.exe
[8 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[7 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/02/28 21:48:34 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
[2011/02/28 21:43:37 | 000,004,576 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/28 21:43:37 | 000,004,576 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/28 18:28:40 | 000,024,800 | ---- | M] () -- C:\Users\User\Documents\Essay 1.odt
[2011/02/28 18:14:02 | 000,018,894 | ---- | M] () -- C:\Users\User\Documents\Reader Response #2.odt
[2011/02/28 18:02:14 | 000,000,416 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{333E1AB1-3355-44B5-899A-B6ABBB5D1C32}.job
[2011/02/28 17:50:07 | 020,513,694 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/02/28 17:50:07 | 007,155,372 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/02/28 17:43:34 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/02/28 17:43:25 | 3755,102,208 | -HS- | M] () -- C:\hiberfil.sys
[2011/02/28 12:32:25 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011/02/28 10:49:02 | 000,000,000 | ---- | M] () -- C:\Users\User\AppData\Local\prvlcl.dat
[2011/02/28 10:44:45 | 000,002,339 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2011/02/27 21:29:31 | 000,001,760 | ---- | M] () -- C:\Users\User\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/02/27 21:12:45 | 000,384,624 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/02/26 15:26:48 | 000,022,232 | ---- | M] () -- C:\Users\User\Documents\Flower For Algernon.odt
[2011/02/25 15:24:48 | 000,017,186 | ---- | M] () -- C:\Users\User\Documents\Letter from the Trenches.odt
[2011/02/24 20:21:21 | 000,000,764 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011/02/24 20:19:09 | 000,430,659 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20110227-164736.backup
[2011/02/24 20:08:59 | 000,000,501 | ---- | M] () -- C:\Users\User\Desktop\Steam.lnk
[2011/02/23 16:13:58 | 001,170,298 | ---- | M] () -- C:\Users\User\Documents\Trench Warfare.odt
[2011/02/20 11:23:42 | 000,000,565 | ---- | M] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk
[2011/02/19 15:42:49 | 000,020,353 | ---- | M] () -- C:\Users\User\Documents\Endocrine System.odt
[2011/02/19 12:30:03 | 000,019,598 | ---- | M] () -- C:\Users\User\Documents\PRINCIPLES OF SELLING PRESENTATION.odt
[2011/02/19 11:43:29 | 000,000,510 | ---- | M] () -- C:\Users\User\Desktop\SpeedFan.lnk
[2011/02/19 11:43:29 | 000,000,045 | ---- | M] () -- C:\Windows\System32\initdebug.nfo
[2011/02/18 21:31:03 | 000,169,774 | ---- | M] () -- C:\Users\User\Documents\Euclid Essay.odt
[2011/02/18 20:22:02 | 000,056,626 | ---- | M] () -- C:\Users\User\Documents\Pascal Triangle Patterns.odt
[2011/02/18 20:21:58 | 000,011,059 | ---- | M] () -- C:\Users\User\Documents\Odd And Even.odt
[2011/02/16 20:22:42 | 000,001,119 | -H-- | M] () -- C:\IPH.PH
[2011/02/16 20:22:41 | 000,001,678 | ---- | M] () -- C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\AIM.lnk
[2011/02/16 20:22:40 | 000,001,654 | ---- | M] () -- C:\Users\Public\Desktop\AIM.lnk
[2011/02/16 18:57:59 | 000,018,394 | ---- | M] () -- C:\Users\User\Documents\ELA paper # 1 1st draft.odt
[2011/02/09 18:05:39 | 000,430,425 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20110224-201909.backup
[2011/02/09 12:38:05 | 000,018,001 | ---- | M] () -- C:\Users\User\Documents\Essay Proposal.odt
[2011/02/07 18:14:08 | 000,019,348 | ---- | M] () -- C:\Users\User\Documents\English Reader Response 1.odt
[2011/02/05 22:40:43 | 000,039,936 | ---- | M] () -- C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/05 21:51:58 | 000,000,000 | ---- | M] () -- C:\Users\User\AppData\Roaming\AVSDVDPlayer.m3u
[2011/02/04 16:58:33 | 000,430,293 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20110209-180539.backup
[2011/02/02 18:49:11 | 000,022,328 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011/02/02 18:49:11 | 000,022,328 | ---- | M] () -- C:\Users\User\AppData\Roaming\PnkBstrK.sys
[2011/02/02 18:48:54 | 000,103,736 | ---- | M] () -- C:\Windows\System32\PnkBstrB.ex0
[2011/02/02 18:48:53 | 000,669,184 | ---- | M] () -- C:\Windows\System32\pbsvc.exe
[2011/02/02 14:23:17 | 000,270,904 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr
[2011/02/01 21:06:43 | 000,002,032 | ---- | M] () -- C:\Users\User\AppData\Local\d3d9caps.dat
[8 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[7 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/28 12:39:49 | 000,018,894 | ---- | C] () -- C:\Users\User\Documents\Reader Response #2.odt
[2011/02/28 12:26:17 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011/02/28 12:26:17 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/02/28 12:26:17 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
[2011/02/28 12:26:17 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/02/28 12:26:17 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/02/27 21:29:31 | 000,001,760 | ---- | C] () -- C:\Users\User\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/02/27 18:05:27 | 000,001,118 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2011/02/27 18:03:08 | 000,001,187 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2011/02/27 17:59:28 | 000,000,997 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2011/02/27 17:57:08 | 000,001,985 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2011/02/26 14:42:57 | 000,022,232 | ---- | C] () -- C:\Users\User\Documents\Flower For Algernon.odt
[2011/02/25 15:24:46 | 000,017,186 | ---- | C] () -- C:\Users\User\Documents\Letter from the Trenches.odt
[2011/02/24 20:21:21 | 000,000,764 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2011/02/24 20:09:00 | 000,000,501 | ---- | C] () -- C:\Users\User\Desktop\Steam.lnk
[2011/02/23 16:13:57 | 001,170,298 | ---- | C] () -- C:\Users\User\Documents\Trench Warfare.odt
[2011/02/23 10:47:02 | 000,201,184 | ---- | C] () -- C:\Windows\System32\winrm.vbs
[2011/02/23 10:47:02 | 000,004,675 | ---- | C] () -- C:\Windows\System32\wsmanconfig_schema.xml
[2011/02/23 10:47:02 | 000,002,426 | ---- | C] () -- C:\Windows\System32\WsmTxt.xsl
[2011/02/20 11:23:42 | 000,000,565 | ---- | C] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk
[2011/02/19 15:00:32 | 000,020,353 | ---- | C] () -- C:\Users\User\Documents\Endocrine System.odt
[2011/02/19 12:07:36 | 000,019,598 | ---- | C] () -- C:\Users\User\Documents\PRINCIPLES OF SELLING PRESENTATION.odt
[2011/02/19 11:43:29 | 000,000,510 | ---- | C] () -- C:\Users\User\Desktop\SpeedFan.lnk
[2011/02/19 11:43:00 | 000,000,045 | ---- | C] () -- C:\Windows\System32\initdebug.nfo
[2011/02/18 21:26:28 | 000,169,774 | ---- | C] () -- C:\Users\User\Documents\Euclid Essay.odt
[2011/02/18 20:21:54 | 000,011,059 | ---- | C] () -- C:\Users\User\Documents\Odd And Even.odt
[2011/02/16 16:22:15 | 000,056,626 | ---- | C] () -- C:\Users\User\Documents\Pascal Triangle Patterns.odt
[2011/02/15 20:59:37 | 000,012,400 | ---- | C] () -- C:\Windows\System32\drivers\AsIO.sys
[2011/02/15 20:59:33 | 000,011,832 | ---- | C] () -- C:\Windows\System32\drivers\AsInsHelp64.sys
[2011/02/15 20:59:33 | 000,010,216 | ---- | C] () -- C:\Windows\System32\drivers\AsInsHelp32.sys
[2011/02/15 20:51:50 | 000,000,000 | ---- | C] () -- C:\Users\User\AppData\Local\prvlcl.dat
[2011/02/14 18:25:30 | 000,018,394 | ---- | C] () -- C:\Users\User\Documents\ELA paper # 1 1st draft.odt
[2011/02/09 12:36:49 | 000,024,800 | ---- | C] () -- C:\Users\User\Documents\Essay 1.odt
[2011/02/09 12:22:37 | 000,018,001 | ---- | C] () -- C:\Users\User\Documents\Essay Proposal.odt
[2011/02/07 12:51:41 | 000,019,348 | ---- | C] () -- C:\Users\User\Documents\English Reader Response 1.odt
[2011/02/01 21:27:29 | 3755,102,208 | -HS- | C] () -- C:\hiberfil.sys
[2011/02/01 21:08:38 | 000,004,756 | ---- | C] () -- C:\Windows\System32\nvinfo.pb
[2011/02/01 17:20:32 | 000,000,782 | ---- | C] () -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Webshots.lnk
[2010/10/14 01:36:44 | 000,179,263 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2010/02/07 18:07:07 | 000,000,056 | ---- | C] () -- C:\Windows\VideoConvert.INI
[2010/02/04 21:02:12 | 002,434,856 | ---- | C] () -- C:\Windows\System32\pbsvc_bc2.exe
[2009/09/03 13:07:10 | 000,041,872 | ---- | C] () -- C:\Windows\System32\xfcodec.dll
[2009/06/19 14:01:09 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/06/19 14:01:09 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2008/11/28 20:00:32 | 000,000,262 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2008/09/24 15:18:49 | 000,281,760 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2008/09/24 15:18:49 | 000,025,888 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2008/07/26 11:07:48 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/06/18 21:40:00 | 000,036,120 | ---- | C] () -- C:\Windows\System32\SpoonUninstall-dBpowerAMP Music Converter.dat
[2008/06/18 21:39:59 | 000,131,072 | ---- | C] () -- C:\Windows\System32\SpoonUninstall.exe
[2008/06/13 16:33:42 | 000,000,136 | ---- | C] () -- C:\Windows\System32\cpuz.ini
[2008/06/10 11:13:25 | 000,000,016 | ---- | C] () -- C:\Windows\popcinfo.dat
[2008/06/08 21:29:28 | 000,039,936 | ---- | C] () -- C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/06/07 14:12:25 | 000,000,092 | ---- | C] () -- C:\Users\User\AppData\Local\fusioncache.dat
[2008/06/07 14:06:06 | 000,669,184 | ---- | C] () -- C:\Windows\System32\pbsvc.exe
[2008/06/07 13:17:09 | 000,022,328 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2008/06/07 13:17:09 | 000,022,328 | ---- | C] () -- C:\Users\User\AppData\Roaming\PnkBstrK.sys
[2008/06/07 13:16:52 | 000,103,736 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2008/06/07 13:16:51 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2008/06/07 13:16:49 | 000,000,319 | ---- | C] () -- C:\Windows\game.ini
[2008/06/06 21:02:11 | 000,000,023 | ---- | C] () -- C:\Windows\BlendSettings.ini
[2008/06/05 22:56:28 | 000,000,000 | ---- | C] () -- C:\Users\User\AppData\Roaming\AVSDVDPlayer.m3u
[2008/06/05 20:30:56 | 000,007,224 | ---- | C] () -- C:\ProgramData\lxdd
[2008/06/05 18:42:42 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2008/06/05 15:18:26 | 000,000,264 | ---- | C] () -- C:\Windows\_delis32.ini
[2008/06/05 14:01:32 | 000,001,160 | ---- | C] () -- C:\Windows\mozver.dat
[2008/06/05 13:21:11 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2008/06/05 12:04:41 | 000,344,064 | ---- | C] () -- C:\Windows\System32\lxddcoin.dll
[2008/06/05 12:03:04 | 000,045,056 | ---- | C] () -- C:\Windows\System32\LXF3PMON.DLL
[2008/06/05 12:03:04 | 000,032,768 | ---- | C] () -- C:\Windows\System32\LXF3FXPU.DLL
[2008/06/05 12:02:44 | 000,036,864 | ---- | C] () -- C:\Windows\System32\lxf3oem.dll
[2008/06/05 12:02:44 | 000,012,288 | ---- | C] () -- C:\Windows\System32\LXF3PMRC.DLL
[2008/06/05 12:01:51 | 000,000,044 | ---- | C] () -- C:\Windows\System32\lxddrwrd.ini
[2008/06/05 12:01:21 | 000,286,720 | ---- | C] () -- C:\Windows\System32\LXDDinst.dll
[2008/06/05 12:01:19 | 000,208,896 | ---- | C] () -- C:\Windows\System32\lxddgrd.dll
[2008/06/04 15:26:10 | 000,139,264 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2008/06/04 14:25:16 | 000,025,982 | ---- | C] () -- C:\Windows\Ascd_log.ini
[2008/06/04 14:24:59 | 000,024,576 | ---- | C] () -- C:\Windows\System32\AsIO.dll
[2008/06/04 14:21:35 | 000,007,680 | ---- | C] () -- C:\Windows\System32\drivers\ASACPI.sys
[2008/06/04 14:21:34 | 000,025,944 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2008/06/04 14:21:28 | 000,012,536 | ---- | C] () -- C:\Windows\System32\drivers\ASUSHWIO.SYS
[2008/06/04 14:18:40 | 000,002,032 | ---- | C] () -- C:\Users\User\AppData\Local\d3d9caps.dat
[2008/05/22 17:22:18 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2008/05/22 17:18:54 | 000,012,288 | ---- | C] () -- C:\Windows\System32\DivXWMPExtType.dll
[2007/01/23 13:40:03 | 000,065,536 | ---- | C] () -- C:\Windows\System32\lxddcaps.dll
[2007/01/09 11:13:08 | 000,692,224 | ---- | C] () -- C:\Windows\System32\lxdddrs.dll
[2006/11/02 07:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 07:47:37 | 000,384,624 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 07:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 05:33:01 | 020,513,694 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 05:33:01 | 007,155,372 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 05:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 05:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 05:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 03:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 03:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 02:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 02:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006/10/06 12:08:04 | 000,069,632 | ---- | C] () -- C:\Windows\System32\lxddcnv4.dll
[2006/05/17 21:47:12 | 000,040,960 | ---- | C] () -- C:\Windows\System32\lxddvs.dll
[2003/09/23 07:14:42 | 001,099,264 | ---- | C] () -- C:\Windows\System32\cygxml2-2.dll
[2003/08/10 09:59:20 | 000,980,992 | ---- | C] () -- C:\Windows\System32\cygiconv-2.dll
[2003/08/08 19:28:16 | 000,061,440 | ---- | C] () -- C:\Windows\System32\cygz.dll
[1999/01/27 13:39:06 | 000,065,024 | ---- | C] () -- C:\Windows\System32\indounin.dll
[1997/06/13 07:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\System32\Iyvu9_32.dll
[1996/04/03 14:33:26 | 000,005,248 | ---- | C] () -- C:\Windows\System32\giveio.sys

========== LOP Check ==========

[2010/07/05 19:55:59 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\2K Sports
[2009/01/22 17:28:14 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\acccore
[2010/02/09 20:06:27 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\AnvSoft
[2010/02/19 13:44:28 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Aura4You
[2009/10/16 20:37:17 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\AVG9
[2008/07/24 14:55:59 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Bioshock
[2010/07/15 19:03:40 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Bioshock2
[2009/12/23 19:49:34 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Braid
[2009/06/25 20:57:16 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Dark Sector
[2010/12/31 11:49:18 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\FUJIFILM
[2008/06/05 19:25:50 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Gadu-Gadu
[2011/01/29 11:36:31 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\HandBrake
[2010/01/19 21:00:54 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\IObit
[2008/06/05 13:24:26 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\iWin
[2010/02/27 12:15:02 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Leadertech
[2010/02/19 13:36:15 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Leawo
[2008/06/05 12:06:28 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Lexmark Productivity Studio
[2009/03/02 20:46:47 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\NetMeter
[2011/02/06 19:57:35 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\SoftGrid Client
[2010/08/30 19:03:36 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Teleca
[2008/06/04 14:23:48 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TMP
[2011/02/06 17:59:16 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TP
[2010/08/14 18:11:45 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TS3Client
[2010/05/15 11:58:46 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Ubisoft
[2008/06/05 14:23:55 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Webshots
[2008/09/25 18:34:27 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\XRay Engine
[2010/12/16 20:43:05 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\ZombieDriver
[2011/02/28 16:50:04 | 000,032,550 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/02/28 18:02:14 | 000,000,416 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{333E1AB1-3355-44B5-899A-B6ABBB5D1C32}.job

========== Purity Check ==========



========== Custom Scans ==========


< >

< >

< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () -- C:\bootmgr
[2008/06/04 17:10:55 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
[2006/09/18 16:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
[2008/06/05 15:18:21 | 000,000,000 | ---- | M] () -- C:\Debug.QC6
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | ---- | M] () -- C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | ---- | M] () -- C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | ---- | M] () -- C:\globdata.ini
[2011/02/28 17:43:25 | 3755,102,208 | -HS- | M] () -- C:\hiberfil.sys
[2007/11/07 08:00:40 | 000,000,843 | ---- | M] () -- C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | ---- | M] (Microsoft Corporation) -- C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | ---- | M] (Microsoft Corporation) -- C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | ---- | M] (Microsoft Corporation) -- C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | ---- | M] (Microsoft Corporation) -- C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | ---- | M] (Microsoft Corporation) -- C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | ---- | M] (Microsoft Corporation) -- C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | ---- | M] (Microsoft Corporation) -- C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.3082.dll
[2009/03/22 20:43:33 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2011/02/16 20:22:42 | 000,001,119 | -H-- | M] () -- C:\IPH.PH
[2009/03/22 20:43:33 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2011/02/28 17:43:23 | 4070,760,448 | -HS- | M] () -- C:\pagefile.sys
[2007/11/07 08:00:40 | 000,005,686 | ---- | M] () -- C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | ---- | M] () -- C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | ---- | M] () -- C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/11/02 07:37:12 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 07:37:12 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 07:37:12 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/06/19 14:07:11 | 000,037,665 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 16:37:34 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 07:35:48 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2007/02/26 23:16:25 | 000,103,936 | ---- | M] () -- C:\Windows\System32\spool\prtprocs\w32x86\lxdddrpp.dll
[2006/10/26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
[7 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/06/08 13:55:10 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/11/02 05:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 05:34:05 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 05:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/10/20 20:15:13 | 000,000,339 | -HS- | M] () -- C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/01/26 09:27:52 | 000,908,128 | ---- | M] (techPowerUp (www.techpowerup.com)) -- C:\Users\User\Desktop\GPU-Z.0.5.1.exe
[2011/02/28 21:48:34 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2008/06/05 17:58:39 | 000,000,402 | -HS- | M] () -- C:\Users\User\Favorites\desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >
[2011/01/19 16:16:29 | 000,007,224 | ---- | M] () -- C:\ProgramData\lxdd

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< %systemroot%\system32\winlog\*.* >

< %systemroot%\system32\Language\*.* >

< %systemroot%\system32\Settings\*.* >

< %systemroot%\system32\*.quo >

< %SYSTEMROOT%\AppPatch\*.exe >

< %SYSTEMROOT%\inf\*.exe >

< %SYSTEMROOT%\Installer\*.exe >

< %systemroot%\system32\config\*.bak2 >

< %systemroot%\system32\Computers\*.* >

< %SystemRoot%\system32\Sound\*.* >

< %SystemRoot%\system32\SpecialImg\*.* >

< %SystemRoot%\system32\code\*.* >

< %SystemRoot%\system32\draft\*.* >

< %SystemRoot%\system32\MSSSys\*.* >

< %ProgramFiles%\Javascript\*.* >

< %systemroot%\pchealth\helpctr\System\*.exe /s >

< %systemroot%\Web\*.exe >

< %systemroot%\system32\msn\*.* >

< %systemroot%\system32\*.tro >

< %AppData%\Microsoft\Installer\msupdates\*.* >

< %ProgramFiles%\Messenger\*.* >

< %systemroot%\system32\systhem32\*.* >

< %systemroot%\system\*.exe >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >


========== Alternate Data Streams ==========

@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:5C321E34
@Alternate Data Stream - 508 bytes -> C:\ProgramData\TEMP:05EE1EEF
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:AC6124CA

< End of report >
 
OTL Extras logfile created on: 2/28/2011 9:51:20 PM - Run 1
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Users\User\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 65.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 698.63 Gb Total Space | 486.40 Gb Free Space | 69.62% Space Free | Partition Type: NTFS
Drive D: | 111.79 Gb Total Space | 17.13 Gb Free Space | 15.32% Space Free | Partition Type: NTFS
Drive F: | 1863.01 Gb Total Space | 1556.11 Gb Free Space | 83.53% Space Free | Partition Type: NTFS

Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2158934232-3957428742-2026527031-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "D:\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "D:\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-2158934232-3957428742-2026527031-1000]
"EnableNotifications" = 0
"EnableNotificationsRef" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 1
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{2B02ADD1-3182-496F-85A9-6B19CB1DECAC}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{540EBAD4-3204-4F0F-AFFE-1CD9EBCE1291}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{E282B796-485C-4987-9AD9-6E83D24F4EB4}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{003AC244-DCC0-4E51-AD91-A9B30423D3CD}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\fear2\fear2.exe |
"{003C9592-CB13-46FD-AF04-346C0CF1FEBA}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\lxddmon.exe |
"{004B4D73-ED51-4334-9BD7-0F205AC1508C}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\puzzle quest\puzzle quest.exe |
"{0157CD7C-E77B-4DD0-91ED-8CE2764A4267}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez - bound in blood\cojbibgame_x86.exe |
"{01F267EF-558C-4B28-AC89-5F023430B012}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe |
"{04364725-0C75-46C7-83E0-A9DBCFF50168}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\swarm.exe |
"{05C19064-36B9-416A-A664-864AB3CD83B1}" = protocol=17 | dir=in | app=c:\program files\eidos\batman arkham asylum\binaries\shippingpc-bmgame.exe |
"{05D59025-EF5C-482E-9825-FB4A95E3A68F}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{07AB361D-77DB-4172-92B5-5FFC1E435299}" = protocol=6 | dir=in | app=c:\program files\sierra entertainment\world in conflict\wic_ds.exe |
"{0856D5B7-70D9-4F2F-ADFB-19085DA9C512}" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysis.exe |
"{088032EF-278F-4DBA-86D6-17F460D7ABFC}" = protocol=17 | dir=in | app=c:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\dedicated\xrengine.exe |
"{097E1D1D-ABEB-4681-A60E-619DF3D98057}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{09B6B20C-A012-43CA-AE84-045120D72BB1}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\metro 2033\metro2033.exe |
"{09C3866B-8BBF-4644-BCBD-97C286249F24}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\world of goo\worldofgoo.exe |
"{09C86618-750A-44B4-B154-437444831850}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\nba 2k10\nba2k10.exe |
"{0B3D06AA-8BC1-4694-90E9-0EE9ABE97B4A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord\config.exe |
"{0C0C6772-5DE8-43A6-AD9E-01CBD066AE4C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
"{0C49038D-B9E6-4AD3-A657-43AD706CBF04}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{0CBC3BC8-8A15-4D18-AA1B-8717DBDD666D}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{0F37EE85-2128-453D-9C95-1221601F9113}" = protocol=6 | dir=in | app=c:\program files\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{0F652132-7D25-4388-97B5-05404DA940A3}" = protocol=17 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutparadise.exe |
"{0F8B1EF6-F9B5-4BC1-8776-665819B98470}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dead rising 2\deadrising2.exe |
"{0FC76C2B-F33E-4762-A990-C1C6EF4CA6EC}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\street fighter iv\sf4launcher.exe |
"{10A96A7D-7BAC-4EA2-A621-C48535C6F7D3}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\lost planet 2\launcher.exe |
"{10B6FD05-18B5-46F1-BF51-EAA9FCEB9711}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddtime.exe |
"{11A22D60-30BB-4215-9A10-83468BD23CF1}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\kane & lynch 2 - dog days\kl2.exe |
"{124C2B14-C1D3-4F11-A6EB-0CE39138F832}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
"{12E36C7C-EFB3-42AD-830C-1C59B72B70FB}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{13041940-296D-4FD2-B5CA-C65161573C83}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\stranger's wrath\launcher.exe |
"{13145265-EB83-4F42-9AE2-9E0CACA979AD}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\darksiders\darksiderspc.exe |
"{143CAC2C-FCE2-4C8E-A76D-0929665EE1A5}" = protocol=6 | dir=in | app=c:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe |
"{1472AF1D-16C5-4F45-9E80-5D344ED3C654}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\brothers in arms hells highway\binaries\biahh.exe |
"{14D25EB3-C4A4-4DAD-9E57-69D586BB1CFF}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{151004D6-9CBA-4FDF-974E-5996C57D286E}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\just cause 2\justcause2.exe |
"{15ACBD81-3056-4E4E-8730-124C58C36324}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of juarez\chromed.exe |
"{15CCADE5-C333-46AC-BDA9-932850EB5881}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mafia ii\pc\mafia2.exe |
"{15DE9095-A362-4258-A368-24D25091734C}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
"{16911EA1-E82C-4503-AF3D-67B1CB5FCA4C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe |
"{178E97B8-8DFF-45F4-8B72-BBC03B1E661C}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\support\ea help\electronic_arts_technical_support.htm |
"{181C7C26-F338-46AE-8F36-7A68BAC00012}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
"{182CC714-3218-49F4-9259-504BFA1610FC}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{195B3CD4-3475-4E24-89EC-C45C496FE489}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{1A1634F8-419A-4086-B816-334698054684}" = protocol=17 | dir=in | app=c:\program files\ea games\mirror's edge\binaries\mirrorsedge.exe |
"{1A24F262-04C1-4BA6-9946-E75356C9317E}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\nba 2k10\nba2k10.exe |
"{1B21E070-10D1-4682-B2C2-B482102EB077}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\fc2editor.exe |
"{1BAE1A42-9860-455C-B9D0-9F004EC2121E}" = protocol=6 | dir=in | app=c:\program files\thq\company of heroes\reliccoh.exe |
"{1C21EEDD-6D45-4302-8E7F-D3F524BBC5CA}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{1C340250-1264-42ED-89BD-48891D7CB781}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{1D053FE9-5930-43D1-B31E-672E25A60569}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2launcher.exe |
"{1D4B34C4-60F1-4B05-BA95-5A0D53427B05}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dead rising 2\deadrising2.exe |
"{1EB6B739-D904-4140-9BDB-52292758BF90}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\lara croft and the guardian of light\lcgol.exe |
"{2080E5C6-00B2-40B7-8480-709653545E77}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\lxddmon.exe |
"{20B6779B-5283-4636-BF54-D0C7B14C48EE}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\mass effect 2\docs\ea help\electronic_arts_technical_support.htm |
"{214DB483-A345-4A0D-AF5B-821F6ED4A29F}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the first encounter\bin\samhd.exe |
"{217DB2A5-A964-4D12-B314-CB0F52410768}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mafia ii\pc\mafia2.exe |
"{220B6318-3363-4340-8E26-E696A52654D1}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\fear2\fear2.exe |
"{221A3963-1059-4BEC-8DA8-BD2B19330E60}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{225128F2-EDA8-454F-A2E7-CD0A97A93F7A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\master levels of doom\master.bat |
"{22B55AD6-2BF0-42CD-A97C-FE10F16FB52D}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{2413E968-37EE-4D7F-8164-B37EE30F6E6F}" = protocol=17 | dir=in | app=c:\program files\mass effect\masseffectlauncher.exe |
"{242E3B4F-37DC-426D-A510-2D3FC73659AE}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{262EE673-E0AC-462B-A1E5-4CE8E7850194}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
"{27236550-D04D-44A3-8D02-50191B4F512D}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe |
"{27874F3A-3464-43D1-A727-D069A76CE810}" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
"{27922E03-7A40-418C-A4B1-826A645A8D3C}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\zombie driver\release\zombiedriver.exe |
"{28A72F28-0644-4A1E-806F-A351B59759AE}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{28D28CB6-89DF-4644-85A7-2AC495FECDC8}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
"{2992E1A9-86D6-42BF-A178-FCCD354205F5}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse.exe |
"{29C7BB64-A636-4F9C-AC71-D22DA41F894A}" = protocol=6 | dir=in | app=c:\program files\microsoft games\gears of war\binaries\wargame-g4wlive.exe |
"{2BBA62B1-2D19-4D4D-9344-8943E1F30D4B}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{2C14D40F-F7FB-48CF-9207-3DF4010ED828}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\fc2serverlauncher.exe |
"{2DCBDEEA-D350-4D7B-8F87-94C77E163CDB}" = protocol=6 | dir=in | app=c:\program files\volition inc\red faction guerrilla\rfg.exe |
"{2E6FED51-D3BF-4845-802B-98350BA01014}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\world of goo\worldofgoo.exe |
"{31508687-39C9-4F29-A944-3F7AC38740AB}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\splinter cell - double agent\scdalauncher.exe |
"{3364C110-70BC-4DB1-92A1-4168459CE7C8}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_launcher.exe |
"{33C6CD20-D2CA-46AE-87C1-1CB78EDEC9D8}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty black ops\blackops.exe |
"{343E2E50-67C2-45A9-92B0-905C50824A95}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{34884A1D-B493-44D5-9BC4-B047294D25C4}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\app4r.exe |
"{350EB60F-6011-479D-BE38-4F543B7A0371}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\support\ea help\electronic_arts_technical_support.htm |
"{3536584F-69F4-4523-B96B-AB74F50DE3B2}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\trine\trine_launcher.exe |
"{35C6096D-53FD-4E3F-B0E3-BE29103141BD}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\nba 2k10\nba2k10.exe |
"{3638A793-2146-45C4-8530-0A57C6E3461F}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{36C53010-F4C8-4100-9860-18A546E13668}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\srcds.exe |
"{37F39F62-CB81-419A-B9A9-8AF9CD82B439}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx9.exe |
"{398C4DC2-944A-4C1C-93F9-523F5FEB9555}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{3BD34B2D-4661-4C35-8D46-CCBC44C09A5D}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{3D717709-CF86-4A75-944B-86373470F344}" = protocol=6 | dir=in | app=c:\windows\system32\lxddcoms.exe |
"{3E575595-08BF-4ACD-9683-AEB3A45976A1}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddjswx.exe |
"{3EBB4CE7-31B1-4F25-9FCF-0FA727789E29}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\just cause 2\justcause2.exe |
"{3F3092F8-F1BA-48FB-BE46-7567A0460621}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\street fighter iv\sf4launcher.exe |
"{4010F668-C938-4B31-96C1-3F8613C79A99}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii\overlord2.exe |
"{40949D3D-C6BB-425C-A43C-C0888528DA75}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{41122A7F-775D-4909-9A22-1017E851396E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dark sector\ds.exe |
"{41A7A8FF-59AC-4836-B8A1-64AE53A92DE5}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\zombie driver\release\zombiedriver.exe |
"{41ACFB5F-2326-4269-AFE5-9DB93806466A}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\magicka\magicka.exe |
"{4207F842-8F41-4A21-B409-16BA1154510F}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\world of goo\worldofgoo.exe |
"{424B41E9-432A-4FD6-9EA7-EF715B195BD0}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx9.exe |
"{427FD28E-EB07-4C9D-9811-E9636E75FC4F}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\deus ex\system\deusex.exe |
"{4324FCC6-774B-489F-BED7-FA4FF6FC0051}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
"{4439BDF4-60BB-4C47-8CC8-CF7266B3EFA5}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe |
"{45068224-8717-47CB-A0C5-1AE00566AD89}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\darksiders\darksiderspc.exe |
"{451B4609-6B3B-429A-BAD3-0DC602A1AF13}" = protocol=6 | dir=in | app=c:\program files\rockstar games\eflc\launcheflc.exe |
"{4555AB55-9E76-4908-9B63-C0885D5001A5}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\support\ea help\electronic_arts_technical_support.htm |
"{45D8E8F7-236B-4772-BF5F-D0DCDFD497EC}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{4632C30B-5617-4DA1-B706-C11668CE0439}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"{4661A307-6162-4AB6-A86C-626CCB441F01}" = protocol=17 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutlauncher.exe |
"{489ADA24-FFBC-43DD-95D9-8449CCC12106}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\stranger's wrath\launcher.exe |
"{48CFE89F-609C-44D6-AA41-D870E5BB0D83}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\fc2benchmarktool.exe |
"{49645A37-259D-40DD-A734-D294B841265B}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\puzzle quest\puzzle quest.exe |
"{4AE9E47F-4344-4D89-9692-1DAD383532E0}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\stalker call of pripyat\stalker-cop.exe |
"{4B74E938-66FF-4429-A05E-4B5FF885EE8C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\lost planet extreme condition\lostplanetdx9.exe |
"{4C744EDD-2AA4-4854-8D99-B8BEA4B8409F}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{4D3C931B-191D-4824-ACFF-2D1804F2916C}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii\overlord2.exe |
"{4D3FE883-CD08-4091-9D52-A9E8B7BA5FB2}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\kane & lynch 2 - dog days\kl2.exe |
"{4DF26338-4CAA-420E-9D8B-12097DE5C0A0}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\coj.exe |
"{4E125AB4-6470-4533-ADF7-853EADCF4AE2}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\support\ea help\electronic_arts_technical_support.htm |
"{4E42D5F3-602A-409C-BC69-3AEF0E791B9A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\overlord\overlord.exe |
"{4E617162-C93C-44AD-88AC-FA550094FDE7}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dead rising 2\deadrising2.exe |
"{4EC94F39-F853-454D-9900-4DB8D312134E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty black ops\blackopsmp.exe |
"{4ECB50C8-AB4F-44C7-BEC8-8B35B350C8AF}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{4F335B39-ECDC-4E38-AF81-A0AFFA475AF6}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\lost planet 2\launcher.exe |
"{4FD22D6C-9C49-481F-B079-367DEA18050E}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddjswx.exe |
"{50956241-FDE5-46F1-8C78-5FBBFC43ED1B}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{512E74F0-7FC4-4AB3-B70E-4A8CCBC7F5E8}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{540A03FC-35D7-4D18-81B9-1C920EF6C16B}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\kane & lynch 2 - dog days\kl2.exe |
"{544DEB2D-3B98-40BF-9D9B-A76EB3780920}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{544F0751-C977-48FE-914E-C8C395D8B3A7}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\cojdx10_benchmark.exe |
"{5501D76F-2CE5-4670-AB43-2EC48358C08D}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
"{55CE70F4-12BC-4866-A875-963F7DD10E96}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{56E6D562-B6CA-4852-90B5-DBD48CCD2CB9}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |
"{580F7797-1221-4F39-B11F-2854F499FB7D}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\deus ex\system\deusex.exe |
"{58CBB649-444D-435A-8B09-78FB6118AF5F}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{595C1129-32D0-49F1-9BCC-112A0DAE5C05}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\srcds.exe |
"{59F62B48-DCE4-4FB2-BAA0-AE4B3472203D}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{5B676469-CDEA-4EEA-B099-ADEDE2FC09ED}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\magicka\magicka.exe |
"{5CBC580E-8DC8-4A63-B4BE-A7C82DEC4F74}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\just cause 2\justcause2.exe |
"{5CD69F34-3D10-4E92-B554-B2665F7B0BAD}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{5DD212EB-99D1-4844-AE78-4FA3B2922E8F}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\darksiders\darksiderspc.exe |
"{5DF20690-0000-4399-A546-E17DA46271FF}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"{5E0716E5-2E24-4977-88F5-3325939848BB}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\swarm.exe |
"{5E9866AE-4CFC-4BAB-A3BF-C1159944B366}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\farcry2.exe |
"{5F4641A7-51C6-4AF1-8821-A54C963ED8F4}" = protocol=6 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutlauncher.exe |
"{5F4E8088-0E5A-422E-BB8E-D1B7EB674702}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of duty black ops\blackops.exe |
"{5FD8E8E7-054F-41AE-B118-8D40D8FAED05}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\operation flashpoint dragon rising\ofdr.exe |
"{60057FE5-D0D6-403B-87D2-24E3530191F9}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{604047A5-BBB3-43EE-A7AE-7B31D269BA2F}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_launcher.exe |
"{632262E6-059B-4175-9806-BC680FB7330B}" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\lxddamon.exe |
"{6338217A-2103-48D9-9CAA-C5D9E3E58542}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{634AC63A-4CEF-4915-8996-A3102888419B}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\srcds.exe |
"{639B23DA-E017-4D08-8DB6-6D75674CC4CE}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |
"{64F61CC4-DAB9-4AF0-9484-BB6224A52809}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\nba 2k10\nba2k10.exe |
"{65A53AB1-5977-443D-AEBB-BCFCAAA3A210}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\operation flashpoint dragon rising\mission editor\missioneditor.exe |
"{65D7DF6D-2FC9-49DA-811E-EBADFDD8F0E2}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\audiosurf\engine\questviewer.exe |
"{6636C51B-C8AD-4C62-9832-7639579F5265}" = protocol=17 | dir=in | app=c:\program files\rockstar games\eflc\launcheflc.exe |
"{66B29653-1D38-4649-B91A-3B69BAF102D8}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{66B57346-B101-4BDD-929D-54449095AA78}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\operation flashpoint dragon rising\ofdr.exe |
"{6799F92A-CF07-4944-8693-B759BE2381E1}" = protocol=6 | dir=in | app=c:\program files\activision\prototype\prototypef.exe |
"{67A2F08B-85A8-4470-BBFE-940B7D4E114A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
"{67CBFC10-FB26-4A99-8921-FB7A182EB751}" = protocol=17 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{6900AE99-3F59-4A5A-85D8-08830A57FE1F}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{6943D60A-21C0-44E6-9C9D-1FED5E2CA7B5}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\call of duty black ops\blackopsmp.exe |
"{6A382599-2138-4977-858C-52486637B120}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii - demo\overlord2demo.exe |
"{6A44D30C-F60F-4A28-AA45-947928FE5307}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{6A59F21B-0819-4015-907B-16745ACA7C90}" = protocol=17 | dir=in | app=c:\program files\thq\company of heroes\reliccoh.exe |
"{6A904618-459A-45DA-94AC-79DDD36FA649}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
"{6B63C470-AC41-4F43-ABE1-6E02AA7F0051}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\magicka\magicka.exe |
"{6BDAAFF7-8105-43A5-8B25-3442C7ED4B93}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\deus ex\system\deusex.exe |
"{6C4972C7-7F59-4468-A87D-9801AEF71B20}" = protocol=17 | dir=in | app=d:\bad comapny2\bfbc2betaupdater.exe |
"{6C8E9008-EB56-4910-BD3B-A376B3ACCE2A}" = protocol=6 | dir=in | app=c:\program files\codemasters\grid\grid.exe |
"{6CA3CCE0-6895-4A6F-9DB0-E3C4DE42A3A8}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii\config.exe |
"{6DCD6C71-71C3-4F3D-926F-6BB48AE08CEA}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2launcher.exe |
"{6F24C27C-2A0C-4630-B549-FF0EE9FAE010}" = protocol=6 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
"{6F37C987-144A-4F4E-ADB7-D24E8E0031C2}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{707B965E-9E87-4A00-AA40-E813D606E588}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe |
"{70C7FC4A-3030-459D-A36D-18A15D6C3D60}" = protocol=6 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutconfigtool.exe |
"{70D42897-3D79-43AE-A372-0ED9BCE52DEB}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the first encounter\bin\samhd.exe |
"{70F15F90-FBDD-447C-806B-0F632A1D45EB}" = protocol=17 | dir=in | app=c:\windows\system32\lxddcoms.exe |
"{718C0DEB-5A4E-45AB-AF5B-CB18C3E7BB0E}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{719918F6-85F4-43BE-8964-F3512FAD2946}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\lara croft and the guardian of light\lcgol.exe |
"{7307F0DE-142F-4600-9610-9E4973E1E75C}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddtime.exe |
"{7390064C-DD69-4F3F-B389-87E7AFA312FE}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe |
"{73FADEEC-5AB5-4C74-8133-6C937DD19C2F}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{750791CF-9FFB-4F9E-942A-0E861C6A69E2}" = protocol=6 | dir=in | app=c:\program files\eidos\batman arkham asylum\binaries\shippingpc-bmgame.exe |
"{75494D7A-76B4-4F72-9EC6-B12D0E7FDA7E}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\lxddamon.exe |
"{75BA40A6-A1B2-4791-893D-6E5B8190F127}" = protocol=17 | dir=in | app=c:\program files\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{76316E8A-248A-4D55-816F-9CCCE20B4B0A}" = protocol=6 | dir=in | app=d:\bad comapny2\bfbc2betaupdater.exe |
"{76995064-7A1B-486B-B6FE-60A39084317A}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dead space\dead space.exe |
"{7738F963-5D9B-41C4-B941-9619787C9249}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse.exe |
"{77521A7D-FFD0-48D9-94EC-4ACAB3CD6523}" = protocol=17 | dir=in | app=c:\program files\activision\prototype\prototypef.exe |
"{777D850A-46C4-468B-B9BA-5767619A8A81}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\zombie driver\release\zombiedriver.exe |
"{77805F0C-70F9-4FF4-8689-5D1EED1E68E4}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{77B12C76-00D2-448F-B093-5F3C38CB2E69}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{7881819C-5F49-471F-989E-87A13F6759CD}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\karol754\counter-strike source\hl2.exe |
"{7A295A25-607B-46FE-BCF6-C4227A5A7841}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\just cause 2\justcause2.exe |
"{7AABD464-8BA4-4620-A20A-1A21B5D60336}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dirt 2\dirt2.exe |
"{7AB0A3B1-D72F-4794-9FA4-5368BABB9320}" = protocol=6 | dir=in | app=c:\program files\mass effect\binaries\masseffect.exe |
"{7AC779A1-3E62-4CC4-835F-2C8FB9BB1E7A}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"{7B0D4BB2-CADC-4792-B6DB-8D6CD618255E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\swarm.exe |
"{7B568CA3-1644-4FFC-A00C-94C777EA7490}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\operation flashpoint dragon rising\mission editor\missioneditor.exe |
"{7C3DFE81-34B5-4A73-97C1-01B848CC0794}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\mafia ii\pc\mafia2.exe |
"{7CA06C45-0C45-4392-99B3-341DA3F03D82}" = protocol=6 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{7DE626F6-DA19-4842-A16D-9649ABC49F07}" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
"{7E3A66A1-36BE-4FC9-8ECF-0C587002E0DA}" = protocol=6 | dir=in | app=c:\program files\sierra entertainment\world in conflict\wic.exe |
"{7E530CF5-7E82-45EF-BB39-2E05F24B25FB}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord\overlord.exe |
"{7EAB93AC-1FA1-4248-A879-C77FFDF358FA}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\brothers in arms hells highway\binaries\biahh.exe |
"{7EADF3FC-5093-4BC1-8F85-DEA8FDE4F544}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\chromed.exe |
"{7FAA06AB-673A-4EB6-9FB8-9BF2E523F857}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the first encounter\bin\samhd.exe |
"{7FB325D8-F9BD-4138-894B-E40FFA7187A7}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\overlord\config.exe |
"{8023FC32-982D-4545-8A4A-3A95530A5B56}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\mass effect 2\masseffect2launcher.exe |
"{80DC56E7-CE82-4E14-A51F-0AFE7F9C0DC8}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{81FA11F8-42C0-431C-ACB5-D54C3153AB11}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{836DDE86-1B68-409A-9758-28779143748F}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\karol754\counter-strike source\hl2.exe |
"{851322B0-1F06-4A1F-B0BD-A4F8C22B9B34}" = protocol=6 | dir=in | app=c:\program files\mass effect\masseffectlauncher.exe |
"{85CA29B0-2DE6-4EB1-A36F-277D06655F9A}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
"{86C9C2CF-936E-400D-8927-D53538CACE19}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\fc2editor.exe |
 
Extras log is such a pain. Can I message you it? uploading is not possible over 200k. I cant upload that virus because its in the quarantine area, should I restore the virus and then upload it from the original folder?

Edit: I attached it, I ziped it.
 

Attachments

  • Extras.zip
    35.2 KB · Views: 0
ok sorry from the beginning:

Extras:

OTL Extras logfile created on: 2/28/2011 9:51:20 PM - Run 1
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Users\User\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 65.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 698.63 Gb Total Space | 486.40 Gb Free Space | 69.62% Space Free | Partition Type: NTFS
Drive D: | 111.79 Gb Total Space | 17.13 Gb Free Space | 15.32% Space Free | Partition Type: NTFS
Drive F: | 1863.01 Gb Total Space | 1556.11 Gb Free Space | 83.53% Space Free | Partition Type: NTFS

Computer Name: USER-PC | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2158934232-3957428742-2026527031-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "D:\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "D:\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-2158934232-3957428742-2026527031-1000]
"EnableNotifications" = 0
"EnableNotificationsRef" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 1
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{2B02ADD1-3182-496F-85A9-6B19CB1DECAC}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{540EBAD4-3204-4F0F-AFFE-1CD9EBCE1291}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{E282B796-485C-4987-9AD9-6E83D24F4EB4}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{003AC244-DCC0-4E51-AD91-A9B30423D3CD}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\fear2\fear2.exe |
"{003C9592-CB13-46FD-AF04-346C0CF1FEBA}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\lxddmon.exe |
"{004B4D73-ED51-4334-9BD7-0F205AC1508C}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\puzzle quest\puzzle quest.exe |
"{0157CD7C-E77B-4DD0-91ED-8CE2764A4267}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez - bound in blood\cojbibgame_x86.exe |
"{01F267EF-558C-4B28-AC89-5F023430B012}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe |
"{04364725-0C75-46C7-83E0-A9DBCFF50168}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\swarm.exe |
"{05C19064-36B9-416A-A664-864AB3CD83B1}" = protocol=17 | dir=in | app=c:\program files\eidos\batman arkham asylum\binaries\shippingpc-bmgame.exe |
"{05D59025-EF5C-482E-9825-FB4A95E3A68F}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{07AB361D-77DB-4172-92B5-5FFC1E435299}" = protocol=6 | dir=in | app=c:\program files\sierra entertainment\world in conflict\wic_ds.exe |
"{0856D5B7-70D9-4F2F-ADFB-19085DA9C512}" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysis.exe |
"{088032EF-278F-4DBA-86D6-17F460D7ABFC}" = protocol=17 | dir=in | app=c:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\dedicated\xrengine.exe |
"{097E1D1D-ABEB-4681-A60E-619DF3D98057}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{09B6B20C-A012-43CA-AE84-045120D72BB1}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\metro 2033\metro2033.exe |
"{09C3866B-8BBF-4644-BCBD-97C286249F24}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\world of goo\worldofgoo.exe |
"{09C86618-750A-44B4-B154-437444831850}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\nba 2k10\nba2k10.exe |
"{0B3D06AA-8BC1-4694-90E9-0EE9ABE97B4A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord\config.exe |
"{0C0C6772-5DE8-43A6-AD9E-01CBD066AE4C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
"{0C49038D-B9E6-4AD3-A657-43AD706CBF04}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{0CBC3BC8-8A15-4D18-AA1B-8717DBDD666D}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{0F37EE85-2128-453D-9C95-1221601F9113}" = protocol=6 | dir=in | app=c:\program files\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{0F652132-7D25-4388-97B5-05404DA940A3}" = protocol=17 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutparadise.exe |
"{0F8B1EF6-F9B5-4BC1-8776-665819B98470}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dead rising 2\deadrising2.exe |
"{0FC76C2B-F33E-4762-A990-C1C6EF4CA6EC}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\street fighter iv\sf4launcher.exe |
"{10A96A7D-7BAC-4EA2-A621-C48535C6F7D3}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\lost planet 2\launcher.exe |
"{10B6FD05-18B5-46F1-BF51-EAA9FCEB9711}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddtime.exe |
"{11A22D60-30BB-4215-9A10-83468BD23CF1}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\kane & lynch 2 - dog days\kl2.exe |
"{124C2B14-C1D3-4F11-A6EB-0CE39138F832}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
"{12E36C7C-EFB3-42AD-830C-1C59B72B70FB}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{13041940-296D-4FD2-B5CA-C65161573C83}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\stranger's wrath\launcher.exe |
"{13145265-EB83-4F42-9AE2-9E0CACA979AD}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\darksiders\darksiderspc.exe |
"{143CAC2C-FCE2-4C8E-A76D-0929665EE1A5}" = protocol=6 | dir=in | app=c:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe |
"{1472AF1D-16C5-4F45-9E80-5D344ED3C654}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\brothers in arms hells highway\binaries\biahh.exe |
"{14D25EB3-C4A4-4DAD-9E57-69D586BB1CFF}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{151004D6-9CBA-4FDF-974E-5996C57D286E}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\just cause 2\justcause2.exe |
"{15ACBD81-3056-4E4E-8730-124C58C36324}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of juarez\chromed.exe |
"{15CCADE5-C333-46AC-BDA9-932850EB5881}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mafia ii\pc\mafia2.exe |
"{15DE9095-A362-4258-A368-24D25091734C}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
"{16911EA1-E82C-4503-AF3D-67B1CB5FCA4C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe |
"{178E97B8-8DFF-45F4-8B72-BBC03B1E661C}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\support\ea help\electronic_arts_technical_support.htm |
"{181C7C26-F338-46AE-8F36-7A68BAC00012}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
"{182CC714-3218-49F4-9259-504BFA1610FC}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{195B3CD4-3475-4E24-89EC-C45C496FE489}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{1A1634F8-419A-4086-B816-334698054684}" = protocol=17 | dir=in | app=c:\program files\ea games\mirror's edge\binaries\mirrorsedge.exe |
"{1A24F262-04C1-4BA6-9946-E75356C9317E}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\nba 2k10\nba2k10.exe |
"{1B21E070-10D1-4682-B2C2-B482102EB077}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\fc2editor.exe |
"{1BAE1A42-9860-455C-B9D0-9F004EC2121E}" = protocol=6 | dir=in | app=c:\program files\thq\company of heroes\reliccoh.exe |
"{1C21EEDD-6D45-4302-8E7F-D3F524BBC5CA}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{1C340250-1264-42ED-89BD-48891D7CB781}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{1D053FE9-5930-43D1-B31E-672E25A60569}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2launcher.exe |
"{1D4B34C4-60F1-4B05-BA95-5A0D53427B05}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dead rising 2\deadrising2.exe |
"{1EB6B739-D904-4140-9BDB-52292758BF90}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\lara croft and the guardian of light\lcgol.exe |
"{2080E5C6-00B2-40B7-8480-709653545E77}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\lxddmon.exe |
"{20B6779B-5283-4636-BF54-D0C7B14C48EE}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\mass effect 2\docs\ea help\electronic_arts_technical_support.htm |
"{214DB483-A345-4A0D-AF5B-821F6ED4A29F}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the first encounter\bin\samhd.exe |
"{217DB2A5-A964-4D12-B314-CB0F52410768}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mafia ii\pc\mafia2.exe |
"{220B6318-3363-4340-8E26-E696A52654D1}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\fear2\fear2.exe |
"{221A3963-1059-4BEC-8DA8-BD2B19330E60}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{225128F2-EDA8-454F-A2E7-CD0A97A93F7A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\master levels of doom\master.bat |
"{22B55AD6-2BF0-42CD-A97C-FE10F16FB52D}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{2413E968-37EE-4D7F-8164-B37EE30F6E6F}" = protocol=17 | dir=in | app=c:\program files\mass effect\masseffectlauncher.exe |
"{242E3B4F-37DC-426D-A510-2D3FC73659AE}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{262EE673-E0AC-462B-A1E5-4CE8E7850194}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
"{27236550-D04D-44A3-8D02-50191B4F512D}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe |
"{27874F3A-3464-43D1-A727-D069A76CE810}" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
"{27922E03-7A40-418C-A4B1-826A645A8D3C}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\zombie driver\release\zombiedriver.exe |
"{28A72F28-0644-4A1E-806F-A351B59759AE}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{28D28CB6-89DF-4644-85A7-2AC495FECDC8}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
"{2992E1A9-86D6-42BF-A178-FCCD354205F5}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse.exe |
"{29C7BB64-A636-4F9C-AC71-D22DA41F894A}" = protocol=6 | dir=in | app=c:\program files\microsoft games\gears of war\binaries\wargame-g4wlive.exe |
"{2BBA62B1-2D19-4D4D-9344-8943E1F30D4B}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{2C14D40F-F7FB-48CF-9207-3DF4010ED828}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\fc2serverlauncher.exe |
"{2DCBDEEA-D350-4D7B-8F87-94C77E163CDB}" = protocol=6 | dir=in | app=c:\program files\volition inc\red faction guerrilla\rfg.exe |
"{2E6FED51-D3BF-4845-802B-98350BA01014}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\world of goo\worldofgoo.exe |
"{31508687-39C9-4F29-A944-3F7AC38740AB}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\splinter cell - double agent\scdalauncher.exe |
"{3364C110-70BC-4DB1-92A1-4168459CE7C8}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_launcher.exe |
"{33C6CD20-D2CA-46AE-87C1-1CB78EDEC9D8}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty black ops\blackops.exe |
"{343E2E50-67C2-45A9-92B0-905C50824A95}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{34884A1D-B493-44D5-9BC4-B047294D25C4}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\app4r.exe |
"{350EB60F-6011-479D-BE38-4F543B7A0371}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\support\ea help\electronic_arts_technical_support.htm |
"{3536584F-69F4-4523-B96B-AB74F50DE3B2}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\trine\trine_launcher.exe |
"{35C6096D-53FD-4E3F-B0E3-BE29103141BD}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\nba 2k10\nba2k10.exe |
"{3638A793-2146-45C4-8530-0A57C6E3461F}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{36C53010-F4C8-4100-9860-18A546E13668}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\srcds.exe |
"{37F39F62-CB81-419A-B9A9-8AF9CD82B439}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx9.exe |
"{398C4DC2-944A-4C1C-93F9-523F5FEB9555}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{3BD34B2D-4661-4C35-8D46-CCBC44C09A5D}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{3D717709-CF86-4A75-944B-86373470F344}" = protocol=6 | dir=in | app=c:\windows\system32\lxddcoms.exe |
"{3E575595-08BF-4ACD-9683-AEB3A45976A1}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddjswx.exe |
"{3EBB4CE7-31B1-4F25-9FCF-0FA727789E29}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\just cause 2\justcause2.exe |
"{3F3092F8-F1BA-48FB-BE46-7567A0460621}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\street fighter iv\sf4launcher.exe |
"{4010F668-C938-4B31-96C1-3F8613C79A99}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii\overlord2.exe |
"{40949D3D-C6BB-425C-A43C-C0888528DA75}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{41122A7F-775D-4909-9A22-1017E851396E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dark sector\ds.exe |
"{41A7A8FF-59AC-4836-B8A1-64AE53A92DE5}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\zombie driver\release\zombiedriver.exe |
"{41ACFB5F-2326-4269-AFE5-9DB93806466A}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\magicka\magicka.exe |
"{4207F842-8F41-4A21-B409-16BA1154510F}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\world of goo\worldofgoo.exe |
"{424B41E9-432A-4FD6-9EA7-EF715B195BD0}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx9.exe |
"{427FD28E-EB07-4C9D-9811-E9636E75FC4F}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\deus ex\system\deusex.exe |
"{4324FCC6-774B-489F-BED7-FA4FF6FC0051}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
"{4439BDF4-60BB-4C47-8CC8-CF7266B3EFA5}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe |
"{45068224-8717-47CB-A0C5-1AE00566AD89}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\darksiders\darksiderspc.exe |
"{451B4609-6B3B-429A-BAD3-0DC602A1AF13}" = protocol=6 | dir=in | app=c:\program files\rockstar games\eflc\launcheflc.exe |
"{4555AB55-9E76-4908-9B63-C0885D5001A5}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\support\ea help\electronic_arts_technical_support.htm |
"{45D8E8F7-236B-4772-BF5F-D0DCDFD497EC}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{4632C30B-5617-4DA1-B706-C11668CE0439}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"{4661A307-6162-4AB6-A86C-626CCB441F01}" = protocol=17 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutlauncher.exe |
"{489ADA24-FFBC-43DD-95D9-8449CCC12106}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\stranger's wrath\launcher.exe |
"{48CFE89F-609C-44D6-AA41-D870E5BB0D83}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\fc2benchmarktool.exe |
"{49645A37-259D-40DD-A734-D294B841265B}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\puzzle quest\puzzle quest.exe |
"{4AE9E47F-4344-4D89-9692-1DAD383532E0}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\stalker call of pripyat\stalker-cop.exe |
"{4B74E938-66FF-4429-A05E-4B5FF885EE8C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\lost planet extreme condition\lostplanetdx9.exe |
"{4C744EDD-2AA4-4854-8D99-B8BEA4B8409F}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{4D3C931B-191D-4824-ACFF-2D1804F2916C}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii\overlord2.exe |
"{4D3FE883-CD08-4091-9D52-A9E8B7BA5FB2}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\kane & lynch 2 - dog days\kl2.exe |
"{4DF26338-4CAA-420E-9D8B-12097DE5C0A0}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\coj.exe |
"{4E125AB4-6470-4533-ADF7-853EADCF4AE2}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\support\ea help\electronic_arts_technical_support.htm |
"{4E42D5F3-602A-409C-BC69-3AEF0E791B9A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\overlord\overlord.exe |
"{4E617162-C93C-44AD-88AC-FA550094FDE7}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dead rising 2\deadrising2.exe |
"{4EC94F39-F853-454D-9900-4DB8D312134E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty black ops\blackopsmp.exe |
"{4ECB50C8-AB4F-44C7-BEC8-8B35B350C8AF}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{4F335B39-ECDC-4E38-AF81-A0AFFA475AF6}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\lost planet 2\launcher.exe |
"{4FD22D6C-9C49-481F-B079-367DEA18050E}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddjswx.exe |
"{50956241-FDE5-46F1-8C78-5FBBFC43ED1B}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{512E74F0-7FC4-4AB3-B70E-4A8CCBC7F5E8}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{540A03FC-35D7-4D18-81B9-1C920EF6C16B}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\kane & lynch 2 - dog days\kl2.exe |
"{544DEB2D-3B98-40BF-9D9B-A76EB3780920}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{544F0751-C977-48FE-914E-C8C395D8B3A7}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\cojdx10_benchmark.exe |
"{5501D76F-2CE5-4670-AB43-2EC48358C08D}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
"{55CE70F4-12BC-4866-A875-963F7DD10E96}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{56E6D562-B6CA-4852-90B5-DBD48CCD2CB9}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |
"{580F7797-1221-4F39-B11F-2854F499FB7D}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\deus ex\system\deusex.exe |
"{58CBB649-444D-435A-8B09-78FB6118AF5F}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{595C1129-32D0-49F1-9BCC-112A0DAE5C05}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\srcds.exe |
"{59F62B48-DCE4-4FB2-BAA0-AE4B3472203D}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{5B676469-CDEA-4EEA-B099-ADEDE2FC09ED}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\magicka\magicka.exe |
"{5CBC580E-8DC8-4A63-B4BE-A7C82DEC4F74}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\just cause 2\justcause2.exe |
"{5CD69F34-3D10-4E92-B554-B2665F7B0BAD}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{5DD212EB-99D1-4844-AE78-4FA3B2922E8F}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\darksiders\darksiderspc.exe |
"{5DF20690-0000-4399-A546-E17DA46271FF}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"{5E0716E5-2E24-4977-88F5-3325939848BB}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\swarm.exe |
"{5E9866AE-4CFC-4BAB-A3BF-C1159944B366}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\farcry2.exe |
"{5F4641A7-51C6-4AF1-8821-A54C963ED8F4}" = protocol=6 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutlauncher.exe |
"{5F4E8088-0E5A-422E-BB8E-D1B7EB674702}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of duty black ops\blackops.exe |
"{5FD8E8E7-054F-41AE-B118-8D40D8FAED05}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\operation flashpoint dragon rising\ofdr.exe |
"{60057FE5-D0D6-403B-87D2-24E3530191F9}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{604047A5-BBB3-43EE-A7AE-7B31D269BA2F}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_launcher.exe |
"{632262E6-059B-4175-9806-BC680FB7330B}" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\lxddamon.exe |
"{6338217A-2103-48D9-9CAA-C5D9E3E58542}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{634AC63A-4CEF-4915-8996-A3102888419B}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\srcds.exe |
"{639B23DA-E017-4D08-8DB6-6D75674CC4CE}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |
"{64F61CC4-DAB9-4AF0-9484-BB6224A52809}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\nba 2k10\nba2k10.exe |
"{65A53AB1-5977-443D-AEBB-BCFCAAA3A210}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\operation flashpoint dragon rising\mission editor\missioneditor.exe |
"{65D7DF6D-2FC9-49DA-811E-EBADFDD8F0E2}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\audiosurf\engine\questviewer.exe |
"{6636C51B-C8AD-4C62-9832-7639579F5265}" = protocol=17 | dir=in | app=c:\program files\rockstar games\eflc\launcheflc.exe |
"{66B29653-1D38-4649-B91A-3B69BAF102D8}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{66B57346-B101-4BDD-929D-54449095AA78}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\operation flashpoint dragon rising\ofdr.exe |
"{6799F92A-CF07-4944-8693-B759BE2381E1}" = protocol=6 | dir=in | app=c:\program files\activision\prototype\prototypef.exe |
"{67A2F08B-85A8-4470-BBFE-940B7D4E114A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
"{67CBFC10-FB26-4A99-8921-FB7A182EB751}" = protocol=17 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{6900AE99-3F59-4A5A-85D8-08830A57FE1F}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{6943D60A-21C0-44E6-9C9D-1FED5E2CA7B5}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\call of duty black ops\blackopsmp.exe |
"{6A382599-2138-4977-858C-52486637B120}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii - demo\overlord2demo.exe |
"{6A44D30C-F60F-4A28-AA45-947928FE5307}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{6A59F21B-0819-4015-907B-16745ACA7C90}" = protocol=17 | dir=in | app=c:\program files\thq\company of heroes\reliccoh.exe |
"{6A904618-459A-45DA-94AC-79DDD36FA649}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
"{6B63C470-AC41-4F43-ABE1-6E02AA7F0051}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\magicka\magicka.exe |
"{6BDAAFF7-8105-43A5-8B25-3442C7ED4B93}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\deus ex\system\deusex.exe |
"{6C4972C7-7F59-4468-A87D-9801AEF71B20}" = protocol=17 | dir=in | app=d:\bad comapny2\bfbc2betaupdater.exe |
"{6C8E9008-EB56-4910-BD3B-A376B3ACCE2A}" = protocol=6 | dir=in | app=c:\program files\codemasters\grid\grid.exe |
"{6CA3CCE0-6895-4A6F-9DB0-E3C4DE42A3A8}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii\config.exe |
"{6DCD6C71-71C3-4F3D-926F-6BB48AE08CEA}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2launcher.exe |
"{6F24C27C-2A0C-4630-B549-FF0EE9FAE010}" = protocol=6 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
"{6F37C987-144A-4F4E-ADB7-D24E8E0031C2}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{707B965E-9E87-4A00-AA40-E813D606E588}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe |
"{70C7FC4A-3030-459D-A36D-18A15D6C3D60}" = protocol=6 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutconfigtool.exe |
"{70D42897-3D79-43AE-A372-0ED9BCE52DEB}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the first encounter\bin\samhd.exe |
"{70F15F90-FBDD-447C-806B-0F632A1D45EB}" = protocol=17 | dir=in | app=c:\windows\system32\lxddcoms.exe |
"{718C0DEB-5A4E-45AB-AF5B-CB18C3E7BB0E}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{719918F6-85F4-43BE-8964-F3512FAD2946}" = protocol=17 | dir=in |
 
app=c:\program files\steam\steamapps\common\lara croft and the guardian of light\lcgol.exe |
"{7307F0DE-142F-4600-9610-9E4973E1E75C}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddtime.exe |
"{7390064C-DD69-4F3F-B389-87E7AFA312FE}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe |
"{73FADEEC-5AB5-4C74-8133-6C937DD19C2F}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{750791CF-9FFB-4F9E-942A-0E861C6A69E2}" = protocol=6 | dir=in | app=c:\program files\eidos\batman arkham asylum\binaries\shippingpc-bmgame.exe |
"{75494D7A-76B4-4F72-9EC6-B12D0E7FDA7E}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\lxddamon.exe |
"{75BA40A6-A1B2-4791-893D-6E5B8190F127}" = protocol=17 | dir=in | app=c:\program files\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{76316E8A-248A-4D55-816F-9CCCE20B4B0A}" = protocol=6 | dir=in | app=d:\bad comapny2\bfbc2betaupdater.exe |
"{76995064-7A1B-486B-B6FE-60A39084317A}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dead space\dead space.exe |
"{7738F963-5D9B-41C4-B941-9619787C9249}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse.exe |
"{77521A7D-FFD0-48D9-94EC-4ACAB3CD6523}" = protocol=17 | dir=in | app=c:\program files\activision\prototype\prototypef.exe |
"{777D850A-46C4-468B-B9BA-5767619A8A81}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\zombie driver\release\zombiedriver.exe |
"{77805F0C-70F9-4FF4-8689-5D1EED1E68E4}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{77B12C76-00D2-448F-B093-5F3C38CB2E69}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{7881819C-5F49-471F-989E-87A13F6759CD}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\karol754\counter-strike source\hl2.exe |
"{7A295A25-607B-46FE-BCF6-C4227A5A7841}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\just cause 2\justcause2.exe |
"{7AABD464-8BA4-4620-A20A-1A21B5D60336}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dirt 2\dirt2.exe |
"{7AB0A3B1-D72F-4794-9FA4-5368BABB9320}" = protocol=6 | dir=in | app=c:\program files\mass effect\binaries\masseffect.exe |
"{7AC779A1-3E62-4CC4-835F-2C8FB9BB1E7A}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"{7B0D4BB2-CADC-4792-B6DB-8D6CD618255E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\swarm.exe |
"{7B568CA3-1644-4FFC-A00C-94C777EA7490}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\operation flashpoint dragon rising\mission editor\missioneditor.exe |
"{7C3DFE81-34B5-4A73-97C1-01B848CC0794}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\mafia ii\pc\mafia2.exe |
"{7CA06C45-0C45-4392-99B3-341DA3F03D82}" = protocol=6 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{7DE626F6-DA19-4842-A16D-9649ABC49F07}" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
"{7E3A66A1-36BE-4FC9-8ECF-0C587002E0DA}" = protocol=6 | dir=in | app=c:\program files\sierra entertainment\world in conflict\wic.exe |
"{7E530CF5-7E82-45EF-BB39-2E05F24B25FB}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord\overlord.exe |
"{7EAB93AC-1FA1-4248-A879-C77FFDF358FA}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\brothers in arms hells highway\binaries\biahh.exe |
"{7EADF3FC-5093-4BC1-8F85-DEA8FDE4F544}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\chromed.exe |
"{7FAA06AB-673A-4EB6-9FB8-9BF2E523F857}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the first encounter\bin\samhd.exe |
"{7FB325D8-F9BD-4138-894B-E40FFA7187A7}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\overlord\config.exe |
"{8023FC32-982D-4545-8A4A-3A95530A5B56}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\mass effect 2\masseffect2launcher.exe |
"{80DC56E7-CE82-4E14-A51F-0AFE7F9C0DC8}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{81FA11F8-42C0-431C-ACB5-D54C3153AB11}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{836DDE86-1B68-409A-9758-28779143748F}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\karol754\counter-strike source\hl2.exe |
"{851322B0-1F06-4A1F-B0BD-A4F8C22B9B34}" = protocol=6 | dir=in | app=c:\program files\mass effect\masseffectlauncher.exe |
"{85CA29B0-2DE6-4EB1-A36F-277D06655F9A}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
"{86C9C2CF-936E-400D-8927-D53538CACE19}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\fc2editor.exe |
"{87634851-B96D-465E-BB3C-E4EC4D3D7E32}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{87A08979-4084-4B6D-8CE2-6F6D04BA55F6}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\karol754\counter-strike source\hl2.exe |
"{87BD9B00-B14C-4215-8E6C-C444FFB36E4A}" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\app4r.exe |
"{88B7B053-ACDB-45C5-B54B-2A737BCE5A3E}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the first encounter\bin\samhd_demo.exe |
"{89ECF44D-62AC-40E5-89F7-F118FA513EE8}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{8A395CAB-AFA5-4F5E-BDE0-D52A440B1C54}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\fc2serverlauncher.exe |
"{8A449558-4C19-42B9-B939-DC12463BC542}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\mass effect 2\masseffect2launcher.exe |
"{8AB25940-0F40-4F9F-9BBB-85F904AAE114}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii - demo\config.exe |
"{8AC98F69-5560-430C-B3E3-39E30CDABA55}" = protocol=6 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
"{8AE615C6-52C3-4ABF-AE04-7E62FCCD588E}" = protocol=17 | dir=in | app=c:\program files\thq\company of heroes\relicdownloader\relicdownloader.exe |
"{8AF7B693-55A2-4048-ACAB-87305A3EBD7A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\metro 2033\metro2033.exe |
"{8BA2F3AB-F2E8-43B6-842F-FFD8AEC0835F}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddpswx.exe |
"{8C5477C6-A461-4F96-8B6D-49A888245B97}" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysis.exe |
"{8C604B4F-50E7-4FB9-A533-C4666A42BACA}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{8DF1B2EE-A7AC-4D4F-93C5-D57ABEFAAE26}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddjswx.exe |
"{8E357E17-922D-4130-A64A-7B85BB4A3C54}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{8E4B4838-6C69-4C94-8BFB-72BF755DF2DC}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
"{8E87516F-FB14-4F92-8E71-72599D080CD7}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{90B9CD12-E253-4067-88AA-D5AB91D74707}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\rainbow six vegas 2\binaries\r6vegas2_game.exe |
"{90DA8A76-85B5-411C-9B3C-26FC1E1C701D}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\call of juarez\chromed.exe |
"{92EB5A7A-1B77-4555-9569-9BEFF3320358}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddtime.exe |
"{9316DEB4-FEC6-47EF-AFA9-5223C00AF509}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe |
"{9318B24B-2BE1-4BA8-A5AE-A6292EC0F72D}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\stalker call of pripyat\stalker-cop.exe |
"{932D502D-8ED4-429E-9F46-C2F9636FAA99}" = protocol=6 | dir=in | app=c:\program files\ea games\mirror's edge\binaries\mirrorsedge.exe |
"{935421A7-DA59-4F35-B542-A33ABAE4A192}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe |
"{95609E6B-0305-40FF-BB28-C97399CFFF9D}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dark sector\ds.exe |
"{960A5144-4921-4388-9080-35F123DF5F69}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{9782628A-386B-4E5F-A11C-4F06A59B3639}" = dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{979F9E13-80D2-405A-B848-38180AD5D8D9}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\darkest of days demo\darkestofdays.exe |
"{97DAE012-48D7-4830-B996-B440BB2ED428}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\stranger's wrath\launcher.exe |
"{98000ED0-885F-4D46-A46D-311EFB8D4AF8}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mass effect 2\masseffect2launcher.exe |
"{990AE074-24FA-46AC-A2E8-8F86FA8364B6}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\lost planet 2\launcher.exe |
"{9968BE73-B823-47CA-B2B1-39A5E5D7C6D9}" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"{997045CD-851A-4964-83E2-F2C8F74DE8D8}" = protocol=6 | dir=in | app=c:\program files\sierra entertainment\world in conflict\wic_online.exe |
"{99FC028C-BA7F-443E-9958-15EDE5D83103}" = protocol=6 | dir=in | app=c:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\dedicated\xrengine.exe |
"{9AB24A05-E1F9-4848-9351-B2C4615858AA}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\resident evil 5\launcher.exe |
"{9C288D39-CC5D-483D-8344-5D75FFC32AB9}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\resident evil 5\launcher.exe |
"{9C5FB571-5CCC-49D9-A4E6-D17BEB127623}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the first encounter\bin\samhd.exe |
"{9C637531-9D5D-4086-9BD7-77B81E847DAE}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\stalker call of pripyat\stalker-cop.exe |
"{9C775270-3914-43A2-BD15-AC11EE92714A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\darkest of days demo\darkestofdays.exe |
"{9D6BD5B2-C5E2-4959-8D4B-0E4FE76DA12B}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\rainbow six vegas 2\binaries\r6vegas2_game.exe |
"{9D8C7D30-354F-4855-A69D-2A2E4A1CFC1F}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of juarez\coj.exe |
"{9E2DEC76-CB90-4A07-BF2F-8E0887E3AB4A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mass effect 2\masseffect2launcher.exe |
"{9E7E940B-F71E-4B15-90E6-E1FBBA918E3F}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe |
"{9ECBCE6E-5086-4F05-ABFF-EF78FFD5B25B}" = protocol=17 | dir=in | app=c:\program files\sierra entertainment\world in conflict\wic_ds.exe |
"{9EEF70A8-AD99-40FC-9A43-561E7A74AE2A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse_unrestricted.exe |
"{9F0DEE79-0188-4A2C-8304-48473DC9756D}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\alien swarm\swarm.exe |
"{A0217962-60A7-4B39-82C0-9284CC1929C3}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe |
"{A037B565-441A-42C1-989E-4528A85332E5}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{A0535611-24AE-40D5-A7A1-B6C20C51B288}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx10.exe |
"{A1BF24A8-C0F2-4491-B1F5-F4CE73E6DD0C}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\alien swarm\srcds.exe |
"{A297182E-F959-4DD7-8AE0-E669D17043F6}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{A3825F88-ECAB-4282-AAFA-9C517F9954B6}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\lost planet extreme condition\lostplanetdx10.exe |
"{A395F056-B72E-470E-B1B1-28E63B9FEEEF}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx10.exe |
"{A3E4E7B7-29BE-400E-8F83-8F803B1EA65B}" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
"{A4CC5468-FEA6-47FB-BB58-34BC4326B033}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A587EEFA-828F-4E76-87DB-AC1E1A798219}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse.exe |
"{A631634C-01D8-4987-B977-D323E9145BD9}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2launcher.exe |
"{A64C7318-7C56-43C3-B90E-24C787B8A89E}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii\config.exe |
"{A67FFCF8-4A31-4BAB-AE67-38DFD02E057C}" = protocol=6 | dir=in | app=c:\program files\thq\company of heroes\relicdownloader\relicdownloader.exe |
"{A784E5D5-7A66-47A1-99F5-D104B7BF4148}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{A9CB515B-2C43-4EE8-B871-D38FD051D1CD}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dead rising 2\deadrising2.exe |
"{AA3877A6-669D-4F37-B72D-7B61B39A3096}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{AA657E37-3DB6-48D1-8CD5-DA08965B5B67}" = protocol=17 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{AC38C145-C4DD-4C37-8896-C4711304F402}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\coj_dx10.exe |
"{AC9EE6E5-F380-40F8-BBEB-002CD8E8FD3C}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\operation flashpoint dragon rising\mission editor\missioneditor.exe |
"{ACB80D1C-5981-4295-9740-E22FE22D94A2}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\killingfloor\system\killingfloor.exe |
"{AD49510F-F925-44B1-BA50-2D4BE71FD030}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\lara croft and the guardian of light\lcgol.exe |
"{AD8EE79C-8732-4A1A-98AB-B5F129A3A59D}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{ADCD43A1-1A03-4348-A06C-D064D903FAF0}" = protocol=6 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{AE1F594C-DBE6-400F-83D8-E9862F095D27}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddjswx.exe |
"{AF24B7D0-33F2-487B-8107-D5B880F0700A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\trine\trine_launcher.exe |
"{AF82513F-0F55-4C84-8BBC-B8C4C5428694}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{B0CEA569-27D8-47B0-AEF5-BD59217D1D8A}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\lara croft and the guardian of light\lcgol.exe |
"{B28E44A7-6EB4-4DFB-801E-56FEAA28F0C0}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\srcds.exe |
"{B29F8BBC-E0E4-416A-A19F-F50F6C289ACA}" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\lxddmon.exe |
"{B3987365-4510-4E82-BC93-C33DAA7DAF1A}" = protocol=17 | dir=in | app=c:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe |
"{B4EDFBDD-DFAC-4D6C-9AEB-6BEFBDB95CDA}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse.exe |
"{B4F3F90C-89C9-4545-A28F-59230BA2C33E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\trine\trine_launcher.exe |
"{B5D1C8D8-5F49-4560-9C1C-1225543575FB}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\fear2\fear2.exe |
"{B68BFA38-160D-4031-9587-7095D8FA44B7}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\fc2benchmarktool.exe |
"{B6D8302D-6D95-4194-99E0-031F68B83DB9}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"{B6FE578B-96DD-40BA-9398-30D4126A8B76}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"{B8B47658-B3A5-4CCD-AB23-A91940F492B4}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\street fighter iv\sf4launcher.exe |
"{BA1C857F-F217-4EA0-8741-C789B9EDFBB9}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddpswx.exe |
"{BA721395-22AA-402A-8E49-95FDD8B9CA9C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\lost planet extreme condition\lostplanetdx10.exe |
"{BABA3339-1A00-49C9-8169-802DD43EEB1E}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\street fighter iv\sf4launcher.exe |
"{BC136759-1B69-4852-A4D9-ABBC236397BF}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse.exe |
"{BCD38C76-64AD-4902-85D3-1762F671B088}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe |
"{BCE4DC92-8D02-4C44-AE30-65D7C6E8CD76}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of juarez\coj_dx10.exe |
"{BE414669-E000-4F33-9A50-ABB76D33383F}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\call of juarez\coj.exe |
"{BF6810A2-C6A3-4387-90C4-E37562A36A5E}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse_unrestricted.exe |
"{C097B379-1572-497F-BBC4-E4F4904274BE}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\coj_dx10.exe |
"{C0BCF4CD-C789-4282-A6B7-113345963024}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\darksiders\darksiderspc.exe |
"{C0F1E67F-56F1-499E-94D0-0957AE137D3E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{C14FDBD9-74F6-4F4F-A53E-5FEEBFD8091F}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the first encounter\bin\samhd_demo.exe |
"{C20AEC67-52ED-4290-8DC5-BFF2A250FA2D}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe |
"{C2BD7582-EF61-47C8-8058-FF880994A038}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddpswx.exe |
"{C2F36701-148B-45AD-A373-E7FCF9F40472}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\just cause 2\justcause2.exe |
"{C3C49105-2172-4895-8E54-73AD089DBA86}" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\lxddmon.exe |
"{C4AD998A-6164-4D42-9F97-5BB173347890}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe |
"{C4C71167-DF9E-4FCC-8CAD-725A92A67CEC}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{C4F5EB23-4DAB-4C0A-96B2-130E6331B623}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\lost planet extreme condition\lostplanetdx9.exe |
"{C4FE29C9-56A1-45CD-8F3C-52F0A748E56D}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\supreme commander 2\bin\supremecommander2.exe |
"{C58AE285-A575-458C-9419-403363B23018}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\stranger's wrath\launcher.exe |
"{C5F988C0-8438-4ACF-9BB7-A2C009A5AF41}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\supreme commander 2\bin\supremecommander2.exe |
"{C62D5C3C-DC6B-4EB0-B688-26DBE5DC5F69}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\call of juarez\coj_dx10.exe |
"{C68DC321-5E00-47D0-B8C4-58748D08505C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\lost planet 2\launcher.exe |
"{C6D9F28B-D5B5-4FA3-8832-1D4DC97E06E1}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{C7DF3864-BB2C-4B8B-B3FA-747F3B1E3BF4}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{C84D0A69-2388-4FB0-8306-E0B3FDD408A0}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\swarm.exe |
"{C91A51DD-595F-403D-83F9-95F95F1CF505}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of duty black ops\blackopsmp.exe |
"{C96EEE1B-84A9-4E68-BFD7-EE895D669E26}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2launcher.exe |
"{C99CE8BB-9EEC-48CC-8683-0ADA0FB16CE2}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{CA44F58C-7B82-43FD-8245-8CC5DB486AD7}" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"{CAC6FB4A-09C4-4084-878D-4888375323F5}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii - demo\overlord2demo.exe |
"{CAE2EF9A-58E9-4360-928F-B36DF8FBF037}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{CB128A1A-B801-481F-93D6-21FBC1BD531E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{CB6D2AA7-977A-4CF7-A059-7101897F6019}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddtime.exe |
"{CCEB6D51-6FAC-44D0-A91A-559A0E9D2E3F}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\magicka\magicka.exe |
"{CCFEE085-E347-4EC8-9042-4D9EE0CE06F6}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\supreme commander 2\bin\supremecommander2.exe |
"{CD01FC1A-8873-4EA1-90D7-0957403512F2}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{CD5B62E1-92AC-4E62-BB48-F27FAF4BC223}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe |
"{CD5D1C8B-6142-4A2C-9DD1-3E82142A6036}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe |
"{CD7F5429-4D43-4EA8-90F5-2DAE02FB1EA0}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\audiosurf\engine\questviewer.exe |
"{D040FD67-BE56-43AF-8823-16683E17BA7E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\puzzle quest\puzzle quest.exe |
"{D13F3A79-A6C8-42FF-9D9E-4B4B1E13F64B}" = protocol=6 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutparadise.exe |
"{D1545D83-3CF7-4D3D-86E2-F5409DD73D23}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\master levels of doom\master.bat |
"{D24AA66B-E27A-43E2-9040-3478B9BD6271}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\call of juarez\cojdx10_benchmark.exe |
"{D24C3510-3C88-4844-A44D-D063314D2490}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii - demo\config.exe |
"{D27E36AA-C567-4A7C-9C03-8F499F37E861}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse_unrestricted.exe |
"{D47DA684-66D2-4BA2-A59E-E3963541941B}" = protocol=17 | dir=in |
 
app=f:\steam\steamapps\common\operation flashpoint dragon rising\mission editor\missioneditor.exe |
"{D4BAE24A-249E-44E8-A6FD-BC5CD25A78DE}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mass effect 2\masseffect2launcher.exe |
"{D537629B-C57B-4199-817F-8116A31889FA}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\peggle extreme\peggleextreme.exe |
"{D57AFE04-52A0-41D9-8124-20157A99C29E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mass effect 2\masseffect2launcher.exe |
"{D5BB49B9-C77B-44E5-8C47-90DA190E634C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mass effect 2\docs\ea help\electronic_arts_technical_support.htm |
"{D61224ED-4934-404A-853C-FF122D952229}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
"{D74BDA31-2BE4-4604-BD9B-D4D896B43C78}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\world of goo\worldofgoo.exe |
"{D7708D8D-EF21-4F75-ACE8-0CCC2088EE8A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\just cause 2\justcause2.exe |
"{D784D5BA-906A-4E8D-B390-1C1C95376E9A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\cojdx10_benchmark.exe |
"{D7DF279C-606B-49B8-B402-321A37228AFB}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\coj.exe |
"{D88EF919-7A45-417B-BFF4-DFCA4AFC5199}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse_unrestricted.exe |
"{D8B4D5FB-588C-4606-AE7A-99301E20797B}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez - bound in blood\cojbibgame_x86.exe |
"{D8F50015-56EB-40EF-B191-7FF2BB9D9930}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\farcry2.exe |
"{D98B4735-0FFD-48B1-B201-61D02DDB6D20}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\stalker call of pripyat\stalker-cop.exe |
"{DA4A4162-A171-47A9-B154-586C8C069925}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\splinter cell - double agent\scdalauncher.exe |
"{DA4BC8AC-1446-468F-89F7-D929653306B2}" = protocol=6 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysis.exe |
"{DB0B0A66-056B-413B-AFB1-1195D7F9D7ED}" = protocol=17 | dir=in | app=c:\program files\codemasters\grid\grid.exe |
"{DB356ECE-115E-4F5B-8671-7BBD78B9098A}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dead space\dead space.exe |
"{DB8BF4A6-65D3-46A4-A614-6C637DDDA61A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\deus ex\system\deusex.exe |
"{DC62129D-ABBA-44B5-B71F-70ED08518F73}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\doom 2\doom2.bat |
"{DC949B31-9429-4F1C-B1BA-5CF5D14CBE10}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\mafia ii\pc\mafia2.exe |
"{DD40BDF7-AF68-444F-BB08-62F33E14D516}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{DEDA25AD-B252-4795-9F72-C00AA1B240B7}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2launcher.exe |
"{DF52CD4B-2B37-4318-8921-A1316A084B48}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{E08BA285-8B9C-4959-ABA4-6C90F8A3DB4E}" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
"{E0942DEB-3276-4E0F-A7AF-10A476E809C1}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
"{E0A15DDA-A157-41CF-B8AD-EFDBAB094CDA}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse.exe |
"{E13F380D-9197-4819-98A5-A07BEBB278F9}" = protocol=17 | dir=in | app=c:\program files\volition inc\red faction guerrilla\rfg.exe |
"{E15AC2C1-CA32-4432-B437-FA5E5BEA6818}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2launcher.exe |
"{E20BB974-8BA5-49A8-819F-1342192EF929}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe |
"{E21E47A0-FC3F-4737-A92F-B701E0A72206}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\call of duty black ops\blackops.exe |
"{E37556C3-10E5-4331-B688-4CC4794C0E7A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
"{E41124FB-B967-4AD5-8D3E-081FCDBA5EFC}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\operation flashpoint dragon rising\ofdr.exe |
"{E4953C7D-4240-4F33-B9B0-9F3F73B5FCDF}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dirt 2\dirt2.exe |
"{E4E8C859-C9B3-4B2E-903F-744B3C48F9B7}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty black ops\blackops.exe |
"{E5618049-59CA-4356-9ABB-043EA07322A3}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\alien swarm\swarm.exe |
"{E5CD4AC4-BB1F-4465-A6C6-29BE0E412573}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{E5ED4F87-A257-444A-93F7-098B4082F5A6}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2launcher.exe |
"{E5FC8B15-8B18-4A32-9C06-F89D1FB81CC1}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe |
"{E60A59CA-DD1D-4CEE-B44D-DB7809119F51}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\operation flashpoint dragon rising\ofdr.exe |
"{E6AA022B-5692-49E2-A6E2-F4D7F4FB5D65}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
"{E6D3B735-F510-4D48-AE46-6C5B72742A7B}" = protocol=17 | dir=in | app=c:\program files\sierra entertainment\world in conflict\wic.exe |
"{E6F943FB-BEA8-4C71-ADC3-330C5E44C090}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\alien swarm\srcds.exe |
"{E81BBD2E-FF98-4BB7-B4D5-27ED77F01D22}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\doom 2\doom2.bat |
"{E8286468-12FE-4563-9575-F7C9020F365B}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\mass effect 2\docs\ea help\electronic_arts_technical_support.htm |
"{E8D3B2ED-8973-44E1-9D04-3BFD84994611}" = protocol=6 | dir=in | app=c:\program files\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{E9337803-110C-425B-BDE4-C4C4164F523A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
"{E93B6C61-ACFE-44D2-8808-2EAEB4CF4971}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{E9950158-E127-419C-8889-239D14117874}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\puzzle quest\puzzle quest.exe |
"{EA878C4A-8AA3-421B-8EA2-49AAE98578D9}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\metro 2033\metro2033.exe |
"{EB67E135-5B76-4C8D-A962-FBAE78D2E171}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{EC650021-C11D-4D74-82BF-2AE8B3AC408C}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\rainbow six vegas 2\binaries\r6vegas2_game.exe |
"{ED2B6F0B-EB85-4C82-944F-61ED5A624A9E}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty black ops\blackopsmp.exe |
"{ED2E91A7-2E0B-4F56-8C84-9942D5CDB884}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\supreme commander 2\bin\supremecommander2.exe |
"{ED7C133D-E7B4-41E3-A1B0-20BA013BA997}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{EE4F613A-93F0-45C8-B2C7-5C59947A4A4B}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\metro 2033\metro2033.exe |
"{EF6C3A40-87DA-4117-8AE9-EAE54F82AC76}" = protocol=17 | dir=in | app=c:\program files\mass effect\binaries\masseffect.exe |
"{EF9DF154-7969-4ADE-A0F2-0CBA1E74789C}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\fear2\fear2.exe |
"{F09A57E5-F0D1-4600-9A41-BEC1AD3D2C67}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\kane & lynch 2 - dog days\kl2.exe |
"{F1196620-08D8-4E2A-8701-25761F915AD6}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{F1A00F28-38B3-4335-99E5-ECE9907CA62E}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
"{F1FDE7C3-CA19-40DF-AD49-999C40929E2F}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mass effect 2\docs\ea help\electronic_arts_technical_support.htm |
"{F2BB1C88-0ABF-424E-A688-9A455BD1DDD3}" = protocol=17 | dir=in | app=c:\program files\sierra entertainment\world in conflict\wic_online.exe |
"{F3E00A04-148A-4727-878D-61F0ADE3E701}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"{F5C2EC19-91C4-404A-A1A2-51BAFFBD3656}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of juarez\cojdx10_benchmark.exe |
"{F60DEF98-0983-4526-936F-A338E42E03D0}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\chromed.exe |
"{F7E06316-0876-4770-B7EA-8C8E885B0184}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2launcher.exe |
"{F84009BC-9C0A-49A5-ABAC-406C92F7485E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe |
"{F85AB511-8A15-4917-9B02-559FDA87CD13}" = protocol=17 | dir=in | app=c:\program files\microsoft games\gears of war\binaries\wargame-g4wlive.exe |
"{F8954B33-96B6-4E55-81D4-8C9327A3E068}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\rainbow six vegas 2\binaries\r6vegas2_game.exe |
"{F979BC35-5E8B-4C55-8DAD-F69CA5F9A0A9}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddpswx.exe |
"{F984F00F-C457-484D-812C-1FEA95EAA843}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\supreme commander 2\bin\supremecommander2.exe |
"{F9E57377-EEE8-4802-B6DA-351DA178A2E9}" = protocol=17 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutconfigtool.exe |
"{FA414B4B-7775-4CF2-A399-498D048FBF21}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\karol754\counter-strike source\hl2.exe |
"{FB0C80DC-9C16-4736-AE09-24981CDB435D}" = protocol=17 | dir=in | app=c:\program files\activision\call of duty 4 - modern warfare\iw3mp.exe |
"{FB2D287D-4297-4488-B23D-976BB5E31C1A}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{FDD6A029-8DB0-4DDA-A5F6-AED7193ECFF8}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\peggle extreme\peggleextreme.exe |
"{FE06F299-1FD7-4B0F-B546-11F36B171820}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\trine\trine_launcher.exe |
"{FF3A7E60-7B45-4FC0-824A-0EF53465094E}" = protocol=6 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysis.exe |
"{FF9F4632-A353-43F0-8F32-F9BAB4EB8152}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\zombie driver\release\zombiedriver.exe |
"{FFD931F3-387F-433B-8302-546FB4EC171C}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\supreme commander 2\bin\supremecommander2.exe |
"TCP Query User{002323C0-EFEB-4625-A3E0-318C51564DB1}C:\program files\steam\steamapps\common\street fighter iv\streetfighteriv.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\street fighter iv\streetfighteriv.exe |
"TCP Query User{0BA4EA77-9CEE-48B7-A896-5D070FD8B17F}C:\users\user\appdata\local\temp\c3ce06baa0504d618da4e76b7512b906\relicdownloader.exe" = protocol=6 | dir=in | app=c:\users\user\appdata\local\temp\c3ce06baa0504d618da4e76b7512b906\relicdownloader.exe |
"TCP Query User{192CFEAC-59C0-45F6-BC35-5A96E4D7B705}C:\program files\steam\steamapps\common\dirt 2\dirt2_game.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dirt 2\dirt2_game.exe |
"TCP Query User{1A623A84-C0C8-4751-A9AA-F2609C5106DA}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"TCP Query User{1C0B00DC-D896-423C-88C2-E5E888357102}C:\program files\rockstar games\eflc\eflc.exe" = protocol=6 | dir=in | app=c:\program files\rockstar games\eflc\eflc.exe |
"TCP Query User{2222A774-7F70-4E37-B489-63DC2385C8B6}C:\program files\steam\steamapps\common\splinter cell - double agent\scda-offline\system\splintercell4.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\splinter cell - double agent\scda-offline\system\splintercell4.exe |
"TCP Query User{2762BB5A-F0A9-4D9F-8755-862BA43E92A1}C:\program files\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe |
"TCP Query User{30C879E3-F0BF-45C4-935C-E70E4CB54C4E}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{350D3E42-5CC7-4883-A606-24494CC3A469}C:\users\user\appdata\local\temp\b6e54071f05341868e8567ff58759800\relicdownloader.exe" = protocol=6 | dir=in | app=c:\users\user\appdata\local\temp\b6e54071f05341868e8567ff58759800\relicdownloader.exe |
"TCP Query User{35781E8C-03CE-4333-9882-98ED78C5AF06}C:\program files\steam\steamapps\common\left 4 dead demo\left4dead.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead demo\left4dead.exe |
"TCP Query User{3EEDD4CD-F39E-4789-B9EF-D9BBE8579E45}C:\program files\steam\steamapps\common\dead space\dead space.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dead space\dead space.exe |
"TCP Query User{4016158E-4406-4DA8-88A7-4BCA4207AF95}D:\xfire\xfire.exe" = protocol=6 | dir=in | app=d:\xfire\xfire.exe |
"TCP Query User{40BFBA37-F409-4C97-9199-094DDFE0FDE6}C:\program files\bethesda softworks\fallout 3\fallout3.exe" = protocol=6 | dir=in | app=c:\program files\bethesda softworks\fallout 3\fallout3.exe |
"TCP Query User{45065ADD-A523-49BF-80FC-1EF88870CACF}C:\program files\steam\steamapps\karol754\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\karol754\team fortress 2\hl2.exe |
"TCP Query User{45540C66-C621-4853-9DB6-ED33DF69E051}C:\program files\steam\steamapps\common\rainbow six vegas 2\binaries\r6vegas2_game.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\rainbow six vegas 2\binaries\r6vegas2_game.exe |
"TCP Query User{4619A8B2-1E12-48D1-8905-96741E7FA239}F:\steam\steamapps\karol754\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=f:\steam\steamapps\karol754\team fortress 2\hl2.exe |
"TCP Query User{47D78FD3-4F4C-4BF0-A1C1-B54F469B88A9}C:\program files\steam\steamapps\common\dead space\dead space.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dead space\dead space.exe |
"TCP Query User{4D210AE6-1123-4304-96F1-16897E279534}C:\program files\atari\the chronicles of riddick - assault on dark athena\system\win32_x86\darkathena.exe" = protocol=6 | dir=in | app=c:\program files\atari\the chronicles of riddick - assault on dark athena\system\win32_x86\darkathena.exe |
"TCP Query User{4ED731BD-F2D9-47C5-A6E4-06D2CC1B351D}C:\program files\aim\aim.exe" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
"TCP Query User{509986D4-94D1-4E53-9050-B8879893722D}C:\program files\steam\steamapps\common\lost planet 2\lp2dx11.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\lost planet 2\lp2dx11.exe |
"TCP Query User{554975A4-4FF8-4BDD-84C2-899620C944EE}C:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutparadise.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutparadise.exe |
"TCP Query User{5E88EA7A-19CC-47E1-879A-B6DFFB595F00}C:\program files\steam\steamapps\common\nba 2k10\nba2k10.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\nba 2k10\nba2k10.exe |
"TCP Query User{5F530874-596B-4E2F-BF00-7056BE282177}C:\program files\electronic arts\crytek\crysis wars\bin32\crysis.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\crytek\crysis wars\bin32\crysis.exe |
"TCP Query User{5FF98F51-A5BE-4A90-BDC8-C968AB6DB3F5}C:\program files\steam\steamapps\karol754\half-life\hl.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\karol754\half-life\hl.exe |
"TCP Query User{694DB969-31DE-49C7-AABD-9B3613FCA641}F:\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=6 | dir=in | app=f:\steam\steamapps\common\resident evil 5\re5dx10.exe |
"TCP Query User{701B7E57-210F-4660-8BD8-CAA6121B2590}C:\program files\bethesda softworks\fallout 3\fallout3.exe" = protocol=6 | dir=in | app=c:\program files\bethesda softworks\fallout 3\fallout3.exe |
"TCP Query User{779996EB-F920-4655-AC6E-6E0469B0C8B7}C:\program files\rockstar games\grand theft auto iv\gtaiv.exe" = protocol=6 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\gtaiv.exe |
"TCP Query User{784900E5-A1B7-4E40-B49E-021D1E3AD798}C:\program files\steam\steamapps\common\street fighter iv\streetfighteriv.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\street fighter iv\streetfighteriv.exe |
"TCP Query User{7FC540C0-D628-4704-85CE-87E24A749FF2}C:\program files\gadu-gadu\gg.exe" = protocol=6 | dir=in | app=c:\program files\gadu-gadu\gg.exe |
"TCP Query User{80750F8C-289B-4391-A0C5-07C6B0DF3B08}C:\program files\lexmark 2500 series\lxddamon.exe" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\lxddamon.exe |
"TCP Query User{8E7CF103-5729-41B9-8E61-A646A808291C}C:\program files\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"TCP Query User{915DB8AA-C706-49ED-A855-BF6B7E125203}C:\program files\steam\steamapps\common\splinter cell - double agent\scda-offline\system\splintercell4.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\splinter cell - double agent\scda-offline\system\splintercell4.exe |
"TCP Query User{969CFDA0-B0F4-481C-90E5-06793C5CF943}C:\program files\microsoft games\gears of war\binaries\wargame-g4wlive.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\gears of war\binaries\wargame-g4wlive.exe |
"TCP Query User{9AEF7486-F923-4695-953A-54562B2E4C68}C:\program files\thq\company of heroes\reliccoh.exe" = protocol=6 | dir=in | app=c:\program files\thq\company of heroes\reliccoh.exe |
"TCP Query User{9B8CBBE5-AFFF-4221-97FD-C6439BA366D3}C:\program files\steam\steamapps\common\lost planet 2\lp2dx9.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\lost planet 2\lp2dx9.exe |
"TCP Query User{A45E5F71-4CD3-489D-907E-C4F65D544C1C}C:\program files\rockstar games\grand theft auto iv\gtaiv.exe" = protocol=6 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\gtaiv.exe |
"TCP Query User{A4E67B54-1256-410B-9310-400E30468659}C:\program files\lexmark 2500 series\app4r.exe" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\app4r.exe |
"TCP Query User{A85DB545-F398-41D5-9479-E21CC093639F}C:\program files\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\resident evil 5\re5dx10.exe |
"TCP Query User{A9E2E490-194A-4DF6-8E5B-C7EDD248F9E3}C:\program files\electronic arts\crytek\crysis wars\bin32\crysis.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\crytek\crysis wars\bin32\crysis.exe |
"TCP Query User{AD66CA4F-0A21-40F9-85AF-5B78143ED69B}D:\bad comapny2\bfbc2game.exe" = protocol=6 | dir=in | app=d:\bad comapny2\bfbc2game.exe |
"TCP Query User{B0FAE153-C7FF-4C06-BB57-CAFE0F6BD26E}C:\program files\eidos\batman arkham asylum\binaries\shippingpc-bmgame.exe" = protocol=6 | dir=in | app=c:\program files\eidos\batman arkham asylum\binaries\shippingpc-bmgame.exe |
"TCP Query User{B19C34CE-0E76-4064-A03F-BA2C3340AA1B}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{B5394CBB-8337-4D29-A8B3-667A90DCA5A4}C:\users\user\appdata\local\temp\e9e416c32092471c863b1563b6fb0ff6\relicdownloader.exe" = protocol=6 | dir=in | app=c:\users\user\appdata\local\temp\e9e416c32092471c863b1563b6fb0ff6\relicdownloader.exe |
"TCP Query User{B94A7F7B-7342-43A3-A94A-462775B2B1FE}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"TCP Query User{C1382188-9B58-4197-97CF-0B5052E0533A}D:\grid\grid.exe" = protocol=6 | dir=in | app=d:\grid\grid.exe |
"TCP Query User{C28CC99D-C743-4B80-ACCD-9B06C3C843D0}C:\program files\thq\company of heroes\relicdownloader\relicdownloader.exe" = protocol=6 | dir=in | app=c:\program files\thq\company of heroes\relicdownloader\relicdownloader.exe |
"TCP Query User{C57056AE-CBD5-4B60-B988-FE9C5596F707}C:\program files\volition inc\red faction guerrilla\rfg.exe" = protocol=6 | dir=in | app=c:\program files\volition inc\red faction guerrilla\rfg.exe |
"TCP Query User{C70BF536-14A6-4018-9D49-03732A4F27CF}C:\users\user\desktop\tf2 idle\steamstats.exe" = protocol=6 | dir=in | app=c:\users\user\desktop\tf2 idle\steamstats.exe |
"TCP Query User{CB6EA058-2B4B-4899-9D23-724EEA21B4B6}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{D5E1C3DD-6C3F-411F-99D2-D77B17AA60DA}C:\users\user\desktop\tf2 idle\steamstats.exe" = protocol=6 | dir=in | app=c:\users\user\desktop\tf2 idle\steamstats.exe |
"TCP Query User{DFDE6D09-F0C4-471F-A822-5571B2A3B7CE}C:\program files\codemasters\grid\grid.exe" = protocol=6 | dir=in | app=c:\program files\codemasters\grid\grid.exe |
"TCP Query User{E076DF82-C275-4DE7-927B-E9486C7ED543}D:\xfire\xfire.exe" = protocol=6 | dir=in | app=d:\xfire\xfire.exe |
"TCP Query User{E4F81C3E-6E96-4B08-9C88-5E77FFB3CBE6}C:\program files\steam\steamapps\karol754\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\karol754\team fortress 2\hl2.exe |
"TCP Query User{EEFACDA8-6694-46ED-A185-5A034C8EB31C}C:\program files\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe |
"TCP Query User{FD5C0A90-C662-4792-B5CD-D84CF972CF2F}C:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe" = protocol=6 | dir=in | app=c:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe |
"TCP Query User{FE860E23-FEEB-4ACB-B6E5-E964D947217F}C:\program files\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\resident evil 5\re5dx10.exe |
"UDP Query User{07CEE403-ECCD-45E3-BBB9-8554A792C00C}C:\program files\electronic arts\crytek\crysis wars\bin32\crysis.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis wars\bin32\crysis.exe |
"UDP Query User{0C2718CA-B9DD-4FFC-80A4-E4403B3C2DE3}C:\program files\atari\the chronicles of riddick - assault on dark athena\system\win32_x86\darkathena.exe" = protocol=17 | dir=in | app=c:\program files\atari\the chronicles of riddick - assault on dark athena\system\win32_x86\darkathena.exe |
"UDP Query User{10BEFDED-BAB6-4540-9B46-95FC9543AB9E}C:\program files\bethesda softworks\fallout 3\fallout3.exe" = protocol=17 | dir=in | app=c:\program files\bethesda softworks\fallout 3\fallout3.exe |
"UDP Query User{1841CBE7-F559-4EB2-875B-ABA8263BFF4F}C:\program files\steam\steamapps\common\street fighter iv\streetfighteriv.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\street fighter iv\streetfighteriv.exe |
"UDP Query User{25D49622-1684-43FD-9A15-8F284FA88A5D}C:\users\user\appdata\local\temp\e9e416c32092471c863b1563b6fb0ff6\relicdownloader.exe" = protocol=17 | dir=in | app=c:\users\user\appdata\local\temp\e9e416c32092471c863b1563b6fb0ff6\relicdownloader.exe |
"UDP Query User{2C8AA39A-0CE6-4D77-A396-BA69C5C58952}C:\program files\eidos\batman arkham asylum\binaries\shippingpc-bmgame.exe" = protocol=17 | dir=in | app=c:\program files\eidos\batman arkham asylum\binaries\shippingpc-bmgame.exe |
"UDP Query User{3658ED4C-64FB-4021-B314-3DC541A2D795}C:\users\user\desktop\tf2 idle\steamstats.exe" = protocol=17 | dir=in | app=c:\users\user\desktop\tf2 idle\steamstats.exe |
"UDP Query User{388D77C9-9A16-49B5-9372-572B103A2D5E}C:\program files\steam\steamapps\common\lost planet 2\lp2dx9.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\lost planet 2\lp2dx9.exe |
"UDP Query User{3A1A8D69-EA0B-4A43-91DD-80139E361AB6}C:\program files\steam\steamapps\karol754\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\karol754\team fortress 2\hl2.exe |
"UDP Query User{3F762A09-B090-4277-A2AA-CA52CA48E1E8}C:\program files\lexmark 2500 series\app4r.exe" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\app4r.exe |
"UDP Query User{42470FC1-B363-46D0-9A36-0D5AB6B55901}C:\users\user\appdata\local\temp\c3ce06baa0504d618da4e76b7512b906\relicdownloader.exe" = protocol=17 | dir=in | app=c:\users\user\appdata\local\temp\c3ce06baa0504d618da4e76b7512b906\relicdownloader.exe |
"UDP Query User{4318D333-474A-49CD-B2EC-988CF852D7DB}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{44E23F4C-4678-45EA-875F-039DC0E54A2D}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{468418D5-C011-4230-9B01-420275419582}C:\program files\thq\company of heroes\reliccoh.exe" = protocol=17 | dir=in | app=c:\program files\thq\company of heroes\reliccoh.exe |
"UDP Query User{46ACD912-7302-426A-8983-4CBCFBBEAE5A}C:\program files\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe |
"UDP Query User{48C002FC-1652-4088-9C8A-150DAED5C361}C:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe" = protocol=17 | dir=in | app=c:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe |
"UDP Query User{4EB7726D-90E9-4738-A186-F4997F977AC0}D:\xfire\xfire.exe" = protocol=17 | dir=in | app=d:\xfire\xfire.exe |
"UDP Query User{516960F6-B2FB-4179-9D40-CD75FF8A5E11}C:\program files\aim\aim.exe" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
"UDP Query User{51A590AA-3D62-431C-B185-8007F8818416}C:\program files\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\resident evil 5\re5dx10.exe |
"UDP Query User{637CAB72-81E9-4E73-BBAD-A0858F9603B5}C:\program files\rockstar games\eflc\eflc.exe" = protocol=17 | dir=in | app=c:\program files\rockstar games\eflc\eflc.exe |
"UDP Query User{64EFF5F4-28D1-4047-A648-550979600E29}C:\program files\steam\steamapps\common\splinter cell - double agent\scda-offline\system\splintercell4.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\splinter cell - double agent\scda-offline\system\splintercell4.exe |
"UDP Query User{654869F2-8F3F-4083-AE4C-47E1960ADD86}C:\program files\thq\company of heroes\relicdownloader\relicdownloader.exe" = protocol=17 | dir=in | app=c:\program files\thq\company of heroes\relicdownloader\relicdownloader.exe |
"UDP Query User{658ABB8F-E3EF-4127-B014-AF03AED51BE3}C:\program files\rockstar games\grand theft auto iv\gtaiv.exe" = protocol=17 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\gtaiv.exe |
"UDP Query User{6E130025-78CC-4065-BF47-754A3BB4DF2B}C:\program files\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\resident evil 5\re5dx10.exe |
"UDP Query User{76272F58-B2AD-408C-99AC-7D762B652D48}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"UDP Query User{7A833394-6FF0-43EB-9931-647E572143C2}C:\program files\codemasters\grid\grid.exe" = protocol=17 | dir=in | app=c:\program files\codemasters\grid\grid.exe |
"UDP Query User{7F1FB66C-3A16-472A-9414-5AEA003DFDD7}C:\program files\bethesda softworks\fallout 3\fallout3.exe" = protocol=17 | dir=in | app=c:\program files\bethesda softworks\fallout 3\fallout3.exe |
"UDP Query User{834565D2-119F-48A4-8035-6CC87A853BAC}C:\users\user\desktop\tf2 idle\steamstats.exe" = protocol=17 | dir=in | app=c:\users\user\desktop\tf2 idle\steamstats.exe |
"UDP Query User{847E1C96-7655-4A39-8081-0004843A6FAA}C:\users\user\appdata\local\temp\b6e54071f05341868e8567ff58759800\relicdownloader.exe" = protocol=17 | dir=in | app=c:\users\user\appdata\local\temp\b6e54071f05341868e8567ff58759800\relicdownloader.exe |
"UDP Query User{86A6F03B-67BF-45FC-BCD2-2CEB893B804F}D:\grid\grid.exe" = protocol=17 | dir=in | app=d:\grid\grid.exe |
"UDP Query User{9464B34D-2614-44EE-93E2-BC87D6624F65}D:\bad comapny2\bfbc2game.exe" = protocol=17 | dir=in | app=d:\bad comapny2\bfbc2game.exe |
"UDP Query User{984BBD36-F377-4172-A6B0-ACAD4DF16DF6}F:\steam\steamapps\karol754\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=f:\steam\steamapps\karol754\team fortress 2\hl2.exe |
"UDP Query User{98DBF7D7-13E3-4725-96F8-9D422294C614}C:\program files\lexmark 2500 series\lxddamon.exe" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\lxddamon.exe |
"UDP Query User{9AE2770E-C3DF-48CF-B772-8225E0B11EA9}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{A99D9D76-C819-43EF-94DA-E93955D56BBA}C:\program files\electronic arts\crytek\crysis wars\bin32\crysis.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis wars\bin32\crysis.exe |
"UDP Query User{A9EC8D32-22A0-4D03-895A-931693703F1C}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
"UDP Query User{AA8A4F07-E579-4976-8E7E-A14A276D68FE}C:\program files\rockstar games\grand theft auto iv\gtaiv.exe" = protocol=17 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\gtaiv.exe |
"UDP Query User{B38B995F-921C-4900-9A04-1254CCFE4E57}C:\program files\steam\steamapps\common\lost planet 2\lp2dx11.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\lost planet 2\lp2dx11.exe |
"UDP Query User{B3B86969-563F-48C7-A3B6-2C2D95DF1E39}C:\program files\steam\steamapps\karol754\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\karol754\team fortress 2\hl2.exe |
"UDP Query User{B4832CBD-1211-41FA-A0C9-8852FEEF3143}C:\program files\gadu-gadu\gg.exe" = protocol=17 | dir=in | app=c:\program files\gadu-gadu\gg.exe |
"UDP Query User{B5529654-26EF-46DB-9DF5-465B84636D4E}C:\program files\steam\steamapps\common\dirt 2\dirt2_game.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dirt 2\dirt2_game.exe |
"UDP Query User{BAC30FFC-4593-4C5F-A738-E03C61672F85}C:\program files\microsoft games\gears of war\binaries\wargame-g4wlive.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\gears of war\binaries\wargame-g4wlive.exe |
"UDP Query User{BFAF378C-230F-46BF-8F49-BDDD1BDC399C}C:\program files\volition inc\red faction guerrilla\rfg.exe" = protocol=17 | dir=in | app=c:\program files\volition inc\red faction guerrilla\rfg.exe |
"UDP Query User{C08C49D1-7864-4920-B339-57AC2BBA55C1}C:\program files\steam\steamapps\common\splinter cell - double agent\scda-offline\system\splintercell4.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\splinter cell - double agent\scda-offline\system\splintercell4.exe |
"UDP Query User{C41B4F64-4D56-4E70-AECD-53F4A5A994B8}C:\program files\steam\steamapps\common\rainbow six vegas 2\binaries\r6vegas2_game.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\rainbow six vegas 2\binaries\r6vegas2_game.exe |
"UDP Query User{C5CD08B2-3F35-4177-8192-B22150DE79EF}C:\program files\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
"UDP Query User{C8FC970F-A640-4B22-B4B2-9F65C51C7512}F:\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=17 | dir=in | app=f:\steam\steamapps\common\resident evil 5\re5dx10.exe |
"UDP Query User{D6853EA1-8D4D-4F47-A8A7-622820B820F6}C:\program files\steam\steamapps\karol754\half-life\hl.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\karol754\half-life\hl.exe |
"UDP Query User{DA57E934-EC40-448C-B7C0-F72FCF2AB252}C:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutparadise.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutparadise.exe |
"UDP Query User{DA60E5BE-FE0A-4DD0-8343-4263646BB50E}C:\program files\steam\steamapps\common\nba 2k10\nba2k10.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\nba 2k10\nba2k10.exe |
"UDP Query User{DBE387D6-10C2-4A81-B884-92B1565C2800}C:\program files\steam\steamapps\common\left 4 dead demo\left4dead.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead demo\left4dead.exe |
"UDP Query User{DCA9C6DB-37DB-4E9F-934A-5E22F14F6961}C:\program files\steam\steamapps\common\street fighter iv\streetfighteriv.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\street fighter iv\streetfighteriv.exe |
"UDP Query User{E734E51E-D9A6-478E-930A-A79AEDF223FE}C:\program files\steam\steamapps\common\dead space\dead space.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dead space\dead space.exe |
"UDP Query User{E7B933B6-FEE4-446A-A02B-93D5EF53F4C4}D:\xfire\xfire.exe" = protocol=17 | dir=in | app=d:\xfire\xfire.exe |
"UDP Query User{F785936F-6E38-4918-8BA4-07230F6266E9}C:\program files\steam\steamapps\common\dead space\dead space.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dead space\dead space.exe |
"UDP Query User{F8C62894-64D2-4DBC-989B-A88BD60A5A13}C:\program files\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{000E79B7-E725-4F01-870A-C12942B7F8E4}" = Crysis(R)
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{1170D24F-42B7-40CF-AA1B-6395CE562354}" = Gears of War
"{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"{14574B7F-75D1-4718-B7F2-EBF6E2862A35}" = Company of Heroes - FAKEMSI
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{199E6632-EB28-4F73-AECB-3E192EB92D18}" = Company of Heroes - FAKEMSI
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1B0FBB9A-995D-47cd-87CD-13E68B676E4F}" = Mass Effect
"{1BBDD6C0-ED6F-43C3-8A9C-84E3249A5615}" = Twin USB Vibration Gamepad
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FDA5A37-B22D-43FF-B582-B8964050DC13}" = Microsoft Games for Windows - LIVE Redistributable
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{25724802-CC14-4B90-9F3B-3D6955EE27B1}" = Company of Heroes - FAKEMSI
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
"{2987EE84-C4EE-4FF5-8160-32DE00D6ABC6}" = GTA2
"{310BC5E2-31AF-49BB-904D-E71EB93645DC}" = AI Suite
"{32072109-98AC-4BDD-BDD8-B9EDDB1EA971}" = SwitchBlade
"{32C4A4EB-C97D-414E-99C5-38F8DFD31D5D}" = Company of Heroes - FAKEMSI
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{43430808-081A-4C0D-B7CC-601000028501}" = LOST PLANET 2
"{4343080E-448E-4E2C-B27F-B91000018201}" = Dead Rising 2
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4E79A60F-15D2-4BEC-91AD-E41EC42E61B0}" = Batman: Arkham Asylum
"{50193078-F553-4EBA-AA77-64C9FAA12F98}" = Company of Heroes - FAKEMSI
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{51D718D1-DA81-4FAD-919F-5C1CE3C33379}" = Company of Heroes - FAKEMSI
"{5454083B-1308-4485-BF17-111000028701}" = Grand Theft Auto: Episodes from Liberty City
 
"{5454083B-1308-4485-BF17-111000038701}" = Grand Theft Auto: Episodes from Liberty City
"{5454083B-1308-4485-BF17-1110000B8301}" = Grand Theft Auto IV
"{5454083B-1308-4485-BF17-1110000D8301}" = Grand Theft Auto IV
"{5454085C-840F-4070-8FAA-441000038301}" = BioShock 2
"{54C93A8C-A15A-4439-BE64-2342202D4FF0}" = OpenOffice.org 2.3
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{579BA58C-F33D-4970-9953-B94B43768AC3}" = Grand Theft Auto IV
"{5A0B7BA5-4682-4273-81C2-69B17E649103}" = GRID
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{61B8B2F9-D8DA-4B24-89A9-DB09F38A4899}" = Grand Theft Auto: Episodes From Liberty City
"{66F78C51-D108-4F0C-A93C-1CBE74CE338F}" = Company of Heroes - FAKEMSI
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7353BAE6-5E49-46C4-A9B5-8A269A313789}" = Crysis WARHEAD(R)
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7F4B1592-222F-4E5F-A100-E5AFD61A0BB3}" = Company of Heroes - FAKEMSI
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{80D03817-7943-4839-8E96-B9F924C5E67D}" = Company of Heroes - FAKEMSI
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{86A4C6D9-29EE-4719-AFA1-BA3341862B83}" = Microsoft Games for Windows - LIVE
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{88B32652-CAE0-4909-A463-5840D2689D93}" = FUJIFILM FinePixViewer S Ver.2.1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8CFA9151-6404-409A-AF22-4632D04582FD}" = Assassin's Creed
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"{9322A850-9091-4D0E-B252-3E82EDA3D94A}" = Prototype(TM)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{97E5205F-EA4F-438F-B211-F1846419F1C1}" = Company of Heroes - FAKEMSI
"{97EA42A5-3FAB-4948-B74D-F3C44B13F5CE}" = Crysis WARHEAD(R) Patch
"{99A7722D-9ACB-43F3-A222-ABC7133F159E}" = Company of Heroes - FAKEMSI
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A996B6A-846E-4A89-B9C4-17546B7BE49F}" = Burnout(TM) Paradise The Ultimate Box
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A357EF4C-2B6F-4980-ACA9-B1E42A74D7F3}" = Red Faction Guerrilla
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF4238F-7C29-451D-9925-C753271A5728}" = Microsoft Visual C++ Run Time Lib Setup
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{AEDBD563-24BB-4EE3-8366-A654DAC2D988}" = Mirror's Edge™
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 266.58
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 266.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 266.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.1.13.1
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B93EEE50-9C8F-45DF-95E4-3D85A6E242F3}" = DarksidersInstaller
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{BA801B94-C28D-46EE-B806-E1E021A3D519}" = Company of Heroes - FAKEMSI
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFADE4AF-C0CF-4A04-A776-741318F1658F}" = Content Transfer
"{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.3.26 Game
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D4D244D1-05E0-4D24-86A2-B2433C435671}" = Company of Heroes - FAKEMSI
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E280923D-C5D9-4728-8C79-AC9A0DC75875}" = BioShock
"{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
"{EAF636A9-F664-4703-A659-85A894DA264F}" = Company of Heroes - FAKEMSI
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F11ADC64-C89E-47F4-A0B3-3665FF859397}" = World in Conflict
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F138762F-5A1F-4CF0-A5E1-1588EF6088A4}" = The Witcher Enhanced Edition
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AIM_7" = AIM 7
"AVS DVD Player_is1" = AVS DVD Player version 2.4
"CCleaner" = CCleaner
"Company of Heroes" = Company of Heroes
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.57
"Crysis WARHEAD(R)" = Crysis WARHEAD(R)
"Crysis WARHEAD(R) Patch" = Crysis WARHEAD(R) Patch
"dBpowerAMP Music Converter" = dBpowerAMP Music Converter
"DVD Flick_is1" = DVD Flick 1.3.0.7
"EADM" = EA Download Manager
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FormatFactory" = FormatFactory 2.20
"Fraps" = Fraps (remove only)
"GoldWave v5.20" = GoldWave v5.20
"HandBrake" = HandBrake 0.9.5
"Host OpenAL (ADI)" = Host OpenAL (ADI)
"InstallShield_{1170D24F-42B7-40CF-AA1B-6395CE562354}" = Gears of War
"InstallShield_{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"InstallShield_{9322A850-9091-4D0E-B252-3E82EDA3D94A}" = Prototype(TM)
"InstallShield_{A357EF4C-2B6F-4980-ACA9-B1E42A74D7F3}" = Red Faction Guerrilla
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"Lexmark 2500 Series" = Lexmark 2500 Series
"Lexmark Fax Solutions" = Lexmark Fax Solutions
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"NetMeter_is1" = NetMeter 1.1.3
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenAL" = OpenAL
"Peggle World of Warcraft Edition" = Peggle World of Warcraft Edition
"PunkBusterSvc" = PunkBuster Services
"Smart Defrag_is1" = Smart Defrag
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"sp6" = Logitech SetPoint 6.20
"SpeedFan" = SpeedFan (remove only)
"SpywareBlaster_is1" = SpywareBlaster 4.4
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VLC media player 1.1.5
"Webshots Desktop_is1" = Webshots Desktop
"WinLiveSuite" = Windows Live Essentials
"Xfire" = Xfire (remove only)

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2158934232-3957428742-2026527031-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.2

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/28/2011 11:46:28 AM | Computer Name = User-PC | Source = LoadPerf | ID = 3012
Description =

Error - 2/28/2011 11:46:28 AM | Computer Name = User-PC | Source = LoadPerf | ID = 3011
Description =

Error - 2/28/2011 1:28:36 PM | Computer Name = User-PC | Source = LoadPerf | ID = 3012
Description =

Error - 2/28/2011 1:28:36 PM | Computer Name = User-PC | Source = LoadPerf | ID = 3011
Description =

Error - 2/28/2011 1:48:33 PM | Computer Name = User-PC | Source = LoadPerf | ID = 3012
Description =

Error - 2/28/2011 1:48:33 PM | Computer Name = User-PC | Source = LoadPerf | ID = 3011
Description =

Error - 2/28/2011 6:50:03 PM | Computer Name = User-PC | Source = LoadPerf | ID = 3012
Description =

Error - 2/28/2011 6:50:03 PM | Computer Name = User-PC | Source = LoadPerf | ID = 3011
Description =

Error - 2/28/2011 7:38:14 PM | Computer Name = User-PC | Source = Microsoft-Windows-RestartManager | ID = 10006
Description =

Error - 2/28/2011 7:38:14 PM | Computer Name = User-PC | Source = Microsoft-Windows-RestartManager | ID = 10006
Description =

[ Media Center Events ]
Error - 8/28/2008 8:39:20 AM | Computer Name = User-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 6/24/2009 3:36:42 PM | Computer Name = User-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 7/24/2009 3:26:41 PM | Computer Name = User-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ System Events ]
Error - 2/25/2011 12:13:32 PM | Computer Name = User-PC | Source = DCOM | ID = 10016
Description =

Error - 2/25/2011 12:13:32 PM | Computer Name = User-PC | Source = DCOM | ID = 10016
Description =

Error - 2/27/2011 6:42:56 PM | Computer Name = User-PC | Source = DCOM | ID = 10010
Description =

Error - 2/27/2011 7:17:27 PM | Computer Name = User-PC | Source = DCOM | ID = 10005
Description =

Error - 2/27/2011 7:17:27 PM | Computer Name = User-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 2/27/2011 7:17:27 PM | Computer Name = User-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 2/27/2011 7:25:11 PM | Computer Name = User-PC | Source = Service Control Manager | ID = 7006
Description =

Error - 2/28/2011 1:27:35 PM | Computer Name = User-PC | Source = Service Control Manager | ID = 7030
Description =

Error - 2/28/2011 1:30:24 PM | Computer Name = User-PC | Source = Service Control Manager | ID = 7030
Description =

Error - 2/28/2011 1:32:27 PM | Computer Name = User-PC | Source = Service Control Manager | ID = 7030
Description =


< End of report >






ALL DONE. PHEW.
 
thx.

heres the reply to your #8 post:

I cant upload that virus because its in the quarantine area, should I restore the virus and then upload it from the original folder? if i restore the infected file will it re infect my computer?
 
Feel free to reinstall your AVG at any time.

1. Update your Java version here: http://www.java.com/en/download/installed.jsp

Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

2. Now, we need to remove old Java version and its remnants...

Download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.

=======================================================================

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    Code:
    :OTL
    IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
    IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
    O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
    O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found.
    O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
    O3 - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get.../ultrashim.cab (Reg Error: Key error.)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
    [8 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
    [7 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    @Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:5C321E34
    @Alternate Data Stream - 508 bytes -> C:\ProgramData\TEMP:05EE1EEF
    @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:AC6124CA
    
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • You will get a log that shows the results of the fix. Please post it.

======================================================================

Last scans....

1. Download Security Check from HERE, and save it to your Desktop.
  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

    NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.


2. Download Temp File Cleaner (TFC)
  • Double click on TFC.exe to run the program.
  • Click on Start button to begin cleaning process.
  • TFC will close all running programs, and it may ask you to restart computer.


3. Please run a free online scan with the ESET Online Scanner

  • Disable your antivirus program
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • IMPORTANT! UN-check Remove found threats
  • Accept any security warnings from your browser.
  • Check Scan archives
  • Click Start
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push List of found threats
  • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • NOTE. If Eset won't find any threats, it won't produce any log.
 
I cant upload that virus because its in the quarantine area, should I restore the virus and then upload it from the original folder? if i restore the infected file will it re infect my computer?
Leave it alone.
 
OTL LOG:

All processes killed
========== OTL ==========
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-2158934232-3957428742-2026527031-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{A057A204-BACC-4D26-9990-79A187E2698E} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
C:\Windows\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
C:\Windows\Downloaded Program Files\gp.inf not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.
C:\Windows\System32\SETE86.tmp deleted successfully.
C:\Windows\System32\tmp3A0.tmp deleted successfully.
C:\Windows\System32\tmp3A3.tmp deleted successfully.
C:\Windows\System32\tmp41C4.tmp deleted successfully.
C:\Windows\System32\tmp41C5.tmp deleted successfully.
C:\Windows\System32\tmp46F.tmp deleted successfully.
C:\Windows\System32\tmp478A.tmp deleted successfully.
C:\Windows\System32\tmp479B.tmp deleted successfully.
C:\Windows\1C4551A64743409391E41477CD655043.TMP\WiseCustomCalla.dll deleted successfully.
C:\Windows\1C4551A64743409391E41477CD655043.TMP folder deleted successfully.
C:\Windows\6833245EDD86479A882A8360D62C8194.TMP\WiseCustomCalla.dll deleted successfully.
C:\Windows\6833245EDD86479A882A8360D62C8194.TMP folder deleted successfully.
C:\Windows\A7E07C2B2220441587E3784D5814BC93.TMP\WiseCustomCalla.dll deleted successfully.
C:\Windows\A7E07C2B2220441587E3784D5814BC93.TMP folder deleted successfully.
C:\Windows\DD1865F0AD7340FBB23E1822E02396FF.TMP\WiseCustomCalla.dll deleted successfully.
C:\Windows\DD1865F0AD7340FBB23E1822E02396FF.TMP folder deleted successfully.
C:\Windows\E4D153288C89484BB9AAF5BE9EA6D01C.TMP\WiseCustomCalla.dll deleted successfully.
C:\Windows\E4D153288C89484BB9AAF5BE9EA6D01C.TMP folder deleted successfully.
C:\Windows\F579118563414E21A47F41B57AC749B5.TMP\WiseCustomCalla.dll deleted successfully.
C:\Windows\F579118563414E21A47F41B57AC749B5.TMP folder deleted successfully.
C:\Windows\msdownld.tmp folder deleted successfully.
ADS C:\ProgramData\TEMP:5C321E34 deleted successfully.
ADS C:\ProgramData\TEMP:05EE1EEF deleted successfully.
ADS C:\ProgramData\TEMP:AC6124CA deleted successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 56502 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: User
->Temp folder emptied: 1470651 bytes
->Temporary Internet Files folder emptied: 3094836 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 69328394 bytes
->Flash cache emptied: 25625 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 11752595 bytes

Total Files Cleaned = 82.00 mb


[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Public

User: User
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.22.2 log created on 03012011_185556

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...





Coming up:


Security Check
TFC
ESET
 
Security check log:

Results of screen317's Security Check version 0.99.7
Windows Vista Service Pack 2 (UAC is disabled!)
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
[size=1]WMI entry may not exist for antivirus; attempting automatic update.[/size]
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
CCleaner
Java(TM) 6 Update 22
Adobe Flash Player 10.2.152.26
Adobe Reader X
````````````````````````````````
Process Check:
objlist.exe by Laurent

Spybot Teatimer.exe is disabled!
``````````End of Log````````````
 
TFC LOG:

Getting user folders.

Stopping running processes.

Emptying Temp folders.


User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

User: User
->Temp folder emptied: 32882 bytes
->Temporary Internet Files folder emptied: 37294 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 17190984 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 54015 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 741 bytes

Emptying RecycleBin. Do not interrupt.

RecycleBin emptied: 0 bytes
Process complete!

Total Files Cleaned = 17.00 mb
 
Status
Not open for further replies.
Back