TechSpot

Might be infected, some help

By karol3
Feb 27, 2011
  1. I have randomly gotten a virus notification on my AVG on a full system scan. I have deleted the files which where in the Java folder. I ran spy bot and malwarebyte scans and all are clean, I did download SUPER ANTI SPY WARE and found a virus in

    C:\Windows\winsxs\x86_microsoft-windows-msconfig-exe_31bf3856ad364e35_6.0.6001.18000_none_da7a3e839dc01091

    folder

    the virus is: msconfig.exe

    SUPER ANTI SPY WARE detected in and its quarantined.

    I want to be 100% safe. Here are the necessary logs as stated in the pinned topic.
    Is it safe to permenetly remove msconfg.exe from the quarintined area in SUPER ANTI SPY WARE?

    Thanks.

    Malwarebyte LOG:


    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Database version: 5873

    Windows 6.0.6002 Service Pack 2
    Internet Explorer 8.0.6001.19019

    2/27/2011 9:54:59 PM
    mbam-log-2011-02-27 (21-54-59).txt

    Scan type: Quick scan
    Objects scanned: 156043
    Time elapsed: 2 minute(s), 40 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    GMER LOG:

    GMER 1.0.15.15530 - http://www.gmer.net
    Rootkit scan 2011-02-27 22:14:19
    Windows 6.0.6002 Service Pack 2 Harddisk2\DR2 -> \Device\Ide\IdeDeviceP5T0L0-5 SAMSUNG_HD753LJ rev.1AA01107
    Running: dedn0jns.exe; Driver: C:\Users\User\AppData\Local\Temp\kxldapob.sys


    ---- System - GMER 1.0.15 ----

    SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xA1E9F780]
    SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS ZwTerminateProcess [0x91C8E620]
    SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xA1E9F8D0]
    SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xA1E9F970]

    ---- Kernel code sections - GMER 1.0.15 ----

    .text ntkrnlpa.exe!KeSetEvent + 3F1 828F2B74 4 Bytes [80, F7, E9, A1]
    .text ntkrnlpa.exe!KeSetEvent + 621 828F2DA4 8 Bytes [20, E6, C8, 91, D0, F8, E9, ...]
    .text ntkrnlpa.exe!KeSetEvent + 681 828F2E04 4 Bytes [70, F9, E9, A1]
    .text C:\Windows\system32\DRIVERS\atksgt.sys section is writeable [0xA1E5A300, 0x3B6D8, 0xE8000020]
    .text C:\Windows\system32\DRIVERS\lirsgt.sys section is writeable [0xA1EB1300, 0x1BEE, 0xE8000020]

    ---- User code sections - GMER 1.0.15 ----

    .text C:\Program Files\Mozilla Firefox\firefox.exe[5200] ntdll.dll!LdrLoadDll 774F93A8 5 Bytes JMP 000313F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [73B47817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [73B9A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [73B4BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [73B3F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [73B475E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [73B3E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [73B78395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [73B4DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [73B3FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [73B3FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [73B371CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [73BCCAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [73B6C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [73B3D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [73B36853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [73B3687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1012] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [73B42AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
    AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
    AttachedDevice \FileSystem\fastfat \Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )

    ---- EOF - GMER 1.0.15 ----


    DDS LOG:
    DDS:

    DDS (Ver_10-12-12.02) - NTFSx86
    Run by User at 22:15:45.43 on Sun 02/27/2011
    Internet Explorer: 8.0.6001.19019
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3582.1816 [GMT -5:00]

    AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
    SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ============== Running Processes ===============

    C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\ASUS\AI Suite\EnergySaving\PwSave.exe
    C:\Windows\system32\AEADISRV.EXE
    C:\Program Files\AVG\AVG10\avgwdsvc.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\lxddcoms.exe
    C:\Windows\system32\PnkBstrA.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\Program Files\ASUS\AASP\1.00.91\aaCenter.exe
    C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files\AVG\AVG10\avgtray.exe
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Program Files\Analog Devices\SoundMAX\SoundTray.exe
    C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
    C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Webshots\webshots.scr
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\AVG\AVG10\avgnsx.exe
    C:\Program Files\AVG\AVG10\avgemcx.exe
    C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
    C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
    C:\Program Files\Logitech\SetPointG\SetPointII.exe
    C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\PROGRA~1\AVG\AVG10\avgrsx.exe
    C:\Program Files\AVG\AVG10\avgcsrvx.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Users\User\Desktop\dds.scr
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
    mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
    BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
    BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll
    BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
    TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
    TB: @c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll
    TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
    uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
    mRun: [NWEReboot]
    mRun: [<NO NAME>]
    mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
    mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    mRun: [EvtMgr6] c:\program files\logitech\setpointp\SetPoint.exe /launchGaming
    mRun: [SoundTray] c:\program files\analog devices\soundmax\SoundTray.exe
    mRun: [Ai Nap] "c:\program files\asus\ai suite\ainap\AiNap.exe"
    mRun: [QFan Help] "c:\program files\asus\ai suite\qfan3\QFanHelp.exe"
    mRun: [CPU Power Monitor] "c:\program files\asus\ai suite\aigear3\CpuPowerMonitor.exe"
    mRun: [Cpu Level Up help] "c:\program files\asus\ai suite\CpuLevelUpHelp.exe"
    mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
    StartupFolder: c:\users\user\appdata\roaming\micros~1\windows\startm~1\programs\startup\webshots.lnk - c:\program files\webshots\Launcher.exe
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
    IE: Se&nd to OneNote - d:\micros~1\office14\ONBttnIE.dll/105
    IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll
    IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
    Hosts: 127.0.0.1 www.spywareinfo.com

    ================= FIREFOX ===================

    FF - ProfilePath - c:\users\user\appdata\roaming\mozilla\firefox\profiles\2wd3uea1.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/aol/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us&tb_uuid=100000000000000002&tb_oid=20-05-2010&tb_mrud=20-05-2010
    FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4cc235f1&v=6.011.025.001&i=23&tp=ab&iy=&ychte=us&lng=en-US&q=
    FF - component: c:\program files\avg\avg10\firefox\components\avgssff.dll
    FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
    FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
    FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
    FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll
    FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
    FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
    FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
    FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
    FF - plugin: c:\users\user\appdata\local\yahoo!\browserplus\2.9.2\plugins\npybrowserplus_2.9.2.dll
    FF - plugin: c:\users\user\appdata\roaming\mozilla\firefox\profiles\2wd3uea1.default\extensions\devicedetection@logitech.com\plugins\npLogitechDeviceDetection.dll
    FF - plugin: c:\users\user\appdata\roaming\mozilla\firefox\profiles\2wd3uea1.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Move Media Player: moveplayer@movenetworks.com - %profile%\extensions\moveplayer@movenetworks.com
    FF - Ext: Vista-aero: {07b2a769-ed19-4483-87ce-c643914c81bb} - %profile%\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    FF - Ext: Media Converter: {6e764c17-863a-450f-bdd0-6772bd5aaa18} - %profile%\extensions\{6e764c17-863a-450f-bdd0-6772bd5aaa18}
    FF - Ext: Firefox Showcase: {89506680-e3f4-484c-a2c0-ed711d481eda} - %profile%\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
    FF - Ext: SearchPreview: {EF522540-89F5-46b9-B6FE-1829E2B572C6} - %profile%\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
    FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
    FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - c:\program files\avg\avg10\Firefox
    FF - Ext: AVG Security Toolbar em:version=6.011.025.001 em:displayname=AVG Security Toolbar em:iconURL=chrome://tavgp/skin/logo.ico em:creator=AVG Technologies em:description=AVG Security Toolbar em:homepageURL=http://www.avg.com >: avg@igeared - c:\program files\avg\avg10\toolbar\firefox\avg@igeared

    ---- FIREFOX POLICIES ----
    FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false
    FF - user.js: browser.sessionstore.resume_from_crash - false
    FF - user.js: network.protocol-handler.warn-external.dnupdate - false
    ============= SERVICES / DRIVERS ===============

    R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]
    R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064]
    R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-12-8 251728]
    R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384]
    R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-11-12 299984]
    R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
    R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
    R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-1-6 6128720]
    R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-10-22 265400]
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2011-2-20 22504]
    R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-6-8 21504]
    R2 lxdd_device;lxdd_device;c:\windows\system32\lxddcoms.exe -service --> c:\windows\system32\lxddcoms.exe -service [?]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2008-7-8 1153368]
    R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2011-1-7 378984]
    R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 123472]
    R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 30288]
    R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 27216]
    R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2011-2-1 122984]
    S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2010-10-22 517448]
    S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe --> c:\program files\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [?]
    S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2011-2-27 39272]
    S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
    S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
    S4 lxddCATSCustConnectService;lxddCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxddserv.exe [2007-4-26 99248]
    S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]

    =============== Created Last 30 ================

    2011-02-28 02:29:33 -------- d-----w- c:\users\user\appdata\roaming\SUPERAntiSpyware.com
    2011-02-28 02:29:33 -------- d-----w- c:\progra~2\SUPERAntiSpyware.com
    2011-02-28 02:29:29 -------- d-----w- c:\program files\SUPERAntiSpyware
    2011-02-28 01:41:57 -------- d-----w- C:\avrescue
    2011-02-27 23:22:59 5943120 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{53f92516-038b-4246-a038-28a59990747a}\mpengine.dll
    2011-02-27 23:14:43 -------- d-----w- c:\windows\en
    2011-02-27 23:09:22 39272 ----a-w- c:\windows\system32\drivers\fssfltr.sys
    2011-02-27 23:01:32 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
    2011-02-27 22:46:39 -------- d-----w- c:\program files\Microsoft
    2011-02-27 22:46:36 -------- d-----w- c:\program files\MSN Toolbar
    2011-02-27 22:46:22 -------- d-----w- c:\program files\Bing Bar Installer
    2011-02-27 22:46:21 469256 ----a-w- c:\program files\common files\windows live\.cache\261746251cbd6d004\InstallManager_WLE_WLE.exe
    2011-02-27 22:43:46 15712 ----a-w- c:\program files\common files\windows live\.cache\cace22251cbd6cf03\MeshBetaRemover.exe
    2011-02-27 22:43:37 94040 ----a-w- c:\program files\common files\windows live\.cache\c538d7b51cbd6cf02\DSETUP.dll
    2011-02-27 22:43:37 525656 ----a-w- c:\program files\common files\windows live\.cache\c538d7b51cbd6cf02\DXSETUP.exe
    2011-02-27 22:43:37 1691480 ----a-w- c:\program files\common files\windows live\.cache\c538d7b51cbd6cf02\dsetup32.dll
    2011-02-27 22:43:11 94040 ----a-w- c:\program files\common files\windows live\.cache\b5b87d451cbd6cf01\DSETUP.dll
    2011-02-27 22:43:11 525656 ----a-w- c:\program files\common files\windows live\.cache\b5b87d451cbd6cf01\DXSETUP.exe
    2011-02-27 22:43:11 1691480 ----a-w- c:\program files\common files\windows live\.cache\b5b87d451cbd6cf01\dsetup32.dll
    2011-02-27 22:42:13 -------- d-----w- c:\users\user\appdata\local\Windows Live
    2011-02-27 22:42:11 -------- d-----w- c:\program files\common files\Windows Live
    2011-02-27 22:41:04 754688 ----a-w- c:\windows\system32\webservices.dll
    2011-02-27 17:21:32 -------- d--h--w- c:\windows\PIF
    2011-02-25 01:21:20 -------- d-----w- c:\program files\CCleaner
    2011-02-20 16:23:42 22504 ----a-w- c:\windows\system32\drivers\cpuz135_x32.sys
    2011-02-17 01:22:36 -------- d-----w- c:\program files\common files\Software Update Utility
    2011-02-16 01:59:37 12400 ----a-w- c:\windows\system32\drivers\AsIO.sys
    2011-02-16 01:59:33 11832 ----a-w- c:\windows\system32\drivers\AsInsHelp64.sys
    2011-02-16 01:59:33 10216 ----a-w- c:\windows\system32\drivers\AsInsHelp32.sys
    2011-02-16 01:59:16 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
    2011-02-16 01:59:16 614532 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\IKernel.exe
    2011-02-16 01:59:16 32768 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
    2011-02-16 01:59:16 225280 ----a-w- c:\program files\common files\installshield\iscript\iscript.dll
    2011-02-16 01:59:16 176128 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
    2011-02-10 03:16:05 -------- d-sh--w- c:\windows\system32\%APPDATA%
    2011-02-09 22:15:56 33104 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\msonpppr.dll
    2011-02-09 22:15:56 32656 ----a-w- c:\windows\system32\msonpmon.dll
    2011-02-09 22:14:14 -------- d-----w- c:\windows\PCHEALTH
    2011-02-09 22:12:32 -------- d-----w- c:\program files\Microsoft Visual Studio 8
    2011-02-08 19:14:59 638232 ----a-w- c:\program files\internet explorer\iexplore.exe
    2011-02-06 22:15:10 -------- d-----w- c:\users\user\appdata\local\Microsoft Help
    2011-02-06 20:10:12 -------- d-----w- c:\progra~2\VirtualizedApplications
    2011-02-06 18:25:57 -------- d-----w- c:\program files\Microsoft XNA
    2011-02-06 17:57:50 -------- d-----w- c:\users\user\appdata\local\SoftGrid Client
    2011-02-06 17:57:06 -------- d-----w- c:\users\user\appdata\roaming\SoftGrid Client
    2011-02-06 17:52:53 -------- d-----w- c:\users\user\appdata\roaming\TP

    ==================== Find3M ====================

    2011-02-11 22:14:10 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
    2011-02-02 23:49:11 22328 ----a-w- c:\users\user\appdata\roaming\PnkBstrK.sys
    2011-02-02 23:49:00 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
    2011-02-02 23:48:54 103736 ----a-w- c:\windows\system32\PnkBstrB.ex0
    2011-02-02 23:48:53 669184 ----a-w- c:\windows\system32\pbsvc.exe
    2011-02-02 22:11:20 222080 ------w- c:\windows\system32\MpSigStub.exe
    2011-02-02 19:23:17 270904 ----a-w- c:\windows\system32\PnkBstrB.xtr
    2011-01-20 16:08:16 478720 ----a-w- c:\windows\system32\dxgi.dll
    2011-01-20 16:08:06 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
    2011-01-20 16:08:06 189952 ----a-w- c:\windows\system32\d3d10core.dll
    2011-01-20 16:08:06 160768 ----a-w- c:\windows\system32\d3d10_1.dll
    2011-01-20 16:08:06 1029120 ----a-w- c:\windows\system32\d3d10.dll
    2011-01-20 16:07:58 37376 ----a-w- c:\windows\system32\cdd.dll
    2011-01-20 16:07:42 258048 ----a-w- c:\windows\system32\winspool.drv
    2011-01-20 16:07:16 586240 ----a-w- c:\windows\system32\stobject.dll
    2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf.dll
    2011-01-20 16:06:35 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
    2011-01-20 16:04:54 98816 ----a-w- c:\windows\system32\mfps.dll
    2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat.dll
    2011-01-20 14:28:38 1554432 ----a-w- c:\windows\system32\xpsservices.dll
    2011-01-20 14:27:50 876032 ----a-w- c:\windows\system32\XpsPrint.dll
    2011-01-20 14:26:30 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
    2011-01-20 14:25:25 847360 ----a-w- c:\windows\system32\OpcServices.dll
    2011-01-20 14:24:32 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
    2011-01-20 14:24:26 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
    2011-01-20 14:15:10 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
    2011-01-20 14:14:39 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll
    2011-01-20 14:14:03 302592 ----a-w- c:\windows\system32\mfmp4src.dll
    2011-01-20 14:14:03 261632 ----a-w- c:\windows\system32\mfreadwrite.dll
    2011-01-20 14:12:46 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
    2011-01-20 14:11:34 486400 ----a-w- c:\windows\system32\d3d10level9.dll
    2011-01-20 13:47:51 683008 ----a-w- c:\windows\system32\d2d1.dll
    2011-01-20 13:44:05 1068544 ----a-w- c:\windows\system32\DWrite.dll
    2011-01-20 13:44:03 797184 ----a-w- c:\windows\system32\FntCache.dll
    2011-01-08 08:47:50 34304 ----a-w- c:\windows\system32\atmlib.dll
    2011-01-08 06:28:49 292352 ----a-w- c:\windows\system32\atmfd.dll
    2011-01-08 03:27:00 941160 ----a-w- c:\windows\system32\nvdispco322090.dll
    2011-01-08 03:27:00 837736 ----a-w- c:\windows\system32\nvgenco322040.dll
    2011-01-08 03:27:00 57960 ----a-w- c:\windows\system32\OpenCL.dll
    2011-01-08 03:27:00 5653096 ----a-w- c:\windows\system32\nvwgf2um.dll
    2011-01-08 03:27:00 4941928 ----a-w- c:\windows\system32\nvcuda.dll
    2011-01-08 03:27:00 2895976 ----a-w- c:\windows\system32\nvcuvid.dll
    2011-01-08 03:27:00 2251368 ----a-w- c:\windows\system32\nvcuvenc.dll
    2011-01-08 03:27:00 1965672 ----a-w- c:\windows\system32\nvapi.dll
    2011-01-08 03:27:00 15047272 ----a-w- c:\windows\system32\nvoglv32.dll
    2011-01-08 03:27:00 13011560 ----a-w- c:\windows\system32\nvcompiler.dll
    2011-01-08 03:27:00 10078312 ----a-w- c:\windows\system32\nvd3dum.dll
    2011-01-08 02:06:44 580200 ----a-w- c:\windows\system32\easyUpdatusAPIU.dll
    2011-01-08 02:06:34 3597416 ----a-w- c:\windows\system32\nvcpl.dll
    2011-01-08 02:06:14 2620520 ----a-w- c:\windows\system32\nvsvc.dll
    2011-01-08 02:06:02 66664 ----a-w- c:\windows\system32\nvshext.dll
    2011-01-08 02:06:02 608872 ----a-w- c:\windows\system32\nvvsvc.exe
    2011-01-08 02:06:02 111208 ----a-w- c:\windows\system32\nvmctray.dll
    2010-12-31 13:57:01 2039808 ----a-w- c:\windows\system32\win32k.sys
    2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32.dll
    2010-12-18 06:27:04 916480 ----a-w- c:\windows\system32\wininet.dll
    2010-12-18 06:22:41 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2010-12-18 06:22:27 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
    2010-12-18 06:22:11 71680 ----a-w- c:\windows\system32\iesetup.dll
    2010-12-18 06:22:11 109056 ----a-w- c:\windows\system32\iesysprep.dll
    2010-12-18 05:25:26 385024 ----a-w- c:\windows\system32\html.iec
    2010-12-18 04:48:39 133632 ----a-w- c:\windows\system32\ieUnatt.exe
    2010-12-18 04:47:11 1638912 ----a-w- c:\windows\system32\mshtml.tlb
    2010-12-14 14:49:23 1169408 ----a-w- c:\windows\system32\sdclt.exe
    2010-12-02 09:12:06 837224 ----a-w- c:\windows\system32\nvgenco32hda.dll

    ============= FINISH: 22:16:17.31 ===============

    ATTACH:


    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-12-12.02)

    Microsoft® Windows Vista™ Home Premium
    Boot Device: \Device\HarddiskVolume3
    Install Date: 6/4/2008 5:14:27 PM
    System Uptime: 2/27/2011 9:35:18 PM (1 hours ago)

    Motherboard: ASUSTeK Computer INC. | | P5E
    Processor: Intel(R) Core(TM)2 Quad CPU Q9450 @ 2.66GHz | LGA775 | 2664/333mhz

    ==== Disk Partitions =========================

    A: is Removable
    C: is FIXED (NTFS) - 699 GiB total, 486.476 GiB free.
    D: is FIXED (NTFS) - 112 GiB total, 17.139 GiB free.
    E: is CDROM ()
    F: is FIXED (NTFS) - 1863 GiB total, 1556.113 GiB free.

    ==== Disabled Device Manager Items =============

    Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
    Description: Microsoft 6to4 Adapter
    Device ID: ROOT\*6TO4MP\0001
    Manufacturer: Microsoft
    Name: Microsoft 6to4 Adapter #2
    PNP Device ID: ROOT\*6TO4MP\0001
    Service: tunnel

    Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
    Description: Microsoft Tun Miniport Adapter
    Device ID: ROOT\*TUNMP\0001
    Manufacturer: Microsoft
    Name: Microsoft Tun Miniport Adapter #2
    PNP Device ID: ROOT\*TUNMP\0001
    Service: tunmp

    ==== System Restore Points ===================

    RP849: 2/27/2011 5:35:04 PM - 2/27/11
    RP850: 2/27/2011 5:40:54 PM - Windows Update
    RP851: 2/27/2011 6:22:49 PM - Windows Update

    ==== Installed Programs ======================

    ABBYY FineReader 6.0 Sprint
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader X
    Adobe Shockwave Player 11.5
    AI Suite
    AIM 7
    Apple Application Support
    Apple Software Update
    Assassin's Creed
    AutoUpdate
    AVG 2011
    AVS DVD Player version 2.4
    Batman: Arkham Asylum
    Bing Bar
    Bing Bar Platform
    BioShock
    BioShock 2
    Burnout(TM) Paradise The Ultimate Box
    Call of Duty(R) 4 - Modern Warfare(TM)
    Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
    Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
    CCleaner
    Company of Heroes
    Company of Heroes - FAKEMSI
    Content Transfer
    CPUID CPU-Z 1.57
    Crysis WARHEAD(R)
    Crysis WARHEAD(R) Patch
    Crysis(R)
    D3DX10
    DarksidersInstaller
    dBpowerAMP Music Converter
    Dead Rising 2
    DivX Codec
    DivX Converter
    DivX Player
    DivX Web Player
    Download Updater (AOL LLC)
    DVD Flick 1.3.0.7
    EA Download Manager
    eReg
    Fallout 3
    FormatFactory 2.20
    Fraps (remove only)
    FUJIFILM FinePixViewer S Ver.2.1
    Futuremark SystemInfo
    Gears of War
    GoldWave v5.20
    Grand Theft Auto
    Grand Theft Auto IV
    Grand Theft Auto: Episodes From Liberty City
    GRID
    GTA2
    HandBrake 0.9.5
    Host OpenAL (ADI)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Junk Mail filter update
    Lexmark 2500 Series
    Lexmark Fax Solutions
    Logitech SetPoint 6.20
    LOST PLANET 2
    Malwarebytes' Anti-Malware
    Marvell Miniport Driver
    Mass Effect
    Mesh Runtime
    Messenger Companion
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB2416447)
    Microsoft .NET Framework 1.1 Security Update (KB979906)
    Microsoft .NET Framework 3.5 SP1
    Microsoft .NET Framework 4 Client Profile
    Microsoft Application Error Reporting
    Microsoft Games for Windows - LIVE
    Microsoft Games for Windows - LIVE Redistributable
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Access MUI (English) 2007
    Microsoft Office Access Setup Metadata MUI (English) 2007
    Microsoft Office Enterprise 2007
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Groove MUI (English) 2007
    Microsoft Office Groove Setup Metadata MUI (English) 2007
    Microsoft Office InfoPath MUI (English) 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office Outlook Connector
    Microsoft Office Outlook MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Publisher MUI (English) 2007
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Word MUI (English) 2007
    Microsoft Search Enhancement Pack
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft VC9 runtime libraries
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ Run Time Lib Setup
    Microsoft XNA Framework Redistributable 3.1
    Mirror's Edge™
    Mozilla Firefox (3.6.13)
    MSVCRT
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB941833)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    NetMeter 1.1.3
    NVIDIA 3D Vision Driver 266.58
    NVIDIA Control Panel 266.58
    NVIDIA Graphics Driver 266.58
    NVIDIA HD Audio Driver 1.1.13.1
    NVIDIA Install Application
    NVIDIA PhysX
    NVIDIA PhysX System Software 9.10.0514
    NVIDIA Stereoscopic 3D Driver
    OpenAL
    OpenOffice.org 2.3
    Peggle World of Warcraft Edition
    Project64 1.6
    Prototype(TM)
    PunkBuster Services
    QuickTime
    Rapture3D 2.3.26 Game
    Realtek High Definition Audio Driver
    Red Faction Guerrilla
    Security Update for 2007 Microsoft Office System (KB2288621)
    Security Update for 2007 Microsoft Office System (KB2288931)
    Security Update for 2007 Microsoft Office System (KB2289158)
    Security Update for 2007 Microsoft Office System (KB2344875)
    Security Update for 2007 Microsoft Office System (KB2345043)
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB976321)
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Microsoft Office Access 2007 (KB979440)
    Security Update for Microsoft Office Excel 2007 (KB2345035)
    Security Update for Microsoft Office InfoPath 2007 (KB979441)
    Security Update for Microsoft Office PowerPoint 2007 (KB982158)
    Security Update for Microsoft Office PowerPoint Viewer (KB2413381)
    Security Update for Microsoft Office Publisher 2007 (KB2284697)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    Security Update for Microsoft Office Word 2007 (KB2344993)
    Segoe UI
    Skype Toolbars
    Skype™ 5.1
    Smart Defrag
    SoundMAX
    SpeedFan (remove only)
    Spybot - Search & Destroy
    SpywareBlaster 4.4
    Steam
    SUPERAntiSpyware
    SwitchBlade
    TBS WMP Plug-in
    TeamSpeak 3 Client
    The Witcher Enhanced Edition
    Twin USB Vibration Gamepad
    Ubisoft Game Launcher
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office Access 2007 Help (KB963663)
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office Infopath 2007 Help (KB963662)
    Update for Microsoft Office OneNote 2007 (KB980729)
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Update for Microsoft Office Outlook 2007 (KB2412171)
    Update for Microsoft Office Outlook 2007 Help (KB963677)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Publisher 2007 Help (KB963667)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Word 2007 Help (KB963665)
    Update for Outlook 2007 Junk Email Filter (KB2492475)
    VC80CRTRedist - 8.0.50727.762
    Ventrilo Client
    Viewpoint Media Player
    VLC media player 1.1.5
    Webshots Desktop
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Family Safety
    Windows Live ID Sign-in Assistant
    Windows Live Installer
    Windows Live Mail
    Windows Live Mesh
    Windows Live Mesh ActiveX Control for Remote Connections
    Windows Live Messenger
    Windows Live Messenger Companion Core
    Windows Live MIME IFilter
    Windows Live Movie Maker
    Windows Live Photo Common
    Windows Live Photo Gallery
    Windows Live PIMT Platform
    Windows Live Remote Client
    Windows Live Remote Client Resources
    Windows Live Remote Service
    Windows Live Remote Service Resources
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    Windows Live Writer
    Windows Live Writer Resources
    Windows Media Player Firefox Plugin
    World in Conflict
    Xfire (remove only)
    Yahoo! BrowserPlus 2.9.2

    ==== Event Viewer Messages From Past Week ========

    2/27/2011 6:25:11 PM, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Start with the following error: Access is denied.
    2/27/2011 6:17:27 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
    2/27/2011 6:17:27 PM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    2/27/2011 6:17:27 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
    2/25/2011 11:13:32 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8BC3F05E-D86B-11D0-A075-00C04FB68820} to the user User-PC\User SID (S-1-5-21-2158934232-3957428742-2026527031-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.

    ==== End Of File ===========================
     
  2. Broni

    Broni Malware Annihilator Posts: 52,911   +344

    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ========================================================================

    Download MBRCheck to your desktop

    Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator).
    It will show a black screen with some data on it.
    Enter N to exit.
    A report called MBRcheckxxxx.txt will be on your desktop
    Open this report and post its content in your next reply.

    ======================================================================

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.



    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    Rkill.com
    Rkill.scr
    Rkill.exe

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  3. karol3

    karol3 TS Rookie Topic Starter Posts: 34

    Nice to meet you here is what you asked.

    MBR CHECK:

    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows Vista Home Premium Edition
    Windows Information: Service Pack 2 (build 6002), 32-bit
    Base Board Manufacturer: ASUSTeK Computer INC.
    BIOS Manufacturer: American Megatrends Inc.
    System Manufacturer: System manufacturer
    System Product Name: P5E
    Logical Drives Mask: 0x0000003d

    Kernel Drivers (total 156):
    0x82840000 \SystemRoot\system32\ntkrnlpa.exe
    0x8280D000 \SystemRoot\system32\hal.dll
    0x8040C000 \SystemRoot\system32\kdcom.dll
    0x80413000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
    0x80483000 \SystemRoot\system32\PSHED.dll
    0x80494000 \SystemRoot\system32\BOOTVID.dll
    0x8049C000 \SystemRoot\system32\CLFS.SYS
    0x804DD000 \SystemRoot\system32\CI.dll
    0x80600000 \SystemRoot\system32\drivers\Wdf01000.sys
    0x8067C000 \SystemRoot\system32\drivers\WDFLDR.SYS
    0x80689000 \SystemRoot\system32\drivers\acpi.sys
    0x806CF000 \SystemRoot\system32\drivers\WMILIB.SYS
    0x806D8000 \SystemRoot\system32\drivers\msisadrv.sys
    0x806E0000 \SystemRoot\system32\drivers\pci.sys
    0x80707000 \SystemRoot\System32\drivers\partmgr.sys
    0x80716000 \SystemRoot\system32\drivers\volmgr.sys
    0x80725000 \SystemRoot\System32\drivers\volmgrx.sys
    0x8076F000 \SystemRoot\system32\drivers\pciide.sys
    0x80776000 \SystemRoot\system32\drivers\PCIIDEX.SYS
    0x80784000 \SystemRoot\System32\drivers\mountmgr.sys
    0x80794000 \SystemRoot\system32\drivers\atapi.sys
    0x8079C000 \SystemRoot\system32\drivers\ataport.SYS
    0x807BA000 \SystemRoot\system32\drivers\fltmgr.sys
    0x807EC000 \SystemRoot\system32\drivers\fileinfo.sys
    0x82E07000 \SystemRoot\System32\Drivers\ksecdd.sys
    0x82E78000 \SystemRoot\system32\drivers\ndis.sys
    0x82F83000 \SystemRoot\system32\drivers\msrpc.sys
    0x82FAE000 \SystemRoot\system32\drivers\NETIO.SYS
    0x8BC0F000 \SystemRoot\System32\drivers\tcpip.sys
    0x8BCF9000 \SystemRoot\System32\drivers\fwpkclnt.sys
    0x8BE0D000 \SystemRoot\System32\Drivers\Ntfs.sys
    0x8BF1D000 \SystemRoot\system32\drivers\volsnap.sys
    0x8BF56000 \SystemRoot\System32\Drivers\spldr.sys
    0x8BF5E000 \SystemRoot\system32\speedfan.sys
    0x8BF60000 \SystemRoot\System32\Drivers\mup.sys
    0x8BF6F000 \SystemRoot\system32\giveio.sys
    0x8BF70000 \SystemRoot\System32\drivers\ecache.sys
    0x8BF97000 \SystemRoot\system32\drivers\disk.sys
    0x8BFA8000 \SystemRoot\system32\drivers\CLASSPNP.SYS
    0x8BFC9000 \SystemRoot\system32\drivers\crcdisk.sys
    0x8BFD2000 \SystemRoot\system32\DRIVERS\avgrkx86.sys
    0x8BFD7000 \SystemRoot\system32\DRIVERS\AVGIDSEH.Sys
    0x8BE00000 \SystemRoot\system32\DRIVERS\tunnel.sys
    0x8BD14000 \SystemRoot\system32\DRIVERS\tunmp.sys
    0x8BD1D000 \SystemRoot\system32\DRIVERS\intelppm.sys
    0x8FE00000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
    0x907FA000 \SystemRoot\System32\Drivers\nvBridge.kmd
    0x8BD2C000 \SystemRoot\System32\drivers\dxgkrnl.sys
    0x8BDCC000 \SystemRoot\System32\drivers\watchdog.sys
    0x90809000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
    0x90896000 \SystemRoot\system32\DRIVERS\usbuhci.sys
    0x908A1000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
    0x908DF000 \SystemRoot\system32\DRIVERS\usbehci.sys
    0x908EE000 \SystemRoot\system32\DRIVERS\yk60x86.sys
    0x9093A000 \SystemRoot\System32\DRIVERS\dvd43llh.sys
    0x9093F000 \SystemRoot\system32\DRIVERS\cdrom.sys
    0x90957000 \SystemRoot\system32\DRIVERS\ohci1394.sys
    0x90967000 \SystemRoot\system32\DRIVERS\1394BUS.SYS
    0x90975000 \SystemRoot\system32\DRIVERS\fdc.sys
    0x90980000 \SystemRoot\system32\DRIVERS\ASACPI.sys
    0x90988000 \SystemRoot\system32\DRIVERS\i8042prt.sys
    0x9099B000 \SystemRoot\system32\DRIVERS\kbdclass.sys
    0x909A6000 \SystemRoot\system32\DRIVERS\msiscsi.sys
    0x805BD000 \SystemRoot\system32\DRIVERS\storport.sys
    0x909D5000 \SystemRoot\system32\DRIVERS\TDI.SYS
    0x909E0000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
    0x8BDD8000 \SystemRoot\system32\DRIVERS\ndistapi.sys
    0x90C07000 \SystemRoot\system32\DRIVERS\ndiswan.sys
    0x90C2A000 \SystemRoot\system32\DRIVERS\raspppoe.sys
    0x90C39000 \SystemRoot\system32\DRIVERS\raspptp.sys
    0x90C4D000 \SystemRoot\system32\DRIVERS\rassstp.sys
    0x90C62000 \SystemRoot\system32\DRIVERS\termdd.sys
    0x90C72000 \SystemRoot\system32\DRIVERS\mouclass.sys
    0x90C7D000 \SystemRoot\system32\DRIVERS\swenum.sys
    0x90C7F000 \SystemRoot\system32\DRIVERS\ks.sys
    0x90CA9000 \SystemRoot\system32\DRIVERS\mssmbios.sys
    0x90CB3000 \SystemRoot\system32\DRIVERS\umbus.sys
    0x90CC0000 \SystemRoot\system32\DRIVERS\usbhub.sys
    0x90CF5000 \SystemRoot\system32\DRIVERS\flpydisk.sys
    0x90CFF000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0x90D10000 \SystemRoot\system32\drivers\nvhda32v.sys
    0x90D31000 \SystemRoot\system32\drivers\portcls.sys
    0x90D5E000 \SystemRoot\system32\drivers\drmk.sys
    0x90D83000 \SystemRoot\system32\drivers\ADIHdAud.sys
    0x90DDC000 \SystemRoot\system32\DRIVERS\usbccgp.sys
    0x90DF3000 \SystemRoot\system32\DRIVERS\USBD.SYS
    0x90DF5000 \SystemRoot\system32\DRIVERS\hidusb.sys
    0x8BDE3000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
    0x90C00000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
    0x909F7000 \SystemRoot\system32\DRIVERS\LHidFilt.Sys
    0x90800000 \SystemRoot\system32\DRIVERS\mouhid.sys
    0x8BDF3000 \SystemRoot\system32\DRIVERS\LMouFilt.Sys
    0x8BC00000 \SystemRoot\system32\DRIVERS\kbdhid.sys
    0x82FE9000 \SystemRoot\system32\DRIVERS\usbscan.sys
    0x82FF6000 \SystemRoot\system32\DRIVERS\usbprint.sys
    0x80400000 \SystemRoot\system32\DRIVERS\avgmfx86.sys
    0x90E07000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
    0x90E10000 \SystemRoot\System32\Drivers\Null.SYS
    0x90E17000 \SystemRoot\System32\Drivers\Beep.SYS
    0x90E1E000 \SystemRoot\System32\drivers\vga.sys
    0x90E2A000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
    0x90E4B000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0x90E53000 \SystemRoot\system32\drivers\rdpencdd.sys
    0x90E5B000 \SystemRoot\System32\Drivers\Msfs.SYS
    0x90E66000 \SystemRoot\System32\Drivers\Npfs.SYS
    0x90E74000 \SystemRoot\System32\DRIVERS\rasacd.sys
    0x90E7D000 \SystemRoot\system32\DRIVERS\tdx.sys
    0x90E93000 \SystemRoot\system32\DRIVERS\avgtdix.sys
    0x90EDB000 \SystemRoot\System32\DRIVERS\netbt.sys
    0x90F0D000 \SystemRoot\system32\DRIVERS\smb.sys
    0x90F21000 \SystemRoot\system32\drivers\afd.sys
    0x90F69000 \SystemRoot\system32\DRIVERS\pacer.sys
    0x90F7F000 \SystemRoot\system32\DRIVERS\netbios.sys
    0x90F8D000 \SystemRoot\system32\DRIVERS\wanarp.sys
    0x90FA0000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
    0x90FC2000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
    0x9160B000 \SystemRoot\system32\DRIVERS\rdbss.sys
    0x91647000 \SystemRoot\system32\drivers\nsiproxy.sys
    0x91651000 \SystemRoot\System32\Drivers\dfsc.sys
    0x91668000 \SystemRoot\system32\DRIVERS\avgldx86.sys
    0x916A4000 \SystemRoot\system32\drivers\AsIO.sys
    0x916A6000 \SystemRoot\System32\Drivers\crashdmp.sys
    0x916B3000 \SystemRoot\System32\Drivers\dump_dumpata.sys
    0x916BE000 \SystemRoot\System32\Drivers\dump_atapi.sys
    0x81670000 \SystemRoot\System32\win32k.sys
    0x916C6000 \SystemRoot\System32\drivers\Dxapi.sys
    0x916D0000 \SystemRoot\system32\DRIVERS\monitor.sys
    0x81890000 \SystemRoot\System32\TSDDD.dll
    0x818B0000 \SystemRoot\System32\cdd.dll
    0x916DF000 \SystemRoot\system32\drivers\luafv.sys
    0x91702000 \SystemRoot\system32\drivers\spsys.sys
    0x917B2000 \SystemRoot\system32\DRIVERS\lltdio.sys
    0x917C2000 \SystemRoot\system32\DRIVERS\rspndr.sys
    0xA1C09000 \SystemRoot\system32\drivers\HTTP.sys
    0xA1C76000 \SystemRoot\System32\DRIVERS\srvnet.sys
    0xA1C93000 \SystemRoot\system32\DRIVERS\bowser.sys
    0xA1CAC000 \SystemRoot\System32\drivers\mpsdrv.sys
    0xA1CC1000 \SystemRoot\system32\drivers\mrxdav.sys
    0xA1CE2000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
    0xA1D01000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
    0xA1D3A000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
    0xA1D52000 \SystemRoot\System32\DRIVERS\srv2.sys
    0xA1D7A000 \SystemRoot\System32\DRIVERS\srv.sys
    0xA1DC8000 \SystemRoot\system32\DRIVERS\asyncmac.sys
    0xAA808000 \SystemRoot\system32\DRIVERS\atksgt.sys
    0xAA84B000 \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys
    0xAA856000 \??\C:\Windows\system32\drivers\cpuz135_x32.sys
    0xAA85F000 \SystemRoot\system32\DRIVERS\lirsgt.sys
    0xAA864000 \SystemRoot\system32\drivers\peauth.sys
    0xAA942000 \SystemRoot\System32\Drivers\secdrv.SYS
    0xAA94C000 \SystemRoot\System32\drivers\tcpipreg.sys
    0xAA958000 \SystemRoot\system32\DRIVERS\AVGIDSFilter.Sys
    0xAA962000 \SystemRoot\system32\DRIVERS\AVGIDSDriver.Sys
    0xAA98A000 \SystemRoot\System32\Drivers\fastfat.SYS
    0xAA9B2000 \SystemRoot\system32\DRIVERS\cdfs.sys
    0x77900000 \Windows\System32\ntdll.dll

    Processes (total 68):
    0 System Idle Process
    4 System
    404 C:\Windows\System32\smss.exe
    436 C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
    664 csrss.exe
    736 C:\Windows\System32\wininit.exe
    748 csrss.exe
    780 C:\Windows\System32\services.exe
    808 C:\Windows\System32\winlogon.exe
    860 C:\Windows\System32\lsass.exe
    876 C:\Windows\System32\lsm.exe
    1032 C:\Windows\System32\svchost.exe
    1080 C:\Windows\System32\nvvsvc.exe
    1108 C:\Windows\System32\svchost.exe
    1236 C:\Windows\System32\svchost.exe
    1260 C:\Windows\System32\svchost.exe
    1272 C:\Windows\System32\svchost.exe
    1404 C:\Windows\System32\audiodg.exe
    1432 C:\Windows\System32\svchost.exe
    1452 C:\Windows\System32\SLsvc.exe
    1500 C:\Windows\System32\svchost.exe
    1664 C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
    1676 C:\Windows\System32\nvvsvc.exe
    1700 C:\Windows\System32\svchost.exe
    132 C:\Windows\System32\spoolsv.exe
    268 C:\Windows\System32\svchost.exe
    1092 C:\Windows\System32\taskeng.exe
    1316 C:\Windows\System32\dwm.exe
    1892 C:\Windows\explorer.exe
    700 C:\Program Files\ASUS\AI Suite\EnergySaving\PwSave.exe
    644 C:\Program Files\ASUS\AASP\1.00.91\aaCenter.exe
    1640 C:\Windows\System32\taskeng.exe
    2184 C:\Windows\System32\AEADISRV.EXE
    2292 C:\Program Files\AVG\AVG10\avgwdsvc.exe
    2376 C:\Windows\System32\lxddcoms.exe
    2520 C:\Windows\System32\PnkBstrA.exe
    2536 C:\Windows\System32\svchost.exe
    2548 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    2848 C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    2932 C:\Windows\System32\svchost.exe
    2988 C:\Program Files\AVG\AVG10\avgtray.exe
    3124 C:\Windows\System32\svchost.exe
    3176 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
    3212 C:\Program Files\Analog Devices\SoundMAX\SoundTray.exe
    3304 C:\Windows\System32\SearchIndexer.exe
    3344 C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
    3380 C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe
    3396 C:\Program Files\Analog Devices\Core\smax4pnp.exe
    3420 C:\Windows\ehome\ehtray.exe
    3440 C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
    3476 C:\Program Files\Windows Sidebar\sidebar.exe
    3512 C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    3824 C:\Windows\ehome\ehmsas.exe
    3848 C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
    3884 C:\Program Files\Webshots\Webshots.scr
    2832 C:\Program Files\AVG\AVG10\avgnsx.exe
    620 C:\Program Files\AVG\AVG10\avgemcx.exe
    2720 C:\Program Files\Windows Sidebar\sidebar.exe
    1212 C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
    3600 C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
    3732 C:\Program Files\Logitech\SetPointG\SetPointII.exe
    4616 C:\Windows\System32\svchost.exe
    4920 C:\PROGRA~1\AVG\AVG10\avgrsx.exe
    4724 C:\Program Files\AVG\AVG10\avgcsrvx.exe
    1508 C:\Program Files\Mozilla Firefox\firefox.exe
    5972 C:\Windows\System32\SearchProtocolHost.exe
    1708 C:\Windows\System32\SearchFilterHost.exe
    5568 C:\Users\User\Desktop\MBRCheck.exe

    \\.\C: --> \\.\PhysicalDrive1 at offset 0x00000000`00100000 (NTFS)
    \\.\D: --> \\.\PhysicalDrive2 at offset 0x00000000`00100000 (NTFS)
    \\.\F: --> \\.\PhysicalDrive0 at offset 0x00000000`00100000 (NTFS)

    PhysicalDrive1 Model Number: SAMSUNGHD753LJ, Rev: 1AA01107
    PhysicalDrive2 Model Number: WDCWD1200JD-00HBB0, Rev: 08.02D08
    PhysicalDrive0 Model Number: WDCWD20EARS-00MVWB0, Rev: 51.0AB51

    Size Device Name MBR Status
    --------------------------------------------
    698 GB \\.\PhysicalDrive1 Windows 2008 MBR code detected
    SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979
    111 GB \\.\PhysicalDrive2 Windows XP MBR code detected
    SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
    1863 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected
    SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979


    Done!




    COMBO FIX LOG:

    ComboFix 11-02-27.03 - User 02/28/2011 12:28:05.1.4 - x86
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3582.2504 [GMT -5:00]
    Running from: c:\users\User\Desktop\ComboFix.exe
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\$$DELETME.wtspai32.dll
    c:\$$deletme.wtspai32.dll\$$DeleteMe.authui.dll.01c8c67dbedeec23.000d
    c:\$$deletme.wtspai32.dll\$$DeleteMe.CbsMsg.dll.01c8c67dbf396063.001e
    c:\$$deletme.wtspai32.dll\$$DeleteMe.crypt32.dll.01c8c67dbe6324a3.0003
    c:\$$deletme.wtspai32.dll\$$DeleteMe.csrsrv.dll.01c8c67dbfca9443.0029
    c:\$$deletme.wtspai32.dll\$$DeleteMe.dhcpcsvc.dll.01c8c67dbee14d83.000e
    c:\$$deletme.wtspai32.dll\$$DeleteMe.dhcpcsvc6.dll.01c8c67dbee61043.0010
    c:\$$deletme.wtspai32.dll\$$DeleteMe.dnsapi.dll.01c8c67dbe99e443.0009
    c:\$$deletme.wtspai32.dll\$$DeleteMe.dnsrslvr.dll.01c8c67dbe99e443.000a
    c:\$$deletme.wtspai32.dll\$$DeleteMe.dps.dll.01c8c67dc0890243.0031
    c:\$$deletme.wtspai32.dll\$$DeleteMe.dpx.dll.01c8c67dbf2fdae3.0019
    c:\$$deletme.wtspai32.dll\$$DeleteMe.FirewallAPI.dll.01c8c67dbf61d7c3.0021
    c:\$$deletme.wtspai32.dll\$$DeleteMe.gdi32.dll.01c8c67dbf02a0c3.0016
    c:\$$deletme.wtspai32.dll\$$DeleteMe.imagehlp.dll.01c8c67dbe6a48c3.0005
    c:\$$deletme.wtspai32.dll\$$DeleteMe.iphlpsvc.dll.01c8c67dbf643923.0024
    c:\$$deletme.wtspai32.dll\$$DeleteMe.kmddsp.tsp.01c8c67dc07aba03.002f
    c:\$$deletme.wtspai32.dll\$$DeleteMe.loadperf.dll.01c8c67dbf2d7983.0018
    c:\$$deletme.wtspai32.dll\$$DeleteMe.localspl.dll.01c8c67dc086a0e3.0030
    c:\$$deletme.wtspai32.dll\$$DeleteMe.MpClient.dll.01c8c67dbfa6dfa3.0027
    c:\$$deletme.wtspai32.dll\$$DeleteMe.MpRtPlug.dll.01c8c67dbfa21ce3.0025
    c:\$$deletme.wtspai32.dll\$$DeleteMe.MPSSVC.dll.01c8c67dbf61d7c3.0023
    c:\$$deletme.wtspai32.dll\$$DeleteMe.MpSvc.dll.01c8c67dbfa47e43.0026
    c:\$$deletme.wtspai32.dll\$$DeleteMe.msxml3.dll.01c8c67dbf4c6b63.0020
    c:\$$deletme.wtspai32.dll\$$DeleteMe.msxml3r.dll.01c8c67dbf4a0a03.001f
    c:\$$deletme.wtspai32.dll\$$DeleteMe.msxml6.dll.01c8c67dbeed3463.0013
    c:\$$deletme.wtspai32.dll\$$DeleteMe.msxml6r.dll.01c8c67dbeed3463.0012
    c:\$$deletme.wtspai32.dll\$$DeleteMe.ndptsp.tsp.01c8c67dc0890243.0032
    c:\$$deletme.wtspai32.dll\$$DeleteMe.netcfgx.dll.01c8c67dc0713483.002e
    c:\$$deletme.wtspai32.dll\$$DeleteMe.oleaut32.dll.01c8c67dbec71e63.000b
    c:\$$deletme.wtspai32.dll\$$DeleteMe.poqexec.exe.01c8c67dbe60c343.0002
    c:\$$deletme.wtspai32.dll\$$DeleteMe.qmgr.dll.01c8c67dbe527b03.0000
    c:\$$deletme.wtspai32.dll\$$DeleteMe.rpcrt4.dll.01c8c67dbe8dfd63.0008
    c:\$$deletme.wtspai32.dll\$$DeleteMe.schannel.dll.01c8c67dbee14d83.000f
    c:\$$deletme.wtspai32.dll\$$DeleteMe.schedsvc.dll.01c8c67dbf2fdae3.001a
    c:\$$deletme.wtspai32.dll\$$DeleteMe.setupapi.dll.01c8c67dbf323c43.001b
    c:\$$deletme.wtspai32.dll\$$DeleteMe.shell32.dll.01c8c67dbee61043.0011
    c:\$$deletme.wtspai32.dll\$$DeleteMe.SLC.dll.01c8c67dbefb7ca3.0014
    c:\$$deletme.wtspai32.dll\$$DeleteMe.SLsvc.exe.01c8c67dbefb7ca3.0015
    c:\$$deletme.wtspai32.dll\$$DeleteMe.srclient.dll.01c8c67dbf323c43.001c
    c:\$$deletme.wtspai32.dll\$$DeleteMe.sysmain.dll.01c8c67dbfd8dc83.002c
    c:\$$deletme.wtspai32.dll\$$DeleteMe.TrustedInstaller.exe.01c8c67dbf396063.001d
    c:\$$deletme.wtspai32.dll\$$DeleteMe.umpnpmgr.dll.01c8c67dbf2b1823.0017
    c:\$$deletme.wtspai32.dll\$$DeleteMe.urlmon.dll.01c8c67dbe7d53c3.0006
    c:\$$deletme.wtspai32.dll\$$DeleteMe.user32.dll.01c8c67dbe599f23.0001
    c:\$$deletme.wtspai32.dll\$$DeleteMe.wbemcomn.dll.01c8c67dbfdd9f43.002d
    c:\$$deletme.wtspai32.dll\$$DeleteMe.WebClnt.dll.01c8c67dbfcf5703.002a
    c:\$$deletme.wtspai32.dll\$$DeleteMe.wfapigp.dll.01c8c67dbf61d7c3.0022
    c:\$$deletme.wtspai32.dll\$$DeleteMe.WindowsCodecs.dll.01c8c67dbedeec23.000c
    c:\$$deletme.wtspai32.dll\$$DeleteMe.wininet.dll.01c8c67dbe8477e3.0007
    c:\$$deletme.wtspai32.dll\$$DeleteMe.winsrv.dll.01c8c67dbfca9443.0028
    c:\$$deletme.wtspai32.dll\$$DeleteMe.wmi.dll.01c8c67dbe6a48c3.0004
    c:\$$deletme.wtspai32.dll\$$DeleteMe.wtsapi32.dll.01c8c67dbfd8dc83.002b
    C:\install.exe
    c:\windows\system32\out.txt

    .
    ((((((((((((((((((((((((( Files Created from 2011-01-28 to 2011-02-28 )))))))))))))))))))))))))))))))
    .

    2011-02-28 17:32 . 2011-02-28 17:32 -------- d-----w- c:\users\User\AppData\Local\temp
    2011-02-28 17:32 . 2011-02-28 17:32 -------- d-----w- c:\users\Default\AppData\Local\temp
    2011-02-28 02:29 . 2011-02-28 02:29 -------- d-----w- c:\users\User\AppData\Roaming\SUPERAntiSpyware.com
    2011-02-28 02:29 . 2011-02-28 02:29 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
    2011-02-28 02:29 . 2011-02-28 02:29 -------- d-----w- c:\program files\SUPERAntiSpyware
    2011-02-28 01:41 . 2011-02-28 01:41 -------- d-----w- C:\avrescue
    2011-02-27 23:22 . 2011-02-23 14:35 5943120 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{53F92516-038B-4246-A038-28A59990747A}\mpengine.dll
    2011-02-27 23:14 . 2011-02-27 23:14 -------- d-----w- c:\windows\en
    2011-02-27 23:09 . 2011-02-27 23:09 -------- dc----w- c:\windows\system32\DRVSTORE
    2011-02-27 23:09 . 2010-09-23 05:21 39272 ----a-w- c:\windows\system32\drivers\fssfltr.sys
    2011-02-27 23:01 . 2011-02-27 23:01 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
    2011-02-27 22:49 . 2011-02-27 23:15 -------- d-----w- c:\program files\Windows Live
    2011-02-27 22:46 . 2011-02-27 22:46 -------- d-----w- c:\program files\Microsoft
    2011-02-27 22:46 . 2011-02-27 22:46 -------- d-----w- c:\program files\MSN Toolbar
    2011-02-27 22:46 . 2011-02-27 22:46 -------- d-----w- c:\program files\Bing Bar Installer
    2011-02-27 22:42 . 2011-02-27 22:42 -------- d-----w- c:\users\User\AppData\Local\Windows Live
    2011-02-27 22:42 . 2011-02-27 22:42 -------- d-----w- c:\program files\Common Files\Windows Live
    2011-02-27 22:41 . 2009-08-04 08:02 754688 ----a-w- c:\windows\system32\webservices.dll
    2011-02-27 17:21 . 2011-02-27 17:21 -------- d--h--w- c:\windows\PIF
    2011-02-25 01:21 . 2011-02-25 01:21 -------- d-----w- c:\program files\CCleaner
    2011-02-20 16:23 . 2011-01-19 22:47 22504 ----a-w- c:\windows\system32\drivers\cpuz135_x32.sys
    2011-02-17 01:22 . 2011-02-17 01:22 -------- d-----w- c:\program files\Common Files\Software Update Utility
    2011-02-16 01:59 . 2007-12-17 22:14 12400 ----a-w- c:\windows\system32\drivers\AsIO.sys
    2011-02-16 01:59 . 2008-01-04 18:34 11832 ----a-w- c:\windows\system32\drivers\AsInsHelp64.sys
    2011-02-16 01:59 . 2008-01-04 18:34 10216 ----a-w- c:\windows\system32\drivers\AsInsHelp32.sys
    2011-02-16 01:59 . 2002-07-25 15:07 614532 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe
    2011-02-16 01:59 . 2001-09-05 09:18 77824 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\ctor.dll
    2011-02-16 01:59 . 2001-09-05 09:18 225280 ----a-w- c:\program files\Common Files\InstallShield\IScript\iscript.dll
    2011-02-16 01:59 . 2001-09-05 09:14 176128 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\iuser.dll
    2011-02-16 01:59 . 2001-09-05 09:13 32768 ----a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\objectps.dll
    2011-02-10 03:16 . 2011-02-10 03:16 -------- d-sh--w- c:\windows\system32\%APPDATA%
    2011-02-09 22:15 . 2008-11-10 16:41 32656 ----a-w- c:\windows\system32\msonpmon.dll
    2011-02-09 22:15 . 2006-10-27 00:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
    2011-02-09 22:14 . 2011-02-11 21:41 -------- d-----w- c:\program files\Microsoft Works
    2011-02-09 22:14 . 2011-02-09 22:14 -------- d-----w- c:\windows\PCHEALTH
    2011-02-09 22:12 . 2011-02-09 22:12 -------- d-----w- c:\program files\Microsoft Visual Studio 8
    2011-02-09 18:25 . 2011-02-09 18:25 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
    2011-02-09 02:46 . 2011-02-09 02:46 -------- d-----r- C:\MSOCache
    2011-02-08 19:14 . 2010-12-18 06:28 638232 ----a-w- c:\program files\Internet Explorer\iexplore.exe
    2011-02-06 23:46 . 2011-02-16 01:56 -------- d-----w- c:\users\User\AppData\Roaming\Download Manager
    2011-02-06 22:15 . 2011-02-13 04:46 -------- d-----w- c:\programdata\Microsoft Help
    2011-02-06 22:15 . 2011-02-06 22:15 -------- d-----w- c:\users\User\AppData\Local\Microsoft Help
    2011-02-06 20:10 . 2011-02-06 20:10 -------- d-----w- c:\programdata\VirtualizedApplications
    2011-02-06 18:25 . 2011-02-06 18:25 -------- d-----w- c:\program files\Microsoft XNA
    2011-02-06 17:57 . 2011-02-06 22:59 -------- d-----w- c:\users\User\AppData\Local\SoftGrid Client
    2011-02-06 17:57 . 2011-02-07 00:57 -------- d-----w- c:\users\User\AppData\Roaming\SoftGrid Client
    2011-02-06 17:52 . 2011-02-06 22:59 -------- d-----w- c:\users\User\AppData\Roaming\TP

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-02-27 22:47 . 2009-08-18 16:24 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
    2011-02-11 22:14 . 2008-06-07 18:16 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
    2011-02-02 23:49 . 2008-06-07 18:17 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
    2011-02-02 23:49 . 2008-06-07 18:17 22328 ----a-w- c:\users\User\AppData\Roaming\PnkBstrK.sys
    2011-02-02 23:49 . 2008-06-07 18:16 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
    2011-02-02 23:48 . 2008-06-07 18:16 103736 ----a-w- c:\windows\system32\PnkBstrB.ex0
    2011-02-02 23:48 . 2008-06-07 19:06 669184 ----a-w- c:\windows\system32\pbsvc.exe
    2011-02-02 22:11 . 2009-10-03 12:29 222080 ------w- c:\windows\system32\MpSigStub.exe
    2011-02-02 19:23 . 2009-04-02 22:34 270904 ----a-w- c:\windows\system32\PnkBstrB.xtr
    2011-01-08 03:27 . 2011-02-02 02:08 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
    2011-01-08 02:06 . 2011-01-08 02:06 580200 ----a-w- c:\windows\system32\easyUpdatusAPIU.dll
    2011-01-08 02:06 . 2011-01-08 02:06 3597416 ----a-w- c:\windows\system32\nvcpl.dll
    2011-01-08 02:06 . 2011-01-08 02:06 2620520 ----a-w- c:\windows\system32\nvsvc.dll
    2011-01-08 02:06 . 2011-01-08 02:06 66664 ----a-w- c:\windows\system32\nvshext.dll
    2011-01-08 02:06 . 2011-01-08 02:06 608872 ----a-w- c:\windows\system32\nvvsvc.exe
    2011-01-08 02:06 . 2011-01-08 02:06 111208 ----a-w- c:\windows\system32\nvmctray.dll
    2010-12-28 15:55 . 2011-01-12 14:20 413696 ----a-w- c:\windows\system32\odbc32.dll
    2010-12-20 23:09 . 2008-07-30 19:50 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-12-20 23:08 . 2008-07-30 19:50 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-12-14 14:49 . 2011-01-12 14:20 1169408 ----a-w- c:\windows\system32\sdclt.exe
    2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
    2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-10-28 1352272]
    "SoundTray"="c:\program files\Analog Devices\SoundMAX\SoundTray.exe" [2007-05-21 49152]
    "Ai Nap"="c:\program files\ASUS\AI Suite\AiNap\AiNap.exe" [2009-07-02 1435136]
    "QFan Help"="c:\program files\ASUS\AI Suite\QFan3\QFanHelp.exe" [2009-07-02 601088]
    "CPU Power Monitor"="c:\program files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe" [2008-01-09 627200]
    "Cpu Level Up help"="c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2007-12-01 881152]
    "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-06-06 1261568]

    c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Webshots.lnk - c:\program files\Webshots\Launcher.exe [2008-6-5 157000]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux2"=wdmaud.drv

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart

    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Exif Launcher S.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Exif Launcher S.lnk
    backup=c:\windows\pss\Exif Launcher S.lnk.CommonStartup
    backupExtension=.CommonStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    2010-11-10 17:49 932288 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    2010-11-10 17:49 35736 ----a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ai Nap]
    2009-07-02 01:23 1435136 ----a-w- c:\program files\ASUS\AI Suite\AiNap\AiNap.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ContentTransferWMDetector.exe]
    2008-07-11 22:51 423200 ----a-w- c:\program files\Sony\Content Transfer\ContentTransferWMDetector.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpu Level Up help]
    2007-12-01 01:03 881152 ----a-w- c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPU Power Monitor]
    2008-01-09 15:17 627200 ----a-w- c:\program files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
    2007-05-04 06:40 312240 ----a-w- c:\program files\Lexmark Fax Solutions\fm3032.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
    2008-10-25 16:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxddamon]
    2007-03-05 07:40 20480 ----a-w- c:\program files\Lexmark 2500 Series\lxddamon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxddmon.exe]
    2007-05-04 06:38 291760 ----a-w- c:\program files\Lexmark 2500 Series\lxddmon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2010-11-29 22:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2158934232-3957428742-2026527031-1000]
    "EnableNotificationsRef"=dword:00000001

    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R3 cpuz130;cpuz130;c:\users\User\AppData\Local\Temp\cpuz130\cpuz_x32.sys [x]
    R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [x]
    R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [x]
    R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2008-05-06 11520]
    R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
    R3 XDva195;XDva195;c:\windows\system32\XDva195.sys [x]
    R4 lxddCATSCustConnectService;lxddCATSCustConnectService;c:\windows\system32\spool\DRIVERS\W32X86\3\\lxddserv.exe [2007-04-26 99248]
    R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
    S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
    S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
    S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2011-01-19 22504]
    S2 lxdd_device;lxdd_device;c:\windows\system32\lxddcoms.exe [2007-04-26 537520]
    S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
    S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-08 378984]
    S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2010-11-11 122984]


    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
    .
    Contents of the 'Scheduled Tasks' folder

    2011-02-27 c:\windows\Tasks\User_Feed_Synchronization-{333E1AB1-3355-44B5-899A-B6ABBB5D1C32}.job
    - c:\windows\system32\msfeedssync.exe [2011-02-08 04:47]
    .
    .
    ------- Supplementary Scan -------
    .
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
    IE: Se&nd to OneNote - d:\micros~1\Office14\ONBttnIE.dll/105
    FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/aol/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us&tb_uuid=100000000000000002&tb_oid=20-05-2010&tb_mrud=20-05-2010
    FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4cc235f1&v=6.011.025.001&i=23&tp=ab&iy=&ychte=us&lng=en-US&q=
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Move Media Player: moveplayer@movenetworks.com - %profile%\extensions\moveplayer@movenetworks.com
    FF - Ext: Vista-aero: {07b2a769-ed19-4483-87ce-c643914c81bb} - %profile%\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    FF - Ext: Media Converter: {6e764c17-863a-450f-bdd0-6772bd5aaa18} - %profile%\extensions\{6e764c17-863a-450f-bdd0-6772bd5aaa18}
    FF - Ext: Firefox Showcase: {89506680-e3f4-484c-a2c0-ed711d481eda} - %profile%\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
    FF - Ext: SearchPreview: {EF522540-89F5-46b9-B6FE-1829E2B572C6} - %profile%\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
    FF - Ext: Personas: personas@christopher.beard - %profile%\extensions\personas@christopher.beard
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false
    FF - user.js: browser.sessionstore.resume_from_crash - false
    FF - user.js: network.protocol-handler.warn-external.dnupdate - false
    .
    - - - - ORPHANS REMOVED - - - -

    BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
    WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    HKLM-Run-NWEReboot - (no file)
    MSConfigStartUp-SunJavaUpdateSched - c:\program files\Common Files\Java\Java Update\jusched.exe
    AddRemove-Grand Theft Auto - d:\gta ii\Uninst.isu
    AddRemove-{75D84EF7-0D8C-4e70-B3FA-7B42A5D4E0EB} - c:\program files\Common Files\BioWare\Uninstall Mass Effect 2.exe



    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-02-28 12:32
    Windows 6.0.6002 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-2158934232-3957428742-2026527031-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
    "??"=hex:0c,d4,45,b8,3b,14,07,9f,1e,6e,ad,4f,5a,85,e6,b9,19,53,76,18,04,97,4b,
    bc,9d,a9,82,c2,dc,e7,5c,51,2c,a5,0e,18,e0,b7,5c,3e,59,a4,be,21,d0,43,f7,a2,\
    "??"=hex:e2,06,90,c3,a9,ab,f7,ca,1c,f7,63,d7,3e,f2,89,5d

    [HKEY_USERS\S-1-5-21-2158934232-3957428742-2026527031-1000\Software\SecuROM\License information*]
    "datasecu"=hex:83,de,4a,fb,7e,f2,23,63,72,10,a8,17,43,e0,79,db,c2,47,4c,3f,58,
    ec,4a,4e,c3,68,6e,97,5e,84,f1,22,40,62,2d,f5,17,1b,bd,27,19,22,d3,a1,e4,4a,\
    "rkeysecu"=hex:9e,75,97,ea,ba,23,ca,e1,69,94,3b,81,f2,05,06,08

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    Completion time: 2011-02-28 12:34:08
    ComboFix-quarantined-files.txt 2011-02-28 17:34

    Pre-Run: 522,515,251,200 bytes free
    Post-Run: 522,432,208,896 bytes free

    Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,3,5
    - - End Of File - - FDCBEA6FCC1BE8BAF1355844415D7CB4
     
  4. Broni

    Broni Malware Annihilator Posts: 52,911   +344

    Looks good now :)

    How is computer doing?

    Download OTL to your Desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Under the Custom Scan box paste this in:


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    %systemroot%\system32\config\*.bak2
    %systemroot%\system32\Computers\*.*
    %SystemRoot%\system32\Sound\*.*
    %SystemRoot%\system32\SpecialImg\*.*
    %SystemRoot%\system32\code\*.*
    %SystemRoot%\system32\draft\*.*
    %SystemRoot%\system32\MSSSys\*.*
    %ProgramFiles%\Javascript\*.*
    %systemroot%\pchealth\helpctr\System\*.exe /s
    %systemroot%\Web\*.exe
    %systemroot%\system32\msn\*.*
    %systemroot%\system32\*.tro
    %AppData%\Microsoft\Installer\msupdates\*.*
    %ProgramFiles%\Messenger\*.*
    %systemroot%\system32\systhem32\*.*
    %systemroot%\system\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    /md5stop


    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  5. karol3

    karol3 TS Rookie Topic Starter Posts: 34

    Thank for your time, sir. Well my pc is doing well, AVG free for now. So am i safe? I deleted my java 6 program since it was infected and I still have Trojan.Agent/Gen-Nullo in my quarantine section of SUPERAntiSpyware, its MSCONFIG.EXE located in

    C:\Windows\winsxs\x86_microsoft-windows-msconfig-exe_31bf3856ad364e35_6.0.6001.18000_none_da7a3e839dc01091

    is it safe to permanently delete it?

    Logs coming up.
     
  6. karol3

    karol3 TS Rookie Topic Starter Posts: 34

    OTL:

    OTL logfile created on: 2/28/2011 9:51:20 PM - Run 1
    OTL by OldTimer - Version 3.2.22.2 Folder = C:\Users\User\Desktop
    Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.19019)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 65.00% Memory free
    7.00 Gb Paging File | 6.00 Gb Available in Paging File | 82.00% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 698.63 Gb Total Space | 486.40 Gb Free Space | 69.62% Space Free | Partition Type: NTFS
    Drive D: | 111.79 Gb Total Space | 17.13 Gb Free Space | 15.32% Space Free | Partition Type: NTFS
    Drive F: | 1863.01 Gb Total Space | 1556.11 Gb Free Space | 83.53% Space Free | Partition Type: NTFS

    Computer Name: USER-PC | User Name: User | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2011/02/28 21:48:34 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
    PRC - [2011/02/24 19:33:04 | 001,242,448 | ---- | M] (Valve Corporation) -- F:\Steam\Steam.exe
    PRC - [2011/02/18 14:05:46 | 002,423,752 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    PRC - [2011/01/07 21:06:12 | 000,803,432 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
    PRC - [2011/01/07 19:48:56 | 000,378,984 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    PRC - [2010/11/09 15:08:58 | 000,146,000 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
    PRC - [2010/10/14 20:09:30 | 000,451,152 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPointG\SetPointII.exe
    PRC - [2009/07/01 20:23:52 | 001,435,136 | ---- | M] () -- C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
    PRC - [2009/04/11 01:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
    PRC - [2009/03/19 15:41:28 | 000,623,104 | ---- | M] () -- C:\Program Files\ASUS\AASP\1.00.91\aaCenter.exe
    PRC - [2009/03/05 15:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    PRC - [2009/01/22 20:43:54 | 001,352,704 | ---- | M] () -- C:\Program Files\ASUS\AI Suite\EnergySaving\PwSave.exe
    PRC - [2008/05/13 14:50:56 | 003,310,920 | ---- | M] (Webshots.com) -- C:\Program Files\Webshots\Webshots.scr
    PRC - [2008/01/09 10:17:18 | 000,627,200 | ---- | M] () -- C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe
    PRC - [2007/06/06 18:41:36 | 000,086,016 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AEADISRV.EXE
    PRC - [2007/05/21 14:53:42 | 000,049,152 | ---- | M] (Sonic Focus, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SoundTray.exe
    PRC - [2007/04/26 00:21:22 | 000,537,520 | ---- | M] ( ) -- C:\Windows\System32\lxddcoms.exe


    ========== Modules (SafeList) ==========

    MOD - [2011/02/28 21:48:34 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
    MOD - [2010/08/31 10:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll


    ========== Win32 Services (SafeList) ==========

    SRV - File not found [On_Demand | Stopped] -- -- (DAUpdaterSvc)
    SRV - [2011/01/07 19:48:56 | 000,378,984 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
    SRV - [2010/11/17 08:23:41 | 000,403,240 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
    SRV - [2010/10/28 05:13:30 | 000,293,456 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
    SRV - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
    SRV - [2008/01/19 02:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV - [2007/06/06 18:41:36 | 000,086,016 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AEADISRV.EXE -- (AEADIFilters)
    SRV - [2007/04/26 00:21:42 | 000,099,248 | ---- | M] () [Disabled | Stopped] -- C:\Windows\System32\spool\DRIVERS\W32X86\3\\lxddserv.exe -- (lxddCATSCustConnectService)
    SRV - [2007/04/26 00:21:22 | 000,537,520 | ---- | M] ( ) [Auto | Running] -- C:\Windows\System32\lxddcoms.exe -- (lxdd_device)


    ========== Driver Services (SafeList) ==========

    DRV - [2011/01/19 17:47:12 | 000,022,504 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\cpuz135_x32.sys -- (cpuz135)
    DRV - [2011/01/07 22:27:00 | 010,467,656 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
    DRV - [2010/11/11 18:10:50 | 000,122,984 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
    DRV - [2010/08/24 12:31:02 | 000,037,328 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
    DRV - [2010/08/24 12:30:52 | 000,038,864 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
    DRV - [2010/05/10 13:41:30 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
    DRV - [2010/02/17 13:25:48 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
    DRV - [2009/07/28 14:50:42 | 000,281,760 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)
    DRV - [2009/07/28 14:50:42 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
    DRV - [2008/12/18 22:43:06 | 000,020,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\L8042Kbd.sys -- (L8042Kbd)
    DRV - [2008/05/06 16:06:00 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\wdcsam.sys -- (WDC_SAM)
    DRV - [2007/12/17 17:14:06 | 000,012,400 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\AsIO.sys -- (AsIO)
    DRV - [2006/10/18 00:44:48 | 000,007,680 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)
    DRV - [2006/09/24 08:28:46 | 000,005,248 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Boot | Running] -- C:\Windows\system32\speedfan.sys -- (speedfan)
    DRV - [2005/08/17 07:47:48 | 000,073,696 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdserd.sys -- (sscdserd) SAMSUNG CDMA Modem Diagnostic Serial Port (WDM)
    DRV - [2005/08/17 07:46:26 | 000,093,872 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdmdm.sys -- (sscdmdm)
    DRV - [2005/08/17 07:46:20 | 000,008,272 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdmdfl.sys -- (sscdmdfl)
    DRV - [2005/08/17 07:45:00 | 000,058,352 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM)
    DRV - [1996/04/03 14:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\system32\giveio.sys -- (giveio)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========



    IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



    IE - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
    IE - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
    IE - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 89 A7 EE 71 A0 D7 CB 01 [binary data]
    IE - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
    IE - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
    FF - prefs.js..browser.search.defaulturl: "http://aim.search.aol.com/aol/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us&tb_uuid=100000000000000002&tb_oid=20-05-2010&tb_mrud=20-05-2010"
    FF - prefs.js..browser.search.suggest.enabled: false
    FF - prefs.js..browser.search.useDBForOrder: true
    FF - prefs.js..extensions.enabledItems: {89506680-e3f4-484c-a2c0-ed711d481eda}:0.9.5.6
    FF - prefs.js..extensions.enabledItems: {6e764c17-863a-450f-bdd0-6772bd5aaa18}:1.0.3
    FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071303000006
    FF - prefs.js..extensions.enabledItems: {EF522540-89F5-46b9-B6FE-1829E2B572C6}:4.9.4
    FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.6.1
    FF - prefs.js..extensions.enabledItems: DeviceDetection@logitech.com:1.20.0.66
    FF - prefs.js..extensions.enabledItems: {07b2a769-ed19-4483-87ce-c643914c81bb}:3.0.0.91
    FF - prefs.js..keyword.URL: "http://search.avg.com/route/?d=4cc235f1&v=6.011.025.001&i=23&tp=ab&iy=&ychte=us&lng=en-US&q="


    FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\
    FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared
    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/01/26 22:28:51 | 000,000,000 | ---D | M]
    FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/02/09 17:14:56 | 000,000,000 | ---D | M]

    [2008/06/12 17:55:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Extensions
    [2011/02/28 11:05:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\extensions
    [2010/05/27 20:09:49 | 000,000,000 | ---D | M] (Vista-aero) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}
    [2010/05/11 11:01:14 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    [2009/04/07 19:09:52 | 000,000,000 | ---D | M] (Media Converter) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\extensions\{6e764c17-863a-450f-bdd0-6772bd5aaa18}
    [2010/10/28 18:35:07 | 000,000,000 | ---D | M] (Firefox Showcase) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
    [2010/11/11 17:49:17 | 000,000,000 | ---D | M] (SearchPreview) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
    [2010/10/28 18:35:07 | 000,000,000 | ---D | M] (Разпознаване на устройство Logitech) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\extensions\DeviceDetection@logitech.com
    [2009/03/18 21:39:35 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\extensions\moveplayer@movenetworks.com
    [2010/09/17 17:15:55 | 000,000,000 | ---D | M] (Personas) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\extensions\personas@christopher.beard
    [2010/05/27 20:09:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}\chrome\mozapps\extensions
    [2009/01/22 17:28:49 | 000,001,739 | ---- | M] () -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\searchplugins\aim-search.xml
    [2009/06/07 19:04:32 | 000,002,190 | ---- | M] () -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\searchplugins\hulu.xml
    [2010/05/20 20:26:48 | 000,001,705 | ---- | M] () -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\2wd3uea1.default\searchplugins\shmoop.xml
    [2011/02/27 15:13:06 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
    [2010/11/23 19:17:26 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
    [2009/03/09 18:17:25 | 000,221,184 | ---- | M] (CNN) -- C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll
    [2007/04/16 12:07:12 | 000,180,293 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll

    O1 HOSTS File: ([2011/02/28 12:32:25 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
    O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
    O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found.
    O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
    O3 - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
    O4 - HKLM..\Run: [Ai Nap] C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe ()
    O4 - HKLM..\Run: [Cpu Level Up help] C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe ()
    O4 - HKLM..\Run: [CPU Power Monitor] C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe ()
    O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
    O4 - HKLM..\Run: [QFan Help] C:\Program Files\ASUS\AI Suite\QFan3\QFanHelp.exe ()
    O4 - HKLM..\Run: [SoundTray] C:\Program Files\Analog Devices\SoundMAX\SoundTray.exe (Sonic Focus, Inc.)
    O4 - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
    O4 - Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Webshots.lnk = C:\Program Files\Webshots\Launcher.exe (Webshots.com)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
     
  7. karol3

    karol3 TS Rookie Topic Starter Posts: 34

    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 157
    O7 - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
    O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.18.47.61 209.18.47.62
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O24 - Desktop WallPaper: C:\Users\User\AppData\Roaming\Webshots\The Webshots Desktop\Webshots Wallpaper.bmp
    O24 - Desktop BackupWallPaper: C:\Users\User\AppData\Roaming\Webshots\The Webshots Desktop\Webshots Wallpaper.bmp
    O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
    O32 - HKLM CDRom: AutoRun - 1
    O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
    O34 - HKLM BootExecute: (autocheck autochk *) - File not found
    O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - File not found
    O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - File not found
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    NetSvcs: FastUserSwitchingCompatibility - File not found
    NetSvcs: Ias - File not found
    NetSvcs: Nla - File not found
    NetSvcs: Ntmssvc - File not found
    NetSvcs: NWCWorkstation - File not found
    NetSvcs: Nwsapagent - File not found
    NetSvcs: SRService - File not found
    NetSvcs: WmdmPmSp - File not found
    NetSvcs: LogonHours - File not found
    NetSvcs: PCAudit - File not found
    NetSvcs: helpsvc - File not found
    NetSvcs: uploadmgr - File not found

    Drivers32: msacm.ac3acm - C:\Windows\System32\AC3ACM.acm (fccHandler)
    Drivers32: msacm.alf2cd - C:\Windows\System32\alf2cd.acm (NCT Company)
    Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
    Drivers32: msacm.lhacm - C:\Windows\System32\lhacm.acm (Microsoft Corporation)
    Drivers32: msacm.scg726 - C:\Windows\System32\Scg726.acm (SHARP Corporation)
    Drivers32: msacm.voxacm160 - C:\Windows\System32\vct3216.acm (Voxware, Inc.)
    Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
    Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
    Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
    Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
    Drivers32: vidc.dvsd - C:\Windows\System32\mcdvd_32.dll (MainConcept)
    Drivers32: VIDC.FPS1 - C:\Windows\System32\frapsvid.dll (Beepa P/L)
    Drivers32: VIDC.I420 - lvcodec2.dll File not found
    Drivers32: vidc.iv31 - C:\Windows\System32\ir32_32.dll (Intel(R) Corporation)
    Drivers32: vidc.iv32 - C:\Windows\System32\ir32_32.dll (Intel(R) Corporation)
    Drivers32: vidc.iv41 - C:\Windows\System32\ir41_32.ax (Intel Corporation)
    Drivers32: vidc.iv50 - C:\Windows\System32\ir50_32.dll (Intel Corporation)
    Drivers32: VIDC.XFR1 - C:\Windows\System32\xfcodec.dll ()
    Drivers32: vidc.xvid - C:\Windows\System32\xvidvfw.dll ()
    Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)

    CREATERESTOREPOINT
    Restore point Set: OTL Restore Point

    ========== Files/Folders - Created Within 30 Days ==========

    [2011/02/28 21:48:30 | 000,581,120 | ---- | C] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
    [2011/02/28 18:38:21 | 000,000,000 | -HSD | C] -- C:\Config.Msi
    [2011/02/28 12:34:11 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
    [2011/02/28 12:34:09 | 000,000,000 | ---D | C] -- C:\Windows\temp
    [2011/02/28 12:34:09 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\temp
    [2011/02/28 12:26:17 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
    [2011/02/28 12:26:17 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
    [2011/02/28 12:26:17 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
    [2011/02/28 12:26:13 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
    [2011/02/28 12:26:04 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2011/02/28 12:25:49 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
    [2011/02/27 22:19:25 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\New Folder
    [2011/02/27 21:29:33 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\SUPERAntiSpyware.com
    [2011/02/27 21:29:33 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
    [2011/02/27 21:29:30 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
    [2011/02/27 21:29:29 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
    [2011/02/27 20:41:57 | 000,000,000 | ---D | C] -- C:\avrescue
    [2011/02/27 18:14:43 | 000,000,000 | ---D | C] -- C:\Windows\en
    [2011/02/27 18:09:22 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE
    [2011/02/27 18:06:16 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live
    [2011/02/27 18:01:32 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server Compact Edition
    [2011/02/27 17:49:04 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
    [2011/02/27 17:46:39 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft
    [2011/02/27 17:42:13 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Windows Live
    [2011/02/27 17:42:11 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
    [2011/02/27 12:21:32 | 000,000,000 | -H-D | C] -- C:\Windows\PIF
    [2011/02/24 20:21:20 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
    [2011/02/24 19:48:52 | 000,000,000 | ---D | C] -- C:\Users\User\Documents\puzzle quest
    [2011/02/23 10:49:01 | 000,000,000 | ---D | C] -- C:\Windows\System32\WindowsPowerShell
    [2011/02/20 11:23:42 | 000,022,504 | ---- | C] (CPUID) -- C:\Windows\System32\drivers\cpuz135_x32.sys
    [2011/02/20 11:23:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
    [2011/02/19 11:43:29 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
    [2011/02/19 11:43:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan
    [2011/02/16 20:22:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIM
    [2011/02/16 20:22:36 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Software Update Utility
    [2011/02/15 20:59:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
    [2011/02/09 22:16:05 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA%
    [2011/02/09 17:16:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
    [2011/02/09 17:14:49 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
    [2011/02/09 17:14:34 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio
    [2011/02/09 17:14:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
    [2011/02/09 17:14:14 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
    [2011/02/09 17:12:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2005
    [2011/02/09 17:12:32 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 8
    [2011/02/09 17:11:46 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
    [2011/02/08 21:46:06 | 000,000,000 | R--D | C] -- C:\MSOCache
    [2011/02/06 18:46:17 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Download Manager
    [2011/02/06 17:15:10 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\Microsoft Help
    [2011/02/06 17:15:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
    [2011/02/06 15:10:12 | 000,000,000 | ---D | C] -- C:\ProgramData\VirtualizedApplications
    [2011/02/06 13:25:57 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft XNA
    [2011/02/06 12:57:50 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\SoftGrid Client
    [2011/02/06 12:57:06 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\SoftGrid Client
    [2011/02/06 12:52:53 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\TP
    [2011/02/01 21:28:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
    [2011/02/01 21:08:38 | 000,057,960 | ---- | C] (Khronos Group) -- C:\Windows\System32\OpenCL.dll
    [2008/06/05 12:01:21 | 000,413,696 | ---- | C] ( ) -- C:\Windows\System32\lxddinpa.dll
    [2008/06/05 12:01:21 | 000,397,312 | ---- | C] ( ) -- C:\Windows\System32\lxddiesc.dll
    [2008/06/05 12:01:21 | 000,323,584 | ---- | C] ( ) -- C:\Windows\System32\LXDDhcp.dll
    [2008/06/05 12:01:20 | 001,232,896 | ---- | C] ( ) -- C:\Windows\System32\lxddserv.dll
    [2008/06/05 12:01:20 | 000,999,424 | ---- | C] ( ) -- C:\Windows\System32\lxddusb1.dll
    [2008/06/05 12:01:20 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\lxddpmui.dll
    [2008/06/05 12:01:20 | 000,585,728 | ---- | C] ( ) -- C:\Windows\System32\lxddlmpm.dll
    [2008/06/05 12:01:20 | 000,163,840 | ---- | C] ( ) -- C:\Windows\System32\lxddprox.dll
    [2008/06/05 12:01:20 | 000,094,208 | ---- | C] ( ) -- C:\Windows\System32\lxddpplc.dll
    [2008/06/05 12:01:19 | 000,700,416 | ---- | C] ( ) -- C:\Windows\System32\lxddhbn3.dll
    [2008/06/05 12:01:19 | 000,385,968 | ---- | C] ( ) -- C:\Windows\System32\lxddih.exe
    [2008/06/05 12:01:18 | 000,684,032 | ---- | C] ( ) -- C:\Windows\System32\lxddcomc.dll
    [2008/06/05 12:01:18 | 000,537,520 | ---- | C] ( ) -- C:\Windows\System32\lxddcoms.exe
    [2008/06/05 12:01:18 | 000,425,984 | ---- | C] ( ) -- C:\Windows\System32\lxddcomm.dll
    [2008/06/05 12:01:18 | 000,394,160 | ---- | C] ( ) -- C:\Windows\System32\lxddcfg.exe
    [8 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
    [7 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

    ========== Files - Modified Within 30 Days ==========

    [2011/02/28 21:48:34 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
    [2011/02/28 21:43:37 | 000,004,576 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
    [2011/02/28 21:43:37 | 000,004,576 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
    [2011/02/28 18:28:40 | 000,024,800 | ---- | M] () -- C:\Users\User\Documents\Essay 1.odt
    [2011/02/28 18:14:02 | 000,018,894 | ---- | M] () -- C:\Users\User\Documents\Reader Response #2.odt
    [2011/02/28 18:02:14 | 000,000,416 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{333E1AB1-3355-44B5-899A-B6ABBB5D1C32}.job
    [2011/02/28 17:50:07 | 020,513,694 | ---- | M] () -- C:\Windows\System32\perfh009.dat
    [2011/02/28 17:50:07 | 007,155,372 | ---- | M] () -- C:\Windows\System32\perfc009.dat
    [2011/02/28 17:43:34 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2011/02/28 17:43:25 | 3755,102,208 | -HS- | M] () -- C:\hiberfil.sys
    [2011/02/28 12:32:25 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
    [2011/02/28 10:49:02 | 000,000,000 | ---- | M] () -- C:\Users\User\AppData\Local\prvlcl.dat
    [2011/02/28 10:44:45 | 000,002,339 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
    [2011/02/27 21:29:31 | 000,001,760 | ---- | M] () -- C:\Users\User\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2011/02/27 21:12:45 | 000,384,624 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
    [2011/02/26 15:26:48 | 000,022,232 | ---- | M] () -- C:\Users\User\Documents\Flower For Algernon.odt
    [2011/02/25 15:24:48 | 000,017,186 | ---- | M] () -- C:\Users\User\Documents\Letter from the Trenches.odt
    [2011/02/24 20:21:21 | 000,000,764 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
    [2011/02/24 20:19:09 | 000,430,659 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20110227-164736.backup
    [2011/02/24 20:08:59 | 000,000,501 | ---- | M] () -- C:\Users\User\Desktop\Steam.lnk
    [2011/02/23 16:13:58 | 001,170,298 | ---- | M] () -- C:\Users\User\Documents\Trench Warfare.odt
    [2011/02/20 11:23:42 | 000,000,565 | ---- | M] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk
    [2011/02/19 15:42:49 | 000,020,353 | ---- | M] () -- C:\Users\User\Documents\Endocrine System.odt
    [2011/02/19 12:30:03 | 000,019,598 | ---- | M] () -- C:\Users\User\Documents\PRINCIPLES OF SELLING PRESENTATION.odt
    [2011/02/19 11:43:29 | 000,000,510 | ---- | M] () -- C:\Users\User\Desktop\SpeedFan.lnk
    [2011/02/19 11:43:29 | 000,000,045 | ---- | M] () -- C:\Windows\System32\initdebug.nfo
    [2011/02/18 21:31:03 | 000,169,774 | ---- | M] () -- C:\Users\User\Documents\Euclid Essay.odt
    [2011/02/18 20:22:02 | 000,056,626 | ---- | M] () -- C:\Users\User\Documents\Pascal Triangle Patterns.odt
    [2011/02/18 20:21:58 | 000,011,059 | ---- | M] () -- C:\Users\User\Documents\Odd And Even.odt
    [2011/02/16 20:22:42 | 000,001,119 | -H-- | M] () -- C:\IPH.PH
    [2011/02/16 20:22:41 | 000,001,678 | ---- | M] () -- C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\AIM.lnk
    [2011/02/16 20:22:40 | 000,001,654 | ---- | M] () -- C:\Users\Public\Desktop\AIM.lnk
    [2011/02/16 18:57:59 | 000,018,394 | ---- | M] () -- C:\Users\User\Documents\ELA paper # 1 1st draft.odt
    [2011/02/09 18:05:39 | 000,430,425 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20110224-201909.backup
    [2011/02/09 12:38:05 | 000,018,001 | ---- | M] () -- C:\Users\User\Documents\Essay Proposal.odt
    [2011/02/07 18:14:08 | 000,019,348 | ---- | M] () -- C:\Users\User\Documents\English Reader Response 1.odt
    [2011/02/05 22:40:43 | 000,039,936 | ---- | M] () -- C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/02/05 21:51:58 | 000,000,000 | ---- | M] () -- C:\Users\User\AppData\Roaming\AVSDVDPlayer.m3u
    [2011/02/04 16:58:33 | 000,430,293 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20110209-180539.backup
    [2011/02/02 18:49:11 | 000,022,328 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys
    [2011/02/02 18:49:11 | 000,022,328 | ---- | M] () -- C:\Users\User\AppData\Roaming\PnkBstrK.sys
    [2011/02/02 18:48:54 | 000,103,736 | ---- | M] () -- C:\Windows\System32\PnkBstrB.ex0
    [2011/02/02 18:48:53 | 000,669,184 | ---- | M] () -- C:\Windows\System32\pbsvc.exe
    [2011/02/02 14:23:17 | 000,270,904 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr
    [2011/02/01 21:06:43 | 000,002,032 | ---- | M] () -- C:\Users\User\AppData\Local\d3d9caps.dat
    [8 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
    [7 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2011/02/28 12:39:49 | 000,018,894 | ---- | C] () -- C:\Users\User\Documents\Reader Response #2.odt
    [2011/02/28 12:26:17 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
    [2011/02/28 12:26:17 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
    [2011/02/28 12:26:17 | 000,089,088 | ---- | C] () -- C:\Windows\MBR.exe
    [2011/02/28 12:26:17 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
    [2011/02/28 12:26:17 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
    [2011/02/27 21:29:31 | 000,001,760 | ---- | C] () -- C:\Users\User\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2011/02/27 18:05:27 | 000,001,118 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
    [2011/02/27 18:03:08 | 000,001,187 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
    [2011/02/27 17:59:28 | 000,000,997 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
    [2011/02/27 17:57:08 | 000,001,985 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
    [2011/02/26 14:42:57 | 000,022,232 | ---- | C] () -- C:\Users\User\Documents\Flower For Algernon.odt
    [2011/02/25 15:24:46 | 000,017,186 | ---- | C] () -- C:\Users\User\Documents\Letter from the Trenches.odt
    [2011/02/24 20:21:21 | 000,000,764 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
    [2011/02/24 20:09:00 | 000,000,501 | ---- | C] () -- C:\Users\User\Desktop\Steam.lnk
    [2011/02/23 16:13:57 | 001,170,298 | ---- | C] () -- C:\Users\User\Documents\Trench Warfare.odt
    [2011/02/23 10:47:02 | 000,201,184 | ---- | C] () -- C:\Windows\System32\winrm.vbs
    [2011/02/23 10:47:02 | 000,004,675 | ---- | C] () -- C:\Windows\System32\wsmanconfig_schema.xml
    [2011/02/23 10:47:02 | 000,002,426 | ---- | C] () -- C:\Windows\System32\WsmTxt.xsl
    [2011/02/20 11:23:42 | 000,000,565 | ---- | C] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk
    [2011/02/19 15:00:32 | 000,020,353 | ---- | C] () -- C:\Users\User\Documents\Endocrine System.odt
    [2011/02/19 12:07:36 | 000,019,598 | ---- | C] () -- C:\Users\User\Documents\PRINCIPLES OF SELLING PRESENTATION.odt
    [2011/02/19 11:43:29 | 000,000,510 | ---- | C] () -- C:\Users\User\Desktop\SpeedFan.lnk
    [2011/02/19 11:43:00 | 000,000,045 | ---- | C] () -- C:\Windows\System32\initdebug.nfo
    [2011/02/18 21:26:28 | 000,169,774 | ---- | C] () -- C:\Users\User\Documents\Euclid Essay.odt
    [2011/02/18 20:21:54 | 000,011,059 | ---- | C] () -- C:\Users\User\Documents\Odd And Even.odt
    [2011/02/16 16:22:15 | 000,056,626 | ---- | C] () -- C:\Users\User\Documents\Pascal Triangle Patterns.odt
    [2011/02/15 20:59:37 | 000,012,400 | ---- | C] () -- C:\Windows\System32\drivers\AsIO.sys
    [2011/02/15 20:59:33 | 000,011,832 | ---- | C] () -- C:\Windows\System32\drivers\AsInsHelp64.sys
    [2011/02/15 20:59:33 | 000,010,216 | ---- | C] () -- C:\Windows\System32\drivers\AsInsHelp32.sys
    [2011/02/15 20:51:50 | 000,000,000 | ---- | C] () -- C:\Users\User\AppData\Local\prvlcl.dat
    [2011/02/14 18:25:30 | 000,018,394 | ---- | C] () -- C:\Users\User\Documents\ELA paper # 1 1st draft.odt
    [2011/02/09 12:36:49 | 000,024,800 | ---- | C] () -- C:\Users\User\Documents\Essay 1.odt
    [2011/02/09 12:22:37 | 000,018,001 | ---- | C] () -- C:\Users\User\Documents\Essay Proposal.odt
    [2011/02/07 12:51:41 | 000,019,348 | ---- | C] () -- C:\Users\User\Documents\English Reader Response 1.odt
    [2011/02/01 21:27:29 | 3755,102,208 | -HS- | C] () -- C:\hiberfil.sys
    [2011/02/01 21:08:38 | 000,004,756 | ---- | C] () -- C:\Windows\System32\nvinfo.pb
    [2011/02/01 17:20:32 | 000,000,782 | ---- | C] () -- C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Webshots.lnk
    [2010/10/14 01:36:44 | 000,179,263 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
    [2010/02/07 18:07:07 | 000,000,056 | ---- | C] () -- C:\Windows\VideoConvert.INI
    [2010/02/04 21:02:12 | 002,434,856 | ---- | C] () -- C:\Windows\System32\pbsvc_bc2.exe
    [2009/09/03 13:07:10 | 000,041,872 | ---- | C] () -- C:\Windows\System32\xfcodec.dll
    [2009/06/19 14:01:09 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
    [2009/06/19 14:01:09 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
    [2008/11/28 20:00:32 | 000,000,262 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
    [2008/09/24 15:18:49 | 000,281,760 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
    [2008/09/24 15:18:49 | 000,025,888 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
    [2008/07/26 11:07:48 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
    [2008/06/18 21:40:00 | 000,036,120 | ---- | C] () -- C:\Windows\System32\SpoonUninstall-dBpowerAMP Music Converter.dat
    [2008/06/18 21:39:59 | 000,131,072 | ---- | C] () -- C:\Windows\System32\SpoonUninstall.exe
    [2008/06/13 16:33:42 | 000,000,136 | ---- | C] () -- C:\Windows\System32\cpuz.ini
    [2008/06/10 11:13:25 | 000,000,016 | ---- | C] () -- C:\Windows\popcinfo.dat
    [2008/06/08 21:29:28 | 000,039,936 | ---- | C] () -- C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2008/06/07 14:12:25 | 000,000,092 | ---- | C] () -- C:\Users\User\AppData\Local\fusioncache.dat
    [2008/06/07 14:06:06 | 000,669,184 | ---- | C] () -- C:\Windows\System32\pbsvc.exe
    [2008/06/07 13:17:09 | 000,022,328 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
    [2008/06/07 13:17:09 | 000,022,328 | ---- | C] () -- C:\Users\User\AppData\Roaming\PnkBstrK.sys
    [2008/06/07 13:16:52 | 000,103,736 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
    [2008/06/07 13:16:51 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
    [2008/06/07 13:16:49 | 000,000,319 | ---- | C] () -- C:\Windows\game.ini
    [2008/06/06 21:02:11 | 000,000,023 | ---- | C] () -- C:\Windows\BlendSettings.ini
    [2008/06/05 22:56:28 | 000,000,000 | ---- | C] () -- C:\Users\User\AppData\Roaming\AVSDVDPlayer.m3u
    [2008/06/05 20:30:56 | 000,007,224 | ---- | C] () -- C:\ProgramData\lxdd
    [2008/06/05 18:42:42 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
    [2008/06/05 15:18:26 | 000,000,264 | ---- | C] () -- C:\Windows\_delis32.ini
    [2008/06/05 14:01:32 | 000,001,160 | ---- | C] () -- C:\Windows\mozver.dat
    [2008/06/05 13:21:11 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
    [2008/06/05 12:04:41 | 000,344,064 | ---- | C] () -- C:\Windows\System32\lxddcoin.dll
    [2008/06/05 12:03:04 | 000,045,056 | ---- | C] () -- C:\Windows\System32\LXF3PMON.DLL
    [2008/06/05 12:03:04 | 000,032,768 | ---- | C] () -- C:\Windows\System32\LXF3FXPU.DLL
    [2008/06/05 12:02:44 | 000,036,864 | ---- | C] () -- C:\Windows\System32\lxf3oem.dll
    [2008/06/05 12:02:44 | 000,012,288 | ---- | C] () -- C:\Windows\System32\LXF3PMRC.DLL
    [2008/06/05 12:01:51 | 000,000,044 | ---- | C] () -- C:\Windows\System32\lxddrwrd.ini
    [2008/06/05 12:01:21 | 000,286,720 | ---- | C] () -- C:\Windows\System32\LXDDinst.dll
    [2008/06/05 12:01:19 | 000,208,896 | ---- | C] () -- C:\Windows\System32\lxddgrd.dll
    [2008/06/04 15:26:10 | 000,139,264 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
    [2008/06/04 14:25:16 | 000,025,982 | ---- | C] () -- C:\Windows\Ascd_log.ini
    [2008/06/04 14:24:59 | 000,024,576 | ---- | C] () -- C:\Windows\System32\AsIO.dll
    [2008/06/04 14:21:35 | 000,007,680 | ---- | C] () -- C:\Windows\System32\drivers\ASACPI.sys
    [2008/06/04 14:21:34 | 000,025,944 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
    [2008/06/04 14:21:28 | 000,012,536 | ---- | C] () -- C:\Windows\System32\drivers\ASUSHWIO.SYS
    [2008/06/04 14:18:40 | 000,002,032 | ---- | C] () -- C:\Users\User\AppData\Local\d3d9caps.dat
    [2008/05/22 17:22:18 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
    [2008/05/22 17:18:54 | 000,012,288 | ---- | C] () -- C:\Windows\System32\DivXWMPExtType.dll
    [2007/01/23 13:40:03 | 000,065,536 | ---- | C] () -- C:\Windows\System32\lxddcaps.dll
    [2007/01/09 11:13:08 | 000,692,224 | ---- | C] () -- C:\Windows\System32\lxdddrs.dll
    [2006/11/02 07:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
    [2006/11/02 07:47:37 | 000,384,624 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
    [2006/11/02 07:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
    [2006/11/02 05:33:01 | 020,513,694 | ---- | C] () -- C:\Windows\System32\perfh009.dat
    [2006/11/02 05:33:01 | 007,155,372 | ---- | C] () -- C:\Windows\System32\perfc009.dat
    [2006/11/02 05:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
    [2006/11/02 05:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
    [2006/11/02 05:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
    [2006/11/02 03:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
    [2006/11/02 03:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
    [2006/11/02 02:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
    [2006/11/02 02:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
    [2006/10/06 12:08:04 | 000,069,632 | ---- | C] () -- C:\Windows\System32\lxddcnv4.dll
    [2006/05/17 21:47:12 | 000,040,960 | ---- | C] () -- C:\Windows\System32\lxddvs.dll
    [2003/09/23 07:14:42 | 001,099,264 | ---- | C] () -- C:\Windows\System32\cygxml2-2.dll
    [2003/08/10 09:59:20 | 000,980,992 | ---- | C] () -- C:\Windows\System32\cygiconv-2.dll
    [2003/08/08 19:28:16 | 000,061,440 | ---- | C] () -- C:\Windows\System32\cygz.dll
    [1999/01/27 13:39:06 | 000,065,024 | ---- | C] () -- C:\Windows\System32\indounin.dll
    [1997/06/13 07:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\System32\Iyvu9_32.dll
    [1996/04/03 14:33:26 | 000,005,248 | ---- | C] () -- C:\Windows\System32\giveio.sys

    ========== LOP Check ==========

    [2010/07/05 19:55:59 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\2K Sports
    [2009/01/22 17:28:14 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\acccore
    [2010/02/09 20:06:27 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\AnvSoft
    [2010/02/19 13:44:28 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Aura4You
    [2009/10/16 20:37:17 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\AVG9
    [2008/07/24 14:55:59 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Bioshock
    [2010/07/15 19:03:40 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Bioshock2
    [2009/12/23 19:49:34 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Braid
    [2009/06/25 20:57:16 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Dark Sector
    [2010/12/31 11:49:18 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\FUJIFILM
    [2008/06/05 19:25:50 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Gadu-Gadu
    [2011/01/29 11:36:31 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\HandBrake
    [2010/01/19 21:00:54 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\IObit
    [2008/06/05 13:24:26 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\iWin
    [2010/02/27 12:15:02 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Leadertech
    [2010/02/19 13:36:15 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Leawo
    [2008/06/05 12:06:28 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Lexmark Productivity Studio
    [2009/03/02 20:46:47 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\NetMeter
    [2011/02/06 19:57:35 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\SoftGrid Client
    [2010/08/30 19:03:36 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Teleca
    [2008/06/04 14:23:48 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TMP
    [2011/02/06 17:59:16 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TP
    [2010/08/14 18:11:45 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\TS3Client
    [2010/05/15 11:58:46 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Ubisoft
    [2008/06/05 14:23:55 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Webshots
    [2008/09/25 18:34:27 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\XRay Engine
    [2010/12/16 20:43:05 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\ZombieDriver
    [2011/02/28 16:50:04 | 000,032,550 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
    [2011/02/28 18:02:14 | 000,000,416 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{333E1AB1-3355-44B5-899A-B6ABBB5D1C32}.job

    ========== Purity Check ==========



    ========== Custom Scans ==========


    < >

    < >

    < %SYSTEMDRIVE%\*.* >
    [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
    [2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () -- C:\bootmgr
    [2008/06/04 17:10:55 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
    [2006/09/18 16:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
    [2008/06/05 15:18:21 | 000,000,000 | ---- | M] () -- C:\Debug.QC6
    [2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1028.txt
    [2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1031.txt
    [2007/11/07 08:00:40 | 000,010,134 | ---- | M] () -- C:\eula.1033.txt
    [2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1036.txt
    [2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1040.txt
    [2007/11/07 08:00:40 | 000,000,118 | ---- | M] () -- C:\eula.1041.txt
    [2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.1042.txt
    [2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.2052.txt
    [2007/11/07 08:00:40 | 000,017,734 | ---- | M] () -- C:\eula.3082.txt
    [2007/11/07 08:00:40 | 000,001,110 | ---- | M] () -- C:\globdata.ini
    [2011/02/28 17:43:25 | 3755,102,208 | -HS- | M] () -- C:\hiberfil.sys
    [2007/11/07 08:00:40 | 000,000,843 | ---- | M] () -- C:\install.ini
    [2007/11/07 08:03:18 | 000,076,304 | ---- | M] (Microsoft Corporation) -- C:\install.res.1028.dll
    [2007/11/07 08:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.1031.dll
    [2007/11/07 08:03:18 | 000,091,152 | ---- | M] (Microsoft Corporation) -- C:\install.res.1033.dll
    [2007/11/07 08:03:18 | 000,097,296 | ---- | M] (Microsoft Corporation) -- C:\install.res.1036.dll
    [2007/11/07 08:03:18 | 000,095,248 | ---- | M] (Microsoft Corporation) -- C:\install.res.1040.dll
    [2007/11/07 08:03:18 | 000,081,424 | ---- | M] (Microsoft Corporation) -- C:\install.res.1041.dll
    [2007/11/07 08:03:18 | 000,079,888 | ---- | M] (Microsoft Corporation) -- C:\install.res.1042.dll
    [2007/11/07 08:03:18 | 000,075,792 | ---- | M] (Microsoft Corporation) -- C:\install.res.2052.dll
    [2007/11/07 08:03:18 | 000,096,272 | ---- | M] (Microsoft Corporation) -- C:\install.res.3082.dll
    [2009/03/22 20:43:33 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
    [2011/02/16 20:22:42 | 000,001,119 | -H-- | M] () -- C:\IPH.PH
    [2009/03/22 20:43:33 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
    [2011/02/28 17:43:23 | 4070,760,448 | -HS- | M] () -- C:\pagefile.sys
    [2007/11/07 08:00:40 | 000,005,686 | ---- | M] () -- C:\vcredist.bmp
    [2007/11/07 08:09:22 | 001,442,522 | ---- | M] () -- C:\VC_RED.cab
    [2007/11/07 08:12:28 | 000,232,960 | ---- | M] () -- C:\VC_RED.MSI

    < %systemroot%\Fonts\*.com >
    [2006/11/02 07:37:12 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
    [2006/11/02 07:37:12 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
    [2006/11/02 07:37:12 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
    [2009/06/19 14:07:11 | 000,037,665 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont

    < %systemroot%\Fonts\*.dll >

    < %systemroot%\Fonts\*.ini >
    [2006/09/18 16:37:34 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini

    < %systemroot%\Fonts\*.ini2 >

    < %systemroot%\Fonts\*.exe >

    < %systemroot%\system32\spool\prtprocs\w32x86\*.* >
    [2006/11/02 07:35:48 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
    [2007/02/26 23:16:25 | 000,103,936 | ---- | M] () -- C:\Windows\System32\spool\prtprocs\w32x86\lxdddrpp.dll
    [2006/10/26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll

    < %systemroot%\REPAIR\*.bak1 >

    < %systemroot%\REPAIR\*.ini >

    < %systemroot%\system32\*.jpg >

    < %systemroot%\*.jpg >

    < %systemroot%\*.png >

    < %systemroot%\*.scr >
    [2010/11/10 02:28:46 | 000,301,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
    [7 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

    < %systemroot%\*._sy >

    < %APPDATA%\Adobe\Update\*.* >

    < %ALLUSERSPROFILE%\Favorites\*.* >

    < %APPDATA%\Microsoft\*.* >

    < %PROGRAMFILES%\*.* >
    [2008/06/08 13:55:10 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini

    < %APPDATA%\Update\*.* >

    < %systemroot%\*. /mp /s >

    < %systemroot%\System32\config\*.sav >
    [2006/11/02 05:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
    [2006/11/02 05:34:05 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
    [2006/11/02 05:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
    [2006/11/02 05:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
    [2006/11/02 05:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV

    < %PROGRAMFILES%\bak. /s >

    < %systemroot%\system32\bak. /s >

    < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

    < %systemroot%\system32\config\systemprofile\*.dat /x >

    < %systemroot%\*.config >

    < %systemroot%\system32\*.db >

    < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
    [2009/10/20 20:15:13 | 000,000,339 | -HS- | M] () -- C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

    < %USERPROFILE%\Desktop\*.exe >
    [2011/01/26 09:27:52 | 000,908,128 | ---- | M] (techPowerUp (www.techpowerup.com)) -- C:\Users\User\Desktop\GPU-Z.0.5.1.exe
    [2011/02/28 21:48:34 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe

    < %PROGRAMFILES%\Common Files\*.* >

    < %systemroot%\*.src >

    < %systemroot%\install\*.* >

    < %systemroot%\system32\DLL\*.* >

    < %systemroot%\system32\HelpFiles\*.* >

    < %systemroot%\system32\rundll\*.* >

    < %systemroot%\winn32\*.* >

    < %systemroot%\Java\*.* >

    < %systemroot%\system32\test\*.* >

    < %systemroot%\system32\Rundll32\*.* >

    < %systemroot%\AppPatch\Custom\*.* >

    < %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

    < %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

    < %PROGRAMFILES%\Internet Explorer\*.tmp >

    < %PROGRAMFILES%\Internet Explorer\*.dat >

    < %USERPROFILE%\My Documents\*.exe >

    < %USERPROFILE%\*.exe >

    < %systemroot%\ADDINS\*.* >

    < %systemroot%\assembly\*.bak2 >

    < %systemroot%\Config\*.* >

    < %systemroot%\REPAIR\*.bak2 >

    < %systemroot%\SECURITY\Database\*.sdb /x >

    < %systemroot%\SYSTEM\*.bak2 >

    < %systemroot%\Web\*.bak2 >

    < %systemroot%\Driver Cache\*.* >

    < %PROGRAMFILES%\Mozilla Firefox\0*.exe >

    < %ProgramFiles%\Microsoft Common\*.* >

    < %ProgramFiles%\TinyProxy. >

    < %USERPROFILE%\Favorites\*.url /x >
    [2008/06/05 17:58:39 | 000,000,402 | -HS- | M] () -- C:\Users\User\Favorites\desktop.ini

    < %systemroot%\system32\*.bk >

    < %systemroot%\*.te >

    < %systemroot%\system32\system32\*.* >

    < %ALLUSERSPROFILE%\*.dat /x >
    [2011/01/19 16:16:29 | 000,007,224 | ---- | M] () -- C:\ProgramData\lxdd

    < %systemroot%\system32\drivers\*.rmv >

    < dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

    < dir /b "%systemroot%\*.exe" | find /i " " /c >

    < %PROGRAMFILES%\Microsoft\*.* >

    < %systemroot%\System32\Wbem\proquota.exe >

    < %PROGRAMFILES%\Mozilla Firefox\*.dat >

    < %USERPROFILE%\Cookies\*.txt /x >

    < %SystemRoot%\system32\fonts\*.* >

    < %systemroot%\system32\winlog\*.* >

    < %systemroot%\system32\Language\*.* >

    < %systemroot%\system32\Settings\*.* >

    < %systemroot%\system32\*.quo >

    < %SYSTEMROOT%\AppPatch\*.exe >

    < %SYSTEMROOT%\inf\*.exe >

    < %SYSTEMROOT%\Installer\*.exe >

    < %systemroot%\system32\config\*.bak2 >

    < %systemroot%\system32\Computers\*.* >

    < %SystemRoot%\system32\Sound\*.* >

    < %SystemRoot%\system32\SpecialImg\*.* >

    < %SystemRoot%\system32\code\*.* >

    < %SystemRoot%\system32\draft\*.* >

    < %SystemRoot%\system32\MSSSys\*.* >

    < %ProgramFiles%\Javascript\*.* >

    < %systemroot%\pchealth\helpctr\System\*.exe /s >

    < %systemroot%\Web\*.exe >

    < %systemroot%\system32\msn\*.* >

    < %systemroot%\system32\*.tro >

    < %AppData%\Microsoft\Installer\msupdates\*.* >

    < %ProgramFiles%\Messenger\*.* >

    < %systemroot%\system32\systhem32\*.* >

    < %systemroot%\system\*.exe >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >


    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:5C321E34
    @Alternate Data Stream - 508 bytes -> C:\ProgramData\TEMP:05EE1EEF
    @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:AC6124CA

    < End of report >
     
  8. Broni

    Broni Malware Annihilator Posts: 52,911   +344

    Good news :)

    Upload the file to http://www.virustotal.com/ for security check:
    IMPORTANT! If the file is listed as already analyzed, click on Reanalyse file now button.
     
  9. karol3

    karol3 TS Rookie Topic Starter Posts: 34

    OTL Extras logfile created on: 2/28/2011 9:51:20 PM - Run 1
    OTL by OldTimer - Version 3.2.22.2 Folder = C:\Users\User\Desktop
    Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.19019)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 65.00% Memory free
    7.00 Gb Paging File | 6.00 Gb Available in Paging File | 82.00% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 698.63 Gb Total Space | 486.40 Gb Free Space | 69.62% Space Free | Partition Type: NTFS
    Drive D: | 111.79 Gb Total Space | 17.13 Gb Free Space | 15.32% Space Free | Partition Type: NTFS
    Drive F: | 1863.01 Gb Total Space | 1556.11 Gb Free Space | 83.53% Space Free | Partition Type: NTFS

    Computer Name: USER-PC | User Name: User | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
    .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

    [HKEY_USERS\S-1-5-21-2158934232-3957428742-2026527031-1000\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
    https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "D:\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [PlayWithVLC] -- "D:\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0
    "VistaSp1" = Reg Error: Unknown registry data type -- File not found
    "VistaSp2" = Reg Error: Unknown registry data type -- File not found

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-2158934232-3957428742-2026527031-1000]
    "EnableNotifications" = 0
    "EnableNotificationsRef" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "DisableNotifications" = 1
    "EnableFirewall" = 1
    "DoNotAllowExceptions" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{2B02ADD1-3182-496F-85A9-6B19CB1DECAC}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
    "{540EBAD4-3204-4F0F-AFFE-1CD9EBCE1291}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
    "{E282B796-485C-4987-9AD9-6E83D24F4EB4}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{003AC244-DCC0-4E51-AD91-A9B30423D3CD}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\fear2\fear2.exe |
    "{003C9592-CB13-46FD-AF04-346C0CF1FEBA}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\lxddmon.exe |
    "{004B4D73-ED51-4334-9BD7-0F205AC1508C}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\puzzle quest\puzzle quest.exe |
    "{0157CD7C-E77B-4DD0-91ED-8CE2764A4267}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez - bound in blood\cojbibgame_x86.exe |
    "{01F267EF-558C-4B28-AC89-5F023430B012}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe |
    "{04364725-0C75-46C7-83E0-A9DBCFF50168}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\swarm.exe |
    "{05C19064-36B9-416A-A664-864AB3CD83B1}" = protocol=17 | dir=in | app=c:\program files\eidos\batman arkham asylum\binaries\shippingpc-bmgame.exe |
    "{05D59025-EF5C-482E-9825-FB4A95E3A68F}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
    "{07AB361D-77DB-4172-92B5-5FFC1E435299}" = protocol=6 | dir=in | app=c:\program files\sierra entertainment\world in conflict\wic_ds.exe |
    "{0856D5B7-70D9-4F2F-ADFB-19085DA9C512}" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysis.exe |
    "{088032EF-278F-4DBA-86D6-17F460D7ABFC}" = protocol=17 | dir=in | app=c:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\dedicated\xrengine.exe |
    "{097E1D1D-ABEB-4681-A60E-619DF3D98057}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\killingfloor\system\killingfloor.exe |
    "{09B6B20C-A012-43CA-AE84-045120D72BB1}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\metro 2033\metro2033.exe |
    "{09C3866B-8BBF-4644-BCBD-97C286249F24}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\world of goo\worldofgoo.exe |
    "{09C86618-750A-44B4-B154-437444831850}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\nba 2k10\nba2k10.exe |
    "{0B3D06AA-8BC1-4694-90E9-0EE9ABE97B4A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord\config.exe |
    "{0C0C6772-5DE8-43A6-AD9E-01CBD066AE4C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
    "{0C49038D-B9E6-4AD3-A657-43AD706CBF04}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
    "{0CBC3BC8-8A15-4D18-AA1B-8717DBDD666D}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
    "{0F37EE85-2128-453D-9C95-1221601F9113}" = protocol=6 | dir=in | app=c:\program files\activision\call of duty 4 - modern warfare\iw3mp.exe |
    "{0F652132-7D25-4388-97B5-05404DA940A3}" = protocol=17 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutparadise.exe |
    "{0F8B1EF6-F9B5-4BC1-8776-665819B98470}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dead rising 2\deadrising2.exe |
    "{0FC76C2B-F33E-4762-A990-C1C6EF4CA6EC}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\street fighter iv\sf4launcher.exe |
    "{10A96A7D-7BAC-4EA2-A621-C48535C6F7D3}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\lost planet 2\launcher.exe |
    "{10B6FD05-18B5-46F1-BF51-EAA9FCEB9711}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddtime.exe |
    "{11A22D60-30BB-4215-9A10-83468BD23CF1}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\kane & lynch 2 - dog days\kl2.exe |
    "{124C2B14-C1D3-4F11-A6EB-0CE39138F832}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
    "{12E36C7C-EFB3-42AD-830C-1C59B72B70FB}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
    "{13041940-296D-4FD2-B5CA-C65161573C83}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\stranger's wrath\launcher.exe |
    "{13145265-EB83-4F42-9AE2-9E0CACA979AD}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\darksiders\darksiderspc.exe |
    "{143CAC2C-FCE2-4C8E-A76D-0929665EE1A5}" = protocol=6 | dir=in | app=c:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe |
    "{1472AF1D-16C5-4F45-9E80-5D344ED3C654}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\brothers in arms hells highway\binaries\biahh.exe |
    "{14D25EB3-C4A4-4DAD-9E57-69D586BB1CFF}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
    "{151004D6-9CBA-4FDF-974E-5996C57D286E}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\just cause 2\justcause2.exe |
    "{15ACBD81-3056-4E4E-8730-124C58C36324}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of juarez\chromed.exe |
    "{15CCADE5-C333-46AC-BDA9-932850EB5881}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mafia ii\pc\mafia2.exe |
    "{15DE9095-A362-4258-A368-24D25091734C}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
    "{16911EA1-E82C-4503-AF3D-67B1CB5FCA4C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe |
    "{178E97B8-8DFF-45F4-8B72-BBC03B1E661C}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\support\ea help\electronic_arts_technical_support.htm |
    "{181C7C26-F338-46AE-8F36-7A68BAC00012}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
    "{182CC714-3218-49F4-9259-504BFA1610FC}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\borderlands\binaries\borderlands.exe |
    "{195B3CD4-3475-4E24-89EC-C45C496FE489}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
    "{1A1634F8-419A-4086-B816-334698054684}" = protocol=17 | dir=in | app=c:\program files\ea games\mirror's edge\binaries\mirrorsedge.exe |
    "{1A24F262-04C1-4BA6-9946-E75356C9317E}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\nba 2k10\nba2k10.exe |
    "{1B21E070-10D1-4682-B2C2-B482102EB077}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\fc2editor.exe |
    "{1BAE1A42-9860-455C-B9D0-9F004EC2121E}" = protocol=6 | dir=in | app=c:\program files\thq\company of heroes\reliccoh.exe |
    "{1C21EEDD-6D45-4302-8E7F-D3F524BBC5CA}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
    "{1C340250-1264-42ED-89BD-48891D7CB781}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
    "{1D053FE9-5930-43D1-B31E-672E25A60569}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2launcher.exe |
    "{1D4B34C4-60F1-4B05-BA95-5A0D53427B05}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dead rising 2\deadrising2.exe |
    "{1EB6B739-D904-4140-9BDB-52292758BF90}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\lara croft and the guardian of light\lcgol.exe |
    "{2080E5C6-00B2-40B7-8480-709653545E77}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\lxddmon.exe |
    "{20B6779B-5283-4636-BF54-D0C7B14C48EE}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\mass effect 2\docs\ea help\electronic_arts_technical_support.htm |
    "{214DB483-A345-4A0D-AF5B-821F6ED4A29F}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the first encounter\bin\samhd.exe |
    "{217DB2A5-A964-4D12-B314-CB0F52410768}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mafia ii\pc\mafia2.exe |
    "{220B6318-3363-4340-8E26-E696A52654D1}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\fear2\fear2.exe |
    "{221A3963-1059-4BEC-8DA8-BD2B19330E60}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe |
    "{225128F2-EDA8-454F-A2E7-CD0A97A93F7A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\master levels of doom\master.bat |
    "{22B55AD6-2BF0-42CD-A97C-FE10F16FB52D}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe |
    "{2413E968-37EE-4D7F-8164-B37EE30F6E6F}" = protocol=17 | dir=in | app=c:\program files\mass effect\masseffectlauncher.exe |
    "{242E3B4F-37DC-426D-A510-2D3FC73659AE}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
    "{262EE673-E0AC-462B-A1E5-4CE8E7850194}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
    "{27236550-D04D-44A3-8D02-50191B4F512D}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe |
    "{27874F3A-3464-43D1-A727-D069A76CE810}" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
    "{27922E03-7A40-418C-A4B1-826A645A8D3C}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\zombie driver\release\zombiedriver.exe |
    "{28A72F28-0644-4A1E-806F-A351B59759AE}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
    "{28D28CB6-89DF-4644-85A7-2AC495FECDC8}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
    "{2992E1A9-86D6-42BF-A178-FCCD354205F5}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse.exe |
    "{29C7BB64-A636-4F9C-AC71-D22DA41F894A}" = protocol=6 | dir=in | app=c:\program files\microsoft games\gears of war\binaries\wargame-g4wlive.exe |
    "{2BBA62B1-2D19-4D4D-9344-8943E1F30D4B}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
    "{2C14D40F-F7FB-48CF-9207-3DF4010ED828}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\fc2serverlauncher.exe |
    "{2DCBDEEA-D350-4D7B-8F87-94C77E163CDB}" = protocol=6 | dir=in | app=c:\program files\volition inc\red faction guerrilla\rfg.exe |
    "{2E6FED51-D3BF-4845-802B-98350BA01014}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\world of goo\worldofgoo.exe |
    "{31508687-39C9-4F29-A944-3F7AC38740AB}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\splinter cell - double agent\scdalauncher.exe |
    "{3364C110-70BC-4DB1-92A1-4168459CE7C8}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_launcher.exe |
    "{33C6CD20-D2CA-46AE-87C1-1CB78EDEC9D8}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty black ops\blackops.exe |
    "{343E2E50-67C2-45A9-92B0-905C50824A95}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
    "{34884A1D-B493-44D5-9BC4-B047294D25C4}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\app4r.exe |
    "{350EB60F-6011-479D-BE38-4F543B7A0371}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\support\ea help\electronic_arts_technical_support.htm |
    "{3536584F-69F4-4523-B96B-AB74F50DE3B2}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\trine\trine_launcher.exe |
    "{35C6096D-53FD-4E3F-B0E3-BE29103141BD}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\nba 2k10\nba2k10.exe |
    "{3638A793-2146-45C4-8530-0A57C6E3461F}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
    "{36C53010-F4C8-4100-9860-18A546E13668}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\srcds.exe |
    "{37F39F62-CB81-419A-B9A9-8AF9CD82B439}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx9.exe |
    "{398C4DC2-944A-4C1C-93F9-523F5FEB9555}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
    "{3BD34B2D-4661-4C35-8D46-CCBC44C09A5D}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
    "{3D717709-CF86-4A75-944B-86373470F344}" = protocol=6 | dir=in | app=c:\windows\system32\lxddcoms.exe |
    "{3E575595-08BF-4ACD-9683-AEB3A45976A1}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddjswx.exe |
    "{3EBB4CE7-31B1-4F25-9FCF-0FA727789E29}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\just cause 2\justcause2.exe |
    "{3F3092F8-F1BA-48FB-BE46-7567A0460621}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\street fighter iv\sf4launcher.exe |
    "{4010F668-C938-4B31-96C1-3F8613C79A99}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii\overlord2.exe |
    "{40949D3D-C6BB-425C-A43C-C0888528DA75}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
    "{41122A7F-775D-4909-9A22-1017E851396E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dark sector\ds.exe |
    "{41A7A8FF-59AC-4836-B8A1-64AE53A92DE5}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\zombie driver\release\zombiedriver.exe |
    "{41ACFB5F-2326-4269-AFE5-9DB93806466A}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\magicka\magicka.exe |
    "{4207F842-8F41-4A21-B409-16BA1154510F}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\world of goo\worldofgoo.exe |
    "{424B41E9-432A-4FD6-9EA7-EF715B195BD0}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx9.exe |
    "{427FD28E-EB07-4C9D-9811-E9636E75FC4F}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\deus ex\system\deusex.exe |
    "{4324FCC6-774B-489F-BED7-FA4FF6FC0051}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
    "{4439BDF4-60BB-4C47-8CC8-CF7266B3EFA5}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe |
    "{45068224-8717-47CB-A0C5-1AE00566AD89}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\darksiders\darksiderspc.exe |
    "{451B4609-6B3B-429A-BAD3-0DC602A1AF13}" = protocol=6 | dir=in | app=c:\program files\rockstar games\eflc\launcheflc.exe |
    "{4555AB55-9E76-4908-9B63-C0885D5001A5}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\support\ea help\electronic_arts_technical_support.htm |
    "{45D8E8F7-236B-4772-BF5F-D0DCDFD497EC}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
    "{4632C30B-5617-4DA1-B706-C11668CE0439}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
    "{4661A307-6162-4AB6-A86C-626CCB441F01}" = protocol=17 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutlauncher.exe |
    "{489ADA24-FFBC-43DD-95D9-8449CCC12106}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\stranger's wrath\launcher.exe |
    "{48CFE89F-609C-44D6-AA41-D870E5BB0D83}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\fc2benchmarktool.exe |
    "{49645A37-259D-40DD-A734-D294B841265B}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\puzzle quest\puzzle quest.exe |
    "{4AE9E47F-4344-4D89-9692-1DAD383532E0}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\stalker call of pripyat\stalker-cop.exe |
    "{4B74E938-66FF-4429-A05E-4B5FF885EE8C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\lost planet extreme condition\lostplanetdx9.exe |
    "{4C744EDD-2AA4-4854-8D99-B8BEA4B8409F}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
    "{4D3C931B-191D-4824-ACFF-2D1804F2916C}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii\overlord2.exe |
    "{4D3FE883-CD08-4091-9D52-A9E8B7BA5FB2}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\kane & lynch 2 - dog days\kl2.exe |
    "{4DF26338-4CAA-420E-9D8B-12097DE5C0A0}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\coj.exe |
    "{4E125AB4-6470-4533-ADF7-853EADCF4AE2}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\support\ea help\electronic_arts_technical_support.htm |
    "{4E42D5F3-602A-409C-BC69-3AEF0E791B9A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\overlord\overlord.exe |
    "{4E617162-C93C-44AD-88AC-FA550094FDE7}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dead rising 2\deadrising2.exe |
    "{4EC94F39-F853-454D-9900-4DB8D312134E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty black ops\blackopsmp.exe |
    "{4ECB50C8-AB4F-44C7-BEC8-8B35B350C8AF}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
    "{4F335B39-ECDC-4E38-AF81-A0AFFA475AF6}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\lost planet 2\launcher.exe |
    "{4FD22D6C-9C49-481F-B079-367DEA18050E}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddjswx.exe |
    "{50956241-FDE5-46F1-8C78-5FBBFC43ED1B}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
    "{512E74F0-7FC4-4AB3-B70E-4A8CCBC7F5E8}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
    "{540A03FC-35D7-4D18-81B9-1C920EF6C16B}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\kane & lynch 2 - dog days\kl2.exe |
    "{544DEB2D-3B98-40BF-9D9B-A76EB3780920}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
    "{544F0751-C977-48FE-914E-C8C395D8B3A7}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\cojdx10_benchmark.exe |
    "{5501D76F-2CE5-4670-AB43-2EC48358C08D}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
    "{55CE70F4-12BC-4866-A875-963F7DD10E96}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
    "{56E6D562-B6CA-4852-90B5-DBD48CCD2CB9}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |
    "{580F7797-1221-4F39-B11F-2854F499FB7D}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\deus ex\system\deusex.exe |
    "{58CBB649-444D-435A-8B09-78FB6118AF5F}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
    "{595C1129-32D0-49F1-9BCC-112A0DAE5C05}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\srcds.exe |
    "{59F62B48-DCE4-4FB2-BAA0-AE4B3472203D}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
    "{5B676469-CDEA-4EEA-B099-ADEDE2FC09ED}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\magicka\magicka.exe |
    "{5CBC580E-8DC8-4A63-B4BE-A7C82DEC4F74}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\just cause 2\justcause2.exe |
    "{5CD69F34-3D10-4E92-B554-B2665F7B0BAD}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\borderlands\binaries\borderlands.exe |
    "{5DD212EB-99D1-4844-AE78-4FA3B2922E8F}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\darksiders\darksiderspc.exe |
    "{5DF20690-0000-4399-A546-E17DA46271FF}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
    "{5E0716E5-2E24-4977-88F5-3325939848BB}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\swarm.exe |
    "{5E9866AE-4CFC-4BAB-A3BF-C1159944B366}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\farcry2.exe |
    "{5F4641A7-51C6-4AF1-8821-A54C963ED8F4}" = protocol=6 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutlauncher.exe |
    "{5F4E8088-0E5A-422E-BB8E-D1B7EB674702}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of duty black ops\blackops.exe |
    "{5FD8E8E7-054F-41AE-B118-8D40D8FAED05}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\operation flashpoint dragon rising\ofdr.exe |
    "{60057FE5-D0D6-403B-87D2-24E3530191F9}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
    "{604047A5-BBB3-43EE-A7AE-7B31D269BA2F}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_launcher.exe |
    "{632262E6-059B-4175-9806-BC680FB7330B}" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\lxddamon.exe |
    "{6338217A-2103-48D9-9CAA-C5D9E3E58542}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
    "{634AC63A-4CEF-4915-8996-A3102888419B}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\srcds.exe |
    "{639B23DA-E017-4D08-8DB6-6D75674CC4CE}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |
    "{64F61CC4-DAB9-4AF0-9484-BB6224A52809}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\nba 2k10\nba2k10.exe |
    "{65A53AB1-5977-443D-AEBB-BCFCAAA3A210}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\operation flashpoint dragon rising\mission editor\missioneditor.exe |
    "{65D7DF6D-2FC9-49DA-811E-EBADFDD8F0E2}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\audiosurf\engine\questviewer.exe |
    "{6636C51B-C8AD-4C62-9832-7639579F5265}" = protocol=17 | dir=in | app=c:\program files\rockstar games\eflc\launcheflc.exe |
    "{66B29653-1D38-4649-B91A-3B69BAF102D8}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe |
    "{66B57346-B101-4BDD-929D-54449095AA78}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\operation flashpoint dragon rising\ofdr.exe |
    "{6799F92A-CF07-4944-8693-B759BE2381E1}" = protocol=6 | dir=in | app=c:\program files\activision\prototype\prototypef.exe |
    "{67A2F08B-85A8-4470-BBFE-940B7D4E114A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
    "{67CBFC10-FB26-4A99-8921-FB7A182EB751}" = protocol=17 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\launchgtaiv.exe |
    "{6900AE99-3F59-4A5A-85D8-08830A57FE1F}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
    "{6943D60A-21C0-44E6-9C9D-1FED5E2CA7B5}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\call of duty black ops\blackopsmp.exe |
    "{6A382599-2138-4977-858C-52486637B120}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii - demo\overlord2demo.exe |
    "{6A44D30C-F60F-4A28-AA45-947928FE5307}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
    "{6A59F21B-0819-4015-907B-16745ACA7C90}" = protocol=17 | dir=in | app=c:\program files\thq\company of heroes\reliccoh.exe |
    "{6A904618-459A-45DA-94AC-79DDD36FA649}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
    "{6B63C470-AC41-4F43-ABE1-6E02AA7F0051}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\magicka\magicka.exe |
    "{6BDAAFF7-8105-43A5-8B25-3442C7ED4B93}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\deus ex\system\deusex.exe |
    "{6C4972C7-7F59-4468-A87D-9801AEF71B20}" = protocol=17 | dir=in | app=d:\bad comapny2\bfbc2betaupdater.exe |
    "{6C8E9008-EB56-4910-BD3B-A376B3ACCE2A}" = protocol=6 | dir=in | app=c:\program files\codemasters\grid\grid.exe |
    "{6CA3CCE0-6895-4A6F-9DB0-E3C4DE42A3A8}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii\config.exe |
    "{6DCD6C71-71C3-4F3D-926F-6BB48AE08CEA}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2launcher.exe |
    "{6F24C27C-2A0C-4630-B549-FF0EE9FAE010}" = protocol=6 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
    "{6F37C987-144A-4F4E-ADB7-D24E8E0031C2}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
    "{707B965E-9E87-4A00-AA40-E813D606E588}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe |
    "{70C7FC4A-3030-459D-A36D-18A15D6C3D60}" = protocol=6 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutconfigtool.exe |
    "{70D42897-3D79-43AE-A372-0ED9BCE52DEB}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the first encounter\bin\samhd.exe |
    "{70F15F90-FBDD-447C-806B-0F632A1D45EB}" = protocol=17 | dir=in | app=c:\windows\system32\lxddcoms.exe |
    "{718C0DEB-5A4E-45AB-AF5B-CB18C3E7BB0E}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
    "{719918F6-85F4-43BE-8964-F3512FAD2946}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\lara croft and the guardian of light\lcgol.exe |
    "{7307F0DE-142F-4600-9610-9E4973E1E75C}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddtime.exe |
    "{7390064C-DD69-4F3F-B389-87E7AFA312FE}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe |
    "{73FADEEC-5AB5-4C74-8133-6C937DD19C2F}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
    "{750791CF-9FFB-4F9E-942A-0E861C6A69E2}" = protocol=6 | dir=in | app=c:\program files\eidos\batman arkham asylum\binaries\shippingpc-bmgame.exe |
    "{75494D7A-76B4-4F72-9EC6-B12D0E7FDA7E}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\lxddamon.exe |
    "{75BA40A6-A1B2-4791-893D-6E5B8190F127}" = protocol=17 | dir=in | app=c:\program files\activision\call of duty 4 - modern warfare\iw3mp.exe |
    "{76316E8A-248A-4D55-816F-9CCCE20B4B0A}" = protocol=6 | dir=in | app=d:\bad comapny2\bfbc2betaupdater.exe |
    "{76995064-7A1B-486B-B6FE-60A39084317A}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dead space\dead space.exe |
    "{7738F963-5D9B-41C4-B941-9619787C9249}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse.exe |
    "{77521A7D-FFD0-48D9-94EC-4ACAB3CD6523}" = protocol=17 | dir=in | app=c:\program files\activision\prototype\prototypef.exe |
    "{777D850A-46C4-468B-B9BA-5767619A8A81}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\zombie driver\release\zombiedriver.exe |
    "{77805F0C-70F9-4FF4-8689-5D1EED1E68E4}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
    "{77B12C76-00D2-448F-B093-5F3C38CB2E69}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
    "{7881819C-5F49-471F-989E-87A13F6759CD}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\karol754\counter-strike source\hl2.exe |
    "{7A295A25-607B-46FE-BCF6-C4227A5A7841}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\just cause 2\justcause2.exe |
    "{7AABD464-8BA4-4620-A20A-1A21B5D60336}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dirt 2\dirt2.exe |
    "{7AB0A3B1-D72F-4794-9FA4-5368BABB9320}" = protocol=6 | dir=in | app=c:\program files\mass effect\binaries\masseffect.exe |
    "{7AC779A1-3E62-4CC4-835F-2C8FB9BB1E7A}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
    "{7B0D4BB2-CADC-4792-B6DB-8D6CD618255E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\swarm.exe |
    "{7B568CA3-1644-4FFC-A00C-94C777EA7490}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\operation flashpoint dragon rising\mission editor\missioneditor.exe |
    "{7C3DFE81-34B5-4A73-97C1-01B848CC0794}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\mafia ii\pc\mafia2.exe |
    "{7CA06C45-0C45-4392-99B3-341DA3F03D82}" = protocol=6 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
    "{7DE626F6-DA19-4842-A16D-9649ABC49F07}" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
    "{7E3A66A1-36BE-4FC9-8ECF-0C587002E0DA}" = protocol=6 | dir=in | app=c:\program files\sierra entertainment\world in conflict\wic.exe |
    "{7E530CF5-7E82-45EF-BB39-2E05F24B25FB}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord\overlord.exe |
    "{7EAB93AC-1FA1-4248-A879-C77FFDF358FA}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\brothers in arms hells highway\binaries\biahh.exe |
    "{7EADF3FC-5093-4BC1-8F85-DEA8FDE4F544}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\chromed.exe |
    "{7FAA06AB-673A-4EB6-9FB8-9BF2E523F857}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the first encounter\bin\samhd.exe |
    "{7FB325D8-F9BD-4138-894B-E40FFA7187A7}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\overlord\config.exe |
    "{8023FC32-982D-4545-8A4A-3A95530A5B56}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\mass effect 2\masseffect2launcher.exe |
    "{80DC56E7-CE82-4E14-A51F-0AFE7F9C0DC8}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
    "{81FA11F8-42C0-431C-ACB5-D54C3153AB11}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe |
    "{836DDE86-1B68-409A-9758-28779143748F}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\karol754\counter-strike source\hl2.exe |
    "{851322B0-1F06-4A1F-B0BD-A4F8C22B9B34}" = protocol=6 | dir=in | app=c:\program files\mass effect\masseffectlauncher.exe |
    "{85CA29B0-2DE6-4EB1-A36F-277D06655F9A}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
    "{86C9C2CF-936E-400D-8927-D53538CACE19}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\fc2editor.exe |
     
  10. karol3

    karol3 TS Rookie Topic Starter Posts: 34

    Extras log is such a pain. Can i message you it? uploading is not possible over 200k. I cant upload that virus because its in the quarantine area, should I restore the virus and then upload it from the original folder?

    Edit: i attached it, i ziped it.
     

    Attached Files:

  11. Broni

    Broni Malware Annihilator Posts: 52,911   +344

    You're doing fine by splitting it.
    Go on....
     
  12. karol3

    karol3 TS Rookie Topic Starter Posts: 34

    sorry, should I post it here to, will you use the attachment?
     
  13. Broni

    Broni Malware Annihilator Posts: 52,911   +344

    We don't accept attachments.
    All logs have to be pasted.
     
  14. karol3

    karol3 TS Rookie Topic Starter Posts: 34

    ok sorry from the beginning:

    Extras:

    OTL Extras logfile created on: 2/28/2011 9:51:20 PM - Run 1
    OTL by OldTimer - Version 3.2.22.2 Folder = C:\Users\User\Desktop
    Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.6001.19019)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 65.00% Memory free
    7.00 Gb Paging File | 6.00 Gb Available in Paging File | 82.00% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 698.63 Gb Total Space | 486.40 Gb Free Space | 69.62% Space Free | Partition Type: NTFS
    Drive D: | 111.79 Gb Total Space | 17.13 Gb Free Space | 15.32% Space Free | Partition Type: NTFS
    Drive F: | 1863.01 Gb Total Space | 1556.11 Gb Free Space | 83.53% Space Free | Partition Type: NTFS

    Computer Name: USER-PC | User Name: User | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
    .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

    [HKEY_USERS\S-1-5-21-2158934232-3957428742-2026527031-1000\SOFTWARE\Classes\<extension>]
    .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
    https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "D:\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [PlayWithVLC] -- "D:\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0
    "VistaSp1" = Reg Error: Unknown registry data type -- File not found
    "VistaSp2" = Reg Error: Unknown registry data type -- File not found

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-2158934232-3957428742-2026527031-1000]
    "EnableNotifications" = 0
    "EnableNotificationsRef" = 1

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "DisableNotifications" = 1
    "EnableFirewall" = 1
    "DoNotAllowExceptions" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{2B02ADD1-3182-496F-85A9-6B19CB1DECAC}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
    "{540EBAD4-3204-4F0F-AFFE-1CD9EBCE1291}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
    "{E282B796-485C-4987-9AD9-6E83D24F4EB4}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{003AC244-DCC0-4E51-AD91-A9B30423D3CD}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\fear2\fear2.exe |
    "{003C9592-CB13-46FD-AF04-346C0CF1FEBA}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\lxddmon.exe |
    "{004B4D73-ED51-4334-9BD7-0F205AC1508C}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\puzzle quest\puzzle quest.exe |
    "{0157CD7C-E77B-4DD0-91ED-8CE2764A4267}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez - bound in blood\cojbibgame_x86.exe |
    "{01F267EF-558C-4B28-AC89-5F023430B012}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe |
    "{04364725-0C75-46C7-83E0-A9DBCFF50168}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\swarm.exe |
    "{05C19064-36B9-416A-A664-864AB3CD83B1}" = protocol=17 | dir=in | app=c:\program files\eidos\batman arkham asylum\binaries\shippingpc-bmgame.exe |
    "{05D59025-EF5C-482E-9825-FB4A95E3A68F}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
    "{07AB361D-77DB-4172-92B5-5FFC1E435299}" = protocol=6 | dir=in | app=c:\program files\sierra entertainment\world in conflict\wic_ds.exe |
    "{0856D5B7-70D9-4F2F-ADFB-19085DA9C512}" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysis.exe |
    "{088032EF-278F-4DBA-86D6-17F460D7ABFC}" = protocol=17 | dir=in | app=c:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\dedicated\xrengine.exe |
    "{097E1D1D-ABEB-4681-A60E-619DF3D98057}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\killingfloor\system\killingfloor.exe |
    "{09B6B20C-A012-43CA-AE84-045120D72BB1}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\metro 2033\metro2033.exe |
    "{09C3866B-8BBF-4644-BCBD-97C286249F24}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\world of goo\worldofgoo.exe |
    "{09C86618-750A-44B4-B154-437444831850}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\nba 2k10\nba2k10.exe |
    "{0B3D06AA-8BC1-4694-90E9-0EE9ABE97B4A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord\config.exe |
    "{0C0C6772-5DE8-43A6-AD9E-01CBD066AE4C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
    "{0C49038D-B9E6-4AD3-A657-43AD706CBF04}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
    "{0CBC3BC8-8A15-4D18-AA1B-8717DBDD666D}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
    "{0F37EE85-2128-453D-9C95-1221601F9113}" = protocol=6 | dir=in | app=c:\program files\activision\call of duty 4 - modern warfare\iw3mp.exe |
    "{0F652132-7D25-4388-97B5-05404DA940A3}" = protocol=17 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutparadise.exe |
    "{0F8B1EF6-F9B5-4BC1-8776-665819B98470}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dead rising 2\deadrising2.exe |
    "{0FC76C2B-F33E-4762-A990-C1C6EF4CA6EC}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\street fighter iv\sf4launcher.exe |
    "{10A96A7D-7BAC-4EA2-A621-C48535C6F7D3}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\lost planet 2\launcher.exe |
    "{10B6FD05-18B5-46F1-BF51-EAA9FCEB9711}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddtime.exe |
    "{11A22D60-30BB-4215-9A10-83468BD23CF1}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\kane & lynch 2 - dog days\kl2.exe |
    "{124C2B14-C1D3-4F11-A6EB-0CE39138F832}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
    "{12E36C7C-EFB3-42AD-830C-1C59B72B70FB}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
    "{13041940-296D-4FD2-B5CA-C65161573C83}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\stranger's wrath\launcher.exe |
    "{13145265-EB83-4F42-9AE2-9E0CACA979AD}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\darksiders\darksiderspc.exe |
    "{143CAC2C-FCE2-4C8E-A76D-0929665EE1A5}" = protocol=6 | dir=in | app=c:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe |
    "{1472AF1D-16C5-4F45-9E80-5D344ED3C654}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\brothers in arms hells highway\binaries\biahh.exe |
    "{14D25EB3-C4A4-4DAD-9E57-69D586BB1CFF}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
    "{151004D6-9CBA-4FDF-974E-5996C57D286E}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\just cause 2\justcause2.exe |
    "{15ACBD81-3056-4E4E-8730-124C58C36324}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of juarez\chromed.exe |
    "{15CCADE5-C333-46AC-BDA9-932850EB5881}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mafia ii\pc\mafia2.exe |
    "{15DE9095-A362-4258-A368-24D25091734C}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
    "{16911EA1-E82C-4503-AF3D-67B1CB5FCA4C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe |
    "{178E97B8-8DFF-45F4-8B72-BBC03B1E661C}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\support\ea help\electronic_arts_technical_support.htm |
    "{181C7C26-F338-46AE-8F36-7A68BAC00012}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
    "{182CC714-3218-49F4-9259-504BFA1610FC}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\borderlands\binaries\borderlands.exe |
    "{195B3CD4-3475-4E24-89EC-C45C496FE489}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
    "{1A1634F8-419A-4086-B816-334698054684}" = protocol=17 | dir=in | app=c:\program files\ea games\mirror's edge\binaries\mirrorsedge.exe |
    "{1A24F262-04C1-4BA6-9946-E75356C9317E}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\nba 2k10\nba2k10.exe |
    "{1B21E070-10D1-4682-B2C2-B482102EB077}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\fc2editor.exe |
    "{1BAE1A42-9860-455C-B9D0-9F004EC2121E}" = protocol=6 | dir=in | app=c:\program files\thq\company of heroes\reliccoh.exe |
    "{1C21EEDD-6D45-4302-8E7F-D3F524BBC5CA}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
    "{1C340250-1264-42ED-89BD-48891D7CB781}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
    "{1D053FE9-5930-43D1-B31E-672E25A60569}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2launcher.exe |
    "{1D4B34C4-60F1-4B05-BA95-5A0D53427B05}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dead rising 2\deadrising2.exe |
    "{1EB6B739-D904-4140-9BDB-52292758BF90}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\lara croft and the guardian of light\lcgol.exe |
    "{2080E5C6-00B2-40B7-8480-709653545E77}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\lxddmon.exe |
    "{20B6779B-5283-4636-BF54-D0C7B14C48EE}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\mass effect 2\docs\ea help\electronic_arts_technical_support.htm |
    "{214DB483-A345-4A0D-AF5B-821F6ED4A29F}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the first encounter\bin\samhd.exe |
    "{217DB2A5-A964-4D12-B314-CB0F52410768}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mafia ii\pc\mafia2.exe |
    "{220B6318-3363-4340-8E26-E696A52654D1}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\fear2\fear2.exe |
    "{221A3963-1059-4BEC-8DA8-BD2B19330E60}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe |
    "{225128F2-EDA8-454F-A2E7-CD0A97A93F7A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\master levels of doom\master.bat |
    "{22B55AD6-2BF0-42CD-A97C-FE10F16FB52D}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe |
    "{2413E968-37EE-4D7F-8164-B37EE30F6E6F}" = protocol=17 | dir=in | app=c:\program files\mass effect\masseffectlauncher.exe |
    "{242E3B4F-37DC-426D-A510-2D3FC73659AE}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
    "{262EE673-E0AC-462B-A1E5-4CE8E7850194}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
    "{27236550-D04D-44A3-8D02-50191B4F512D}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe |
    "{27874F3A-3464-43D1-A727-D069A76CE810}" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
    "{27922E03-7A40-418C-A4B1-826A645A8D3C}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\zombie driver\release\zombiedriver.exe |
    "{28A72F28-0644-4A1E-806F-A351B59759AE}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
    "{28D28CB6-89DF-4644-85A7-2AC495FECDC8}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
    "{2992E1A9-86D6-42BF-A178-FCCD354205F5}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse.exe |
    "{29C7BB64-A636-4F9C-AC71-D22DA41F894A}" = protocol=6 | dir=in | app=c:\program files\microsoft games\gears of war\binaries\wargame-g4wlive.exe |
    "{2BBA62B1-2D19-4D4D-9344-8943E1F30D4B}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
    "{2C14D40F-F7FB-48CF-9207-3DF4010ED828}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\fc2serverlauncher.exe |
    "{2DCBDEEA-D350-4D7B-8F87-94C77E163CDB}" = protocol=6 | dir=in | app=c:\program files\volition inc\red faction guerrilla\rfg.exe |
    "{2E6FED51-D3BF-4845-802B-98350BA01014}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\world of goo\worldofgoo.exe |
    "{31508687-39C9-4F29-A944-3F7AC38740AB}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\splinter cell - double agent\scdalauncher.exe |
    "{3364C110-70BC-4DB1-92A1-4168459CE7C8}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_launcher.exe |
    "{33C6CD20-D2CA-46AE-87C1-1CB78EDEC9D8}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty black ops\blackops.exe |
    "{343E2E50-67C2-45A9-92B0-905C50824A95}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
    "{34884A1D-B493-44D5-9BC4-B047294D25C4}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\app4r.exe |
    "{350EB60F-6011-479D-BE38-4F543B7A0371}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\support\ea help\electronic_arts_technical_support.htm |
    "{3536584F-69F4-4523-B96B-AB74F50DE3B2}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\trine\trine_launcher.exe |
    "{35C6096D-53FD-4E3F-B0E3-BE29103141BD}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\nba 2k10\nba2k10.exe |
    "{3638A793-2146-45C4-8530-0A57C6E3461F}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
    "{36C53010-F4C8-4100-9860-18A546E13668}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\srcds.exe |
    "{37F39F62-CB81-419A-B9A9-8AF9CD82B439}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx9.exe |
    "{398C4DC2-944A-4C1C-93F9-523F5FEB9555}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
    "{3BD34B2D-4661-4C35-8D46-CCBC44C09A5D}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
    "{3D717709-CF86-4A75-944B-86373470F344}" = protocol=6 | dir=in | app=c:\windows\system32\lxddcoms.exe |
    "{3E575595-08BF-4ACD-9683-AEB3A45976A1}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddjswx.exe |
    "{3EBB4CE7-31B1-4F25-9FCF-0FA727789E29}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\just cause 2\justcause2.exe |
    "{3F3092F8-F1BA-48FB-BE46-7567A0460621}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\street fighter iv\sf4launcher.exe |
    "{4010F668-C938-4B31-96C1-3F8613C79A99}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii\overlord2.exe |
    "{40949D3D-C6BB-425C-A43C-C0888528DA75}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
    "{41122A7F-775D-4909-9A22-1017E851396E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dark sector\ds.exe |
    "{41A7A8FF-59AC-4836-B8A1-64AE53A92DE5}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\zombie driver\release\zombiedriver.exe |
    "{41ACFB5F-2326-4269-AFE5-9DB93806466A}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\magicka\magicka.exe |
    "{4207F842-8F41-4A21-B409-16BA1154510F}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\world of goo\worldofgoo.exe |
    "{424B41E9-432A-4FD6-9EA7-EF715B195BD0}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx9.exe |
    "{427FD28E-EB07-4C9D-9811-E9636E75FC4F}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\deus ex\system\deusex.exe |
    "{4324FCC6-774B-489F-BED7-FA4FF6FC0051}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
    "{4439BDF4-60BB-4C47-8CC8-CF7266B3EFA5}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe |
    "{45068224-8717-47CB-A0C5-1AE00566AD89}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\darksiders\darksiderspc.exe |
    "{451B4609-6B3B-429A-BAD3-0DC602A1AF13}" = protocol=6 | dir=in | app=c:\program files\rockstar games\eflc\launcheflc.exe |
    "{4555AB55-9E76-4908-9B63-C0885D5001A5}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\support\ea help\electronic_arts_technical_support.htm |
    "{45D8E8F7-236B-4772-BF5F-D0DCDFD497EC}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
    "{4632C30B-5617-4DA1-B706-C11668CE0439}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
    "{4661A307-6162-4AB6-A86C-626CCB441F01}" = protocol=17 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutlauncher.exe |
    "{489ADA24-FFBC-43DD-95D9-8449CCC12106}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\stranger's wrath\launcher.exe |
    "{48CFE89F-609C-44D6-AA41-D870E5BB0D83}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\fc2benchmarktool.exe |
    "{49645A37-259D-40DD-A734-D294B841265B}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\puzzle quest\puzzle quest.exe |
    "{4AE9E47F-4344-4D89-9692-1DAD383532E0}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\stalker call of pripyat\stalker-cop.exe |
    "{4B74E938-66FF-4429-A05E-4B5FF885EE8C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\lost planet extreme condition\lostplanetdx9.exe |
    "{4C744EDD-2AA4-4854-8D99-B8BEA4B8409F}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
    "{4D3C931B-191D-4824-ACFF-2D1804F2916C}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii\overlord2.exe |
    "{4D3FE883-CD08-4091-9D52-A9E8B7BA5FB2}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\kane & lynch 2 - dog days\kl2.exe |
    "{4DF26338-4CAA-420E-9D8B-12097DE5C0A0}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\coj.exe |
    "{4E125AB4-6470-4533-ADF7-853EADCF4AE2}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\support\ea help\electronic_arts_technical_support.htm |
    "{4E42D5F3-602A-409C-BC69-3AEF0E791B9A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\overlord\overlord.exe |
    "{4E617162-C93C-44AD-88AC-FA550094FDE7}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dead rising 2\deadrising2.exe |
    "{4EC94F39-F853-454D-9900-4DB8D312134E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty black ops\blackopsmp.exe |
    "{4ECB50C8-AB4F-44C7-BEC8-8B35B350C8AF}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
    "{4F335B39-ECDC-4E38-AF81-A0AFFA475AF6}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\lost planet 2\launcher.exe |
    "{4FD22D6C-9C49-481F-B079-367DEA18050E}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddjswx.exe |
    "{50956241-FDE5-46F1-8C78-5FBBFC43ED1B}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
    "{512E74F0-7FC4-4AB3-B70E-4A8CCBC7F5E8}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
    "{540A03FC-35D7-4D18-81B9-1C920EF6C16B}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\kane & lynch 2 - dog days\kl2.exe |
    "{544DEB2D-3B98-40BF-9D9B-A76EB3780920}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
    "{544F0751-C977-48FE-914E-C8C395D8B3A7}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\cojdx10_benchmark.exe |
    "{5501D76F-2CE5-4670-AB43-2EC48358C08D}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
    "{55CE70F4-12BC-4866-A875-963F7DD10E96}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
    "{56E6D562-B6CA-4852-90B5-DBD48CCD2CB9}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |
    "{580F7797-1221-4F39-B11F-2854F499FB7D}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\deus ex\system\deusex.exe |
    "{58CBB649-444D-435A-8B09-78FB6118AF5F}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
    "{595C1129-32D0-49F1-9BCC-112A0DAE5C05}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\srcds.exe |
    "{59F62B48-DCE4-4FB2-BAA0-AE4B3472203D}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
    "{5B676469-CDEA-4EEA-B099-ADEDE2FC09ED}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\magicka\magicka.exe |
    "{5CBC580E-8DC8-4A63-B4BE-A7C82DEC4F74}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\just cause 2\justcause2.exe |
    "{5CD69F34-3D10-4E92-B554-B2665F7B0BAD}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\borderlands\binaries\borderlands.exe |
    "{5DD212EB-99D1-4844-AE78-4FA3B2922E8F}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\darksiders\darksiderspc.exe |
    "{5DF20690-0000-4399-A546-E17DA46271FF}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
    "{5E0716E5-2E24-4977-88F5-3325939848BB}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\swarm.exe |
    "{5E9866AE-4CFC-4BAB-A3BF-C1159944B366}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\farcry2.exe |
    "{5F4641A7-51C6-4AF1-8821-A54C963ED8F4}" = protocol=6 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutlauncher.exe |
    "{5F4E8088-0E5A-422E-BB8E-D1B7EB674702}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of duty black ops\blackops.exe |
    "{5FD8E8E7-054F-41AE-B118-8D40D8FAED05}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\operation flashpoint dragon rising\ofdr.exe |
    "{60057FE5-D0D6-403B-87D2-24E3530191F9}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
    "{604047A5-BBB3-43EE-A7AE-7B31D269BA2F}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_launcher.exe |
    "{632262E6-059B-4175-9806-BC680FB7330B}" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\lxddamon.exe |
    "{6338217A-2103-48D9-9CAA-C5D9E3E58542}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
    "{634AC63A-4CEF-4915-8996-A3102888419B}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\srcds.exe |
    "{639B23DA-E017-4D08-8DB6-6D75674CC4CE}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |
    "{64F61CC4-DAB9-4AF0-9484-BB6224A52809}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\nba 2k10\nba2k10.exe |
    "{65A53AB1-5977-443D-AEBB-BCFCAAA3A210}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\operation flashpoint dragon rising\mission editor\missioneditor.exe |
    "{65D7DF6D-2FC9-49DA-811E-EBADFDD8F0E2}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\audiosurf\engine\questviewer.exe |
    "{6636C51B-C8AD-4C62-9832-7639579F5265}" = protocol=17 | dir=in | app=c:\program files\rockstar games\eflc\launcheflc.exe |
    "{66B29653-1D38-4649-B91A-3B69BAF102D8}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe |
    "{66B57346-B101-4BDD-929D-54449095AA78}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\operation flashpoint dragon rising\ofdr.exe |
    "{6799F92A-CF07-4944-8693-B759BE2381E1}" = protocol=6 | dir=in | app=c:\program files\activision\prototype\prototypef.exe |
    "{67A2F08B-85A8-4470-BBFE-940B7D4E114A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
    "{67CBFC10-FB26-4A99-8921-FB7A182EB751}" = protocol=17 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\launchgtaiv.exe |
    "{6900AE99-3F59-4A5A-85D8-08830A57FE1F}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
    "{6943D60A-21C0-44E6-9C9D-1FED5E2CA7B5}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\call of duty black ops\blackopsmp.exe |
    "{6A382599-2138-4977-858C-52486637B120}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii - demo\overlord2demo.exe |
    "{6A44D30C-F60F-4A28-AA45-947928FE5307}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
    "{6A59F21B-0819-4015-907B-16745ACA7C90}" = protocol=17 | dir=in | app=c:\program files\thq\company of heroes\reliccoh.exe |
    "{6A904618-459A-45DA-94AC-79DDD36FA649}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
    "{6B63C470-AC41-4F43-ABE1-6E02AA7F0051}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\magicka\magicka.exe |
    "{6BDAAFF7-8105-43A5-8B25-3442C7ED4B93}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\deus ex\system\deusex.exe |
    "{6C4972C7-7F59-4468-A87D-9801AEF71B20}" = protocol=17 | dir=in | app=d:\bad comapny2\bfbc2betaupdater.exe |
    "{6C8E9008-EB56-4910-BD3B-A376B3ACCE2A}" = protocol=6 | dir=in | app=c:\program files\codemasters\grid\grid.exe |
    "{6CA3CCE0-6895-4A6F-9DB0-E3C4DE42A3A8}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii\config.exe |
    "{6DCD6C71-71C3-4F3D-926F-6BB48AE08CEA}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2launcher.exe |
    "{6F24C27C-2A0C-4630-B549-FF0EE9FAE010}" = protocol=6 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
    "{6F37C987-144A-4F4E-ADB7-D24E8E0031C2}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
    "{707B965E-9E87-4A00-AA40-E813D606E588}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe |
    "{70C7FC4A-3030-459D-A36D-18A15D6C3D60}" = protocol=6 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutconfigtool.exe |
    "{70D42897-3D79-43AE-A372-0ED9BCE52DEB}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the first encounter\bin\samhd.exe |
    "{70F15F90-FBDD-447C-806B-0F632A1D45EB}" = protocol=17 | dir=in | app=c:\windows\system32\lxddcoms.exe |
    "{718C0DEB-5A4E-45AB-AF5B-CB18C3E7BB0E}" = protocol=17 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
    "{719918F6-85F4-43BE-8964-F3512FAD2946}" = protocol=17 | dir=in |
     
  15. karol3

    karol3 TS Rookie Topic Starter Posts: 34

    app=c:\program files\steam\steamapps\common\lara croft and the guardian of light\lcgol.exe |
    "{7307F0DE-142F-4600-9610-9E4973E1E75C}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddtime.exe |
    "{7390064C-DD69-4F3F-B389-87E7AFA312FE}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe |
    "{73FADEEC-5AB5-4C74-8133-6C937DD19C2F}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
    "{750791CF-9FFB-4F9E-942A-0E861C6A69E2}" = protocol=6 | dir=in | app=c:\program files\eidos\batman arkham asylum\binaries\shippingpc-bmgame.exe |
    "{75494D7A-76B4-4F72-9EC6-B12D0E7FDA7E}" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\lxddamon.exe |
    "{75BA40A6-A1B2-4791-893D-6E5B8190F127}" = protocol=17 | dir=in | app=c:\program files\activision\call of duty 4 - modern warfare\iw3mp.exe |
    "{76316E8A-248A-4D55-816F-9CCCE20B4B0A}" = protocol=6 | dir=in | app=d:\bad comapny2\bfbc2betaupdater.exe |
    "{76995064-7A1B-486B-B6FE-60A39084317A}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\dead space\dead space.exe |
    "{7738F963-5D9B-41C4-B941-9619787C9249}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse.exe |
    "{77521A7D-FFD0-48D9-94EC-4ACAB3CD6523}" = protocol=17 | dir=in | app=c:\program files\activision\prototype\prototypef.exe |
    "{777D850A-46C4-468B-B9BA-5767619A8A81}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\zombie driver\release\zombiedriver.exe |
    "{77805F0C-70F9-4FF4-8689-5D1EED1E68E4}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
    "{77B12C76-00D2-448F-B093-5F3C38CB2E69}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
    "{7881819C-5F49-471F-989E-87A13F6759CD}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\karol754\counter-strike source\hl2.exe |
    "{7A295A25-607B-46FE-BCF6-C4227A5A7841}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\just cause 2\justcause2.exe |
    "{7AABD464-8BA4-4620-A20A-1A21B5D60336}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dirt 2\dirt2.exe |
    "{7AB0A3B1-D72F-4794-9FA4-5368BABB9320}" = protocol=6 | dir=in | app=c:\program files\mass effect\binaries\masseffect.exe |
    "{7AC779A1-3E62-4CC4-835F-2C8FB9BB1E7A}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
    "{7B0D4BB2-CADC-4792-B6DB-8D6CD618255E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\swarm.exe |
    "{7B568CA3-1644-4FFC-A00C-94C777EA7490}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\operation flashpoint dragon rising\mission editor\missioneditor.exe |
    "{7C3DFE81-34B5-4A73-97C1-01B848CC0794}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\mafia ii\pc\mafia2.exe |
    "{7CA06C45-0C45-4392-99B3-341DA3F03D82}" = protocol=6 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
    "{7DE626F6-DA19-4842-A16D-9649ABC49F07}" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
    "{7E3A66A1-36BE-4FC9-8ECF-0C587002E0DA}" = protocol=6 | dir=in | app=c:\program files\sierra entertainment\world in conflict\wic.exe |
    "{7E530CF5-7E82-45EF-BB39-2E05F24B25FB}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord\overlord.exe |
    "{7EAB93AC-1FA1-4248-A879-C77FFDF358FA}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\brothers in arms hells highway\binaries\biahh.exe |
    "{7EADF3FC-5093-4BC1-8F85-DEA8FDE4F544}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\chromed.exe |
    "{7FAA06AB-673A-4EB6-9FB8-9BF2E523F857}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the first encounter\bin\samhd.exe |
    "{7FB325D8-F9BD-4138-894B-E40FFA7187A7}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\overlord\config.exe |
    "{8023FC32-982D-4545-8A4A-3A95530A5B56}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\mass effect 2\masseffect2launcher.exe |
    "{80DC56E7-CE82-4E14-A51F-0AFE7F9C0DC8}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
    "{81FA11F8-42C0-431C-ACB5-D54C3153AB11}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\killingfloor\system\killingfloor.exe |
    "{836DDE86-1B68-409A-9758-28779143748F}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\karol754\counter-strike source\hl2.exe |
    "{851322B0-1F06-4A1F-B0BD-A4F8C22B9B34}" = protocol=6 | dir=in | app=c:\program files\mass effect\masseffectlauncher.exe |
    "{85CA29B0-2DE6-4EB1-A36F-277D06655F9A}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
    "{86C9C2CF-936E-400D-8927-D53538CACE19}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\fc2editor.exe |
    "{87634851-B96D-465E-BB3C-E4EC4D3D7E32}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
    "{87A08979-4084-4B6D-8CE2-6F6D04BA55F6}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\karol754\counter-strike source\hl2.exe |
    "{87BD9B00-B14C-4215-8E6C-C444FFB36E4A}" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\app4r.exe |
    "{88B7B053-ACDB-45C5-B54B-2A737BCE5A3E}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the first encounter\bin\samhd_demo.exe |
    "{89ECF44D-62AC-40E5-89F7-F118FA513EE8}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
    "{8A395CAB-AFA5-4F5E-BDE0-D52A440B1C54}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\fc2serverlauncher.exe |
    "{8A449558-4C19-42B9-B939-DC12463BC542}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\mass effect 2\masseffect2launcher.exe |
    "{8AB25940-0F40-4F9F-9BBB-85F904AAE114}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii - demo\config.exe |
    "{8AC98F69-5560-430C-B3E3-39E30CDABA55}" = protocol=6 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
    "{8AE615C6-52C3-4ABF-AE04-7E62FCCD588E}" = protocol=17 | dir=in | app=c:\program files\thq\company of heroes\relicdownloader\relicdownloader.exe |
    "{8AF7B693-55A2-4048-ACAB-87305A3EBD7A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\metro 2033\metro2033.exe |
    "{8BA2F3AB-F2E8-43B6-842F-FFD8AEC0835F}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddpswx.exe |
    "{8C5477C6-A461-4F96-8B6D-49A888245B97}" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysis.exe |
    "{8C604B4F-50E7-4FB9-A533-C4666A42BACA}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
    "{8DF1B2EE-A7AC-4D4F-93C5-D57ABEFAAE26}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddjswx.exe |
    "{8E357E17-922D-4130-A64A-7B85BB4A3C54}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
    "{8E4B4838-6C69-4C94-8BFB-72BF755DF2DC}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
    "{8E87516F-FB14-4F92-8E71-72599D080CD7}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
    "{90B9CD12-E253-4067-88AA-D5AB91D74707}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\rainbow six vegas 2\binaries\r6vegas2_game.exe |
    "{90DA8A76-85B5-411C-9B3C-26FC1E1C701D}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\call of juarez\chromed.exe |
    "{92EB5A7A-1B77-4555-9569-9BEFF3320358}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddtime.exe |
    "{9316DEB4-FEC6-47EF-AFA9-5223C00AF509}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe |
    "{9318B24B-2BE1-4BA8-A5AE-A6292EC0F72D}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\stalker call of pripyat\stalker-cop.exe |
    "{932D502D-8ED4-429E-9F46-C2F9636FAA99}" = protocol=6 | dir=in | app=c:\program files\ea games\mirror's edge\binaries\mirrorsedge.exe |
    "{935421A7-DA59-4F35-B542-A33ABAE4A192}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe |
    "{95609E6B-0305-40FF-BB28-C97399CFFF9D}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dark sector\ds.exe |
    "{960A5144-4921-4388-9080-35F123DF5F69}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
    "{9782628A-386B-4E5F-A11C-4F06A59B3639}" = dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
    "{979F9E13-80D2-405A-B848-38180AD5D8D9}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\darkest of days demo\darkestofdays.exe |
    "{97DAE012-48D7-4830-B996-B440BB2ED428}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\stranger's wrath\launcher.exe |
    "{98000ED0-885F-4D46-A46D-311EFB8D4AF8}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mass effect 2\masseffect2launcher.exe |
    "{990AE074-24FA-46AC-A2E8-8F86FA8364B6}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\lost planet 2\launcher.exe |
    "{9968BE73-B823-47CA-B2B1-39A5E5D7C6D9}" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
    "{997045CD-851A-4964-83E2-F2C8F74DE8D8}" = protocol=6 | dir=in | app=c:\program files\sierra entertainment\world in conflict\wic_online.exe |
    "{99FC028C-BA7F-443E-9958-15EDE5D83103}" = protocol=6 | dir=in | app=c:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\dedicated\xrengine.exe |
    "{9AB24A05-E1F9-4848-9351-B2C4615858AA}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\resident evil 5\launcher.exe |
    "{9C288D39-CC5D-483D-8344-5D75FFC32AB9}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\resident evil 5\launcher.exe |
    "{9C5FB571-5CCC-49D9-A4E6-D17BEB127623}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the first encounter\bin\samhd.exe |
    "{9C637531-9D5D-4086-9BD7-77B81E847DAE}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\stalker call of pripyat\stalker-cop.exe |
    "{9C775270-3914-43A2-BD15-AC11EE92714A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\darkest of days demo\darkestofdays.exe |
    "{9D6BD5B2-C5E2-4959-8D4B-0E4FE76DA12B}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\rainbow six vegas 2\binaries\r6vegas2_game.exe |
    "{9D8C7D30-354F-4855-A69D-2A2E4A1CFC1F}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of juarez\coj.exe |
    "{9E2DEC76-CB90-4A07-BF2F-8E0887E3AB4A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mass effect 2\masseffect2launcher.exe |
    "{9E7E940B-F71E-4B15-90E6-E1FBBA918E3F}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe |
    "{9ECBCE6E-5086-4F05-ABFF-EF78FFD5B25B}" = protocol=17 | dir=in | app=c:\program files\sierra entertainment\world in conflict\wic_ds.exe |
    "{9EEF70A8-AD99-40FC-9A43-561E7A74AE2A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse_unrestricted.exe |
    "{9F0DEE79-0188-4A2C-8304-48473DC9756D}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\alien swarm\swarm.exe |
    "{A0217962-60A7-4B39-82C0-9284CC1929C3}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe |
    "{A037B565-441A-42C1-989E-4528A85332E5}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
    "{A0535611-24AE-40D5-A7A1-B6C20C51B288}" = protocol=17 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx10.exe |
    "{A1BF24A8-C0F2-4491-B1F5-F4CE73E6DD0C}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\alien swarm\srcds.exe |
    "{A297182E-F959-4DD7-8AE0-E669D17043F6}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
    "{A3825F88-ECAB-4282-AAFA-9C517F9954B6}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\lost planet extreme condition\lostplanetdx10.exe |
    "{A395F056-B72E-470E-B1B1-28E63B9FEEEF}" = protocol=6 | dir=in | app=c:\program files\ubisoft\assassin's creed\assassinscreed_dx10.exe |
    "{A3E4E7B7-29BE-400E-8F83-8F803B1EA65B}" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
    "{A4CC5468-FEA6-47FB-BB58-34BC4326B033}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{A587EEFA-828F-4E76-87DB-AC1E1A798219}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse.exe |
    "{A631634C-01D8-4987-B977-D323E9145BD9}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2launcher.exe |
    "{A64C7318-7C56-43C3-B90E-24C787B8A89E}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii\config.exe |
    "{A67FFCF8-4A31-4BAB-AE67-38DFD02E057C}" = protocol=6 | dir=in | app=c:\program files\thq\company of heroes\relicdownloader\relicdownloader.exe |
    "{A784E5D5-7A66-47A1-99F5-D104B7BF4148}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
    "{A9CB515B-2C43-4EE8-B871-D38FD051D1CD}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dead rising 2\deadrising2.exe |
    "{AA3877A6-669D-4F37-B72D-7B61B39A3096}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\borderlands\binaries\borderlands.exe |
    "{AA657E37-3DB6-48D1-8CD5-DA08965B5B67}" = protocol=17 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
    "{AC38C145-C4DD-4C37-8896-C4711304F402}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\coj_dx10.exe |
    "{AC9EE6E5-F380-40F8-BBEB-002CD8E8FD3C}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\operation flashpoint dragon rising\mission editor\missioneditor.exe |
    "{ACB80D1C-5981-4295-9740-E22FE22D94A2}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\killingfloor\system\killingfloor.exe |
    "{AD49510F-F925-44B1-BA50-2D4BE71FD030}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\lara croft and the guardian of light\lcgol.exe |
    "{AD8EE79C-8732-4A1A-98AB-B5F129A3A59D}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
    "{ADCD43A1-1A03-4348-A06C-D064D903FAF0}" = protocol=6 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\launchgtaiv.exe |
    "{AE1F594C-DBE6-400F-83D8-E9862F095D27}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddjswx.exe |
    "{AF24B7D0-33F2-487B-8107-D5B880F0700A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\trine\trine_launcher.exe |
    "{AF82513F-0F55-4C84-8BBC-B8C4C5428694}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
    "{B0CEA569-27D8-47B0-AEF5-BD59217D1D8A}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\lara croft and the guardian of light\lcgol.exe |
    "{B28E44A7-6EB4-4DFB-801E-56FEAA28F0C0}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\srcds.exe |
    "{B29F8BBC-E0E4-416A-A19F-F50F6C289ACA}" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\lxddmon.exe |
    "{B3987365-4510-4E82-BC93-C33DAA7DAF1A}" = protocol=17 | dir=in | app=c:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe |
    "{B4EDFBDD-DFAC-4D6C-9AEB-6BEFBDB95CDA}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse.exe |
    "{B4F3F90C-89C9-4545-A28F-59230BA2C33E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\trine\trine_launcher.exe |
    "{B5D1C8D8-5F49-4560-9C1C-1225543575FB}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\fear2\fear2.exe |
    "{B68BFA38-160D-4031-9587-7095D8FA44B7}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\fc2benchmarktool.exe |
    "{B6D8302D-6D95-4194-99E0-031F68B83DB9}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
    "{B6FE578B-96DD-40BA-9398-30D4126A8B76}" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
    "{B8B47658-B3A5-4CCD-AB23-A91940F492B4}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\street fighter iv\sf4launcher.exe |
    "{BA1C857F-F217-4EA0-8741-C789B9EDFBB9}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddpswx.exe |
    "{BA721395-22AA-402A-8E49-95FDD8B9CA9C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\lost planet extreme condition\lostplanetdx10.exe |
    "{BABA3339-1A00-49C9-8169-802DD43EEB1E}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\street fighter iv\sf4launcher.exe |
    "{BC136759-1B69-4852-A4D9-ABBC236397BF}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse.exe |
    "{BCD38C76-64AD-4902-85D3-1762F671B088}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe |
    "{BCE4DC92-8D02-4C44-AE30-65D7C6E8CD76}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of juarez\coj_dx10.exe |
    "{BE414669-E000-4F33-9A50-ABB76D33383F}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\call of juarez\coj.exe |
    "{BF6810A2-C6A3-4387-90C4-E37562A36A5E}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse_unrestricted.exe |
    "{C097B379-1572-497F-BBC4-E4F4904274BE}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\coj_dx10.exe |
    "{C0BCF4CD-C789-4282-A6B7-113345963024}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\darksiders\darksiderspc.exe |
    "{C0F1E67F-56F1-499E-94D0-0957AE137D3E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
    "{C14FDBD9-74F6-4F4F-A53E-5FEEBFD8091F}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the first encounter\bin\samhd_demo.exe |
    "{C20AEC67-52ED-4290-8DC5-BFF2A250FA2D}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe |
    "{C2BD7582-EF61-47C8-8058-FF880994A038}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddpswx.exe |
    "{C2F36701-148B-45AD-A373-E7FCF9F40472}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\just cause 2\justcause2.exe |
    "{C3C49105-2172-4895-8E54-73AD089DBA86}" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\lxddmon.exe |
    "{C4AD998A-6164-4D42-9F97-5BB173347890}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe |
    "{C4C71167-DF9E-4FCC-8CAD-725A92A67CEC}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
    "{C4F5EB23-4DAB-4C0A-96B2-130E6331B623}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\lost planet extreme condition\lostplanetdx9.exe |
    "{C4FE29C9-56A1-45CD-8F3C-52F0A748E56D}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\supreme commander 2\bin\supremecommander2.exe |
    "{C58AE285-A575-458C-9419-403363B23018}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\stranger's wrath\launcher.exe |
    "{C5F988C0-8438-4ACF-9BB7-A2C009A5AF41}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\supreme commander 2\bin\supremecommander2.exe |
    "{C62D5C3C-DC6B-4EB0-B688-26DBE5DC5F69}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\call of juarez\coj_dx10.exe |
    "{C68DC321-5E00-47D0-B8C4-58748D08505C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\lost planet 2\launcher.exe |
    "{C6D9F28B-D5B5-4FA3-8832-1D4DC97E06E1}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
    "{C7DF3864-BB2C-4B8B-B3FA-747F3B1E3BF4}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
    "{C84D0A69-2388-4FB0-8306-E0B3FDD408A0}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\alien swarm\swarm.exe |
    "{C91A51DD-595F-403D-83F9-95F95F1CF505}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of duty black ops\blackopsmp.exe |
    "{C96EEE1B-84A9-4E68-BFD7-EE895D669E26}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2launcher.exe |
    "{C99CE8BB-9EEC-48CC-8683-0ADA0FB16CE2}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
    "{CA44F58C-7B82-43FD-8245-8CC5DB486AD7}" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
    "{CAC6FB4A-09C4-4084-878D-4888375323F5}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii - demo\overlord2demo.exe |
    "{CAE2EF9A-58E9-4360-928F-B36DF8FBF037}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
    "{CB128A1A-B801-481F-93D6-21FBC1BD531E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
    "{CB6D2AA7-977A-4CF7-A059-7101897F6019}" = protocol=6 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddtime.exe |
    "{CCEB6D51-6FAC-44D0-A91A-559A0E9D2E3F}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\magicka\magicka.exe |
    "{CCFEE085-E347-4EC8-9042-4D9EE0CE06F6}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\supreme commander 2\bin\supremecommander2.exe |
    "{CD01FC1A-8873-4EA1-90D7-0957403512F2}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
    "{CD5B62E1-92AC-4E62-BB48-F27FAF4BC223}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\assassin's creed 2\assassinscreediigame.exe |
    "{CD5D1C8B-6142-4A2C-9DD1-3E82142A6036}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe |
    "{CD7F5429-4D43-4EA8-90F5-2DAE02FB1EA0}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\audiosurf\engine\questviewer.exe |
    "{D040FD67-BE56-43AF-8823-16683E17BA7E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\puzzle quest\puzzle quest.exe |
    "{D13F3A79-A6C8-42FF-9D9E-4B4B1E13F64B}" = protocol=6 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutparadise.exe |
    "{D1545D83-3CF7-4D3D-86E2-F5409DD73D23}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\master levels of doom\master.bat |
    "{D24AA66B-E27A-43E2-9040-3478B9BD6271}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\call of juarez\cojdx10_benchmark.exe |
    "{D24C3510-3C88-4844-A44D-D063314D2490}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\overlord ii - demo\config.exe |
    "{D27E36AA-C567-4A7C-9C03-8F499F37E861}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse_unrestricted.exe |
    "{D47DA684-66D2-4BA2-A59E-E3963541941B}" = protocol=17 | dir=in |
     
  16. karol3

    karol3 TS Rookie Topic Starter Posts: 34

    app=f:\steam\steamapps\common\operation flashpoint dragon rising\mission editor\missioneditor.exe |
    "{D4BAE24A-249E-44E8-A6FD-BC5CD25A78DE}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mass effect 2\masseffect2launcher.exe |
    "{D537629B-C57B-4199-817F-8116A31889FA}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\peggle extreme\peggleextreme.exe |
    "{D57AFE04-52A0-41D9-8124-20157A99C29E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mass effect 2\masseffect2launcher.exe |
    "{D5BB49B9-C77B-44E5-8C47-90DA190E634C}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\mass effect 2\docs\ea help\electronic_arts_technical_support.htm |
    "{D61224ED-4934-404A-853C-FF122D952229}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
    "{D74BDA31-2BE4-4604-BD9B-D4D896B43C78}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\world of goo\worldofgoo.exe |
    "{D7708D8D-EF21-4F75-ACE8-0CCC2088EE8A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\just cause 2\justcause2.exe |
    "{D784D5BA-906A-4E8D-B390-1C1C95376E9A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\cojdx10_benchmark.exe |
    "{D7DF279C-606B-49B8-B402-321A37228AFB}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\coj.exe |
    "{D88EF919-7A45-417B-BFF4-DFCA4AFC5199}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse_unrestricted.exe |
    "{D8B4D5FB-588C-4606-AE7A-99301E20797B}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez - bound in blood\cojbibgame_x86.exe |
    "{D8F50015-56EB-40EF-B191-7FF2BB9D9930}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\far cry 2\bin\farcry2.exe |
    "{D98B4735-0FFD-48B1-B201-61D02DDB6D20}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\stalker call of pripyat\stalker-cop.exe |
    "{DA4A4162-A171-47A9-B154-586C8C069925}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\splinter cell - double agent\scdalauncher.exe |
    "{DA4BC8AC-1446-468F-89F7-D929653306B2}" = protocol=6 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysis.exe |
    "{DB0B0A66-056B-413B-AFB1-1195D7F9D7ED}" = protocol=17 | dir=in | app=c:\program files\codemasters\grid\grid.exe |
    "{DB356ECE-115E-4F5B-8671-7BBD78B9098A}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\dead space\dead space.exe |
    "{DB8BF4A6-65D3-46A4-A614-6C637DDDA61A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\deus ex\system\deusex.exe |
    "{DC62129D-ABBA-44B5-B71F-70ED08518F73}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\doom 2\doom2.bat |
    "{DC949B31-9429-4F1C-B1BA-5CF5D14CBE10}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\mafia ii\pc\mafia2.exe |
    "{DD40BDF7-AF68-444F-BB08-62F33E14D516}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
    "{DEDA25AD-B252-4795-9F72-C00AA1B240B7}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2launcher.exe |
    "{DF52CD4B-2B37-4318-8921-A1316A084B48}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
    "{E08BA285-8B9C-4959-ABA4-6C90F8A3DB4E}" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysisdedicatedserver.exe |
    "{E0942DEB-3276-4E0F-A7AF-10A476E809C1}" = protocol=6 | dir=in | app=c:\program files\skype\plugin manager\skypepm.exe |
    "{E0A15DDA-A157-41CF-B8AD-EFDBAB094CDA}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\serious sam hd the second encounter\bin\samhd_tse.exe |
    "{E13F380D-9197-4819-98A5-A07BEBB278F9}" = protocol=17 | dir=in | app=c:\program files\volition inc\red faction guerrilla\rfg.exe |
    "{E15AC2C1-CA32-4432-B437-FA5E5BEA6818}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2launcher.exe |
    "{E20BB974-8BA5-49A8-819F-1342192EF929}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe |
    "{E21E47A0-FC3F-4737-A92F-B701E0A72206}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\call of duty black ops\blackops.exe |
    "{E37556C3-10E5-4331-B688-4CC4794C0E7A}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe |
    "{E41124FB-B967-4AD5-8D3E-081FCDBA5EFC}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\operation flashpoint dragon rising\ofdr.exe |
    "{E4953C7D-4240-4F33-B9B0-9F3F73B5FCDF}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dirt 2\dirt2.exe |
    "{E4E8C859-C9B3-4B2E-903F-744B3C48F9B7}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty black ops\blackops.exe |
    "{E5618049-59CA-4356-9ABB-043EA07322A3}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\alien swarm\swarm.exe |
    "{E5CD4AC4-BB1F-4465-A6C6-29BE0E412573}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
    "{E5ED4F87-A257-444A-93F7-098B4082F5A6}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2launcher.exe |
    "{E5FC8B15-8B18-4A32-9C06-F89D1FB81CC1}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe |
    "{E60A59CA-DD1D-4CEE-B44D-DB7809119F51}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\operation flashpoint dragon rising\ofdr.exe |
    "{E6AA022B-5692-49E2-A6E2-F4D7F4FB5D65}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
    "{E6D3B735-F510-4D48-AE46-6C5B72742A7B}" = protocol=17 | dir=in | app=c:\program files\sierra entertainment\world in conflict\wic.exe |
    "{E6F943FB-BEA8-4C71-ADC3-330C5E44C090}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\alien swarm\srcds.exe |
    "{E81BBD2E-FF98-4BB7-B4D5-27ED77F01D22}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\doom 2\doom2.bat |
    "{E8286468-12FE-4563-9575-F7C9020F365B}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\mass effect 2\docs\ea help\electronic_arts_technical_support.htm |
    "{E8D3B2ED-8973-44E1-9D04-3BFD84994611}" = protocol=6 | dir=in | app=c:\program files\activision\call of duty 4 - modern warfare\iw3mp.exe |
    "{E9337803-110C-425B-BDE4-C4C4164F523A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead\left4dead.exe |
    "{E93B6C61-ACFE-44D2-8808-2EAEB4CF4971}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
    "{E9950158-E127-419C-8889-239D14117874}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\puzzle quest\puzzle quest.exe |
    "{EA878C4A-8AA3-421B-8EA2-49AAE98578D9}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\metro 2033\metro2033.exe |
    "{EB67E135-5B76-4C8D-A962-FBAE78D2E171}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
    "{EC650021-C11D-4D74-82BF-2AE8B3AC408C}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\rainbow six vegas 2\binaries\r6vegas2_game.exe |
    "{ED2B6F0B-EB85-4C82-944F-61ED5A624A9E}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\call of duty black ops\blackopsmp.exe |
    "{ED2E91A7-2E0B-4F56-8C84-9942D5CDB884}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\supreme commander 2\bin\supremecommander2.exe |
    "{ED7C133D-E7B4-41E3-A1B0-20BA013BA997}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
    "{EE4F613A-93F0-45C8-B2C7-5C59947A4A4B}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\metro 2033\metro2033.exe |
    "{EF6C3A40-87DA-4117-8AE9-EAE54F82AC76}" = protocol=17 | dir=in | app=c:\program files\mass effect\binaries\masseffect.exe |
    "{EF9DF154-7969-4ADE-A0F2-0CBA1E74789C}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\fear2\fear2.exe |
    "{F09A57E5-F0D1-4600-9A41-BEC1AD3D2C67}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\kane & lynch 2 - dog days\kl2.exe |
    "{F1196620-08D8-4E2A-8701-25761F915AD6}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\borderlands\binaries\borderlands.exe |
    "{F1A00F28-38B3-4335-99E5-ECE9907CA62E}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe |
    "{F1FDE7C3-CA19-40DF-AD49-999C40929E2F}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mass effect 2\docs\ea help\electronic_arts_technical_support.htm |
    "{F2BB1C88-0ABF-424E-A688-9A455BD1DDD3}" = protocol=17 | dir=in | app=c:\program files\sierra entertainment\world in conflict\wic_online.exe |
    "{F3E00A04-148A-4727-878D-61F0ADE3E701}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
    "{F5C2EC19-91C4-404A-A1A2-51BAFFBD3656}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\call of juarez\cojdx10_benchmark.exe |
    "{F60DEF98-0983-4526-936F-A338E42E03D0}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\call of juarez\chromed.exe |
    "{F7E06316-0876-4770-B7EA-8C8E885B0184}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2launcher.exe |
    "{F84009BC-9C0A-49A5-ABAC-406C92F7485E}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe |
    "{F85AB511-8A15-4917-9B02-559FDA87CD13}" = protocol=17 | dir=in | app=c:\program files\microsoft games\gears of war\binaries\wargame-g4wlive.exe |
    "{F8954B33-96B6-4E55-81D4-8C9327A3E068}" = protocol=6 | dir=in | app=f:\steam\steamapps\common\rainbow six vegas 2\binaries\r6vegas2_game.exe |
    "{F979BC35-5E8B-4C55-8DAD-F69CA5F9A0A9}" = protocol=17 | dir=in | app=c:\windows\system32\spool\drivers\w32x86\3\lxddpswx.exe |
    "{F984F00F-C457-484D-812C-1FEA95EAA843}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\supreme commander 2\bin\supremecommander2.exe |
    "{F9E57377-EEE8-4802-B6DA-351DA178A2E9}" = protocol=17 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutconfigtool.exe |
    "{FA414B4B-7775-4CF2-A399-498D048FBF21}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\karol754\counter-strike source\hl2.exe |
    "{FB0C80DC-9C16-4736-AE09-24981CDB435D}" = protocol=17 | dir=in | app=c:\program files\activision\call of duty 4 - modern warfare\iw3mp.exe |
    "{FB2D287D-4297-4488-B23D-976BB5E31C1A}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
    "{FDD6A029-8DB0-4DDA-A5F6-AED7193ECFF8}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\peggle extreme\peggleextreme.exe |
    "{FE06F299-1FD7-4B0F-B546-11F36B171820}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\trine\trine_launcher.exe |
    "{FF3A7E60-7B45-4FC0-824A-0EF53465094E}" = protocol=6 | dir=in | app=c:\program files\electronic arts\crytek\crysis\bin32\crysis.exe |
    "{FF9F4632-A353-43F0-8F32-F9BAB4EB8152}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\zombie driver\release\zombiedriver.exe |
    "{FFD931F3-387F-433B-8302-546FB4EC171C}" = protocol=17 | dir=in | app=f:\steam\steamapps\common\supreme commander 2\bin\supremecommander2.exe |
    "TCP Query User{002323C0-EFEB-4625-A3E0-318C51564DB1}C:\program files\steam\steamapps\common\street fighter iv\streetfighteriv.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\street fighter iv\streetfighteriv.exe |
    "TCP Query User{0BA4EA77-9CEE-48B7-A896-5D070FD8B17F}C:\users\user\appdata\local\temp\c3ce06baa0504d618da4e76b7512b906\relicdownloader.exe" = protocol=6 | dir=in | app=c:\users\user\appdata\local\temp\c3ce06baa0504d618da4e76b7512b906\relicdownloader.exe |
    "TCP Query User{192CFEAC-59C0-45F6-BC35-5A96E4D7B705}C:\program files\steam\steamapps\common\dirt 2\dirt2_game.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dirt 2\dirt2_game.exe |
    "TCP Query User{1A623A84-C0C8-4751-A9AA-F2609C5106DA}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
    "TCP Query User{1C0B00DC-D896-423C-88C2-E5E888357102}C:\program files\rockstar games\eflc\eflc.exe" = protocol=6 | dir=in | app=c:\program files\rockstar games\eflc\eflc.exe |
    "TCP Query User{2222A774-7F70-4E37-B489-63DC2385C8B6}C:\program files\steam\steamapps\common\splinter cell - double agent\scda-offline\system\splintercell4.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\splinter cell - double agent\scda-offline\system\splintercell4.exe |
    "TCP Query User{2762BB5A-F0A9-4D9F-8755-862BA43E92A1}C:\program files\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe |
    "TCP Query User{30C879E3-F0BF-45C4-935C-E70E4CB54C4E}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
    "TCP Query User{350D3E42-5CC7-4883-A606-24494CC3A469}C:\users\user\appdata\local\temp\b6e54071f05341868e8567ff58759800\relicdownloader.exe" = protocol=6 | dir=in | app=c:\users\user\appdata\local\temp\b6e54071f05341868e8567ff58759800\relicdownloader.exe |
    "TCP Query User{35781E8C-03CE-4333-9882-98ED78C5AF06}C:\program files\steam\steamapps\common\left 4 dead demo\left4dead.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead demo\left4dead.exe |
    "TCP Query User{3EEDD4CD-F39E-4789-B9EF-D9BBE8579E45}C:\program files\steam\steamapps\common\dead space\dead space.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dead space\dead space.exe |
    "TCP Query User{4016158E-4406-4DA8-88A7-4BCA4207AF95}D:\xfire\xfire.exe" = protocol=6 | dir=in | app=d:\xfire\xfire.exe |
    "TCP Query User{40BFBA37-F409-4C97-9199-094DDFE0FDE6}C:\program files\bethesda softworks\fallout 3\fallout3.exe" = protocol=6 | dir=in | app=c:\program files\bethesda softworks\fallout 3\fallout3.exe |
    "TCP Query User{45065ADD-A523-49BF-80FC-1EF88870CACF}C:\program files\steam\steamapps\karol754\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\karol754\team fortress 2\hl2.exe |
    "TCP Query User{45540C66-C621-4853-9DB6-ED33DF69E051}C:\program files\steam\steamapps\common\rainbow six vegas 2\binaries\r6vegas2_game.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\rainbow six vegas 2\binaries\r6vegas2_game.exe |
    "TCP Query User{4619A8B2-1E12-48D1-8905-96741E7FA239}F:\steam\steamapps\karol754\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=f:\steam\steamapps\karol754\team fortress 2\hl2.exe |
    "TCP Query User{47D78FD3-4F4C-4BF0-A1C1-B54F469B88A9}C:\program files\steam\steamapps\common\dead space\dead space.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\dead space\dead space.exe |
    "TCP Query User{4D210AE6-1123-4304-96F1-16897E279534}C:\program files\atari\the chronicles of riddick - assault on dark athena\system\win32_x86\darkathena.exe" = protocol=6 | dir=in | app=c:\program files\atari\the chronicles of riddick - assault on dark athena\system\win32_x86\darkathena.exe |
    "TCP Query User{4ED731BD-F2D9-47C5-A6E4-06D2CC1B351D}C:\program files\aim\aim.exe" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
    "TCP Query User{509986D4-94D1-4E53-9050-B8879893722D}C:\program files\steam\steamapps\common\lost planet 2\lp2dx11.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\lost planet 2\lp2dx11.exe |
    "TCP Query User{554975A4-4FF8-4BDD-84C2-899620C944EE}C:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutparadise.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutparadise.exe |
    "TCP Query User{5E88EA7A-19CC-47E1-879A-B6DFFB595F00}C:\program files\steam\steamapps\common\nba 2k10\nba2k10.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\nba 2k10\nba2k10.exe |
    "TCP Query User{5F530874-596B-4E2F-BF00-7056BE282177}C:\program files\electronic arts\crytek\crysis wars\bin32\crysis.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\crytek\crysis wars\bin32\crysis.exe |
    "TCP Query User{5FF98F51-A5BE-4A90-BDC8-C968AB6DB3F5}C:\program files\steam\steamapps\karol754\half-life\hl.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\karol754\half-life\hl.exe |
    "TCP Query User{694DB969-31DE-49C7-AABD-9B3613FCA641}F:\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=6 | dir=in | app=f:\steam\steamapps\common\resident evil 5\re5dx10.exe |
    "TCP Query User{701B7E57-210F-4660-8BD8-CAA6121B2590}C:\program files\bethesda softworks\fallout 3\fallout3.exe" = protocol=6 | dir=in | app=c:\program files\bethesda softworks\fallout 3\fallout3.exe |
    "TCP Query User{779996EB-F920-4655-AC6E-6E0469B0C8B7}C:\program files\rockstar games\grand theft auto iv\gtaiv.exe" = protocol=6 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\gtaiv.exe |
    "TCP Query User{784900E5-A1B7-4E40-B49E-021D1E3AD798}C:\program files\steam\steamapps\common\street fighter iv\streetfighteriv.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\street fighter iv\streetfighteriv.exe |
    "TCP Query User{7FC540C0-D628-4704-85CE-87E24A749FF2}C:\program files\gadu-gadu\gg.exe" = protocol=6 | dir=in | app=c:\program files\gadu-gadu\gg.exe |
    "TCP Query User{80750F8C-289B-4391-A0C5-07C6B0DF3B08}C:\program files\lexmark 2500 series\lxddamon.exe" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\lxddamon.exe |
    "TCP Query User{8E7CF103-5729-41B9-8E61-A646A808291C}C:\program files\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
    "TCP Query User{915DB8AA-C706-49ED-A855-BF6B7E125203}C:\program files\steam\steamapps\common\splinter cell - double agent\scda-offline\system\splintercell4.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\splinter cell - double agent\scda-offline\system\splintercell4.exe |
    "TCP Query User{969CFDA0-B0F4-481C-90E5-06793C5CF943}C:\program files\microsoft games\gears of war\binaries\wargame-g4wlive.exe" = protocol=6 | dir=in | app=c:\program files\microsoft games\gears of war\binaries\wargame-g4wlive.exe |
    "TCP Query User{9AEF7486-F923-4695-953A-54562B2E4C68}C:\program files\thq\company of heroes\reliccoh.exe" = protocol=6 | dir=in | app=c:\program files\thq\company of heroes\reliccoh.exe |
    "TCP Query User{9B8CBBE5-AFFF-4221-97FD-C6439BA366D3}C:\program files\steam\steamapps\common\lost planet 2\lp2dx9.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\lost planet 2\lp2dx9.exe |
    "TCP Query User{A45E5F71-4CD3-489D-907E-C4F65D544C1C}C:\program files\rockstar games\grand theft auto iv\gtaiv.exe" = protocol=6 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\gtaiv.exe |
    "TCP Query User{A4E67B54-1256-410B-9310-400E30468659}C:\program files\lexmark 2500 series\app4r.exe" = protocol=6 | dir=in | app=c:\program files\lexmark 2500 series\app4r.exe |
    "TCP Query User{A85DB545-F398-41D5-9479-E21CC093639F}C:\program files\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\resident evil 5\re5dx10.exe |
    "TCP Query User{A9E2E490-194A-4DF6-8E5B-C7EDD248F9E3}C:\program files\electronic arts\crytek\crysis wars\bin32\crysis.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\crytek\crysis wars\bin32\crysis.exe |
    "TCP Query User{AD66CA4F-0A21-40F9-85AF-5B78143ED69B}D:\bad comapny2\bfbc2game.exe" = protocol=6 | dir=in | app=d:\bad comapny2\bfbc2game.exe |
    "TCP Query User{B0FAE153-C7FF-4C06-BB57-CAFE0F6BD26E}C:\program files\eidos\batman arkham asylum\binaries\shippingpc-bmgame.exe" = protocol=6 | dir=in | app=c:\program files\eidos\batman arkham asylum\binaries\shippingpc-bmgame.exe |
    "TCP Query User{B19C34CE-0E76-4064-A03F-BA2C3340AA1B}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
    "TCP Query User{B5394CBB-8337-4D29-A8B3-667A90DCA5A4}C:\users\user\appdata\local\temp\e9e416c32092471c863b1563b6fb0ff6\relicdownloader.exe" = protocol=6 | dir=in | app=c:\users\user\appdata\local\temp\e9e416c32092471c863b1563b6fb0ff6\relicdownloader.exe |
    "TCP Query User{B94A7F7B-7342-43A3-A94A-462775B2B1FE}C:\program files\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
    "TCP Query User{C1382188-9B58-4197-97CF-0B5052E0533A}D:\grid\grid.exe" = protocol=6 | dir=in | app=d:\grid\grid.exe |
    "TCP Query User{C28CC99D-C743-4B80-ACCD-9B06C3C843D0}C:\program files\thq\company of heroes\relicdownloader\relicdownloader.exe" = protocol=6 | dir=in | app=c:\program files\thq\company of heroes\relicdownloader\relicdownloader.exe |
    "TCP Query User{C57056AE-CBD5-4B60-B988-FE9C5596F707}C:\program files\volition inc\red faction guerrilla\rfg.exe" = protocol=6 | dir=in | app=c:\program files\volition inc\red faction guerrilla\rfg.exe |
    "TCP Query User{C70BF536-14A6-4018-9D49-03732A4F27CF}C:\users\user\desktop\tf2 idle\steamstats.exe" = protocol=6 | dir=in | app=c:\users\user\desktop\tf2 idle\steamstats.exe |
    "TCP Query User{CB6EA058-2B4B-4899-9D23-724EEA21B4B6}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
    "TCP Query User{D5E1C3DD-6C3F-411F-99D2-D77B17AA60DA}C:\users\user\desktop\tf2 idle\steamstats.exe" = protocol=6 | dir=in | app=c:\users\user\desktop\tf2 idle\steamstats.exe |
    "TCP Query User{DFDE6D09-F0C4-471F-A822-5571B2A3B7CE}C:\program files\codemasters\grid\grid.exe" = protocol=6 | dir=in | app=c:\program files\codemasters\grid\grid.exe |
    "TCP Query User{E076DF82-C275-4DE7-927B-E9486C7ED543}D:\xfire\xfire.exe" = protocol=6 | dir=in | app=d:\xfire\xfire.exe |
    "TCP Query User{E4F81C3E-6E96-4B08-9C88-5E77FFB3CBE6}C:\program files\steam\steamapps\karol754\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\karol754\team fortress 2\hl2.exe |
    "TCP Query User{EEFACDA8-6694-46ED-A185-5A034C8EB31C}C:\program files\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe |
    "TCP Query User{FD5C0A90-C662-4792-B5CD-D84CF972CF2F}C:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe" = protocol=6 | dir=in | app=c:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe |
    "TCP Query User{FE860E23-FEEB-4ACB-B6E5-E964D947217F}C:\program files\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\resident evil 5\re5dx10.exe |
    "UDP Query User{07CEE403-ECCD-45E3-BBB9-8554A792C00C}C:\program files\electronic arts\crytek\crysis wars\bin32\crysis.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis wars\bin32\crysis.exe |
    "UDP Query User{0C2718CA-B9DD-4FFC-80A4-E4403B3C2DE3}C:\program files\atari\the chronicles of riddick - assault on dark athena\system\win32_x86\darkathena.exe" = protocol=17 | dir=in | app=c:\program files\atari\the chronicles of riddick - assault on dark athena\system\win32_x86\darkathena.exe |
    "UDP Query User{10BEFDED-BAB6-4540-9B46-95FC9543AB9E}C:\program files\bethesda softworks\fallout 3\fallout3.exe" = protocol=17 | dir=in | app=c:\program files\bethesda softworks\fallout 3\fallout3.exe |
    "UDP Query User{1841CBE7-F559-4EB2-875B-ABA8263BFF4F}C:\program files\steam\steamapps\common\street fighter iv\streetfighteriv.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\street fighter iv\streetfighteriv.exe |
    "UDP Query User{25D49622-1684-43FD-9A15-8F284FA88A5D}C:\users\user\appdata\local\temp\e9e416c32092471c863b1563b6fb0ff6\relicdownloader.exe" = protocol=17 | dir=in | app=c:\users\user\appdata\local\temp\e9e416c32092471c863b1563b6fb0ff6\relicdownloader.exe |
    "UDP Query User{2C8AA39A-0CE6-4D77-A396-BA69C5C58952}C:\program files\eidos\batman arkham asylum\binaries\shippingpc-bmgame.exe" = protocol=17 | dir=in | app=c:\program files\eidos\batman arkham asylum\binaries\shippingpc-bmgame.exe |
    "UDP Query User{3658ED4C-64FB-4021-B314-3DC541A2D795}C:\users\user\desktop\tf2 idle\steamstats.exe" = protocol=17 | dir=in | app=c:\users\user\desktop\tf2 idle\steamstats.exe |
    "UDP Query User{388D77C9-9A16-49B5-9372-572B103A2D5E}C:\program files\steam\steamapps\common\lost planet 2\lp2dx9.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\lost planet 2\lp2dx9.exe |
    "UDP Query User{3A1A8D69-EA0B-4A43-91DD-80139E361AB6}C:\program files\steam\steamapps\karol754\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\karol754\team fortress 2\hl2.exe |
    "UDP Query User{3F762A09-B090-4277-A2AA-CA52CA48E1E8}C:\program files\lexmark 2500 series\app4r.exe" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\app4r.exe |
    "UDP Query User{42470FC1-B363-46D0-9A36-0D5AB6B55901}C:\users\user\appdata\local\temp\c3ce06baa0504d618da4e76b7512b906\relicdownloader.exe" = protocol=17 | dir=in | app=c:\users\user\appdata\local\temp\c3ce06baa0504d618da4e76b7512b906\relicdownloader.exe |
    "UDP Query User{4318D333-474A-49CD-B2EC-988CF852D7DB}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
    "UDP Query User{44E23F4C-4678-45EA-875F-039DC0E54A2D}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
    "UDP Query User{468418D5-C011-4230-9B01-420275419582}C:\program files\thq\company of heroes\reliccoh.exe" = protocol=17 | dir=in | app=c:\program files\thq\company of heroes\reliccoh.exe |
    "UDP Query User{46ACD912-7302-426A-8983-4CBCFBBEAE5A}C:\program files\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe |
    "UDP Query User{48C002FC-1652-4088-9C8A-150DAED5C361}C:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe" = protocol=17 | dir=in | app=c:\program files\deep silver\s.t.a.l.k.e.r. - clear sky\bin\xrengine.exe |
    "UDP Query User{4EB7726D-90E9-4738-A186-F4997F977AC0}D:\xfire\xfire.exe" = protocol=17 | dir=in | app=d:\xfire\xfire.exe |
    "UDP Query User{516960F6-B2FB-4179-9D40-CD75FF8A5E11}C:\program files\aim\aim.exe" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
    "UDP Query User{51A590AA-3D62-431C-B185-8007F8818416}C:\program files\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\resident evil 5\re5dx10.exe |
    "UDP Query User{637CAB72-81E9-4E73-BBAD-A0858F9603B5}C:\program files\rockstar games\eflc\eflc.exe" = protocol=17 | dir=in | app=c:\program files\rockstar games\eflc\eflc.exe |
    "UDP Query User{64EFF5F4-28D1-4047-A648-550979600E29}C:\program files\steam\steamapps\common\splinter cell - double agent\scda-offline\system\splintercell4.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\splinter cell - double agent\scda-offline\system\splintercell4.exe |
    "UDP Query User{654869F2-8F3F-4083-AE4C-47E1960ADD86}C:\program files\thq\company of heroes\relicdownloader\relicdownloader.exe" = protocol=17 | dir=in | app=c:\program files\thq\company of heroes\relicdownloader\relicdownloader.exe |
    "UDP Query User{658ABB8F-E3EF-4127-B014-AF03AED51BE3}C:\program files\rockstar games\grand theft auto iv\gtaiv.exe" = protocol=17 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\gtaiv.exe |
    "UDP Query User{6E130025-78CC-4065-BF47-754A3BB4DF2B}C:\program files\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\resident evil 5\re5dx10.exe |
    "UDP Query User{76272F58-B2AD-408C-99AC-7D762B652D48}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
    "UDP Query User{7A833394-6FF0-43EB-9931-647E572143C2}C:\program files\codemasters\grid\grid.exe" = protocol=17 | dir=in | app=c:\program files\codemasters\grid\grid.exe |
    "UDP Query User{7F1FB66C-3A16-472A-9414-5AEA003DFDD7}C:\program files\bethesda softworks\fallout 3\fallout3.exe" = protocol=17 | dir=in | app=c:\program files\bethesda softworks\fallout 3\fallout3.exe |
    "UDP Query User{834565D2-119F-48A4-8035-6CC87A853BAC}C:\users\user\desktop\tf2 idle\steamstats.exe" = protocol=17 | dir=in | app=c:\users\user\desktop\tf2 idle\steamstats.exe |
    "UDP Query User{847E1C96-7655-4A39-8081-0004843A6FAA}C:\users\user\appdata\local\temp\b6e54071f05341868e8567ff58759800\relicdownloader.exe" = protocol=17 | dir=in | app=c:\users\user\appdata\local\temp\b6e54071f05341868e8567ff58759800\relicdownloader.exe |
    "UDP Query User{86A6F03B-67BF-45FC-BCD2-2CEB893B804F}D:\grid\grid.exe" = protocol=17 | dir=in | app=d:\grid\grid.exe |
    "UDP Query User{9464B34D-2614-44EE-93E2-BC87D6624F65}D:\bad comapny2\bfbc2game.exe" = protocol=17 | dir=in | app=d:\bad comapny2\bfbc2game.exe |
    "UDP Query User{984BBD36-F377-4172-A6B0-ACAD4DF16DF6}F:\steam\steamapps\karol754\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=f:\steam\steamapps\karol754\team fortress 2\hl2.exe |
    "UDP Query User{98DBF7D7-13E3-4725-96F8-9D422294C614}C:\program files\lexmark 2500 series\lxddamon.exe" = protocol=17 | dir=in | app=c:\program files\lexmark 2500 series\lxddamon.exe |
    "UDP Query User{9AE2770E-C3DF-48CF-B772-8225E0B11EA9}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
    "UDP Query User{A99D9D76-C819-43EF-94DA-E93955D56BBA}C:\program files\electronic arts\crytek\crysis wars\bin32\crysis.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\crytek\crysis wars\bin32\crysis.exe |
    "UDP Query User{A9EC8D32-22A0-4D03-895A-931693703F1C}C:\program files\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\eadm\core.exe |
    "UDP Query User{AA8A4F07-E579-4976-8E7E-A14A276D68FE}C:\program files\rockstar games\grand theft auto iv\gtaiv.exe" = protocol=17 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\gtaiv.exe |
    "UDP Query User{B38B995F-921C-4900-9A04-1254CCFE4E57}C:\program files\steam\steamapps\common\lost planet 2\lp2dx11.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\lost planet 2\lp2dx11.exe |
    "UDP Query User{B3B86969-563F-48C7-A3B6-2C2D95DF1E39}C:\program files\steam\steamapps\karol754\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\karol754\team fortress 2\hl2.exe |
    "UDP Query User{B4832CBD-1211-41FA-A0C9-8852FEEF3143}C:\program files\gadu-gadu\gg.exe" = protocol=17 | dir=in | app=c:\program files\gadu-gadu\gg.exe |
    "UDP Query User{B5529654-26EF-46DB-9DF5-465B84636D4E}C:\program files\steam\steamapps\common\dirt 2\dirt2_game.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dirt 2\dirt2_game.exe |
    "UDP Query User{BAC30FFC-4593-4C5F-A738-E03C61672F85}C:\program files\microsoft games\gears of war\binaries\wargame-g4wlive.exe" = protocol=17 | dir=in | app=c:\program files\microsoft games\gears of war\binaries\wargame-g4wlive.exe |
    "UDP Query User{BFAF378C-230F-46BF-8F49-BDDD1BDC399C}C:\program files\volition inc\red faction guerrilla\rfg.exe" = protocol=17 | dir=in | app=c:\program files\volition inc\red faction guerrilla\rfg.exe |
    "UDP Query User{C08C49D1-7864-4920-B339-57AC2BBA55C1}C:\program files\steam\steamapps\common\splinter cell - double agent\scda-offline\system\splintercell4.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\splinter cell - double agent\scda-offline\system\splintercell4.exe |
    "UDP Query User{C41B4F64-4D56-4E70-AECD-53F4A5A994B8}C:\program files\steam\steamapps\common\rainbow six vegas 2\binaries\r6vegas2_game.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\rainbow six vegas 2\binaries\r6vegas2_game.exe |
    "UDP Query User{C5CD08B2-3F35-4177-8192-B22150DE79EF}C:\program files\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\tom clancy's splinter cell conviction\src\system\conviction_game.exe |
    "UDP Query User{C8FC970F-A640-4B22-B4B2-9F65C51C7512}F:\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=17 | dir=in | app=f:\steam\steamapps\common\resident evil 5\re5dx10.exe |
    "UDP Query User{D6853EA1-8D4D-4F47-A8A7-622820B820F6}C:\program files\steam\steamapps\karol754\half-life\hl.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\karol754\half-life\hl.exe |
    "UDP Query User{DA57E934-EC40-448C-B7C0-F72FCF2AB252}C:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutparadise.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\burnout(tm) paradise the ultimate box\burnoutparadise.exe |
    "UDP Query User{DA60E5BE-FE0A-4DD0-8343-4263646BB50E}C:\program files\steam\steamapps\common\nba 2k10\nba2k10.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\nba 2k10\nba2k10.exe |
    "UDP Query User{DBE387D6-10C2-4A81-B884-92B1565C2800}C:\program files\steam\steamapps\common\left 4 dead demo\left4dead.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead demo\left4dead.exe |
    "UDP Query User{DCA9C6DB-37DB-4E9F-934A-5E22F14F6961}C:\program files\steam\steamapps\common\street fighter iv\streetfighteriv.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\street fighter iv\streetfighteriv.exe |
    "UDP Query User{E734E51E-D9A6-478E-930A-A79AEDF223FE}C:\program files\steam\steamapps\common\dead space\dead space.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dead space\dead space.exe |
    "UDP Query User{E7B933B6-FEE4-446A-A02B-93D5EF53F4C4}D:\xfire\xfire.exe" = protocol=17 | dir=in | app=d:\xfire\xfire.exe |
    "UDP Query User{F785936F-6E38-4918-8BA4-07230F6266E9}C:\program files\steam\steamapps\common\dead space\dead space.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\dead space\dead space.exe |
    "UDP Query User{F8C62894-64D2-4DBC-989B-A88BD60A5A13}C:\program files\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{000E79B7-E725-4F01-870A-C12942B7F8E4}" = Crysis(R)
    "{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
    "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
    "{1170D24F-42B7-40CF-AA1B-6395CE562354}" = Gears of War
    "{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
    "{14574B7F-75D1-4718-B7F2-EBF6E2862A35}" = Company of Heroes - FAKEMSI
    "{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
    "{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
    "{199E6632-EB28-4F73-AECB-3E192EB92D18}" = Company of Heroes - FAKEMSI
    "{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
    "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
    "{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
    "{1B0FBB9A-995D-47cd-87CD-13E68B676E4F}" = Mass Effect
    "{1BBDD6C0-ED6F-43C3-8A9C-84E3249A5615}" = Twin USB Vibration Gamepad
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
    "{1FDA5A37-B22D-43FF-B582-B8964050DC13}" = Microsoft Games for Windows - LIVE Redistributable
    "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
    "{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
    "{25724802-CC14-4B90-9F3B-3D6955EE27B1}" = Company of Heroes - FAKEMSI
    "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
    "{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
    "{2987EE84-C4EE-4FF5-8160-32DE00D6ABC6}" = GTA2
    "{310BC5E2-31AF-49BB-904D-E71EB93645DC}" = AI Suite
    "{32072109-98AC-4BDD-BDD8-B9EDDB1EA971}" = SwitchBlade
    "{32C4A4EB-C97D-414E-99C5-38F8DFD31D5D}" = Company of Heroes - FAKEMSI
    "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
    "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
    "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
    "{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
    "{43430808-081A-4C0D-B7CC-601000028501}" = LOST PLANET 2
    "{4343080E-448E-4E2C-B27F-B91000018201}" = Dead Rising 2
    "{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
    "{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
    "{4E79A60F-15D2-4BEC-91AD-E41EC42E61B0}" = Batman: Arkham Asylum
    "{50193078-F553-4EBA-AA77-64C9FAA12F98}" = Company of Heroes - FAKEMSI
    "{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
    "{51D718D1-DA81-4FAD-919F-5C1CE3C33379}" = Company of Heroes - FAKEMSI
    "{5454083B-1308-4485-BF17-111000028701}" = Grand Theft Auto: Episodes from Liberty City
     
  17. karol3

    karol3 TS Rookie Topic Starter Posts: 34

    "{5454083B-1308-4485-BF17-111000038701}" = Grand Theft Auto: Episodes from Liberty City
    "{5454083B-1308-4485-BF17-1110000B8301}" = Grand Theft Auto IV
    "{5454083B-1308-4485-BF17-1110000D8301}" = Grand Theft Auto IV
    "{5454085C-840F-4070-8FAA-441000038301}" = BioShock 2
    "{54C93A8C-A15A-4439-BE64-2342202D4FF0}" = OpenOffice.org 2.3
    "{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
    "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
    "{579BA58C-F33D-4970-9953-B94B43768AC3}" = Grand Theft Auto IV
    "{5A0B7BA5-4682-4273-81C2-69B17E649103}" = GRID
    "{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
    "{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
    "{61B8B2F9-D8DA-4B24-89A9-DB09F38A4899}" = Grand Theft Auto: Episodes From Liberty City
    "{66F78C51-D108-4F0C-A93C-1CBE74CE338F}" = Company of Heroes - FAKEMSI
    "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
    "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
    "{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
    "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
    "{7353BAE6-5E49-46C4-A9B5-8A269A313789}" = Crysis WARHEAD(R)
    "{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
    "{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
    "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
    "{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
    "{7F4B1592-222F-4E5F-A100-E5AFD61A0BB3}" = Company of Heroes - FAKEMSI
    "{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
    "{80D03817-7943-4839-8E96-B9F924C5E67D}" = Company of Heroes - FAKEMSI
    "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
    "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
    "{86A4C6D9-29EE-4719-AFA1-BA3341862B83}" = Microsoft Games for Windows - LIVE
    "{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
    "{88B32652-CAE0-4909-A463-5840D2689D93}" = FUJIFILM FinePixViewer S Ver.2.1
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
    "{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
    "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
    "{8CFA9151-6404-409A-AF22-4632D04582FD}" = Assassin's Creed
    "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
    "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
    "{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
    "{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
    "{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
    "{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
    "{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
    "{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
    "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
    "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
    "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
    "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
    "{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
    "{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
    "{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
    "{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
    "{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
    "{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
    "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
    "{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
    "{9322A850-9091-4D0E-B252-3E82EDA3D94A}" = Prototype(TM)
    "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
    "{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
    "{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
    "{97E5205F-EA4F-438F-B211-F1846419F1C1}" = Company of Heroes - FAKEMSI
    "{97EA42A5-3FAB-4948-B74D-F3C44B13F5CE}" = Crysis WARHEAD(R) Patch
    "{99A7722D-9ACB-43F3-A222-ABC7133F159E}" = Company of Heroes - FAKEMSI
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9A996B6A-846E-4A89-B9C4-17546B7BE49F}" = Burnout(TM) Paradise The Ultimate Box
    "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
    "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
    "{A357EF4C-2B6F-4980-ACA9-B1E42A74D7F3}" = Red Faction Guerrilla
    "{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
    "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
    "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
    "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
    "{AAF4238F-7C29-451D-9925-C753271A5728}" = Microsoft Visual C++ Run Time Lib Setup
    "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
    "{AC76BA86-7AD7-1033-7B44-AA0000000001}" = Adobe Reader X
    "{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
    "{AEDBD563-24BB-4EE3-8366-A654DAC2D988}" = Mirror's Edge™
    "{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
    "{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 266.58
    "{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 266.58
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 266.58
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.1.13.1
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
    "{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
    "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
    "{B93EEE50-9C8F-45DF-95E4-3D85A6E242F3}" = DarksidersInstaller
    "{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
    "{BA801B94-C28D-46EE-B806-E1E021A3D519}" = Company of Heroes - FAKEMSI
    "{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
    "{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
    "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
    "{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
    "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
    "{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
    "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
    "{CFADE4AF-C0CF-4A04-A776-741318F1658F}" = Content Transfer
    "{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.3.26 Game
    "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
    "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
    "{D4D244D1-05E0-4D24-86A2-B2433C435671}" = Company of Heroes - FAKEMSI
    "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
    "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
    "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
    "{E280923D-C5D9-4728-8C79-AC9A0DC75875}" = BioShock
    "{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
    "{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skype™ 5.1
    "{EAF636A9-F664-4703-A659-85A894DA264F}" = Company of Heroes - FAKEMSI
    "{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
    "{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
    "{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
    "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
    "{F11ADC64-C89E-47F4-A0B3-3665FF859397}" = World in Conflict
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{F138762F-5A1F-4CF0-A5E1-1588EF6088A4}" = The Witcher Enhanced Edition
    "{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
    "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
    "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
    "Adobe Shockwave Player" = Adobe Shockwave Player 11.5
    "AIM_7" = AIM 7
    "AVS DVD Player_is1" = AVS DVD Player version 2.4
    "CCleaner" = CCleaner
    "Company of Heroes" = Company of Heroes
    "CPUID CPU-Z_is1" = CPUID CPU-Z 1.57
    "Crysis WARHEAD(R)" = Crysis WARHEAD(R)
    "Crysis WARHEAD(R) Patch" = Crysis WARHEAD(R) Patch
    "dBpowerAMP Music Converter" = dBpowerAMP Music Converter
    "DVD Flick_is1" = DVD Flick 1.3.0.7
    "EADM" = EA Download Manager
    "ENTERPRISE" = Microsoft Office Enterprise 2007
    "FormatFactory" = FormatFactory 2.20
    "Fraps" = Fraps (remove only)
    "GoldWave v5.20" = GoldWave v5.20
    "HandBrake" = HandBrake 0.9.5
    "Host OpenAL (ADI)" = Host OpenAL (ADI)
    "InstallShield_{1170D24F-42B7-40CF-AA1B-6395CE562354}" = Gears of War
    "InstallShield_{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
    "InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
    "InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
    "InstallShield_{9322A850-9091-4D0E-B252-3E82EDA3D94A}" = Prototype(TM)
    "InstallShield_{A357EF4C-2B6F-4980-ACA9-B1E42A74D7F3}" = Red Faction Guerrilla
    "InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
    "Lexmark 2500 Series" = Lexmark 2500 Series
    "Lexmark Fax Solutions" = Lexmark Fax Solutions
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
    "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
    "NetMeter_is1" = NetMeter 1.1.3
    "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
    "OpenAL" = OpenAL
    "Peggle World of Warcraft Edition" = Peggle World of Warcraft Edition
    "PunkBusterSvc" = PunkBuster Services
    "Smart Defrag_is1" = Smart Defrag
    "SoftwareUpdUtility" = Download Updater (AOL LLC)
    "sp6" = Logitech SetPoint 6.20
    "SpeedFan" = SpeedFan (remove only)
    "SpywareBlaster_is1" = SpywareBlaster 4.4
    "TeamSpeak 3 Client" = TeamSpeak 3 Client
    "ViewpointMediaPlayer" = Viewpoint Media Player
    "VLC media player" = VLC media player 1.1.5
    "Webshots Desktop_is1" = Webshots Desktop
    "WinLiveSuite" = Windows Live Essentials
    "Xfire" = Xfire (remove only)

    ========== HKEY_USERS Uninstall List ==========

    [HKEY_USERS\S-1-5-21-2158934232-3957428742-2026527031-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.2

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 2/28/2011 11:46:28 AM | Computer Name = User-PC | Source = LoadPerf | ID = 3012
    Description =

    Error - 2/28/2011 11:46:28 AM | Computer Name = User-PC | Source = LoadPerf | ID = 3011
    Description =

    Error - 2/28/2011 1:28:36 PM | Computer Name = User-PC | Source = LoadPerf | ID = 3012
    Description =

    Error - 2/28/2011 1:28:36 PM | Computer Name = User-PC | Source = LoadPerf | ID = 3011
    Description =

    Error - 2/28/2011 1:48:33 PM | Computer Name = User-PC | Source = LoadPerf | ID = 3012
    Description =

    Error - 2/28/2011 1:48:33 PM | Computer Name = User-PC | Source = LoadPerf | ID = 3011
    Description =

    Error - 2/28/2011 6:50:03 PM | Computer Name = User-PC | Source = LoadPerf | ID = 3012
    Description =

    Error - 2/28/2011 6:50:03 PM | Computer Name = User-PC | Source = LoadPerf | ID = 3011
    Description =

    Error - 2/28/2011 7:38:14 PM | Computer Name = User-PC | Source = Microsoft-Windows-RestartManager | ID = 10006
    Description =

    Error - 2/28/2011 7:38:14 PM | Computer Name = User-PC | Source = Microsoft-Windows-RestartManager | ID = 10006
    Description =

    [ Media Center Events ]
    Error - 8/28/2008 8:39:20 AM | Computer Name = User-PC | Source = MCUpdate | ID = 0
    Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

    Error - 6/24/2009 3:36:42 PM | Computer Name = User-PC | Source = MCUpdate | ID = 0
    Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

    Error - 7/24/2009 3:26:41 PM | Computer Name = User-PC | Source = MCUpdate | ID = 0
    Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

    [ System Events ]
    Error - 2/25/2011 12:13:32 PM | Computer Name = User-PC | Source = DCOM | ID = 10016
    Description =

    Error - 2/25/2011 12:13:32 PM | Computer Name = User-PC | Source = DCOM | ID = 10016
    Description =

    Error - 2/27/2011 6:42:56 PM | Computer Name = User-PC | Source = DCOM | ID = 10010
    Description =

    Error - 2/27/2011 7:17:27 PM | Computer Name = User-PC | Source = DCOM | ID = 10005
    Description =

    Error - 2/27/2011 7:17:27 PM | Computer Name = User-PC | Source = Service Control Manager | ID = 7009
    Description =

    Error - 2/27/2011 7:17:27 PM | Computer Name = User-PC | Source = Service Control Manager | ID = 7000
    Description =

    Error - 2/27/2011 7:25:11 PM | Computer Name = User-PC | Source = Service Control Manager | ID = 7006
    Description =

    Error - 2/28/2011 1:27:35 PM | Computer Name = User-PC | Source = Service Control Manager | ID = 7030
    Description =

    Error - 2/28/2011 1:30:24 PM | Computer Name = User-PC | Source = Service Control Manager | ID = 7030
    Description =

    Error - 2/28/2011 1:32:27 PM | Computer Name = User-PC | Source = Service Control Manager | ID = 7030
    Description =


    < End of report >






    ALL DONE. PHEW.
     
  18. Broni

    Broni Malware Annihilator Posts: 52,911   +344

    Good :)

    Just in case, you missed it, read my reply #8 while I'll review your logs.
     
  19. karol3

    karol3 TS Rookie Topic Starter Posts: 34

    thx.

    heres the reply to your #8 post:

    I cant upload that virus because its in the quarantine area, should I restore the virus and then upload it from the original folder? if i restore the infected file will it re infect my computer?
     
  20. Broni

    Broni Malware Annihilator Posts: 52,911   +344

    Feel free to reinstall your AVG at any time.

    1. Update your Java version here: http://www.java.com/en/download/installed.jsp

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    2. Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it to its own folder
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.

    =======================================================================

    Run OTL
    • Under the Custom Scans/Fixes box at the bottom, paste in the following

      Code:
      :OTL
      IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
      IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
      O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
      O2 - BHO: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found.
      O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
      O3 - HKU\S-1-5-21-2158934232-3957428742-2026527031-1000\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
      O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get.../ultrashim.cab (Reg Error: Key error.)
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
      O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
      [8 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
      [7 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
      @Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:5C321E34
      @Alternate Data Stream - 508 bytes -> C:\ProgramData\TEMP:05EE1EEF
      @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:AC6124CA
      
      
      :Services
      
      :Reg
      
      :Files
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
      
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    ======================================================================

    Last scans....

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.


    2. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    3. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • IMPORTANT! UN-check Remove found threats
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
     
  21. Broni

    Broni Malware Annihilator Posts: 52,911   +344

    Leave it alone.
     
  22. karol3

    karol3 TS Rookie Topic Starter Posts: 34

    ok will do those soon.
     
  23. karol3

    karol3 TS Rookie Topic Starter Posts: 34

    OTL LOG:

    All processes killed
    ========== OTL ==========
    Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found.
    Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\{A3BC75A2-1F87-4686-AA43-5347D756017C} not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A3BC75A2-1F87-4686-AA43-5347D756017C}\ not found.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully.
    Registry value HKEY_USERS\S-1-5-21-2158934232-3957428742-2026527031-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{A057A204-BACC-4D26-9990-79A187E2698E} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}\ not found.
    Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
    C:\Windows\Downloaded Program Files\erma.inf moved successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
    C:\Windows\Downloaded Program Files\gp.inf not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.
    C:\Windows\System32\SETE86.tmp deleted successfully.
    C:\Windows\System32\tmp3A0.tmp deleted successfully.
    C:\Windows\System32\tmp3A3.tmp deleted successfully.
    C:\Windows\System32\tmp41C4.tmp deleted successfully.
    C:\Windows\System32\tmp41C5.tmp deleted successfully.
    C:\Windows\System32\tmp46F.tmp deleted successfully.
    C:\Windows\System32\tmp478A.tmp deleted successfully.
    C:\Windows\System32\tmp479B.tmp deleted successfully.
    C:\Windows\1C4551A64743409391E41477CD655043.TMP\WiseCustomCalla.dll deleted successfully.
    C:\Windows\1C4551A64743409391E41477CD655043.TMP folder deleted successfully.
    C:\Windows\6833245EDD86479A882A8360D62C8194.TMP\WiseCustomCalla.dll deleted successfully.
    C:\Windows\6833245EDD86479A882A8360D62C8194.TMP folder deleted successfully.
    C:\Windows\A7E07C2B2220441587E3784D5814BC93.TMP\WiseCustomCalla.dll deleted successfully.
    C:\Windows\A7E07C2B2220441587E3784D5814BC93.TMP folder deleted successfully.
    C:\Windows\DD1865F0AD7340FBB23E1822E02396FF.TMP\WiseCustomCalla.dll deleted successfully.
    C:\Windows\DD1865F0AD7340FBB23E1822E02396FF.TMP folder deleted successfully.
    C:\Windows\E4D153288C89484BB9AAF5BE9EA6D01C.TMP\WiseCustomCalla.dll deleted successfully.
    C:\Windows\E4D153288C89484BB9AAF5BE9EA6D01C.TMP folder deleted successfully.
    C:\Windows\F579118563414E21A47F41B57AC749B5.TMP\WiseCustomCalla.dll deleted successfully.
    C:\Windows\F579118563414E21A47F41B57AC749B5.TMP folder deleted successfully.
    C:\Windows\msdownld.tmp folder deleted successfully.
    ADS C:\ProgramData\TEMP:5C321E34 deleted successfully.
    ADS C:\ProgramData\TEMP:05EE1EEF deleted successfully.
    ADS C:\ProgramData\TEMP:AC6124CA deleted successfully.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 67 bytes
    ->Flash cache emptied: 56502 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: User
    ->Temp folder emptied: 1470651 bytes
    ->Temporary Internet Files folder emptied: 3094836 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 69328394 bytes
    ->Flash cache emptied: 25625 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 11752595 bytes

    Total Files Cleaned = 82.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: Public

    User: User
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.22.2 log created on 03012011_185556

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...





    Coming up:


    Security Check
    TFC
    ESET
     
  24. karol3

    karol3 TS Rookie Topic Starter Posts: 34

    Security check log:

    Results of screen317's Security Check version 0.99.7
    Windows Vista Service Pack 2 (UAC is disabled!)
    Internet Explorer 8
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Enabled!
    WMI entry may not exist for antivirus; attempting automatic update.
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Malwarebytes' Anti-Malware
    CCleaner
    Java(TM) 6 Update 22
    Adobe Flash Player 10.2.152.26
    Adobe Reader X
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Spybot Teatimer.exe is disabled!
    ``````````End of Log````````````
     
  25. karol3

    karol3 TS Rookie Topic Starter Posts: 34

    TFC LOG:

    Getting user folders.

    Stopping running processes.

    Emptying Temp folders.


    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: User
    ->Temp folder emptied: 32882 bytes
    ->Temporary Internet Files folder emptied: 37294 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 17190984 bytes
    ->Flash cache emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 54015 bytes
    %systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 741 bytes

    Emptying RecycleBin. Do not interrupt.

    RecycleBin emptied: 0 bytes
    Process complete!

    Total Files Cleaned = 17.00 mb
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...