also @ TechSpot: Microsoft wants Xbox to be the entertainment hub for all your devices

TechSpot

[Solved] Need help removing System-Check malware virus

Discussion in 'Virus and Malware Removal' started by res0jh1y2, Jan 2, 2012.

  1. res0jh1y2 Newcomer, in training

    OTL Log part 2 of 2

    ========== Files - Modified Within 30 Days ==========

    [2012/01/05 22:41:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4021511835-731674042-3818716740-1000UA.job
    [2012/01/05 22:36:41 | 000,002,305 | ---- | M] () -- C:\Users\OWNER\Application Data\Microsoft\Internet Explorer\Quick Launch\Safari.lnk
    [2012/01/05 22:35:19 | 000,001,989 | ---- | M] () -- C:\Users\OWNER\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
    [2012/01/05 22:34:51 | 000,000,949 | ---- | M] () -- C:\Users\OWNER\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk
    [2012/01/05 22:10:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2012/01/05 22:07:08 | 000,614,692 | ---- | M] () -- C:\Windows\System32\perfh009.dat
    [2012/01/05 22:07:08 | 000,108,654 | ---- | M] () -- C:\Windows\System32\perfc009.dat
    [2012/01/05 22:01:42 | 000,000,374 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics
    [2012/01/05 22:01:24 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2012/01/05 22:01:23 | 000,004,176 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
    [2012/01/05 22:01:23 | 000,004,176 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
    [2012/01/05 22:01:16 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2012/01/05 22:01:12 | 3487,309,824 | -HS- | M] () -- C:\hiberfil.sys
    [2012/01/05 21:36:50 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\OWNER\Desktop\OTL.exe
    [2012/01/04 19:48:22 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
    [2012/01/02 16:31:26 | 000,002,032 | ---- | M] () -- C:\Users\OWNER\AppData\Local\d3d9caps.dat
    [2012/01/01 18:42:00 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
    [2011/12/31 17:54:39 | 000,517,728 | ---- | M] () -- C:\Users\OWNER\Documents\NewYearWish2012.pdf
    [2011/12/31 17:54:06 | 000,368,640 | ---- | M] () -- C:\Users\OWNER\Documents\NewYearWish2012.pdf.pra
    [2011/12/28 19:29:06 | 000,003,120 | ---- | M] () -- C:\Windows\System32\ALLFSAF8a.ocx
    [2011/12/28 10:52:24 | 002,236,845 | ---- | M] () -- C:\Users\OWNER\Documents\DSC00012.JPG
    [2011/12/28 10:52:02 | 002,205,667 | ---- | M] () -- C:\Users\OWNER\Documents\DSC00011.JPG
    [2011/12/28 10:51:10 | 001,901,949 | ---- | M] () -- C:\Users\OWNER\Documents\DSC00010.JPG
    [2011/12/28 10:50:58 | 001,850,996 | ---- | M] () -- C:\Users\OWNER\Documents\DSC00009.JPG
    [2011/12/28 10:50:24 | 002,089,400 | ---- | M] () -- C:\Users\OWNER\Documents\DSC00008.JPG
    [2011/12/28 10:50:10 | 002,354,554 | ---- | M] () -- C:\Users\OWNER\Documents\DSC00007.JPG
    [2011/12/28 10:49:44 | 002,299,025 | ---- | M] () -- C:\Users\OWNER\Documents\DSC00006.JPG
    [2011/12/27 07:41:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4021511835-731674042-3818716740-1000Core.job
    [2011/12/26 16:29:41 | 000,121,344 | ---- | M] () -- C:\Users\OWNER\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/12/18 17:12:51 | 000,513,032 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
    [2011/12/17 09:24:16 | 000,330,034 | ---- | M] () -- C:\Users\OWNER\Documents\Daniela_12_Birthday2011.pdf
    [2011/12/10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

    ========== Files Created - No Company Name ==========

    [2012/01/05 22:35:19 | 000,001,989 | ---- | C] () -- C:\Users\OWNER\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
    [2012/01/05 22:35:03 | 000,002,305 | ---- | C] () -- C:\Users\OWNER\Application Data\Microsoft\Internet Explorer\Quick Launch\Safari.lnk
    [2012/01/05 22:34:51 | 000,000,949 | ---- | C] () -- C:\Users\OWNER\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk
    [2012/01/05 21:57:55 | 000,001,743 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
    [2012/01/05 21:57:55 | 000,001,630 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
    [2012/01/05 21:57:55 | 000,001,589 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
    [2012/01/05 21:57:55 | 000,000,944 | ---- | C] () -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
    [2012/01/05 21:57:55 | 000,000,915 | ---- | C] () -- C:\Users\OWNER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
    [2012/01/05 21:57:55 | 000,000,604 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live.lnk
    [2012/01/04 19:38:12 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
    [2012/01/04 19:38:12 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
    [2012/01/04 19:38:12 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
    [2012/01/04 19:38:12 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
    [2012/01/04 19:38:12 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
    [2012/01/02 18:07:13 | 3487,309,824 | -HS- | C] () -- C:\hiberfil.sys
    [2012/01/02 18:07:13 | 3487,309,824 | -HS- | C] () -- \hiberfil.sys
    [2011/12/31 17:54:37 | 000,517,728 | ---- | C] () -- C:\Users\OWNER\Documents\NewYearWish2012.pdf
    [2011/12/31 17:54:06 | 000,368,640 | ---- | C] () -- C:\Users\OWNER\Documents\NewYearWish2012.pdf.pra
    [2011/12/29 11:18:43 | 002,354,554 | ---- | C] () -- C:\Users\OWNER\Documents\DSC00007.JPG
    [2011/12/29 11:18:43 | 002,299,025 | ---- | C] () -- C:\Users\OWNER\Documents\DSC00006.JPG
    [2011/12/29 11:18:43 | 002,236,845 | ---- | C] () -- C:\Users\OWNER\Documents\DSC00012.JPG
    [2011/12/29 11:18:43 | 002,205,667 | ---- | C] () -- C:\Users\OWNER\Documents\DSC00011.JPG
    [2011/12/29 11:18:43 | 002,089,400 | ---- | C] () -- C:\Users\OWNER\Documents\DSC00008.JPG
    [2011/12/29 11:18:43 | 001,901,949 | ---- | C] () -- C:\Users\OWNER\Documents\DSC00010.JPG
    [2011/12/29 11:18:43 | 001,850,996 | ---- | C] () -- C:\Users\OWNER\Documents\DSC00009.JPG
    [2011/12/28 19:29:06 | 000,003,120 | ---- | C] () -- C:\Windows\System32\ALLFSAF8a.ocx
    [2011/12/17 09:20:08 | 000,330,034 | ---- | C] () -- C:\Users\OWNER\Documents\Daniela_12_Birthday2011.pdf
    [2011/10/15 00:54:52 | 000,321,856 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe
    [2010/12/30 20:11:35 | 000,504,108 | ---- | C] () -- C:\Users\OWNER\AppData\Local\rx_image32.Cache
    [2010/12/19 21:42:23 | 000,000,106 | ---- | C] () -- C:\Windows\VaultMediaClient.INI
    [2010/08/29 14:26:20 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
    [2010/05/19 19:47:37 | 000,139,264 | ---- | C] () -- C:\Windows\System32\gswin32c.exe
    [2009/12/29 19:56:57 | 000,000,165 | ---- | C] () -- C:\Windows\QUICKEN.INI
    [2009/11/17 20:21:04 | 000,000,133 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
    [2009/11/15 07:54:10 | 000,057,344 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
    [2009/11/13 11:42:54 | 000,000,094 | ---- | C] () -- C:\Windows\biblesuite1.ini
    [2009/11/13 11:42:54 | 000,000,088 | ---- | C] () -- C:\Windows\bibsuitesavers.ini
    [2009/11/13 11:42:54 | 000,000,031 | ---- | C] () -- C:\Windows\bibaudiosuite.ini
    [2009/10/17 06:32:00 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
    [2009/10/17 06:32:00 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
    [2009/08/03 14:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
    [2009/08/03 14:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
    [2009/04/26 16:08:24 | 000,000,256 | ---- | C] () -- C:\Windows\System32\pool.bin
    [2008/12/04 19:37:52 | 000,000,056 | ---- | C] () -- C:\Windows\System32\ezsidmv.dat
    [2008/09/25 15:01:54 | 000,339,968 | ---- | C] () -- C:\Windows\System32\pythoncom25.dll
    [2008/09/25 15:01:54 | 000,114,688 | ---- | C] () -- C:\Windows\System32\pywintypes25.dll
    [2008/08/21 20:30:42 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
    [2008/06/16 13:47:46 | 000,000,000 | ---- | C] () -- C:\Windows\System32\px.ini
    [2008/04/23 19:21:52 | 000,074,608 | ---- | C] () -- C:\Windows\TrueInstall.exe
    [2008/03/26 18:56:36 | 000,096,577 | ---- | C] () -- C:\Windows\hpqins16.dat
    [2008/03/10 18:20:16 | 000,002,026 | ---- | C] () -- C:\Windows\TLTitleData.ini
    [2008/03/10 18:19:46 | 000,086,870 | ---- | C] () -- C:\Windows\System32\BerlitzSCR.dat
    [2008/03/02 15:02:51 | 000,004,735 | ---- | C] () -- C:\Users\OWNER\AppData\Local\Tescan002.rtf
    [2008/01/26 21:21:40 | 000,000,093 | ---- | C] () -- C:\Users\OWNER\AppData\Local\fusioncache.dat
    [2007/12/31 23:41:45 | 018,082,864 | ---- | C] () -- C:\Users\OWNER\AppData\Local\rx_image.Cache
    [2007/12/31 23:41:45 | 001,359,660 | ---- | C] () -- C:\Users\OWNER\AppData\Local\rx_audio.Cache
    [2007/10/14 14:11:44 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
    [2007/10/07 11:28:33 | 000,993,216 | ---- | C] () -- C:\Windows\System32\DVC.EXE
    [2007/10/07 11:28:33 | 000,167,424 | ---- | C] () -- C:\Windows\System32\lame_enc.dll
    [2007/10/07 11:28:32 | 000,086,016 | ---- | C] () -- C:\Windows\System32\DVResampleru.dll
    [2007/10/07 08:20:08 | 000,194,248 | ---- | C] () -- C:\Windows\System32\LTRFD13n.DLL
    [2007/10/07 08:14:54 | 000,196,096 | ---- | C] () -- C:\Windows\System32\macd32.dll
    [2007/10/07 08:14:54 | 000,138,752 | ---- | C] () -- C:\Windows\System32\mase32.dll
    [2007/10/07 08:14:54 | 000,136,192 | ---- | C] () -- C:\Windows\System32\mamc32.dll
    [2007/10/07 08:14:54 | 000,057,856 | ---- | C] () -- C:\Windows\System32\masd32.dll
    [2007/10/07 08:14:54 | 000,027,648 | ---- | C] () -- C:\Windows\System32\ma32.dll
    [2007/10/06 15:50:45 | 000,348,160 | ---- | C] () -- C:\Windows\System32\cdga.dll
    [2007/10/06 12:48:22 | 000,148,935 | ---- | C] () -- C:\Windows\hpoins19.dat
    [2007/10/06 12:46:42 | 000,026,952 | ---- | C] () -- C:\Windows\hpomdl19.dat
    [2007/10/06 11:41:10 | 000,404,480 | ---- | C] () -- C:\Windows\System32\libmplayer.dll
    [2007/10/06 11:41:10 | 000,200,704 | ---- | C] () -- C:\Windows\System32\TomsMoComp_ff.dll
    [2007/10/06 11:41:10 | 000,114,688 | ---- | C] () -- C:\Windows\System32\libmpeg2_ff.dll
    [2007/10/06 07:27:01 | 000,121,344 | ---- | C] () -- C:\Users\OWNER\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2007/10/05 22:00:24 | 000,000,000 | RHS- | C] () -- \MSDOS.SYS
    [2007/10/05 22:00:24 | 000,000,000 | RHS- | C] () -- \IO.SYS
    [2007/10/05 21:59:06 | 000,000,011 | ---- | C] () -- C:\Windows\VSWizard.ini
    [2007/09/29 09:08:05 | 000,008,192 | R-S- | C] () -- \BOOTSECT.BAK
    [2007/09/29 09:08:04 | 000,333,257 | RHS- | C] () -- \bootmgr
    [2007/09/29 08:01:51 | 000,024,576 | ---- | C] () -- C:\Windows\System32\LSIReg.dll
    [2007/09/28 17:31:20 | 000,002,032 | ---- | C] () -- C:\Users\OWNER\AppData\Local\d3d9caps.dat
    [2006/11/02 07:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
    [2006/11/02 07:47:37 | 000,513,032 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
    [2006/11/02 07:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
    [2006/11/02 05:33:01 | 000,614,692 | ---- | C] () -- C:\Windows\System32\perfh009.dat
    [2006/11/02 05:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
    [2006/11/02 05:33:01 | 000,108,654 | ---- | C] () -- C:\Windows\System32\perfc009.dat
    [2006/11/02 05:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
    [2006/11/02 05:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
    [2006/11/02 05:23:09 | 000,000,121 | ---- | C] () -- \AUTOEXEC.BAT
    [2006/11/02 03:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
    [2006/11/02 03:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
    [2006/11/02 02:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
    [2006/11/02 02:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
    [2006/11/02 01:25:08 | 000,000,010 | ---- | C] () -- \config.sys
    [2003/05/31 19:43:00 | 000,005,632 | ---- | C] () -- C:\Windows\TrueProcess.exe

    ========== LOP Check ==========

    [2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Application Data
    [2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Desktop
    [2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Documents
    [2007/12/31 15:18:07 | 000,000,000 | ---D | M] -- C:\Users\All Users\eSellerate
    [2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Favorites
    [2011/12/01 19:46:43 | 000,000,000 | ---D | M] -- C:\Users\All Users\GARMIN
    [2009/10/21 06:14:22 | 000,000,000 | ---D | M] -- C:\Users\All Users\Kiwee Toolbar2
    [2009/01/18 18:16:18 | 000,000,000 | ---D | M] -- C:\Users\All Users\Nova Development
    [2010/05/19 19:47:57 | 000,000,000 | ---D | M] -- C:\Users\All Users\OCRTemp
    [2007/10/07 09:31:16 | 000,000,000 | ---D | M] -- C:\Users\All Users\Pinnacle
    [2007/10/07 09:31:38 | 000,000,000 | ---D | M] -- C:\Users\All Users\Pinnacle Studio
    [2011/03/10 11:34:06 | 000,000,000 | ---D | M] -- C:\Users\All Users\Radialpoint
    [2008/01/26 21:21:17 | 000,000,000 | ---D | M] -- C:\Users\All Users\SmartSound Software Inc
    [2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Start Menu
    [2006/11/02 08:02:04 | 000,000,000 | -HSD | M] -- C:\Users\All Users\Templates
    [2010/12/30 19:58:18 | 000,000,000 | ---D | M] -- C:\Users\All Users\Uninstall
    [2008/03/15 08:18:49 | 000,000,000 | ---D | M] -- C:\Users\All Users\Windows Home Server
    [2012/01/01 18:08:17 | 000,000,000 | ---D | M] -- C:\Users\All Users\WindowsSearch
    [2011/01/01 11:40:59 | 000,000,000 | ---D | M] -- C:\Users\All Users\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    [2006/11/02 06:18:34 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData
    [2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\Users\Default\Application Data
    [2006/11/02 05:23:35 | 000,000,000 | R--D | M] -- C:\Users\Default\Desktop
    [2006/11/02 08:02:03 | 000,000,000 | R--D | M] -- C:\Users\Default\Documents
    [2006/11/02 05:23:35 | 000,000,000 | R--D | M] -- C:\Users\Default\Downloads
    [2006/11/02 05:23:35 | 000,000,000 | R--D | M] -- C:\Users\Default\Favorites
    [2006/11/02 05:23:35 | 000,000,000 | R--D | M] -- C:\Users\Default\Links
    [2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\Users\Default\Local Settings
    [2006/11/02 05:23:35 | 000,000,000 | R--D | M] -- C:\Users\Default\Music
    [2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\Users\Default\My Documents
    [2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\Users\Default\NetHood
    [2006/11/02 05:23:35 | 000,000,000 | R--D | M] -- C:\Users\Default\Pictures
    [2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\Users\Default\PrintHood
    [2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\Users\Default\Recent
    [2006/11/02 05:23:35 | 000,000,000 | ---D | M] -- C:\Users\Default\Saved Games
    [2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\Users\Default\SendTo
    [2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\Users\Default\Start Menu
    [2006/11/02 08:02:03 | 000,000,000 | -HSD | M] -- C:\Users\Default\Templates
    [2007/10/07 08:16:30 | 000,000,000 | R--D | M] -- C:\Users\Default\Videos
    [2008/03/03 19:53:28 | 000,000,000 | ---D | M] -- C:\Users\OWNER\AppData
    [2007/09/28 17:31:20 | 000,000,000 | -HSD | M] -- C:\Users\OWNER\Application Data
    [2012/01/05 22:31:19 | 000,000,000 | ---D | M] -- C:\Users\OWNER\Audio Books
    [2010/10/12 19:45:19 | 000,000,000 | R--D | M] -- C:\Users\OWNER\Contacts
    [2007/09/28 17:31:20 | 000,000,000 | -HSD | M] -- C:\Users\OWNER\Cookies
    [2012/01/05 22:44:28 | 000,000,000 | R--D | M] -- C:\Users\OWNER\Desktop
    [2012/01/05 22:46:01 | 000,000,000 | R--D | M] -- C:\Users\OWNER\Documents
    [2012/01/05 22:44:28 | 000,000,000 | R--D | M] -- C:\Users\OWNER\Downloads
    [2011/02/13 08:43:15 | 000,000,000 | R--D | M] -- C:\Users\OWNER\Favorites
    [2007/10/05 20:02:56 | 000,000,000 | R--D | M] -- C:\Users\OWNER\Links
    [2007/09/28 17:31:20 | 000,000,000 | -HSD | M] -- C:\Users\OWNER\Local Settings
    [2011/01/16 09:38:10 | 000,000,000 | R--D | M] -- C:\Users\OWNER\Music
    [2007/09/28 17:31:20 | 000,000,000 | -HSD | M] -- C:\Users\OWNER\My Documents
    [2007/09/28 17:31:20 | 000,000,000 | -HSD | M] -- C:\Users\OWNER\NetHood
    [2011/12/29 11:19:53 | 000,000,000 | R--D | M] -- C:\Users\OWNER\Pictures
    [2007/09/28 17:31:20 | 000,000,000 | -HSD | M] -- C:\Users\OWNER\PrintHood
    [2007/09/28 17:31:20 | 000,000,000 | -HSD | M] -- C:\Users\OWNER\Recent
    [2009/11/15 08:33:48 | 000,000,000 | ---D | M] -- C:\Users\OWNER\Ringtones
    [2007/10/06 14:36:24 | 000,000,000 | R--D | M] -- C:\Users\OWNER\Saved Games
    [2007/10/05 20:02:56 | 000,000,000 | R--D | M] -- C:\Users\OWNER\Searches
    [2007/09/28 17:31:20 | 000,000,000 | -HSD | M] -- C:\Users\OWNER\SendTo
    [2007/09/28 17:31:20 | 000,000,000 | -HSD | M] -- C:\Users\OWNER\Start Menu
    [2007/09/28 17:31:20 | 000,000,000 | -HSD | M] -- C:\Users\OWNER\Templates
    [2012/01/04 18:51:51 | 000,000,000 | ---D | M] -- C:\Users\OWNER\Tracing
    [2011/11/22 08:00:29 | 000,000,000 | R--D | M] -- C:\Users\OWNER\Videos
    [2012/01/04 19:53:33 | 000,000,000 | ---D | M] -- C:\Users\Public\AppData
    [2012/01/02 18:09:12 | 000,000,000 | R--D | M] -- C:\Users\Public\Desktop
    [2007/11/18 14:43:44 | 000,000,000 | R--D | M] -- C:\Users\Public\Documents
    [2006/11/02 07:50:50 | 000,000,000 | R--D | M] -- C:\Users\Public\Downloads
    [2006/11/02 05:23:35 | 000,000,000 | R--D | M] -- C:\Users\Public\Favorites
    [2007/11/18 11:55:54 | 000,000,000 | R--D | M] -- C:\Users\Public\Music
    [2007/10/07 08:16:30 | 000,000,000 | ---D | M] -- C:\Users\Public\My Documents
    [2010/10/24 19:54:23 | 000,000,000 | R--D | M] -- C:\Users\Public\Pictures
    [2010/08/16 18:07:09 | 000,000,000 | R--D | M] -- C:\Users\Public\Recorded TV
    [2007/10/07 08:16:30 | 000,000,000 | R--D | M] -- C:\Users\Public\Videos
    [2006/11/02 06:18:34 | 000,000,000 | ---D | M] -- C:\Users\UpdatusUser\AppData
    [2011/12/28 20:54:36 | 000,000,000 | -HSD | M] -- C:\Users\UpdatusUser\Application Data
    [2011/12/28 20:54:37 | 000,000,000 | ---D | M] -- C:\Users\UpdatusUser\Contacts
    [2011/12/28 20:54:36 | 000,000,000 | -HSD | M] -- C:\Users\UpdatusUser\Cookies
    [2006/11/02 05:23:35 | 000,000,000 | R--D | M] -- C:\Users\UpdatusUser\Desktop
    [2011/12/28 20:54:36 | 000,000,000 | R--D | M] -- C:\Users\UpdatusUser\Documents
    [2006/11/02 05:23:35 | 000,000,000 | R--D | M] -- C:\Users\UpdatusUser\Downloads
    [2006/11/02 05:23:35 | 000,000,000 | R--D | M] -- C:\Users\UpdatusUser\Favorites
    [2006/11/02 05:23:35 | 000,000,000 | R--D | M] -- C:\Users\UpdatusUser\Links
    [2011/12/28 20:54:36 | 000,000,000 | -HSD | M] -- C:\Users\UpdatusUser\Local Settings
    [2006/11/02 05:23:35 | 000,000,000 | R--D | M] -- C:\Users\UpdatusUser\Music
    [2011/12/28 20:54:36 | 000,000,000 | -HSD | M] -- C:\Users\UpdatusUser\My Documents
    [2011/12/28 20:54:36 | 000,000,000 | -HSD | M] -- C:\Users\UpdatusUser\NetHood
    [2006/11/02 05:23:35 | 000,000,000 | R--D | M] -- C:\Users\UpdatusUser\Pictures
    [2011/12/28 20:54:36 | 000,000,000 | -HSD | M] -- C:\Users\UpdatusUser\PrintHood
    [2011/12/28 20:54:36 | 000,000,000 | -HSD | M] -- C:\Users\UpdatusUser\Recent
    [2006/11/02 05:23:35 | 000,000,000 | ---D | M] -- C:\Users\UpdatusUser\Saved Games
    [2011/12/28 20:54:37 | 000,000,000 | ---D | M] -- C:\Users\UpdatusUser\Searches
    [2011/12/28 20:54:36 | 000,000,000 | -HSD | M] -- C:\Users\UpdatusUser\SendTo
    [2011/12/28 20:54:36 | 000,000,000 | -HSD | M] -- C:\Users\UpdatusUser\Start Menu
    [2011/12/28 20:54:36 | 000,000,000 | -HSD | M] -- C:\Users\UpdatusUser\Templates
    [2007/10/07 08:16:30 | 000,000,000 | R--D | M] -- C:\Users\UpdatusUser\Videos
    [2012/01/05 21:58:58 | 000,032,560 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========



    ========== Custom Scans ==========


    < %SYSTEMDRIVE%\*.* >
    [2007/10/07 09:38:18 | 000,000,121 | ---- | M] () -- C:\AUTOEXEC.BAT
    [2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () -- C:\bootmgr
    [2007/09/29 09:08:05 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
    [2012/01/04 19:53:32 | 000,013,558 | ---- | M] () -- C:\ComboFix.txt
    [2006/09/18 16:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
    [2009/11/15 07:53:52 | 000,087,497 | ---- | M] () -- C:\Cucu_Video_log.txt
    [2012/01/05 22:01:12 | 3487,309,824 | -HS- | M] () -- C:\hiberfil.sys
    [2007/10/05 22:00:24 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
    [2008/03/04 20:41:08 | 000,015,215 | ---- | M] () -- C:\mombi.log
    [2007/10/05 22:00:24 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
    [2009/11/24 15:33:05 | 000,000,549 | ---- | M] () -- C:\NTDClient.log
    [2012/01/05 22:01:11 | 947,912,703 | -HS- | M] () -- C:\pagefile.sys
    [2008/12/06 10:33:36 | 000,000,000 | ---- | M] () -- C:\plx_proxy.log
    [2007/09/28 17:58:06 | 000,000,206 | ---- | M] () -- C:\realtek.log
    [2007/09/28 17:58:06 | 000,000,420 | ---- | M] () -- C:\RHDSetup.log
    [2007/10/05 22:27:49 | 000,916,162 | ---- | M] () -- C:\TB.log

    < %systemroot%\Fonts\*.com >
    [2006/11/02 07:37:12 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
    [2006/11/02 07:37:12 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
    [2006/11/02 07:37:12 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
    [2009/10/17 07:04:01 | 000,037,665 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont

    < %systemroot%\Fonts\*.dll >

    < %systemroot%\Fonts\*.ini >
    [2006/09/18 16:37:34 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini

    < %systemroot%\Fonts\*.ini2 >

    < %systemroot%\Fonts\*.exe >

    < %systemroot%\system32\spool\prtprocs\w32x86\*.* >
    [2008/01/19 02:34:28 | 000,089,600 | ---- | M] (Hewlett-Packard Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
    [2006/11/02 07:35:48 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
    [2006/10/26 18:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll

    < %systemroot%\REPAIR\*.bak1 >

    < %systemroot%\REPAIR\*.ini >

    < %systemroot%\system32\*.jpg >

    < %systemroot%\*.jpg >

    < %systemroot%\*.png >

    < %systemroot%\*.scr >
    [2005/02/24 16:21:54 | 000,757,760 | ---- | M] (Frontier Groove Inc.) -- C:\Windows\AZVENA.scr
    [2011/05/13 14:42:24 | 000,302,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

    < %systemroot%\*._sy >

    < %APPDATA%\Adobe\Update\*.* >

    < %ALLUSERSPROFILE%\Favorites\*.* >

    < %APPDATA%\Microsoft\*.* >

    < %PROGRAMFILES%\*.* >
    [2008/04/02 16:05:52 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini

    < %APPDATA%\Update\*.* >

    < %systemroot%\*. /mp /s >

    < %systemroot%\System32\config\*.sav >
    [2006/11/02 05:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
    [2006/11/02 05:34:05 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
    [2006/11/02 05:34:05 | 000,008,192 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
    [2006/11/02 05:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
    [2006/11/02 05:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV

    < %PROGRAMFILES%\bak. /s >

    < %systemroot%\system32\bak. /s >

    < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

    < %systemroot%\system32\config\systemprofile\*.dat /x >

    < %systemroot%\*.config >

    < %systemroot%\system32\*.db >
    [2007/09/13 16:26:26 | 000,641,024 | ---- | M] () -- C:\Windows\system32\NEROINSTAEC43759.DB

    < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
    [2012/01/05 22:34:51 | 000,000,082 | -HS- | M] () -- C:\Users\OWNER\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

    < %USERPROFILE%\Desktop\*.exe >
    [2012/01/05 21:36:50 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\OWNER\Desktop\OTL.exe

    < %PROGRAMFILES%\Common Files\*.* >

    < %systemroot%\*.src >

    < %systemroot%\install\*.* >

    < %systemroot%\system32\DLL\*.* >

    < %systemroot%\system32\HelpFiles\*.* >

    < %systemroot%\system32\rundll\*.* >

    < %systemroot%\winn32\*.* >

    < %systemroot%\Java\*.* >

    < %systemroot%\system32\test\*.* >

    < %systemroot%\system32\Rundll32\*.* >

    < %systemroot%\AppPatch\Custom\*.* >

    < %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

    < %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

    < %PROGRAMFILES%\Internet Explorer\*.tmp >

    < %PROGRAMFILES%\Internet Explorer\*.dat >

    < %USERPROFILE%\My Documents\*.exe >

    < %USERPROFILE%\*.exe >

    < %systemroot%\ADDINS\*.* >

    < %systemroot%\assembly\*.bak2 >

    < %systemroot%\Config\*.* >

    < %systemroot%\REPAIR\*.bak2 >

    < %systemroot%\SECURITY\Database\*.sdb /x >
    [2011/12/30 08:23:04 | 000,008,192 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.chk
    [2011/12/30 08:22:34 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edb.log
    [2008/04/02 16:04:39 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00001.jrs
    [2008/04/02 16:04:39 | 001,048,576 | ---- | M] () -- C:\Windows\SECURITY\Database\edbres00002.jrs
    [2011/12/30 08:22:34 | 001,056,768 | ---- | M] () -- C:\Windows\SECURITY\Database\tmp.edb

    < %systemroot%\SYSTEM\*.bak2 >

    < %systemroot%\Web\*.bak2 >

    < %systemroot%\Driver Cache\*.* >

    < %PROGRAMFILES%\Mozilla Firefox\0*.exe >

    < %ProgramFiles%\Microsoft Common\*.* >

    < %ProgramFiles%\TinyProxy. >

    < %USERPROFILE%\Favorites\*.url /x >
    [2010/12/30 19:56:03 | 000,000,402 | -HS- | M] () -- C:\Users\OWNER\Favorites\desktop.ini

    < %systemroot%\system32\*.bk >

    < %systemroot%\*.te >

    < %systemroot%\system32\system32\*.* >

    < %ALLUSERSPROFILE%\*.dat /x >
    [2010/05/04 19:51:04 | 000,004,211 | ---- | M] () -- C:\ProgramData\hpzinstall.log
    [2009/11/17 20:21:04 | 000,000,133 | ---- | M] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
    [2010/08/29 14:26:20 | 000,000,258 | RHS- | M] () -- C:\ProgramData\ntuser.pol

    < %systemroot%\system32\drivers\*.rmv >

    < dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

    < dir /b "%systemroot%\*.exe" | find /i " " /c >

    < %PROGRAMFILES%\Microsoft\*.* >

    < %systemroot%\System32\Wbem\proquota.exe >

    < %PROGRAMFILES%\Mozilla Firefox\*.dat >

    < %USERPROFILE%\Cookies\*.txt /x >

    < %SystemRoot%\system32\fonts\*.* >

    < %systemroot%\system32\winlog\*.* >

    < %systemroot%\system32\Language\*.* >

    < %systemroot%\system32\Settings\*.* >

    < %systemroot%\system32\*.quo >

    < %SYSTEMROOT%\AppPatch\*.exe >

    < %SYSTEMROOT%\inf\*.exe >

    < %SYSTEMROOT%\Installer\*.exe >

    < %systemroot%\system32\config\*.bak2 >

    < %systemroot%\system32\Computers\*.* >

    < %SystemRoot%\system32\Sound\*.* >

    < %SystemRoot%\system32\SpecialImg\*.* >

    < %SystemRoot%\system32\code\*.* >

    < %SystemRoot%\system32\draft\*.* >

    < %SystemRoot%\system32\MSSSys\*.* >

    < %ProgramFiles%\Javascript\*.* >

    < %systemroot%\pchealth\helpctr\System\*.exe /s >

    < %systemroot%\Web\*.exe >

    < %systemroot%\system32\msn\*.* >

    < %systemroot%\system32\*.tro >

    < %AppData%\Microsoft\Installer\msupdates\*.* >

    < %ProgramFiles%\Messenger\*.* >

    < %systemroot%\system32\systhem32\*.* >

    < %systemroot%\system\*.exe >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

    < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >


    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 76 bytes -> C:\Users\OWNER\Documents\Tosci Slideshow.dmss:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Users\OWNER\Documents\Tosci 04162009.dmss:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Users\OWNER\Documents\Slideshow2.dmsm:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Users\OWNER\Documents\Slideshow1.dmsm:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Users\OWNER\Documents\Slideshow0.dmsm:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Users\OWNER\Documents\Slideshow.dmsm:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Users\OWNER\Documents\Silvesto E Giuseppa.jwl:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Users\OWNER\Documents\Path of Daggers 261.wma:Roxio EMC Stream
    @Alternate Data Stream - 76 bytes -> C:\Users\OWNER\Documents\Andrea Del Principe Kylee kate Sargant - Buonanotte Amore.jwl:Roxio EMC Stream

    < End of report >
  2. res0jh1y2 Newcomer, in training

    Extras Log part 1 of 2

    OTL Extras logfile created on: 1/5/2012 10:46:58 PM - Run 1
    OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\OWNER\Desktop
    Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.25 Gb Total Physical Memory | 1.84 Gb Available Physical Memory | 56.79% Memory free
    8.05 Gb Paging File | 6.57 Gb Available in Paging File | 81.59% Paging File free
    Paging file location(s): c:\pagefile.sys 5000 6000 [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
    Drive C: | 465.76 Gb Total Space | 74.74 Gb Free Space | 16.05% Space Free | Partition Type: NTFS

    Computer Name: OWNER-PC-DEN | User Name: OWNER | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
    .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

    ========== Shell Spawning ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
    Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 1
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0
    "VistaSp1" = Reg Error: Unknown registry data type -- File not found
    "VistaSp2" = Reg Error: Unknown registry data type -- File not found

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    ========== Firewall Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1
    "DoNotAllowExceptions" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{0130B062-96C3-4C33-A11C-2F2F177838ED}" = rport=80 | protocol=6 | dir=out | app=c:\program files\common files\intuit\update service\intuitupdater.exe |
    "{057748BD-99E8-4A37-8803-DDD317307AF7}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{0626BB58-F604-4F34-9859-A6E1380B26A2}" = lport=63331 | protocol=6 | dir=in | name=windows live onecare |
    "{0E9EF908-ECAD-42F3-8A6D-8CE7C8CB51D5}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
    "{128696C8-B7CD-47A3-9B65-34F20388A45D}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{1D1F75DD-92DC-456E-9A5B-8F781F8B6A47}" = lport=10243 | protocol=6 | dir=in | app=system |
    "{1F4B6381-AB3F-4C12-8C37-F7EAF4D02EF2}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{20AF259C-BCD2-40A4-BE7D-BF6964C46775}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
    "{22B221DA-3F02-4082-BEDD-684E9D45AEA6}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{2A77E1E3-69D2-499F-9CB5-C2C75EC895FC}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{3071B60A-784C-4C07-9992-0831648085D8}" = rport=80 | protocol=6 | dir=out | app=c:\program files\common files\intuit\update service\intuitupdateservice.exe |
    "{335ABFBD-AD42-45A7-AC0B-E37A7055F175}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
    "{37FCDC00-F019-4BC4-BB4F-A5AC4E475D24}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
    "{3934E592-AD2E-405D-9AC9-F47BDECDACC4}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{3D3F49FB-5403-47C5-AE6A-0090869D0E99}" = lport=6331 | protocol=6 | dir=in | name=windows live onecare |
    "{417F9C36-291A-4F49-B398-2078EC27D7F9}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{41EC1B85-B455-4F3B-8EC1-9355E9C5E191}" = rport=10243 | protocol=6 | dir=out | app=system |
    "{45EF26A4-CDAA-4032-84F1-CCE5E5DD683A}" = lport=10243 | protocol=6 | dir=in | app=system |
    "{48C7FBB6-0E2E-4550-A884-2B1C5F60E961}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{4901E274-F86C-4043-A71D-BDD222D9F8AB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{52235340-A264-4493-8B56-1682EE64D55F}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
    "{5570ED42-21D8-4413-A966-DF5BDB47CF62}" = lport=10243 | protocol=6 | dir=in | app=system |
    "{59ABA3D9-98E5-42DB-A4EA-34F7B22D603E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{5ABE6C3F-F853-407B-8F9F-20BCEE8F36FF}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{615787A2-AD6C-46CF-80DC-EB1C22D1E289}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{64E54819-DB66-43E2-93BD-A6DF59C2F3A9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
    "{76A37A82-5744-4695-8C19-6B658EA094D6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{7949A94D-FE1F-4AF7-B55D-BE78BA7F8863}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{7ABC3DF2-827C-404E-BC7F-8520AA039224}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{7BA1D2B3-D6EA-4381-84CD-A79B0E3A33FF}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{7C230B74-2851-41FC-99F0-9B001B7FCEFD}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
    "{7D868EBE-3E1E-48AF-88E4-BD3B433E049D}" = lport=1900 | protocol=17 | dir=in | app=%programfiles%\zune\zune.exe |
    "{7F76ED14-4EFC-40F0-9F61-731E0AEA1B94}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{8AFA080E-27AD-430E-849A-E88548B96CDD}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{8D5C65E3-DF75-459E-9BAF-CFEA7076BF95}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
    "{8E04088E-2514-4915-AEF1-9CF2F550AE00}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{8FF1D550-81D8-4943-A41B-5349CFA76B32}" = rport=10243 | protocol=6 | dir=out | app=system |
    "{9A615BB6-0069-4070-83B3-B1B8C4AE717F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{9B40FC5C-A1BE-4471-B9A3-CF2E95B216D1}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{9C9F59C2-C58C-4379-9D40-5773E172D7C2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
    "{A1FAD785-2B6D-4ED9-861D-40357C903874}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{A242BAA8-9FDE-4BA0-A608-8C5FA88634F4}" = rport=2869 | protocol=6 | dir=out | app=system |
    "{A3AE8197-CD29-4620-964A-E9396EBCC4D4}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
    "{A737CFB2-AAE9-4461-8625-39952AB722AE}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{A7473AE4-5ABB-4A52-A934-0BB43E7E02F8}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{C6A6838B-6275-46E3-978D-2F661C6FF228}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{C9ACA28E-DDE7-4A00-9843-1CD5BCD5C66C}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
    "{CC3B5DFE-FE42-47F0-BD63-507928729D60}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{CD27DEF1-B01D-4F5B-881A-6CC9DEC0836D}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{CF95D667-0C63-4B72-8856-50C1298F3BF5}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
    "{D04FC068-4882-4640-A78F-9C14D3706895}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{DE1D34C9-DE61-4AF7-89E0-CEC5C2A7EF03}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{E19309FA-D981-4BFA-9E02-DE4F46EAA846}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
    "{E62A2600-2962-4814-BB2E-87D5C86DA525}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{E7AF5B55-8248-4132-96FA-A5FF0D8FC9E7}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{E7D24B76-375C-4146-9E52-C8E85644F0EF}" = rport=10243 | protocol=6 | dir=out | app=system |
    "{EADA1C34-B58A-4F88-9B69-8336FCC67DC4}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{EB13796E-AC28-4236-80AB-B02EEE4A7F40}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{F0759104-98C8-48BB-8A4B-324072320741}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{F726BD60-5376-4F97-BDE1-2B1D0BADECB3}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{FC94A511-89CF-48A6-936C-001A76A5490E}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{03FD5E72-273A-488F-B353-9E95BF2FF0E8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{0BC37EB9-5AC3-436A-90D8-5CCB0984ABA6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{0BFE5EE7-CFB4-4E4C-AD9C-1490E7BECE54}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{0D7723B6-6CD9-4E1B-ACC8-0068771FDF53}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
    "{1343B8B6-58B0-41D7-BF72-A40785D9A271}" = protocol=17 | dir=in | app=c:\program files\roxio\digital home 10\roxioupnpservice10.exe |
    "{1CCF2786-842A-4D18-8E56-309170B95073}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
    "{1DAF1323-2995-4752-A8A0-A0E7ACF98620}" = protocol=17 | dir=in | app=c:\program files\roxio\digital home 10\roxioupnpservice10.exe |
    "{1FDA763F-5382-4D50-AD1F-290B05D927B2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{23FEC879-11D2-491E-86FF-A2F9AF0D49E2}" = protocol=17 | dir=in | app=c:\program files\common files\roxio shared\10.0\sharedcom\roxliveshare10.exe |
    "{2C7A9DE5-56D5-4137-81AF-FEC139C57BA4}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{2CB98344-FD69-42F8-AEA4-95B021377ADB}" = protocol=17 | dir=in | app=c:\program files\turbotax\deluxe 2007\32bit\updatemgr.exe |
    "{2D41B30C-A44B-442D-88F9-22A5DCAC5ABE}" = protocol=6 | dir=in | app=c:\program files\common files\roxio shared\10.0\sharedcom\roxliveshare10.exe |
    "{2ECCC785-DD8F-474D-8EDC-7B308A339A42}" = protocol=17 | dir=in | app=c:\program files\common files\roxio shared\10.0\sharedcom\roxliveshare10.exe |
    "{379F6392-5C37-43D4-9E25-F5579C4246C2}" = protocol=17 | dir=in | app=c:\program files\common files\roxio shared\10.0\sharedcom\roxliveshare10.exe |
    "{3A8CB746-421E-4809-8A94-6CF14551BD36}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{41C1B19C-3643-4F09-831E-3FE496C689BC}" = protocol=17 | dir=in | app=c:\program files\pinnacle\studio 10\programs\pmsregisterfile.exe |
    "{43C3DAA5-AC9D-428B-AB56-75793849DCBE}" = protocol=6 | dir=out | app=system |
    "{456F0066-CEF6-4F55-BFA4-7834C91712D6}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
    "{46374AA3-A5A0-4E60-B608-25B22997DE70}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
    "{467AA821-A178-446F-907B-AA6AE8D3346A}" = protocol=6 | dir=out | app=system |
    "{49458302-4415-4FB7-B488-00FF4E1B3D27}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
    "{499FE795-653A-404B-B77B-9F4EAD2EBFF1}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{4B83154C-0682-4F0B-A45B-1F18F7B33CE0}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
    "{51A4B50A-05FD-40D2-85C6-F1E1905E50B5}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{51D4BC83-DA09-4BB9-A752-D59A182E81F6}" = protocol=6 | dir=out | app=%programfiles%\zune\zunenss.exe |
    "{53BF4EE2-D3F0-460E-BF57-22D47BD4503B}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{53EB8557-CA0C-4AA4-9AF5-76E9C576939A}" = protocol=17 | dir=in | app=c:\program files\roxio\digital home 10\roxioupnprenderer10.exe |
    "{5996B4E7-57F2-4445-9B59-640B050D22B2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{5AA25C1A-9F84-4797-88FB-2D808FC17AF3}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{5E4155F6-5B82-45A5-B1D4-7E13D6CCEEC7}" = protocol=17 | dir=out | app=%programfiles%\zune\zunenss.exe |
    "{6A16F458-D3FD-40FE-AECE-B6542CD8D93C}" = protocol=17 | dir=in | app=c:\program files\pinnacle\studio 10\programs\umi.exe |
    "{6C472D7B-C1A0-4A8B-AC6C-E7CB7BCB0556}" = protocol=17 | dir=in | app=c:\program files\verizon\vsp\servicepointservice.exe |
    "{6E4F7BC8-1332-44C8-935C-D32362B516D8}" = protocol=17 | dir=in | app=c:\users\owner\appdata\local\google\google talk plugin\googletalkplugin.dll |
    "{6ED4D756-212C-4778-9D14-25E1E8BF958B}" = protocol=6 | dir=in | app=c:\program files\roxio\digital home 10\roxioupnprenderer10.exe |
    "{6F9D34B2-B502-4EAC-B166-4D233DFFAD88}" = protocol=6 | dir=out | app=system |
    "{7051913A-4D23-47D8-BDE5-41A8589100C5}" = protocol=17 | dir=in | app=%programfiles%\zune\zunenss.exe |
    "{739F8EB0-B636-4C30-95A1-9308FE50A62F}" = protocol=6 | dir=in | app=c:\program files\common files\roxio shared\10.0\sharedcom\roxliveshare10.exe |
    "{78A76EF1-C003-4C16-9BCC-B5700400C978}" = protocol=6 | dir=in | app=c:\program files\pinnacle\studio 10\programs\rm.exe |
    "{82C5E88B-F181-4417-82C5-8618AA3199D5}" = protocol=6 | dir=out | app=%systemroot%\system32\wudfhost.exe |
    "{84210697-4E81-4759-A293-F7002635B926}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
    "{84FC653C-E5BB-4D58-9170-1DCD9FF3ECD9}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
    "{85050E8B-5FF1-4E20-A4BF-9D494BC66C1B}" = protocol=17 | dir=out | app=%programfiles%\zune\zunenss.exe |
    "{868A98C4-8010-4A23-AB49-BCCAB4AFA7F8}" = protocol=6 | dir=in | app=c:\users\owner\appdata\local\google\google talk plugin\googletalkplugin.dll |
    "{8701DFE1-45C5-44A1-A6E1-72CA01FDF247}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{87B0DAB8-25DA-43AB-BFC3-646F413AED77}" = protocol=6 | dir=in | app=c:\program files\turbotax\deluxe 2007\32bit\updatemgr.exe |
    "{907025F9-4076-48B1-A1C6-70D089A05397}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
    "{91A0D92E-AC56-43CB-BB16-AFC590F3F765}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{93ECBCC1-BA9C-4202-AE2E-B6BAFB02B384}" = protocol=6 | dir=in | app=%programfiles%\zune\zunenss.exe |
    "{953156DA-4440-41AF-8608-C4937EDCA99D}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
    "{9AC3E7E2-ECD9-4A02-9EDC-96E58DA48C27}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
    "{9AE4B073-E05F-4E7A-8DA0-0E3381E27C70}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{9EF3DB9E-F0A8-4B58-9E6C-D4A6DF8A9EF3}" = protocol=6 | dir=in | app=c:\program files\roxio\digital home 10\roxioupnprenderer10.exe |
    "{A466014A-860E-4803-868B-9266D87D2A23}" = protocol=6 | dir=in | app=c:\program files\roxio\digital home 10\roxioupnpservice10.exe |
    "{A4CF2F54-E0A9-467E-A10F-E390DF5C4594}" = protocol=6 | dir=in | app=c:\program files\pinnacle\studio 10\programs\studio.exe |
    "{A5972EC6-F28C-4C98-9582-E9A3CE6C8C2D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{A86F6848-732D-4AAF-9B2C-8FE0AA5B8662}" = protocol=6 | dir=out | app=system |
    "{AFA92881-DF1C-45CD-8FF1-6CF6FFF6EBDB}" = protocol=17 | dir=in | app=c:\program files\roxio\digital home 10\roxioupnpservice10.exe |
    "{B3B6F03B-7229-4752-B0C5-7D78890AC461}" = protocol=6 | dir=out | app=%systemroot%\system32\wudfhost.exe |
    "{B4D31F3C-238E-4A5B-A2E8-5C7E7A829750}" = dir=in | app=c:\program files\itunes\itunes.exe |
    "{B6EF933F-4758-4614-9949-FFB0CE935FB2}" = dir=in | app=c:\program files\skype\phone\skype.exe |
    "{BA47B61B-6A4C-43DB-8E7A-3F9E8FD4F466}" = protocol=6 | dir=in | app=c:\program files\turbotax\deluxe 2007\32bit\ttax.exe |
    "{BE513763-ADA8-4166-9259-1D0D76B5178B}" = protocol=17 | dir=in | app=c:\program files\pinnacle\studio 10\programs\rm.exe |
    "{BED40899-41AE-454D-A934-6685D183002C}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
    "{BFEB84FC-083E-4B51-89C9-AAD4CFB8F128}" = protocol=6 | dir=out | app=system |
    "{C06E8A8C-24FA-438D-BCF8-458FC89DE157}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{C25DB5EF-54E9-4D94-B91C-FA575363D5CA}" = protocol=17 | dir=in | app=c:\program files\pinnacle\studio 10\programs\studio.exe |
    "{CD283F75-5102-45F3-8F60-95649BFACDAF}" = protocol=17 | dir=in | app=c:\users\owner\appdata\local\google\google talk plugin\googletalkplugin.exe |
    "{D02194BA-ABED-43B7-A8D5-A8E72F47FE97}" = protocol=6 | dir=in | app=c:\program files\roxio\digital home 10\roxioupnpservice10.exe |
    "{D140EBF0-1341-4C65-998D-087BBFB8CE0A}" = protocol=6 | dir=out | app=%programfiles%\zune\zunenss.exe |
    "{D1F1B65C-D4F7-4040-A23E-20FB83F67762}" = protocol=6 | dir=out | app=system |
    "{D5E997FD-C2B6-4C87-ACDB-5F29E6251D18}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{DCA1D227-5DF6-4348-B836-CF760C235B77}" = protocol=17 | dir=in | app=%programfiles%\zune\zunenss.exe |
    "{E5804615-1199-4B6A-9EE3-FDC142D722AE}" = protocol=6 | dir=out | app=%systemroot%\system32\wudfhost.exe |
    "{F1AF71A8-5DBD-4E6D-A648-E89A673E719C}" = protocol=6 | dir=in | app=c:\program files\roxio\digital home 10\roxioupnpservice10.exe |
    "{F2A69896-3318-4198-AA97-C8A71CE4DE2C}" = protocol=6 | dir=in | app=%programfiles%\zune\zunenss.exe |
    "{F3C39E36-E7F4-495F-B902-0EA471EECDF2}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{F40A6641-1B3E-4744-9161-A15005D5FDF6}" = protocol=17 | dir=in | app=c:\program files\roxio\digital home 10\roxioupnprenderer10.exe |
    "{F801EF96-448E-46CC-9EBC-917D609D6A63}" = protocol=6 | dir=in | app=c:\users\owner\appdata\local\google\google talk plugin\googletalkplugin.exe |
    "{F829267D-F445-4F24-A666-0DCC783BB52C}" = protocol=6 | dir=in | app=c:\program files\pinnacle\studio 10\programs\pmsregisterfile.exe |
    "{F8A24608-45B3-4E68-B986-DEC3591B2808}" = protocol=17 | dir=in | app=c:\program files\turbotax\deluxe 2007\32bit\ttax.exe |
    "{F8F05C24-B33C-4E94-ACA1-66EBB487B9E0}" = protocol=6 | dir=in | app=c:\program files\pinnacle\studio 10\programs\umi.exe |
    "{FCCBF37A-1CFA-4B11-927F-35183BB212C5}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
    "{FCF53428-82B3-4973-95DC-3761E9CC43F2}" = protocol=6 | dir=in | app=c:\program files\common files\roxio shared\10.0\sharedcom\roxliveshare10.exe |
    "{FD791C01-09FB-40F9-A205-AF58C55FE78F}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
    "{FDB38BF3-432B-40C0-A00D-CDD5027181C2}" = protocol=6 | dir=in | app=c:\program files\verizon\vsp\servicepointservice.exe |
    "{FECC87AB-65C4-4E7C-9870-A4C89E35220E}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
    "TCP Query User{47979139-70A4-4A39-BAFE-8BA0F854E1E3}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
    "TCP Query User{4C515785-C349-40E4-8660-D4462D5AF4A3}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
    "TCP Query User{5383F590-75A1-4866-B4FB-175385430595}C:\program files\pinnacle\studio 10\programs\studio.exe" = protocol=6 | dir=in | app=c:\program files\pinnacle\studio 10\programs\studio.exe |
    "TCP Query User{97F28B83-26E9-4542-8E5B-DA6778E8C80D}C:\program files\verizon\verizon media manager\release\verizon media manager.exe" = protocol=6 | dir=in | app=c:\program files\verizon\verizon media manager\release\verizon media manager.exe |
    "UDP Query User{3437124A-267A-4551-9F60-0FDDC223DFA9}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
    "UDP Query User{96A4CCF4-EDBA-4DB0-94AE-5A6751BE9380}C:\program files\verizon\verizon media manager\release\verizon media manager.exe" = protocol=17 | dir=in | app=c:\program files\verizon\verizon media manager\release\verizon media manager.exe |
    "UDP Query User{E72A0FC3-52F2-48A2-8752-2E3EC234506E}C:\program files\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files\google\google earth\plugin\geplugin.exe |
    "UDP Query User{F9582E48-0A31-4900-A825-045033E76D27}C:\program files\pinnacle\studio 10\programs\studio.exe" = protocol=17 | dir=in | app=c:\program files\pinnacle\studio 10\programs\studio.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{055FEF8E-4B86-400F-A5C6-8FAC0042DCD9}" = NVIDIA ForceWare Multimedia
    "{05BDC796-3451-4F81-B91D-E98F7ADA76C2}" = TurboTax 2010 WinPerTaxSupport
    "{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
    "{07EEE598-5F21-4B57-B40B-46592625B3D9}" = Zune Language Pack (PTB)
    "{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Central Data
    "{098122AB-C605-4853-B441-C0A4EB359B75}" = DirectXInstallService
    "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
    "{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
    "{0F052922-4BCE-4763-A540-00857554336D}" = Redist
    "{12A3AF78-CBB5-484B-AE87-927C4DE6B9A8}" = Garmin City Navigator North America NT 2011.10 Update
    "{15C77FC3-8137-4A5E-8F81-F559045DD6B0}" = Shipping Assistant 3.6
    "{15F4085A-BC98-4590-AFFD-03BBBE49524E}" = Garmin Communicator Plugin
    "{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
    "{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
    "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
    "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
    "{1AAE4354-EE96-4414-B5A5-726162E60700}" = Berlitz Learning System - Italian
    "{1B683082-8791-4D00-8ADE-6C8986FCCC68}" = Roxio CinePlayer
    "{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
    "{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Central Tools
    "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
    "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
    "{20CFBF87-73BD-4EC5-80B4-9C894126BD14}" = TurboTax 2008 wvaiper
    "{21E49794-7C13-4E84-8659-55BD378267D5}" = Windows Home Server Connector
    "{22DE1881-9D24-4981-B5CC-EC7E9F2F4D52}" = Rhapsody Player Engine
    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
    "{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java(TM) 6 Update 20
    "{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
    "{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
    "{2A9DFFD8-4E09-4B91-B957-454805B0D7C4}" = Zune Language Pack (CHS)
    "{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
    "{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
    "{311C9C43-C4E2-442C-BCB4-D86DB2BF81D1}" = MemoriesOnTV
    "{31B2D73B-4311-4D95-A131-32FB2194D1CB}" = Microsoft UI Engine
    "{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3
    "{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5
    "{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
    "{324CEC09-007A-48eb-90E0-9D42D4D5EB0A}" = NetDeviceManager
    "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
    "{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
    "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
    "{3589A659-F732-4E65-A89A-5438C332E59D}" = Zune Language Pack (ELL)
    "{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
    "{3782EC09-4000-475E-8A59-9CABD6F03B4C}" = TurboTax 2010 WinPerFedFormset
    "{3881DB80-EAA2-012B-ADAE-000000000000}" = TurboTax 2009 WinPerFedFormset
    "{38975F50-EAA2-012B-ADB4-000000000000}" = TurboTax 2009 WinPerReleaseEngine
    "{38A34630-EAA2-012B-ADB6-000000000000}" = TurboTax 2009 WinPerTaxSupport
    "{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
    "{3C5A81D0-EAA2-012B-AE9F-000000000000}" = TurboTax 2009 wrapper
    "{3CB05291-F546-458E-A796-B5BCF5A3CDC4}" = Studio 10
    "{3CCB26F5-E2A7-4C91-8340-9149D7B7C2BE}" = Virtual Earth 3D (Beta)
    "{3D29DFC0-EAA2-012B-AED3-000000000000}" = TurboTax 2009 wvaiper
    "{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
    "{3E67A8DA-FE7B-4160-8465-F5571EA18753}" = Roxio Disc Gallery
    "{4286E640-B5FB-11DF-AC4B-005056C00008}" = Google Earth
    "{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
    "{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
    "{4F2FCCCF-29F3-44B9-886F-6D16F8417522}" = TurboTax 2010 wrapper
    "{51C839E1-2BE4-4E77-A1BA-CCEA5DAFA741}" = Zune Language Pack (KOR)
    "{537BF16E-7412-448C-95D8-846E85A1D817}" = Roxio Easy Media Creator
    "{53CDAAAB-6D41-4A36-BAA4-90261DE31B13}" = NetZero For Cosmi
    "{548B3DC6-2300-47E1-BA7B-74AD25F8DEBF}" = Form Fill (Windows Live Toolbar)
    "{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
    "{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
    "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
    "{57C51D56-B287-4C11-9192-EC3C46EF76A4}" = Zune Language Pack (RUS)
    "{59716973-C123-4B46-B44B-36FCD9CEB8A3}" = Print Artist 22 Platinum
    "{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}" = Roxio BackOnTrack
    "{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
    "{5C93E291-A1CC-4E51-85C6-E194209FCDB4}" = Zune Language Pack (PTG)
    "{5CF6EEE9-86B1-3DB6-A07C-8F6C079C39BA}" = Google Talk Plugin
    "{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
    "{5DEFD397-4012-46C3-B6DA-E8013E660772}" = Zune Language Pack (NOR)
    "{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}" = Roxio File Backup
    "{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
    "{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
    "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
    "{6740BCB0-5863-47F4-80F4-44F394DE4FE2}" = Zune Language Pack (NLD)
    "{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
    "{68108E66-D13A-4EE8-A6F4-40E4B90C2A26}" = Windows Live Toolbar Feed Detector (Windows Live Toolbar)
    "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
    "{69EB5C18-1222-41F1-8C75-69B5F55F4321}" = Garmin Lifetime Updater
    "{6B33492E-FBBC-4EC3-8738-09E16E395A10}" = Zune Language Pack (ESP)
    "{6EB931CD-A7DA-4A44-B74A-89C8EB50086F}" = Zune Language Pack (SVE)
    "{6F50C41C-6CFB-49E1-AF91-E1AACDE24FBA}" = Garmin City Navigator North America NT 2012.30 Update
    "{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
    "{71DFAA65-77FA-41F3-A748-013B5A8524A3}" = Garmin City Navigator North America NT 2010.30
    "{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Central Audio
    "{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
    "{759142E8-25B0-42AE-B408-4215065D3F4B}" = Windows Live Family Safety
    "{76BA306B-2AA0-47C0-AB6B-F313AB56C136}" = Zune Language Pack (MSL)
    "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    "{7745B7A9-F323-4BB9-9811-01BF57A028DA}" = Map Button (Windows Live Toolbar)
    "{777CA40C-0206-4EF6-A0FC-618BF06BF8D0}" = Intel(R) PRO Network Connections 12.1.12.0
    "{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}" = Bing Bar
    "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
    "{789FC4C2-7DEE-4dc0-9E12-9A013AE80C8E}" = 3300
    "{78AE804E-C0CD-4E81-8C3B-63061742800D}" = Multimedia Bible and Christian References
    "{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
    "{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
    "{7B1FF9C5-ABDE-4D1B-BE70-DF6A4A546131}" = Hallmark Card Studio Trial Edition 2009
    "{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
    "{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
    "{7F1B3341-A94E-4F5C-B587-CA0EB964221E}" = Microsoft Money Shared Libraries
    "{7F6D7FD9-648D-4DD9-BB6E-3990C675ECA4}" = NVIDIA PhysX
    "{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
    "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
    "{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
    "{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
    "{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
    "{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
    "{8960A0A1-BB5A-479E-92CF-65AB9D684B43}" = Zune Language Pack (PLK)
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{8B112338-2B08-4851-AF84-E7CAD74CEB32}" = Zune Language Pack (DAN)
    "{8C5FAD77-F678-4758-A296-C12F08D179E0}" = Microsoft IntelliPoint 6.2
    "{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Roxio CinePlayer Decoder Pack
    "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
    "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
    "{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
    "{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
    "{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
    "{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
    "{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
    "{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
    "{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
    "{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
    "{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
    "{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
    "{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
    "{926BD0E8-24A3-41D2-AF9B-340F1A37ED12}" = MobileMe Control Panel
    "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
    "{92ECE3F9-591E-4C12-8A62-B9FCE38BF646}" = Zune Language Pack (IND)
    "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
    "{964D07BE-460C-4862-B59C-49575B8F46DC}" = Google SketchUp Pro 8
    "{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
    "{9A9A1828-31D1-4590-A99F-022B7237AFAE}" = Roxio MediaShare
    "{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
    "{9B75648B-6C30-4A0D-9DE6-0D09D20AF5A5}" = Zune
    "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
    "{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = AnswerWorks 5.0 English Runtime
    "{A0724A7E-F4E7-498e-B3F9-6FB2B909E56E}" = 3100_3200_3300_Help
    "{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
    "{A3B7C670-4A1E-4EE2-950E-C875BC1965D0}" = Copy
    "{A525E00B-6609-442E-9DCD-64453C233E8D}" = TurboTax 2010 WinPerReleaseEngine
    "{A5A53EA8-A11E-49F0-BDF5-AE536426A31A}" = Zune Language Pack (CHT)
    "{A654A805-41D9-40C7-AA46-4AF04F044D61}" = Adobe® Photoshop® Album Starter Edition 3.2
    "{A6A9D7C4-1E5B-42FD-98F5-E067A942AEE1}" = AQUAZONE "Virtual Aquarium Collection"
    "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
    "{A80FA752-C491-4ED9-ABF0-4278563160B2}" = 32 Bit HP CIO Components Installer
    "{A8F2E50B-86E2-4D96-9BD2-9758BCC6F9B3}" = Zune Language Pack (CSY)
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
    "{A9FE08B0-7804-43FF-8B90-04EEC285FFF6}" = Microsoft Office Live Add-in Patches
    "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
    "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
    "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
    "{AC76BA86-7AD7-1033-7B44-A83000000003}" = Adobe Reader 8.3.1
    "{AC76BA86-7AD7-2447-0000-800000000003}" = Chinese Simplified Fonts Support For Adobe Reader 8
    "{AC76BA86-7AD7-5760-0000-800000000003}" = Japanese Fonts Support For Adobe Reader 8
    "{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
    "{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
    "{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
    "{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 285.62
    "{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 285.62
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 285.62
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 285.62
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.11.0621
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.5.20
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
    "{B4870774-5F3A-46D9-9DFE-06FB5599E26B}" = Zune Language Pack (FIN)
    "{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Central Copy
    "{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
    "{B7DBF6E8-0D17-4BE4-853B-ACD6EFBD4A1F}" = iTunes
    "{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
    "{B986E497-3E38-4361-9F35-3FEC4F7FF771}" = Berlitz Before You Know It Flash Cards
    "{BB830F9E-53B3-492F-B39C-2DF615D1C9E1}" = TurboTax 2010 wvaiper
    "{BCF16F16-AC0E-4ABE-A9EF-412CF484BA51}" = Windows Live Family Safety
    "{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}" = Zune Language Pack (DEU)
    "{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
    "{BF83EFE2-C9F0-40D4-841C-2066668C1D7A}" = Roxio Easy Media Creator 10 Suite
    "{C33F3EF6-3625-4FE5-BCBA-41361C99AF1D}" = Camera Assistant Software for ViewSonic
    "{C5D37FFA-7483-410B-982B-91E93FD3B7DA}" = Zune Language Pack (ITA)
    "{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
    "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
    "{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}" = Zune Language Pack (FRA)
    "{C6BE19C6-B102-4038-B2A6-1C313872DBB4}" = Zune Language Pack (HUN)
    "{C716522C-3731-4667-8579-40B098294500}" = Toolbox
    "{C73A3AB4-99A4-45E5-B77F-09A3065E0D6A}" = Microsoft IntelliType Pro 6.1
    "{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
    "{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
    "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
    "{CCB71FF8-DE82-469C-8641-44378F4443EB}" = Garmin WebUpdater
    "{CCF6F57B-F6B4-4508-BF45-63AAC9DE416A}" = Quicken 2010
    "{CD95D125-2992-4858-B3EF-5F6FB52FBAD6}" = Skype Toolbars
    "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
    "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
    "{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
    "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
    "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
    "{D5B3C1B7-37C2-47B0-B6DD-EC53D3FB3B01}" = HP MediaSmart Server
    "{D6F2C4FD-149A-4BA0-A95D-2A80F10EE751}" = OverDrive Media Console
    "{D8A781C9-3892-4E2E-9320-480CF896CFBB}" = Zune Language Pack (JPN)
    "{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
    "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
    "{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
    "{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software
    "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
    "{E0A43EF2-46A5-4de2-916A-C515D8AA1618}" = 3100_3200_3300trb
    "{E1180142-3B31-4DCC-9D27-7AC2D37662BF}" = LightScribe 1.4.124.1
    "{E5538179-A892-499A-B7AA-8D7074EB203B}" = Vz In Home Agent
    "{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
    "{E633D396-5188-4E9D-8F6B-BFB8BF3467E8}" = Skypeâ„¢ 5.1
    "{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
    "{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
    "{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
    "{EC877639-07AB-495C-BFD1-D63AF9140810}" = Roxio Activation Module
    "{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Central Core
    "{F084395C-40FB-4DB3-981C-B51E74E1E83D}" = Smart Menus (Windows Live Toolbar)
    "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{F19F7B24-AAD4-4236-8475-5335483DA676}" = Avery Wizard 3.1
    "{F2AF3E5D-9697-485C-A5AC-E2B9468C446A}" = Safari
    "{F2CB8C3C-9C9E-4FAB-9067-655601C5F748}" = Windows Mobile Device Updater Component
    "{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
    "{FC47C7A5-BE63-11D5-B7C9-005004566E4D}" = ViewSonic Windows Vista Signed Files
    "{FCC3BD6A-F118-475D-8748-7EE08EA0AF56}" = HDView for Internet Explorer
    "{FD727056-F0C4-4811-9688-9EBF450D22C4}" = AXIS Media Control Embedded Installer
    "{FDB46DE7-9045-47BB-970A-3E4ED5369E03}" = EMC 10 Content
    "{FDB5E0F3-86EA-4379-8A2F-1BC2436543E9}" = iCloud
    "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
    "{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
    "{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
    "{FF1482CF-D19B-44DD-B887-9698CB51DFD5}" = Studio 10.8 Patch
    "49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
    "Adobe Acrobat 4.0" = Adobe Acrobat 4.0
    "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
    "Adobe® Photoshop® Album Starter Edition 3.2" = Adobe® Photoshop® Album Starter Edition 3.2
    "AOL Radio Toolbar" = AOL Radio Toolbar
    "Audit Support Center" = Audit Support Center 1.0
    "AXIS Media Control Embedded" = AXIS Media Control Embedded
    "Cucusoft DVD to Zune + Zune Video Converter Suite_is1" = Cucusoft DVD to Zune + Zune Video Converter Suite 8.2.8.2
    "Digital Editions" = Adobe Digital Editions
    "Google Chrome" = Google Chrome
    "Google Updater" = Google Updater
    "HECI" = Intel(R) Management Engine Interface
    "HOMESTUDENTR" = Microsoft Office Home and Student 2007
    "HP Imaging Device Functions" = HP Imaging Device Functions 8.0
    "HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
    "HPExtendedCapabilities" = HP Customer Participation Program 8.0
    "HPOCR" = HP OCR Software 8.0
    "InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
    "InstallShield_{EB7A2041-6A16-4BAC-8079-43B985673C2C}" = Avery Wizard 3.1
    "johnqtv1 Toolbar" = johnqtv1 Toolbar
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
    "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
    "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Microsoft Security Client" = Microsoft Security Essentials
    "Money2008b" = Microsoft Money Plus
    "NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
    "PDF-File Converter" = PDF-File Converter
    "PROSetDX" = Intel(R) PRO Network Connections 12.1.12.0
    "Quicken WillMaker Plus 2007" = Quicken WillMaker Plus 2007
    "RadialpointClientGateway_is1" = Verizon Servicepoint 3.7.44
    "Shop for HP Supplies" = Shop for HP Supplies
    "SoftwareUpdUtility" = Download Updater (AOL LLC)
    "SystemRequirementsLab" = System Requirements Lab
    "TurboTax 2008" = TurboTax 2008
    "TurboTax 2009" = TurboTax 2009
    "TurboTax 2010" = TurboTax 2010
    "TurboTax Deluxe 2007" = TurboTax Deluxe 2007
    "Verizon FiOS Activation_is1" = Verizon FiOS Activation
    "Verizon Media Manager" = Verizon Media Manager
    "WinLiveSuite" = Windows Live Essentials
    "Yahoo! Applications" = Verizon Yahoo! Applications
    "Yahoo! Software Update" = Yahoo! Software Update
    "Zune" = Zune
  3. res0jh1y2 Newcomer, in training

    Extras Log part 2 of 2

    ========== HKEY_USERS Uninstall List ==========

    [HKEY_USERS\S-1-5-21-4021511835-731674042-3818716740-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "AOL Radio Toolbar" = AOL Radio Toolbar
    "GoToMeeting" = GoToMeeting 4.5.0.457
    "HuluDesktop" = Hulu Desktop
    "MusicManager" = Music Manager
    "Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8

    ========== Last 10 Event Log Errors ==========

    [ Application Events ]
    Error - 12/27/2011 9:55:22 PM | Computer Name = OWNER-PC-Den | Source = MsiInstaller | ID = 1023
    Description =

    Error - 12/29/2011 8:04:28 PM | Computer Name = OWNER-PC-Den | Source = Application Error | ID = 1000
    Description = Faulting application iexplore.exe, version 9.0.8112.16421, time stamp
    0x4d76255d, faulting module Flash10w.ocx, version 10.3.183.7, time stamp 0x4e52e8e0,
    exception code 0xc0000005, fault offset 0x000ba050, process id 0xb04, application
    start time 0x01ccc63ca0159b1b.

    Error - 12/30/2011 9:37:30 AM | Computer Name = OWNER-PC-Den | Source = Application Error | ID = 1000
    Description = Faulting application msnmsgr.exe, version 15.4.3538.513, time stamp
    0x4dcdb2b3, faulting module ntdll.dll, version 6.0.6002.18327, time stamp 0x4cb73436,
    exception code 0xc0000374, fault offset 0x000b06fc, process id 0xb5c, application
    start time 0x01ccc6f09f64755b.

    Error - 1/1/2012 6:43:23 PM | Computer Name = OWNER-PC-Den | Source = Application Error | ID = 1000
    Description = Faulting application nvcplui.exe, version 3.9.731.0, time stamp 0x4e991d0e,
    faulting module unknown, version 0.0.0.0, time stamp 0x00000000, exception code
    0xc0000005, fault offset 0x0062fb28, process id 0xee8, application start time 0x01ccc8d6af2a8f60.

    Error - 1/1/2012 8:07:38 PM | Computer Name = OWNER-PC-Den | Source = ESENT | ID = 488
    Description = wlcomm (5796) C:\Users\OWNER\AppData\Local\Microsoft\Windows Live\Contacts\matthew_carpenter6@msn.com\15.4\:
    An attempt to create the file "C:\Users\OWNER\AppData\Local\Microsoft\Windows Live\Contacts\matthew_carpenter6@msn.com\15.4\DBStore\contacts.pat"
    failed with system error 5 (0x00000005): "Access is denied. ". The create file
    operation will fail with error -1032 (0xfffffbf8).

    Error - 1/1/2012 8:07:38 PM | Computer Name = OWNER-PC-Den | Source = ESENT | ID = 217
    Description = wlcomm (5796) C:\Users\OWNER\AppData\Local\Microsoft\Windows Live\Contacts\matthew_carpenter6@msn.com\15.4\:
    Error (-1032) during backup of a database (file C:\Users\OWNER\AppData\Local\Microsoft\Windows
    Live\Contacts\matthew_carpenter6@msn.com\15.4\DBStore\contacts.edb). The database
    will be unable to restore.

    Error - 1/1/2012 8:07:38 PM | Computer Name = OWNER-PC-Den | Source = ESENT | ID = 215
    Description = wlcomm (5796) C:\Users\OWNER\AppData\Local\Microsoft\Windows Live\Contacts\matthew_carpenter6@msn.com\15.4\:
    The backup has been stopped because it was halted by the client or the connection
    with the client failed.

    Error - 1/2/2012 5:26:46 PM | Computer Name = OWNER-PC-Den | Source = EventSystem | ID = 4609
    Description =

    Error - 1/2/2012 8:20:40 PM | Computer Name = OWNER-PC-Den | Source = Application Error | ID = 1000
    Description = Faulting application crppjugr.exe, version 1.0.15.15641, time stamp
    0x4e21f2b1, faulting module crppjugr.exe, version 1.0.15.15641, time stamp 0x4e21f2b1,
    exception code 0xc0000005, fault offset 0x0000c676, process id 0x127c, application
    start time 0x01ccc9ad11fbc952.

    Error - 1/2/2012 8:57:44 PM | Computer Name = OWNER-PC-Den | Source = Perflib | ID = 1010
    Description =

    [ Media Center Events ]
    Error - 4/24/2010 1:01:49 PM | Computer Name = OWNER-PC-Den | Source = Media Center Guide | ID = 0
    Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
    returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

    Error - 4/30/2010 3:50:05 PM | Computer Name = OWNER-PC-Den | Source = Media Center Guide | ID = 0
    Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
    returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

    Error - 5/1/2010 5:47:36 PM | Computer Name = OWNER-PC-Den | Source = Media Center Guide | ID = 0
    Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
    returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

    Error - 5/24/2010 3:11:09 PM | Computer Name = OWNER-PC-Den | Source = Media Center Guide | ID = 0
    Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
    returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

    Error - 5/24/2010 4:17:10 PM | Computer Name = OWNER-PC-Den | Source = Media Center Guide | ID = 0
    Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
    returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

    Error - 5/28/2010 6:15:24 AM | Computer Name = OWNER-PC-Den | Source = Media Center Guide | ID = 0
    Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
    returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

    Error - 5/29/2010 12:11:22 PM | Computer Name = OWNER-PC-Den | Source = Media Center Guide | ID = 0
    Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
    returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

    Error - 6/6/2010 12:09:57 PM | Computer Name = OWNER-PC-Den | Source = Media Center Guide | ID = 0
    Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
    returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

    Error - 6/12/2010 12:00:24 PM | Computer Name = OWNER-PC-Den | Source = Media Center Guide | ID = 0
    Description = Event Info: ERROR: SqmApiWrapper.TimerRecord failed; Win32 GetLastError
    returned 10000105 Process: DefaultDomain Object Name: Media Center Guide

    Error - 8/1/2010 2:27:35 PM | Computer Name = OWNER-PC-Den | Source = Media Center Guide | ID = 0
    Description = Event Info: ERROR: SqmApiWrapper.WaitForUploadComplete failed. Please
    try to ping www.msn.com prior to filing a bug.; Win32 GetLastError returned 10000109
    Process: DefaultDomain Object Name: Media Center Guide

    [ System Events ]
    Error - 1/5/2012 11:01:50 PM | Computer Name = OWNER-PC-Den | Source = Service Control Manager | ID = 7009
    Description =

    Error - 1/5/2012 11:01:50 PM | Computer Name = OWNER-PC-Den | Source = Service Control Manager | ID = 7009
    Description =

    Error - 1/5/2012 11:01:50 PM | Computer Name = OWNER-PC-Den | Source = Service Control Manager | ID = 7000
    Description =

    Error - 1/5/2012 11:01:50 PM | Computer Name = OWNER-PC-Den | Source = Service Control Manager | ID = 7001
    Description =

    Error - 1/5/2012 11:01:50 PM | Computer Name = OWNER-PC-Den | Source = Service Control Manager | ID = 7026
    Description =

    Error - 1/5/2012 11:02:08 PM | Computer Name = OWNER-PC-Den | Source = ipnathlp | ID = 31004
    Description = The DNS proxy agent was unable to allocate 0 bytes of memory. This
    may indicate that the system is low on virtual memory, or that the memory manager
    has encountered an internal error.

    Error - 1/5/2012 11:03:40 PM | Computer Name = OWNER-PC-Den | Source = DCOM | ID = 10005
    Description =

    Error - 1/5/2012 11:03:40 PM | Computer Name = OWNER-PC-Den | Source = Service Control Manager | ID = 7009
    Description =

    Error - 1/5/2012 11:03:40 PM | Computer Name = OWNER-PC-Den | Source = DCOM | ID = 10005
    Description =

    Error - 1/5/2012 11:03:40 PM | Computer Name = OWNER-PC-Den | Source = Service Control Manager | ID = 7009
    Description =


    < End of report >
  4. res0jh1y2 Newcomer, in training

    Clean up and thanks

    Thanks for your help with removing this virus. I assume I can delete the downloaded programs and logs created through this process, correct? Let me know if there is anything else I need to do to clean up my PC.
  5. Broni Malware Annihilator

    Any current issues?

    Run OTL
    • Under the Custom Scans/Fixes box at the bottom, paste in the following

      Code:
      :OTL
      SRV - File not found [Auto | Stopped] -- -- (RoxLiveShare9)
      SRV - File not found [Disabled | Stopped] -- -- (NMIndexingService)
      SRV - File not found [Auto | Stopped] -- -- (McciCMService)
      O15 - HKU\S-1-5-21-4021511835-731674042-3818716740-1000\..Trusted Domains: //@surf.mar@/ ([]money in Local intranet)
      O15 - HKU\S-1-5-21-4021511835-731674042-3818716740-1000\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
      O15 - HKU\S-1-5-21-4021511835-731674042-3818716740-1000\..Trusted Domains: turbotax.com ([]https in Trusted sites)
      O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get.../ultrashim.cab (Reg Error: Key error.)
      O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/...nAxControl.CAB (Reg Error: Key error.)
      O16 - DPF: vzTCPConfig http://my.verizon.com/micro/speedopt...zTCPConfig.CAB (Reg Error: Key error.)
      @Alternate Data Stream - 76 bytes -> C:\Users\OWNER\Documents\Tosci Slideshow.dmss:Roxio EMC Stream
      @Alternate Data Stream - 76 bytes -> C:\Users\OWNER\Documents\Tosci 04162009.dmss:Roxio EMC Stream
      @Alternate Data Stream - 76 bytes -> C:\Users\OWNER\Documents\Slideshow2.dmsm:Roxio EMC Stream
      @Alternate Data Stream - 76 bytes -> C:\Users\OWNER\Documents\Slideshow1.dmsm:Roxio EMC Stream
      @Alternate Data Stream - 76 bytes -> C:\Users\OWNER\Documents\Slideshow0.dmsm:Roxio EMC Stream
      @Alternate Data Stream - 76 bytes -> C:\Users\OWNER\Documents\Slideshow.dmsm:Roxio EMC Stream
      @Alternate Data Stream - 76 bytes -> C:\Users\OWNER\Documents\Silvesto E Giuseppa.jwl:Roxio EMC Stream
      @Alternate Data Stream - 76 bytes -> C:\Users\OWNER\Documents\Path of Daggers 261.wma:Roxio EMC Stream
      @Alternate Data Stream - 76 bytes -> C:\Users\OWNER\Documents\Andrea Del Principe Kylee kate Sargant - Buonanotte Amore.jwl:Roxio EMC Stream
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
      
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    ==============================================================

    1. Update your Java version here: http://www.java.com/en/download/installed.jsp

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    2. Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it to its own folder
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.

    ===================================================================

    Last scans....

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

      NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.


    2. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    3. Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click on List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
  6. res0jh1y2 Newcomer, in training

    OTL log

    All processes killed
    ========== OTL ==========
    Service RoxLiveShare9 stopped successfully!
    Service RoxLiveShare9 deleted successfully!
    Service NMIndexingService stopped successfully!
    Service NMIndexingService deleted successfully!
    Service McciCMService stopped successfully!
    Service McciCMService deleted successfully!
    Registry key HKEY_USERS\S-1-5-21-4021511835-731674042-3818716740-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\//@surf.mar@/\ deleted successfully.
    Registry key HKEY_USERS\S-1-5-21-4021511835-731674042-3818716740-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\intuit.com\ttlc\ deleted successfully.
    Registry key HKEY_USERS\S-1-5-21-4021511835-731674042-3818716740-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\turbotax.com\ deleted successfully.
    Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
    C:\Windows\Downloaded Program Files\erma.inf moved successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
    Starting removal of ActiveX control Garmin Communicator Plug-In
    Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Garmin Communicator Plug-In\DownloadInformation\\INF .
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Garmin Communicator Plug-In\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Garmin Communicator Plug-In\ not found.
    Starting removal of ActiveX control vzTCPConfig
    Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\vzTCPConfig\DownloadInformation\\INF .
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\vzTCPConfig\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\vzTCPConfig\ not found.
    ADS C:\Users\OWNER\Documents\Tosci Slideshow.dmss:Roxio EMC Stream deleted successfully.
    ADS C:\Users\OWNER\Documents\Tosci 04162009.dmss:Roxio EMC Stream deleted successfully.
    ADS C:\Users\OWNER\Documents\Slideshow2.dmsm:Roxio EMC Stream deleted successfully.
    ADS C:\Users\OWNER\Documents\Slideshow1.dmsm:Roxio EMC Stream deleted successfully.
    ADS C:\Users\OWNER\Documents\Slideshow0.dmsm:Roxio EMC Stream deleted successfully.
    ADS C:\Users\OWNER\Documents\Slideshow.dmsm:Roxio EMC Stream deleted successfully.
    ADS C:\Users\OWNER\Documents\Silvesto E Giuseppa.jwl:Roxio EMC Stream deleted successfully.
    ADS C:\Users\OWNER\Documents\Path of Daggers 261.wma:Roxio EMC Stream deleted successfully.
    ADS C:\Users\OWNER\Documents\Andrea Del Principe Kylee kate Sargant - Buonanotte Amore.jwl:Roxio EMC Stream deleted successfully.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 67 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: OWNER
    ->Temp folder emptied: 54268402 bytes
    ->Temporary Internet Files folder emptied: 2429495177 bytes
    ->Java cache emptied: 66836379 bytes
    ->Google Chrome cache emptied: 197071377 bytes
    ->Apple Safari cache emptied: 9216000 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: UpdatusUser
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 67 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 131500 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 162 bytes

    Total Files Cleaned = 2,629.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default

    User: Default User

    User: OWNER

    User: Public

    User: UpdatusUser

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.31.0 log created on 01052012_233849

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...
  7. res0jh1y2 Newcomer, in training

    Java tasks

    I completed the version update of Java. Below is the JavaRa Log


    JavaRa 1.16 Removal Log.

    Report follows after line.

    ------------------------------------

    The JavaRa removal process was started on Fri Jan 06 00:22:00 2012

    Found and removed: C:\Program Files\Java\jre1.6.0_03

    Found and removed: C:\Program Files\Java\jre1.6.0_05

    Found and removed: C:\Program Files\Java\jre1.6.0_07

    Found and removed: C:\Users\OWNER\AppData\LocalLow\Sun\Java\jre1.6.0_11

    Found and removed: C:\Users\OWNER\AppData\LocalLow\Sun\Java\jre1.6.0_12

    Found and removed: C:\Users\OWNER\AppData\LocalLow\Sun\Java\jre1.6.0_13

    Found and removed: C:\Users\OWNER\AppData\LocalLow\Sun\Java\jre1.6.0_15

    Found and removed: C:\Users\OWNER\AppData\LocalLow\Sun\Java\jre1.6.0_17

    Found and removed: C:\Users\OWNER\AppData\LocalLow\Sun\Java\jre1.6.0_20

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0001-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0002-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0003-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0004-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0005-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0006-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0007-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0008-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0009-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0010-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0011-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0012-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0013-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0014-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0015-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0016-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0017-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0018-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0019-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0020-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0021-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0022-ABCDEFFDCBA}. The error returned was 124.

    Found and removed: Applications\java.exe

    Found and removed: Applications\javaw.exe

    Found and removed: JavaPlugin.FamilyVersionSupport

    Found and removed: Installer\Products\8A0F842331866D117AB7000B0D610007

    Found and removed: CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0014-0002-FFFF-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBC}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBB}

    Found and removed: CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBC}

    Found and removed: JavaScript

    Found and removed: JavaScript Author

    Found and removed: JavaScript1.1

    Found and removed: JavaScript1.1 Author

    Found and removed: JavaScript1.2

    Found and removed: JavaScript1.2 Author

    Found and removed: Software\Classes\CLSID\{CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA}

    Found and removed: Software\Classes\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB}

    Found and removed: Software\Classes\JavaPlugin.160_03

    Found and removed: Software\Classes\JavaPlugin.160_05

    Found and removed: Software\Classes\JavaPlugin.160_07

    Found and removed: Software\JavaSoft\Java Update

    Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_03

    Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_05

    Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_07

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBB}

    Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBC}

    Found and removed: SOFTWARE\Classes\JavaPlugin

    Found and removed: SOFTWARE\Classes\JavaPlugin.160_03

    Found and removed: SOFTWARE\Classes\JavaPlugin.160_05

    Found and removed: SOFTWARE\Classes\JavaPlugin.160_07

    Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_03

    Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_05

    Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_07

    Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6

    Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_03

    Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_05

    Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_07

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_03

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_05

    Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_07

    Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}

    Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\

    Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\

    Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_07\

    Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_03.b05\

    Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_05.b13\

    Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10}

    Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.1

    Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.1.1

    Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.1.2

    Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.1.3

    Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.2

    Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.2.1

    Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.3

    Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.3.1

    Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.4

    Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.4.1

    Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.4.2

    Found and removed: SOFTWARE\MozillaPlugins\@java.com/JavaPlugin\MimeTypes\application/x-java-applet;version=1.5
  8. res0jh1y2 Newcomer, in training

    SecurityCheck checkup Log

    Results of screen317's Security Check version 0.99.24
    Windows Vista Service Pack 2 x86 (UAC is enabled)
    Internet Explorer 9
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Enabled!
    Microsoft Security Essentials
    WMI entry may not exist for antivirus; attempting automatic update.
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Java(TM) 6 Update 30
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Out of date Java installed!
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Windows Defender MSMpEng.exe
    Malwarebytes' Anti-Malware mbamservice.exe
    Malwarebytes' Anti-Malware mbamgui.exe
    Microsoft Security Essentials msseces.exe
    Microsoft Security Client Antimalware MsMpEng.exe
    Microsoft Security Client Antimalware NisSrv.exe
    ``````````End of Log````````````
  9. Broni Malware Annihilator

    Uninstall:
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
  10. res0jh1y2 Newcomer, in training

    ESET Online Scanner

    ESET Online Scanner finished scan and did not find any threats.
  11. res0jh1y2 Newcomer, in training

    Java uninstall

    Using uninstall from Control Panel I uninstall per your prior post Java 6 update 3 and 5. I did not find a Java 6, update 7.
  12. Broni Malware Annihilator

    Your computer is clean [IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. (Windows XP only) Run defrag at your convenience.

    11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    12. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    13. Please, let me know, how your computer is doing.
  13. res0jh1y2 Newcomer, in training

    OTL Log run per last post

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: OWNER
    ->Temp folder emptied: 4379800 bytes
    ->Temporary Internet Files folder emptied: 23112568 bytes
    ->Java cache emptied: 0 bytes
    ->Google Chrome cache emptied: 13945492 bytes
    ->Apple Safari cache emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: UpdatusUser
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 49088 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 2418249172 bytes

    Total Files Cleaned = 2,346.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default

    User: Default User

    User: OWNER

    User: Public

    User: UpdatusUser

    Total Flash Files Cleaned = 0.00 mb



    OTL by OldTimer - Version 3.2.31.0 log created on 01062012_144058

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...
  14. Broni Malware Annihilator

    Whenever ready.....
  15. res0jh1y2 Newcomer, in training

    Status

    I just finished performing the steps from your prior post #32. Complete OTL clean up, deleted remaining tools and logs, downloaded WOT, TFC and PSI. My PC appears to be working fine. Thank-you very much for your help!
  16. Broni Malware Annihilator

    Way to go!! [IMG]
    Good luck and stay safe :)