for step 1:
exeHelper by Raktor
Build 20100414
Run at 18:24:13 on 11/22/11
Now searching...
Checking for numerical processes...
Checking for sysguard processes...
Checking for bad processes...
Checking for bad files...
Checking for bad registry entries...
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values...
Resetting policies...
--Finished--
for step 4:
All processes killed
========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Yahoo Messengger not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found.
Unable to delete ADS C:\ProgramData\TEMP:517B507A .
Unable to delete ADS C:\Windows\System32:{4B9A1497-0817-47C4-9612-D6A1C53ACF57} .
File/Folder C:\*.tmp not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{002B1C9B-02DD-4BD2-9865-E82F98C1FA52}C:\users\ewanie\appdata\local\temp\winorab.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{007D520E-CE76-4A6E-9AC8-D4E641EDE2EC}C:\users\ewanie\appdata\local\temp\gctnw.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{026B7A24-6F26-42AA-A586-645D58441565}C:\users\ewanie\appdata\local\temp\winxxebkx.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{055597DC-9FA8-4288-86CA-202B6A5088A3}C:\users\ewanie\appdata\local\temp\bnpn.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{0589C260-7572-4DE3-B673-74C8500C94F1}C:\users\ewanie\appdata\local\temp\wincclsh.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{05EE446E-131B-42EC-8132-3214B3712461}C:\users\ewanie\appdata\local\temp\winnitps.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{078EEB9A-62CB-45BC-B3A5-364DC87A87C5}C:\users\ewanie\appdata\local\temp\winwgug.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{07E66442-E3B3-4865-A8E3-4E208E92882F}C:\users\ewanie\appdata\local\temp\kjkqpr.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{0960CB3A-17A3-4340-91DF-9AC994537D60}C:\users\ewanie\appdata\local\temp\winmcvp.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{09A4C06A-AA2E-4C2E-B879-6D76CA19F619}C:\users\ewanie\appdata\local\temp\winxlldga.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{0B370911-22E0-4204-947A-D3628CC997E0}C:\users\ewanie\appdata\local\temp\vkgxg.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{0ED6C604-7580-4CB1-91B1-173DFEF69371}C:\users\ewanie\appdata\local\temp\winyeyd.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{0FDA0341-7815-4D15-A878-F41076B77F1B}C:\users\ewanie\appdata\local\temp\winnavtq.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{0FEAA6B5-CCF2-4941-A056-CE9CF29C5DF2}C:\users\ewanie\appdata\local\temp\wineovhgn.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{134D47A0-F7D3-495F-8CBD-BE4B96B2B716}C:\users\ewanie\appdata\local\temp\winbootyy.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{1DE874F6-EDEC-4884-A919-92B620CD0ABD}C:\users\ewanie\appdata\local\temp\lhmwa.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{1FA97849-858F-4365-A1E0-9BD0B2F770C8}C:\users\ewanie\appdata\local\temp\winmmsly.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{211D0876-5D95-4611-91AE-36E362541832}C:\users\ewanie\appdata\local\temp\winpwiwh.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{2B9A8CAA-6E22-4442-8B63-A8D38891BD52}C:\users\ewanie\appdata\local\temp\winlkvo.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{2CF0D45C-1CDF-4F7A-8745-833AB82E6CE1}C:\users\ewanie\appdata\local\temp\winkewq.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{2E0B779E-707A-467B-892F-56E05AE5CE77}C:\users\ewanie\appdata\local\temp\rhud.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{3AB41250-0A57-4BC3-A2A4-16026CE8AFAA}C:\users\ewanie\appdata\local\temp\wincvclwk.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{3DFC36D0-F0FA-458C-AB68-0AD48B486F45}C:\users\ewanie\appdata\local\temp\winsadjay.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{486AE1D4-8DA1-411B-A8E6-AF9470915C13}I:\music.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{4B4C7E64-C243-49DA-90DD-4E4AE0897FC8}C:\users\ewanie\appdata\local\temp\winmqcpr.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{4DF6BE4C-579E-4BD6-B436-B4E12C02D0C1}C:\users\ewanie\appdata\local\temp\winymtvb.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{50E84207-6A4C-4C89-87F1-1FE8F57CD729}C:\users\ewanie\appdata\local\temp\qvfb.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{55621035-963F-433E-A00D-7EF624B922AB}C:\users\ewanie\appdata\local\temp\winucci.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{5941F712-2A65-4AD4-B8E9-813AA9F2C371}C:\users\ewanie\appdata\local\temp\winhahwro.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{5E9827D9-F33F-44B9-AA38-AF7987A8993C}H:\music.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{64BB1E7A-42C8-4D40-A856-1A068656AB99}C:\users\ewanie\appdata\local\temp\winpnoxy.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{68BD322E-301B-407C-BAB7-19FCE368F969}C:\users\ewanie\appdata\local\temp\wingoplh.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{6A1F9F30-3FDB-4C2C-AAE9-FEDDE21A0DC9}C:\users\ewanie\appdata\local\temp\yjoi.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{6BF4A930-9C7D-4CC0-A3D6-1BB6707D1DA6}C:\users\ewanie\appdata\local\temp\dlwsip.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{6F9A809D-86B0-4FE9-83B0-183C47269EBE}C:\users\ewanie\appdata\local\temp\winxsoxyn.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{71326173-D82F-438E-BF31-0FE3A1EF06BD}C:\users\ewanie\appdata\local\temp\winijlei.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{793784E9-5D99-4C10-9DDC-16B2E55281FF}C:\users\ewanie\appdata\local\temp\winyuhdf.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{7A388CA0-3A43-474C-8756-A54D62C2B726}C:\users\ewanie\appdata\local\temp\winjyjxai.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{7CDA0079-8893-4E61-BC3F-4876D00509A5}C:\users\ewanie\appdata\local\temp\winjjxms.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{7EC50F80-CFFB-437D-9DA3-53F5859FE68D}C:\users\ewanie\appdata\local\temp\winvxstu.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{8A865A58-5515-4C51-8EF9-747101FAD546}C:\users\ewanie\appdata\local\temp\ystxt.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{8B5A5A42-5F49-46DE-A77A-B29495CF9BB2}C:\users\ewanie\appdata\local\temp\winynqny.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{8CF7F59B-E48C-4F17-A2D1-6253C833CCCE}C:\users\ewanie\appdata\local\temp\hsci.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{8D6DDF81-27BB-42C1-89AC-195F571B04DD}C:\users\ewanie\appdata\local\temp\dpuo.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{8E880761-43E4-4679-9DBA-E1DA47E3BA33}C:\users\ewanie\appdata\local\temp\winycojuq.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{8F65BC02-3837-4E98-9B50-F07F606D0D8E}C:\users\ewanie\appdata\local\temp\qldi.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{94C557A8-F72B-45FD-AED5-7C309B805DA1}C:\users\ewanie\appdata\local\temp\winhhfh.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{9B45C4CE-2B10-4974-A473-A0F9B5CA370B}C:\users\ewanie\appdata\local\temp\tvuyx.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{9EB9F82D-FEA8-4B54-A92F-DDBB3E9C327D}C:\users\ewanie\appdata\local\temp\winrmgul.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{9F6D05D3-34CA-463A-B503-5ED0FBF49424}C:\users\ewanie\appdata\local\temp\winennx.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{A0AC3B94-A3A8-4F77-981E-768DEBF12EC9}C:\users\ewanie\appdata\local\temp\wincnwvd.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{A1134EFE-1C72-45CB-AD6C-75D602ED3BA7}C:\users\ewanie\appdata\local\temp\winjcidg.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{A1D7D716-4C4A-4172-A855-79DD00C36E8E}C:\users\ewanie\appdata\local\temp\rkowmy.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{A9C5A98C-38A7-4163-9D3B-632FE577B1F9}C:\users\ewanie\appdata\local\temp\winwehukq.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{AA4D4DA7-1981-45D8-9AD9-8C9844AF3893}C:\users\ewanie\appdata\local\temp\winowmy.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{ABAED87A-40B5-4B70-B742-728A246395CA}C:\users\ewanie\appdata\local\temp\ccwcm.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{AE75260C-E35D-4DCD-9F67-21DD26C3EF37}C:\users\ewanie\appdata\local\temp\winlneip.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{AEA75748-4B65-486F-B5B1-971DFD816C36}C:\users\ewanie\appdata\local\temp\vcml.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{AFA5057A-E4E0-4E16-B3DF-605301D0DEE8}C:\users\ewanie\appdata\local\temp\winyrgeq.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{B3118242-9E13-47D0-871A-044D313C5A56}C:\users\ewanie\appdata\local\temp\wingoaf.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{B3533A12-B3EB-4A05-AF60-783ED883AD27}C:\users\ewanie\appdata\local\temp\cgjonn.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{B651062E-D860-436C-8FAB-679AD4E96A17}C:\users\ewanie\appdata\local\temp\winjjoceu.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{C15AB151-14AA-4196-9830-7ABC7C0C48D7}C:\users\ewanie\appdata\local\temp\ddgl.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{C1658E99-8BFB-4A4C-BD02-228D6578E4DF}C:\users\ewanie\appdata\local\temp\bgkw.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{C48F2760-C633-4E82-B700-9D244732AE94}C:\users\ewanie\appdata\local\temp\windvsxh.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{C9B94725-97CA-43EB-9FE7-7175151FA178}C:\users\ewanie\appdata\local\temp\kagfn.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{CC9F25BC-F06B-4199-8A69-6EED41ACE516}C:\users\ewanie\appdata\local\temp\efhbyc.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{CE66FD0B-57AA-40AD-9A98-72D27C4CCD57}C:\users\ewanie\appdata\local\temp\winfstrbk.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{D0BD6FDB-D4D2-4067-A1C8-27B6C841EDD7}C:\users\ewanie\appdata\local\temp\winljilgj.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{D3EC1861-832B-44FE-B2FF-3D2A14538374}C:\users\ewanie\appdata\local\temp\gccvk.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{D580608D-888D-411E-8BC7-28EEC85972C3}C:\users\ewanie\appdata\local\temp\dvay.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{D63188BC-C2E1-40A7-8334-590081EE7063}C:\users\ewanie\appdata\local\temp\winelifw.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{D851A4F9-8361-4376-9C50-03EBAAB42DB1}C:\users\ewanie\appdata\local\temp\wingsmkml.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{E0ED9EF7-69D4-4DE3-B0D3-8FF04393582D}C:\users\ewanie\appdata\local\temp\winwkem.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{E16A190E-C77B-4E53-8D03-A06B53738E6E}C:\users\ewanie\appdata\local\temp\xwok.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{E62CCA66-DF23-4854-A812-81E22D65567A}C:\users\ewanie\appdata\local\temp\winunitcn.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{E6D255B5-1E2E-4705-BCDF-4FA932A2C4E3}C:\users\ewanie\appdata\local\temp\winllqk.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{EAAEF287-D606-4B58-8A54-E59BDE28E1D3}C:\users\ewanie\appdata\local\temp\wfpih.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{F33BBE90-8DAC-49D5-9B4A-A7E716A0B8B3}C:\users\ewanie\appdata\local\temp\qwcdch.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{F3973009-01FF-41AC-8D49-DCB3AF7089EC}C:\users\ewanie\appdata\local\temp\winhusal.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{F99741D5-EE16-47E1-A220-0FC3F9D2C7DB}C:\users\ewanie\appdata\local\temp\gmyjx.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{FC078542-AD19-49BA-A2EC-EF696867A397}C:\users\ewanie\appdata\local\temp\enhrs.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{FE4DF9DF-BE93-497E-BCF1-78A559D10D81}C:\users\ewanie\appdata\local\temp\sddoe.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{FEA12824-22B7-472F-9F7E-462FA94EB794}C:\users\ewanie\appdata\local\temp\winaigmhu.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{FF160059-2B4A-40E2-938F-D15F3817E2C4}C:\users\ewanie\appdata\local\temp\winfyoa.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{051B8955-5E43-4830-B19E-8EEABFBF0C7F}C:\users\ewanie\appdata\local\temp\wincclsh.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{06259494-C808-49A9-886E-1C247C402257}C:\users\ewanie\appdata\local\temp\winlkvo.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{0E2C9ACA-0F6A-440D-B313-EE4A18DA7CC4}C:\users\ewanie\appdata\local\temp\winwkem.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{10102AAB-703E-44F9-AE18-3C3A213A4D6C}C:\users\ewanie\appdata\local\temp\winpwiwh.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{131B03E6-2242-46AB-B9D2-48C90756317B}C:\users\ewanie\appdata\local\temp\kjkqpr.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{18FC4EA6-4DA7-4002-A343-29E9E99916BA}C:\users\ewanie\appdata\local\temp\winjjoceu.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{1A33E578-75F2-4E10-939A-8C868AF461DE}C:\users\ewanie\appdata\local\temp\tvuyx.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{1B20EBE3-26CB-4E72-9927-070B9AFCB8AA}C:\users\ewanie\appdata\local\temp\yjoi.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{1B3BEB98-2DFB-4744-8F85-33C65A3A3E5A}C:\users\ewanie\appdata\local\temp\winhusal.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{1FCAB14E-2E27-4D67-BDE9-112A46EC7F8A}C:\users\ewanie\appdata\local\temp\winlneip.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{20504F36-B3F6-4E81-8CFA-7AD34CCC5C18}C:\users\ewanie\appdata\local\temp\wincvclwk.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{223A534A-4682-46CC-9E1B-880394BAA433}C:\users\ewanie\appdata\local\temp\winllqk.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{2503A975-365B-4B3B-9AD9-A06EBBBBEA69}C:\users\ewanie\appdata\local\temp\winbootyy.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{25D154A4-ED93-47B9-AAF8-6ABADC8869BB}C:\users\ewanie\appdata\local\temp\qvfb.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{2A279DB7-85CC-43E2-99C3-6586D454B560}C:\users\ewanie\appdata\local\temp\winkewq.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{2A8B7143-96BC-4331-B7E2-62D48F7094AC}C:\users\ewanie\appdata\local\temp\winucci.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{3070356C-6995-49A9-8C0F-4EC7F86425C1}C:\users\ewanie\appdata\local\temp\winxxebkx.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{3091DBAA-48FB-421D-911E-492F0B3B85B7}C:\users\ewanie\appdata\local\temp\gmyjx.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{32528F24-CB82-4885-93FB-DEE0CD195A5C}C:\users\ewanie\appdata\local\temp\winfstrbk.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{3DF7F6E5-8781-4D55-BBB7-D256FEC870B5}C:\users\ewanie\appdata\local\temp\wingoplh.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{3F3812D5-6CD1-4753-B35F-7F8B962A69F4}C:\users\ewanie\appdata\local\temp\bgkw.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{494F81E1-2D0F-431D-AAFD-EE2C7174FB0B}C:\users\ewanie\appdata\local\temp\hsci.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{4B9650E8-7D6D-4DA4-9524-593351435C1C}C:\users\ewanie\appdata\local\temp\efhbyc.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{4F4D11B3-481F-4D39-BFAD-AD3B453CFCD6}C:\users\ewanie\appdata\local\temp\qldi.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{52494B2F-6029-42A3-8600-13C74026EF7F}C:\users\ewanie\appdata\local\temp\winjcidg.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{52C90B49-9DEB-4EA6-A35E-18DEE2FD8BB4}C:\users\ewanie\appdata\local\temp\gctnw.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{57FD7B92-6AE4-4B7E-9F86-FF1E0EAB6F27}C:\users\ewanie\appdata\local\temp\winorab.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{5A255FF3-DD04-435B-A784-23659A2261FA}C:\users\ewanie\appdata\local\temp\winrmgul.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{5B1D0B02-CA54-4B4D-9D6C-CB6652CCAB12}C:\users\ewanie\appdata\local\temp\dlwsip.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{5BC50A5E-D152-490B-8C92-A8CF9268357E}C:\users\ewanie\appdata\local\temp\winijlei.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{5E3D818F-4F4A-4E48-AD50-10955B5ED2F9}C:\users\ewanie\appdata\local\temp\enhrs.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{61FF397D-8339-42AD-8367-935491ADF26F}C:\users\ewanie\appdata\local\temp\dpuo.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{6909C380-B561-471D-8401-E0C8D39CB0D0}C:\users\ewanie\appdata\local\temp\winycojuq.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{69A9A193-7570-4B6D-BBEC-6029DFCDD77D}C:\users\ewanie\appdata\local\temp\windvsxh.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{783B6A21-6398-4CA9-8DE5-98E38D9FBDB7}C:\users\ewanie\appdata\local\temp\winymtvb.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{7887EF43-05A6-4150-A9C9-BC7A7C3E3CE4}C:\users\ewanie\appdata\local\temp\wingsmkml.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{7A372559-74D2-4D8A-A148-C9B9F75CCEDA}C:\users\ewanie\appdata\local\temp\winyrgeq.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{807FF827-DB6A-48E8-B8D5-0222320AE692}C:\users\ewanie\appdata\local\temp\winyeyd.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{81A6B690-C2A1-4604-8E01-628A459EF091}C:\users\ewanie\appdata\local\temp\winennx.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{85B6C61C-49CE-47A6-9635-7E2871EF2E23}C:\users\ewanie\appdata\local\temp\winnavtq.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{879068D5-EA6D-40FD-9740-236764BBED3D}C:\users\ewanie\appdata\local\temp\dvay.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{88B7987B-26DE-4AA2-8F75-F8BBD30F1A6C}C:\users\ewanie\appdata\local\temp\vcml.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{89E0D369-CAF3-4FA8-9107-71AB9A77A4F6}C:\users\ewanie\appdata\local\temp\winhhfh.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{8AD8CBC0-A482-495D-8244-D64F41570445}C:\users\ewanie\appdata\local\temp\winmcvp.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{8C35EC9B-2BEF-4971-9DC5-7EBD6D8B1513}C:\users\ewanie\appdata\local\temp\lhmwa.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{8CF5C3CA-392E-454A-BC31-946F035AD9C3}C:\users\ewanie\appdata\local\temp\cgjonn.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{8E700707-33DC-47FE-9186-BC748B35E1C6}C:\users\ewanie\appdata\local\temp\winnitps.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{8EBC15C0-A284-4C9D-91AE-5985D012DFED}C:\users\ewanie\appdata\local\temp\winowmy.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{90B9B62A-969D-4520-A7BC-B0F17F0FCFB3}C:\users\ewanie\appdata\local\temp\wfpih.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{93FBCFDA-6D2C-4536-B4FD-4728ACACA7E5}C:\users\ewanie\appdata\local\temp\sddoe.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{99F28409-D3CF-4754-A921-2355C40E367E}C:\users\ewanie\appdata\local\temp\winynqny.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{9F962162-685C-46B3-9F4C-FC93885E8688}C:\users\ewanie\appdata\local\temp\winjyjxai.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{A0EFCF05-B623-45F1-8036-844179AE581F}C:\users\ewanie\appdata\local\temp\qwcdch.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{A2E14AB7-7ED6-4C66-861C-2741B06C274A}C:\users\ewanie\appdata\local\temp\winpnoxy.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{A321488D-FFAC-47B9-BEE8-835394EF2938}C:\users\ewanie\appdata\local\temp\winfyoa.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{A4B4467B-E2BE-4334-88E7-8ED71A91DF12}C:\users\ewanie\appdata\local\temp\wineovhgn.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{A83AF39B-2083-42D2-82CC-9691C0BA540A}C:\users\ewanie\appdata\local\temp\winjjxms.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{ABD2BF8B-766F-4BC2-8920-5396E3FF3182}C:\users\ewanie\appdata\local\temp\winmkmqr.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{AE5954AC-C7FB-47A4-835C-C4704EB2682B}C:\users\ewanie\appdata\local\temp\rhud.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{AECA2DB6-A21D-455C-82BB-7B86104333CA}C:\users\ewanie\appdata\local\temp\kagfn.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{B4D250F7-51DD-4DC1-88D1-4D42740CE9C8}C:\users\ewanie\appdata\local\temp\winwehukq.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{B4E698D2-F7F4-4797-9EEC-67DAEA7CD219}C:\users\ewanie\appdata\local\temp\winunitcn.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{BC03A618-79C0-43C4-AABD-102540430476}C:\users\ewanie\appdata\local\temp\gccvk.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{BD026D2C-8F85-4999-B05B-AD2FB93FC71A}C:\users\ewanie\appdata\local\temp\xwok.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{BF362179-B001-42FF-87AC-16028F5B2EFB}C:\users\ewanie\appdata\local\temp\winvxstu.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{BF7769B2-A0F7-4065-8CBB-701DED526175}C:\users\ewanie\appdata\local\temp\winhahwro.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{C1777712-A1C4-49F7-A8E5-4542ACA2A11D}H:\music.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{C44289CA-E16E-4A14-BACB-AFF3CEF173A6}C:\users\ewanie\appdata\local\temp\winelifw.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{C6255CFE-A1EB-4388-85E3-612B883119D1}I:\music.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{C8894BC8-2284-40A8-AB45-38643D585653}C:\users\ewanie\appdata\local\temp\bnpn.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{CA5C539E-3ADD-467F-A48D-F70C3E5A2989}C:\users\ewanie\appdata\local\temp\ddgl.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{CB0C88E0-168A-4D55-AEDF-6B4EEF931AA3}C:\users\ewanie\appdata\local\temp\winaigmhu.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{CC67C72A-EBFA-4A78-B47B-BFC92D6CF538}C:\users\ewanie\appdata\local\temp\winmqcpr.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{D05E08DC-0623-4B1D-9FE3-7FE9C202D1D5}C:\users\ewanie\appdata\local\temp\vkgxg.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{D2CD7038-5E4A-4DEE-AEA6-C2F71D7F80B8}C:\users\ewanie\appdata\local\temp\wincnwvd.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{D3BF27A8-528F-4F71-AFAB-09AB9F36ADA0}C:\users\ewanie\appdata\local\temp\winljilgj.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{D65DCF5B-5AA2-4337-8ACF-D40575B4136B}C:\users\ewanie\appdata\local\temp\winmmsly.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{D978142D-4765-49C4-8BB3-9325487215DB}C:\users\ewanie\appdata\local\temp\ccwcm.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{DBE38C86-508A-41D6-BBFB-786182899F89}C:\users\ewanie\appdata\local\temp\winyuhdf.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{DDD6D712-E557-4CDA-91A0-6575DF2D827B}C:\users\ewanie\appdata\local\temp\ystxt.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{E49EFB6A-EE23-4BBA-BACC-13A4ACFF814D}C:\users\ewanie\appdata\local\temp\wingoaf.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{E600B0CA-4B35-484E-BBB0-A51197BFE639}C:\users\ewanie\appdata\local\temp\winxlldga.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{E911D784-50E6-4CE4-AA2C-35A10C36E067}C:\users\ewanie\appdata\local\temp\winwgug.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{EA33C351-81A2-4392-B19F-F97743F3B9F6}C:\users\ewanie\appdata\local\temp\winsadjay.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{F2341E61-E7C5-4F0A-9EBB-80C97F7CEFB4}C:\users\ewanie\appdata\local\temp\winxsoxyn.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{FEC3D0C8-2852-446E-8C22-B91B1BAD70B2}C:\users\ewanie\appdata\local\temp\rkowmy.exe not found.
========== FILES ==========
< ipconfig /flushdns /c >Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\ewanie\Downloads\cmd.bat deleted successfully.
C:\Users\ewanie\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: ewanie
->Temp folder emptied: 48216 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 9392124 bytes
->Flash cache emptied: 0 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 9.00 mb
[EMPTYFLASH]
User: All Users
User: Default
User: Default User
User: ewanie
->Flash cache emptied: 0 bytes
User: Public
Total Flash Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.31.0 log created on 11222011_195806
Files\Folders moved on Reboot...
File\Folder C:\Windows\temp\mcafee_DfpIftdomZhnnUO not found!
File\Folder C:\Windows\temp\mcafee_yxI6WGlUbLEyTZo not found!
File\Folder C:\Windows\temp\mcmsc_HM7WUFhPy2bXH4q not found!
File\Folder C:\Windows\temp\mcmsc_T51iOimoXYhoJ9m not found!
C:\Windows\temp\sqlite_qfwbks9zXw7nO4D moved successfully.
C:\Windows\temp\sqlite_SYKo819HvB6xBZ1 moved successfully.
Registry entries deleted on Reboot...
<>
OTL logfile created on: 22/11/2011 7:43:15 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\ewanie\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00004409 | Country: Malaysia | Language: ENM | Date Format: d/M/yyyy
1013.69 Mb Total Physical Memory | 90.23 Mb Available Physical Memory | 8.90% Memory free
2.24 Gb Paging File | 0.82 Gb Available in Paging File | 36.76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 177.06 Gb Total Space | 111.87 Gb Free Space | 63.18% Space Free | Partition Type: NTFS
Drive G: | 29.28 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: EWANIE-PC | User Name: ewanie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/11/20 01:42:01 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\ewanie\Downloads\OTL.exe
PRC - [2011/11/10 18:07:27 | 000,192,512 | ---- | M] () -- C:\Program Files\Maxis Broadband\Maxis Broadband.exe
PRC - [2010/10/07 04:28:12 | 003,768,176 | ---- | M] (Stardock) -- C:\Program Files\Stardock\ObjectDockFree\ObjectDock.exe
PRC - [2009/09/23 16:45:50 | 001,287,176 | ---- | M] (Panda Security) -- C:\Program Files\Panda USB Vaccine\USBVaccine.exe
PRC - [2009/02/21 00:46:52 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
PRC - [2008/10/29 14:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/03/11 05:14:54 | 000,335,872 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\Network Utility\LANUtil.exe
PRC - [2008/03/11 05:14:54 | 000,229,376 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\Network Utility\NSUService.exe
PRC - [2008/03/08 02:48:38 | 000,921,600 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
PRC - [2008/03/04 05:45:48 | 000,333,088 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
PRC - [2008/02/23 08:38:50 | 000,192,512 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\Apoint.exe
PRC - [2008/02/23 08:38:50 | 000,049,152 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\ApntEx.exe
PRC - [2008/02/23 08:38:49 | 000,050,472 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\ApMsgFwd.exe
PRC - [2008/02/16 02:56:56 | 000,147,456 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
PRC - [2008/02/16 02:56:54 | 000,184,320 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
PRC - [2008/02/16 02:56:50 | 000,274,432 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
PRC - [2008/01/21 10:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2008/01/16 18:46:08 | 002,458,128 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
PRC - [2008/01/10 07:50:22 | 000,767,976 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe
PRC - [2007/12/27 08:35:46 | 000,415,584 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Wallpaper Setting Tool\VWSet.exe
PRC - [2007/12/15 04:57:36 | 000,550,752 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
PRC - [2007/12/13 23:32:00 | 004,243,232 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\SonicStage Mastering Studio\Audio Filter\SSMSFilter.exe
PRC - [2007/12/12 03:33:42 | 000,358,224 | ---- | M] (McAfee, Inc.) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
PRC - [2007/12/06 01:04:10 | 000,695,624 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe
PRC - [2007/11/27 01:46:14 | 000,023,880 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSK\msksrver.exe
PRC - [2007/11/22 03:38:28 | 000,380,928 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\ISB Utility\ISBMgr.exe
PRC - [2007/11/02 10:12:38 | 000,652,624 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2007/11/02 10:12:38 | 000,265,040 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\MSC\mcuimgr.exe
PRC - [2007/09/11 15:45:04 | 000,124,832 | ---- | M] () -- C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
PRC - [2007/08/15 11:05:18 | 000,182,392 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
PRC - [2007/08/15 11:05:18 | 000,100,472 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
PRC - [2007/07/25 03:02:14 | 000,144,704 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe
PRC - [2007/07/19 06:54:42 | 000,856,864 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MPF\MpfSrv.exe
PRC - [2007/01/05 10:48:52 | 000,112,152 | R--- | M] (InterVideo) -- c:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
========== Modules (No Company Name) ========== MOD - [2011/11/15 13:39:54 | 000,420,920 | ---- | M] () -- C:\Users\ewanie\AppData\Local\Google\Chrome\Application\15.0.874.121\ppgooglenaclpluginchrome.dll
MOD - [2011/11/15 13:39:53 | 003,702,840 | ---- | M] () -- C:\Users\ewanie\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
MOD - [2011/11/15 13:38:16 | 000,122,952 | ---- | M] () -- C:\Users\ewanie\AppData\Local\Google\Chrome\Application\15.0.874.121\avutil-51.dll
MOD - [2011/11/15 13:38:15 | 000,222,280 | ---- | M] () -- C:\Users\ewanie\AppData\Local\Google\Chrome\Application\15.0.874.121\avformat-53.dll
MOD - [2011/11/15 13:38:14 | 001,746,504 | ---- | M] () -- C:\Users\ewanie\AppData\Local\Google\Chrome\Application\15.0.874.121\avcodec-53.dll
MOD - [2011/11/10 18:07:27 | 000,192,512 | ---- | M] () -- C:\Program Files\Maxis Broadband\Maxis Broadband.exe
MOD - [2010/10/05 01:54:31 | 000,053,760 | ---- | M] () -- C:\Program Files\Stardock\ObjectDockFree\zlib.dll
MOD - [2010/10/05 01:54:29 | 000,807,936 | ---- | M] () -- C:\Program Files\Stardock\ObjectDockFree\CrashRpt.dll
MOD - [2010/10/05 01:54:29 | 000,675,840 | ---- | M] () -- C:\Program Files\Stardock\ObjectDockFree\DockShellHook.dll
MOD - [2009/07/02 17:43:28 | 000,159,744 | ---- | M] () -- C:\Program Files\Maxis Broadband\SMSPlugin.dll
MOD - [2009/03/11 16:42:14 | 000,139,264 | ---- | M] () -- C:\Program Files\Maxis Broadband\LocaleMgrPlugin.dll
MOD - [2009/03/11 16:40:56 | 000,032,768 | ---- | M] () -- C:\Program Files\Maxis Broadband\NotifyServicePlugin.dll
MOD - [2009/03/11 16:39:16 | 000,061,440 | ---- | M] () -- C:\Program Files\Maxis Broadband\ConfigFilePlugin.dll
MOD - [2009/03/11 16:38:18 | 000,098,304 | ---- | M] () -- C:\Program Files\Maxis Broadband\DeviceMgrPlugin.dll
MOD - [2009/03/11 16:36:36 | 000,139,264 | ---- | M] () -- C:\Program Files\Maxis Broadband\NetInfoPlugin.dll
MOD - [2009/03/11 16:34:26 | 000,090,112 | ---- | M] () -- C:\Program Files\Maxis Broadband\DialUpPlugin.dll
MOD - [2009/03/11 16:33:32 | 000,176,128 | ---- | M] () -- C:\Program Files\Maxis Broadband\DeviceMgrUIPlugin.dll
MOD - [2009/03/11 16:17:14 | 000,864,256 | ---- | M] () -- C:\Program Files\Maxis Broadband\NDISAPI.dll
MOD - [2009/03/10 20:08:16 | 000,155,648 | R--- | M] () -- C:\Program Files\Maxis Broadband\DetectDev.dll
MOD - [2009/03/10 20:08:16 | 000,061,440 | R--- | M] () -- C:\Program Files\Maxis Broadband\XCodec.dll
MOD - [2009/03/10 20:08:16 | 000,061,440 | R--- | M] () -- C:\Program Files\Maxis Broadband\DeviceOperate.dll
MOD - [2009/03/10 20:08:14 | 000,561,152 | R--- | M] () -- C:\Program Files\Maxis Broadband\atcomm.dll
MOD - [2008/11/08 10:52:10 | 000,090,112 | R--- | M] () -- C:\Program Files\Maxis Broadband\FileManager.dll
MOD - [2008/11/08 10:52:08 | 000,014,848 | R--- | M] () -- C:\Program Files\Maxis Broadband\isaputrace.dll
MOD - [2008/02/05 08:08:45 | 000,249,856 | ---- | M] () -- C:\Windows\System32\igfxTMM.dll
MOD - [2007/12/21 20:06:58 | 002,969,600 | ---- | M] () -- C:\Program Files\Common Files\Sony Shared\AVLib\SonicStage Effect Plugins\Sony Limiter Plugin.dll
MOD - [2007/04/05 04:14:06 | 000,344,064 | ---- | M] () -- C:\Windows\System32\SSMSIppCustom.dll
========== Win32 Services (SafeList) ========== SRV - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/07/21 08:17:45 | 000,732,672 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/02/21 00:46:52 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc)
SRV - [2008/03/11 05:14:54 | 000,229,376 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\Network Utility\NSUService.exe -- (NSUService)
SRV - [2008/03/05 11:58:30 | 000,141,152 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Media plus\SOHDs.exe -- (SOHDs)
SRV - [2008/03/05 11:56:42 | 000,423,776 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Media plus\SOHDms.exe -- (SOHDms)
SRV - [2008/03/05 11:54:50 | 000,182,112 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VAIO Media plus\SOHCImp.exe -- (SOHCImp)
SRV - [2008/03/04 05:45:48 | 000,333,088 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe -- (VcmIAlzMgr)
SRV - [2008/03/04 04:27:14 | 000,165,152 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe -- (VcmXmlIfHelper)
SRV - [2008/02/16 02:56:56 | 000,147,456 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe -- (VzFw)
SRV - [2008/02/16 02:56:56 | 000,147,456 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe -- (VAIO Entertainment TV Device Arbitration Service)
SRV - [2008/02/16 02:56:54 | 000,184,320 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe -- (VzCdbSvc)
SRV - [2008/02/16 02:56:50 | 000,274,432 | ---- | M] (Sony Corporation) [On_Demand | Running] -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe -- (Vcsw)
SRV - [2008/01/21 10:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008/01/16 18:46:08 | 002,458,128 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe -- (McNASvc)
SRV - [2008/01/10 07:50:22 | 000,767,976 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\MSC\mcmscsvc.exe -- (mcmscsvc)
SRV - [2007/12/12 03:33:42 | 000,358,224 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe -- (McProxy)
SRV - [2007/12/06 01:04:10 | 000,695,624 | ---- | M] (McAfee, Inc.) [On_Demand | Running] -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe -- (McSysmon)
SRV - [2007/11/28 17:08:02 | 000,151,552 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe -- (SPTISRV)
SRV - [2007/11/28 17:02:20 | 000,122,880 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe -- (MSCSPTISRV)
SRV - [2007/11/28 16:43:44 | 000,135,168 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe -- (PACSPTISVR)
SRV - [2007/11/27 01:46:14 | 000,023,880 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\MSK\MskSrver.exe -- (MSK80Service)
SRV - [2007/11/08 00:35:40 | 000,447,816 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2007/09/11 15:45:04 | 000,124,832 | ---- | M] () [Auto | Running] -- C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor6.0)
SRV - [2007/08/15 11:05:18 | 000,182,392 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Event Service\VESMgr.exe -- (VAIO Event Service)
SRV - [2007/07/25 03:02:14 | 000,144,704 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\McAfee\VirusScan\Mcshield.exe -- (McShield)
SRV - [2007/07/19 06:54:42 | 000,856,864 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\MPF\MPFSrv.exe -- (MpfService)
SRV - [2007/01/05 10:48:52 | 000,112,152 | R--- | M] (InterVideo) [Auto | Running] -- c:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
========== Driver Services (SafeList) ========== DRV - [2011/08/31 17:00:50 | 000,022,216 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2009/02/17 20:38:12 | 000,112,128 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2008/12/30 11:57:52 | 000,103,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbfake.sys -- (hwusbfake)
DRV - [2008/12/13 11:27:50 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2008/02/23 08:38:50 | 000,164,400 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2008/02/06 08:06:19 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2007/12/17 09:57:23 | 000,009,344 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SFEP.sys -- (SFEP)
DRV - [2007/12/14 12:03:35 | 000,758,784 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2007/12/14 08:40:06 | 000,010,216 | ---- | M] (Sony Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\DMICall.sys -- (DMICall)
DRV - [2007/12/03 03:51:42 | 000,040,488 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfesmfk.sys -- (mfesmfk)
DRV - [2007/11/22 21:44:08 | 000,201,320 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2007/11/22 21:44:08 | 000,079,304 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2007/11/22 21:44:08 | 000,035,240 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2007/11/22 21:44:04 | 000,033,832 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mferkdk.sys -- (mferkdk)
DRV - [2007/07/13 21:21:12 | 000,125,728 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\Mpfp.sys -- (MPFP)
DRV - [2007/06/06 08:00:39 | 000,812,544 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ti21sony.sys -- (ti21sony)
DRV - [2007/05/26 16:03:06 | 000,128,104 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\WimFltr.sys -- (WimFltr)
DRV - [2007/04/18 11:09:28 | 000,011,032 | ---- | M] (InterVideo) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\regi.sys -- (regi)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3885349237-2032763224-3641379520-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://vaio-online.sony.com/IE - HKU\S-1-5-21-3885349237-2032763224-3641379520-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.facebook.com/IE - HKU\S-1-5-21-3885349237-2032763224-3641379520-1003\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3885349237-2032763224-3641379520-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.450: C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\ewanie\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\ewanie\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\ewanie\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\
[email protected]: C:\Users\ewanie\AppData\Roaming\IDM\idmmzcc5
[2011/07/21 14:28:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ewanie\AppData\Roaming\Mozilla\Extensions
========== Chrome ========== CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\ewanie\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Users\ewanie\AppData\Local\Google\Chrome\Application\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Users\ewanie\AppData\Local\Google\Chrome\Application\plugins\nprpjplug.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\ewanie\AppData\Local\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\ewanie\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = c:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Picasa2\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Users\ewanie\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Angry Birds = C:\Users\ewanie\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.1.2.1_0\
CHR - Extension: Bouncy Mouse = C:\Users\ewanie\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgdllcbmneiklcmbeclfegccdjholomb\1.0.1_0\
CHR - Extension: Dead Frontier = C:\Users\ewanie\AppData\Local\Google\Chrome\User Data\Default\Extensions\dglbaehakkaojfihjkgkpknbjldhhmmn\1.1_0\
CHR - Extension: Foursquare for chrome = C:\Users\ewanie\AppData\Local\Google\Chrome\User Data\Default\Extensions\haoobafgmgfodlcibfojjpdengcifnen\1.0.0.1_0\
CHR - Extension: Google Theme = C:\Users\ewanie\AppData\Local\Google\Chrome\User Data\Default\Extensions\imoaoigekmpoalkbfohhjgkcocjdapne\1.0.1_0\
CHR - Extension: ChatVibes Facebook Video Chat! = C:\Users\ewanie\AppData\Local\Google\Chrome\User Data\Default\Extensions\jddljohkbhegmdbfgmpjimeneejbdibf\1.0.8_0\
CHR - Extension: Earbits Radio = C:\Users\ewanie\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgkjffcdjblaipglnmhanakilfbniihj\1.0.2_0\
CHR - Extension: FastestChrome - Browse Faster = C:\Users\ewanie\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmffncokckfccddfenhkhnllmlobdahm\5.8.0_0\
O1 HOSTS File: ([2011/11/22 19:33:20 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (McAfee Phishing Filter) - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\Program Files\McAfee\MSK\mcapbho.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll (McAfee, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-3885349237-2032763224-3641379520-1003\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-3885349237-2032763224-3641379520-1003..\Run: [Facebook Update] C:\Users\ewanie\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-3885349237-2032763224-3641379520-1003..\Run: [NSUFloatingUI] C:\Program Files\Sony\Network Utility\LANUtil.exe (Sony Corporation)
O4 - HKU\S-1-5-21-3885349237-2032763224-3641379520-1003..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED File not found
O4 - Startup: C:\Users\ewanie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Audio Filter.lnk = C:\Program Files\Sony\SonicStage Mastering Studio\Audio Filter\SSMSFilter.exe (Sony Corporation)
O4 - Startup: C:\Users\ewanie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDockFree\ObjectDock.exe (Stardock)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\S-1-5-21-3885349237-2032763224-3641379520-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{21095519-1237-4E64-A25B-50158B5AE502}: NameServer = 58.71.136.10 58.71.132.10
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\VESWinlogon: DllName - (VESWinlogon.dll) - C:\Windows\System32\VESWinlogon.dll (Sony Corporation)
O22 - SharedTaskScheduler: {1984D045-52CF-49cd-DB77-08F378FEA4DB} - ObjectDockShellExt - C:\Program Files\Stardock\ObjectDockFree\ODMenu.dll (Stardock)
O24 - Desktop WallPaper: C:\Users\ewanie\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\ewanie\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/19 05:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.) - G:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2007/11/21 07:41:52 | 000,000,047 | R--- | M] () - G:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{01907089-f199-11e0-b23f-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{01907089-f199-11e0-b23f-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{036fdef2-0770-11e1-bf34-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{036fdef2-0770-11e1-bf34-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{3b6ed1bb-0a57-11e1-8e72-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{3b6ed1bb-0a57-11e1-8e72-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{3b6ed1c3-0a57-11e1-8e72-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{3b6ed1c3-0a57-11e1-8e72-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{3b6ed1cb-0a57-11e1-8e72-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{3b6ed1cb-0a57-11e1-8e72-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{5916c968-0bab-11e1-898c-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{5916c968-0bab-11e1-898c-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{5f904b62-0b81-11e1-943e-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{5f904b62-0b81-11e1-943e-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{5f904b6d-0b81-11e1-943e-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{5f904b6d-0b81-11e1-943e-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{7e242947-dc50-11e0-8c54-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{7e242947-dc50-11e0-8c54-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{7e24295c-dc50-11e0-8c54-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{7e24295c-dc50-11e0-8c54-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{8b2bf129-eddb-11e0-87b2-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{8b2bf129-eddb-11e0-87b2-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{8da7941c-e84a-11e0-bb30-001e101fc33c}\Shell - "" = AutoRun
O33 - MountPoints2\{8da7941c-e84a-11e0-bb30-001e101fc33c}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{8da79426-e84a-11e0-bb30-001e101ff8c4}\Shell - "" = AutoRun
O33 - MountPoints2\{8da79426-e84a-11e0-bb30-001e101ff8c4}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{8da7943c-e84a-11e0-bb30-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{8da7943c-e84a-11e0-bb30-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{a6a132e2-f6e0-11e0-9a5a-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{a6a132e2-f6e0-11e0-9a5a-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{abcc9e4f-ca54-11e0-9465-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{abcc9e4f-ca54-11e0-9465-001a80f6ffdf}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{abcc9e7e-ca54-11e0-9465-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{abcc9e7e-ca54-11e0-9465-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{b861bc05-f4d3-11e0-83f9-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{b861bc05-f4d3-11e0-83f9-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{bec080f8-08f2-11e1-bece-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{bec080f8-08f2-11e1-bece-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{d04d5c0e-d092-11e0-82e0-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{d04d5c0e-d092-11e0-82e0-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{e1bccaab-0df5-11e1-8017-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{e1bccaab-0df5-11e1-8017-001a80f6ffdf}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{f32cc677-d501-11e0-b7b9-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{f32cc677-d501-11e0-b7b9-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{f62b4d2e-ca4d-11e0-a012-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{f62b4d2e-ca4d-11e0-a012-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{f62b4d37-ca4d-11e0-a012-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{f62b4d37-ca4d-11e0-a012-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{f62b4d3f-ca4d-11e0-a012-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{f62b4d3f-ca4d-11e0-a012-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{fad1926c-0f3f-11e1-86e0-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{fad1926c-0f3f-11e1-86e0-001a80f6ffdf}\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{fb2422d9-1375-11e1-82ba-001a80f6ffdf}\Shell - "" = AutoRun
O33 - MountPoints2\{fb2422d9-1375-11e1-82ba-001a80f6ffdf}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\AutoRun.exe -- [2009/01/24 01:22:18 | 000,126,976 | R--- | M] (Huawei Technologies Co., Ltd.)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2011/11/22 19:50:47 | 000,000,000 | ---D | C] -- C:\Users\ewanie\Desktop\untuk geek
[2011/11/22 19:20:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Panda Security
[2011/11/22 19:04:26 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/11/22 18:58:27 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011/11/22 18:38:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Security
[2011/11/22 18:38:11 | 000,000,000 | ---D | C] -- C:\Program Files\Panda USB Vaccine
[2011/11/22 02:04:06 | 000,000,000 | ---D | C] -- C:\Users\ewanie\Documents\TOLONG AWEK AKU PONTIANAK DVDRIP.AVI
[2011/11/21 18:03:20 | 000,000,000 | ---D | C] -- C:\Users\ewanie\AppData\Roaming\DMCache
[2011/11/21 18:02:59 | 000,000,000 | ---D | C] -- C:\Users\ewanie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
[2011/11/21 18:02:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
[2011/11/21 17:49:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Stardock
[2011/11/21 02:02:31 | 000,000,000 | ---D | C] -- C:\Users\ewanie\Documents\Angry Birds
[2011/11/20 22:20:08 | 000,000,000 | ---D | C] -- C:\Users\ewanie\Documents\Al Hijab 2011 DVDRip
[2011/11/20 21:45:24 | 000,000,000 | ---D | C] -- C:\Users\ewanie\AppData\Roaming\Malwarebytes
[2011/11/20 21:44:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/20 21:44:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/11/20 21:44:07 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011/11/20 21:44:06 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/11/20 21:43:39 | 000,000,000 | -H-D | C] -- C:\Users\ewanie\Documents\PICT0926-1.JPG.files
[2011/11/20 21:43:05 | 000,000,000 | -H-D | C] -- C:\Users\ewanie\Documents\jeje.JPG.files
[2011/11/20 12:45:33 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2011/11/11 14:08:02 | 000,000,000 | ---D | C] -- C:\Users\ewanie\Documents\sushi game
[2011/11/11 14:05:47 | 000,000,000 | R--D | C] -- C:\Users\ewanie\Documents\Diner Dash 2
[2011/11/11 02:25:54 | 000,000,000 | ---D | C] -- C:\Users\ewanie\AppData\Roaming\PlayFirst
[2011/11/11 02:25:54 | 000,000,000 | ---D | C] -- C:\ProgramData\PlayFirst
[2011/11/11 02:21:37 | 000,000,000 | ---D | C] -- C:\Users\ewanie\AppData\Roaming\Rovio
[2011/11/10 18:08:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maxis Broadband
[2011/11/10 18:07:48 | 000,621,056 | ---- | C] (DiBcom SA) -- C:\Windows\System32\drivers\mod7700.sys
[2011/11/10 18:07:48 | 000,112,128 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ewusbnet.sys
[2011/11/10 18:07:48 | 000,103,040 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ewusbfake.sys
[2011/11/10 18:07:48 | 000,102,784 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ewusbmdm.sys
[2011/11/10 18:07:48 | 000,023,424 | ---- | C] (Huawei Tech. Co., Ltd.) -- C:\Windows\System32\drivers\ewdcsc.sys
[2011/11/09 22:27:17 | 000,000,000 | ---D | C] -- C:\Users\ewanie\Documents\mlk
[2011/11/04 05:55:12 | 000,000,000 | ---D | C] -- C:\Users\ewanie\AppData\Roaming\Uniblue
[2011/11/01 01:09:09 | 000,000,000 | ---D | C] -- C:\Users\ewanie\AppData\Local\Facebook
[2011/10/31 20:52:02 | 000,000,000 | ---D | C] -- C:\ProgramData\TamoSoft
[2011/07/30 18:10:15 | 000,501,576 | ---- | C] (Yahoo! Inc.) -- C:\Users\ewanie\AppData\Local\msgr9us.exe
========== Files - Modified Within 30 Days ========== [2011/11/22 19:46:09 | 000,000,270 | ---- | M] () -- C:\Windows\tasks\Check Updates for Windows Live Toolbar.job
[2011/11/22 19:36:26 | 000,000,258 | ---- | M] () -- C:\Windows\tasks\SpeedUpMyPC.job
[2011/11/22 19:36:18 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/22 19:36:17 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/22 19:36:08 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/11/22 19:36:05 | 1063,706,624 | -HS- | M] () -- C:\hiberfil.sys
[2011/11/22 19:34:55 | 000,030,329 | ---- | M] () -- C:\Windows\System32\Config.MPF
[2011/11/22 19:33:20 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts
[2011/11/22 19:06:04 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3885349237-2032763224-3641379520-1003UA.job
[2011/11/22 17:51:23 | 000,667,644 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/11/22 17:51:23 | 000,133,484 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/11/22 02:29:06 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3885349237-2032763224-3641379520-1003UA.job
[2011/11/21 23:28:04 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3885349237-2032763224-3641379520-1003Core.job
[2011/11/21 01:48:58 | 000,000,258 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2011/11/20 22:34:09 | 000,080,384 | ---- | M] () -- C:\Users\ewanie\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/20 17:46:31 | 000,000,000 | ---- | M] () -- C:\114788e
[2011/11/20 12:45:32 | 168,331,553 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/11/19 20:06:01 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3885349237-2032763224-3641379520-1003Core.job
[2011/11/15 01:00:00 | 000,000,356 | ---- | M] () -- C:\Windows\tasks\McDefragTask.job
[2011/11/09 22:31:08 | 000,203,776 | -H-- | M] () -- C:\Users\ewanie\Documents\photothumb.db
[2011/11/08 22:52:49 | 002,048,931 | ---- | M] () -- C:\Users\ewanie\Documents\m.zip
[2011/11/08 02:10:37 | 000,001,680 | ---- | M] () -- C:\Users\ewanie\Application Data\Microsoft\Internet Explorer\Quick Launch\Snipping Tool.lnk
[2011/11/01 01:00:00 | 000,000,348 | ---- | M] () -- C:\Windows\tasks\McQcTask.job
========== Files Created - No Company Name ========== [2011/11/20 21:41:30 | 000,641,940 | ---- | C] () -- C:\Users\ewanie\Documents\PICT0926-1.JPG
[2011/11/20 21:40:46 | 000,823,639 | ---- | C] () -- C:\Users\ewanie\Documents\jeje.JPG
[2011/11/20 17:46:31 | 000,000,000 | ---- | C] () -- C:\114788e
[2011/11/20 12:45:04 | 168,331,553 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011/11/19 13:41:16 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011/11/08 02:10:37 | 000,001,680 | ---- | C] () -- C:\Users\ewanie\Application Data\Microsoft\Internet Explorer\Quick Launch\Snipping Tool.lnk
[2011/11/05 20:50:48 | 000,203,776 | -H-- | C] () -- C:\Users\ewanie\Documents\photothumb.db
[2011/11/04 05:55:14 | 000,000,258 | ---- | C] () -- C:\Windows\tasks\SpeedUpMyPC.job
[2011/11/01 23:24:05 | 000,000,932 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3885349237-2032763224-3641379520-1003UA.job
[2011/11/01 23:23:58 | 000,000,910 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3885349237-2032763224-3641379520-1003Core.job
[2011/07/31 03:36:38 | 000,106,605 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011/07/31 03:36:38 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011/07/24 17:46:57 | 000,065,536 | ---- | C] () -- C:\Windows\IFinst27.exe
[2011/07/21 10:12:01 | 000,080,384 | ---- | C] () -- C:\Users\ewanie\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/21 08:59:18 | 000,000,209 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2011/07/21 08:50:45 | 000,001,356 | ---- | C] () -- C:\Users\ewanie\AppData\Local\d3d9caps.dat
[2011/07/21 08:34:49 | 000,000,000 | ---- | C] () -- C:\Windows\VAIOUpdt.INI
[2011/07/21 08:28:34 | 000,344,064 | ---- | C] () -- C:\Windows\System32\SSMSIppCustom.dll
[2008/02/05 08:09:01 | 000,204,800 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1295.dll
[2008/02/05 08:09:00 | 000,910,464 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll
[2008/02/05 08:08:45 | 000,249,856 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll
[2006/11/02 20:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 20:47:37 | 000,428,984 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 20:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 18:33:01 | 000,667,644 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 18:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 18:33:01 | 000,133,484 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 18:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 18:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 16:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 16:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 15:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 15:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
========== LOP Check ========== [2011/11/22 18:19:27 | 000,000,000 | ---D | M] -- C:\Users\ewanie\AppData\Roaming\DMCache
[2011/07/21 16:10:09 | 000,000,000 | ---D | M] -- C:\Users\ewanie\AppData\Roaming\InterVideo
[2011/09/13 22:28:33 | 000,000,000 | ---D | M] -- C:\Users\ewanie\AppData\Roaming\KompoZer
[2011/07/24 17:39:45 | 000,000,000 | ---D | M] -- C:\Users\ewanie\AppData\Roaming\OpenOffice.org
[2011/08/17 08:22:00 | 000,000,000 | ---D | M] -- C:\Users\ewanie\AppData\Roaming\PhotoScape
[2011/11/11 02:25:54 | 000,000,000 | ---D | M] -- C:\Users\ewanie\AppData\Roaming\PlayFirst
[2011/11/11 02:21:37 | 000,000,000 | ---D | M] -- C:\Users\ewanie\AppData\Roaming\Rovio
[2011/07/24 17:55:38 | 000,000,000 | ---D | M] -- C:\Users\ewanie\AppData\Roaming\Stardock
[2011/07/27 09:27:52 | 000,000,000 | ---D | M] -- C:\Users\ewanie\AppData\Roaming\TigerPlayer
[2011/11/04 05:55:12 | 000,000,000 | ---D | M] -- C:\Users\ewanie\AppData\Roaming\Uniblue
[2011/08/06 18:34:28 | 000,000,000 | ---D | M] -- C:\Users\ewanie\AppData\Roaming\WindSolutions
[2011/10/09 21:18:54 | 000,000,000 | ---D | M] -- C:\Users\ewanie\AppData\Roaming\YoudaGames
[2011/11/22 19:46:09 | 000,000,270 | ---- | M] () -- C:\Windows\Tasks\Check Updates for Windows Live Toolbar.job
[2011/11/21 23:28:04 | 000,000,910 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3885349237-2032763224-3641379520-1003Core.job
[2011/11/22 02:29:06 | 000,000,932 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3885349237-2032763224-3641379520-1003UA.job
[2011/11/15 01:00:00 | 000,000,356 | ---- | M] () -- C:\Windows\Tasks\McDefragTask.job
[2011/11/01 01:00:00 | 000,000,348 | ---- | M] () -- C:\Windows\Tasks\McQcTask.job
[2011/11/22 19:35:06 | 000,032,642 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/11/22 19:36:26 | 000,000,258 | ---- | M] () -- C:\Windows\Tasks\SpeedUpMyPC.job
========== Purity Check ========== < End of report >
for step 5:
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-11-22 20:09:32
-----------------------------
20:09:32.088 OS Version: Windows 6.0.6001 Service Pack 1
20:09:32.088 Number of processors: 2 586 0xF0D
20:09:32.088 ComputerName: EWANIE-PC UserName: ewanie
20:13:38.994 Initialize success
20:14:57.592 The log file has been saved successfully to "C:\Users\ewanie\Desktop\aswMBR.txt"
I hope this thing will help you to resolve my problems.
thanks again