Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Slow running and video issues [Closed]


  • This topic is locked This topic is locked

#1
Darrel Rude

Darrel Rude

    Member

  • Member
  • PipPip
  • 22 posts
Hi first off I would like to thank you all for doing this great service.
I am running windows Vista Home Premium.
OK my problems are a slow running computer with a video shut down that restarts my computer. The video card is fairly new and has enough memory to run. My computer boots up very very slow and sometimes not at all unless I leave it off for several days. This happens to be my oldest sons PC so I am not sure what he has done to it or anything. But he has moved out and we have taken it over for the grand kids. If you could take a look at it and tell me what it needs to be fixed I would appreciate it. I run malware bytes, spybot, SUPERAnti spyware along with avg. Also if there is a program that I could use to block any porn on this PC that would be wonderful since we have grand kids and older nephews using this.



Thanks in advance :)
Darrel Rude

Here is the log:

OTL logfile created on: 1/12/2014 10:22:07 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\tylene\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.50 Gb Total Physical Memory | 1.18 Gb Available Physical Memory | 47.07% Memory free
5.23 Gb Paging File | 3.58 Gb Available in Paging File | 68.30% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111.70 Gb Total Space | 24.49 Gb Free Space | 21.93% Space Free | Partition Type: NTFS
Drive D: | 111.43 Gb Total Space | 111.33 Gb Free Space | 99.91% Space Free | Partition Type: NTFS

Computer Name: TYLENE-PC | User Name: tylene | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2014/01/12 10:06:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\tylene\Desktop\OTL.exe
PRC - [2013/12/19 13:37:25 | 001,819,936 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
PRC - [2013/12/19 13:37:25 | 000,930,592 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2013/12/09 21:15:27 | 002,279,712 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
PRC - [2013/12/09 21:14:56 | 001,494,304 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
PRC - [2013/08/27 16:16:14 | 001,028,896 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
PRC - [2013/01/05 09:03:14 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
PRC - [2012/08/01 03:48:54 | 002,345,592 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe
PRC - [2012/01/31 15:02:52 | 007,391,072 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2011/09/09 02:10:56 | 001,082,208 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe
PRC - [2011/08/18 00:33:26 | 000,659,296 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2011/05/23 13:13:04 | 000,657,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe
PRC - [2011/03/28 02:00:52 | 000,351,072 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgcsrvx.exe
PRC - [2011/03/16 15:05:20 | 001,025,888 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgemcx.exe
PRC - [2011/02/10 06:55:18 | 001,148,256 | ---- | M] () -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2011/02/08 04:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe
PRC - [2009/04/11 01:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/01/26 14:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2007/03/23 06:04:54 | 004,423,680 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2007/01/31 20:18:42 | 000,053,248 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
PRC - [2006/12/29 19:51:56 | 000,028,672 | ---- | M] () -- C:\Acer\Empowering Technology\ePerformance\MemCheck.exe


========== Modules (No Company Name) ==========

MOD - [2013/12/03 21:48:04 | 000,399,312 | ---- | M] () -- C:\Users\tylene\AppData\Local\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll
MOD - [2013/12/03 21:48:02 | 004,055,504 | ---- | M] () -- C:\Users\tylene\AppData\Local\Google\Chrome\Application\31.0.1650.63\pdf.dll
MOD - [2013/12/03 21:47:08 | 001,619,408 | ---- | M] () -- C:\Users\tylene\AppData\Local\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll
MOD - [2013/04/21 20:44:32 | 000,087,952 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2013/04/21 20:44:04 | 001,242,952 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/02/10 06:55:18 | 001,148,256 | ---- | M] () -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe


========== Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SBSDWSCService)
SRV - File not found [Auto | Stopped] -- C:\Windows\system32\INCAinternet\nProtect Security Platform 2007\nspsvc.exe -- (NSPService)
SRV - File not found [Auto | Stopped] -- c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon -- (CLTNetCnService)
SRV - [2014/01/11 16:21:57 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/12/09 21:14:56 | 001,494,304 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService)
SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2013/01/05 09:03:14 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE -- (!SASCORE)
SRV - [2012/07/13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/01/31 15:02:52 | 007,391,072 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011/02/08 04:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2010/10/06 10:31:48 | 000,517,448 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe -- (AVG Security Toolbar Service)
SRV - [2008/01/19 02:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/04/04 20:54:08 | 000,266,343 | ---- | M] (CyberLink) [Disabled | Stopped] -- C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe -- (Acer HomeMedia Connect Service)
SRV - [2007/02/07 02:04:26 | 000,457,512 | ---- | M] (HiTRSUT) [Disabled | Stopped] -- C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe -- (eDataSecurity Service)
SRV - [2007/01/31 20:18:42 | 000,053,248 | ---- | M] (Acer Inc.) [Auto | Running] -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe -- (eRecoveryService)
SRV - [2006/12/29 19:51:56 | 000,028,672 | ---- | M] () [Auto | Running] -- C:\Acer\Empowering Technology\ePerformance\MemCheck.exe -- (AcerMemUsageCheckService)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleXNt.sys -- (EagleXNt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleNT.sys -- (EagleNT)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2013/12/19 15:26:04 | 010,471,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2013/04/04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2013/01/05 09:03:12 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2013/01/05 09:03:12 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV)
DRV - [2012/11/12 04:47:48 | 000,255,968 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2011/05/27 18:05:18 | 000,134,480 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2011/05/14 18:17:28 | 000,012,872 | ---- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2011/04/04 23:59:56 | 000,297,168 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011/03/16 15:03:20 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avgrkx86.sys -- (Avgrkx86)
DRV - [2011/03/01 13:25:18 | 000,034,896 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011/02/22 07:12:38 | 000,022,992 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\AVGIDSEH.sys -- (AVGIDSEH)
DRV - [2011/02/10 06:53:30 | 000,028,624 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2011/02/10 06:53:28 | 000,024,144 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2010/11/25 21:16:26 | 000,231,936 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2010/11/17 07:04:12 | 000,097,296 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AtihdLH3.sys -- (AtiHDAudioService)
DRV - [2010/02/11 02:42:22 | 004,450,816 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2010/02/11 02:42:22 | 004,450,816 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2009/06/29 07:58:00 | 000,100,368 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2007/02/02 03:37:36 | 000,982,272 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\smserial.sys -- (smserial)
DRV - [2006/12/07 20:12:02 | 000,076,584 | ---- | M] () [Kernel | Auto | Running] -- C:\Acer\Empowering Technology\eRecovery\int15.sys -- (int15)
DRV - [2006/10/29 22:22:26 | 000,008,192 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\AtiPcie.sys -- (AtiPcie)
DRV - [2005/01/03 01:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\npptNT2.sys -- (NPPTNT2)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.c...rch/search.html
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - SOFTWARE\Classes\CLSID\{03402f96-3dc7-4285-bc50-9e81fefafe43}\InprocServer32 File not found
IE - HKLM\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - SOFTWARE\Classes\CLSID\{EA756889-2338-43DB-8F07-D1CA6FB9C90D}\InprocServer32 File not found
IE - HKLM\..\SearchScopes,DefaultScope = {0B4A10D1-FBD6-451d-BFDA-F03252B05984}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{0B4A10D1-FBD6-451d-BFDA-F03252B05984}: "URL" = http://slirsredirect...mrud=25-10-2010
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7


IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com [binary data]
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SEARCH PAGE = http://us.rd.yahoo.c...//www.yahoo.com
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo....=utf-8&fr=b1ie7
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.abcmouse.com/
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\..\URLSearchHook: {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - SOFTWARE\Classes\CLSID\{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}\InprocServer32 File not found
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - SOFTWARE\Classes\CLSID\{EA756889-2338-43DB-8F07-D1CA6FB9C90D}\InprocServer32 File not found
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\..\SearchScopes\{105E99FF-8B9A-4492-B155-06194B9056D2}: "URL" = http://www.bing.com/...ferrer:source?}
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\..\SearchScopes\{443789B7-F39C-4b5c-9287-DA72D38F4FE6}: "URL" = http://search.aol.co...nType=TB50TRie7
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = https://www.google.c...q={searchTerms}
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\..\SearchScopes\{8FF90DE1-C74E-41C5-9193-5CE4C39DD58D}: "URL" = http://search.yahoo....=utf-8&fr=b1ie7
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://toolbar.ask.c...rchTerms}&crm=1
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\..\SearchScopes\{ECA9AE06-3CE3-401B-BFE4-B1D31CABF64D}: "URL" = http://search.us.com...k={searchTerms}
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@funwebproducts.com/Plugin: C:\Program Files\FunWebProducts\Installr\1.bin\NPFunWeb.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll File not found
FF - HKLM\Software\MozillaPlugins\@virtools.com/3DviaPlayer: C:\Program Files\Virtools\3D Life Player\npvirtools.dll (Dassault Systèmes)
FF - HKCU\Software\MozillaPlugins\@tnt2toolbar.com/Plugin: C:\Users\tylene\AppData\Local\TNT2\2.0.0.1159\npTNT2.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\tylene\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\tylene\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2013/04/10 18:32:55 | 000,000,000 | ---D | M]


========== Chrome ==========

CHR - default_search_provider: Ask Search (Enabled)
CHR - default_search_provider: search_url = http://www.search.as...q={searchTerms}
CHR - default_search_provider: suggest_url = http://ss.websearch....q={searchTerms},
CHR - homepage: http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\tylene\AppData\Local\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\tylene\AppData\Local\Google\Chrome\Application\31.0.1650.63\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\tylene\AppData\Local\Google\Chrome\Application\31.0.1650.63\gcswf32.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\tylene\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\plugins/avgnpss.dll
CHR - plugin: Java Deployment Toolkit 6.0.170.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java™ Platform SE 6 U17 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: 3DVIA player (Enabled) = C:\Program Files\Virtools\3D Life Player\npvirtools.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Google Update (Enabled) = C:\Users\tylene\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Users\tylene\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\tylene\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: AVG Safe Search = C:\Users\tylene\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\
CHR - Extension: Google Wallet = C:\Users\tylene\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0\
CHR - Extension: Gmail = C:\Users\tylene\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2013/12/31 18:06:25 | 000,452,756 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 15549 more lines...
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKU\S-1-5-21-198807665-1997887991-823707001-1000\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Windows\System32\eDStoolbar.dll (HiTRUST)
O3 - HKU\S-1-5-21-198807665-1997887991-823707001-1000\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll File not found
O3 - HKU\S-1-5-21-198807665-1997887991-823707001-1000\..\Toolbar\WebBrowser: (AIM Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [eRecoveryService] File not found
O4 - HKLM..\Run: [NvBackend] C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [Nvtmru] C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\S-1-5-21-198807665-1997887991-823707001-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-198807665-1997887991-823707001-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-198807665-1997887991-823707001-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html File not found
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre7\bin\jp2iexp.dll ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.45.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 204.186.80.229 216.144.187.101 216.144.187.199
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C6A024A7-052B-455B-BACC-0393418B4FED}: DhcpNameServer = 204.186.80.229 216.144.187.101 216.144.187.199
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Users\tylene\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\tylene\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{e5ae8258-5d23-11e0-af8b-001c253cc788}\Shell - "" = AutoRun
O33 - MountPoints2\{e5ae8258-5d23-11e0-af8b-001c253cc788}\Shell\AutoRun\command - "" = K:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2014/01/12 10:07:02 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\tylene\Desktop\OTL.exe
[2014/01/11 19:14:43 | 000,000,000 | ---D | C] -- C:\Windows\LastGood
[2014/01/01 11:26:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Oracle
[2014/01/01 11:26:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2014/01/01 11:24:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2013/12/31 17:01:30 | 000,000,000 | ---D | C] -- C:\SUPERDelete
[2013/12/31 12:33:24 | 000,000,000 | ---D | C] -- C:\Users\tylene\AppData\Local\NVIDIA
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2014/01/12 10:22:40 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2014/01/12 10:22:40 | 000,003,296 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2014/01/12 10:17:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/01/12 10:07:10 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-198807665-1997887991-823707001-1000UA.job
[2014/01/12 10:06:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\tylene\Desktop\OTL.exe
[2014/01/12 08:37:22 | 148,539,411 | ---- | M] () -- C:\Windows\System32\drivers\AVG\incavi.avm
[2014/01/11 19:19:23 | 000,640,530 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014/01/11 19:19:23 | 000,118,782 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014/01/11 18:49:06 | 000,000,143 | ---- | M] () -- C:\Users\tylene\Desktop\ABCmouse.com.url
[2014/01/05 18:07:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-198807665-1997887991-823707001-1000Core.job
[2014/01/01 17:37:39 | 000,472,210 | ---- | M] () -- C:\Windows\System32\drivers\AVG\iavichjg.avm
[2014/01/01 11:20:16 | 000,002,053 | ---- | M] () -- C:\Users\tylene\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2014/01/01 10:22:31 | 000,315,080 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2014/01/01 10:22:26 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/12/31 18:06:25 | 000,452,756 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2013/12/31 12:49:42 | 000,000,870 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/12/19 15:26:04 | 000,053,024 | ---- | M] (Khronos Group) -- C:\Windows\System32\OpenCL.dll
[2013/12/19 15:26:04 | 000,018,439 | ---- | M] () -- C:\Windows\System32\nvinfo.pb
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files Created - No Company Name ==========

[2014/01/11 18:49:06 | 000,000,143 | ---- | C] () -- C:\Users\tylene\Desktop\ABCmouse.com.url
[2013/12/31 12:41:22 | 000,018,439 | ---- | C] () -- C:\Windows\System32\nvinfo.pb
[2012/09/25 05:00:39 | 000,033,958 | ---- | C] () -- C:\ProgramData\uninstaller.exe
[2012/08/16 13:49:39 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2012/05/10 16:48:45 | 000,422,966 | ---- | C] () -- C:\Users\tylene\spring-paisley-by-valentina-ramos.jpg
[2012/05/10 16:46:52 | 000,437,709 | ---- | C] () -- C:\Users\tylene\paisley-by-chelmers.jpg
[2012/05/10 16:45:59 | 000,111,935 | ---- | C] () -- C:\Users\tylene\amy_butler_soul_blossoms_dancing_paisley_in_lemon.jpg
[2012/05/10 16:42:43 | 000,093,800 | ---- | C] () -- C:\Users\tylene\paisley.jpg
[2012/03/08 15:57:42 | 000,000,154 | ---- | C] () -- C:\Users\tylene\AppData\Roaming\wklnhst.dat
[2011/12/18 22:31:33 | 000,000,552 | ---- | C] () -- C:\Users\tylene\AppData\Local\d3d8caps.dat
[2011/09/06 14:24:27 | 000,138,056 | ---- | C] () -- C:\Users\tylene\AppData\Roaming\PnkBstrK.sys
[2011/05/18 23:11:00 | 000,012,288 | ---- | C] () -- C:\Users\tylene\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/12 14:54:25 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011/03/11 18:19:35 | 000,001,362 | -HS- | C] () -- C:\ProgramData\1799715130
[2007/12/05 21:27:48 | 000,000,632 | RHS- | C] () -- C:\Users\tylene\ntuser.pol
[2007/12/05 21:19:44 | 000,001,356 | ---- | C] () -- C:\Users\tylene\AppData\Local\d3d9caps.dat

========== ZeroAccess Check ==========

[2006/11/02 07:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 12:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/11 01:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 01:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/01/04 21:41:38 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2013/01/04 21:41:38 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
[2012/04/12 15:46:45 | 000,000,000 | ---D | M] -- C:\Users\tylene\AppData\Roaming\.minecraft
[2008/04/10 01:56:29 | 000,000,000 | ---D | M] -- C:\Users\tylene\AppData\Roaming\acccore
[2007/12/05 21:01:02 | 000,000,000 | ---D | M] -- C:\Users\tylene\AppData\Roaming\Acer
[2010/11/01 09:33:18 | 000,000,000 | ---D | M] -- C:\Users\tylene\AppData\Roaming\AVG10
[2011/01/16 11:45:27 | 000,000,000 | ---D | M] -- C:\Users\tylene\AppData\Roaming\EurekaLog
[2009/12/01 17:44:10 | 000,000,000 | ---D | M] -- C:\Users\tylene\AppData\Roaming\fretsonfire
[2008/06/15 10:11:13 | 000,000,000 | ---D | M] -- C:\Users\tylene\AppData\Roaming\FrostWire
[2007/12/05 21:01:01 | 000,000,000 | ---D | M] -- C:\Users\tylene\AppData\Roaming\Leadertech
[2008/06/15 09:59:03 | 000,000,000 | ---D | M] -- C:\Users\tylene\AppData\Roaming\LimeWire
[2012/03/06 21:48:03 | 000,000,000 | ---D | M] -- C:\Users\tylene\AppData\Roaming\Mumble
[2012/09/25 05:03:49 | 000,000,000 | ---D | M] -- C:\Users\tylene\AppData\Roaming\OpenOffice.org
[2012/03/08 15:57:55 | 000,000,000 | ---D | M] -- C:\Users\tylene\AppData\Roaming\Template

========== Purity Check ==========



< End of report >

This log just popped up after several mins.

OTL Extras logfile created on: 1/12/2014 10:22:07 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\tylene\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.50 Gb Total Physical Memory | 1.18 Gb Available Physical Memory | 47.07% Memory free
5.23 Gb Paging File | 3.58 Gb Available in Paging File | 68.30% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111.70 Gb Total Space | 24.49 Gb Free Space | 21.93% Space Free | Partition Type: NTFS
Drive D: | 111.43 Gb Total Space | 111.33 Gb Free Space | 99.91% Space Free | Partition Type: NTFS

Computer Name: TYLENE-PC | User Name: tylene | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0A284193-7579-49B2-A756-225EEB9CAFAE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0EFE6A0F-DE20-4B7E-96F5-9B93A61538F9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{1EE0BAF8-8C7C-4CFB-A0FA-D9F5AB9CB5F9}" = lport=2869 | protocol=6 | dir=in | app=system |
"{32F4B00F-FA2A-4A8A-A08A-DF9F386DCAF5}" = lport=2869 | protocol=6 | dir=in | app=system |
"{353B9E95-235B-4541-8589-6808680224B6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{362A40FA-7D03-46A2-A743-FF9F39C7691D}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{384CF205-57F3-45E5-9B8F-8B1CEF686FA0}" = lport=80 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\netservice\nvnetworkservice.exe |
"{44CFC842-CBF5-476C-B6F8-47D234CF1A1F}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{47DEE498-79D1-4544-ACFE-0A0CF9A26A35}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{6E01B5EB-BC11-4F6E-8ADA-68D4B0C7E1E9}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{7911C26C-A5F3-4AA0-973E-BD464266AA9B}" = lport=443 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\netservice\nvnetworkservice.exe |
"{799756BA-35C1-4544-B649-24FC6AC8CF0F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{8CA7C029-D75B-4E3B-8C66-EFF4E5286ED3}" = lport=10243 | protocol=6 | dir=in | app=system |
"{8FE7DA23-33F7-415C-8853-28A03993B3AF}" = rport=10243 | protocol=6 | dir=out | app=system |
"{9CA7093A-02E9-4E0D-B658-2FAE368660ED}" = lport=6881 | protocol=6 | dir=in | name=blizzard downloader: 6881 |
"{AAA7C920-6606-4D4F-8B0D-4E55276F70F4}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{B9249A3E-ED20-4A2D-979B-31A93E63C6FA}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 |
"{C4948A81-BC8B-411E-887A-757381AFA6B2}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01F1BE07-22BE-4820-BDEC-1460A33C4C8C}" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\blizzard downloader.exe |
"{02FCAA3A-8A3D-4435-95CA-71382C20371F}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe |
"{03D6B426-DA69-4332-8E98-60E71148703C}" = protocol=17 | dir=in | app=c:\nexon\combat arms\engine.exe |
"{0543A820-03AD-4048-B1B4-9B916721D730}" = protocol=6 | dir=in | app=c:\program files\world of warcraft\launcher.exe |
"{0E418E33-A247-4735-AC56-B69A6B3DFAE3}" = protocol=17 | dir=in | app=c:\ngm\ngm.exe |
"{104C5CCB-0164-44DE-AE26-E629DC2D4815}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{10AAD3ED-2CD1-4346-9E23-61EE633CD235}" = protocol=6 | dir=in | app=c:\program files\reactor\ijjioptimizer.exe |
"{1175A6DD-29A6-4970-A4D6-6EA1D6B0ADBC}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{15011D1B-9230-4502-A82D-ABDE56C4F366}" = protocol=17 | dir=in | app=c:\program files\reactor\ijjioptimizer.exe |
"{18656F46-6C5E-49C7-9D51-9508B0BE3D0E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1955E669-BE1F-4C13-B854-FB32F2900974}" = dir=in | app=c:\program files\acer arcade live\acer homemedia connect\kernel\dms\clmsserver.exe |
"{1A0801E4-C586-41E2-9A05-497D7AFBD36E}" = protocol=6 | dir=out | app=system |
"{1CC076D9-6828-4233-AE5D-4DE9A898995C}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |
"{1DAEB0EB-1F2B-457A-9F1A-9ED85E2A781F}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{2360AD26-E039-42F6-99D5-148801936859}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{23BB9AC8-3B87-4548-BE20-A4E5E6F00B22}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe |
"{27F3C1E8-BD04-45E3-92AA-EEB2C10BCCA5}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe |
"{2997449D-C312-4A23-983E-746B6434C1E3}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"{2A3284A1-5F44-4C16-A9AC-D97C3FA579BD}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
"{2A70D7B6-1DD3-4F8E-9508-285B6F824ECF}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{2E253BF3-C710-4D32-8775-2EBE1645272B}" = protocol=6 | dir=in | app=c:\nexon\combat arms\nmservice.exe |
"{33DD0D81-FAA2-4613-8E73-54A420DACCAB}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{33E16C6E-9CC1-4BB9-8248-1361C03C86E7}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{353346C9-88D2-4F2B-B06B-4DB59C7DE656}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe |
"{39C15E90-E0D9-40D1-96CC-D85D73084862}" = protocol=17 | dir=in | app=c:\program files\malwarebytes' anti-malware\mbam.exe |
"{3C1F099B-C469-4D22-B78F-0A21345D2E15}" = protocol=17 | dir=in | app=c:\program files\diablo iii\diablo iii.exe |
"{3CEC30A6-8B5A-4AC9-85E8-3C8583B6AB32}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{3F5D1730-BBBD-4F6F-94D5-303AD5E9E3F5}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{3F8E7F0C-6AC2-47E2-BA94-7593D3E1B672}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{40CF92F9-3A2E-44E0-966A-D3621C9CDCF6}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-enus-downloader.exe |
"{40E5137A-44C0-46DD-80C6-7FA5C4074E1A}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{423737C1-0043-4395-A377-5ACBA995B85D}" = protocol=6 | dir=in | app=c:\ngm\ngm.exe |
"{4341EBC5-C98E-4C43-8D9B-BBAF1E75EC30}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"{4858C672-8913-401C-B061-35C5061D0EE6}" = protocol=17 | dir=in | app=c:\nexon\combat arms\combatarms.exe |
"{4D4DC209-7CC2-4F5B-AC82-FD61E1485584}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{4FDBBD8C-BBB8-4626-AD09-9E2591F693DA}" = protocol=6 | dir=in | app=c:\nexon\combat arms\engine.exe |
"{51FC7DF5-AE5F-4957-9215-E59A62A66F5D}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe |
"{55B1C7DC-7880-407A-961E-BE4025220C47}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{57CF1F95-0C1E-4990-A3FC-75CB6A0A68F7}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe |
"{5954CBF7-5734-4779-A4B5-AB6FB1E994DB}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.2.9901-to-3.1.3.9947-enus-downloader.exe |
"{5EB3679D-F825-4AC6-A248-540F1B137A96}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5F06C73B-3B46-4ED5-983C-2880071833B2}" = dir=in | app=c:\program files\acer arcade live\acer homemedia connect\homemedia connect.exe |
"{64C52DD3-2977-4C34-BDA1-8FD96179DF00}" = dir=in | app=c:\program files\acer arcade live\slideshow dvd\component\clsldvd.exe |
"{65B6DA2F-C470-4696-B8C1-65AEBAFE8C6E}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe |
"{6830174A-753D-404E-9720-262EFDE15C99}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6CDB8785-C83C-4688-9C5A-801A00C49DD9}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{6F50B5F0-7A15-407E-8541-38AE43B8E58B}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |
"{7518E0EC-A528-4A2E-B823-D9263FBA984B}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |
"{7A70955E-FFF3-4FCE-A8F1-B46A8493C663}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.2.9901-to-3.1.3.9947-enus-downloader.exe |
"{7C43695F-1B33-41C8-BCE2-7D1241C84E05}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-enus-downloader.exe |
"{7C465A77-2DA0-4E03-BC06-6E425C68A19D}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{7E942602-C888-434C-B880-C4C453E6ED48}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"{8122CA6D-B25D-4AE7-A688-10717D25E4E2}" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
"{84D120FD-8D90-4F4A-BBC6-11FA6FFAE50C}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{8A96D29D-04C0-4922-A949-240DA5336E93}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{8BB0C99E-4DA6-468A-9BA9-2BE1E1A03E26}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe |
"{8E37B6CA-1EB0-4C16-A60A-DDCD1D255975}" = protocol=17 | dir=in | app=c:\program files\7-zip\7zfm.exe |
"{9480E193-EE2D-448C-820B-9F4252D72C51}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"{953973B5-860E-4962-B940-99D8EFC82113}" = protocol=6 | dir=in | app=c:\program files\diablo iii\diablo iii.exe |
"{A0005963-1D47-4836-8E2D-D422F6C02875}" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
"{A0E22BD1-9D17-41A4-BF50-419B503C50D0}" = dir=in | app=c:\program files\acer arcade live\acer dv magician\component\dvax2process.exe |
"{A1290D40-45B3-4D6A-ABA3-9345CEFAE026}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A29EB778-A598-4AFB-A02B-3AAF0582A211}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{A3A4C078-0F1A-4303-B561-92FF33DC1F74}" = protocol=17 | dir=in | app=c:\nexon\combat arms\nmservice.exe |
"{A47B9B4C-CC99-4D7B-ACAA-8A0487E4376D}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{A4B01E6D-E5C2-42BC-B2CA-BA114D197A89}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{A58686B6-9F63-47B9-806B-8BAC32497EA0}" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\launcher.patch.exe |
"{A763DBAD-652E-442E-92A7-0BCB0A82A3FA}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A8757501-B402-4C19-AD10-EA4697A9512B}" = dir=in | app=c:\program files\acer arcade live\acer videomagician\videomagician.exe |
"{ABC648F9-D27E-480E-8BED-107A8E823CD3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{AD8A6BF5-CE11-4215-B3E0-933D801C5AA1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{AF1BBD3E-46EA-410F-AD5F-AAE1D658167D}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe |
"{B243D1FD-5397-4038-8AB3-FF20EA3A2563}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{B581826C-68F8-4CAF-8A83-76191C779A2A}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{B617E48C-6910-4904-B9C7-EE1284E22C3E}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{B685A922-CF7A-4F72-80E6-357132F86720}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{BF188B5F-1F47-4373-88ED-7C25E04A8A72}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{C0B04953-9D63-4886-9FEE-B20972592777}" = dir=in | app=c:\program files\acer arcade live\acer arcade live main page\acer arcade live.exe |
"{C191D004-450C-4CFD-A5D8-34DEA6A13EC9}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{C35ECBFE-FECE-4DD5-96F1-72D6331AED93}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{C5A6A6A0-D297-4AA6-9383-21A16C3F9929}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{C5F1E16C-E4FC-43D9-877C-0F20E7E19D41}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{C8852AB5-E36C-47DC-8CFC-CAF4E8A20E3B}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe |
"{CB148BE8-9A09-414F-A047-5499FFB01B15}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe |
"{CD423AFD-6913-4EF9-BE4B-EDC2B9596BEA}" = protocol=6 | dir=in | app=c:\program files\malwarebytes' anti-malware\mbam.exe |
"{CEAEC2ED-8B65-4B9F-9095-F93FE57F6137}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |
"{CF31282A-32A1-4334-84F7-1FFB234858A0}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{CFC3BC11-D992-4A82-B174-774575C66EEB}" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\blizzard downloader.exe |
"{D0C6FF09-29A4-4F4D-99ED-B9E4CD3E9904}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{D2023506-A8DD-4E94-B5A0-D1A8EE080279}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D3838423-88F1-4F9E-BA2A-4ECCADB0A8E3}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{D6BF55CF-E20E-45B4-94C6-17D55A03E638}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{D7226279-F468-4FFE-909D-5E19DB37F86D}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{D8A0F955-55FA-4061-B2B7-C40E573D7DD1}" = protocol=6 | dir=in | app=c:\nexon\combat arms\combatarms.exe |
"{DF5F81F6-BD0C-488A-9461-358427412D6A}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{DFFF3429-DA90-43DB-898C-FAEEFE3F39E2}" = dir=in | app=c:\program files\acer arcade live\acer homemedia\homemedia.exe |
"{E0F0629E-160C-40C8-BD43-E405A9E6CAC8}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe |
"{E1F95799-C729-47F2-AA64-6D287C222D72}" = protocol=6 | dir=in | app=c:\program files\7-zip\7zfm.exe |
"{E59634F8-1C07-40AC-84E1-E301FBC238EE}" = dir=in | app=c:\program files\acer arcade live\acer dvdivine\dvdivine.exe |
"{EA7B8C5F-0052-4061-9CC1-BA928CE5AE6F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{EBBAA889-1542-4B7A-8AB4-C0FB5382F9F3}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{ED1511EE-5BAC-4BE0-A000-B7FB41DD1597}" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\launcher.patch.exe |
"{ED1E9675-5C5C-4552-8979-8FFBD704C996}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{EDECD3AD-184E-4832-9890-D4626CCE3D24}" = protocol=17 | dir=in | app=c:\program files\world of warcraft\launcher.exe |
"{EF342487-8AB3-4642-BA56-A374AA5E6973}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F045CDC5-A1B0-4F23-B6CE-B7FB52DD10FD}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"{F42A10AE-D383-4A78-9E05-64BBC84376C5}" = dir=in | app=c:\program files\acer arcade live\acer dv magician\component\arawp.exe |
"{F9DE4F7E-02CE-4B68-8807-58B1C864B107}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{FACE2135-6513-4C7A-8D03-47B35641F21A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FB6B7BE1-8026-4AA9-91F1-710CDFFA401C}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe |
"{FC855D24-FA77-42F3-A2C2-9793636C22ED}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe |
"{FEC4F87D-DE04-4AA6-A9B7-3C87EED9290A}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"TCP Query User{04444929-8E9F-49AD-BA3B-A7827AC6998E}C:\program files\unreal tournament 3\binaries\ut3.exe" = protocol=6 | dir=in | app=c:\program files\unreal tournament 3\binaries\ut3.exe |
"TCP Query User{22844458-F8D1-43D3-B07A-C0A6B3B9B082}C:\users\[bleep] sucker\rohanclient.exe" = protocol=6 | dir=in | app=c:\users\[bleep] sucker\rohanclient.exe |
"TCP Query User{262B37C9-55FB-4C50-AC81-3C476427A36A}C:\program files\reactor\reactor.exe" = protocol=6 | dir=in | app=c:\program files\reactor\reactor.exe |
"TCP Query User{294B3D62-291A-4B1E-AFA1-0686004ADCAB}C:\users\public\games\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe |
"TCP Query User{33974345-25BF-43D1-8534-50C6858EC516}C:\program files\aim6\aim6.exe" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"TCP Query User{35D24B9C-3FCA-42E4-85AC-2341EAF1E8F9}C:\program files\electronic arts\medal of honor\binaries\moh.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\medal of honor\binaries\moh.exe |
"TCP Query User{371ECC4F-46C0-4546-8C6F-C7542308726D}C:\users\[bleep] sucker\appdata\local\temp\blizzard launcher temporary - b5e56cd8\launcher.exe" = protocol=6 | dir=in | app=c:\users\[bleep] sucker\appdata\local\temp\blizzard launcher temporary - b5e56cd8\launcher.exe |
"TCP Query User{50EE071C-6A76-411F-8AF4-C082CBA35B1A}C:\users\public\games\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe |
"TCP Query User{51819A09-F2EB-4BBD-A6F5-12CA40BAF309}C:\users\[bleep] sucker\appdata\local\temp\blizzard launcher temporary - 0e0153c0\launcher.exe" = protocol=6 | dir=in | app=c:\users\[bleep] sucker\appdata\local\temp\blizzard launcher temporary - 0e0153c0\launcher.exe |
"TCP Query User{5E4197D0-77B2-46F6-8877-992624166369}C:\program files\electronic arts\medal of honor\mp\mohmpgame.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\medal of honor\mp\mohmpgame.exe |
"TCP Query User{609F3066-5817-4D3C-B230-9BD80C337812}C:\users\[bleep] sucker\desktop\wow-2.4.3.8568-to-3.0.2.8916-enus-downloader.exe" = protocol=6 | dir=in | app=c:\users\[bleep] sucker\desktop\wow-2.4.3.8568-to-3.0.2.8916-enus-downloader.exe |
"TCP Query User{750CFBD8-A6BC-40F5-BF33-662D884227CD}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{8711B33A-8584-4697-8B7E-BDA67B04848A}C:\program files\world of warcraft\repair.exe" = protocol=6 | dir=in | app=c:\program files\world of warcraft\repair.exe |
"TCP Query User{89013C02-3915-4F39-88F2-A9524DBBDACF}C:\users\public\games\world of warcraft\wow-4.2.1.2736-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\wow-4.2.1.2736-enus-tools-downloader.exe |
"TCP Query User{8C1D5EE9-DE2B-4296-A630-E2E4246F835D}C:\users\public\games\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\backgrounddownloader.exe |
"TCP Query User{A6585C2E-CBA2-44FC-AAF7-1241A4ADC056}C:\users\public\games\world of warcraft\wow-4.2.1.2730-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\wow-4.2.1.2730-enus-tools-downloader.exe |
"TCP Query User{A842EA2C-5D19-477E-A80E-5894142B12E3}C:\users\[bleep] sucker\appdata\roaming\myspace\im\bin\myspaceim.exe" = protocol=6 | dir=in | app=c:\users\[bleep] sucker\appdata\roaming\myspace\im\bin\myspaceim.exe |
"TCP Query User{B8BC4268-BEC7-486E-B6DA-DE34EBB718EE}C:\users\public\games\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"TCP Query User{EA0620C4-F959-4233-9E7B-703231A97257}C:\program files\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\program files\world of warcraft\backgrounddownloader.exe |
"TCP Query User{FE342EBC-3217-41E1-8ACB-EA412B7EB33A}C:\program files\frostwire\frostwire.exe" = protocol=6 | dir=in | app=c:\program files\frostwire\frostwire.exe |
"UDP Query User{092966BF-8D84-43F2-9AA8-32FCD5B987EF}C:\users\[bleep] sucker\appdata\local\temp\blizzard launcher temporary - 0e0153c0\launcher.exe" = protocol=17 | dir=in | app=c:\users\[bleep] sucker\appdata\local\temp\blizzard launcher temporary - 0e0153c0\launcher.exe |
"UDP Query User{0A44B8CE-8A0B-4E4C-B526-5F04B86E3581}C:\users\[bleep] sucker\desktop\wow-2.4.3.8568-to-3.0.2.8916-enus-downloader.exe" = protocol=17 | dir=in | app=c:\users\[bleep] sucker\desktop\wow-2.4.3.8568-to-3.0.2.8916-enus-downloader.exe |
"UDP Query User{0AC80537-9468-4B53-93EA-89BBB01089DC}C:\program files\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\program files\world of warcraft\backgrounddownloader.exe |
"UDP Query User{2550E130-ADB4-4265-9ED3-A6BB80E07DE2}C:\users\public\games\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe |
"UDP Query User{28C4C946-37ED-4810-AA08-F602411860C6}C:\program files\electronic arts\medal of honor\mp\mohmpgame.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\medal of honor\mp\mohmpgame.exe |
"UDP Query User{2EF936D0-8924-46A1-9CAB-CB63AF765327}C:\users\public\games\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\backgrounddownloader.exe |
"UDP Query User{3EA77F15-23D5-4921-8170-D5CA858056FE}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{406850FF-85C6-469F-88EA-CC35F000B224}C:\users\[bleep] sucker\appdata\local\temp\blizzard launcher temporary - b5e56cd8\launcher.exe" = protocol=17 | dir=in | app=c:\users\[bleep] sucker\appdata\local\temp\blizzard launcher temporary - b5e56cd8\launcher.exe |
"UDP Query User{4FB23641-FFA8-46BE-B750-D6D00C7B464F}C:\program files\reactor\reactor.exe" = protocol=17 | dir=in | app=c:\program files\reactor\reactor.exe |
"UDP Query User{5FFD3770-BF29-414B-9873-457D0B7F0BDA}C:\program files\aim6\aim6.exe" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"UDP Query User{661684A7-8B26-423E-ADF8-CAAEDCB00B13}C:\program files\unreal tournament 3\binaries\ut3.exe" = protocol=17 | dir=in | app=c:\program files\unreal tournament 3\binaries\ut3.exe |
"UDP Query User{75C8C69B-BE55-4BD7-84FB-85A17D40CE23}C:\users\[bleep] sucker\appdata\roaming\myspace\im\bin\myspaceim.exe" = protocol=17 | dir=in | app=c:\users\[bleep] sucker\appdata\roaming\myspace\im\bin\myspaceim.exe |
"UDP Query User{968D3D5D-9970-4DA0-8896-AB47E12D062E}C:\program files\frostwire\frostwire.exe" = protocol=17 | dir=in | app=c:\program files\frostwire\frostwire.exe |
"UDP Query User{97FC1154-FE73-47D0-8E68-EAE5673BE7A0}C:\program files\world of warcraft\repair.exe" = protocol=17 | dir=in | app=c:\program files\world of warcraft\repair.exe |
"UDP Query User{9B09DD48-ACB0-4ABA-9EEB-998435CE5714}C:\program files\electronic arts\medal of honor\binaries\moh.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\medal of honor\binaries\moh.exe |
"UDP Query User{C2B2549C-5195-4EA0-9195-1CA130454A82}C:\users\public\games\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe |
"UDP Query User{DB3DFED5-8FC5-403F-8CAB-0DEABE200A95}C:\users\public\games\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"UDP Query User{E012B638-9EAE-44BF-A35C-1B70F8BE2501}C:\users\public\games\world of warcraft\wow-4.2.1.2736-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\wow-4.2.1.2736-enus-tools-downloader.exe |
"UDP Query User{EC957B91-311B-4733-81A9-7A79DA72875B}C:\users\[bleep] sucker\rohanclient.exe" = protocol=17 | dir=in | app=c:\users\[bleep] sucker\rohanclient.exe |
"UDP Query User{FBA34C74-FAEC-4E31-AE83-E8B5081A5EE8}C:\users\public\games\world of warcraft\wow-4.2.1.2730-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\wow-4.2.1.2730-enus-tools-downloader.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{021661E0-C377-C87B-9583-E0A69E61A489}" = Catalyst Control Center Localization Thai
"{023387B5-AF74-D690-D2C6-C8D474597284}" = CCC Help Polish
"{042B8532-E27C-C06E-A8F5-71F36B98B2DE}" = Catalyst Control Center Localization Portuguese
"{07AE9F43-360F-7412-577B-2B4B73E5EAB9}" = CCC Help Hungarian
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0C09E020-9996-4E1C-9839-97DA8F9C8D6B}" = CCC Help Danish
"{132888AE-EF67-41C5-BCA2-7D5D2488AB63}" = Acer HomeMedia Connect
"{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2224B408-E7E4-15CF-0674-EC7C36D68741}" = Catalyst Control Center Localization Hungarian
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{236D1288-99DB-C3D6-D132-EDE6317BF619}" = CCC Help Japanese
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 45
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
"{2AABA091-41DF-D0D3-83F8-0133F8C7AA97}" = Catalyst Control Center Localization Swedish
"{317DE552-B622-0DD2-4E7E-28400D64C100}" = Catalyst Control Center Localization Dutch
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{41581EF5-45A7-11DA-9D78-000129760D75}" = Acer SlideShow DVD
"{42DF661F-6351-B582-DE2C-B8C46B30303F}" = CCC Help Dutch
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4E868D3D-6EEB-4273-926C-2287236B5B79}" = 3DVIA player 5.0
"{4F5641C5-409C-7E5A-A2F9-B6D00A190B55}" = Catalyst Control Center Graphics Previews Vista
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{56504C77-8B9F-4EB2-B33B-C5B9F50B5D64}" = AVG 2011
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{5EA96EEF-4E57-C1F0-6A06-088191FE110C}" = CCC Help Thai
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{67ADE9AF-5CD9-4089-8825-55DE4B366799}" = NTI Backup NOW! 4.7
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7007D9E6-F820-CFEA-EB87-9C9377A967F7}" = CCC Help Swedish
"{710EA46C-2A49-F39A-5EC7-3884DC5329D7}" = Catalyst Control Center Localization Spanish
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{74AF0F2A-A87D-B6B7-6671-61B53F98254B}" = Catalyst Control Center Localization Turkish
"{760F3E42-B1E4-5324-4C4A-0459C8938B6A}" = Catalyst Control Center Localization Italian
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
"{7B5AA67E-FEA0-40BB-BAB5-CA56645A589C}" = NVIDIA PhysX
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{837F9742-DCC8-3FF4-5066-E11E48EE2391}" = Catalyst Control Center Localization Korean
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86861408-CB40-247E-B851-608792116658}" = CCC Help Norwegian
"{86E71966-9EE0-9AD3-2C17-FC3A0B8BB810}" = Catalyst Control Center Localization Chinese Standard
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8BCA7792-CF78-46C6-66A7-EB9A8F0FB0A2}" = Catalyst Control Center Localization Russian
"{8C42C789-B0EF-3226-9069-D1956B220B38}" = Catalyst Control Center Localization Greek
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{901DC58A-5C1B-4315-BA40-5AD3D3A463B9}" = REACTOR
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{91FD46D2-4FB7-4A51-8637-556E1BE1DB7C}" = iTunes
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{94389919-B0AA-4882-9BE8-9F0B004ECA35}" = Acer Tour
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C353B52-07E4-07A7-B95F-392D8AA37210}" = Catalyst Control Center Localization Japanese
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9DBB76DD-812B-26E9-C681-B7CD2DA27A78}" = CCC Help French
"{9F96AFEF-28F1-2479-1D6A-33F8D4A7BF11}" = CCC Help Chinese Standard
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A10FCB8E-F4C3-0C5E-4FFC-8C9A560095A8}" = CCC Help Russian
"{A6038CD2-72AF-2C0A-C1A3-93D360F5A889}" = CCC Help Korean
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA4BF92B-2AAF-11DA-9D78-000129760D75}" = Acer HomeMedia
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB6097D9-D722-4987-BD9E-A076E2848EE2}" = Acer Empowering Technology
"{AE223864-BFA1-1F17-49B2-13C8971DACA2}" = Catalyst Control Center Localization German
"{AEEAE013-92F1-4515-B278-139F1A692A36}" = Acer eDataSecurity Management
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B145EC69-66F5-11D8-9D75-000129760D75}" = Acer DVDivine
"{B22D8435-CB77-849A-B9AE-D1737A073914}" = Catalyst Control Center Localization Polish
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 332.21
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 332.21
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 1.8.1
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 332.21
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.13.0725
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 10.11.15
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer" = NVIDIA LED Visualizer 1.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service" = NVIDIA Network Service
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C485A66D-3521-20E8-2A7B-F060B1773491}" = Catalyst Control Center Localization French
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C792A75A-2A1F-4991-9B85-291745478A79}" = NetAssistant
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D462BF9E-0C35-4705-BF9B-3DF9F3816643}" = Acer ePerformance Management
"{D5E905F1-7657-7B1E-E5BD-2C69C89C8ABE}" = CCC Help Italian
"{D68ED35B-7D9B-4F5F-B38A-92286DDE2EBF}" = AVG 2011
"{D6DB00A1-4BCC-AB1B-24C2-0999BDA43D85}" = CCC Help Greek
"{D7D4DB0F-9070-AED1-D2F4-D11BD42C7588}" = CCC Help Chinese Traditional
"{D7F01E28-9D36-F8EC-872F-9FD71792F858}" = CCC Help Finnish
"{DA6AB13B-4D72-6EBB-AA4D-656CE9C0E512}" = CCC Help English
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DF59BA36-54DC-6BB4-FCED-C9B9F2BCB4AE}" = CCC Help Spanish
"{E0325EFE-9D02-0F1E-7306-F4D95979715A}" = Catalyst Control Center Localization Chinese Traditional
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E14ADE0E-75F3-4A46-87E5-26692DD626EC}" = Apple Mobile Device Support
"{E63AA3F4-5647-0BC8-24FC-F40CFE56B579}" = Catalyst Control Center Localization Norwegian
"{E6541F6A-3D2D-30E5-57F9-4DD411C2E4F0}" = CCC Help German
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{E720B248-D9F5-5E20-8E72-3E419D45D703}" = Catalyst Control Center Localization Finnish
"{E8E32E53-18F7-095E-CC75-F77E412F1AD9}" = CCC Help Portuguese
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}" = Acer Arcade Live Main Page
"{F09030B7-7B8A-30DE-539B-607C9B1831DB}" = CCC Help Czech
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{F6EFFB76-4A07-11DA-9D78-000129760D75}" = Acer DV Magician
"{F76D7388-A433-E572-4718-CD3421738166}" = CCC Help Turkish
"{F79A208D-D929-11D9-9D77-000129760D75}" = Acer VideoMagician
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"7-Zip" = 7-Zip 4.57
"Acer Assist" = Acer Assist
"Acer Registration" = Acer Registration
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AVG" = AVG 2011
"Combat Arms" = Combat Arms
"Driver Cleaner Pro" = DH Driver Cleaner Professional Edition
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"My Interactive Pooh™" = My Interactive Pooh™
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"The Weather Channel Desktop" = The Weather Channel Desktop
"WinLiveSuite" = Windows Live Essentials
"Wireless Keyboard" = Wireless Keyboard
"World of Warcraft" = World of Warcraft

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-198807665-1997887991-823707001-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 1/3/2014 01:00:01 | Computer Name = tylene-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 1/3/2014 01:00:02 | Computer Name = tylene-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 1/4/2014 01:00:01 | Computer Name = tylene-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 1/4/2014 01:00:02 | Computer Name = tylene-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 1/5/2014 01:00:01 | Computer Name = tylene-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 1/5/2014 01:00:01 | Computer Name = tylene-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 1/11/2014 20:14:30 | Computer Name = tylene-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 1/11/2014 20:14:32 | Computer Name = tylene-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 1/11/2014 20:18:36 | Computer Name = tylene-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 1/11/2014 20:18:36 | Computer Name = tylene-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 1/12/2014 11:21:48 | Computer Name = tylene-PC | Source = Application Hang | ID = 1002
Description = The program OTL.exe version 3.2.69.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 20cc Start Time: 01cf0fa7d91104c0 Termination Time: 15

[ Media Center Events ]
Error - 10/6/2008 23:48:42 | Computer Name = tylene-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 1/19/2009 14:31:15 | Computer Name = tylene-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 4/29/2009 23:17:20 | Computer Name = tylene-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 5/27/2009 15:28:57 | Computer Name = tylene-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 6/29/2009 19:27:32 | Computer Name = tylene-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 7/15/2009 15:32:09 | Computer Name = tylene-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 11/29/2009 14:44:45 | Computer Name = tylene-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 12/13/2009 20:50:26 | Computer Name = tylene-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ System Events ]
Error - 1/9/2014 13:22:40 | Computer Name = tylene-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 1/10/2014 07:31:27 | Computer Name = tylene-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 1/10/2014 07:31:27 | Computer Name = tylene-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 1/10/2014 07:31:27 | Computer Name = tylene-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 1/11/2014 01:11:33 | Computer Name = tylene-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 1/11/2014 01:11:33 | Computer Name = tylene-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 1/11/2014 01:11:33 | Computer Name = tylene-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 1/11/2014 19:17:52 | Computer Name = tylene-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 1/11/2014 19:17:52 | Computer Name = tylene-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 1/11/2014 19:17:52 | Computer Name = tylene-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =


< End of report >

Edited by Darrel Rude, 12 January 2014 - 11:14 AM.

  • 0

Advertisements


#2
crooleeck

crooleeck

    Member

  • Member
  • PipPipPip
  • 882 posts
Hi Darrel Rude and welcome at GeekstoGo!

I'm crooleeck and I'll try to help you. But first please notice that I'm not limitless, I'm not familiar with all software, I don't know everything. However, it has taken me years to learn what I know. I would be glad to help you.

Please be patient with me as I am currently in training, and all of my responses to you have to be reviewed by my instructor before I post them. Just keep in mind that you get the advantage as you have 2 people examining your issue.

Fight against malware is NOT instantaneous, most infections require several courses of action to completely eradicate. It's also time-consuming, so be patient! We all like to know final result, so if you have since resolved the issues you were originally experiencing, or have received help elsewhere, please post.

Note:
  • Please watch this topic.
  • Do exactly - step by step - what I wish for. Don't be afraid! If there's anything you don't understand, stop and ask!
  • Please don't run unsupervised tools or fix on your own without my direction - it can be dangerous
  • You must reply within 3 days or your topic will be closed

Also if there is a program that I could use to block any porn on this PC that would be wonderful since we have grand kids and older nephews using this.

First, let me fix main problems. I'll give you a couple of advice about security when we can work on clean machine. ;)

Step 1:
  • Download aswMBR to your desktop.
  • Double click the aswMBR.exe to run it.
  • Agreed to update.
  • Click the Scan button to start scan.

    Posted Image
  • On completion of the scan click Save log, save it to your desktop and post in your next reply

Step 2:
Please navigate to C:\Users\tylene\Desktop\Extras.txt and post the content.

Step 3:
Download AdwCleaner to your desktop.
  • run AdwCleaner and select Scan
  • When finished, hit the Log buton
  • Notepad will open, please copy content and post in next replay

In your next post I want to see:
  • content of Extras.txt
  • aswMBR scan log
  • AdwCleaner scan log

  • 0

#3
Darrel Rude

Darrel Rude

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
As per request logs on the way.

OTL Extras logfile created on: 1/12/2014 10:22:07 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\tylene\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.50 Gb Total Physical Memory | 1.18 Gb Available Physical Memory | 47.07% Memory free
5.23 Gb Paging File | 3.58 Gb Available in Paging File | 68.30% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 111.70 Gb Total Space | 24.49 Gb Free Space | 21.93% Space Free | Partition Type: NTFS
Drive D: | 111.43 Gb Total Space | 111.33 Gb Free Space | 99.91% Space Free | Partition Type: NTFS

Computer Name: TYLENE-PC | User Name: tylene | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0A284193-7579-49B2-A756-225EEB9CAFAE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0EFE6A0F-DE20-4B7E-96F5-9B93A61538F9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{1EE0BAF8-8C7C-4CFB-A0FA-D9F5AB9CB5F9}" = lport=2869 | protocol=6 | dir=in | app=system |
"{32F4B00F-FA2A-4A8A-A08A-DF9F386DCAF5}" = lport=2869 | protocol=6 | dir=in | app=system |
"{353B9E95-235B-4541-8589-6808680224B6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{362A40FA-7D03-46A2-A743-FF9F39C7691D}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{384CF205-57F3-45E5-9B8F-8B1CEF686FA0}" = lport=80 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\netservice\nvnetworkservice.exe |
"{44CFC842-CBF5-476C-B6F8-47D234CF1A1F}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{47DEE498-79D1-4544-ACFE-0A0CF9A26A35}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{6E01B5EB-BC11-4F6E-8ADA-68D4B0C7E1E9}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{7911C26C-A5F3-4AA0-973E-BD464266AA9B}" = lport=443 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\netservice\nvnetworkservice.exe |
"{799756BA-35C1-4544-B649-24FC6AC8CF0F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{8CA7C029-D75B-4E3B-8C66-EFF4E5286ED3}" = lport=10243 | protocol=6 | dir=in | app=system |
"{8FE7DA23-33F7-415C-8853-28A03993B3AF}" = rport=10243 | protocol=6 | dir=out | app=system |
"{9CA7093A-02E9-4E0D-B658-2FAE368660ED}" = lport=6881 | protocol=6 | dir=in | name=blizzard downloader: 6881 |
"{AAA7C920-6606-4D4F-8B0D-4E55276F70F4}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{B9249A3E-ED20-4A2D-979B-31A93E63C6FA}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 |
"{C4948A81-BC8B-411E-887A-757381AFA6B2}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01F1BE07-22BE-4820-BDEC-1460A33C4C8C}" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\blizzard downloader.exe |
"{02FCAA3A-8A3D-4435-95CA-71382C20371F}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe |
"{03D6B426-DA69-4332-8E98-60E71148703C}" = protocol=17 | dir=in | app=c:\nexon\combat arms\engine.exe |
"{0543A820-03AD-4048-B1B4-9B916721D730}" = protocol=6 | dir=in | app=c:\program files\world of warcraft\launcher.exe |
"{0E418E33-A247-4735-AC56-B69A6B3DFAE3}" = protocol=17 | dir=in | app=c:\ngm\ngm.exe |
"{104C5CCB-0164-44DE-AE26-E629DC2D4815}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{10AAD3ED-2CD1-4346-9E23-61EE633CD235}" = protocol=6 | dir=in | app=c:\program files\reactor\ijjioptimizer.exe |
"{1175A6DD-29A6-4970-A4D6-6EA1D6B0ADBC}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"{15011D1B-9230-4502-A82D-ABDE56C4F366}" = protocol=17 | dir=in | app=c:\program files\reactor\ijjioptimizer.exe |
"{18656F46-6C5E-49C7-9D51-9508B0BE3D0E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1955E669-BE1F-4C13-B854-FB32F2900974}" = dir=in | app=c:\program files\acer arcade live\acer homemedia connect\kernel\dms\clmsserver.exe |
"{1A0801E4-C586-41E2-9A05-497D7AFBD36E}" = protocol=6 | dir=out | app=system |
"{1CC076D9-6828-4233-AE5D-4DE9A898995C}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |
"{1DAEB0EB-1F2B-457A-9F1A-9ED85E2A781F}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{2360AD26-E039-42F6-99D5-148801936859}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{23BB9AC8-3B87-4548-BE20-A4E5E6F00B22}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe |
"{27F3C1E8-BD04-45E3-92AA-EEB2C10BCCA5}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe |
"{2997449D-C312-4A23-983E-746B6434C1E3}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"{2A3284A1-5F44-4C16-A9AC-D97C3FA579BD}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
"{2A70D7B6-1DD3-4F8E-9508-285B6F824ECF}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{2E253BF3-C710-4D32-8775-2EBE1645272B}" = protocol=6 | dir=in | app=c:\nexon\combat arms\nmservice.exe |
"{33DD0D81-FAA2-4613-8E73-54A420DACCAB}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{33E16C6E-9CC1-4BB9-8248-1361C03C86E7}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{353346C9-88D2-4F2B-B06B-4DB59C7DE656}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1637\agent.exe |
"{39C15E90-E0D9-40D1-96CC-D85D73084862}" = protocol=17 | dir=in | app=c:\program files\malwarebytes' anti-malware\mbam.exe |
"{3C1F099B-C469-4D22-B78F-0A21345D2E15}" = protocol=17 | dir=in | app=c:\program files\diablo iii\diablo iii.exe |
"{3CEC30A6-8B5A-4AC9-85E8-3C8583B6AB32}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yserver.exe |
"{3F5D1730-BBBD-4F6F-94D5-303AD5E9E3F5}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{3F8E7F0C-6AC2-47E2-BA94-7593D3E1B672}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{40CF92F9-3A2E-44E0-966A-D3621C9CDCF6}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-enus-downloader.exe |
"{40E5137A-44C0-46DD-80C6-7FA5C4074E1A}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1737\agent.exe |
"{423737C1-0043-4395-A377-5ACBA995B85D}" = protocol=6 | dir=in | app=c:\ngm\ngm.exe |
"{4341EBC5-C98E-4C43-8D9B-BBAF1E75EC30}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |
"{4858C672-8913-401C-B061-35C5061D0EE6}" = protocol=17 | dir=in | app=c:\nexon\combat arms\combatarms.exe |
"{4D4DC209-7CC2-4F5B-AC82-FD61E1485584}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{4FDBBD8C-BBB8-4626-AD09-9E2591F693DA}" = protocol=6 | dir=in | app=c:\nexon\combat arms\engine.exe |
"{51FC7DF5-AE5F-4957-9215-E59A62A66F5D}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe |
"{55B1C7DC-7880-407A-961E-BE4025220C47}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{57CF1F95-0C1E-4990-A3FC-75CB6A0A68F7}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe |
"{5954CBF7-5734-4779-A4B5-AB6FB1E994DB}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.2.9901-to-3.1.3.9947-enus-downloader.exe |
"{5EB3679D-F825-4AC6-A248-540F1B137A96}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5F06C73B-3B46-4ED5-983C-2880071833B2}" = dir=in | app=c:\program files\acer arcade live\acer homemedia connect\homemedia connect.exe |
"{64C52DD3-2977-4C34-BDA1-8FD96179DF00}" = dir=in | app=c:\program files\acer arcade live\slideshow dvd\component\clsldvd.exe |
"{65B6DA2F-C470-4696-B8C1-65AEBAFE8C6E}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe |
"{6830174A-753D-404E-9720-262EFDE15C99}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{6CDB8785-C83C-4688-9C5A-801A00C49DD9}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstrb.exe |
"{6F50B5F0-7A15-407E-8541-38AE43B8E58B}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |
"{7518E0EC-A528-4A2E-B823-D9263FBA984B}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |
"{7A70955E-FFF3-4FCE-A8F1-B46A8493C663}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.2.9901-to-3.1.3.9947-enus-downloader.exe |
"{7C43695F-1B33-41C8-BCE2-7D1241C84E05}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.1.3.9947-to-3.2.0.10192-enus-downloader.exe |
"{7C465A77-2DA0-4E03-BC06-6E425C68A19D}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{7E942602-C888-434C-B880-C4C453E6ED48}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"{8122CA6D-B25D-4AE7-A688-10717D25E4E2}" = protocol=17 | dir=in | app=c:\program files\aim\aim.exe |
"{84D120FD-8D90-4F4A-BBC6-11FA6FFAE50C}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{8A96D29D-04C0-4922-A949-240DA5336E93}" = protocol=17 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{8BB0C99E-4DA6-468A-9BA9-2BE1E1A03E26}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe |
"{8E37B6CA-1EB0-4C16-A60A-DDCD1D255975}" = protocol=17 | dir=in | app=c:\program files\7-zip\7zfm.exe |
"{9480E193-EE2D-448C-820B-9F4252D72C51}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |
"{953973B5-860E-4962-B940-99D8EFC82113}" = protocol=6 | dir=in | app=c:\program files\diablo iii\diablo iii.exe |
"{A0005963-1D47-4836-8E2D-D422F6C02875}" = protocol=6 | dir=in | app=c:\program files\aim\aim.exe |
"{A0E22BD1-9D17-41A4-BF50-419B503C50D0}" = dir=in | app=c:\program files\acer arcade live\acer dv magician\component\dvax2process.exe |
"{A1290D40-45B3-4D6A-ABA3-9345CEFAE026}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A29EB778-A598-4AFB-A02B-3AAF0582A211}" = protocol=6 | dir=in | app=c:\program files\yahoo!\messenger\yahoomessenger.exe |
"{A3A4C078-0F1A-4303-B561-92FF33DC1F74}" = protocol=17 | dir=in | app=c:\nexon\combat arms\nmservice.exe |
"{A47B9B4C-CC99-4D7B-ACAA-8A0487E4376D}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{A4B01E6D-E5C2-42BC-B2CA-BA114D197A89}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{A58686B6-9F63-47B9-806B-8BAC32497EA0}" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\launcher.patch.exe |
"{A763DBAD-652E-442E-92A7-0BCB0A82A3FA}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A8757501-B402-4C19-AD10-EA4697A9512B}" = dir=in | app=c:\program files\acer arcade live\acer videomagician\videomagician.exe |
"{ABC648F9-D27E-480E-8BED-107A8E823CD3}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{AD8A6BF5-CE11-4215-B3E0-933D801C5AA1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{AF1BBD3E-46EA-410F-AD5F-AAE1D658167D}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1675\agent.exe |
"{B243D1FD-5397-4038-8AB3-FF20EA3A2563}" = protocol=17 | dir=in | app=c:\program files\steam\steam.exe |
"{B581826C-68F8-4CAF-8A83-76191C779A2A}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{B617E48C-6910-4904-B9C7-EE1284E22C3E}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{B685A922-CF7A-4F72-80E6-357132F86720}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{BF188B5F-1F47-4373-88ED-7C25E04A8A72}" = protocol=17 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{C0B04953-9D63-4886-9FEE-B20972592777}" = dir=in | app=c:\program files\acer arcade live\acer arcade live main page\acer arcade live.exe |
"{C191D004-450C-4CFD-A5D8-34DEA6A13EC9}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{C35ECBFE-FECE-4DD5-96F1-72D6331AED93}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{C5A6A6A0-D297-4AA6-9383-21A16C3F9929}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{C5F1E16C-E4FC-43D9-877C-0F20E7E19D41}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{C8852AB5-E36C-47DC-8CFC-CAF4E8A20E3B}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe |
"{CB148BE8-9A09-414F-A047-5499FFB01B15}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe |
"{CD423AFD-6913-4EF9-BE4B-EDC2B9596BEA}" = protocol=6 | dir=in | app=c:\program files\malwarebytes' anti-malware\mbam.exe |
"{CEAEC2ED-8B65-4B9F-9095-F93FE57F6137}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |
"{CF31282A-32A1-4334-84F7-1FFB234858A0}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe |
"{CFC3BC11-D992-4A82-B174-774575C66EEB}" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\blizzard downloader.exe |
"{D0C6FF09-29A4-4F4D-99ED-B9E4CD3E9904}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1040\agent.exe |
"{D2023506-A8DD-4E94-B5A0-D1A8EE080279}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D3838423-88F1-4F9E-BA2A-4ECCADB0A8E3}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{D6BF55CF-E20E-45B4-94C6-17D55A03E638}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{D7226279-F468-4FFE-909D-5E19DB37F86D}" = protocol=6 | dir=in | app=c:\windows\system32\pnkbstra.exe |
"{D8A0F955-55FA-4061-B2B7-C40E573D7DD1}" = protocol=6 | dir=in | app=c:\nexon\combat arms\combatarms.exe |
"{DF5F81F6-BD0C-488A-9461-358427412D6A}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{DFFF3429-DA90-43DB-898C-FAEEFE3F39E2}" = dir=in | app=c:\program files\acer arcade live\acer homemedia\homemedia.exe |
"{E0F0629E-160C-40C8-BD43-E405A9E6CAC8}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe |
"{E1F95799-C729-47F2-AA64-6D287C222D72}" = protocol=6 | dir=in | app=c:\program files\7-zip\7zfm.exe |
"{E59634F8-1C07-40AC-84E1-E301FBC238EE}" = dir=in | app=c:\program files\acer arcade live\acer dvdivine\dvdivine.exe |
"{EA7B8C5F-0052-4061-9CC1-BA928CE5AE6F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe |
"{EBBAA889-1542-4B7A-8AB4-C0FB5382F9F3}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{ED1511EE-5BAC-4BE0-A000-B7FB41DD1597}" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\launcher.patch.exe |
"{ED1E9675-5C5C-4552-8979-8FFBD704C996}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{EDECD3AD-184E-4832-9890-D4626CCE3D24}" = protocol=17 | dir=in | app=c:\program files\world of warcraft\launcher.exe |
"{EF342487-8AB3-4642-BA56-A374AA5E6973}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F045CDC5-A1B0-4F23-B6CE-B7FB52DD10FD}" = protocol=6 | dir=in | app=c:\program files\steam\steam.exe |
"{F42A10AE-D383-4A78-9E05-64BBC84376C5}" = dir=in | app=c:\program files\acer arcade live\acer dv magician\component\arawp.exe |
"{F9DE4F7E-02CE-4B68-8807-58B1C864B107}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{FACE2135-6513-4C7A-8D03-47B35641F21A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FB6B7BE1-8026-4AA9-91F1-710CDFFA401C}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1544\agent.exe |
"{FC855D24-FA77-42F3-A2C2-9793636C22ED}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.2045\agent.exe |
"{FEC4F87D-DE04-4AA6-A9B7-3C87EED9290A}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1363\agent.exe |
"TCP Query User{04444929-8E9F-49AD-BA3B-A7827AC6998E}C:\program files\unreal tournament 3\binaries\ut3.exe" = protocol=6 | dir=in | app=c:\program files\unreal tournament 3\binaries\ut3.exe |
"TCP Query User{22844458-F8D1-43D3-B07A-C0A6B3B9B082}C:\users\[bleep] sucker\rohanclient.exe" = protocol=6 | dir=in | app=c:\users\[bleep] sucker\rohanclient.exe |
"TCP Query User{262B37C9-55FB-4C50-AC81-3C476427A36A}C:\program files\reactor\reactor.exe" = protocol=6 | dir=in | app=c:\program files\reactor\reactor.exe |
"TCP Query User{294B3D62-291A-4B1E-AFA1-0686004ADCAB}C:\users\public\games\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe |
"TCP Query User{33974345-25BF-43D1-8534-50C6858EC516}C:\program files\aim6\aim6.exe" = protocol=6 | dir=in | app=c:\program files\aim6\aim6.exe |
"TCP Query User{35D24B9C-3FCA-42E4-85AC-2341EAF1E8F9}C:\program files\electronic arts\medal of honor\binaries\moh.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\medal of honor\binaries\moh.exe |
"TCP Query User{371ECC4F-46C0-4546-8C6F-C7542308726D}C:\users\[bleep] sucker\appdata\local\temp\blizzard launcher temporary - b5e56cd8\launcher.exe" = protocol=6 | dir=in | app=c:\users\[bleep] sucker\appdata\local\temp\blizzard launcher temporary - b5e56cd8\launcher.exe |
"TCP Query User{50EE071C-6A76-411F-8AF4-C082CBA35B1A}C:\users\public\games\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe |
"TCP Query User{51819A09-F2EB-4BBD-A6F5-12CA40BAF309}C:\users\[bleep] sucker\appdata\local\temp\blizzard launcher temporary - 0e0153c0\launcher.exe" = protocol=6 | dir=in | app=c:\users\[bleep] sucker\appdata\local\temp\blizzard launcher temporary - 0e0153c0\launcher.exe |
"TCP Query User{5E4197D0-77B2-46F6-8877-992624166369}C:\program files\electronic arts\medal of honor\mp\mohmpgame.exe" = protocol=6 | dir=in | app=c:\program files\electronic arts\medal of honor\mp\mohmpgame.exe |
"TCP Query User{609F3066-5817-4D3C-B230-9BD80C337812}C:\users\[bleep] sucker\desktop\wow-2.4.3.8568-to-3.0.2.8916-enus-downloader.exe" = protocol=6 | dir=in | app=c:\users\[bleep] sucker\desktop\wow-2.4.3.8568-to-3.0.2.8916-enus-downloader.exe |
"TCP Query User{750CFBD8-A6BC-40F5-BF33-662D884227CD}C:\program files\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files\limewire\limewire.exe |
"TCP Query User{8711B33A-8584-4697-8B7E-BDA67B04848A}C:\program files\world of warcraft\repair.exe" = protocol=6 | dir=in | app=c:\program files\world of warcraft\repair.exe |
"TCP Query User{89013C02-3915-4F39-88F2-A9524DBBDACF}C:\users\public\games\world of warcraft\wow-4.2.1.2736-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\wow-4.2.1.2736-enus-tools-downloader.exe |
"TCP Query User{8C1D5EE9-DE2B-4296-A630-E2E4246F835D}C:\users\public\games\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\backgrounddownloader.exe |
"TCP Query User{A6585C2E-CBA2-44FC-AAF7-1241A4ADC056}C:\users\public\games\world of warcraft\wow-4.2.1.2730-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\wow-4.2.1.2730-enus-tools-downloader.exe |
"TCP Query User{A842EA2C-5D19-477E-A80E-5894142B12E3}C:\users\[bleep] sucker\appdata\roaming\myspace\im\bin\myspaceim.exe" = protocol=6 | dir=in | app=c:\users\[bleep] sucker\appdata\roaming\myspace\im\bin\myspaceim.exe |
"TCP Query User{B8BC4268-BEC7-486E-B6DA-DE34EBB718EE}C:\users\public\games\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"TCP Query User{EA0620C4-F959-4233-9E7B-703231A97257}C:\program files\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\program files\world of warcraft\backgrounddownloader.exe |
"TCP Query User{FE342EBC-3217-41E1-8ACB-EA412B7EB33A}C:\program files\frostwire\frostwire.exe" = protocol=6 | dir=in | app=c:\program files\frostwire\frostwire.exe |
"UDP Query User{092966BF-8D84-43F2-9AA8-32FCD5B987EF}C:\users\[bleep] sucker\appdata\local\temp\blizzard launcher temporary - 0e0153c0\launcher.exe" = protocol=17 | dir=in | app=c:\users\[bleep] sucker\appdata\local\temp\blizzard launcher temporary - 0e0153c0\launcher.exe |
"UDP Query User{0A44B8CE-8A0B-4E4C-B526-5F04B86E3581}C:\users\[bleep] sucker\desktop\wow-2.4.3.8568-to-3.0.2.8916-enus-downloader.exe" = protocol=17 | dir=in | app=c:\users\[bleep] sucker\desktop\wow-2.4.3.8568-to-3.0.2.8916-enus-downloader.exe |
"UDP Query User{0AC80537-9468-4B53-93EA-89BBB01089DC}C:\program files\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\program files\world of warcraft\backgrounddownloader.exe |
"UDP Query User{2550E130-ADB4-4265-9ED3-A6BB80E07DE2}C:\users\public\games\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\temp\wow-4.3-5.0.15890-enus-downloader.exe |
"UDP Query User{28C4C946-37ED-4810-AA08-F602411860C6}C:\program files\electronic arts\medal of honor\mp\mohmpgame.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\medal of honor\mp\mohmpgame.exe |
"UDP Query User{2EF936D0-8924-46A1-9CAB-CB63AF765327}C:\users\public\games\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\backgrounddownloader.exe |
"UDP Query User{3EA77F15-23D5-4921-8170-D5CA858056FE}C:\program files\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files\limewire\limewire.exe |
"UDP Query User{406850FF-85C6-469F-88EA-CC35F000B224}C:\users\[bleep] sucker\appdata\local\temp\blizzard launcher temporary - b5e56cd8\launcher.exe" = protocol=17 | dir=in | app=c:\users\[bleep] sucker\appdata\local\temp\blizzard launcher temporary - b5e56cd8\launcher.exe |
"UDP Query User{4FB23641-FFA8-46BE-B750-D6D00C7B464F}C:\program files\reactor\reactor.exe" = protocol=17 | dir=in | app=c:\program files\reactor\reactor.exe |
"UDP Query User{5FFD3770-BF29-414B-9873-457D0B7F0BDA}C:\program files\aim6\aim6.exe" = protocol=17 | dir=in | app=c:\program files\aim6\aim6.exe |
"UDP Query User{661684A7-8B26-423E-ADF8-CAAEDCB00B13}C:\program files\unreal tournament 3\binaries\ut3.exe" = protocol=17 | dir=in | app=c:\program files\unreal tournament 3\binaries\ut3.exe |
"UDP Query User{75C8C69B-BE55-4BD7-84FB-85A17D40CE23}C:\users\[bleep] sucker\appdata\roaming\myspace\im\bin\myspaceim.exe" = protocol=17 | dir=in | app=c:\users\[bleep] sucker\appdata\roaming\myspace\im\bin\myspaceim.exe |
"UDP Query User{968D3D5D-9970-4DA0-8896-AB47E12D062E}C:\program files\frostwire\frostwire.exe" = protocol=17 | dir=in | app=c:\program files\frostwire\frostwire.exe |
"UDP Query User{97FC1154-FE73-47D0-8E68-EAE5673BE7A0}C:\program files\world of warcraft\repair.exe" = protocol=17 | dir=in | app=c:\program files\world of warcraft\repair.exe |
"UDP Query User{9B09DD48-ACB0-4ABA-9EEB-998435CE5714}C:\program files\electronic arts\medal of honor\binaries\moh.exe" = protocol=17 | dir=in | app=c:\program files\electronic arts\medal of honor\binaries\moh.exe |
"UDP Query User{C2B2549C-5195-4EA0-9195-1CA130454A82}C:\users\public\games\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\temp\wow-4.2.1.2727-enus-tools-downloader.exe |
"UDP Query User{DB3DFED5-8FC5-403F-8CAB-0DEABE200A95}C:\users\public\games\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\launcher.exe |
"UDP Query User{E012B638-9EAE-44BF-A35C-1B70F8BE2501}C:\users\public\games\world of warcraft\wow-4.2.1.2736-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\wow-4.2.1.2736-enus-tools-downloader.exe |
"UDP Query User{EC957B91-311B-4733-81A9-7A79DA72875B}C:\users\[bleep] sucker\rohanclient.exe" = protocol=17 | dir=in | app=c:\users\[bleep] sucker\rohanclient.exe |
"UDP Query User{FBA34C74-FAEC-4E31-AE83-E8B5081A5EE8}C:\users\public\games\world of warcraft\wow-4.2.1.2730-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\users\public\games\world of warcraft\wow-4.2.1.2730-enus-tools-downloader.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{021661E0-C377-C87B-9583-E0A69E61A489}" = Catalyst Control Center Localization Thai
"{023387B5-AF74-D690-D2C6-C8D474597284}" = CCC Help Polish
"{042B8532-E27C-C06E-A8F5-71F36B98B2DE}" = Catalyst Control Center Localization Portuguese
"{07AE9F43-360F-7412-577B-2B4B73E5EAB9}" = CCC Help Hungarian
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0C09E020-9996-4E1C-9839-97DA8F9C8D6B}" = CCC Help Danish
"{132888AE-EF67-41C5-BCA2-7D5D2488AB63}" = Acer HomeMedia Connect
"{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2224B408-E7E4-15CF-0674-EC7C36D68741}" = Catalyst Control Center Localization Hungarian
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{236D1288-99DB-C3D6-D132-EDE6317BF619}" = CCC Help Japanese
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 17
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 45
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
"{2AABA091-41DF-D0D3-83F8-0133F8C7AA97}" = Catalyst Control Center Localization Swedish
"{317DE552-B622-0DD2-4E7E-28400D64C100}" = Catalyst Control Center Localization Dutch
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{41581EF5-45A7-11DA-9D78-000129760D75}" = Acer SlideShow DVD
"{42DF661F-6351-B582-DE2C-B8C46B30303F}" = CCC Help Dutch
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4E868D3D-6EEB-4273-926C-2287236B5B79}" = 3DVIA player 5.0
"{4F5641C5-409C-7E5A-A2F9-B6D00A190B55}" = Catalyst Control Center Graphics Previews Vista
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{56504C77-8B9F-4EB2-B33B-C5B9F50B5D64}" = AVG 2011
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{5EA96EEF-4E57-C1F0-6A06-088191FE110C}" = CCC Help Thai
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{67ADE9AF-5CD9-4089-8825-55DE4B366799}" = NTI Backup NOW! 4.7
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7007D9E6-F820-CFEA-EB87-9C9377A967F7}" = CCC Help Swedish
"{710EA46C-2A49-F39A-5EC7-3884DC5329D7}" = Catalyst Control Center Localization Spanish
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{74AF0F2A-A87D-B6B7-6671-61B53F98254B}" = Catalyst Control Center Localization Turkish
"{760F3E42-B1E4-5324-4C4A-0459C8938B6A}" = Catalyst Control Center Localization Italian
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
"{7B5AA67E-FEA0-40BB-BAB5-CA56645A589C}" = NVIDIA PhysX
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{837F9742-DCC8-3FF4-5066-E11E48EE2391}" = Catalyst Control Center Localization Korean
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86861408-CB40-247E-B851-608792116658}" = CCC Help Norwegian
"{86E71966-9EE0-9AD3-2C17-FC3A0B8BB810}" = Catalyst Control Center Localization Chinese Standard
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8BCA7792-CF78-46C6-66A7-EB9A8F0FB0A2}" = Catalyst Control Center Localization Russian
"{8C42C789-B0EF-3226-9069-D1956B220B38}" = Catalyst Control Center Localization Greek
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{901DC58A-5C1B-4315-BA40-5AD3D3A463B9}" = REACTOR
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{91FD46D2-4FB7-4A51-8637-556E1BE1DB7C}" = iTunes
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{94389919-B0AA-4882-9BE8-9F0B004ECA35}" = Acer Tour
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C353B52-07E4-07A7-B95F-392D8AA37210}" = Catalyst Control Center Localization Japanese
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9DBB76DD-812B-26E9-C681-B7CD2DA27A78}" = CCC Help French
"{9F96AFEF-28F1-2479-1D6A-33F8D4A7BF11}" = CCC Help Chinese Standard
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A10FCB8E-F4C3-0C5E-4FFC-8C9A560095A8}" = CCC Help Russian
"{A6038CD2-72AF-2C0A-C1A3-93D360F5A889}" = CCC Help Korean
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA4BF92B-2AAF-11DA-9D78-000129760D75}" = Acer HomeMedia
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB6097D9-D722-4987-BD9E-A076E2848EE2}" = Acer Empowering Technology
"{AE223864-BFA1-1F17-49B2-13C8971DACA2}" = Catalyst Control Center Localization German
"{AEEAE013-92F1-4515-B278-139F1A692A36}" = Acer eDataSecurity Management
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B145EC69-66F5-11D8-9D75-000129760D75}" = Acer DVDivine
"{B22D8435-CB77-849A-B9AE-D1737A073914}" = Catalyst Control Center Localization Polish
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 332.21
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 332.21
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 1.8.1
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 332.21
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.13.0725
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 10.11.15
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer" = NVIDIA LED Visualizer 1.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service" = NVIDIA Network Service
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C485A66D-3521-20E8-2A7B-F060B1773491}" = Catalyst Control Center Localization French
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C792A75A-2A1F-4991-9B85-291745478A79}" = NetAssistant
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D462BF9E-0C35-4705-BF9B-3DF9F3816643}" = Acer ePerformance Management
"{D5E905F1-7657-7B1E-E5BD-2C69C89C8ABE}" = CCC Help Italian
"{D68ED35B-7D9B-4F5F-B38A-92286DDE2EBF}" = AVG 2011
"{D6DB00A1-4BCC-AB1B-24C2-0999BDA43D85}" = CCC Help Greek
"{D7D4DB0F-9070-AED1-D2F4-D11BD42C7588}" = CCC Help Chinese Traditional
"{D7F01E28-9D36-F8EC-872F-9FD71792F858}" = CCC Help Finnish
"{DA6AB13B-4D72-6EBB-AA4D-656CE9C0E512}" = CCC Help English
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DF59BA36-54DC-6BB4-FCED-C9B9F2BCB4AE}" = CCC Help Spanish
"{E0325EFE-9D02-0F1E-7306-F4D95979715A}" = Catalyst Control Center Localization Chinese Traditional
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E14ADE0E-75F3-4A46-87E5-26692DD626EC}" = Apple Mobile Device Support
"{E63AA3F4-5647-0BC8-24FC-F40CFE56B579}" = Catalyst Control Center Localization Norwegian
"{E6541F6A-3D2D-30E5-57F9-4DD411C2E4F0}" = CCC Help German
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{E720B248-D9F5-5E20-8E72-3E419D45D703}" = Catalyst Control Center Localization Finnish
"{E8E32E53-18F7-095E-CC75-F77E412F1AD9}" = CCC Help Portuguese
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}" = Acer Arcade Live Main Page
"{F09030B7-7B8A-30DE-539B-607C9B1831DB}" = CCC Help Czech
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{F6EFFB76-4A07-11DA-9D78-000129760D75}" = Acer DV Magician
"{F76D7388-A433-E572-4718-CD3421738166}" = CCC Help Turkish
"{F79A208D-D929-11D9-9D77-000129760D75}" = Acer VideoMagician
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"7-Zip" = 7-Zip 4.57
"Acer Assist" = Acer Assist
"Acer Registration" = Acer Registration
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AVG" = AVG 2011
"Combat Arms" = Combat Arms
"Driver Cleaner Pro" = DH Driver Cleaner Professional Edition
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"My Interactive Pooh™" = My Interactive Pooh™
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"The Weather Channel Desktop" = The Weather Channel Desktop
"WinLiveSuite" = Windows Live Essentials
"Wireless Keyboard" = Wireless Keyboard
"World of Warcraft" = World of Warcraft

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-198807665-1997887991-823707001-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 1/3/2014 01:00:01 | Computer Name = tylene-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 1/3/2014 01:00:02 | Computer Name = tylene-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 1/4/2014 01:00:01 | Computer Name = tylene-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 1/4/2014 01:00:02 | Computer Name = tylene-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 1/5/2014 01:00:01 | Computer Name = tylene-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 1/5/2014 01:00:01 | Computer Name = tylene-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 1/11/2014 20:14:30 | Computer Name = tylene-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 1/11/2014 20:14:32 | Computer Name = tylene-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 1/11/2014 20:18:36 | Computer Name = tylene-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 1/11/2014 20:18:36 | Computer Name = tylene-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 1/12/2014 11:21:48 | Computer Name = tylene-PC | Source = Application Hang | ID = 1002
Description = The program OTL.exe version 3.2.69.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 20cc Start Time: 01cf0fa7d91104c0 Termination Time: 15

[ Media Center Events ]
Error - 10/6/2008 23:48:42 | Computer Name = tylene-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 1/19/2009 14:31:15 | Computer Name = tylene-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 4/29/2009 23:17:20 | Computer Name = tylene-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 5/27/2009 15:28:57 | Computer Name = tylene-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 6/29/2009 19:27:32 | Computer Name = tylene-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 7/15/2009 15:32:09 | Computer Name = tylene-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 11/29/2009 14:44:45 | Computer Name = tylene-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 12/13/2009 20:50:26 | Computer Name = tylene-PC | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ System Events ]
Error - 1/9/2014 13:22:40 | Computer Name = tylene-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 1/10/2014 07:31:27 | Computer Name = tylene-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 1/10/2014 07:31:27 | Computer Name = tylene-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 1/10/2014 07:31:27 | Computer Name = tylene-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 1/11/2014 01:11:33 | Computer Name = tylene-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 1/11/2014 01:11:33 | Computer Name = tylene-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 1/11/2014 01:11:33 | Computer Name = tylene-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 1/11/2014 19:17:52 | Computer Name = tylene-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 1/11/2014 19:17:52 | Computer Name = tylene-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 1/11/2014 19:17:52 | Computer Name = tylene-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =


< End of report >


aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2014-01-12 12:30:39
-----------------------------
12:30:39.333 OS Version: Windows 6.0.6002 Service Pack 2
12:30:39.334 Number of processors: 2 586 0x6B01
12:30:39.335 ComputerName: TYLENE-PC UserName: tylene
12:30:40.696 Initialize success
12:32:02.238 AVAST engine defs: 14011200
12:34:08.123 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
12:34:08.128 Disk 0 Vendor: ST3250820AS 3.AAD Size: 238475MB BusType: 3
12:34:08.244 Disk 0 MBR read successfully
12:34:08.250 Disk 0 MBR scan
12:34:08.273 Disk 0 unknown MBR code
12:34:08.280 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 9993 MB offset 63
12:34:08.303 Disk 0 Partition 2 80 (A) 06 FAT16 NTFS 114376 MB offset 20466810
12:34:08.331 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 114102 MB offset 254710575
12:34:08.361 Disk 0 scanning sectors +488392065
12:34:08.524 Disk 0 scanning C:\Windows\system32\drivers
12:34:20.798 Service scanning
12:34:53.457 Modules scanning
12:35:02.162 Disk 0 trace - called modules:
12:35:02.559 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
12:35:02.572 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85916290]
12:35:02.584 3 CLASSPNP.SYS[89dc28b3] -> nt!IofCallDriver -> [0x8583a910]
12:35:02.597 5 acpi.sys[8960b6bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x85852560]
12:35:03.090 AVAST engine scan C:\Windows
12:35:06.531 AVAST engine scan C:\Windows\system32
12:40:04.046 AVAST engine scan C:\Windows\system32\drivers
12:40:19.096 AVAST engine scan C:\Users\tylene
12:46:43.852 AVAST engine scan C:\ProgramData
12:49:21.207 Scan finished successfully
12:50:06.198 Disk 0 MBR has been saved successfully to "C:\Users\tylene\Desktop\MBR.dat"
12:50:06.206 The log file has been saved successfully to "C:\Users\tylene\Desktop\aswMBR.txt"


# AdwCleaner v3.017 - Report created 12/01/2014 at 12:54:29
# Updated 12/01/2014 by Xplode
# Operating System : Windows Vista ™ Home Premium Service Pack 2 (32 bits)
# Username : tylene - TYLENE-PC
# Running from : C:\Users\tylene\Desktop\adwcleaner - Copy.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : Viewpoint Manager Service

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\AVG Security Toolbar
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\ProgramData\Trymedia
Folder Deleted : C:\ProgramData\Viewpoint
Folder Deleted : C:\Program Files\Common Files\Software Update Utility
Folder Deleted : C:\Users\tylene\AppData\Local\Temp\apn
Folder Deleted : C:\Users\tylene\AppData\LocalLow\AskSBar
Folder Deleted : C:\Users\tylene\AppData\LocalLow\Internet Saving Optimizer
Folder Deleted : C:\Users\tylene\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla
File Deleted : C:\Program Files\Mozilla Firefox\Components\AskSearch.js

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla
Key Deleted : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdate
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@funwebproducts.com/Plugin
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0579B4B6-0293-4D73-B02D-5EBB0BA0F0A2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{1E8FC16F-4C51-49C4-BC9B-4FC24BDDCEE7}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0579B4B6-0293-4D73-B02D-5EBB0BA0F0A2}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F84D69AA-3E20-4305-984E-18E640D7F7FF}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{443789B7-F39C-4B5C-9287-DA72D38F4FE6}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{0579B4B6-0293-4D73-B02D-5EBB0BA0F0A2}]
Key Deleted : HKCU\Software\AVG Security Toolbar
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\AppDataLow\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}
Key Deleted : HKCU\Software\AppDataLow\AskBarDis
Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\AVG Security Toolbar
Key Deleted : HKCU\Software\AppDataLow\Software\DoubleD
Key Deleted : HKCU\Software\AppDataLow\Software\Internet Saving Optimizer
Key Deleted : HKCU\Software\AppDataLow\Software\Media Access Startup
Key Deleted : HKCU\Software\AppDataLow\Software\ShopperReports3
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\Software\Tarma Installer
Key Deleted : HKLM\Software\Viewpoint
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C792A75A-2A1F-4991-9B85-291745478A79}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AskSBar Uninstall
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\QueryExplorer
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ShopperReportsSA
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SoftwareUpdUtility
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16526


-\\ Google Chrome v

[ File : C:\Users\tylene\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted : icon_url
Deleted : search_url
Deleted : suggest_url

*************************

AdwCleaner[R0].txt - [7795 octets] - [12/01/2014 12:52:20]
AdwCleaner[S0].txt - [7889 octets] - [12/01/2014 12:54:29]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7949 octets] ##########
  • 0

#4
crooleeck

crooleeck

    Member

  • Member
  • PipPipPip
  • 882 posts
Darrel Rude,
please read carefully. I've asked for use scan option in AdwCleaner. You performed Clean option, that unnecessarily shot down AVG toolbar. Now, if want to use AVG toolbar, it need to be reinstalled.

OK, let's clean your system:

Step 1:
OTL fix:
Please copy following script:

:commands
[createrestorepoint]

:otl
SRV - File not found [Disabled | Stopped] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - SOFTWARE\Classes\CLSID\{03402f96-3dc7-4285-bc50-9e81fefafe43}\InprocServer32 File not found
IE - HKLM\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - SOFTWARE\Classes\CLSID\{EA756889-2338-43DB-8F07-D1CA6FB9C90D}\InprocServer32 File not found
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\..\URLSearchHook: {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - SOFTWARE\Classes\CLSID\{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}\InprocServer32 File not found
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\..\URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - SOFTWARE\Classes\CLSID\{EA756889-2338-43DB-8F07-D1CA6FB9C90D}\InprocServer32 File not found
IE - HKU\S-1-5-21-198807665-1997887991-823707001-1000\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://toolbar.ask.c...rchTerms}&crm=1
O3 - HKU\S-1-5-21-198807665-1997887991-823707001-1000\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll File not found
O3 - HKU\S-1-5-21-198807665-1997887991-823707001-1000\..\Toolbar\WebBrowser: (AIM Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll File not found
O4 - HKLM..\Run: [eRecoveryService] File not found
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html File not found
[2012/09/25 05:00:39 | 000,033,958 | ---- | C] () -- C:\ProgramData\uninstaller.exe
[2012/03/08 15:57:42 | 000,000,154 | ---- | C] () -- C:\Users\tylene\AppData\Roaming\wklnhst.dat
[2011/12/18 22:31:33 | 000,000,552 | ---- | C] () -- C:\Users\tylene\AppData\Local\d3d8caps.dat
[2011/09/06 14:24:27 | 000,138,056 | ---- | C] () -- C:\Users\tylene\AppData\Roaming\PnkBstrK.sys
[2011/04/12 14:54:25 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011/03/11 18:19:35 | 000,001,362 | -HS- | C] () -- C:\ProgramData\1799715130
[2007/12/05 21:19:44 | 000,001,356 | ---- | C] () -- C:\Users\tylene\AppData\Local\d3d9caps.dat

:commands
[emptytemp]


Run OTL, under Custom Scan/Fixes paste it. Close all windows without OTL and hit Run Fix button. Please agreed for restart. After computer starts, OTL will display removing log, please post it.

Step 2:
I see you have only: 21.93% free space on C: partition. Microsft Windows need atleast 20%, so it's good moment to move some files (as photos, movies, music) to antoher partition. You have d: partition almost all free.
  • Please move some files to partition d:
  • Defrag system partition:
  • Click Menu Start
  • In the search box, type Disk Defragmenter, and then, in the list of results, click Disk Defragmenter
  • Under Current status, select partition c:
  • Click Analyze disk. Administrator permission required If you're prompted for an administrator password or confirmation, type the password or provide confirmation.
  • Click Defragment disk. Administrator permission required If you're prompted for an administrator password or confirmation, type the password or provide confirmation
That should improve machine performance.

In your next post I want to see otl remove log.
  • 0

#5
Darrel Rude

Darrel Rude

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
Sorry I did not do the proper scan for you the first time.

My Defragment disk just ran last night do you still want me to run again? I do not have the option to analyze any disks.
here is the log requested

All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== OTL ==========
Error: No service named Viewpoint Manager Service was found to stop!
Service\Driver key Viewpoint Manager Service not found.
File C:\Program Files\Viewpoint\Common\ViewpointService.exe not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{03402f96-3dc7-4285-bc50-9e81fefafe43} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03402f96-3dc7-4285-bc50-9e81fefafe43}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{EA756889-2338-43DB-8F07-D1CA6FB9C90D} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EA756889-2338-43DB-8F07-D1CA6FB9C90D}\ not found.
Registry value HKEY_USERS\S-1-5-21-198807665-1997887991-823707001-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}\ not found.
Registry value HKEY_USERS\S-1-5-21-198807665-1997887991-823707001-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{EA756889-2338-43DB-8F07-D1CA6FB9C90D} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EA756889-2338-43DB-8F07-D1CA6FB9C90D}\ not found.
Registry key HKEY_USERS\S-1-5-21-198807665-1997887991-823707001-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CF739809-1C6C-47C0-85B9-569DBB141420}\ not found.
Registry value HKEY_USERS\S-1-5-21-198807665-1997887991-823707001-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{61539ECD-CC67-4437-A03C-9AACCBD14326} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{61539ECD-CC67-4437-A03C-9AACCBD14326}\ not found.
Registry value HKEY_USERS\S-1-5-21-198807665-1997887991-823707001-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{DE9C389F-3316-41A7-809B-AA305ED9D922} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DE9C389F-3316-41A7-809B-AA305ED9D922}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\eRecoveryService not found.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&AOL Toolbar Search\ not found.
File C:\ProgramData\uninstaller.exe not found.
File C:\Users\tylene\AppData\Roaming\wklnhst.dat not found.
File C:\Users\tylene\AppData\Local\d3d8caps.dat not found.
File C:\Users\tylene\AppData\Roaming\PnkBstrK.sys not found.
File C:\ProgramData\ntuser.pol not found.
File C:\ProgramData\1799715130 not found.
File C:\Users\tylene\AppData\Local\d3d9caps.dat not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: tylene
->Temp folder emptied: 32558 bytes
->Temporary Internet Files folder emptied: 259007221 bytes
->Java cache emptied: 78098 bytes
->Google Chrome cache emptied: 131478571 bytes
->Flash cache emptied: 539 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 549349581 bytes
RecycleBin emptied: 2693230057 bytes

Total Files Cleaned = 3,465.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 01122014_154241

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • 0

#6
Darrel Rude

Darrel Rude

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
Ran the Defrag anyway took like 10 minutes did it on all drives moved some files to D: as you recommended.

Edited by Darrel Rude, 12 January 2014 - 06:23 PM.

  • 0

#7
crooleeck

crooleeck

    Member

  • Member
  • PipPipPip
  • 882 posts
OK, let's take a overlook your system.

Step 1:
Eset Online Scanner
Note: You can use either Internet Explorer or Mozilla FireFox for this scan.

Vista / 7 / 8 users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

Please go here then click on: Posted Image

If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
All of the following instructions work with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: Posted Image
  • When prompted allow Add-On/Active X to install.
  • Make sure that the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology


    Posted Image
  • Now click on: Posted Image
  • The virus signature database will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically. The scan may take several hours.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close, make sure you copy the logfile first!
  • Now click on: Posted Image
  • Use notepad to open the logfile located at C:\Program Files (x86)\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Step 2:
Posted Image I see you have installed Malwarebytes Anti-Malware, please perform quick scan.

  • Run Malwarebytes Anti-Malware
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

How is your computer running now? Remember to post logs from both scans.
  • 0

#8
Darrel Rude

Darrel Rude

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
The Computer is still running and starting up slowly. Also when I log into world of warcraft after just a few seconds the screen goes black and the entire computer reboots itself. I am going to uninstall WoW and reinstall it to see if that fixes that issue. Then I will let you know. Its just WoW that it does it with.

Here are the logs requested.

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=8
# iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=a9d5b5e5e2d08a43affa9dcd9b1facbe
# engine=16634
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-01-13 05:38:58
# local_time=2014-01-13 12:38:58 (-0500, Eastern Standard Time)
# country="United States"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1032 16777213 100 95 0 132694482 0 0
# compatibility_mode=5892 16776574 100 100 100379977 226242266 0 0
# scanned=142676
# found=4
# cleaned=4
# scan_time=7397
sh=174B4984C45177B554D25F8999F44DF5CA771E8C ft=1 fh=de76e9361c4ed4f9 vn="a variant of Win32/Adware.Yontoo.B application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll.vir"
sh=9639EAE9121C32BB7E09B11288DB466E3F45E288 ft=1 fh=b36f657fcf8d3d19 vn="a variant of Win32/PriceGong.A application (cleaned by deleting - quarantined)" ac=C fn="C:\Program Files\Trend Micro\HijackThis\backups\backup-20110311-195313-330.dll"
sh=4469DBDA42C4180DB38A6FDC54742B90DE76B6D6 ft=1 fh=891889440bc326db vn="multiple threats (cleaned by deleting - quarantined)" ac=C fn="C:\Users\tylene\Downloads\openofficesuite-setup.exe"
sh=890368473ECBC404DCD42FF0C6C38397102F59C0 ft=1 fh=4c7db45bf4256cb3 vn="Win32/PrcView application (cleaned by deleting - quarantined)" ac=C fn="C:\Windows\System32\Process.exe"


Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org

Database version: v2014.01.13.06

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
tylene :: TYLENE-PC [administrator]

Protection: Enabled

1/13/2014 13:19:46
mbam-log-2014-01-13 (13-19-46).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 216680
Time elapsed: 8 minute(s), 28 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
  • 0

#9
crooleeck

crooleeck

    Member

  • Member
  • PipPipPip
  • 882 posts

The Computer is still running and starting up slowly. Also when I log into world of warcraft after just a few seconds the screen goes black and the entire computer reboots itself. I am going to uninstall WoW and reinstall it to see if that fixes that issue. Then I will let you know. Its just WoW that it does it with.


It can be a Blue Screen. I don't think that reinstall WoW can resolve the problem. Reinstall video card driver is a good idea, especially if new version was published

Step 1:
Please Disable Automatic Restart on BSOD:
  • Right-click on Computer, select Properties
  • Click Advanced System Settings
  • On the Advanced tab, under Startup and Recovery, click Settings
  • Under System Failure, uncheck the box next to Automatic restart

Step 2:
Also perform checkdisk:
  • Menu Start -> Computer
  • Right click on C: drive, click Properties
  • On Tools tab, click Check Now...
  • Tick both box and click Start
  • Agreed for schedule check.
With pictures you can find how to:
http://www.geekstogo...ws-7-and-vista/

Can you clean PC? I mean get rid of the dust.
  • 0

#10
Darrel Rude

Darrel Rude

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
Okay I have cleaned the pc done the checkdisk. I have not redownloaded WoW yet because its lagging our other computers in the house. Its never been a blue screen that shuts the PC off. I log into WoW the screen turns black the computer shuts off and restarts. The computer is still running slow.
  • 0

#11
crooleeck

crooleeck

    Member

  • Member
  • PipPipPip
  • 882 posts

Its never been a blue screen that shuts the PC off

In Vista you will no see blue screen by default, that's why I want to Disable Automatic Restart on BSOD. Please complete instructions:
  • Right-click on Computer, select Properties
  • Click Advanced System Settings
  • On the Advanced tab, under Startup and Recovery, click Settings
  • Under System Failure, uncheck the box next to Automatic restart

  • 0

#12
Darrel Rude

Darrel Rude

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
I did do that per your request on the previous post for checkdisk. I downloaded WoW again but have not had the chance to play it as of yet. I will get on there now and see if it continues. I also cleaned out the dust which wasn't much. So give me a few min to see what happens.

Thanks

Darrel Rude
  • 0

#13
Darrel Rude

Darrel Rude

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
Okay I figured out the problem with WoW. And my PC is running better thanks for your help. Now I have a laptop that needs assistance. I will be posting shortly.

Thanks again

Darrel Rude

Edited by Darrel Rude, 15 January 2014 - 08:29 AM.

  • 0

#14
crooleeck

crooleeck

    Member

  • Member
  • PipPipPip
  • 882 posts

I will be posting shortly.

Any news?
  • 0

#15
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP