Jump to content

DC981

Members
  • Content Count

    13
  • Joined

  • Last visited

About DC981

  • Rank
    Member
  1. After running for 3 hours, it's still at 7% in spite of the fact that it searched through three times as many files as 2 hours ago, I need to stop it. Here's what it found: C:AdwCleanerQuarantineCDocuments and SettingsAdministratorApplication Da[email protected]50eecf0c7a1eb.comcontentbg.js.vir Win32/Adware.MultiPlug.H application C:AdwCleanerQuarantineCDocuments and SettingsAdministratorApplication Da[email protected]50fbc3c412e48.comcontentbg.js.vir Win32/Adware.MultiPlug.H application C:AdwCleanerQuarantineCDocuments and SettingsAdministratorLocal SettingsApplication DataBabylonSetupSetup.exe.vir Win32/Toolbar.Babylon application C:AdwCleanerQuarantineCDocuments and SettingsAdministratorLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionseeagmkkfclhgnfoailfapcecdjooldak1.0_0bg.js.vir Win32/Adware.MultiPlug.H application C:AdwCleanerQuarantineCDocuments and SettingsAdministratorLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsniapdbllcanepiiimjjndipklodoedlc1.0.2_0background.html.vir JS/Adware.Yontoo.B application C:AdwCleanerQuarantineCDocuments and SettingsAdministratorLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsniapdbllcanepiiimjjndipklodoedlc1.0.2_0yl.js.vir JS/Adware.Yontoo.A application C:AdwCleanerQuarantineCDocuments and SettingsAdministratorLocal SettingsApplication DatauTorrentBarldrtbuTo0.dll.vir a variant of Win32/Toolbar.Conduit.P application C:AdwCleanerQuarantineCDocuments and SettingsAdministratorLocal SettingsApplication DatauTorrentBarldrtbuTo2.dll.vir a variant of Win32/Toolbar.Conduit.P application C:AdwCleanerQuarantineCDocuments and SettingsAdministratorLocal SettingsApplication DatauTorrentBarldrtbuTor.dll.vir a variant of Win32/Toolbar.Conduit.P application C:AdwCleanerQuarantineCDocuments and SettingsAdministratorLocal SettingsApplication DatauTorrentBartbuTo0.dll.vir a variant of Win32/Toolbar.Conduit.B application C:AdwCleanerQuarantineCDocuments and SettingsAdministratorLocal SettingsApplication DatauTorrentBartbuTo2.dll.vir a variant of Win32/Toolbar.Conduit.B application C:AdwCleanerQuarantineCDocuments and SettingsAdministratorLocal SettingsApplication DatauTorrentBartbuTor.dll.vir a variant of Win32/Toolbar.Conduit.B application C:AdwCleanerQuarantineCDocuments and SettingsAdministratorLocal SettingsApplication DatauTorrentBarplugins{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}3.6.12binPriceGongIE.dll.vir a variant of Win32/PriceGong.A application C:AdwCleanerQuarantineCDocuments and SettingsAll UsersApplication DataADDICT-THINGeeagmkkfclhgnfoailfapcecdjooldak.crx.vir Win32/Adware.MultiPlug.H application C:AdwCleanerQuarantineCDocuments and SettingsAll UsersApplication Datacontinuetosave50eecf0c7a345.dll.vir Win32/Adware.MultiPlug.I application C:AdwCleanerQuarantineCDocuments and SettingsAll UsersApplication DataTarma Installer{889DF117-14D1-44EE-9F31-C5FB5D47F68B}_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application C:AdwCleanerQuarantineCDocuments and SettingsBrunoLocal SettingsApplication DataAskToolbarsetup.exe.vir a variant of Win32/Bundled.Toolbar.Ask application C:AdwCleanerQuarantineCDocuments and SettingsBrunoLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionseeagmkkfclhgnfoailfapcecdjooldak1.0_1bg.js.vir Win32/Adware.MultiPlug.H application C:AdwCleanerQuarantineCDocuments and SettingsBrunoLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsniapdbllcanepiiimjjndipklodoedlc1.0.2_1background.html.vir JS/Adware.Yontoo.B application C:AdwCleanerQuarantineCDocuments and SettingsBrunoLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsniapdbllcanepiiimjjndipklodoedlc1.0.2_1yl.js.vir JS/Adware.Yontoo.A application C:AdwCleanerQuarantineCDocuments and SettingsBrunoLocal SettingsApplication DatauTorrentBarldrtbuTo0.dll.vir a variant of Win32/Toolbar.Conduit.P application C:AdwCleanerQuarantineCDocuments and SettingsBrunoLocal SettingsApplication DatauTorrentBarldrtbuTo2.dll.vir a variant of Win32/Toolbar.Conduit.P application C:AdwCleanerQuarantineCDocuments and SettingsBrunoLocal SettingsApplication DatauTorrentBartbuTo0.dll.vir a variant of Win32/Toolbar.Conduit.B application C:AdwCleanerQuarantineCDocuments and SettingsBrunoLocal SettingsApplication DatauTorrentBartbuTo2.dll.vir a variant of Win32/Toolbar.Conduit.B application C:AdwCleanerQuarantineCDocuments and SettingsBrunoLocal SettingsApplication DatauTorrentBarplugins{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}3.6.8binPriceGongIE.dll.vir a variant of Win32/PriceGong.A application C:AdwCleanerQuarantineCDocuments and SettingsPetraaApplication Da[email protected]5023db04d6776.infocontentbg.js.vir Win32/Adware.MultiPlug.H application C:AdwCleanerQuarantineCDocuments and SettingsPetraaLocal SettingsApplication DataBabylonSetupBExternal.dll.vir a variant of Win32/Toolbar.Babylon.F application C:AdwCleanerQuarantineCDocuments and SettingsPetraaLocal SettingsApplication DataBabylonSetupIECookieLow.dll.vir a variant of Win32/Toolbar.Babylon.E application C:AdwCleanerQuarantineCDocuments and SettingsPetraaLocal SettingsApplication DataBabylonSetupSetup.exe.vir a variant of Win32/Toolbar.Babylon.H application C:AdwCleanerQuarantineCDocuments and SettingsPetraaLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionseeagmkkfclhgnfoailfapcecdjooldak1.0_0bg.js.vir Win32/Adware.MultiPlug.H application C:AdwCleanerQuarantineCDocuments and SettingsPetraaLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsniapdbllcanepiiimjjndipklodoedlc1.0.2_0background.html.vir JS/Adware.Yontoo.B application C:AdwCleanerQuarantineCDocuments and SettingsPetraaLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsniapdbllcanepiiimjjndipklodoedlc1.0.2_0yl.js.vir JS/Adware.Yontoo.A application C:AdwCleanerQuarantineCDocuments and SettingsPetraaLocal SettingsApplication DatauTorrentBarldrtbuTor.dll.vir a variant of Win32/Toolbar.Conduit.P application C:AdwCleanerQuarantineCDocuments and SettingsPetraaLocal SettingsApplication DatauTorrentBartbuTor.dll.vir a variant of Win32/Toolbar.Conduit.B application C:AdwCleanerQuarantineCProgram FilesNCH SoftwareExpressBurnexpressburn.exe.vir a variant of Win32/Bundled.Toolbar.Google.C application C:AdwCleanerQuarantineCProgram FilesNCH SoftwareExpressBurnexpressburnsetup_v4.68.exe.vir a variant of Win32/Bundled.Toolbar.Google.C application C:AdwCleanerQuarantineCProgram FilesNCH SoftwareRecordpadrecordpad.exe.vir a variant of Win32/Bundled.Toolbar.Google.C application C:AdwCleanerQuarantineCProgram FilesNCH SoftwareRecordpadrecordpadsetup_v4.32.exe.vir a variant of Win32/Bundled.Toolbar.Google.C application C:AdwCleanerQuarantineCProgram FilesNCH SoftwareVoxalvoxal.exe.vir a variant of Win32/Bundled.Toolbar.Google.C application C:AdwCleanerQuarantineCProgram FilesNCH SoftwareVoxalvoxalsetup_v1.02.exe.vir a variant of Win32/Bundled.Toolbar.Google.C application C:AdwCleanerQuarantineCProgram FilesuTorrentBarldrtbuTo0.dll.vir a variant of Win32/Toolbar.Conduit.P application C:AdwCleanerQuarantineCProgram FilesuTorrentBarldrtbuTo2.dll.vir a variant of Win32/Toolbar.Conduit.P application C:AdwCleanerQuarantineCProgram FilesuTorrentBarldrtbuTor.dll.vir a variant of Win32/Toolbar.Conduit.P application C:AdwCleanerQuarantineCProgram FilesuTorrentBarprxtbuTo0.dll.vir Win32/Toolbar.Conduit.N application C:AdwCleanerQuarantineCProgram FilesuTorrentBarprxtbuTor.dll.vir Win32/Toolbar.Conduit.O application C:AdwCleanerQuarantineCProgram FilesuTorrentBartbuTo0.dll.vir a variant of Win32/Toolbar.Conduit.B application C:AdwCleanerQuarantineCProgram FilesuTorrentBartbuTo2.dll.vir a variant of Win32/Toolbar.Conduit.B application C:AdwCleanerQuarantineCProgram FilesuTorrentBartbuTor.dll.vir a variant of Win32/Toolbar.Conduit.B application C:AdwCleanerQuarantineCProgram FilesYontooYontooIEClient.dll.vir a variant of Win32/Adware.Yontoo.A application C:AdwCleanerQuarantineCProgram FilesYontooYontooLayers.crx.vir multiple threats C:AdwCleanerQuarantineCProgram Files~Web AssistantExtension32.dll.vir a variant of Win32/Toolbar.Perion.A application C:AdwCleanerQuarantineCProgram Files~Web AssistantExtensionUpdaterService.exe.vir a variant of Win32/Toolbar.BitCocktail.B application C:AdwCleanerQuarantineCProgram Files~Web AssistantInstallerHelper.dll.vir a variant of Win32/Toolbar.BitCocktail.A application C:AdwCleanerQuarantineCProgram Files~Web Assistantsource.crx.vir Win32/Toolbar.Perion.D application C:AdwCleanerQuarantineCProgram Files~Web AssistantFirefoxchromecontentmain.js.vir Win32/Toolbar.Perion.D application C:Documents and SettingsAdministratordesktopGamesDont_Starve_Beta_20Apr_2013_ZuSE.7z a variant of Win32/HackTool.Crack.BQ application C:Documents and SettingsAdministratordesktopGamesPAYDAY.2.V1.01.PLUS17TRN.LINGON.ZIP a variant of Win32/Packed.VMProtect.AAH trojan C:Documents and SettingsAdministratordesktopGamesPday2+17Tr-LNG_v1.0..exe a variant of Win32/Packed.VMProtect.AAH trojan C:Documents and SettingsAdministratorLocal SettingsTemporary Internet FilesContent.IE5KLT2CES8stubinst_pkg_en-eu[1].cab Win32/OpenCandy application C:Documents and SettingsAdministratorMy DocumentsDownloadsccsetup408.exe Win32/Bundled.Toolbar.Google.D application C:Documents and SettingsAdministratorMy DocumentsDownloadssetup.exe Win32/InstalleRex.E application C:Documents and SettingsAdministratorMy DocumentsDownloadsvxlsetup.exe a variant of Win32/Bundled.Toolbar.Google.C application
  2. Here's the FRST thing Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 28-12-2013 01 Ran by Administrator at 2013-12-28 19:55:34 Run:1 Running from C:Documents and SettingsAdministratorMy DocumentsDownloads Boot Mode: Normal ============================================== Content of fixlist: ***************** start HKUPetraa...Winlogon: [shell] C:RECYCLERS-1-5-21-2410097703-9931454827-202138925-7790djwi2kcew.exe,explorer.exe,C:Documents and SettingsPetraafxmdk.exe <==== ATTENTION AppInit_DLLs: C:Program FilesCONTIN~1SPROTE~1.DLL [ 2013-12-17] () URLSearchHook: ATTENTION ==> Default URLSearchHook is missing. SearchScopes: HKLM - DefaultScope value is missing. FF ProfilePath: C:Documents and SettingsAdministratorApplication DataMozillaFirefoxProfiles5gozow0a.default S2 xthxbdrbrxtccdiwenti; C:WindowsSystem32svchost.exe [14336 2008-04-14] (Microsoft Corporation) S3 FairplayKD; ??C:Documents and SettingsAll UsersApplication DataMTA San Andreas All1.3tempFairplayKD.sys [x] NETSVC: xthxbdrbrxtccdiwenti -> No Registry Path. C:WINDOWS85EBB28365AF4C539EBE7C0A232762F7.TMP C:Documents and SettingsBrunojagex_runescape_preferences.dat C:Documents and SettingsBrunojagex_runescape_preferences2.dat C:Documents and SettingsAdministratorLocal SettingsTempAutoRun.exe C:Documents and SettingsAdministratorLocal SettingsTempAutoRunGUI.dll C:Documents and SettingsAdministratorLocal SettingsTempCmdLineExt03.dll C:Documents and SettingsAdministratorLocal SettingsTempdrm_dialogs.dll C:Documents and SettingsAdministratorLocal SettingsTempeauninstall.exe C:Documents and SettingsAdministratorLocal SettingsTempNEventMessages.dll C:Documents and SettingsAdministratorLocal SettingsTempQuarantine.exe C:Documents and SettingsAdministratorLocal SettingsTempSIntf16.dll C:Documents and SettingsAdministratorLocal SettingsTempSIntf32.dll C:Documents and SettingsAdministratorLocal SettingsTempSIntfNT.dll C:Documents and SettingsAdministratorLocal SettingsTempThe Sims 2_uninst.exe C:Documents and SettingsAdministratorLocal SettingsTempUninstall.exe C:Documents and SettingsAdministratorLocal SettingsTempVP6Install.exe C:Documents and SettingsAdministratorLocal SettingsTemp_is402.exe C:Documents and SettingsAdministratorLocal SettingsTemp_is427.exe C:Documents and SettingsAdministratorLocal SettingsTemp_isBF7.exe C:Documents and SettingsBrunoLocal SettingsTempdrm_dyndata_7370014.dll C:Documents and SettingsBrunoLocal SettingsTempiMesh_setup.exe C:Documents and SettingsBrunoLocal SettingsTempjre-6u24-windows-i586-iftw-rv.exe C:Documents and SettingsBrunoLocal SettingsTempNEventMessages.dll C:Documents and SettingsBrunoLocal SettingsTempswt-win32-3349.dll C:Documents and SettingsPetraaLocal SettingsTemp2780.exe C:Documents and SettingsPetraaLocal SettingsTemp332732.exe C:Documents and SettingsPetraaLocal SettingsTemp7za.exe C:Documents and SettingsPetraaLocal SettingsTempavguidx.dll C:Documents and SettingsPetraaLocal SettingsTempCommonInstaller.exe C:Documents and SettingsPetraaLocal SettingsTempcoupish-babylon.exe C:Documents and SettingsPetraaLocal SettingsTempeauninstall.exe C:Documents and SettingsPetraaLocal SettingsTempiGearedHelper.dll C:Documents and SettingsPetraaLocal SettingsTempload1.exe C:Documents and SettingsPetraaLocal SettingsTemplowproc.exe C:Documents and SettingsPetraaLocal SettingsTempMachineIdCreator.exe C:Documents and SettingsPetraaLocal SettingsTempNero-8.1.1.3 lite.exe C:Documents and SettingsPetraaLocal SettingsTempNEventMessages.dll C:Documents and SettingsPetraaLocal SettingsTempstubhelper.dll C:Documents and SettingsPetraaLocal SettingsTempswt-win32-3349.dll C:Documents and SettingsPetraaLocal SettingsTempThe Sims 2_uninst.exe C:Documents and SettingsPetraaLocal SettingsTempToolbarInstaller.exe C:Documents and SettingsPetraaLocal SettingsTempToolbar_Phpnuke.exe C:Documents and SettingsPetraaLocal SettingsTempTsu-0950.dll end ***************** HKUPetraaSoftwareMicrosoftWindows NTCurrentVersionWinlogonShell => Value deleted successfully. HKLMSoftwareMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs => Value was restored successfully. Default URLSearchHook was restored successfully . HKLMSOFTWAREMicrosoftInternet ExplorerSearchScopesDefaultScope => Value was restored successfully. => Should not be moved. xthxbdrbrxtccdiwenti => Service deleted successfully. FairplayKD => Service deleted successfully. HKLMSOFTWAREMicrosoftWindows NTCurrentVersionSvcHostnetsvcs xthxbdrbrxtccdiwenti => Value deleted successfully. C:WINDOWS85EBB28365AF4C539EBE7C0A232762F7.TMP => Moved successfully. C:Documents and SettingsBrunojagex_runescape_preferences.dat => Moved successfully. C:Documents and SettingsBrunojagex_runescape_preferences2.dat => Moved successfully. C:Documents and SettingsAdministratorLocal SettingsTempAutoRun.exe => Moved successfully. C:Documents and SettingsAdministratorLocal SettingsTempAutoRunGUI.dll => Moved successfully. C:Documents and SettingsAdministratorLocal SettingsTempCmdLineExt03.dll => Moved successfully. C:Documents and SettingsAdministratorLocal SettingsTempdrm_dialogs.dll => Moved successfully. C:Documents and SettingsAdministratorLocal SettingsTempeauninstall.exe => Moved successfully. C:Documents and SettingsAdministratorLocal SettingsTempNEventMessages.dll => Moved successfully. C:Documents and SettingsAdministratorLocal SettingsTempQuarantine.exe => Moved successfully. C:Documents and SettingsAdministratorLocal SettingsTempSIntf16.dll => Moved successfully. C:Documents and SettingsAdministratorLocal SettingsTempSIntf32.dll => Moved successfully. C:Documents and SettingsAdministratorLocal SettingsTempSIntfNT.dll => Moved successfully. C:Documents and SettingsAdministratorLocal SettingsTempThe Sims 2_uninst.exe => Moved successfully. C:Documents and SettingsAdministratorLocal SettingsTempUninstall.exe => Moved successfully. C:Documents and SettingsAdministratorLocal SettingsTempVP6Install.exe => Moved successfully. C:Documents and SettingsAdministratorLocal SettingsTemp_is402.exe => Moved successfully. C:Documents and SettingsAdministratorLocal SettingsTemp_is427.exe => Moved successfully. C:Documents and SettingsAdministratorLocal SettingsTemp_isBF7.exe => Moved successfully. C:Documents and SettingsBrunoLocal SettingsTempdrm_dyndata_7370014.dll => Moved successfully. C:Documents and SettingsBrunoLocal SettingsTempiMesh_setup.exe => Moved successfully. C:Documents and SettingsBrunoLocal SettingsTempjre-6u24-windows-i586-iftw-rv.exe => Moved successfully. C:Documents and SettingsBrunoLocal SettingsTempNEventMessages.dll => Moved successfully. C:Documents and SettingsBrunoLocal SettingsTempswt-win32-3349.dll => Moved successfully. C:Documents and SettingsPetraaLocal SettingsTemp2780.exe => Moved successfully. C:Documents and SettingsPetraaLocal SettingsTemp332732.exe => Moved successfully. C:Documents and SettingsPetraaLocal SettingsTemp7za.exe => Moved successfully. C:Documents and SettingsPetraaLocal SettingsTempavguidx.dll => Moved successfully. C:Documents and SettingsPetraaLocal SettingsTempCommonInstaller.exe => Moved successfully. C:Documents and SettingsPetraaLocal SettingsTempcoupish-babylon.exe => Moved successfully. C:Documents and SettingsPetraaLocal SettingsTempeauninstall.exe => Moved successfully. C:Documents and SettingsPetraaLocal SettingsTempiGearedHelper.dll => Moved successfully. C:Documents and SettingsPetraaLocal SettingsTempload1.exe => Moved successfully. C:Documents and SettingsPetraaLocal SettingsTemplowproc.exe => Moved successfully. C:Documents and SettingsPetraaLocal SettingsTempMachineIdCreator.exe => Moved successfully. C:Documents and SettingsPetraaLocal SettingsTempNero-8.1.1.3 lite.exe => Moved successfully. C:Documents and SettingsPetraaLocal SettingsTempNEventMessages.dll => Moved successfully. C:Documents and SettingsPetraaLocal SettingsTempstubhelper.dll => Moved successfully. C:Documents and SettingsPetraaLocal SettingsTempswt-win32-3349.dll => Moved successfully. C:Documents and SettingsPetraaLocal SettingsTempThe Sims 2_uninst.exe => Moved successfully. C:Documents and SettingsPetraaLocal SettingsTempToolbarInstaller.exe => Moved successfully. C:Documents and SettingsPetraaLocal SettingsTempToolbar_Phpnuke.exe => Moved successfully. C:Documents and SettingsPetraaLocal SettingsTempTsu-0950.dll => Moved successfully. ==== End of Fixlog ==== I had ESET running for around an hour now (just at 7%) but I've noticed just now that the bad image errors aren't appearing. They stopped somewhere during me following your newest instructions. I'll let ESET run for as long as I can but thought I should let you know in case I should do something else at this point.
  3. I apologize for my relative slowness. Since you said nothing about the first thing, which produced a log, I'll post it as well Rkill.txt thing: Rkill 2.6.4 by Lawrence Abrams (Grinler) http://www.bleepingcomputer.com/ Copyright 2008-2013 BleepingComputer.com More Information about Rkill can be found at this link: http://www.bleepingcomputer.com/forums/topic308364.html Program started at: 12/27/2013 09:24:27 PM in x86 mode. Windows Version: Microsoft Windows XP Service Pack 3 Checking for Windows services to stop: * No malware services found to stop. Checking for processes to terminate: * No malware processes found to kill. Active Proxy Server Detected * Proxy Disabled. * ProxyOverride value deleted. * ProxyServer value deleted. * AutoConfigURL value deleted. * Proxy settings were backed up to Registry file. Checking Registry for malware related settings: * No issues found in the Registry. Backup Registry file created at: C:Documents and SettingsAdministratorDesktoprkillrkill-12-27-2013-09-24-35.reg Resetting .EXE, .COM, & .BAT associations in the Windows Registry. Performing miscellaneous checks: * Reparse Point/Junctions Found (Most likely legitimate)! * C:WINDOWSMicrosoft.NETassemblyGAC_32System.EnterpriseServicesv4.0_4.0.0.0__b03f5f7f11d50a3a => C:WINDOWSWinSxSx86_System.EnterpriseServices_b03f5f7f11d50a3a_4.0.0.0_x-ww_29b51492 [Dir] * C:WINDOWSMicrosoft.NETassemblyGAC_MSILMicrosoft.Workflow.Compilerv4.0_4.0.0.0__31bf3856ad364e35 => C:WINDOWSWinSxSMSIL_Microsoft.Workflow.Compiler_31bf3856ad364e35_4.0.0.0_x-ww_97359ba5 [Dir] Checking Windows Service Integrity: * Alerter [Missing Service] * Browser [Missing Service] * lanmanworkstation [Missing Service] * Messenger [Missing Service] * Netlogon [Missing Service] * NtLmSsp [Missing Service] * RpcLocator [Missing Service] * NetBIOS [Missing Service] Searching for Missing Digital Signatures: * No issues found. Checking HOSTS File: * HOSTS file entries found: 127.0.0.1 localhost 127.0.0.1 mpa.one.microsoft.com 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 127.0.0.1 activate-sjc0.adobe.com 127.0.0.1 adobe.activate.com 127.0.0.1 adobeereg.com 127.0.0.1 www.adobeereg.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 20 out of 23 HOSTS entries shown. Please review HOSTS file for further entries. Program finished at: 12/27/2013 09:26:01 PM Execution time: 0 hours(s), 1 minute(s), and 34 seconds(s) FRST Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-12-2013 01 Ran by Administrator (administrator) on PETRA on 27-12-2013 21:26:25 Running from C:Documents and SettingsAdministratorMy DocumentsDownloads Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English(US) Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (ATI Technologies Inc.) C:WINDOWSsystem32ati2evxx.exe (ATI Technologies Inc.) C:WINDOWSsystem32ati2evxx.exe (AVAST Software) C:Program FilesAVAST SoftwareAvastAvastSvc.exe (Oracle Corporation) C:Program FilesJavajre7binjqs.exe (LogMeIn, Inc.) C:Program FilesLogMeIn HamachiLMIGuardianSvc.exe (Malwarebytes Corporation) D:GMalwarebytes' Anti-Malwarembamscheduler.exe (Malwarebytes Corporation) D:GMalwarebytes' Anti-Malwarembamservice.exe (Microsoft Corporation) C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE () C:Program FilesRealNetworksRealDownloaderrndlresolversvc.exe () C:Program FilesCyberLinkShared filesRichVideo.exe (Microsoft Corporation) C:Program FilesMicrosoft Application Virtualization Clientsftvsa.exe (Malwarebytes Corporation) D:GMalwarebytes' Anti-Malwarembamgui.exe (Microsoft Corporation) C:Program FilesUPHCleanuphclean.exe (Microsoft Corporation) C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSVC.EXE (Microsoft Corporation) C:Program FilesMicrosoft Application Virtualization Clientsftlist.exe (LogMeIn Inc.) C:Program FilesLogMeIn Hamachihamachi-2.exe (Microsoft Corporation) C:Program FilesCommon FilesMicrosoft SharedVirtualization HandlerCVHSVC.EXE (Microsoft Corporation) C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSVCM.EXE (Microsoft Corporation) C:WINDOWSsystem32wuauclt.exe (Realtek Semiconductor Corp.) C:WINDOWSRTHDCPL.EXE (D-Link) C:Program FilesD-LinkAirPlus GAirGCFG.exe (Alpha Networks Inc.) C:Program FilesANIANIWZCS2 ServiceWZCSLDR2.exe () C:Program FilesDivXDivX UpdateDivXUpdate.exe (Adobe Systems Incorporated) C:Program FilesCommon FilesAdobeARM1.0AdobeARM.exe (RealNetworks, Inc.) C:Program FilesRealRealPlayerUpdaterealsched.exe (AVAST Software) C:Program FilesAVAST SoftwareAvastAvastUI.exe (LogMeIn Inc.) C:Program FilesLogMeIn Hamachihamachi-2-ui.exe (Oracle Corporation) C:Program FilesCommon FilesJavaJava Updatejusched.exe (Microsoft Corporation) C:Program FilesMessengermsmsgs.exe (BitTorrent Inc.) C:Program FilesuTorrentuTorrent.exe (Skype Technologies S.A.) C:Program FilesSkypePhoneSkype.exe (Valve Corporation) C:Program FilesSteamSteam.exe (Google Inc.) C:Program FilesGoogleChromeApplicationchrome.exe (Google Inc.) C:Program FilesGoogleChromeApplicationchrome.exe (Google Inc.) C:Program FilesGoogleChromeApplicationchrome.exe (Google Inc.) C:Program FilesGoogleChromeApplicationchrome.exe (Google Inc.) C:Program FilesGoogleChromeApplicationchrome.exe (Google Inc.) C:Program FilesGoogleChromeApplicationchrome.exe (Google Inc.) C:Program FilesGoogleChromeApplicationchrome.exe (Google Inc.) C:Program FilesGoogleChromeApplicationchrome.exe (Google Inc.) C:Program FilesGoogleChromeApplicationchrome.exe (Google Inc.) C:Program FilesGoogleChromeApplicationchrome.exe (Google Inc.) C:Program FilesGoogleChromeApplicationchrome.exe (Google Inc.) C:Program FilesGoogleChromeApplicationchrome.exe ==================== Registry (Whitelisted) ================== HKLM...Run: [RTHDCPL] - C:WINDOWSRTHDCPL.EXE [18789920 2009-12-08] (Realtek Semiconductor Corp.) HKLM...Run: [LanguageShortcut] - C:Program FilesCyberLinkPowerDVDLanguageLanguage.exe [49152 2006-09-29] () HKLM...Run: [D-Link AirPlus G] - C:Program FilesD-LinkAirPlus GAirGCFG.exe [1552384 2006-11-17] (D-Link) HKLM...Run: [ANIWZCS2Service] - C:Program FilesANIANIWZCS2 ServiceWZCSLDR2.exe [49152 2006-06-29] (Alpha Networks Inc.) HKLM...Run: [DivXUpdate] - C:Program FilesDivXDivX UpdateDivXUpdate.exe [1144104 2010-06-03] () HKLM...Run: [NokiaMServer] - C:Program FilesCommon FilesNokiaMPlatformNokiaMServer /watchfiles startup HKLM...Run: [Adobe Reader Speed Launcher] - C:Program FilesAdobeReader 9.0Readerreader_sl.exe [38872 2012-07-31] (Adobe Systems Incorporated) HKLM...Run: [Adobe ARM] - C:Program FilesCommon FilesAdobeARM1.0AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM...Run: [TkBellExe] - C:Program FilesRealRealPlayerUpdaterealsched.exe [295512 2013-04-01] (RealNetworks, Inc.) HKLM...Run: [avast] - C:Program FilesAVAST SoftwareAvastAvastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM...Run: [AdobeAAMUpdater-1.0] - C:Program FilesCommon FilesAdobeOOBEPDAppUWAupdaterstartuputility.exe [472992 2013-03-21] (Adobe Systems Incorporated) HKLM...Run: [switchBoard] - C:Program FilesCommon FilesAdobeSwitchBoardSwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM...Run: [AdobeCS6ServiceManager] - C:Program FilesCommon FilesAdobeCS6ServiceManagerCS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM...Run: [20131121] - C:Program FilesAVAST SoftwareAvastSetupemupdate5cfa0952-aa0e-44c3-b578-4d6941337895.exe [180184 2013-11-23] (AVAST Software) HKLM...Run: [LogMeIn Hamachi Ui] - C:Program FilesLogMeIn Hamachihamachi-2-ui.exe [3806544 2013-11-29] (LogMeIn Inc.) HKLM...Run: [sunJavaUpdateSched] - C:Program FilesCommon FilesJavaJava Updatejusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM...Runonce: [AvgUninstallURL] - cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBBAFYARgBSAEUARQAtAFYAMABLAE0AQwAtAEUAOQBWAFUAVwAtAEUAVwAwAFYAQQAtAFUAVQAzAFgATAAtAEYARQBXADkANwA"&"inst=NwA3AC0ANQA5ADcAOQAxADQAMQA5ADgALQBGAEwAKwA5AC0AWABPADkAKwAxAC0AWABPADMANgArADEA"&"prod=90"&"ver=9.0.872 WinlogonNotifyAtiExtEvent: C:Windowssystem32Ati2evxx.dll (ATI Technologies Inc.) WinlogonNotifyLMIinit: C:Windowssystem32LMIinit.dll (LogMeIn, Inc.) HKCU...Run: [Google Update] - C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe [136176 2011-06-03] (Google Inc.) HKCU...Run: [swg] - C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe [39408 2010-05-23] (Google Inc.) HKCU...Run: [MSMSGS] - C:Program FilesMessengermsmsgs.exe [1695232 2008-04-14] (Microsoft Corporation) HKCU...Run: [Facebook Update] - C:Documents and SettingsAdministratorLocal SettingsApplication DataFacebookUpdateFacebookUpdate.exe [138096 2012-07-12] (Facebook Inc.) HKCU...Run: [uTorrent] - C:Program FilesuTorrentuTorrent.exe [802136 2013-04-20] (BitTorrent Inc.) HKCU...Run: [skype] - C:Program FilesSkypePhoneSkype.exe [20588704 2013-11-15] (Skype Technologies S.A.) HKCU...Run: [steam] - C:Program FilesSteamSteam.exe [1823656 2013-12-11] (Valve Corporation) HKCU...Run: [PC Suite Tray] - "C:Program FilesNokiaNokia PC Suite 7PCSuite.exe" -onlytray HKCU...Run: [EvolveClient] - C:Program FilesEchobitEvolveEvolveClient.exe [3207072 2013-11-30] (Echobit LLC) MountPoints2: {8a2a7f71-ea8c-11e1-bd5f-001d7d5c9254} - F:setup.exe HKUBruno...Run: [msnmsgr] - C:Program FilesWindows LiveMessengermsnmsgr.exe [ 2010-04-16] (Microsoft Corporation) HKUBruno...Run: [Google Update] - "C:Documents and SettingsBrunoLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe" /c HKUBruno...Run: [blazeServoTool] - "C:Program FilesBlazeVideoBlazeDTV 6.0MediaDetector.exe" HKUBruno...Run: [swg] - C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe [ 2010-05-23] (Google Inc.) HKUBruno...Winlogon: [shell] HKUPetraa...Run: [msnmsgr] - C:Program FilesWindows LiveMessengermsnmsgr.exe [ 2010-04-16] (Microsoft Corporation) HKUPetraa...Run: [swg] - C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe [ 2010-05-23] (Google Inc.) HKUPetraa...Run: [PC Suite Tray] - "C:Program FilesNokiaNokia PC Suite 7PCSuite.exe" -onlytray HKUPetraa...Run: [Akamai NetSession Interface] - C:Documents and SettingsPetraaLocal SettingsApplication DataAkamainetsession_win.exe [ 2013-06-05] (Akamai Technologies, Inc.) HKUPetraa...Winlogon: [shell] C:RECYCLERS-1-5-21-2410097703-9931454827-202138925-7790djwi2kcew.exe,explorer.exe,C:Documents and SettingsPetraafxmdk.exe <==== ATTENTION AppInit_DLLs: C:Program FilesCONTIN~1SPROTE~1.DLL [ 2013-12-17] () Startup: C:Documents and SettingsAdministratorStart MenuProgramsStartupMagicDisc.lnk ShortcutTarget: MagicDisc.lnk -> C:Program FilesMagicDiscMagicDisc.exe (MagicISO, Inc.) Startup: C:Documents and SettingsAll UsersStart MenuProgramsStartupMicrosoft Office.lnk ShortcutTarget: Microsoft Office.lnk -> C:Program FilesMicrosoft OfficeOffice10OSA.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page Redirect Cache = http://www.msn.com/ HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page Redirect Cache_TIMESTAMP = 0x5E2A95BEC7C6CA01 HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page Redirect Cache AcceptLangs = hr URLSearchHook: ATTENTION ==> Default URLSearchHook is missing. SearchScopes: HKLM - DefaultScope value is missing. BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelperShim.dll (Adobe Systems Incorporated) BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:Documents and SettingsAll UsersApplication DataRealNetworksRealDownloaderBrowserPluginsIErndlbrowserrecordplugin.dll (RealDownloader) BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre7binssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll (Microsoft Corporation) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll (Google Inc.) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.7.9012.1008swg.dll (Google Inc.) BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre7binjp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll (AVAST Software) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - RadioBar Toolbar - {5B291E6C-9A74-4034-971B-A4B007A0B315} - No File Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar_32.dll (Google Inc.) Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:Program FilesCommon FilesMicrosoft SharedWeb FoldersPKMCDO.DLL (Microsoft Corporation) Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:Program FilesWindows LiveMessengermsgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:Program FilesCommon FilesMicrosoft SharedInformation RetrievalMSITSS.DLL (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:Program FilesWindows LiveMessengermsgrapp.14.0.8117.0416.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:Program FilesCommon FilesSkypeSkype4COM.dll (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt TcpipParameters: [DhcpNameServer] 83.139.104.2 83.139.105.2 Tcpip..Interfaces{EF775A33-B11B-4473-926D-D70AD9A08E75}: [NameServer]195.29.166.116,195.29.166.117 FireFox: ======== FF ProfilePath: C:Documents and SettingsAdministratorApplication DataMozillaFirefoxProfiles5gozow0a.default FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", ""); FF SearchEngineOrder.user_pref("browser.search.order.1,S", "");: user_pref("browser.search.order.1,S", ""); FF Homepage: www.google.com FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:WINDOWSsystem32MacromedFlashNPSWF32_11_9_900_170.dll () FF Plugin: @adobe.com/ShockwavePlayer - C:WINDOWSsystem32AdobeDirectornp32dsw_1166636.dll (Adobe Systems, Inc.) FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:Program FilesDivXDivX Plus Web Playernpdivx32.dll (DivX,Inc.) FF Plugin: @idsoftware.com/QuakeLive - C:Documents and SettingsAll UsersApplication Dataid SoftwareQuakeLivenpquakezero.dll (id Software Inc.) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:Program FilesJavajre7bindtpluginnpDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:Program FilesJavajre7binplugin2npjp2.dll (Oracle Corporation) FF Plugin: @live.heroesandgenerals.com/npretox - C:Program FilesHeroes & Generalslivenpretoxlive.dll No File FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:PROGRA~1MICROS~2Office14NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WPF,version=3.5 - C:WINDOWSMicrosoft.NETFrameworkv3.5Windows Presentation FoundationNPWPF.dll (Microsoft Corporation) FF Plugin: @nexon.net/NxGame - C:Documents and SettingsAll UsersApplication DataNexonUSNGMnpNxGameUS.dll (Nexon) FF Plugin: @ngm.nexoneu.com/NxGame - C:Documents and SettingsAll UsersApplication DataNexonEUNGMnpNxGameeu.dll No File FF Plugin: @pandonetworks.com/PandoWebPlugin - C:Program FilesPando NetworksMedia BoosternpPandoWebPlugin.dll (Pando Networks) FF Plugin: @real.com/nppl3260;version=16.0.1.18 - c:program filesrealrealplayerNetscape6nppl3260.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.1 - C:Documents and SettingsAll UsersApplication DataRealNetworksRealDownloaderBrowserPluginsMozillaPluginsnprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.1 - C:Documents and SettingsAll UsersApplication DataRealNetworksRealDownloaderBrowserPluginsMozillaPluginsnprndlhtml5videoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.1 - C:Documents and SettingsAll UsersApplication DataRealNetworksRealDownloaderBrowserPluginsMozillaPluginsnprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF Plugin: @real.com/nprpplugin;version=16.0.1.18 - c:program filesrealrealplayerNetscape6nprpplugin.dll (RealPlayer) FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:Documents and SettingsAll UsersApplication DataRealNetworksRealDownloaderBrowserPluginsnpdlplugin.dll (RealDownloader) FF Plugin: @tools.google.com/Google Update;version=3 - C:Program FilesGoogleUpdate1.3.22.3npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:Program FilesGoogleUpdate1.3.22.3npGoogleUpdate3.dll (Google Inc.) FF Plugin: Adobe Reader - C:Program FilesAdobeReader 9.0ReaderAIRnppdf32.dll (Adobe Systems Inc.) FF Plugin: adobe.com/AdobeAAMDetect - C:Program FilesCommon FilesAdobeOOBEPDAppCCMUtilitiesnpAdobeAAMDetect32.dll (Adobe Systems) FF Plugin HKCU: @onlive.com/OnLiveGameClientDetector,version=1.0.0 - C:Program FilesOnLivePluginnpolgdet.dll (OnLive) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:Documents and SettingsAdministratorLocal SettingsApplication DataFacebookVideoSkypenpFacebookVideoCalling.dll (Skype Limited) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleUpdate1.3.22.3npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleUpdate1.3.22.3npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:Documents and SettingsAdministratorLocal SettingsApplication DataUnityWebPlayerloadernpUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:Program FilesPando NetworksMedia BoosternpPandoWebPlugin.dll (Pando Networks) FF Plugin HKCU: ubisoft.com/uplaypc - D:GSettlersDataBase_DbgBinReleaseorbitnpuplaypc.dll No File FF SearchPlugin: C:Program Filesmozilla firefoxsearchpluginsfacesmoochtb.xml FF Extension: Auto Refresh - C:Documents and SettingsAdministratorApplication [email protected]plugin.xpi FF Extension: ip:filtered: - C:Documents and SettingsAdministratorApplication DataMozillaFirefoxProfiles5gozow0a.defaultExtensionsip:filtered:@p4ul.info.xpi FF Extension: Microsoft .NET Framework Assistant - C:Documents and SettingsAdministratorApplication DataMozillaFirefoxProfiles5gozow0a.defaultExtensions{20a82645-c095-46ed-80e3-08825760534b}.xpi FF HKLM...FirefoxExtensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:Documents and SettingsAll UsersApplication DataRealRealPlayerBrowserRecordPluginFirefoxExt FF Extension: No Name - C:Documents and SettingsAll UsersApplication DataRealRealPlayerBrowserRecordPluginFirefoxExt FF HKLM...FirefoxExtensions: [{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}] - C:Documents and SettingsAll UsersApplication DataRealRealPlayerBrowserRecordPluginFirefoxExt FF Extension: No Name - C:Documents and SettingsAll UsersApplication DataRealRealPlayerBrowserRecordPluginFirefoxExt FF HKLM...FirefoxExtensions: [{C3949AC2-4B17-43ee-B4F1-D26B9D42404D}] - C:Documents and SettingsAll UsersApplication DataRealRealPlayerBrowserRecordPluginFirefoxExt FF Extension: No Name - C:Documents and SettingsAll UsersApplication DataRealRealPlayerBrowserRecordPluginFirefoxExt FF HKLM...FirefoxExtensions: [{DAC3F861-B30D-40dd-9166-F4E75327FAC7}] - C:Documents and SettingsAll UsersApplication DataRealNetworksRealDownloaderBrowserPluginsFirefoxExt FF Extension: RealDownloader - C:Documents and SettingsAll UsersApplication DataRealNetworksRealDownloaderBrowserPluginsFirefoxExt FF HKLM...FirefoxExtensions: [[email protected]] - C:Program FilesAVAST SoftwareAvastWebRepFF FF Extension: avast! Online Security - C:Program FilesAVAST SoftwareAvastWebRepFF Chrome: ======= CHR Plugin: (Shockwave Flash) - C:Program FilesGoogleChromeApplication31.0.1650.63PepperFlashpepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:Program FilesGoogleChromeApplication31.0.1650.63ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:Program FilesGoogleChromeApplication31.0.1650.63pdf.dll () CHR Plugin: (Microsoftu00AE Windows Media Player Firefox Plugin) - C:Documents and SettingsAdministratorApplication DataMozillapluginsnp-mswmp.dll (Microsoft Corporation) CHR Plugin: (Adobe Acrobat) - C:Program FilesAdobeReader 9.0ReaderBrowsernppdf32.dll (Adobe Systems Inc.) CHR Plugin: (ijji Auto Install Plugin for Mozilla) - C:Program FilesMozilla Firefoxpluginsnpijjiautoinstallpluginff.dll (NHN USA Inc.) CHR Plugin: (RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:Program FilesMozilla Firefoxpluginsnppl3260.dll (RealNetworks, Inc.) CHR Plugin: (RealJukebox NS Plugin) - C:Program FilesMozilla Firefoxpluginsnprjplug.dll No File CHR Plugin: (RealPlayer Download Plugin) - C:Program FilesMozilla Firefoxpluginsnprpplugin.dll (RealPlayer) CHR Plugin: (Microsoftu00AE DRM) - C:Program FilesWindows Media Playernpdrmv2.dll (Microsoft Corporation) CHR Plugin: (Microsoftu00AE DRM) - C:Program FilesWindows Media Playernpwmsdrm.dll (Microsoft Corporation) CHR Plugin: (Facebook Video Calling Plugin) - C:Documents and SettingsAdministratorLocal SettingsApplication DataFacebookVideoSkypenpFacebookVideoCalling.dll (Skype Limited) CHR Plugin: (Google Update) - C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleUpdate1.3.21.135npGoogleUpdate3.dll No File CHR Plugin: (Unity Player) - C:Documents and SettingsAdministratorLocal SettingsApplication DataUnityWebPlayerloadernpUnity3D32.dll (Unity Technologies ApS) CHR Plugin: (Nexon Game Controller) - C:Documents and SettingsAll UsersApplication DataNexonUSNGMnpNxGameUS.dll (Nexon) CHR Plugin: (RealNetworks Chrome Background Extension Plug-In (32-bit) ) - C:Documents and SettingsAll UsersApplication DataRealRealPlayerBrowserRecordPluginMozillaPluginsnprpchromebrowserrecordext.dll (RealNetworks, Inc.) CHR Plugin: (RealPlayer HTML5VideoShim Plug-In (32-bit) ) - C:Documents and SettingsAll UsersApplication DataRealRealPlayerBrowserRecordPluginMozillaPluginsnprphtml5videoshim.dll (RealNetworks, Inc.) CHR Plugin: (QUAKE LIVE) - C:Documents and SettingsAll UsersApplication Dataid SoftwareQuakeLivenpquakezero.dll (id Software Inc.) CHR Plugin: (Microsoft Office 2010) - C:PROGRA~1MICROS~2Office14NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (AVG SiteSafety plugin) - C:Program FilesCommon FilesAVG Secure SearchSiteSafetyInstaller14.2.0npsitesafety.dll No File CHR Plugin: (DivX Web Player) - C:Program FilesDivXDivX Plus Web Playernpdivx32.dll (DivX,Inc.) CHR Plugin: (Java Platform SE 7 U9) - C:Program FilesJavajre7binplugin2npjp2.dll (Oracle Corporation) CHR Plugin: (OnLive Game Client Detector) - C:Program FilesOnLivePluginnpolgdet.dll (OnLive) CHR Plugin: (Pando Web Plugin) - C:Program FilesPando NetworksMedia BoosternpPandoWebPlugin.dll (Pando Networks) CHR Plugin: (Windows Presentation Foundation) - C:WINDOWSMicrosoft.NETFrameworkv3.5Windows Presentation FoundationNPWPF.dll (Microsoft Corporation) CHR Plugin: (Shockwave for Director) - C:WINDOWSsystem32AdobeDirectornp32dsw_1166636.dll (Adobe Systems, Inc.) CHR Plugin: (Shockwave Flash) - C:WINDOWSsystem32MacromedFlashNPSWF32_11_6_602_171.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.90.5) - C:WINDOWSsystem32npDeployJava1.dll No File CHR Extension: (RealDownloader) - C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsidhngdhcfkoamngbedgpaokgjbnpdiji1.3.1_0 CHR Extension: (Google Wallet) - C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsnmmhkkegccagdldgiimedpiccmgmieda0.0.6.0_0 CHR HKLM...ChromeExtension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:Documents and SettingsAll UsersApplication DataRealNetworksRealDownloaderBrowserPluginsChromeExtrealdownloader.crx ========================== Services (Whitelisted) ================= R2 Akamai; c:program filescommon filesakamai/netsession_win_8fa3539.dll [4569856 2013-08-02] (Akamai Technologies, Inc.) S2 ANIWZCSdService; C:Program FilesANIANIWZCS2 ServiceANIWZCSdS.exe [49152 2006-07-03] (Alpha Networks Inc.) R2 avast! Antivirus; C:Program FilesAVAST SoftwareAvastAvastSvc.exe [46808 2013-05-09] (AVAST Software) S3 EvoSvc; C:Documents and SettingsAll UsersApplication DataEchobitEvolveEvoSvc.log [739385 2013-12-09] () R2 Hamachi2Svc; C:Program FilesLogMeIn Hamachihamachi-2.exe [1664336 2013-11-29] (LogMeIn Inc.) R2 LMIGuardianSvc; C:Program FilesLogMeIn HamachiLMIGuardianSvc.exe [375056 2013-10-11] (LogMeIn, Inc.) R2 MBAMScheduler; d:gMalwarebytes' Anti-Malwarembamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; d:gMalwarebytes' Anti-Malwarembamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S2 PnkBstrA; C:WINDOWSsystem32PnkBstrA.exe [76888 2012-03-26] () R2 RealNetworks Downloader Resolver Service; C:Program FilesRealNetworksRealDownloaderrndlresolversvc.exe [39056 2013-03-06] () R2 RichVideo; C:Program FilesCyberLinkShared filesRichVideo.exe [167936 2005-08-08] () S3 TunngleService; C:Program FilesTunngleTnglCtrl.exe [746392 2013-03-20] (Tunngle.net GmbH) R2 UPHClean; C:Program FilesUPHCleanuphclean.exe [241725 2005-04-27] (Microsoft Corporation) S2 xthxbdrbrxtccdiwenti; C:WindowsSystem32svchost.exe [14336 2008-04-14] (Microsoft Corporation) R2 JavaQuickStarterService; "C:Program FilesJavajre7binjqs.exe" -service -config "C:Program FilesJavajre7libdeployjqsjqs.conf" S2 vToolbarUpdater17.2.0; C:Program FilesCommon FilesAVG Secure SearchvToolbarUpdater17.2.0ToolbarUpdater.exe [x] ==================== Drivers (Whitelisted) ==================== S3 AF9035BDA; C:WindowsSystem32DriversAF9035BDA.sys [459776 2010-10-29] (AfaTech ) S3 Ambfilt; C:WindowsSystem32driversAmbfilt.sys [1691480 2009-11-18] (Creative) R1 AmdK8; C:WindowsSystem32DRIVERSAmdK8.sys [36864 2006-07-01] (Advanced Micro Devices) S1 AmdPPM; C:WindowsSystem32DRIVERSAmdPPM.sys [33792 2007-04-16] (Advanced Micro Devices) R2 ANIO; C:WINDOWSsystem32ANIO.SYS [28195 2005-12-11] (Alpha Networks Inc.) R2 aswFsBlk; C:WindowsSystem32DriversaswFsBlk.sys [29816 2013-05-09] (AVAST Software) R2 aswMonFlt; C:WINDOWSsystem32driversaswMonFlt.sys [66336 2013-05-09] (AVAST Software) R1 AswRdr; C:WindowsSystem32DriversAswRdr.sys [49760 2013-05-09] (AVAST Software) R0 aswRvrt; C:WindowsSystem32DriversaswRvrt.sys [49376 2013-05-09] () R1 aswSnx; C:WindowsSystem32DriversaswSnx.sys [770344 2013-06-27] (AVAST Software) R1 aswSP; C:WindowsSystem32DriversaswSP.sys [369584 2013-06-27] (AVAST Software) R1 aswTdi; C:WindowsSystem32DriversaswTdi.sys [56080 2013-05-09] (AVAST Software) R0 aswVmm; C:WindowsSystem32DriversaswVmm.sys [175176 2013-06-27] () R2 atksgt; C:WindowsSystem32DRIVERSatksgt.sys [271360 2013-04-14] () R1 avgtp; C:WINDOWSsystem32driversavgtpx86.sys [37664 2013-11-12] (AVG Technologies) S3 CCDECODE; C:WindowsSystem32DRIVERSCCDECODE.sys [17024 2008-04-14] (Microsoft Corporation) R3 EvolveVirtualAdapter; C:WindowsSystem32DRIVERSevolve.sys [18584 2013-08-02] (Echobit, LLC) R3 hamachi; C:WindowsSystem32DRIVERShamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) R2 lirsgt; C:WindowsSystem32DRIVERSlirsgt.sys [18048 2013-04-14] () R3 MBAMProtector; C:WINDOWSsystem32driversmbam.sys [22856 2013-04-04] (Malwarebytes Corporation) S3 Monfilt; C:WindowsSystem32driversMonfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.) S3 MPE; C:WindowsSystem32DRIVERSMPE.sys [15232 2008-04-14] (Microsoft Corporation) S3 NdisIP; C:WindowsSystem32DRIVERSNdisIP.sys [10880 2008-04-14] (Microsoft Corporation) R0 nvata; C:WindowsSystem32DRIVERSnvata.sys [105472 2006-10-18] (NVIDIA Corporation) R3 NVENETFD; C:WindowsSystem32DRIVERSNVENETFD.sys [54784 2008-08-01] (NVIDIA Corporation) R3 nvnetbus; C:WindowsSystem32DRIVERSnvnetbus.sys [22016 2008-08-01] (NVIDIA Corporation) S3 RT73; C:WindowsSystem32DRIVERSDr71WU.sys [245504 2005-11-03] (Ralink Technology, Corp.) S3 SCREAMINGBDRIVER; C:WindowsSystem32driversScreamingBAudio.sys [34896 2012-07-31] (Screaming Bee LLC) R3 Sftfs; C:WindowsSystem32DRIVERSSftfsxp.sys [587944 2013-06-26] (Microsoft Corporation) R3 Sftplay; C:WindowsSystem32DRIVERSSftplayxp.sys [213288 2013-06-26] (Microsoft Corporation) R3 Sftredir; C:WindowsSystem32DRIVERSSftredirxp.sys [23208 2013-06-26] (Microsoft Corporation) R3 Sftvol; C:WindowsSystem32DRIVERSSftvolxp.sys [19112 2013-06-26] (Microsoft Corporation) R0 sfvfs02; C:WindowsSystem32driverssfvfs02.sys [66048 2005-09-29] (Protection Technology) R1 StarOpen; C:WindowsSystem32DriversStarOpen.sys [5632 2006-07-24] () R3 tap0901t; C:WindowsSystem32DRIVERStap0901t.sys [27136 2009-09-16] (Tunngle.net) S3 tenCapture; C:WindowsSystem32DRIVERStenCapture.sys [20664 2012-07-20] (Hajo Krabbenhöft) R3 VCSVADHWSer; C:WindowsSystem32DRIVERSvcsvad.sys [17792 2008-12-26] (Avnex) R3 voxaldriver; C:WindowsSystem32DRIVERSvoxaldriverx86.sys [43344 2013-11-10] () S3 EagleXNt; ??C:WINDOWSsystem32driversEagleXNt.sys [x] S3 FairplayKD; ??C:Documents and SettingsAll UsersApplication DataMTA San Andreas All1.3tempFairplayKD.sys [x] S4 IntelIde; No ImagePath S4 LMIRfsClientNP; No ImagePath U1 WS2IFSL; ==================== NetSvcs (Whitelisted) =================== NETSVC: xthxbdrbrxtccdiwenti -> No Registry Path. ==================== One Month Created Files and Folders ======== 2013-12-27 21:26 - 2013-12-27 21:26 - 00000000 ____D C:FRST 2013-12-27 21:24 - 2013-12-27 21:26 - 00005594 _____ C:Documents and SettingsAdministratordesktopRkill.txt 2013-12-27 21:24 - 2013-12-27 21:24 - 00000000 ____D C:Documents and SettingsAdministratordesktoprkill 2013-12-26 09:13 - 2013-12-26 09:13 - 00000858 _____ C:WINDOWSsetupact.log 2013-12-26 09:13 - 2013-12-26 09:13 - 00000000 _____ C:WINDOWSsetuperr.log 2013-12-25 18:52 - 2013-12-25 18:52 - 00000000 ____D C:Documents and SettingsBrunoLocal SettingsApplication DataLogMeIn 2013-12-25 15:32 - 2013-12-26 09:13 - 00017457 _____ C:WINDOWSsetupapi.log 2013-12-24 20:45 - 2013-12-24 20:45 - 00000000 ____D C:Documents and SettingsAdministratorApplication DataSierra Entertainment 2013-12-24 20:42 - 2013-12-24 20:45 - 00000000 ____D C:Documents and SettingsAdministratorMy DocumentsEmpire Earth III 2013-12-24 20:42 - 2013-12-24 20:43 - 00075974 _____ C:WINDOWSDirectX.log 2013-12-24 20:42 - 2013-12-24 20:42 - 00000000 ____D C:WINDOWS85EBB28365AF4C539EBE7C0A232762F7.TMP 2013-12-24 15:34 - 2013-12-24 15:34 - 00000000 ____D C:Documents and SettingsAll UsersStart MenuPrograms7 Days to Die 2013-12-23 15:42 - 2013-12-23 15:42 - 00006338 _____ C:WINDOWSDPINST.LOG 2013-12-23 15:02 - 2013-12-23 15:02 - 00000000 ____D C:Program FilesCommon FilesJava 2013-12-23 15:00 - 2013-12-23 15:00 - 00000000 ____D C:Documents and SettingsAll UsersStart MenuProgramsJava 2013-12-23 15:00 - 2013-12-23 14:59 - 00264616 _____ (Oracle Corporation) C:WINDOWSsystem32javaws.exe 2013-12-23 15:00 - 2013-12-23 14:59 - 00175016 _____ (Oracle Corporation) C:WINDOWSsystem32javaw.exe 2013-12-23 15:00 - 2013-12-23 14:59 - 00174504 _____ (Oracle Corporation) C:WINDOWSsystem32java.exe 2013-12-23 15:00 - 2013-12-23 14:59 - 00145408 _____ (Oracle Corporation) C:WINDOWSsystem32javacpl.cpl 2013-12-23 15:00 - 2013-12-23 14:59 - 00094632 _____ (Oracle Corporation) C:WINDOWSsystem32WindowsAccessBridge.dll 2013-12-23 14:26 - 2013-12-23 14:26 - 00000000 ____D C:Documents and SettingsAdministratorMy DocumentsDayZ 2013-12-23 14:26 - 2013-12-23 14:26 - 00000000 ____D C:Documents and SettingsAdministratorLocal SettingsApplication DataDayZ 2013-12-19 14:35 - 2013-12-19 20:42 - 00000000 ____D C:AdwCleaner 2013-12-17 16:25 - 2013-12-17 16:26 - 00000000 ____D C:rsit 2013-12-17 16:25 - 2013-12-17 16:26 - 00000000 ____D C:Program Filestrend micro 2013-12-17 16:00 - 2013-12-17 16:02 - 00594166 _____ C:Documents and SettingsAdministratorMy Documentscc_20131217_160055.reg 2013-12-17 15:48 - 2013-12-17 15:48 - 00000000 ____D C:Program FilesCCleaner 2013-12-17 15:48 - 2013-12-17 15:48 - 00000000 ____D C:Documents and SettingsAll UsersStart MenuProgramsCCleaner 2013-12-17 15:37 - 2013-12-17 15:37 - 00000000 ____D C:Documents and SettingsAdministratorLocal SettingsApplication DataLogMeIn 2013-12-17 15:32 - 2013-12-17 15:32 - 00000000 ____D C:Program FilesCONTIN~1 2013-12-17 06:43 - 2013-12-17 06:43 - 00000000 ____D C:Program FilesLogMeIn Hamachi 2013-12-17 06:43 - 2013-12-17 06:43 - 00000000 ____D C:Documents and SettingsAll UsersStart MenuProgramsHamachi 2013-12-16 14:51 - 2013-12-16 14:51 - 00300544 _____ C:Documents and SettingsAdministratordesktopKod veselog Bere.ppt 2013-12-13 08:21 - 2013-12-13 23:50 - 00000000 ____D C:Documents and SettingsAdministratorMy DocumentsNexus Mod Manager 2013-12-12 22:48 - 2013-12-12 22:48 - 00000000 __HDC C:WINDOWS$NtUninstallKB2904266$ 2013-12-12 22:48 - 2013-12-12 22:48 - 00000000 __HDC C:WINDOWS$NtUninstallKB2898715$ 2013-12-12 22:43 - 2013-12-12 22:43 - 00000000 __HDC C:WINDOWS$NtUninstallKB2893984$ 2013-12-12 22:43 - 2013-12-12 22:43 - 00000000 __HDC C:WINDOWS$NtUninstallKB2893294$ 2013-12-12 22:43 - 2013-12-12 22:43 - 00000000 __HDC C:WINDOWS$NtUninstallKB2892075$ 2013-12-11 21:01 - 2013-12-11 21:01 - 00020480 _____ C:Documents and SettingsBrunodesktopTemeljni pristup istraživanju tržišta nekretnina.ppt 2013-12-10 22:20 - 2013-12-10 22:20 - 03686454 _____ C:Documents and SettingsPetraadesktopiva.bmp 2013-12-02 17:58 - 2013-12-02 17:58 - 00000000 ____D C:Documents and SettingsAdministratorMy DocumentsElectronic Arts 2013-12-02 13:07 - 2009-07-20 13:34 - 00409600 _____ (ActiveLock) C:WINDOWSsystem32activelock1884.ocx 2013-11-27 07:03 - 2013-12-27 08:03 - 00000444 _____ C:WINDOWSTasksRNUpgradeHelperLogonPrompt_Administrator.job 2013-11-27 07:03 - 2013-12-18 07:09 - 00000434 _____ C:WINDOWSTasksReclaimerUpdateXML_Administrator.job 2013-11-27 07:03 - 2013-11-27 07:04 - 00000438 _____ C:WINDOWSTasksReclaimerUpdateFiles_Administrator.job ==================== One Month Modified Files and Folders ======= 2013-12-27 21:27 - 2012-01-05 10:59 - 00000000 ____D C:Documents and SettingsAdministratorApplication DatauTorrent 2013-12-27 21:26 - 2013-12-27 21:26 - 00000000 ____D C:FRST 2013-12-27 21:26 - 2013-12-27 21:24 - 00005594 _____ C:Documents and SettingsAdministratordesktopRkill.txt 2013-12-27 21:25 - 2012-07-29 21:08 - 00000000 ____D C:Documents and SettingsAdministratorApplication DataSkype 2013-12-27 21:24 - 2013-12-27 21:24 - 00000000 ____D C:Documents and SettingsAdministratordesktoprkill 2013-12-27 21:08 - 2012-09-16 13:37 - 00000830 _____ C:WINDOWSTasksAdobe Flash Player Updater.job 2013-12-27 21:08 - 2010-06-30 15:53 - 00001028 _____ C:WINDOWSTasksGoogleUpdateTaskUserS-1-5-21-343818398-854245398-725345543-1005UA.job 2013-12-27 21:03 - 2011-11-21 14:53 - 00001080 _____ C:WINDOWSTasksFacebookUpdateTaskUserS-1-5-21-343818398-854245398-725345543-500UA.job 2013-12-27 20:53 - 2013-05-19 17:51 - 00000000 ____D C:Program FilesSteam 2013-12-27 20:40 - 2010-05-23 20:54 - 00000936 _____ C:WINDOWSTasksGoogleUpdateTaskMachineUA.job 2013-12-27 20:30 - 2011-05-13 18:36 - 00001060 _____ C:WINDOWSTasksGoogleUpdateTaskUserS-1-5-21-343818398-854245398-725345543-500UA.job 2013-12-27 12:42 - 2013-05-10 11:42 - 00000378 ____H C:WINDOWSTasksavast! Emergency Update.job 2013-12-27 10:08 - 2010-06-30 15:53 - 00000976 _____ C:WINDOWSTasksGoogleUpdateTaskUserS-1-5-21-343818398-854245398-725345543-1005Core.job 2013-12-27 09:03 - 2011-11-21 14:53 - 00001058 _____ C:WINDOWSTasksFacebookUpdateTaskUserS-1-5-21-343818398-854245398-725345543-500Core.job 2013-12-27 08:51 - 2010-09-15 21:08 - 00000286 _____ C:WINDOWSTasksRealUpgradeScheduledTaskS-1-5-21-343818398-854245398-725345543-1005.job 2013-12-27 08:16 - 2010-02-17 10:16 - 01223749 _____ C:WINDOWSWindowsUpdate.log 2013-12-27 08:06 - 2013-01-20 11:24 - 00000000 ____D C:Documents and SettingsLocalServiceLocal SettingsApplication DataLogMeIn Hamachi 2013-12-27 08:06 - 2013-01-20 11:24 - 00000000 ____D C:Documents and SettingsAdministratorLocal SettingsApplication DataLogMeIn Hamachi 2013-12-27 08:06 - 2010-03-16 21:31 - 00000007 _____ C:WINDOWSsystem32ANIWZCSUSERNAME 2013-12-27 08:04 - 2013-02-10 07:20 - 00000294 _____ C:WINDOWSTasksRealUpgradeLogonTaskS-1-5-21-343818398-854245398-725345543-500.job 2013-12-27 08:04 - 2001-08-23 12:00 - 00002262 _____ C:WINDOWSsystem32wpa.dbl 2013-12-27 08:03 - 2013-11-27 07:03 - 00000444 _____ C:WINDOWSTasksRNUpgradeHelperLogonPrompt_Administrator.job 2013-12-27 08:03 - 2013-06-15 21:05 - 00000294 _____ C:WINDOWSTasksRealPlayerRealUpgradeLogonTaskS-1-5-21-343818398-854245398-725345543-500.job 2013-12-27 08:03 - 2013-06-03 17:16 - 00000350 _____ C:WINDOWSTasksAVG-Secure-Search-Update_JUNE2013_TB_rmv.job 2013-12-27 08:03 - 2013-04-04 18:46 - 00000278 _____ C:WINDOWSTasksRealPlayerRealUpgradeLogonTaskS-1-5-21-343818398-854245398-725345543-1005.job 2013-12-27 08:03 - 2013-04-02 16:11 - 00000280 _____ C:WINDOWSTasksRealPlayerRealUpgradeLogonTaskS-1-5-21-343818398-854245398-725345543-1008.job 2013-12-27 08:03 - 2011-12-30 17:32 - 00000328 _____ C:WINDOWSTasksGlaryInitialize.job 2013-12-27 08:03 - 2011-07-21 10:30 - 00000000 ____D C:Program FilesCommon FilesAkamai 2013-12-27 08:03 - 2011-04-21 11:04 - 00000278 _____ C:WINDOWSTasksRealUpgradeLogonTaskS-1-5-21-343818398-854245398-725345543-1005.job 2013-12-27 08:03 - 2011-02-14 21:59 - 00000280 _____ C:WINDOWSTasksRealUpgradeLogonTaskS-1-5-21-343818398-854245398-725345543-1008.job 2013-12-27 08:03 - 2010-12-11 13:58 - 00000288 _____ C:WINDOWSTasksiMeshNAG.job 2013-12-27 08:03 - 2010-05-23 20:54 - 00000932 _____ C:WINDOWSTasksGoogleUpdateTaskMachineCore.job 2013-12-27 08:03 - 2010-02-17 11:10 - 00000159 _____ C:WINDOWSwiadebug.log 2013-12-27 08:03 - 2010-02-17 11:10 - 00000050 _____ C:WINDOWSwiaservc.log 2013-12-27 08:03 - 2010-02-17 10:21 - 00032580 _____ C:WINDOWSSchedLgU.Txt 2013-12-27 08:03 - 2010-02-17 10:21 - 00000006 ____H C:WINDOWSTasksSA.DAT 2013-12-26 23:01 - 2013-04-01 18:33 - 00000302 _____ C:WINDOWSTasksRealPlayerRealUpgradeScheduledTaskS-1-5-21-343818398-854245398-725345543-500.job 2013-12-26 20:39 - 2013-01-22 19:56 - 00000000 ____D C:Documents and SettingsBrunoLocal SettingsApplication DataLogMeIn Hamachi 2013-12-26 20:38 - 2013-04-04 18:46 - 00000286 _____ C:WINDOWSTasksRealPlayerRealUpgradeScheduledTaskS-1-5-21-343818398-854245398-725345543-1005.job 2013-12-26 15:43 - 2012-11-10 22:00 - 00000000 ___RD C:Documents and SettingsAdministratordesktopGames 2013-12-26 09:13 - 2013-12-26 09:13 - 00000858 _____ C:WINDOWSsetupact.log 2013-12-26 09:13 - 2013-12-26 09:13 - 00000000 _____ C:WINDOWSsetuperr.log 2013-12-26 09:13 - 2013-12-25 15:32 - 00017457 _____ C:WINDOWSsetupapi.log 2013-12-26 09:11 - 2011-07-06 14:13 - 00000000 ____D C:Documents and SettingsAdministratorLocal SettingsApplication DataAdobe 2013-12-26 09:06 - 2013-04-28 19:55 - 00000000 ____D C:Documents and SettingsAll UsersApplication DataPackage Cache 2013-12-25 23:01 - 2010-03-15 18:55 - 00000278 ___SH C:Documents and SettingsBrunontuser.ini 2013-12-25 23:00 - 2011-04-28 16:30 - 00000000 ____D C:Documents and SettingsBrunoApplication DataSoftGrid Client 2013-12-25 20:17 - 2013-04-02 16:11 - 00000288 _____ C:WINDOWSTasksRealPlayerRealUpgradeScheduledTaskS-1-5-21-343818398-854245398-725345543-1008.job 2013-12-25 18:52 - 2013-12-25 18:52 - 00000000 ____D C:Documents and SettingsBrunoLocal SettingsApplication DataLogMeIn 2013-12-25 18:47 - 2011-04-28 16:29 - 00000000 ____D C:Documents and SettingsAll UsersDocumentsSoftGrid Client 2013-12-25 15:33 - 2010-02-17 10:16 - 00000000 ____D C:WINDOWSsystem32DirectX 2013-12-25 12:34 - 2013-02-12 14:33 - 00000000 ____D C:Documents and SettingsAdministratorMy DocumentsMy Cheat Tables 2013-12-25 11:47 - 2012-10-25 16:14 - 00002473 _____ C:Documents and SettingsAdministratorStart MenuProgramsPoke.lnk 2013-12-25 09:27 - 2012-12-01 10:04 - 00002265 _____ C:Documents and SettingsAll UsersdesktopSkype.lnk 2013-12-24 20:45 - 2013-12-24 20:45 - 00000000 ____D C:Documents and SettingsAdministratorApplication DataSierra Entertainment 2013-12-24 20:45 - 2013-12-24 20:42 - 00000000 ____D C:Documents and SettingsAdministratorMy DocumentsEmpire Earth III 2013-12-24 20:43 - 2013-12-24 20:42 - 00075974 _____ C:WINDOWSDirectX.log 2013-12-24 20:42 - 2013-12-24 20:42 - 00000000 ____D C:WINDOWS85EBB28365AF4C539EBE7C0A232762F7.TMP 2013-12-24 20:42 - 2013-05-26 21:20 - 00000000 ____D C:Program FilesCommon FilesWise Installation Wizard 2013-12-24 20:31 - 2010-02-17 13:50 - 00000000 ___HD C:Program FilesInstallShield Installation Information 2013-12-24 15:34 - 2013-12-24 15:34 - 00000000 ____D C:Documents and SettingsAll UsersStart MenuPrograms7 Days to Die 2013-12-23 19:23 - 2011-05-06 20:39 - 00000302 _____ C:WINDOWSTasksRealUpgradeScheduledTaskS-1-5-21-343818398-854245398-725345543-500.job 2013-12-23 18:02 - 2012-02-10 19:52 - 00000000 ____D C:Documents and SettingsAdministratordesktopFolders 2013-12-23 15:42 - 2013-12-23 15:42 - 00006338 _____ C:WINDOWSDPINST.LOG 2013-12-23 15:42 - 2011-09-10 17:04 - 00000000 ____D C:Program FilesNokia 2013-12-23 15:42 - 2011-09-10 17:04 - 00000000 ____D C:Program FilesCommon FilesNokia 2013-12-23 15:41 - 2013-08-09 10:04 - 00000000 ____D C:Program FilesMSI Afterburner 2013-12-23 15:37 - 2013-05-25 09:04 - 00000000 ____D C:Documents and SettingsAdministratorLocal SettingsApplication DataFreeciv-2.3.2-gtk2 2013-12-23 15:35 - 2013-08-24 22:14 - 00000000 ____D C:Program FilesFinalAlert 2 Yuri's Revenge 2013-12-23 15:33 - 2013-06-10 10:58 - 00000000 ____D C:Program FilesPortable 2013-12-23 15:32 - 2010-08-29 17:55 - 00000288 _____ C:WINDOWSTasksRealUpgradeScheduledTaskS-1-5-21-343818398-854245398-725345543-1008.job 2013-12-23 15:30 - 2013-01-20 10:53 - 00000000 ____D C:Documents and SettingsAll UsersApplication DataCloudSoft 2013-12-23 15:30 - 2011-08-27 16:29 - 00000000 ____D C:Documents and SettingsAll UsersApplication DataInstallMate 2013-12-23 15:02 - 2013-12-23 15:02 - 00000000 ____D C:Program FilesCommon FilesJava 2013-12-23 15:00 - 2013-12-23 15:00 - 00000000 ____D C:Documents and SettingsAll UsersStart MenuProgramsJava 2013-12-23 14:59 - 2013-12-23 15:00 - 00264616 _____ (Oracle Corporation) C:WINDOWSsystem32javaws.exe 2013-12-23 14:59 - 2013-12-23 15:00 - 00175016 _____ (Oracle Corporation) C:WINDOWSsystem32javaw.exe 2013-12-23 14:59 - 2013-12-23 15:00 - 00174504 _____ (Oracle Corporation) C:WINDOWSsystem32java.exe 2013-12-23 14:59 - 2013-12-23 15:00 - 00145408 _____ (Oracle Corporation) C:WINDOWSsystem32javacpl.cpl 2013-12-23 14:59 - 2013-12-23 15:00 - 00094632 _____ (Oracle Corporation) C:WINDOWSsystem32WindowsAccessBridge.dll 2013-12-23 14:53 - 2010-03-18 19:19 - 00000278 __SHC C:Documents and SettingsAdministratorntuser.ini 2013-12-23 14:52 - 2010-06-17 21:32 - 00000000 ____D C:Program FilesJava 2013-12-23 14:51 - 2010-09-25 19:26 - 00000000 ____D C:Program FilesMozilla Firefox 2013-12-23 14:39 - 2012-07-29 21:07 - 00000000 ____D C:Documents and SettingsAll UsersApplication DataSkype 2013-12-23 14:38 - 2012-11-30 19:53 - 00000000 ___RD C:Program FilesSkype 2013-12-23 14:29 - 2010-02-17 11:02 - 00000000 ____D C:WINDOWSsystem 2013-12-23 14:26 - 2013-12-23 14:26 - 00000000 ____D C:Documents and SettingsAdministratorMy DocumentsDayZ 2013-12-23 14:26 - 2013-12-23 14:26 - 00000000 ____D C:Documents and SettingsAdministratorLocal SettingsApplication DataDayZ 2013-12-23 09:36 - 2011-05-13 18:37 - 00071288 _____ C:Documents and SettingsAdministratorLocal SettingsApplication DataGDIPFONTCACHEV1.DAT 2013-12-22 19:24 - 2011-06-10 14:56 - 00063488 _____ C:Documents and SettingsAdministratorLocal SettingsApplication DataDCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-12-22 19:24 - 2010-07-01 20:59 - 00000069 _____ C:WINDOWSNeroDigital.ini 2013-12-22 14:35 - 2010-02-22 10:16 - 00000000 __HDC C:WINDOWS$NtUninstallKB954154_WM11$ 2013-12-22 14:33 - 2010-02-22 11:47 - 00000000 ____D C:Program FilesWinRAR 2013-12-20 07:59 - 2010-02-18 09:48 - 00000000 ____D C:Program FilesAVG 2013-12-20 07:58 - 2011-11-03 23:02 - 00000000 ____D C:Documents and SettingsAll UsersApplication DataAVG2012 2013-12-20 07:30 - 2011-05-13 18:36 - 00001008 _____ C:WINDOWSTasksGoogleUpdateTaskUserS-1-5-21-343818398-854245398-725345543-500Core.job 2013-12-19 20:42 - 2013-12-19 14:35 - 00000000 ____D C:AdwCleaner 2013-12-18 07:09 - 2013-11-27 07:03 - 00000434 _____ C:WINDOWSTasksReclaimerUpdateXML_Administrator.job 2013-12-17 16:36 - 2010-02-17 11:05 - 03609016 _____ C:WINDOWSsystem32FNTCACHE.DAT 2013-12-17 16:26 - 2013-12-17 16:25 - 00000000 ____D C:rsit 2013-12-17 16:26 - 2013-12-17 16:25 - 00000000 ____D C:Program Filestrend micro 2013-12-17 16:02 - 2013-12-17 16:00 - 00594166 _____ C:Documents and SettingsAdministratorMy Documentscc_20131217_160055.reg 2013-12-17 15:56 - 2013-05-07 15:13 - 00000000 ____D C:Documents and SettingsAdministratorApplication DataFileZilla 2013-12-17 15:56 - 2012-02-09 18:47 - 00000000 ____D C:Documents and SettingsAdministratorApplication DataVso 2013-12-17 15:56 - 2011-06-01 06:03 - 00000000 ____D C:Documents and SettingsAdministratorApplication DataMedia Player Classic 2013-12-17 15:56 - 2010-04-29 19:26 - 00000000 ____D C:Documents and SettingsAdministratorTracing 2013-12-17 15:56 - 2010-03-18 19:19 - 00000000 ____D C:Documents and SettingsAdministrator 2013-12-17 15:56 - 2010-02-17 11:39 - 00000000 ____D C:WINDOWSMinidump 2013-12-17 15:48 - 2013-12-17 15:48 - 00000000 ____D C:Program FilesCCleaner 2013-12-17 15:48 - 2013-12-17 15:48 - 00000000 ____D C:Documents and SettingsAll UsersStart MenuProgramsCCleaner 2013-12-17 15:37 - 2013-12-17 15:37 - 00000000 ____D C:Documents and SettingsAdministratorLocal SettingsApplication DataLogMeIn 2013-12-17 15:37 - 2012-12-08 22:25 - 00000000 ____D C:Documents and SettingsAll UsersApplication DataLogMeIn 2013-12-17 15:32 - 2013-12-17 15:32 - 00000000 ____D C:Program FilesCONTIN~1 2013-12-17 06:43 - 2013-12-17 06:43 - 00000000 ____D C:Program FilesLogMeIn Hamachi 2013-12-17 06:43 - 2013-12-17 06:43 - 00000000 ____D C:Documents and SettingsAll UsersStart MenuProgramsHamachi 2013-12-16 14:51 - 2013-12-16 14:51 - 00300544 _____ C:Documents and SettingsAdministratordesktopKod veselog Bere.ppt 2013-12-16 14:25 - 2013-02-05 08:38 - 00002475 _____ C:Documents and SettingsAll UsersStart MenuProgramsMicrosoft PowerPoint.lnk 2013-12-15 11:13 - 2013-02-05 08:38 - 00002489 _____ C:Documents and SettingsAll UsersStart MenuProgramsMicrosoft Word.lnk 2013-12-14 23:20 - 2012-11-22 17:15 - 00000000 ____D C:Documents and SettingsAdministratorLocal SettingsApplication DataFallout3 2013-12-14 23:20 - 2011-05-10 13:56 - 00000000 ____D C:Documents and SettingsAdministratorApplication DataInstallShield Installation Information 2013-12-14 10:11 - 2011-12-06 18:41 - 00000000 ____D C:Documents and SettingsAdministratorLocal SettingsApplication DataSkyrim 2013-12-13 23:50 - 2013-12-13 08:21 - 00000000 ____D C:Documents and SettingsAdministratorMy DocumentsNexus Mod Manager 2013-12-13 08:21 - 2012-07-18 16:39 - 00000000 ____D C:Documents and SettingsAdministratorLocal SettingsApplication DataBlack_Tree_Gaming 2013-12-12 22:49 - 2010-02-22 08:31 - 00000000 ____D C:WINDOWSie8updates 2013-12-12 22:48 - 2013-12-12 22:48 - 00000000 __HDC C:WINDOWS$NtUninstallKB2904266$ 2013-12-12 22:48 - 2013-12-12 22:48 - 00000000 __HDC C:WINDOWS$NtUninstallKB2898715$ 2013-12-12 22:48 - 2013-08-08 08:50 - 00000000 ____D C:WINDOWSsystem32MRT 2013-12-12 22:48 - 2010-02-22 08:34 - 00046560 _____ C:WINDOWSsystem32TZLog.log 2013-12-12 22:43 - 2013-12-12 22:43 - 00000000 __HDC C:WINDOWS$NtUninstallKB2893984$ 2013-12-12 22:43 - 2013-12-12 22:43 - 00000000 __HDC C:WINDOWS$NtUninstallKB2893294$ 2013-12-12 22:43 - 2013-12-12 22:43 - 00000000 __HDC C:WINDOWS$NtUninstallKB2892075$ 2013-12-12 22:43 - 2010-02-22 08:35 - 88123800 _____ (Microsoft Corporation) C:WINDOWSsystem32MRT.exe 2013-12-11 21:01 - 2013-12-11 21:01 - 00020480 _____ C:Documents and SettingsBrunodesktopTemeljni pristup istraživanju tržišta nekretnina.ppt 2013-12-11 20:31 - 2013-10-10 20:42 - 00071288 _____ C:WINDOWSsystem32GDIPFONTCACHEV1.DAT 2013-12-11 08:00 - 2011-05-18 07:00 - 00000000 ____D C:Documents and SettingsAdministratorLocal SettingsApplication DataMy Games 2013-12-10 22:48 - 2010-03-21 13:22 - 00000278 ___SH C:Documents and SettingsPetraantuser.ini 2013-12-10 22:20 - 2013-12-10 22:20 - 03686454 _____ C:Documents and SettingsPetraadesktopiva.bmp 2013-12-10 22:08 - 2012-09-16 13:37 - 00692616 _____ (Adobe Systems Incorporated) C:WINDOWSsystem32FlashPlayerApp.exe 2013-12-10 22:08 - 2012-09-16 13:37 - 00071048 _____ (Adobe Systems Incorporated) C:WINDOWSsystem32FlashPlayerCPLApp.cpl 2013-12-10 21:25 - 2010-04-21 21:33 - 00071288 _____ C:Documents and SettingsPetraaLocal SettingsApplication DataGDIPFONTCACHEV1.DAT 2013-12-10 21:17 - 2010-02-18 13:36 - 00002497 _____ C:Documents and SettingsPetraadesktopMicrosoft Office Word 2003.lnk 2013-12-10 21:12 - 2013-01-24 20:57 - 00000000 ____D C:Documents and SettingsPetraaLocal SettingsApplication DataLogMeIn Hamachi 2013-12-10 19:15 - 2013-06-27 12:31 - 00003730 _____ C:Program FilesMozilla Firefoxavg-secure-search.xml 2013-12-10 19:15 - 2011-12-18 20:20 - 00000000 ____D C:WINDOWSsystem32cache 2013-12-07 13:50 - 2013-10-20 07:21 - 00000000 ____D C:Documents and SettingsAdministratorApplication Data.minecraft 2013-12-06 07:45 - 2013-02-23 07:37 - 00001809 _____ C:Documents and SettingsAll UsersdesktopGoogle Chrome.lnk 2013-12-04 22:43 - 2013-08-04 13:30 - 01317082 _____ C:Documents and SettingsLocalServiceLocal SettingsApplication DataWPFFontCache_v0400-S-1-5-21-343818398-854245398-725345543-500-0.dat 2013-12-04 22:43 - 2013-03-24 23:02 - 00379826 _____ C:Documents and SettingsLocalServiceLocal SettingsApplication DataWPFFontCache_v0400-System.dat 2013-12-02 17:58 - 2013-12-02 17:58 - 00000000 ____D C:Documents and SettingsAdministratorMy DocumentsElectronic Arts 2013-12-02 10:51 - 2011-05-10 14:28 - 00000000 ____D C:Documents and SettingsAdministratorMy DocumentsMy Games 2013-11-30 09:34 - 2013-03-09 11:29 - 00000000 ____D C:Documents and SettingsAdministratorMy DocumentsSimCity 4 2013-11-29 18:26 - 2013-03-09 10:23 - 00000533 _____ C:WINDOWSeReg.dat 2013-11-29 11:06 - 2013-09-29 15:13 - 00000000 ____D C:Documents and SettingsAdministratorApplication DataTropico 4 2013-11-27 07:04 - 2013-11-27 07:03 - 00000438 _____ C:WINDOWSTasksReclaimerUpdateFiles_Administrator.job Files to move or delete: ==================== C:Documents and SettingsBrunojagex_runescape_preferences.dat C:Documents and SettingsBrunojagex_runescape_preferences2.dat Some content of TEMP: ==================== C:Documents and SettingsAdministratorLocal SettingsTempAutoRun.exe C:Documents and SettingsAdministratorLocal SettingsTempAutoRunGUI.dll C:Documents and SettingsAdministratorLocal SettingsTempCmdLineExt03.dll C:Documents and SettingsAdministratorLocal SettingsTempdrm_dialogs.dll C:Documents and SettingsAdministratorLocal SettingsTempeauninstall.exe C:Documents and SettingsAdministratorLocal SettingsTempNEventMessages.dll C:Documents and SettingsAdministratorLocal SettingsTempQuarantine.exe C:Documents and SettingsAdministratorLocal SettingsTempSIntf16.dll C:Documents and SettingsAdministratorLocal SettingsTempSIntf32.dll C:Documents and SettingsAdministratorLocal SettingsTempSIntfNT.dll C:Documents and SettingsAdministratorLocal SettingsTempThe Sims 2_uninst.exe C:Documents and SettingsAdministratorLocal SettingsTempUninstall.exe C:Documents and SettingsAdministratorLocal SettingsTempVP6Install.exe C:Documents and SettingsAdministratorLocal SettingsTemp_is402.exe C:Documents and SettingsAdministratorLocal SettingsTemp_is427.exe C:Documents and SettingsAdministratorLocal SettingsTemp_isBF7.exe C:Documents and SettingsBrunoLocal SettingsTempdrm_dyndata_7370014.dll C:Documents and SettingsBrunoLocal SettingsTempiMesh_setup.exe C:Documents and SettingsBrunoLocal SettingsTempjre-6u24-windows-i586-iftw-rv.exe C:Documents and SettingsBrunoLocal SettingsTempNEventMessages.dll C:Documents and SettingsBrunoLocal SettingsTempswt-win32-3349.dll C:Documents and SettingsPetraaLocal SettingsTemp2780.exe C:Documents and SettingsPetraaLocal SettingsTemp332732.exe C:Documents and SettingsPetraaLocal SettingsTemp7za.exe C:Documents and SettingsPetraaLocal SettingsTempavguidx.dll C:Documents and SettingsPetraaLocal SettingsTempCommonInstaller.exe C:Documents and SettingsPetraaLocal SettingsTempcoupish-babylon.exe C:Documents and SettingsPetraaLocal SettingsTempeauninstall.exe C:Documents and SettingsPetraaLocal SettingsTempiGearedHelper.dll C:Documents and SettingsPetraaLocal SettingsTempload1.exe C:Documents and SettingsPetraaLocal SettingsTemplowproc.exe C:Documents and SettingsPetraaLocal SettingsTempMachineIdCreator.exe C:Documents and SettingsPetraaLocal SettingsTempNero-8.1.1.3 lite.exe C:Documents and SettingsPetraaLocal SettingsTempNEventMessages.dll C:Documents and SettingsPetraaLocal SettingsTempstubhelper.dll C:Documents and SettingsPetraaLocal SettingsTempswt-win32-3349.dll C:Documents and SettingsPetraaLocal SettingsTempThe Sims 2_uninst.exe C:Documents and SettingsPetraaLocal SettingsTempToolbarInstaller.exe C:Documents and SettingsPetraaLocal SettingsTempToolbar_Phpnuke.exe C:Documents and SettingsPetraaLocal SettingsTempTsu-0950.dll ==================== Bamital & volsnap Check ================= C:Windowsexplorer.exe => MD5 is legit C:WindowsSystem32winlogon.exe => MD5 is legit C:WindowsSystem32svchost.exe => MD5 is legit C:WindowsSystem32services.exe => MD5 is legit C:WindowsSystem32User32.dll => MD5 is legit C:WindowsSystem32userinit.exe => MD5 is legit C:WindowsSystem32Driversvolsnap.sys =>
  4. The bad image things started showing up after I restarted my pc. Basically, I started my pc up, logged in for a minute, restarted and the things started appearing. Here's the log. CKScanner 2.4 - Additional Security Risks - These are not necessarily bad c:documents and settingsadministratordesktopgamesmindcrackversion c:documents and settingsadministratordesktopgamesmindcrackinstmodsliteloader.zip c:documents and settingsadministratordesktopgamesmindcrackinstmodsminecraftforge.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftforgemodloader-client-0.log c:documents and settingsadministratordesktopgamesmindcrackminecraftforgemodloader-client-0.log.lck c:documents and settingsadministratordesktopgamesmindcrackminecraftforgemodloader-client-1.log c:documents and settingsadministratordesktopgamesmindcrackminecraftforgemodloader-client-2.log c:documents and settingsadministratordesktopgamesmindcrackminecraftgregtech.log c:documents and settingsadministratordesktopgamesmindcrackminecraftliteloader.properties c:documents and settingsadministratordesktopgamesmindcrackminecraftliteloader.txt c:documents and settingsadministratordesktopgamesmindcrackminecraftoptions.txt c:documents and settingsadministratordesktopgamesmindcrackminecraftbinjinput.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftbinlwjgl.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftbinlwjgl_util.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftbinminecraft.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftbinnativesjinput-dx8.dll c:documents and settingsadministratordesktopgamesmindcrackminecraftbinnativesjinput-dx8_64.dll c:documents and settingsadministratordesktopgamesmindcrackminecraftbinnativesjinput-raw.dll c:documents and settingsadministratordesktopgamesmindcrackminecraftbinnativesjinput-raw_64.dll c:documents and settingsadministratordesktopgamesmindcrackminecraftbinnativeslwjgl.dll c:documents and settingsadministratordesktopgamesmindcrackminecraftbinnativeslwjgl64.dll c:documents and settingsadministratordesktopgamesmindcrackminecraftbinnativesopenal32.dll c:documents and settingsadministratordesktopgamesmindcrackminecraftbinnativesopenal64.dll c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigadvancedmachines.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigadvancedsolarpanel.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigappliedenergistics.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigbibliocraft.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigccturtle.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigchargepads.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigchickenchunks.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigcodechickencore.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigcompactsolars.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigcomputercraft.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigdamageindicatorsmod.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigdrceph.petrogen.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigee3.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigenderstorage.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigfactorization.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigfactorization.cfgtech c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigforge.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigforgechunkloading.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfiggravigun.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfiggravisuite.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigic2.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigic2.cfgtech c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigic2.lang c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigic2nuclearcontrol.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigic2nuclearcontrol.lang c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigimmibis.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfiginvtweaks.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfiginvtweaksrules.txt c:documents and settingsadministratordesktopgamesmindcrackminecraftconfiginvtweakstree.txt c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigironchest.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigmagicyarn.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigmfreloaded.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigminechem.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigmiscperipherals.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigmmmpowersuits.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigmodstats.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigmodularforcefieldsystem.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigmystcraft_config.txt c:documents and settingsadministratordesktopgamesmindcrackminecraftconfignei.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigneiserver.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigneisubset.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfignetherores.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigobsidiplates.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigplc.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigportalgun.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigpowerconverters.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigpowercrystalscore.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigropesplus.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigsecretroomsmod.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigsoulshards.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigstevescarts.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigthaumcraft.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigthaumicbees.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigtraincraft.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigtwilightforest.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigwirelessredstone.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigxreliquary.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigxycraft.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigbuildcraftmain.conf c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigcofhlexicon.whitelist c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigcofhomnitools.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigcofhthermalexpansion.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigextrabiomesextrabiomes.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigextrabiomesextrabiomes.cfgult c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigforestryapiculture.conf c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigforestrybackpacks.conf c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigforestrybase.conf c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigforestrycommon.conf c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigforestrypipes.conf c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigforestryextrabeesmachines.conf c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigforestryextrabeesmain.conf c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigforestrygamemodeseasy.conf c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigforestrygamemodeshard.conf c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigforestrygamemodesnormal.conf c:documents and settingsadministratordesktopgamesmindcrackminecraftconfiggregtechblockitemids.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfiggregtechgregtech.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfiggregtechgregtech.lang c:documents and settingsadministratordesktopgamesmindcrackminecraftconfiggregtechrecipes.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfiggregtechrecipesadvancedconfig.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigrailcraftmodules.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigrailcraftrailcraft.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigredpowerredpower.cfg c:documents and settingsadministratordesktopgamesmindcrackminecraftconfigredpowerredpower.lang c:documents and settingsadministratordesktopgamesmindcrackminecraftcoremodscodechickencore.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftcoremodsmiscperipherals.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftcoremodsnotenoughitems.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftlibargo-2.25.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftlibasm-all-4.0.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftlibbcprov-jdk15on-147.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftlibguava-12.0.1.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftmiscperipheralsromprogramsdiamondpipe c:documents and settingsadministratordesktopgamesmindcrackminecraftmiscperipheralsromprogramsenergyarray c:documents and settingsadministratordesktopgamesmindcrackminecraftmiscperipheralsromprogramsgates c:documents and settingsadministratordesktopgamesmindcrackminecraftmiscperipheralsromprogramsgradient c:documents and settingsadministratordesktopgamesmindcrackminecraftmiscperipheralsromprogramsmusic c:documents and settingsadministratordesktopgamesmindcrackminecraftmiscperipheralsromprogramsreactorcontrol c:documents and settingsadministratordesktopgamesmindcrackminecraftmiscperipheralsromprogramsreadbee c:documents and settingsadministratordesktopgamesmindcrackminecraftmiscperipheralsromprogramsreadcart c:documents and settingsadministratordesktopgamesmindcrackminecraftmiscperipheralsromprogramsreadtree c:documents and settingsadministratordesktopgamesmindcrackminecraftmiscperipheralsromprogramswrpulse c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsadvancedmachines.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsadvancedsolarpanel.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsbuildcraft.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftmodschickenchunks.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftmodscofhcore.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodscomputercraft.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsenderstorage.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsextrabees.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsextrabiomes.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsfactorization.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsforestry.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsgravisuite.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsgregtech.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsic2.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsic2nuclearcontrol.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsintegratedsoundpacks.litemod c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsinvtweaks.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsironchest.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsmodularforcefieldsystem.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsneiplugins.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsneipluginsredpower.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsobsidiplates.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsomnitools.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodspetrogen.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsportalgun.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsrailcraft.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsredpowercompat.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsredpowercore.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsredpowerdigital.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsredpowermechanical.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodssoulshards.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsstevescarts.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsthaumcraft.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsthaumicbees.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsthermalexpansion.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodstraincraft.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftmodstwilightforest.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsvoxelcommon.litemod c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsvoxelmap.litemod c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsvoxelmenu.litemod c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsvoxelpacket.litemod c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsvoxelplayer.litemod c:documents and settingsadministratordesktopgamesmindcrackminecraftmodswirelessredstoneaddons.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftmodswirelessredstonecore.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftmodswirelessredstoneredpower.jar c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsxycraft.zip c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsvoxelmodpackvoxelmodpack.properties c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsvoxelmodpackvoxelserver.properties c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsvoxelmodsvoxelmap.properties c:documents and settingsadministratordesktopgamesmindcrackminecraftmodsvoxelmodsvoxelplayer.properties c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesmusiccalm1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesmusiccalm2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesmusiccalm3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewmusichal1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewmusichal2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewmusichal3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewmusichal4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewmusicnuance1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewmusicnuance2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewmusicpiano1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewmusicpiano2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewmusicpiano3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundambientcavecave1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundambientcavecave10.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundambientcavecave11.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundambientcavecave12.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundambientcavecave13.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundambientcavecave2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundambientcavecave3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundambientcavecave4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundambientcavecave5.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundambientcavecave6.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundambientcavecave7.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundambientcavecave8.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundambientcavecave9.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundambientweatherrain1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundambientweatherrain2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundambientweatherrain3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundambientweatherrain4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundambientweatherthunder1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundambientweatherthunder2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundambientweatherthunder3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsounddamagefallbig1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsounddamagefallbig2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsounddamagefallsmall.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsounddamagehurtflesh1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsounddamagehurtflesh2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsounddamagehurtflesh3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundfirefire.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundfireignite.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundic2nuclearcontrolalarm-default.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundic2nuclearcontrolalarm-sci-fi.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundliquidlava.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundliquidlavapop.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundliquidsplash.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundliquidwater.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobchicken1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobchicken2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobchicken3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobchickenhurt1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobchickenhurt2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobchickenplop.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcow1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcow2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcow3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcow4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcowhurt1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcowhurt2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcowhurt3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcreeper1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcreeper2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcreeper3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcreeper4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcreeperdeath.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobpig1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobpig2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobpig3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobpigdeath.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobsheep1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobsheep2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobsheep3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobskeleton1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobskeleton2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobskeleton3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobskeletondeath.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobskeletonhurt1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobskeletonhurt2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobskeletonhurt3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobskeletonhurt4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobslime1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobslime2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobslime3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobslime4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobslime5.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobslimeattack1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobslimeattack2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobspider1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobspider2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobspider3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobspider4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobspiderdeath.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombie1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombie2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombie3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiedeath.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiehurt1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiehurt2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobblazebreathe1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobblazebreathe2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobblazebreathe3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobblazebreathe4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobblazedeath.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobblazehit1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobblazehit2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobblazehit3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobblazehit4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcathiss1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcathiss2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcathiss3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcathitt1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcathitt2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcathitt3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcatmeow1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcatmeow2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcatmeow3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcatmeow4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcatpurr1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcatpurr2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcatpurr3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcatpurreow1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobcatpurreow2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobendermendeath.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobendermenhit1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobendermenhit2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobendermenhit3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobendermenhit4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobendermenidle1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobendermenidle2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobendermenidle3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobendermenidle4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobendermenidle5.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobendermenportal.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobendermenportal2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobendermenscream1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobendermenscream2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobendermenscream3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobendermenscream4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobendermenstare.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobghastaffectionate scream.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobghastcharge.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobghastdeath.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobghastfireball4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobghastmoan1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobghastmoan2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobghastmoan3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobghastmoan4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobghastmoan5.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobghastmoan6.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobghastmoan7.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobghastscream1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobghastscream2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobghastscream3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobghastscream4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobghastscream5.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobirongolemdeath.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobirongolemhit1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobirongolemhit2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobirongolemhit3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobirongolemhit4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobirongolemthrow.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobirongolemwalk1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobirongolemwalk2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobirongolemwalk3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobirongolemwalk4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobmagmacubebig1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobmagmacubebig2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobmagmacubebig3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobmagmacubebig4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobmagmacubejump1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobmagmacubejump2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobmagmacubejump3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobmagmacubejump4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobmagmacubesmall1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobmagmacubesmall2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobmagmacubesmall3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobmagmacubesmall4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobmagmacubesmall5.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobsilverfishhit1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobsilverfishhit2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobsilverfishhit3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobsilverfishkill.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobsilverfishsay1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobsilverfishsay2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobsilverfishsay3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobsilverfishsay4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobsilverfishstep1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobsilverfishstep2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobsilverfishstep3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobsilverfishstep4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobwolfbark1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobwolfbark2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobwolfbark3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobwolfdeath.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobwolfgrowl1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobwolfgrowl2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobwolfgrowl3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobwolfhowl1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobwolfhowl2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobwolfhurt1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobwolfhurt2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobwolfhurt3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobwolfpanting.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobwolfshake.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobwolfwhine.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiemetal1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiemetal2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiemetal3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiewood1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiewood2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiewood3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiewood4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiewoodbreak.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiepigzpig1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiepigzpig2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiepigzpig3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiepigzpig4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiepigzpigangry1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiepigzpigangry2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiepigzpigangry3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiepigzpigangry4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiepigzpigdeath.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiepigzpighurt1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundmobzombiepigzpighurt2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundnotebass.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundnotebassattack.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundnotebd.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundnoteharp.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundnotehat.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundnotepling.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundnotesnare.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundportalportal.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundportaltravel.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundportaltrigger.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandombow.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandombowhit1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandombowhit2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandombowhit3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandombowhit4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandombreak.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandombreath.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomburp.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomchestclosed.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomchestopen.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomclick.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomdoor_close.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomdoor_open.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomdrink.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomdrr.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomeat1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomeat2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomeat3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomexplode1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomexplode2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomexplode3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomexplode4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomfizz.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomfuse.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomglass1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomglass2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomglass3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomhurt.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomlevelup.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomold_explode.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomorb.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandompop.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomsplash.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundrandomwood click.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepcloth1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepcloth2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepcloth3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepcloth4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepgrass1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepgrass2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepgrass3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepgrass4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepgravel1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepgravel2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepgravel3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepgravel4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepsand1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepsand2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepsand3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepsand4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepsnow1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepsnow2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepsnow3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepsnow4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepstone1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepstone2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepstone3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepstone4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepwood1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepwood2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepwood3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundstepwood4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundtilepistonin.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesnewsoundtilepistonout.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunafp_launch.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunapg_firing.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunapg_turn.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgundinosaur_fizzle1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgundinosaur_fizzle2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgundinosaur_fizzle3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgundropper_iris_close_01.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgundropper_iris_open_01.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgundropper_iris_open_02.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunenergy_bounce1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunenergy_bounce2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunenergy_sing_explosion1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunenergy_sing_flyby1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunenergy_sing_flyby2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunfizzler_shutdown_01.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunfizzler_start_01.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunlaser_activation_01.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunlaser_node_power_off.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunlaser_node_power_on.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunobject_use_failure_01.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunobject_use_start_01.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunobject_use_stop_01.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunphys_bouncy_cube_lg_01.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunphys_bouncy_cube_lg_02.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunphys_bouncy_cube_lg_03.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunphys_bouncy_cube_lg_04.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunpl_burnpain1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunpl_burnpain2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunpl_burnpain3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunportal_enter_01.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunportal_enter_02.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunportal_enter_03.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunportal_exit_01.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunportal_exit_02.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunportal_fizzle_01.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunportal_fizzle_02.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunportal_invalid_01.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunportal_invalid_02.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunportal_invalid_03.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunportal_invalid_04.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunportal_open_blue_01.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunportal_open_red_01.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunportal_open_red_02.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunsuperphys_small_zap1.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunsuperphys_small_zap2.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunsuperphys_small_zap3.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunsuperphys_small_zap4.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunwpn_portalgun_active_01.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunwpn_portal_gun_fire_b01.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunwpn_portal_gun_fire_b02.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunwpn_portal_gun_fire_b03.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunwpn_portal_gun_fire_r01.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunwpn_portal_gun_fire_r02.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunwpn_portal_gun_fire_r03.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunwpn_portal_reset_01.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunheploopenergy_sing_10_loop.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunheploopenergy_sing_11_loop.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunheploopenergy_sing_12_loop.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunheploopenergy_sing_13_loop.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunheploopenergy_sing_14_loop.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunheploopenergy_sing_15_loop.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunheploopenergy_sing_16_loop.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunheploopenergy_sing_17_loop.ogg c:documents and settingsadministratordesktopgamesmindcrackminecraftresourcesportalgunsoundportalgunheploopenergy_sing_1_loop.ogg c:documents and settingsadministratordesktopgamesmindcrackm
  5. Did as instructed and here's the log but TFC has the same problem as before and I'm getting the 'bad image' error. Malwarebytes found two new things which were downloaded today and I removed them. Malwarebytes Anti-Malware (PRO) 1.75.0.1300 www.malwarebytes.org Database version: v2013.12.23.02 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Administrator :: PETRA [administrator] Protection: Enabled 23.12.2013 9:19:03 MBAM-log-2013-12-23 (14-27-41).txt Scan type: Full scan (A:|C:|D:|E:|F:|G:|Q:|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 554610 Time elapsed: 4 hour(s), 59 minute(s), 59 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 2 D:GDayZ Standalone AlphaDayZ Standalone Alphasteam_api.dll (Trojan.VirTool) -> No action taken. D:GDayZ Standalone AlphaDayZ Standalone AlphaCracksteam_api.dll (Trojan.VirTool) -> No action taken. (end)
  6. I removed all the threats. Here's the log. Malwarebytes Anti-Malware (PRO) 1.75.0.1300 www.malwarebytes.org Database version: v2013.12.22.02 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Administrator :: PETRA [administrator] Protection: Enabled 22.12.2013 9:19:16 MBAM-log-2013-12-22 (14-31-59).txt Scan type: Full scan (A:|C:|D:|E:|F:|G:|Q:|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 559510 Time elapsed: 4 hour(s), 19 minute(s), 12 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 17 C:AdwCleanerQuarantineCDocuments and SettingsAll UsersApplication DataSweetIMMessengerupdatesweetimsetup.exe.vir (PUP.Optional.SweetIM) -> No action taken. C:AdwCleanerQuarantineCDocuments and SettingsBrunoLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsogccgbmabaphcakpiclgcnmcnimhokcj1.4.0.4_0mgHelperGC.dll.vir (PUP.Optional.SweetIM) -> No action taken. C:AdwCleanerQuarantineCDocuments and SettingsPetraaLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsogccgbmabaphcakpiclgcnmcnimhokcj1.4.0.4_1mgHelperGC.dll.vir (PUP.Optional.SweetIM) -> No action taken. C:AdwCleanerQuarantineCProgram FilesConduitCommunity AlertsAlert.dll.vir (PUP.Optional.Conduit) -> No action taken. C:AdwCleanerQuarantineCProgram FilesuTorrentBaruTorrentBarToolbarHelper1.exe.vir (PUP.Optional.Conduit.A) -> No action taken. C:AdwCleanerQuarantineCProgram FilesYontooOptChrome.exe.vir (PUP.Optional.OptChrome.A) -> No action taken. C:AdwCleanerQuarantineCProgram Files~Web Assistantis-M2UE3.tmp.vir (PUP.Optional.SweetPacks.A) -> No action taken. C:AdwCleanerQuarantineCWINDOWSsystem32ARFCwrtc.exe.vir (PUP.Optional.InstallBrain.A) -> No action taken. C:NetmarbleGlobalMarbleStationxfire_installer.exe (PUP.Optional.OpenCandy) -> No action taken. C:Program FilesWinRARCrack.exe (Trojan.Dropper) -> No action taken. C:System Volume Information_restore{291B1760-F527-4C6F-9135-455B79DED990}RP63A0110581.exe (PUP.Optional.SweetIM) -> No action taken. C:System Volume Information_restore{291B1760-F527-4C6F-9135-455B79DED990}RP63A0110665.exe (PUP.Optional.OptChrome.A) -> No action taken. C:System Volume Information_restore{291B1760-F527-4C6F-9135-455B79DED990}RP63A0110634.dll (PUP.Optional.Conduit) -> No action taken. C:System Volume Information_restore{291B1760-F527-4C6F-9135-455B79DED990}RP63A0110681.exe (PUP.Optional.Conduit.A) -> No action taken. C:System Volume Information_restore{291B1760-F527-4C6F-9135-455B79DED990}RP63A0110845.exe (PUP.Optional.InstallBrain.A) -> No action taken. C:System Volume Information_restore{291B1760-F527-4C6F-9135-455B79DED990}RP63A0110920.dll (PUP.Optional.SweetIM) -> No action taken. C:System Volume Information_restore{291B1760-F527-4C6F-9135-455B79DED990}RP63A0110921.dll (PUP.Optional.SweetIM) -> No action taken. (end)
  7. I removed AVG. Got TFC but had a problem with it... Basically, I did as you instructed but when I pressed start it got to "Stopping running processes." and that was it. Actually left it running for over 5 hours and it was still frozen on that. Eventually had to restart my pc and tried again by leaving it frozen for half an hour. Is is supposed to be like that or am I experiencing a problem?
  8. I'm gonna assume you're not just praising the awesomeness of cows... Is it that bad? # AdwCleaner v3.015 - Report created 19/12/2013 at 20:37:31 # Updated 10/12/2013 by Xplode # Operating System : Microsoft Windows XP Service Pack 3 (32 bits) # Username : Administrator - PETRA # Running from : C:Documents and SettingsAdministratorMy DocumentsDownloadsAdwCleaner (1).exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:Documents and SettingsAll UsersApplication DataAVG Secure Search Folder Deleted : C:Documents and SettingsAll UsersApplication DataBabylon Folder Deleted : C:Documents and SettingsAll UsersApplication Dataclsoft ltd Folder Deleted : C:Documents and SettingsAll UsersApplication Datacontinuetosave Folder Deleted : C:Documents and SettingsAll UsersApplication DataGinyasBrowserCompanion Folder Deleted : C:Documents and SettingsAll UsersApplication DataNCH Software Folder Deleted : C:Documents and SettingsAll UsersApplication DataPremium Folder Deleted : C:Documents and SettingsAll UsersApplication DataRightClick Folder Deleted : C:Documents and SettingsAll UsersApplication DataSweetIM Folder Deleted : C:Documents and SettingsAll UsersApplication DataTarma Installer Folder Deleted : C:Documents and SettingsAll UsersApplication DataTrymedia Folder Deleted : C:Documents and SettingsAll UsersApplication DataADDICT-THING Folder Deleted : C:Program Files~Web Assistant Folder Deleted : C:Program FilesAVG Secure Search Folder Deleted : C:Program FilesBrowserCompanion Folder Deleted : C:Program FilesConduit Folder Deleted : C:Program Filesdriver-soft Folder Deleted : C:Program FilesNCH Software Folder Deleted : C:Program FilesPerion Folder Deleted : C:Program FilesYontoo Folder Deleted : C:Program FilesuTorrentBar Folder Deleted : C:Program FilesCommon FilesAVG Secure Search Folder Deleted : C:WINDOWSsystem32ARFC Folder Deleted : C:WINDOWSsystem32jmdp Folder Deleted : C:WINDOWSsystem32WNLT Folder Deleted : C:Documents and SettingsBrunoLocal SettingsApplication DataAskToolbar Folder Deleted : C:Documents and SettingsBrunoLocal SettingsApplication DataAVG Secure Search Folder Deleted : C:Documents and SettingsBrunoLocal SettingsApplication DataConduit Folder Deleted : C:Documents and SettingsBrunoLocal SettingsApplication DataPackageAware Folder Deleted : C:Documents and SettingsBrunoLocal SettingsApplication DatauTorrentBar Folder Deleted : C:Documents and SettingsBrunoApplication DataAVG Secure Search Folder Deleted : C:Documents and SettingsBrunoApplication Datafacemoods.com Folder Deleted : C:Documents and SettingsPetraaLocal SettingsApplication DataAVG Secure Search Folder Deleted : C:Documents and SettingsPetraaLocal SettingsApplication DataBabylon Folder Deleted : C:Documents and SettingsPetraaLocal SettingsApplication DataConduit Folder Deleted : C:Documents and SettingsPetraaLocal SettingsApplication DatauTorrentBar Folder Deleted : C:Documents and SettingsPetraaApplication DataAVG Secure Search Folder Deleted : C:Documents and SettingsPetraaApplication DataBabylonToolbar Folder Deleted : C:Documents and SettingsPetraaApplication Datafacemoods.com Folder Deleted : C:Documents and SettingsAdministratorLocal SettingsApplication DataAskToolbar Folder Deleted : C:Documents and SettingsAdministratorLocal SettingsApplication DataAVG Secure Search Folder Deleted : C:Documents and SettingsAdministratorLocal SettingsApplication DataBabylon Folder Deleted : C:Documents and SettingsAdministratorLocal SettingsApplication DataConduit Folder Deleted : C:Documents and SettingsAdministratorLocal SettingsApplication DataPackageAware Folder Deleted : C:Documents and SettingsAdministratorLocal SettingsApplication DatauTorrentBar Folder Deleted : C:Documents and SettingsAdministratorApplication DataAVG Secure Search Folder Deleted : C:Documents and SettingsAdministratorApplication DataBabylonToolbar Folder Deleted : C:Documents and SettingsAdministratorApplication DataExpressFiles Folder Deleted : C:Documents and SettingsAdministratorApplication DataNCH Software Folder Deleted : C:Documents and SettingsAdministratorApplication DataSimilarSites Folder Deleted : C:Documents and SettingsAdministratorApplication Datayourfiledownloader Folder Deleted : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultSweetIMToolbarData Folder Deleted : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultExtensions{ACAA314B-EEBA-48E4-AD47-84E31C44796C} Folder Deleted : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultExtensions{EEE6C361-6118-11DC-9C72-001320C79847} Folder Deleted : C:Documents and SettingsBrunoApplication [email protected]bbers.com Folder Deleted : C:Documents and SettingsPetraaApplication [email protected]bbers.com Folder Deleted : C:Documents and SettingsAdministratorApplication [email protected]bbers.com Folder Deleted : C:Documents and SettingsPetraaApplication [email protected]lon.com Folder Deleted : C:Documents and SettingsPetraaApplication [email protected]edibar.com Folder Deleted : C:Documents and SettingsPetraaApplication Da[email protected]5023db04d6776.info Folder Deleted : C:Documents and SettingsBrunoApplication [email protected]om Folder Deleted : C:Documents and SettingsBrunoApplication DataMozillaFirefoxProfilesc0bbqulh.defaultExtensions{20a82645-c095-46ed-80e3-08825760534b} Folder Deleted : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultExtensions{20a82645-c095-46ed-80e3-08825760534b} Folder Deleted : C:Documents and SettingsBrunoApplication DataMozillaFirefoxProfilesc0bbqulh.defaultExtensions{ba23dafc-5a36-4bdd-9d69-ed60da9d6c78} Folder Deleted : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultExtensions{ba23dafc-5a36-4bdd-9d69-ed60da9d6c78} Folder Deleted : C:Documents and SettingsAdministratorApplication Da[email protected]50eecf0c7a1eb.com Folder Deleted : C:Documents and SettingsAdministratorApplication Da[email protected]50fbc3c412e48.com Folder Deleted : C:Documents and SettingsAdministratorApplication Da[email protected]510f82f0498ed.com Folder Deleted : C:Documents and SettingsAdministratorApplication DataMozill[email protected]weliketheweb.com [!] Folder Deleted : C:Documents and SettingsBrunoLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsjifflliplgeajjdhmkcfnngfpgbjonjg [!] Folder Deleted : C:Documents and SettingsPetraaLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsjifflliplgeajjdhmkcfnngfpgbjonjg [!] Folder Deleted : C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsjifflliplgeajjdhmkcfnngfpgbjonjg [!] Folder Deleted : C:Documents and SettingsBrunoLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsjmfkcklnlgedgbglfkkgedjfmejoahla [!] Folder Deleted : C:Documents and SettingsPetraaLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsjmfkcklnlgedgbglfkkgedjfmejoahla [!] Folder Deleted : C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsjmfkcklnlgedgbglfkkgedjfmejoahla [!] Folder Deleted : C:Documents and SettingsBrunoLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof [!] Folder Deleted : C:Documents and SettingsPetraaLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof [!] Folder Deleted : C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof [!] Folder Deleted : C:Documents and SettingsBrunoLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsniapdbllcanepiiimjjndipklodoedlc [!] Folder Deleted : C:Documents and SettingsPetraaLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsniapdbllcanepiiimjjndipklodoedlc [!] Folder Deleted : C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsniapdbllcanepiiimjjndipklodoedlc [!] Folder Deleted : C:Documents and SettingsBrunoLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsogccgbmabaphcakpiclgcnmcnimhokcj [!] Folder Deleted : C:Documents and SettingsPetraaLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsogccgbmabaphcakpiclgcnmcnimhokcj [!] Folder Deleted : C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsogccgbmabaphcakpiclgcnmcnimhokcj [!] Folder Deleted : C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsolakgnkoldmagdblaalodobkmeokmgjj [!] Folder Deleted : C:Documents and SettingsBrunoLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionseeagmkkfclhgnfoailfapcecdjooldak [!] Folder Deleted : C:Documents and SettingsPetraaLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionseeagmkkfclhgnfoailfapcecdjooldak [!] Folder Deleted : C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionseeagmkkfclhgnfoailfapcecdjooldak File Deleted : C:END File Deleted : C:WINDOWSsystem32ImhxxpComm.dll File Deleted : C:Program FilesMozilla Firefoxsearchpluginsavg-secure-search.xml File Deleted : C:Program FilesMozilla Firefoxbrowsersearchpluginsavg-secure-search.xml File Deleted : C:Program FilesMozilla FirefoxsearchpluginsBabylon.xml File Deleted : C:Documents and SettingsAdministratorApplication DataMozillaFirefoxProfiles5gozow0a.defaultsearchpluginsConduit.xml File Deleted : C:Program FilesMozilla FirefoxsearchpluginsfcmdSrch.xml File Deleted : C:Documents and SettingsBrunoApplication DataMozillaFirefoxProfilesc0bbqulh.defaultsearchpluginsMyStart Search.xml File Deleted : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultsearchpluginsMyStart Search.xml File Deleted : C:Documents and SettingsAdministratorApplication DataMozillaFirefoxProfiles5gozow0a.defaultsearchpluginsMyStart Search.xml File Deleted : C:Documents and SettingsAdministratorApplication DataMozillaFirefoxProfiles5gozow0a.defaultsearchpluginsSweetIM Search.xml File Deleted : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultsearchpluginsSweetIm.xml File Deleted : C:Documents and SettingsAdministratorApplication DataMozillaFirefoxProfiles5gozow0a.defaultsearchpluginsSweetIm.xml File Deleted : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultsearchpluginsSweetpacks Search.xml File Deleted : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultuser.js File Deleted : C:Documents and SettingsAdministratorApplication DataMozillaFirefoxProfiles5gozow0a.defaultuser.js File Deleted : C:WINDOWSTasksExpress FilesUpdate.job File Deleted : C:WINDOWSTasksGinyasBrowserCompanion Chrome Watcher.job File Deleted : C:WINDOWSTasksGinyasBrowserCompanion FireFox Watcher.job File Deleted : C:WINDOWSTasksGinyasBrowserCompanion Runner.job File Deleted : C:WINDOWSTasksGinyasBrowserCompanion Stats Report.job File Deleted : C:WINDOWSTasksGinyasBrowserCompanion Update Checker.job ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Value Deleted : HKLMSOFTWAREMozillaFirefoxExtensions [[email protected]] Value Deleted : HKLMSOFTWAREMozillaFirefoxExtensions [[email protected]] Value Deleted : HKLMSOFTWAREMozillaFirefoxExtensions [{20a82645-c095-46ed-80e3-08825760534b}] Key Deleted : HKLMSOFTWAREGoogleChromeExtensionsclbfjfbnelcflpgpklppgplejolacbej Key Deleted : HKLMSOFTWAREGoogleChromeExtensionsdhkplhfnhceodhffomolpfigojocbpcb Key Deleted : HKLMSOFTWAREGoogleChromeExtensionsdlnembnfbcpjnepmfjmngjenhhajpdfd Key Deleted : HKLMSOFTWAREGoogleChromeExtensionsjbpkiefagocgkmemidfngdkamloieekf Key Deleted : HKLMSOFTWAREGoogleChromeExtensionsjifflliplgeajjdhmkcfnngfpgbjonjg Key Deleted : HKLMSOFTWAREGoogleChromeExtensionsjmfkcklnlgedgbglfkkgedjfmejoahla Key Deleted : HKLMSOFTWAREGoogleChromeExtensionsndibdjnfmopecpmkdieinmbadjfpblof Key Deleted : HKLMSOFTWAREGoogleChromeExtensionsniapdbllcanepiiimjjndipklodoedlc Key Deleted : HKLMSOFTWAREGoogleChromeExtensionsogccgbmabaphcakpiclgcnmcnimhokcj Key Deleted : HKLMSOFTWAREGoogleChromeExtensionseeagmkkfclhgnfoailfapcecdjooldak Key Deleted : HKCUToolbar Key Deleted : HKLMSOFTWAREClassesAppIDExtension.DLL Key Deleted : HKLMSOFTWAREClassesAppIDScriptHelper.EXE Key Deleted : HKLMSOFTWAREClassesAppIDtdataprotocol.DLL Key Deleted : HKLMSOFTWAREClassesAppIDupdatebho.DLL Key Deleted : HKLMSOFTWAREClassesAppIDViProtocol.DLL Key Deleted : HKLMSOFTWAREClassesAppIDwit4ie.DLL Key Deleted : HKLMSOFTWAREClassesAppIDYontooIEClient.DLL Key Deleted : HKLMSOFTWAREClassesAVG Secure Search.BrowserWndAPI Key Deleted : HKLMSOFTWAREClassesAVG Secure Search.BrowserWndAPI.1 Key Deleted : HKLMSOFTWAREClassesAVG Secure Search.PugiObj Key Deleted : HKLMSOFTWAREClassesAVG Secure Search.PugiObj.1 Key Deleted : HKLMSOFTWAREClassesb Key Deleted : HKLMSOFTWAREClassesBabylon.dskBnd Key Deleted : HKLMSOFTWAREClassesBabylon.dskBnd.1 Key Deleted : HKLMSOFTWAREClassesbbylnApp.appCore Key Deleted : HKLMSOFTWAREClassesbbylnApp.appCore.1 Key Deleted : HKLMSOFTWAREClassesbbylntlbr.bbylntlbrHlpr Key Deleted : HKLMSOFTWAREClassesbbylntlbr.bbylntlbrHlpr.1 Key Deleted : HKLMSOFTWAREClassesescort.escrtBtn.1 Key Deleted : HKLMSOFTWAREClassesExtension.ExtensionHelperObject Key Deleted : HKLMSOFTWAREClassesExtension.ExtensionHelperObject.1 Key Deleted : HKLMSOFTWAREClassesfacemoods.xtrnl Key Deleted : HKLMSOFTWAREClassesfacemoods.xtrnl.1 Key Deleted : HKLMSOFTWAREClassesfacemoodsApp.appCore Key Deleted : HKLMSOFTWAREClassesfacemoodsApp.appCore.1 Key Deleted : HKLMSOFTWAREClassesMediaPlayer.GraphicsUtils Key Deleted : HKLMSOFTWAREClassesMediaPlayer.GraphicsUtils.1 Key Deleted : HKLMSOFTWAREClassesMgMediaPlayer.GifAnimator Key Deleted : HKLMSOFTWAREClassesMgMediaPlayer.GifAnimator.1 Key Deleted : HKLMSOFTWAREClassesProd.cap Key Deleted : HKLMSOFTWAREClassesprotector_dll.protectorbho Key Deleted : HKLMSOFTWAREClassesprotector_dll.protectorbho.1 Key Deleted : HKLMSOFTWAREClassesprotocolshandlerviprotocol Key Deleted : HKLMSOFTWAREClassesScriptHelper.ScriptHelperApi Key Deleted : HKLMSOFTWAREClassesScriptHelper.ScriptHelperApi.1 Key Deleted : HKLMSOFTWAREClassessim-packages Key Deleted : HKLMSOFTWAREClassesSWEETIE.IEToolbar Key Deleted : HKLMSOFTWAREClassesSWEETIE.IEToolbar.1 Key Deleted : HKLMSOFTWAREClassestdataprotocol.CTData Key Deleted : HKLMSOFTWAREClassestdataprotocol.CTData.1 Key Deleted : HKLMSOFTWAREClassesViProtocol.ViProtocolOLE Key Deleted : HKLMSOFTWAREClassesViProtocol.ViProtocolOLE.1 Key Deleted : HKLMSOFTWAREClasseswit4ie.WitBHO Key Deleted : HKLMSOFTWAREClasseswit4ie.WitBHO.2 Key Deleted : HKLMSOFTWAREClassesYontooIEClient.Api Key Deleted : HKLMSOFTWAREClassesYontooIEClient.Api.1 Key Deleted : HKLMSOFTWAREClassesYontooIEClient.Layers Key Deleted : HKLMSOFTWAREClassesYontooIEClient.Layers.1 Value Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun [vProt] Key Deleted : [email protected]/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Key Deleted : HKLMSOFTWAREClassesToolbar.CT2786678 Key Deleted : HKLMSOFTWAREClassesAppID{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Key Deleted : HKLMSOFTWAREClassesAppID{20EDC024-43C5-423E-B7F5-FD93523E0D9F} Key Deleted : HKLMSOFTWAREClassesAppID{373ED12D-B306-43AC-9485-A7C5133DC34C} Key Deleted : HKLMSOFTWAREClassesAppID{5B1881D1-D9C7-46DF-B041-1E593282C7D0} Key Deleted : HKLMSOFTWAREClassesAppID{608D3067-77E8-463D-9084-908966806826} Key Deleted : HKLMSOFTWAREClassesAppID{B302A1BD-0157-49FA-90F1-4E94F22C7B4B} Key Deleted : HKLMSOFTWAREClassesAppID{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Key Deleted : HKLMSOFTWAREClassesAppID{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Deleted : HKLMSOFTWAREClassesAppID{C2178B36-2955-479B-818C-A2AE8E500454} Key Deleted : HKLMSOFTWAREClassesAppID{CFDAFE39-20CE-451D-BD45-A37452F39CF0} Key Deleted : HKLMSOFTWAREClassesAppID{EA28B360-05E0-4F93-8150-02891F1D8D3C} Key Deleted : HKLMSOFTWAREClassesAppID{ED6535E7-F778-48A5-A060-549D30024511} Key Deleted : HKLMSOFTWAREClassesCLSID{00000001-4FEF-40D3-B3FA-E0531B897F98} Key Deleted : HKLMSOFTWAREClassesCLSID{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Deleted : HKLMSOFTWAREClassesCLSID{35B8892D-C3FB-4D88-990D-31DB2EBD72BD} Key Deleted : HKLMSOFTWAREClassesCLSID{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Deleted : HKLMSOFTWAREClassesCLSID{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Key Deleted : HKLMSOFTWAREClassesCLSID{408CFAD9-8F13-4747-8EC7-770A339C7237} Key Deleted : HKLMSOFTWAREClassesCLSID{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLMSOFTWAREClassesCLSID{64697678-0000-0010-8000-00AA00389B71} Key Deleted : HKLMSOFTWAREClassesCLSID{7E84186E-B5DE-4226-8A66-6E49C6B511B4} Key Deleted : HKLMSOFTWAREClassesCLSID{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Deleted : HKLMSOFTWAREClassesCLSID{933B95E2-E7B7-4AD9-B952-7AC336682AE3} Key Deleted : HKLMSOFTWAREClassesCLSID{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLMSOFTWAREClassesCLSID{99066096-8989-4612-841F-621A01D54AD7} Key Deleted : HKLMSOFTWAREClassesCLSID{B658800C-F66E-4EF3-AB85-6C0C227862A9} Key Deleted : HKLMSOFTWAREClassesCLSID{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3} Key Deleted : HKLMSOFTWAREClassesCLSID{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Key Deleted : HKLMSOFTWAREClassesCLSID{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKLMSOFTWAREClassesCLSID{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Deleted : HKLMSOFTWAREClassesCLSID{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLMSOFTWAREClassesCLSID{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Deleted : HKLMSOFTWAREClassesCLSID{FE9271F2-6EFD-44B0-A826-84C829536E93} Key Deleted : HKLMSOFTWAREClassesCLSID{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} Key Deleted : HKLMSOFTWAREClassesCLSID{A97B89CD-B65C-49DD-AF46-2B772C627456} Key Deleted : HKLMSOFTWAREClassesInterface{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLMSOFTWAREClassesInterface{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Deleted : HKLMSOFTWAREClassesInterface{1AD27395-1659-4DFF-A319-2CFA243861A5} Key Deleted : HKLMSOFTWAREClassesInterface{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F} Key Deleted : HKLMSOFTWAREClassesInterface{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C} Key Deleted : HKLMSOFTWAREClassesInterface{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLMSOFTWAREClassesInterface{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLMSOFTWAREClassesInterface{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Deleted : HKLMSOFTWAREClassesInterface{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F} Key Deleted : HKLMSOFTWAREClassesInterface{FE0273D1-99DF-4AC0-87D5-1371C6271785} Key Deleted : HKLMSOFTWAREClassesTypeLib{07CAC314-E962-4F78-89AB-DD002F2490EE} Key Deleted : HKLMSOFTWAREClassesTypeLib{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Key Deleted : HKLMSOFTWAREClassesTypeLib{93E3D79C-0786-48FF-9329-93BC9F6DC2B3} Key Deleted : HKLMSOFTWAREClassesTypeLib{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Deleted : HKLMSOFTWAREClassesTypeLib{AC329328-7EC4-4C34-B672-0A2B90CB9B00} Key Deleted : HKLMSOFTWAREClassesTypeLib{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Key Deleted : HKLMSOFTWAREClassesTypeLib{D372567D-67C1-4B29-B3F0-159B52B3E967} Key Deleted : HKLMSOFTWAREClassesTypeLib{E2343056-CC08-46AC-B898-BFC7ACF4E755} Key Deleted : HKLMSOFTWAREClassesTypeLib{EEE6C35F-6118-11DC-9C72-001320C79847} Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{2EECD738-5844-4A99-B4B6-146BF802613B} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{336D0C35-8A85-403A-B9D2-65C292C39087} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{3C490BF5-4244-4310-B4A7-3361F288DAC5} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{41069220-F72A-40EA-A8F3-BCD5E1FBC8F0} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{98889811-442D-49DD-99D7-DC866BE87DBC} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{EEE6C35B-6118-11DC-9C72-001320C79847} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{EEE6C35D-6118-11DC-9C72-001320C79847} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{A97B89CD-B65C-49DD-AF46-2B772C627456} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{2EECD738-5844-4A99-B4B6-146BF802613B} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{336D0C35-8A85-403A-B9D2-65C292C39087} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{3C490BF5-4244-4310-B4A7-3361F288DAC5} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{41069220-F72A-40EA-A8F3-BCD5E1FBC8F0} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{98889811-442D-49DD-99D7-DC866BE87DBC} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{D4027C7F-154A-4066-A1AD-4243D8127440} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{EEE6C35B-6118-11DC-9C72-001320C79847} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Deleted : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExtPreApproved{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExtPreApproved{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExtPreApproved{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExtPreApproved{A97B89CD-B65C-49DD-AF46-2B772C627456} Key Deleted : HKLMSOFTWAREMicrosoftInternet ExplorerLow RightsElevationPolicy{EEE6C367-6118-11DC-9C72-001320C79847} Key Deleted : HKLMSOFTWAREMicrosoftInternet ExplorerLow RightsElevationPolicy{222A29CD-C493-4323-945A-24A02D1E7434} Key Deleted : HKLMSOFTWAREMicrosoftInternet ExplorerLow RightsElevationPolicy{4BFB942B-76EB-4F09-851A-5509132E86FA} Key Deleted : HKCUSoftwareMicrosoftInternet ExplorerSearchScopes{0D7562AE-8EF6-416D-A838-AB665251703A} Key Deleted : HKCUSoftwareMicrosoftInternet ExplorerSearchScopes{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Key Deleted : HKCUSoftwareMicrosoftInternet ExplorerSearchScopes{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E} Key Deleted : HKCUSoftwareMicrosoftInternet ExplorerSearchScopes{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} Key Deleted : HKCUSoftwareMicrosoftInternet ExplorerSearchScopes{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCUSoftwareMicrosoftInternet ExplorerSearchScopes{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Deleted : HKCUSoftwareMicrosoftInternet ExplorerSearchScopes{EEE6C360-6118-11DC-9C72-001320C79847} Key Deleted : HKLMSOFTWAREMicrosoftInternet ExplorerSearchScopes{EEE6C360-6118-11DC-9C72-001320C79847} Value Deleted : HKLMSOFTWAREMicrosoftInternet ExplorerToolbar [{3C490BF5-4244-4310-B4A7-3361F288DAC5}] Value Deleted : HKLMSOFTWAREMicrosoftInternet ExplorerToolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] Value Deleted : HKLMSOFTWAREMicrosoftInternet ExplorerToolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}] Value Deleted : HKLMSOFTWAREMicrosoftInternet ExplorerToolbar [{EEE6C35B-6118-11DC-9C72-001320C79847}] Value Deleted : HKLMSOFTWAREMicrosoftInternet ExplorerToolbar [{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}] Value Deleted : HKCUSoftwareMicrosoftInternet ExplorerToolbarWebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Value Deleted : HKCUSoftwareMicrosoftInternet ExplorerToolbarWebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}] Value Deleted : HKCUSoftwareMicrosoftInternet ExplorerToolbarWebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}] Value Deleted : HKCUSoftwareMicrosoftInternet ExplorerToolbarWebBrowser [{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}] Value Deleted : HKCUSoftwareMicrosoftInternet ExplorerURLSearchHooks [{EEE6C35D-6118-11DC-9C72-001320C79847}] Value Deleted : HKCUSoftwareMicrosoftInternet ExplorerURLSearchHooks [{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}] Value Deleted : HKLMSYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList [C:Program Filesfacesmoochtbdtuser.exe] Value Deleted : HKLMSYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList [C:WINDOWSsystem32ARFCwrtc.exe] Value Deleted : HKLMSYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList [C:Program FilesYourFileDownloaderDownloader.exe] Value Deleted : HKLMSYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList [C:Program FilesYourFileDownloaderYourFile.exe] Value Deleted : HKLMSYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList [C:Program FilesExpressFilesexpressdl.exe] Value Deleted : HKLMSYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList [C:Program FilesExpressFilesExpressFiles.exe] Key Deleted : HKCUSoftwareAskToolbar Key Deleted : HKCUSoftwareAVG Secure Search Key Deleted : HKCUSoftwarebbrs_002.tb Key Deleted : HKCUSoftwareBlabbers Key Deleted : HKCUSoftwareBrowserCompanion Key Deleted : HKCUSoftwareConduit Key Deleted : HKCUSoftwareExpressFiles Key Deleted : HKCUSoftwareHeadlight Key Deleted : HKCUSoftwareIM Key Deleted : HKCUSoftwareImInstaller Key Deleted : HKCUSoftwareNCH Software Key Deleted : HKCUSoftwareSmartBar Key Deleted : HKCUSoftwareSoftonic Key Deleted : HKCUSoftwareSomoto Toolbar Key Deleted : HKCUSoftwareWeb Assistant Key Deleted : HKCUSoftwareYahooPartnerToolbar Key Deleted : HKCUSoftwareuTorrentBar Key Deleted : HKCUSoftwareAppDataLowSoftwareSmartBar Key Deleted : HKLMSoftwareAVG Secure Search Key Deleted : HKLMSoftwareAVG Security Toolbar Key Deleted : HKLMSoftwareBabylon Key Deleted : HKLMSoftwareBrowserCompanion Key Deleted : HKLMSoftwareConduit Key Deleted : HKLMSoftwareExpressFiles Key Deleted : HKLMSoftwareGinyasBrowserCompanion Key Deleted : HKLMSoftwareNCH Software Key Deleted : HKLMSoftwareSProtector Key Deleted : HKLMSoftwareTarma Installer Key Deleted : HKLMSoftwareTrymedia Systems Key Deleted : HKLMSoftwareWeb Assistant Key Deleted : HKLMSoftwareYourFileDownloader Key Deleted : HKLMSoftwareuTorrentBar Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstall{889DF117-14D1-44EE-9F31-C5FB5D47F68B} Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstall{A7BC02AF-1128-4A31-BCF8-1A3EE803D3B3} Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstall{A81A974F-8A22-43E6-9243-5198FF758DA1} Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstallAVG Secure Search Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstalluTorrentBar Toolbar Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionApp ManagementARPCache{889DF117-14D1-44EE-9F31-C5FB5D47F68B} Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionApp ManagementARPCache{A7BC02AF-1128-4A31-BCF8-1A3EE803D3B3} Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionApp ManagementARPCache{A81A974F-8A22-43E6-9243-5198FF758DA1} Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionApp ManagementARPCacheAVG Secure Search Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionApp ManagementARPCachewnlt Key Deleted : HKLMSOFTWAREMicrosoftWindowsCurrentVersionApp ManagementARPCacheuTorrentBar Toolbar Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components02F47BF73B948514FAACADD8CBBDF37D Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components07D5290CDBDAE4242926B8E6CA650501 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components080D9F5E1E95FEE4794CE438E635239E Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components08E33F7B61DEFF24BB9673ED7D467636 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components0E3D8A5B48622A445A7DF73FEFF32C3F Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components0FF2AEFF45EEA0A48A4B33C1973B6094 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components1E264E0A5959A1C46BA9175A878B12EA Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components2E6768B6932D112438F047C54D180635 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components305B09CE8C53A214DB58887F62F25536 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components34EDDB1BFB3A2D448845F3EFD0F15A43 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components351716A953E21214898904032EAE2E81 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components397C771A7BCAC904697C3EC629ED33ED Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components427EA997C413D1D47907CBFC7B2DB432 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components4318DF19719275242801CBE292063A4C Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components45FC115D1FEAEF849A4E1610D6EC8BF0 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components46A5861A389ADB844AF89E31BC9DF0A1 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components49B0E1A6FF50BBE4289E4E23DE6EA0C7 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components4CCCAC049F34D0540AAC13011398BEDB Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components5C4389D0BFB302C479DE4178BD5D9EBA Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components5D2B09BDEF4FE54418E6F3373CDBC7AC Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components61B65D3397A1FBF4CB1571B5E4F6B5B0 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components68E8A05C60DD9254591DBD16C94EDDBF Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components697E782CF574CC34CBB9566440BA12BC Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components69D6A6B2ED56AF24EA6335EAD6E91CA4 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components6AE27A8613CF7EA4782F2886F67295E5 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components75D5168E5E176C24981B4E5DBD991078 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components7CE172051F585E04187BCB97570BFA74 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components7FFA128C2B0FF414D805FC5627883401 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components86A901BA5265452499DCBF719C378EE3 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components86EDC790504E1834DBC20C9A04328FD2 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components8724E58E6C7D00C48A0D4F3345EB2C26 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components88ABD1CD5C40EC84789A7F6EF86DAC5E Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components97C3D0F82E712E241A2F969F45E3351C Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components980289C22F80A7C4BB9323DC61255E4E Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components98CC8BF5A4A6E6C4ABF7051DDAB8B058 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components9A4B7EF3789F871419D9302583B20C15 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components9E7F556BF224D804D96A96F0F6344789 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsA189D17A469616C4688D23E192996267 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsA6C53B0F76C44004A8F36716213017DB Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsAB676B0E1B9EFA049B9F7DDDA9645734 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsB31BBB0B825EDEF45AB0FE7099C68C81 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsB471D8D7319336B4CA89374ED0D7B806 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsB59F2D8189784CC46A4597F2842480B0 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsBC30043663AA2CA4DA1DAA9CA5FDCC75 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsBD746FB95FB8E5B45BF66BE54D5FD91F Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsBF4F885EDEE45644EB1E0C99E0162399 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsCCF399FCD6D2D3F46BF02A1378654FC9 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsCE21F3FD57B244142880EF15A165A156 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsD149C1355C98DE24E82CEFBD996FE06A Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsD15DAF33C220F91468A1D7D57C31ACD7 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsD3BA76A44C779424889063D5098ED2D6 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsD6D0EB9FDBD90C04D92A7E729058F10D Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsDB59FDB786388EA4D897F3EE715683AC Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsDB8DAD19CFBCC2049A4477183787E8C5 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsE1C820A74ED67374BA048B52CB3C3804 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsE4748F9A4181FCE46A23C13B517B9420 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsEC65F200D112357449C8B1BC3CFA03D0 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsF327D0C73C0973644A21E8CC852267A0 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsF754C503375A13344B22388E18DFE87E Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsFA96423FE2B98E248A3B23548D1E22D9 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsFDC83385E6C239F4C876A77A37DF581D Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ProductsF479A18A22A86E3429341589FF57D81A Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ProductsFA20CB7A821113A4CB8FA1E38E303D3B Key Deleted : HKLMSoftwareClassesInstallerFeaturesF479A18A22A86E3429341589FF57D81A Key Deleted : HKLMSoftwareClassesInstallerFeaturesFA20CB7A821113A4CB8FA1E38E303D3B Key Deleted : HKLMSoftwareClassesInstallerProductsF479A18A22A86E3429341589FF57D81A Key Deleted : HKLMSoftwareClassesInstallerProductsFA20CB7A821113A4CB8FA1E38E303D3B Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUpgradeCodes789034A89BAC50E4782F0A7BDBF75632 Key Deleted : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUpgradeCodesA97CEC23332751B47BA4B95BAA50C9D0 ***** [ Browsers ] ***** - Internet Explorer v8.0.6001.18702 Setting Restored : HKCUSoftwareMicrosoftInternet ExplorerMain [start Page] Setting Restored : HKLMSOFTWAREMicrosoftInternet ExplorerMain [start Page] Setting Restored : HKLMSOFTWAREMicrosoftInternet ExplorerAboutURls [Tabs] Setting Restored : HKLMSOFTWAREMicrosoftInternet ExplorerSearch [searchAssistant] - Mozilla Firefox v22.0 (en-US) [ File : C:Documents and SettingsBrunoApplication DataMozillaFirefoxProfilesc0bbqulh.defaultprefs.js ] Line Deleted : user_pref("aol_toolbar.default.homepage.check", false); Line Deleted : user_pref("aol_toolbar.default.search.check", false); Line Deleted : user_pref("avg.install.installDirPath", "C:Documents and SettingsAll UsersApplication DataAVG Secure SearchFireFoxExt15.3.0.11"); Line Deleted : user_pref("avg.install.userSPSettings", "Search The Web"); Line Deleted : user_pref("avg.userPreferences.URLBarFocus.whiteList", "bing.com|google.w+|yahoo.w+|gmail.w+|hotmail.w+|live.w+|isearch.avg.com|mysearch.avg.com"); Line Deleted : user_pref("browser.search.selectedEngine", "Search The Web"); Line Deleted : user_pref("extensions.BabylonToolbar.prtkDS", 0); Line Deleted : user_pref("extensions.BabylonToolbar.prtkHmpg", 0); Line Deleted : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", ""); Line Deleted : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", ""); Line Deleted : user_pref("sweetim.toolbar.previous.browser.startup.homepage", ""); Line Deleted : user_pref("sweetim.toolbar.previous.keyword.URL", ""); Line Deleted : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", ""); Line Deleted : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", ""); Line Deleted : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", ""); Line Deleted : user_pref("sweetim.toolbar.searchguard.enable", ""); [ File : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultprefs.js ] Line Deleted : user_pref("aol_toolbar.default.homepage.check", false); Line Deleted : user_pref("aol_toolbar.default.search.check", false); Line Deleted : user_pref("avg.install.installDirPath", "C:Documents and SettingsAll UsersApplication DataAVG Secure SearchFireFoxExt14.2.0.1"); Line Deleted : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com"); Line Deleted : user_pref("browser.search.defaultenginename", "MyStart Search"); Line Deleted : user_pref("browser.search.order.1", "Search the web (Babylon)"); Line Deleted : user_pref("browser.search.selectedEngine", "Search The Web"); Line Deleted : user_pref("extensions.5023db04d67eb.scode", "(function(){try{if('aol.com,mail.google.com,premiumreports.info,search.babylon.com,search.gboxapp.com'.indexOf(window.self.location.hostname)>-1) return;}c[...] Line Deleted : user_pref("extensions.BabylonToolbar.admin", false); Line Deleted : user_pref("extensions.BabylonToolbar.aflt", "babsst"); Line Deleted : user_pref("extensions.BabylonToolbar.babExt", ""); Line Deleted : user_pref("extensions.BabylonToolbar.babTrack", "affID=110819&tt=050412_30b"); Line Deleted : user_pref("extensions.BabylonToolbar.bbDpng", 18); Line Deleted : user_pref("extensions.BabylonToolbar.dfltLng", "en"); Line Deleted : user_pref("extensions.BabylonToolbar.dfltSrch", true); Line Deleted : user_pref("extensions.BabylonToolbar.excTlbr", false); Line Deleted : user_pref("extensions.BabylonToolbar.hmpg", true); Line Deleted : user_pref("extensions.BabylonToolbar.id", "64467e62000000000000001d7d5c9254"); Line Deleted : user_pref("extensions.BabylonToolbar.instlDay", "15444"); Line Deleted : user_pref("extensions.BabylonToolbar.instlRef", "sst"); Line Deleted : user_pref("extensions.BabylonToolbar.lastDP", 18); Line Deleted : user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.5.3.1718:15:56"); Line Deleted : user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "16.0"); Line Deleted : user_pref("extensions.BabylonToolbar.newTab", true); Line Deleted : user_pref("extensions.BabylonToolbar.noFFXTlbr", false); Line Deleted : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar"); Line Deleted : user_pref("extensions.BabylonToolbar.propectorlck", 102170485); Line Deleted : user_pref("extensions.BabylonToolbar.prtkDS", 0); Line Deleted : user_pref("extensions.BabylonToolbar.prtkHmpg", 1); Line Deleted : user_pref("extensions.BabylonToolbar.prtnrId", "babylon"); Line Deleted : user_pref("extensions.BabylonToolbar.ptch_0717", true); Line Deleted : user_pref("extensions.BabylonToolbar.smplGrp", "tzb"); Line Deleted : user_pref("extensions.BabylonToolbar.srcExt", "ss"); Line Deleted : user_pref("extensions.BabylonToolbar.tlbrId", "tb9"); Line Deleted : user_pref("extensions.BabylonToolbar.vrsn", "1.5.3.17"); Line Deleted : user_pref("extensions.BabylonToolbar.vrsnTs", "1.5.3.1718:15:56"); Line Deleted : user_pref("extensions.BabylonToolbar.vrsni", "1.5.3.17"); Line Deleted : user_pref("extensions.BabylonToolbar_i.aflt", "babsst"); Line Deleted : user_pref("extensions.BabylonToolbar_i.babExt", ""); Line Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110819&tt=050412_30b"); Line Deleted : user_pref("extensions.BabylonToolbar_i.hardId", "64467e62000000000000001d7d5c9254"); Line Deleted : user_pref("extensions.BabylonToolbar_i.id", "64467e62000000000000001d7d5c9254"); Line Deleted : user_pref("extensions.BabylonToolbar_i.instlDay", "15444"); Line Deleted : user_pref("extensions.BabylonToolbar_i.instlRef", "sst"); Line Deleted : user_pref("extensions.BabylonToolbar_i.newTab", false); Line Deleted : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar"); Line Deleted : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon"); Line Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); Line Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); Line Deleted : user_pref("extensions.BabylonToolbar_i.tlbrId", "tb9"); Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17"); Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1718:15:56"); Line Deleted : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17"); Line Deleted : user_pref("extensions.enabledAddons", "[email protected]:1.2.0,[email protected]:1.5.0,{ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.9,{ba23dafc-5a36-4bdd-9d69-ed60da9d6c78}:1.1,{EEE6C361-6118-11D[...] Line Deleted : user_pref("extensions.incredibar.admin", false); Line Deleted : user_pref("extensions.incredibar.aflt", "orgnl"); Line Deleted : user_pref("extensions.incredibar.cntry", "HR"); Line Deleted : user_pref("extensions.incredibar.dfltLng", ""); Line Deleted : user_pref("extensions.incredibar.dfltSrch", false); Line Deleted : user_pref("extensions.incredibar.did", "10650"); Line Deleted : user_pref("extensions.incredibar.excTlbr", false); Line Deleted : user_pref("extensions.incredibar.hdrMd5", "8ECBA5165467F70CFFC267D7B6D3C2F1"); Line Deleted : user_pref("extensions.incredibar.hmpg", false); Line Deleted : user_pref("extensions.incredibar.id", "64467e62000000000000001d7d5c9254"); Line Deleted : user_pref("extensions.incredibar.installerproductid", "26"); Line Deleted : user_pref("extensions.incredibar.instlDay", "15561"); Line Deleted : user_pref("extensions.incredibar.instlRef", ""); Line Deleted : user_pref("extensions.incredibar.lastVrsnTs", "1.5.11.1417:52:40"); Line Deleted : user_pref("extensions.incredibar.newTab", false); Line Deleted : user_pref("extensions.incredibar.noFFXTlbr", false); Line Deleted : user_pref("extensions.incredibar.ppd", "201%5F5"); Line Deleted : user_pref("extensions.incredibar.prdct", "incredibar"); Line Deleted : user_pref("extensions.incredibar.productid", "26"); Line Deleted : user_pref("extensions.incredibar.prtnrId", "Incredibar"); Line Deleted : user_pref("extensions.incredibar.sg", "none"); Line Deleted : user_pref("extensions.incredibar.smplGrp", "none"); Line Deleted : user_pref("extensions.incredibar.tlbrId", "base"); Line Deleted : user_pref("extensions.incredibar.upn2", "6PQG2Pjoor"); Line Deleted : user_pref("extensions.incredibar.upn2n", "92543376822309155"); Line Deleted : user_pref("extensions.incredibar.vrsn", "1.5.11.14"); Line Deleted : user_pref("extensions.incredibar.vrsnTs", "1.5.11.1417:52:40"); Line Deleted : user_pref("extensions.incredibar.vrsni", "1.5.11.14"); Line Deleted : user_pref("extensions.incredibar_i.aflt", "orgnl"); Line Deleted : user_pref("extensions.incredibar_i.dfltLng", ""); Line Deleted : user_pref("extensions.incredibar_i.did", "10650"); Line Deleted : user_pref("extensions.incredibar_i.excTlbr", false); Line Deleted : user_pref("extensions.incredibar_i.id", "64467e62000000000000001d7d5c9254"); Line Deleted : user_pref("extensions.incredibar_i.installerproductid", "26"); Line Deleted : user_pref("extensions.incredibar_i.instlDay", "15561"); Line Deleted : user_pref("extensions.incredibar_i.instlRef", ""); Line Deleted : user_pref("extensions.incredibar_i.ms_url_id", ""); Line Deleted : user_pref("extensions.incredibar_i.newTab", false); Line Deleted : user_pref("extensions.incredibar_i.ppd", "201%5F5"); Line Deleted : user_pref("extensions.incredibar_i.prdct", "incredibar"); Line Deleted : user_pref("extensions.incredibar_i.productid", "26"); Line Deleted : user_pref("extensions.incredibar_i.prtnrId", "Incredibar"); Line Deleted : user_pref("extensions.incredibar_i.smplGrp", "none"); Line Deleted : user_pref("extensions.incredibar_i.tlbrId", "base"); Line Deleted : user_pref("extensions.incredibar_i.upn2", "6PQG2Pjoor"); Line Deleted : user_pref("extensions.incredibar_i.upn2n", "92543376822309155"); Line Deleted : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14"); Line Deleted : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1417:52:40"); Line Deleted : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14"); Line Deleted : user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0"); Line Deleted : user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7"); Line Deleted : user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log"); Line Deleted : user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000"); Line Deleted : user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7"); Line Deleted : user_pref("sweetim.toolbar.mode.debug", "false"); Line Deleted : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", ""); Line Deleted : user_pref("sweetim.toolbar.previous.browser.search.defaulturl", ""); Line Deleted : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", ""); Line Deleted : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", ""); Line Deleted : user_pref("sweetim.toolbar.search.history.capacity", "10"); Line Deleted : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", ""); Line Deleted : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", ""); Line Deleted : user_pref("sweetim.toolbar.searchguard.enable", ""); Line Deleted : user_pref("sweetim.toolbar.simapp_id", "{06BC8253-E3CA-11E0-B9D7-001D7D5C9254}"); Line Deleted : user_pref("sweetim.toolbar.version", "1.2.0.2"); [ File : C:Documents and SettingsAdministratorApplication DataMozillaFirefoxProfiles5gozow0a.defaultprefs.js ] Line Deleted : user_pref("aol_toolbar.default.homepage.check", false); Line Deleted : user_pref("aol_toolbar.default.search.check", false); Line Deleted : user_pref("avg.install.installDirPath", "C:Documents and SettingsAll UsersApplication DataAVG Secure Search12.2.5.32"); Line Deleted : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com"); Line Deleted : user_pref("browser.search.defaultenginename", "SweetIM Search"); Line Deleted : user_pref("browser.search.defaultthis.engineName", "uTorrentBar Customized Web Search"); Line Deleted : user_pref("browser.search.selectedEngine", "uTorrentBar Customized Web Search"); Line Deleted : user_pref("extensions.5023db04d67eb.scode", "(function(){try{if('aol.com,mail.google.com,mystart.incredibar.com,premiumreports.info,search.babylon.com,search.funmoods.com,search.gboxapp.com,search.swe[...] Line Deleted : user_pref("extensions.50eecf0c7a25e.scode", "(function(){if(window.self.location.hostname.indexOf("acebook.co")>-1){return};if(window.self.location.protocol.indexOf('hxxp')>-1 && window.self==window[...] Line Deleted : user_pref("extensions.50fbc3c412ebb.scode", "(function(){if(window.self.location.hostname.indexOf("acebook.co")>-1){return};if(window.self.location.protocol.indexOf('hxxp')>-1 && window.self==window[...] Line Deleted : user_pref("extensions.510f82f049960.scode", "if(window.top==window.self){new function(){if(!document.getElementById("__yael_once")){var b=this,j=["horizontal","vertical","images-horizontal","[...] Line Deleted : user_pref("extensions.BabylonToolbar.aflt", "babsst"); Line Deleted : user_pref("extensions.BabylonToolbar.babTrack", "affID=100473"); Line Deleted : user_pref("extensions.BabylonToolbar.bbDpng", 5); Line Deleted : user_pref("extensions.BabylonToolbar.dfltLng", "en"); Line Deleted : user_pref("extensions.BabylonToolbar.dfltSrch", true); Line Deleted : user_pref("extensions.BabylonToolbar.hmpg", true); Line Deleted : user_pref("extensions.BabylonToolbar.id", "64467e62000000000000001d7d5c9254"); Line Deleted : user_pref("extensions.BabylonToolbar.instlDay", "15209"); Line Deleted : user_pref("extensions.BabylonToolbar.instlRef", "sst"); Line Deleted : user_pref("extensions.BabylonToolbar.lastDP", 5); Line Deleted : user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.4.35.1014:25:43"); Line Deleted : user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "16.0"); Line Deleted : user_pref("extensions.BabylonToolbar.newTab", true); Line Deleted : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar"); Line Deleted : user_pref("extensions.BabylonToolbar.propectorlck", 93291069); Line Deleted : user_pref("extensions.BabylonToolbar.prtkDS", 0); Line Deleted : user_pref("extensions.BabylonToolbar.prtkHmpg", 0); Line Deleted : user_pref("extensions.BabylonToolbar.prtnrId", "babylon"); Line Deleted : user_pref("extensions.BabylonToolbar.ptch_0717", true); Line Deleted : user_pref("extensions.BabylonToolbar.smplGrp", "azb"); Line Deleted : user_pref("extensions.BabylonToolbar.srcExt", "ss"); Line Deleted : user_pref("extensions.BabylonToolbar.srchPrvdr", "Search the web (Babylon)"); Line Deleted : user_pref("extensions.BabylonToolbar.tlbrId", "base"); Line Deleted : user_pref("extensions.BabylonToolbar.vrsn", "1.4.35.10"); Line Deleted : user_pref("extensions.BabylonToolbar.vrsnTs", "1.4.35.1014:25:43"); Line Deleted : user_pref("extensions.enabledItems", "{20a82645-c095-46ed-80e3-08825760534b}:1.1,[email protected]:1.0,{ABDE892B-13A8-4d1b-88E6-365A6E755758}:15.0.1,{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24,{1E73965B-8[...] Line Deleted : user_pref("extentions.y2layers.defaultEnableAppsList", "DropDownDeals,buzzdock,YontooNewOffers"); Line Deleted : user_pref("extentions.y2layers.installId", "54e204f7-d79d-4f75-a144-86b5eacc967e"); Line Deleted : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", ""); Line Deleted : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "Search The Web"); Line Deleted : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", ""); Line Deleted : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", ""); Line Deleted : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", ""); Line Deleted : user_pref("sweetim.toolbar.searchguard.enable", ""); - Google Chrome v31.0.1650.63 [ File : C:Documents and SettingsBrunoLocal SettingsApplication DataGoogleChromeUser DataDefaultpreferences ] [ File : C:Documents and SettingsPetraaLocal SettingsApplication DataGoogleChromeUser DataDefaultpreferences ] [ File : C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleChromeUser DataDefaultpreferences ] Deleted : homepage Deleted : urls_to_restore_on_startup ************************* AdwCleaner[R0].txt - [66126 octets] - [19/12/2013 14:36:19] AdwCleaner[R1].txt - [66191 octets] - [19/12/2013 20:34:05] AdwCleaner[s0].txt - [59711 octets] - [19/12/2013 20:37:31] ########## EOF - C:AdwCleanerAdwCleaner[s0].txt - [59772 octets] ##########
  9. I didn't click clean, just copied this. No program matters much if it means fixing this problem. # AdwCleaner v3.015 - Report created 19/12/2013 at 14:36:19 # Updated 10/12/2013 by Xplode # Operating System : Microsoft Windows XP Service Pack 3 (32 bits) # Username : Administrator - PETRA # Running from : C:Documents and SettingsAdministratorMy DocumentsDownloadsAdwCleaner.exe # Option : Scan ***** [ Services ] ***** ***** [ Files / Folders ] ***** File Found : C:Documents and SettingsAdministratorApplication DataMozillaFirefoxProfiles5gozow0a.defaultsearchpluginsConduit.xml File Found : C:Documents and SettingsAdministratorApplication DataMozillaFirefoxProfiles5gozow0a.defaultsearchpluginsMyStart Search.xml File Found : C:Documents and SettingsAdministratorApplication DataMozillaFirefoxProfiles5gozow0a.defaultsearchpluginsSweetIM Search.xml File Found : C:Documents and SettingsAdministratorApplication DataMozillaFirefoxProfiles5gozow0a.defaultsearchpluginsSweetIm.xml File Found : C:Documents and SettingsAdministratorApplication DataMozillaFirefoxProfiles5gozow0a.defaultuser.js File Found : C:Documents and SettingsBrunoApplication DataMozillaFirefoxProfilesc0bbqulh.defaultsearchpluginsMyStart Search.xml File Found : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultsearchpluginsMyStart Search.xml File Found : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultsearchpluginsSweetIm.xml File Found : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultsearchpluginsSweetpacks Search.xml File Found : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultuser.js File Found : C:END File Found : C:Program FilesMozilla Firefoxbrowsersearchpluginsavg-secure-search.xml File Found : C:Program FilesMozilla Firefoxsearchpluginsavg-secure-search.xml File Found : C:Program FilesMozilla FirefoxsearchpluginsBabylon.xml File Found : C:Program FilesMozilla FirefoxsearchpluginsfcmdSrch.xml File Found : C:WINDOWSsystem32ImhxxpComm.dll File Found : C:WINDOWSTasksExpress FilesUpdate.job File Found : C:WINDOWSTasksGinyasBrowserCompanion Chrome Watcher.job File Found : C:WINDOWSTasksGinyasBrowserCompanion FireFox Watcher.job File Found : C:WINDOWSTasksGinyasBrowserCompanion Runner.job File Found : C:WINDOWSTasksGinyasBrowserCompanion Stats Report.job File Found : C:WINDOWSTasksGinyasBrowserCompanion Update Checker.job Folder Found : C:Documents and SettingsAdministratorApplication Da[email protected]50eecf0c7a1eb.com Folder Found : C:Documents and SettingsAdministratorApplication Da[email protected]50eecf0c7a1eb.com Folder Found : C:Documents and SettingsAdministratorApplication Da[email protected]50fbc3c412e48.com Folder Found : C:Documents and SettingsAdministratorApplication Da[email protected]50fbc3c412e48.com Folder Found : C:Documents and SettingsAdministratorApplication Da[email protected]510f82f0498ed.com Folder Found : C:Documents and SettingsAdministratorApplication Da[email protected]510f82f0498ed.com Folder Found : C:Documents and SettingsAdministratorApplication Da[email protected]510f82f0498ed.com Folder Found : C:Documents and SettingsAdministratorApplication [email protected]bbers.com Folder Found : C:Documents and SettingsAdministratorApplication [email protected]bbers.com Folder Found : C:Documents and SettingsAdministratorApplication [email protected]bbers.com Folder Found : C:Documents and SettingsAdministratorApplication [email protected]bbers.com Folder Found : C:Documents and SettingsAdministratorApplication [email protected]bbers.com Folder Found : C:Documents and SettingsAdministratorApplication [email protected]bbers.com Folder Found : C:Documents and SettingsAdministratorApplication [email protected]bbers.com Folder Found : C:Documents and SettingsAdministratorApplication DataMozill[email protected]weliketheweb.com Folder Found : C:Documents and SettingsAdministratorApplication DataMozill[email protected]weliketheweb.com Folder Found : C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionseeagmkkfclhgnfoailfapcecdjooldak Folder Found : C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsjifflliplgeajjdhmkcfnngfpgbjonjg Folder Found : C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsjmfkcklnlgedgbglfkkgedjfmejoahla Folder Found : C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof Folder Found : C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsniapdbllcanepiiimjjndipklodoedlc Folder Found : C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsogccgbmabaphcakpiclgcnmcnimhokcj Folder Found : C:Documents and SettingsAdministratorLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsolakgnkoldmagdblaalodobkmeokmgjj Folder Found : C:Documents and SettingsBrunoApplication DataMozillaFirefoxProfilesc0bbqulh.defaultExtensions{20a82645-c095-46ed-80e3-08825760534b} Folder Found : C:Documents and SettingsBrunoApplication DataMozillaFirefoxProfilesc0bbqulh.defaultExtensions{20a82645-c095-46ed-80e3-08825760534b} Folder Found : C:Documents and SettingsBrunoApplication DataMozillaFirefoxProfilesc0bbqulh.defaultExtensions{20a82645-c095-46ed-80e3-08825760534b} Folder Found : C:Documents and SettingsBrunoApplication DataMozillaFirefoxProfilesc0bbqulh.defaultExtensions{20a82645-c095-46ed-80e3-08825760534b} Folder Found : C:Documents and SettingsBrunoApplication DataMozillaFirefoxProfilesc0bbqulh.defaultExtensions{ba23dafc-5a36-4bdd-9d69-ed60da9d6c78} Folder Found : C:Documents and SettingsBrunoApplication DataMozillaFirefoxProfilesc0bbqulh.defaultExtensions{ba23dafc-5a36-4bdd-9d69-ed60da9d6c78} Folder Found : C:Documents and SettingsBrunoApplication DataMozillaFirefoxProfilesc0bbqulh.defaultExtensions{ba23dafc-5a36-4bdd-9d69-ed60da9d6c78} Folder Found : C:Documents and SettingsBrunoApplication DataMozillaFirefoxProfilesc0bbqulh.defaultExtensions{ba23dafc-5a36-4bdd-9d69-ed60da9d6c78} Folder Found : C:Documents and SettingsBrunoApplication [email protected]bbers.com Folder Found : C:Documents and SettingsBrunoApplication [email protected]bbers.com Folder Found : C:Documents and SettingsBrunoApplication [email protected]bbers.com Folder Found : C:Documents and SettingsBrunoApplication [email protected]bbers.com Folder Found : C:Documents and SettingsBrunoApplication [email protected]bbers.com Folder Found : C:Documents and SettingsBrunoApplication [email protected]bbers.com Folder Found : C:Documents and SettingsBrunoApplication [email protected]bbers.com Folder Found : C:Documents and SettingsBrunoApplication [email protected]om Folder Found : C:Documents and SettingsBrunoApplication [email protected]om Folder Found : C:Documents and SettingsBrunoLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionseeagmkkfclhgnfoailfapcecdjooldak Folder Found : C:Documents and SettingsBrunoLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsjifflliplgeajjdhmkcfnngfpgbjonjg Folder Found : C:Documents and SettingsBrunoLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsjmfkcklnlgedgbglfkkgedjfmejoahla Folder Found : C:Documents and SettingsBrunoLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof Folder Found : C:Documents and SettingsBrunoLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsniapdbllcanepiiimjjndipklodoedlc Folder Found : C:Documents and SettingsBrunoLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsogccgbmabaphcakpiclgcnmcnimhokcj Folder Found : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultExtensions{20a82645-c095-46ed-80e3-08825760534b} Folder Found : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultExtensions{20a82645-c095-46ed-80e3-08825760534b} Folder Found : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultExtensions{20a82645-c095-46ed-80e3-08825760534b} Folder Found : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultExtensions{20a82645-c095-46ed-80e3-08825760534b} Folder Found : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultExtensions{ACAA314B-EEBA-48E4-AD47-84E31C44796C} Folder Found : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultExtensions{ACAA314B-EEBA-48e4-AD47-84E31C44796C} Folder Found : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultExtensions{ACAA314B-EEBA-48e4-AD47-84E31C44796C} Folder Found : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultExtensions{ba23dafc-5a36-4bdd-9d69-ed60da9d6c78} Folder Found : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultExtensions{ba23dafc-5a36-4bdd-9d69-ed60da9d6c78} Folder Found : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultExtensions{ba23dafc-5a36-4bdd-9d69-ed60da9d6c78} Folder Found : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultExtensions{ba23dafc-5a36-4bdd-9d69-ed60da9d6c78} Folder Found : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultExtensions{EEE6C361-6118-11DC-9C72-001320C79847} Folder Found : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultExtensions{EEE6C361-6118-11DC-9C72-001320C79847} Folder Found : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultExtensions{EEE6C361-6118-11DC-9C72-001320C79847} Folder Found : C:Documents and SettingsPetraaApplication Da[email protected]5023db04d6776.info Folder Found : C:Documents and SettingsPetraaApplication Da[email protected]5023db04d6776.info Folder Found : C:Documents and SettingsPetraaApplication Da[email protected]5023db04d6776.info Folder Found : C:Documents and SettingsPetraaApplication [email protected]bbers.com Folder Found : C:Documents and SettingsPetraaApplication [email protected]bbers.com Folder Found : C:Documents and SettingsPetraaApplication [email protected]bbers.com Folder Found : C:Documents and SettingsPetraaApplication [email protected]bbers.com Folder Found : C:Documents and SettingsPetraaApplication [email protected]bbers.com Folder Found : C:Documents and SettingsPetraaApplication [email protected]bbers.com Folder Found : C:Documents and SettingsPetraaApplication [email protected]bbers.com Folder Found : C:Documents and SettingsPetraaApplication [email protected]lon.com Folder Found : C:Documents and SettingsPetraaApplication [email protected]lon.com Folder Found : C:Documents and SettingsPetraaApplication [email protected]lon.com Folder Found : C:Documents and SettingsPetraaApplication [email protected]edibar.com Folder Found : C:Documents and SettingsPetraaApplication [email protected]edibar.com Folder Found : C:Documents and SettingsPetraaApplication [email protected]edibar.com Folder Found : C:Documents and SettingsPetraaLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionseeagmkkfclhgnfoailfapcecdjooldak Folder Found : C:Documents and SettingsPetraaLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsjifflliplgeajjdhmkcfnngfpgbjonjg Folder Found : C:Documents and SettingsPetraaLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsjmfkcklnlgedgbglfkkgedjfmejoahla Folder Found : C:Documents and SettingsPetraaLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsndibdjnfmopecpmkdieinmbadjfpblof Folder Found : C:Documents and SettingsPetraaLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsniapdbllcanepiiimjjndipklodoedlc Folder Found : C:Documents and SettingsPetraaLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsogccgbmabaphcakpiclgcnmcnimhokcj Folder Found C:Documents and SettingsAdministratorApplication DataAVG Secure Search Folder Found C:Documents and SettingsAdministratorApplication DataBabylonToolbar Folder Found C:Documents and SettingsAdministratorApplication DataExpressFiles Folder Found C:Documents and SettingsAdministratorApplication DataNCH Software Folder Found C:Documents and SettingsAdministratorApplication DataSimilarSites Folder Found C:Documents and SettingsAdministratorApplication Datayourfiledownloader Folder Found C:Documents and SettingsAdministratorLocal SettingsApplication DataAskToolbar Folder Found C:Documents and SettingsAdministratorLocal SettingsApplication DataAVG Secure Search Folder Found C:Documents and SettingsAdministratorLocal SettingsApplication DataBabylon Folder Found C:Documents and SettingsAdministratorLocal SettingsApplication DataConduit Folder Found C:Documents and SettingsAdministratorLocal SettingsApplication DataPackageAware Folder Found C:Documents and SettingsAdministratorLocal SettingsApplication DatauTorrentBar Folder Found C:Documents and SettingsAll UsersApplication DataADDICT-THING Folder Found C:Documents and SettingsAll UsersApplication DataAVG Secure Search Folder Found C:Documents and SettingsAll UsersApplication DataBabylon Folder Found C:Documents and SettingsAll UsersApplication Dataclsoft ltd Folder Found C:Documents and SettingsAll UsersApplication Datacontinuetosave Folder Found C:Documents and SettingsAll UsersApplication Datacontinuetosave Folder Found C:Documents and SettingsAll UsersApplication DataGinyasBrowserCompanion Folder Found C:Documents and SettingsAll UsersApplication DataNCH Software Folder Found C:Documents and SettingsAll UsersApplication DataPremium Folder Found C:Documents and SettingsAll UsersApplication DataRightClick Folder Found C:Documents and SettingsAll UsersApplication DataSweetIM Folder Found C:Documents and SettingsAll UsersApplication DataTarma Installer Folder Found C:Documents and SettingsAll UsersApplication DataTrymedia Folder Found C:Documents and SettingsBrunoApplication DataAVG Secure Search Folder Found C:Documents and SettingsBrunoApplication Datafacemoods.com Folder Found C:Documents and SettingsBrunoLocal SettingsApplication DataAskToolbar Folder Found C:Documents and SettingsBrunoLocal SettingsApplication DataAVG Secure Search Folder Found C:Documents and SettingsBrunoLocal SettingsApplication DataConduit Folder Found C:Documents and SettingsBrunoLocal SettingsApplication DataPackageAware Folder Found C:Documents and SettingsBrunoLocal SettingsApplication DatauTorrentBar Folder Found C:Documents and SettingsPetraaApplication DataAVG Secure Search Folder Found C:Documents and SettingsPetraaApplication DataBabylonToolbar Folder Found C:Documents and SettingsPetraaApplication Datafacemoods.com Folder Found C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultSweetIMToolbarData Folder Found C:Documents and SettingsPetraaLocal SettingsApplication DataAVG Secure Search Folder Found C:Documents and SettingsPetraaLocal SettingsApplication DataBabylon Folder Found C:Documents and SettingsPetraaLocal SettingsApplication DataConduit Folder Found C:Documents and SettingsPetraaLocal SettingsApplication DatauTorrentBar Folder Found C:Program Files~Web Assistant Folder Found C:Program FilesAVG Secure Search Folder Found C:Program FilesBrowserCompanion Folder Found C:Program FilesCommon FilesAVG Secure Search Folder Found C:Program FilesConduit Folder Found C:Program Filesdriver-soft Folder Found C:Program FilesNCH Software Folder Found C:Program FilesPerion Folder Found C:Program FilesuTorrentBar Folder Found C:Program FilesYontoo Folder Found C:WINDOWSsystem32ARFC Folder Found C:WINDOWSsystem32jmdp Folder Found C:WINDOWSsystem32WNLT ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Found : HKCUSoftwareAppDataLowSoftwareSmartBar Key Found : HKCUSoftwareAskToolbar Key Found : HKCUSoftwareAVG Secure Search Key Found : HKCUSoftwarebbrs_002.tb Key Found : HKCUSoftwareBlabbers Key Found : HKCUSoftwareBrowserCompanion Key Found : HKCUSoftwareConduit Key Found : HKCUSoftwareExpressFiles Key Found : HKCUSoftwareHeadlight Key Found : HKCUSoftwareIM Key Found : HKCUSoftwareImInstaller Key Found : HKCUSoftwareMicrosoftInternet ExplorerSearchScopes{0D7562AE-8EF6-416D-A838-AB665251703A} Key Found : HKCUSoftwareMicrosoftInternet ExplorerSearchScopes{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Key Found : HKCUSoftwareMicrosoftInternet ExplorerSearchScopes{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E} Key Found : HKCUSoftwareMicrosoftInternet ExplorerSearchScopes{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} Key Found : HKCUSoftwareMicrosoftInternet ExplorerSearchScopes{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKCUSoftwareMicrosoftInternet ExplorerSearchScopes{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Key Found : HKCUSoftwareMicrosoftInternet ExplorerSearchScopes{EEE6C360-6118-11DC-9C72-001320C79847} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{2EECD738-5844-4A99-B4B6-146BF802613B} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{336D0C35-8A85-403A-B9D2-65C292C39087} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{3C490BF5-4244-4310-B4A7-3361F288DAC5} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{41069220-F72A-40EA-A8F3-BCD5E1FBC8F0} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{98889811-442D-49DD-99D7-DC866BE87DBC} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{D4027C7F-154A-4066-A1AD-4243D8127440} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{EEE6C35B-6118-11DC-9C72-001320C79847} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtSettings{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{2EECD738-5844-4A99-B4B6-146BF802613B} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{336D0C35-8A85-403A-B9D2-65C292C39087} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{3C490BF5-4244-4310-B4A7-3361F288DAC5} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{41069220-F72A-40EA-A8F3-BCD5E1FBC8F0} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{98889811-442D-49DD-99D7-DC866BE87DBC} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{A97B89CD-B65C-49DD-AF46-2B772C627456} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{D4027C7F-154A-4066-A1AD-4243D8127440} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{EEE6C35B-6118-11DC-9C72-001320C79847} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{EEE6C35D-6118-11DC-9C72-001320C79847} Key Found : HKCUSoftwareMicrosoftWindowsCurrentVersionExtStats{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Found : HKCUSoftwareNCH Software Key Found : HKCUSoftwareSmartBar Key Found : HKCUSoftwareSoftonic Key Found : HKCUSoftwareSomoto Toolbar Key Found : HKCUSoftwareuTorrentBar Key Found : HKCUSoftwareWeb Assistant Key Found : HKCUSoftwareYahooPartnerToolbar Key Found : HKCUToolbar Key Found : HKLMSoftwareAVG Secure Search Key Found : HKLMSoftwareAVG Security Toolbar Key Found : HKLMSoftwareBabylon Key Found : HKLMSoftwareBrowserCompanion Key Found : HKLMSOFTWAREClassesAppID{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Key Found : HKLMSOFTWAREClassesAppID{20EDC024-43C5-423E-B7F5-FD93523E0D9F} Key Found : HKLMSOFTWAREClassesAppID{373ED12D-B306-43AC-9485-A7C5133DC34C} Key Found : HKLMSOFTWAREClassesAppID{5B1881D1-D9C7-46DF-B041-1E593282C7D0} Key Found : HKLMSOFTWAREClassesAppID{608D3067-77E8-463D-9084-908966806826} Key Found : HKLMSOFTWAREClassesAppID{B302A1BD-0157-49FA-90F1-4E94F22C7B4B} Key Found : HKLMSOFTWAREClassesAppID{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Key Found : HKLMSOFTWAREClassesAppID{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Found : HKLMSOFTWAREClassesAppID{C2178B36-2955-479B-818C-A2AE8E500454} Key Found : HKLMSOFTWAREClassesAppID{CFDAFE39-20CE-451D-BD45-A37452F39CF0} Key Found : HKLMSOFTWAREClassesAppID{EA28B360-05E0-4F93-8150-02891F1D8D3C} Key Found : HKLMSOFTWAREClassesAppID{ED6535E7-F778-48A5-A060-549D30024511} Key Found : HKLMSOFTWAREClassesAppIDExtension.DLL Key Found : HKLMSOFTWAREClassesAppIDScriptHelper.EXE Key Found : HKLMSOFTWAREClassesAppIDtdataprotocol.DLL Key Found : HKLMSOFTWAREClassesAppIDupdatebho.DLL Key Found : HKLMSOFTWAREClassesAppIDViProtocol.DLL Key Found : HKLMSOFTWAREClassesAppIDwit4ie.DLL Key Found : HKLMSOFTWAREClassesAppIDYontooIEClient.DLL Key Found : HKLMSOFTWAREClassesAVG Secure Search.BrowserWndAPI Key Found : HKLMSOFTWAREClassesAVG Secure Search.BrowserWndAPI.1 Key Found : HKLMSOFTWAREClassesAVG Secure Search.PugiObj Key Found : HKLMSOFTWAREClassesAVG Secure Search.PugiObj.1 Key Found : HKLMSOFTWAREClassesb Key Found : HKLMSOFTWAREClassesBabylon.dskBnd Key Found : HKLMSOFTWAREClassesBabylon.dskBnd.1 Key Found : HKLMSOFTWAREClassesbbylnApp.appCore Key Found : HKLMSOFTWAREClassesbbylnApp.appCore.1 Key Found : HKLMSOFTWAREClassesbbylntlbr.bbylntlbrHlpr Key Found : HKLMSOFTWAREClassesbbylntlbr.bbylntlbrHlpr.1 Key Found : HKLMSOFTWAREClassesCLSID{00000001-4FEF-40D3-B3FA-E0531B897F98} Key Found : HKLMSOFTWAREClassesCLSID{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Found : HKLMSOFTWAREClassesCLSID{35B8892D-C3FB-4D88-990D-31DB2EBD72BD} Key Found : HKLMSOFTWAREClassesCLSID{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Found : HKLMSOFTWAREClassesCLSID{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Key Found : HKLMSOFTWAREClassesCLSID{408CFAD9-8F13-4747-8EC7-770A339C7237} Key Found : HKLMSOFTWAREClassesCLSID{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Found : HKLMSOFTWAREClassesCLSID{64697678-0000-0010-8000-00AA00389B71} Key Found : HKLMSOFTWAREClassesCLSID{7E84186E-B5DE-4226-8A66-6E49C6B511B4} Key Found : HKLMSOFTWAREClassesCLSID{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Found : HKLMSOFTWAREClassesCLSID{933B95E2-E7B7-4AD9-B952-7AC336682AE3} Key Found : HKLMSOFTWAREClassesCLSID{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKLMSOFTWAREClassesCLSID{99066096-8989-4612-841F-621A01D54AD7} Key Found : HKLMSOFTWAREClassesCLSID{A97B89CD-B65C-49DD-AF46-2B772C627456} Key Found : HKLMSOFTWAREClassesCLSID{B658800C-F66E-4EF3-AB85-6C0C227862A9} Key Found : HKLMSOFTWAREClassesCLSID{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} Key Found : HKLMSOFTWAREClassesCLSID{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3} Key Found : HKLMSOFTWAREClassesCLSID{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Key Found : HKLMSOFTWAREClassesCLSID{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Found : HKLMSOFTWAREClassesCLSID{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Found : HKLMSOFTWAREClassesCLSID{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKLMSOFTWAREClassesCLSID{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Found : HKLMSOFTWAREClassesCLSID{FE9271F2-6EFD-44B0-A826-84C829536E93} Key Found : HKLMSOFTWAREClassesescort.escrtBtn.1 Key Found : HKLMSOFTWAREClassesExtension.ExtensionHelperObject Key Found : HKLMSOFTWAREClassesExtension.ExtensionHelperObject.1 Key Found : HKLMSOFTWAREClassesfacemoods.xtrnl Key Found : HKLMSOFTWAREClassesfacemoods.xtrnl.1 Key Found : HKLMSOFTWAREClassesfacemoodsApp.appCore Key Found : HKLMSOFTWAREClassesfacemoodsApp.appCore.1 Key Found : HKLMSoftwareClassesInstallerFeaturesF479A18A22A86E3429341589FF57D81A Key Found : HKLMSoftwareClassesInstallerFeaturesFA20CB7A821113A4CB8FA1E38E303D3B Key Found : HKLMSoftwareClassesInstallerProductsF479A18A22A86E3429341589FF57D81A Key Found : HKLMSoftwareClassesInstallerProductsFA20CB7A821113A4CB8FA1E38E303D3B Key Found : HKLMSOFTWAREClassesInterface{03E2A1F3-4402-4121-8B35-733216D61217} Key Found : HKLMSOFTWAREClassesInterface{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Found : HKLMSOFTWAREClassesInterface{1AD27395-1659-4DFF-A319-2CFA243861A5} Key Found : HKLMSOFTWAREClassesInterface{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F} Key Found : HKLMSOFTWAREClassesInterface{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C} Key Found : HKLMSOFTWAREClassesInterface{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Found : HKLMSOFTWAREClassesInterface{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Found : HKLMSOFTWAREClassesInterface{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Found : HKLMSOFTWAREClassesInterface{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F} Key Found : HKLMSOFTWAREClassesInterface{FE0273D1-99DF-4AC0-87D5-1371C6271785} Key Found : HKLMSOFTWAREClassesMediaPlayer.GraphicsUtils Key Found : HKLMSOFTWAREClassesMediaPlayer.GraphicsUtils.1 Key Found : HKLMSOFTWAREClassesMgMediaPlayer.GifAnimator Key Found : HKLMSOFTWAREClassesMgMediaPlayer.GifAnimator.1 Key Found : HKLMSOFTWAREClassesProd.cap Key Found : HKLMSOFTWAREClassesprotector_dll.protectorbho Key Found : HKLMSOFTWAREClassesprotector_dll.protectorbho.1 Key Found : HKLMSOFTWAREClassesprotocolshandlerviprotocol Key Found : HKLMSOFTWAREClassesScriptHelper.ScriptHelperApi Key Found : HKLMSOFTWAREClassesScriptHelper.ScriptHelperApi.1 Key Found : HKLMSOFTWAREClassessim-packages Key Found : HKLMSOFTWAREClassesSWEETIE.IEToolbar Key Found : HKLMSOFTWAREClassesSWEETIE.IEToolbar.1 Key Found : HKLMSOFTWAREClassestdataprotocol.CTData Key Found : HKLMSOFTWAREClassestdataprotocol.CTData.1 Key Found : HKLMSOFTWAREClassesToolbar.CT2786678 Key Found : HKLMSOFTWAREClassesTypeLib{07CAC314-E962-4F78-89AB-DD002F2490EE} Key Found : HKLMSOFTWAREClassesTypeLib{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Key Found : HKLMSOFTWAREClassesTypeLib{93E3D79C-0786-48FF-9329-93BC9F6DC2B3} Key Found : HKLMSOFTWAREClassesTypeLib{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Found : HKLMSOFTWAREClassesTypeLib{AC329328-7EC4-4C34-B672-0A2B90CB9B00} Key Found : HKLMSOFTWAREClassesTypeLib{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Key Found : HKLMSOFTWAREClassesTypeLib{D372567D-67C1-4B29-B3F0-159B52B3E967} Key Found : HKLMSOFTWAREClassesTypeLib{E2343056-CC08-46AC-B898-BFC7ACF4E755} Key Found : HKLMSOFTWAREClassesTypeLib{EEE6C35F-6118-11DC-9C72-001320C79847} Key Found : HKLMSOFTWAREClassesViProtocol.ViProtocolOLE Key Found : HKLMSOFTWAREClassesViProtocol.ViProtocolOLE.1 Key Found : HKLMSOFTWAREClasseswit4ie.WitBHO Key Found : HKLMSOFTWAREClasseswit4ie.WitBHO.2 Key Found : HKLMSOFTWAREClassesYontooIEClient.Api Key Found : HKLMSOFTWAREClassesYontooIEClient.Api.1 Key Found : HKLMSOFTWAREClassesYontooIEClient.Layers Key Found : HKLMSOFTWAREClassesYontooIEClient.Layers.1 Key Found : HKLMSoftwareConduit Key Found : HKLMSoftwareExpressFiles Key Found : HKLMSoftwareGinyasBrowserCompanion Key Found : HKLMSOFTWAREGoogleChromeExtensionsclbfjfbnelcflpgpklppgplejolacbej Key Found : HKLMSOFTWAREGoogleChromeExtensionsdhkplhfnhceodhffomolpfigojocbpcb Key Found : HKLMSOFTWAREGoogleChromeExtensionsdlnembnfbcpjnepmfjmngjenhhajpdfd Key Found : HKLMSOFTWAREGoogleChromeExtensionseeagmkkfclhgnfoailfapcecdjooldak Key Found : HKLMSOFTWAREGoogleChromeExtensionsjbpkiefagocgkmemidfngdkamloieekf Key Found : HKLMSOFTWAREGoogleChromeExtensionsjifflliplgeajjdhmkcfnngfpgbjonjg Key Found : HKLMSOFTWAREGoogleChromeExtensionsjmfkcklnlgedgbglfkkgedjfmejoahla Key Found : HKLMSOFTWAREGoogleChromeExtensionsndibdjnfmopecpmkdieinmbadjfpblof Key Found : HKLMSOFTWAREGoogleChromeExtensionsniapdbllcanepiiimjjndipklodoedlc Key Found : HKLMSOFTWAREGoogleChromeExtensionsogccgbmabaphcakpiclgcnmcnimhokcj Key Found : HKLMSOFTWAREMicrosoftInternet ExplorerLow RightsElevationPolicy{222A29CD-C493-4323-945A-24A02D1E7434} Key Found : HKLMSOFTWAREMicrosoftInternet ExplorerLow RightsElevationPolicy{4BFB942B-76EB-4F09-851A-5509132E86FA} Key Found : HKLMSOFTWAREMicrosoftInternet ExplorerLow RightsElevationPolicy{EEE6C367-6118-11DC-9C72-001320C79847} Key Found : HKLMSOFTWAREMicrosoftInternet ExplorerSearchScopes{EEE6C360-6118-11DC-9C72-001320C79847} Key Found : HKLMSOFTWAREMicrosoftWindowsCurrentVersionApp ManagementARPCache{889DF117-14D1-44EE-9F31-C5FB5D47F68B} Key Found : HKLMSOFTWAREMicrosoftWindowsCurrentVersionApp ManagementARPCache{A7BC02AF-1128-4A31-BCF8-1A3EE803D3B3} Key Found : HKLMSOFTWAREMicrosoftWindowsCurrentVersionApp ManagementARPCache{A81A974F-8A22-43E6-9243-5198FF758DA1} Key Found : HKLMSOFTWAREMicrosoftWindowsCurrentVersionApp ManagementARPCacheAVG Secure Search Key Found : HKLMSOFTWAREMicrosoftWindowsCurrentVersionApp ManagementARPCacheuTorrentBar Toolbar Key Found : HKLMSOFTWAREMicrosoftWindowsCurrentVersionApp ManagementARPCachewnlt Key Found : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Key Found : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} Key Found : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Found : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExtPreApproved{A97B89CD-B65C-49DD-AF46-2B772C627456} Key Found : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExtPreApproved{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Key Found : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExtPreApproved{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Found : HKLMSOFTWAREMicrosoftWindowsCurrentVersionExtPreApproved{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUpgradeCodes789034A89BAC50E4782F0A7BDBF75632 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUpgradeCodesA97CEC23332751B47BA4B95BAA50C9D0 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components02F47BF73B948514FAACADD8CBBDF37D Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components07D5290CDBDAE4242926B8E6CA650501 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components080D9F5E1E95FEE4794CE438E635239E Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components08E33F7B61DEFF24BB9673ED7D467636 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components0E3D8A5B48622A445A7DF73FEFF32C3F Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components0FF2AEFF45EEA0A48A4B33C1973B6094 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components1E264E0A5959A1C46BA9175A878B12EA Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components2E6768B6932D112438F047C54D180635 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components305B09CE8C53A214DB58887F62F25536 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components34EDDB1BFB3A2D448845F3EFD0F15A43 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components351716A953E21214898904032EAE2E81 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components397C771A7BCAC904697C3EC629ED33ED Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components427EA997C413D1D47907CBFC7B2DB432 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components4318DF19719275242801CBE292063A4C Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components45FC115D1FEAEF849A4E1610D6EC8BF0 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components46A5861A389ADB844AF89E31BC9DF0A1 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components49B0E1A6FF50BBE4289E4E23DE6EA0C7 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components4CCCAC049F34D0540AAC13011398BEDB Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components5C4389D0BFB302C479DE4178BD5D9EBA Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components5D2B09BDEF4FE54418E6F3373CDBC7AC Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components61B65D3397A1FBF4CB1571B5E4F6B5B0 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components68E8A05C60DD9254591DBD16C94EDDBF Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components697E782CF574CC34CBB9566440BA12BC Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components69D6A6B2ED56AF24EA6335EAD6E91CA4 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components6AE27A8613CF7EA4782F2886F67295E5 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components75D5168E5E176C24981B4E5DBD991078 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components7CE172051F585E04187BCB97570BFA74 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components7FFA128C2B0FF414D805FC5627883401 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components86A901BA5265452499DCBF719C378EE3 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components86EDC790504E1834DBC20C9A04328FD2 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components8724E58E6C7D00C48A0D4F3345EB2C26 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components88ABD1CD5C40EC84789A7F6EF86DAC5E Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components97C3D0F82E712E241A2F969F45E3351C Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components980289C22F80A7C4BB9323DC61255E4E Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components98CC8BF5A4A6E6C4ABF7051DDAB8B058 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components9A4B7EF3789F871419D9302583B20C15 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18Components9E7F556BF224D804D96A96F0F6344789 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsA189D17A469616C4688D23E192996267 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsA6C53B0F76C44004A8F36716213017DB Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsAB676B0E1B9EFA049B9F7DDDA9645734 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsB31BBB0B825EDEF45AB0FE7099C68C81 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsB471D8D7319336B4CA89374ED0D7B806 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsB59F2D8189784CC46A4597F2842480B0 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsBC30043663AA2CA4DA1DAA9CA5FDCC75 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsBD746FB95FB8E5B45BF66BE54D5FD91F Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsBF4F885EDEE45644EB1E0C99E0162399 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsCCF399FCD6D2D3F46BF02A1378654FC9 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsCE21F3FD57B244142880EF15A165A156 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsD149C1355C98DE24E82CEFBD996FE06A Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsD15DAF33C220F91468A1D7D57C31ACD7 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsD3BA76A44C779424889063D5098ED2D6 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsD6D0EB9FDBD90C04D92A7E729058F10D Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsDB59FDB786388EA4D897F3EE715683AC Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsDB8DAD19CFBCC2049A4477183787E8C5 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsE1C820A74ED67374BA048B52CB3C3804 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsE4748F9A4181FCE46A23C13B517B9420 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsEC65F200D112357449C8B1BC3CFA03D0 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsF327D0C73C0973644A21E8CC852267A0 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsF754C503375A13344B22388E18DFE87E Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsFA96423FE2B98E248A3B23548D1E22D9 Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ComponentsFDC83385E6C239F4C876A77A37DF581D Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ProductsF479A18A22A86E3429341589FF57D81A Key Found : HKLMSoftwareMicrosoftWindowsCurrentVersionInstallerUserDataS-1-5-18ProductsFA20CB7A821113A4CB8FA1E38E303D3B Key Found : HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstall{889DF117-14D1-44EE-9F31-C5FB5D47F68B} Key Found : HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstall{A7BC02AF-1128-4A31-BCF8-1A3EE803D3B3} Key Found : HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstall{A81A974F-8A22-43E6-9243-5198FF758DA1} Key Found : HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstallAVG Secure Search Key Found : HKLMSOFTWAREMicrosoftWindowsCurrentVersionUninstalluTorrentBar Toolbar Key Found : [email protected]/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Key Found : HKLMSoftwareNCH Software Key Found : HKLMSoftwareSProtector Key Found : HKLMSoftwareTarma Installer Key Found : HKLMSoftwareTrymedia Systems Key Found : HKLMSoftwareuTorrentBar Key Found : HKLMSoftwareWeb Assistant Key Found : HKLMSoftwareYourFileDownloader Value Found : HKCUSoftwareMicrosoftInternet ExplorerToolbarWebBrowser [{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}] Value Found : HKCUSoftwareMicrosoftInternet ExplorerToolbarWebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}] Value Found : HKCUSoftwareMicrosoftInternet ExplorerToolbarWebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}] Value Found : HKCUSoftwareMicrosoftInternet ExplorerToolbarWebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}] Value Found : HKCUSoftwareMicrosoftInternet ExplorerURLSearchHooks [{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}] Value Found : HKCUSoftwareMicrosoftInternet ExplorerURLSearchHooks [{EEE6C35D-6118-11DC-9C72-001320C79847}] Value Found : HKLMSOFTWAREMicrosoftInternet ExplorerToolbar [{3C490BF5-4244-4310-B4A7-3361F288DAC5}] Value Found : HKLMSOFTWAREMicrosoftInternet ExplorerToolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] Value Found : HKLMSOFTWAREMicrosoftInternet ExplorerToolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}] Value Found : HKLMSOFTWAREMicrosoftInternet ExplorerToolbar [{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}] Value Found : HKLMSOFTWAREMicrosoftInternet ExplorerToolbar [{EEE6C35B-6118-11DC-9C72-001320C79847}] Value Found : HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun [vProt] Value Found : HKLMSOFTWAREMozillaFirefoxExtensions [{20a82645-c095-46ed-80e3-08825760534b}] Value Found : HKLMSOFTWAREMozillaFirefoxExtensions [{20a82645-c095-46ed-80e3-08825760534b}] Value Found : HKLMSOFTWAREMozillaFirefoxExtensions [{20a82645-c095-46ed-80e3-08825760534b}] Value Found : HKLMSOFTWAREMozillaFirefoxExtensions [{20a82645-c095-46ed-80e3-08825760534b}] Value Found : HKLMSOFTWAREMozillaFirefoxExtensions [[email protected]] Value Found : HKLMSOFTWAREMozillaFirefoxExtensions [[email protected]] Value Found : HKLMSOFTWAREMozillaFirefoxExtensions [[email protected]] Value Found : HKLMSOFTWAREMozillaFirefoxExtensions [[email protected]] Value Found : HKLMSYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList [C:Program FilesExpressFilesexpressdl.exe] Value Found : HKLMSYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList [C:Program FilesExpressFilesExpressFiles.exe] Value Found : HKLMSYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList [C:Program Filesfacesmoochtbdtuser.exe] Value Found : HKLMSYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList [C:Program FilesYourFileDownloaderDownloader.exe] Value Found : HKLMSYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList [C:Program FilesYourFileDownloaderYourFile.exe] Value Found : HKLMSYSTEMCurrentControlSetServicesSharedAccessParametersFirewallPolicyStandardProfileAuthorizedApplicationsList [C:WINDOWSsystem32ARFCwrtc.exe] ***** [ Browsers ] ***** - Internet Explorer v8.0.6001.18702 - Mozilla Firefox v22.0 (en-US) [ File : C:Documents and SettingsBrunoApplication DataMozillaFirefoxProfilesc0bbqulh.defaultprefs.js ] Line Found : user_pref("aol_toolbar.default.homepage.check", false); Line Found : user_pref("aol_toolbar.default.search.check", false); Line Found : user_pref("avg.install.installDirPath", "C:Documents and SettingsAll UsersApplication DataAVG Secure SearchFireFoxExt15.3.0.11"); Line Found : user_pref("avg.install.userSPSettings", "Search The Web"); Line Found : user_pref("avg.userPreferences.URLBarFocus.whiteList", "bing.com|google.w+|yahoo.w+|gmail.w+|hotmail.w+|live.w+|isearch.avg.com|mysearch.avg.com"); Line Found : user_pref("browser.search.selectedEngine", "Search The Web"); Line Found : user_pref("extensions.BabylonToolbar.prtkDS", 0); Line Found : user_pref("extensions.BabylonToolbar.prtkHmpg", 0); Line Found : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", ""); Line Found : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", ""); Line Found : user_pref("sweetim.toolbar.previous.browser.startup.homepage", ""); Line Found : user_pref("sweetim.toolbar.previous.keyword.URL", ""); Line Found : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", ""); Line Found : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", ""); Line Found : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", ""); Line Found : user_pref("sweetim.toolbar.searchguard.enable", ""); [ File : C:Documents and SettingsPetraaApplication DataMozillaFirefoxProfileswzthyyza.defaultprefs.js ] Line Found : user_pref("aol_toolbar.default.homepage.check", false); Line Found : user_pref("aol_toolbar.default.search.check", false); Line Found : user_pref("avg.install.installDirPath", "C:Documents and SettingsAll UsersApplication DataAVG Secure SearchFireFoxExt14.2.0.1"); Line Found : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com"); Line Found : user_pref("browser.search.defaultenginename", "MyStart Search"); Line Found : user_pref("browser.search.order.1", "Search the web (Babylon)"); Line Found : user_pref("browser.search.selectedEngine", "Search The Web"); Line Found : user_pref("extensions.5023db04d67eb.scode", "(function(){try{if('aol.com,mail.google.com,premiumreports.info,search.babylon.com,search.gboxapp.com'.indexOf(window.self.location.hostname)>-1) return;}c[...] Line Found : user_pref("extensions.BabylonToolbar.admin", false); Line Found : user_pref("extensions.BabylonToolbar.aflt", "babsst"); Line Found : user_pref("extensions.BabylonToolbar.babExt", ""); Line Found : user_pref("extensions.BabylonToolbar.babTrack", "affID=110819&tt=050412_30b"); Line Found : user_pref("extensions.BabylonToolbar.bbDpng", 18); Line Found : user_pref("extensions.BabylonToolbar.dfltLng", "en"); Line Found : user_pref("extensions.BabylonToolbar.dfltSrch", true); Line Found : user_pref("extensions.BabylonToolbar.excTlbr", false); Line Found : user_pref("extensions.BabylonToolbar.hmpg", true); Line Found : user_pref("extensions.BabylonToolbar.id", "64467e62000000000000001d7d5c9254"); Line Found : user_pref("extensions.BabylonToolbar.instlDay", "15444"); Line Found : user_pref("extensions.BabylonToolbar.instlRef", "sst"); Line Found : user_pref("extensions.BabylonToolbar.lastDP", 18); Line Found : user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.5.3.1718:15:56"); Line Found : user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "16.0"); Line Found : user_pref("extensions.BabylonToolbar.newTab", true); Line Found : user_pref("extensions.BabylonToolbar.noFFXTlbr", false); Line Found : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar"); Line Found : user_pref("extensions.BabylonToolbar.propectorlck", 102170485); Line Found : user_pref("extensions.BabylonToolbar.prtkDS", 0); Line Found : user_pref("extensions.BabylonToolbar.prtkHmpg", 1); Line Found : user_pref("extensions.BabylonToolbar.prtnrId", "babylon"); Line Found : user_pref("extensions.BabylonToolbar.ptch_0717", true); Line Found : user_pref("extensions.BabylonToolbar.smplGrp", "tzb"); Line Found : user_pref("extensions.BabylonToolbar.srcExt", "ss"); Line Found : user_pref("extensions.BabylonToolbar.tlbrId", "tb9"); Line Found : user_pref("extensions.BabylonToolbar.vrsn", "1.5.3.17"); Line Found : user_pref("extensions.BabylonToolbar.vrsnTs", "1.5.3.1718:15:56"); Line Found : user_pref("extensions.BabylonToolbar.vrsni", "1.5.3.17"); Line Found : user_pref("extensions.BabylonToolbar_i.aflt", "babsst"); Line Found : user_pref("extensions.BabylonToolbar_i.babExt", ""); Line Found : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110819&tt=050412_30b"); Line Found : user_pref("extensions.BabylonToolbar_i.hardId", "64467e62000000000000001d7d5c9254"); Line Found : user_pref("extensions.BabylonToolbar_i.id", "64467e62000000000000001d7d5c9254"); Line Found : user_pref("extensions.BabylonToolbar_i.instlDay", "15444"); Line Found : user_pref("extensions.BabylonToolbar_i.instlRef", "sst"); Line Found : user_pref("extensions.BabylonToolbar_i.newTab", false); Line Found : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar"); Line Found : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon"); Line Found : user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); Line Found : user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); Line Found : user_pref("extensions.BabylonToolbar_i.tlbrId", "tb9"); Line Found : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17"); Line Found : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1718:15:56"); Line Found : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17"); Line Found : user_pref("extensions.enabledAddons", "[email protected]:1.2.0,[email protected]:1.5.0,{ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.9,{ba23dafc-5a36-4bdd-9d69-ed60da9d6c78}:1.1,{EEE6C361-6118-11D[...] Line Found : user_pref("extensions.incredibar.admin", false); Line Found : user_pref("extensions.incredibar.aflt", "orgnl"); Line Found : user_pref("extensions.incredibar.cntry", "HR"); Line Found : user_pref("extensions.incredibar.dfltLng", ""); Line Found : user_pref("extensions.incredibar.dfltSrch", false); Line Found : user_pref("extensions.incredibar.did", "10650"); Line Found : user_pref("extensions.incredibar.excTlbr", false); Line Found : user_pref("extensions.incredibar.hdrMd5", "8ECBA5165467F70CFFC267D7B6D3C2F1"); Line Found : user_pref("extensions.incredibar.hmpg", false); Line Found : user_pref("extensions.incredibar.id", "64467e62000000000000001d7d5c9254"); Line Found : user_pref("extensions.incredibar.installerproductid", "26"); Line Found : user_pref("extensions.incredibar.instlDay", "15561"); Line Found : user_pref("extensions.incredibar.instlRef", ""); Line Found : user_pref("extensions.incredibar.lastVrsnTs", "1.5.11.1417:52:40"); Line Found : user_pref("extensions.incredibar.newTab", false); Line Found : user_pref("extensions.incredibar.noFFXTlbr", false); Line Found : user_pref("extensions.incredibar.ppd", "201%5F5"); Line Found : user_pref("extensions.incredibar.prdct", "incredibar"); Line Found : user_pref("extensions.incredibar.productid", "26"); Line Found : user_pref("extensions.incredibar.prtnrId", "Incredibar"); Line Found : user_pref("extensions.incredibar.sg", "none"); Line Found : user_pref("extensions.incredibar.smplGrp", "none"); Line Found : user_pref("extensions.incredibar.tlbrId", "base"); Line Found : user_pref("extensions.incredibar.upn2", "6PQG2Pjoor"); Line Found : user_pref("extensions.incredibar.upn2n", "92543376822309155"); Line Found : user_pref("extensions.incredibar.vrsn", "1.5.11.14"); Line Found : user_pref("extensions.incredibar.vrsnTs", "1.5.11.1417:52:40"); Line Found : user_pref("extensions.incredibar.vrsni", "1.5.11.14"); Line Found : user_pref("extensions.incredibar_i.aflt", "orgnl"); Line Found : user_pref("extensions.incredibar_i.dfltLng", ""); Line Found : user_pref("extensions.incredibar_i.did", "10650"); Line Found : user_pref("extensions.incredibar_i.excTlbr", false); Line Found : user_pref("extensions.incredibar_i.id", "64467e62000000000000001d7d5c9254"); Line Found : user_pref("extensions.incredibar_i.installerproductid", "26"); Line Found : user_pref("extensions.incredibar_i.instlDay", "15561"); Line Found : user_pref("extensions.incredibar_i.instlRef", ""); Line Found : user_pref("extensions.incredibar_i.ms_url_id", ""); Line Found : user_pref("extensions.incredibar_i.newTab", false); Line Found : user_pref("extensions.incredibar_i.ppd", "201%5F5"); Line Found : user_pref("extensions.incredibar_i.prdct", "incredibar"); Line Found : user_pref("extensions.incredibar_i.productid", "26"); Line Found : user_pref("extensions.incredibar_i.prtnrId", "Incredibar"); Line Found : user_pref("extensions.incredibar_i.smplGrp", "none"); Line Found : user_pref("extensions.incredibar_i.tlbrId", "base"); Line Found : user_pref("extensions.incredibar_i.upn2", "6PQG2Pjoor"); Line Found : user_pref("extensions.incredibar_i.upn2n", "92543376822309155"); Line Found : user_pref("extensions.incredibar_i.vrsn", "1.5.11.14"); Line Found : user_pref("extensions.incredibar_i.vrsnTs", "1.5.11.1417:52:40"); Line Found : user_pref("extensions.incredibar_i.vrsni", "1.5.11.14"); Line Found : user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0"); Line Found : user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7"); Line Found : user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log"); Line Found : user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000"); Line Found : user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7"); Line Found : user_pref("sweetim.toolbar.mode.debug", "false"); Line Found : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", ""); Line Found : user_pref("sweetim.toolbar.previous.browser.search.defaulturl", ""); Line Found : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", ""); Line Found : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", ""); Line Found : user_pref("sweetim.toolbar.search.history.capacity", "10"); Line Found : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_DS", ""); Line Found : user_pref("sweetim.toolbar.searchguard.UserRejectedGuard_HP", ""); Line Found : user_pref("sweetim.toolbar.searchguard.enable", ""); Line Found : user_pref("sweetim.toolbar.simapp_id", "{06BC8253-E3CA-11E0-B9D7-001D7D5C9254}"); Line Found : user_pref("sweetim.toolbar.version", "1.2.0.2"); [ File : C:Documents and SettingsAdministratorApplication DataMozillaFirefoxProfiles5gozow0a.defaultprefs.js ] Line Found : user_pref("aol_toolbar.default.homepage.check", false); Line Found : user_pref("aol_toolbar.default.search.check", false); Line Found : user_pref("avg.install.installDirPath", "C:Documents and SettingsAll UsersApplication DataAVG Secure Search12.2.5.32"); Line Found : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com"); Line Found : user_pref("browser.search.defaultenginename", "SweetIM Search"); Line Found : user_pref("browser.search.defaultthis.engineName", "uTorrentBar Customized Web Search"); Line Found : user_pref("browser.search.selectedEngine", "uTorrentBar Customized Web Search"); Line Found : user_pref("extensions.5023db04d67eb.scode", "(function(){try{if('aol.com,mail.google.com,mystart.incredibar.com,premiumreports.info,search.babylon.com,search.funmoods.com,search.gboxapp.com,search.swe[...] Line Found : user_pref("extensions.50eecf0c7a25e.scode", "(function(){if(window.self.location.hostname.indexOf("acebook.co")>-1){return};if(window.self.location.protocol.i
  10. Okay, done. DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.25.2 Run by Administrator at 20:37:29 on 2013-12-18 Microsoft Windows XP Professional 5.1.2600.3.1250.385.1033.18.2047.550 [GMT 1:00] . AV: AVG Anti-Virus Free Edition 2012 *Enabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} . ============== Running Processes ================ . ??C:PROGRA~1AVGAVG2012avgrsx.exe ??C:Program FilesAVGAVG2012avgcsrvx.exe C:WINDOWSsystem32Ati2evxx.exe C:Program FilesAVAST SoftwareAvastAvastSvc.exe C:WINDOWSsystem32Ati2evxx.exe C:WINDOWSsystem32spoolsv.exe C:WINDOWSExplorer.EXE C:Program FilesAVGAVG2012avgwdsvc.exe C:Program FilesJavajre7binjqs.exe C:Program FilesLogMeIn HamachiLMIGuardianSvc.exe d:gMalwarebytes' Anti-Malwarembamscheduler.exe d:gMalwarebytes' Anti-Malwarembamservice.exe C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE d:gMalwarebytes' Anti-Malwarembamgui.exe C:Program FilesRealNetworksRealDownloaderrndlresolversvc.exe C:Program FilesCyberLinkShared filesRichVideo.exe C:Program FilesMicrosoft Application Virtualization Clientsftvsa.exe C:Program FilesUPHCleanuphclean.exe C:Program FilesCommon FilesAVG Secure SearchvToolbarUpdater17.2.0ToolbarUpdater.exe C:Program FilesAVGAVG2012avgnsx.exe C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSVC.EXE C:Program FilesCommon FilesAVG Secure SearchvToolbarUpdater17.2.0loggingserver.exe C:Program FilesLogMeIn Hamachihamachi-2.exe C:Program FilesAVGAVG2012AVGIDSAgent.exe C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSvcM.exe C:WINDOWSSystem32alg.exe C:WINDOWSsystem32wuauclt.exe C:WINDOWSRTHDCPL.EXE C:Program FilesD-LinkAirPlus GAirGCFG.exe C:Program FilesANIANIWZCS2 ServiceWZCSLDR2.exe C:Program FilesDivXDivX UpdateDivXUpdate.exe C:Program FilesAVGAVG2012avgtray.exe C:Program FilesAVG Secure Searchvprot.exe C:Program FilesCommon FilesAdobeARM1.0AdobeARM.exe C:program filesrealrealplayerupdaterealsched.exe C:Program FilesAVAST SoftwareAvastavastUI.exe C:Program FilesCommon FilesJavaJava Updatejusched.exe C:Program FilesLogMeIn Hamachihamachi-2-ui.exe C:WINDOWSsystem32ctfmon.exe C:Program FilesMessengermsmsgs.exe C:Program FilesuTorrentuTorrent.exe C:Program FilesSkypePhoneSkype.exe C:Program FilesMagicDiscMagicDisc.exe C:Program FilesCommon FilesJavaJava Updatejucheck.exe C:Program FilesGoogleChromeApplicationchrome.exe C:Program FilesGoogleChromeApplicationchrome.exe C:Program FilesGoogleChromeApplicationchrome.exe C:Program FilesGoogleChromeApplicationchrome.exe C:Program FilesGoogleChromeApplicationchrome.exe C:Program FilesGoogleChromeApplicationchrome.exe C:Program FilesGoogleChromeApplicationchrome.exe C:Program FilesGoogleChromeApplicationchrome.exe C:Program FilesGoogleChromeApplicationchrome.exe C:Program FilesGoogleChromeApplicationchrome.exe C:Program FilesGoogleChromeApplicationchrome.exe C:Program FilesGoogleChromeApplicationchrome.exe C:WINDOWSsystem32wbemwmiprvse.exe C:WINDOWSSystem32svchost.exe -k netsvcs C:WINDOWSsystem32svchost.exe -k WudfServiceGroup C:WINDOWSsystem32svchost.exe -k NetworkService C:WINDOWSsystem32svchost.exe -k LocalService C:WINDOWSsystem32svchost.exe -k LocalService C:WINDOWSSystem32svchost.exe -k Akamai C:WINDOWSsystem32svchost.exe -k imgsvc . ============== Pseudo HJT Report =============== . uURLSearchHooks: {EEE6C35D-6118-11DC-9C72-001320C79847} - <orphaned> uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:program filesutorrentbarprxtbuTo0.dll BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:program filescommon filesadobeacrobatactivexAcroIEHelperShim.dll BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:documents and settingsall usersapplication datarealnetworksrealdownloaderbrowserpluginsierndlbrowserrecordplugin.dll BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - c:program filesavgavg2012avgssie.dll BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:program filesjavajre7binssv.dll BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:program filesavast softwareavastaswWebRepIE.dll BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:program filescommon filesmicrosoft sharedwindows liveWindowsLiveLogin.dll BHO: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:program filesavg secure search17.2.0.38AVG Secure Search_toolbar.dll BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:program filesgooglegoogle toolbarGoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:program filesgooglegoogletoolbarnotifier5.7.9012.1008swg.dll BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:program filesutorrentbarprxtbuTo0.dll BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:program filesjavajre7binjp2ssv.dll BHO: Yontoo: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - c:program filesyontooYontooIEClient.dll TB: RadioBar Toolbar: {5B291E6C-9A74-4034-971B-A4B007A0B315} - LocalServer32 - <no file> TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:program filesgooglegoogle toolbarGoogleToolbar_32.dll TB: <No Name>: {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - LocalServer32 - <no file> TB: uTorrentBar Toolbar: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - c:program filesutorrentbarprxtbuTo0.dll TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:program filesavg secure search17.2.0.38AVG Secure Search_toolbar.dll TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:program filesutorrentbarprxtbuTo0.dll TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:program filesavast softwareavastaswWebRepIE.dll TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:program filesgooglegoogle toolbarGoogleToolbar_32.dll uRun: [ctfmon.exe] c:windowssystem32ctfmon.exe uRun: [Google Update] "c:documents and settingsadministratorlocal settingsapplication datagoogleupdateGoogleUpdate.exe" /c uRun: [swg] "c:program filesgooglegoogletoolbarnotifierGoogleToolbarNotifier.exe" uRun: [MSMSGS] "c:program filesmessengermsmsgs.exe" /background uRun: [Facebook Update] "c:documents and settingsadministratorlocal settingsapplication datafacebookupdateFacebookUpdate.exe" /c /nocrashserver uRun: [uTorrent] "c:program filesutorrentuTorrent.exe" /MINIMIZED uRun: [skype] "c:program filesskypephoneSkype.exe" /minimized /regrun uRun: [steam] "c:program filessteamsteam.exe" -silent uRun: [PC Suite Tray] "c:program filesnokianokia pc suite 7PCSuite.exe" -onlytray uRun: [EvolveClient] "c:program filesechobitevolveEvolveClient.exe" -autorun mRun: [RTHDCPL] RTHDCPL.EXE mRun: [LanguageShortcut] "c:program filescyberlinkpowerdvdlanguageLanguage.exe" mRun: [D-Link AirPlus G] c:program filesd-linkairplus gAirGCFG.exe mRun: [ANIWZCS2Service] c:program filesanianiwzcs2 serviceWZCSLDR2.exe mRun: [DivXUpdate] "c:program filesdivxdivx updateDivXUpdate.exe" /CHECKNOW mRun: [AVG_TRAY] "c:program filesavgavg2012avgtray.exe" mRun: [NokiaMServer] c:program filescommon filesnokiamplatformNokiaMServer /watchfiles startup mRun: [vProt] "c:program filesavg secure searchvprot.exe" mRun: [Adobe Reader Speed Launcher] "c:program filesadobereader 9.0readerReader_sl.exe" mRun: [Adobe ARM] "c:program filescommon filesadobearm1.0AdobeARM.exe" mRun: [TkBellExe] "c:program filesrealrealplayerupdaterealsched.exe" -osboot mRun: [avast] "c:program filesavast softwareavastavastUI.exe" /nogui mRun: [AdobeAAMUpdater-1.0] "c:program filescommon filesadobeoobepdappuwaUpdaterStartupUtility.exe" mRun: [switchBoard] c:program filescommon filesadobeswitchboardSwitchBoard.exe mRun: [AdobeCS6ServiceManager] "c:program filescommon filesadobecs6servicemanagerCS6ServiceManager.exe" -launchedbylogin mRun: [MSIAfterburner] "c:program filesmsi afterburnerMSIAfterburner.exe" /s mRun: [sunJavaUpdateSched] "c:program filescommon filesjavajava updatejusched.exe" mRun: [20131121] c:program filesavast softwareavastsetupemupdate5cfa0952-aa0e-44c3-b578-4d6941337895.exe /check mRun: [LogMeIn Hamachi Ui] "c:program fileslogmein hamachihamachi-2-ui.exe" --auto-start mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBBAFYARgBSAEUARQAtAFYAMABLAE0AQwAtAEUAOQBWAFUAVwAtAEUAVwAwAFYAQQAtAFUAVQAzAFgATAAtAEYARQBXADkANwA"&"inst=NwA3AC0ANQA5ADcAOQAxADQAMQA5ADgALQBGAEwAKwA5AC0AWABPADkAKwAxAC0AWABPADMANgArADEA"&"prod=90"&"ver=9.0.872 dRun: [ctfmon.exe] c:windowssystem32CTFMON.EXE StartupFolder: c:docume~1admini~1startm~1programsstartupmagicd~1.lnk - c:program filesmagicdiscMagicDisc.exe StartupFolder: c:docume~1alluse~1startm~1programsstartupmicros~1.lnk - c:program filesmicrosoft officeoffice10OSA.EXE uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: NoDriveTypeAutoRun = dword:145 IE: E&xport to Microsoft Excel - c:progra~1micros~2office10EXCEL.EXE/3000 IE: Search the Web - c:program filessweetimtoolbarsinternet explorerresourcesmenuext.html IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:program filesmessengermsmsgs.exe TCP: NameServer = 83.139.104.2 83.139.105.2 TCP: Interfaces{9F532E7A-D2E6-4832-8A7E-976ACA85AE9C} : DHCPNameServer = 192.168.1.1 TCP: Interfaces{DD7927E4-10E5-4104-9AC0-5963CD4B0215} : DHCPNameServer = 83.139.104.2 83.139.105.2 TCP: Interfaces{EF775A33-B11B-4473-926D-D70AD9A08E75} : NameServer = 195.29.166.116,195.29.166.117 Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:program filescommon filesmicrosoft sharedweb foldersPKMCDO.DLL Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:program filesavgavg2012avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:program filescommon filesskypeSkype4COM.dll Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:program filescommon filesavg secure searchviprotocolinstaller17.2.0ViProtocol.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: LMIinit - LMIinit.dll AppInit_DLLs= c:progra~1contin~1sprote~1.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:windowssystem32WPDShServiceObj.dll mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:program filesgooglechromeapplication31.0.1650.63installerchrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome Hosts: 127.0.0.1 mpa.one.microsoft.com . ================= FIREFOX =================== . FF - ProfilePath - c:documents and settingsadministratorapplication datamozillafirefoxprofiles5gozow0a.default FF - prefs.js: browser.search.selectedEngine - uTorrentBar Customized Web Search FF - prefs.js: browser.startup.homepage - www.google.com FF - prefs.js: network.proxy.type - 0 FF - plugin: c:documents and settingsadministratorapplication datamozillapluginsnp-mswmp.dll FF - plugin: c:documents and settingsadministratorlocal settingsapplication datafacebookvideoskypenpFacebookVideoCalling.dll FF - plugin: c:documents and settingsadministratorlocal settingsapplication datagoogleupdate1.3.22.3npGoogleUpdate3.dll FF - plugin: c:documents and settingsadministratorlocal settingsapplication dataunitywebplayerloadernpUnity3D32.dll FF - plugin: c:documents and settingsall usersapplication dataid softwarequakelivenpquakezero.dll FF - plugin: c:documents and settingsall usersapplication datanexonusngmnpNxGameUS.dll FF - plugin: c:documents and settingsall usersapplication datarealnetworksrealdownloaderbrowserpluginsmozillapluginsnprndlchromebrowserrecordext.dll FF - plugin: c:documents and settingsall usersapplication datarealnetworksrealdownloaderbrowserpluginsmozillapluginsnprndlhtml5videoshim.dll FF - plugin: c:documents and settingsall usersapplication datarealnetworksrealdownloaderbrowserpluginsmozillapluginsnprndlpepperflashvideoshim.dll FF - plugin: c:documents and settingsall usersapplication datarealnetworksrealdownloaderbrowserpluginsnpdlplugin.dll FF - plugin: c:progra~1micros~2office14NPSPWRAP.DLL FF - plugin: c:program filesadobereader 9.0readerairnppdf32.dll FF - plugin: c:program filescommon filesadobeoobepdappccmutilitiesnpAdobeAAMDetect32.dll FF - plugin: c:program filescommon filesadobeoobepdappccmutilitiesnpAdobeAAMDetect64.dll FF - plugin: c:program filescommon filesavg secure searchsitesafetyinstaller17.2.0npsitesafety.dll FF - plugin: c:program filesdivxdivx plus web playernpdivx32.dll FF - plugin: c:program filesgoogleupdate1.3.22.3npGoogleUpdate3.dll FF - plugin: c:program filesjavajre7binplugin2npjp2.dll FF - plugin: c:program filesonlivepluginnpolgdet.dll FF - plugin: c:program filespando networksmedia boosternpPandoWebPlugin.dll FF - plugin: c:program filesrealrealplayernetscape6nprpplugin.dll FF - plugin: c:windowssystem32adobedirectornp32dsw_1166636.dll FF - plugin: c:windowssystem32macromedflashNPSWF32_11_9_900_170.dll FF - plugin: c:windowssystem32npDeployJava1.dll FF - plugin: c:windowssystem32npptools.dll FF - plugin: c:windowssystem32npwmsdrm.dll FF - ExtSQL: 2013-11-11 08:50; [email protected]; c:documents and settingsadministratorapplication datamozill[email protected]weliketheweb.com FF - ExtSQL: !HIDDEN! 2010-02-22 08:31; {20a82645-c095-46ed-80e3-08825760534b}; c:windowsmicrosoft.netframeworkv3.5windows presentation foundationDotNetAssistantExtension . ---- FIREFOX POLICIES ---- FF - user.js: extentions.y2layers.installId - 54e204f7-d79d-4f75-a144-86b5eacc967e FF - user.js: extentions.y2layers.defaultEnableAppsList - DropDownDeals,buzzdock,YontooNewOffers . FF - user.js: extensions.autoDisableScopes - 14 . ============= SERVICES / DRIVERS =============== . R0 aswRvrt;aswRvrt;c:windowssystem32driversaswRvrt.sys [2013-5-10 49376] R0 aswVmm;aswVmm;c:windowssystem32driversaswVmm.sys [2013-5-10 175176] R0 AVGIDSEH;AVGIDSEH;c:windowssystem32driversAVGIDSEH.sys [2011-2-22 23120] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:windowssystem32driversavgrkx86.sys [2011-1-19 32592] R1 aswSnx;aswSnx;c:windowssystem32driversaswSnx.sys [2013-5-10 770344] R1 aswSP;aswSP;c:windowssystem32driversaswSP.sys [2013-5-10 369584] R1 Avgldx86;AVG AVI Loader Driver;c:windowssystem32driversavgldx86.sys [2011-1-7 230608] R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:windowssystem32driversavgmfx86.sys [2011-3-1 40016] R1 Avgtdix;AVG TDI Driver;c:windowssystem32driversavgtdix.sys [2011-2-10 295248] R1 avgtp;avgtp;c:windowssystem32driversavgtpx86.sys [2012-8-30 37664] R2 Akamai;Akamai NetSession Interface;c:windowssystem32svchost.exe -k Akamai [2008-4-14 14336] R2 aswFsBlk;aswFsBlk;c:windowssystem32driversaswFsBlk.sys [2013-5-10 29816] R2 aswMonFlt;aswMonFlt;c:windowssystem32driversaswMonFlt.sys [2013-5-10 66336] R2 avast! Antivirus;avast! Antivirus;c:program filesavast softwareavastAvastSvc.exe [2013-5-10 46808] R2 AVGIDSAgent;AVGIDSAgent;c:program filesavgavg2012AVGIDSAgent.exe [2011-10-12 4433248] R2 avgwd;AVG WatchDog;c:program filesavgavg2012avgwdsvc.exe [2011-8-2 192776] R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:program fileslogmein hamachihamachi-2.exe [2013-11-29 1664336] R2 LMIGuardianSvc;LMIGuardianSvc;c:program fileslogmein hamachiLMIGuardianSvc.exe [2013-10-11 375056] R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:windowssystem32driversLMIRfsDriver.sys [2012-12-8 47640] R2 MBAMScheduler;MBAMScheduler;d:gmalwarebytes' anti-malwarembamscheduler.exe [2013-11-10 418376] R2 MBAMService;MBAMService;d:gmalwarebytes' anti-malwarembamservice.exe [2013-11-10 701512] R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:program filesrealnetworksrealdownloaderrndlresolversvc.exe [2013-3-6 39056] R2 vToolbarUpdater17.2.0;vToolbarUpdater17.2.0;c:program filescommon filesavg secure searchvtoolbarupdater17.2.0ToolbarUpdater.exe [2013-12-10 1771544] R3 AVGIDSDriver;AVGIDSDriver;c:windowssystem32driversAVGIDSDriver.sys [2011-3-30 134608] R3 AVGIDSFilter;AVGIDSFilter;c:windowssystem32driversAVGIDSFilter.sys [2011-2-10 24272] R3 AVGIDSShim;AVGIDSShim;c:windowssystem32driversAVGIDSShim.sys [2011-2-10 16720] R3 EvolveVirtualAdapter;Evolve Virtual Miniport Driver;c:windowssystem32driversevolve.sys [2013-8-2 18584] R3 MBAMProtector;MBAMProtector;c:windowssystem32driversmbam.sys [2011-3-27 22856] R3 RTCore32;RTCore32;c:program filesmsi afterburnerRTCore32.sys [2011-9-6 5632] R3 Sftfs;Sftfs;c:windowssystem32driversSftfsxp.sys [2009-12-2 587944] R3 Sftplay;Sftplay;c:windowssystem32driversSftplayxp.sys [2009-12-2 213288] R3 Sftvol;Sftvol;c:windowssystem32driversSftvolxp.sys [2009-12-2 19112] R3 sftvsa;Application Virtualization Service Agent;c:program filesmicrosoft application virtualization clientsftvsa.exe [2013-6-26 207528] R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:windowssystem32driverstap0901t.sys [2012-4-2 27136] R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:windowssystem32driversvcsvad.sys [2013-9-6 17792] R3 voxaldriver;Voxal Filter Driver 2.12.00;c:windowssystem32driversvoxaldriverx86.sys [2013-9-5 43344] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:windowsmicrosoft.netframeworkv4.0.30319mscorsvw.exe [2010-3-18 130384] S2 cvhsvc;Client Virtualization Handler;c:program filescommon filesmicrosoft sharedvirtualization handlerCVHSVC.EXE [2013-4-22 822504] S2 sftlist;Application Virtualization Client;c:program filesmicrosoft application virtualization clientsftlist.exe [2013-6-26 523944] S2 SkypeUpdate;Skype Updater;c:program filesskypeupdaterUpdater.exe [2013-9-5 171680] S2 xthxbdrbrxtccdiwenti;xthxbdrbrxtccdiwenti;c:windowssystem32svchost.exe -k netsvcs [2008-4-14 14336] S3 AF9035BDA;AF9035 BDA Devices;c:windowssystem32driversAF9035BDA.sys [2010-10-29 459776] S3 Ambfilt;Ambfilt;c:windowssystem32driversAmbfilt.sys [2010-2-17 1691480] S3 EagleXNt;EagleXNt;??c:windowssystem32driverseaglexnt.sys --> c:windowssystem32driversEagleXNt.sys [?] S3 EvoSvc;Evolve Service;c:program filesechobitevolveEvoSvc.exe [2013-8-2 1570208] S3 FairplayKD;FairplayKD;??c:documents and settingsall usersapplication datamta san andreas all1.3tempfairplaykd.sys --> c:documents and settingsall usersapplication datamta san andreas all1.3tempFairplayKD.sys [?] S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:windowssystem32driversnmwcdnsu.sys [2011-9-10 137600] S3 nmwcdnsuc;Nokia USB Flashing Generic;c:windowssystem32driversnmwcdnsuc.sys [2011-9-10 8576] S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:windowssystem32driversScreamingBAudio.sys [2012-7-31 34896] S3 Sftredir;Sftredir;c:windowssystem32driversSftredirxp.sys [2009-12-2 23208] S3 SwitchBoard;Adobe SwitchBoard;c:program filescommon filesadobeswitchboardSwitchBoard.exe [2010-2-19 517096] S3 tenCapture;tenCapture;c:windowssystem32driverstenCapture.sys [2013-9-5 20664] S3 TunngleService;TunngleService;c:program filestunngleTnglCtrl.exe [2013-5-19 746392] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:windowsmicrosoft.netframeworkv4.0.30319wpfWPFFontCache_v0400.exe [2013-7-20 754856] S4 LMIRfsClientNP;LMIRfsClientNP; [x] . =============== Created Last 30 ================ . 2013-12-17 15:25:25 -------- d-----w- c:program filestrend micro 2013-12-17 14:48:18 -------- d-----w- c:program filesCCleaner 2013-12-17 14:37:18 -------- d-----w- c:documents and settingsadministratorlocal settingsapplication dataLogMeIn 2013-12-17 14:32:04 -------- d-----w- c:program filesCONTIN~1 2013-12-17 05:43:28 -------- d-----w- c:program filesLogMeIn Hamachi 2013-12-02 12:07:10 409600 ----a-w- c:windowssystem32activelock1884.ocx 2013-11-24 10:41:45 -------- d-----w- c:documents and settingsadministratorlocal settingsapplication dataOrigin 2013-11-23 18:40:40 696320 ----a-w- c:program filescommon filesinstallshieldprofessionalruntime0701intel32iKernel.dll 2013-11-23 18:40:40 57344 ----a-w- c:program filescommon filesinstallshieldprofessionalruntime0701intel32ctor.dll 2013-11-23 18:40:40 5632 ----a-w- c:program filescommon filesinstallshieldprofessionalruntime0701intel32DotNetInstaller.exe 2013-11-23 18:40:40 237568 ----a-w- c:program filescommon filesinstallshieldprofessionalruntime0701intel32iscript.dll 2013-11-23 18:40:40 155648 ----a-w- c:program filescommon filesinstallshieldprofessionalruntime0701intel32iuser.dll 2013-11-23 18:40:38 163972 ----a-w- c:program filescommon filesinstallshieldprofessionalruntime0701intel32iGdi.dll 2013-11-23 18:40:37 282756 ----a-w- c:program filescommon filesinstallshieldprofessionalruntime0701intel32setup.dll 2013-11-23 13:20:31 -------- d-----w- c:program filescommon filesDirectX 2013-11-23 13:20:11 -------- d-----w- c:documents and settingsall usersapplication dataAirline Tycoon 2 2013-11-20 15:42:22 -------- d-----w- c:documents and settingsadministrator3079Saves . ==================== Find3M ==================== . 2013-12-10 21:08:15 71048 ----a-w- c:windowssystem32FlashPlayerCPLApp.cpl 2013-12-10 21:08:15 692616 ----a-w- c:windowssystem32FlashPlayerApp.exe 2013-11-13 02:59:42 150528 ----a-w- c:windowssystem32imagehlp.dll 2013-11-12 07:20:33 37664 ----a-w- c:windowssystem32driversavgtpx86.sys 2013-11-10 15:52:25 61 ----a-w- c:windowssystem32SYSVCDRV.SYS 2013-11-10 15:46:57 43344 ----a-w- c:windowssystem32driversvoxaldriverx86.sys 2013-11-07 05:38:51 591360 ----a-w- c:windowssystem32rpcrt4.dll 2013-11-06 01:03:31 7168 ----a-w- c:windowssystem32xpsp4res.dll 2013-10-30 02:26:17 1879040 ----a-w- c:windowssystem32win32k.sys 2013-10-29 07:57:34 920064 ----a-w- c:windowssystem32wininet.dll 2013-10-29 07:57:33 43520 ----a-w- c:windowssystem32licmgr10.dll 2013-10-29 07:57:33 18944 ----a-w- c:windowssystem32corpol.dll 2013-10-29 07:57:33 1469440 ----a-w- c:windowssystem32inetcpl.cpl 2013-10-29 00:45:02 385024 ----a-w- c:windowssystem32html.iec 2013-10-23 23:45:49 172032 ----a-w- c:windowssystem32scrrun.dll 2013-10-15 08:58:14 27136 ----a-w- c:windowssystem32ImHttpComm.dll 2013-10-12 15:56:19 278528 ----a-w- c:windowssystem32oakley.dll 2013-10-09 13:12:48 287744 ----a-w- c:windowssystem32gdi32.dll 2013-10-07 10:59:21 603136 ----a-w- c:windowssystem32crypt32.dll 2013-09-30 15:53:04 632656 ----a-w- c:windowssystem32msvcr80.dll 2013-09-30 15:53:04 554832 ----a-w- c:windowssystem32msvcp80.dll 2013-09-30 15:53:04 479232 ----a-w- c:windowssystem32msvcm80.dll . ============= FINISH: 20:39:54,07 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows XP Professional Boot Device: DeviceHarddiskVolume1 Install Date: 17.2.2010 10:19:05 System Uptime: 18.12.2013 6:34:52 (14 hours ago) . Motherboard: Gigabyte Technology Co., Ltd. | | M52L-S3 Processor: AMD Athlon 64 X2 Dual Core Processor 5600+ | Socket M2 | 2913/200mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 103 GiB total, 7,954 GiB free. D: is FIXED (NTFS) - 196 GiB total, 82,051 GiB free. E: is CDROM () F: is CDROM () G: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP34: 2.12.2013 16:44:53 - Removed TheSims3EP7 RP35: 2.12.2013 16:47:13 - Removed The Sims 3 RP36: 2.12.2013 16:54:12 - Installed The Sims 3 RP37: 2.12.2013 17:21:10 - Installed The Sims 3 RP38: 2.12.2013 17:39:56 - Removed The Sims 3 RP39: 2.12.2013 17:44:27 - Installed The Sims 3 RP40: 2.12.2013 18:06:33 - Installed The Sims 3 RP41: 2.12.2013 18:11:49 - Installed TheSims3EP8 RP42: 2.12.2013 18:23:40 - Installed TheSims3EP7 RP43: 3.12.2013 18:38:01 - System Checkpoint RP44: 4.12.2013 22:27:32 - System Checkpoint RP45: 6.12.2013 7:19:11 - System Checkpoint RP46: 7.12.2013 19:48:27 - System Checkpoint RP47: 8.12.2013 17:44:42 - Installed The Sims 3 Ambitions RP48: 8.12.2013 20:45:27 - Installed The Sims 3 RP49: 8.12.2013 20:57:33 - Installed TheSims3EP9 RP50: 10.12.2013 10:01:47 - System Checkpoint RP51: 10.12.2013 10:59:20 - Removed Sid Mieir's Railroads RP52: 10.12.2013 11:00:49 - Installed DirectX RP53: 10.12.2013 11:01:33 - Installed Sid Meier's Railroads! RP54: 11.12.2013 21:29:15 - System Checkpoint RP55: 12.12.2013 11:26:01 - Configured Sid Meier's Railroads! RP56: 12.12.2013 22:41:33 - Software Distribution Service 3.0 RP57: 13.12.2013 18:01:31 - Software Distribution Service 3.0 RP58: 14.12.2013 23:14:28 - Removed Fallout 3 RP59: 14.12.2013 23:18:11 - Installed DirectX RP60: 14.12.2013 23:20:54 - Installed Fallout 3 RP61: 16.12.2013 18:07:46 - System Checkpoint RP62: 17.12.2013 20:36:58 - System Checkpoint . ==== Installed Programs ====================== . 3D Snow version 4.2 7-Zip 4.57 ACDSee 10 Photo Manager Adobe AIR Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Flash Professional CS6 Adobe Help Manager Adobe Photoshop CS6 Adobe Reader 9.5.2 - Croatian Adobe Shockwave Player 11.6 Advertising Center AirPlus G Akamai NetSession Interface Service Alat za učitavanje Windows Live ANIO Service ANIWZCS2 Service Anno 1701 Any Video Converter 5.0.6 Any Video Converter Professional 3.6.0 ATI Display Driver µTorrent avast! Free Antivirus AVG 2012 AVG Security Toolbar AVI ReComp 1.5.3 AviSynth 2.5 Bandisoft MPEG-1 Decoder Battlefield 2 Demo Black & White® 2 Black & White® 2 Battle of the Gods BS.Player PRO Casino Tycoon CCleaner Cheat Engine 6.2 Compatibility Pack for the 2007 Office system ContinueToSave Democracy 3 Democracy 3 sex education Mod DolbyFiles Door Kickers Lite Driver Genius Enemy Territory - QUAKE Wars Euro Truck Simulator 2 v1.3.1 Evolve Express Burn Facebook Video Calling 1.2.0.287 Fallout 3 Fallout 3 - The Garden of Eden Creation Kit Fallout Mod Manager 0.13.21 Fallout2 Fate of the World: Tipping Point 1.1 FileZilla Client 3.6.0.2 FinalAlert 2 Yuri's Revenge Fraps (remove only) Free MP4 Video Converter version 5.0.7.403 Freeciv 2.3.2 (GTK+ client) FreeFox FileBulldog Toolbar FTL version 1.03.3 Game Dev Tycoon v1.3.2 © Greenheart Games version 1 Garry's Mod Glary Utilities 2.41.0.1358 Google Chrome Google Toolbar for Internet Explorer Google Update Helper GTA San Andreas Half-Life 2 HandBrake 0.9.9.1 Hitman Blood Money Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB928788) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Format 11 SDK (KB929773) Hotfix for Windows Media Format 11 SDK (KB932390) Hotfix for Windows Media Format 11 SDK (KB933547) Hotfix for Windows Media Format 11 SDK (KB935551) Hotfix for Windows Media Format 11 SDK (KB935552) Hotfix for Windows Media Format 11 SDK (KB939209) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows Media Player 11 (KB944882) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB2570791) Hotfix for Windows XP (KB2633952) Hotfix for Windows XP (KB2756822) Hotfix for Windows XP (KB2779562) Hotfix for Windows XP (KB932716-v2) Hotfix for Windows XP (KB942288-v3) Hotfix for Windows XP (KB944043-v3) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB954708) Hotfix for Windows XP (KB958655-v2) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB969084) Hotfix for Windows XP (KB976002-v5) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB981793) IcoFX 1.5 iCoolsoft Sansa Converter ImagXpress Java 7 Update 25 Java Auto Updater Java 6 Update 18 Java 6 Update 31 JavaFX 2.1.1 K-Lite Codec Pack 7.9.0 (Basic) LogMeIn Hamachi MagicDisc 2.7.106 Malwarebytes Anti-Malware version 1.75.0.1300 Mass Effect™ 3 mediAvatar Video Converter Pro Menu Templates - Starter Kit Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2698023) Microsoft .NET Framework 1.1 Security Update (KB2833941) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Extended Microsoft Application Error Reporting Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Choice Guard Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Games for Windows - LIVE Redistributable Microsoft Games for Windows Marketplace Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 Microsoft Office Click-to-Run 2010 Microsoft Office File Validation Add-In Microsoft Office FrontPage 2003 Microsoft Office Home and Business 2010 - English Microsoft Office Professional Edition 2003 Microsoft Office XP Professional with FrontPage Microsoft Software Update for Web Folders (English) 12 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 Microsoft WSE 3.0 Runtime Microsoft XNA Framework Redistributable 3.0 Microsoft XNA Framework Redistributable 3.1 Microsoft XNA Framework Redistributable 4.0 Refresh Microsoft_VC80_CRT_x86 Microsoft_VC90_CRT_x86 Moj paradies fotosvijet Movie Templates - Starter Kit Mozilla Firefox 22.0 (x86 en-US) Mozilla Maintenance Service MP3 Encoder v1.0 MSI Afterburner 2.3.1 MSVC80_x86 MSVCRT MSXML 4.0 SP3 Parser (KB2721691) MSXML 4.0 SP3 Parser (KB2758694) MSXML 4.0 SP3 Parser (KB973685) MSXML4 Parser Multiplayer Monopoly Online Game MUSHclient (remove only) Nero 8 Lite 8.1.1.3 Nero 9 Lite Nero BurningROM Nero ControlCenter Nero CoverDesigner Nero CoverDesigner Help Nero Installer Nero StartSmart NeroBurningROM neroxml Nexon Game Manager Nexus Mod Manager Nokia Connectivity Cable Driver Nokia Ovi Player Nokia PC Suite Nokia_Multimedia_Common_Components_2_5 NVIDIA Drivers NVIDIA PhysX OnLive OpenAL Origin osu! Pando Media Booster PAYDAY 2 Beta PC Connectivity Solution PCSX2 - Playstation 2 Emulator PDF Settings CS6 Poke PowerDVD Quake Live Mozilla Plugin Race The Sun 1.0 Railroad Tycoon 3 REACTOR Real Lives 2010 RealDownloader RealNetworks - Microsoft Visual C++ 2008 Runtime RealNetworks - Microsoft Visual C++ 2010 Runtime RealPlayer Realtek High Definition Audio Driver RealUpgrade 1.1 RecordPad Sound Recorder Redshirt Rise Of Legends Rise of Nations RPG Maker VX Ace RPG MAKER VX Ace Lite RPG Maker VX RTP SAMSUNG CDMA Modem Driver Set SAMSUNG Mobile Composite Device Software Samsung Mobile phone USB driver Software SAMSUNG Mobile USB Modem 1.0 Software SAMSUNG Mobile USB Modem Software Samsung PC Studio Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2840629) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2861697) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576) Security Update for Microsoft .NET Framework 4 Client Profile (KB2832407) Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393) Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628) Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2858302v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2861188) Security Update for Microsoft .NET Framework 4 Extended (KB2487367) Security Update for Microsoft .NET Framework 4 Extended (KB2656351) Security Update for Microsoft .NET Framework 4 Extended (KB2736428) Security Update for Microsoft .NET Framework 4 Extended (KB2742595) Security Update for Microsoft .NET Framework 4 Extended (KB2858302v2) Security Update for Microsoft Windows (KB2564958) Security Update for Windows Internet Explorer 8 (KB2482017) Security Update for Windows Internet Explorer 8 (KB2497640) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2530548) Security Update for Windows Internet Explorer 8 (KB2544521) Security Update for Windows Internet Explorer 8 (KB2559049) Security Update for Windows Internet Explorer 8 (KB2586448) Security Update for Windows Internet Explorer 8 (KB2618444) Security Update for Windows Internet Explorer 8 (KB2647516) Security Update for Windows Internet Explorer 8 (KB2675157) Security Update for Windows Internet Explorer 8 (KB2699988) Security Update for Windows Internet Explorer 8 (KB2722913) Security Update for Windows Internet Explorer 8 (KB2744842) Security Update for Windows Internet Explorer 8 (KB2761465) Security Update for Windows Internet Explorer 8 (KB2792100) Security Update for Windows Internet Explorer 8 (KB2797052) Security Update for Windows Internet Explorer 8 (KB2799329) Security Update for Windows Internet Explorer 8 (KB2809289) Security Update for Windows Internet Explorer 8 (KB2817183) Security Update for Windows Internet Explorer 8 (KB2829530) Security Update for Windows Internet Explorer 8 (KB2838727) Security Update for Windows Internet Explorer 8 (KB2846071) Security Update for Windows Internet Explorer 8 (KB2847204) Security Update for Windows Internet Explorer 8 (KB2862772) Security Update for Windows Internet Explorer 8 (KB2870699) Security Update for Windows Internet Explorer 8 (KB2879017) Security Update for Windows Internet Explorer 8 (KB2888505) Security Update for Windows Internet Explorer 8 (KB2898785) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB2834904-v2) Security Update for Windows Media Player (KB2834904) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2483614) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2503665) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2536276) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2555917) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567053) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2584146) Security Update for Windows XP (KB2585542) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2598479) Security Update for Windows XP (KB2603381) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2619339) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2621440) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2631813) Security Update for Windows XP (KB2633171) Security Update for Windows XP (KB2639417) Security Update for Windows XP (KB2641653) Security Update for Windows XP (KB2646524) Security Update for Windows XP (KB2647518) Security Update for Windows XP (KB2653956) Security Update for Windows XP (KB2655992) Security Update for Windows XP (KB2659262) Security Update for Windows XP (KB2660465) Security Update for Windows XP (KB2661637) Security Update for Windows XP (KB2676562) Security Update for Windows XP (KB2686509) Security Update for Windows XP (KB2691442) Security Update for Windows XP (KB2695962) Security Update for Windows XP (KB2698365) Security Update for Windows XP (KB2705219) Security Update for Windows XP (KB2707511) Security Update for Windows XP (KB2709162) Security Update for Windows XP (KB2712808) Security Update for Windows XP (KB2718523) Security Update for Windows XP (KB2719985) Security Update for Windows XP (KB2723135) Security Update for Windows XP (KB2724197) Security Update for Windows XP (KB2727528) Security Update for Windows XP (KB2731847) Security Update for Windows XP (KB2753842-v2) Security Update for Windows XP (KB2753842) Security Update for Windows XP (KB2757638) Security Update for Windows XP (KB2758857) Security Update for Windows XP (KB2761226) Security Update for Windows XP (KB2770660) Security Update for Windows XP (KB2778344) Security Update for Windows XP (KB2779030) Security Update for Windows XP (KB2780091) Security Update for Windows XP (KB2799494) Security Update for Windows XP (KB2802968) Security Update for Windows XP (KB2807986) Security Update for Windows XP (KB2808735) Security Update for Windows XP (KB2813170) Security Update for Windows XP (KB2813347) Security Update for Windows XP (KB2820197) Security Update for Windows XP (KB2820917) Security Update for Windows XP (KB2829361) Security Update for Windows XP (KB2834886) Security Update for Windows XP (KB2839229) Security Update for Windows XP (KB2845187) Security Update for Windows XP (KB2847311) Security Update for Windows XP (KB2849470) Security Update for Windows XP (KB2850851) Security Update for Windows XP (KB2850869) Security Update for Windows XP (KB2859537) Security Update for Windows XP (KB2862152) Security Update for Windows XP (KB2862330) Security Update for Windows XP (KB2862335) Security Update for Windows XP (KB2864063) Security Update for Windows XP (KB2868038) Security Update for Windows XP (KB2868626) Security Update for Windows XP (KB2876217) Security Update for Windows XP (KB2876315) Security Update for Windows XP (KB2876331) Security Update for Windows XP (KB2883150) Security Update for Windows XP (KB2884256) Security Update for Windows XP (KB2892075) Security Update for Windows XP (KB2893294) Security Update for Windows XP (KB2893984) Security Update for Windows XP (KB2898715) Security Update for Windows XP (KB2900986) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953155) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB955417) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB970483) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975254) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Segoe UI Sid Meier's Railroads! Sid Meier's Railroads! Holiday Scenario Sid Meier's Railroads! Intercontinental 1.01 SimCity™ Skype™ 6.10 Sony Vegas Pro 8.0 Star Commander Steam Subtitle Workshop 2.51 SweetIM for Messenger 3.6 SweetIM Toolbar for Internet Explorer 4.2 swMSM System Requirements Lab CYRI TextMaker Viewer The Lord of the Rings FREE Trial The Saboteur™ The Settlers 7 - Paths to a Kingdom The Sims™ 3 The Sims™ 3 Ambitions The Sims™ 3 Seasons The Sims™ 3 Supernatural The Sims™ 3 University Life Theme Hospital Time Adjuster STANDARD 3.1 Tropico 4 Collectors Bundle Tunngle beta Ubisoft Game Launcher UE3Redist Unity Web Player Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Windows (KB971513) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB978506) Update for Windows Internet Explorer 8 (KB982632) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2541763) Update for Windows XP (KB2607712) Update for Windows XP (KB2616676) Update for Windows XP (KB2641690) Update for Windows XP (KB2661254-v2) Update for Windows XP (KB2718704) Update for Windows XP (KB2736233) Update for Windows XP (KB2749655) Update for Windows XP (KB2863058) Update for Windows XP (KB2904266) Update for Windows XP (KB898461) Update for Windows XP (KB943729) Update for Windows XP (KB951618-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955704) Update for Windows XP (KB955759) Update for Windows XP (KB958752) Update for Windows XP (KB961503) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) User Profile Hive Cleanup Service uTorrentBar Toolbar VC80CRTRedist - 8.0.50727.4053 VobSub 2.23 Voxal Voice Changer WebFldrs XP Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0) Windows Driver Package - Nokia Modem (06/01/2009 4.1) Windows Driver Package - Nokia Modem (06/01/2009 7.01.0.3) Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0) Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 8 Windows Live Communications Platform Windows Live Essentials Windows Live ID Sign-in Assistant Windows Live Messenger Windows Media Format 11 runtime Windows Media Player 11 WinRAR archiver WorldPainter 1.2.0 Wurm Online 3.0.1 XML Paper Specification Shared Components Pack 1.0 Xvid 1.3.0 Yontoo 1.10.02 . ==== Event Viewer Messages From Past Week ======== . 18.12.2013 6:38:13, error: Service Control Manager [7034] - The ANIWZCSd Service service terminated unexpectedly. It has done this 1 time(s). 17.12.2013 16:38:04, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the MBAMService service. 17.12.2013 15:35:08, error: Dhcp [1002] - The IP address lease 109.60.99.152 for the Network Card with network address 001D7D5C9254 has been denied by the DHCP server 10.255.2.10 (The DHCP Server sent a DHCPNACK message). 16.12.2013 6:46:58, error: Service Control Manager [7000] - The Application Layer Gateway Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 16.12.2013 6:46:57, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Application Layer Gateway Service service to connect. 16.12.2013 6:45:36, error: Service Control Manager [7034] - The PnkBstrA service terminated unexpectedly. It has done this 1 time(s). 16.12.2013 6:44:28, error: Dhcp [1002] - The IP address lease 109.60.112.216 for the Network Card with network address 001D7D5C9254 has been denied by the DHCP server 10.255.3.10 (The DHCP Server sent a DHCPNACK message). 16.12.2013 21:34:27, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the JavaQuickStarterService service. 16.12.2013 21:33:49, error: Service Control Manager [7023] - The IPSEC Services service terminated with the following error: The authentication service is unknown. 16.12.2013 21:32:54, error: Dhcp [1002] - The IP address lease 109.60.106.11 for the Network Card with network address 001D7D5C9254 has been denied by the DHCP server 10.255.3.10 (The DHCP Server sent a DHCPNACK message). 16.12.2013 20:53:28, error: Service Control Manager [7023] - The xthxbdrbrxtccdiwenti service terminated with the following error: The system cannot find the file specified. 16.12.2013 20:53:28, error: Service Control Manager [7023] - The Application Virtualization Client service terminated with the following error: A dynamic link library (DLL) initialization routine failed. 16.12.2013 20:53:28, error: Service Control Manager [7001] - The Client Virtualization Handler service depends on the Application Virtualization Client service which failed to start because of the following error: A dynamic link library (DLL) initialization routine failed. 16.12.2013 20:53:20, error: Server [2505] - The server could not bind to the transport DeviceNetBT_Tcpip_{DD7927E4-10E5-4104-9AC0-5963CD4B0215} because another computer on the network has the same name. The server could not start. 14.12.2013 22:56:26, error: Dhcp [1002] - The IP address lease 109.60.98.207 for the Network Card with network address 001D7D5C9254 has been denied by the DHCP server 10.255.2.10 (The DHCP Server sent a DHCPNACK message). 14.12.2013 12:08:51, error: Service Control Manager [7034] - The Skype Updater service terminated unexpectedly. It has done this 1 time(s). 13.12.2013 21:03:03, error: Dhcp [1002] - The IP address lease 94.253.151.168 for the Network Card with network address 001D7D5C9254 has been denied by the DHCP server 10.255.2.10 (The DHCP Server sent a DHCPNACK message). . ==== End Of File =========================== I hope this is what you meant.
  11. I feel quite dumb now but what do you mean?
  12. I've been looking around for solutions to this problem that cropped up and I can't really find one that could fix it. Basically, from the moment my pc actually starts up I keep getting Bad image messages with "Application or DLL *** .dll not valid Windows image. Check against installation diskette." It's the same thing for all programs and I'm not sure if it's a common or a simple thing but I don't know of a way to fix it. One of the reasons why I'm not having an easy time fixing it is because I know very little about computers so I'm sure you'll have just as a hard time helping me fix it. I really hope this can be fixed easily because I can't really afford to go and have it fixed by a professional.
×
×
  • Create New...