Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

googleads.l.doublee-click.net

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

googleads.l.doublee-click.net

Unread postby flyingmojo » October 3rd, 2012, 11:17 pm

Hello

I was getting a lot of redirects to ad sites when clicking on links from google searches, but now I'm just getting "Server not found. Firefox can't find the server at googleads.l.doublee-click.net". It comes and goes, but when it's on, I have to copy and paste the url address. I also recently got and deleted a fake antivirus malware recently. Not sure if that is related.

Here are my dds logs:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.5.0
Run by Me at 20:06:28 on 2012-10-03
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.1856 [GMT -7:00]
.
AV: Avira Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\WINDOWS\OEM03Mon.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Browny02\Brother\BrStMonW.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe
C:\program files\real\realplayer\update\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe
C:\Documents and Settings\Me\Local Settings\Application Data\Akamai\netsession_win.exe
C:\Program Files\DELL\DELL Webcam Manager\DellWMgr.exe
C:\Documents and Settings\Me\Local Settings\Apps\F.lux\flux.exe
C:\Documents and Settings\All Users\Application Data\GameXN\GameXNGO.exe
C:\Documents and Settings\Me\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Documents and Settings\Me\Local Settings\Application Data\Akamai\netsession_win.exe
C:\WINDOWS\System32\svchost.exe -k Akamai
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Macrium\Reflect\ReflectService.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\Program Files\Browny02\BrYNSvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\FileZilla FTP Client\filezilla.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://google.ca/
uInternet Settings,ProxyOverride = 127.0.0.1:9421;*.local;<local>
uURLSearchHooks: pdfforge Toolbar: {b922d405-6d13-4a2b-ae89-08a030da4402} - c:\program files\pdfforge toolbar\ie\6.3\pdfforgeToolbarIE.dll
uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files\ask.com\GenericAskToolbar.dll
uURLSearchHooks: FreeOnlineRadioPlayerRecorder Toolbar: {f999a48b-1950-4d81-9971-79018f807b4b} - c:\program files\freeonlineradioplayerrecorder\prxtbFree.dll
uURLSearchHooks: YTNavAssistPlugin Class: {81017ea9-9aa8-4a6a-9734-7af40e7d593f} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll
BHO: Canon Easy-WebPrint EX BHO: {3785d0ad-bfff-47f6-bf5b-a587c162fed9} - c:\program files\canon\easy-webprint ex\ewpexbho.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: pdfforge Toolbar: {b922d405-6d13-4a2b-ae89-08a030da4402} - c:\program files\pdfforge toolbar\ie\6.3\pdfforgeToolbarIE.dll
BHO: Avira SearchFree Toolbar plus Web Protection: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: FreeOnlineRadioPlayerRecorder Toolbar: {f999a48b-1950-4d81-9971-79018f807b4b} - c:\program files\freeonlineradioplayerrecorder\prxtbFree.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
TB: Canon Easy-WebPrint EX: {759d9886-0c6f-4498-bab6-4a5f47c6c72f} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll
TB: FreeOnlineRadioPlayerRecorder Toolbar: {f999a48b-1950-4d81-9971-79018f807b4b} - c:\program files\freeonlineradioplayerrecorder\prxtbFree.dll
TB: Avira SearchFree Toolbar plus Web Protection: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: pdfforge Toolbar: {b922d405-6d13-4a2b-ae89-08a030da4402} - c:\program files\pdfforge toolbar\ie\6.3\pdfforgeToolbarIE.dll
EB: Canon Easy-WebPrint EX: {21347690-ec41-4f9a-8887-1f4aee672439} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [Akamai NetSession Interface] "c:\documents and settings\me\local settings\application data\akamai\netsession_win.exe"
uRun: [DELL Webcam Manager] "c:\program files\dell\dell webcam manager\DellWMgr.exe" /s
uRun: [F.lux] "c:\documents and settings\me\local settings\apps\f.lux\flux.exe" /noshow
uRun: [GameXN GO] "c:\documents and settings\all users\application data\gamexn\GameXNGO.exe" /startup
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini"
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [Smart File Advisor] "c:\program files\smart file advisor\sfa.exe" /checkassoc
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Nikon Message Center 2] c:\program files\nikon\nikon message center 2\NkMC2.exe -s
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [OEM03Mon.exe] c:\windows\OEM03Mon.exe
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [BrStsMon00] c:\program files\browny02\brother\BrStMonW.exe /AUTORUN
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [nthfx] rundll32.exe ",UlStripWhitespace
mRun: [opcmc] "c:\windows\system32\rundll32.exe" ,Vec2TransformNormalArray
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe"
mRun: [<NO NAME>]
mRun: [SearchSettings] "c:\program files\common files\spigot\search settings\SearchSettings.exe"
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
StartupFolder: c:\docume~1\me\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\me\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\me\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe
StartupFolder: c:\docume~1\me\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\docume~1\me\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Open with WordPerfect - c:\program files\corel\wordperfect office x5\programs\WPLauncher.hta
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: c:\program files\avira\antivir desktop\avsda.dll
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.co ... 1.71.0.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupda ... 8789686343
TCP: DhcpNameServer = 192.168.1.254 75.153.176.9
TCP: Interfaces\{38221CDD-BC3A-41B4-81AB-2FF8E9C71A8E} : DhcpNameServer = 192.168.1.254 75.153.176.9
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\me\application data\mozilla\firefox\profiles\otb6cqra.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/firefox
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?clien ... Y%5ECA&&q=
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll
FF - component: c:\program files\common files\spigot\wtxpcom\components\WidgiToolbarFF.dll
FF - component: c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\me\application data\mozilla\firefox\profiles\otb6cqra.default\extensions\{195a3098-0bd5-4e90-ae22-ba1c540afd1e}\plugins\npGarmin.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\canon\easy-photoprint ex\NPEZFFPI.DLL
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npRLCT4Player.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nprpplugin.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nprpplugin.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_4_402_278.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npptools.dll
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [2010-9-28 15328]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2012-5-21 36000]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2004-8-4 14336]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\avira\antivir desktop\sched.exe [2012-5-21 86224]
R2 AntiVirService;Avira Realtime Protection;c:\program files\avira\antivir desktop\avguard.exe [2012-5-21 110032]
R2 AntiVirWebService;Avira Web Protection;c:\program files\avira\antivir desktop\avwebgrd.exe [2012-5-21 465360]
R2 Application Updater;Application Updater;c:\program files\application updater\ApplicationUpdater.exe [2012-9-19 795072]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2012-5-21 83392]
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2012-9-21 399432]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-7-10 676936]
R2 ReflectService;Macrium Reflect Image Mounting Service;c:\program files\macrium\reflect\ReflectService.exe [2010-9-28 220128]
R2 RPCQT;Remote Procedure Call (CQTPM);c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
R2 Skype C2C Service;Skype C2C Service;c:\documents and settings\all users\application data\skype\toolbars\skype c2c service\c2c_service.exe [2012-8-13 3064000]
R3 BrYNSvc;BrYNSvc;c:\program files\browny02\BrYNSvc.exe [2012-1-15 245760]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-7-10 22856]
R3 RLDesignVirtualAudioCableWdm;Live! Cam Virtual;c:\windows\system32\drivers\livecamv.sys [2011-11-17 31616]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-8-17 136176]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-13 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-14 250288]
S3 DrvSnSht;DrvSnSht;\??\c:\program files\r-drive image\drvsnsht.sys --> c:\program files\r-drive image\DrvSnSht.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-8-17 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-4-25 114144]
S3 OEM03Vfx;Creative Camera OEM003 Video VFX Driver;c:\windows\system32\drivers\OEM03Vfx.sys [2011-11-17 7424]
S3 OEM03Vid;Creative Camera OEM003 Driver;c:\windows\system32\drivers\OEM03Vid.sys [2011-11-17 235808]
S3 R-ImageDisk;R-ImageDisk;\??\c:\program files\r-drive image\r-imagedisk.sys --> c:\program files\r-drive image\R-ImageDisk.sys [?]
S3 rt2870;D-Link dnetr28u USB Extensible Wireless LAN Card Driver;c:\windows\system32\drivers\Drt2870.sys [2012-1-13 829152]
.
=============== Created Last 30 ================
.
2012-10-02 00:51:22 1611 ----a-w- c:\windows\system32\drivers\etc\mvps.bat
2012-09-30 23:43:04 -------- d-----w- c:\documents and settings\me\application data\AskToolbar
2012-09-30 14:33:43 -------- d-----w- c:\program files\common files\xing shared
2012-09-30 14:33:16 129176 ----a-w- c:\program files\mozilla firefox\plugins\nprpplugin.dll
2012-09-26 22:11:01 -------- d-----w- c:\documents and settings\me\application data\Search Settings
2012-09-26 22:10:57 -------- d-----w- c:\program files\Application Updater
2012-09-26 22:10:56 -------- d-----w- c:\program files\pdfforge Toolbar
2012-09-26 22:10:56 -------- d-----w- c:\program files\common files\Spigot
2012-09-21 18:18:22 10213296 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2012-09-21 16:22:27 -------- d-----w- c:\windows\system32\wbem\repository\FS
2012-09-21 16:22:27 -------- d-----w- c:\windows\system32\wbem\Repository
2012-09-21 03:57:59 -------- d-----w- c:\documents and settings\all users\application data\036DFF9800001BEA004D4DA77B07D329
.
==================== Find3M ====================
.
2012-09-30 14:33:07 499712 ----a-w- c:\windows\system32\msvcp71.dll
2012-09-30 14:33:07 348160 ----a-w- c:\windows\system32\msvcr71.dll
2012-09-21 18:18:24 73136 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-21 18:18:24 696240 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-08 00:04:46 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-28 15:14:53 916992 ----a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14:53 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-08-28 15:14:52 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07:15 385024 ----a-w- c:\windows\system32\html.iec
2012-08-05 23:45:31 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-08-05 23:45:30 772592 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-08-05 23:45:30 687600 ----a-w- c:\windows\system32\deployJava1.dll
2012-07-06 13:58:51 78336 ----a-w- c:\windows\system32\browser.dll
.
============= FINISH: 20:07:21.53 ===============


.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 7/9/2010 1:29:21 PM
System Uptime: 10/3/2012 9:22:20 AM (11 hours ago)
.
Motherboard: Dell Inc. | | 0RY007
Processor: Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz | Socket 775 | 2394/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 462 GiB total, 59.263 GiB free.
D: is CDROM ()
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP1: 9/28/2012 9:24:14 AM - System Checkpoint
RP2: 9/29/2012 10:21:26 AM - System Checkpoint
RP3: 9/30/2012 10:33:06 AM - System Checkpoint
RP4: 10/1/2012 10:42:27 AM - System Checkpoint
RP5: 10/2/2012 12:30:08 PM - System Checkpoint
RP6: 10/3/2012 12:38:05 PM - System Checkpoint
.
==== Installed Programs ======================
.
.
µTorrent
7-Zip 4.65
AC3Filter 1.62b
Acoustica Effects Pack
Acrobat.com
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.4)
Advanced Audio FX Engine
Advanced Video FX Engine
AGEIA PhysX v2.6.0
Aimersoft Video Converter Ultimate(Build 4.1.0.2)
Akamai NetSession Interface
Akamai NetSession Interface Service
AltoMP3 Gold 5.20
AMD APP SDK Runtime
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ask Toolbar
ATI Catalyst Install Manager
ATI Parental Control & Encoder
Audacity 1.2.6
Avira Free Antivirus
Avira SearchFree Toolbar plus Web Protection Updater
AVS Screen Capture version 2.0.1
AVS Update Manager 1.0
AVS Video Converter 6
AVS Video Editor 5
AVS Video Recorder 2.4
AVS4YOU Software Navigator 1.4
Battlefield Play4Free
Bonjour
Brother MFL-Pro Suite MFC-295CN
calibre
Canon Easy-WebPrint EX
Canon MP Navigator EX 3.0
Canon MP250 series MP Drivers
Canon Utilities Easy-PhotoPrint EX
Canon Utilities My Printer
Canon Utilities Solution Menu
Catalyst Control Center
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
ccc-utility
CCC Help English
Chinese Simplified Fonts Support For Adobe Reader 9
Corel WordPerfect Office - iFilter
Dell Driver Download Manager
Dell Resource CD
DELL Webcam Center
DELL Webcam Manager
DivX Setup
DjVuLibre+DjView
Dropbox
DVD Shrink 3.2
Easy Thumbnails (Remove only)
Elecard MPEG-2 PlugIn for WMP
EPSON Printer Software
F.lux
Far Cry Demo
FileZilla Client 3.5.3
Free PDF to Word Doc Converter v1.1
FreeOnlineRadioPlayerRecorder Toolbar
Freez FLV to MP3 Converter
GameXN GO
Garmin USB Drivers
GnuWin32: Patch-2.5.9-7
Google Earth
Google Update Helper
Halo 2 for Windows Vista
High Definition Audio Driver Package - KB888111
HL-2270DW
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB2570791)
Hotfix for Windows XP (KB2633952)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB981793)
Intel(R) PRO Network Connections 12.1.12.0
IsoBuster 2.8.5
iTunes
Java Auto Updater
Java(TM) 7 Update 5
LIVE gaming on Windows Runtime Version 1.0.6027
Live! Cam Avatar Creator
Live! Cam Avatar v1.0
Livestream Procaster
Macrium Reflect - Free Edition
Macromedia Dreamweaver 8
Macromedia Extension Manager
MagicDisc 2.7.106
Malwarebytes Anti-Malware version 1.65.0.1400
Manga Studio EX 4.0
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Minecraft Beta Cracked
MobileMe Control Panel
Mobipocket Reader 6.2
Monitor Integrated Webcam Driver (1.00.13.0608)
Mozilla Firefox 15.0.1 (x86 en-US)
Mozilla Maintenance Service
MP3 Editor for Free v7.0.1
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Nikon Message Center 2
NVIDIA Drivers
OpenOffice.org 3.2
Paint.NET v3.5.10
PaperPort Image Printer
PDFCreator
pdfforge Toolbar v6.3
Picture Control Utility
PunkBuster Services
QuickTime
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.1
Roxio Creator Audio
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE
Roxio Creator Tools
Roxio Express Labeler 3
Roxio Update Manager
ScanSoft PaperPort 11
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596856) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596880) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597162) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2596786) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2596917) 32-Bit Edition
Security Update for Microsoft Windows (KB2564958)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB2497640)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2530548)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB2559049)
Security Update for Windows Internet Explorer 8 (KB2586448)
Security Update for Windows Internet Explorer 8 (KB2618444)
Security Update for Windows Internet Explorer 8 (KB2647516)
Security Update for Windows Internet Explorer 8 (KB2675157)
Security Update for Windows Internet Explorer 8 (KB2699988)
Security Update for Windows Internet Explorer 8 (KB2722913)
Security Update for Windows Internet Explorer 8 (KB2744842)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player (KB979402)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476490)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2503658)
Security Update for Windows XP (KB2503665)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2506223)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2511455)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB2535512)
Security Update for Windows XP (KB2536276-v2)
Security Update for Windows XP (KB2536276)
Security Update for Windows XP (KB2544893-v2)
Security Update for Windows XP (KB2544893)
Security Update for Windows XP (KB2555917)
Security Update for Windows XP (KB2562937)
Security Update for Windows XP (KB2566454)
Security Update for Windows XP (KB2567053)
Security Update for Windows XP (KB2567680)
Security Update for Windows XP (KB2570222)
Security Update for Windows XP (KB2570947)
Security Update for Windows XP (KB2584146)
Security Update for Windows XP (KB2585542)
Security Update for Windows XP (KB2592799)
Security Update for Windows XP (KB2598479)
Security Update for Windows XP (KB2603381)
Security Update for Windows XP (KB2618451)
Security Update for Windows XP (KB2619339)
Security Update for Windows XP (KB2620712)
Security Update for Windows XP (KB2621440)
Security Update for Windows XP (KB2624667)
Security Update for Windows XP (KB2631813)
Security Update for Windows XP (KB2633171)
Security Update for Windows XP (KB2639417)
Security Update for Windows XP (KB2641653)
Security Update for Windows XP (KB2646524)
Security Update for Windows XP (KB2647518)
Security Update for Windows XP (KB2653956)
Security Update for Windows XP (KB2655992)
Security Update for Windows XP (KB2659262)
Security Update for Windows XP (KB2660465)
Security Update for Windows XP (KB2676562)
Security Update for Windows XP (KB2685939)
Security Update for Windows XP (KB2686509)
Security Update for Windows XP (KB2691442)
Security Update for Windows XP (KB2695962)
Security Update for Windows XP (KB2698365)
Security Update for Windows XP (KB2705219)
Security Update for Windows XP (KB2707511)
Security Update for Windows XP (KB2709162)
Security Update for Windows XP (KB2712808)
Security Update for Windows XP (KB2718523)
Security Update for Windows XP (KB2719985)
Security Update for Windows XP (KB2723135)
Security Update for Windows XP (KB2731847)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982381)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Segoe UI
Simple Port Forwarding
SING & SEE v1.4.9
Singorama! Bonus Software
Skype Click to Call
Skype™ 5.10
Smart File Advisor 1.1.1
Spin It Again
System Requirements Lab
System Requirements Lab CYRI
TrackMania Nations Forever
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB982632)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB2541763)
Update for Windows XP (KB2607712)
Update for Windows XP (KB2616676)
Update for Windows XP (KB2641690)
Update for Windows XP (KB2718704)
Update for Windows XP (KB2736233)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VC80CRTRedist - 8.0.50727.6195
ViewNX 2
VLC media player 1.0.1
WebFldrs XP
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver
World of Warcraft
Xvid 1.2.2 final uninstall
Yahoo! Messenger
Yahoo! Software Update
Yahoo! Toolbar
.
==== Event Viewer Messages From Past Week ========
.
10/1/2012 7:37:15 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
.
==== End Of File ===========================
flyingmojo
Regular Member
 
Posts: 51
Joined: August 21st, 2009, 10:59 pm
Advertisement
Register to Remove

Re: googleads.l.doublee-click.net

Unread postby askey127 » October 4th, 2012, 8:26 am

Hi flyingmojo,
You will always get infections from using P2P programs and/or downloading files from crack sites.
As a condition of receiving our help, you need to remove these, and any other pieces of illegal software.
This will be your last warning if you want help here, since you have been told about P2P programs and our policy before.
-----------------------------------------------------------
Remove Programs Using Control Panel
From Start, Settings, Control Panel or Start, Control Panel, click Add/Remove Programs.
Highlight each Entry, as follows, one by one, if it exists, and choose Remove :

PDFCreator
Minecraft Beta Cracked
Ask Toolbar
µTorrent

Take extra care in answering questions posed by any Uninstaller.
-----------------------------------------------------------
REBOOT (RESTART) Your Machine
---------------------------------------------
Run CKScanner
Download CKScanner from HERE
Important - Save it to your desktop.
Doubleclick CKScanner.exe and click Search For Files.
After a couple minutes or less, when the cursor hourglass disappears, click Save List To File.
A message box will verify the file saved. Run the Program Just Once.
Double-click the CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.
---------------------------------------------
Download the OTL Scanner
Please download OTL.exe by OldTimer and save it to your desktop.
---------------------------------------------
Run a Scan with OTL
  • For WinXP, double click on the OTL icon to run it.
  • Check the boxes labeled :
    • Scan All Users
    • LOP check
    • Purity check
    • Extra Registry > Use SafeList
  • Make sure all other windows are closed to let it run uninterrupted.
  • Click on the Run Scan button at the top left hand corner. Do not change any settings unless otherwise told to do so.
    When the scan starts, OTL may appear to be frozen while it runs. Please be patient.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. (desktop)
OTL.txt will be open on your desktop, and Extras.txt will be minimized in your taskbar.
The Extras.txt file will only appear as a running Notepad document the very first time you run OTL.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them as a reply. Use separate replies if more convenient.

So we will be looking for the contents of CKFiles.txt, OTL.txt, and Extras.txt
askey127
User avatar
askey127
Admin/Teacher
Admin/Teacher
 
Posts: 14025
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA

Re: googleads.l.doublee-click.net

Unread postby flyingmojo » October 5th, 2012, 7:06 pm

Hello askey127

I've deleted all the programs except Ask Toolbar. I couldn't find it anywhere in my add-ons or "add or remove programs" list. I did find it though in my program files, in a directory called ask.com, but the same directory appears to have some of my antivirus (Avira) files, so I left it alone.

Here's the cck log:
CKScanner - Additional Security Risks - These are not necessarily bad
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_224514_4\rashaderstmbasedetailcrackndetailncrack.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_224514_4\rashaderstmbasedetailcrackndetailncrackalphatest.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_224514_4\rashaderstmbasedetailcrackndetailncrackalphatestlightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_224514_4\rashaderstmbasedetailcrackndetailncrackalphatestlightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_224514_4\rashaderstmbasedetailcrackndetailncrackalphatestpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_224514_4\rashaderstmbasedetailcrackndetailncrackalphatestshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_224514_4\rashaderstmbasedetailcrackndetailncracklightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_224514_4\rashaderstmbasedetailcrackndetailncracklightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_224514_4\rashaderstmbasedetailcrackndetailncrackpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_224514_4\rashaderstmbasedetailcrackndetailncrackshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_224514_4\rashaderstmbasedetaildirtcrackndetailncrack.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_224514_4\rashaderstmbasedetaildirtcrackndetailncrackalphatest.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_224514_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_224514_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_224514_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_224514_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_224514_4\rashaderstmbasedetaildirtcrackndetailncracklightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_224514_4\rashaderstmbasedetaildirtcrackndetailncracklightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_224514_4\rashaderstmbasedetaildirtcrackndetailncrackpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_224514_4\rashaderstmbasedetaildirtcrackndetailncrackshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225129_4\rashaderstmbasedetailcrackndetailncrack.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225129_4\rashaderstmbasedetailcrackndetailncrackalphatest.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225129_4\rashaderstmbasedetailcrackndetailncrackalphatestlightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225129_4\rashaderstmbasedetailcrackndetailncrackalphatestlightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225129_4\rashaderstmbasedetailcrackndetailncrackalphatestpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225129_4\rashaderstmbasedetailcrackndetailncrackalphatestshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225129_4\rashaderstmbasedetailcrackndetailncracklightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225129_4\rashaderstmbasedetailcrackndetailncracklightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225129_4\rashaderstmbasedetailcrackndetailncrackpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225129_4\rashaderstmbasedetailcrackndetailncrackshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225129_4\rashaderstmbasedetaildirtcrackndetailncrack.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225129_4\rashaderstmbasedetaildirtcrackndetailncrackalphatest.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225129_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225129_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225129_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225129_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225129_4\rashaderstmbasedetaildirtcrackndetailncracklightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225129_4\rashaderstmbasedetaildirtcrackndetailncracklightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225129_4\rashaderstmbasedetaildirtcrackndetailncrackpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225129_4\rashaderstmbasedetaildirtcrackndetailncrackshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225507_4\rashaderstmbasedetailcrackndetailncrack.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225507_4\rashaderstmbasedetailcrackndetailncrackalphatest.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225507_4\rashaderstmbasedetailcrackndetailncrackalphatestlightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225507_4\rashaderstmbasedetailcrackndetailncrackalphatestlightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225507_4\rashaderstmbasedetailcrackndetailncrackalphatestpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225507_4\rashaderstmbasedetailcrackndetailncrackalphatestshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225507_4\rashaderstmbasedetailcrackndetailncracklightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225507_4\rashaderstmbasedetailcrackndetailncracklightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225507_4\rashaderstmbasedetailcrackndetailncrackpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225507_4\rashaderstmbasedetailcrackndetailncrackshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225507_4\rashaderstmbasedetaildirtcrackndetailncrack.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225507_4\rashaderstmbasedetaildirtcrackndetailncrackalphatest.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225507_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225507_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225507_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225507_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225507_4\rashaderstmbasedetaildirtcrackndetailncracklightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225507_4\rashaderstmbasedetaildirtcrackndetailncracklightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225507_4\rashaderstmbasedetaildirtcrackndetailncrackpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_225507_4\rashaderstmbasedetaildirtcrackndetailncrackshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_226090_4\rashaderstmbasedetailcrackndetailncrack.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_226090_4\rashaderstmbasedetailcrackndetailncrackalphatest.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_226090_4\rashaderstmbasedetailcrackndetailncrackalphatestlightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_226090_4\rashaderstmbasedetailcrackndetailncrackalphatestlightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_226090_4\rashaderstmbasedetailcrackndetailncrackalphatestpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_226090_4\rashaderstmbasedetailcrackndetailncrackalphatestshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_226090_4\rashaderstmbasedetailcrackndetailncracklightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_226090_4\rashaderstmbasedetailcrackndetailncracklightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_226090_4\rashaderstmbasedetailcrackndetailncrackpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_226090_4\rashaderstmbasedetailcrackndetailncrackshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_226090_4\rashaderstmbasedetaildirtcrackndetailncrack.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_226090_4\rashaderstmbasedetaildirtcrackndetailncrackalphatest.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_226090_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_226090_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_226090_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_226090_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_226090_4\rashaderstmbasedetaildirtcrackndetailncracklightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_226090_4\rashaderstmbasedetaildirtcrackndetailncracklightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_226090_4\rashaderstmbasedetaildirtcrackndetailncrackpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_226090_4\rashaderstmbasedetaildirtcrackndetailncrackshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_227018_4\rashaderstmbasedetailcrackndetailncrack.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_227018_4\rashaderstmbasedetailcrackndetailncrackalphatest.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_227018_4\rashaderstmbasedetailcrackndetailncrackalphatestlightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_227018_4\rashaderstmbasedetailcrackndetailncrackalphatestlightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_227018_4\rashaderstmbasedetailcrackndetailncrackalphatestpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_227018_4\rashaderstmbasedetailcrackndetailncrackalphatestshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_227018_4\rashaderstmbasedetailcrackndetailncracklightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_227018_4\rashaderstmbasedetailcrackndetailncracklightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_227018_4\rashaderstmbasedetailcrackndetailncrackpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_227018_4\rashaderstmbasedetailcrackndetailncrackshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_227018_4\rashaderstmbasedetaildirtcrackndetailncrack.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_227018_4\rashaderstmbasedetaildirtcrackndetailncrackalphatest.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_227018_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_227018_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_227018_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_227018_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_227018_4\rashaderstmbasedetaildirtcrackndetailncracklightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_227018_4\rashaderstmbasedetaildirtcrackndetailncracklightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_227018_4\rashaderstmbasedetaildirtcrackndetailncrackpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-816f-0824a1c2cb35}_227018_4\rashaderstmbasedetaildirtcrackndetailncrackshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_221900_3\rashaderstmbasedetailcrackndetailncrack.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_221900_3\rashaderstmbasedetailcrackndetailncrackalphatest.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_221900_3\rashaderstmbasedetailcrackndetailncrackalphatestlightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_221900_3\rashaderstmbasedetailcrackndetailncrackalphatestlightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_221900_3\rashaderstmbasedetailcrackndetailncrackalphatestpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_221900_3\rashaderstmbasedetailcrackndetailncrackalphatestshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_221900_3\rashaderstmbasedetailcrackndetailncracklightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_221900_3\rashaderstmbasedetailcrackndetailncracklightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_221900_3\rashaderstmbasedetailcrackndetailncrackpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_221900_3\rashaderstmbasedetailcrackndetailncrackshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_221900_3\rashaderstmbasedetaildirtcrackndetailncrack.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_221900_3\rashaderstmbasedetaildirtcrackndetailncrackalphatest.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_221900_3\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_221900_3\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_221900_3\rashaderstmbasedetaildirtcrackndetailncrackalphatestpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_221900_3\rashaderstmbasedetaildirtcrackndetailncrackalphatestshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_221900_3\rashaderstmbasedetaildirtcrackndetailncracklightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_221900_3\rashaderstmbasedetaildirtcrackndetailncracklightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_221900_3\rashaderstmbasedetaildirtcrackndetailncrackpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_221900_3\rashaderstmbasedetaildirtcrackndetailncrackshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_3\rashaderstmbasedetailcrackndetailncrack.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_3\rashaderstmbasedetailcrackndetailncrackalphatest.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_3\rashaderstmbasedetailcrackndetailncrackalphatestlightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_3\rashaderstmbasedetailcrackndetailncrackalphatestlightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_3\rashaderstmbasedetailcrackndetailncrackalphatestpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_3\rashaderstmbasedetailcrackndetailncrackalphatestshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_3\rashaderstmbasedetailcrackndetailncracklightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_3\rashaderstmbasedetailcrackndetailncracklightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_3\rashaderstmbasedetailcrackndetailncrackpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_3\rashaderstmbasedetailcrackndetailncrackshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_3\rashaderstmbasedetaildirtcrackndetailncrack.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_3\rashaderstmbasedetaildirtcrackndetailncrackalphatest.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_3\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_3\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_3\rashaderstmbasedetaildirtcrackndetailncrackalphatestpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_3\rashaderstmbasedetaildirtcrackndetailncrackalphatestshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_3\rashaderstmbasedetaildirtcrackndetailncracklightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_3\rashaderstmbasedetaildirtcrackndetailncracklightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_3\rashaderstmbasedetaildirtcrackndetailncrackpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_3\rashaderstmbasedetaildirtcrackndetailncrackshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_4\rashaderstmbasedetailcrackndetailncrack.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_4\rashaderstmbasedetailcrackndetailncrackalphatest.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_4\rashaderstmbasedetailcrackndetailncrackalphatestlightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_4\rashaderstmbasedetailcrackndetailncrackalphatestlightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_4\rashaderstmbasedetailcrackndetailncrackalphatestpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_4\rashaderstmbasedetailcrackndetailncrackalphatestshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_4\rashaderstmbasedetailcrackndetailncracklightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_4\rashaderstmbasedetailcrackndetailncracklightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_4\rashaderstmbasedetailcrackndetailncrackpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_4\rashaderstmbasedetailcrackndetailncrackshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_4\rashaderstmbasedetaildirtcrackndetailncrack.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_4\rashaderstmbasedetaildirtcrackndetailncrackalphatest.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_4\rashaderstmbasedetaildirtcrackndetailncracklightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_4\rashaderstmbasedetaildirtcrackndetailncracklightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_4\rashaderstmbasedetaildirtcrackndetailncrackpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222418_4\rashaderstmbasedetaildirtcrackndetailncrackshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222577_4\rashaderstmbasedetailcrackndetailncrack.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222577_4\rashaderstmbasedetailcrackndetailncrackalphatest.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222577_4\rashaderstmbasedetailcrackndetailncrackalphatestlightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222577_4\rashaderstmbasedetailcrackndetailncrackalphatestlightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222577_4\rashaderstmbasedetailcrackndetailncrackalphatestpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222577_4\rashaderstmbasedetailcrackndetailncrackalphatestshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222577_4\rashaderstmbasedetailcrackndetailncracklightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222577_4\rashaderstmbasedetailcrackndetailncracklightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222577_4\rashaderstmbasedetailcrackndetailncrackpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222577_4\rashaderstmbasedetailcrackndetailncrackshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222577_4\rashaderstmbasedetaildirtcrackndetailncrack.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222577_4\rashaderstmbasedetaildirtcrackndetailncrackalphatest.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222577_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222577_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222577_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222577_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222577_4\rashaderstmbasedetaildirtcrackndetailncracklightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222577_4\rashaderstmbasedetaildirtcrackndetailncracklightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222577_4\rashaderstmbasedetaildirtcrackndetailncrackpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_222577_4\rashaderstmbasedetaildirtcrackndetailncrackshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_223032_4\rashaderstmbasedetailcrackndetailncrack.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_223032_4\rashaderstmbasedetailcrackndetailncrackalphatest.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_223032_4\rashaderstmbasedetailcrackndetailncrackalphatestlightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_223032_4\rashaderstmbasedetailcrackndetailncrackalphatestlightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_223032_4\rashaderstmbasedetailcrackndetailncrackalphatestpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_223032_4\rashaderstmbasedetailcrackndetailncrackalphatestshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_223032_4\rashaderstmbasedetailcrackndetailncracklightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_223032_4\rashaderstmbasedetailcrackndetailncracklightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_223032_4\rashaderstmbasedetailcrackndetailncrackpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_223032_4\rashaderstmbasedetailcrackndetailncrackshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_223032_4\rashaderstmbasedetaildirtcrackndetailncrack.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_223032_4\rashaderstmbasedetaildirtcrackndetailncrackalphatest.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_223032_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_223032_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_223032_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_223032_4\rashaderstmbasedetaildirtcrackndetailncrackalphatestshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_223032_4\rashaderstmbasedetaildirtcrackndetailncracklightmap.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_223032_4\rashaderstmbasedetaildirtcrackndetailncracklightmapshadow.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_223032_4\rashaderstmbasedetaildirtcrackndetailncrackpointlight.cfx
c:\documents and settings\me\my documents\battlefield play4free\mods\main\cache\{d7b71ee2-d783-11cf-df69-0824a1c2cb35}_223032_4\rashaderstmbasedetaildirtcrackndetailncrackshadow.cfx
c:\documents and settings\me\my documents\downloads\new folder (3)\cracks\version1.0\projecti.g.i2v1.0nocdfixedexeeng.rar
c:\documents and settings\me\my documents\downloads\new folder (3)\cracks\version1.2\deviance.nfo
c:\documents and settings\me\my documents\downloads\new folder (3)\cracks\version1.2\igi2.exe
c:\documents and settings\me\my documents\downloads\new folder (3)\cracks\version1.2\projectigi2v1.2nocdfixedexeeng.rar
c:\documents and settings\me\my documents\downloads\new folder (3)\cracks\version1.3\deviance.nfo
c:\documents and settings\me\my documents\downloads\new folder (3)\cracks\version1.3\igi2.exe
c:\documents and settings\me\my documents\downloads\new folder (3)\cracks\version1.3\projectigi2covertstrikev1.3fixedexeeng.rar
c:\documents and settings\me\my documents\minecraft\minecraft_beta_cracked_v1.8.1.exe
c:\documents and settings\me\my documents\minecraft\minecraft_beta_cracked_v1.8.1.zip
c:\documents and settings\me\my documents\my documents\immigration\poems\crack me.doc
c:\documents and settings\me\my documents\my documents\my dropbox\misc\astrology\[astrology software] janus 4.1 + crack tsrh read nfo (very good_works fine)\installjanus4.exe
c:\program files\acoustica spin it again\presets\vinyl declick & decrackle.preset
scanner sequence 3.ZZ.11.DVNANL
----- EOF -----

The 2 OTL logs I will post seperately
flyingmojo
Regular Member
 
Posts: 51
Joined: August 21st, 2009, 10:59 pm

Re: googleads.l.doublee-click.net

Unread postby flyingmojo » October 5th, 2012, 7:08 pm

OTL logfile created on: 10/5/2012 3:13:42 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Me\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.09 Gb Available Physical Memory | 69.58% Memory free
4.84 Gb Paging File | 3.92 Gb Available in Paging File | 80.95% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 462.29 Gb Total Space | 77.64 Gb Free Space | 16.80% Space Free | Partition Type: NTFS

Computer Name: MERLIN | User Name: Me | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/10/05 15:11:17 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Me\Desktop\OTL.exe
PRC - [2012/10/03 22:45:36 | 000,161,768 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2012/09/30 07:33:08 | 000,296,096 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\real\realplayer\Update\realsched.exe
PRC - [2012/09/19 16:27:56 | 001,100,680 | ---- | M] (Spigot, Inc.) -- C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe
PRC - [2012/09/19 16:21:14 | 000,795,072 | ---- | M] (Spigot, Inc.) -- C:\Program Files\Application Updater\ApplicationUpdater.exe
PRC - [2012/09/07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/09/07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/07 17:04:44 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/08/13 13:33:30 | 003,064,000 | ---- | M] (Skype Technologies S.A.) -- C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012/08/10 18:59:52 | 004,440,896 | ---- | M] (Akamai Technologies, Inc.) -- C:\Documents and Settings\Me\Local Settings\Application Data\Akamai\netsession_win.exe
PRC - [2012/08/08 16:26:40 | 000,348,664 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012/06/20 13:18:08 | 001,568,976 | ---- | M] (Ask) -- C:\Program Files\Ask.com\Updater\Updater.exe
PRC - [2012/05/24 11:39:22 | 027,112,840 | ---- | M] (Dropbox, Inc.) -- C:\Documents and Settings\Me\Application Data\Dropbox\bin\Dropbox.exe
PRC - [2012/05/02 01:42:31 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2012/05/02 00:55:24 | 000,465,360 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe
PRC - [2012/05/02 00:34:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2012/04/24 02:11:59 | 000,080,336 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011/08/31 12:10:19 | 000,347,008 | ---- | M] (EasyBits Software AS) -- C:\Documents and Settings\All Users\Application Data\GameXN\GameXNGO.exe
PRC - [2011/07/28 16:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/09/28 15:02:58 | 000,220,128 | ---- | M] () -- C:\Program Files\Macrium\Reflect\ReflectService.exe
PRC - [2010/06/10 14:42:44 | 002,621,440 | R--- | M] (Brother Industries, Ltd.) -- C:\Program Files\Browny02\Brother\BrStMonW.exe
PRC - [2010/06/01 10:17:48 | 005,252,408 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2010/05/21 00:28:00 | 011,312,128 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2010/05/21 00:27:58 | 011,318,784 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2010/01/25 09:22:56 | 000,245,760 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files\Browny02\BrYNSvc.exe
PRC - [2009/10/18 19:12:00 | 001,983,816 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
PRC - [2009/08/28 23:00:12 | 000,966,656 | ---- | M] () -- C:\Documents and Settings\Me\Local Settings\Apps\F.lux\flux.exe
PRC - [2009/02/23 20:43:12 | 000,576,000 | ---- | M] (MagicISO, Inc.) -- C:\Program Files\MagicDisc\MagicDisc.exe
PRC - [2009/02/09 10:31:56 | 000,143,360 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
PRC - [2008/11/09 13:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/06/07 12:14:36 | 000,118,784 | ---- | M] (Creative Technology Ltd.) -- C:\Program Files\DELL\DELL Webcam Manager\DellWMgr.exe
PRC - [2007/05/18 10:00:00 | 000,036,864 | R--- | M] (Creative Technology Ltd.) -- C:\WINDOWS\OEM03Mon.exe
PRC - [2006/04/18 04:00:00 | 000,102,400 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE


========== Modules (No Company Name) ==========

MOD - [2012/06/14 10:06:43 | 011,817,472 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\dbc413807cb7360b3e26ef3ca1d54f9a\System.Web.ni.dll
MOD - [2012/06/14 09:16:19 | 012,433,920 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\01abbadafaf265d9f4ac9bbb247acb98\System.Windows.Forms.ni.dll
MOD - [2012/06/14 09:16:10 | 001,592,320 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll
MOD - [2012/06/14 09:14:52 | 000,303,104 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
MOD - [2012/05/11 09:44:05 | 000,971,264 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\3d5b7368bde0f65aa15d9f46b498cc89\System.Configuration.ni.dll
MOD - [2012/05/11 09:44:00 | 000,025,600 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\016444dfc5f7e3d11c776f2fbc7a4594\Accessibility.ni.dll
MOD - [2012/05/10 23:46:35 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\3bba1b8b0b5ef0be238b011cc7a0575e\System.Xml.ni.dll
MOD - [2012/05/10 23:44:56 | 007,953,408 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\e4b5afc4da43b1c576f9322f9f2e1bfe\System.ni.dll
MOD - [2012/05/10 23:44:41 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\e337c89bc9f81b69d7237aa70e935900\mscorlib.ni.dll
MOD - [2012/04/16 23:11:02 | 000,398,288 | ---- | M] () -- C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
MOD - [2012/01/08 06:41:12 | 000,093,696 | ---- | M] () -- C:\Program Files\FileZilla FTP Client\fzshellext.dll
MOD - [2011/11/03 08:28:36 | 001,292,288 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2011/11/02 00:26:32 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/11/02 00:26:12 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/07/28 16:09:42 | 000,096,112 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011/07/28 16:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
MOD - [2011/04/19 21:56:56 | 000,270,336 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
MOD - [2010/09/28 15:02:58 | 000,220,128 | ---- | M] () -- C:\Program Files\Macrium\Reflect\ReflectService.exe
MOD - [2010/06/01 10:17:46 | 000,929,792 | ---- | M] () -- C:\Program Files\Yahoo!\Messenger\yui.dll
MOD - [2010/05/04 15:36:28 | 000,970,752 | ---- | M] () -- C:\Program Files\OpenOffice.org 3\program\libxml2.dll
MOD - [2010/03/16 12:22:12 | 000,014,848 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AxInterop.WBOCXLib.dll
MOD - [2010/03/15 11:28:22 | 000,141,824 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2009/08/28 23:00:12 | 000,966,656 | ---- | M] () -- C:\Documents and Settings\Me\Local Settings\Apps\F.lux\flux.exe
MOD - [2009/02/27 17:38:20 | 000,139,264 | R--- | M] () -- C:\Program Files\Brother\BrUtilities\BrLogAPI.dll
MOD - [2008/04/13 17:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/13 17:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2002/11/26 14:43:18 | 000,106,496 | ---- | M] () -- C:\WINDOWS\system32\BrMuSNMP.dll


========== Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2012/10/03 22:45:36 | 000,161,768 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2012/09/21 11:18:24 | 000,250,288 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/19 16:21:14 | 000,795,072 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater)
SRV - [2012/09/11 08:14:25 | 004,537,664 | ---- | M] () [Auto | Running] -- c:\program files\common files\akamai/netsession_win_5891ae0.dll -- (Akamai)
SRV - [2012/09/07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/09/07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/09/06 16:44:38 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/08/13 13:33:30 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012/07/13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/05/02 01:42:31 | 000,086,224 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2012/05/02 00:55:24 | 000,465,360 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe -- (AntiVirWebService)
SRV - [2012/05/02 00:34:37 | 000,110,032 | ---- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010/09/28 15:02:58 | 000,220,128 | ---- | M] () [Auto | Running] -- C:\Program Files\Macrium\Reflect\ReflectService.exe -- (ReflectService)
SRV - [2010/01/25 09:22:56 | 000,245,760 | ---- | M] (Brother Industries, Ltd.) [On_Demand | Running] -- C:\Program Files\Browny02\BrYNSvc.exe -- (BrYNSvc)
SRV - [2008/11/09 13:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/04/13 17:11:54 | 023,274,496 | R-S- | M] (Lavasoft ) [Auto | Running] -- C:\WINDOWS\system32\Rpcqt.dll -- (RPCQT)
SRV - [2006/04/18 04:00:00 | 000,102,400 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE -- (EPSON_PM_RPCV4_01)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\R-Drive Image\R-ImageDisk.sys -- (R-ImageDisk)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS -- (OMCI)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\R-Drive Image\DrvSnSht.sys -- (DrvSnSht)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2012/09/07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/04/27 10:20:04 | 000,137,928 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2012/04/25 00:32:27 | 000,083,392 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2012/04/16 21:18:01 | 000,036,000 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avkmgr.sys -- (avkmgr)
DRV - [2011/04/19 19:41:56 | 006,537,728 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2010/10/11 16:05:47 | 000,436,792 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2010/09/28 15:03:22 | 000,015,328 | ---- | M] (Macrium Software) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\pssnap.sys -- (pssnap)
DRV - [2010/06/17 15:14:27 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010/05/06 18:35:04 | 000,829,152 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Drt2870.sys -- (rt2870)
DRV - [2009/02/24 19:42:14 | 000,116,736 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mcdbus.sys -- (mcdbus)
DRV - [2007/05/02 16:21:22 | 004,403,712 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2007/04/24 10:00:00 | 000,235,808 | R--- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\OEM03Vid.sys -- (OEM03Vid)
DRV - [2007/03/05 03:45:04 | 000,007,424 | R--- | M] (EyePower Games Pte. Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\OEM03Vfx.sys -- (OEM03Vfx)
DRV - [2007/01/15 18:57:08 | 000,031,616 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\livecamv.sys -- (RLDesignVirtualAudioCableWdm)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-527237240-1972579041-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/
IE - HKU\S-1-5-21-527237240-1972579041-839522115-1004\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKU\S-1-5-21-527237240-1972579041-839522115-1004\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-527237240-1972579041-839522115-1004\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\6.3\pdfforgeToolbarIE.dll (Spigot, Inc.)
IE - HKU\S-1-5-21-527237240-1972579041-839522115-1004\..\URLSearchHook: {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Program Files\FreeOnlineRadioPlayerRecorder\prxtbFree.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-527237240-1972579041-839522115-1004\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-527237240-1972579041-839522115-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKU\S-1-5-21-527237240-1972579041-839522115-1004\..\SearchScopes\{212018DD-EDD5-4FEB-883F-63A27C6FA8BC}: "URL" = http://websearch.ask.com/redirect?clien ... src=crm&q={searchTerms}&locale=&apn_ptnrs=^ABY&apn_dtid=^YYYYYY^YY^CA&apn_uid=f1a27c58-f0bf-4b4a-a3f0-e66e924d2881&apn_sauid=4713E7BA-F301-450C-BFEB-28BAB38B0066
IE - HKU\S-1-5-21-527237240-1972579041-839522115-1004\..\SearchScopes\{22726A85-0B1F-4FA3-9EDF-5321CC808116}: "URL" = http://search.yahoo.com/search?fr=chr-g ... =827316&p={searchTerms}
IE - HKU\S-1-5-21-527237240-1972579041-839522115-1004\..\SearchScopes\{4EBD8267-63F8-4874-BAA1-C86435A9F3AB}: "URL" = http://flvtubesearch.co/?tmp=toolbar_Fl ... &Keywords={searchTerms}&clid=e11273c92b5a412b877c2d23d9da49b9
IE - HKU\S-1-5-21-527237240-1972579041-839522115-1004\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2737658
IE - HKU\S-1-5-21-527237240-1972579041-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-527237240-1972579041-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;*.local;<local>

========== FireFox ==========

FF - prefs.js..CT3201318.browser.search.defaultthis.engineName: true
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.selectedEngineURL: "http://flvtubesearch.co/?tmp=toolbar_flvtube_results&prt=flvtubetb01ff&clid=e11273c92b5a412b877c2d23d9da49b9&subid=2211&Keywords={searchTerms}"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.ca/firefox"
FF - prefs.js..extensions.enabledAddons: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:3.0.1
FF - prefs.js..extensions.enabledAddons: {5384767E-00D9-40E9-B72F-9CC39D655D6F}:1.4.2.1
FF - prefs.js..extensions.enabledAddons: {B098D44C-B4E0-11E1-8270-B8AC6F996F26}:2.0.14
FF - prefs.js..extensions.enabledAddons: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.2.145
FF - prefs.js..extensions.enabledAddons: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.2.2
FF - prefs.js..extensions.enabledAddons: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.10
FF - prefs.js..extensions.enabledAddons: {0153E448-190B-4987-BDE1-F256CADA672F}:15.0.6
FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.87
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.3
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.9
FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.7.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: wtxpcom@mybrowserbar.com:4.7
FF - prefs.js..extensions.enabledItems: battlefieldplay4free@ea.com:1.0.64.2
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.6.0.8442
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.6
FF - prefs.js..extensions.enabledItems: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:3.0.1
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=AVR-3&o=APN10400&locale=en_CA&apn_uid=f1a27c58-f0bf-4b4a-a3f0-e66e924d2881&apn_ptnrs=%5EABY&apn_sauid=4713E7BA-F301-450C-BFEB-28BAB38B0066&apn_dtid=%5EYYYYYY%5EYY%5ECA&&q="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.6.14: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/09/30 07:33:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/01/03 12:19:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/09/30 07:33:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/06 16:44:39 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/09/30 07:34:05 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{B098D44C-B4E0-11E1-8270-B8AC6F996F26}: C:\Documents and Settings\Me\Local Settings\Application Data\{B098D44C-B4E0-11E1-8270-B8AC6F996F26}\ [2012/06/12 15:48:05 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Documents and Settings\Me\Application Data\IDM\idmmzcc3

[2010/07/10 12:20:39 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Me\Application Data\Mozilla\Extensions
[2012/10/05 15:15:56 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\1kwudyor.new\extensions
[2010/09/26 13:01:26 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\ch32jr89.new\extensions
[2010/09/26 10:33:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\ch32jr89.new\extensions\staged-xpis
[2012/09/26 17:22:31 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\otb6cqra.default\extensions
[2011/08/26 09:31:25 | 000,000,000 | ---D | M] (Garmin Communicator) -- C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\otb6cqra.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2010/12/27 13:30:35 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\otb6cqra.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/08/22 18:13:37 | 000,000,000 | ---D | M] (FLV Runner) -- C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\otb6cqra.default\extensions\{3bbd3c14-4c16-4989-8366-95bc9179779d}
[2012/04/25 09:10:29 | 000,000,000 | ---D | M] (EPUBReader) -- C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\otb6cqra.default\extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}
[2012/09/21 09:19:16 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\otb6cqra.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}(2)
[2012/09/25 10:04:52 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\otb6cqra.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012/09/21 09:20:05 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\otb6cqra.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(2)
[2011/08/31 17:07:30 | 000,000,000 | ---D | M] (Battlefield Play4Free) -- C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\otb6cqra.default\extensions\battlefieldplay4free@ea.com
[2012/08/08 16:29:00 | 000,000,000 | ---D | M] (Avira SearchFree Toolbar plus Web Protection) -- C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\otb6cqra.default\extensions\toolbar@ask.com
[2009/03/18 14:40:42 | 000,019,153 | ---- | M] () (No name found) -- C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\ch32jr89.new\extensions\staged-xpis\{20a82645-c095-46ed-80e3-08825760534b}\MicrosoftDotNetFrameworkAssistant.xpi
[2012/09/01 09:32:19 | 001,625,368 | ---- | M] () (No name found) -- C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\otb6cqra.default\extensions\firebug@software.joehewitt.com.xpi
[2012/09/26 17:22:31 | 000,340,018 | ---- | M] () (No name found) -- C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\otb6cqra.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi
[2012/09/05 17:06:37 | 001,268,546 | ---- | M] () (No name found) -- C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\otb6cqra.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}.xpi
[2012/08/08 16:29:00 | 000,002,344 | ---- | M] () -- C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\otb6cqra.default\searchplugins\askcom.xml
[2012/08/04 00:46:01 | 000,000,913 | ---- | M] () -- C:\Documents and Settings\Me\Application Data\Mozilla\Firefox\Profiles\otb6cqra.default\searchplugins\conduit.xml
[2012/09/06 16:44:33 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/09/06 16:44:33 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/09/30 07:33:38 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2012/06/12 15:48:05 | 000,000,000 | ---D | M] (Mozilla Safe Browsing) -- C:\DOCUMENTS AND SETTINGS\ME\LOCAL SETTINGS\APPLICATION DATA\{B098D44C-B4E0-11E1-8270-B8AC6F996F26}
[2012/01/03 12:19:28 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 &lt;video&gt;) -- C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\DIVXHTML5
[2012/09/06 16:44:38 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/09/30 07:33:16 | 000,129,176 | ---- | M] (RealPlayer) -- C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2012/08/30 11:19:17 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/08/30 11:19:17 | 000,002,253 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2011/03/04 12:58:21 | 000,000,732 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\6.3\pdfforgeToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (FreeOnlineRadioPlayerRecorder Toolbar) - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Program Files\FreeOnlineRadioPlayerRecorder\prxtbFree.dll (Conduit Ltd.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\6.3\pdfforgeToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (FreeOnlineRadioPlayerRecorder Toolbar) - {f999a48b-1950-4d81-9971-79018f807b4b} - C:\Program Files\FreeOnlineRadioPlayerRecorder\prxtbFree.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-527237240-1972579041-839522115-1004\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKU\S-1-5-21-527237240-1972579041-839522115-1004\..\Toolbar\WebBrowser: (Avira SearchFree Toolbar plus Web Protection) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKU\S-1-5-21-527237240-1972579041-839522115-1004\..\Toolbar\WebBrowser: (FreeOnlineRadioPlayerRecorder Toolbar) - {F999A48B-1950-4D81-9971-79018F807B4B} - C:\Program Files\FreeOnlineRadioPlayerRecorder\prxtbFree.dll (Conduit Ltd.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Nikon Message Center 2] C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe (Nikon Corporation)
O4 - HKLM..\Run: [nthfx] rundll32.exe ",UlStripWhitespace File not found
O4 - HKLM..\Run: [OEM03Mon.exe] C:\WINDOWS\OEM03Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [opcmc] "C:\WINDOWS\system32\rundll32.exe" ,Vec2TransformNormalArray File not found
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [Smart File Advisor] C:\Program Files\Smart File Advisor\sfa.exe (Filefacts.net)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-527237240-1972579041-839522115-1004..\Run: [Akamai NetSession Interface] C:\Documents and Settings\Me\Local Settings\Application Data\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKU\S-1-5-21-527237240-1972579041-839522115-1004..\Run: [DELL Webcam Manager] C:\Program Files\DELL\DELL Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)
O4 - HKU\S-1-5-21-527237240-1972579041-839522115-1004..\Run: [F.lux] C:\Documents and Settings\Me\Local Settings\Apps\F.lux\flux.exe ()
O4 - HKU\S-1-5-21-527237240-1972579041-839522115-1004..\Run: [GameXN GO] C:\Documents and Settings\All Users\Application Data\GameXN\GameXNGO.exe (EasyBits Software AS)
O4 - HKU\S-1-5-21-527237240-1972579041-839522115-1004..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\Me\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Me\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Documents and Settings\Me\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O4 - Startup: C:\Documents and Settings\Me\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-527237240-1972579041-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Open with WordPerfect - c:\Program Files\Corel\WordPerfect Office X5\Programs\WPLauncher.hta File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O15 - HKU\S-1-5-21-527237240-1972579041-839522115-1004\..Trusted Ranges: Range1979 ([http] in Trusted sites)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.systemrequirementslab.co ... 1.71.0.cab (SysInfo Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupda ... 8789686343 (WUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 75.153.176.9
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{38221CDD-BC3A-41B4-81AB-2FF8E9C71A8E}: DhcpNameServer = 192.168.1.254 75.153.176.9
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Me\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Me\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/07/09 13:28:04 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{3625f840-d58c-11df-9984-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{3625f840-d58c-11df-9984-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{3625f840-d58c-11df-9984-806d6172696f}\Shell\AutoRun\command - "" = E:\AutoRunMorrowind.exe
O33 - MountPoints2\{3625f840-d58c-11df-9984-806d6172696f}\Shell\install\command - "" = E:\Setup.exe
O33 - MountPoints2\{576da2eb-905f-11df-9253-001d099ab033}\Shell - "" = AutoRun
O33 - MountPoints2\{576da2eb-905f-11df-9253-001d099ab033}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{576da2eb-905f-11df-9253-001d099ab033}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/10/05 15:11:17 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Me\Desktop\OTL.exe
[2012/10/03 22:46:00 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012/10/03 22:45:52 | 000,246,760 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2012/10/03 22:45:52 | 000,143,872 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2012/10/03 22:45:48 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2012/10/03 22:45:48 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2012/10/03 22:45:48 | 000,093,672 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll
[2012/10/03 20:06:29 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Me\Start Menu\Programs\Administrative Tools
[2012/09/30 16:43:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Me\Application Data\AskToolbar
[2012/09/30 07:33:43 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2012/09/30 07:33:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\RealNetworks
[2012/09/26 15:11:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Me\Application Data\Search Settings
[2012/09/26 15:10:57 | 000,000,000 | ---D | C] -- C:\Program Files\Application Updater
[2012/09/26 15:10:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Spigot
[2012/09/26 15:10:56 | 000,000,000 | ---D | C] -- C:\Program Files\pdfforge Toolbar
[2012/09/21 11:18:22 | 010,213,296 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerInstaller.exe
[2012/09/20 20:57:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\036DFF9800001BEA004D4DA77B07D329
[2012/09/08 18:04:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\B&L2rvsd
[2012/09/08 18:02:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\B&L1
[2012/09/06 16:44:31 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/10/05 15:18:15 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/10/05 15:18:00 | 000,000,228 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2012/10/05 15:11:17 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Me\Desktop\OTL.exe
[2012/10/05 14:48:27 | 000,000,272 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-527237240-1972579041-839522115-1004.job
[2012/10/05 14:48:21 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-527237240-1972579041-839522115-1004.job
[2012/10/05 14:46:53 | 000,000,874 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/05 14:46:50 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/10/05 14:38:01 | 000,000,878 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/04 11:09:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/10/04 08:38:24 | 000,458,240 | ---- | M] () -- C:\Documents and Settings\Me\Desktop\CKScanner.exe
[2012/10/03 22:45:36 | 000,093,672 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll
[2012/10/03 22:45:35 | 000,821,736 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\npDeployJava1.dll
[2012/10/03 22:45:35 | 000,746,984 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll
[2012/10/03 22:45:35 | 000,246,760 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2012/10/03 22:45:35 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2012/10/03 22:45:35 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2012/10/03 22:45:35 | 000,143,872 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2012/10/01 17:50:38 | 000,147,086 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.zip
[2012/09/30 22:37:57 | 001,756,929 | ---- | M] () -- C:\Documents and Settings\Me\My Documents\gurc.pdf
[2012/09/30 07:34:00 | 000,000,747 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
[2012/09/30 07:33:30 | 000,198,864 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll
[2012/09/30 07:33:14 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll
[2012/09/30 07:33:14 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll
[2012/09/30 07:33:11 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\WINDOWS\System32\pncrt.dll
[2012/09/28 21:27:06 | 000,000,553 | ---- | M] () -- C:\Documents and Settings\Me\Desktop\edit-ghost.gif
[2012/09/22 03:04:23 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/09/21 11:18:24 | 000,696,240 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/09/21 11:18:24 | 000,073,136 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/09/21 11:18:22 | 010,213,296 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerInstaller.exe
[2012/09/21 09:34:20 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\Me\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/09/21 09:34:20 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/21 09:24:23 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/09/19 19:25:06 | 000,010,302 | -HS- | M] () -- C:\Documents and Settings\Me\Desktop\Folder.jpg
[2012/09/19 19:25:06 | 000,002,264 | -HS- | M] () -- C:\Documents and Settings\Me\Desktop\AlbumArtSmall.jpg
[2012/09/18 18:56:52 | 096,373,559 | ---- | M] () -- C:\Documents and Settings\Me\Desktop\OoP_Podcast122_RichardKaczynski.mp3
[2012/09/07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/10/04 08:38:23 | 000,458,240 | ---- | C] () -- C:\Documents and Settings\Me\Desktop\CKScanner.exe
[2012/09/30 22:37:57 | 001,756,929 | ---- | C] () -- C:\Documents and Settings\Me\My Documents\gurc.pdf
[2012/09/30 07:34:00 | 000,000,747 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\RealPlayer.lnk
[2012/09/28 21:27:03 | 000,000,553 | ---- | C] () -- C:\Documents and Settings\Me\Desktop\edit-ghost.gif
[2012/09/21 09:34:20 | 000,000,802 | ---- | C] () -- C:\Documents and Settings\Me\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/09/18 18:53:46 | 096,373,559 | ---- | C] () -- C:\Documents and Settings\Me\Desktop\OoP_Podcast122_RichardKaczynski.mp3
[2012/01/17 17:32:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\PowerReg.dat
[2012/01/15 13:52:33 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\BRTCPCON.DLL
[2012/01/15 13:52:32 | 000,000,114 | ---- | C] () -- C:\WINDOWS\System32\BRLMW03A.INI
[2012/01/15 13:52:31 | 000,000,050 | ---- | C] () -- C:\WINDOWS\System32\BRADM10A.DAT
[2012/01/13 13:04:26 | 000,315,392 | ---- | C] () -- C:\WINDOWS\System32\ANPDApi.dll
[2012/01/13 13:04:26 | 000,048,640 | ---- | C] () -- C:\WINDOWS\System32\ANPD64.SYS
[2012/01/13 13:04:26 | 000,029,411 | ---- | C] () -- C:\WINDOWS\System32\ANPD.SYS
[2012/01/13 13:03:51 | 000,014,051 | ---- | C] () -- C:\WINDOWS\System32\RaCoInst.dat
[2011/12/05 11:42:07 | 000,155,136 | ---- | C] () -- C:\WINDOWS\System32\AI_ContextMenu.dll
[2011/11/17 23:15:33 | 000,000,076 | RHS- | C] () -- C:\WINDOWS\CT4CET.bin
[2011/11/17 21:58:11 | 000,031,616 | ---- | C] () -- C:\WINDOWS\System32\drivers\livecamv.sys
[2011/09/20 21:28:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ViewNX2.INI
[2011/09/20 21:04:15 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Galaxy Swirl
[2011/09/20 21:04:15 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Galactic Static
[2011/09/20 21:04:15 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Funk Animals
[2011/09/20 21:04:15 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Me\Application Data\Frameworks
[2011/09/20 21:04:15 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Me\Application Data\Framework
[2011/09/20 21:04:15 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Me\Application Data\Fonts
[2011/09/20 21:04:15 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT
[2011/09/20 21:04:15 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLet.DAT
[2011/09/20 21:04:15 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLes.DAT
[2011/05/20 09:57:28 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2011/05/02 18:16:57 | 000,000,354 | ---- | C] () -- C:\WINDOWS\HEGAMES.INI
[2011/04/19 22:10:32 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\OVDecode.dll
[2011/02/12 17:32:08 | 000,000,818 | ---- | C] () -- C:\WINDOWS\Brpfx04a.ini
[2011/02/12 17:32:08 | 000,000,153 | ---- | C] () -- C:\WINDOWS\brpcfx.ini
[2011/02/12 17:31:59 | 000,000,419 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2011/02/12 17:31:40 | 000,000,050 | ---- | C] () -- C:\WINDOWS\System32\bridf08b.dat
[2011/02/12 17:31:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\brdfxspd.dat
[2011/02/12 17:31:36 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\BrMuSNMP.dll
[2011/02/12 17:29:20 | 000,031,767 | ---- | C] () -- C:\WINDOWS\maxlink.ini
[2011/01/15 19:07:57 | 000,138,264 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2011/01/15 19:07:56 | 000,138,056 | ---- | C] () -- C:\Documents and Settings\Me\Application Data\PnkBstrK.sys
[2011/01/15 19:07:39 | 000,234,768 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.exe
[2011/01/15 19:07:35 | 003,360,624 | ---- | C] () -- C:\WINDOWS\System32\pbsvc.exe
[2011/01/15 19:07:35 | 000,075,136 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrA.exe
[2011/01/01 03:28:19 | 000,043,052 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/11/16 10:04:11 | 000,819,200 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010/11/16 10:04:11 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010/09/01 15:35:46 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Me\Local Settings\Application Data\PUTTY.RND
[2010/08/19 14:31:13 | 000,002,516 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
[2010/08/19 14:31:13 | 000,000,088 | RHS- | C] () -- C:\Documents and Settings\All Users\Application Data\82EFD4432E.sys
[2010/07/11 10:46:26 | 000,167,936 | ---- | C] () -- C:\Documents and Settings\Me\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2012/09/20 20:56:56 | 000,002,048 | -HS- | M] () -- C:\RECYCLER\S-1-5-18\$07295d3001730d5c2e5b1f5281e9217c\@
[2012/09/21 19:31:09 | 000,000,000 | -HSD | M] -- C:\RECYCLER\S-1-5-18\$07295d3001730d5c2e5b1f5281e9217c\U
[2010/08/19 14:29:39 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2010/04/16 09:09:07 | 001,509,888 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 05:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/13 17:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/09/21 09:18:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\036DFF9800001BEA004D4DA77B07D329
[2010/11/02 09:27:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Borland
[2011/12/12 13:46:46 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/10/25 16:28:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Easybits GO
[2011/09/20 21:04:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2010/07/17 17:40:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2012/10/05 15:17:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GameXN
[2011/09/20 21:04:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Iterate Items
[2011/09/20 21:04:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Keychains
[2011/09/20 21:04:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Limiter
[2010/12/07 22:30:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Macrium
[2011/09/20 21:06:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nikon
[2011/02/12 17:29:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/08/19 22:36:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Smart Soft
[2010/09/29 16:17:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/04/19 11:48:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TrackMania
[2011/09/20 21:04:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2011/01/29 15:28:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Uninstall
[2010/07/11 10:27:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2012/08/12 15:43:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\xml_param
[2011/09/20 19:11:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Zeon
[2010/07/11 16:18:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/07/29 20:36:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\.ABC
[2012/10/05 14:33:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\.minecraft
[2012/08/07 09:38:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\.techniclauncher
[2011/12/02 20:31:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\Aimersoft Video Converter Ultimate
[2012/09/30 16:43:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\AskToolbar
[2011/04/17 22:52:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\Azureus
[2012/05/28 18:13:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\calibre
[2011/12/12 13:50:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\Canon Easy-WebPrint EX
[2010/07/10 15:43:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/01/03 12:19:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\DDMSettings
[2011/03/04 12:56:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\DMCache
[2012/10/05 14:47:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\Dropbox
[2010/08/23 16:54:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\Easy Thumbnails
[2012/10/03 22:51:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\FileZilla
[2011/08/04 13:37:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\GARMIN
[2010/11/02 09:33:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\GetRightToGo
[2012/10/05 14:47:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\go
[2012/01/13 13:03:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\Leadertech
[2011/08/31 21:54:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\Mobipocket
[2012/04/04 12:48:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\MP3 Editor for Free
[2011/06/01 07:06:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\MSNInstaller
[2011/09/20 21:06:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\Nikon
[2010/10/14 11:44:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\OpenOffice.org
[2011/12/15 15:51:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\PC-FAX TX
[2011/03/24 09:31:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\pdfforge
[2012/09/30 16:42:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\PriceGong
[2011/03/09 11:34:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\ProtectDISC
[2011/09/20 19:11:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\ScanSoft
[2012/09/26 15:11:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\Search Settings
[2010/08/19 22:29:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\Smart PDF Creator Pro
[2011/05/23 22:27:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\Smith Micro
[2011/11/07 22:32:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\SystemRequirementsLab
[2011/11/17 22:31:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\tmp
[2012/03/04 11:32:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\Uniblue
[2012/10/05 14:44:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\uTorrent
[2012/06/23 10:07:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\wtxpcom
[2011/09/20 19:11:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Me\Application Data\Zeon

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05D195EC

< End of report >


OTL Extras logfile created on: 10/5/2012 3:13:42 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Me\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.09 Gb Available Physical Memory | 69.58% Memory free
4.84 Gb Paging File | 3.92 Gb Available in Paging File | 80.95% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 462.29 Gb Total Space | 77.64 Gb Free Space | 16.80% Space Free | Partition Type: NTFS

Computer Name: MERLIN | User Name: Me | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_USERS\S-1-5-21-527237240-1972579041-839522115-1004\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
jsfile [edit] -- "C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe" "%1" (Macromedia, Inc.)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- "C:\Program Files\Smart File Advisor\sfa.exe" /unknown "%1" (Filefacts.net)
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"54925:UDP" = 54925:UDP:*:Enabled:BrotherNetwork Scanner
"1047:TCP" = 1047:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- (Microsoft Corporation)
"C:\WINDOWS\system32\usmt\migwiz.exe" = C:\WINDOWS\system32\usmt\migwiz.exe:*:Disabled:Files and Settings Transfer Wizard -- (Microsoft Corporation)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager
"C:\Program Files\World of Warcraft\Launcher.exe" = C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher
"C:\Program Files\ABC\abc.exe" = C:\Program Files\ABC\abc.exe:*:Enabled:abc
"C:\Program Files\Microsoft Games\Age of Empires II\EMPIRES2.ICD" = C:\Program Files\Microsoft Games\Age of Empires II\EMPIRES2.ICD:*:Disabled:Age of Empires II
"C:\Program Files\GameSpy Arcade\Aphex.exe" = C:\Program Files\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade
"C:\Program Files\Microsoft Games\Halo Trial\halo.exe" = C:\Program Files\Microsoft Games\Halo Trial\halo.exe:*:Disabled:Halo
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth -- (Google)
"C:\Program Files\Vuze\Azureus.exe" = C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus / Vuze
"C:\Documents and Settings\Me\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Me\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox -- (Dropbox, Inc.)
"C:\Program Files\Simple Port Forwarding\spf.exe" = C:\Program Files\Simple Port Forwarding\spf.exe:*:Enabled:Simple Port Forwarding -- (PcWinTech.com)
"C:\WINDOWS\system32\PnkBstrA.exe" = C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA -- ()
"C:\WINDOWS\system32\PnkBstrB.exe" = C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB -- ()
"C:\Program Files\Mozilla Firefox\plugin-container.exe" = C:\Program Files\Mozilla Firefox\plugin-container.exe:*:Disabled:Plugin Container for Firefox -- (Mozilla Corporation)
"C:\Program Files\Valve\Steam\SteamApps\common\the ball demo\Binaries\Win32\TheBall.exe" = C:\Program Files\Valve\Steam\SteamApps\common\the ball demo\Binaries\Win32\TheBall.exe:*:Enabled:The Ball Demo
"C:\Program Files\Valve\Steam\SteamApps\flyingmojo\half-life 2 deathmatch\hl2.exe" = C:\Program Files\Valve\Steam\SteamApps\flyingmojo\half-life 2 deathmatch\hl2.exe:*:Enabled:hl2
"C:\Program Files\EA Games\Battlefield Play4Free\BFP4f.exe" = C:\Program Files\EA Games\Battlefield Play4Free\BFP4f.exe:*:Enabled:BFP4f -- ()
"C:\Program Files\Macromedia\Dreamweaver 8\Dreamweaver.exe" = C:\Program Files\Macromedia\Dreamweaver 8\Dreamweaver.exe:*:Enabled:Dreamweaver 8 -- (Macromedia, Inc.)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
"C:\WINDOWS\system32\rundll32.exe" = C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App -- (Microsoft Corporation)
"C:\Program Files\Infogrames\Putt Putt Saves the Zoo\puttzoo.exe" = C:\Program Files\Infogrames\Putt Putt Saves the Zoo\puttzoo.exe:*:Enabled:sputm90r
"C:\Program Files\Valve\Steam\SteamApps\common\trackmania nations forever\TmForever.exe" = C:\Program Files\Valve\Steam\SteamApps\common\trackmania nations forever\TmForever.exe:*:Enabled:TrackMania Nations Forever
"C:\Program Files\Valve\Steam\SteamApps\common\trackmania nations forever\TmForeverLauncher.exe" = C:\Program Files\Valve\Steam\SteamApps\common\trackmania nations forever\TmForeverLauncher.exe:*:Enabled:TrackMania Nations Forever
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)
"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger -- (Microsoft Corporation)
"C:\Program Files\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe" = C:\Program Files\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe:*:Enabled:Blizzard Downloader
"C:\Program Files\World of Warcraft\Launcher.patch.exe" = C:\Program Files\World of Warcraft\Launcher.patch.exe:*:Enabled:Blizzard Launcher
"C:\Program Files\Microsoft Games\Halo 2\halo2.exe" = C:\Program Files\Microsoft Games\Halo 2\halo2.exe:*:Enabled:Halo 2
"C:\Documents and Settings\Me\Local Settings\Application Data\Akamai\netsession_win.exe" = C:\Documents and Settings\Me\Local Settings\Application Data\Akamai\netsession_win.exe:*:Disabled:netsession_win -- (Akamai Technologies, Inc.)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Disabled:Java(TM) Platform SE binary
"C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Disabled:VLC media player -- ()
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service -- (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent
"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Disabled:Java(TM) Platform SE binary
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02570AE0-BEE0-4A6C-BE3F-D806E9F2EA17}" = ScanSoft PaperPort 11
"{0837A661-FEC3-48B3-876C-91E7D32048A9}" = Macromedia Dreamweaver 8
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{0CA38F52-F0FA-4B9F-8A36-EC8A9609FBBC}" = Halo 2 for Windows Vista
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP250_series" = Canon MP250 series MP Drivers
"{19A492A0-888F-44A0-9B21-D91700763F62}" = Catalyst Control Center - Branding
"{1D5E29AD-39A9-4D0A-A8B6-46A6FCD8C995}" = Live! Cam Avatar v1.0
"{1DF03ECE-6AF4-414E-B118-C316F151A9A2}" = Corel WordPerfect Office - iFilter
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{1F77C418-2C90-459C-BD33-B56A4182B9FA}" = System Requirements Lab CYRI
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2515EAA9-AE9F-4F0A-8301-B40034838B8A}" = Livestream Procaster
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 7
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2BC2781A-F7F6-452E-95EB-018A522F1B2C}" = PaperPort Image Printer
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{342126E1-173C-4585-BFBE-3EBDD20E3E9E}" = Mobipocket Reader 6.2
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36CDA33B-909B-4719-97D1-C4B99309BDC7}" = ATI Parental Control & Encoder
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{529125EF-E3AC-4B74-97E6-F688A7C0F1BF}" = Paint.NET v3.5.10
"{531336A9-55EB-4367-8064-7180849D5676}" = calibre
"{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager
"{582876EC-A178-44D4-9823-C10D6C62EAFF}" = AGEIA PhysX v2.6.0
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}" = Brother MFL-Pro Suite MFC-295CN
"{6C9EF6DE-391E-665A-92F2-2BF72DF53E61}" = Catalyst Control Center
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{777CA40C-0206-4EF6-A0FC-618BF06BF8D0}" = Intel(R) PRO Network Connections 12.1.12.0
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{839916F4-D8B5-4407-BE6D-6D4EB9D96AF4}" = LIVE gaming on Windows Runtime Version 1.0.6027
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{87441A59-5E64-4096-A170-14EFE67200C3}" = Picture Control Utility
"{87686C21-8A15-4b4d-A3F1-11141D9BE094}" = Battlefield Play4Free
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A25FF1C0-80B6-4B8B-A551-DC525697A408}" = AMD APP SDK Runtime
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A71D5E81-B967-43DB-93D7-FD31BFB95748}" = MobileMe Control Panel
"{A8DF1374-7E6B-448A-87BB-2DCE71874F2B}" = Macrium Reflect - Free Edition
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{AC76BA86-7AD7-2447-0000-900000000003}" = Chinese Simplified Fonts Support For Adobe Reader 9
"{AFBF90DF-9FBE-002F-E8F4-2EC713678BD7}" = Catalyst Control Center InstallProxy
"{B014EE44-9197-4513-9613-71E6EB1B514E}" = Nikon Message Center 2
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BB85B4D1-FE48-9AC2-ACF3-5833D539C606}" = ATI Catalyst Install Manager
"{BB9C808A-2F32-41ED-BCFC-DE3A32590A6F}" = Singorama! Bonus Software
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2F6A415-2A69-48F1-8F91-B9381B33FF1A}" = pdfforge Toolbar v6.3
"{C85C8CE6-CA92-7CDC-75C3-AA9C22E7FD75}" = ccc-utility
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D41DA7B0-DE4C-20A5-FC4C-F00327548F0D}" = CCC Help English
"{DDD62492-32A7-412B-8AF1-2CF032AD42E3}" = ViewNX 2
"{E2A97415-BD97-4867-B906-05E39E9EE51F}" = HL-2270DW
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6D6B258-E3CA-4AAC-965A-68D3E3140A8C}" = iTunes
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"{F90D9C89-7918-7994-66CC-513C4A92D3A6}" = Catalyst Control Center Graphics Previews Common
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"7-Zip" = 7-Zip 4.65
"AC3Filter_is1" = AC3Filter 1.62b
"Acoustica Effects Pack" = Acoustica Effects Pack
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Advanced Video FX Engine" = Advanced Video FX Engine
"Aimersoft Video Converter Ultimate_is1" = Aimersoft Video Converter Ultimate(Build 4.1.0.2)
"Akamai" = Akamai NetSession Interface Service
"AltoMP3 Gold" = AltoMP3 Gold 5.20
"Audacity_is1" = Audacity 1.2.6
"Avira AntiVir Desktop" = Avira Free Antivirus
"AVS Screen Capture_is1" = AVS Screen Capture version 2.0.1
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS Video Editor_is1" = AVS Video Editor 5
"AVS Video Recorder_is1" = AVS Video Recorder 2.4
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"CanonMyPrinter" = Canon Utilities My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Creative OEM003" = Monitor Integrated Webcam Driver (1.00.13.0608)
"DELL Webcam Center" = DELL Webcam Center
"DELL Webcam Manager" = DELL Webcam Manager
"DivX Setup" = DivX Setup
"DjVuLibre+DjView" = DjVuLibre+DjView
"DVD Shrink_is1" = DVD Shrink 3.2
"Easy Thumbnails_is1" = Easy Thumbnails (Remove only)
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"Elecard MPEG-2 PlugIn for WMP 4.1.100318" = Elecard MPEG-2 PlugIn for WMP
"EPSON Printer and Utilities" = EPSON Printer Software
"FileZilla Client" = FileZilla Client 3.5.3
"Free PDF to Word Doc Converter_is1" = Free PDF to Word Doc Converter v1.1
"FreeOnlineRadioPlayerRecorder Toolbar" = FreeOnlineRadioPlayerRecorder Toolbar
"Freez FLV to MP3 Converter v1.5_is1" = Freez FLV to MP3 Converter
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"ie8" = Windows Internet Explorer 8
"InstallShield_{471BB1D9-6F59-4093-B46D-373772D5C111}" = Far Cry Demo
"IsoBuster_is1" = IsoBuster 2.8.5
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.0.1400
"Manga Studio EX 4.0" = Manga Studio EX 4.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 15.0.1 (x86 en-US)" = Mozilla Firefox 15.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 3.0" = Canon MP Navigator EX 3.0
"MP3 Editor for Free_is1" = MP3 Editor for Free v7.0.1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA Drivers" = NVIDIA Drivers
"Patch-2.5.9-7_is1" = GnuWin32: Patch-2.5.9-7
"PunkBusterSvc" = PunkBuster Services
"RealPlayer 15.0" = RealPlayer
"Simple Port Forwarding" = Simple Port Forwarding
"SING & SEE PROFESSIONAL_is1" = SING & SEE v1.4.9
"Smart File Advisor_is1" = Smart File Advisor 1.1.1
"Spin It Again" = Spin It Again
"Steam App 11020" = TrackMania Nations Forever
"VLC media player" = VLC media player 1.0.1
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xvid_is1" = Xvid 1.2.2 final uninstall
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-527237240-1972579041-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Avira SearchFree Toolbar plus Web Protection Updater
"Akamai" = Akamai NetSession Interface
"Dropbox" = Dropbox
"f031ef6ac137efc5" = Dell Driver Download Manager
"Flux" = F.lux
"Game Organizer" = GameXN GO
"uTorrent" = µTorrent

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 10/5/2012 6:18:35 PM | Computer Name = MERLIN | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/10/05 15:18:35.671]: [00003532]: GetDeviceIpAddress:
GetAddressByName [BRN001BA963C296] Error

Error - 10/5/2012 6:19:10 PM | Computer Name = MERLIN | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/10/05 15:19:10.171]: [00003532]: GetDeviceIpAddress:
GetAddressByName [BRN001BA963C296] Error

Error - 10/5/2012 6:19:44 PM | Computer Name = MERLIN | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/10/05 15:19:44.671]: [00003532]: GetDeviceIpAddress:
GetAddressByName [BRN001BA963C296] Error

Error - 10/5/2012 6:20:19 PM | Computer Name = MERLIN | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/10/05 15:20:19.187]: [00003532]: GetDeviceIpAddress:
GetAddressByName [BRN001BA963C296] Error

Error - 10/5/2012 6:20:53 PM | Computer Name = MERLIN | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/10/05 15:20:53.687]: [00003532]: GetDeviceIpAddress:
GetAddressByName [BRN001BA963C296] Error

Error - 10/5/2012 6:21:28 PM | Computer Name = MERLIN | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/10/05 15:21:28.187]: [00003532]: GetDeviceIpAddress:
GetAddressByName [BRN001BA963C296] Error

Error - 10/5/2012 6:22:02 PM | Computer Name = MERLIN | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/10/05 15:22:02.687]: [00003532]: GetDeviceIpAddress:
GetAddressByName [BRN001BA963C296] Error

Error - 10/5/2012 6:22:37 PM | Computer Name = MERLIN | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/10/05 15:22:37.187]: [00003532]: GetDeviceIpAddress:
GetAddressByName [BRN001BA963C296] Error

Error - 10/5/2012 6:23:11 PM | Computer Name = MERLIN | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/10/05 15:23:11.687]: [00003532]: GetDeviceIpAddress:
GetAddressByName [BRN001BA963C296] Error

Error - 10/5/2012 6:23:46 PM | Computer Name = MERLIN | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/10/05 15:23:46.203]: [00003532]: GetDeviceIpAddress:
GetAddressByName [BRN001BA963C296] Error

[ System Events ]
Error - 9/21/2012 12:18:28 PM | Computer Name = MERLIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 9/21/2012 12:24:37 PM | Computer Name = MERLIN | Source = Service Control Manager | ID = 7024
Description = The Avira Realtime Protection service terminated with service-specific
error 306 (0x132).

Error - 9/21/2012 12:24:37 PM | Computer Name = MERLIN | Source = Service Control Manager | ID = 7001
Description = The Avira Web Protection service depends on the Avira Realtime Protection
service which failed to start because of the following error: %%1066

Error - 9/21/2012 12:27:33 PM | Computer Name = MERLIN | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM
Service service to connect.

Error - 9/21/2012 12:27:33 PM | Computer Name = MERLIN | Source = Service Control Manager | ID = 7000
Description = The IMAPI CD-Burning COM Service service failed to start due to the
following error: %%1053

Error - 9/21/2012 12:36:09 PM | Computer Name = MERLIN | Source = Service Control Manager | ID = 7024
Description = The Avira Realtime Protection service terminated with service-specific
error 306 (0x132).

Error - 9/21/2012 12:36:09 PM | Computer Name = MERLIN | Source = Service Control Manager | ID = 7001
Description = The Avira Web Protection service depends on the Avira Realtime Protection
service which failed to start because of the following error: %%1066

Error - 9/21/2012 10:32:57 PM | Computer Name = MERLIN | Source = Service Control Manager | ID = 7024
Description = The Avira Realtime Protection service terminated with service-specific
error 306 (0x132).

Error - 9/21/2012 10:32:57 PM | Computer Name = MERLIN | Source = Service Control Manager | ID = 7001
Description = The Avira Web Protection service depends on the Avira Realtime Protection
service which failed to start because of the following error: %%1066

Error - 10/1/2012 10:37:15 PM | Computer Name = MERLIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}


< End of report >
flyingmojo
Regular Member
 
Posts: 51
Joined: August 21st, 2009, 10:59 pm

Re: googleads.l.doublee-click.net

Unread postby flyingmojo » October 5th, 2012, 7:12 pm

OTL Extras logfile created on: 10/5/2012 3:13:42 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Me\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.09 Gb Available Physical Memory | 69.58% Memory free
4.84 Gb Paging File | 3.92 Gb Available in Paging File | 80.95% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 462.29 Gb Total Space | 77.64 Gb Free Space | 16.80% Space Free | Partition Type: NTFS

Computer Name: MERLIN | User Name: Me | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_USERS\S-1-5-21-527237240-1972579041-839522115-1004\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
jsfile [edit] -- "C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe" "%1" (Macromedia, Inc.)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- "C:\Program Files\Smart File Advisor\sfa.exe" /unknown "%1" (Filefacts.net)
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"54925:UDP" = 54925:UDP:*:Enabled:BrotherNetwork Scanner
"1047:TCP" = 1047:TCP:*:Enabled:Akamai NetSession Interface
"5000:UDP" = 5000:UDP:*:Enabled:Akamai NetSession Interface

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- (Microsoft Corporation)
"C:\WINDOWS\system32\usmt\migwiz.exe" = C:\WINDOWS\system32\usmt\migwiz.exe:*:Disabled:Files and Settings Transfer Wizard -- (Microsoft Corporation)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager
"C:\Program Files\World of Warcraft\Launcher.exe" = C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:Blizzard Launcher
"C:\Program Files\ABC\abc.exe" = C:\Program Files\ABC\abc.exe:*:Enabled:abc
"C:\Program Files\Microsoft Games\Age of Empires II\EMPIRES2.ICD" = C:\Program Files\Microsoft Games\Age of Empires II\EMPIRES2.ICD:*:Disabled:Age of Empires II
"C:\Program Files\GameSpy Arcade\Aphex.exe" = C:\Program Files\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade
"C:\Program Files\Microsoft Games\Halo Trial\halo.exe" = C:\Program Files\Microsoft Games\Halo Trial\halo.exe:*:Disabled:Halo
"C:\Program Files\Google\Google Earth\client\googleearth.exe" = C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth -- (Google)
"C:\Program Files\Vuze\Azureus.exe" = C:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus / Vuze
"C:\Documents and Settings\Me\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Me\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox -- (Dropbox, Inc.)
"C:\Program Files\Simple Port Forwarding\spf.exe" = C:\Program Files\Simple Port Forwarding\spf.exe:*:Enabled:Simple Port Forwarding -- (PcWinTech.com)
"C:\WINDOWS\system32\PnkBstrA.exe" = C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA -- ()
"C:\WINDOWS\system32\PnkBstrB.exe" = C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB -- ()
"C:\Program Files\Mozilla Firefox\plugin-container.exe" = C:\Program Files\Mozilla Firefox\plugin-container.exe:*:Disabled:Plugin Container for Firefox -- (Mozilla Corporation)
"C:\Program Files\Valve\Steam\SteamApps\common\the ball demo\Binaries\Win32\TheBall.exe" = C:\Program Files\Valve\Steam\SteamApps\common\the ball demo\Binaries\Win32\TheBall.exe:*:Enabled:The Ball Demo
"C:\Program Files\Valve\Steam\SteamApps\flyingmojo\half-life 2 deathmatch\hl2.exe" = C:\Program Files\Valve\Steam\SteamApps\flyingmojo\half-life 2 deathmatch\hl2.exe:*:Enabled:hl2
"C:\Program Files\EA Games\Battlefield Play4Free\BFP4f.exe" = C:\Program Files\EA Games\Battlefield Play4Free\BFP4f.exe:*:Enabled:BFP4f -- ()
"C:\Program Files\Macromedia\Dreamweaver 8\Dreamweaver.exe" = C:\Program Files\Macromedia\Dreamweaver 8\Dreamweaver.exe:*:Enabled:Dreamweaver 8 -- (Macromedia, Inc.)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test -- (Microsoft Corporation)
"C:\WINDOWS\system32\rundll32.exe" = C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App -- (Microsoft Corporation)
"C:\Program Files\Infogrames\Putt Putt Saves the Zoo\puttzoo.exe" = C:\Program Files\Infogrames\Putt Putt Saves the Zoo\puttzoo.exe:*:Enabled:sputm90r
"C:\Program Files\Valve\Steam\SteamApps\common\trackmania nations forever\TmForever.exe" = C:\Program Files\Valve\Steam\SteamApps\common\trackmania nations forever\TmForever.exe:*:Enabled:TrackMania Nations Forever
"C:\Program Files\Valve\Steam\SteamApps\common\trackmania nations forever\TmForeverLauncher.exe" = C:\Program Files\Valve\Steam\SteamApps\common\trackmania nations forever\TmForeverLauncher.exe:*:Enabled:TrackMania Nations Forever
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger -- (Microsoft Corporation)
"C:\Program Files\Messenger\msmsgs.exe" = C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger -- (Microsoft Corporation)
"C:\Program Files\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe" = C:\Program Files\World of Warcraft\WoW-x.x.x.x-4.0.0.12911-Downloader.exe:*:Enabled:Blizzard Downloader
"C:\Program Files\World of Warcraft\Launcher.patch.exe" = C:\Program Files\World of Warcraft\Launcher.patch.exe:*:Enabled:Blizzard Launcher
"C:\Program Files\Microsoft Games\Halo 2\halo2.exe" = C:\Program Files\Microsoft Games\Halo 2\halo2.exe:*:Enabled:Halo 2
"C:\Documents and Settings\Me\Local Settings\Application Data\Akamai\netsession_win.exe" = C:\Documents and Settings\Me\Local Settings\Application Data\Akamai\netsession_win.exe:*:Disabled:netsession_win -- (Akamai Technologies, Inc.)
"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Disabled:Java(TM) Platform SE binary
"C:\Program Files\VideoLAN\VLC\vlc.exe" = C:\Program Files\VideoLAN\VLC\vlc.exe:*:Disabled:VLC media player -- ()
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit -- (Apple Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service -- (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent
"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Disabled:Java(TM) Platform SE binary
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02570AE0-BEE0-4A6C-BE3F-D806E9F2EA17}" = ScanSoft PaperPort 11
"{0837A661-FEC3-48B3-876C-91E7D32048A9}" = Macromedia Dreamweaver 8
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{0CA38F52-F0FA-4B9F-8A36-EC8A9609FBBC}" = Halo 2 for Windows Vista
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP250_series" = Canon MP250 series MP Drivers
"{19A492A0-888F-44A0-9B21-D91700763F62}" = Catalyst Control Center - Branding
"{1D5E29AD-39A9-4D0A-A8B6-46A6FCD8C995}" = Live! Cam Avatar v1.0
"{1DF03ECE-6AF4-414E-B118-C316F151A9A2}" = Corel WordPerfect Office - iFilter
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{1F77C418-2C90-459C-BD33-B56A4182B9FA}" = System Requirements Lab CYRI
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2515EAA9-AE9F-4F0A-8301-B40034838B8A}" = Livestream Procaster
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 7
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2BC2781A-F7F6-452E-95EB-018A522F1B2C}" = PaperPort Image Printer
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{342126E1-173C-4585-BFBE-3EBDD20E3E9E}" = Mobipocket Reader 6.2
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36CDA33B-909B-4719-97D1-C4B99309BDC7}" = ATI Parental Control & Encoder
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{529125EF-E3AC-4B74-97E6-F688A7C0F1BF}" = Paint.NET v3.5.10
"{531336A9-55EB-4367-8064-7180849D5676}" = calibre
"{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager
"{582876EC-A178-44D4-9823-C10D6C62EAFF}" = AGEIA PhysX v2.6.0
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}" = Brother MFL-Pro Suite MFC-295CN
"{6C9EF6DE-391E-665A-92F2-2BF72DF53E61}" = Catalyst Control Center
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{777CA40C-0206-4EF6-A0FC-618BF06BF8D0}" = Intel(R) PRO Network Connections 12.1.12.0
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{839916F4-D8B5-4407-BE6D-6D4EB9D96AF4}" = LIVE gaming on Windows Runtime Version 1.0.6027
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{87441A59-5E64-4096-A170-14EFE67200C3}" = Picture Control Utility
"{87686C21-8A15-4b4d-A3F1-11141D9BE094}" = Battlefield Play4Free
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 12
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A25FF1C0-80B6-4B8B-A551-DC525697A408}" = AMD APP SDK Runtime
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A71D5E81-B967-43DB-93D7-FD31BFB95748}" = MobileMe Control Panel
"{A8DF1374-7E6B-448A-87BB-2DCE71874F2B}" = Macrium Reflect - Free Edition
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{AC76BA86-7AD7-2447-0000-900000000003}" = Chinese Simplified Fonts Support For Adobe Reader 9
"{AFBF90DF-9FBE-002F-E8F4-2EC713678BD7}" = Catalyst Control Center InstallProxy
"{B014EE44-9197-4513-9613-71E6EB1B514E}" = Nikon Message Center 2
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{BB85B4D1-FE48-9AC2-ACF3-5833D539C606}" = ATI Catalyst Install Manager
"{BB9C808A-2F32-41ED-BCFC-DE3A32590A6F}" = Singorama! Bonus Software
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2F6A415-2A69-48F1-8F91-B9381B33FF1A}" = pdfforge Toolbar v6.3
"{C85C8CE6-CA92-7CDC-75C3-AA9C22E7FD75}" = ccc-utility
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D41DA7B0-DE4C-20A5-FC4C-F00327548F0D}" = CCC Help English
"{DDD62492-32A7-412B-8AF1-2CF032AD42E3}" = ViewNX 2
"{E2A97415-BD97-4867-B906-05E39E9EE51F}" = HL-2270DW
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F6D6B258-E3CA-4AAC-965A-68D3E3140A8C}" = iTunes
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"{F90D9C89-7918-7994-66CC-513C4A92D3A6}" = Catalyst Control Center Graphics Previews Common
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"7-Zip" = 7-Zip 4.65
"AC3Filter_is1" = AC3Filter 1.62b
"Acoustica Effects Pack" = Acoustica Effects Pack
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Advanced Video FX Engine" = Advanced Video FX Engine
"Aimersoft Video Converter Ultimate_is1" = Aimersoft Video Converter Ultimate(Build 4.1.0.2)
"Akamai" = Akamai NetSession Interface Service
"AltoMP3 Gold" = AltoMP3 Gold 5.20
"Audacity_is1" = Audacity 1.2.6
"Avira AntiVir Desktop" = Avira Free Antivirus
"AVS Screen Capture_is1" = AVS Screen Capture version 2.0.1
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS Video Editor_is1" = AVS Video Editor 5
"AVS Video Recorder_is1" = AVS Video Recorder 2.4
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"CanonMyPrinter" = Canon Utilities My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Creative OEM003" = Monitor Integrated Webcam Driver (1.00.13.0608)
"DELL Webcam Center" = DELL Webcam Center
"DELL Webcam Manager" = DELL Webcam Manager
"DivX Setup" = DivX Setup
"DjVuLibre+DjView" = DjVuLibre+DjView
"DVD Shrink_is1" = DVD Shrink 3.2
"Easy Thumbnails_is1" = Easy Thumbnails (Remove only)
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"Elecard MPEG-2 PlugIn for WMP 4.1.100318" = Elecard MPEG-2 PlugIn for WMP
"EPSON Printer and Utilities" = EPSON Printer Software
"FileZilla Client" = FileZilla Client 3.5.3
"Free PDF to Word Doc Converter_is1" = Free PDF to Word Doc Converter v1.1
"FreeOnlineRadioPlayerRecorder Toolbar" = FreeOnlineRadioPlayerRecorder Toolbar
"Freez FLV to MP3 Converter v1.5_is1" = Freez FLV to MP3 Converter
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"ie8" = Windows Internet Explorer 8
"InstallShield_{471BB1D9-6F59-4093-B46D-373772D5C111}" = Far Cry Demo
"IsoBuster_is1" = IsoBuster 2.8.5
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.0.1400
"Manga Studio EX 4.0" = Manga Studio EX 4.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 15.0.1 (x86 en-US)" = Mozilla Firefox 15.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 3.0" = Canon MP Navigator EX 3.0
"MP3 Editor for Free_is1" = MP3 Editor for Free v7.0.1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA Drivers" = NVIDIA Drivers
"Patch-2.5.9-7_is1" = GnuWin32: Patch-2.5.9-7
"PunkBusterSvc" = PunkBuster Services
"RealPlayer 15.0" = RealPlayer
"Simple Port Forwarding" = Simple Port Forwarding
"SING & SEE PROFESSIONAL_is1" = SING & SEE v1.4.9
"Smart File Advisor_is1" = Smart File Advisor 1.1.1
"Spin It Again" = Spin It Again
"Steam App 11020" = TrackMania Nations Forever
"VLC media player" = VLC media player 1.0.1
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xvid_is1" = Xvid 1.2.2 final uninstall
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-527237240-1972579041-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Avira SearchFree Toolbar plus Web Protection Updater
"Akamai" = Akamai NetSession Interface
"Dropbox" = Dropbox
"f031ef6ac137efc5" = Dell Driver Download Manager
"Flux" = F.lux
"Game Organizer" = GameXN GO
"uTorrent" = µTorrent

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 10/5/2012 6:18:35 PM | Computer Name = MERLIN | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/10/05 15:18:35.671]: [00003532]: GetDeviceIpAddress:
GetAddressByName [BRN001BA963C296] Error

Error - 10/5/2012 6:19:10 PM | Computer Name = MERLIN | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/10/05 15:19:10.171]: [00003532]: GetDeviceIpAddress:
GetAddressByName [BRN001BA963C296] Error

Error - 10/5/2012 6:19:44 PM | Computer Name = MERLIN | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/10/05 15:19:44.671]: [00003532]: GetDeviceIpAddress:
GetAddressByName [BRN001BA963C296] Error

Error - 10/5/2012 6:20:19 PM | Computer Name = MERLIN | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/10/05 15:20:19.187]: [00003532]: GetDeviceIpAddress:
GetAddressByName [BRN001BA963C296] Error

Error - 10/5/2012 6:20:53 PM | Computer Name = MERLIN | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/10/05 15:20:53.687]: [00003532]: GetDeviceIpAddress:
GetAddressByName [BRN001BA963C296] Error

Error - 10/5/2012 6:21:28 PM | Computer Name = MERLIN | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/10/05 15:21:28.187]: [00003532]: GetDeviceIpAddress:
GetAddressByName [BRN001BA963C296] Error

Error - 10/5/2012 6:22:02 PM | Computer Name = MERLIN | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/10/05 15:22:02.687]: [00003532]: GetDeviceIpAddress:
GetAddressByName [BRN001BA963C296] Error

Error - 10/5/2012 6:22:37 PM | Computer Name = MERLIN | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/10/05 15:22:37.187]: [00003532]: GetDeviceIpAddress:
GetAddressByName [BRN001BA963C296] Error

Error - 10/5/2012 6:23:11 PM | Computer Name = MERLIN | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/10/05 15:23:11.687]: [00003532]: GetDeviceIpAddress:
GetAddressByName [BRN001BA963C296] Error

Error - 10/5/2012 6:23:46 PM | Computer Name = MERLIN | Source = Brother BrLog | ID = 1001
Description = STI BrtSTI: [2012/10/05 15:23:46.203]: [00003532]: GetDeviceIpAddress:
GetAddressByName [BRN001BA963C296] Error

[ System Events ]
Error - 9/21/2012 12:18:28 PM | Computer Name = MERLIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 9/21/2012 12:24:37 PM | Computer Name = MERLIN | Source = Service Control Manager | ID = 7024
Description = The Avira Realtime Protection service terminated with service-specific
error 306 (0x132).

Error - 9/21/2012 12:24:37 PM | Computer Name = MERLIN | Source = Service Control Manager | ID = 7001
Description = The Avira Web Protection service depends on the Avira Realtime Protection
service which failed to start because of the following error: %%1066

Error - 9/21/2012 12:27:33 PM | Computer Name = MERLIN | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM
Service service to connect.

Error - 9/21/2012 12:27:33 PM | Computer Name = MERLIN | Source = Service Control Manager | ID = 7000
Description = The IMAPI CD-Burning COM Service service failed to start due to the
following error: %%1053

Error - 9/21/2012 12:36:09 PM | Computer Name = MERLIN | Source = Service Control Manager | ID = 7024
Description = The Avira Realtime Protection service terminated with service-specific
error 306 (0x132).

Error - 9/21/2012 12:36:09 PM | Computer Name = MERLIN | Source = Service Control Manager | ID = 7001
Description = The Avira Web Protection service depends on the Avira Realtime Protection
service which failed to start because of the following error: %%1066

Error - 9/21/2012 10:32:57 PM | Computer Name = MERLIN | Source = Service Control Manager | ID = 7024
Description = The Avira Realtime Protection service terminated with service-specific
error 306 (0x132).

Error - 9/21/2012 10:32:57 PM | Computer Name = MERLIN | Source = Service Control Manager | ID = 7001
Description = The Avira Web Protection service depends on the Avira Realtime Protection
service which failed to start because of the following error: %%1066

Error - 10/1/2012 10:37:15 PM | Computer Name = MERLIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}


< End of report >
flyingmojo
Regular Member
 
Posts: 51
Joined: August 21st, 2009, 10:59 pm

Re: googleads.l.doublee-click.net

Unread postby askey127 » October 5th, 2012, 8:26 pm

flyingmojo,
-----------------------------------------------------------
Your logs show signs of a Remote Access Infection on your computer.
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
...and others
These indicate you have this named infection : .... Zero Access Trojan
See these Antivirus analyses :

A Remote Access Infection will allow the person who infected your computer to use your computer as if he were sitting in front of it, and he may ....
  • Steal bank account details.
  • Steal credit card numbers.
  • Steal your personal details.
  • Modify your computer to make it easier to infect.
  • Use your computer as part of a botnet, to distribute porn or spam.
  • Anything else he cares to think of ..... and most attackers are very inventive people.

You are strongly advised to do the following immediately ....
  • Disconnect the infected computer from the internet and from any networked computers.
  • Call all of your banks, credit card companies, and financial institutions, and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change all your online passwords -- for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.

Do not change passwords or do any transactions while using the infected computer, because the attacker will get the new passwords and transaction information.

The only way to remove these type of infections and leave yourself with a secure computer, is to re-format your hard drive and re-install Windows.

It is impossible to discover all of the modifications that your attacker may have made to your computer while he had access to it, and though we may be able to remove all the obvious signs of infection from your computer, and leave you with an apparently fully functioning machine, that does NOT mean it would be Secure.

If you use your computer for any of the following ....
  • Online Banking.
  • Finances or credit of any kind.
  • Filling out your tax forms online or offline.
  • Filling out Social Security or Personal Insurance forms online or offline.
  • Making online purchases or payments of any type.
  • Anything involving the use of confidential data.
.... then a re-format and re-installation should be the only choice you should make.

If you insist, we are prepared to help you "clean" your machine, but we strongly advise you against this course of action, and you must understand that although we may be able to restore your computer to a usable condition, it will NOT be secure until a re-format and Windows re-installation is performed, and should not be used for any of the activities listed above.
(You will have to remove all cracked programs for us to help you).
To help you decide, please take some time to read the following articles, then let me know how you want to proceed.
askey127
User avatar
askey127
Admin/Teacher
Admin/Teacher
 
Posts: 14025
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA

Re: googleads.l.doublee-click.net

Unread postby flyingmojo » October 5th, 2012, 10:07 pm

Yikes!
Ok, I've disconnected from the internet, and I'm writing this from another PC. I've also limited my account on Paypal. I will have to really do some thinking, but that is really the only online financial stuff I do on my PC (never trusted online banking). I will reformat my hard drive, but before I do, I want to save most of what I have on there - documents and outlook express files. Is this okay to do? This won't reinfect my PC when I transfer all the files to the reformatted hard drive?

Thanks
flyingmojo
Regular Member
 
Posts: 51
Joined: August 21st, 2009, 10:59 pm

Re: googleads.l.doublee-click.net

Unread postby askey127 » October 6th, 2012, 8:13 am

flyingmojo,
You can save files which are Data.
Do not save any Programs, or executable files, or anything in the "Program Files", "Application Data" or "AppData" folders.
Don't save any settings or preferences for browsers.
When you save to another media, and re-install Windows, you will need to get all the Windows Updates, and install a new, updated Antivirus before you do any surfing.
Microsoft Security Essentials is just fine. http://www.microsoft.com/security/pc-security/mse.aspx

When you are ready to copy back your saved documents, do a complete scan of the media you used before copying anything. (Right click on the media Drive letter, choose scan with Antivirus)
Be sure not to copy anything the AV doesn't like.
You can re-install any programs for which you have the original disks.

Going forward, avoid using any P2P sharing programs like utorrent, and surfing any crack or warez sites.
Good luck and be careful what you click on..
askey127
User avatar
askey127
Admin/Teacher
Admin/Teacher
 
Posts: 14025
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA

Re: googleads.l.doublee-click.net

Unread postby askey127 » October 9th, 2012, 6:11 am

Since this issue is being resolved with a Re-Installation of Windows, this thread will be closed.
User avatar
askey127
Admin/Teacher
Admin/Teacher
 
Posts: 14025
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA
Advertisement
Register to Remove


  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 127 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware